fix(auth): bind request auth snapshots
This commit is contained in:
+13
-15
@@ -4,7 +4,7 @@ import type { AuthenticationConfigProvider, LoadedAuthConfig } from "./types.js"
|
||||
import type { LocalUserRecord, LocalUserRegistry } from "./local-registry.js";
|
||||
import type { AuthSessionStore } from "./session-store.js";
|
||||
import { rolesToPermissions } from "./config.js";
|
||||
import { getPrincipal, requireExactOrigin, sessionCookieName } from "./auth.js";
|
||||
import { captureAuthConfigSnapshot, getPrincipal, requireExactOrigin, sessionCookieName } from "./auth.js";
|
||||
import { requirePermission, isPrincipalContext } from "./authorization.js";
|
||||
import { deriveCsrfToken } from "./csrf.js";
|
||||
import { verifyWithDummy } from "./password.js";
|
||||
@@ -114,17 +114,15 @@ export function registerAuthRoutes(app: FastifyInstance, deps: AuthRouteDependen
|
||||
const limiter = new LoginFailureLimiter();
|
||||
const verificationGate = new VerificationGate();
|
||||
|
||||
app.get("/auth/config", async (_request, reply) => {
|
||||
try {
|
||||
const mode = deps.authentication?.current().value.mode ?? deps.authMode;
|
||||
return reply.send({ mode, localLogin: mode === "local", oidcLogin: false });
|
||||
} catch {
|
||||
return unavailable(reply);
|
||||
}
|
||||
app.get("/auth/config", async (request, reply) => {
|
||||
const snapshot = captureAuthConfigSnapshot(request, deps.authentication);
|
||||
if (!snapshot) return unavailable(reply);
|
||||
const mode = snapshot.value.mode;
|
||||
return reply.send({ mode, localLogin: mode === "local", oidcLogin: false });
|
||||
});
|
||||
|
||||
app.post("/auth/local/login", async (request, reply) => {
|
||||
const configured = currentLocalConfig(deps);
|
||||
const configured = currentLocalConfig(captureAuthConfigSnapshot(request, deps.authentication), deps);
|
||||
if (configured.kind === "unavailable") {
|
||||
return unavailableAfterDummy(verificationGate, argon2SafePassword(loginPayload(request).password), reply);
|
||||
}
|
||||
@@ -189,7 +187,7 @@ export function registerAuthRoutes(app: FastifyInstance, deps: AuthRouteDependen
|
||||
if (!token || !deps.sessionStore) return unavailable(reply);
|
||||
try {
|
||||
await deps.sessionStore.revoke(token);
|
||||
reply.clearCookie(sessionCookieName(), cookieOptions(currentSecure(deps), false));
|
||||
reply.clearCookie(sessionCookieName(), cookieOptions(currentSecure(request), false));
|
||||
return reply.code(204).send();
|
||||
} catch {
|
||||
return unavailable(reply);
|
||||
@@ -235,7 +233,7 @@ export function registerAuthRoutes(app: FastifyInstance, deps: AuthRouteDependen
|
||||
});
|
||||
}
|
||||
|
||||
function currentLocalConfig(deps: AuthRouteDependencies):
|
||||
function currentLocalConfig(loaded: LoadedAuthConfig | undefined, deps: AuthRouteDependencies):
|
||||
| {
|
||||
revision: string;
|
||||
origin: string;
|
||||
@@ -247,8 +245,8 @@ function currentLocalConfig(deps: AuthRouteDependencies):
|
||||
| { kind: "not_local" }
|
||||
| { kind: "unavailable" } {
|
||||
try {
|
||||
const loaded = deps.authentication?.current();
|
||||
if (!loaded || loaded.value.mode !== "local") return { kind: "not_local" };
|
||||
if (!loaded) return { kind: "unavailable" };
|
||||
if (loaded.value.mode !== "local") return { kind: "not_local" };
|
||||
const registry = deps.resolveLocalUserRegistry?.(loaded) ?? deps.localUserRegistry;
|
||||
if (!registry) return { kind: "unavailable" };
|
||||
const url = new URL(loaded.value.publicUrl);
|
||||
@@ -265,8 +263,8 @@ function currentLocalConfig(deps: AuthRouteDependencies):
|
||||
}
|
||||
}
|
||||
|
||||
function currentSecure(deps: AuthRouteDependencies): boolean {
|
||||
try { return new URL(deps.authentication?.current().value.publicUrl ?? "").protocol === "https:"; } catch { return false; }
|
||||
function currentSecure(request: FastifyRequest): boolean {
|
||||
return request.authConfigSnapshot?.value.publicUrl.startsWith("https:") ?? false;
|
||||
}
|
||||
|
||||
function cookieOptions(secure: boolean, remembered: boolean) {
|
||||
|
||||
Reference in New Issue
Block a user