feat(auth): centralize ThothII permission enforcement
This commit is contained in:
@@ -1,11 +1,10 @@
|
||||
import type { FastifyInstance, FastifyReply, FastifyRequest } from "fastify";
|
||||
import { getPrincipal } from "../auth/auth.js";
|
||||
import type { AppConfig } from "../config.js";
|
||||
import { isPrincipalContext, requirePermission } from "../auth/authorization.js";
|
||||
import { PiManagementError, type PiManagementService } from "../pi/management.js";
|
||||
|
||||
export function piManagementRoutes(
|
||||
app: FastifyInstance,
|
||||
deps: { config: AppConfig; service: PiManagementService },
|
||||
deps: { service: PiManagementService },
|
||||
): void {
|
||||
app.get("/pi-management/status", async (request, reply) => run(request, reply, deps, () => deps.service.status()));
|
||||
app.get("/pi-management/options", async (request, reply) => run(request, reply, deps, () => deps.service.options()));
|
||||
@@ -22,17 +21,11 @@ export function piManagementRoutes(
|
||||
async function run<T>(
|
||||
request: FastifyRequest,
|
||||
reply: FastifyReply,
|
||||
deps: { config: AppConfig; service: PiManagementService },
|
||||
deps: { service: PiManagementService },
|
||||
action: () => Promise<T>,
|
||||
): Promise<T | FastifyReply> {
|
||||
const principal = getPrincipal(request);
|
||||
if (!managementAllowed(deps.config, principal.isAdmin)) {
|
||||
return reply.code(403).send({ code: "pi_management_forbidden", error: "Pi management is not permitted" });
|
||||
}
|
||||
if (deps.config.authMode === "none" && isManagementWrite(request.method)
|
||||
&& !sameOriginOrNonBrowser(request)) {
|
||||
return reply.code(403).send({ code: "pi_management_forbidden", error: "Pi management is not permitted" });
|
||||
}
|
||||
const principal = requirePermission(request, reply, "pi.manage");
|
||||
if (!isPrincipalContext(principal)) return principal;
|
||||
try {
|
||||
return await action();
|
||||
} catch (error) {
|
||||
@@ -43,25 +36,3 @@ async function run<T>(
|
||||
return reply.code(503).send({ code: "pi_management_unavailable", error: "Pi management is unavailable" });
|
||||
}
|
||||
}
|
||||
|
||||
function managementAllowed(config: AppConfig, isAdmin: boolean): boolean {
|
||||
return (config.authMode === "none" && !config.publicExposure)
|
||||
|| (config.authMode === "upstream" && isAdmin);
|
||||
}
|
||||
|
||||
function isManagementWrite(method: string): boolean {
|
||||
return method === "POST" || method === "PUT" || method === "PATCH" || method === "DELETE";
|
||||
}
|
||||
|
||||
function sameOriginOrNonBrowser(request: FastifyRequest): boolean {
|
||||
const origin = request.headers.origin;
|
||||
if (origin === undefined) return true;
|
||||
if (typeof origin !== "string" || typeof request.headers.host !== "string") return false;
|
||||
try {
|
||||
const supplied = new URL(origin);
|
||||
const expected = new URL(`${request.protocol}://${request.headers.host}`);
|
||||
return supplied.origin === expected.origin;
|
||||
} catch {
|
||||
return false;
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user