fix(auth): honor HTTPS sessions in Pi management

This commit is contained in:
2026-08-17 01:46:34 +02:00
parent 09e546c1ef
commit 8c67cb75dc
5 changed files with 146 additions and 14 deletions
+10
View File
@@ -23,11 +23,21 @@ export function requirePermission(
return reply.code(403).send({ code: "auth_forbidden", error: "This operation is not permitted" });
}
/**
* A resolved cookie session is populated only by the central auth boundary, after its
* request-snapshot Origin and CSRF checks. Route-specific legacy guards must not reinterpret
* the internal transport host/protocol for that already-authorized browser request.
*/
export function hasCookieBackedAuthSession(request: FastifyRequest): boolean {
return request.authSession !== undefined;
}
/** Permit non-browser clients and browsers whose declared origin matches the request host. */
export function requireSameOriginOrNonBrowser(
request: FastifyRequest,
reply: FastifyReply,
): FastifyReply | undefined {
if (hasCookieBackedAuthSession(request)) return undefined;
const origin = request.headers.origin;
if (origin === undefined) return undefined;
if (typeof origin !== "string" || typeof request.headers.host !== "string") {