fix(auth): bind current local registry and CORS

This commit is contained in:
2026-08-17 00:34:58 +02:00
parent c34e01e9b9
commit 94c2cd3709
15 changed files with 514 additions and 87 deletions
+10 -3
View File
@@ -2,7 +2,7 @@ import type { FastifyRequest, FastifyReply, preHandlerHookHandler } from "fastif
import { localPrincipal, type PrincipalContext, upstreamPrincipal } from "./principal.js";
import { rolesToPermissions } from "./config.js";
import type { AuthenticationConfigProvider, AuthMode, AuthSessionRecord } from "./types.js";
import type { AuthSessionStore } from "./session-store.js";
import { AuthSessionOperationalError, type AuthSessionStore } from "./session-store.js";
import { deriveCsrfToken, csrfTokensEqual } from "./csrf.js";
import { requireSameOriginOrNonBrowser } from "./authorization.js";
@@ -78,7 +78,10 @@ export function authenticateSession(deps: AuthDependencies): preHandlerHookHandl
try {
session = await deps.sessionStore.resolve(token);
if (session) await deps.sessionStore.touch(token);
} catch {
} catch (error) {
if (error instanceof AuthSessionOperationalError) {
return reply.code(503).send({ code: "auth_unavailable", error: "Authentication is unavailable" });
}
return authenticationRequired(reply);
}
if (!session) return authenticationRequired(reply);
@@ -174,7 +177,11 @@ function singleHeader(value: string | string[] | undefined): string | false | un
function matchesOrigin(request: FastifyRequest, expectedOrigin: string): boolean {
const origin = singleHeader(request.headers.origin);
if (origin !== expectedOrigin) return false;
try {
if (origin === undefined || origin === false || new URL(origin).origin !== expectedOrigin) return false;
} catch {
return false;
}
const fetchSite = singleHeader(request.headers["sec-fetch-site"]);
return fetchSite === undefined || fetchSite === "same-origin";
}