fix(auth): bound OIDC initiation and transport

This commit is contained in:
2026-08-17 07:03:19 +02:00
parent 8573500121
commit bdabecbb63
15 changed files with 747 additions and 111 deletions
+10 -4
View File
@@ -12,6 +12,7 @@ const MAX_ENTRIES = 256;
const TIMEOUT_MS = 5_000;
const DIGEST_FILENAME = /^[a-f0-9]{64}\.json$/;
const CLAIM_FILENAME = /^[a-f0-9]{64}\.claim$/;
const OIDC_SLOT_FILENAME = /^slot-(?:[0-5][0-9]|6[0-3])\.json$/;
const invalid = (): Error => new Error("auth_session_store_invalid");
@@ -119,8 +120,10 @@ function validateRoot(root: string): void {
|| !win32.isAbsolute(root) || win32.normalize(root) !== root) throw invalid();
}
function validateFilename(filename: string, allowClaim = false): void {
if (typeof filename !== "string" || (!DIGEST_FILENAME.test(filename) && !(allowClaim && CLAIM_FILENAME.test(filename)))) throw invalid();
function validateFilename(filename: string, allowClaim = false, allowOidcSlot = false): void {
if (typeof filename !== "string" || (!DIGEST_FILENAME.test(filename)
&& !(allowClaim && CLAIM_FILENAME.test(filename))
&& !(allowOidcSlot && OIDC_SLOT_FILENAME.test(filename)))) throw invalid();
}
function safeThtExecutable(value: string | undefined): string {
@@ -151,7 +154,9 @@ function encodedRequest(request: BridgeRequest): Buffer {
} else {
if (request.filename === undefined) throw invalid();
const allowClaim = request.operation === "remove" && request.directory === "oidc";
validateFilename(request.filename, allowClaim);
const allowOidcSlot = request.directory === "oidc"
&& (request.operation === "create" || request.operation === "read" || request.operation === "remove");
validateFilename(request.filename, allowClaim, allowOidcSlot);
if (request.contentBase64 !== undefined && request.operation !== "create" && request.operation !== "replace") throw invalid();
}
if ((request.operation === "claim-consume" || request.operation === "read-claim" || request.operation === "remove-claim")
@@ -349,7 +354,8 @@ export function createWindowsAuthStorageBridge(options: WindowsAuthStorageBridge
const response = await request({ version: PROTOCOL_VERSION, operation: "list", root, directory });
if (response.entries === undefined) throw invalid();
for (const entry of response.entries) {
if (!DIGEST_FILENAME.test(entry.name) && !(directory === "oidc" && CLAIM_FILENAME.test(entry.name))) throw invalid();
if (!DIGEST_FILENAME.test(entry.name) && !(directory === "oidc"
&& (CLAIM_FILENAME.test(entry.name) || OIDC_SLOT_FILENAME.test(entry.name)))) throw invalid();
}
return response.entries.map((entry) => ({ name: entry.name, modifiedUnixMs: entry.modifiedUnixMs }));
},