fix(auth): restore permission boundary safeguards

This commit is contained in:
2026-08-16 18:03:36 +02:00
parent 2e0489ce22
commit f99bddcdf0
8 changed files with 126 additions and 14 deletions
+20
View File
@@ -22,3 +22,23 @@ export function requirePermission(
if (hasPermission(principal, permission)) return principal;
return reply.code(403).send({ code: "auth_forbidden", error: "This operation is not permitted" });
}
/** Permit non-browser clients and browsers whose declared origin matches the request host. */
export function requireSameOriginOrNonBrowser(
request: FastifyRequest,
reply: FastifyReply,
): FastifyReply | undefined {
const origin = request.headers.origin;
if (origin === undefined) return undefined;
if (typeof origin !== "string" || typeof request.headers.host !== "string") {
return reply.code(403).send({ code: "auth_forbidden", error: "This operation is not permitted" });
}
try {
const supplied = new URL(origin);
const expected = new URL(`${request.protocol}://${request.headers.host}`);
if (supplied.origin === expected.origin) return undefined;
} catch {
// Invalid browser origins are forbidden below.
}
return reply.code(403).send({ code: "auth_forbidden", error: "This operation is not permitted" });
}