fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -1,5 +1,9 @@
|
||||
import type { FastifyInstance, FastifyReply, FastifyRequest } from "fastify";
|
||||
import { isPrincipalContext, requirePermission } from "../auth/authorization.js";
|
||||
import {
|
||||
isPrincipalContext,
|
||||
requirePermission,
|
||||
requireSameOriginOrNonBrowser,
|
||||
} from "../auth/authorization.js";
|
||||
import { PiManagementError, type PiManagementService } from "../pi/management.js";
|
||||
|
||||
export function piManagementRoutes(
|
||||
@@ -26,6 +30,10 @@ async function run<T>(
|
||||
): Promise<T | FastifyReply> {
|
||||
const principal = requirePermission(request, reply, "pi.manage");
|
||||
if (!isPrincipalContext(principal)) return principal;
|
||||
if (principal.issuer === "local" && isWrite(request.method)) {
|
||||
const csrfDenied = requireSameOriginOrNonBrowser(request, reply);
|
||||
if (csrfDenied) return csrfDenied;
|
||||
}
|
||||
try {
|
||||
return await action();
|
||||
} catch (error) {
|
||||
@@ -36,3 +44,7 @@ async function run<T>(
|
||||
return reply.code(503).send({ code: "pi_management_unavailable", error: "Pi management is unavailable" });
|
||||
}
|
||||
}
|
||||
|
||||
function isWrite(method: string): boolean {
|
||||
return method === "POST" || method === "PUT" || method === "PATCH" || method === "DELETE";
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user