fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -102,7 +102,8 @@ export function sessionRoutes(
|
||||
admissionLeases.set(req, release);
|
||||
});
|
||||
app.addHook("preHandler", async (req, reply) => {
|
||||
if (req.url === "/runtime/prewarm" || req.url === "/sessions" || req.url.startsWith("/sessions/")) {
|
||||
const pathname = req.url.split("?", 1)[0];
|
||||
if (pathname === "/runtime/prewarm" || pathname === "/sessions" || pathname.startsWith("/sessions/")) {
|
||||
const principal = requirePermission(req, reply, "session.use");
|
||||
if (!isPrincipalContext(principal)) return principal;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user