fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -3,7 +3,7 @@ import type { ThtRunner } from "../tht/tht-runner.js";
|
||||
import type { PrincipalContext } from "../auth/principal.js";
|
||||
import type { Settings } from "../settings/settings-store.js";
|
||||
import type { WorkspaceRegistry } from "../workspaces/registry.js";
|
||||
import { isPrincipalContext, requirePermission } from "../auth/authorization.js";
|
||||
import { hasPermission, isPrincipalContext, requirePermission } from "../auth/authorization.js";
|
||||
|
||||
export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
tht: ThtRunner; getSettings: (principal: PrincipalContext) => Promise<Settings>;
|
||||
@@ -13,11 +13,16 @@ export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
const runner = deps.tht as any;
|
||||
return typeof runner.withPrincipal === "function" ? runner.withPrincipal(principal) : runner;
|
||||
};
|
||||
const readPrincipal = (principal: PrincipalContext): PrincipalContext => ({
|
||||
...principal,
|
||||
// The harness still consumes this compatibility bit; it must never exceed session.read_all.
|
||||
isAdmin: hasPermission(principal, "session.read_all"),
|
||||
});
|
||||
const isNotFound = (error: unknown) => /not found|non trovata|inesistente|404/i.test(
|
||||
error instanceof Error ? error.message : String(error),
|
||||
);
|
||||
const locate = async (principal: PrincipalContext, id: string, legacyWorkspace?: string) => {
|
||||
const runner = runnerFor(principal);
|
||||
const runner = runnerFor(readPrincipal(principal));
|
||||
if (typeof runner.sessionShow !== "function") return { manifest: {}, workspace: legacyWorkspace };
|
||||
const registry = deps.workspaceRegistry as Partial<WorkspaceRegistry>;
|
||||
const revisions = typeof registry.listRetainedSnapshots === "function"
|
||||
@@ -65,7 +70,7 @@ export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
return reply.code(503).send({ error: "session storage is unavailable" });
|
||||
}
|
||||
try {
|
||||
return await runnerFor(principal).sqlPreview(id, { limit, offset }, workspace);
|
||||
return await runnerFor(readPrincipal(principal)).sqlPreview(id, { limit, offset }, workspace);
|
||||
} catch (error: any) {
|
||||
return reply.code(500).send({ error: error.message ?? String(error) });
|
||||
}
|
||||
@@ -87,7 +92,7 @@ export function sqlRoutes(app: FastifyInstance, deps: {
|
||||
return reply.code(503).send({ error: "session storage is unavailable" });
|
||||
}
|
||||
try {
|
||||
return await runnerFor(principal).sqlExport(id, workspace);
|
||||
return await runnerFor(readPrincipal(principal)).sqlExport(id, workspace);
|
||||
} catch (error: any) {
|
||||
return reply.code(500).send({ error: error.message ?? String(error) });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user