fix(auth): restore permission boundary safeguards
This commit is contained in:
@@ -1,7 +1,7 @@
|
||||
import { expect, test } from "vitest";
|
||||
import Fastify from "fastify";
|
||||
import { authPreHandler, getPrincipal } from "../src/auth/auth.js";
|
||||
import { hasPermission } from "../src/auth/authorization.js";
|
||||
import { hasPermission, requireSameOriginOrNonBrowser } from "../src/auth/authorization.js";
|
||||
import type { PrincipalContext } from "../src/auth/principal.js";
|
||||
import type { Permission } from "../src/auth/types.js";
|
||||
|
||||
@@ -54,3 +54,21 @@ test("compatibility adapters derive roles and permissions before routes inspect
|
||||
expect(elevated.json()).toMatchObject({ roles: ["admin"], isAdmin: true });
|
||||
expect(malformed.json()).toMatchObject({ roles: ["user"], isAdmin: false });
|
||||
});
|
||||
|
||||
test("same-origin guard permits non-browser and same-origin calls but rejects a cross-origin browser", async () => {
|
||||
const app = Fastify();
|
||||
app.get("/guard", async (request, reply) => {
|
||||
const denied = requireSameOriginOrNonBrowser(request, reply);
|
||||
return denied ?? { ok: true };
|
||||
});
|
||||
|
||||
expect((await app.inject({ method: "GET", url: "/guard" })).statusCode).toBe(200);
|
||||
expect((await app.inject({
|
||||
method: "GET", url: "/guard", headers: { host: "127.0.0.1:8080", origin: "http://127.0.0.1:8080" },
|
||||
})).statusCode).toBe(200);
|
||||
const denied = await app.inject({
|
||||
method: "GET", url: "/guard", headers: { host: "127.0.0.1:8080", origin: "https://evil.example" },
|
||||
});
|
||||
expect(denied.statusCode).toBe(403);
|
||||
expect(denied.json()).toEqual({ code: "auth_forbidden", error: "This operation is not permitted" });
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user