fix(authz): fold subject into the memo key, fix symbol/-0 and redirect issues

Fix round 2 for Task 7 (plan amendment 9e3624e5):

- N1 (Important): the memo key carried scope and permission but not the
  subject, so a request that reassigns ctx.user mid-flight (impersonation,
  step-up auth, session revocation, or an authz-before-auth middleware
  ordering mistake) could be served the previous principal's cached
  verdict. subjectId (typeof + String, matching the existing scope/value
  encoding style) is now folded into every memo key.
- N2 (Minor): the primitive-value memo key used String(resource), which
  collapses distinct Symbol("row") values into one slot and maps -0 onto
  0's slot. Added a dedicated bySymbol identity memo (WeakMap-style, but a
  plain Map since symbols aren't valid WeakMap keys pre-registry symbols
  and the memo is request-scoped anyway) and special-cased Object.is(x,-0)
  to render as "-0".
- N3 (Minor): the rejected-redirect console.error interpolated
  redirectTo directly, exactly the value most likely to carry CR/LF in
  that branch. Switched to JSON.stringify(redirectTo) for the log line.
- N4 (Minor): a non-ASCII (but otherwise valid, local) redirectTo passed
  isLocalPath and then threw inside `new Response` building the Location
  header. Wrapped it in encodeURI().

Added 5 regression tests: subject swap re-evaluates, clearing ctx.user
denies, two same-description symbols get separate verdicts, 0 vs -0 get
separate verdicts, non-ASCII redirectTo 303s with an encoded location
instead of throwing. N1 revert-checked: temporarily restored the
two-element (no-subject) key and confirmed both subject-swap tests fail
against it before restoring the fix.
This commit is contained in:
2026-08-04 18:59:56 +05:30
parent 9e3624e584
commit 77b9e49bf2
2 changed files with 133 additions and 10 deletions
+90
View File
@@ -203,6 +203,83 @@ describe("memoisation does not cross-authorize distinct resources", () => {
});
});
describe("memoisation does not cross-authorize distinct subjects", () => {
test("swapping ctx.user mid-request re-evaluates for the new subject", async () => {
const ctx = makeCtx({ id: "u1" });
const store = memoryPermissionStore();
await store.grant("u1", "post:delete", "allow");
await withMiddleware(ctx, store);
const resource = { authorId: "u1" };
expect(await can(ctx, "post:delete", resource)).toBe(true);
(ctx as unknown as { user?: unknown }).user = { id: "u2" };
expect(await can(ctx, "post:delete", resource)).toBe(false);
});
test("clearing ctx.user mid-request denies rather than replaying the old verdict", async () => {
const ctx = makeCtx({ id: "u1" });
const store = memoryPermissionStore();
await store.assignRole("u1", "editor");
await withMiddleware(ctx, store);
expect(await can(ctx, "post:write")).toBe(true);
(ctx as unknown as { user?: unknown }).user = null;
expect(await can(ctx, "post:write")).toBe(false);
});
});
describe("memoisation identity edge cases", () => {
test("two distinct symbols with the same description do not share a verdict", async () => {
const approved = Symbol("row");
const other = Symbol("row");
const localCatalog = mergeCatalogs([
{
source: "symbol-identity-test.ts",
module: defineAuthz({
permissions: { "sym:pick": {} },
policies: {
isApproved: async (_s: unknown, r?: unknown) =>
r === approved ? { allowed: true } : { allowed: false, reason: "not approved" },
},
bindings: { "sym:pick": ["isApproved"] },
}),
},
]);
const ctx = makeCtx({ id: "u1" });
const store = memoryPermissionStore();
await store.grant("u1", "sym:pick", "allow");
await authzMiddleware({ catalog: localCatalog, store, strict: false })(
ctx,
async () => new Response("ok"),
);
expect(await can(ctx, "sym:pick", approved)).toBe(true);
expect(await can(ctx, "sym:pick", other)).toBe(false);
});
test("0 and -0 do not share a verdict", async () => {
const localCatalog = mergeCatalogs([
{
source: "negative-zero-test.ts",
module: defineAuthz({
permissions: { "zero:pick": {} },
policies: {
isPositiveZero: async (_s: unknown, r?: unknown) =>
Object.is(r, 0) ? { allowed: true } : { allowed: false, reason: "not +0" },
},
bindings: { "zero:pick": ["isPositiveZero"] },
}),
},
]);
const ctx = makeCtx({ id: "u1" });
const store = memoryPermissionStore();
await store.grant("u1", "zero:pick", "allow");
await authzMiddleware({ catalog: localCatalog, store, strict: false })(
ctx,
async () => new Response("ok"),
);
expect(await can(ctx, "zero:pick", 0)).toBe(true);
expect(await can(ctx, "zero:pick", -0)).toBe(false);
});
});
describe("guardPermission hardening", () => {
test("throws the setup error and never calls next without the middleware", async () => {
const ctx = makeCtx({ id: "u1" });
@@ -242,6 +319,19 @@ describe("guardPermission hardening", () => {
expect(res.headers.get("cache-control")).toBe("private, no-store");
});
test("a non-ASCII redirectTo returns 303 with an encoded location rather than throwing", async () => {
const ctx = makeCtx({ id: "u1" });
await withMiddleware(ctx);
// Built at runtime (no \u escapes in source) per the repo-wide constraint.
const target = "/" + String.fromCharCode(0x65e5) + String.fromCharCode(0x672c);
const res = await guardPermission("post:write", { redirectTo: target })(
ctx,
async () => new Response("passed"),
);
expect(res.status).toBe(303);
expect(res.headers.get("location")).toBe(encodeURI(target));
});
test("redirectTo is ignored for an /api/ request, which gets 403 instead", async () => {
const ctx = {
user: { id: "u1" },