fix(authz): close memo cross-authorization and guard hardening gaps
Fix round 1 for Task 7, addressing review findings against the brief's
own memoKey design (now superseded per plan amendment cc8085bc):
- C1: memoKey's String(id) + JSON.stringify-with-catch cross-authorized
distinct resources whenever their ids stringified the same (numeric
vs string ids, object-shaped ids) or whenever JSON.stringify threw
(circular references, BigInt fields, throwing getters all shared one
"<unserialisable>" bucket, so the first verdict computed for any of
them became the cached verdict for all of them in that request).
- C2: filterCan inherited the same bypass, returning rows the subject
could not act on.
- Replaced serialisation-based memoization with identity-based
memoization: object resources are memoised in a WeakMap keyed by the
resource reference itself (never serialised), primitives/absent
resources in a Map keyed by [scope, permission, typeof, String(value)]
so 7 and "7" can never collide.
- I1: scope is now read from ctx.tenant at decision time (currentScope),
not captured once at middleware-install time, so a tenant switch
mid-request is honoured on the next check.
- I2/M1: guardPermission's redirectTo now only fires for non-JSON/API
requests (replicated wantsJson check, since authz may only import
core as types) and only for a validated local path (isLocalPath),
closing an open-redirect and a JSON-caller-follows-303 gap.
- I3: getResource is now wrapped in try/catch; a throw denies with the
standard opaque 403 body instead of propagating the loader's error
(e.g. a SQL string) to the client.
- Added cache-control: private, no-store to both the 303 and 403
responses.
Added 11 regression tests. C1/C2 revert-checked: temporarily restored
the old memoKey design and confirmed the four collision tests fail
against it before restoring the fix.
This commit is contained in:
@@ -139,4 +139,131 @@ describe("filterCan", () => {
|
||||
const posts = [{ authorId: "u1" }, { authorId: "other" }, { authorId: "u1" }];
|
||||
expect(await filterCan(ctx, "post:delete", posts)).toHaveLength(2);
|
||||
});
|
||||
|
||||
test("handles BigInt fields and circular references without leaking", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
const store = memoryPermissionStore();
|
||||
await store.grant("u1", "post:delete", "allow");
|
||||
await withMiddleware(ctx, store);
|
||||
|
||||
const mine = { authorId: "u1", views: 10n } as Record<string, unknown>;
|
||||
const other = { authorId: "other", views: 11n } as Record<string, unknown>;
|
||||
const circularMine = { authorId: "u1" } as Record<string, unknown>;
|
||||
circularMine.self = circularMine;
|
||||
const circularOther = { authorId: "other" } as Record<string, unknown>;
|
||||
circularOther.self = circularOther;
|
||||
|
||||
const result = await filterCan(ctx, "post:delete", [mine, other, circularMine, circularOther]);
|
||||
expect(result).toEqual([mine, circularMine]);
|
||||
});
|
||||
|
||||
test("returns an empty array for an empty input", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
await withMiddleware(ctx);
|
||||
expect(await filterCan(ctx, "post:delete", [])).toEqual([]);
|
||||
});
|
||||
});
|
||||
|
||||
describe("memoisation does not cross-authorize distinct resources", () => {
|
||||
test("a numeric id and a string id on different resources do not collide", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
const store = memoryPermissionStore();
|
||||
await store.grant("u1", "post:delete", "allow");
|
||||
await withMiddleware(ctx, store);
|
||||
expect(await can(ctx, "post:delete", { id: 7, authorId: "u1" })).toBe(true);
|
||||
expect(await can(ctx, "post:delete", { id: "7", authorId: "other" })).toBe(false);
|
||||
});
|
||||
|
||||
test("resources with object-shaped ids do not collide", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
const store = memoryPermissionStore();
|
||||
await store.grant("u1", "post:delete", "allow");
|
||||
await withMiddleware(ctx, store);
|
||||
expect(await can(ctx, "post:delete", { id: { tenant: "A" }, authorId: "u1" })).toBe(true);
|
||||
expect(await can(ctx, "post:delete", { id: { tenant: "B" }, authorId: "other" })).toBe(false);
|
||||
});
|
||||
|
||||
test("two distinct resource objects sharing the same id value do not share a verdict", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
const store = memoryPermissionStore();
|
||||
await store.grant("u1", "post:delete", "allow");
|
||||
await withMiddleware(ctx, store);
|
||||
expect(await can(ctx, "post:delete", { id: 1, authorId: "u1" })).toBe(true);
|
||||
expect(await can(ctx, "post:delete", { id: 1, authorId: "other" })).toBe(false);
|
||||
});
|
||||
|
||||
test("switching ctx.tenant mid-request changes the scope for subsequent checks", async () => {
|
||||
const ctx = makeCtx({ id: "u1" }, "t1");
|
||||
const store = memoryPermissionStore();
|
||||
await store.assignRole("u1", "editor", { tenantId: "t1" });
|
||||
await withMiddleware(ctx, store);
|
||||
expect(await can(ctx, "post:write")).toBe(true);
|
||||
(ctx as unknown as { tenant?: { id: string } }).tenant = { id: "t2" };
|
||||
expect(await can(ctx, "post:write")).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe("guardPermission hardening", () => {
|
||||
test("throws the setup error and never calls next without the middleware", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
let called = false;
|
||||
await expect(
|
||||
guardPermission("post:write")(ctx, async () => {
|
||||
called = true;
|
||||
return new Response("passed");
|
||||
}),
|
||||
).rejects.toThrow(/authzMiddleware/);
|
||||
expect(called).toBe(false);
|
||||
});
|
||||
|
||||
test("a throwing getResource denies with the standard body, not the loader's message", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
await withMiddleware(ctx);
|
||||
const guard = guardPermission("post:delete", {
|
||||
getResource: () => {
|
||||
throw new Error("SELECT * FROM posts WHERE id = 1 -- boom");
|
||||
},
|
||||
});
|
||||
const res = await guard(ctx, async () => new Response("passed"));
|
||||
expect(res.status).toBe(403);
|
||||
const body = (await res.json()) as Record<string, unknown>;
|
||||
expect(body).toEqual({ ok: false, error: "Forbidden" });
|
||||
});
|
||||
|
||||
test("redirectTo issues a 303 for a page request", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
await withMiddleware(ctx);
|
||||
const res = await guardPermission("post:write", { redirectTo: "/login" })(
|
||||
ctx,
|
||||
async () => new Response("passed"),
|
||||
);
|
||||
expect(res.status).toBe(303);
|
||||
expect(res.headers.get("location")).toBe("/login");
|
||||
expect(res.headers.get("cache-control")).toBe("private, no-store");
|
||||
});
|
||||
|
||||
test("redirectTo is ignored for an /api/ request, which gets 403 instead", async () => {
|
||||
const ctx = {
|
||||
user: { id: "u1" },
|
||||
tenant: undefined,
|
||||
locals: {},
|
||||
url: new URL("http://localhost/api/x"),
|
||||
req: new Request("http://localhost/api/x"),
|
||||
} as unknown as Context;
|
||||
await withMiddleware(ctx);
|
||||
const res = await guardPermission("post:write", { redirectTo: "/login" })(
|
||||
ctx,
|
||||
async () => new Response("passed"),
|
||||
);
|
||||
expect(res.status).toBe(403);
|
||||
});
|
||||
|
||||
test("an off-site redirectTo is refused and falls back to 403", async () => {
|
||||
const ctx = makeCtx({ id: "u1" });
|
||||
await withMiddleware(ctx);
|
||||
const res = await guardPermission("post:write", {
|
||||
redirectTo: "https://evil.example.com/harvest",
|
||||
})(ctx, async () => new Response("passed"));
|
||||
expect(res.status).toBe(403);
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user