Files
WRNexusJS/packages/dev-server/test/gateway-basic-auth.test.ts
ClintchizandClaude Opus 5 c64434a131 fix(security): close SSRF, credential-leak, and auth bypass findings in 0.8.4
Audit of 0.8.4 found the repo's own gates green, so these came from manual
review; each is covered by a new regression test.

security/fetch.ts
- safeFetch re-attached Authorization/Cookie on a same-origin redirect that
  followed a cross-origin hop (a -> b -> b), handing credentials to the second
  host. Compare against the origin the caller trusted, not the previous hop.
- The private-network guard resolved the host, approved it, then let fetch
  resolve again, so a low-TTL record could answer public for the check and
  private for the connection. Pin the connection to the validated address,
  preserving Host and TLS serverName. Opt out with pinDns: false.
- 0:0:0:0:0:ffff:127.0.0.1, ::ffff:7f00:1 and fec0::1 were not treated as
  private. Add uncompressed IPv4-mapped forms, site-local IPv6, 198.18/15
  and 192.0.0/24.

security/url.ts
- sanitizeUrl returned "//evil.com" verbatim via the relative-path fast path,
  bypassing the host checks it had just run; in an href that navigates
  cross-origin. Resolve protocol-relative input instead.

dev-server/gateway.ts
- Malformed base64 in an Authorization header threw out of checkAuth on an
  unauthenticated path. Fail closed.
- split(":", 2) truncated passwords at the first colon, so a password
  containing ":" could never authenticate.
- The credential compare short-circuited on length mismatch, leaking length
  by timing. Extracted as verifyBasicAuth so it is testable.

authz/index.ts
- Namespace wildcards only matched the first segment, so "post:comment:*"
  did not grant "post:comment:delete". Match at every depth.

uploader/operations.ts
- Validate transcoder dimensions and bitrate rather than trusting the declared
  type, and reject ".." path segments.

package.json
- The brace-expansion override pinned 5.0.8, which is inside the advisory
  range >=4.0.0 <5.0.9. Bump to 5.0.9; bun audit is now clean.

Verified: check:production passes (typecheck, lint, 1033 tests, format,
ASVS, public-API baseline, editor checks).

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-08-04 15:57:22 +05:30

41 lines
1.5 KiB
TypeScript

import { describe, expect, test } from "bun:test";
import { verifyBasicAuth } from "../src/gateway.ts";
const pairs = [
{ user: "admin", pass: "hunter2" },
{ user: "ops", pass: "p:a:s:s" },
];
const basic = (raw: string) => `Basic ${btoa(raw)}`;
describe("gateway basic auth", () => {
test("accepts a configured pair", () => {
expect(verifyBasicAuth(basic("admin:hunter2"), pairs)).toBe(true);
});
test("accepts a password containing colons", () => {
// split(":", 2) used to truncate this to "p", so it could never match.
expect(verifyBasicAuth(basic("ops:p:a:s:s"), pairs)).toBe(true);
});
test("rejects wrong credentials", () => {
expect(verifyBasicAuth(basic("admin:wrong"), pairs)).toBe(false);
expect(verifyBasicAuth(basic("nobody:hunter2"), pairs)).toBe(false);
});
test("fails closed on malformed input instead of throwing", () => {
// An unauthenticated request must not be able to raise a 500 here.
expect(() => verifyBasicAuth("Basic !!!!not-base64", pairs)).not.toThrow();
expect(verifyBasicAuth("Basic !!!!not-base64", pairs)).toBe(false);
expect(verifyBasicAuth(basic("no-colon-at-all"), pairs)).toBe(false);
expect(verifyBasicAuth("Bearer token", pairs)).toBe(false);
expect(verifyBasicAuth(null, pairs)).toBe(false);
expect(verifyBasicAuth(undefined, pairs)).toBe(false);
expect(verifyBasicAuth("", pairs)).toBe(false);
});
test("empty credentials never match", () => {
expect(verifyBasicAuth(basic(":"), pairs)).toBe(false);
});
});