Files
WRNexusJS/packages
Clintchiz b7f3507b59 fix(authz): close memo cross-authorization and guard hardening gaps
Fix round 1 for Task 7, addressing review findings against the brief's
own memoKey design (now superseded per plan amendment cc8085bc):

- C1: memoKey's String(id) + JSON.stringify-with-catch cross-authorized
  distinct resources whenever their ids stringified the same (numeric
  vs string ids, object-shaped ids) or whenever JSON.stringify threw
  (circular references, BigInt fields, throwing getters all shared one
  "<unserialisable>" bucket, so the first verdict computed for any of
  them became the cached verdict for all of them in that request).
- C2: filterCan inherited the same bypass, returning rows the subject
  could not act on.
- Replaced serialisation-based memoization with identity-based
  memoization: object resources are memoised in a WeakMap keyed by the
  resource reference itself (never serialised), primitives/absent
  resources in a Map keyed by [scope, permission, typeof, String(value)]
  so 7 and "7" can never collide.
- I1: scope is now read from ctx.tenant at decision time (currentScope),
  not captured once at middleware-install time, so a tenant switch
  mid-request is honoured on the next check.
- I2/M1: guardPermission's redirectTo now only fires for non-JSON/API
  requests (replicated wantsJson check, since authz may only import
  core as types) and only for a validated local path (isLocalPath),
  closing an open-redirect and a JSON-caller-follows-303 gap.
- I3: getResource is now wrapped in try/catch; a throw denies with the
  standard opaque 403 body instead of propagating the loader's error
  (e.g. a SQL string) to the client.
- Added cache-control: private, no-store to both the 303 and 403
  responses.

Added 11 regression tests. C1/C2 revert-checked: temporarily restored
the old memoKey design and confirmed the four collision tests fail
against it before restoring the fix.
2026-08-04 18:41:18 +05:30
..
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30
2026-08-04 12:19:09 +05:30