mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix: prevent admin escalation when AUTH_ENABLED=false
When auth was disabled, users could log out, reach the login page, and authenticate with the default admin/admin credentials to gain full admin privileges — defeating the purpose of AUTH_ENABLED=false. Defense-in-depth fix across five layers: - Skip ensureDefaultAdmin() when auth is disabled (no admin user seeded) - Return 403 from POST /api/auth/login when auth is disabled - Return synthetic anonymous user from GET /api/auth/session when auth is disabled - Hide logout button in settings when auth is disabled - Redirect /login and /change-password to / via AuthGuard when auth is disabled Closes #90
This commit is contained in:
@@ -36,8 +36,10 @@ import { userFileRoutes } from "./routes/user-files.js";
|
||||
runMigrations();
|
||||
console.log("Database initialized");
|
||||
|
||||
// Create default admin user if no users exist
|
||||
await ensureDefaultAdmin();
|
||||
// Create default admin user if no users exist and auth is enabled
|
||||
if (env.AUTH_ENABLED) {
|
||||
await ensureDefaultAdmin();
|
||||
}
|
||||
|
||||
function ensureInstanceId() {
|
||||
const existing = db
|
||||
|
||||
Reference in New Issue
Block a user