fix: prevent admin escalation when AUTH_ENABLED=false

When auth was disabled, the backend middleware attached the first admin
user from the database to every request, and the frontend granted all 12
permissions. This gave every unauthenticated visitor full admin access
to user management, settings, teams, branding, and feature installation.

Now both layers use role "user" with user-level permissions so tools,
files, and pipelines still work without login while admin-only routes
correctly return 403.

Closes #72
This commit is contained in:
ashim-hq
2026-04-21 23:38:42 +08:00
parent 7d422c2fd0
commit bf73150301
2 changed files with 10 additions and 19 deletions
+7 -9
View File
@@ -659,16 +659,14 @@ function isPublicRoute(url: string): boolean {
export async function authMiddleware(app: FastifyInstance): Promise<void> {
app.addHook("preHandler", async (request: FastifyRequest, reply: FastifyReply) => {
// When auth is disabled, attach the first admin user so requireAuth/requireAdmin pass
// When auth is disabled, attach a synthetic non-admin user so tools work
// but admin-only routes (user management, settings write, etc.) stay locked
if (!env.AUTH_ENABLED) {
const adminUser = db.select().from(schema.users).where(eq(schema.users.role, "admin")).get();
if (adminUser) {
(request as FastifyRequest & { user?: AuthUser }).user = {
id: adminUser.id,
username: adminUser.username,
role: "admin",
};
}
(request as FastifyRequest & { user?: AuthUser }).user = {
id: "anonymous",
username: "anonymous",
role: "user",
};
return;
}
+3 -10
View File
@@ -11,19 +11,12 @@ interface AuthState {
permissions: string[];
}
const ALL_PERMISSIONS = [
const USER_PERMISSIONS = [
"tools:use",
"files:own",
"files:all",
"apikeys:own",
"apikeys:all",
"pipelines:own",
"pipelines:all",
"settings:read",
"settings:write",
"users:manage",
"teams:manage",
"branding:manage",
];
export function useAuth() {
@@ -51,8 +44,8 @@ export function useAuth() {
authEnabled: false,
isAuthenticated: true,
mustChangePassword: false,
role: "admin",
permissions: ALL_PERMISSIONS,
role: "user",
permissions: USER_PERMISSIONS,
});
return;
}