mirror of
https://github.com/snapotter-hq/SnapOtter.git
synced 2026-08-03 07:46:42 +02:00
fix: prevent admin escalation when AUTH_ENABLED=false
When auth was disabled, the backend middleware attached the first admin user from the database to every request, and the frontend granted all 12 permissions. This gave every unauthenticated visitor full admin access to user management, settings, teams, branding, and feature installation. Now both layers use role "user" with user-level permissions so tools, files, and pipelines still work without login while admin-only routes correctly return 403. Closes #72
This commit is contained in:
@@ -659,16 +659,14 @@ function isPublicRoute(url: string): boolean {
|
||||
|
||||
export async function authMiddleware(app: FastifyInstance): Promise<void> {
|
||||
app.addHook("preHandler", async (request: FastifyRequest, reply: FastifyReply) => {
|
||||
// When auth is disabled, attach the first admin user so requireAuth/requireAdmin pass
|
||||
// When auth is disabled, attach a synthetic non-admin user so tools work
|
||||
// but admin-only routes (user management, settings write, etc.) stay locked
|
||||
if (!env.AUTH_ENABLED) {
|
||||
const adminUser = db.select().from(schema.users).where(eq(schema.users.role, "admin")).get();
|
||||
if (adminUser) {
|
||||
(request as FastifyRequest & { user?: AuthUser }).user = {
|
||||
id: adminUser.id,
|
||||
username: adminUser.username,
|
||||
role: "admin",
|
||||
};
|
||||
}
|
||||
(request as FastifyRequest & { user?: AuthUser }).user = {
|
||||
id: "anonymous",
|
||||
username: "anonymous",
|
||||
role: "user",
|
||||
};
|
||||
return;
|
||||
}
|
||||
|
||||
|
||||
@@ -11,19 +11,12 @@ interface AuthState {
|
||||
permissions: string[];
|
||||
}
|
||||
|
||||
const ALL_PERMISSIONS = [
|
||||
const USER_PERMISSIONS = [
|
||||
"tools:use",
|
||||
"files:own",
|
||||
"files:all",
|
||||
"apikeys:own",
|
||||
"apikeys:all",
|
||||
"pipelines:own",
|
||||
"pipelines:all",
|
||||
"settings:read",
|
||||
"settings:write",
|
||||
"users:manage",
|
||||
"teams:manage",
|
||||
"branding:manage",
|
||||
];
|
||||
|
||||
export function useAuth() {
|
||||
@@ -51,8 +44,8 @@ export function useAuth() {
|
||||
authEnabled: false,
|
||||
isAuthenticated: true,
|
||||
mustChangePassword: false,
|
||||
role: "admin",
|
||||
permissions: ALL_PERMISSIONS,
|
||||
role: "user",
|
||||
permissions: USER_PERMISSIONS,
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user