[core] fix: harden auth middleware, WebSocket guard, and policies guard (#1899)

- Add missing return after socket.close() in WebSocket gateway to
  prevent cross-session event subscription on forbidden connections
- Return 401 Unauthorized instead of 500 Internal Server Error when
  API key header is missing or malformed
- Deny by default in PoliciesGuard when no @CheckPolicies handlers
  are defined, preventing accidental exposure of undecorated endpoints

Co-authored-by: Dani Lipari <dani.lipari@dontouch.ch>
This commit is contained in:
Dani LipariandDani Lipari authored and GitHub committed 2026-02-16 14:34:50 +07:00
1 parent 52222a6b98
commit f8329c29b1
3 files changed
+6 -2

No files matched your search

+1
View File
@@ -93,6 +93,7 @@ export class WebsocketGatewayCore
if (!ability.can(Action.Use, new SessionName(session))) {
socket.close(WebSocketCloseCode.POLICY_VIOLATION, 'Forbidden');
return;
}
this.logger.debug(`New client connected: ${request.url} - ${socket.id}`);
+1 -2
View File
@@ -1,6 +1,5 @@
import {
Injectable,
InternalServerErrorException,
NestMiddleware,
UnauthorizedException,
} from '@nestjs/common';
@@ -16,7 +15,7 @@ export class ApiKeyAuthMiddleware implements NestMiddleware {
const exception =
err instanceof UnauthorizedException
? err
: new InternalServerErrorException();
: new UnauthorizedException();
res.status(exception.getStatus()).json(exception.getResponse());
return;
}
+4
View File
@@ -26,6 +26,10 @@ export class PoliciesGuard implements CanActivate {
context.getClass(),
]) || [];
if (handlers.length === 0) {
throw new ForbiddenException();
}
const req = context.switchToHttp().getRequest();
const user = req.user;
const ability = this.caslAbilityFactory.createForUser(user);