[core] fix: harden auth middleware, WebSocket guard, and policies guard (#1899)
- Add missing return after socket.close() in WebSocket gateway to prevent cross-session event subscription on forbidden connections - Return 401 Unauthorized instead of 500 Internal Server Error when API key header is missing or malformed - Deny by default in PoliciesGuard when no @CheckPolicies handlers are defined, preventing accidental exposure of undecorated endpoints Co-authored-by: Dani Lipari <dani.lipari@dontouch.ch>
This commit is contained in:
1 parent
52222a6b98
commit
f8329c29b1
3 files changed
+6
-2
No files matched your search
@@ -93,6 +93,7 @@ export class WebsocketGatewayCore
|
||||
|
||||
if (!ability.can(Action.Use, new SessionName(session))) {
|
||||
socket.close(WebSocketCloseCode.POLICY_VIOLATION, 'Forbidden');
|
||||
return;
|
||||
}
|
||||
|
||||
this.logger.debug(`New client connected: ${request.url} - ${socket.id}`);
|
||||
|
||||
@@ -1,6 +1,5 @@
|
||||
import {
|
||||
Injectable,
|
||||
InternalServerErrorException,
|
||||
NestMiddleware,
|
||||
UnauthorizedException,
|
||||
} from '@nestjs/common';
|
||||
@@ -16,7 +15,7 @@ export class ApiKeyAuthMiddleware implements NestMiddleware {
|
||||
const exception =
|
||||
err instanceof UnauthorizedException
|
||||
? err
|
||||
: new InternalServerErrorException();
|
||||
: new UnauthorizedException();
|
||||
res.status(exception.getStatus()).json(exception.getResponse());
|
||||
return;
|
||||
}
|
||||
|
||||
@@ -26,6 +26,10 @@ export class PoliciesGuard implements CanActivate {
|
||||
context.getClass(),
|
||||
]) || [];
|
||||
|
||||
if (handlers.length === 0) {
|
||||
throw new ForbiddenException();
|
||||
}
|
||||
|
||||
const req = context.switchToHttp().getRequest();
|
||||
const user = req.user;
|
||||
const ability = this.caslAbilityFactory.createForUser(user);
|
||||
|
||||
Reference in new issue
Block a user