Problem
require_auth (crates/trapfalld/src/auth.rs:244-250) decides public routes with path.ends_with("/setup"), ends_with("/auth/login"), ends_with("/auth/logout") and path.contains("/envelope/"). Dashboard routes embed user-controlled slugs (/api/0/projects/{slug}/...), and create_project does no slug validation.
Scenario
A project with slug setup or envelope makes GET/PATCH/DELETE /api/0/projects/setup and /api/0/projects/envelope/issues|search skip authentication.
Fix
- Match exact paths (
==) and /api/{id}/envelope/ by segment.
- Reject reserved slugs on project create/update.
- Preferably split public and protected routers instead of string matching in one middleware (
protected_routes() already exists but is unused).
- Add regression tests for slugs
setup, envelope, login.
Found in static audit of develop @ db3ca67.
Problem
require_auth(crates/trapfalld/src/auth.rs:244-250) decides public routes withpath.ends_with("/setup"),ends_with("/auth/login"),ends_with("/auth/logout")andpath.contains("/envelope/"). Dashboard routes embed user-controlled slugs (/api/0/projects/{slug}/...), andcreate_projectdoes no slug validation.Scenario
A project with slug
setuporenvelopemakesGET/PATCH/DELETE /api/0/projects/setupand/api/0/projects/envelope/issues|searchskip authentication.Fix
==) and/api/{id}/envelope/by segment.protected_routes()already exists but is unused).setup,envelope,login.Found in static audit of develop @ db3ca67.