Skip to content

fix(auth): exact-path public routes + reserved project slugs (#329) - #343

Merged
ajianaz merged 3 commits into
developfrom
fix/329-auth-bypass
Oct 7, 2026
Merged

ajianaz merged 3 commits into
developfrom
fix/329-auth-bypass

Conversation

@ajianaz

@ajianaz ajianaz commented Oct 7, 2026 •

Copy link
Copy Markdown
Contributor

What

require_auth now matches public routes exactly (/health, /metrics, /api/0/config, /api/0/setup, /api/0/auth/login, /api/0/auth/logout) and the ingest route /api/{id}/envelope/ by path segments. create_project/update_project reject empty, /-containing and reserved slugs with 400.

Why

Suffix/substring checks (ends_with("/setup"), contains("/envelope/")) let a project with slug setup or envelope reach /api/0/projects/{slug}... without authentication (view/modify/delete). Fixes #329.

Testing

  • Unit tests for is_public_path.
  • Integration tests: 401 on lookalike paths, public routes still reachable, reserved slug create returns 400.
  • cargo test -p trapfalld and cargo clippy -p trapfalld --all-targets -- -D warnings pass (CI green on Check/Clippy/Test/Format/Build).

Note: unmatched paths (e.g. /api/0/projects/x/setup) fall to the SPA fallback and return the SPA, not API data; unchanged. Cargo/npm Audit failures are pre-existing on develop (new advisories), tracked separately.

🤖 Generated with Claude Code

ajianaz and others added 3 commits October 7, 2026 14:57
…ved project slugs

Fixes #329

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Resolves RUSTSEC-2026-0285 (rustls TLS 1.3 handshake) and the devalue,
source-map-js and undici advisories that fail the Security workflow.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
@ajianaz
ajianaz merged commit 94e2abc into develop Oct 7, 2026
16 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

security: auth bypass via path-suffix matching in require_auth

1 participant