Discovered during code review of PR #397 (issue #222, "add authentication to production/session/preset management API endpoints").
PR #397 correctly guards all production/session/preset/participant-disconnect mutation endpoints with the requireApiKey preHandler. However, two mutating /api/v1/share endpoints were left unauthenticated and are outside #222's stated scope:
src/api_share.ts — POST /api/v1/share: persists a share link to the DB (dbManager.addShareLink) and mints OSC delegate tokens via mintOscShareUrl. With API_KEY set, any client with network reach can still create share links → real OSC token/cost/access exposure.
src/api_share.ts — DELETE /api/v1/share/:id ("Revoke a reusable share link", dbManager.deleteShareLink): an unauthenticated caller can revoke arbitrary share links (DoS).
Recommendation
Apply preHandler: requireApiKey to both routes (the frontend already sends Bearer to /share), consistent with the management-plane guarding introduced in #397. Add integration-test coverage mirroring src/api_auth_guard.test.ts.
Note
PR #397's description claims it guards "All /api/v1/ management endpoints" — that wording is inaccurate given these two routes; worth correcting if the PR body is referenced later.
Discovered during code review of PR #397 (issue #222, "add authentication to production/session/preset management API endpoints").
PR #397 correctly guards all production/session/preset/participant-disconnect mutation endpoints with the
requireApiKeypreHandler. However, two mutating/api/v1/shareendpoints were left unauthenticated and are outside #222's stated scope:src/api_share.ts—POST /api/v1/share: persists a share link to the DB (dbManager.addShareLink) and mints OSC delegate tokens viamintOscShareUrl. WithAPI_KEYset, any client with network reach can still create share links → real OSC token/cost/access exposure.src/api_share.ts—DELETE /api/v1/share/:id("Revoke a reusable share link",dbManager.deleteShareLink): an unauthenticated caller can revoke arbitrary share links (DoS).Recommendation
Apply
preHandler: requireApiKeyto both routes (the frontend already sendsBearerto/share), consistent with the management-plane guarding introduced in #397. Add integration-test coverage mirroringsrc/api_auth_guard.test.ts.Note
PR #397's description claims it guards "All
/api/v1/management endpoints" — that wording is inaccurate given these two routes; worth correcting if the PR body is referenced later.