Skip to content

Security: guard unauthenticated /api/v1/share mutation endpoints (POST + DELETE) #399

Description

@birme

Discovered during code review of PR #397 (issue #222, "add authentication to production/session/preset management API endpoints").

PR #397 correctly guards all production/session/preset/participant-disconnect mutation endpoints with the requireApiKey preHandler. However, two mutating /api/v1/share endpoints were left unauthenticated and are outside #222's stated scope:

  • src/api_share.ts — POST /api/v1/share: persists a share link to the DB (dbManager.addShareLink) and mints OSC delegate tokens via mintOscShareUrl. With API_KEY set, any client with network reach can still create share links → real OSC token/cost/access exposure.
  • src/api_share.ts — DELETE /api/v1/share/:id ("Revoke a reusable share link", dbManager.deleteShareLink): an unauthenticated caller can revoke arbitrary share links (DoS).

Recommendation

Apply preHandler: requireApiKey to both routes (the frontend already sends Bearer to /share), consistent with the management-plane guarding introduced in #397. Add integration-test coverage mirroring src/api_auth_guard.test.ts.

Note

PR #397's description claims it guards "All /api/v1/ management endpoints" — that wording is inaccurate given these two routes; worth correcting if the PR body is referenced later.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions