Skip to content

fix: guard unauthenticated /api/v1/share POST and DELETE endpoints - #400

Merged
birme merged 1 commit into
mainfrom
bug-fixer/fix-399-guard-share-endpoints
Oct 7, 2026
Merged

birme merged 1 commit into
mainfrom
bug-fixer/fix-399-guard-share-endpoints

Conversation

@birme

@birme birme commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

Summary

  • Add requireApiKey preHandler to POST /api/v1/share and DELETE /api/v1/share/:id in src/api_share.ts, closing an auth gap where any network-reachable client could mint OSC delegate tokens or revoke arbitrary share links even with API_KEY set (Security: guard unauthenticated /api/v1/share mutation endpoints (POST + DELETE) #399).
  • Leave the public GET /api/v1/share/:id redemption endpoint unauthenticated — recipients must be able to open share links without a key.
  • Add src/api_share_auth_guard.test.ts covering: unauthenticated POST/DELETE rejected with 401, GET still public, authenticated POST passes the guard (mirrors src/api_auth_guard.test.ts).

Test plan

  • Tests pass (npx jest src/api_share_auth_guard.test.ts src/api_rate_limit.test.ts src/api_auth_guard.test.ts — 18 passed)
  • TypeScript compiles (npm run typecheck)
  • Lint clean (npm run lint)
  • Manual: POST /api/v1/share and DELETE /api/v1/share/:id return 401 without a Bearer token when API_KEY is set; GET /api/v1/share/:id still redeems

Closes #399

🤖 Generated with Claude Code

)

The POST /share (persists a share link + mints OSC delegate tokens) and
DELETE /share/:id (revokes a share link) mutating endpoints were missing
the requireApiKey preHandler that guards every other management-plane
mutation. Add the existing, already-tested guard to both routes. The
public GET /share/:id redemption endpoint stays unauthenticated so
recipients can still open share links.

Add src/api_share_auth_guard.test.ts asserting the two mutating routes
return 401 when unauthenticated, the GET redemption route stays public,
and an authenticated POST passes the guard.

Co-Authored-By: Claude Opus 4.8 <[email protected]>
@birme

birme commented Oct 7, 2026

Copy link
Copy Markdown
Contributor Author

code-reviewer verdict: LGTM (self-authored PR — recorded as a marker since GitHub blocks state-bearing self-review).

Zero Blocking, zero Warnings. The fix adds the existing requireApiKey preHandler to POST /api/v1/share and DELETE /api/v1/share/:id while intentionally leaving the public GET /api/v1/share/:id redemption route open, matching the guard convention in api_groups.ts/api_productions.ts. New regression test api_share_auth_guard.test.ts exercises the unauthenticated→401 path for both routes plus positive GET/authenticated-POST checks. CI green (lint, pretty, ts, unittests all SUCCESS).

@birme
birme merged commit 459be23 into main Oct 7, 2026
4 checks passed
@birme
birme deleted the bug-fixer/fix-399-guard-share-endpoints branch October 7, 2026 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security: guard unauthenticated /api/v1/share mutation endpoints (POST + DELETE)

2 participants