mirror of
https://github.com/fawney19/Aether.git
synced 2026-10-07 01:47:47 +08:00
feat(security): harden gateway boundaries and usage policies
Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change. Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
This commit is contained in:
@@ -628,7 +628,7 @@ fn classifies_admin_management_token_write_routes_and_permission_catalog() {
|
||||
http::Method::POST,
|
||||
"/api/admin/management-tokens",
|
||||
"create_token",
|
||||
"admin:management_tokens:write",
|
||||
"admin:management_tokens:admin",
|
||||
),
|
||||
(
|
||||
http::Method::PUT,
|
||||
@@ -640,7 +640,7 @@ fn classifies_admin_management_token_write_routes_and_permission_catalog() {
|
||||
http::Method::POST,
|
||||
"/api/admin/management-tokens/token-123/regenerate",
|
||||
"regenerate_token",
|
||||
"admin:management_tokens:write",
|
||||
"admin:management_tokens:admin",
|
||||
),
|
||||
];
|
||||
|
||||
|
||||
@@ -68,11 +68,11 @@ fn classifies_admin_provider_oauth_batch_import_task_status_as_admin_proxy_route
|
||||
);
|
||||
assert_eq!(
|
||||
decision.auth_endpoint_signature.as_deref(),
|
||||
Some("admin:pool")
|
||||
Some("admin:provider_oauth")
|
||||
);
|
||||
assert_eq!(
|
||||
management_token_required_permission(&http::Method::GET, &decision).as_deref(),
|
||||
Some("admin:pool:read")
|
||||
Some("admin:provider_oauth:read")
|
||||
);
|
||||
assert!(!decision.is_execution_runtime_candidate());
|
||||
}
|
||||
@@ -86,42 +86,42 @@ fn classifies_admin_provider_oauth_maintenance_routes_as_admin_proxy_route() {
|
||||
"/api/admin/provider-oauth/keys/key-123/complete",
|
||||
"complete_key_oauth",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/keys/key-123/refresh",
|
||||
"refresh_key_oauth",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/providers/provider-123/complete",
|
||||
"complete_provider_oauth",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/providers/provider-123/import-refresh-token",
|
||||
"import_refresh_token",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/providers/provider-123/cookie-authorize",
|
||||
"cookie_authorize",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/providers/provider-123/cookie-authorize/tasks",
|
||||
"start_cookie_authorize_task",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::GET,
|
||||
@@ -135,7 +135,7 @@ fn classifies_admin_provider_oauth_maintenance_routes_as_admin_proxy_route() {
|
||||
"/api/admin/provider-oauth/providers/provider-123/agent-identity-import/tasks",
|
||||
"start_agent_identity_import_task",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::GET,
|
||||
@@ -148,22 +148,22 @@ fn classifies_admin_provider_oauth_maintenance_routes_as_admin_proxy_route() {
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/providers/provider-123/batch-import",
|
||||
"batch_import_oauth",
|
||||
"admin:pool",
|
||||
"admin:pool:write",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
"/api/admin/provider-oauth/providers/provider-123/batch-import/tasks",
|
||||
"start_batch_import_oauth_task",
|
||||
"admin:pool",
|
||||
"admin:pool:write",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
(
|
||||
http::Method::GET,
|
||||
"/api/admin/provider-oauth/providers/provider-123/batch-import/tasks/task-123",
|
||||
"get_batch_import_task_status",
|
||||
"admin:pool",
|
||||
"admin:pool:read",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:read",
|
||||
),
|
||||
(
|
||||
http::Method::POST,
|
||||
@@ -177,7 +177,7 @@ fn classifies_admin_provider_oauth_maintenance_routes_as_admin_proxy_route() {
|
||||
"/api/admin/provider-oauth/providers/provider-123/device-poll",
|
||||
"device_poll",
|
||||
"admin:provider_oauth",
|
||||
"admin:provider_oauth:write",
|
||||
"admin:provider_oauth:admin",
|
||||
),
|
||||
] {
|
||||
let uri: Uri = path.parse().expect("uri should parse");
|
||||
|
||||
@@ -947,6 +947,34 @@ fn classifies_auth_routes_as_public_support_route() {
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn does_not_classify_state_changing_auth_routes_for_get() {
|
||||
for path in [
|
||||
"/api/auth/login",
|
||||
"/api/auth/refresh",
|
||||
"/api/auth/register",
|
||||
"/api/auth/logout",
|
||||
"/api/auth/send-verification-code",
|
||||
"/api/auth/verify-email",
|
||||
"/api/auth/verification-status",
|
||||
] {
|
||||
let headers = headers(&[]);
|
||||
let uri: Uri = path.parse().expect("uri should parse");
|
||||
assert!(
|
||||
classify_control_route(&http::Method::GET, &uri, &headers).is_none(),
|
||||
"state-changing auth route {path} must not accept GET"
|
||||
);
|
||||
}
|
||||
|
||||
let headers = headers(&[]);
|
||||
let uri: Uri = "/api/auth/me".parse().expect("uri should parse");
|
||||
assert_eq!(
|
||||
classify_control_route(&http::Method::GET, &uri, &headers)
|
||||
.and_then(|decision| decision.route_kind),
|
||||
Some("me".to_string())
|
||||
);
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn classifies_oauth_public_providers_route() {
|
||||
let headers = headers(&[]);
|
||||
|
||||
Reference in New Issue
Block a user