fix(security): require auth for diagnostics endpoint

This commit is contained in:
Brad Groux 2026-01-28 17:36:10 -06:00
parent da1532feec
commit 4531e3799f
3 changed files with 51 additions and 3 deletions

View file

@ -3982,3 +3982,6 @@
{"type":"task.status_changed","taskId":"task_20260128__Lw2Vb","project":"veritas-kanban","status":"done","previousStatus":"in-progress","id":"evt_WFW75mOwCz77","timestamp":"2026-01-28T23:31:09.124Z"}
{"type":"task.status_changed","taskId":"task_20260128_YBVPjr","project":"veritas-kanban","status":"in-progress","previousStatus":"todo","id":"evt_-Q9MF8qp6ooV","timestamp":"2026-01-28T23:31:37.283Z"}
{"type":"task.status_changed","taskId":"task_20260128_LTxaqy","project":"veritas-kanban","status":"done","previousStatus":"in-progress","id":"evt_nG6Fvxu8bFRF","timestamp":"2026-01-28T23:32:14.721Z"}
{"type":"task.status_changed","taskId":"task_20260128_YBVPjr","project":"veritas-kanban","status":"done","previousStatus":"in-progress","id":"evt_IAZpiRzZRG6H","timestamp":"2026-01-28T23:32:43.547Z"}
{"type":"task.status_changed","taskId":"task_20260128_x5JkTP","project":"veritas-kanban","status":"in-progress","previousStatus":"todo","id":"evt_qqhmpqQ-bwcQ","timestamp":"2026-01-28T23:32:45.968Z"}
{"type":"task.status_changed","taskId":"task_20260128_k3ei6P","project":"veritas-kanban","status":"in-progress","previousStatus":"todo","id":"evt_nj3Vnn_YfkIa","timestamp":"2026-01-28T23:33:10.169Z"}

View file

@ -1,4 +1,48 @@
[
{
"id": "activity_1769643190169_96cmq8zbc",
"type": "status_changed",
"taskId": "task_20260128_k3ei6P",
"taskTitle": "SECURITY: Require authentication for auth diagnostics endpoint",
"details": {
"from": "todo",
"status": "in-progress"
},
"timestamp": "2026-01-28T23:33:10.169Z"
},
{
"id": "activity_1769643165968_0v68miifq",
"type": "status_changed",
"taskId": "task_20260128_x5JkTP",
"taskTitle": "PERF: Reduce API payload over-fetching with field selection",
"details": {
"from": "todo",
"status": "in-progress"
},
"timestamp": "2026-01-28T23:32:45.968Z"
},
{
"id": "activity_1769643163558_fw49r0nzx",
"type": "comment_added",
"taskId": "task_20260128_YBVPjr",
"taskTitle": "PERF: Review rate limit threshold for API consumers",
"details": {
"author": "Veritas",
"preview": "Adjusted rate limits for local dev tool: general A..."
},
"timestamp": "2026-01-28T23:32:43.558Z"
},
{
"id": "activity_1769643163547_xpeurh2ll",
"type": "status_changed",
"taskId": "task_20260128_YBVPjr",
"taskTitle": "PERF: Review rate limit threshold for API consumers",
"details": {
"from": "in-progress",
"status": "done"
},
"timestamp": "2026-01-28T23:32:43.547Z"
},
{
"id": "activity_1769643139691_rckexf1qm",
"type": "task_updated",

View file

@ -22,6 +22,7 @@ import { errorHandler, AppError } from './middleware/error-handler.js';
import { requestIdMiddleware } from './middleware/request-id.js';
import {
authenticate,
authorize,
authenticateWebSocket,
validateWebSocketOrigin,
getAuthStatus,
@ -200,12 +201,12 @@ app.get('/health', (_req, res) => {
res.json({ status: 'ok', timestamp: new Date().toISOString() });
});
// Auth diagnostic endpoint (separate from auth routes)
// Auth diagnostic endpoint (admin-only, requires authentication)
// Available at both /api/auth/diagnostics and /api/v1/auth/diagnostics
app.get('/api/auth/diagnostics', (_req, res) => {
app.get('/api/auth/diagnostics', authenticate, authorize('admin'), (_req, res) => {
res.json(getAuthStatus());
});
app.get('/api/v1/auth/diagnostics', (_req, res) => {
app.get('/api/v1/auth/diagnostics', authenticate, authorize('admin'), (_req, res) => {
res.json(getAuthStatus());
});