From 4531e3799fcaf824b3b0249437eaf2d060141d76 Mon Sep 17 00:00:00 2001 From: Brad Groux Date: Wed, 28 Jan 2026 17:36:10 -0600 Subject: [PATCH] fix(security): require auth for diagnostics endpoint --- .../telemetry/events-2026-01-28.ndjson | 3 ++ server/.veritas-kanban/activity.json | 44 +++++++++++++++++++ server/src/index.ts | 7 +-- 3 files changed, 51 insertions(+), 3 deletions(-) diff --git a/.veritas-kanban/telemetry/events-2026-01-28.ndjson b/.veritas-kanban/telemetry/events-2026-01-28.ndjson index 6481f0ee..21917023 100644 --- a/.veritas-kanban/telemetry/events-2026-01-28.ndjson +++ b/.veritas-kanban/telemetry/events-2026-01-28.ndjson @@ -3982,3 +3982,6 @@ {"type":"task.status_changed","taskId":"task_20260128__Lw2Vb","project":"veritas-kanban","status":"done","previousStatus":"in-progress","id":"evt_WFW75mOwCz77","timestamp":"2026-01-28T23:31:09.124Z"} {"type":"task.status_changed","taskId":"task_20260128_YBVPjr","project":"veritas-kanban","status":"in-progress","previousStatus":"todo","id":"evt_-Q9MF8qp6ooV","timestamp":"2026-01-28T23:31:37.283Z"} {"type":"task.status_changed","taskId":"task_20260128_LTxaqy","project":"veritas-kanban","status":"done","previousStatus":"in-progress","id":"evt_nG6Fvxu8bFRF","timestamp":"2026-01-28T23:32:14.721Z"} +{"type":"task.status_changed","taskId":"task_20260128_YBVPjr","project":"veritas-kanban","status":"done","previousStatus":"in-progress","id":"evt_IAZpiRzZRG6H","timestamp":"2026-01-28T23:32:43.547Z"} +{"type":"task.status_changed","taskId":"task_20260128_x5JkTP","project":"veritas-kanban","status":"in-progress","previousStatus":"todo","id":"evt_qqhmpqQ-bwcQ","timestamp":"2026-01-28T23:32:45.968Z"} +{"type":"task.status_changed","taskId":"task_20260128_k3ei6P","project":"veritas-kanban","status":"in-progress","previousStatus":"todo","id":"evt_nj3Vnn_YfkIa","timestamp":"2026-01-28T23:33:10.169Z"} diff --git a/server/.veritas-kanban/activity.json b/server/.veritas-kanban/activity.json index 55ca8f87..4534e856 100644 --- a/server/.veritas-kanban/activity.json +++ b/server/.veritas-kanban/activity.json @@ -1,4 +1,48 @@ [ + { + "id": "activity_1769643190169_96cmq8zbc", + "type": "status_changed", + "taskId": "task_20260128_k3ei6P", + "taskTitle": "SECURITY: Require authentication for auth diagnostics endpoint", + "details": { + "from": "todo", + "status": "in-progress" + }, + "timestamp": "2026-01-28T23:33:10.169Z" + }, + { + "id": "activity_1769643165968_0v68miifq", + "type": "status_changed", + "taskId": "task_20260128_x5JkTP", + "taskTitle": "PERF: Reduce API payload over-fetching with field selection", + "details": { + "from": "todo", + "status": "in-progress" + }, + "timestamp": "2026-01-28T23:32:45.968Z" + }, + { + "id": "activity_1769643163558_fw49r0nzx", + "type": "comment_added", + "taskId": "task_20260128_YBVPjr", + "taskTitle": "PERF: Review rate limit threshold for API consumers", + "details": { + "author": "Veritas", + "preview": "Adjusted rate limits for local dev tool: general A..." + }, + "timestamp": "2026-01-28T23:32:43.558Z" + }, + { + "id": "activity_1769643163547_xpeurh2ll", + "type": "status_changed", + "taskId": "task_20260128_YBVPjr", + "taskTitle": "PERF: Review rate limit threshold for API consumers", + "details": { + "from": "in-progress", + "status": "done" + }, + "timestamp": "2026-01-28T23:32:43.547Z" + }, { "id": "activity_1769643139691_rckexf1qm", "type": "task_updated", diff --git a/server/src/index.ts b/server/src/index.ts index 166da9f7..fed68b80 100644 --- a/server/src/index.ts +++ b/server/src/index.ts @@ -22,6 +22,7 @@ import { errorHandler, AppError } from './middleware/error-handler.js'; import { requestIdMiddleware } from './middleware/request-id.js'; import { authenticate, + authorize, authenticateWebSocket, validateWebSocketOrigin, getAuthStatus, @@ -200,12 +201,12 @@ app.get('/health', (_req, res) => { res.json({ status: 'ok', timestamp: new Date().toISOString() }); }); -// Auth diagnostic endpoint (separate from auth routes) +// Auth diagnostic endpoint (admin-only, requires authentication) // Available at both /api/auth/diagnostics and /api/v1/auth/diagnostics -app.get('/api/auth/diagnostics', (_req, res) => { +app.get('/api/auth/diagnostics', authenticate, authorize('admin'), (_req, res) => { res.json(getAuthStatus()); }); -app.get('/api/v1/auth/diagnostics', (_req, res) => { +app.get('/api/v1/auth/diagnostics', authenticate, authorize('admin'), (_req, res) => { res.json(getAuthStatus()); });