fix(companion): reject empty local token as auth bypass - #17
Draft
cursor[bot] wants to merge 1 commit into
Draft
Conversation
Nullish coalescing kept WEBCHAIN_LOCAL_TOKEN="" as a valid credential, so an empty x-webchain-token header authenticated session and command routes. Co-authored-by: esadrianno <esadrianno@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bug and impact
WEBCHAIN_LOCAL_TOKEN=""(orlocalToken: "") was treated as a valid companion credential.??keeps empty strings, so a request withx-webchain-token: ""authenticated and could create browser sessions and run commands.Trigger: set
WEBCHAIN_LOCAL_TOKEN=(or passlocalToken: "") and callPOST /sessionswith an emptyx-webchain-tokenheader. Missing headers still returned 401; the empty-to-empty match did not.Root cause
Nullish coalescing does not fall through on
"", so an empty env/option never reached the local-dev default and compared equal to an empty header.Fix
Refuse to boot when the resolved token is empty or whitespace. Treat empty or whitespace headers as unauthenticated.
Tests
services/companion/src/server.test.tscovers empty header, empty/whitespacelocalToken, and emptyWEBCHAIN_LOCAL_TOKEN.pnpm --filter @webchain/companion testandtest:coveragepassed (line coverage 94.66%, threshold 90).