mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 21:12:49 +08:00
fix(guest): guard reserved __guest__ principal in user mgmt
The by-id user-management handlers use findById, which has no role filter, so supplying the synthetic GUEST_USER_ID let an admin delete, re-role, reset-password, and read/write permissions on the shared guest principal (privilege-escalation / DoS / credential-login holes). - web/api/users.ts: 404-guard every :id handler against GUEST_USER_ID (DELETE, reset-password, role, GET/PUT permissions). - data/users.ts: defense-in-depth — setRoleIfNotLastAdmin and deleteUserIfNotLastAdmin return "not_found" for any role=guest row. - web/api/session.ts: wrap POST /guest createSession in try/catch so a missing guest row yields 503 instead of an unhandled 500. - Tests: data-layer guest-protection + users-router 404 by-id guards. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
45414b3baa
commit
365352cdd3
5 files changed
+79
-3
No files matched your search
+10
-1
@@ -141,7 +141,16 @@ export function createSessionRouter(
|
||||
res.status(403).json({ error: "guest mode disabled" });
|
||||
return;
|
||||
}
|
||||
const { token } = sessions.createSession(GUEST_USER_ID, { ttlMs: GUEST_SESSION_TTL_MS, skipCap: true });
|
||||
let token: string;
|
||||
try {
|
||||
// If the reserved guest row is somehow missing, the session FK would
|
||||
// throw; surface a clean 503 rather than letting it become a 500.
|
||||
({ token } = sessions.createSession(GUEST_USER_ID, { ttlMs: GUEST_SESSION_TTL_MS, skipCap: true }));
|
||||
} catch (err) {
|
||||
logger.error({ err }, "guest session creation failed");
|
||||
res.status(503).json({ error: "guest unavailable" });
|
||||
return;
|
||||
}
|
||||
setSessionCookie(res, token);
|
||||
res.json({ id: GUEST_USER_ID, username: GUEST_USERNAME, role: "guest" });
|
||||
});
|
||||
|
||||
Reference in new issue
Block a user