fix(guest): normalize guestMode config on load + strict-boolean authorize gate

loadConfig now sanitizes guestMode the same way the write path does: bots is
coerced to "all" | string[] (numbers/objects/missing fall back to the default
"all"), and permissions are rebuilt from defaults with each known flag
strict-coerced to a boolean so a hand-edited/legacy/corrupt config.json can no
longer crash the gate or leak garbage index keys. The authorize guest gate now
uses === true instead of a truthy check.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
saopig1andClaude Opus 4.8 committed 2026-06-25 15:59:42 +08:00
1 parent 952f1fbad3
commit 66230e6b43
4 files changed
+84 -9

No files matched your search

+1 -1
View File
@@ -19,7 +19,7 @@ export function authorize<P = Record<string, string>>(opts: {
if (!user) { res.status(401).json({ error: "unauthenticated" }); return; }
if (user.role === "admin") { next(); return; }
if (user.role === "guest") {
if (opts.guestFlag && user.guest?.[opts.guestFlag]) { next(); return; }
if (opts.guestFlag && user.guest?.[opts.guestFlag] === true) { next(); return; }
res.status(403).json({ error: "forbidden" });
return;
}