fix(api): close second silent dev-login path in authedRequest
Oracle round-4 finding: authedRequest() called the private login() helper whenever no bearer token existed AND on 401 retry. That helper posts to /api/v1/auth/dev-login, so any authenticated API call could silently issue dev-login regardless of UI gating. - authedRequest checks devLoginAllowed() (VITE_ENABLE_DEV_LOGIN !== 'false') before calling login(). When dev-login is disabled it throws AuthRequiredError instead. - 401 retry path gated the same way. - New AuthRequiredError exported so callers (store, scenes) can route unauthenticated users to the login page instead of swallowing. - src/lib/api.test.ts: regression test 'throws AuthRequiredError instead of silently calling /dev-login when no token'. With VITE_ENABLE_DEV_LOGIN=false api.me() rejects with /Sign in required/ and no POST to /dev-login is observed. 30/30 unit tests green.
This commit is contained in:
@@ -106,3 +106,20 @@ describe("api client", () => {
|
||||
expect(calls.filter((c) => c.url.endsWith("/dev-login")).length).toBe(2); // initial + retry login
|
||||
});
|
||||
});
|
||||
|
||||
describe("authedRequest fail-closed when dev-login disabled", () => {
|
||||
beforeEach(() => {
|
||||
import.meta.env.VITE_ENABLE_DEV_LOGIN = "false";
|
||||
});
|
||||
it("throws AuthRequiredError instead of silently calling /dev-login when no token", async () => {
|
||||
const calls = mockFetch([
|
||||
(url) =>
|
||||
url.endsWith("/api/v1/auth/me")
|
||||
? new Response(JSON.stringify({ user_id: "u", tenant_id: "t", email: "dev@flow-master.ai" }), { status: 200 })
|
||||
: undefined,
|
||||
]);
|
||||
await expect(api.me()).rejects.toThrow(/Sign in required/);
|
||||
expect(calls.filter((c) => c.url.endsWith("/dev-login")).length).toBe(0);
|
||||
delete (import.meta.env as any).VITE_ENABLE_DEV_LOGIN;
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user