CodeIssuesDiscussionsWikiPull RequestsProjectsCommitsActionsReleasesContributorsPulse● GatesSecuritySettingsDeploymentsPipelineInsightsAgents✨ Explain✨ Ask AI✨ Workspace✨ Spec✨ Tests▓ Debt Map✨ NL Search🏛 Archaeology
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 | /**
* Regression coverage for a systemic bug found via a full production HTTP
* sweep: 13 route files registered their auth middleware with a glued
* wildcard pattern (e.g. `router.use("/settings/tokens*", requireAuth)` --
* no slash before the `*`). That pattern does not match the bare path at
* all in this Hono version (confirmed via a standalone reproduction), so
* the middleware silently never ran.
*
* Two of these (admin-security.tsx's /admin/security and /admin/soc2) were
* a live, unauthenticated information-disclosure bug in production --
* confirmed via `curl` returning a real 200 with the SOC 2 evidence
* dashboard rendered, no login required. The rest crashed with a raw 500
* (`c.get("user")!` dereferencing null) instead of leaking data, but were
* equally broken as an auth gate.
*
* This file covers the requireAuth-gated ones not already covered by a
* dedicated test file (admin-security.test.ts covers /admin/security +
* /admin/soc2; ai-standup.test.ts covers /standups; admin.test.ts covers
* /admin/autopilot/health, a related-but-distinct routing bug).
*/
import { describe, it, expect } from "bun:test";
async function expectLoginRedirect(path: string, init?: RequestInit) {
const app = (await import("../app")).default;
const res = await app.request(path, init);
expect(res.status).toBe(302);
expect(res.headers.get("location") || "").toContain("/login");
}
describe("wildcard auth-gate regression — requireAuth-protected settings pages", () => {
it("GET /settings/tokens requires auth", async () => {
await expectLoginRedirect("/settings/tokens");
});
it("GET /api/user/tokens requires auth", async () => {
await expectLoginRedirect("/api/user/tokens");
});
it("GET /settings/sessions requires auth", async () => {
await expectLoginRedirect("/settings/sessions");
});
it("GET /settings/integrations requires auth", async () => {
await expectLoginRedirect("/settings/integrations");
});
it("GET /settings/agents requires auth", async () => {
await expectLoginRedirect("/settings/agents");
});
it("GET /settings/deploy-targets requires auth", async () => {
await expectLoginRedirect("/settings/deploy-targets");
});
it("GET /orgs/:slug/settings/secrets requires auth", async () => {
await expectLoginRedirect("/orgs/test/settings/secrets");
});
});
|