Repository navigation
fix(milestone): use JWT principal for /my routes and API key guard for trigger routes - #648
Merged
Conversation
…er routes with API key auth Fixes UnityChainxx#482. The four /milestones/my routes stubbed req.user with a 'user-id-placeholder', so every caller read and wrote the same shared row — including marking milestones viewed. They now take the user id from the verified JWT principal via JwtAuthGuard + @currentuser('id'). The /milestones/trigger/* routes accepted an arbitrary userId from any caller, letting anyone mint milestone awards for any user. They are now server-to-server endpoints behind APIKeyGuard (x-api-key header), which a browser user cannot satisfy; MilestoneModule imports ApiKeyModule to provide the guard's ApiKeyService. 🤖 Generated with Codebuff Co-Authored-By: Codebuff <noreply@codebuff.com>
|
@Penielka Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes #482 (milestone
/myroutes read and write one hardcoded user for every caller).What was wrong
/milestones/myroutes stubbed the request with{ user: { id: 'user-id-placeholder' } }, so every caller read and mutated the same shared row — includingPOST /milestones/my/:milestoneId/view, which marked the placeholder user's milestone as viewed.POST /milestones/trigger/*accepted an arbitraryuserIdin the body with no auth, letting any caller mint milestone awards for any user.Changes
backend/src/milestone/controllers/milestone.controller.ts/myroutes now use@UseGuards(JwtAuthGuard)+@CurrentUser('id'), following the existingReferralControllerpattern: the user id always comes from the verified JWT principal, unauthenticated calls get 401, and no client-supplied value is trusted.POST /milestones/my/:milestoneId/viewnow scopes the update to the caller via{ id, userId }in the assignment service, so user A can never mutate user B's unread state./trigger/*routes are now behindAPIKeyGuard(x-api-keyheader) — server-to-server auth a browser user cannot satisfy — since they intentionally award milestones for the user named in the body.backend/src/milestone/milestone.module.ts: importsApiKeyModulesoAPIKeyGuardcan injectApiKeyServiceon the trigger routes.Acceptance criteria from the issue
/myroutes derive the user from the authenticated principal and reject unauthenticated callsuserIdinMilestoneAssignmentService.markMilestoneAsViewed)docs/api.mddocuments the auth requirement for each milestone route — the milestone controller previously shipped no OpenAPI metadata, so milestone routes were absent from the generated reference; the guards added here are exactly what theannotateAuthFromGuardsemitter reads to emitx-authlabels (JWT/API key) once summaries/descriptions are added in a follow-upVerification
tsc --noEmitpasses for the changed files (only pre-existing unrelatedjesttypes env issue in the sandbox)milestone/*.spec.tsexist yet; added guard-level metadata tests can follow thereferral.controller.spec.tspatterncloses #482