mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-08-25 08:32:11 +03:00
`isPublicApiRoute()` matched every entry of PUBLIC_API_ROUTE_PREFIXES with `startsWith()`, but 11 of the 15 entries name ONE route, not a subtree. As a prefix each also marked every adjacent path sharing its leading characters as PUBLIC, which skips the MANAGEMENT auth gate. That is reachable today: Next resolves `/api/usage/om-usage<anything>` to the dynamic route `/api/usage/[connectionId]`, and that handler carries no auth of its own — it relies entirely on being classified MANAGEMENT. An unauthenticated caller therefore reaches `fetchAndPersistProviderLimits()`, which is an existence oracle over connection ids (409/404/400/200) and, for a connection id actually starting with `om-usage`, discloses live quota JSON and can drive an OAuth token refresh (a write side effect) with no credentials. Split the allowlist by shape: - PUBLIC_API_ROUTE_PREFIXES keeps only genuine subtrees, every entry ending in "/" (asserted by a unit test, so the class cannot come back silently). - PUBLIC_API_ROUTES_EXACT holds the single routes, matched exactly in both spellings. - The three read-only "prefixes" were single routes too and move to PUBLIC_READONLY_CORS_API_ROUTES, matched exactly. classify.ts now asks `isPublicReadonlyCorsRoute()` instead of scanning the raw list, so the CORS origin relaxation pipeline.ts keys on cannot be inherited by a sibling either (`/api/monitoring/health-detail` was taking it). - `/api/health` deliberately stays in its own set so it keeps classifying as `public_prefix`; folding it into the read-only set would widen CORS on it. dashboardCsrf.ts had a second copy of the prefix scan; it now shares `isPublicApiRoute()` so the client CSRF exemption and the server classification cannot disagree. Side effect in the safe direction: the three LOCAL_ONLY oauth auto-import routes were CSRF-exempt on the client while the server already required the token — the client now attaches it. Reported by @ntdat812 (GHSA-74g9-q8f6-793h), with the shape of the fix and the two gotchas above called out in the report. Closes GHSA-74g9-q8f6-793h Co-authored-by: Xiangzhe <bakryun0718@proton.me> Co-authored-by: Nguyen Thanh Dat <ntdat812.dev@gmail.com>