mirror of
https://github.com/dograh-hq/dograh.git
synced 2026-07-25 12:01:04 +02:00
fix: gate OSS email/password auth endpoints outside local auth mode
The /auth signup/login/me routes were mounted unconditionally, so the SaaS deployment accepted unauthenticated signups that created oss_* provider-id users (and auto-provisioned MPS service keys) bypassing Stack Auth entirely. Gate them with a router-level dependency that 404s when AUTH_PROVIDER is not "local", rather than conditionally mounting the router, so the OpenAPI spec and the clients generated from it stay identical across deployment modes. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
parent
ceb01a16a3
commit
f4c711627c
2 changed files with 19 additions and 1 deletions
|
|
@ -5,7 +5,11 @@ from api.db import db_client
|
|||
from api.db.models import UserModel
|
||||
from api.enums import OrganizationConfigurationKey, PostHogEvent
|
||||
from api.schemas.auth import AuthResponse, LoginRequest, SignupRequest, UserResponse
|
||||
from api.services.auth.depends import create_user_configuration_with_mps_key, get_user
|
||||
from api.services.auth.depends import (
|
||||
create_user_configuration_with_mps_key,
|
||||
get_user,
|
||||
require_local_auth,
|
||||
)
|
||||
from api.services.configuration.ai_model_configuration import (
|
||||
convert_legacy_ai_model_configuration_to_v2,
|
||||
)
|
||||
|
|
@ -15,6 +19,7 @@ from api.utils.auth import create_jwt_token, hash_password, verify_password
|
|||
router = APIRouter(
|
||||
prefix="/auth",
|
||||
tags=["auth"],
|
||||
dependencies=[Depends(require_local_auth)],
|
||||
)
|
||||
|
||||
|
||||
|
|
|
|||
|
|
@ -20,6 +20,19 @@ from api.services.posthog_client import (
|
|||
)
|
||||
from api.utils.auth import decode_jwt_token
|
||||
|
||||
|
||||
async def require_local_auth() -> None:
|
||||
"""Reject email/password auth requests outside OSS (local) deployments.
|
||||
|
||||
The auth router stays mounted in every mode so the OpenAPI spec — and the
|
||||
clients generated from it — don't vary with AUTH_PROVIDER; the gate has to
|
||||
happen at request time. Without it, the SaaS deployment accepts
|
||||
unauthenticated signups that mint oss_* users bypassing Stack Auth.
|
||||
"""
|
||||
if AUTH_PROVIDER != "local":
|
||||
raise HTTPException(status_code=404, detail="Not found")
|
||||
|
||||
|
||||
POSTHOG_ORGANIZATION_GROUP_TYPE = "organization"
|
||||
POSTHOG_ORGANIZATION_USES_MPS_BILLING_V2_PROPERTY = "uses_mps_billing_v2"
|
||||
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue