fix: harden auth, cron secrets, and provider flows (GNU-17) (#148)
- Replace === with crypto.timingSafeEqual in all 7 cron routes via shared lib/auth/cron.ts - Add in-memory rate limiting (60 req/min) and expires_at support to calendar feed - Add exponential backoff on MFA verify after 3 failed attempts - Add 60s cooldown on password reset requests - Validate bank callback auth code format before API call - Redact session IDs from bank sync and callback logs - Validate OAuth redirect_uris against allowlist (claude.ai, claude.com, localhost) - Remove excessive PII/debug console logging from login page Co-authored-by: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 4.6
parent
5c8db1ec60
commit
550cadcb06
@@ -69,6 +69,12 @@ export async function GET(request: Request) {
|
||||
return NextResponse.redirect(`${baseUrl}/settings?bank_error=missing_parameters`)
|
||||
}
|
||||
|
||||
// Validate authorization code format
|
||||
const codePattern = /^[a-zA-Z0-9._~+\/-]{8,2048}$/
|
||||
if (!codePattern.test(code)) {
|
||||
return NextResponse.redirect(`${baseUrl}/settings?bank_error=invalid_code_format`)
|
||||
}
|
||||
|
||||
const supabase = await createServiceClient()
|
||||
|
||||
try {
|
||||
@@ -105,7 +111,7 @@ export async function GET(request: Request) {
|
||||
|
||||
console.log('[enable-banking] Session created successfully', {
|
||||
connectionId: pendingConnection.id,
|
||||
sessionId: session_id,
|
||||
sessionId: '[REDACTED]',
|
||||
accountCount: accounts.length,
|
||||
consentExpiresAt,
|
||||
})
|
||||
@@ -150,7 +156,7 @@ export async function GET(request: Request) {
|
||||
console.error('[enable-banking] Failed to update connection after session creation', {
|
||||
connectionId: pendingConnection.id,
|
||||
updateError: { message: updateError.message, code: updateError.code, details: updateError.details },
|
||||
sessionId: session_id,
|
||||
sessionId: '[REDACTED]',
|
||||
})
|
||||
throw new Error(`Failed to update connection: ${updateError.message}`)
|
||||
}
|
||||
|
||||
@@ -10,6 +10,7 @@ import {
|
||||
generateConsentExpiryEmailSubject,
|
||||
} from '@/lib/email/consent-notification-templates'
|
||||
import { ensureInitialized } from '@/lib/init'
|
||||
import { verifyCronSecret } from '@/lib/auth/cron'
|
||||
import type { StoredAccount } from '@/extensions/general/enable-banking/types'
|
||||
|
||||
ensureInitialized()
|
||||
@@ -24,13 +25,8 @@ ensureInitialized()
|
||||
* Deduplication via external_id makes repeated runs safe.
|
||||
*/
|
||||
export async function GET(request: Request) {
|
||||
// Verify cron secret
|
||||
const authHeader = request.headers.get('authorization')
|
||||
const cronSecret = process.env.CRON_SECRET
|
||||
|
||||
if (!cronSecret || authHeader !== `Bearer ${cronSecret}`) {
|
||||
return NextResponse.json({ error: 'Unauthorized' }, { status: 401 })
|
||||
}
|
||||
const authError = verifyCronSecret(request)
|
||||
if (authError) return authError
|
||||
|
||||
const supabaseUrl = process.env.NEXT_PUBLIC_SUPABASE_URL
|
||||
const supabaseServiceKey = process.env.SUPABASE_SERVICE_ROLE_KEY
|
||||
@@ -212,7 +208,7 @@ export async function GET(request: Request) {
|
||||
connectionId: connection.id,
|
||||
userId: connection.user_id,
|
||||
bankName: connection.bank_name,
|
||||
sessionId: connection.session_id,
|
||||
sessionId: '[REDACTED]',
|
||||
consentExpires: connection.consent_expires,
|
||||
lastSyncedAt: connection.last_synced_at,
|
||||
message,
|
||||
|
||||
Reference in New Issue
Block a user