Skip to content

fix(migrate): Migrate's signed server-to-server routes pass the session middleware - #402

Merged
ABB65 merged 1 commit into
mainfrom
fix/migrate-s2s-public-paths
Oct 3, 2026
Merged

ABB65 merged 1 commit into
mainfrom
fix/migrate-s2s-public-paths

Conversation

@ABB65

@ABB65 ABB65 commented Oct 3, 2026

Copy link
Copy Markdown
Member

The session middleware 401s every /api path that is not in PUBLIC_PATHS, so Migrate's signed server-to-server calls never reached their routes: /api/migrate/account-state (S1, on main) is unreachable today. The unit test calls the handler directly, so it did not show.

  • Exact-match allowlist (not a prefix): /api/migrate/account-state, /api/migrate/provision, /api/migrate/grants/status, /api/migrate/grants/install-url. Each route verifies Migrate's signature and single-use jti itself. A listed path whose route does not exist yet just 404s.
  • /api/migrate/claim and /api/migrate/grants/:id/* stay behind the session; tests assert the 401 for them and for look-alike suffixes.
  • The E4 install-callback exemption (/api/github/setup with a signed state) comes with the E4 PR, not here.

Tests: auth-middleware-public-paths 22/22, eslint clean.

@ABB65

ABB65 commented Oct 3, 2026

Copy link
Copy Markdown
Member Author

ONAY (t8, 77f4daf). Middleware test file 22/22 and eslint clean in a clean worktree; exact-match list (not a prefix), the user routes /api/migrate/claim and /api/migrate/grants/:id[/checkout] and look-alike suffixes still 401. Non-blocking: a trailing slash or a different case on the four paths is 401, which fails closed and is fine for a signed client that posts the exact path. Per our E4 split I drop my own middleware change; S2 relies on this entry for /api/migrate/provision.

@ABB65
ABB65 merged commit debfda3 into main Oct 3, 2026
1 of 2 checks passed
@ABB65
ABB65 deleted the fix/migrate-s2s-public-paths branch October 3, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant