Repository navigation
fix(api): propagate authenticated principal through handlers - #1476
Conversation
Attach the resolved AuthUser principal to the request context before dispatch and reuse it in the current-user permissions path. Cover admin, user API key, and session credentials without duplicate validation.
The authentication follow-up propagates the resolved principal through the request context. Match that enriched context in the existing end-to-end dashboard test while preserving its business argument assertions.
HandleRequest now propagates the authenticated principal through context. Keep end-to-end mocks strict on business arguments while accepting the enriched request context passed to downstream services.
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
Important Review skippedNo new commits to review since the last review. ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Pro Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
📝 WalkthroughWalkthroughAuthentication principals are stored in request context and reused across validation, routing, CSRF checks, permission checks, and handlers. Session and API-key authentication paths are centralized, with tests covering single validation and mixed credentials. ChangesPrincipal authentication flow
Estimated code review effort: 4 (Complex) | ~45 minutes Sequence Diagram(s)sequenceDiagram
participant Client
participant HandleRequest
participant Middleware
participant Router
participant Handler
Client->>HandleRequest: API request with credentials
HandleRequest->>Middleware: authenticatePrincipal
Middleware-->>HandleRequest: contextual Principal
HandleRequest->>Router: route with updated context
Router->>Handler: invoke authenticated handler
Handler->>Middleware: requireSessionPrincipal or requirePermission
Middleware-->>Handler: session or authorization result
Possibly related PRs
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches🧪 Generate unit tests (beta)
Comment |
Summary
Why
Follow-up to #194 and merged PR #864. The merged refactor returned a
Principal, but the production request pipeline still discarded it before handler dispatch. That caused duplicate credential validation and inconsistent mixed-credential behavior.Refs #194
Verification
go test -race ./internal/api -run 'HandleRequest|RouterAuthUser|RequireAuth|ValidateSecurity' -count=1go test -race ./internal/api -count=1Summary by CodeRabbit
Security & Authentication
Bug Fixes