Skip to content

fix(security): enforce session boundary and origin validation for APIs and WebSockets (#102) - #146

Merged
BerryUIKI merged 1 commit into
devfrom
bugfix/102-session-boundary-origin-validation
Oct 4, 2026
Merged

BerryUIKI merged 1 commit into
devfrom
bugfix/102-session-boundary-origin-validation

Conversation

@BerryUIKI

Copy link
Copy Markdown
Owner

Summary

Resolves #102 (F02).

  • Origin Boundary Enforcement: Validates the \Origin\ header across all HTTP requests and WebSocket handshakes against configured allowed desktop/local origins (\http://localhost:5173\, \http://127.0.0.1:5173\, \http://localhost:8000\, \http://127.0.0.1:8000\, \ auri://localhost, etc.). Untrusted browser origins receive HTTP 403 or WebSocket code 1008 policy violation.
  • Ephemeral Session Token: Generates a cryptographic session token per application launch (\SessionManager), exposed via \GET /api/v1/auth/session\ and \GET /api/v1/info.
  • Session Validation: Enforces valid session tokens when supplied via \X-Session-Token, \Authorization: Bearer, cookie, or query parameters. Rejects invalid credentials with HTTP 401.
  • WebSocket Protection: /ws/workflow/run\ checks origin and session token prior to connection acceptance.
  • Regression Tests: Added \�ackend/tests/test_session_security.py\ covering origin rejection, websocket handshake gating, session token extraction, and valid local client flows.

Verification

  • \�ackend/tests/test_session_security.py: 7/7 passed.
  • Full backend pytest suite: 171/171 passed.

@BerryUIKI
BerryUIKI merged commit 7d3143c into dev Oct 4, 2026
3 checks passed
@BerryUIKI
BerryUIKI deleted the bugfix/102-session-boundary-origin-validation branch October 4, 2026 21:29
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant