0
0
Fork 0
mirror of https://github.com/discourse/discourse.git synced 2026-08-06 13:08:40 +08:00
discourse/spec/lib/auth
Alan Guo Xiang Tan a79188a0b7
SECURITY: Bind shared session key to auth token and enforce user gates [backport 2026.1] (#41691)
Backport of #41610 to release/2026.1.

---

This PR binds the shared session key to the session's `UserAuthToken` so
it can no longer be replayed after the session is revoked.

When the `long_polling_base_url` site setting points to an external
origin, the auth cookie is not sent with message_bus requests, so each
authenticated page render mints a shared session key: a random token
that Discourse stores in Redis pointing at the user's id, embeds in the
page, and the client replays on the `X-Shared-Session-Key` header. That
Redis entry is given a 7-day TTL. On each request the key was resolved
to its user id and returned before the suspended/active check ran, so a
captured key kept authenticating for the full 7 days of its TTL. Logout,
suspension, password change, and token revocation never touched the
Redis entry, so none of them stopped it.

Key changes:

* Store the key as `shared_session_user_auth_token_id:<key> ->
token.id`, building the Redis key name in one place
(`Auth::DefaultCurrentUserProvider.shared_session_redis_key`). Legacy
`shared_session_key_*` entries are never read, so every pre-deploy key
fails closed with no migration; clients re-mint on their next page load.
* Resolve the user through the bound token, applying the same
suspended/active and `maximum_session_age` checks as cookie auth, so the
key revokes and expires with the session instead of outliving it on the
Redis TTL.
* Mint against the token's effective user so admin impersonation keeps
live updates; the key stays the admin's and reverts to them when
impersonation ends.
* Rely on token destruction for revocation on every path rather than
deleting the Redis entry, since a gone token already makes its key fail
closed on lookup; orphaned entries expire on the 7-day TTL.
2026-07-14 15:48:25 +08:00
..
default_current_user_provider_spec.rb SECURITY: Bind shared session key to auth token and enforce user gates [backport 2026.1] (#41691) 2026-07-14 15:48:25 +08:00
discord_authenticator_spec.rb DEV: Fix username/name mapping for Discord auth (#31494) 2025-02-25 17:33:26 +11:00
discourse_id_authenticator_spec.rb DEV: Remove unnecessary rails_helper requires (#33812) 2025-07-24 13:50:04 +02:00
facebook_authenticator_spec.rb DEV: Allow fab! without block (#24314) 2023-11-09 16:47:59 -06:00
github_authenticator_spec.rb DEV: Allow fab! without block (#24314) 2023-11-09 16:47:59 -06:00
google_oauth2_authenticator_spec.rb DEV: Allow fab! without block (#24314) 2023-11-09 16:47:59 -06:00
linkedin_oidc_authenticator_spec.rb FEATURE: Allow users to sign in using LinkedIn OpenID Connect (#26281) 2024-04-19 18:47:30 +08:00
managed_authenticator_spec.rb DEV: Fix linting and test for b1ea35bb30 (#34688) 2025-09-02 13:43:34 -04:00
result_spec.rb DEV: Apply syntax_tree formatting to spec/* 2023-01-09 11:49:28 +00:00
twitter_authenticator_spec.rb FIX: Twitter login problem check not reporting accurately (#35593) 2025-10-24 09:42:58 -04:00