Repository navigation
fix(sandbox): restrict terminal and prod code execution to admins #1664
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -3,17 +3,22 @@ import { z } from 'zod/v4'; | |
| import { broadcastPageEvent, createPageEventPayload } from '@/lib/websocket'; | ||
| import { loggers } from '@pagespace/lib/logging/logger-config' | ||
| import { getCreatablePageTypes } from '@pagespace/lib/content/page-types.config' | ||
| import { PageType } from '@pagespace/lib/utils/enums' | ||
| import { auditRequest } from '@pagespace/lib/audit/audit-log'; | ||
| import { trackPageOperation } from '@pagespace/lib/monitoring/activity-tracker'; | ||
| import { authenticateRequestWithOptions, isAuthError, checkMCPCreateScope, isMCPAuthResult, canPrincipalEditPage } from '@/lib/auth'; | ||
| import { pageService, type CreatePageParams } from '@/services/api'; | ||
|
|
||
| const AUTH_OPTIONS = { allow: ['session', 'mcp'] as const, requireCSRF: true }; | ||
| const creatablePageTypes = [ | ||
| ...getCreatablePageTypes(), | ||
| PageType.TERMINAL, | ||
| ] as unknown as [string, ...string[]]; | ||
|
|
||
| // Zod schema for page creation request | ||
| const createPageSchema = z.object({ | ||
| title: z.string().min(1, 'Title is required'), | ||
| type: z.enum(getCreatablePageTypes() as [string, ...string[]]), | ||
| type: z.enum(creatablePageTypes), | ||
| driveId: z.string().min(1, 'Drive ID is required'), | ||
| parentId: z.string().nullable().optional(), | ||
| content: z.string().optional(), | ||
|
|
@@ -45,6 +50,10 @@ export async function POST(request: Request) { | |
| } | ||
|
|
||
| const validatedData = parseResult.data; | ||
| if (validatedData.type === PageType.TERMINAL && auth.role !== 'admin') { | ||
| auditRequest(request, { eventType: 'authz.access.denied', userId, resourceType: 'page', resourceId: validatedData.driveId, details: { reason: 'app_admin_required', type: validatedData.type, method: 'POST' }, riskScore: 0.5 }); | ||
| return NextResponse.json({ error: 'Terminal pages require administrator privileges' }, { status: 403 }); | ||
| } | ||
|
Comment on lines
+53
to
+56
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Use centralized permission helpers for the TERMINAL create gate (Line 53). This inline As per coding guidelines, 🤖 Prompt for AI AgentsSource: Coding guidelines |
||
|
|
||
| // Check MCP token scope - scoped tokens can only create pages in allowed drives | ||
| const scopeError = checkMCPCreateScope(auth, validatedData.driveId); | ||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Replace inline role check with centralized permission evaluation (Line 57).
auth.role !== 'admin'is a custom authorization path in an API route and should use the shared permission layer for consistency and policy correctness.As per coding guidelines,
apps/web/src/app/api/**/*.{ts,tsx}must “Use centralized permission logic from@pagespace/lib/permissions/permissionsviagetUserAccessLevel()andcanUserEditPage()functions,” and**/*.{ts,tsx}must “Always use centralized permission functions frompackages/lib/src/permissions/. Never roll your own access checks.”🤖 Prompt for AI Agents
Source: Coding guidelines