Repository navigation
[Security][P1] Block suspended users in MCP token auth path - #556
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
📝 WalkthroughWalkthroughThis PR implements security enforcement for suspended users in the MCP token authentication path. It adds suspension checking to MCP token validation, logs security events for suspended user access attempts, revokes tokens on first detection, and includes test coverage for the new behavior. Changes
Sequence DiagramsequenceDiagram
participant Client
participant validateMCP as validateMCPToken
participant DB as Database
participant Logger as logSecurityEvent
participant Server as Auth Server
Client->>validateMCP: Request with MCP token
validateMCP->>DB: Load user data + suspendedAt
DB-->>validateMCP: User record returned
alt User is suspended
validateMCP->>Logger: Log security event<br/>(mcp_token_user_suspended)
Logger-->>validateMCP: Event recorded
validateMCP->>DB: Update token revokedAt
DB-->>validateMCP: Token revoked
validateMCP->>Server: Return null (deny access)
Server-->>Client: 401 Unauthorized
else User is active
validateMCP->>Server: Validation successful
Server-->>Client: Grant access
end
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20 minutes Possibly related PRs
Poem
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. ✨ Finishing touches
🧪 Generate unit tests (beta)
No actionable comments were generated in the recent review. 🎉 Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Summary
validateMCPToken.revokedAt) on first suspended-user detection.Behavior Decision
Previously issued MCP tokens are revoked on first post-suspension use, then denied on all subsequent requests.
Files Changed
apps/web/src/lib/auth/index.tsapps/web/src/lib/auth/__tests__/auth-middleware.test.tsdocs/security/2026-02-11-security-posture-assessment.mdTesting
pnpm --filter web test -- src/lib/auth/__tests__/auth-middleware.test.tssrc/lib/auth/__tests__/auth-middleware.test.ts), but the command also executed additional unrelated suites in this environment and failed on pre-existing issues:src/lib/auth/__tests__/admin-role-version.test.ts(EPERMconnecting to127.0.0.1:5432/::1:5432)src/app/api/ai/settings/__tests__/route.test.tsexpecting201but receiving400Closes #548
Summary by CodeRabbit
Bug Fixes
Documentation