diff --git a/CHANGELOG.md b/CHANGELOG.md index 0fb7e1e93f..6f75e481fe 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## Unreleased +### Changed + +- Hardened the validation of the device id in the biometric authentication + ### Fixed - Fixed the net performance percentage of date ranges in the portfolio performance calculation by including the gross performance at the start date diff --git a/apps/api/src/app/auth/auth.controller.ts b/apps/api/src/app/auth/auth.controller.ts index da45f0071a..4cc42b5c16 100644 --- a/apps/api/src/app/auth/auth.controller.ts +++ b/apps/api/src/app/auth/auth.controller.ts @@ -28,6 +28,7 @@ import { Request, Response } from 'express'; import { getReasonPhrase, StatusCodes } from 'http-status-codes'; import { AuthService } from './auth.service'; +import { GenerateAuthenticationOptionsDto } from './generate-authentication-options.dto'; @AllowDuringImpersonation() @Controller('auth') @@ -122,7 +123,7 @@ export class AuthController { @Post('webauthn/generate-authentication-options') @UseGuards(CustomThrottlerGuard) public async generateAuthenticationOptions( - @Body() body: { deviceId: string } + @Body() body: GenerateAuthenticationOptionsDto ) { return this.webAuthService.generateAuthenticationOptions(body.deviceId); } diff --git a/apps/api/src/app/auth/generate-authentication-options.dto.ts b/apps/api/src/app/auth/generate-authentication-options.dto.ts new file mode 100644 index 0000000000..6cc45d9fc8 --- /dev/null +++ b/apps/api/src/app/auth/generate-authentication-options.dto.ts @@ -0,0 +1,6 @@ +import { IsUUID } from 'class-validator'; + +export class GenerateAuthenticationOptionsDto { + @IsUUID() + deviceId: string; +} diff --git a/apps/api/src/app/auth/web-auth.service.ts b/apps/api/src/app/auth/web-auth.service.ts index 568822fb8d..6aa86a684c 100644 --- a/apps/api/src/app/auth/web-auth.service.ts +++ b/apps/api/src/app/auth/web-auth.service.ts @@ -21,7 +21,8 @@ import { Inject, Injectable, InternalServerErrorException, - Logger + Logger, + NotFoundException } from '@nestjs/common'; import { REQUEST } from '@nestjs/core'; import { JwtService } from '@nestjs/jwt'; @@ -170,7 +171,7 @@ export class WebAuthService { const device = await this.deviceService.authDevice({ id: deviceId }); if (!device) { - throw new Error('Device not found'); + throw new NotFoundException('Device not found'); } // Compute in the background during the biometric authentication