From 6e128bba15e6170e0c8127dc75b458a4bb8b8570 Mon Sep 17 00:00:00 2001 From: Thomas Kaul <4159106+dtslvr@users.noreply.github.com> Date: Sat, 19 Sep 2026 19:31:23 +0200 Subject: [PATCH] Task/harden validation of device id in biometric authentication (#7915) * Fix internal server error caused by invalid device id in biometric authentication * Update changelog --- CHANGELOG.md | 4 ++++ apps/api/src/app/auth/auth.controller.ts | 3 ++- .../api/src/app/auth/generate-authentication-options.dto.ts | 6 ++++++ apps/api/src/app/auth/web-auth.service.ts | 5 +++-- 4 files changed, 15 insertions(+), 3 deletions(-) create mode 100644 apps/api/src/app/auth/generate-authentication-options.dto.ts diff --git a/CHANGELOG.md b/CHANGELOG.md index 0fb7e1e93f..6f75e481fe 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 ## Unreleased +### Changed + +- Hardened the validation of the device id in the biometric authentication + ### Fixed - Fixed the net performance percentage of date ranges in the portfolio performance calculation by including the gross performance at the start date diff --git a/apps/api/src/app/auth/auth.controller.ts b/apps/api/src/app/auth/auth.controller.ts index da45f0071a..4cc42b5c16 100644 --- a/apps/api/src/app/auth/auth.controller.ts +++ b/apps/api/src/app/auth/auth.controller.ts @@ -28,6 +28,7 @@ import { Request, Response } from 'express'; import { getReasonPhrase, StatusCodes } from 'http-status-codes'; import { AuthService } from './auth.service'; +import { GenerateAuthenticationOptionsDto } from './generate-authentication-options.dto'; @AllowDuringImpersonation() @Controller('auth') @@ -122,7 +123,7 @@ export class AuthController { @Post('webauthn/generate-authentication-options') @UseGuards(CustomThrottlerGuard) public async generateAuthenticationOptions( - @Body() body: { deviceId: string } + @Body() body: GenerateAuthenticationOptionsDto ) { return this.webAuthService.generateAuthenticationOptions(body.deviceId); } diff --git a/apps/api/src/app/auth/generate-authentication-options.dto.ts b/apps/api/src/app/auth/generate-authentication-options.dto.ts new file mode 100644 index 0000000000..6cc45d9fc8 --- /dev/null +++ b/apps/api/src/app/auth/generate-authentication-options.dto.ts @@ -0,0 +1,6 @@ +import { IsUUID } from 'class-validator'; + +export class GenerateAuthenticationOptionsDto { + @IsUUID() + deviceId: string; +} diff --git a/apps/api/src/app/auth/web-auth.service.ts b/apps/api/src/app/auth/web-auth.service.ts index 568822fb8d..6aa86a684c 100644 --- a/apps/api/src/app/auth/web-auth.service.ts +++ b/apps/api/src/app/auth/web-auth.service.ts @@ -21,7 +21,8 @@ import { Inject, Injectable, InternalServerErrorException, - Logger + Logger, + NotFoundException } from '@nestjs/common'; import { REQUEST } from '@nestjs/core'; import { JwtService } from '@nestjs/jwt'; @@ -170,7 +171,7 @@ export class WebAuthService { const device = await this.deviceService.authDevice({ id: deviceId }); if (!device) { - throw new Error('Device not found'); + throw new NotFoundException('Device not found'); } // Compute in the background during the biometric authentication