Browse Source

Task/harden validation of device id in biometric authentication (#7915)

* Fix internal server error caused by invalid device id in biometric authentication

* Update changelog
pull/7913/head
Thomas Kaul 1 week ago
committed by GitHub
parent
commit
6e128bba15
No known key found for this signature in database GPG Key ID: B5690EEEBB952194
  1. 4
      CHANGELOG.md
  2. 3
      apps/api/src/app/auth/auth.controller.ts
  3. 6
      apps/api/src/app/auth/generate-authentication-options.dto.ts
  4. 5
      apps/api/src/app/auth/web-auth.service.ts

4
CHANGELOG.md

@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0
## Unreleased ## Unreleased
### Changed
- Hardened the validation of the device id in the biometric authentication
### Fixed ### Fixed
- Fixed the net performance percentage of date ranges in the portfolio performance calculation by including the gross performance at the start date - Fixed the net performance percentage of date ranges in the portfolio performance calculation by including the gross performance at the start date

3
apps/api/src/app/auth/auth.controller.ts

@ -28,6 +28,7 @@ import { Request, Response } from 'express';
import { getReasonPhrase, StatusCodes } from 'http-status-codes'; import { getReasonPhrase, StatusCodes } from 'http-status-codes';
import { AuthService } from './auth.service'; import { AuthService } from './auth.service';
import { GenerateAuthenticationOptionsDto } from './generate-authentication-options.dto';
@AllowDuringImpersonation() @AllowDuringImpersonation()
@Controller('auth') @Controller('auth')
@ -122,7 +123,7 @@ export class AuthController {
@Post('webauthn/generate-authentication-options') @Post('webauthn/generate-authentication-options')
@UseGuards(CustomThrottlerGuard) @UseGuards(CustomThrottlerGuard)
public async generateAuthenticationOptions( public async generateAuthenticationOptions(
@Body() body: { deviceId: string } @Body() body: GenerateAuthenticationOptionsDto
) { ) {
return this.webAuthService.generateAuthenticationOptions(body.deviceId); return this.webAuthService.generateAuthenticationOptions(body.deviceId);
} }

6
apps/api/src/app/auth/generate-authentication-options.dto.ts

@ -0,0 +1,6 @@
import { IsUUID } from 'class-validator';
export class GenerateAuthenticationOptionsDto {
@IsUUID()
deviceId: string;
}

5
apps/api/src/app/auth/web-auth.service.ts

@ -21,7 +21,8 @@ import {
Inject, Inject,
Injectable, Injectable,
InternalServerErrorException, InternalServerErrorException,
Logger Logger,
NotFoundException
} from '@nestjs/common'; } from '@nestjs/common';
import { REQUEST } from '@nestjs/core'; import { REQUEST } from '@nestjs/core';
import { JwtService } from '@nestjs/jwt'; import { JwtService } from '@nestjs/jwt';
@ -170,7 +171,7 @@ export class WebAuthService {
const device = await this.deviceService.authDevice({ id: deviceId }); const device = await this.deviceService.authDevice({ id: deviceId });
if (!device) { if (!device) {
throw new Error('Device not found'); throw new NotFoundException('Device not found');
} }
// Compute in the background during the biometric authentication // Compute in the background during the biometric authentication

Loading…
Cancel
Save