Browse Source
Task/harden validation of device id in biometric authentication (#7915)
* Fix internal server error caused by invalid device id in biometric authentication
* Update changelog
pull/7913/head
Thomas Kaul
1 week ago
committed by
GitHub
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
4 changed files with
15 additions and
3 deletions
-
CHANGELOG.md
-
apps/api/src/app/auth/auth.controller.ts
-
apps/api/src/app/auth/generate-authentication-options.dto.ts
-
apps/api/src/app/auth/web-auth.service.ts
|
|
|
@ -7,6 +7,10 @@ and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0 |
|
|
|
|
|
|
|
## Unreleased |
|
|
|
|
|
|
|
### Changed |
|
|
|
|
|
|
|
- Hardened the validation of the device id in the biometric authentication |
|
|
|
|
|
|
|
### Fixed |
|
|
|
|
|
|
|
- Fixed the net performance percentage of date ranges in the portfolio performance calculation by including the gross performance at the start date |
|
|
|
|
|
|
|
@ -28,6 +28,7 @@ import { Request, Response } from 'express'; |
|
|
|
import { getReasonPhrase, StatusCodes } from 'http-status-codes'; |
|
|
|
|
|
|
|
import { AuthService } from './auth.service'; |
|
|
|
import { GenerateAuthenticationOptionsDto } from './generate-authentication-options.dto'; |
|
|
|
|
|
|
|
@AllowDuringImpersonation() |
|
|
|
@Controller('auth') |
|
|
|
@ -122,7 +123,7 @@ export class AuthController { |
|
|
|
@Post('webauthn/generate-authentication-options') |
|
|
|
@UseGuards(CustomThrottlerGuard) |
|
|
|
public async generateAuthenticationOptions( |
|
|
|
@Body() body: { deviceId: string } |
|
|
|
@Body() body: GenerateAuthenticationOptionsDto |
|
|
|
) { |
|
|
|
return this.webAuthService.generateAuthenticationOptions(body.deviceId); |
|
|
|
} |
|
|
|
|
|
|
|
@ -0,0 +1,6 @@ |
|
|
|
import { IsUUID } from 'class-validator'; |
|
|
|
|
|
|
|
export class GenerateAuthenticationOptionsDto { |
|
|
|
@IsUUID() |
|
|
|
deviceId: string; |
|
|
|
} |
|
|
|
@ -21,7 +21,8 @@ import { |
|
|
|
Inject, |
|
|
|
Injectable, |
|
|
|
InternalServerErrorException, |
|
|
|
Logger |
|
|
|
Logger, |
|
|
|
NotFoundException |
|
|
|
} from '@nestjs/common'; |
|
|
|
import { REQUEST } from '@nestjs/core'; |
|
|
|
import { JwtService } from '@nestjs/jwt'; |
|
|
|
@ -170,7 +171,7 @@ export class WebAuthService { |
|
|
|
const device = await this.deviceService.authDevice({ id: deviceId }); |
|
|
|
|
|
|
|
if (!device) { |
|
|
|
throw new Error('Device not found'); |
|
|
|
throw new NotFoundException('Device not found'); |
|
|
|
} |
|
|
|
|
|
|
|
// Compute in the background during the biometric authentication
|
|
|
|
|