Skip to content

v0.2.0: fix(security): close auth & PII findings from security review (#6)

Choose a tag to compare

@alonle alonle released this 17 May 18:44
· 5 commits to main since this release
11d24b2
* fix(security): close auth & PII findings from security review

- auth: mark Better Auth `domainId`/`isSuperAdmin` additionalFields as
  `input: false`. Without this, any authenticated user could POST
  `{ isSuperAdmin: true }` to `/api/auth/update-user` and self-promote
  to super-admin, bypassing every org/role/ownership check.
- middleware: API-key requests can no longer be redirected to a
  different organization via `:orgId` / `x-organization-id`.
  Mismatched header returns 403 instead of silently rewriting the
  bound org. Session-based auth behavior is unchanged.
- search: drop `users.email` from `getIssueDetail`'s issue / solution /
  comment selects and response shape. Previously any authenticated
  user could enumerate Public-org issue UUIDs and harvest author
  emails. Also drops `email` from the shared `authorSchema` so types
  stay consistent.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(mcp-server): drop email from IssueDetail type after backend change

CI build failed because mcp-server's local IssueDetail type still
required `author.email`, which the backend service no longer returns.
The formatter never rendered email anyway, so drop it from the type
and update the test fixtures.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>