Skip to content

core: the API has no authentication whatsoever #42

Description

@joelpeace48-cell

Problem

No route requires credentials. src/index.ts registers CORS and two route
plugins, and that is the whole security model. Every endpoint added from here —
attestation submission, usage ingestion, admin operations — inherits open
access by default, which is the wrong direction to build in.

What to do

Establish the auth layer before more routes land:

  • Gateway credentials — API keys for machine clients. Store a hash, never
    the key. Prefix keys so they are detectable in leak scanning, and support
    rotation with an overlap window.
  • Operator sessions — short-lived JWTs for humans, for the dashboard.
  • A Fastify preHandler that is applied by default and must be explicitly
    opted out of
    for public routes. Deny by default; an endpoint that forgets to
    declare auth should fail closed, not open.
  • Scopes: attest:write, usage:write, export:read, admin.

Acceptance criteria

  • Keys stored hashed with per-key salt
  • Auth applied by default, opt-out explicit and reviewed
  • Scope enforcement with tests per scope
  • Rotation supported without downtime

Notes

Blocks the attestation, usage, and export endpoints. Worth doing first —
retrofitting auth across a grown route surface is where gaps get left.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

GrantFox OSSIssue tracked in GrantFox OSSThird CampaignCampaign: Third Campaignarea:coreServer bootstrap and pluginsdifficulty:hardDesign judgement required; subtle failure modespriority:criticalBlocks everything else; security or build-breakingtype:securityAuth, funds, secrets, or abuse surface

Type

No type

Projects

No projects

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions