enforce mandatory X-Session-Id header for access token validation
Session binding was bypassable: if the X-Session-Id header was absent, validate_token skipped the check entirely, allowing a stolen JWT to be used without the originating session. Server-side: reject 401 early in Flask middleware and daemon WebSocket handler when X-Session-Id is missing, before calling validate_token. Updated validate_token to always enforce session_id matching for access tokens (refresh tokens are unaffected as they carry no session_id claim). Frontend: removed dead if (stored.session_id) guards in api.js since the header is now always required. Added X-Session-Id to logout request headers and always store session_id on login/refresh.
This commit is contained in:
@@ -196,6 +196,8 @@ def _auth_middleware():
|
||||
|
||||
token_string = auth_header[7:] # strip "Bearer "
|
||||
session_header = request.headers.get("X-Session-Id")
|
||||
if not session_header:
|
||||
return jsonify({"ok": False, "error": "unauthorized"}), 401
|
||||
payload = validate_token(
|
||||
token_string, token_type="access", session_id=session_header
|
||||
)
|
||||
|
||||
Reference in New Issue
Block a user