|
local mode isolation: anonymous user is a NULL-owner user, not an alias
Local mode (NAVI_AUTH_ENABLED=false) used an anonymous admin whose admin role widened every session listing to ALL users' chats — acceptable only while assuming a private database, but a real leak on any shared one. - session listings (list_all/list_page/count_all/search_list): new scoping rule — non-admin with user_id=None sees only user_id IS NULL rows; named owner unchanged; admin unchanged - session create/list routes: owner id is None in local mode (sessions are persisted ownerless), admin listing flag resolved only when auth is enabled - check_session_access: local mode allows only NULL-owner sessions — a user-owned session by id is 403 - debug/admin endpoints (require_admin) stay reachable in local mode - prod DB: 30 stray user_id='anonymous' rows reassigned to NULL owner Tests: store scoping unit tests, local-mode integration tests (sidebar filtering + access by id), updated check_session_access unit tests. Full pytest 1239 passed, 1 skipped. |
|---|
|
|
| navi/api/routes/sessions.py |
|---|
| navi/auth/deps.py |
|---|
| navi/core/pg_session_store.py |
|---|
| navi/core/session.py |
|---|
| tests/integration/test_auth_disabled.py |
|---|
| tests/unit/api/test_websocket.py |
|---|
| tests/unit/auth/test_deps.py |
|---|
| tests/unit/core/test_pg_session_store.py |
|---|