DC-053: Public share links + Tailscale-mediated share (Pro-gated)
- Share-store: HMAC-signed tokens bound to serviceId+kind, persistent signing secret in dataDir/.share-secret, atomic writes, auto-prune - Routes: admin endpoints gated on licenseManager.isPro() (402 Free); public endpoints CSRF-exempt (token IS proof) - Tailscale path: mints single-use ephemeral pre-auth key, emails join link, rolls back share record if createAuthKey throws - Email-failure path: exposes urlPath for manual delivery fallback - 53 new tests (24 store + 29 routes), full suite 1372/1372 - Drift-test parser hardened against quoted-word comments - share-store dataDir resolver handles Proxy/function values CHANGELOG + BACKLOG updated.
This commit is contained in:
@@ -157,6 +157,11 @@ function csrfValidationMiddleware(req, res, next) {
|
||||
// the user has no session cookie yet (they just clicked an email link).
|
||||
// CSRF on this boundary is enforced by SameSite=Lax instead.
|
||||
'/api/v1/auth/invites/:token/accept',
|
||||
// DC-053: share-link subscribe + Tailscale redeem originate from the
|
||||
// public share page (cross-origin). The token itself is the proof; CSRF
|
||||
// is bounded by the token's TTL + scope. Same model as invite accept.
|
||||
'/api/v1/share/:token/subscribe',
|
||||
'/api/v1/share/:token/redeem-tailscale',
|
||||
'/health',
|
||||
'/health/live',
|
||||
'/health/ready',
|
||||
|
||||
Reference in New Issue
Block a user