security(external_user): protect unnecessary route access to external users
This commit is contained in:
+35
-13
@@ -378,19 +378,41 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
|
||||
auth_middleware,
|
||||
));
|
||||
|
||||
// CalDAV/CardDAV/WebDAV with auth middleware (merged, not nested)
|
||||
let caldav_protected = caldav_router.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
auth_middleware,
|
||||
));
|
||||
let carddav_protected = carddav_router.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
auth_middleware,
|
||||
));
|
||||
let webdav_protected = webdav_router.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
auth_middleware,
|
||||
));
|
||||
// CalDAV/CardDAV/WebDAV with auth + internal-only middleware
|
||||
// (merged, not nested). External users have no calendar, no
|
||||
// address book, and no home folder — locking them out of these
|
||||
// protocol subtrees in one place avoids leaking the protocol
|
||||
// surface to a principal kind that can do nothing with it. The
|
||||
// `require_internal_user_layer` runs AFTER auth (tower order:
|
||||
// later .layer() = outermost = runs first).
|
||||
use oxicloud::interfaces::middleware::user::require_internal_user_layer;
|
||||
let caldav_protected = caldav_router
|
||||
.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
require_internal_user_layer,
|
||||
))
|
||||
.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
auth_middleware,
|
||||
));
|
||||
let carddav_protected = carddav_router
|
||||
.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
require_internal_user_layer,
|
||||
))
|
||||
.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
auth_middleware,
|
||||
));
|
||||
let webdav_protected = webdav_router
|
||||
.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
require_internal_user_layer,
|
||||
))
|
||||
.layer(axum::middleware::from_fn_with_state(
|
||||
app_state.clone(),
|
||||
auth_middleware,
|
||||
));
|
||||
|
||||
// Magic-link redemption — public, no CSRF, no rate limit (the token IS
|
||||
// the credential and `mark_used` is single-use). PR 12 will add a
|
||||
|
||||
Reference in New Issue
Block a user