security(external_user): protect unnecessary route access to external users

This commit is contained in:
Edouard Vanbelle
2026-06-02 14:46:27 +02:00
parent 21c06da700
commit 6d70a7000e
8 changed files with 236 additions and 19 deletions
+35 -13
View File
@@ -378,19 +378,41 @@ async fn main() -> Result<(), Box<dyn std::error::Error>> {
auth_middleware,
));
// CalDAV/CardDAV/WebDAV with auth middleware (merged, not nested)
let caldav_protected = caldav_router.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
auth_middleware,
));
let carddav_protected = carddav_router.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
auth_middleware,
));
let webdav_protected = webdav_router.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
auth_middleware,
));
// CalDAV/CardDAV/WebDAV with auth + internal-only middleware
// (merged, not nested). External users have no calendar, no
// address book, and no home folder — locking them out of these
// protocol subtrees in one place avoids leaking the protocol
// surface to a principal kind that can do nothing with it. The
// `require_internal_user_layer` runs AFTER auth (tower order:
// later .layer() = outermost = runs first).
use oxicloud::interfaces::middleware::user::require_internal_user_layer;
let caldav_protected = caldav_router
.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
require_internal_user_layer,
))
.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
auth_middleware,
));
let carddav_protected = carddav_router
.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
require_internal_user_layer,
))
.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
auth_middleware,
));
let webdav_protected = webdav_router
.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
require_internal_user_layer,
))
.layer(axum::middleware::from_fn_with_state(
app_state.clone(),
auth_middleware,
));
// Magic-link redemption — public, no CSRF, no rate limit (the token IS
// the credential and `mark_used` is single-use). PR 12 will add a