Skip to content

fix: auth-gate /refs and /activity/* endpoints - #555

Open
ryankc33 wants to merge 2 commits into
garrytan:mainfrom
ryankc33:fix/auth-refs-activity-endpoints
Open

ryankc33 wants to merge 2 commits into
garrytan:mainfrom
ryankc33:fix/auth-refs-activity-endpoints

Conversation

@ryankc33

Copy link
Copy Markdown

Summary

  • Require bearer auth on /refs, /activity/stream, and /activity/history endpoints — previously any local process or website could read browse state without authentication
  • Remove Access-Control-Allow-Origin: * headers from those endpoints so web pages can no longer read responses via cross-origin fetch
  • Add query-parameter token fallback to validateAuth for EventSource compatibility (it cannot set custom headers)
  • Update Chrome extension callers (background.js, sidepanel.js) to pass auth tokens on all three endpoints

Test plan

  • New browse/test/endpoint-auth.test.ts — 12 tests covering all three endpoints
  • Unauthenticated requests return 401
  • Wrong token returns 401
  • Valid bearer header returns 200
  • Query-parameter token returns 200 (EventSource compat)
  • Access-Control-Allow-Origin header is absent from authenticated responses
  • Existing sidebar-integration.test.ts still passes (13/13)
  • Existing activity.test.ts still passes (18/18)

🤖 Generated with Claude Code

ryankc33 and others added 2 commits March 27, 2026 12:59
These endpoints were unauthenticated, allowing any local process to read
browser refs, current URL, and command activity history. The wildcard
Access-Control-Allow-Origin headers also allowed web pages to read the
responses via cross-origin fetch. Now all three endpoints require the
same bearer token used by sidebar endpoints, with a query-parameter
fallback for EventSource (which cannot set custom headers).

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Verifies that unauthenticated requests return 401 and that
Access-Control-Allow-Origin: * is no longer present on responses.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@jelitzamulryan80

Copy link
Copy Markdown

Good call gating these endpoints behind auth. The query param fallback for EventSource is a reasonable tradeoff since SSE clients can't set custom headers. Worth noting: the token in the URL will show up in server access logs and potentially in referrer headers if the page navigates. If that's a concern, you could rotate the token periodically or add a short-lived session mechanism.

@time-attack

Copy link
Copy Markdown
Contributor

@16francej Please close this PR. The affected browser endpoints were secured more safely in #595 and later hardening. This old version can put auth tokens in URLs, where they may leak into logs, so it must not be merged.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants