mirror of
https://github.com/Stirling-Tools/Stirling-PDF.git
synced 2026-09-03 05:10:16 +03:00
fix: allow anonymous access to /invite/:token accept page (#7612)
## Problem In the self-hosted build with login enabled, admin-generated invite links point to the SPA route `/invite/<token>`, but that route is not covered by the anonymous whitelist. Anonymous users get 401 / redirected to `/login` before the React app can mount - even though the APIs the page calls (`/api/v1/invite/validate`, `/api/v1/invite/accept`) are already whitelisted. Since accepting an invite is how a *new* account is created, requiring authentication first makes the feature unusable. ## Fix Add `INVITE_LINK_PATTERN` (`^/invite/[^/]+/?$`) in `RequestUriUtils.java`, matched at the end of `isPublicAuthEndpoint()` - mirroring the existing `SHARE_LINK_PATTERN` handling. The invite data APIs remain protected by their own token validation; only the SPA bootstrap page becomes anonymously reachable. ## Tests Added unit tests in `RequestUriUtilsTest.java` mirroring the share-link tests: - `/invite/<token>` (with/without trailing slash, with context path) ? public - bare `/invite` and `/invite/` ? NOT public (token segment required) - `/invite/<token>/foo` nested paths ? NOT public - `/inviteX` prefix over-match ? NOT public ## Verification Pattern behavior validated against all test cases above. Live-tested on 2.14.3 self-hosted: anonymous `GET /invite/<token>` returned 401 before the fix; the whitelisted accept flow itself (`validate` + `accept` APIs) works anonymously end-to-end.
This commit is contained in:
@@ -5,6 +5,10 @@ import java.util.regex.Pattern;
|
||||
public class RequestUriUtils {
|
||||
|
||||
private static final Pattern SHARE_LINK_PATTERN = Pattern.compile("^/share/[^/]+/?$");
|
||||
// Invite tokens are 36-char lowercase UUIDs (UUID.randomUUID().toString()); match exactly
|
||||
private static final Pattern INVITE_LINK_PATTERN =
|
||||
Pattern.compile(
|
||||
"^/invite/[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}/?$");
|
||||
|
||||
public static boolean isStaticResource(String requestURI) {
|
||||
return isStaticResource("", requestURI);
|
||||
@@ -209,7 +213,9 @@ public class RequestUriUtils {
|
||||
// Workflow participant endpoints - access controlled by share tokens, not login
|
||||
|| trimmedUri.startsWith("/api/v1/workflow/participant/")
|
||||
// Share-link SPA bootstrap; data APIs remain protected
|
||||
|| SHARE_LINK_PATTERN.matcher(trimmedUri).matches();
|
||||
|| SHARE_LINK_PATTERN.matcher(trimmedUri).matches()
|
||||
// Invite-accept SPA bootstrap; data APIs remain protected
|
||||
|| INVITE_LINK_PATTERN.matcher(trimmedUri).matches();
|
||||
}
|
||||
|
||||
private static String stripContextPath(String contextPath, String requestURI) {
|
||||
|
||||
@@ -236,4 +236,86 @@ class RequestUriUtilsTest {
|
||||
RequestUriUtils.isPublicAuthEndpoint(
|
||||
"/api/v1/storage/share-links/abc123/metadata", ""));
|
||||
}
|
||||
|
||||
// --- invite-accept SPA bootstrap ---
|
||||
|
||||
private static final String INVITE_TOKEN = "06a20e7e-2e35-4e26-be7d-2dce14f28f12";
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteLinkToken() {
|
||||
assertTrue(RequestUriUtils.isPublicAuthEndpoint("/invite/" + INVITE_TOKEN, ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteLinkTokenTrailingSlash() {
|
||||
assertTrue(RequestUriUtils.isPublicAuthEndpoint("/invite/" + INVITE_TOKEN + "/", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteLinkWithContextPath() {
|
||||
assertTrue(RequestUriUtils.isPublicAuthEndpoint("/app/invite/" + INVITE_TOKEN, "/app"));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteRootNotPublic() {
|
||||
// Avoid matching bare "/invite" or "/invite/" - must have a token segment
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite", ""));
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite/", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteNestedPathNotPublic() {
|
||||
// Guard against future additions like /invite/<token>/foo becoming accidentally public
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite/" + INVITE_TOKEN + "/foo", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_invitePrefixDoesNotOvermatch() {
|
||||
// "/inviteX" must not match the invite pattern
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/inviteX", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteNonUuidTokenNotPublic() {
|
||||
// Only exactly-shaped 36-char lowercase UUID tokens are treated as invite links
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite/abc123", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteUppercaseUuidNotPublic() {
|
||||
// Tokens are generated lowercase by UUID.randomUUID().toString()
|
||||
assertFalse(
|
||||
RequestUriUtils.isPublicAuthEndpoint(
|
||||
"/invite/06A20E7E-2E35-4E26-BE7D-2DCE14F28F12", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteWrongLengthNotPublic() {
|
||||
// 35-char and 37-char UUID-like tokens are not valid UUIDs
|
||||
assertFalse(
|
||||
RequestUriUtils.isPublicAuthEndpoint(
|
||||
"/invite/06a20e7e-2e35-4e26-be7d-2dce14f28f1", ""));
|
||||
assertFalse(
|
||||
RequestUriUtils.isPublicAuthEndpoint(
|
||||
"/invite/06a20e7e-2e35-4e26-be7d-2dce14f28f122", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteWrongGroupingNotPublic() {
|
||||
// Groups of 8-4-4-4-4 must not be shifted around (e.g. 4-4-4-4-8)
|
||||
assertFalse(
|
||||
RequestUriUtils.isPublicAuthEndpoint(
|
||||
"/invite/06a2-0e7e-2e35-4e26-be7d2dce14f28f12", ""));
|
||||
}
|
||||
|
||||
@Test
|
||||
void testIsPublicAuthEndpoint_inviteTokenInvalidCharsNotPublic() {
|
||||
// Hex-only; anything outside [0-9a-f] or the UUID hyphens is rejected
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite/abc$123", ""));
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite/abc..123", ""));
|
||||
assertFalse(RequestUriUtils.isPublicAuthEndpoint("/invite/abc%2F123", ""));
|
||||
assertFalse(
|
||||
RequestUriUtils.isPublicAuthEndpoint(
|
||||
"/invite/06a20e7e-2e35-4e26-be7d-2dce14f28f1g", ""));
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user