Commit 7dcde27
fix(rest+runtime): plug anonymous /data/* leak and decouple runtime from service-cloud
Two related fixes that together close the CRM cross-account data leak
reported at crm.objectos.app.
## Phase R - runtime ↔ service-cloud decoupling
`packages/runtime` no longer depends on `@objectstack/service-cloud`.
Cloud-side runtime helpers physically moved to `packages/runtime/src/cloud/`:
- artifact-api-client / file-artifact-api-client
- artifact-environment-registry / environment-registry
- artifact-kernel-factory
- auth-proxy-plugin
- kernel-manager (+ tests)
- objectos-stack
apps/objectos/server/{ensure-local-identity, fs-app-bundle-resolver,
single-project-plugin}.ts removed (logic absorbed into runtime/cloud
or the per-project stack).
apps/cloud and apps/objectos `objectstack.config.ts` updated to import
the cloud helpers from `@objectstack/runtime/cloud` instead of
`@objectstack/service-cloud`.
## Phase S - REST requireAuth gate (CF leak root fix)
Anonymous requests to `/api/v1/data/*` were bypassing security checks
entirely because plugin-security short-circuits when userId/roles are
absent (kept for standalone public demos). Added an opt-in REST-layer
gate so deployments that mount the auth tier reject anon callers
*before* hitting ObjectQL.
- `RestApiConfigSchema.requireAuth: z.boolean().default(false)`
(packages/spec/src/api/rest-server.zod.ts)
- `RestServer.enforceAuth(req, res, ctx)` returns 401
`{error: "unauthenticated"}` (OPTIONS preflight excluded)
(packages/rest/src/rest-server.ts)
- All 9 `/data/*` routes gated: list, read, create, update, delete,
batch, createMany, updateMany, deleteMany. The 4 batch routes also
now resolve and forward exec context, so authenticated batch ops
finally get proper RBAC enforcement.
- CLI auto-enables `requireAuth` whenever `tierEnabled('auth')` is
true; stack-level `api.requireAuth` overrides
(packages/cli/src/commands/serve.ts).
Verified locally:
- anon GET /api/v1/data/account -> 401 (was leaking data)
- anon POST /api/v1/data/account/createMany -> 401
- authed cloud GET /data/sys_project -> 200
- authed cloud GET /cloud/projects -> 200
- packages/rest test suite (53 tests) -> all pass
ROADMAP updated with S1 entry.
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>1 parent fcc92dc commit 7dcde27
30 files changed
Lines changed: 1650 additions & 1710 deletions
File tree
- apps
- cloud
- objectos
- server
- packages
- cli/src/commands
- rest/src
- runtime
- src
- cloud
- spec/src/api
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
104 | 104 | | |
105 | 105 | | |
106 | 106 | | |
| 107 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
39 | 39 | | |
40 | 40 | | |
41 | 41 | | |
42 | | - | |
43 | | - | |
44 | | - | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
45 | 45 | | |
46 | 46 | | |
47 | 47 | | |
| |||
56 | 56 | | |
57 | 57 | | |
58 | 58 | | |
| 59 | + | |
59 | 60 | | |
60 | 61 | | |
61 | 62 | | |
| |||
111 | 112 | | |
112 | 113 | | |
113 | 114 | | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
114 | 133 | | |
115 | 134 | | |
116 | 135 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
4 | 4 | | |
5 | 5 | | |
6 | 6 | | |
7 | | - | |
| 7 | + | |
8 | 8 | | |
9 | | - | |
10 | | - | |
11 | | - | |
12 | | - | |
13 | | - | |
14 | | - | |
15 | | - | |
16 | | - | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
17 | 14 | | |
18 | 15 | | |
19 | | - | |
| 16 | + | |
20 | 17 | | |
21 | 18 | | |
22 | 19 | | |
23 | | - | |
24 | | - | |
25 | | - | |
26 | | - | |
27 | | - | |
28 | | - | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
29 | 37 | | |
30 | 38 | | |
31 | 39 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1 | 1 | | |
2 | 2 | | |
3 | 3 | | |
4 | | - | |
| 4 | + | |
5 | 5 | | |
6 | 6 | | |
7 | 7 | | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
8 | 14 | | |
9 | 15 | | |
10 | | - | |
11 | | - | |
12 | | - | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
13 | 20 | | |
14 | 21 | | |
15 | | - | |
16 | | - | |
17 | | - | |
18 | | - | |
19 | | - | |
20 | | - | |
21 | | - | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
22 | 29 | | |
23 | | - | |
24 | | - | |
25 | | - | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
26 | 33 | | |
27 | 34 | | |
28 | | - | |
29 | | - | |
30 | | - | |
31 | | - | |
| 35 | + | |
32 | 36 | | |
33 | | - | |
34 | | - | |
35 | | - | |
36 | | - | |
| 37 | + | |
37 | 38 | | |
38 | | - | |
39 | | - | |
40 | | - | |
41 | | - | |
42 | | - | |
43 | | - | |
44 | | - | |
45 | | - | |
46 | | - | |
47 | | - | |
48 | | - | |
49 | | - | |
50 | | - | |
51 | | - | |
52 | | - | |
53 | | - | |
54 | | - | |
55 | | - | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
56 | 48 | | |
57 | 49 | | |
58 | 50 | | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
46 | 46 | | |
47 | 47 | | |
48 | 48 | | |
49 | | - | |
50 | 49 | | |
51 | 50 | | |
52 | 51 | | |
| |||
This file was deleted.
This file was deleted.
This file was deleted.
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
765 | 765 | | |
766 | 766 | | |
767 | 767 | | |
| 768 | + | |
| 769 | + | |
| 770 | + | |
| 771 | + | |
| 772 | + | |
| 773 | + | |
768 | 774 | | |
769 | 775 | | |
770 | 776 | | |
771 | 777 | | |
772 | | - | |
| 778 | + | |
773 | 779 | | |
774 | 780 | | |
775 | 781 | | |
| |||
0 commit comments