Repository navigation
test: verify revoked keys fail gateway auth immediately - #1403
kaizercodes wants to merge 7 commits into
Conversation
|
@kaizercodes Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits. You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀 |
|
Thanks for the contribution! We reviewed this PR while merging the open queue and couldn't merge it yet. Here's what needs fixing:
This branch also has merge conflicts with |
…-gateway-authentication Resolves merge conflicts against CalloraOrg/Callora-Backend@1518ce6 (68 commit(s) behind) so the PR is mergeable.
|
@greatest0fallt1me thanks for the review — pushed a fix to this branch. What changed:
Head: One honest caveat: the new gateway cases in |
The new integration cases called GET /gateway/echo and used the Authorization header, but the gateway proxy handler is mounted at /api/gateway and authenticates with x-api-key. Mount the real createGatewayRouter router at /api/gateway (same convention as tests/integration/proxy.test.ts) against an in-process upstream stub, revoke through the real DELETE /api/keys/:id route, and assert the handler's actual 403 response for a revoked key.
|
@greatest0fallt1me Thanks for the review — both points are addressed on the current head (
Verification: Could you take another look? |
Overview
This PR closes the gap where
gatewayRoutes.tsconsultsgetTokenRevocationService().isRevoked(apiKeyHash)andDELETE /keys/:idadds the hash, but no end-to-end test proved that a deleted key is rejected on the very next gateway call. It adds that integration coverage and tightens the revocation path so the hash (not plaintext) is what gates authentication.Related Issue
Changes
🔐 Revocation enforcement
[MODIFY]
src/middleware/gatewayApiKeyAuth.ts401immediately when the hash is revoked, before any upstream dispatch.[MODIFY]
src/routes/gatewayRoutes.ts[MODIFY]
src/routes/apiKeyRoutes.tsDELETE /keys/:idrecords the sha256 hash of the key in the revocation service so subsequent gateway calls fail closed.[MODIFY]
src/services/tokenRevocation.tsisRevokedtakes the hash, not the raw key.🧪 Integration coverage
tests/integration/keys.test.tscreateApiKeyRouter, calls the gateway successfully, deletes the key, then asserts the next gateway call returns401.Verification Results
DELETE /keys/:idreturns 401Security & Failure Modes
401and no proxy attempt.Compatibility
No public API or route shape changes. The revocation service now consistently keys by sha256 hash, matching how
gatewayRoutes.tsalready calledisRevoked(apiKeyHash).Closes #1318