fix(security): harden auth and secret handling (HH-444) (#101)
* fix(security): harden auth and credential handling (HH-444) * fix(security): address HH-444 review blockers * fix(security): close remaining HH-444 review blockers --------- Co-authored-by: Rogee <rogee@ipao.vip>
This commit is contained in:
@@ -13,34 +13,50 @@ class BaseActionCableConnector {
|
||||
websocketHost = '',
|
||||
presenceInterval = PRESENCE_INTERVAL
|
||||
) {
|
||||
// Read access-token for WebSocket auth from cookie
|
||||
let accessToken = '';
|
||||
try {
|
||||
const raw = Cookies.get('cw_d_session_info');
|
||||
if (raw) {
|
||||
const parsed = JSON.parse(raw);
|
||||
accessToken = parsed['access-token'] || '';
|
||||
}
|
||||
} catch (e) {
|
||||
// Ignore cookie parse errors
|
||||
}
|
||||
this.consumer = null;
|
||||
this.subscription = null;
|
||||
this.websocketHost = websocketHost;
|
||||
this.pubsubToken = pubsubToken;
|
||||
this.app = app;
|
||||
this.events = {};
|
||||
this.reconnectTimer = null;
|
||||
this.isAValidEvent = () => true;
|
||||
this.connect();
|
||||
this.triggerPresenceInterval = () => {
|
||||
setTimeout(() => {
|
||||
this.subscription?.updatePresence();
|
||||
this.triggerPresenceInterval();
|
||||
}, presenceInterval);
|
||||
};
|
||||
this.triggerPresenceInterval();
|
||||
}
|
||||
|
||||
// Default to the page origin so the URL is never undefined.
|
||||
const wsOrigin = websocketHost || window.location.origin;
|
||||
async connect() {
|
||||
const wsOrigin = this.websocketHost || window.location.origin;
|
||||
let websocketURL = `${wsOrigin}/cable`;
|
||||
if (accessToken) {
|
||||
websocketURL += `?access-token=${encodeURIComponent(accessToken)}`;
|
||||
} else if (pubsubToken) {
|
||||
websocketURL += `?pubsub_token=${encodeURIComponent(pubsubToken)}`;
|
||||
if (Cookies.get('cw_d_session_state')) {
|
||||
try {
|
||||
const response = await window.axios.post('/api/v1/auth/ws_ticket');
|
||||
const ticket = response.data?.data?.ticket;
|
||||
if (!ticket) throw new Error('missing websocket ticket');
|
||||
websocketURL += `?ticket=${encodeURIComponent(ticket)}`;
|
||||
this.usesWSTicket = true;
|
||||
} catch (error) {
|
||||
this.initReconnectTimer();
|
||||
return;
|
||||
}
|
||||
} else if (this.pubsubToken) {
|
||||
websocketURL += `?pubsub_token=${encodeURIComponent(this.pubsubToken)}`;
|
||||
this.usesWSTicket = false;
|
||||
}
|
||||
|
||||
this.consumer = createConsumer(websocketURL);
|
||||
this.subscription = this.consumer.subscriptions.create(
|
||||
{
|
||||
channel: 'RoomChannel',
|
||||
pubsub_token: pubsubToken,
|
||||
account_id: app.$store.getters.getCurrentAccountId,
|
||||
user_id: app.$store.getters.getCurrentUserID,
|
||||
pubsub_token: this.pubsubToken,
|
||||
account_id: this.app.$store.getters.getCurrentAccountId,
|
||||
user_id: this.app.$store.getters.getCurrentUserID,
|
||||
},
|
||||
{
|
||||
updatePresence() {
|
||||
@@ -49,25 +65,23 @@ class BaseActionCableConnector {
|
||||
received: this.onReceived,
|
||||
disconnected: () => {
|
||||
BaseActionCableConnector.isDisconnected = true;
|
||||
if (this.usesWSTicket) {
|
||||
this.consumer?.disconnect();
|
||||
this.consumer = null;
|
||||
this.subscription = null;
|
||||
}
|
||||
this.onDisconnected();
|
||||
this.initReconnectTimer();
|
||||
},
|
||||
}
|
||||
);
|
||||
this.app = app;
|
||||
this.events = {};
|
||||
this.reconnectTimer = null;
|
||||
this.isAValidEvent = () => true;
|
||||
this.triggerPresenceInterval = () => {
|
||||
setTimeout(() => {
|
||||
this.subscription.updatePresence();
|
||||
this.triggerPresenceInterval();
|
||||
}, presenceInterval);
|
||||
};
|
||||
this.triggerPresenceInterval();
|
||||
}
|
||||
|
||||
checkConnection() {
|
||||
if (!this.consumer) {
|
||||
this.connect();
|
||||
return;
|
||||
}
|
||||
const isConnectionActive = this.consumer.connection.isOpen();
|
||||
const isReconnected =
|
||||
BaseActionCableConnector.isDisconnected && isConnectionActive;
|
||||
@@ -101,7 +115,7 @@ class BaseActionCableConnector {
|
||||
onDisconnected = () => {};
|
||||
|
||||
disconnect() {
|
||||
this.consumer.disconnect();
|
||||
this.consumer?.disconnect();
|
||||
}
|
||||
|
||||
onReceived = ({ event, data } = {}) => {
|
||||
|
||||
Reference in New Issue
Block a user