Skip to content

Commit f274d9b

Browse files
committed
fix(supervisor): authorize the dequeue route and reject absent tokens in enforce mode
The workload server's dequeue route never called authorizeWorkloadRequest, and enforce mode only rejected present-but-invalid deployment tokens (jwt_invalid), letting requests with no token header at all (token_absent) through. Guard the dequeue route like the other workload-action routes and fail token_absent when WORKLOAD_TOKEN_ENFORCEMENT=enforce.
1 parent 0a23814 commit f274d9b

1 file changed

Lines changed: 7 additions & 2 deletions

File tree

  • apps/supervisor/src/workloadServer

‎apps/supervisor/src/workloadServer/index.ts‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -197,7 +197,7 @@ export class WorkloadServer extends EventEmitter<WorkloadServerEvents> {
197197
* Verify the deployment token from the workload deployment-id header and return the verified
198198
* environment_id to forward upstream. The env id is only forwarded in enforce mode: in log mode
199199
* we still verify + record metrics but attach no header (so the platform never scopes). Only
200-
* enforce fails a request, and only for a present-but-invalid token; absent and legacy ids pass.
200+
* enforce fails a request, and only for an absent or invalid token; legacy bare ids pass.
201201
*
202202
* `claims` are returned on any valid token, for local use only - never to scope the platform,
203203
* which is why environmentId stays gated on enforce.
@@ -213,7 +213,7 @@ export class WorkloadServer extends EventEmitter<WorkloadServerEvents> {
213213

214214
const result = await verifyDeploymentIdHeader(this.deploymentIdFromRequest(req), "http");
215215

216-
if (result.outcome === "jwt_invalid" && workloadTokenEnforced) {
216+
if (workloadTokenEnforced && (result.outcome === "jwt_invalid" || result.outcome === "token_absent")) {
217217
return { ok: false };
218218
}
219219

@@ -735,6 +735,11 @@ export class WorkloadServer extends EventEmitter<WorkloadServerEvents> {
735735
"GET",
736736
async () => {
737737
const { req, reply, params } = ctx;
738+
const auth = await this.authorizeWorkloadRequest(req);
739+
if (!auth.ok) {
740+
reply.empty(401);
741+
return;
742+
}
738743
const dequeueResponse = await this.workerClient.dequeueFromVersion(
739744
params.deploymentId,
740745
1,

0 commit comments

Comments
 (0)