Commit 901ff41
committed
Reject whitespace-only resolved identity, not just empty strings (CL-6286)
ResolvedCallerSchema used "string >= 1" -- a LENGTH constraint, so " " (length
1) passed it and got seated as a "valid" principal/tenant, just like the
empty-string exploit in a different costume. Require at least one
non-whitespace character (type("string").narrow(s => s.trim().length > 0))
instead, with a ctx.mustBe() message so the rejection reads clearly in logs.1 parent 22573d3 commit 901ff41
1 file changed
Lines changed: 15 additions & 4 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
41 | 41 | | |
42 | 42 | | |
43 | 43 | | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
44 | 54 | | |
45 | 55 | | |
46 | 56 | | |
47 | 57 | | |
48 | | - | |
49 | | - | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
50 | 61 | | |
51 | 62 | | |
52 | | - | |
53 | | - | |
| 63 | + | |
| 64 | + | |
54 | 65 | | |
55 | 66 | | |
56 | 67 | | |
| |||
0 commit comments