Skip to content

Auth bypass when PROXLY_SECRET unset + secret transmitted in URL query string #1

@consigcody94

Description

@consigcody94

Found via code audit. packages/server/src/auth.ts:3-7. validateSecret returns true when env var unset. Also secret extracted from URL query params - logged by proxies/CDNs.

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions