maziggy
|
3fa9ed2b91
|
Add authentication to 200+ API endpoints (CVE-2026-25505)
Security fix for critical vulnerability (CVSS 9.8) where API endpoints
were accessible without authentication when auth was enabled.
Changes:
- Add RequirePermissionIfAuthEnabled() to all unprotected route files:
archives, projects, settings, api_keys, groups, cloud, github_backup,
support, notifications, notification_templates, maintenance, filaments,
external_links, smart_plugs, discovery, firmware, kprofiles, camera,
ams_history, pending_uploads, updates, spoolman, system, print_queue,
printers
- Keep image-serving endpoints (thumbnails, timelapse, photos, camera
streams, icons) unauthenticated since <img> tags cannot send headers
- Add backend integration tests for endpoint auth enforcement
- Add frontend tests for ownership-based permissions (canModify)
Fixes: CVE-2026-25505
|
2026-02-03 08:44:07 +01:00 |
|