Skip to content

fix(auth): centralize session recovery and sanitize SVG uploads - #1419

Merged
mftee merged 2 commits into
CodeGirlsInc:mainfrom
Maryermarh:feature/session-upload-security
Sep 25, 2026
Merged

mftee merged 2 commits into
CodeGirlsInc:mainfrom
Maryermarh:feature/session-upload-security

Conversation

@Maryermarh

Copy link
Copy Markdown
Contributor

Summary

  • centralize managed 401 refresh/retry and proactive JWT-expiry handling
  • align login, refresh, logout, and protected requests on canonical API/session helpers
  • accept only bounded static SVG subsets and rasterize them without active content
  • separate scalar sanitization, API mapping, and browser SVG sanitization responsibilities

Issues

Validation

  • static diff, API contract, security, import/export, and secret review completed
  • automated tests, lint/typecheck, builds, dependency installation, and CI were not run per maintainer request

Closes #1309
Closes #1310
Closes #1311
Closes #1312

Add proactive expiry checks and centralized 401 refresh/logout handling, safely rasterize static SVG uploads, and clarify sanitizer module boundaries.

Closes CodeGirlsInc#1309
Closes CodeGirlsInc#1310
Closes CodeGirlsInc#1311
Closes CodeGirlsInc#1312
@vercel

vercel Bot commented Sep 25, 2026

Copy link
Copy Markdown
Contributor

@Maryermarh is attempting to deploy a commit to the Mftee's projects Team on Vercel.

A member of the Team first needs to authorize it.

@drips-wave

drips-wave Bot commented Sep 25, 2026

Copy link
Copy Markdown

@Maryermarh Great news! 🎉 Based on an automated assessment of this PR, the linked Wave issue(s) no longer count against your application limits.

You can now already apply to more issues while waiting for a review of this PR. Keep up the great work! 🚀

Learn more about application limits

# Conflicts:
#	backend/src/auth/auth.controller.ts
#	backend/src/dispute/dispute.service.ts
#	backend/src/documents/documents.controller.ts
#	backend/src/documents/pipes/file-validation.pipe.ts
#	backend/src/documents/pipes/mime-type-validation.pipe.ts
#	frontend/app/[locale]/(protected)/admin/providers/page.tsx
#	frontend/app/[locale]/(protected)/admin/users/page.tsx
#	frontend/app/[locale]/(protected)/disputes/[id]/page.tsx
#	frontend/app/[locale]/(protected)/disputes/page.tsx
#	frontend/app/[locale]/(protected)/documents/upload/page.tsx
#	frontend/app/[locale]/(protected)/layout.tsx
#	frontend/app/[locale]/(protected)/settings/data/page.tsx
#	frontend/app/[locale]/(protected)/settings/security/page.tsx
#	frontend/app/[locale]/2fa/setup/page.tsx
#	frontend/app/[locale]/2fa/verify/page.tsx
#	frontend/app/[locale]/forgot-password/page.tsx
#	frontend/app/[locale]/login/LoginForm.tsx
#	frontend/app/[locale]/reset-password/page.tsx
#	frontend/app/[locale]/verify-email/page.tsx
#	frontend/components/LanguageSwitcher.tsx
#	frontend/components/disputes/FileDisputeModal.tsx
#	frontend/components/layout/NotificationBell.tsx
#	frontend/lib/__tests__/session-expiry.test.ts
#	frontend/lib/api-client.ts
#	frontend/lib/auth-session.ts
#	frontend/lib/session-expiry-warning.ts
#	frontend/test-utils/LoginForm.test.tsx
#	frontend/test-utils/api-client.test.ts
#	frontend/test-utils/language-switcher.test.tsx
#	frontend/test-utils/mocks/handlers.ts

@mftee mftee left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Reviewed and resolved a large conflict against main, similar in scope to #1420: PR #1415/#1420 had already landed a competing auth-cookie scheme covering most of this PR's plumbing changes. Kept main's already-deployed session/auth code and backported this PR's real contribution — the extensive SVG upload-security work (allow/deny element lists, URL-attribute checks, dimension/element-count limits) into file-validation.pipe.ts, added image/svg+xml to the shared documentUpload contract so it isn't rejected before reaching that sanitizer, wired the browser-side sanitizeSvg pre-check into the upload page for early feedback, and kept the 403-vs-401 (ForbiddenException) correction in dispute.service.ts's ownership check. Dropped the now-superseded auth-cookie/session-bootstrap plumbing and the disputes.ts/SessionBootstrap files that duplicated what main already has. Good, thorough SVG-sanitization allowlist.

@mftee
mftee merged commit 0359ddc into CodeGirlsInc:main Sep 25, 2026
0 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

2 participants