Skip to content

API key authentication does not rotate or scope keys per tenant allowing cross-tenant replay #1446

Description

@Junirezz

Context
backend/src/auth/apiKey.ts stores apiKey as single global API_KEY env var and checks req.headers['x-api-key'] === API_KEY without tenant scoping.

Why this is a gap
Compromised key works for all tenants and cannot be rotated per tenant without downtime; also no expiry or last-used tracking for audit.

Acceptance Criteria

  • Store apiKey per tenantId in apiKey table with hashedKey, scopes[], expiresAt, lastUsedAt
  • Middleware checks tenantId from path/query and validates scopes includes required scope for route
  • Return 401 API_KEY_EXPIRED or SCOPE_INSUFFICIENT with WWW-Authenticate header
  • Test: create two tenants with different keys and assert cross-tenant key gets 401
  • Migration adds table, existing single-key still works via fallback env var with deprecation log

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions