fix(api): require auth on families, children, and attendance read routes #4

Open
kianiadkny wants to merge 0 commits from fix/auth-guard-data-routes into staging
Owner

Summary

Protects API routes that exposed family, child, volunteer, and attendance data without authentication.

Changes

  • Adds requireAuth and requireRole('volunteer') to GET /families/
  • Adds the same protection to GET /families/children and GET /families/volunteers
  • Protects GET /children/ and GET /children/search
  • Protects GET /attendance/all

Security context

The staging API returned real minors' names, dates of birth, medical metadata, family records, and attendance records to unauthenticated callers. This patch closes that public route exposure.

Verification

  • node --check apps/backend/src/routes/families.js
  • node --check apps/backend/src/routes/children.js
  • node --check apps/backend/src/routes/attendance.js

Follow-up

This closes code-review finding #1. The separate auth-model alignment finding remains open: backend JWT issuance, Supabase JWKS verification, and role claims must be reconciled before relying on role enforcement as the complete access-control model.

## Summary Protects API routes that exposed family, child, volunteer, and attendance data without authentication. ### Changes - Adds `requireAuth` and `requireRole('volunteer')` to `GET /families/` - Adds the same protection to `GET /families/children` and `GET /families/volunteers` - Protects `GET /children/` and `GET /children/search` - Protects `GET /attendance/all` ## Security context The staging API returned real minors' names, dates of birth, medical metadata, family records, and attendance records to unauthenticated callers. This patch closes that public route exposure. ## Verification - `node --check apps/backend/src/routes/families.js` - `node --check apps/backend/src/routes/children.js` - `node --check apps/backend/src/routes/attendance.js` ## Follow-up This closes code-review finding #1. The separate auth-model alignment finding remains open: backend JWT issuance, Supabase JWKS verification, and role claims must be reconciled before relying on role enforcement as the complete access-control model.
Five GET routes served children's PII (names, DOB, medical info),
family data, volunteer profiles, and attendance records with no
authentication. Verified live on staging.

Add requireAuth + requireRole('volunteer') to:
- GET /families/
- GET /families/children
- GET /families/volunteers
- GET /children/ and /children/search
- GET /attendance/all

Addresses code review finding #1 (critical).
This branch is already included in the target branch. There is nothing to merge.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin fix/auth-guard-data-routes:fix/auth-guard-data-routes
git switch fix/auth-guard-data-routes

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch staging
git merge --no-ff fix/auth-guard-data-routes
git switch fix/auth-guard-data-routes
git rebase staging
git switch staging
git merge --ff-only fix/auth-guard-data-routes
git switch fix/auth-guard-data-routes
git rebase staging
git switch staging
git merge --no-ff fix/auth-guard-data-routes
git switch staging
git merge --squash fix/auth-guard-data-routes
git switch staging
git merge --ff-only fix/auth-guard-data-routes
git switch staging
git merge fix/auth-guard-data-routes
git push origin staging
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
kianiadkny/kisima_champions!4
No description provided.