fix(api): require auth on families, children, and attendance read routes #4
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "fix/auth-guard-data-routes"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Summary
Protects API routes that exposed family, child, volunteer, and attendance data without authentication.
Changes
requireAuthandrequireRole('volunteer')toGET /families/GET /families/childrenandGET /families/volunteersGET /children/andGET /children/searchGET /attendance/allSecurity context
The staging API returned real minors' names, dates of birth, medical metadata, family records, and attendance records to unauthenticated callers. This patch closes that public route exposure.
Verification
node --check apps/backend/src/routes/families.jsnode --check apps/backend/src/routes/children.jsnode --check apps/backend/src/routes/attendance.jsFollow-up
This closes code-review finding #1. The separate auth-model alignment finding remains open: backend JWT issuance, Supabase JWKS verification, and role claims must be reconciled before relying on role enforcement as the complete access-control model.
Five GET routes served children's PII (names, DOB, medical info), family data, volunteer profiles, and attendance records with no authentication. Verified live on staging. Add requireAuth + requireRole('volunteer') to: - GET /families/ - GET /families/children - GET /families/volunteers - GET /children/ and /children/search - GET /attendance/all Addresses code review finding #1 (critical).View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.