Skip to content

Accept Bearer tokens on the seven cookie-only API routes (0.5.3) - #286

Merged
ralyodio merged 1 commit into
masterfrom
fix/qc-send-auth
Oct 6, 2026
Merged

ralyodio merged 1 commit into
masterfrom
fix/qc-send-auth

Conversation

@ralyodio

@ralyodio ralyodio commented Oct 6, 2026

Copy link
Copy Markdown
Contributor

qc send failed with "Not sent: Unauthorized". Before sending, qc reads /api/chat/conversations/[id]/participants and /api/crypto/public-keys, and both had their own cookie-only auth.

An audit found seven such routes: participants, chat/messages, chat/messages/[id], crypto/public-keys, crypto/public-keys/all, and both disappearing-messages routes. Each now checks Authorization: Bearer first, through a shared bearerToken(), then falls back to cookies as before. This also fixes cookie-less passkey and CoinPay browser sessions on those routes.

Tests: 670/670, including a new test for Bearer with no cookie. next build passes.

🤖 Generated with Claude Code

qc send failed with 'Unauthorized': it reads participants from
/api/chat/conversations/[id]/participants and public keys from
/api/crypto/public-keys, and both parsed only cookies. Same for chat/messages,
chat/messages/[id], public-keys/all and the disappearing-messages routes.
They now take Authorization: Bearer first (shared bearerToken()), cookies
after, which also covers cookie-less passkey and CoinPay browser sessions.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

ThreatCrush Security Scan

13 finding(s)

MEDIUM: 9 | LOW: 4

Severity Rule Location
MEDIUM redos-nested-quantifier src/app/api/profile/update/route.js:73
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:38
MEDIUM js-unescaped-html-sink src/app/blog/[slug]/page.jsx:66
MEDIUM js-unescaped-html-sink src/app/faq/page.jsx:57
MEDIUM js-unescaped-html-sink src/app/layout.jsx:137
MEDIUM js-unescaped-html-sink src/app/layout.jsx:141
MEDIUM js-unescaped-html-sink src/app/page.jsx:47
MEDIUM redos-nested-quantifier src/lib/auth/dns-name.js:88
MEDIUM js-unescaped-html-sink src/lib/components/chat/MessageItem.jsx:121
LOW secret-generic-credential src/app/api/auth/register-anon/route.test.js:32
LOW secret-jwt tests/debug-sms.js:10
LOW secret-generic-credential tests/private-key-import-export.test.js:252
LOW secret-generic-credential tests/private-key-import-export.test.js:264

Snippets are redacted; ThreatCrush never prints matched credential material.

@ralyodio
ralyodio merged commit 3f608b9 into master Oct 6, 2026
11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant