refactor: authorize API routes with per-endpoint scopes (#1823)

Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
This commit is contained in:
Elias Schneider
2026-10-09 21:33:14 +02:00
committed by GitHub
co-authored by copilot-swe-agent[bot]
parent 1bd6f006c8
commit 0ec6bfa191
48 changed files with 1422 additions and 681 deletions
+6 -5
View File
@@ -14,6 +14,7 @@ import (
"github.com/pocket-id/pocket-id/backend/internal/appconfig"
"github.com/pocket-id/pocket-id/backend/internal/apperror"
"github.com/pocket-id/pocket-id/backend/internal/auditlogs"
"github.com/pocket-id/pocket-id/backend/internal/authz"
"github.com/pocket-id/pocket-id/backend/internal/dto"
"github.com/pocket-id/pocket-id/backend/internal/httpserver"
"github.com/pocket-id/pocket-id/backend/internal/utils"
@@ -38,7 +39,7 @@ func (h *handler) beginRegistration(c *gin.Context) error {
return fmt.Errorf("error loading app configuration: %w", err)
}
userID := c.GetString("userID")
userID := authz.PrincipalFrom(c).UserID
options, err := h.service.BeginRegistration(c.Request.Context(), dbConfig, userID)
if err != nil {
return err
@@ -60,7 +61,7 @@ func (h *handler) verifyRegistration(c *gin.Context) error {
return apperror.MissingSessionID()
}
userID := c.GetString("userID")
userID := authz.PrincipalFrom(c).UserID
credential, err := h.service.VerifyRegistration(c.Request.Context(), dbConfig, sessionID, userID, c.Request, c.ClientIP())
if err != nil {
return err
@@ -129,7 +130,7 @@ func (h *handler) verifyLogin(c *gin.Context) error {
}
func (h *handler) listCredentials(c *gin.Context) error {
userID := c.GetString("userID")
userID := authz.PrincipalFrom(c).UserID
credentials, err := h.service.ListCredentials(c.Request.Context(), userID)
if err != nil {
return err
@@ -145,7 +146,7 @@ func (h *handler) listCredentials(c *gin.Context) error {
}
func (h *handler) deleteCredential(c *gin.Context) error {
userID := c.GetString("userID")
userID := authz.PrincipalFrom(c).UserID
credentialID := c.Param("id")
clientIP := c.ClientIP()
userAgent := c.Request.UserAgent()
@@ -160,7 +161,7 @@ func (h *handler) deleteCredential(c *gin.Context) error {
}
func (h *handler) updateCredential(c *gin.Context) error {
userID := c.GetString("userID")
userID := authz.PrincipalFrom(c).UserID
credentialID := c.Param("id")
var input dto.WebauthnCredentialUpdateDto