Skip to content

fix(api): require auth for message routes#2047

Open
chinook1001 wants to merge 1 commit into
SecureBananaLabs:mainfrom
chinook1001:codex/protect-message-routes
Open

fix(api): require auth for message routes#2047
chinook1001 wants to merge 1 commit into
SecureBananaLabs:mainfrom
chinook1001:codex/protect-message-routes

Conversation

@chinook1001
Copy link
Copy Markdown

Summary

  • require authMiddleware for all message routes
  • prevent unauthenticated clients from listing or creating messages
  • add regression coverage for unauthenticated rejection and authenticated send/list success

Fixes #2046

/claim #743

Validation

  • node --test apps/api/src/tests/health.test.js apps/api/src/tests/messageRoutes.test.js

github-actions Bot added a commit that referenced this pull request May 30, 2026
@chinook1001 chinook1001 force-pushed the codex/protect-message-routes branch from 76d5791 to c2bd8d9 Compare May 30, 2026 12:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Message routes should require authentication

1 participant