Repository navigation
fix(auth): refuse an empty-string password on both login paths - #8261
Conversation
An account configured as `"password": ""` authenticated anyone who submitted an empty password, on the OIDC interaction path and on HTTP Basic. Only explicit misconfiguration produces it, so this is hardening rather than a vulnerability, but both paths should fail closed the way they already do for a nullish password. Reported by Wenhao Wu (Southeast University) while verifying the fix for GHSA-62cj-9j72-mfrh. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw
|
ⓘ Qodo reviews are paused because the subscription is no longer active. Ask your workspace admin to reactivate the subscription to resume reviews. Manage billing |
PR Summary by QodoReject empty configured passwords across login paths
AI Description
Diagram
High-Level Assessment
Files changed (4)
|
Code Review by Qodo🐞 Bugs (0) 📘 Rule violations (0) 📎 Requirement gaps (0)
Great, no issues found!Qodo reviewed your code and found no material issues that require reviewTip of the day💡 Did you know, you can add REVIEW.md to your repo root and Qodo follows it on every PR |
Follow-up hardening from Wenhao Wu (Southeast University), raised while verifying the fix for GHSA-62cj-9j72-mfrh in 3.3.6.
The gap
A
settings.usersentry with"password": ""logged in anyone who submitted an empty password — on the OIDC interaction path and on HTTP Basic. Both paths already fail closed for a nullish password; an empty string slipped through because it is a string and compares equal to an empty submission.Not a vulnerability: only explicit misconfiguration produces it, and Wenhao classified it that way too. But an empty password is never what an operator means, so it should be refused like a missing one.
Fix
verifyInteractiveLogin()now rejectspassword === ''alongside non-string values.webaccess.tsrejects an empty password in the same condition that already rejects a nullish one.Tests
OidcProviderSecurity.ts: rejects an empty-string password against both an empty and a non-empty submission.webaccess.ts: three credential shapes (admin:,admin,admin:anything) all get 401, mirroring the existing nullish-password spec.Without the fix 3 of these fail; with it all 91 in those two files pass. Full backend suite: 1810 passing.
tsc --noEmitclean.🤖 Generated with Claude Code
https://claude.ai/code/session_013S4pYSjwUsiZtdtMMpW7bw