fix: Validate session in middleware for non-GET requests to /sessions/me (#10213)

This commit is contained in:
Manuel
2026-03-15 18:51:40 +00:00
committed by GitHub
parent d826dc7635
commit 2a9fdab367
2 changed files with 65 additions and 1 deletions
+64
View File
@@ -256,4 +256,68 @@ describe('Parse.Session', () => {
expect(newSession.createdWith.action).toBe('create');
expect(newSession.createdWith.authProvider).toBeUndefined();
});
describe('PUT /sessions/me', () => {
it('should return error with invalid session token', async () => {
const response = await request({
method: 'PUT',
url: 'http://localhost:8378/1/sessions/me',
headers: {
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'rest',
'X-Parse-Session-Token': 'r:invalid-session-token',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
}).catch(e => e);
expect(response.status).not.toBe(500);
expect(response.data.code).toBe(Parse.Error.INVALID_SESSION_TOKEN);
});
it('should return error without session token', async () => {
const response = await request({
method: 'PUT',
url: 'http://localhost:8378/1/sessions/me',
headers: {
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'rest',
'Content-Type': 'application/json',
},
body: JSON.stringify({}),
}).catch(e => e);
expect(response.status).toBeGreaterThanOrEqual(400);
expect(response.status).toBeLessThan(500);
expect(response.data?.code).toBeDefined();
});
});
describe('DELETE /sessions/me', () => {
it('should return error with invalid session token', async () => {
const response = await request({
method: 'DELETE',
url: 'http://localhost:8378/1/sessions/me',
headers: {
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'rest',
'X-Parse-Session-Token': 'r:invalid-session-token',
},
}).catch(e => e);
expect(response.status).not.toBe(500);
expect(response.data.code).toBe(Parse.Error.INVALID_SESSION_TOKEN);
});
it('should return error without session token', async () => {
const response = await request({
method: 'DELETE',
url: 'http://localhost:8378/1/sessions/me',
headers: {
'X-Parse-Application-Id': 'test',
'X-Parse-REST-API-Key': 'rest',
},
}).catch(e => e);
expect(response.status).toBeGreaterThanOrEqual(400);
expect(response.status).toBeLessThan(500);
expect(response.data?.code).toBeDefined();
});
});
});
+1 -1
View File
@@ -377,7 +377,7 @@ const handleRateLimit = async (req, res, next) => {
export const handleParseSession = async (req, res, next) => {
try {
const info = req.info;
if (req.auth || req.url === '/sessions/me') {
if (req.auth || (req.url === '/sessions/me' && req.method === 'GET')) {
next();
return;
}