Commit 19d0db2
fix(auth): close CSRF on /auth/email/start + per-IP magic-link rate-limit (P0)
Auth P0 chain found by QA 2026-05-29. Two findings on the magic-link
abuse surface, ship together.
Findings closed in this PR:
AUTH-163 (P0): /auth/email/start accepted Content-Type: application/
x-www-form-urlencoded and inserted a magic_links row. Combined with
no Origin/Referer enforcement that was a textbook CSRF primitive:
a malicious site could <form action="https://api.instanode.dev/
auth/email/start" method="POST"> to spam any arbitrary email with
magic-links from the victim's IP. Fix: require Content-Type:
application/json (charset suffix permitted). Form-encoded bodies
are rejected with 400 invalid_content_type BEFORE the body is
parsed or the DB is touched. The legitimate dashboard / CLI /
agent flows all set application/json — the only callers that send
urlencoded bodies are third-party-origin browser forms, which is
exactly the attack surface we want to close.
AUTH-107 / AUTH-097 (P0/P1): no CAPTCHA on /auth/email/start AND no
per-IP magic-link rate-limit. Without CAPTCHA (deferred — the
Brevo sender gap (project memory project_brevo_sender_not_validated)
is the real blocker, and CAPTCHA on a non-deliverable email path
just frustrates legitimate users), per-IP limit is the load-bearing
abuse-defence. Existing per-email limit (5/hr/email) is trivially
bypassed by rotating the email — an attacker can spam any number
of 3rd-party addresses from a single IP. Fix: per-IP rate limit
of magicLinkPerIPRateLimit (5) per magicLinkPerIPRateLimitWindow
(1h), keyed by SHA-256 of c.IP() in Redis under
magicLinkPerIPRLKeyPrefix ("ml:ip:rl"). Runs AFTER email
validation (so a typo doesn't burn budget) but BEFORE the per-email
limit (so it fires even when the per-email budget is fresh). Fail-
open on Redis error per CLAUDE.md convention 1. Limited path returns
202 — identical to the success path — so an attacker gains no
enumeration signal. Operator visibility via
metrics.MagicLinkEmailRateLimited counter + magic_link.start.
ip_rate_limited structured log.
Regression tests (each reproduces the original exploit and asserts the
fix blocks it):
TestAuthEmailStart_RejectsFormUrlencoded
TestAuthEmailStart_AcceptsJSONWithCharset (guardrail — legit flow)
TestAuthEmailStart_PerIPRateLimit (counter-level + handler-level)
Rule-22 surface checklist:
- api/internal/handlers/magic_link.go (handler)
- OpenAPI: handlers/openapi.go not updated
(no new public envelope — invalid_content_type follows the
existing error-code envelope shape; per-IP-limited still returns
the existing 202 success shape). Follow-up: surface
invalid_content_type in codeToAgentAction so agents get the right
"set Content-Type: application/json" prose without consulting the
spec. Same polish PR as the PR-1 reauth_required entry.
- content/llms.txt not impacted
- instanode-web pricing not impacted
- NR alert: bump ml:ip:rl rate-limit counter into the existing
magic_link.email_rate_limited alert (counter reused). Follow-up
to split into per-IP and per-email tiles for operator clarity.
Live-verify (rule 14) and curl evidence (per finding) attached in PR
body.
Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>1 parent f2fb140 commit 19d0db2
2 files changed
Lines changed: 287 additions & 0 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
| 58 | + | |
| 59 | + | |
| 60 | + | |
| 61 | + | |
| 62 | + | |
| 63 | + | |
| 64 | + | |
| 65 | + | |
| 66 | + | |
| 67 | + | |
| 68 | + | |
| 69 | + | |
| 70 | + | |
| 71 | + | |
| 72 | + | |
| 73 | + | |
| 74 | + | |
| 75 | + | |
| 76 | + | |
| 77 | + | |
| 78 | + | |
| 79 | + | |
| 80 | + | |
| 81 | + | |
| 82 | + | |
| 83 | + | |
| 84 | + | |
| 85 | + | |
| 86 | + | |
| 87 | + | |
| 88 | + | |
| 89 | + | |
| 90 | + | |
| 91 | + | |
| 92 | + | |
| 93 | + | |
| 94 | + | |
| 95 | + | |
| 96 | + | |
| 97 | + | |
| 98 | + | |
| 99 | + | |
| 100 | + | |
| 101 | + | |
| 102 | + | |
| 103 | + | |
| 104 | + | |
| 105 | + | |
| 106 | + | |
| 107 | + | |
| 108 | + | |
| 109 | + | |
| 110 | + | |
| 111 | + | |
| 112 | + | |
| 113 | + | |
| 114 | + | |
| 115 | + | |
| 116 | + | |
| 117 | + | |
| 118 | + | |
| 119 | + | |
| 120 | + | |
| 121 | + | |
| 122 | + | |
| 123 | + | |
| 124 | + | |
| 125 | + | |
| 126 | + | |
| 127 | + | |
| 128 | + | |
| 129 | + | |
| 130 | + | |
| 131 | + | |
| 132 | + | |
| 133 | + | |
| 134 | + | |
| 135 | + | |
| 136 | + | |
| 137 | + | |
| 138 | + | |
| 139 | + | |
| 140 | + | |
| 141 | + | |
| 142 | + | |
| 143 | + | |
| 144 | + | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
| 176 | + | |
| 177 | + | |
| 178 | + | |
| 179 | + | |
| 180 | + | |
| 181 | + | |
| 182 | + | |
| 183 | + | |
| 184 | + | |
| 185 | + | |
| 186 | + | |
| 187 | + | |
| 188 | + | |
| 189 | + | |
| 190 | + | |
| 191 | + | |
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
38 | 38 | | |
39 | 39 | | |
40 | 40 | | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
41 | 54 | | |
42 | 55 | | |
43 | 56 | | |
| |||
129 | 142 | | |
130 | 143 | | |
131 | 144 | | |
| 145 | + | |
| 146 | + | |
| 147 | + | |
| 148 | + | |
| 149 | + | |
| 150 | + | |
| 151 | + | |
| 152 | + | |
| 153 | + | |
| 154 | + | |
| 155 | + | |
| 156 | + | |
| 157 | + | |
| 158 | + | |
| 159 | + | |
| 160 | + | |
| 161 | + | |
| 162 | + | |
| 163 | + | |
| 164 | + | |
| 165 | + | |
| 166 | + | |
| 167 | + | |
| 168 | + | |
| 169 | + | |
| 170 | + | |
| 171 | + | |
| 172 | + | |
| 173 | + | |
| 174 | + | |
| 175 | + | |
132 | 176 | | |
133 | 177 | | |
134 | 178 | | |
| |||
155 | 199 | | |
156 | 200 | | |
157 | 201 | | |
| 202 | + | |
| 203 | + | |
| 204 | + | |
| 205 | + | |
| 206 | + | |
| 207 | + | |
| 208 | + | |
| 209 | + | |
| 210 | + | |
| 211 | + | |
| 212 | + | |
| 213 | + | |
| 214 | + | |
| 215 | + | |
| 216 | + | |
| 217 | + | |
| 218 | + | |
| 219 | + | |
| 220 | + | |
| 221 | + | |
| 222 | + | |
| 223 | + | |
| 224 | + | |
| 225 | + | |
158 | 226 | | |
159 | 227 | | |
160 | 228 | | |
| |||
178 | 246 | | |
179 | 247 | | |
180 | 248 | | |
| 249 | + | |
| 250 | + | |
| 251 | + | |
| 252 | + | |
| 253 | + | |
| 254 | + | |
| 255 | + | |
| 256 | + | |
| 257 | + | |
| 258 | + | |
| 259 | + | |
| 260 | + | |
| 261 | + | |
| 262 | + | |
| 263 | + | |
| 264 | + | |
| 265 | + | |
| 266 | + | |
| 267 | + | |
| 268 | + | |
| 269 | + | |
| 270 | + | |
| 271 | + | |
| 272 | + | |
| 273 | + | |
| 274 | + | |
| 275 | + | |
| 276 | + | |
181 | 277 | | |
182 | 278 | | |
183 | 279 | | |
| |||
0 commit comments