mirror of
https://github.com/paperclipai/paperclip.git
synced 2026-10-07 07:23:08 +02:00
## Thinking Path > - Paperclip's company-scoped HTTP routes must reject inaccessible resources before returning resource-specific authorization results. > - The shared `getAccessibleResource` helper established that invariant, but direct tool-access routes still fetched globally unique IDs first and then returned 403 from later authorization checks. > - A signed-in user could therefore distinguish a valid foreign-company resource ID from an unknown ID. > - This change applies the existing tenant-aware lookup gate consistently across direct tool-resource routes and rejects inaccessible OAuth state before callback-specific authorization. ## Linked Issues or Issue Description - No standalone issue exists. This is a security-hardening follow-up to #3967. - **Observed:** a member of company A can submit a known application, connection, profile, profile-entry, or OAuth-state ID belonging to company B and receive a different response than for a random missing ID. - **Expected:** missing and inaccessible foreign resources are indistinguishable at the HTTP boundary. Signed-in instance administrators still require company membership for company-scoped access. - **Reproduction:** create resources in company B, authenticate as an owner of company A without B membership, and call the direct `/api/tool-*` routes using B's IDs. Before this change, affected calls returned 403 while unknown IDs returned 404. ## What Changed - Wrapped direct application, connection, profile, and profile-entry lookups in `server/src/routes/tool-access.ts` with the shared `getAccessibleResource` 404 gate. - Added tenant membership validation to OAuth callback-state lookup before session/role checks, returning the same invalid-state response as an unknown state. - Expanded route regressions across connection/profile endpoint families, including grants, usage, installs, gateway-backed test calls, OAuth, mutations, catalog/activity reads, profile entries, and instance-admin-without-membership access. - Updated application update/delete expectations from cross-tenant 403 to non-enumerating 404 responses. ## Verification After rebasing onto current `master`: - `pnpm exec vitest run src/__tests__/tool-access-service.test.ts` from `server/` — 113 passed. - `pnpm --filter @paperclipai/server typecheck` — previously passed on the same implementation; affected upstream paths were unchanged before this mechanical rebase. ## Risks - Low implementation risk: no schema, migration, or successful same-company response changes. - Intentional behavior change: inaccessible foreign tool-resource IDs now return 404 instead of 403; inaccessible OAuth states return the same 400 body as missing/expired states. - The gate reuses `getAccessibleResource` / `hasCompanyAccess` semantics established by #3967. > For core feature work, check [`ROADMAP.md`](ROADMAP.md) first and discuss it in `#dev` before opening the PR. Feature PRs that overlap with planned core work may need to be redirected — check the roadmap first. See `CONTRIBUTING.md`. ## Model Used - OpenAI Codex, exact model ID `openai-codex/gpt-5.6-sol`; repository, shell, test, TypeScript language-server, and GitHub CLI tool access enabled. ## Checklist - [x] I have included a thinking path that traces from project context to this change - [x] I have specified the model used (with version and capability details) - [x] I have checked ROADMAP.md and confirmed this PR does not duplicate planned core work - [x] I have searched GitHub for duplicate or related PRs and linked them above - [x] I have either linked an existing issue or described the issue in-PR - [x] I have not referenced internal/instance-local Paperclip issues or links - [x] My branch name describes the change and contains no internal Paperclip ticket ID - [x] I have run focused tests locally on the final rebased head and they pass - [x] I have added or updated tests where applicable - [x] Documentation update — N/A: internal authorization correction only - [x] I have considered and documented risks above - [ ] All Paperclip CI gates are green on the new rebased head - [x] Greptile's prior review was 5/5 with no open findings - [x] I will address all Greptile and reviewer comments before requesting merge Co-authored-by: Daniel Sauer <sauerdaniel@users.noreply.github.com>