M1 security: close the password backdoor, apply re-review, pin E.164

Acts on an adversarial review of the M1 auth and authorization code.
Five findings fixed; the rest recorded in SECURITY-FINDINGS.md as the
M1 exit criteria rather than left in a tool transcript.

- auth: serve /phone-number/request-password-reset, /phone-number/
  reset-password and /sign-in/phone-number as 404. better-auth's
  phoneNumber() registers all three unconditionally -- they are NOT
  gated on emailAndPassword.enabled:false. Left live they form a
  silent second credential path: request-password-reset stores an OTP
  and sends no SMS (sendPasswordResetOTP was never configured, so the
  owner is never told), reset-password mints a bcrypt credential row,
  and sign-in/phone-number then accepts it forever with no OTP. The
  OTP gate still applies, so this is not remote unauthenticated
  takeover -- it converts one momentary OTP compromise into permanent
  access the victim cannot see or rotate.

- auth: drop bearer(). It accepts the plaintext sessions.token column
  as an Authorization credential, making any single leaked row a
  replayable login. The mobile client it was added for is hypothetical.

- auth: pin E.164 via phoneNumberValidator, and add toE164/isE164 to
  @linkder/shared. phone is UNIQUE and bans are per-account, so
  "+34600111222" and "0034600111222" being separately storable meant
  one handset could hold two accounts and a ban was escapable by
  retyping. 15 tests.

- auth: NEXT_PUBLIC_APP_URL now throws in production instead of
  falling back to localhost, which was silently dropping Secure and
  the __Secure- prefix from the production session cookie.

- pro.upsertProfile: actually apply requiresReReview. It was computed,
  returned to the client and never acted on, so a verified plumber
  could become a verified electrician in another city by ignoring a
  response flag. Now demotes to pending in the same transaction and
  audits it. Trade changes count as material (they did not before) --
  the licence is per-trade. Needed a verified -> pending edge in
  VERIFICATION_GRAPH, which did not exist.

Removed two untracked scratch repro files. The impersonation repro
depended on bearer() for transport and no longer applies as written;
the underlying finding (resolveSession drops impersonatedBy, so admin
actions are audited as the victim) is open and documented.

typecheck, lint, build clean; 127 tests pass.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
serfowi
2026-08-21 01:19:32 -04:00
co-authored by Claude Opus 5
parent cebeda7f4c
commit c617bc9687
26 changed files with 2012 additions and 52 deletions
@@ -85,7 +85,7 @@ CREATE TABLE "credentials" (
"id" uuid PRIMARY KEY DEFAULT gen_random_uuid() NOT NULL,
"pro_id" uuid NOT NULL,
"kind" "credential_kind" NOT NULL,
"file_url" text NOT NULL,
"file_key" text NOT NULL,
"issuer" text,
"expires_at" timestamp with time zone,
"review_status" "review_status" DEFAULT 'pending' NOT NULL,
+3 -3
View File
@@ -1,5 +1,5 @@
{
"id": "d2669c23-7683-48e2-a271-03f7e5ddcbd1",
"id": "6b9ea99a-a893-432a-9bea-ab3e145c97a2",
"prevId": "00000000-0000-0000-0000-000000000000",
"version": "7",
"dialect": "postgresql",
@@ -580,8 +580,8 @@
"primaryKey": false,
"notNull": true
},
"file_url": {
"name": "file_url",
"file_key": {
"name": "file_key",
"type": "text",
"primaryKey": false,
"notNull": true
+2 -2
View File
@@ -5,8 +5,8 @@
{
"idx": 0,
"version": "7",
"when": 1787250714989,
"tag": "0000_colossal_masked_marvel",
"when": 1787252153406,
"tag": "0000_material_shadow_king",
"breakpoints": true
}
]
+2 -1
View File
@@ -109,7 +109,8 @@ export const credentials = pgTable(
.notNull()
.references(() => proProfiles.userId, { onDelete: 'cascade' }),
kind: credentialKind('kind').notNull(),
fileUrl: text('file_url').notNull(),
/** R2 object key. Private — resolve with a signed GET, never a public URL. */
fileKey: text('file_key').notNull(),
issuer: text('issuer'),
expiresAt: timestamp('expires_at', { withTimezone: true }),
reviewStatus: reviewStatus('review_status').notNull().default('pending'),