fix(coderd): enforce required external auth on workspace create (#26314)

Required external auth (`optional = false`) was only enforced by
client-side preflight checks, so creating a workspace via the REST API
succeeded even when the owner had never authenticated, producing a
broken workspace.

`createWorkspace` now validates the workspace owner's external auth
server-side and returns 403 before any row is inserted or prebuild is
claimed. The owner (not the initiator) is checked because build-time
token injection uses their links, so this also covers admin-on-behalf-of
creates and prebuild claims. Use `optional = true` to allow
pre-provisioning for unauthenticated users.

Fixes PLAT-241.

> This PR was generated by Coder Agents on behalf of
@dylanhuff-at-coder.
This commit is contained in:
dylanhuff-at-coder
2026-06-25 15:47:35 -07:00
committed by GitHub
parent 953091c7bc
commit fde3639714
4 changed files with 335 additions and 14 deletions
+5 -2
View File
@@ -1341,7 +1341,10 @@ func TestWorkspaceDeleteSuspendedUser(t *testing.T) {
template := coderdtest.CreateTemplate(t, client, first.OrganizationID, version.ID)
workspace := coderdtest.CreateWorkspace(t, client, template.ID)
coderdtest.AwaitWorkspaceBuildJobCompleted(t, client, workspace.LatestBuild.ID)
require.Equal(t, 1, validateCalls) // Ensure the external link is working
// Ensure the external link is working. Workspace creation validates the
// owner's required external auth, and the build's token injection
// validates it again.
require.Equal(t, 2, validateCalls)
// Suspend the user
ctx := testutil.Context(t, testutil.WaitLong)
@@ -1355,7 +1358,7 @@ func TestWorkspaceDeleteSuspendedUser(t *testing.T) {
})
require.NoError(t, err)
build = coderdtest.AwaitWorkspaceBuildJobCompleted(t, owner, build.ID)
require.Equal(t, 2, validateCalls)
require.Equal(t, 3, validateCalls)
require.Equal(t, codersdk.WorkspaceStatusDeleted, build.Status)
}