fix(chat-otp): re-check authType before minting deployment auth cookie (#5600)

PUT verify no longer trusts a stale authType at cookie-mint time — it
now re-checks the chat is still email-auth before issuing the cookie,
matching the existing POST guard and the public-file OTP route.
This commit is contained in:
Waleed
2026-07-11 14:15:07 -07:00
committed by GitHub
parent b73116226a
commit eb12333032
2 changed files with 41 additions and 0 deletions
@@ -529,6 +529,43 @@ describe('Chat OTP API Route', () => {
})
})
describe('PUT - Verify OTP (authType re-check)', () => {
beforeEach(() => {
mockGetStorageMethod.mockReturnValue('redis')
mockRedisGet.mockResolvedValue(`${mockOTP}:0`)
})
it('rejects verification when the chat has switched away from email auth', async () => {
mockDbSelect.mockImplementationOnce(() => ({
from: vi.fn().mockReturnValue({
where: vi.fn().mockReturnValue({
limit: vi.fn().mockResolvedValue([
{
id: mockChatId,
authType: 'password',
password: 'encrypted-password',
},
]),
}),
}),
}))
const request = new NextRequest('http://localhost:3000/api/chat/test/otp', {
method: 'PUT',
body: JSON.stringify({ email: mockEmail, otp: mockOTP }),
})
await PUT(request, { params: Promise.resolve({ identifier: mockIdentifier }) })
expect(mockCreateErrorResponse).toHaveBeenCalledWith(
'This chat does not use email authentication',
400
)
expect(mockRedisGet).not.toHaveBeenCalled()
expect(mockSetChatAuthCookie).not.toHaveBeenCalled()
})
})
describe('PUT - Verify OTP (Database path)', () => {
beforeEach(() => {
mockGetStorageMethod.mockReturnValue('database')
@@ -174,6 +174,10 @@ export const PUT = withRouteHandler(
const deployment = deploymentResult[0]
if (deployment.authType !== 'email') {
return createErrorResponse('This chat does not use email authentication', 400)
}
const storedValue = await getOTP('chat', deployment.id, email)
if (!storedValue) {
return createErrorResponse('No verification code found, request a new one', 400)