Skip to content

feat(security): enforce credential ownership and retire legacy api_keys (#1050) - #1078

Merged
sbharatjoshi merged 2 commits into
mainfrom
feat/credentials-vault-ownership-and-api-key-removal
Oct 8, 2026
Merged

sbharatjoshi merged 2 commits into
mainfrom
feat/credentials-vault-ownership-and-api-key-removal

Conversation

@forgespectrayan

Copy link
Copy Markdown
Collaborator

Summary

Addresses #1050.

This PR migrates API keys to the universal credentials vault (credentials table / CredentialService / /api/v1/credentials), remediates Insecure Direct Object References (IDOR) across credential endpoints, enables user-scoped credential listing and administrative oversight, rewires inbound API key authentication to CredentialRepository.findByKeyHash(...), and completely removes the deprecated api_keys subsystem.

Key Changes

  • Flyway Migration (V10__retire_api_keys_and_add_credential_key_hash.sql):
    • Adds indexed key_hash VARCHAR(64) column to credentials table (idx_credentials_key_hash).
    • Drops legacy api_keys table.
  • Universal Credential Ownership & IDOR Remediation (CredentialController & DefaultCredentialService):
    • Updates class-level security to @PreAuthorize("isAuthenticated()").
    • Replaces unverified X-Tenant-ID header with authoritative tenant resolution from SecurityUtils.getTenantId().
    • Enforces ownership checks on mutations and reads: regular users can only access their own credentials; tenant admins can oversee their tenant's credentials; platform operators (super-admin) have fleet-wide access.
    • Unauthorized cross-user and cross-tenant access returns HTTP 403 [SPE-820-001 / SPE-SEC-001].
    • Enforces elevated scope assignment validation so tenant admins cannot assign spector:admin or super-admin roles.
  • User-Scoped Listing & Admin Oversight (GET /api/v1/credentials):
    • Regular users list only their own credentials (record.userId() == callerUserId).
    • Tenant admins list all credentials within their tenant (with optional ?userId= filter).
    • Platform operators list credentials fleet-wide (with optional ?tenantId= and ?userId= filters).
  • Inbound API Key Authentication via Universal Vault (ApiKeyAuthenticationFilter):
    • Queries CredentialRepository.findByKeyHash(sha256Hex(rawKey)) for active AUTH credentials.
    • Correctly binds user principal, authorities/scopes, and tenant context.
    • Throttles last_used_at updates via in-memory 60s coalesce throttle.
  • Complete Retirement of Legacy api_keys:
    • Removed ApiKeyStore.java.
    • Removed deprecated /api-keys endpoints from AuthController.java.
    • Removed obsolete /api/v1/auth/api-keys from docs/openapi.yaml.
    • Purged deprecated tests and updated regression suites.

Verification

  • mvn license:check: 100% compliant across all 29 modules.
  • mvn test -pl synapse/spector-synapse: 1718 tests run, 0 failures, 0 errors, 5 skipped.
  • New adversarial repository test suite (JdbcCredentialRepositoryAdversarialTest) covering hash collisions, case sensitivity, tenant isolation, and empty-string queries.
  • Updated security matrix suite (ControllerSecurityMatrixTest) covering IDOR gating and two-tier admin differentiation.

— Forge (Maintainer)

forgespectrayan and others added 2 commits October 7, 2026 22:36
… api_keys table (#1050)

- Add Flyway migration V10__retire_api_keys_and_add_credential_key_hash.sql
  adding key_hash column and index to credentials, and dropping api_keys
- Add CredentialCategory.AUTH for inbound API keys & authentication
- Support key_hash in CredentialRecord, merge-credential.sql, and find-by-key-hash.sql
- Implement findByKeyHash, findAll, and findAllByUserId in JdbcCredentialRepository
- Add comprehensive repository unit and adversarial tests

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
…ys (#1050)

- Enforce credential ownership and tenant isolation in CredentialController
  and DefaultCredentialService (IDOR remediation)
- Support user-scoped listing for regular users and administrative oversight for admins
- Authenticate inbound API keys via CredentialRepository.findByKeyHash in ApiKeyAuthenticationFilter
- Completely remove legacy api_keys table, ApiKeyStore.java, and AuthController routes
- Update OpenAPI specification to remove retired api-keys paths
- Expand test suites covering IDOR protection, two-tier admin scope validation, and inbound auth

Co-authored-by: Bharat Joshi <bharatjoshi@spectrayan.com>
Signed-off-by: Forge <forge@spectrayan.com>
@forgespectrayan
forgespectrayan requested review from a team as code owners October 8, 2026 04:01
@sbharatjoshi
sbharatjoshi merged commit 7578505 into main Oct 8, 2026
14 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants