Problem
At device registration the API does not check that the identity token belongs to the session's account. The identity token is a 300-second bearer that the API accepts more than once. Someone with a full session on their own account and another member's leaked identity token can claim that member's subject first. From then on, the one-subject-one-account rule refuses the member's own device registrations, and the member's new devices post their approval requests to the wrong account.
No key is disclosed: a factor for another account's key cannot open the member's account. The effect is a denial of device approval for the member until an operator intervenes.
Found during the ADR audit (ADR 0039 draft, residual E3 extension).
Fix
Registration binds the identity token to the session: the API refuses a token whose subject does not belong to the caller's account, or the token is made single-use and account-bound at issue.
Acceptance
- A registration with an identity token issued for another account is refused with a named check, and nothing is written.
- A replayed identity token is refused after its first use.
- Gate: the API gate and the contract suite block the merge.
Files
apps/api/src/auth/ device registration and identity token issue
Depends on
Part of #1262.
Problem
At device registration the API does not check that the identity token belongs to the session's account. The identity token is a 300-second bearer that the API accepts more than once. Someone with a full session on their own account and another member's leaked identity token can claim that member's subject first. From then on, the one-subject-one-account rule refuses the member's own device registrations, and the member's new devices post their approval requests to the wrong account.
No key is disclosed: a factor for another account's key cannot open the member's account. The effect is a denial of device approval for the member until an operator intervenes.
Found during the ADR audit (ADR 0039 draft, residual E3 extension).
Fix
Registration binds the identity token to the session: the API refuses a token whose subject does not belong to the caller's account, or the token is made single-use and account-bound at issue.
Acceptance
Files
apps/api/src/auth/device registration and identity token issueDepends on
Part of #1262.