Conversation
Secure a route or a group where it is declared, with no firewall rules: - Authenticated@cbsecurity: the user must be logged in - Authorized@cbsecurity: logged in and satisfying the `permissions`, `roles` and `mode` (any|all|none) declared in the route `meta()` - JwtAuth@cbsecurity and BasicAuth@cbsecurity: Authorized, authenticating through the JWT or Basic validators - Guard: the base class for custom middleware Denied requests go through the firewall's invalid access flow, so redirect, override and block actions, module overrides, interception points and logging behave exactly like a firewall rule or annotation. The Security interceptor gains public validateAccess() and processInvalidAccess() methods for this; the annotation path now shares processInvalidAccess() with no behavior change. The route specs run only when the installed ColdBox can run route middleware in execute() and group meta (8.3+); the Guard specs run everywhere. Co-Authored-By: Claude <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01E8yy4oK5vnaVucmYLg4UtY
Contributor
Author
|
CI status
Generated by Claude Code |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds ready-made ColdBox route middleware so a route or a group can be secured where it is declared, without firewall rules.
Authenticated@cbsecurity: logged in (ignores meta)Authorized@cbsecurity: logged in and satisfying routemetapermissions,rolesandmode(any,all,none)JwtAuth@cbsecurity/BasicAuth@cbsecurity: likeAuthorized, through those validatorsGuard: base class for custom middlewareDenied requests go through the firewall's invalid access flow, so redirect, override and block actions, module overrides, interception points (
annotationTypeismiddleware) and logging behave like a rule or annotation.Securitygains publicvalidateAccess()andprocessInvalidAccess(), and the annotation path now sharesprocessInvalidAccess()with no behavior change. The firewall interceptor must stay loaded (autoLoadFirewall, default true), otherwise a clearcbsecurity.MiddlewareRequiresFirewallis thrown.Design note: a router file loads before modules, so
getInstance( "SomeFactory@cbsecurity" )cannot run insideRouter.configure(). That is why parameters travel in the routemeta()and not as middleware arguments.Requirements
metaand middleware insideexecute(): ColdBox 8.3+, see ColdBox/coldbox-platform PR on branchclaude/funny-mendel-eeim2l.Issues
No issue is linked yet, please link or create one.
Type of change
Checklist
cfformatapplied to my files)Testing
BoxLang 1.18, TestBox 7.1, against the companion ColdBox changes: 138 passed, 31 of them new (
MiddlewareSpec).development(8.2 behavior): the route specs skip themselves via feature detection (16 passed, 15 skipped, 0 failed), so CI on released ColdBox stays green. The harnessRouter.cfconly registers middleware routes when the router supports them, so ColdBox 7 still loads (I could not run ColdBox 7 here).format:checkstill flagsSecuritySpec.cfc, which I did not touch.🤖 Generated with Claude Code
https://claude.ai/code/session_01E8yy4oK5vnaVucmYLg4UtY
Generated by Claude Code