fix: prevent auth bypass when token validation fails

validateToken() returns array(false, $errorMessage) when a token is
invalid or its signature fails. The token branch in auth.php assigned
$user = $ret[0] unconditionally, leaving $user as boolean false on
failure. Because isset($false) is true in PHP, the ZM_OPT_USE_AUTH gate
in index.php (!isset($user)) was skipped, allowing unauthenticated
access via any malformed ?token= value. It also permitted an
unauthenticated DoS: downstream $user->Username() on a bool fatals.

Check !$ret[0] and unset($user) on failure, mirroring the existing
validateUser branch, so $user stays undefined and the auth gate blocks
the request. The API call sites already throw UnauthorizedException on
!$user and are unaffected.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Isaac ConnorandClaude Opus 4.8 committed 2026-07-11 01:20:16 -04:00
1 parent 346a4baa82
commit 6b94903e63
1 file changed
+9 -1
+9 -1
View File
@@ -565,7 +565,15 @@ if (ZM_OPT_USE_AUTH) {
// don't know the token type. That will
// be checked later
$ret = validateToken($_REQUEST['token'], 'any');
$user = $ret[0];
if (!$ret[0]) {
// validateToken returns array(false, $errorMessage) on failure.
// Assigning false to $user would leave isset($user) true, bypassing
// the ZM_OPT_USE_AUTH gate in index.php. Unset so $user stays undefined.
ZM\Warning($ret[1]);
unset($user); // unset should be ok here because we aren't in a function
} else {
$user = $ret[0];
}
} else {
// Non token based auth - session required for $_SESSION access
if (!is_session_started()) {