From 6b94903e634fdb46cb71a48eadccf1aa14f0c2bb Mon Sep 17 00:00:00 2001 From: Isaac Connor Date: Sat, 11 Jul 2026 01:19:02 -0400 Subject: [PATCH] fix: prevent auth bypass when token validation fails validateToken() returns array(false, $errorMessage) when a token is invalid or its signature fails. The token branch in auth.php assigned $user = $ret[0] unconditionally, leaving $user as boolean false on failure. Because isset($false) is true in PHP, the ZM_OPT_USE_AUTH gate in index.php (!isset($user)) was skipped, allowing unauthenticated access via any malformed ?token= value. It also permitted an unauthenticated DoS: downstream $user->Username() on a bool fatals. Check !$ret[0] and unset($user) on failure, mirroring the existing validateUser branch, so $user stays undefined and the auth gate blocks the request. The API call sites already throw UnauthorizedException on !$user and are unaffected. Co-Authored-By: Claude Opus 4.8 (1M context) --- web/includes/auth.php | 10 +++++++++- 1 file changed, 9 insertions(+), 1 deletion(-) diff --git a/web/includes/auth.php b/web/includes/auth.php index 3a168794c..bbce5e61e 100644 --- a/web/includes/auth.php +++ b/web/includes/auth.php @@ -565,7 +565,15 @@ if (ZM_OPT_USE_AUTH) { // don't know the token type. That will // be checked later $ret = validateToken($_REQUEST['token'], 'any'); - $user = $ret[0]; + if (!$ret[0]) { + // validateToken returns array(false, $errorMessage) on failure. + // Assigning false to $user would leave isset($user) true, bypassing + // the ZM_OPT_USE_AUTH gate in index.php. Unset so $user stays undefined. + ZM\Warning($ret[1]); + unset($user); // unset should be ok here because we aren't in a function + } else { + $user = $ret[0]; + } } else { // Non token based auth - session required for $_SESSION access if (!is_session_started()) {