cms.c2sgmbh/src/lib/tenantAccess.ts
Martin Porwoll 8cb04fd130 fix: enforce mandatory tenant parameter on frontend API routes
Custom API routes at /api/posts, /api/search, and /api/search/suggestions
used payload.find() with overrideAccess:true (default) and optional tenant
filtering. Without a ?tenant= parameter, ALL data from ALL tenants was
returned — causing cross-tenant data leaks (e.g. sensualmoment.de Journal
showing blogwoman articles).

Now all three routes require a tenant parameter (400 error without it).
Also accepts where[tenant][equals] format for compatibility with
payload-contracts API clients. Removed debug logging from tenantAccess.ts.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
2026-02-27 15:22:48 +00:00

96 lines
2.8 KiB
TypeScript

// src/lib/tenantAccess.ts
import type { Access, PayloadRequest } from 'payload'
/**
* Ermittelt die Tenant-ID aus dem Request-Host.
* Gleicht die Domain mit der tenants-Collection ab.
*/
export async function getTenantIdFromHost(req: PayloadRequest): Promise<number | null> {
try {
// Host-Header extrahieren (unterstützt verschiedene Formate)
const headers = req.headers as Headers | Record<string, string | string[] | undefined>
const host =
typeof headers.get === 'function'
? headers.get('host')
: (headers as Record<string, string | string[] | undefined>)['host']
if (!host || typeof host !== 'string') {
return null
}
// Domain normalisieren: Port und www entfernen
const domain = host.split(':')[0].replace(/^www\./, '').toLowerCase().trim()
if (!domain) {
return null
}
// Tenant aus Datenbank suchen (domains ist ein Array mit domain-Subfeld)
const result = await req.payload.find({
collection: 'tenants',
where: {
'domains.domain': { equals: domain },
},
limit: 1,
depth: 0,
})
if (result.docs.length > 0 && result.docs[0]?.id) {
return Number(result.docs[0].id)
}
return null
} catch (error) {
console.error('[TenantAccess] Error resolving tenant from host:', error)
return null
}
}
/**
* Extracts tenant ID from the where[tenant][equals] query parameter.
* Used as fallback when the Host header doesn't match any tenant domain
* (e.g. when the CMS is accessed via cms.c2sgmbh.de by frontend API clients).
*/
function getTenantIdFromQuery(req: PayloadRequest): number | null {
try {
const url = req.url ? new URL(req.url, 'http://localhost') : null
const param = url?.searchParams.get('where[tenant][equals]')
if (param) {
const id = Number(param)
if (!isNaN(id) && id > 0) return id
}
return null
} catch {
return null
}
}
/**
* Access-Control für öffentlich lesbare, aber tenant-isolierte Collections.
*
* - Authentifizierte Admin-User: Voller Lesezugriff
* - Anonyme Requests: Nur Daten des eigenen Tenants
*
* Tenant resolution order:
* 1. Host header (matches tenant domain config)
* 2. where[tenant][equals] query parameter (for API clients like contracts)
*
* The returned access filter ensures tenant isolation regardless of which
* method resolved the tenant ID.
*/
export const tenantScopedPublicRead: Access = async ({ req }) => {
const hasUser = !!req.user
const hostTenantId = await getTenantIdFromHost(req)
const queryTenantId = getTenantIdFromQuery(req)
const tenantId = hostTenantId ?? queryTenantId
return hasUser ? true : tenantId ? { tenant: { equals: tenantId } } : false
}
/**
* Access-Control: Nur authentifizierte User
*/
export const authenticatedOnly: Access = ({ req }) => {
return !!req.user
}