Skip to content

fix(security): stop deploymentId enumeration via 403 vs 404 - #349

Merged
ShreeChaturvedi merged 1 commit into
mainfrom
fix/320-deployment-auth-enumeration
Aug 3, 2026
Merged

ShreeChaturvedi merged 1 commit into
mainfrom
fix/320-deployment-auth-enumeration

Conversation

@ShreeChaturvedi

Copy link
Copy Markdown
Owner

Summary

  • Bad API keys now return `404 { error: 'Not found' }`, matching missing deployments.
  • Adds unit tests covering both branches.

Fixes #320

Return the same status/body for unknown deploymentIds and invalid
x-api-key so deployment IDs cannot be enumerated via 403 vs 404.

Fixes #320
@ShreeChaturvedi
ShreeChaturvedi merged commit d1cf2d7 into main Aug 3, 2026
@ShreeChaturvedi
ShreeChaturvedi deleted the fix/320-deployment-auth-enumeration branch August 3, 2026 21:18
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Prevent deploymentId enumeration via API-key auth error differences

1 participant