From 866601025d7960a36ee4260a9815e815f419ff39 Mon Sep 17 00:00:00 2001 From: Adam Moussa <166072409+amoussa1229@users.noreply.github.com> Date: Wed, 20 May 2026 18:08:55 -0400 Subject: [PATCH] Validate dev-login input: reject empty email and invalid role Empty-string email passed model binding but created a ghost user with no identity. Invalid role strings (e.g. "SuperHero") silently defaulted to Admin, granting unintended elevated access. Now returns 400 for both cases. Default role changed from Admin to Dispatcher (least privilege). --- api/src/ProposalSystem.Api/Controllers/AuthController.cs | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-) diff --git a/api/src/ProposalSystem.Api/Controllers/AuthController.cs b/api/src/ProposalSystem.Api/Controllers/AuthController.cs index 247d122..19dcf12 100644 --- a/api/src/ProposalSystem.Api/Controllers/AuthController.cs +++ b/api/src/ProposalSystem.Api/Controllers/AuthController.cs @@ -99,7 +99,13 @@ public class AuthController : ControllerBase if (string.IsNullOrEmpty(signingKey)) return StatusCode(500, new { message = "Dev signing key not configured" }); - var role = Enum.TryParse(request.Role, true, out var parsed) ? parsed : UserRole.Admin; + if (string.IsNullOrWhiteSpace(request.Email)) + return BadRequest(new { message = "Email is required" }); + + if (!string.IsNullOrEmpty(request.Role) && !Enum.TryParse(request.Role, true, out _)) + return BadRequest(new { message = $"Invalid role: '{request.Role}'. Valid roles are: Dispatcher, Admin, SysAdmin" }); + + var role = Enum.TryParse(request.Role, true, out var parsed) ? parsed : UserRole.Dispatcher; var user = await _db.Users.FirstOrDefaultAsync(u => u.Email == request.Email, ct); if (user == null)