Skip to content

fix or relation of sub-array - #298

Closed
TitouanT wants to merge 1 commit into
fastify:mainfrom
TitouanT:fix-or-relation-of-sub-array
Closed

TitouanT wants to merge 1 commit into
fastify:mainfrom
TitouanT:fix-or-relation-of-sub-array

Conversation

@TitouanT

@TitouanT TitouanT commented Sep 11, 2026 •

Copy link
Copy Markdown

Currently the result of an or-array is forgotten if anything comes after it.

for example, this case fails with the relation and: [[false, false], true] As a logic expression it is expressed as (false || false) && true, which is false but the authentication process accepts it.

I generated multiple tests to find more example of error cases and see if any other existed. And added it to the test cases to prevent regression.

Checklist

Currently the result of an or-array is forgotten if anything comes after
it.

for example, this case fails with the relation `and`: `[[false, false], true]`
As a logic expression it is expressed as `(false || false) && true`,
which is `false` but the authentication process accepts it.

I generated multiple tests to find more example of error cases and see
if any other existed. And added it to the test cases to prevent
regression.

Signed-off-by: TitouanT <titouan.teyssier@gmail.com>
@TitouanT

TitouanT commented Sep 11, 2026 •

Copy link
Copy Markdown
Author

Failing cases of the tests I added before the fix (shortened the output):

✖ failing tests:

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],true,true] (1.651285ms)
  AssertionError [ERR_ASSERTION]: true == false
  {
    generatedMessage: true,
    code: 'ERR_ASSERTION',
    actual: true,
    expected: false,
    operator: '==',
    diff: 'simple'
  }

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],true] (0.296815ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],[false,true]] (0.332723ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],[true,false]] (0.275936ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [true,[false,false],[true,true]] (0.330319ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],true] (0.361428ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],[false,true]] (0.359024ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],[true,false]] (0.195352ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false,false],[true,true]] (0.189361ms)
  AssertionError [ERR_ASSERTION]: true == false

test at test/logic-gate.test.js:28:5
✖ Relation and for expression [[false],true] (0.331511ms)
  AssertionError [ERR_ASSERTION]: true == false

They all fail only when the main relation is and, so the sub-array relation is or.
The expression are the following:

[true,[false,false],true,true]
[true,[false,false],true]
[true,[false,false],[false,true]]
[true,[false,false],[true,false]]
[true,[false,false],[true,true]]
[[false,false],true]
[[false,false],[false,true]]
[[false,false],[true,false]]
[[false,false],[true,true]]
[[false],true]

The test transforms a given boolean expression into a chain of auth functions that will pass if the boolean is true and fail if the boolean is false.

@TitouanT

Copy link
Copy Markdown
Author

Apparaently someone else 'found' that bug and fixed it in 5.1.1
I would still recomend to add a fuzzer even if my strategy to add test was somewhat copied into handpicked tests. This way no subtle regression would pass through for the tested authent topologies.

@TitouanT TitouanT closed this Sep 16, 2026
@mcollina

Copy link
Copy Markdown
Member

Sorry! I received a vulnerability and I published the advisory. I had sol generate the test and most of the fix. If you want to send a fuzzer PR, go ahead!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants