💂 fix: Enforce ALLOW_EMAIL_LOGIN on the Backend Login Route (#14180)

* 🔒 fix: Enforce ALLOW_EMAIL_LOGIN on Backend Login Route

ALLOW_EMAIL_LOGIN=false previously only hid the login form; POST
/api/auth/login stayed mounted and accepted valid credentials. Add a
validateEmailLogin middleware (mirroring validateRegistration /
validatePasswordReset) that rejects login with 403 when the flag is
disabled, with an ALLOW_EMAIL_LOGIN_OVERRIDE escape hatch for
intentional direct API login (each use logged with request IP).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* fix: Gate admin local login by email login flag

* fix: Move email login gate into api package

* test: Avoid mutating readonly request ip

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Danny Avila <danny@librechat.ai>
This commit is contained in:
Cha 2026-07-09 21:55:36 +08:00 committed by GitHub
parent cb5454d364
commit 73c43ded25
No known key found for this signature in database
GPG key ID: B5690EEEBB952194
12 changed files with 203 additions and 0 deletions

View file

@ -2,6 +2,7 @@ const validatePasswordReset = require('./validatePasswordReset');
const setTwoFactorTempUser = require('./setTwoFactorTempUser');
const validateRegistration = require('./validateRegistration');
const buildEndpointOption = require('./buildEndpointOption');
const validateEmailLogin = require('./validateEmailLogin');
const validateMessageReq = require('./validateMessageReq');
const { prepareMessageRequestValidation, sendValidationResponse } = require('./messageValidation');
const checkDomainAllowed = require('./checkDomainAllowed');
@ -53,4 +54,5 @@ module.exports = {
buildEndpointOption,
validateRegistration,
validatePasswordReset,
validateEmailLogin,
};

View file

@ -0,0 +1,3 @@
const { validateEmailLogin } = require('@librechat/api');
module.exports = validateEmailLogin;