mirror of
https://github.com/Kpa-clawbot/meshcore-analyzer.git
synced 2026-10-07 12:01:58 +00:00
Part A of #2128: optional, off-by-default user accounts. With the feature off nothing changes; with it on, visitors can register and log in, and admins manage users and use the operator actions without the API key. PR #2130 (settings sync) builds on this one. The two are meant to be merged together. ## The situation - Operator actions (geofilter save and prune, backup, perf reset) need the shared `apiKey`. There is no per-person right. - Nothing in CoreScope knows who a visitor is, so the requests in #2128 that need that (#1835, #2092, #1508, #730) have nothing to build on. ## What this PR adds **Two new Go modules** - `internal/users`: a separate `users.db` (SQLite through `modernc.org/sqlite`) with users, sessions, single-use tokens, an audit log and a mail log. Passwords use argon2id. - `internal/mailer`: a `Mailer` interface with a Brevo client (send, delivery events, webhook parsing) and an in-memory fake for tests. **Server (`cmd/server`)**, active only with `userManagement.enabled` - 24 routes, all documented in OpenAPI under the `users` tag ([`auth_routes.go`](https://github.com/efiten/CoreScope/blob/feat/user-management/cmd/server/auth_routes.go)): - auth: register, activate, login, logout, me, forgot, reset; - account: profile, password, email change with confirmation, sessions, self-delete; - admin: list, detail, disable, enable, delete, role, resend activation, manual activation, mail status refresh; - a Brevo webhook, registered only when `mail.webhookSecret` is set. - `requireAdmin` replaces `requireAPIKey` at the 7 operator call sites: the API key **or** an admin session. With the feature off it is the old API-key gate (`TestRequireAdminWithoutUserManagementIsAPIKeyGate`). - `/api/config/client` gets `userManagement: {enabled: true}` only when the service started; with the feature off the response is byte-identical. **Frontend** - `auth.js` (header account control, request helper that adds the CSRF header), `account.js` (login, register, activate, forgot, reset, confirm email, my account), `admin-users.js` (`#/admin/users`, deep-linked filters), `account.css` (theme tokens only). - On phones the top-bar control is hidden, so a conditional entry goes into the bottom-nav "More" sheet and the nav drawer. - The customizer geofilter tab and the Perf "Reset stats" button use the admin session when there is one. **Config.** A `userManagement` block (`config.example.json`, [`docs/user-guide/accounts.md`](https://github.com/efiten/CoreScope/blob/feat/user-management/docs/user-guide/accounts.md)). The Brevo key can come from `CORESCOPE_BREVO_API_KEY`. The server refuses to start when the block is enabled but incomplete. ## Security choices - Session cookie `cs_session`: HttpOnly, SameSite=Lax, Secure when `publicBaseUrl` is https. Every cookie-authenticated state change needs the `X-CS-CSRF` header and a matching Origin. - Activation needs the token **and** the account password. Without the password, an attacker who keeps re-registering a known address could get the owner to activate an account that carries the attacker's password. - Register, forgot and email change answer identically for known and unknown addresses. A password reset ends all sessions, a password change ends all other sessions, and both end outstanding email-change links. - Rate limits: login 10 per 15 minutes, register and forgot 5 per hour, per IP and per address. The bucket count is capped. `trustedProxies` makes the per-IP limits see real client IPs behind a proxy. - Server logs carry `#<user id>`, never addresses, tokens or passwords; mail-provider error texts are redacted before logging. ## Performance No change to an existing hot path with the feature off. With it on: - One `users.db` lookup per authenticated request (session by token hash). - The admin user table rebuilds its `tbody` on each filter change. `users.List` caps the result at 1000 rows (`internal/users/users.go`), which bounds the rebuild. - `map[string]interface{}` in `openapi.go`: 79 before, 78 after. ## Verification - `internal/users`, `internal/mailer` and `cmd/server`: `go vet` and `go test -race` pass locally. 121 new Go tests. - `cmd/server` with `-tags e2etest`: vet and the e2e hook tests pass. - `sh test-all.sh` exits 0. `tests/unit/test-user-management-ui.js`: 67 passing (vm, real modules). - `tests/e2e/test-user-management-e2e.js` (6 steps) passed locally against an `e2etest` build with the fake mailer and against a feature-off build. CI builds the `e2etest` binary and runs the suite on a second server (`deploy.yml`). - On a staging instance with a real Brevo key: register, activation mail delivered, activate, admin table, "Refresh status" showing sent, deferred, delivered, opened and clicked. ## Not in this PR - Settings sync (#2130), the admin dashboard, approval flows and notifications (parts B to E of #2128). - A `requireReadAuth` mode (#1835). Sessions from this PR are what such a mode would accept. - Binary size and build time with `modernc.org/sqlite` linked next to `mattn/go-sqlite3` were not measured. Their driver names do not collide. #1992 discusses the driver choice. - No Brevo webhook was configured on staging; delivery status there came from "Refresh status". --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
163 lines
6.7 KiB
Docker
163 lines
6.7 KiB
Docker
# syntax=docker/dockerfile:1
|
|
# Build stage always runs natively on the builder's arch ($BUILDPLATFORM) and
|
|
# cross-compiles to $TARGETOS/$TARGETARCH. No QEMU for compilation.
|
|
#
|
|
# The SQLite driver is github.com/mattn/go-sqlite3, which is cgo, so the Go
|
|
# toolchain alone can no longer cross-compile this: it needs a C compiler that
|
|
# can target the other architecture. `zig cc` is that compiler. Targeting musl
|
|
# makes the result fully static (see -extldflags below), so the runtime stage
|
|
# has no libc dependency on the base image at all.
|
|
#
|
|
# BUILDPLATFORM is auto-set by buildx; default to linux/amd64 so plain
|
|
# `docker build` (without buildx) doesn't fail on an empty platform string.
|
|
ARG BUILDPLATFORM=linux/amd64
|
|
FROM --platform=$BUILDPLATFORM golang:1.27-alpine AS builder
|
|
|
|
ARG APP_VERSION=unknown
|
|
ARG GIT_COMMIT=unknown
|
|
ARG BUILD_TIME=unknown
|
|
# Provided by buildx for multi-arch builds
|
|
ARG TARGETOS
|
|
ARG TARGETARCH
|
|
|
|
# Keep these in step with the Makefile: netgo/osusergo preserve the pure-Go
|
|
# resolver and user lookup the binaries had under CGO_ENABLED=0, and
|
|
# sqlite_omit_load_extension drops the dlopen path so -static links cleanly.
|
|
ENV GO_BUILD_TAGS=netgo,osusergo,sqlite_omit_load_extension \
|
|
ZIG_GLOBAL_CACHE_DIR=/tmp/zig-cache
|
|
|
|
# Pinned zig, checksum-verified. Arch comes from `uname -m` rather than
|
|
# TARGETARCH because this stage is pinned to BUILDPLATFORM — it has to work when
|
|
# someone builds on an arm64 machine too.
|
|
ARG ZIG_VERSION=0.16.0
|
|
RUN apk add --no-cache curl xz && \
|
|
case "$(uname -m)" in \
|
|
x86_64) ZA=x86_64; ZSHA=70e49664a74374b48b51e6f3fdfbf437f6395d42509050588bd49abe52ba3d00 ;; \
|
|
aarch64) ZA=aarch64; ZSHA=ea4b09bfb22ec6f6c6ceac57ab63efb6b46e17ab08d21f69f3a48b38e1534f17 ;; \
|
|
*) echo "unsupported builder arch $(uname -m)" >&2; exit 1 ;; \
|
|
esac && \
|
|
curl -sSLo /tmp/zig.tar.xz "https://ziglang.org/download/${ZIG_VERSION}/zig-${ZA}-linux-${ZIG_VERSION}.tar.xz" && \
|
|
echo "${ZSHA} /tmp/zig.tar.xz" | sha256sum -c - && \
|
|
mkdir -p /opt/zig && tar -xJf /tmp/zig.tar.xz -C /opt/zig --strip-components=1 && \
|
|
ln -s /opt/zig/zig /usr/local/bin/zig && rm /tmp/zig.tar.xz && \
|
|
zig version
|
|
|
|
# zigcc resolves TARGETARCH to a zig target triple once, so the three build
|
|
# steps below stay readable and cannot disagree with each other.
|
|
RUN printf '%s\n' '#!/bin/sh' \
|
|
'case "$TARGETARCH" in' \
|
|
' amd64) t=x86_64-linux-musl ;;' \
|
|
' arm64) t=aarch64-linux-musl ;;' \
|
|
' *) echo "unsupported TARGETARCH=$TARGETARCH" >&2; exit 1 ;;' \
|
|
'esac' \
|
|
'exec zig cc -target "$t" "$@"' > /usr/local/bin/zigcc && chmod +x /usr/local/bin/zigcc
|
|
ENV CC=zigcc CGO_ENABLED=1
|
|
|
|
# Build server
|
|
WORKDIR /build/server
|
|
COPY cmd/server/go.mod cmd/server/go.sum ./
|
|
COPY internal/geofilter/ ../../internal/geofilter/
|
|
COPY internal/sigvalidate/ ../../internal/sigvalidate/
|
|
COPY internal/packetpath/ ../../internal/packetpath/
|
|
COPY internal/dbconfig/ ../../internal/dbconfig/
|
|
COPY internal/dbschema/ ../../internal/dbschema/
|
|
COPY internal/prunequeue/ ../../internal/prunequeue/
|
|
COPY internal/perfio/ ../../internal/perfio/
|
|
COPY internal/mbcapqueue/ ../../internal/mbcapqueue/
|
|
COPY internal/lora/ ../../internal/lora/
|
|
COPY internal/users/ ../../internal/users/
|
|
COPY internal/mailer/ ../../internal/mailer/
|
|
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/tmp/zig-cache \
|
|
go mod download
|
|
COPY cmd/server/ ./
|
|
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/tmp/zig-cache \
|
|
GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
|
|
go build -trimpath -tags ${GO_BUILD_TAGS} \
|
|
-ldflags "-s -w -extldflags '-static -Wl,-s' -X main.Version=${APP_VERSION} -X main.Commit=${GIT_COMMIT} -X main.BuildTime=${BUILD_TIME}" \
|
|
-o /corescope-server .
|
|
|
|
# Build ingestor
|
|
WORKDIR /build/ingestor
|
|
COPY cmd/ingestor/go.mod cmd/ingestor/go.sum ./
|
|
COPY internal/geofilter/ ../../internal/geofilter/
|
|
COPY internal/sigvalidate/ ../../internal/sigvalidate/
|
|
COPY internal/packetpath/ ../../internal/packetpath/
|
|
COPY internal/dbconfig/ ../../internal/dbconfig/
|
|
COPY internal/dbschema/ ../../internal/dbschema/
|
|
COPY internal/prunequeue/ ../../internal/prunequeue/
|
|
COPY internal/perfio/ ../../internal/perfio/
|
|
COPY internal/mbcapqueue/ ../../internal/mbcapqueue/
|
|
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/tmp/zig-cache \
|
|
go mod download
|
|
COPY cmd/ingestor/ ./
|
|
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/tmp/zig-cache \
|
|
GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
|
|
go build -trimpath -tags ${GO_BUILD_TAGS} \
|
|
-ldflags "-s -w -extldflags '-static -Wl,-s'" \
|
|
-o /corescope-ingestor .
|
|
|
|
# Build decrypt CLI
|
|
WORKDIR /build/decrypt
|
|
COPY cmd/decrypt/go.mod cmd/decrypt/go.sum ./
|
|
COPY internal/channel/ ../../internal/channel/
|
|
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/tmp/zig-cache \
|
|
go mod download
|
|
COPY cmd/decrypt/ ./
|
|
RUN --mount=type=cache,target=/root/.cache/go-build \
|
|
--mount=type=cache,target=/go/pkg/mod \
|
|
--mount=type=cache,target=/tmp/zig-cache \
|
|
GOOS=${TARGETOS} GOARCH=${TARGETARCH} \
|
|
go build -trimpath -tags ${GO_BUILD_TAGS} \
|
|
-ldflags "-s -w -extldflags '-static -Wl,-s' -X main.version=${APP_VERSION}" \
|
|
-o /corescope-decrypt .
|
|
|
|
# Runtime image
|
|
FROM alpine:3.20
|
|
|
|
RUN apk add --no-cache mosquitto mosquitto-clients supervisor caddy wget
|
|
|
|
WORKDIR /app
|
|
|
|
# Go binaries (statically linked; they do not use this image's libc)
|
|
COPY --from=builder /corescope-server /corescope-ingestor /corescope-decrypt /app/
|
|
|
|
# Frontend assets + config
|
|
COPY public/ ./public/
|
|
COPY config.example.json channel-rainbow.json ./
|
|
|
|
# Bake git commit SHA — manage.sh and CI write .git-commit before build
|
|
# Default to "unknown" if not provided
|
|
RUN echo "unknown" > .git-commit
|
|
|
|
# Supervisor + Mosquitto + Caddy config
|
|
COPY docker/supervisord-go.conf /etc/supervisor/conf.d/supervisord.conf
|
|
COPY docker/supervisord-go-no-mosquitto.conf /etc/supervisor/conf.d/supervisord-no-mosquitto.conf
|
|
COPY docker/supervisord-go-no-caddy.conf /etc/supervisor/conf.d/supervisord-no-caddy.conf
|
|
COPY docker/supervisord-go-no-mosquitto-no-caddy.conf /etc/supervisor/conf.d/supervisord-no-mosquitto-no-caddy.conf
|
|
COPY docker/mosquitto.conf /etc/mosquitto/mosquitto.conf
|
|
COPY docker/Caddyfile /etc/caddy/Caddyfile
|
|
|
|
# Data directory
|
|
RUN mkdir -p /app/data /var/lib/mosquitto /data/caddy && \
|
|
chown -R mosquitto:mosquitto /var/lib/mosquitto
|
|
|
|
# Entrypoint
|
|
COPY docker/entrypoint-go.sh /entrypoint.sh
|
|
RUN chmod +x /entrypoint.sh
|
|
|
|
EXPOSE 80 443 1883
|
|
|
|
VOLUME ["/app/data", "/data/caddy"]
|
|
|
|
ENTRYPOINT ["/entrypoint.sh"]
|