mirror of
https://github.com/Kpa-clawbot/meshcore-analyzer.git
synced 2026-10-11 20:17:35 +00:00
Part A of #2128: optional, off-by-default user accounts. With the feature off nothing changes; with it on, visitors can register and log in, and admins manage users and use the operator actions without the API key. PR #2130 (settings sync) builds on this one. The two are meant to be merged together. ## The situation - Operator actions (geofilter save and prune, backup, perf reset) need the shared `apiKey`. There is no per-person right. - Nothing in CoreScope knows who a visitor is, so the requests in #2128 that need that (#1835, #2092, #1508, #730) have nothing to build on. ## What this PR adds **Two new Go modules** - `internal/users`: a separate `users.db` (SQLite through `modernc.org/sqlite`) with users, sessions, single-use tokens, an audit log and a mail log. Passwords use argon2id. - `internal/mailer`: a `Mailer` interface with a Brevo client (send, delivery events, webhook parsing) and an in-memory fake for tests. **Server (`cmd/server`)**, active only with `userManagement.enabled` - 24 routes, all documented in OpenAPI under the `users` tag ([`auth_routes.go`](https://github.com/efiten/CoreScope/blob/feat/user-management/cmd/server/auth_routes.go)): - auth: register, activate, login, logout, me, forgot, reset; - account: profile, password, email change with confirmation, sessions, self-delete; - admin: list, detail, disable, enable, delete, role, resend activation, manual activation, mail status refresh; - a Brevo webhook, registered only when `mail.webhookSecret` is set. - `requireAdmin` replaces `requireAPIKey` at the 7 operator call sites: the API key **or** an admin session. With the feature off it is the old API-key gate (`TestRequireAdminWithoutUserManagementIsAPIKeyGate`). - `/api/config/client` gets `userManagement: {enabled: true}` only when the service started; with the feature off the response is byte-identical. **Frontend** - `auth.js` (header account control, request helper that adds the CSRF header), `account.js` (login, register, activate, forgot, reset, confirm email, my account), `admin-users.js` (`#/admin/users`, deep-linked filters), `account.css` (theme tokens only). - On phones the top-bar control is hidden, so a conditional entry goes into the bottom-nav "More" sheet and the nav drawer. - The customizer geofilter tab and the Perf "Reset stats" button use the admin session when there is one. **Config.** A `userManagement` block (`config.example.json`, [`docs/user-guide/accounts.md`](https://github.com/efiten/CoreScope/blob/feat/user-management/docs/user-guide/accounts.md)). The Brevo key can come from `CORESCOPE_BREVO_API_KEY`. The server refuses to start when the block is enabled but incomplete. ## Security choices - Session cookie `cs_session`: HttpOnly, SameSite=Lax, Secure when `publicBaseUrl` is https. Every cookie-authenticated state change needs the `X-CS-CSRF` header and a matching Origin. - Activation needs the token **and** the account password. Without the password, an attacker who keeps re-registering a known address could get the owner to activate an account that carries the attacker's password. - Register, forgot and email change answer identically for known and unknown addresses. A password reset ends all sessions, a password change ends all other sessions, and both end outstanding email-change links. - Rate limits: login 10 per 15 minutes, register and forgot 5 per hour, per IP and per address. The bucket count is capped. `trustedProxies` makes the per-IP limits see real client IPs behind a proxy. - Server logs carry `#<user id>`, never addresses, tokens or passwords; mail-provider error texts are redacted before logging. ## Performance No change to an existing hot path with the feature off. With it on: - One `users.db` lookup per authenticated request (session by token hash). - The admin user table rebuilds its `tbody` on each filter change. `users.List` caps the result at 1000 rows (`internal/users/users.go`), which bounds the rebuild. - `map[string]interface{}` in `openapi.go`: 79 before, 78 after. ## Verification - `internal/users`, `internal/mailer` and `cmd/server`: `go vet` and `go test -race` pass locally. 121 new Go tests. - `cmd/server` with `-tags e2etest`: vet and the e2e hook tests pass. - `sh test-all.sh` exits 0. `tests/unit/test-user-management-ui.js`: 67 passing (vm, real modules). - `tests/e2e/test-user-management-e2e.js` (6 steps) passed locally against an `e2etest` build with the fake mailer and against a feature-off build. CI builds the `e2etest` binary and runs the suite on a second server (`deploy.yml`). - On a staging instance with a real Brevo key: register, activation mail delivered, activate, admin table, "Refresh status" showing sent, deferred, delivered, opened and clicked. ## Not in this PR - Settings sync (#2130), the admin dashboard, approval flows and notifications (parts B to E of #2128). - A `requireReadAuth` mode (#1835). Sessions from this PR are what such a mode would accept. - Binary size and build time with `modernc.org/sqlite` linked next to `mattn/go-sqlite3` were not measured. Their driver names do not collide. #1992 discusses the driver choice. - No Brevo webhook was configured on staging; delivery status there came from "Refresh status". --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
138 lines
4.6 KiB
Go
138 lines
4.6 KiB
Go
package main
|
|
|
|
import (
|
|
"errors"
|
|
"fmt"
|
|
"net"
|
|
"net/url"
|
|
"path/filepath"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/meshcore-analyzer/users"
|
|
)
|
|
|
|
// UserManagementConfig is the "userManagement" block of config.json.
|
|
type UserManagementConfig struct {
|
|
Enabled bool `json:"enabled"`
|
|
DBPath string `json:"dbPath,omitempty"`
|
|
AdminEmails []string `json:"adminEmails,omitempty"`
|
|
PublicBaseURL string `json:"publicBaseUrl,omitempty"`
|
|
SessionDays int `json:"sessionDays,omitempty"`
|
|
TrustedProxies []string `json:"trustedProxies,omitempty"`
|
|
Mail UserMailConfig `json:"mail"`
|
|
}
|
|
|
|
// UserMailConfig is userManagement.mail.
|
|
type UserMailConfig struct {
|
|
Provider string `json:"provider,omitempty"`
|
|
BrevoAPIKey string `json:"brevoApiKey,omitempty"`
|
|
FromEmail string `json:"fromEmail,omitempty"`
|
|
FromName string `json:"fromName,omitempty"`
|
|
WebhookSecret string `json:"webhookSecret,omitempty"`
|
|
}
|
|
|
|
// UserManagementEnabled reports whether optional accounts are on. Nil config
|
|
// or absent section means off (the default).
|
|
func (c *Config) UserManagementEnabled() bool {
|
|
return c != nil && c.UserManagement != nil && c.UserManagement.Enabled
|
|
}
|
|
|
|
// userMgmtSettings is the validated, resolved form the auth service runs on.
|
|
type userMgmtSettings struct {
|
|
dbPath string
|
|
adminEmails map[string]bool
|
|
baseURL *url.URL // no trailing slash, no query or fragment
|
|
secureCookie bool
|
|
sessionTTL time.Duration
|
|
trustedProxies []*net.IPNet
|
|
provider string // "brevo" or (e2etest builds only) "fake"
|
|
brevoAPIKey string
|
|
fromEmail string
|
|
fromName string
|
|
webhookSecret string
|
|
}
|
|
|
|
const defaultSessionDays = 30
|
|
|
|
// fakeMailerAllowed is flipped only by the e2etest build (auth_e2e.go).
|
|
var fakeMailerAllowed bool
|
|
|
|
// resolveUserManagement validates the block and fills defaults. It refuses
|
|
// configurations where nobody could activate an account, so the server
|
|
// fails at startup instead of running half-working.
|
|
func resolveUserManagement(u *UserManagementConfig, measurementDBPath string, getenv func(string) string) (*userMgmtSettings, error) {
|
|
set := &userMgmtSettings{adminEmails: map[string]bool{}}
|
|
|
|
set.dbPath = strings.TrimSpace(u.DBPath)
|
|
if set.dbPath == "" {
|
|
set.dbPath = filepath.Join(filepath.Dir(measurementDBPath), "users.db")
|
|
}
|
|
for _, raw := range u.AdminEmails {
|
|
e, err := users.NormalizeEmail(raw)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("userManagement.adminEmails: %q is not a valid address", raw)
|
|
}
|
|
set.adminEmails[e] = true
|
|
}
|
|
|
|
base, err := url.Parse(strings.TrimSpace(u.PublicBaseURL))
|
|
if err != nil || (base.Scheme != "http" && base.Scheme != "https") || base.Host == "" {
|
|
return nil, errors.New("userManagement.publicBaseUrl must be an absolute http(s) URL, e.g. https://corescope.example.org")
|
|
}
|
|
base.Path = strings.TrimRight(base.Path, "/")
|
|
base.RawQuery, base.Fragment = "", ""
|
|
set.baseURL = base
|
|
set.secureCookie = base.Scheme == "https"
|
|
|
|
days := u.SessionDays
|
|
if days <= 0 {
|
|
days = defaultSessionDays
|
|
}
|
|
if days > 365 {
|
|
days = 365
|
|
}
|
|
set.sessionTTL = time.Duration(days) * 24 * time.Hour
|
|
set.trustedProxies = parseCIDRList(u.TrustedProxies, "userManagement.trustedProxies")
|
|
|
|
set.provider = strings.ToLower(strings.TrimSpace(u.Mail.Provider))
|
|
if set.provider == "" {
|
|
set.provider = "brevo"
|
|
}
|
|
set.brevoAPIKey = envOrValue(getenv, "CORESCOPE_BREVO_API_KEY", u.Mail.BrevoAPIKey)
|
|
set.webhookSecret = envOrValue(getenv, "CORESCOPE_BREVO_WEBHOOK_SECRET", u.Mail.WebhookSecret)
|
|
from, err := users.NormalizeEmail(u.Mail.FromEmail)
|
|
if err != nil {
|
|
return nil, errors.New("userManagement.mail.fromEmail must be a valid address")
|
|
}
|
|
set.fromEmail = from
|
|
set.fromName = strings.TrimSpace(u.Mail.FromName)
|
|
if set.fromName == "" {
|
|
set.fromName = "CoreScope"
|
|
}
|
|
|
|
switch set.provider {
|
|
case "brevo":
|
|
if set.brevoAPIKey == "" {
|
|
return nil, errors.New("userManagement.mail: a Brevo API key is required (mail.brevoApiKey or CORESCOPE_BREVO_API_KEY)")
|
|
}
|
|
case "fake":
|
|
if !fakeMailerAllowed {
|
|
return nil, errors.New(`userManagement.mail.provider "fake" is only available in e2etest builds`)
|
|
}
|
|
default:
|
|
return nil, fmt.Errorf("userManagement.mail.provider %q is not supported (use \"brevo\")", u.Mail.Provider)
|
|
}
|
|
if set.webhookSecret != "" && len(set.webhookSecret) < 16 {
|
|
return nil, errors.New("userManagement.mail.webhookSecret must be at least 16 characters")
|
|
}
|
|
return set, nil
|
|
}
|
|
|
|
func envOrValue(getenv func(string) string, key, fallback string) string {
|
|
if v := strings.TrimSpace(getenv(key)); v != "" {
|
|
return v
|
|
}
|
|
return strings.TrimSpace(fallback)
|
|
}
|