mirror of
https://github.com/Kpa-clawbot/meshcore-analyzer.git
synced 2026-10-11 09:17:25 +00:00
Part A of #2128: optional, off-by-default user accounts. With the feature off nothing changes; with it on, visitors can register and log in, and admins manage users and use the operator actions without the API key. PR #2130 (settings sync) builds on this one. The two are meant to be merged together. ## The situation - Operator actions (geofilter save and prune, backup, perf reset) need the shared `apiKey`. There is no per-person right. - Nothing in CoreScope knows who a visitor is, so the requests in #2128 that need that (#1835, #2092, #1508, #730) have nothing to build on. ## What this PR adds **Two new Go modules** - `internal/users`: a separate `users.db` (SQLite through `modernc.org/sqlite`) with users, sessions, single-use tokens, an audit log and a mail log. Passwords use argon2id. - `internal/mailer`: a `Mailer` interface with a Brevo client (send, delivery events, webhook parsing) and an in-memory fake for tests. **Server (`cmd/server`)**, active only with `userManagement.enabled` - 24 routes, all documented in OpenAPI under the `users` tag ([`auth_routes.go`](https://github.com/efiten/CoreScope/blob/feat/user-management/cmd/server/auth_routes.go)): - auth: register, activate, login, logout, me, forgot, reset; - account: profile, password, email change with confirmation, sessions, self-delete; - admin: list, detail, disable, enable, delete, role, resend activation, manual activation, mail status refresh; - a Brevo webhook, registered only when `mail.webhookSecret` is set. - `requireAdmin` replaces `requireAPIKey` at the 7 operator call sites: the API key **or** an admin session. With the feature off it is the old API-key gate (`TestRequireAdminWithoutUserManagementIsAPIKeyGate`). - `/api/config/client` gets `userManagement: {enabled: true}` only when the service started; with the feature off the response is byte-identical. **Frontend** - `auth.js` (header account control, request helper that adds the CSRF header), `account.js` (login, register, activate, forgot, reset, confirm email, my account), `admin-users.js` (`#/admin/users`, deep-linked filters), `account.css` (theme tokens only). - On phones the top-bar control is hidden, so a conditional entry goes into the bottom-nav "More" sheet and the nav drawer. - The customizer geofilter tab and the Perf "Reset stats" button use the admin session when there is one. **Config.** A `userManagement` block (`config.example.json`, [`docs/user-guide/accounts.md`](https://github.com/efiten/CoreScope/blob/feat/user-management/docs/user-guide/accounts.md)). The Brevo key can come from `CORESCOPE_BREVO_API_KEY`. The server refuses to start when the block is enabled but incomplete. ## Security choices - Session cookie `cs_session`: HttpOnly, SameSite=Lax, Secure when `publicBaseUrl` is https. Every cookie-authenticated state change needs the `X-CS-CSRF` header and a matching Origin. - Activation needs the token **and** the account password. Without the password, an attacker who keeps re-registering a known address could get the owner to activate an account that carries the attacker's password. - Register, forgot and email change answer identically for known and unknown addresses. A password reset ends all sessions, a password change ends all other sessions, and both end outstanding email-change links. - Rate limits: login 10 per 15 minutes, register and forgot 5 per hour, per IP and per address. The bucket count is capped. `trustedProxies` makes the per-IP limits see real client IPs behind a proxy. - Server logs carry `#<user id>`, never addresses, tokens or passwords; mail-provider error texts are redacted before logging. ## Performance No change to an existing hot path with the feature off. With it on: - One `users.db` lookup per authenticated request (session by token hash). - The admin user table rebuilds its `tbody` on each filter change. `users.List` caps the result at 1000 rows (`internal/users/users.go`), which bounds the rebuild. - `map[string]interface{}` in `openapi.go`: 79 before, 78 after. ## Verification - `internal/users`, `internal/mailer` and `cmd/server`: `go vet` and `go test -race` pass locally. 121 new Go tests. - `cmd/server` with `-tags e2etest`: vet and the e2e hook tests pass. - `sh test-all.sh` exits 0. `tests/unit/test-user-management-ui.js`: 67 passing (vm, real modules). - `tests/e2e/test-user-management-e2e.js` (6 steps) passed locally against an `e2etest` build with the fake mailer and against a feature-off build. CI builds the `e2etest` binary and runs the suite on a second server (`deploy.yml`). - On a staging instance with a real Brevo key: register, activation mail delivered, activate, admin table, "Refresh status" showing sent, deferred, delivered, opened and clicked. ## Not in this PR - Settings sync (#2130), the admin dashboard, approval flows and notifications (parts B to E of #2128). - A `requireReadAuth` mode (#1835). Sessions from this PR are what such a mode would accept. - Binary size and build time with `modernc.org/sqlite` linked next to `mattn/go-sqlite3` were not measured. Their driver names do not collide. #1992 discusses the driver choice. - No Brevo webhook was configured on staging; delivery status there came from "Refresh status". --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
128 lines
4.0 KiB
Go
128 lines
4.0 KiB
Go
package users
|
|
|
|
import (
|
|
"errors"
|
|
"testing"
|
|
)
|
|
|
|
func mustCreate(t *testing.T, st *Store, email, name string) *User {
|
|
t.Helper()
|
|
u, err := st.CreatePending(email, name, "$argon2id$placeholder")
|
|
if err != nil {
|
|
t.Fatalf("CreatePending(%s): %v", email, err)
|
|
}
|
|
return u
|
|
}
|
|
|
|
func TestCreatePendingAndDuplicate(t *testing.T) {
|
|
st, clk := newTestStore(t)
|
|
u := mustCreate(t, st, "alice@example.org", "Alice")
|
|
if u.ID == 0 || u.Status != StatusPending || u.Role != RoleUser || !u.CreatedAt.Equal(clk.Now()) {
|
|
t.Fatalf("unexpected user: %+v", u)
|
|
}
|
|
if _, err := st.CreatePending("alice@example.org", "Other", "x"); !errors.Is(err, ErrEmailTaken) {
|
|
t.Fatalf("duplicate err = %v; want ErrEmailTaken", err)
|
|
}
|
|
got, err := st.GetByEmail("alice@example.org")
|
|
if err != nil || got.ID != u.ID {
|
|
t.Fatalf("GetByEmail = %+v, %v", got, err)
|
|
}
|
|
if _, err := st.GetByID(9999); !errors.Is(err, ErrNotFound) {
|
|
t.Fatalf("GetByID(missing) err = %v", err)
|
|
}
|
|
}
|
|
|
|
func TestActivateOnlyPending(t *testing.T) {
|
|
st, _ := newTestStore(t)
|
|
admin := mustCreate(t, st, "admin@example.org", "Admin")
|
|
u := mustCreate(t, st, "bob@example.org", "Bob")
|
|
by := admin.ID
|
|
if err := st.Activate(u.ID, RoleAdmin, &by); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got, _ := st.GetByID(u.ID)
|
|
if got.Status != StatusActive || got.Role != RoleAdmin || got.ActivatedAt == nil || got.ActivatedBy == nil || *got.ActivatedBy != admin.ID {
|
|
t.Fatalf("after Activate: %+v", got)
|
|
}
|
|
if err := st.Activate(u.ID, RoleUser, nil); !errors.Is(err, ErrNotFound) {
|
|
t.Fatalf("second Activate err = %v; want ErrNotFound", err)
|
|
}
|
|
}
|
|
|
|
func TestSettersAndEmailUniqueness(t *testing.T) {
|
|
st, clk := newTestStore(t)
|
|
a := mustCreate(t, st, "a@example.org", "Aa")
|
|
mustCreate(t, st, "b@example.org", "Bb")
|
|
if err := st.SetEmail(a.ID, "b@example.org"); !errors.Is(err, ErrEmailTaken) {
|
|
t.Fatalf("SetEmail to taken = %v", err)
|
|
}
|
|
if err := st.SetEmail(a.ID, "c@example.org"); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := st.SetDisplayName(a.ID, "New name"); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := st.SetPassword(a.ID, "newhash"); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := st.SetStatus(a.ID, StatusDisabled); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := st.SetRole(a.ID, RoleAdmin); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := st.SetEmailBouncing(a.ID, true); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
if err := st.TouchLogin(a.ID); err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
got, _ := st.GetByID(a.ID)
|
|
if got.Email != "c@example.org" || got.DisplayName != "New name" || got.PasswordHash != "newhash" ||
|
|
got.Status != StatusDisabled || got.Role != RoleAdmin || !got.EmailBouncing ||
|
|
got.LastLoginAt == nil || !got.LastLoginAt.Equal(clk.Now()) {
|
|
t.Fatalf("after setters: %+v", got)
|
|
}
|
|
if err := st.SetStatus(9999, StatusActive); !errors.Is(err, ErrNotFound) {
|
|
t.Fatalf("SetStatus(missing) = %v", err)
|
|
}
|
|
}
|
|
|
|
func TestListFiltersAndAdminCount(t *testing.T) {
|
|
st, _ := newTestStore(t)
|
|
a := mustCreate(t, st, "alice@example.org", "Alice")
|
|
b := mustCreate(t, st, "bob@example.org", "Bob_1")
|
|
mustCreate(t, st, "carol@example.org", "Carol")
|
|
st.Activate(a.ID, RoleAdmin, nil)
|
|
st.Activate(b.ID, RoleUser, nil)
|
|
|
|
all, err := st.List(ListFilter{})
|
|
if err != nil || len(all) != 3 {
|
|
t.Fatalf("List all = %d, %v", len(all), err)
|
|
}
|
|
pending, _ := st.List(ListFilter{Status: StatusPending})
|
|
if len(pending) != 1 || pending[0].Email != "carol@example.org" {
|
|
t.Fatalf("pending = %+v", pending)
|
|
}
|
|
admins, _ := st.List(ListFilter{Role: RoleAdmin})
|
|
if len(admins) != 1 || admins[0].ID != a.ID {
|
|
t.Fatalf("admins = %+v", admins)
|
|
}
|
|
q, _ := st.List(ListFilter{Query: "BOB"})
|
|
if len(q) != 1 || q[0].ID != b.ID {
|
|
t.Fatalf("query BOB = %+v", q)
|
|
}
|
|
// LIKE wildcards in the query are literal.
|
|
if w, _ := st.List(ListFilter{Query: "_"}); len(w) != 1 || w[0].ID != b.ID {
|
|
t.Fatalf("query _ = %+v", w)
|
|
}
|
|
n, err := st.CountActiveAdmins()
|
|
if err != nil || n != 1 {
|
|
t.Fatalf("CountActiveAdmins = %d, %v", n, err)
|
|
}
|
|
st.SetStatus(a.ID, StatusDisabled)
|
|
if n, _ := st.CountActiveAdmins(); n != 0 {
|
|
t.Fatalf("disabled admin still counted: %d", n)
|
|
}
|
|
}
|