mirror of
https://github.com/Kpa-clawbot/meshcore-analyzer.git
synced 2026-10-11 05:17:20 +00:00
Part A of #2128: optional, off-by-default user accounts. With the feature off nothing changes; with it on, visitors can register and log in, and admins manage users and use the operator actions without the API key. PR #2130 (settings sync) builds on this one. The two are meant to be merged together. ## The situation - Operator actions (geofilter save and prune, backup, perf reset) need the shared `apiKey`. There is no per-person right. - Nothing in CoreScope knows who a visitor is, so the requests in #2128 that need that (#1835, #2092, #1508, #730) have nothing to build on. ## What this PR adds **Two new Go modules** - `internal/users`: a separate `users.db` (SQLite through `modernc.org/sqlite`) with users, sessions, single-use tokens, an audit log and a mail log. Passwords use argon2id. - `internal/mailer`: a `Mailer` interface with a Brevo client (send, delivery events, webhook parsing) and an in-memory fake for tests. **Server (`cmd/server`)**, active only with `userManagement.enabled` - 24 routes, all documented in OpenAPI under the `users` tag ([`auth_routes.go`](https://github.com/efiten/CoreScope/blob/feat/user-management/cmd/server/auth_routes.go)): - auth: register, activate, login, logout, me, forgot, reset; - account: profile, password, email change with confirmation, sessions, self-delete; - admin: list, detail, disable, enable, delete, role, resend activation, manual activation, mail status refresh; - a Brevo webhook, registered only when `mail.webhookSecret` is set. - `requireAdmin` replaces `requireAPIKey` at the 7 operator call sites: the API key **or** an admin session. With the feature off it is the old API-key gate (`TestRequireAdminWithoutUserManagementIsAPIKeyGate`). - `/api/config/client` gets `userManagement: {enabled: true}` only when the service started; with the feature off the response is byte-identical. **Frontend** - `auth.js` (header account control, request helper that adds the CSRF header), `account.js` (login, register, activate, forgot, reset, confirm email, my account), `admin-users.js` (`#/admin/users`, deep-linked filters), `account.css` (theme tokens only). - On phones the top-bar control is hidden, so a conditional entry goes into the bottom-nav "More" sheet and the nav drawer. - The customizer geofilter tab and the Perf "Reset stats" button use the admin session when there is one. **Config.** A `userManagement` block (`config.example.json`, [`docs/user-guide/accounts.md`](https://github.com/efiten/CoreScope/blob/feat/user-management/docs/user-guide/accounts.md)). The Brevo key can come from `CORESCOPE_BREVO_API_KEY`. The server refuses to start when the block is enabled but incomplete. ## Security choices - Session cookie `cs_session`: HttpOnly, SameSite=Lax, Secure when `publicBaseUrl` is https. Every cookie-authenticated state change needs the `X-CS-CSRF` header and a matching Origin. - Activation needs the token **and** the account password. Without the password, an attacker who keeps re-registering a known address could get the owner to activate an account that carries the attacker's password. - Register, forgot and email change answer identically for known and unknown addresses. A password reset ends all sessions, a password change ends all other sessions, and both end outstanding email-change links. - Rate limits: login 10 per 15 minutes, register and forgot 5 per hour, per IP and per address. The bucket count is capped. `trustedProxies` makes the per-IP limits see real client IPs behind a proxy. - Server logs carry `#<user id>`, never addresses, tokens or passwords; mail-provider error texts are redacted before logging. ## Performance No change to an existing hot path with the feature off. With it on: - One `users.db` lookup per authenticated request (session by token hash). - The admin user table rebuilds its `tbody` on each filter change. `users.List` caps the result at 1000 rows (`internal/users/users.go`), which bounds the rebuild. - `map[string]interface{}` in `openapi.go`: 79 before, 78 after. ## Verification - `internal/users`, `internal/mailer` and `cmd/server`: `go vet` and `go test -race` pass locally. 121 new Go tests. - `cmd/server` with `-tags e2etest`: vet and the e2e hook tests pass. - `sh test-all.sh` exits 0. `tests/unit/test-user-management-ui.js`: 67 passing (vm, real modules). - `tests/e2e/test-user-management-e2e.js` (6 steps) passed locally against an `e2etest` build with the fake mailer and against a feature-off build. CI builds the `e2etest` binary and runs the suite on a second server (`deploy.yml`). - On a staging instance with a real Brevo key: register, activation mail delivered, activate, admin table, "Refresh status" showing sent, deferred, delivered, opened and clicked. ## Not in this PR - Settings sync (#2130), the admin dashboard, approval flows and notifications (parts B to E of #2128). - A `requireReadAuth` mode (#1835). Sessions from this PR are what such a mode would accept. - Binary size and build time with `modernc.org/sqlite` linked next to `mattn/go-sqlite3` were not measured. Their driver names do not collide. #1992 discusses the driver choice. - No Brevo webhook was configured on staging; delivery status there came from "Refresh status". --------- Co-authored-by: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
217 lines
9.2 KiB
Go
217 lines
9.2 KiB
Go
package main
|
|
|
|
import (
|
|
"fmt"
|
|
"strings"
|
|
"testing"
|
|
|
|
"github.com/meshcore-analyzer/mailer"
|
|
"github.com/meshcore-analyzer/users"
|
|
)
|
|
|
|
// adminFixture: config admin "boss" plus regular user "uma".
|
|
func adminFixture(t *testing.T) (*authFixture, *client, *client) {
|
|
f := newAuthFixture(t, "boss@example.org")
|
|
return f, f.registerAndActivate(t, "boss@example.org", "Boss", pw), f.registerAndActivate(t, "uma@example.org", "Uma", pw)
|
|
}
|
|
|
|
func userPath(id int64, suffix string) string {
|
|
return fmt.Sprintf("/api/admin/users/%d%s", id, suffix)
|
|
}
|
|
|
|
func TestAdminUsersRequiresAdmin(t *testing.T) {
|
|
f, _, uma := adminFixture(t)
|
|
expectStatus(t, f.do("GET", "/api/admin/users", nil), 401)
|
|
expectStatus(t, f.do("GET", "/api/admin/users", nil, as(uma)), 403)
|
|
}
|
|
|
|
func TestAdminListAndDetail(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
f.do("POST", "/api/auth/register", registerRequest{Email: "pending@example.org", DisplayName: "Pen", Password: pw})
|
|
w := f.do("GET", "/api/admin/users?status=pending", nil, as(boss))
|
|
expectStatus(t, w, 200)
|
|
rows := decode[[]adminUserJSON](t, w)
|
|
if len(rows) != 1 || rows[0].Email != "pending@example.org" || rows[0].LastMail == nil || rows[0].LastMail.Purpose != "activate" {
|
|
t.Fatalf("pending rows = %+v", rows)
|
|
}
|
|
expectStatus(t, f.do("GET", "/api/admin/users?status=bogus", nil, as(boss)), 400)
|
|
w = f.do("GET", userPath(uma.me.ID, ""), nil, as(boss))
|
|
expectStatus(t, w, 200)
|
|
d := decode[adminUserDetailJSON](t, w)
|
|
if d.User.Email != "uma@example.org" || len(d.Sessions) != 1 || len(d.Mail) != 1 || len(d.Audit) == 0 {
|
|
t.Fatalf("detail = %+v", d)
|
|
}
|
|
all := decode[[]adminUserJSON](t, f.do("GET", "/api/admin/users", nil, as(boss)))
|
|
for _, r := range all {
|
|
if r.Email == "boss@example.org" && !r.ConfigAdmin {
|
|
t.Fatal("config admin not marked")
|
|
}
|
|
}
|
|
}
|
|
|
|
func TestAdminDisableEnable(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/disable"), nil, as(boss)), 200)
|
|
expectStatus(t, f.do("GET", "/api/auth/me", nil, as(uma)), 401)
|
|
expectStatus(t, f.do("POST", "/api/auth/login", loginRequest{Email: "uma@example.org", Password: pw}), 401)
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/disable"), nil, as(boss)), 409)
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/enable"), nil, as(boss)), 200)
|
|
f.login(t, "uma@example.org", pw)
|
|
}
|
|
|
|
func TestAdminGuards(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
expectStatus(t, f.do("POST", userPath(boss.me.ID, "/disable"), nil, as(boss)), 409) // self
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/role"), roleRequest{Role: users.RoleAdmin}, as(boss)), 200)
|
|
umaAdmin := f.login(t, "uma@example.org", pw)
|
|
expectStatus(t, f.do("POST", userPath(boss.me.ID, "/disable"), nil, as(umaAdmin)), 409) // config admin
|
|
expectStatus(t, f.do("DELETE", userPath(boss.me.ID, ""), nil, as(umaAdmin)), 409) // config admin
|
|
expectStatus(t, f.do("POST", userPath(boss.me.ID, "/role"), roleRequest{Role: users.RoleUser}, as(umaAdmin)), 409) // config admin
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/role"), roleRequest{Role: "root"}, as(boss)), 400)
|
|
// uma may demote herself: boss remains.
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/role"), roleRequest{Role: users.RoleUser}, as(umaAdmin)), 200)
|
|
}
|
|
|
|
func TestAdminLastAdminCannotDemoteSelf(t *testing.T) {
|
|
f := newAuthFixture(t)
|
|
solo := f.registerAndActivate(t, "solo@example.org", "Solo", pw)
|
|
f.st.SetRole(solo.me.ID, users.RoleAdmin) // UI-promoted, not a config admin
|
|
expectStatus(t, f.do("POST", userPath(solo.me.ID, "/role"), roleRequest{Role: users.RoleUser}, as(solo)), 409)
|
|
}
|
|
|
|
func TestAdminManualActivate(t *testing.T) {
|
|
f, boss, _ := adminFixture(t)
|
|
f.do("POST", "/api/auth/register", registerRequest{Email: "late@example.org", DisplayName: "Late", Password: pw})
|
|
link := f.lastToken(t)
|
|
late, _ := f.st.GetByEmail("late@example.org")
|
|
expectStatus(t, f.do("POST", userPath(late.ID, "/activate"), nil, as(boss)), 200)
|
|
got, _ := f.st.GetByID(late.ID)
|
|
if got.Status != users.StatusActive || got.ActivatedBy == nil || *got.ActivatedBy != boss.me.ID {
|
|
t.Fatalf("after manual activate: %+v", got)
|
|
}
|
|
expectStatus(t, f.do("POST", "/api/auth/activate", activateRequest{Token: link, Password: pw}), 410)
|
|
expectStatus(t, f.do("POST", userPath(late.ID, "/activate"), nil, as(boss)), 409)
|
|
if !hasAudit(t, f, late.ID, "user.activate.manual") {
|
|
t.Fatal("no user.activate.manual audit row")
|
|
}
|
|
f.login(t, "late@example.org", pw)
|
|
}
|
|
|
|
func TestAdminResendActivation(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
f.do("POST", "/api/auth/register", registerRequest{Email: "re@example.org", DisplayName: "Re", Password: pw})
|
|
old := f.lastToken(t)
|
|
re, _ := f.st.GetByEmail("re@example.org")
|
|
expectStatus(t, f.do("POST", userPath(re.ID, "/resend-activation"), nil, as(boss)), 200)
|
|
fresh := f.lastToken(t)
|
|
if fresh == old {
|
|
t.Fatal("no new link sent")
|
|
}
|
|
expectStatus(t, f.do("POST", "/api/auth/activate", activateRequest{Token: old, Password: pw}), 410)
|
|
expectStatus(t, f.do("POST", "/api/auth/activate", activateRequest{Token: fresh, Password: pw}), 200)
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/resend-activation"), nil, as(boss)), 409)
|
|
}
|
|
|
|
func TestAdminDelete(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
expectStatus(t, f.do("DELETE", userPath(uma.me.ID, ""), nil, as(boss)), 200)
|
|
expectStatus(t, f.do("GET", userPath(uma.me.ID, ""), nil, as(boss)), 404)
|
|
}
|
|
|
|
func TestAdminMailRefresh(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
mails, _ := f.st.MailForUser(uma.me.ID, 10)
|
|
m := mails[0]
|
|
f.fake.SetEvents(m.ProviderMessageID, []mailer.Event{
|
|
{MessageID: m.ProviderMessageID, Event: mailer.EventHardBounce, Reason: "user unknown", At: m.SentAt.Add(60e9)},
|
|
})
|
|
w := f.do("POST", userPath(uma.me.ID, fmt.Sprintf("/mail/%d/refresh", m.ID)), nil, as(boss))
|
|
expectStatus(t, w, 200)
|
|
if got := decode[mailJSON](t, w); got.LastEvent != mailer.EventHardBounce || got.LastReason != "user unknown" {
|
|
t.Fatalf("refreshed = %+v", got)
|
|
}
|
|
if !hasAudit(t, f, uma.me.ID, "user.mail.refresh") {
|
|
t.Fatal("no user.mail.refresh audit row")
|
|
}
|
|
if u, _ := f.st.GetByID(uma.me.ID); !u.EmailBouncing {
|
|
t.Fatal("hard bounce did not flag the address")
|
|
}
|
|
expectStatus(t, f.do("POST", userPath(boss.me.ID, fmt.Sprintf("/mail/%d/refresh", m.ID)), nil, as(boss)), 404) // wrong owner
|
|
}
|
|
|
|
func hasAudit(t *testing.T, f *authFixture, userID int64, action string) bool {
|
|
t.Helper()
|
|
entries, err := f.st.AuditFor(userID, 50)
|
|
if err != nil {
|
|
t.Fatal(err)
|
|
}
|
|
for _, e := range entries {
|
|
if e.Action == action {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
// A pending row squatting on a config-admin address is not an admin yet and
|
|
// stays deletable.
|
|
func TestAdminDeletePendingSquatterOnConfigAddress(t *testing.T) {
|
|
f, boss, _ := adminFixture(t)
|
|
f.do("POST", "/api/auth/register", registerRequest{Email: "squat@example.org", DisplayName: "Sq", Password: pw})
|
|
f.srv.auth.set.adminEmails["squat@example.org"] = true
|
|
sq, _ := f.st.GetByEmail("squat@example.org")
|
|
expectStatus(t, f.do("DELETE", userPath(sq.ID, ""), nil, as(boss)), 200)
|
|
if _, err := f.st.GetByID(sq.ID); err == nil {
|
|
t.Fatal("pending squatter still present")
|
|
}
|
|
}
|
|
|
|
func TestAdminUnknownAndBadID(t *testing.T) {
|
|
f, boss, _ := adminFixture(t)
|
|
expectStatus(t, f.do("POST", userPath(9999, "/disable"), nil, as(boss)), 404)
|
|
expectStatus(t, f.do("GET", "/api/admin/users/abc", nil, as(boss)), 400)
|
|
}
|
|
|
|
// A pending account must go through activation; disable then enable must not
|
|
// be a way around it.
|
|
func TestAdminCannotDisablePending(t *testing.T) {
|
|
f, boss, _ := adminFixture(t)
|
|
f.do("POST", "/api/auth/register", registerRequest{Email: "pend@example.org", DisplayName: "Pe", Password: pw})
|
|
p, _ := f.st.GetByEmail("pend@example.org")
|
|
expectStatus(t, f.do("POST", userPath(p.ID, "/disable"), nil, as(boss)), 409)
|
|
got, _ := f.st.GetByID(p.ID)
|
|
if got.Status != users.StatusPending {
|
|
t.Fatalf("status = %s, want pending", got.Status)
|
|
}
|
|
expectStatus(t, f.do("POST", userPath(p.ID, "/enable"), nil, as(boss)), 409)
|
|
}
|
|
|
|
func TestAdminDisableKillsPendingLinks(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
confirm, reset := pendingLinks(t, f, uma, "uma@example.org", "attacker@example.org")
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/disable"), nil, as(boss)), 200)
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/enable"), nil, as(boss)), 200)
|
|
expectStatus(t, f.do("POST", "/api/account/confirm-email", tokenRequest{Token: confirm}), 410)
|
|
expectStatus(t, f.do("POST", "/api/auth/reset", resetRequest{Token: reset, Password: "another new secret"}), 410)
|
|
}
|
|
|
|
func TestAdminDisableTokenStoreFailureIs500(t *testing.T) {
|
|
f, boss, uma := adminFixture(t)
|
|
f.breakTable(t, "tokens")
|
|
expectStatus(t, f.do("POST", userPath(uma.me.ID, "/disable"), nil, as(boss)), 500)
|
|
}
|
|
|
|
func TestAdminRoleChangeOnPendingIs409(t *testing.T) {
|
|
f, boss, _ := adminFixture(t)
|
|
f.do("POST", "/api/auth/register", registerRequest{Email: "pend@example.org", DisplayName: "Pend", Password: pw})
|
|
p, _ := f.st.GetByEmail("pend@example.org")
|
|
w := f.do("POST", userPath(p.ID, "/role"), roleRequest{Role: users.RoleAdmin}, as(boss))
|
|
expectStatus(t, w, 409)
|
|
if !strings.Contains(w.Body.String(), "activate the account first") {
|
|
t.Fatalf("body = %s", w.Body.String())
|
|
}
|
|
if got, _ := f.st.GetByID(p.ID); got.Role != users.RoleUser {
|
|
t.Fatalf("role changed on a pending user: %+v", got)
|
|
}
|
|
}
|