mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
* fix(identity): 1 defect(s) (OC-0151)
* fix(ws): 1 defect(s) (OC-0152)
* fix(admin): 1 defect(s) (OC-0153)
* fix(admin): 1 defect(s) (OC-0154)
* fix(voice): 2 defect(s) (OC-0155, OC-0167)
Replace distributeRoomKey's per-call offer counter with an instance-level
sliding-window budget shared by every voice_e2ee_offer send path.
- OC-0155: back-to-back rotations (the second run immediately by
drainPendingRotationOrArmTimer) each got a fresh pacing budget, so their
combined sends could exceed the server's single per-second cap.
- OC-0167: handleAnnounceInner's drain-time offer send bypassed pacing
entirely, letting a key holder joining a large ongoing call burst every
queued announce's offer unpaced.
The shared budget is reset in clearState() since the server's limit is
scoped per (sender, channel).
* fix(client): 1 defect(s) (OC-0156)
createPresenceSender dropped a queued custom_status when a later plain
status change superseded the pending retry. The retry now carries the
last committed custom_status forward.
* fix(client): 2 defect(s) (OC-0160, OC-0163)
OC-0160: exempt the handshake frames (ready, auth_ok) from the ws message
size limit and run the guard after parsing. A 'ready' frame grows unbounded
with member/channel/DM counts and carries no seq, so dropping it left the
client on empty stores with no error and no recovery path.
OC-0163: bracket a bare IPv6 host when building the wss:// URL so the
authority parses, and collapse bracketed/bare IPv6 literals to the same
cert_store_key so one server is not pinned (and user-confirmed) twice.
* fix(voice): 1 defect(s) (OC-0162)
updatePttKey armed the Rust poller when a PTT key was bound mid-call but
never applied the gate. The poller only emits 'ptt-state' on a press/release
transition, so an idle key produced no event and the already-published mic
stayed hot until the user's first physical press+release. Mirror the join-time
gate computation in updatePttKey, guarded on being in a call, polling actually
being live, and the mic not already being gated.
* fix(client): 1 defect(s) (OC-0164)
* fix(plugin): 1 defect(s) (OC-0165)
scanPluginDirectory now skips a malformed plugin subdirectory and joins its
error instead of aborting the whole scan, and LoadAll logs-and-continues so
one bad plugin directory cannot disable every other plugin.
* fix(ws): 1 defect(s) (OC-0166)
Route PresenceSelfEvent onto the owner's normal-priority queue instead of
letting it fall through to the UserTargetedEvent high-priority case, so a
user's own presence frames all share one FIFO and cannot be delivered out
of order relative to the visible presence_update path.
* fix(db): 1 defect(s) (OC-0168)
* fix(client): 1 defect(s) (OC-0169)
* fix(client): 1 defect(s) (OC-0171)
addMessage appended a broadcast at the tail even when trailing optimistic
rows were still unreconciled, so a message that committed while our own
send was in flight ended up ordered behind the row confirmSend later
stamped with a higher server id/timestamp. Insert before the trailing
unreconciled run instead.
* fix(voice): 1 defect(s) (OC-0172)
* fix(client): 1 defect(s) (OC-0174)
* fix(ws): 1 defect(s) (OC-0175)
* fix(client): 1 defect(s) (OC-0177)
* fix(client): 1 defect(s) (OC-0178)
* fix(voice): 1 defect(s) (OC-0179)
Undeafening no longer sends a voice_mute{muted:false} the server will
refuse while a moderator-imposed mute stands, matching the localServerMuted
guard already present in onMuteToggle.
* fix(client): 1 defect(s) (OC-0182)
* fix(plugin): 1 defect(s) (OC-0183)
* fix(client): 1 defect(s) (OC-0184)
Treat a trailing underscore as an emphasis delimiter, not part of the URL,
when scanning for the end of an autolinked URL.
* fix(client): 1 defect(s) (OC-0185)
Reveal .msg-actions-bar on .message:focus-within, not only on hover, so
keyboard users can see the per-message action buttons they Tab into
instead of activating them at opacity: 0.
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): 1 defect(s) (OC-0186)
* fix(client): 1 defect(s) (OC-0187)
The Add Server modal validated addresses with its own narrower regex that
never gained IPv6 support when api.ts's validator did, so an IPv6 server
could be logged into but never saved as a profile. Extract the validator
into src/lib/hostValidation.ts and use it from both call sites.
* fix(client): 1 defect(s) (OC-0189)
DM sidebar rows dropped mention counts entirely and the header total
excluded muted conversations outright, so a direct mention in a muted DM
was invisible. Render a mention badge that outranks the plain unread
badge, and count a muted channel's mentionCount toward the header total.
* fix(client): 1 defect(s) (OC-0190)
* fix(client): 1 defect(s) (OC-0191)
* fix(client): 2 defect(s) (OC-0157, OC-0176)
* fix(client): 1 defect(s) (OC-0161)
confirmTotp answers 401 for a wrong enrollment code while the session is still valid; firing the global onUnauthorized sink signed the user out and deleted their stored credential. Opt that one call out via a skipUnauthorized flag on doFetch.
* fix(admin): 1 defect(s) (OC-0173)
* fix(identity): 1 defect(s) (OC-0180)
* fix(admin): archived channel PATCH skips voice eviction and fan-out (OC-0158)
handlePatchChannel commits the AdminUpdateChannel write, then re-reads the
channel to drive voice eviction and the visibility fan-out. When that
post-commit re-read failed, the handler returned early: the archive was
durable but connected clients were never told and voice members were never
evicted, leaving users talking in a channel that no longer exists for them.
Drive the post-commit work off the values already in hand rather than
abandoning it when the re-read fails.
Adds SetPatchChannelPostCommitHook so the test can land a cancellation in
that exact window deterministically instead of racing wall-clock timing.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(admin): role changes commit with no client ever notified (OC-0170)
broadcastRoles derived its context from the inbound *http.Request, so the
roles_update fan-out was tied to the request lifetime. A role create,
update, or delete could commit to the database and then broadcast nothing
once that request context was done, leaving every connected client on a
stale role list until the next full resync.
Decouple the fan-out from the request context so the broadcast follows the
commit rather than the caller.
Adds BroadcastRolesForTest to reach broadcastRoles from the external test
package.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): username rename stomps the profile card header (OC-0188)
The account profile card's header is a resolveDisplayName() slot, but the
username-rename save path wrote the raw username straight into it. A user
with a display name set would see the header switch from their display
name to their new username after a rename, disagreeing with every other
surface that renders the same identity.
Resolve the header through the same display-name path the initial render
uses, so a rename updates the username field without touching the header.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): settings overlay never focuses when mounted already-open (OC-0181)
mount() synced initial state — including the show() that calls
focusDialog() — before appending root to the container. .focus() on a
still-detached subtree is a silent no-op, so a caller that mounts while
uiStore.settingsOpen is already true (ConnectPage's lazy first-open path)
got a visible overlay whose focus trap never captured focus: keyboard
users landed outside the dialog with Tab escaping to the page behind it.
Attach root before syncing initial state so focusDialog() runs against a
connected subtree.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* chore: satisfy the CI gates for this fix batch
The fix batch's own commits left three CI gates red. Nothing here changes
behaviour; every edit is a lint, type, or formatting correction to code
this batch introduced.
golangci-lint:
- OC-0153 and OC-0173 replaced the last two uses of admin's setupSanitizer,
and OC-0151 the last use of api's sanitizer, leaving both package-level
bluemonday vars unused. Remove them along with the now-unused imports,
and reword the comments that named them so they still explain why the
fixpoint sanitizer is the right one without pointing at deleted symbols.
- Modernize the new handshake-deadline test's loop to range-over-int.
tsc --noEmit:
- jsdom ships no types and @types/jsdom is not a dependency, so declare the
surface the new admin-panel test uses, following src/types/jitsi-rnnoise.d.ts.
- Narrow the last-call lookup instead of indexing under
noUncheckedIndexedAccess, with an explicit failure message.
- membersStore.setState replaces whole state, so the presence-sender mocks
must supply typingUsers.
prettier: reformat the five files this batch touched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* chore(ledger): record the 2026-08-19 hunt and its fixes
Adds the 41 findings confirmed by the 2026-08-19 hunt and marks the 40
fixed on this branch, each with its commit, the test that pins it, and
revertProof "pass".
"pass" means an independent check, not the fixing agent's self-report:
every commit had its source diff reverted against the working tree, its
own test re-run and required to FAIL, then the source restored and the
test required to PASS. Commits whose tests live inline in Rust
#[cfg(test)] blocks were proven the same way at hunk level, splicing the
pre-fix source onto the post-fix test module.
OC-0159 is recorded as a duplicate of OC-0152: the flow-reconnect and
flow-message lenses independently found the same unbounded handshake
write and proposed the same helper over the same call sites.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* test(e2e): make the voice-roster join fixture self-consistent
The voice-widget join test emitted a voice_state for user_id 4 claiming
username "newvoiceuser", but id 4 is "member2" in MOCK_MEMBERS_MULTI_ROLE.
A real server never sends a voice_state whose username disagrees with the
member record for that id, and the same file's VOICE_STATE_EVENT already
pairs id 1 with "testuser" correctly — this one event was the outlier.
The contradiction was invisible while the roster rendered the payload's
raw username. OC-0177 makes it resolve identity through membersStore so a
nickname shows the same in voice as everywhere else, at which point the
fixture's own inconsistency surfaced as a failure.
Send id 4's real username and assert on it. The test still covers what it
did before — a genuine join by a user not previously in voice, asserted by
name and by roster count.
Verified against the app unchanged: with the old fixture the spec fails
1/5 (matching CI), with this one it passes 5/5.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
---------
Co-authored-by: Claude <noreply@anthropic.com>
376 lines
15 KiB
Go
376 lines
15 KiB
Go
package admin
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"errors"
|
|
"log/slog"
|
|
"net"
|
|
"net/http"
|
|
"net/url"
|
|
"strings"
|
|
"time"
|
|
|
|
"github.com/owncord/server/auth"
|
|
"github.com/owncord/server/config"
|
|
"github.com/owncord/server/db"
|
|
"github.com/owncord/server/service"
|
|
)
|
|
|
|
// ownerRoleID is the role ID assigned to the first user (Owner).
|
|
const ownerRoleID = 1
|
|
|
|
// setupStatusResponse is the JSON shape returned by GET /api/setup/status.
|
|
type setupStatusResponse struct {
|
|
NeedsSetup bool `json:"needs_setup"`
|
|
// Defaults prefills the setup wizard. Present only while setup is needed
|
|
// and the server was wired with its running config (see SetupOptions).
|
|
Defaults *setupDefaults `json:"defaults,omitempty"`
|
|
}
|
|
|
|
// setupRequest is the JSON body for POST /api/setup.
|
|
type setupRequest struct {
|
|
Username string `json:"username"`
|
|
Password string `json:"password"`
|
|
// Wizard carries the optional first-run configuration. Absent = legacy
|
|
// behaviour: create the owner account only.
|
|
Wizard *setupWizardRequest `json:"wizard,omitempty"`
|
|
}
|
|
|
|
// setupResponse is the JSON shape returned on successful setup.
|
|
type setupResponse struct {
|
|
Token string `json:"token"`
|
|
UserID int64 `json:"user_id"`
|
|
Username string `json:"username"`
|
|
InviteCode string `json:"invite_code"`
|
|
// RestartRequired is true when wizard values that are only read at
|
|
// startup differ from the running config; the server restarts itself
|
|
// right after this response is sent.
|
|
RestartRequired bool `json:"restart_required"`
|
|
// RestartURL is where the admin panel will be reachable after the
|
|
// restart (scheme/port may have changed). Empty when no restart happens.
|
|
RestartURL string `json:"restart_url,omitempty"`
|
|
// Warnings lists non-fatal problems (e.g. config.yaml not writable).
|
|
// The account exists whenever this response is returned.
|
|
Warnings []string `json:"warnings,omitempty"`
|
|
}
|
|
|
|
// handleSetupStatus returns whether initial setup is needed (no users exist).
|
|
func handleSetupStatus(database *db.DB, opts SetupOptions) http.HandlerFunc {
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
|
count, err := database.UserCount(r.Context())
|
|
if err != nil {
|
|
writeErr(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to check user count")
|
|
return
|
|
}
|
|
resp := setupStatusResponse{NeedsSetup: count == 0}
|
|
// Prefill defaults are only exposed pre-setup: after the first user
|
|
// exists this endpoint reveals nothing about the configuration.
|
|
if resp.NeedsSetup && opts.RunningCfg != nil {
|
|
cfg := opts.RunningCfg
|
|
d := &setupDefaults{
|
|
ServerName: cfg.Server.Name,
|
|
Motd: "Welcome!",
|
|
Port: cfg.Server.Port,
|
|
TLSMode: cfg.TLS.Mode,
|
|
TLSDomain: cfg.TLS.Domain,
|
|
UploadMaxSizeMB: cfg.Upload.MaxSizeMB,
|
|
VoiceQuality: cfg.Voice.Quality,
|
|
VoiceAutoDownload: cfg.Voice.AutoDownloadLiveKit,
|
|
}
|
|
// The settings table is authoritative for the values the app
|
|
// reads live; fall back to the config/seed values on error.
|
|
if v, err := database.GetSetting(r.Context(), "server_name"); err == nil && v != "" {
|
|
d.ServerName = v
|
|
}
|
|
if v, err := database.GetSetting(r.Context(), "motd"); err == nil {
|
|
d.Motd = v
|
|
}
|
|
if v, err := database.GetSetting(r.Context(), "registration_open"); err == nil {
|
|
d.RegistrationOpen = v == "1" || strings.EqualFold(v, "true")
|
|
}
|
|
resp.Defaults = d
|
|
}
|
|
writeJSON(w, http.StatusOK, resp)
|
|
}
|
|
}
|
|
|
|
// handleSetup creates the first owner account and, when the request carries
|
|
// a wizard payload, applies the chosen settings (DB + config.yaml) and
|
|
// restarts the server if startup-only values changed. It only works when no
|
|
// users exist in the database, preventing abuse after initial setup.
|
|
func handleSetup(database *db.DB, limiter *auth.RateLimiter, allowedOrigins []string, hub HubBroadcaster, opts SetupOptions) http.HandlerFunc {
|
|
return func(w http.ResponseWriter, r *http.Request) {
|
|
req, host, ok := setupPrecheck(w, r, limiter, allowedOrigins)
|
|
if !ok {
|
|
return
|
|
}
|
|
|
|
uid, token, inviteCode, ok := setupCreateOwner(w, r, database, req, host)
|
|
if !ok {
|
|
return
|
|
}
|
|
|
|
warnings, restartRequired, restartURL := setupApplyWizard(r.Context(), database, req.Wizard, uid, r.Host, opts)
|
|
|
|
slog.Info("server setup completed", "owner", req.Username, "user_id", uid, "wizard", req.Wizard != nil, "restart", restartRequired)
|
|
db.WriteAudit(context.WithoutCancel(r.Context()), database, uid, "server_setup", "server", 0,
|
|
"initial setup: owner account created, default channel and invite generated")
|
|
|
|
writeJSON(w, http.StatusCreated, setupResponse{
|
|
Token: token,
|
|
UserID: uid,
|
|
Username: req.Username,
|
|
InviteCode: inviteCode,
|
|
RestartRequired: restartRequired,
|
|
RestartURL: restartURL,
|
|
Warnings: warnings,
|
|
})
|
|
|
|
if restartRequired {
|
|
setupRestartAfterResponse(hub, opts)
|
|
}
|
|
}
|
|
}
|
|
|
|
// setupPrecheck runs every gate in front of the first-run setup endpoint —
|
|
// origin check, rate limit, body decode, credential and wizard validation —
|
|
// before any state is created. It writes the error response itself; ok=false
|
|
// means the caller must return immediately. The returned host is the
|
|
// rate-limit bucket key, reused as the session IP.
|
|
func setupPrecheck(w http.ResponseWriter, r *http.Request, limiter *auth.RateLimiter, allowedOrigins []string) (setupRequest, string, bool) {
|
|
var req setupRequest
|
|
|
|
// CSRF protection: reject cross-origin requests (BUG-097).
|
|
// A request is accepted when it is same-origin, or when its Origin is
|
|
// explicitly allowlisted. Absent Origin = non-browser client (allow).
|
|
if origin := r.Header.Get("Origin"); origin != "" {
|
|
if !isSameOrigin(origin, r.Host) && !isSetupOriginAllowed(origin, allowedOrigins) {
|
|
writeErr(w, http.StatusForbidden, "FORBIDDEN", "cross-origin setup request blocked")
|
|
return req, "", false
|
|
}
|
|
}
|
|
|
|
// Rate limit: 5 attempts per minute per IP.
|
|
// Strip the port so that different source ports from the same IP
|
|
// are correctly grouped under a single rate-limit bucket.
|
|
host, _, err := net.SplitHostPort(r.RemoteAddr)
|
|
if err != nil {
|
|
host = r.RemoteAddr
|
|
}
|
|
setupKey := "setup:" + host
|
|
if !limiter.Allow(setupKey, 5, time.Minute) {
|
|
writeErr(w, http.StatusTooManyRequests, "RATE_LIMITED", "too many setup attempts, try again later")
|
|
return req, "", false
|
|
}
|
|
|
|
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
|
writeErr(w, http.StatusBadRequest, "BAD_REQUEST", "invalid request body")
|
|
return req, "", false
|
|
}
|
|
|
|
// Use the fixpoint sanitizer (service.SanitizeText), not a bare
|
|
// bluemonday.StrictPolicy().Sanitize call: bluemonday's bare Sanitize HTML-escapes
|
|
// survivors (' -> ', & -> &, " -> "), so a name like "O'Brien"
|
|
// would be stored as "O'Brien" — different from what handleLogin
|
|
// looks up later (which only trims), permanently locking the Owner out
|
|
// of their own account. Mirrors the registration path (auth_handler.go)
|
|
// and the profile-rename path (profile_handler.go), which canonicalize
|
|
// usernames the same way. See service.SanitizeText's doc comment.
|
|
req.Username = strings.TrimSpace(service.SanitizeText(req.Username))
|
|
if req.Username == "" || req.Password == "" {
|
|
writeErr(w, http.StatusBadRequest, "BAD_REQUEST", "username and password are required")
|
|
return req, "", false
|
|
}
|
|
|
|
// Validate username format (length, no control/invisible chars).
|
|
if err := auth.ValidateUsername(req.Username); err != nil {
|
|
writeErr(w, http.StatusBadRequest, "BAD_REQUEST", err.Error())
|
|
return req, "", false
|
|
}
|
|
|
|
if err := auth.ValidatePasswordStrength(req.Password); err != nil {
|
|
writeErr(w, http.StatusBadRequest, "BAD_REQUEST", err.Error())
|
|
return req, "", false
|
|
}
|
|
|
|
// Validate the whole wizard payload BEFORE creating the account so a
|
|
// bad value rejects the request instead of leaving a half-configured
|
|
// server behind an already-created owner.
|
|
if req.Wizard != nil {
|
|
if err := validateWizard(req.Wizard); err != nil {
|
|
writeErr(w, http.StatusBadRequest, "BAD_REQUEST", err.Error())
|
|
return req, "", false
|
|
}
|
|
}
|
|
|
|
return req, host, true
|
|
}
|
|
|
|
// setupCreateOwner creates the owner account and everything that ships with
|
|
// it: the session token, the default channels and the bootstrap invite. It
|
|
// writes the error response itself; ok=false means the caller must return
|
|
// immediately.
|
|
func setupCreateOwner(w http.ResponseWriter, r *http.Request, database *db.DB, req setupRequest, host string) (int64, string, string, bool) {
|
|
// Hash the password.
|
|
hash, err := auth.HashPassword(req.Password)
|
|
if err != nil {
|
|
writeErr(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to hash password")
|
|
return 0, "", "", false
|
|
}
|
|
|
|
// Atomically check no users exist and create the owner (BUG-119).
|
|
// This closes the TOCTOU race between UserCount() and CreateUser().
|
|
uid, err := database.CreateOwnerIfEmpty(r.Context(), req.Username, hash, ownerRoleID)
|
|
if errors.Is(err, db.ErrConflict) {
|
|
writeErr(w, http.StatusForbidden, "FORBIDDEN", "setup has already been completed")
|
|
return 0, "", "", false
|
|
}
|
|
if err != nil {
|
|
writeErr(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create user")
|
|
return 0, "", "", false
|
|
}
|
|
|
|
// Issue a session token so the user is immediately logged in.
|
|
token, err := auth.GenerateToken()
|
|
if err != nil {
|
|
writeErr(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to generate session token")
|
|
return 0, "", "", false
|
|
}
|
|
|
|
device := r.Header.Get("User-Agent")
|
|
const maxDeviceLen = 512
|
|
if len(device) > maxDeviceLen {
|
|
device = device[:maxDeviceLen]
|
|
}
|
|
if _, err := database.CreateSession(r.Context(), uid, auth.HashToken(token), device, host); err != nil {
|
|
writeErr(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to create session")
|
|
return 0, "", "", false
|
|
}
|
|
|
|
// Create default channels under canonical categories.
|
|
_, _ = database.CreateChannel(r.Context(), "general", "text", "Text Channels", "Welcome to the server!", 0)
|
|
_, _ = database.CreateChannel(r.Context(), "General", "voice", "Voice Channels", "", 0)
|
|
|
|
// Generate a bootstrap invite code so the owner can invite others.
|
|
// Bound it (5 uses / 24h) rather than minting an unlimited, non-expiring
|
|
// invite — the owner can create fresh invites once logged in.
|
|
bootstrapInviteExpiry := time.Now().Add(24 * time.Hour)
|
|
inviteCode, err := database.CreateInvite(r.Context(), uid, 5, &bootstrapInviteExpiry)
|
|
if err != nil {
|
|
writeErr(w, http.StatusInternalServerError, "INTERNAL_ERROR", "failed to generate invite code")
|
|
return 0, "", "", false
|
|
}
|
|
|
|
return uid, token, inviteCode, true
|
|
}
|
|
|
|
// setupApplyWizard applies the wizard payload. wr == nil is the legacy
|
|
// request shape (create the owner account only) and applies nothing. reqHost
|
|
// is the request's Host header, from which the post-restart admin-panel URL
|
|
// is derived.
|
|
//
|
|
// The account exists from here on, so any
|
|
// failure downgrades to a warning — never a 5xx that would orphan the
|
|
// owner behind an opaque error.
|
|
func setupApplyWizard(ctx context.Context, database *db.DB, wr *setupWizardRequest, uid int64, reqHost string, opts SetupOptions) ([]string, bool, string) {
|
|
var warnings []string
|
|
restartRequired := false
|
|
restartURL := ""
|
|
if wr == nil {
|
|
return warnings, restartRequired, restartURL
|
|
}
|
|
|
|
if err := applyWizardSettings(ctx, database, wr); err != nil {
|
|
slog.Error("setup wizard: saving settings failed", "error", err)
|
|
warnings = append(warnings,
|
|
"could not save server settings: "+err.Error()+" — adjust them later in the admin panel's Settings page")
|
|
}
|
|
if opts.ConfigPath != "" {
|
|
if err := config.Save(opts.ConfigPath, buildConfigPatch(wr, opts.RunningCfg)); err != nil {
|
|
slog.Error("setup wizard: writing config failed", "path", opts.ConfigPath, "error", err)
|
|
warnings = append(warnings,
|
|
"could not write "+opts.ConfigPath+": "+err.Error()+" — your account was created; edit the file manually to apply these settings")
|
|
} else {
|
|
db.WriteAudit(context.WithoutCancel(ctx), database, uid, "config_write", "server", 0,
|
|
"setup wizard wrote "+opts.ConfigPath+" ("+patchedConfigKeys(wr)+")")
|
|
if opts.RunningCfg != nil && wizardChangesRunningConfig(wr, opts.RunningCfg) {
|
|
restartRequired = true
|
|
restartURL = computeRestartURL(reqHost, wr, opts.RunningCfg)
|
|
}
|
|
}
|
|
}
|
|
|
|
return warnings, restartRequired, restartURL
|
|
}
|
|
|
|
// setupRestartAfterResponse hands the setup-wizard restart off to main.go.
|
|
//
|
|
// Called by handleSetup only after it has written its response, so the
|
|
// browser receives the token and the reconnect URL before the process
|
|
// goes away. Mirrors handleRestoreBackup / handleApplyUpdate: broadcast,
|
|
// then request the restart in a goroutine — main.go drains the server and
|
|
// performs the handoff. tryDirectRestartPending loses only to an already
|
|
// in-flight update or restore, which will itself restart the process;
|
|
// skipping is correct then, since the caller's response is written either
|
|
// way.
|
|
func setupRestartAfterResponse(hub HubBroadcaster, opts SetupOptions) {
|
|
if !tryDirectRestartPending() {
|
|
slog.Warn("setup restart skipped: another restart-sensitive operation is already in progress")
|
|
return
|
|
}
|
|
if hub != nil {
|
|
hub.BroadcastServerRestart("setup", restartBroadcastDelaySeconds)
|
|
}
|
|
restartFn := opts.Restart
|
|
if restartFn == nil {
|
|
restartFn = requestRestart
|
|
}
|
|
go restartFn("setup_wizard")
|
|
}
|
|
|
|
// restartBroadcastDelaySeconds is the countdown clients are told before the
|
|
// setup-wizard restart. There are normally no chat clients connected during
|
|
// first-run setup, so this is informational.
|
|
const restartBroadcastDelaySeconds = 3
|
|
|
|
// isSameOrigin reports whether a browser-supplied Origin names this same
|
|
// server, by comparing its host:port against the request's Host header.
|
|
//
|
|
// Browsers send Origin on same-origin POSTs too (Chrome and Edge always,
|
|
// Firefox since 70), so the admin panel's own first-run setup call arrives
|
|
// carrying one. Without this check it is measured against allowed_origins,
|
|
// which is empty in a freshly generated config — so setup failed with
|
|
// "cross-origin setup request blocked" on every new install.
|
|
//
|
|
// Scheme is deliberately not compared. Nothing in this server derives the
|
|
// external scheme (there is no r.TLS or X-Forwarded-Proto handling anywhere),
|
|
// so a TLS-terminating proxy in front would make a scheme check reject
|
|
// legitimate requests. Matching host:port is enough: forging it requires
|
|
// already serving content on this exact host and port, at which point the
|
|
// origin is not the attacker's to borrow. Cross-site attackers cannot set
|
|
// Origin at all — the browser does.
|
|
func isSameOrigin(origin, host string) bool {
|
|
if host == "" {
|
|
return false
|
|
}
|
|
u, err := url.Parse(origin)
|
|
// Require a scheme so a schemeless "//host:port" cannot pass as same-origin.
|
|
if err != nil || u.Scheme == "" || u.Host == "" {
|
|
return false
|
|
}
|
|
return strings.EqualFold(u.Host, host)
|
|
}
|
|
|
|
// isSetupOriginAllowed checks if the given origin is permitted by the
|
|
// configured allowed_origins list. Wildcard "*" allows any origin.
|
|
// An empty list denies all cross-origin requests (safe default).
|
|
func isSetupOriginAllowed(origin string, allowed []string) bool {
|
|
for _, a := range allowed {
|
|
if a == "*" || strings.EqualFold(a, origin) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|