mirror of
https://github.com/J3vb/OwnCord.git
synced 2026-09-03 03:50:00 +03:00
* fix(identity): 1 defect(s) (OC-0151)
* fix(ws): 1 defect(s) (OC-0152)
* fix(admin): 1 defect(s) (OC-0153)
* fix(admin): 1 defect(s) (OC-0154)
* fix(voice): 2 defect(s) (OC-0155, OC-0167)
Replace distributeRoomKey's per-call offer counter with an instance-level
sliding-window budget shared by every voice_e2ee_offer send path.
- OC-0155: back-to-back rotations (the second run immediately by
drainPendingRotationOrArmTimer) each got a fresh pacing budget, so their
combined sends could exceed the server's single per-second cap.
- OC-0167: handleAnnounceInner's drain-time offer send bypassed pacing
entirely, letting a key holder joining a large ongoing call burst every
queued announce's offer unpaced.
The shared budget is reset in clearState() since the server's limit is
scoped per (sender, channel).
* fix(client): 1 defect(s) (OC-0156)
createPresenceSender dropped a queued custom_status when a later plain
status change superseded the pending retry. The retry now carries the
last committed custom_status forward.
* fix(client): 2 defect(s) (OC-0160, OC-0163)
OC-0160: exempt the handshake frames (ready, auth_ok) from the ws message
size limit and run the guard after parsing. A 'ready' frame grows unbounded
with member/channel/DM counts and carries no seq, so dropping it left the
client on empty stores with no error and no recovery path.
OC-0163: bracket a bare IPv6 host when building the wss:// URL so the
authority parses, and collapse bracketed/bare IPv6 literals to the same
cert_store_key so one server is not pinned (and user-confirmed) twice.
* fix(voice): 1 defect(s) (OC-0162)
updatePttKey armed the Rust poller when a PTT key was bound mid-call but
never applied the gate. The poller only emits 'ptt-state' on a press/release
transition, so an idle key produced no event and the already-published mic
stayed hot until the user's first physical press+release. Mirror the join-time
gate computation in updatePttKey, guarded on being in a call, polling actually
being live, and the mic not already being gated.
* fix(client): 1 defect(s) (OC-0164)
* fix(plugin): 1 defect(s) (OC-0165)
scanPluginDirectory now skips a malformed plugin subdirectory and joins its
error instead of aborting the whole scan, and LoadAll logs-and-continues so
one bad plugin directory cannot disable every other plugin.
* fix(ws): 1 defect(s) (OC-0166)
Route PresenceSelfEvent onto the owner's normal-priority queue instead of
letting it fall through to the UserTargetedEvent high-priority case, so a
user's own presence frames all share one FIFO and cannot be delivered out
of order relative to the visible presence_update path.
* fix(db): 1 defect(s) (OC-0168)
* fix(client): 1 defect(s) (OC-0169)
* fix(client): 1 defect(s) (OC-0171)
addMessage appended a broadcast at the tail even when trailing optimistic
rows were still unreconciled, so a message that committed while our own
send was in flight ended up ordered behind the row confirmSend later
stamped with a higher server id/timestamp. Insert before the trailing
unreconciled run instead.
* fix(voice): 1 defect(s) (OC-0172)
* fix(client): 1 defect(s) (OC-0174)
* fix(ws): 1 defect(s) (OC-0175)
* fix(client): 1 defect(s) (OC-0177)
* fix(client): 1 defect(s) (OC-0178)
* fix(voice): 1 defect(s) (OC-0179)
Undeafening no longer sends a voice_mute{muted:false} the server will
refuse while a moderator-imposed mute stands, matching the localServerMuted
guard already present in onMuteToggle.
* fix(client): 1 defect(s) (OC-0182)
* fix(plugin): 1 defect(s) (OC-0183)
* fix(client): 1 defect(s) (OC-0184)
Treat a trailing underscore as an emphasis delimiter, not part of the URL,
when scanning for the end of an autolinked URL.
* fix(client): 1 defect(s) (OC-0185)
Reveal .msg-actions-bar on .message:focus-within, not only on hover, so
keyboard users can see the per-message action buttons they Tab into
instead of activating them at opacity: 0.
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): 1 defect(s) (OC-0186)
* fix(client): 1 defect(s) (OC-0187)
The Add Server modal validated addresses with its own narrower regex that
never gained IPv6 support when api.ts's validator did, so an IPv6 server
could be logged into but never saved as a profile. Extract the validator
into src/lib/hostValidation.ts and use it from both call sites.
* fix(client): 1 defect(s) (OC-0189)
DM sidebar rows dropped mention counts entirely and the header total
excluded muted conversations outright, so a direct mention in a muted DM
was invisible. Render a mention badge that outranks the plain unread
badge, and count a muted channel's mentionCount toward the header total.
* fix(client): 1 defect(s) (OC-0190)
* fix(client): 1 defect(s) (OC-0191)
* fix(client): 2 defect(s) (OC-0157, OC-0176)
* fix(client): 1 defect(s) (OC-0161)
confirmTotp answers 401 for a wrong enrollment code while the session is still valid; firing the global onUnauthorized sink signed the user out and deleted their stored credential. Opt that one call out via a skipUnauthorized flag on doFetch.
* fix(admin): 1 defect(s) (OC-0173)
* fix(identity): 1 defect(s) (OC-0180)
* fix(admin): archived channel PATCH skips voice eviction and fan-out (OC-0158)
handlePatchChannel commits the AdminUpdateChannel write, then re-reads the
channel to drive voice eviction and the visibility fan-out. When that
post-commit re-read failed, the handler returned early: the archive was
durable but connected clients were never told and voice members were never
evicted, leaving users talking in a channel that no longer exists for them.
Drive the post-commit work off the values already in hand rather than
abandoning it when the re-read fails.
Adds SetPatchChannelPostCommitHook so the test can land a cancellation in
that exact window deterministically instead of racing wall-clock timing.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(admin): role changes commit with no client ever notified (OC-0170)
broadcastRoles derived its context from the inbound *http.Request, so the
roles_update fan-out was tied to the request lifetime. A role create,
update, or delete could commit to the database and then broadcast nothing
once that request context was done, leaving every connected client on a
stale role list until the next full resync.
Decouple the fan-out from the request context so the broadcast follows the
commit rather than the caller.
Adds BroadcastRolesForTest to reach broadcastRoles from the external test
package.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): username rename stomps the profile card header (OC-0188)
The account profile card's header is a resolveDisplayName() slot, but the
username-rename save path wrote the raw username straight into it. A user
with a display name set would see the header switch from their display
name to their new username after a rename, disagreeing with every other
surface that renders the same identity.
Resolve the header through the same display-name path the initial render
uses, so a rename updates the username field without touching the header.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* fix(client): settings overlay never focuses when mounted already-open (OC-0181)
mount() synced initial state — including the show() that calls
focusDialog() — before appending root to the container. .focus() on a
still-detached subtree is a silent no-op, so a caller that mounts while
uiStore.settingsOpen is already true (ConnectPage's lazy first-open path)
got a visible overlay whose focus trap never captured focus: keyboard
users landed outside the dialog with Tab escaping to the page behind it.
Attach root before syncing initial state so focusDialog() runs against a
connected subtree.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* chore: satisfy the CI gates for this fix batch
The fix batch's own commits left three CI gates red. Nothing here changes
behaviour; every edit is a lint, type, or formatting correction to code
this batch introduced.
golangci-lint:
- OC-0153 and OC-0173 replaced the last two uses of admin's setupSanitizer,
and OC-0151 the last use of api's sanitizer, leaving both package-level
bluemonday vars unused. Remove them along with the now-unused imports,
and reword the comments that named them so they still explain why the
fixpoint sanitizer is the right one without pointing at deleted symbols.
- Modernize the new handshake-deadline test's loop to range-over-int.
tsc --noEmit:
- jsdom ships no types and @types/jsdom is not a dependency, so declare the
surface the new admin-panel test uses, following src/types/jitsi-rnnoise.d.ts.
- Narrow the last-call lookup instead of indexing under
noUncheckedIndexedAccess, with an explicit failure message.
- membersStore.setState replaces whole state, so the presence-sender mocks
must supply typingUsers.
prettier: reformat the five files this batch touched.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* chore(ledger): record the 2026-08-19 hunt and its fixes
Adds the 41 findings confirmed by the 2026-08-19 hunt and marks the 40
fixed on this branch, each with its commit, the test that pins it, and
revertProof "pass".
"pass" means an independent check, not the fixing agent's self-report:
every commit had its source diff reverted against the working tree, its
own test re-run and required to FAIL, then the source restored and the
test required to PASS. Commits whose tests live inline in Rust
#[cfg(test)] blocks were proven the same way at hunk level, splicing the
pre-fix source onto the post-fix test module.
OC-0159 is recorded as a duplicate of OC-0152: the flow-reconnect and
flow-message lenses independently found the same unbounded handshake
write and proposed the same helper over the same call sites.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
* test(e2e): make the voice-roster join fixture self-consistent
The voice-widget join test emitted a voice_state for user_id 4 claiming
username "newvoiceuser", but id 4 is "member2" in MOCK_MEMBERS_MULTI_ROLE.
A real server never sends a voice_state whose username disagrees with the
member record for that id, and the same file's VOICE_STATE_EVENT already
pairs id 1 with "testuser" correctly — this one event was the outlier.
The contradiction was invisible while the roster rendered the payload's
raw username. OC-0177 makes it resolve identity through membersStore so a
nickname shows the same in voice as everywhere else, at which point the
fixture's own inconsistency surfaced as a failure.
Send id 4's real username and assert on it. The test still covers what it
did before — a genuine join by a user not previously in voice, asserted by
name and by roster count.
Verified against the app unchanged: with the old fixture the spec fails
1/5 (matching CI), with this one it passes 5/5.
Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01M6gVN2JM5wrduhkNaFCxdK
---------
Co-authored-by: Claude <noreply@anthropic.com>
787 lines
28 KiB
Go
787 lines
28 KiB
Go
package api
|
||
|
||
import (
|
||
"context"
|
||
"encoding/json"
|
||
"errors"
|
||
"fmt"
|
||
"log/slog"
|
||
"net/http"
|
||
"strings"
|
||
"time"
|
||
"unicode/utf8"
|
||
|
||
"github.com/go-chi/chi/v5"
|
||
"github.com/owncord/server/auth"
|
||
"github.com/owncord/server/db"
|
||
"github.com/owncord/server/permissions"
|
||
"github.com/owncord/server/service"
|
||
)
|
||
|
||
// maxLoginUsernameLen bounds the username accepted by handleLogin, mirroring
|
||
// auth.ValidateUsername's 32-rune cap on registered usernames. Enforced
|
||
// before the value is ever used to build a RateLimiter map key — see the
|
||
// check in handleLogin for why.
|
||
const maxLoginUsernameLen = 32
|
||
|
||
// genericAuthError is returned for all login/register failures to avoid
|
||
// revealing whether a username exists.
|
||
var genericAuthError = errorResponse{
|
||
Error: "INVALID_CREDENTIALS",
|
||
Message: "invalid invite or credentials",
|
||
}
|
||
|
||
// registerRequest is the JSON body for POST /api/v1/auth/register.
|
||
type registerRequest struct {
|
||
Username string `json:"username"`
|
||
Password string `json:"password"`
|
||
InviteCode string `json:"invite_code"`
|
||
}
|
||
|
||
// loginRequest is the JSON body for POST /api/v1/auth/login.
|
||
type loginRequest struct {
|
||
Username string `json:"username"`
|
||
Password string `json:"password"`
|
||
}
|
||
|
||
// userResponse is the user shape included in auth responses.
|
||
type userResponse struct {
|
||
ID int64 `json:"id"`
|
||
Username string `json:"username"`
|
||
Avatar string `json:"avatar,omitempty"`
|
||
// DisplayName and About are always present (null = unset) so the settings
|
||
// form can tell "cleared" from "the server does not know this field".
|
||
DisplayName *string `json:"display_name"`
|
||
About *string `json:"about"`
|
||
// CustomStatus is the user's own free-text status line.
|
||
CustomStatus *string `json:"custom_status"`
|
||
// Status is the user's own true status, invisible included. This response
|
||
// only ever describes the caller, so there is nothing to hide from them.
|
||
Status string `json:"status"`
|
||
RoleID int64 `json:"role_id"`
|
||
TOTPEnabled bool `json:"totp_enabled"`
|
||
CreatedAt string `json:"created_at"`
|
||
}
|
||
|
||
// authSuccessResponse is returned on successful login/register.
|
||
type authSuccessResponse struct {
|
||
Token string `json:"token,omitempty"`
|
||
PartialToken string `json:"partial_token,omitempty"`
|
||
Requires2FA bool `json:"requires_2fa"`
|
||
User *userResponse `json:"user,omitempty"`
|
||
}
|
||
|
||
// AuthBroadcaster is the interface handleDeleteAccount uses to notify
|
||
// connected WebSocket clients that an account is gone. Satisfied by *ws.Hub
|
||
// (which already implements BroadcastMemberBan for the admin ban path this
|
||
// mirrors).
|
||
type AuthBroadcaster interface {
|
||
BroadcastMemberBan(userID int64)
|
||
}
|
||
|
||
// MountAuthRoutes registers all auth endpoints on the given router.
|
||
// Rate limiters are applied per-endpoint as specified. trustedProxies is the
|
||
// list of CIDRs whose X-Forwarded-For / X-Real-IP headers are honoured for
|
||
// rate-limiting IP resolution. totpKey is the AES-256 key used to encrypt
|
||
// TOTP secrets at rest (M1 security hardening).
|
||
//
|
||
// broadcaster is variadic and optional: MountAuthRoutes is called before the
|
||
// hub exists (router.go mounts auth routes first, and the hub needs the
|
||
// router to register its own webhook route), so a caller that cannot supply
|
||
// one yet may omit it entirely and self-deletion simply sends no event,
|
||
// exactly like today. A caller mounted after hub creation should pass it so
|
||
// DELETE /api/v1/auth/account can broadcast the same member_ban event the
|
||
// admin ban path already sends for the identical anonymise-and-ban DB state.
|
||
func MountAuthRoutes(r chi.Router, database *db.DB, limiter *auth.RateLimiter, trustedProxies []string, totpKey []byte, broadcaster ...AuthBroadcaster) {
|
||
var ab AuthBroadcaster
|
||
if len(broadcaster) > 0 {
|
||
ab = broadcaster[0]
|
||
}
|
||
registerLimiter := limiter
|
||
loginLimiter := limiter
|
||
partialStore := auth.NewPartialAuthStore(partialAuthStoreTTL)
|
||
pendingTOTPStore := auth.NewPendingTOTPStore(pendingTOTPStoreTTL)
|
||
usedTOTPCodes := auth.NewUsedTOTPCodeStore()
|
||
|
||
r.Route("/api/v1/auth", func(r chi.Router) {
|
||
r.With(RateLimitMiddleware(registerLimiter, "register:", scaledAuthLimit(registerRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Post("/register", handleRegister(database, trustedProxies))
|
||
|
||
r.With(RateLimitMiddleware(loginLimiter, "login:", scaledAuthLimit(loginRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Post("/login", handleLogin(database, limiter, partialStore, trustedProxies))
|
||
|
||
r.With(RateLimitMiddleware(limiter, "totp_verify:", scaledAuthLimit(verifyTOTPRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Post("/verify-totp", handleVerifyTOTP(database, partialStore, limiter, usedTOTPCodes, totpKey))
|
||
|
||
r.With(AuthMiddleware(database)).
|
||
Post("/logout", handleLogout(database))
|
||
|
||
r.With(AuthMiddleware(database)).
|
||
Get("/me", handleMe())
|
||
|
||
r.With(AuthMiddleware(database),
|
||
RateLimitMiddleware(limiter, "del_account:", scaledAuthLimit(sensitiveEndpointRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Delete("/account", handleDeleteAccount(database, limiter, ab))
|
||
})
|
||
|
||
r.With(AuthMiddleware(database),
|
||
RateLimitMiddleware(limiter, "totp:", scaledAuthLimit(sensitiveEndpointRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Post("/api/v1/users/me/totp/enable", handleEnableTOTP(pendingTOTPStore, limiter))
|
||
|
||
r.With(AuthMiddleware(database),
|
||
RateLimitMiddleware(limiter, "totp:", scaledAuthLimit(sensitiveEndpointRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Post("/api/v1/users/me/totp/confirm", handleConfirmTOTP(database, pendingTOTPStore, usedTOTPCodes, limiter, totpKey))
|
||
|
||
r.With(AuthMiddleware(database),
|
||
RateLimitMiddleware(limiter, "totp:", scaledAuthLimit(sensitiveEndpointRateLimitPerMinute), time.Minute, trustedProxies)).
|
||
Delete("/api/v1/users/me/totp", handleDisableTOTP(database, pendingTOTPStore, limiter))
|
||
}
|
||
|
||
// handleRegister processes POST /api/v1/auth/register.
|
||
func handleRegister(database *db.DB, trustedProxies []string) http.HandlerFunc {
|
||
proxyNets := parseCIDRList(trustedProxies) // W3-3a: parse once at construction
|
||
return func(w http.ResponseWriter, r *http.Request) {
|
||
if !registerPolicyGate(w, r, database) {
|
||
return
|
||
}
|
||
|
||
req, ok := registerReadRequest(w, r)
|
||
if !ok {
|
||
return
|
||
}
|
||
|
||
// Hash password before consuming the invite so that a hashing failure
|
||
// does not burn a valid invite code.
|
||
hash, err := auth.HashPassword(req.Password)
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to process registration",
|
||
})
|
||
return
|
||
}
|
||
|
||
// Atomically consume the invite and create the user so failed
|
||
// registrations do not burn a valid invite code.
|
||
uid, err := database.CreateUserWithInvite(r.Context(), req.Username, hash, int(permissions.MemberRoleID), req.InviteCode)
|
||
if err != nil {
|
||
// UNIQUE constraint violation → duplicate username → 400.
|
||
// Any other DB error → 500.
|
||
switch {
|
||
case db.IsUniqueConstraintError(err):
|
||
writeJSON(w, http.StatusBadRequest, genericAuthError)
|
||
case errors.Is(err, db.ErrNotFound):
|
||
writeJSON(w, http.StatusBadRequest, genericAuthError)
|
||
default:
|
||
slog.Error("CreateUserWithInvite failed", "err", err, "username", req.Username)
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "registration failed — please try again",
|
||
})
|
||
}
|
||
return
|
||
}
|
||
|
||
ip := clientIPWithProxies(r, proxyNets)
|
||
slog.Info("user registered", "username", req.Username, "user_id", uid, "ip", ip)
|
||
db.WriteAudit(context.WithoutCancel(r.Context()), database, uid, "user_register", "user", uid,
|
||
"new account created via invite")
|
||
|
||
// Issue session.
|
||
token, err := auth.GenerateToken()
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to create session",
|
||
})
|
||
return
|
||
}
|
||
|
||
device := truncateDevice(r.Header.Get("User-Agent"))
|
||
if _, err := database.CreateSession(r.Context(), uid, auth.HashToken(token), device, ip); err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to create session",
|
||
})
|
||
return
|
||
}
|
||
|
||
user, err := database.GetUserByID(r.Context(), uid)
|
||
if err != nil || user == nil {
|
||
slog.Error("failed to fetch user after registration", "user_id", uid, "error", err)
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "registration succeeded but user fetch failed",
|
||
})
|
||
return
|
||
}
|
||
writeJSON(w, http.StatusCreated, authSuccessResponse{
|
||
Token: token,
|
||
Requires2FA: false,
|
||
User: toUserResponse(user),
|
||
})
|
||
}
|
||
}
|
||
|
||
// registerPolicyGate reports whether registration is currently permitted,
|
||
// writing the refusal response itself when it is not.
|
||
func registerPolicyGate(w http.ResponseWriter, r *http.Request, database *db.DB) bool {
|
||
registrationOpen, err := isRegistrationOpen(r.Context(), database)
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to load registration policy",
|
||
})
|
||
return false
|
||
}
|
||
if !registrationOpen {
|
||
writeJSON(w, http.StatusForbidden, errorResponse{
|
||
Error: "FORBIDDEN",
|
||
Message: "registration is currently closed",
|
||
})
|
||
return false
|
||
}
|
||
|
||
require2FA, err := isRequire2FAEnabled(r.Context(), database)
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to load registration policy",
|
||
})
|
||
return false
|
||
}
|
||
if require2FA {
|
||
writeJSON(w, http.StatusForbidden, errorResponse{
|
||
Error: "FORBIDDEN",
|
||
Message: "registration is unavailable while two-factor authentication is required",
|
||
})
|
||
return false
|
||
}
|
||
return true
|
||
}
|
||
|
||
// registerReadRequest decodes and validates the registration body, writing the
|
||
// rejection response itself when the input cannot be used.
|
||
func registerReadRequest(w http.ResponseWriter, r *http.Request) (registerRequest, bool) {
|
||
var req registerRequest
|
||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "malformed request body",
|
||
})
|
||
return req, false
|
||
}
|
||
|
||
// OC-0151: bound the raw field before it ever reaches the fixpoint
|
||
// sanitizer below. sanitizeToFixpoint's cost is quadratic in input
|
||
// length (nested HTML entities force roughly one extra pass per two
|
||
// nesting levels), so an unauthenticated caller could otherwise pin a
|
||
// core for minutes with one oversized username, all before
|
||
// auth.ValidateUsername's 32-rune cap ever runs. This is a cheap
|
||
// byte-length pre-check — *4 still admits any legitimate 32-rune UTF-8
|
||
// username — mirroring sanitizeContent's raw-length bound in
|
||
// service/message.go and loginReadRequest's username bound below.
|
||
if len(req.Username) > maxLoginUsernameLen*4 {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "username is too long",
|
||
})
|
||
return req, false
|
||
}
|
||
|
||
// F: use the fixpoint sanitizer (service.SanitizeText), not a bare
|
||
// bluemonday.StrictPolicy().Sanitize call — Sanitize's output is always HTML-escaped
|
||
// (' -> ', & -> &, " -> "), so a plain call here would store
|
||
// a different string than what handleLogin looks up (which only
|
||
// trims), permanently locking out any username containing one of
|
||
// those characters. See service.SanitizeText's doc comment.
|
||
req.Username = strings.TrimSpace(service.SanitizeText(req.Username))
|
||
req.InviteCode = strings.TrimSpace(req.InviteCode)
|
||
|
||
if req.Username == "" || req.Password == "" || req.InviteCode == "" {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "username, password, and invite_code are required",
|
||
})
|
||
return req, false
|
||
}
|
||
|
||
// Validate username format (length, no control/invisible chars).
|
||
if err := auth.ValidateUsername(req.Username); err != nil {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: err.Error(),
|
||
})
|
||
return req, false
|
||
}
|
||
|
||
// Validate password strength before anything else.
|
||
if err := auth.ValidatePasswordStrength(req.Password); err != nil {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: err.Error(),
|
||
})
|
||
return req, false
|
||
}
|
||
return req, true
|
||
}
|
||
|
||
// handleLogin processes POST /api/v1/auth/login.
|
||
func handleLogin(database *db.DB, limiter *auth.RateLimiter, partialStore *auth.PartialAuthStore, trustedProxies []string) http.HandlerFunc {
|
||
proxyNets := parseCIDRList(trustedProxies) // W3-3a: parse once at construction
|
||
return func(w http.ResponseWriter, r *http.Request) {
|
||
req, ok := loginReadRequest(w, r)
|
||
if !ok {
|
||
return
|
||
}
|
||
|
||
ip := clientIPWithProxies(r, proxyNets)
|
||
|
||
user, ok := loginAuthenticate(w, r, database, limiter, req, ip)
|
||
if !ok {
|
||
return
|
||
}
|
||
|
||
if auth.IsEffectivelyBanned(user) {
|
||
slog.Warn("banned user login attempt", "username", user.Username, "user_id", user.ID, "ip", ip)
|
||
db.WriteAudit(context.WithoutCancel(r.Context()), database, user.ID, "login_blocked_banned", "user", user.ID,
|
||
"banned user attempted login from "+ip)
|
||
writeJSON(w, http.StatusForbidden, errorResponse{
|
||
Error: "FORBIDDEN",
|
||
Message: "your account has been suspended",
|
||
})
|
||
return
|
||
}
|
||
|
||
require2FA, err := isRequire2FAEnabled(r.Context(), database)
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to load authentication policy",
|
||
})
|
||
return
|
||
}
|
||
if user.TOTPSecret != nil {
|
||
partialToken, err := partialStore.Issue(user.ID, truncateDevice(r.Header.Get("User-Agent")), ip)
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to start two-factor challenge",
|
||
})
|
||
return
|
||
}
|
||
writeJSON(w, http.StatusOK, authSuccessResponse{
|
||
PartialToken: partialToken,
|
||
Requires2FA: true,
|
||
})
|
||
return
|
||
}
|
||
if require2FA {
|
||
writeJSON(w, http.StatusForbidden, errorResponse{
|
||
Error: "FORBIDDEN",
|
||
Message: "two-factor authentication must be enabled on this account before login",
|
||
})
|
||
return
|
||
}
|
||
|
||
// Issue session.
|
||
token, err := issueSession(r.Context(), database, user.ID, truncateDevice(r.Header.Get("User-Agent")), ip)
|
||
if err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to create session",
|
||
})
|
||
return
|
||
}
|
||
|
||
// Don't set status to "online" here — the WebSocket connection in
|
||
// serve.go does that when the user actually connects. Setting it here
|
||
// would leave the user permanently "online" if they never open a WS
|
||
// connection or if the client crashes before connecting.
|
||
slog.Info("user logged in", "username", user.Username, "user_id", user.ID, "ip", ip)
|
||
db.WriteAudit(context.WithoutCancel(r.Context()), database, user.ID, "user_login", "user", user.ID,
|
||
"logged in from "+ip)
|
||
writeJSON(w, http.StatusOK, authSuccessResponse{
|
||
Token: token,
|
||
Requires2FA: false,
|
||
User: toUserResponse(user),
|
||
})
|
||
}
|
||
}
|
||
|
||
// loginReadRequest decodes and validates the login body, writing the rejection
|
||
// response itself when the input cannot be used.
|
||
func loginReadRequest(w http.ResponseWriter, r *http.Request) (loginRequest, bool) {
|
||
var req loginRequest
|
||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "malformed request body",
|
||
})
|
||
return req, false
|
||
}
|
||
|
||
req.Username = strings.TrimSpace(req.Username)
|
||
// Do NOT trim req.Password — passwords may intentionally contain
|
||
// leading/trailing whitespace. Bcrypt handles arbitrary bytes.
|
||
|
||
if req.Username == "" || req.Password == "" {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "username and password are required",
|
||
})
|
||
return req, false
|
||
}
|
||
|
||
// F: reject an over-long username before it is ever used to build a
|
||
// RateLimiter map key below (unameKey, failKey, userFailKey, lockout
|
||
// keys). Unlike registration, login has no account to validate
|
||
// against yet, so nothing else bounds this value — an unauthenticated
|
||
// caller could otherwise pin an arbitrarily large, body-sized string
|
||
// as a retained key (Cleanup only evicts it after hours). Mirrors the
|
||
// same 32-rune cap auth.ValidateUsername enforces at registration.
|
||
if utf8.RuneCountInString(req.Username) > maxLoginUsernameLen {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "username is too long",
|
||
})
|
||
return req, false
|
||
}
|
||
return req, true
|
||
}
|
||
|
||
// loginAuthenticate runs the lockout gates, the constant-time password compare
|
||
// and the failure accounting for one login attempt. It returns the
|
||
// authenticated user, or false after writing the rejection response itself.
|
||
func loginAuthenticate(w http.ResponseWriter, r *http.Request, database *db.DB, limiter *auth.RateLimiter, req loginRequest, ip string) (*db.User, bool) {
|
||
// Check per-IP lockout first.
|
||
lockKey := "login_lock:" + ip
|
||
if limiter.IsLockedOut(lockKey) {
|
||
writeJSON(w, http.StatusTooManyRequests, errorResponse{
|
||
Error: "RATE_LIMITED",
|
||
Message: "account temporarily locked due to too many failed attempts",
|
||
})
|
||
return nil, false
|
||
}
|
||
|
||
// BUG-110: Also check per-username lockout to prevent distributed brute force.
|
||
// F1: canonicalize the username the same way GetUserByUsername does (COLLATE
|
||
// NOCASE) before keying the lockout, so case variants of one account
|
||
// (admin/Admin/ADMIN) share a single bucket instead of each getting its own.
|
||
unameKey := strings.ToLower(req.Username)
|
||
userLockKey := "login_user_lock:" + unameKey
|
||
if limiter.IsLockedOut(userLockKey) {
|
||
writeJSON(w, http.StatusTooManyRequests, errorResponse{
|
||
Error: "RATE_LIMITED",
|
||
Message: "account temporarily locked due to too many failed attempts",
|
||
})
|
||
return nil, false
|
||
}
|
||
|
||
// Constant-time lookup: always attempt bcrypt compare even when user
|
||
// does not exist to prevent timing-based username enumeration.
|
||
user, err := database.GetUserByUsername(r.Context(), req.Username)
|
||
|
||
// Distinguish DB errors from authentication failures. DB errors
|
||
// should NOT increment the rate limiter — otherwise a transient
|
||
// DB outage would lock out legitimate users.
|
||
if err != nil && user == nil {
|
||
// Could be a real DB error or simply "user not found".
|
||
// GetUserByUsername returns (nil, nil) for not-found, so a
|
||
// non-nil error here is a genuine DB failure.
|
||
slog.Error("login: GetUserByUsername failed", "err", err, "ip", ip)
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "login temporarily unavailable",
|
||
})
|
||
return nil, false
|
||
}
|
||
|
||
failKey := "login_fail:" + ip
|
||
userFailKey := "login_user_fail:" + unameKey
|
||
// F3: atomically reserve this attempt BEFORE the bcrypt compare. The
|
||
// read-only IsLockedOut gates above are check-then-act: N concurrent
|
||
// requests all pass them before any failure is recorded below, so the
|
||
// per-username cap — the only cross-IP brute-force defence — bound
|
||
// only sequential attackers. Allow records the attempt under the
|
||
// limiter's lock, capping a concurrent burst at the same budget a
|
||
// sequential attacker gets. Sized at threshold+1 so the sequential
|
||
// accepted-input set is unchanged: failures 1–10 still land, the 10th
|
||
// still trips the lockout (via the Check below), and a correct
|
||
// password on attempt 10 still succeeds — successful logins reset
|
||
// both counters. The reservation sits after the DB-error return above
|
||
// so a transient DB outage still does not consume attempts.
|
||
if !limiter.Allow(failKey, scaledAuthLimit(loginFailureThreshold)+1, loginFailureWindow) ||
|
||
!limiter.Allow(userFailKey, loginUserFailureThreshold+1, loginUserFailureWindow) {
|
||
writeJSON(w, http.StatusTooManyRequests, errorResponse{
|
||
Error: "RATE_LIMITED",
|
||
Message: "account temporarily locked due to too many failed attempts",
|
||
})
|
||
return nil, false
|
||
}
|
||
// Always run the password check — with an empty hash when the user does
|
||
// not exist. auth.CheckPassword performs a dummy bcrypt comparison for an
|
||
// empty hash, so bcrypt executes on every path and response time stays
|
||
// constant, preventing timing-based username enumeration. (A `user == nil
|
||
// || CheckPassword(...)` short-circuit would skip bcrypt entirely for
|
||
// unknown usernames, reintroducing the timing side-channel.)
|
||
storedHash := ""
|
||
if user != nil {
|
||
storedHash = user.PasswordHash
|
||
}
|
||
if !auth.CheckPassword(storedHash, req.Password) {
|
||
// The attempt was already recorded atomically up-front (F3); here
|
||
// only decide the lockouts, at the same boundary as before: the
|
||
// 10th in-window failure locks the key. Check is read-only, so
|
||
// the reservation is not double-counted.
|
||
if !limiter.Check(failKey, scaledAuthLimit(loginFailureThreshold)+1, loginFailureWindow) {
|
||
limiter.Lockout(r.Context(), lockKey, loginLockoutDuration)
|
||
}
|
||
// BUG-110: per-username lockout on threshold.
|
||
if !limiter.Check(userFailKey, loginUserFailureThreshold+1, loginUserFailureWindow) {
|
||
limiter.Lockout(r.Context(), userLockKey, loginUserLockoutDuration)
|
||
}
|
||
slog.Info("login failed", "ip", ip, "username_len", len(req.Username))
|
||
writeJSON(w, http.StatusUnauthorized, errorResponse{
|
||
Error: "UNAUTHORIZED",
|
||
Message: "invalid credentials",
|
||
})
|
||
return nil, false
|
||
}
|
||
|
||
// Reset failure counters on success.
|
||
limiter.Reset(r.Context(), failKey)
|
||
limiter.Reset(r.Context(), userFailKey)
|
||
return user, true
|
||
}
|
||
|
||
// handleLogout processes POST /api/v1/auth/logout.
|
||
func handleLogout(database *db.DB) http.HandlerFunc {
|
||
return func(w http.ResponseWriter, r *http.Request) {
|
||
sess, ok := r.Context().Value(SessionKey).(*db.Session)
|
||
if !ok || sess == nil {
|
||
writeJSON(w, http.StatusUnauthorized, errorResponse{
|
||
Error: "UNAUTHORIZED",
|
||
Message: "not authenticated",
|
||
})
|
||
return
|
||
}
|
||
|
||
// The client clears its token optimistically — once logout reaches the
|
||
// server, the revocation must not die with a dropped connection.
|
||
if err := database.DeleteSession(context.WithoutCancel(r.Context()), sess.TokenHash); err != nil {
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to logout",
|
||
})
|
||
return
|
||
}
|
||
|
||
// A custom status is a "what I am doing right now" note. Leaving it
|
||
// standing after the user signed out states something about them that
|
||
// is no longer true, so logout clears it — unlike the chosen presence
|
||
// status, which is a preference and deliberately survives.
|
||
if err := database.UpdateUserCustomStatus(context.WithoutCancel(r.Context()), sess.UserID, nil); err != nil {
|
||
slog.Warn("failed to clear custom status on logout", "user_id", sess.UserID, "err", err)
|
||
}
|
||
|
||
slog.Info("user logged out", "user_id", sess.UserID)
|
||
db.WriteAudit(context.WithoutCancel(r.Context()), database, sess.UserID, "user_logout", "user", sess.UserID, "")
|
||
|
||
w.WriteHeader(http.StatusNoContent)
|
||
}
|
||
}
|
||
|
||
// handleMe processes GET /api/v1/auth/me.
|
||
func handleMe() http.HandlerFunc {
|
||
return func(w http.ResponseWriter, r *http.Request) {
|
||
user, ok := r.Context().Value(UserKey).(*db.User)
|
||
if !ok || user == nil {
|
||
writeJSON(w, http.StatusUnauthorized, errorResponse{
|
||
Error: "UNAUTHORIZED",
|
||
Message: "not authenticated",
|
||
})
|
||
return
|
||
}
|
||
writeJSON(w, http.StatusOK, toUserResponse(user))
|
||
}
|
||
}
|
||
|
||
// deleteAccountRequest is the JSON body for DELETE /api/v1/auth/account.
|
||
type deleteAccountRequest struct {
|
||
Password string `json:"password"`
|
||
}
|
||
|
||
// handleDeleteAccount processes DELETE /api/v1/auth/account.
|
||
// The caller must supply their current password for confirmation.
|
||
// Progressive lockout mirrors the login handler: 3 failures → 15-min lock.
|
||
// broadcaster may be nil, in which case no event is sent and other connected
|
||
// clients converge on their next reconnect instead (same fallback every
|
||
// other broadcaster-optional handler in this package uses).
|
||
func handleDeleteAccount(database *db.DB, limiter *auth.RateLimiter, broadcaster AuthBroadcaster) http.HandlerFunc {
|
||
return func(w http.ResponseWriter, r *http.Request) {
|
||
user, ok := r.Context().Value(UserKey).(*db.User)
|
||
if !ok || user == nil {
|
||
writeJSON(w, http.StatusUnauthorized, errorResponse{
|
||
Error: "UNAUTHORIZED",
|
||
Message: "not authenticated",
|
||
})
|
||
return
|
||
}
|
||
|
||
// Per-user lockout to prevent password brute-force on this destructive endpoint.
|
||
lockKey := auth.Key("delete_lock", user.ID)
|
||
if limiter.IsLockedOut(lockKey) {
|
||
writeJSON(w, http.StatusTooManyRequests, errorResponse{
|
||
Error: "RATE_LIMITED",
|
||
Message: "too many failed attempts, try again later",
|
||
})
|
||
return
|
||
}
|
||
|
||
var req deleteAccountRequest
|
||
if err := json.NewDecoder(r.Body).Decode(&req); err != nil {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "malformed request body",
|
||
})
|
||
return
|
||
}
|
||
|
||
if req.Password == "" {
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "password is required",
|
||
})
|
||
return
|
||
}
|
||
|
||
// Verify the supplied password matches the stored hash.
|
||
failKey := auth.Key("delete_fail", user.ID)
|
||
if !auth.CheckPassword(user.PasswordHash, req.Password) {
|
||
if !limiter.Allow(failKey, deleteAccountFailureThreshold, deleteAccountFailureWindow) {
|
||
limiter.Lockout(r.Context(), lockKey, deleteAccountLockoutDuration)
|
||
}
|
||
writeJSON(w, http.StatusBadRequest, errorResponse{
|
||
Error: "INVALID_INPUT",
|
||
Message: "incorrect password",
|
||
})
|
||
return
|
||
}
|
||
limiter.Reset(r.Context(), failKey)
|
||
|
||
if err := database.DeleteAccount(r.Context(), user.ID); err != nil {
|
||
if errors.Is(err, db.ErrLastAdmin) {
|
||
writeJSON(w, http.StatusForbidden, errorResponse{
|
||
Error: "FORBIDDEN",
|
||
Message: "cannot delete the last admin account",
|
||
})
|
||
return
|
||
}
|
||
slog.Error("DeleteAccount failed", "err", err, "user_id", user.ID)
|
||
writeJSON(w, http.StatusInternalServerError, errorResponse{
|
||
Error: "INTERNAL_ERROR",
|
||
Message: "failed to delete account",
|
||
})
|
||
return
|
||
}
|
||
|
||
ip := clientIP(r)
|
||
slog.Info("account deleted", "username", user.Username, "user_id", user.ID, "ip", ip)
|
||
db.WriteAudit(context.WithoutCancel(r.Context()), database, user.ID, "account_deleted", "user", user.ID,
|
||
"account self-deleted from "+ip)
|
||
|
||
// DeleteAccount left the row in exactly the state an admin ban does
|
||
// (anonymised, banned, sessions revoked) — broadcast the same event so
|
||
// every other connected client drops the deleted user immediately
|
||
// instead of keeping their pre-deletion username until it reconnects.
|
||
if broadcaster != nil {
|
||
broadcaster.BroadcastMemberBan(user.ID)
|
||
}
|
||
|
||
w.WriteHeader(http.StatusNoContent)
|
||
}
|
||
}
|
||
|
||
// toUserResponse converts a db.User to the API response shape.
|
||
func toUserResponse(u *db.User) *userResponse {
|
||
avatar := ""
|
||
if u.Avatar != nil {
|
||
avatar = *u.Avatar
|
||
}
|
||
resp := &userResponse{
|
||
ID: u.ID,
|
||
Username: u.Username,
|
||
Avatar: avatar,
|
||
DisplayName: u.DisplayName,
|
||
About: u.About,
|
||
CustomStatus: u.CustomStatus,
|
||
Status: u.Status,
|
||
RoleID: u.RoleID,
|
||
TOTPEnabled: u.TOTPSecret != nil,
|
||
CreatedAt: u.CreatedAt,
|
||
}
|
||
return resp
|
||
}
|
||
|
||
// truncateDevice truncates the User-Agent to prevent oversized session records.
|
||
const maxDeviceLen = 512
|
||
|
||
func truncateDevice(ua string) string {
|
||
if len(ua) > maxDeviceLen {
|
||
return ua[:maxDeviceLen]
|
||
}
|
||
return ua
|
||
}
|
||
|
||
func issueSession(ctx context.Context, database *db.DB, userID int64, device, ip string) (string, error) {
|
||
token, err := auth.GenerateToken()
|
||
if err != nil {
|
||
return "", err
|
||
}
|
||
if _, err := database.CreateSession(ctx, userID, auth.HashToken(token), device, ip); err != nil {
|
||
return "", err
|
||
}
|
||
return token, nil
|
||
}
|
||
|
||
func isRequire2FAEnabled(ctx context.Context, database *db.DB) (bool, error) {
|
||
return getBooleanSetting(ctx, database, "require_2fa", false)
|
||
}
|
||
|
||
func isRegistrationOpen(ctx context.Context, database *db.DB) (bool, error) {
|
||
return getBooleanSetting(ctx, database, "registration_open", true)
|
||
}
|
||
|
||
func getBooleanSetting(ctx context.Context, database *db.DB, key string, defaultValue bool) (bool, error) {
|
||
value, err := database.GetSetting(ctx, key)
|
||
if err != nil {
|
||
if errors.Is(err, db.ErrNotFound) {
|
||
return defaultValue, nil
|
||
}
|
||
return false, err
|
||
}
|
||
return parseBooleanSettingValue(value)
|
||
}
|
||
|
||
func parseBooleanSettingValue(value string) (bool, error) {
|
||
switch strings.ToLower(strings.TrimSpace(value)) {
|
||
case "1", "true":
|
||
return true, nil
|
||
case "0", "false":
|
||
return false, nil
|
||
default:
|
||
return false, fmt.Errorf("invalid boolean setting value %q", value)
|
||
}
|
||
}
|
||
|
||
func requirePasswordConfirmation(user *db.User, password string) error {
|
||
if password == "" {
|
||
return fmt.Errorf("password is required")
|
||
}
|
||
if !auth.CheckPassword(user.PasswordHash, password) {
|
||
return fmt.Errorf("password confirmation failed")
|
||
}
|
||
return nil
|
||
}
|