Compare commits
21
Commits
342d8a069a
..
v0.1.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
c11b25c20a | ||
|
|
c27aad58ae | ||
|
|
7dffaad8e5 | ||
|
|
583026418d | ||
|
|
fa6d88a768 | ||
|
|
b6c01878a8 | ||
|
|
5dbef8f23f | ||
|
|
ffb12a36b5 | ||
|
|
04b8a5a8b9 | ||
|
|
b4b40e5c2c | ||
|
|
16c9c3a03f | ||
|
|
018c02c759 | ||
|
|
b03a241be2 | ||
|
|
314959c7bf | ||
|
|
ed76b35600 | ||
|
|
b971d2ed97 | ||
|
|
580c2a4257 | ||
|
|
c3c3c8e1a6 | ||
|
|
4049a197b9 | ||
|
|
1a24d21d0a | ||
|
|
7e9bf81bd1 |
+3
-2
@@ -11,8 +11,9 @@ LINKLOG_APP_NAME=LinkLog
|
||||
LINKLOG_VERSION=0.1.0
|
||||
LINKLOG_SECRET_KEY=replace-with-a-long-random-secret
|
||||
LINKLOG_DATA_ENCRYPTION_KEY=generate-with-python-cryptography-fernet-key
|
||||
LINKLOG_TOKEN_EXPIRY_DAYS=30
|
||||
LINKLOG_PUBLIC_URL=localhost
|
||||
LINKLOG_TOKEN_EXPIRY_MINUTES=15
|
||||
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS=30
|
||||
LINKLOG_PUBLIC_URL=linklog.example.com
|
||||
LINKLOG_SMTP_HOST=
|
||||
LINKLOG_SMTP_PORT=587
|
||||
LINKLOG_SMTP_USERNAME=
|
||||
|
||||
@@ -19,11 +19,10 @@ jobs:
|
||||
- name: Validate versions and signed XPI
|
||||
id: release
|
||||
run: |
|
||||
python3 scripts/release/validate_release.py
|
||||
version=$(python3 -c "import json; print(json.load(open('frontend/version.json'))['version'])")
|
||||
echo "version=$version" >> "$GITHUB_OUTPUT"
|
||||
if [ "${GITHUB_REF_NAME#v}" != "$version" ]; then
|
||||
echo "tag ${GITHUB_REF_NAME} does not match release version $version" >&2
|
||||
python3 scripts/release/validate_release.py --github-output "$GITHUB_OUTPUT"
|
||||
backend_version=$(python3 -c "import re; text=open('backend/app/core/config.py').read(); print(re.search(r\"version: str = os\\.getenv\\('LINKLOG_VERSION', '([^']+)'\\)\", text).group(1))")
|
||||
if [ "${GITHUB_REF_NAME#v}" != "$backend_version" ]; then
|
||||
echo "tag ${GITHUB_REF_NAME} does not match backend version $backend_version" >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
@@ -40,51 +39,113 @@ jobs:
|
||||
context: .
|
||||
push: true
|
||||
tags: |
|
||||
${{ env.IMAGE_NAME }}:${{ steps.release.outputs.version }}
|
||||
${{ env.IMAGE_NAME }}:${{ steps.release.outputs.backend_version }}
|
||||
${{ env.IMAGE_NAME }}:latest
|
||||
labels: |
|
||||
org.opencontainers.image.version=${{ steps.release.outputs.version }}
|
||||
org.opencontainers.image.version=${{ steps.release.outputs.backend_version }}
|
||||
org.opencontainers.image.source=https://git.kolkman.org/olaf/Link-Log
|
||||
|
||||
- name: Generate release README
|
||||
env:
|
||||
BACKEND_VERSION: ${{ steps.release.outputs.backend_version }}
|
||||
PLUGIN_VERSION: ${{ steps.release.outputs.plugin_version }}
|
||||
SIGNED_XPI: ${{ steps.release.outputs.signed_xpi }}
|
||||
run: |
|
||||
cat > release-readme.md <<EOF
|
||||
# LinkLog $BACKEND_VERSION
|
||||
|
||||
LinkLog is a Firefox extension and Python web service for saving links with a title, comment, timestamp, and tracking parameters removed. The service stores links in SQLite and can publish them through plugins, including Mastodon.
|
||||
|
||||
## Docker Container
|
||||
|
||||
The current backend/container version is $BACKEND_VERSION. Pull it from the Gitea container registry:
|
||||
|
||||
\`\`\`sh
|
||||
docker pull $IMAGE_NAME:$BACKEND_VERSION
|
||||
\`\`\`
|
||||
|
||||
The same image is also published as:
|
||||
|
||||
\`\`\`sh
|
||||
docker pull $IMAGE_NAME:latest
|
||||
\`\`\`
|
||||
The developer version of the backend is always published as $IMAGE_NAME:latest, which may be ahead of the current release version and may be unstable.
|
||||
Additional information about the backend can be found in the [README](https://git.kolkman.org/olaf/Link-Log/src/branch/main/backend/README.md).
|
||||
|
||||
## Firefox Extension
|
||||
|
||||
The current signed Firefox plugin version, compatible with this version of the backend, is $PLUGIN_VERSION. Download it from the raw repository artifact:
|
||||
|
||||
https://git.kolkman.org/olaf/Link-Log/raw/branch/main/$SIGNED_XPI
|
||||
EOF
|
||||
|
||||
- name: Create Gitea release
|
||||
id: gitea_release
|
||||
env:
|
||||
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
||||
VERSION: ${{ steps.release.outputs.version }}
|
||||
VERSION: ${{ steps.release.outputs.backend_version }}
|
||||
run: |
|
||||
response=$(curl --fail-with-body --silent --show-error \
|
||||
payload_file=$(mktemp)
|
||||
python3 - <<'PY' > "$payload_file"
|
||||
import json
|
||||
import os
|
||||
from pathlib import Path
|
||||
|
||||
version = os.environ['VERSION']
|
||||
print(json.dumps({
|
||||
'tag_name': f'v{version}',
|
||||
'name': f'LinkLog {version}',
|
||||
'body': Path('release-readme.md').read_text(),
|
||||
'draft': False,
|
||||
'prerelease': False,
|
||||
}))
|
||||
PY
|
||||
response_file=$(mktemp)
|
||||
response_status=$(curl --silent --show-error -o "$response_file" -w '%{http_code}' \
|
||||
-X POST \
|
||||
-H "Authorization: token $RELEASE_TOKEN" \
|
||||
-H 'Content-Type: application/json' \
|
||||
-d "{\"tag_name\":\"v$VERSION\",\"name\":\"LinkLog $VERSION\",\"draft\":false,\"prerelease\":false}" \
|
||||
--data-binary "@$payload_file" \
|
||||
https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases)
|
||||
release_id=$(printf '%s' "$response" | jq -r '.id')
|
||||
rm -f "$payload_file"
|
||||
if [ "$response_status" = 409 ]; then
|
||||
response_status=$(curl --silent --show-error -o "$response_file" -w '%{http_code}' \
|
||||
-H "Authorization: token $RELEASE_TOKEN" \
|
||||
"https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/tags/v$VERSION")
|
||||
fi
|
||||
if [ "$response_status" -lt 200 ] || [ "$response_status" -ge 300 ]; then
|
||||
cat "$response_file" >&2
|
||||
exit 1
|
||||
fi
|
||||
response=$(cat "$response_file")
|
||||
rm -f "$response_file"
|
||||
release_id=$(printf '%s' "$response" | python3 -c 'import json, sys; print(json.load(sys.stdin)["id"])')
|
||||
test "$release_id" != null
|
||||
test "$release_id" != 0
|
||||
upload_url="https://git.kolkman.org/api/v1/repos/olaf/Link-Log/releases/$release_id/assets"
|
||||
echo "upload_url=$upload_url" >> "$GITHUB_OUTPUT"
|
||||
|
||||
- name: Upload signed XPI and update manifest
|
||||
- name: Upload release README
|
||||
env:
|
||||
RELEASE_TOKEN: ${{ secrets.RELEASE_TOKEN }}
|
||||
UPLOAD_URL: ${{ steps.gitea_release.outputs.upload_url }}
|
||||
VERSION: ${{ steps.release.outputs.version }}
|
||||
run: |
|
||||
curl --fail-with-body --silent --show-error \
|
||||
response_status=$(curl --silent --show-error -o /tmp/linklog-readme-upload-response -w '%{http_code}' \
|
||||
-X POST -H "Authorization: token $RELEASE_TOKEN" \
|
||||
-H 'Content-Type: application/x-xpinstall' \
|
||||
--data-binary "@XPI/signed/LinkLog-$VERSION.xpi" \
|
||||
"$UPLOAD_URL?name=LinkLog-$VERSION.xpi"
|
||||
curl --fail-with-body --silent --show-error \
|
||||
-X POST -H "Authorization: token $RELEASE_TOKEN" \
|
||||
-H 'Content-Type: application/json' \
|
||||
--data-binary @webextension/updates.json \
|
||||
"$UPLOAD_URL?name=updates.json"
|
||||
-H 'Content-Type: text/markdown' \
|
||||
--data-binary @release-readme.md \
|
||||
"$UPLOAD_URL?name=README.md")
|
||||
if [ "$response_status" -lt 200 ] || [ "$response_status" -ge 300 ]; then
|
||||
cat /tmp/linklog-readme-upload-response >&2
|
||||
exit 1
|
||||
fi
|
||||
|
||||
- name: Publish release links
|
||||
env:
|
||||
VERSION: ${{ steps.release.outputs.version }}
|
||||
BACKEND_VERSION: ${{ steps.release.outputs.backend_version }}
|
||||
PLUGIN_VERSION: ${{ steps.release.outputs.plugin_version }}
|
||||
SIGNED_XPI: ${{ steps.release.outputs.signed_xpi }}
|
||||
run: |
|
||||
echo "Docker image: $IMAGE_NAME:$VERSION"
|
||||
echo "Signed XPI: https://git.kolkman.org/olaf/Link-Log/releases/download/v$VERSION/LinkLog-$VERSION.xpi"
|
||||
echo "Firefox update manifest: https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json"
|
||||
echo "Docker image: $IMAGE_NAME:$BACKEND_VERSION"
|
||||
echo "Signed XPI: https://git.kolkman.org/olaf/Link-Log/raw/branch/main/$SIGNED_XPI (version $PLUGIN_VERSION)"
|
||||
echo "Release README: README.md"
|
||||
|
||||
@@ -12,7 +12,8 @@ frontend/ Jinja templates and browser-side assets
|
||||
webextension/ Firefox Manifest V3 extension
|
||||
Logo.svg Source logo artwork used by the web and extension interfaces
|
||||
Dockerfile Backend container image
|
||||
docker-compose.yml App with traefik reverse proxy hooks
|
||||
docker-compose.yml Production app with Traefik reverse proxy hooks
|
||||
docker-compose.local.yml Local development app with direct port access
|
||||
REQUIREMENTS.md Product requirements
|
||||
VIBE/ Conversation and prompt logs
|
||||
```
|
||||
@@ -68,6 +69,7 @@ Open these URLs:
|
||||
- About: <http://localhost:8000/about>
|
||||
- Admin page: <http://localhost:8000/admin>
|
||||
- Web login: <http://localhost:8000/login>
|
||||
- Token refresh: `POST http://localhost:8000/api/auth/refresh`
|
||||
- Health check: <http://localhost:8000/health>
|
||||
- OpenAPI documentation: <http://localhost:8000/docs>
|
||||
|
||||
@@ -94,13 +96,25 @@ make xpi
|
||||
|
||||
This creates `XPI/unsigned/LinkLog-0.1.0.xpi` from the `webextension/` package and excludes macOS metadata and minified artifacts. The version is read from `webextension/manifest.json`. The `XPI/signed/` directory is reserved for signed release bundles.
|
||||
|
||||
## Docker Deployment
|
||||
|
||||
The main `docker-compose.yml` is the production deployment. It does not publish port 8000 on the host; the application is reachable through Traefik on the external `linklog_traefik` network. Set `LINKLOG_PUBLIC_URL` to the DNS hostname served by Traefik. The default is the documentation hostname `linklog.example.com`, which must be replaced for a real deployment.
|
||||
|
||||
For local development with direct access, use the separate file:
|
||||
|
||||
```sh
|
||||
docker compose -f docker-compose.local.yml up --build
|
||||
```
|
||||
|
||||
This publishes `${APP_PORT:-8000}` and defaults the application URL to `http://localhost:8000`. Do not use the local file for an Internet-facing deployment.
|
||||
|
||||
## Releases
|
||||
|
||||
Releases run in Gitea Actions when a `v*` tag is pushed. The Docker release version comes from `frontend/version.json`; the Firefox plugin version comes from `webextension/manifest.json`. CI also requires both to match `LINKLOG_VERSION`'s default in `backend/app/core/config.py`.
|
||||
Releases run in Gitea Actions when a `v*` tag is pushed. The Docker release version comes from `LINKLOG_VERSION`'s default in `backend/app/core/config.py`; the tag must match that backend version. The Firefox plugin version is independent and comes from the most recent signed `XPI/signed/LinkLog-<version>.xpi` checked into the repository.
|
||||
|
||||
The signed XPI is produced manually and must be checked into `XPI/signed/LinkLog-<version>.xpi` before creating the tag. The workflow validates the embedded manifest, publishes the XPI and `webextension/updates.json` as Gitea release assets, and publishes Docker images to `git.kolkman.org/olaf/link-log:<version>` and `:latest`.
|
||||
The signed XPI is produced manually and should be checked into `XPI/signed/LinkLog-<version>.xpi`. The workflow validates the latest signed XPI's embedded manifest, publishes Docker images to `git.kolkman.org/olaf/link-log:<backend-version>` and `:latest`, and creates a release README that describes the project, the current backend/container version, and the raw signed XPI download URL with the plugin version.
|
||||
|
||||
The extension's `update_url` points at the stable raw repository URL `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json`. Update `webextension/updates.json` with each signed XPI version and commit it together with the XPI. The release page provides a direct install link at `https://git.kolkman.org/olaf/Link-Log/releases/download/v<version>/LinkLog-<version>.xpi`.
|
||||
The extension's `update_url` points at the stable raw repository URL `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/webextension/updates.json`. Update `webextension/updates.json` with each signed XPI version and commit it together with the XPI. Release READMEs point to the raw signed XPI at `https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-<version>.xpi`.
|
||||
|
||||
The workflow requires Gitea Actions secrets named `REGISTRY_USERNAME`, `REGISTRY_TOKEN`, and `RELEASE_TOKEN`. `REGISTRY_TOKEN` is a Gitea access token with permission to push packages; `RELEASE_TOKEN` needs permission to create releases and upload release assets.
|
||||
|
||||
@@ -142,15 +156,16 @@ The manifest includes stable Firefox extension metadata and references the packa
|
||||
1. Start the backend locally.
|
||||
2. Open Firefox and visit `about:debugging#/runtime/this-firefox`.
|
||||
3. Select **Load Temporary Add-on**.
|
||||
4. Choose `webextension/manifest.json`.
|
||||
4. Choose `webextension/manifest.json` (Firefox 142 or newer is required).
|
||||
5. Open the LinkLog extension options and enter:
|
||||
- Backend URL: the URL of your LinkLog server, such as `http://localhost:8000`
|
||||
- Username: `alice`
|
||||
- Email: `alice@example.com`
|
||||
- Password: `secret123`
|
||||
- One-time password: enter it when OTP is enabled
|
||||
6. Save the settings and login.
|
||||
7. Open a webpage, select the LinkLog toolbar button, review the title and URL, add a comment, and submit it.
|
||||
|
||||
When the extension settings page has a valid session, it shows `<username> logged in at <backend URL>` and a **Sign out** button instead of the login form. Signing out revokes the token and returns the form.
|
||||
When the extension settings page has a valid session, it shows `<username> logged in at <backend URL>` and a **Sign out** button instead of the login form. Access and refresh credentials are kept in Firefox session storage, so a browser restart requires login again. Signing out revokes the token family and returns the form.
|
||||
|
||||
Temporary extensions are removed when Firefox restarts. Reload the extension from `about:debugging` after changing its files.
|
||||
|
||||
@@ -164,6 +179,8 @@ cp .env.example .env
|
||||
|
||||
Edit `.env` and replace `LINKLOG_SECRET_KEY` with a long random value. Docker Compose automatically reads `.env` from the repository root. The committed `.env.example` contains safe defaults and placeholders; the real `.env` is ignored by Git.
|
||||
|
||||
When `APP_ENV=production`, application startup fails closed unless `LINKLOG_SECRET_KEY` is a non-default high-entropy value of at least 32 characters and `LINKLOG_DATA_ENCRYPTION_KEY` is a valid Fernet key. Development mode may use local defaults, but production secrets should come from a protected secret mechanism.
|
||||
|
||||
The main configurable values are:
|
||||
|
||||
| Variable | Purpose | Default |
|
||||
@@ -171,8 +188,9 @@ The main configurable values are:
|
||||
| `LINKLOG_SECRET_KEY` | token signing/security secret | required in Docker |
|
||||
| `LINKLOG_DATA_ENCRYPTION_KEY` | Fernet key for encrypting SMTP, Mastodon, and OTP secrets at rest | required in Docker |
|
||||
| `LINKLOG_DATABASE_PATH` | SQLite file path inside the container | `/app/backend/data/linklog.db` |
|
||||
| `LINKLOG_TOKEN_EXPIRY_DAYS` | access-token lifetime | `30` |
|
||||
| `LINKLOG_PUBLIC_URL` | Public hostname used by Traefik and expanded to a callback URL by the backend | `localhost` |
|
||||
| `LINKLOG_TOKEN_EXPIRY_MINUTES` | access-token lifetime | `15` |
|
||||
| `LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS` | refresh-token lifetime | `30` |
|
||||
| `LINKLOG_PUBLIC_URL` | Public hostname used by Traefik and expanded to a callback URL by the backend | `linklog.example.com` |
|
||||
| `LINKLOG_SMTP_HOST` | SMTP server hostname; empty disables delivery in local development | empty |
|
||||
| `LINKLOG_SMTP_PORT` | SMTP server port | `587` |
|
||||
| `LINKLOG_SMTP_USERNAME` | SMTP login username | empty |
|
||||
@@ -247,6 +265,25 @@ curl -X POST http://localhost:8000/api/auth/login \\
|
||||
-d '{"email":"alice@example.com","password":"secret123"}'
|
||||
```
|
||||
|
||||
The login response contains a 15-minute access token, a device-bound refresh token, its expiry time, and a `device_id`. Each successful refresh rotates the refresh token.
|
||||
|
||||
Refresh an access token:
|
||||
|
||||
```sh
|
||||
curl -X POST http://localhost:8000/api/auth/refresh \\
|
||||
-H 'Content-Type: application/json' \\
|
||||
-d '{"refresh_token":"YOUR_REFRESH_TOKEN","device_id":"YOUR_DEVICE_ID"}'
|
||||
```
|
||||
|
||||
Refresh-token reuse or a mismatched device ID returns `401` and revokes the token family. Signing out revokes the token family, while changing the password or completing a password reset revokes all sessions for the user.
|
||||
|
||||
Sign out with the access token in the bearer header:
|
||||
|
||||
```sh
|
||||
curl -X POST http://localhost:8000/api/auth/logout \\
|
||||
-H 'Authorization: Bearer YOUR_ACCESS_TOKEN'
|
||||
```
|
||||
|
||||
Submit a link using the returned access token:
|
||||
|
||||
```sh
|
||||
|
||||
+103
-201
@@ -2,262 +2,164 @@
|
||||
|
||||
**Assessment date:** 2026-08-26
|
||||
**Scope:** Current LinkLog backend, web frontend, Firefox extension, SQLite persistence, SMTP and Mastodon integrations, Docker/Traefik deployment files, and automated tests.
|
||||
**Assessment type:** Source-code security review. This is not a penetration test, dependency vulnerability scan, formal threat model sign-off, or production configuration certification.
|
||||
**Assessment type:** Source-code review. This is not a penetration test, dependency scan, container scan, formal threat-model sign-off, or production configuration certification.
|
||||
|
||||
## Executive Summary
|
||||
|
||||
LinkLog has several good security foundations: authenticated API dependencies, administrator authorization checks, owner checks for link operations, token hashing in the database, email verification, password reset token hashing and single-use behavior, TOTP login enforcement, last-administrator protection, parameterized SQLite queries, upload size limits, and non-root application execution in the container.
|
||||
The current worktree contains strong security improvements: salted scrypt password hashing with legacy upgrade support, bearer-header authentication, hashed and expiring tokens, refresh-token rotation with device binding and family revocation, OTP recovery codes, encrypted newly written secrets, Mastodon SSRF controls, image decoding and re-encoding, reduced extension permissions, proxy-only production Compose, and append-only audit events.
|
||||
|
||||
The current implementation is not ready to expose directly to the public Internet without additional hardening. The most important issues are:
|
||||
The following issues remain before an Internet-facing production release:
|
||||
|
||||
1. Passwords were previously stored as unsalted, fast SHA-256 hashes; this issue has now been addressed in the current worktree with salted scrypt hashes and legacy upgrade support.
|
||||
2. Access tokens are accepted in query strings by session endpoints, which can leak through logs, browser history, proxies, and referrers.
|
||||
3. SMTP credentials, Mastodon credentials, OAuth client secrets, and TOTP secrets are stored in plaintext in SQLite.
|
||||
4. Mastodon instance URLs are user-controlled and the backend makes outbound requests to them, creating an SSRF and egress-control concern.
|
||||
5. Login has no effective rate limiting or account lockout.
|
||||
6. The Firefox extension stores bearer tokens in browser local storage and requests broad website access.
|
||||
7. The Compose setup still exposes the application port directly and relies on deployment-specific Traefik networking and labels.
|
||||
1. Logout still accepts a bearer token in a JSON body rather than using the standard `Authorization` header.
|
||||
2. SMTP, Mastodon, setup, and some user-service errors return raw exception details to clients.
|
||||
3. First-run setup is intentionally unauthenticated and lacks a bootstrap secret and application-level request-size controls.
|
||||
4. Audit event details are serialized without defensive sanitization or size limits at the audit-service boundary.
|
||||
5. The development secret fallback is not rejected at application startup in production.
|
||||
6. Rate limiting is single-instance SQLite state, is not atomic under concurrency, and reset-mail issuance is not independently throttled.
|
||||
7. Runtime verification, security headers, centralized audit export, retention, alerting, and dependency/container/security scanning remain incomplete.
|
||||
|
||||
These findings are prioritized below. Severity describes the potential security impact in a typical Internet-facing deployment, not the likelihood in every environment.
|
||||
The application should remain behind the production reverse proxy, with real DNS/TLS, protected secrets, and restricted network access until these items are addressed.
|
||||
|
||||
## Positive Controls Already Present
|
||||
## Verified Controls
|
||||
|
||||
- Bearer authentication is centralized in `backend/app/api/dependencies.py`.
|
||||
- Administrator routes use `require_admin`; standard users receive `403`.
|
||||
- Link update, delete, and Mastodon-post operations verify ownership.
|
||||
- Tokens are generated with UUID material, stored as SHA-256 hashes, expire, and can be revoked.
|
||||
- Password-reset tokens are random, hashed, expiring, single-use, and revoke existing sessions after reset.
|
||||
- New administrator-created users require email verification before login.
|
||||
- OTP uses time-based verification with a one-step clock window and is required before token issuance when enabled.
|
||||
- The profile API does not return `password_hash` or `otp_secret` after the profile response hardening.
|
||||
- User privilege changes protect against removing the last administrator and prevent an administrator from changing their own privilege.
|
||||
- Uploaded avatars have a 2 MB limit, a restricted MIME allow-list, user-scoped filenames, and a persistent data location.
|
||||
- SQLite foreign keys are enabled and ownership predicates are used for destructive link operations.
|
||||
- SQL statements use parameters rather than interpolated user values.
|
||||
- The Docker image runs the application as UID 10001 after startup and defines a health check.
|
||||
- `.env` and database/runtime files are ignored by Git.
|
||||
- The XPI build validates archive integrity, required files, and manifest parity.
|
||||
- Browser rendering generally uses `textContent` for feed data, reducing DOM-based injection risk.
|
||||
- Passwords use salted scrypt hashes; valid legacy SHA-256 hashes are upgraded on login.
|
||||
- Bearer authentication is centralized through `get_current_user` and `require_admin`.
|
||||
- Query-string authentication is not accepted by protected session endpoints.
|
||||
- Access tokens are short-lived by default; refresh tokens are hashed, separately expiring, device-bound, rotated, and family-revoked on reuse.
|
||||
- Logout, password changes, and password resets revoke session material according to the token lifecycle.
|
||||
- OTP enrollment provides ten one-time recovery codes; only hashes are stored.
|
||||
- Users can recover OTP with password plus a recovery code, and administrators can disable OTP for another user.
|
||||
- Newly written SMTP, Mastodon, OAuth, and OTP secrets are encrypted with an external Fernet key.
|
||||
- Mastodon instances are restricted to HTTPS public hostnames, unsafe resolved addresses are rejected, and redirects are blocked.
|
||||
- Avatar uploads are size-limited, decoded with Pillow, pixel-limited, fully loaded, and re-encoded as server-generated PNG.
|
||||
- Production Compose does not publish the application port and uses the external Traefik network; local direct access is separate.
|
||||
- The Firefox extension uses `activeTab`, session-scoped credentials, exact configured backend permissions, and a self-only extension-page CSP.
|
||||
- SQLite queries are parameterized and foreign-key enforcement is enabled.
|
||||
- An append-only `security_audit_events` table records actor, action, target, outcome, and details for major administrative and destructive operations.
|
||||
- The current automated backend suite passes 49 tests.
|
||||
|
||||
## Findings
|
||||
|
||||
### SA-001: Unsalted fast SHA-256 password hashing
|
||||
|
||||
**Severity:** Critical, remediated in current worktree
|
||||
**Evidence before remediation:** `backend/app/database.py` and `backend/app/services/auth_service.py` used unsalted SHA-256 password comparisons.
|
||||
**Current state:** `backend/app/database.py` now creates salted scrypt hashes in the format `scrypt$N$r$p$salt$digest`. `verify_password()` uses the encoded parameters and constant-time comparison. `authenticate_user()` fetches by username, verifies in Python, and transparently replaces a valid legacy 64-character SHA-256 hash with a new scrypt hash.
|
||||
**Residual impact:** Existing accounts remain exposed until they successfully authenticate once after deployment. An attacker with a copy of an old database may still attack legacy hashes. Existing credentials should be rotated if the old database may have been exposed.
|
||||
|
||||
**Recommendation:** Deploy the current migration, require password rotation for accounts that cannot log in during migration, and monitor for remaining legacy hashes. Review scrypt cost parameters periodically and increase them as hardware changes. Do not revert to a fast general-purpose hash.
|
||||
|
||||
**Priority:** Completed in code; operational migration and credential rotation remain.
|
||||
|
||||
### SA-002: Bearer tokens accepted in query strings
|
||||
### SA-001: Logout uses non-standard token transport
|
||||
|
||||
**Severity:** High, remediated in current worktree
|
||||
**Evidence before remediation:** `backend/app/api/auth.py` exposed `GET /api/auth/me?token=...`, and web/extension callers used the query form.
|
||||
**Current state:** `/api/auth/me` now requires the existing bearer-header dependency. The shared web header, admin session check, Firefox settings page, and tests send `Authorization: Bearer <token>`. A query-string token is rejected with `401`.
|
||||
**Residual impact:** Tokens from old URLs may remain in proxy/browser logs and should be treated as exposed until revoked or rotated.
|
||||
**Evidence before remediation:** `POST /api/auth/logout` accepted `{"token": ...}` in the JSON request body, and the web frontend sent the access token this way.
|
||||
**Impact:** Request bodies may be captured by debugging middleware, application logs, or monitoring systems. The endpoint also diverges from the bearer-header contract used elsewhere, increasing the chance of inconsistent token handling.
|
||||
|
||||
**Recommendation:** Rotate existing access tokens after deployment and scrub historical query parameters from logs where possible. Keep the bearer header as the only credential transport.
|
||||
**Current state:** Logout requires `Authorization: Bearer <access-token>`, rejects body-only tokens with `401`, and revokes the token family server-side. The web frontend and Firefox extension send the header; regression coverage verifies access and refresh tokens are invalid after logout.
|
||||
|
||||
**Priority:** Completed in code; token rotation and log hygiene remain.
|
||||
**Recommendation:** Keep logout header-only, retain family revocation, avoid logging authorization headers, and rotate legacy sessions issued before this change.
|
||||
|
||||
### SA-003: Sensitive secrets stored in plaintext SQLite
|
||||
**Priority:** Completed in code; legacy session rotation and log hygiene remain.
|
||||
|
||||
**Severity:** High, remediated in current worktree for newly written secrets
|
||||
**Evidence:** `backend/app/services/email_service.py` stores SMTP settings including `smtp_password` in `app_settings`; `backend/app/services/mastodon_oauth.py` stores Mastodon application secrets and user access tokens in `app_settings` and `user_plugin_config`; `backend/app/api/user_config.py` stores `otp_secret` in the `users` table. New writes are encrypted, but legacy plaintext rows require rotation.
|
||||
**Impact:** Read access to the database exposes SMTP credentials, Mastodon posting authority, OAuth client secrets, and TOTP seeds. TOTP seeds cannot be changed by a user who loses the database copy. Database backups therefore contain reusable credentials, not just application data.
|
||||
|
||||
**Current state:** Newly stored SMTP passwords, Mastodon OAuth client secrets and access tokens, and TOTP seeds are encrypted with Fernet using `LINKLOG_DATA_ENCRYPTION_KEY`. The key is required in Docker and is not stored in SQLite. The user plugin API no longer returns the Mastodon access token.
|
||||
**Residual impact:** Existing plaintext secrets require a controlled read-and-save rotation after the key is configured. Lost encryption keys make stored secrets unrecoverable.
|
||||
|
||||
**Recommendation:** Supply `LINKLOG_DATA_ENCRYPTION_KEY` through a protected secret mechanism, encrypt backups, rotate credentials after suspected disclosure, and migrate existing plaintext values. Continue omitting secrets from API responses.
|
||||
|
||||
**Priority:** Completed for new writes; existing secret migration and key management remain.
|
||||
|
||||
### SA-004: User-controlled Mastodon instance creates SSRF and uncontrolled egress risk
|
||||
### SA-002: Raw infrastructure errors are returned to clients
|
||||
|
||||
**Severity:** High, remediated in current worktree
|
||||
**Evidence before remediation:** Mastodon instance values were passed to outbound `urlopen()` calls with no DNS/IP-range or redirect controls.
|
||||
**Current state:** `mastodon_security.py` requires hostname-only HTTPS URLs, resolves DNS, rejects loopback, link-local, private, multicast, unspecified, reserved, and IPv4-mapped IPv6 addresses, and uses an opener that refuses redirects. OAuth, posting, and deletion all use these controls.
|
||||
**Residual impact:** DNS and network policy can change after validation; production deployments should still use egress firewalling or a restricted outbound proxy.
|
||||
**Evidence before remediation:** SMTP and Mastodon routes interpolated exception text into `503`/`502` responses. Setup and email-address routes also exposed mail-delivery exception text.
|
||||
**Impact:** Error responses can disclose SMTP hostnames, ports, TLS/library details, upstream response bodies, internal network information, or sensitive URL fragments.
|
||||
|
||||
**Recommendation:** Keep outbound firewalling or an allow-listed proxy in production, monitor DNS rebinding risk, and maintain response-size/time limits.
|
||||
**Current state:** The application assigns a request ID at middleware entry, returns it in `X-Request-ID`, logs technical exception summaries server-side after redacting authorization values, tokens, passwords, secrets, OTP/code values, and secret-bearing URL query values, and returns stable public messages with a reference ID. SMTP setup/admin/email errors and Mastodon registration/callback errors no longer expose raw exception text. Regression tests verify representative exception and secret text is absent from HTTP responses.
|
||||
|
||||
**Priority:** Completed in code; network-level egress controls remain.
|
||||
**Residual impact:** Logging currently uses the application logger rather than a centralized protected sink. Request-ID trust, log retention, access control, and structured redaction should be reviewed in deployment.
|
||||
|
||||
### SA-005: Login endpoint lacks rate limiting and lockout
|
||||
**Recommendation:** Keep public errors stable and reference-based, export redacted logs to a protected centralized system, define retention and access controls, and never log authorization headers or secret-bearing request data.
|
||||
|
||||
**Severity:** High, remediated in current worktree
|
||||
**Evidence before remediation:** `POST /api/auth/login` had no IP, email, or account rate limit, and OTP failures were not throttled separately.
|
||||
**Current state:** Login failures are tracked in SQLite by a SHA-256 key derived from client IP and normalized email. Five failures within 15 minutes cause a two-minute lockout; the endpoint returns `429` with `Retry-After`, and successful password plus OTP authentication clears the counter. Password-reset mail remains generic and should still be rate-limited operationally.
|
||||
**Priority:** Completed in code; centralized logging and operational controls remain.
|
||||
|
||||
**Recommendation:** Use a distributed limiter for multi-instance deployments, add monitoring, and rate-limit password-reset issuance independently. Keep responses generic to avoid account enumeration.
|
||||
### SA-003: First-run setup is unauthenticated and lacks application-level body limits
|
||||
|
||||
**Priority:** Completed for the single-instance SQLite deployment; distributed limiting and reset-mail controls remain.
|
||||
**Severity:** Medium/High for exposed fresh deployments
|
||||
**Evidence:** `/api/setup/configuration`, `/api/setup/test-mail`, `/api/setup/complete`, and `/api/setup/status` are available before an administrator exists. No global request-size middleware or bootstrap secret is enforced in the application.
|
||||
|
||||
**Impact:** Anyone who can reach a fresh instance can overwrite pending setup values, attempt SMTP delivery, consume test-mail quota, and submit oversized request bodies. The setup design is necessary for provisioning but is unsafe when directly exposed.
|
||||
|
||||
**Recommendation:** Require a one-time bootstrap secret supplied through the environment or console, or restrict setup to localhost/private management networking. Add bounded request models and a global body-size limit. Keep strict setup/test-mail throttling, audit setup actions, expire pending setup data, and disable setup routes after provisioning.
|
||||
|
||||
**Severity:** High
|
||||
**Evidence:** `webextension/manifest.json` declares `host_permissions: ["<all_urls>"]`; `webextension/options.js` and `webextension/popup.js` store and retrieve `accessToken` through `browser.storage.local`.
|
||||
**Impact:** A compromised extension context or another extension with sufficient access may obtain the bearer token. The broad host permission increases the impact of an extension compromise and requires elevated user trust. The token grants access until expiry or revocation.
|
||||
**Priority:** High for Internet-facing fresh installations.
|
||||
|
||||
**Recommendation:** Minimize permissions to the APIs actually needed. Prefer `activeTab` and explicit user interaction for page capture, and avoid `<all_urls>` unless required by a demonstrated workflow. Store session credentials in the narrowest available extension storage, minimize token lifetime, support refresh-token rotation, and clear all session material on logout or token invalidation. Add a Content Security Policy and review every extension script for dependency and injection risk.
|
||||
|
||||
**Priority:** High.
|
||||
|
||||
### SA-007: Production Compose configuration exposes the application directly
|
||||
|
||||
**Severity:** Medium/High
|
||||
**Evidence:** `docker-compose.yml` publishes `${APP_PORT:-8000}:8000` while also configuring Traefik labels. The file uses an external `linklog_traefik` network and deployment-specific labels.
|
||||
**Impact:** The application can bypass the reverse proxy and any TLS, authentication middleware, rate limiting, or security headers configured there. The default `LINKLOG_PUBLIC_URL=localhost` is also unsuitable for a public deployment. A network or label mismatch can silently expose an unprotected direct endpoint or make operators disable controls to restore access.
|
||||
|
||||
**Recommendation:** Split local development and production Compose files. In production, do not publish the application port to the host; attach it only to the reverse-proxy network. Ensure the app and Traefik share the same explicitly named network and validate the effective rendered configuration in CI. Require a non-local public hostname, TLS, security headers, request-size limits, and proxy-level rate limiting. Keep the direct port only in a documented local profile.
|
||||
|
||||
**Priority:** High for Internet-facing deployments.
|
||||
|
||||
### SA-008: Initial setup and SMTP validation are unauthenticated by design
|
||||
### SA-004: Audit details are not sanitized at the audit-service boundary
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** `backend/app/api/setup.py` exposes configuration, test-mail, status, and completion routes without a bearer dependency while no administrator exists.
|
||||
**Impact:** This is necessary for first-run provisioning, but an exposed fresh instance allows anyone who can reach it to attempt setup, modify pending configuration, trigger test mail, and consume the five-send testing quota. The setup pending data includes a password hash and SMTP password in the database.
|
||||
**Evidence:** `record_audit_event()` serializes caller-supplied `details` directly to SQLite. Current callers generally avoid secrets, but the service does not enforce that contract or bound nested values and event size.
|
||||
|
||||
**Recommendation:** Restrict first-run setup at the network layer until an operator has completed provisioning, or require a one-time bootstrap secret supplied through the environment/console. Bind setup to localhost or a private management interface where possible. Add CSRF protection if setup ever uses cookies, strict request throttling, audit logging, and an explicit setup expiration/cleanup mechanism. Disable setup routes permanently once configuration completes.
|
||||
**Impact:** A future caller could persist passwords, tokens, OTP codes, SMTP credentials, sensitive URLs, or oversized data in the audit database. Audit records are durable and are not a suitable place for arbitrary request payloads.
|
||||
|
||||
**Priority:** Medium, high for exposed fresh deployments.
|
||||
|
||||
### SA-009: TOTP enrollment has no recovery codes or reset workflow
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** `POST /api/user/otp/setup` returns the seed/provisioning URI and `POST /api/user/otp` requires a valid current OTP code to disable OTP.
|
||||
**Impact:** A user who loses the authenticator device or seed can be locked out. Administrators have no documented recovery path that does not weaken authentication. Database readers can also use the plaintext seed as a second factor.
|
||||
|
||||
**Recommendation:** Generate one-time recovery codes during enrollment, display them once, hash them at rest, and invalidate each code on use. Require password reauthentication for disabling or replacing OTP. Add a controlled administrative recovery workflow with audit logging and notification. Avoid returning the seed after initial setup and never include it in profile responses.
|
||||
**Recommendation:** Use an allow-list of permitted detail fields per action, or recursively redact sensitive key names and URL query values. Bound string lengths and serialized event size. Add direct service tests with nested `password`, `token`, `secret`, and URL values and assert that they are redacted or rejected.
|
||||
|
||||
**Priority:** Medium.
|
||||
|
||||
### SA-010: Avatar validation trusts the client MIME type
|
||||
### SA-005: Production secret fallback is not fail-closed
|
||||
|
||||
**Severity:** Medium, remediated in current worktree
|
||||
**Evidence before remediation:** `Settings.secret_key` defaulted to `dev-secret-key-change-me`, and `LINKLOG_DATA_ENCRYPTION_KEY` was validated when encryption was used rather than fully validated during startup.
|
||||
|
||||
**Impact:** A deployment that omits required configuration can start with a known development secret or fail only when a protected feature is exercised. This creates dangerous configuration drift and complicates incident response.
|
||||
|
||||
**Current state:** `validate_configuration()` runs before FastAPI app construction. In production it rejects a missing or known development `LINKLOG_SECRET_KEY`, application secrets shorter than 32 characters or with insufficient character diversity, and missing `LINKLOG_DATA_ENCRYPTION_KEY`. Any supplied encryption key is checked as a valid Fernet key. Focused tests cover rejection and acceptance paths.
|
||||
|
||||
**Residual impact:** Secret strength checks are pragmatic length/diversity checks rather than a full entropy estimator. Secret provisioning, rotation, and protected storage remain operational requirements.
|
||||
|
||||
**Recommendation:** Keep production startup fail-closed, provision secrets through a protected secret manager, rotate them after suspected disclosure, and consider a stronger entropy policy if deployment requirements warrant it.
|
||||
|
||||
**Priority:** Completed in code; secret provisioning and rotation remain.
|
||||
|
||||
### SA-006: Login and reset-mail throttling are not distributed or atomic
|
||||
|
||||
**Severity:** Medium/High in multi-instance deployments
|
||||
**Evidence:** Login failure state is stored in SQLite and keyed by a client-IP/email hash. The check and increment occur as separate operations. Failed login handling can also issue a password-reset email for a known verified account without an independent reset-mail cooldown.
|
||||
|
||||
**Impact:** Concurrent attempts can overwrite counters, multiple application instances do not share reliable rate state, and reset-mail issuance can be abused to spam a user or consume SMTP resources.
|
||||
|
||||
**Recommendation:** Use an atomic shared limiter such as Redis for multi-instance deployments, with both account and IP buckets. Add an independent per-account/IP reset-mail cooldown and monitoring. Treat trusted proxy headers explicitly when deriving client IPs. Add concurrency, proxy, OTP-failure, and reset-mail abuse tests.
|
||||
|
||||
**Priority:** Medium/High for scaled or public deployments.
|
||||
|
||||
### SA-007: Security headers and global request policy are incomplete
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** `upload_avatar()` in `backend/app/api/user_config.py` selects the extension from `UploadFile.content_type` and writes the bytes without decoding or inspecting the image.
|
||||
**Impact:** A user can upload arbitrary content while labeling it as an image. Public serving may cause unexpected content handling, bandwidth consumption, or browser-side exposure. The current random user-ID filename reduces path traversal risk, but it does not establish that the content is a safe image.
|
||||
**Evidence:** The application does not consistently install or test CSP, HSTS, `X-Content-Type-Options`, frame protections, `Referrer-Policy`, trusted hosts, or a global request-size limit. The extension CSP does not cover the web application.
|
||||
|
||||
**Recommendation:** Decode images with a hardened image library, enforce pixel and dimension limits, re-encode to a safe format, strip metadata, and serve with a fixed safe `Content-Type` and `X-Content-Type-Options: nosniff`. Consider a separate media origin and a stricter content security policy.
|
||||
**Impact:** Browser defense-in-depth and resource exhaustion protections depend on external proxy configuration. A proxy configuration mistake can leave HTML, API, or media responses weaker than intended.
|
||||
|
||||
**Recommendation:** Add a documented application or guaranteed-proxy policy and test headers on HTML, API, and media responses. Use `TrustedHostMiddleware` with explicit production hosts, `nosniff`, restrictive framing/referrer rules, HSTS only on HTTPS, and bounded request bodies.
|
||||
|
||||
**Priority:** Medium.
|
||||
|
||||
### SA-011: Error details can disclose infrastructure information
|
||||
### SA-008: Audit operations lack request correlation, retention, export, and alerting
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** Admin SMTP routes return exception text in `503` responses; Mastodon errors include upstream response bodies; the frontend displays these values to the user.
|
||||
**Impact:** Connection errors can disclose hostnames, ports, TLS details, library messages, upstream response bodies, or internal service information. The behavior is useful for administrators but may expose more detail than intended if an admin session is compromised or error responses are logged.
|
||||
**Evidence:** Audit events contain actor/action/target/outcome/details/time but no request ID, source context, retention policy, protected export, or alerting pipeline.
|
||||
|
||||
**Recommendation:** Log full technical details server-side with correlation IDs. Return a stable user-facing message plus a short reference ID. Allow detailed diagnostics only behind an explicit protected troubleshooting mode. Redact credentials, authorization headers, URLs containing secrets, and SMTP/Mastodon response fields before logging or returning them.
|
||||
**Impact:** Operators can inspect database events but cannot reliably correlate them with request logs, detect attacks promptly, or guarantee retention and tamper-resistant access controls.
|
||||
|
||||
**Recommendation:** Add request IDs at middleware entry, export redacted events to protected logs or a security monitoring system, define retention and access controls, and alert on privilege changes, OTP resets, password resets, credential changes, refresh-token reuse, and destructive actions.
|
||||
|
||||
**Priority:** Medium.
|
||||
|
||||
### SA-012: Token lifecycle has unused refresh-token semantics
|
||||
### SA-009: Dependency, container, secret, and runtime security verification is incomplete
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** `issue_token()` returns a `refresh_token` value, but only the access token is inserted into `tokens`; no refresh endpoint or refresh-token hash is implemented.
|
||||
**Impact:** Clients may assume the refresh token provides renewal or may store a value that cannot be revoked or used. This complicates session reasoning and can lead to unsafe client fallbacks. Access tokens currently live for the configured default of 30 days.
|
||||
**Evidence:** The repository runs functional tests and static syntax checks, but no dependency vulnerability scan, container scan, secret scan, authenticated dynamic test, or live Firefox extension workflow is part of the verified release path.
|
||||
|
||||
**Recommendation:** Either remove `refresh_token` from the API contract or implement a real refresh-token lifecycle: hash and persist refresh tokens, rotate them on use, detect reuse, bind them to a session/device, expire them separately, and revoke the token family on logout or password change. Reduce access-token lifetime after a real refresh flow is available.
|
||||
**Impact:** Known vulnerable dependencies, image issues, accidental secret commits, proxy misconfiguration, and browser-runtime permission failures can reach release despite passing unit tests.
|
||||
|
||||
**Priority:** Medium.
|
||||
**Recommendation:** Add CI jobs for Python dependency and license policy, container scanning, secret scanning, Compose rendering, authenticated dynamic API checks, and a Firefox smoke test covering permission grant, login, refresh, logout, and active-tab capture.
|
||||
|
||||
### SA-013: No explicit security headers, CORS policy, or request-size policy
|
||||
**Priority:** Medium before public release.
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** `backend/app/main.py` does not install security-header or CORS middleware, and the application routes do not define a global request-size limit.
|
||||
**Impact:** Deployment behavior depends entirely on the reverse proxy. Missing `Content-Security-Policy`, `Strict-Transport-Security`, `X-Content-Type-Options`, `Referrer-Policy`, and frame protections weakens browser-side defenses. An overly permissive future CORS configuration could expose bearer-authenticated APIs. Large request bodies may consume resources even where individual avatar limits exist.
|
||||
## Residual Operational Requirements
|
||||
|
||||
**Recommendation:** Add a documented restrictive security-header policy at the application or guaranteed proxy layer. Use `TrustedHostMiddleware` with an explicit production host list. Do not enable broad CORS; if cross-origin extension access requires it, allow only configured origins. Add global request and upload limits at the proxy and application layers.
|
||||
|
||||
**Priority:** Medium.
|
||||
|
||||
### SA-014: Development fallback secret is unsafe if the app is run without Compose configuration
|
||||
|
||||
**Severity:** Medium
|
||||
**Evidence:** `Settings.secret_key` in `backend/app/core/config.py` defaults to `dev-secret-key-change-me`.
|
||||
**Impact:** Local or incorrectly configured deployments can share a known secret. Even if the current token implementation does not use this value for signing, the setting creates a dangerous security assumption and may be used by future features.
|
||||
|
||||
**Recommendation:** Fail closed when `APP_ENV=production` and the secret is absent or matches a known development value. Generate secrets during provisioning, validate minimum length and entropy, and never ship a production fallback. Make all cryptographic uses explicit and test them.
|
||||
|
||||
**Priority:** Medium.
|
||||
|
||||
### SA-015: Some destructive and administrative operations lack audit logging
|
||||
|
||||
**Severity:** Low/Medium
|
||||
**Evidence:** User creation/deletion, privilege changes, SMTP changes, theme changes, OTP enrollment/disablement, link deletion, and Mastodon deletion do not create durable security audit events.
|
||||
**Impact:** Operators cannot reliably determine who changed privileges, modified delivery credentials, enrolled OTP, or deleted local/remote content. This limits incident response and accountability.
|
||||
|
||||
**Recommendation:** Add append-only audit events containing actor ID, action, target type/ID, timestamp, request ID, and outcome. Never store passwords, OTP codes, access tokens, SMTP passwords, or full sensitive request bodies. Export security events to protected logs.
|
||||
|
||||
**Priority:** Low/Medium.
|
||||
|
||||
## Authentication and Authorization Review
|
||||
|
||||
- **Authentication transport:** Bearer headers are used by most APIs, but query-string tokens remain a leakage risk. There is no cookie session, which reduces CSRF exposure for current bearer-only API calls. Credentials are now email-based; usernames remain presentation identities.
|
||||
- **Email authentication:** Primary and additional addresses are checked independently; additional addresses are unusable for login until their verification token is consumed. The profile exposes status but not verification secrets.
|
||||
- **Primary email selection:** Only an already verified alternative address can be promoted to primary. The same user row retains account permissions and active sessions, and the previous primary is retained as a verified alternative.
|
||||
- **Password policy:** New and reset passwords require at least eight characters. This is better than no policy but should be replaced with a longer passphrase-oriented policy and breached-password screening after a proper password hash migration.
|
||||
- **Email verification:** New administrator-created users cannot log in until verified. The setup-created first administrator is marked verified, which is appropriate for bootstrap but should be protected by the setup controls above.
|
||||
- **Password reset:** Tokens are random, hashed, expiring, single-use, and revoke existing access tokens after reset. Reset-email generation errors are intentionally swallowed to preserve generic login behavior, but this should be paired with server-side monitoring.
|
||||
- **OTP:** Login enforcement is present and OTP setup requires confirmation. Recovery codes, secret rotation, reauthentication, and encrypted secret storage are missing.
|
||||
- **Authorization:** Admin checks and link ownership checks are present. The last-administrator invariant is enforced for privilege changes and deletion. Add authorization tests for every new destructive endpoint as the API grows.
|
||||
|
||||
## Data Protection Review
|
||||
|
||||
- SQLite is the primary data store and contains profile data, links, password hashes, tokens, SMTP settings, Mastodon credentials, OAuth state, and OTP secrets. New sensitive values are encrypted with the externally supplied Fernet key; existing plaintext values must be rotated.
|
||||
- Database backups must be treated as credential-bearing secrets, encrypted, access-controlled, rotated, and tested for secure deletion.
|
||||
- Avatar files are persistent and publicly served. Validate and re-encode image content before accepting production uploads.
|
||||
- Link URLs and comments are intentionally public feed data. Operators should document that users must not submit secrets in URLs or comments.
|
||||
- SMTP and Mastodon integration errors should be redacted before entering logs or API responses.
|
||||
|
||||
## Frontend and Extension Review
|
||||
|
||||
- Feed content is generally assigned with `textContent`, which is a good XSS defense.
|
||||
- User-supplied profile values rendered by Jinja should remain autoescaped; do not mark them safe without a narrowly reviewed reason.
|
||||
- The web API currently uses bearer headers, so browser CSRF risk is lower than with cookie sessions. Keep it that way unless a CSRF token design is added.
|
||||
- Browser local storage is exposed to any script running in the same origin. Keep third-party scripts out of authenticated pages and add a restrictive CSP.
|
||||
- The extension's `<all_urls>` host permission should be reduced if the active-tab workflow is sufficient. Review Mozilla Add-ons policies before publishing signed releases.
|
||||
- The extension stores access and refresh-token-like values in `browser.storage.local`; implement actual refresh semantics or stop storing/returning unused refresh values.
|
||||
- Extension error messages should not include tokens or full sensitive URLs.
|
||||
|
||||
## Deployment Checklist
|
||||
|
||||
Before production exposure:
|
||||
|
||||
- [ ] Replace SHA-256 password hashing with Argon2id, scrypt, or bcrypt and migrate existing accounts.
|
||||
- [ ] Remove query-string token authentication and rotate existing access tokens.
|
||||
- [x] Encrypt newly written SMTP, Mastodon, OAuth, and OTP secrets at rest; protect the encryption key separately. Rotate legacy plaintext values.
|
||||
- [ ] Add login, OTP, reset-mail, and setup rate limiting.
|
||||
- [x] Validate Mastodon instances as HTTPS public hostnames, reject unsafe DNS/IP ranges, and block redirects. Keep network-level egress controls in production.
|
||||
- [ ] Disable direct host publication of the application port in production.
|
||||
- [ ] Configure HTTPS, HSTS, CSP, Referrer-Policy, frame protections, `nosniff`, and trusted hosts.
|
||||
- [ ] Define a restrictive CORS policy or leave CORS disabled.
|
||||
- [ ] Add global request-size limits and hardened image decoding/re-encoding.
|
||||
- [ ] Add OTP recovery codes and a protected recovery workflow.
|
||||
- [ ] Remove or implement refresh-token behavior.
|
||||
- [ ] Add security audit events and centralized redacted logging.
|
||||
- [ ] Rotate all credentials and set a unique high-entropy production secret.
|
||||
- [ ] Review extension permissions and submit the XPI only after Mozilla policy review.
|
||||
- [ ] Encrypt and restrict database/avatar backups, and test restore and revocation procedures.
|
||||
- [ ] Run a dependency vulnerability scan and a dynamic penetration test against a production-like deployment.
|
||||
|
||||
## Suggested Priority Order
|
||||
|
||||
1. Password hashing migration.
|
||||
2. Query-token removal and token rotation.
|
||||
3. Secret-at-rest protection and backup controls.
|
||||
4. Login/setup/OTP rate limiting.
|
||||
5. Production network egress controls for Mastodon.
|
||||
6. Production network and TLS hardening.
|
||||
7. Extension permission and credential-storage review.
|
||||
8. Security headers, trusted hosts, request limits, media validation, recovery codes, and audit logging.
|
||||
- Replace documentation hostnames with real DNS names and enforce HTTPS/TLS.
|
||||
- Keep production Compose proxy-only and verify the actual Traefik network and middleware in deployment.
|
||||
- Rotate legacy plaintext secrets and previously issued sessions after upgrades.
|
||||
- Protect and encrypt database/avatar backups; test restoration and token/session revocation.
|
||||
- Monitor failed logins, reset-mail volume, refresh-token reuse, OTP recovery, privilege changes, and destructive actions.
|
||||
- Review the Firefox extension against Mozilla Add-ons policy before signing.
|
||||
|
||||
## Verification Performed
|
||||
|
||||
The repository's automated backend suite was run during this review and passed with 29 tests before the password-storage change; focused password/authentication tests subsequently passed after the remediation. Static Python and JavaScript checks were also used during feature development. These results demonstrate regression coverage, not absence of the findings above. A production release should additionally run a dependency scanner, container scanner, secret scanner, and authenticated dynamic security test.
|
||||
- `PYTHONPATH=. pytest -q`: **49 passed** at the start of this audit.
|
||||
- Static source review of backend APIs/services, frontend assets, extension manifest/scripts, Compose files, configuration, and tests.
|
||||
- Targeted searches for authentication, token, secret, upload, outbound-request, error, and audit-log paths.
|
||||
|
||||
Functional tests demonstrate regression coverage only; they do not certify production security.
|
||||
|
||||
+186
-12
@@ -1,5 +1,167 @@
|
||||
# Chat Log
|
||||
|
||||
### User
|
||||
The release server fails because its curl does not support `--fail-with-body`.
|
||||
|
||||
### Assistant outcome
|
||||
Replaced all three `--fail-with-body` uses in the release workflow with portable curl response capture and explicit HTTP status checks. Failed API and asset-upload responses now print their response body before exiting, while older curl versions remain supported.
|
||||
|
||||
### User
|
||||
When posting to Mastodon change the formatting so there is an empty line between “From my #LinkLog:” and the title.
|
||||
|
||||
### Assistant outcome
|
||||
Updated the Mastodon formatter so the prefix and title are separate paragraphs: `From my #LinkLog:` followed by a blank line and then the title. Existing comment, source URL, and tag paragraph formatting remains unchanged.
|
||||
|
||||
### User
|
||||
Check the modified pages for the correct link because a version number was added to the signed XPI.
|
||||
|
||||
### Assistant outcome
|
||||
Verified that the signed artifact is `XPI/signed/LinkLog-0.1.0.xpi` and that the About page, Profile page, `webextension/updates.json`, README, and related regression test all reference the matching versioned filename. No changes were required.
|
||||
|
||||
### User
|
||||
In the Profile page below the Save profile button add “If you have not downloaded the plugin yet find it here” with a link to the signed plugin.
|
||||
|
||||
### Assistant outcome
|
||||
Added the plugin download prompt immediately below the Save profile button, linking “find it here” to the signed `LinkLog-0.1.0.xpi` artifact. Added profile-page regression assertions and recorded the change in VIBE.
|
||||
|
||||
### User
|
||||
Add a Plugin section to the About page with a download link to the signed XPI file.
|
||||
|
||||
### Assistant outcome
|
||||
Added a Plugin section to the About page with a download link for the signed `LinkLog-0.1.0.xpi` artifact hosted on the repository's raw main branch. Added a page-rendering regression assertion.
|
||||
|
||||
### User
|
||||
The Firefox plugin tests report that `strict_min_version` 112 is too low for `data_collection_permissions`, `storage.session`, and `permissions.request`.
|
||||
|
||||
### Assistant outcome
|
||||
Raised the extension minimum Firefox version to 142.0, covering the reported desktop and Android manifest/API compatibility warnings. Updated the README to require Firefox 142 or newer.
|
||||
|
||||
### User
|
||||
Implement SA-005: during startup reject missing or known development `LINKLOG_SECRET_KEY` in production, validate minimum length and entropy, require and validate the encryption key, and add fail-closed configuration tests.
|
||||
|
||||
### Assistant outcome
|
||||
Added startup configuration validation before FastAPI app construction. Production now rejects missing/default/weak application secrets and missing or invalid Fernet encryption keys, while development defaults remain available. Added configuration tests for rejection and valid production settings, and updated SA-005 documentation.
|
||||
|
||||
### User
|
||||
For SA-002, log technical details server-side with a request/correlation ID, return a stable public message with a short reference ID, redact secrets, and test that exception text is absent from responses.
|
||||
|
||||
### Assistant outcome
|
||||
Added request-ID middleware and stable public error references. SMTP, setup, email-verification, and Mastodon exception paths now log redacted technical summaries server-side without exposing raw exception text, credentials, authorization values, reset tokens, OTP data, or secret-bearing URL values. Added regression coverage and updated SA-002 documentation.
|
||||
|
||||
### User
|
||||
Remedy SA-001: Logout uses non-standard token transport.
|
||||
|
||||
### Assistant outcome
|
||||
Migrated logout to require `Authorization: Bearer <access-token>`, updated the web frontend and Firefox extension, and added regression coverage proving body-only logout is rejected while header logout revokes the access token and refresh-token family. Updated SA-001, the checklist, and README examples.
|
||||
|
||||
### User
|
||||
Perform a new security audit overwriting Security-audit.md with new and remaining issues.
|
||||
|
||||
### Assistant outcome
|
||||
Replaced the historical audit with a fresh current-state review dated 2026-08-26. The new report records verified controls and nine remaining findings: logout token transport, raw infrastructure errors, unauthenticated setup exposure, audit-detail sanitization, production secret fallback, non-distributed rate limiting, incomplete security headers/request policy, missing audit operations, and incomplete dependency/container/secret/runtime verification. The baseline backend suite passed 49 tests.
|
||||
|
||||
### User
|
||||
Update SA-012 to reflect the actual implementation, document device binding, rotation, reuse detection, family revocation, logout and password-reset revocation, update the checklist and README API examples, and add the refresh endpoint to the documented API surface.
|
||||
|
||||
### Assistant outcome
|
||||
Reconciled SA-012 and the authentication documentation with the implemented 15-minute access tokens and 30-day device-bound refresh tokens. Documented hashing, rotation, reuse-triggered family revocation, logout and password-reset revocation, added the refresh endpoint and curl example to the README, corrected extension login instructions, and checked off the refresh-token implementation item.
|
||||
|
||||
### User
|
||||
Replace `LINKLOG_TOKEN_EXPIRY_DAYS` with `LINKLOG_TOKEN_EXPIRY_MINUTES`, add `LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS` to the production Compose environment, and add a CI test comparing Compose variables with Settings.
|
||||
|
||||
### Assistant outcome
|
||||
Updated production Compose to pass the configured 15-minute access-token and 30-day refresh-token settings. Added a repository test that compares `LINKLOG_*` Compose keys with the environment keys declared by `Settings` and rejects the obsolete days-based access-token variable.
|
||||
|
||||
### User
|
||||
Reduce the size of the font of the greeting somewhat.
|
||||
|
||||
### Assistant outcome
|
||||
Reduced the email greeting from 22px to 18px while preserving the Asset font, top alignment, and placement to the right of the 50×50 logo.
|
||||
|
||||
### User
|
||||
Put the greeting to the right of the logo in the header, and align at the top.
|
||||
|
||||
### Assistant outcome
|
||||
Changed the email header to use separate table cells for the logo and greeting. The greeting cell is explicitly top-aligned and padded to the right of the fixed 50×50 logo, avoiding email-client baseline alignment differences.
|
||||
|
||||
### User
|
||||
Put the header text to the right of the logo and align it on the top. Also add a comma after Hello.
|
||||
|
||||
### Assistant outcome
|
||||
Aligned the email logo and header text at the top of the header row, kept the text to the right of the 50×50 logo, and changed the greeting to “Hello, a message from <public hostname>”.
|
||||
|
||||
### User
|
||||
Instead of “Hello” print “Hello a message from <public hostname>”, with the public hostname linking to the LinkLog server.
|
||||
|
||||
### Assistant outcome
|
||||
Updated the branded email header to show “Hello a message from <public hostname>”. The visible hostname is extracted from the configured public URL and links to that server; the existing 50×50 top-left logo and Asset font styling remain in place.
|
||||
|
||||
### User
|
||||
The logo is still full width. Make it 50px by 50px, put it in the top left, and put “Hello” to the right in the Asset font.
|
||||
|
||||
### Assistant outcome
|
||||
Reworked the email header to use a fixed 50×50 logo at the top-left, with “Hello” immediately to its right in the Asset font with email-safe fallbacks. Added regression assertions for the dimensions, placement styling, and greeting.
|
||||
|
||||
### User
|
||||
The Logo in the emails should be 120px wide and centered on the top.
|
||||
|
||||
### Assistant outcome
|
||||
Updated the shared branded email template so the embedded LinkLog logo is explicitly 120px wide and remains centered in the top header. Added a regression assertion for the rendered width.
|
||||
|
||||
### User
|
||||
Mails sent should be formatted nicely in the style of the website and include the logo.
|
||||
|
||||
### Assistant outcome
|
||||
Added branded multipart emails with a LinkLog-styled HTML layout, an embedded logo, and preserved plain-text fallbacks for verification, password-reset, and SMTP test messages. Dynamic usernames and URLs are HTML-escaped, and email tests cover the HTML body, CID logo reference, and escaping.
|
||||
|
||||
### User
|
||||
Fix SA-015: Some destructive and administrative operations lack audit logging.
|
||||
|
||||
### Assistant outcome
|
||||
Added an append-only `security_audit_events` table and audit service. Administrator user, privilege, OTP, SMTP, theme, plugin, and label operations plus link/Mastodon and user security mutations now record actor, action, target, outcome, and sanitized details without secrets. Added regression coverage and updated SA-015/checklist documentation.
|
||||
|
||||
### User
|
||||
Solve SA-010: Avatar validation trusts the client MIME type.
|
||||
|
||||
### Assistant outcome
|
||||
Completed avatar hardening with Pillow: uploads are size-limited, decoded and verified rather than trusted by MIME type, bounded to 25 megapixels, fully loaded, normalized to PNG, and served under a fixed `.png` path. Tests now verify PNG normalization and rejection of fake image bytes. SA-010 is marked remediated with `nosniff` and media-origin isolation retained as deployment hardening.
|
||||
|
||||
### User
|
||||
Run full backend and frontend test suites.
|
||||
|
||||
### Assistant outcome
|
||||
The normal backend suite passed with 46 tests. Frontend and extension validation passed for all JavaScript syntax checks, JSON files, XPI rebuild, and unsigned XPI validation. The warnings-as-errors backend variant failed on unclosed SQLite connection `ResourceWarning` instances under Python 3.13; no functional tests failed.
|
||||
|
||||
### User
|
||||
Address SA-007 and use linklog.example.com as default LINKLOG_PUBLIC_URL.
|
||||
|
||||
### Assistant outcome
|
||||
Hardened the production Compose deployment by removing direct host port publication, keeping the app on the external Traefik network, and using `linklog.example.com` as the default public hostname. Added `docker-compose.local.yml` for explicit local direct-port development, updated `.env.example`, backend defaults, README deployment instructions, and SA-007 status.
|
||||
|
||||
### User
|
||||
Fix SA-009: TOTP enrollment has no recovery codes or reset workflow.
|
||||
|
||||
### Assistant outcome
|
||||
Implemented ten one-time hashed TOTP recovery codes, a password-protected `/api/user/otp/recover` workflow, password reauthentication for normal OTP disablement, one-time code consumption, and profile-page controls for saving and using recovery codes. Updated SA-009 and the deployment checklist.
|
||||
|
||||
### User
|
||||
Continue SA-06: Store session credentials in the narrowest available extension storage, minimize token lifetime, support refresh-token rotation, and clear all session material on logout or token invalidation.
|
||||
|
||||
### Assistant outcome
|
||||
Implemented SA-006 session hardening: access tokens now default to 15 minutes, refresh tokens are hashed and persisted separately with device and family binding, rotation revokes prior family state and detects reuse, and password reset revokes sessions. The extension uses Firefox session storage for credentials, refreshes on 401, clears session and legacy local token keys on invalidation/logout, requests only the configured backend origin, and uses a self-only extension-page CSP.
|
||||
|
||||
### User
|
||||
Also allow an admin to reset (disable) OTP for any user.
|
||||
|
||||
### Assistant outcome
|
||||
Added an administrator-only OTP reset endpoint and admin UI action. Resetting a user clears the OTP seed, disables OTP, and deletes all recovery codes. The operation never returns OTP secrets or recovery material and is covered by authorization, missing-user, state, and recovery-code invalidation tests.
|
||||
|
||||
### User
|
||||
Implement SA-006 permission changes: remove `<all_urls>` and unnecessary `tabs`, request exact access to the configured self-hosted backend, and keep page capture behind `activeTab`.
|
||||
|
||||
### Assistant outcome
|
||||
Updated the Firefox extension manifest to use `activeTab` and `storage` only, with Firefox-compatible optional HTTP/HTTPS host permissions. The options login page now normalizes the backend to an origin and requests only that origin during the user-initiated login. The popup checks that exact grant before session validation or link submission, so it does not perform backend calls without permission.
|
||||
|
||||
## 2026-08-24
|
||||
|
||||
### User
|
||||
@@ -1014,17 +1176,29 @@ Use the VIBE directory to log interactions
|
||||
### Assistant outcome
|
||||
Appended this visible interaction to the project VIBE chat and prompt logs in the repo’s append-only format.
|
||||
|
||||
### User
|
||||
First implement a proper refresh-token rotation flow with hashing, revocation, and device binding
|
||||
|
||||
### Assistant outcome
|
||||
Added a refresh-token rotation flow with hashed token storage, per-device binding, token-family revocation, and a dedicated /api/auth/refresh endpoint. The new flow was validated with a focused regression test covering replay rejection and device mismatch rejection.
|
||||
|
||||
### User
|
||||
Always update VIBE when finished with a step
|
||||
|
||||
### Assistant outcome
|
||||
Completed the final extension hardening pass: removed broad host permissions, validated exact backend origins before authenticated requests, kept auth tokens in session storage, cleared invalid-token state aggressively, and verified the extension syntax plus the focused backend auth tests.
|
||||
|
||||
### Assistant outcome
|
||||
Made popup state transitions defensive by synchronizing both `hidden` attributes and CSS classes. Non-authentication tag-loading errors no longer switch the popup to signed-out state; only a rejected session does. Added `display: none !important` guards for both authentication blocks.
|
||||
|
||||
### User
|
||||
Continue to document every prompt and chat in the VIBE directory.
|
||||
|
||||
### Assistant outcome
|
||||
Recorded this prompt and its outcome in `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md`. Future visible prompts and chat outcomes will continue to be appended there.
|
||||
|
||||
### User
|
||||
The release action should work differently. Rather than publishing the signed XPI and `updates.json`, it should produce a README describing the project, the latest Docker container version, and the latest signed XPI download URL with version number.
|
||||
|
||||
### Assistant outcome
|
||||
Changed the Gitea release workflow to generate `release-readme.md`, use it as the release body, and upload `README.md` as the release asset instead of publishing the signed XPI and `updates.json`. The README describes LinkLog, the Docker image pull location, and the raw signed XPI download URL.
|
||||
|
||||
### User
|
||||
The tagged version will be the version of the backend. However, the version of the plugin is set manually, just use the most recent signed plugin version that lives in the signed repo.
|
||||
|
||||
### Assistant outcome
|
||||
Decoupled backend and plugin release versions. The release tag and Docker image now use the backend `LINKLOG_VERSION`; the workflow discovers the newest semver signed artifact in `XPI/signed/`, validates its embedded manifest, and writes the plugin version and raw XPI URL into the generated release README. Updated release documentation and validated the script, workflow run blocks, and generated README output.
|
||||
|
||||
### User
|
||||
Update the VIBE directory with what you have done.
|
||||
|
||||
### Assistant outcome
|
||||
Appended the release workflow changes and this VIBE update request to `VIBE/PROMPTS.md` and `VIBE/CHAT_LOG.md` in the existing append-only format.
|
||||
|
||||
+125
-96
@@ -87,102 +87,131 @@
|
||||
83. Add a copyright statement to source files refer to GNU license
|
||||
84. Add the version to the name of the resulting xpi
|
||||
85. Set the version number of the backend to 0.1.0
|
||||
84. Add the creation of an xpi bundle for the webextention to the Makefile
|
||||
85. Correct: A signed XPI will be generated manually and checked into the repository under XPI/signed
|
||||
86. The "data_collection_permissions" property is missing from the plugin
|
||||
87. Validate the XPI during the make process of the unsigned xpi
|
||||
88. pressing remove still does not remove a user.
|
||||
89. Trying to remove user alice: Could not remove alice: Internal Server Error
|
||||
90. create a gitea action that is ran every time main is updated and that creates a docker image tagged development
|
||||
91. Use an access token to publish to registry, not username and password
|
||||
92. Add SMTP capabilities to the backend. Use it to validate the email addresses using a validation link in mail
|
||||
93. Do not configure default users at bootstrap. Instead present a configuration page (only present if no administrator is configured). The configuration page asks for the admin users credetials and allows to configure the SMTP settings and sends a test mail after configuration
|
||||
94. After saving the configuration - add link to home page together with "LinkLog is configured and the SMTP test mail was sent."
|
||||
95. In the confiuration seperate the safe and send mail functionality. Allow the user to resend test mail 5 times with a 20 seconds interval and then hold back for 2 minutes - show a visual timer counting down.
|
||||
96. when running the initial config use the defaults from the .env file when available
|
||||
97. Use oauth to register with the mastodon account and obtain access to post
|
||||
98. Allow user to enter the mastodon server to authenticate to
|
||||
99. Clicking authenticate with this server (social.secret-wg.org) generates 502 error
|
||||
100. Log the unlogged chat and promt in the VIBE directory
|
||||
101. when password is mistyped send a password reset link
|
||||
102. when running the initial config use the defaults from the .env file when available
|
||||
103. After saving the configuration - add link to home page together with "LinkLog is configured and the SMTP test mail was sent."
|
||||
104. In the confiuration seperate the safe and send mail functionality. Allow the user to resend test mail 5 times with a 20 seconds interval and then hold back for 2 minutes - show a visual timer counting down.
|
||||
105. Use oauth to register with the mastodon account and obtain access to post
|
||||
106. Allow user to enter the mastodon server to authenticate to
|
||||
107. Log the unlogged chat and promt in the VIBE directory
|
||||
108. Continue to log prompts and chats in VIBE
|
||||
109. use VIVE that is in the current directory
|
||||
110. Posting to mastodon seems to fail, try to fix, add debug logging
|
||||
111. LINKLOG_PUBLIC_URL and TRAEFIK_HOST are the same and can be merged. (use LINKLOG_PUBLIC_URL), fix docker-compose to use said variable
|
||||
112. Format mastodon posts like From my #LinkLog: Title, optional comment, and from: URL
|
||||
113. Only print the 'from' line if there is no title. Put the title directly behind the colon, and put all tags on the last line.
|
||||
114. In the frontend do not show edit buttons on the home page even when a user is logged in. On the /<user>/ page show the edit button on the right of the entry. Also add a delete button.
|
||||
115. Put the buttons on the right hand side of the link item, make the buttons smaller and same color scheme
|
||||
116. Put the mastodon button on the lower right corner of the log entry
|
||||
117. Make sure that the makefile also rebuilds XPI if any of its source files are changed
|
||||
117. Change that location to be immediately below the edit and delete button
|
||||
116. When the user is authorized and on its /<user>/ page show a Mastodon post button with logo; after posting keep it functional but change its color.
|
||||
117. Continue to log interactions to the VIBE directory.
|
||||
118. On the home page, when clicking on the avatar or the user, show the profile information.
|
||||
119. Localize the firefox plugin.
|
||||
120. Create a spanish, german, french and dutch locale.
|
||||
121. On the admin page add the SMTP settings (with the validation button).
|
||||
122. Populate the SMTP fields with the current values except for the password. Send the testmail to the currently authenticated admin user. Only use updated fields when testing. Use the same logic as in the configuration page to restrict endless testing.
|
||||
123. Report any errors that may occur from the SMTP module to the user.
|
||||
124. In the admin screen allow to select multiple themes for the backend. Create at least one plain day and one night theme, and add in all catpuccin themes for good measure.
|
||||
125. For the day and latte themes the contrast on the link items is too low.
|
||||
126. Add 3 other of the most popular themes.
|
||||
127. Show the tags in the linklog on the bottom left, move the date to the bottom right - horizontally align the tags with the date.
|
||||
128. Continue todos.
|
||||
129. Do not show 'no comment provided' but leave empty when no comment has been provided.
|
||||
130. Decrease the space between link-log items.
|
||||
131. Perform the next items on the todo list.
|
||||
132. Correct: move the sort and filter toolbar underneath the theme and menu, in the header, on the home page and on the <user> pages.
|
||||
133. Run frontend and style checks.
|
||||
134. Keep the sort and filter bar left of the logo and pack it snug against the menu and theme selector.
|
||||
135. Correction: the feed header should have the sort and filter bar to the right of the LinkLog logo, compact and underneath the theme selector and menu.
|
||||
136. When a log entry is deleted then all mastodon posts are deleted too.
|
||||
137. Don't forget to update the plugin to work with OTP.
|
||||
138. When the user is not logged in then the plugin should just display no form fields but warn the user that they have to log in with a link to settings.
|
||||
139. Remove DEFAULT_BACKEND setting in the plugin.
|
||||
140. Change the title of the field "One-time password" to "One-time password (when configured)".
|
||||
157. The plugin settings still show 'emailLabel'; make that 'email' as title for the email field.
|
||||
163. When a URL with the same title is already in the database, warn the user, allow comment and hashtag changes, and retrigger plugins such as Mastodon reposting.
|
||||
166. Display any errors that occur during posting.
|
||||
164. When the plugin is activated and the link already exists, show "This link already exists. Comment and tags can be updated, and by submitting publishing will be retriggered."
|
||||
165. When pressing save link the plugin should display "Link saved to <url of linklog server>" and hide all other information. It should only refresh when the plugin is opened again
|
||||
141. Remove any leading and trailing spaces when entering fields in the settings page of the plugin.
|
||||
142. Do a full security audit document in what you have done in detail in Security-audit.md
|
||||
143. Address issue 1. and improve password storage
|
||||
144. The login page should ask for OTP password
|
||||
145. For the new password in the user setting add a validation field to make sure they are the same before submitting
|
||||
146. Change so that authentication is based on email address rather than username - maintain the username for presentation purposes
|
||||
147. Make sure the web plugin follows same logic
|
||||
154. Implement the recommendation for ### SA-002: Bearer tokens accepted in query strings
|
||||
146. Change so that authentication is based on email address rather than username - maintain the username for presentation purposes
|
||||
147. Make sure the web plugin follows same logic
|
||||
148. In the plugin <span data-i18n="emailLabel">emailLabel</span> should read: <span data-i18n="emailLabel">Email</span>
|
||||
149. Allow addition of secondary or tertiary email addresses; validate them before authentication and support profile status/resend controls with holdback.
|
||||
150. Enable the user to change primary email address and remove the original one while maintaining access and rights.
|
||||
151. Choose primary email from already verified alternative email addresses and increase the number of alternative email addresses allowed to 5.
|
||||
152. Make sure an email can only be selected when it has been validated.
|
||||
153. Remove the entire "New primary email address" block; keep only selecting an existing alternative as primary.
|
||||
155. Remove the “New primary email address” functionality and keep only selecting an existing alternative as primary.
|
||||
166. Address SA-003 by using a dedicated secret key supplied through a protected environment/secret file, encrypt sensitive values before SQLite storage
|
||||
167. Address SA-004 by validating Mastodon instances as HTTPS public hostnames, rejecting unsafe DNS/IP ranges including mapped IPv6, and blocking redirects
|
||||
168. Implement SA-005: login endpoint lacks rate limiting and lockout
|
||||
167. Address SA-004 by validating Mastodon instances as HTTPS public hostnames, rejecting unsafe DNS/IP ranges including mapped IPv6, and blocking redirects.
|
||||
158. When the user is logged in the webplugin should not display "Please sign in to use LinkLog."
|
||||
156. When the user is signed in the plugin should not display "Please sign in to use LinkLog." and the link to the settings
|
||||
159. The plugin still does not behave as expected. It still shows that the user should sign in.
|
||||
160. In the popup show that the user has logged in.
|
||||
166. Address SA-003 by using a dedicated secret key supplied through a protected environment/secret file, encrypt sensitive values before SQLite storage
|
||||
161. The popup still shows the sign-in block even though the authenticated session text is displayed; show the block only when signed out.
|
||||
162. The authenticated session text and sign-in block are still shown together.
|
||||
163. Use the VIBE directory to log interactions.
|
||||
164. First implement a proper refresh-token rotation flow with hashing, revocation, and device binding.
|
||||
165. Always update VIBE when finished with a step.
|
||||
86. Add the creation of an xpi bundle for the webextention to the Makefile
|
||||
87. Correct: A signed XPI will be generated manually and checked into the repository under XPI/signed
|
||||
88. The "data_collection_permissions" property is missing from the plugin
|
||||
89. Validate the XPI during the make process of the unsigned xpi
|
||||
90. pressing remove still does not remove a user.
|
||||
91. Trying to remove user alice: Could not remove alice: Internal Server Error
|
||||
92. create a gitea action that is ran every time main is updated and that creates a docker image tagged development
|
||||
93. Use an access token to publish to registry, not username and password
|
||||
94. Add SMTP capabilities to the backend. Use it to validate the email addresses using a validation link in mail
|
||||
95. Do not configure default users at bootstrap. Instead present a configuration page (only present if no administrator is configured). The configuration page asks for the admin users credetials and allows to configure the SMTP settings and sends a test mail after configuration
|
||||
96. After saving the configuration - add link to home page together with "LinkLog is configured and the SMTP test mail was sent."
|
||||
97. In the confiuration seperate the safe and send mail functionality. Allow the user to resend test mail 5 times with a 20 seconds interval and then hold back for 2 minutes - show a visual timer counting down.
|
||||
98. when running the initial config use the defaults from the .env file when available
|
||||
99. Use oauth to register with the mastodon account and obtain access to post
|
||||
100. Allow user to enter the mastodon server to authenticate to
|
||||
101. Clicking authenticate with this server (social.secret-wg.org) generates 502 error
|
||||
102. Log the unlogged chat and promt in the VIBE directory
|
||||
103. when password is mistyped send a password reset link
|
||||
104. when running the initial config use the defaults from the .env file when available
|
||||
105. After saving the configuration - add link to home page together with "LinkLog is configured and the SMTP test mail was sent."
|
||||
106. In the confiuration seperate the safe and send mail functionality. Allow the user to resend test mail 5 times with a 20 seconds interval and then hold back for 2 minutes - show a visual timer counting down.
|
||||
107. Use oauth to register with the mastodon account and obtain access to post
|
||||
108. Allow user to enter the mastodon server to authenticate to
|
||||
109. Log the unlogged chat and promt in the VIBE directory
|
||||
110. Continue to log prompts and chats in VIBE
|
||||
111. use VIVE that is in the current directory
|
||||
112. Posting to mastodon seems to fail, try to fix, add debug logging
|
||||
113. LINKLOG_PUBLIC_URL and TRAEFIK_HOST are the same and can be merged. (use LINKLOG_PUBLIC_URL), fix docker-compose to use said variable
|
||||
114. Format mastodon posts like From my #LinkLog: Title, optional comment, and from: URL
|
||||
115. Only print the 'from' line if there is no title. Put the title directly behind the colon, and put all tags on the last line.
|
||||
116. In the frontend do not show edit buttons on the home page even when a user is logged in. On the /<user>/ page show the edit button on the right of the entry. Also add a delete button.
|
||||
117. Put the buttons on the right hand side of the link item, make the buttons smaller and same color scheme
|
||||
118. Put the mastodon button on the lower right corner of the log entry
|
||||
119. Make sure that the makefile also rebuilds XPI if any of its source files are changed
|
||||
120. Change that location to be immediately below the edit and delete button
|
||||
121. When the user is authorized and on its /<user>/ page show a Mastodon post button with logo; after posting keep it functional but change its color.
|
||||
122. Continue to log interactions to the VIBE directory.
|
||||
123. On the home page, when clicking on the avatar or the user, show the profile information.
|
||||
124. Localize the firefox plugin.
|
||||
125. Create a spanish, german, french and dutch locale.
|
||||
126. On the admin page add the SMTP settings (with the validation button).
|
||||
127. Populate the SMTP fields with the current values except for the password. Send the testmail to the currently authenticated admin user. Only use updated fields when testing. Use the same logic as in the configuration page to restrict endless testing.
|
||||
128. Report any errors that may occur from the SMTP module to the user.
|
||||
129. In the admin screen allow to select multiple themes for the backend. Create at least one plain day and one night theme, and add in all catpuccin themes for good measure.
|
||||
130. For the day and latte themes the contrast on the link items is too low.
|
||||
131. Add 3 other of the most popular themes.
|
||||
132. Show the tags in the linklog on the bottom left, move the date to the bottom right - horizontally align the tags with the date.
|
||||
133. Continue todos.
|
||||
134. Do not show 'no comment provided' but leave empty when no comment has been provided.
|
||||
135. Decrease the space between link-log items.
|
||||
136. Perform the next items on the todo list.
|
||||
137. Correct: move the sort and filter toolbar underneath the theme and menu, in the header, on the home page and on the <user> pages.
|
||||
138. Run frontend and style checks.
|
||||
139. Keep the sort and filter bar left of the logo and pack it snug against the menu and theme selector.
|
||||
140. Correction: the feed header should have the sort and filter bar to the right of the LinkLog logo, compact and underneath the theme selector and menu.
|
||||
141. When a log entry is deleted then all mastodon posts are deleted too.
|
||||
142. Don't forget to update the plugin to work with OTP.
|
||||
143. When the user is not logged in then the plugin should just display no form fields but warn the user that they have to log in with a link to settings.
|
||||
144. Remove DEFAULT_BACKEND setting in the plugin.
|
||||
145. Change the title of the field "One-time password" to "One-time password (when configured)".
|
||||
146. The plugin settings still show 'emailLabel'; make that 'email' as title for the email field.
|
||||
147. When a URL with the same title is already in the database, warn the user, allow comment and hashtag changes, and retrigger plugins such as Mastodon reposting.
|
||||
148. Display any errors that occur during posting.
|
||||
149. When the plugin is activated and the link already exists, show "This link already exists. Comment and tags can be updated, and by submitting publishing will be retriggered."
|
||||
150. When pressing save link the plugin should display "Link saved to <url of linklog server>" and hide all other information. It should only refresh when the plugin is opened again
|
||||
151. Remove any leading and trailing spaces when entering fields in the settings page of the plugin.
|
||||
152. Do a full security audit document in what you have done in detail in Security-audit.md
|
||||
153. Address issue 1. and improve password storage
|
||||
154. The login page should ask for OTP password
|
||||
155. For the new password in the user setting add a validation field to make sure they are the same before submitting
|
||||
156. Change so that authentication is based on email address rather than username - maintain the username for presentation purposes
|
||||
157. Make sure the web plugin follows same logic
|
||||
158. Implement the recommendation for ### SA-002: Bearer tokens accepted in query strings
|
||||
159. Change so that authentication is based on email address rather than username - maintain the username for presentation purposes
|
||||
160. Make sure the web plugin follows same logic
|
||||
161. In the plugin <span data-i18n="emailLabel">emailLabel</span> should read: <span data-i18n="emailLabel">Email</span>
|
||||
162. Allow addition of secondary or tertiary email addresses; validate them before authentication and support profile status/resend controls with holdback.
|
||||
163. Enable the user to change primary email address and remove the original one while maintaining access and rights.
|
||||
164. Choose primary email from already verified alternative email addresses and increase the number of alternative email addresses allowed to 5.
|
||||
165. Make sure an email can only be selected when it has been validated.
|
||||
166. Remove the entire "New primary email address" block; keep only selecting an existing alternative as primary.
|
||||
167. Remove the “New primary email address” functionality and keep only selecting an existing alternative as primary.
|
||||
168. Address SA-003 by using a dedicated secret key supplied through a protected environment/secret file, encrypt sensitive values before SQLite storage
|
||||
169. Address SA-004 by validating Mastodon instances as HTTPS public hostnames, rejecting unsafe DNS/IP ranges including mapped IPv6, and blocking redirects
|
||||
170. Implement SA-005: login endpoint lacks rate limiting and lockout
|
||||
171. Address SA-004 by validating Mastodon instances as HTTPS public hostnames, rejecting unsafe DNS/IP ranges including mapped IPv6, and blocking redirects.
|
||||
172. When the user is logged in the webplugin should not display "Please sign in to use LinkLog."
|
||||
173. When the user is signed in the plugin should not display "Please sign in to use LinkLog." and the link to the settings
|
||||
174. The plugin still does not behave as expected. It still shows that the user should sign in.
|
||||
175. In the popup show that the user has logged in.
|
||||
176. Address SA-003 by using a dedicated secret key supplied through a protected environment/secret file, encrypt sensitive values before SQLite storage
|
||||
177. The popup still shows the sign-in block even though the authenticated session text is displayed; show the block only when signed out.
|
||||
178. The authenticated session text and sign-in block are still shown together.
|
||||
179. Use the VIBE directory to log interactions.
|
||||
180. Implement SA-006: remove broad Firefox extension host access and unnecessary tabs permission, request exact configured backend origin access, and keep page capture behind activeTab.
|
||||
181. Continue to document every prompt and chat in the VIBE directory.
|
||||
182. Continue SA-006: store session credentials in the narrowest available extension storage, minimize token lifetime, support refresh-token rotation, and clear all session material on logout or token invalidation.
|
||||
183. Also allow an admin to reset (disable) OTP for any user.
|
||||
183. Fix SA-009: TOTP enrollment has no recovery codes or reset workflow.
|
||||
183. Address SA-007 and use linklog.example.com as the default LINKLOG_PUBLIC_URL.
|
||||
184. Run full backend and frontend test suites.
|
||||
185. Solve SA-010: Avatar validation trusts the client MIME type.
|
||||
186. Fix SA-015: Some destructive and administrative operations lack audit logging.
|
||||
187. Format sent mail in the website style and include the logo.
|
||||
188. Set the email logo to 120px wide and center it at the top.
|
||||
189. Make the email logo 50px by 50px, place it top-left, and put "Hello" to its right in the Asset font.
|
||||
190. Replace the email greeting with "Hello a message from <public hostname>", linking the hostname to the LinkLog server.
|
||||
191. Put the email header text to the right of the logo, align it at the top, and add a comma after Hello.
|
||||
192. Put the email greeting in a separate top-aligned cell to the right of the logo.
|
||||
193. Reduce the email greeting font size somewhat.
|
||||
194. Replace LINKLOG_TOKEN_EXPIRY_DAYS with LINKLOG_TOKEN_EXPIRY_MINUTES, add LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS to production Compose, and add a CI configuration consistency test.
|
||||
195. Perform a new security audit overwriting Security-audit.md with new and remaining issues.
|
||||
195. Update SA-012 and README for the implemented refresh-token lifecycle, revocation behavior, and refresh endpoint.
|
||||
196. Remedy SA-001: migrate logout from JSON token transport to the Authorization bearer header.
|
||||
197. Implement SA-002: replace raw infrastructure errors with redacted server-side logging, request IDs, and stable public reference messages.
|
||||
198. Implement SA-005: reject missing/default/weak production secrets at startup and validate the Fernet encryption key, with configuration tests.
|
||||
199. Fix Firefox manifest compatibility warnings by aligning the minimum version with data collection permissions and session storage support.
|
||||
200. Add a Plugin section to the About page with a download link to the signed XPI file.
|
||||
201. Below the Save profile button, add a link to download the signed plugin if it has not been downloaded yet.
|
||||
202. Check the modified pages for the correct versioned signed XPI link.
|
||||
203. When posting to Mastodon, add an empty line between "From my #LinkLog:" and the title.
|
||||
204. Fix the release workflow because the runner's curl does not support `--fail-with-body`.
|
||||
205. The release action should work differently. Rather than publishing the signed XPI and `updates.json`, it should produce a README describing the project, the latest Docker container version, and the latest signed XPI download URL with version number.
|
||||
206. The tagged version will be the version of the backend. However, the version of the plugin is set manually, just use the most recent signed plugin version that lives in the signed repo.
|
||||
207. Update the VIBE directory with what you have done.
|
||||
|
||||
## Future entries
|
||||
|
||||
|
||||
Binary file not shown.
Binary file not shown.
@@ -5,7 +5,7 @@ import json
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from uuid import uuid4
|
||||
|
||||
from fastapi import APIRouter, Depends, HTTPException
|
||||
from fastapi import APIRouter, Depends, HTTPException, Request
|
||||
from pydantic import BaseModel
|
||||
|
||||
from backend.app.api.dependencies import require_admin
|
||||
@@ -22,8 +22,12 @@ from backend.app.services.email_verification import create_verification_token
|
||||
from backend.app.services.theme_service import THEMES, get_enabled_themes, save_enabled_themes
|
||||
from backend.app.services.secret_store import encrypt_secret
|
||||
from backend.app.core.config import settings
|
||||
from backend.app.services.audit_service import record_audit_event
|
||||
from backend.app.core.errors import public_error, redacted_error, request_id
|
||||
import logging
|
||||
|
||||
router = APIRouter()
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
class AdminPluginUpdate(BaseModel):
|
||||
@@ -94,8 +98,24 @@ def list_users(_: dict = Depends(require_admin)):
|
||||
return [public_user(row) for row in rows]
|
||||
|
||||
|
||||
@router.post('/users/{user_id}/otp/reset')
|
||||
def reset_user_otp(user_id: str, current_user: dict = Depends(require_admin)):
|
||||
with get_connection() as conn:
|
||||
target = conn.execute('SELECT id FROM users WHERE id = ?', (user_id,)).fetchone()
|
||||
if target is None:
|
||||
raise HTTPException(status_code=404, detail='User not found')
|
||||
conn.execute(
|
||||
'UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?',
|
||||
(user_id,),
|
||||
)
|
||||
conn.execute('DELETE FROM otp_recovery_codes WHERE user_id = ?', (user_id,))
|
||||
conn.commit()
|
||||
record_audit_event(current_user['id'], 'otp_reset', 'user', user_id)
|
||||
return {'status': 'otp_reset', 'enabled': False, 'user_id': user_id}
|
||||
|
||||
|
||||
@router.post('/users', status_code=201)
|
||||
def create_user(payload: AdminUserCreate, _: dict = Depends(require_admin)):
|
||||
def create_user(payload: AdminUserCreate, request: Request, current_user: dict = Depends(require_admin)):
|
||||
username = payload.username.strip()
|
||||
email = payload.email.strip()
|
||||
if not username or not email or len(payload.password) < 8:
|
||||
@@ -125,7 +145,9 @@ def create_user(payload: AdminUserCreate, _: dict = Depends(require_admin)):
|
||||
try:
|
||||
send_verification_email(row['email'], row['username'], verification_url)
|
||||
except Exception as error:
|
||||
raise HTTPException(status_code=503, detail=f'User created but verification email could not be sent: {error}') from error
|
||||
logger.error('User verification email failed request_id=%s error=%s', request_id(request), redacted_error(error))
|
||||
raise HTTPException(status_code=503, detail=public_error(request, 'User created but verification email could not be sent.')) from error
|
||||
record_audit_event(current_user['id'], 'user_created', 'user', row['id'], details={'is_admin': bool(payload.is_admin)})
|
||||
return public_user(row)
|
||||
|
||||
|
||||
@@ -151,24 +173,26 @@ def get_admin_themes(_: dict = Depends(require_admin)):
|
||||
|
||||
|
||||
@router.put('/themes')
|
||||
def update_admin_themes(payload: AdminThemesUpdate, _: dict = Depends(require_admin)):
|
||||
def update_admin_themes(payload: AdminThemesUpdate, current_user: dict = Depends(require_admin)):
|
||||
try:
|
||||
enabled = save_enabled_themes(payload.themes)
|
||||
except ValueError as error:
|
||||
raise HTTPException(status_code=422, detail=str(error)) from error
|
||||
record_audit_event(current_user['id'], 'themes_updated', 'application', details={'themes': enabled})
|
||||
return {'themes': THEMES, 'enabled': enabled}
|
||||
|
||||
|
||||
@router.put('/smtp')
|
||||
def update_admin_smtp_settings(payload: AdminSmtpUpdate, _: dict = Depends(require_admin)):
|
||||
def update_admin_smtp_settings(payload: AdminSmtpUpdate, current_user: dict = Depends(require_admin)):
|
||||
current = get_smtp_settings()
|
||||
values = validate_smtp_values(payload, current)
|
||||
save_smtp_settings(values)
|
||||
record_audit_event(current_user['id'], 'smtp_settings_updated', 'application', details={'host': values['smtp_host'], 'port': values['smtp_port'], 'username': values['smtp_username'], 'tls': values['smtp_use_tls']})
|
||||
return public_smtp_settings(values)
|
||||
|
||||
|
||||
@router.post('/smtp/test')
|
||||
def validate_admin_smtp(payload: AdminSmtpUpdate, current_user: dict = Depends(require_admin)):
|
||||
def validate_admin_smtp(payload: AdminSmtpUpdate, request: Request, current_user: dict = Depends(require_admin)):
|
||||
values = validate_smtp_values(payload, get_smtp_settings())
|
||||
now = datetime.now(timezone.utc)
|
||||
with get_connection() as conn:
|
||||
@@ -189,7 +213,8 @@ def validate_admin_smtp(payload: AdminSmtpUpdate, current_user: dict = Depends(r
|
||||
try:
|
||||
send_test_email(current_user['email'], values)
|
||||
except Exception as error:
|
||||
raise HTTPException(status_code=503, detail=f'SMTP validation failed: {error}') from error
|
||||
logger.error('SMTP validation failed request_id=%s error=%s', request_id(request), redacted_error(error))
|
||||
raise HTTPException(status_code=503, detail=public_error(request, 'SMTP validation failed.')) from error
|
||||
sends = int(rate.get('sends', 0)) + 1
|
||||
updated_rate = {'sends': sends, 'last_sent': now.isoformat()}
|
||||
if sends >= 5:
|
||||
@@ -244,6 +269,7 @@ def update_user_privileges(
|
||||
'SELECT id, username, email, is_admin, avatar_url, bio, created_at, email_verified FROM users WHERE id = ?',
|
||||
(user_id,),
|
||||
).fetchone()
|
||||
record_audit_event(current_user['id'], 'user_privileges_updated', 'user', user_id, details={'is_admin': bool(payload.is_admin)})
|
||||
return public_user(row)
|
||||
|
||||
|
||||
@@ -266,13 +292,15 @@ def delete_user(user_id: str, current_user: dict = Depends(require_admin)):
|
||||
conn.execute('DELETE FROM links WHERE user_id = ?', (user_id,))
|
||||
conn.execute('DELETE FROM users WHERE id = ?', (user_id,))
|
||||
conn.commit()
|
||||
record_audit_event(current_user['id'], 'user_deleted', 'user', user_id)
|
||||
return {'status': 'deleted', 'id': user_id}
|
||||
|
||||
|
||||
@router.delete('/labels/{label_id}')
|
||||
def admin_delete_label(label_id: str, _: dict = Depends(require_admin)):
|
||||
def admin_delete_label(label_id: str, current_user: dict = Depends(require_admin)):
|
||||
if not delete_label(label_id, is_admin=True):
|
||||
raise HTTPException(status_code=404, detail='Label not found')
|
||||
record_audit_event(current_user['id'], 'label_deleted', 'label', label_id)
|
||||
return {'status': 'deleted', 'id': label_id}
|
||||
|
||||
|
||||
@@ -331,7 +359,7 @@ def get_plugin(plugin_name: str, _: dict = Depends(require_admin)):
|
||||
def update_plugin(
|
||||
plugin_name: str,
|
||||
payload: AdminPluginUpdate,
|
||||
_: dict = Depends(require_admin),
|
||||
current_user: dict = Depends(require_admin),
|
||||
):
|
||||
with get_connection() as conn:
|
||||
current = conn.execute(
|
||||
@@ -360,6 +388,7 @@ def update_plugin(
|
||||
)
|
||||
conn.commit()
|
||||
|
||||
record_audit_event(current_user['id'], 'plugin_updated', 'plugin', plugin_name, details={'enabled': enabled})
|
||||
return {
|
||||
'name': plugin_name,
|
||||
'enabled': enabled,
|
||||
|
||||
@@ -3,7 +3,7 @@
|
||||
|
||||
from uuid import uuid4
|
||||
|
||||
from fastapi import APIRouter, Depends, HTTPException, Request
|
||||
from fastapi import APIRouter, Depends, Header, HTTPException, Request
|
||||
from pydantic import BaseModel
|
||||
|
||||
from backend.app.api.dependencies import get_current_user
|
||||
@@ -119,10 +119,12 @@ def reset_password_endpoint(payload: PasswordResetRequest):
|
||||
|
||||
|
||||
@router.post('/logout')
|
||||
def logout(payload: dict):
|
||||
token = payload.get('token')
|
||||
def logout(authorization: str | None = Header(default=None)):
|
||||
if not authorization or not authorization.startswith('Bearer '):
|
||||
raise HTTPException(status_code=401, detail='Missing or invalid Authorization header')
|
||||
token = authorization.replace('Bearer ', '', 1).strip()
|
||||
if not token:
|
||||
raise HTTPException(status_code=400, detail='Token is required')
|
||||
raise HTTPException(status_code=401, detail='Missing or invalid Authorization header')
|
||||
revoked = revoke_token(token)
|
||||
if not revoked:
|
||||
raise HTTPException(status_code=404, detail='Token not found or already revoked')
|
||||
|
||||
@@ -10,6 +10,7 @@ from backend.app.services.link_service import create_link, delete_link, find_own
|
||||
from backend.app.database import get_connection
|
||||
from backend.app.services.plugin_manager import plugin_manager
|
||||
from backend.app.services.token_service import validate_token
|
||||
from backend.app.services.audit_service import record_audit_event
|
||||
|
||||
router = APIRouter()
|
||||
logger = logging.getLogger(__name__)
|
||||
@@ -127,6 +128,7 @@ def delete_link_endpoint(
|
||||
raise HTTPException(status_code=502, detail=result.get('reason', 'Could not delete Mastodon posts'))
|
||||
if not delete_link(link_id, info['user_id']):
|
||||
raise HTTPException(status_code=404, detail='Link not found or not owned by user')
|
||||
record_audit_event(info['user_id'], 'link_deleted', 'link', link_id)
|
||||
return {'status': 'deleted', 'id': link_id}
|
||||
|
||||
|
||||
@@ -150,6 +152,7 @@ def post_link_to_mastodon(
|
||||
result = plugin_manager.post_to_mastodon({'type': 'link_created', **event})
|
||||
if result.get('status') == 'posted':
|
||||
mark_mastodon_posted(link_id, info['user_id'], result.get('post_id'))
|
||||
record_audit_event(info['user_id'], 'mastodon_posted', 'link', link_id)
|
||||
return {'status': 'posted', 'post_id': result.get('post_id')}
|
||||
if result.get('status') == 'skipped':
|
||||
raise HTTPException(status_code=409, detail='Mastodon is not enabled or configured')
|
||||
|
||||
@@ -10,12 +10,15 @@ from starlette.requests import Request
|
||||
|
||||
from backend.app.api.dependencies import get_current_user
|
||||
from backend.app.services.mastodon_oauth import finish_authorization, start_authorization
|
||||
from backend.app.core.errors import public_error, redacted_error, request_id
|
||||
import logging
|
||||
|
||||
router = APIRouter()
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
@router.get('/oauth/start')
|
||||
def oauth_start(instance: str = 'mastodon.social', user: dict = Depends(get_current_user)):
|
||||
def oauth_start(request: Request, instance: str = 'mastodon.social', user: dict = Depends(get_current_user)):
|
||||
try:
|
||||
authorization_url = start_authorization(user['id'], instance)
|
||||
except HTTPError as error:
|
||||
@@ -27,7 +30,8 @@ def oauth_start(instance: str = 'mastodon.social', user: dict = Depends(get_curr
|
||||
headers=headers,
|
||||
) from error
|
||||
except Exception as error:
|
||||
raise HTTPException(status_code=502, detail=f'Could not register with Mastodon: {error}') from error
|
||||
logger.error('Mastodon registration failed request_id=%s error=%s', request_id(request), redacted_error(error))
|
||||
raise HTTPException(status_code=502, detail=public_error(request, 'Could not register with Mastodon.')) from error
|
||||
return {'authorization_url': authorization_url}
|
||||
|
||||
|
||||
@@ -38,5 +42,6 @@ def oauth_callback(request: Request, code: str | None = None, state: str | None
|
||||
try:
|
||||
finish_authorization(code, state)
|
||||
except Exception as callback_error:
|
||||
return RedirectResponse(f'/profile?mastodon_error={quote(str(callback_error))}')
|
||||
logger.error('Mastodon callback failed request_id=%s error=%s', request_id(request), redacted_error(callback_error))
|
||||
return RedirectResponse(f'/profile?mastodon_error={quote(public_error(request, "Could not complete Mastodon authorization."))}')
|
||||
return RedirectResponse('/profile?mastodon=connected')
|
||||
@@ -5,14 +5,17 @@ from datetime import datetime, timedelta, timezone
|
||||
import json
|
||||
from uuid import uuid4
|
||||
|
||||
from fastapi import APIRouter, HTTPException
|
||||
from fastapi import APIRouter, HTTPException, Request
|
||||
from pydantic import BaseModel
|
||||
|
||||
from backend.app.core.config import settings
|
||||
from backend.app.database import get_connection, hash_password
|
||||
from backend.app.services.email_service import get_smtp_settings, save_smtp_settings, send_test_email
|
||||
from backend.app.core.errors import public_error, redacted_error, request_id
|
||||
import logging
|
||||
|
||||
router = APIRouter()
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
class SetupRequest(BaseModel):
|
||||
@@ -92,7 +95,7 @@ def save_configuration(payload: SetupRequest):
|
||||
|
||||
|
||||
@router.post('/test-mail')
|
||||
def test_mail(payload: TestMailRequest | None = None):
|
||||
def test_mail(request: Request, payload: TestMailRequest | None = None):
|
||||
if has_administrator():
|
||||
raise HTTPException(status_code=409, detail='LinkLog is already configured')
|
||||
pending = get_pending_setup()
|
||||
@@ -119,7 +122,8 @@ def test_mail(payload: TestMailRequest | None = None):
|
||||
try:
|
||||
send_test_email(payload.email if payload and payload.email else pending['email'])
|
||||
except Exception as error:
|
||||
raise HTTPException(status_code=503, detail=f'SMTP test mail could not be sent: {error}') from error
|
||||
logger.error('SMTP test mail failed request_id=%s error=%s', request_id(request), redacted_error(error))
|
||||
raise HTTPException(status_code=503, detail=public_error(request, 'SMTP test mail could not be sent.')) from error
|
||||
|
||||
sends = int(rate.get('sends', 0)) + 1
|
||||
updated_rate = {'sends': sends, 'last_sent': now.isoformat()}
|
||||
|
||||
@@ -2,22 +2,32 @@
|
||||
## SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
import json
|
||||
import warnings
|
||||
from io import BytesIO
|
||||
from datetime import datetime, timedelta, timezone
|
||||
from uuid import uuid4
|
||||
|
||||
from fastapi import APIRouter, Depends, File, HTTPException, UploadFile
|
||||
from fastapi import APIRouter, Depends, File, HTTPException, Request, UploadFile
|
||||
from PIL import Image, UnidentifiedImageError
|
||||
from pydantic import BaseModel
|
||||
|
||||
from backend.app.api.dependencies import get_current_user
|
||||
from backend.app.database import AVATARS_DIR, get_connection, hash_password, verify_password
|
||||
from backend.app.services.link_service import create_label, delete_label, list_user_labels, update_label
|
||||
from backend.app.services.otp_service import create_secret, provisioning_uri, verify_code
|
||||
from backend.app.services.otp_service import consume_recovery_code, create_recovery_codes, create_secret, provisioning_uri, verify_code
|
||||
from backend.app.services.email_addresses import add_user_email_address, create_email_verification, list_user_email_addresses
|
||||
from backend.app.services.email_service import send_verification_email, smtp_configured
|
||||
from backend.app.core.config import settings
|
||||
from backend.app.services.secret_store import decrypt_secret, encrypt_secret
|
||||
from backend.app.services.audit_service import record_audit_event
|
||||
from backend.app.core.errors import public_error, redacted_error, request_id
|
||||
import logging
|
||||
|
||||
router = APIRouter()
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
MAX_AVATAR_BYTES = 2 * 1024 * 1024
|
||||
MAX_AVATAR_PIXELS = 25_000_000
|
||||
|
||||
|
||||
class UserConfigUpdate(BaseModel):
|
||||
@@ -32,12 +42,19 @@ class PasswordUpdate(BaseModel):
|
||||
class OtpUpdate(BaseModel):
|
||||
action: str
|
||||
code: str | None = None
|
||||
current_password: str | None = None
|
||||
recovery_code: str | None = None
|
||||
|
||||
|
||||
class AdditionalEmail(BaseModel):
|
||||
email: str
|
||||
|
||||
|
||||
class OtpRecovery(BaseModel):
|
||||
current_password: str
|
||||
recovery_code: str
|
||||
|
||||
|
||||
|
||||
class UserPluginConfigUpdate(BaseModel):
|
||||
instance: str | None = None
|
||||
@@ -103,6 +120,7 @@ def update_password(payload: PasswordUpdate, user: dict = Depends(get_current_us
|
||||
(hash_password(payload.new_password), user['id']),
|
||||
)
|
||||
conn.commit()
|
||||
record_audit_event(user['id'], 'password_changed', 'user', user['id'])
|
||||
return {'status': 'password_updated'}
|
||||
|
||||
|
||||
@@ -119,14 +137,25 @@ def setup_otp(user: dict = Depends(get_current_user)):
|
||||
with get_connection() as conn:
|
||||
conn.execute('UPDATE users SET otp_secret = ?, updated_at = CURRENT_TIMESTAMP WHERE id = ?', (encrypt_secret(secret), user['id']))
|
||||
conn.commit()
|
||||
return {'secret': secret, 'otpauth_url': provisioning_uri(secret, user['username'])}
|
||||
record_audit_event(user['id'], 'otp_enrolled', 'user', user['id'])
|
||||
return {
|
||||
'secret': secret,
|
||||
'otpauth_url': provisioning_uri(secret, user['username']),
|
||||
'recovery_codes': create_recovery_codes(user['id']),
|
||||
}
|
||||
|
||||
|
||||
@router.post('/otp')
|
||||
def update_otp(payload: OtpUpdate, user: dict = Depends(get_current_user)):
|
||||
if payload.action not in {'enable', 'disable'}:
|
||||
raise HTTPException(status_code=422, detail='OTP action must be enable or disable')
|
||||
if not verify_code(decrypt_secret(user['otp_secret']), payload.code):
|
||||
if payload.action == 'disable' and not payload.current_password:
|
||||
raise HTTPException(status_code=400, detail='Current password is required to disable one-time password')
|
||||
if payload.action == 'disable' and not verify_password(payload.current_password, user['password_hash']):
|
||||
raise HTTPException(status_code=400, detail='Current password is incorrect')
|
||||
valid_code = verify_code(decrypt_secret(user['otp_secret']), payload.code)
|
||||
valid_recovery_code = payload.action == 'disable' and payload.recovery_code and consume_recovery_code(user['id'], payload.recovery_code)
|
||||
if not valid_code and not valid_recovery_code:
|
||||
raise HTTPException(status_code=400, detail='Invalid one-time password')
|
||||
with get_connection() as conn:
|
||||
if payload.action == 'enable':
|
||||
@@ -134,16 +163,33 @@ def update_otp(payload: OtpUpdate, user: dict = Depends(get_current_user)):
|
||||
else:
|
||||
conn.execute('UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?', (user['id'],))
|
||||
conn.commit()
|
||||
record_audit_event(user['id'], f'otp_{payload.action}d', 'user', user['id'])
|
||||
return {'status': 'updated', 'enabled': payload.action == 'enable'}
|
||||
|
||||
|
||||
@router.post('/otp/recover')
|
||||
def recover_otp(payload: OtpRecovery, user: dict = Depends(get_current_user)):
|
||||
if not verify_password(payload.current_password, user['password_hash']):
|
||||
raise HTTPException(status_code=400, detail='Current password is incorrect')
|
||||
if not consume_recovery_code(user['id'], payload.recovery_code):
|
||||
raise HTTPException(status_code=400, detail='Recovery code is invalid or already used')
|
||||
with get_connection() as conn:
|
||||
conn.execute(
|
||||
'UPDATE users SET otp_enabled = 0, otp_secret = NULL, updated_at = CURRENT_TIMESTAMP WHERE id = ?',
|
||||
(user['id'],),
|
||||
)
|
||||
conn.commit()
|
||||
record_audit_event(user['id'], 'otp_recovered', 'user', user['id'])
|
||||
return {'status': 'otp_recovered', 'enabled': False}
|
||||
|
||||
|
||||
@router.get('/emails')
|
||||
def get_additional_emails(user: dict = Depends(get_current_user)):
|
||||
return [{'email': user['email'], 'verified': bool(user['email_verified']), 'primary': True}] + list_user_email_addresses(user['id'])
|
||||
|
||||
|
||||
@router.post('/emails', status_code=201)
|
||||
def add_additional_email(payload: AdditionalEmail, user: dict = Depends(get_current_user)):
|
||||
def add_additional_email(payload: AdditionalEmail, request: Request, user: dict = Depends(get_current_user)):
|
||||
email = payload.email.strip().lower()
|
||||
if email == user['email'].lower():
|
||||
raise HTTPException(status_code=409, detail='This is already the primary email address')
|
||||
@@ -166,7 +212,8 @@ def add_additional_email(payload: AdditionalEmail, user: dict = Depends(get_curr
|
||||
try:
|
||||
send_verification_email(email_address, user['username'], verification_url)
|
||||
except Exception as error:
|
||||
raise HTTPException(status_code=503, detail=f'Email address added but verification email could not be sent: {error}') from error
|
||||
logger.error('Additional email verification failed request_id=%s error=%s', request_id(request), redacted_error(error))
|
||||
raise HTTPException(status_code=503, detail=public_error(request, 'Email address added but verification email could not be sent.')) from error
|
||||
with get_connection() as conn:
|
||||
conn.execute(
|
||||
'''INSERT INTO app_settings (name, value, updated_at) VALUES (?, ?, CURRENT_TIMESTAMP)
|
||||
@@ -178,7 +225,7 @@ def add_additional_email(payload: AdditionalEmail, user: dict = Depends(get_curr
|
||||
|
||||
|
||||
@router.post('/emails/{address_id}/resend')
|
||||
def resend_additional_email(address_id: str, user: dict = Depends(get_current_user)):
|
||||
def resend_additional_email(address_id: str, request: Request, user: dict = Depends(get_current_user)):
|
||||
now = datetime.now(timezone.utc)
|
||||
setting_name = f'email_verify_rate:{address_id}'
|
||||
with get_connection() as conn:
|
||||
@@ -202,7 +249,8 @@ def resend_additional_email(address_id: str, user: dict = Depends(get_current_us
|
||||
try:
|
||||
send_verification_email(email, user['username'], verification_url)
|
||||
except Exception as error:
|
||||
raise HTTPException(status_code=503, detail=f'Verification email could not be sent: {error}') from error
|
||||
logger.error('Verification email resend failed request_id=%s error=%s', request_id(request), redacted_error(error))
|
||||
raise HTTPException(status_code=503, detail=public_error(request, 'Verification email could not be sent.')) from error
|
||||
sends = int(rate.get('sends', 0)) + 1
|
||||
updated = {'sends': sends, 'last_sent': now.isoformat()}
|
||||
if sends >= 5:
|
||||
@@ -221,6 +269,7 @@ def remove_additional_email(address_id: str, user: dict = Depends(get_current_us
|
||||
conn.commit()
|
||||
if cursor.rowcount == 0:
|
||||
raise HTTPException(status_code=404, detail='Email address not found')
|
||||
record_audit_event(user['id'], 'email_address_deleted', 'email_address', address_id)
|
||||
return {'status': 'deleted', 'id': address_id}
|
||||
|
||||
|
||||
@@ -249,6 +298,7 @@ def make_email_primary(address_id: str, user: dict = Depends(get_current_user)):
|
||||
(address['email'], user['id']),
|
||||
)
|
||||
conn.commit()
|
||||
record_audit_event(user['id'], 'primary_email_changed', 'user', user['id'])
|
||||
return {'status': 'updated', 'email': address['email']}
|
||||
|
||||
|
||||
@@ -280,6 +330,7 @@ def edit_label(label_id: str, payload: LabelUpdate, user: dict = Depends(get_cur
|
||||
def remove_label(label_id: str, user: dict = Depends(get_current_user)):
|
||||
if not delete_label(label_id, user['id']):
|
||||
raise HTTPException(status_code=404, detail='Label not found or not owned by user')
|
||||
record_audit_event(user['id'], 'label_deleted', 'label', label_id)
|
||||
return {'status': 'deleted', 'id': label_id}
|
||||
|
||||
|
||||
@@ -288,25 +339,33 @@ async def upload_avatar(
|
||||
avatar: UploadFile = File(...),
|
||||
user: dict = Depends(get_current_user),
|
||||
):
|
||||
allowed_types = {
|
||||
'image/gif': '.gif',
|
||||
'image/jpeg': '.jpg',
|
||||
'image/png': '.png',
|
||||
'image/webp': '.webp',
|
||||
}
|
||||
suffix = allowed_types.get(avatar.content_type or '')
|
||||
if suffix is None:
|
||||
if avatar.content_type not in {'image/gif', 'image/jpeg', 'image/png', 'image/webp'}:
|
||||
raise HTTPException(status_code=415, detail='Avatar must be a PNG, JPEG, GIF, or WebP image')
|
||||
|
||||
contents = await avatar.read(2 * 1024 * 1024 + 1)
|
||||
if len(contents) > 2 * 1024 * 1024:
|
||||
contents = await avatar.read(MAX_AVATAR_BYTES + 1)
|
||||
if len(contents) > MAX_AVATAR_BYTES:
|
||||
raise HTTPException(status_code=413, detail='Avatar must be 2 MB or smaller')
|
||||
|
||||
avatar_path = AVATARS_DIR / f'{user["id"]}{suffix}'
|
||||
try:
|
||||
with warnings.catch_warnings():
|
||||
warnings.simplefilter('error', Image.DecompressionBombWarning)
|
||||
with Image.open(BytesIO(contents)) as image:
|
||||
if image.width * image.height > MAX_AVATAR_PIXELS:
|
||||
raise HTTPException(status_code=413, detail='Avatar dimensions are too large')
|
||||
image.verify()
|
||||
with Image.open(BytesIO(contents)) as image:
|
||||
image.load()
|
||||
normalized = image.convert('RGBA')
|
||||
except HTTPException:
|
||||
raise
|
||||
except (Image.DecompressionBombError, Image.DecompressionBombWarning, UnidentifiedImageError, OSError, ValueError) as error:
|
||||
raise HTTPException(status_code=415, detail='Avatar content is not a valid image') from error
|
||||
|
||||
avatar_path = AVATARS_DIR / f'{user["id"]}.png'
|
||||
normalized.save(avatar_path, format='PNG', optimize=True)
|
||||
for existing_path in AVATARS_DIR.glob(f'{user["id"]}.*'):
|
||||
if existing_path != avatar_path:
|
||||
existing_path.unlink(missing_ok=True)
|
||||
avatar_path.write_bytes(contents)
|
||||
avatar_url = f'/media/{avatar_path.name}'
|
||||
|
||||
with get_connection() as conn:
|
||||
@@ -315,6 +374,7 @@ async def upload_avatar(
|
||||
(avatar_url, user['id']),
|
||||
)
|
||||
conn.commit()
|
||||
record_audit_event(user['id'], 'avatar_updated', 'user', user['id'])
|
||||
return {'avatar_url': avatar_url}
|
||||
|
||||
|
||||
|
||||
@@ -5,6 +5,8 @@ from dataclasses import dataclass
|
||||
import os
|
||||
from pathlib import Path
|
||||
|
||||
from cryptography.fernet import Fernet
|
||||
|
||||
|
||||
BASE_DIR = Path(__file__).resolve().parent.parent.parent
|
||||
DB_PATH = BASE_DIR / 'data' / 'linklog.db'
|
||||
@@ -20,13 +22,15 @@ def normalize_public_url(value: str) -> str:
|
||||
|
||||
@dataclass
|
||||
class Settings:
|
||||
app_env: str = os.getenv('APP_ENV', 'development').lower()
|
||||
app_name: str = os.getenv('LINKLOG_APP_NAME', 'LinkLog')
|
||||
version: str = os.getenv('LINKLOG_VERSION', '0.1.0')
|
||||
database_url: str = os.getenv('LINKLOG_DATABASE_URL', f'sqlite:///{DB_PATH}')
|
||||
secret_key: str = os.getenv('LINKLOG_SECRET_KEY', 'dev-secret-key-change-me')
|
||||
data_encryption_key: str = os.getenv('LINKLOG_DATA_ENCRYPTION_KEY', '')
|
||||
token_expiry_days: int = int(os.getenv('LINKLOG_TOKEN_EXPIRY_DAYS', '30'))
|
||||
public_url: str = normalize_public_url(os.getenv('LINKLOG_PUBLIC_URL', 'http://localhost:8000'))
|
||||
token_expiry_minutes: int = int(os.getenv('LINKLOG_TOKEN_EXPIRY_MINUTES', '15'))
|
||||
refresh_token_expiry_days: int = int(os.getenv('LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS', '30'))
|
||||
public_url: str = normalize_public_url(os.getenv('LINKLOG_PUBLIC_URL', 'linklog.example.com'))
|
||||
smtp_host: str = os.getenv('LINKLOG_SMTP_HOST', '')
|
||||
smtp_port: int = int(os.getenv('LINKLOG_SMTP_PORT', '587'))
|
||||
smtp_username: str = os.getenv('LINKLOG_SMTP_USERNAME', '')
|
||||
@@ -58,3 +62,19 @@ class Settings:
|
||||
|
||||
|
||||
settings = Settings()
|
||||
|
||||
|
||||
def validate_configuration(values: Settings) -> None:
|
||||
if values.app_env == 'production':
|
||||
if not values.secret_key or values.secret_key == 'dev-secret-key-change-me':
|
||||
raise RuntimeError('LINKLOG_SECRET_KEY must be configured in production')
|
||||
if len(values.secret_key) < 32 or len(set(values.secret_key)) < 12:
|
||||
raise RuntimeError('LINKLOG_SECRET_KEY must be at least 32 characters with sufficient entropy')
|
||||
if not values.data_encryption_key:
|
||||
raise RuntimeError('LINKLOG_DATA_ENCRYPTION_KEY must be configured in production')
|
||||
|
||||
if values.data_encryption_key:
|
||||
try:
|
||||
Fernet(values.data_encryption_key.encode('ascii'))
|
||||
except (ValueError, UnicodeEncodeError) as error:
|
||||
raise RuntimeError('LINKLOG_DATA_ENCRYPTION_KEY must be a valid Fernet key') from error
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
import re
|
||||
from uuid import uuid4
|
||||
|
||||
from fastapi import Request
|
||||
|
||||
|
||||
SENSITIVE_PATTERN = re.compile(
|
||||
r'(?i)(authorization\s*[:=]\s*bearer\s+[^\s,;]+|'
|
||||
r'(?:token|password|secret|otp|code)(?:[_-](?:token|password|secret|code))?\s*[:=]\s*[^\s,;&]+|'
|
||||
r'([?&](?:token|code|password|secret|otp)=[^&#\s]+))'
|
||||
)
|
||||
|
||||
|
||||
def request_id(request: Request) -> str:
|
||||
return getattr(request.state, 'request_id', None) or str(uuid4())
|
||||
|
||||
|
||||
def redacted_error(error: Exception) -> str:
|
||||
return SENSITIVE_PATTERN.sub('[REDACTED]', str(error))
|
||||
|
||||
|
||||
def public_error(request: Request, message: str) -> str:
|
||||
return f'{message} Reference: {request_id(request)}'
|
||||
@@ -232,6 +232,33 @@ ALTER TABLE tokens ADD COLUMN device_id TEXT;
|
||||
ALTER TABLE tokens ADD COLUMN token_family_id TEXT;
|
||||
CREATE INDEX IF NOT EXISTS idx_tokens_device_id ON tokens(device_id);
|
||||
CREATE INDEX IF NOT EXISTS idx_tokens_family_id ON tokens(token_family_id);
|
||||
'''),
|
||||
(16, '''
|
||||
CREATE TABLE IF NOT EXISTS otp_recovery_codes (
|
||||
id TEXT PRIMARY KEY,
|
||||
user_id TEXT NOT NULL,
|
||||
code_hash TEXT NOT NULL UNIQUE,
|
||||
used INTEGER NOT NULL DEFAULT 0,
|
||||
created_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||
used_at TEXT,
|
||||
FOREIGN KEY(user_id) REFERENCES users(id) ON DELETE CASCADE
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_otp_recovery_codes_user_id ON otp_recovery_codes(user_id);
|
||||
'''),
|
||||
(17, '''
|
||||
CREATE TABLE IF NOT EXISTS security_audit_events (
|
||||
id TEXT PRIMARY KEY,
|
||||
actor_id TEXT,
|
||||
action TEXT NOT NULL,
|
||||
target_type TEXT NOT NULL,
|
||||
target_id TEXT,
|
||||
outcome TEXT NOT NULL DEFAULT 'success',
|
||||
details TEXT NOT NULL DEFAULT '{}',
|
||||
created_at TEXT NOT NULL DEFAULT CURRENT_TIMESTAMP,
|
||||
FOREIGN KEY(actor_id) REFERENCES users(id) ON DELETE SET NULL
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_security_audit_events_created_at ON security_audit_events(created_at);
|
||||
CREATE INDEX IF NOT EXISTS idx_security_audit_events_actor_id ON security_audit_events(actor_id);
|
||||
''')
|
||||
]
|
||||
|
||||
|
||||
+14
-2
@@ -1,8 +1,9 @@
|
||||
## Copyright © 2026 Olaf Kolkman
|
||||
## SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
from fastapi import FastAPI
|
||||
from fastapi import FastAPI, Request
|
||||
import logging
|
||||
from uuid import uuid4
|
||||
from fastapi.responses import HTMLResponse
|
||||
from fastapi.responses import RedirectResponse
|
||||
from fastapi.staticfiles import StaticFiles
|
||||
@@ -17,13 +18,23 @@ from backend.app.api.public import router as public_router
|
||||
from backend.app.api.setup import router as setup_router
|
||||
from backend.app.api.setup import has_administrator
|
||||
from backend.app.api.user_config import router as user_config_router
|
||||
from backend.app.core.config import settings
|
||||
from backend.app.core.config import settings, validate_configuration
|
||||
from backend.app.database import AVATARS_DIR
|
||||
from backend.app.services.link_service import get_public_profile, list_public_links
|
||||
|
||||
logging.basicConfig(level=getattr(logging, settings.log_level, logging.INFO))
|
||||
validate_configuration(settings)
|
||||
|
||||
app = FastAPI(title='LinkLog API', version=settings.version)
|
||||
|
||||
|
||||
@app.middleware('http')
|
||||
async def add_request_id(request: Request, call_next):
|
||||
request.state.request_id = request.headers.get('X-Request-ID') or str(uuid4())
|
||||
response = await call_next(request)
|
||||
response.headers['X-Request-ID'] = request.state.request_id
|
||||
return response
|
||||
|
||||
app.mount('/static', StaticFiles(directory='frontend/static'), name='static')
|
||||
app.mount('/media', StaticFiles(directory=AVATARS_DIR), name='media')
|
||||
app.include_router(auth_router, prefix='/api/auth')
|
||||
@@ -35,6 +46,7 @@ app.include_router(user_config_router, prefix='/api/user')
|
||||
app.include_router(setup_router, prefix='/api/setup')
|
||||
|
||||
templates = Jinja2Templates(directory='frontend/templates')
|
||||
templates.env.globals['app_version'] = settings.version
|
||||
|
||||
|
||||
@app.get('/', response_class=HTMLResponse)
|
||||
|
||||
@@ -0,0 +1,23 @@
|
||||
import json
|
||||
from uuid import uuid4
|
||||
|
||||
from backend.app.database import get_connection
|
||||
|
||||
|
||||
def record_audit_event(
|
||||
actor_id: str | None,
|
||||
action: str,
|
||||
target_type: str,
|
||||
target_id: str | None = None,
|
||||
outcome: str = 'success',
|
||||
details: dict | None = None,
|
||||
) -> None:
|
||||
safe_details = details or {}
|
||||
with get_connection() as conn:
|
||||
conn.execute(
|
||||
'''INSERT INTO security_audit_events
|
||||
(id, actor_id, action, target_type, target_id, outcome, details)
|
||||
VALUES (?, ?, ?, ?, ?, ?, ?)''',
|
||||
(str(uuid4()), actor_id, action, target_type, target_id, outcome, json.dumps(safe_details)),
|
||||
)
|
||||
conn.commit()
|
||||
@@ -2,13 +2,57 @@
|
||||
## SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
from email.message import EmailMessage
|
||||
from html import escape
|
||||
from pathlib import Path
|
||||
from smtplib import SMTP
|
||||
import json
|
||||
from urllib.parse import urlparse
|
||||
|
||||
from backend.app.core.config import settings
|
||||
from backend.app.database import get_connection
|
||||
from backend.app.services.secret_store import decrypt_secret, encrypt_secret
|
||||
|
||||
LOGO_PATH = Path(__file__).resolve().parents[3] / 'frontend' / 'static' / 'logo.svg'
|
||||
|
||||
|
||||
def _html_email(body_html: str) -> str:
|
||||
public_url = settings.public_url
|
||||
parsed_url = urlparse(public_url)
|
||||
public_hostname = parsed_url.hostname or public_url
|
||||
safe_public_url = escape(public_url, quote=True)
|
||||
safe_public_hostname = escape(public_hostname)
|
||||
return f'''<!doctype html>
|
||||
<html lang="en">
|
||||
<body style="margin:0;background:#1e1e2e;color:#cdd6f4;font-family:Arial,sans-serif;line-height:1.6;">
|
||||
<div style="max-width:620px;margin:32px auto;padding:0 20px;">
|
||||
<div style="background:#11111b;border:1px solid #45475a;border-radius:12px;overflow:hidden;">
|
||||
<table role="presentation" width="100%" cellpadding="0" cellspacing="0" border="0" style="background:#181825;">
|
||||
<tr>
|
||||
<td style="padding:20px 24px;text-align:left;vertical-align:top;width:50px;">
|
||||
<img src="cid:linklog-logo" alt="LinkLog" width="50" height="50" style="display:block;width:50px;height:50px;">
|
||||
</td>
|
||||
<td style="padding:20px 0 20px 12px;text-align:left;vertical-align:top;">
|
||||
<span style="color:#cba6f7;font-family:'Asset',Georgia,serif;font-size:18px;line-height:50px;">Hello, a message from <a href="{safe_public_url}" style="color:#cba6f7;text-decoration:underline;">{safe_public_hostname}</a></span>
|
||||
</td>
|
||||
</tr>
|
||||
</table>
|
||||
<div style="padding:28px 32px;">{body_html}</div>
|
||||
</div>
|
||||
<p style="margin:18px 0;text-align:center;color:#a6adc8;font-size:12px;">LinkLog</p>
|
||||
</div>
|
||||
</body>
|
||||
</html>'''
|
||||
|
||||
|
||||
def _add_html_body(message: EmailMessage, html_body: str) -> None:
|
||||
message.add_alternative(_html_email(html_body), subtype='html')
|
||||
html_part = message.get_payload()[-1]
|
||||
try:
|
||||
logo = LOGO_PATH.read_bytes()
|
||||
except OSError:
|
||||
return
|
||||
html_part.add_related(logo, maintype='image', subtype='svg+xml', cid='<linklog-logo>')
|
||||
|
||||
|
||||
def get_smtp_settings() -> dict:
|
||||
values = {
|
||||
@@ -42,7 +86,8 @@ def smtp_configured(smtp_values: dict | None = None) -> bool:
|
||||
return bool(smtp['smtp_host'] and smtp['smtp_from'])
|
||||
|
||||
|
||||
def send_message(email: str, subject: str, body: str, smtp_values: dict | None = None) -> None:
|
||||
def send_message(email: str, subject: str, body: str, html_body: str | None = None,
|
||||
smtp_values: dict | None = None) -> None:
|
||||
smtp = smtp_values or get_smtp_settings()
|
||||
if not smtp_configured(smtp):
|
||||
raise RuntimeError('SMTP is not configured; set LINKLOG_SMTP_HOST and LINKLOG_SMTP_FROM')
|
||||
@@ -52,6 +97,8 @@ def send_message(email: str, subject: str, body: str, smtp_values: dict | None =
|
||||
message['From'] = smtp['smtp_from']
|
||||
message['To'] = email
|
||||
message.set_content(body)
|
||||
if html_body:
|
||||
_add_html_body(message, html_body)
|
||||
|
||||
with SMTP(smtp['smtp_host'], smtp['smtp_port'], timeout=10) as connection:
|
||||
if smtp['smtp_use_tls']:
|
||||
@@ -62,12 +109,17 @@ def send_message(email: str, subject: str, body: str, smtp_values: dict | None =
|
||||
|
||||
|
||||
def send_verification_email(email: str, username: str, verification_url: str) -> None:
|
||||
safe_username = escape(username)
|
||||
safe_url = escape(verification_url, quote=True)
|
||||
send_message(
|
||||
email,
|
||||
'Verify your LinkLog email address',
|
||||
f'Hello {username},\n\n'
|
||||
f'Verify your LinkLog email address by opening this link:\n{verification_url}\n\n'
|
||||
f'This link expires in {settings.email_verification_expiry_hours} hours.\n',
|
||||
f'<p>Hello {safe_username},</p><p>Verify your LinkLog email address:</p>'
|
||||
f'<p><a href="{safe_url}" style="display:inline-block;padding:10px 16px;background:#89b4fa;color:#11111b;text-decoration:none;border-radius:6px;">Verify email address</a></p>'
|
||||
f'<p style="color:#a6adc8;font-size:14px;">This link expires in {settings.email_verification_expiry_hours} hours.</p>',
|
||||
)
|
||||
|
||||
|
||||
@@ -76,15 +128,21 @@ def send_test_email(email: str, smtp_values: dict | None = None) -> None:
|
||||
email,
|
||||
'LinkLog SMTP test',
|
||||
'This is a test message from LinkLog. SMTP is configured correctly.\n',
|
||||
smtp_values,
|
||||
'<p>This is a test message from LinkLog.</p><p style="color:#a6adc8;">SMTP is configured correctly.</p>',
|
||||
smtp_values=smtp_values,
|
||||
)
|
||||
|
||||
|
||||
def send_password_reset_email(email: str, username: str, reset_url: str) -> None:
|
||||
safe_username = escape(username)
|
||||
safe_url = escape(reset_url, quote=True)
|
||||
send_message(
|
||||
email,
|
||||
'Reset your LinkLog password',
|
||||
f'Hello {username},\n\n'
|
||||
f'Reset your LinkLog password by opening this link:\n{reset_url}\n\n'
|
||||
f'This link expires in {settings.password_reset_expiry_hours} hours.\n',
|
||||
f'<p>Hello {safe_username},</p><p>Reset your LinkLog password:</p>'
|
||||
f'<p><a href="{safe_url}" style="display:inline-block;padding:10px 16px;background:#f38ba8;color:#11111b;text-decoration:none;border-radius:6px;">Reset password</a></p>'
|
||||
f'<p style="color:#a6adc8;font-size:14px;">This link expires in {settings.password_reset_expiry_hours} hours.</p>',
|
||||
)
|
||||
@@ -7,12 +7,43 @@ import hmac
|
||||
import secrets
|
||||
import time
|
||||
from urllib.parse import quote
|
||||
from uuid import uuid4
|
||||
|
||||
from backend.app.database import get_connection
|
||||
|
||||
|
||||
def create_secret() -> str:
|
||||
return base64.b32encode(secrets.token_bytes(20)).decode('ascii').rstrip('=')
|
||||
|
||||
|
||||
def create_recovery_codes(user_id: str, count: int = 10) -> list[str]:
|
||||
codes = [secrets.token_urlsafe(9) for _ in range(count)]
|
||||
with get_connection() as conn:
|
||||
conn.execute('DELETE FROM otp_recovery_codes WHERE user_id = ?', (user_id,))
|
||||
conn.executemany(
|
||||
'INSERT INTO otp_recovery_codes (id, user_id, code_hash) VALUES (?, ?, ?)',
|
||||
[(str(uuid4()), user_id, hash_recovery_code(code)) for code in codes],
|
||||
)
|
||||
conn.commit()
|
||||
return codes
|
||||
|
||||
|
||||
def hash_recovery_code(code: str) -> str:
|
||||
return hashlib.sha256(code.strip().encode('utf-8')).hexdigest()
|
||||
|
||||
|
||||
def consume_recovery_code(user_id: str, code: str) -> bool:
|
||||
with get_connection() as conn:
|
||||
cursor = conn.execute(
|
||||
'''UPDATE otp_recovery_codes
|
||||
SET used = 1, used_at = CURRENT_TIMESTAMP
|
||||
WHERE user_id = ? AND code_hash = ? AND used = 0''',
|
||||
(user_id, hash_recovery_code(code)),
|
||||
)
|
||||
conn.commit()
|
||||
return cursor.rowcount == 1
|
||||
|
||||
|
||||
def provisioning_uri(secret: str, username: str, issuer: str = 'LinkLog') -> str:
|
||||
return f'otpauth://totp/{quote(issuer)}:{quote(username)}?secret={secret}&issuer={quote(issuer)}'
|
||||
|
||||
|
||||
@@ -68,7 +68,9 @@ class MastodonPlugin(BasePlugin):
|
||||
post_prefix = f'#{str(config["hashtag"]).strip().lstrip("#")} '
|
||||
post_prefix = str(post_prefix if post_prefix is not None else DEFAULT_POST_PREFIX).strip()
|
||||
title = str(event.get('title') or '').strip()
|
||||
status_parts = [f'{post_prefix} {title}'.strip()]
|
||||
status_parts = [post_prefix.strip()]
|
||||
if title:
|
||||
status_parts.append(title)
|
||||
if event.get('comment'):
|
||||
status_parts.append(event['comment'])
|
||||
if title:
|
||||
|
||||
@@ -14,13 +14,15 @@ def hash_token(token: str) -> str:
|
||||
|
||||
|
||||
def _token_expiry() -> datetime:
|
||||
return datetime.now(timezone.utc) + timedelta(days=settings.token_expiry_days)
|
||||
return datetime.now(timezone.utc) + timedelta(minutes=settings.token_expiry_minutes)
|
||||
|
||||
|
||||
def _persist_token(conn, user_id: str, token: str, token_type: str, expires_at: datetime, device_id: str | None, family_id: str | None) -> None:
|
||||
def _persist_token(conn, user_id: str, token: str, token_type: str, expires_at: datetime,
|
||||
device_id: str, family_id: str) -> None:
|
||||
conn.execute(
|
||||
'''
|
||||
INSERT INTO tokens (id, user_id, token_hash, token_type, expires_at, created_at, revoked, device_id, token_family_id)
|
||||
INSERT INTO tokens
|
||||
(id, user_id, token_hash, token_type, expires_at, created_at, revoked, device_id, token_family_id)
|
||||
VALUES (?, ?, ?, ?, ?, CURRENT_TIMESTAMP, 0, ?, ?)
|
||||
''',
|
||||
(str(uuid4()), user_id, hash_token(token), token_type, expires_at.isoformat(), device_id, family_id),
|
||||
@@ -28,18 +30,16 @@ def _persist_token(conn, user_id: str, token: str, token_type: str, expires_at:
|
||||
|
||||
|
||||
def issue_token(user_id: str, username: str, device_id: str | None = None) -> dict:
|
||||
if device_id is None or not device_id.strip():
|
||||
device_id = f'device-{uuid4().hex}'
|
||||
device_id = device_id.strip()
|
||||
token_family_id = str(uuid4())
|
||||
device_id = device_id.strip() if device_id and device_id.strip() else f'device-{uuid4().hex}'
|
||||
family_id = str(uuid4())
|
||||
access_token = f'token-{username}-{uuid4().hex}'
|
||||
refresh_token = f'refresh-{username}-{uuid4().hex}'
|
||||
access_expires_at = _token_expiry()
|
||||
refresh_expires_at = access_expires_at + timedelta(days=30)
|
||||
refresh_expires_at = datetime.now(timezone.utc) + timedelta(days=settings.refresh_token_expiry_days)
|
||||
|
||||
with get_connection() as conn:
|
||||
_persist_token(conn, user_id, access_token, 'access', access_expires_at, device_id, token_family_id)
|
||||
_persist_token(conn, user_id, refresh_token, 'refresh', refresh_expires_at, device_id, token_family_id)
|
||||
_persist_token(conn, user_id, access_token, 'access', access_expires_at, device_id, family_id)
|
||||
_persist_token(conn, user_id, refresh_token, 'refresh', refresh_expires_at, device_id, family_id)
|
||||
conn.commit()
|
||||
|
||||
return {
|
||||
@@ -48,20 +48,19 @@ def issue_token(user_id: str, username: str, device_id: str | None = None) -> di
|
||||
'expires_at': access_expires_at.isoformat(),
|
||||
'refresh_token': refresh_token,
|
||||
'device_id': device_id,
|
||||
'token_family_id': token_family_id,
|
||||
'token_family_id': family_id,
|
||||
}
|
||||
|
||||
|
||||
def validate_token(token: str) -> dict | None:
|
||||
token_hash = hash_token(token)
|
||||
now = datetime.now(timezone.utc).isoformat()
|
||||
with get_connection() as conn:
|
||||
row = conn.execute(
|
||||
'''
|
||||
SELECT * FROM tokens
|
||||
WHERE token_hash = ? AND token_type = 'access' AND revoked = 0 AND expires_at > ?
|
||||
''',
|
||||
(token_hash, now),
|
||||
(token_hash, datetime.now(timezone.utc).isoformat()),
|
||||
).fetchone()
|
||||
if row is None:
|
||||
return None
|
||||
@@ -69,8 +68,6 @@ def validate_token(token: str) -> dict | None:
|
||||
|
||||
|
||||
def validate_refresh_token(token: str, device_id: str | None = None) -> dict | None:
|
||||
token_hash = hash_token(token)
|
||||
now = datetime.now(timezone.utc).isoformat()
|
||||
with get_connection() as conn:
|
||||
row = conn.execute(
|
||||
'''
|
||||
@@ -78,60 +75,56 @@ def validate_refresh_token(token: str, device_id: str | None = None) -> dict | N
|
||||
WHERE token_hash = ? AND token_type = 'refresh' AND revoked = 0 AND expires_at > ?
|
||||
AND (? IS NULL OR device_id = ?)
|
||||
''',
|
||||
(token_hash, now, device_id, device_id),
|
||||
(hash_token(token), datetime.now(timezone.utc).isoformat(), device_id, device_id),
|
||||
).fetchone()
|
||||
if row is None:
|
||||
return None
|
||||
return dict(row)
|
||||
return dict(row) if row else None
|
||||
|
||||
|
||||
def rotate_refresh_token(refresh_token: str, device_id: str | None = None) -> dict | None:
|
||||
current = validate_refresh_token(refresh_token, device_id)
|
||||
if current is None:
|
||||
return None
|
||||
|
||||
family_id = current.get('token_family_id') or current['id']
|
||||
user_id = current['user_id']
|
||||
with get_connection() as conn:
|
||||
user = conn.execute('SELECT username FROM users WHERE id = ?', (user_id,)).fetchone()
|
||||
if user is None:
|
||||
if current is None:
|
||||
row = conn.execute(
|
||||
'SELECT token_family_id FROM tokens WHERE token_hash = ? AND token_type = ? AND token_family_id IS NOT NULL',
|
||||
(hash_token(refresh_token), 'refresh'),
|
||||
).fetchone()
|
||||
if row:
|
||||
conn.execute('UPDATE tokens SET revoked = 1 WHERE token_family_id = ?', (row['token_family_id'],))
|
||||
conn.commit()
|
||||
return None
|
||||
|
||||
conn.execute(
|
||||
'UPDATE tokens SET revoked = 1 WHERE token_family_id = ? AND token_type = ? AND revoked = 0',
|
||||
(family_id, 'refresh'),
|
||||
)
|
||||
conn.execute(
|
||||
'UPDATE tokens SET revoked = 1 WHERE id = ?',
|
||||
(current['id'],),
|
||||
)
|
||||
|
||||
user = conn.execute('SELECT username FROM users WHERE id = ?', (current['user_id'],)).fetchone()
|
||||
if user is None:
|
||||
return None
|
||||
family_id = current['token_family_id']
|
||||
conn.execute('UPDATE tokens SET revoked = 1 WHERE token_family_id = ?', (family_id,))
|
||||
new_access = f'token-{user["username"]}-{uuid4().hex}'
|
||||
new_refresh = f'refresh-{user["username"]}-{uuid4().hex}'
|
||||
access_expires_at = _token_expiry()
|
||||
refresh_expires_at = access_expires_at + timedelta(days=30)
|
||||
|
||||
_persist_token(conn, user_id, new_access, 'access', access_expires_at, device_id, family_id)
|
||||
_persist_token(conn, user_id, new_refresh, 'refresh', refresh_expires_at, device_id, family_id)
|
||||
refresh_expires_at = datetime.now(timezone.utc) + timedelta(days=settings.refresh_token_expiry_days)
|
||||
_persist_token(conn, current['user_id'], new_access, 'access', access_expires_at, current['device_id'], family_id)
|
||||
_persist_token(conn, current['user_id'], new_refresh, 'refresh', refresh_expires_at, current['device_id'], family_id)
|
||||
conn.commit()
|
||||
|
||||
return {
|
||||
'access_token': new_access,
|
||||
'token_type': 'bearer',
|
||||
'expires_at': access_expires_at.isoformat(),
|
||||
'refresh_token': new_refresh,
|
||||
'device_id': device_id,
|
||||
'user_id': user_id,
|
||||
'device_id': current['device_id'],
|
||||
'user_id': current['user_id'],
|
||||
'username': user['username'],
|
||||
}
|
||||
|
||||
|
||||
def revoke_token(token: str, token_type: str = 'access') -> bool:
|
||||
def revoke_token(token: str) -> bool:
|
||||
token_hash = hash_token(token)
|
||||
with get_connection() as conn:
|
||||
cursor = conn.execute(
|
||||
'UPDATE tokens SET revoked = 1 WHERE token_hash = ? AND token_type = ?',
|
||||
(token_hash, token_type),
|
||||
'''UPDATE tokens SET revoked = 1
|
||||
WHERE token_hash = ? OR token_family_id = (
|
||||
SELECT token_family_id FROM tokens WHERE token_hash = ?
|
||||
)''',
|
||||
(token_hash, token_hash),
|
||||
)
|
||||
conn.commit()
|
||||
return cursor.rowcount > 0
|
||||
|
||||
@@ -3,6 +3,7 @@ uvicorn==0.52.4
|
||||
pydantic==2.13.4
|
||||
jinja2==3.1.6
|
||||
python-multipart==0.0.20
|
||||
Pillow==11.3.0
|
||||
pytest==9.1.1
|
||||
httpx==0.28.1
|
||||
httpx2==2.12.0
|
||||
|
||||
+100
-20
@@ -14,6 +14,7 @@ from backend.app.main import app
|
||||
from backend.app.database import get_connection
|
||||
from backend.app.services.email_service import get_smtp_settings
|
||||
from backend.app.services.login_throttle import clear_login_failures
|
||||
from backend.app.services.otp_service import current_code
|
||||
from backend.app.services.password_reset import create_reset_token
|
||||
from backend.app.services.token_service import issue_token
|
||||
|
||||
@@ -54,6 +55,17 @@ def test_login_returns_token():
|
||||
assert client.get('/api/auth/me', params={'token': payload['access_token']}).status_code == 401
|
||||
|
||||
|
||||
def test_logout_requires_bearer_header_and_revokes_token_family():
|
||||
login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json()
|
||||
token = login['access_token']
|
||||
headers = {'Authorization': f'Bearer {token}'}
|
||||
assert client.post('/api/auth/logout', json={'token': token}).status_code == 401
|
||||
assert client.get('/api/auth/me', headers=headers).status_code == 200
|
||||
assert client.post('/api/auth/logout', headers=headers).status_code == 200
|
||||
assert client.get('/api/auth/me', headers=headers).status_code == 401
|
||||
assert client.post('/api/auth/refresh', json={'refresh_token': login['refresh_token'], 'device_id': login['device_id']}).status_code == 401
|
||||
|
||||
|
||||
def test_login_rate_limit_locks_out_after_five_failures_and_resets_on_success():
|
||||
email = f'unknown-{uuid4().hex}@example.com'
|
||||
for attempt in range(5):
|
||||
@@ -68,7 +80,7 @@ def test_login_rate_limit_locks_out_after_five_failures_and_resets_on_success():
|
||||
assert valid.status_code == 200
|
||||
|
||||
|
||||
def test_refresh_token_rotation_binds_to_device_and_revokes_old_tokens():
|
||||
def test_refresh_token_rotates_and_reuse_revokes_family():
|
||||
device_id = f'device-{uuid4().hex}'
|
||||
login = client.post('/api/auth/login', json={
|
||||
'email': 'alice@example.com',
|
||||
@@ -76,30 +88,27 @@ def test_refresh_token_rotation_binds_to_device_and_revokes_old_tokens():
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert login.status_code == 200
|
||||
refresh_token = login.json()['refresh_token']
|
||||
first_access = login.json()['access_token']
|
||||
first = login.json()
|
||||
|
||||
rotated = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': refresh_token,
|
||||
'refresh_token': first['refresh_token'],
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert rotated.status_code == 200
|
||||
rotated_payload = rotated.json()
|
||||
assert rotated_payload['access_token'] != first_access
|
||||
assert rotated_payload['refresh_token'] != refresh_token
|
||||
assert rotated_payload['device_id'] == device_id
|
||||
second = rotated.json()
|
||||
assert second['refresh_token'] != first['refresh_token']
|
||||
assert client.get('/api/auth/me', headers={'Authorization': f"Bearer {second['access_token']}"}).status_code == 200
|
||||
|
||||
replay = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': refresh_token,
|
||||
reused = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': first['refresh_token'],
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert replay.status_code == 401
|
||||
|
||||
wrong_device = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': rotated_payload['refresh_token'],
|
||||
'device_id': 'device-other',
|
||||
assert reused.status_code == 401
|
||||
family_revoked = client.post('/api/auth/refresh', json={
|
||||
'refresh_token': second['refresh_token'],
|
||||
'device_id': device_id,
|
||||
})
|
||||
assert wrong_device.status_code == 401
|
||||
assert family_revoked.status_code == 401
|
||||
|
||||
|
||||
def test_password_hashes_are_salted_and_legacy_hashes_upgrade_on_login():
|
||||
@@ -218,7 +227,31 @@ def test_admin_reports_smtp_validation_errors():
|
||||
'smtp_use_tls': False,
|
||||
})
|
||||
assert failed_validation.status_code == 503
|
||||
assert 'connection refused' in failed_validation.json()['detail']
|
||||
assert failed_validation.json()['detail'].startswith('SMTP validation failed. Reference: ')
|
||||
assert 'connection refused' not in failed_validation.json()['detail']
|
||||
assert failed_validation.headers['X-Request-ID']
|
||||
|
||||
|
||||
def test_request_id_is_preserved_and_sensitive_error_text_is_not_returned():
|
||||
headers = login_headers()
|
||||
with get_connection() as conn:
|
||||
conn.execute('DELETE FROM app_settings WHERE name = ?', ('admin_smtp_mail_rate',))
|
||||
conn.commit()
|
||||
with patch('backend.app.api.admin.send_test_email', side_effect=RuntimeError('password=super-secret token=abc123')):
|
||||
response = client.post(
|
||||
'/api/admin/smtp/test',
|
||||
headers={**headers, 'X-Request-ID': 'audit-test-123'},
|
||||
json={
|
||||
'smtp_host': 'smtp.example.com',
|
||||
'smtp_port': 2525,
|
||||
'smtp_from': 'admin@example.com',
|
||||
},
|
||||
)
|
||||
assert response.status_code == 503
|
||||
assert response.headers['X-Request-ID'] == 'audit-test-123'
|
||||
assert response.json()['detail'] == 'SMTP validation failed. Reference: audit-test-123'
|
||||
assert 'super-secret' not in response.text
|
||||
assert 'abc123' not in response.text
|
||||
|
||||
|
||||
def test_admin_can_add_list_and_remove_users():
|
||||
@@ -242,6 +275,52 @@ def test_admin_can_add_list_and_remove_users():
|
||||
assert client.put('/api/admin/users/user-1', headers=headers, json={'is_admin': False}).status_code == 400
|
||||
|
||||
|
||||
def test_admin_can_reset_another_users_otp():
|
||||
admin_headers = login_headers()
|
||||
user_login = client.post('/api/auth/login', json={
|
||||
'email': 'bob@example.com',
|
||||
'password': 'secret123',
|
||||
}).json()
|
||||
user_headers = {'Authorization': f"Bearer {user_login['access_token']}"}
|
||||
setup = client.post('/api/user/otp/setup', headers=user_headers)
|
||||
assert setup.status_code == 200
|
||||
secret = setup.json()['secret']
|
||||
recovery_code = setup.json()['recovery_codes'][0]
|
||||
assert client.post('/api/user/otp', headers=user_headers, json={
|
||||
'action': 'enable', 'code': current_code(secret),
|
||||
}).status_code == 200
|
||||
|
||||
assert client.post('/api/admin/users/user-2/otp/reset', headers=admin_headers).json() == {
|
||||
'status': 'otp_reset', 'enabled': False, 'user_id': 'user-2',
|
||||
}
|
||||
assert client.get('/api/user/otp', headers=user_headers).json() == {'enabled': False}
|
||||
assert client.post('/api/user/otp/recover', headers=user_headers, json={
|
||||
'current_password': 'secret123', 'recovery_code': recovery_code,
|
||||
}).status_code == 400
|
||||
assert client.post('/api/admin/users/user-2/otp/reset', headers=login_headers('bob')).status_code == 403
|
||||
assert client.post('/api/admin/users/missing-user/otp/reset', headers=admin_headers).status_code == 404
|
||||
|
||||
|
||||
def test_security_audit_events_are_append_only_and_do_not_store_secrets():
|
||||
admin_headers = login_headers()
|
||||
response = client.put('/api/admin/themes', headers=admin_headers, json={'themes': ['plain-day']})
|
||||
assert response.status_code == 200
|
||||
with get_connection() as conn:
|
||||
event = conn.execute(
|
||||
'''SELECT actor_id, action, target_type, outcome, details
|
||||
FROM security_audit_events
|
||||
WHERE action = 'themes_updated'
|
||||
ORDER BY created_at DESC, rowid DESC LIMIT 1''',
|
||||
).fetchone()
|
||||
assert event is not None
|
||||
assert event['actor_id'] == 'user-1'
|
||||
assert event['target_type'] == 'application'
|
||||
assert event['outcome'] == 'success'
|
||||
assert 'password' not in event['details'].lower()
|
||||
assert 'token' not in event['details'].lower()
|
||||
assert 'secret' not in event['details'].lower()
|
||||
|
||||
|
||||
def test_new_user_must_verify_email_before_login():
|
||||
headers = login_headers()
|
||||
username = f'unverified-{uuid4().hex}'
|
||||
@@ -599,8 +678,7 @@ def test_only_link_owner_can_edit_link():
|
||||
|
||||
def test_logout_revokes_token_and_admin_can_list_plugins():
|
||||
headers = login_headers()
|
||||
token = headers['Authorization'].removeprefix('Bearer ')
|
||||
assert client.post('/api/auth/logout', json={'token': token}).status_code == 200
|
||||
assert client.post('/api/auth/logout', headers=headers).status_code == 200
|
||||
|
||||
revoked_response = client.post('/api/links', headers=headers, json={
|
||||
'title': 'Should fail',
|
||||
@@ -649,6 +727,8 @@ def test_public_and_admin_pages_render_html():
|
||||
about_page = client.get('/about')
|
||||
assert about_page.status_code == 200
|
||||
assert 'Save the good stuff' in about_page.text
|
||||
assert '<h2>Plugin</h2>' in about_page.text
|
||||
assert 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi' in about_page.text
|
||||
assert 'id="auth-about-link" href="/about"' in about_page.text
|
||||
assert client.get('/admin').status_code == 200
|
||||
admin_page = client.get('/admin').text
|
||||
@@ -716,7 +796,7 @@ def test_link_submission_posts_to_enabled_mastodon_plugin():
|
||||
assert received['path'] == '/api/v1/statuses'
|
||||
assert received['authorization'] == 'Bearer test-token'
|
||||
assert received['content_type'] == 'application/x-www-form-urlencoded'
|
||||
assert received['body'] == {'status': ['From my #LinkLog: A useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']}
|
||||
assert received['body'] == {'status': ['From my #LinkLog:\n\nA useful page\n\nWorth sharing\n\nfrom: https://example.com/useful\n\n#python #web']}
|
||||
posted_item = next(item for item in client.get('/api/public/feed/alice', headers=headers).json() if item['id'] == response.json()['id'])
|
||||
assert posted_item['mastodon_posted'] is True
|
||||
finally:
|
||||
|
||||
@@ -0,0 +1,44 @@
|
||||
import re
|
||||
from pathlib import Path
|
||||
import pytest
|
||||
|
||||
from backend.app.core.config import Settings, validate_configuration
|
||||
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[2]
|
||||
|
||||
|
||||
def test_production_configuration_rejects_missing_or_default_secret():
|
||||
with pytest.raises(RuntimeError, match='LINKLOG_SECRET_KEY'):
|
||||
validate_configuration(Settings(app_env='production', secret_key='', data_encryption_key=''))
|
||||
with pytest.raises(RuntimeError, match='LINKLOG_SECRET_KEY'):
|
||||
validate_configuration(Settings(app_env='production', secret_key='dev-secret-key-change-me', data_encryption_key=''))
|
||||
|
||||
|
||||
def test_production_configuration_rejects_weak_or_missing_encryption_key():
|
||||
with pytest.raises(RuntimeError, match='entropy'):
|
||||
validate_configuration(Settings(app_env='production', secret_key='A' * 32, data_encryption_key=''))
|
||||
with pytest.raises(RuntimeError, match='DATA_ENCRYPTION_KEY'):
|
||||
validate_configuration(Settings(app_env='production', secret_key='A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6', data_encryption_key='invalid'))
|
||||
|
||||
|
||||
def test_production_configuration_accepts_strong_secrets():
|
||||
values = Settings(
|
||||
app_env='production',
|
||||
secret_key='A1b2C3d4E5f6G7h8I9j0K1l2M3n4O5p6',
|
||||
data_encryption_key='L5M4sQYVjD1N7pT2Xk8R0aBcDeFgHiJkLmNoPqRsTuV=',
|
||||
)
|
||||
validate_configuration(values)
|
||||
|
||||
|
||||
def test_production_compose_configuration_matches_settings_environment_keys():
|
||||
compose = (ROOT / 'docker-compose.yml').read_text()
|
||||
settings = (ROOT / 'backend' / 'app' / 'core' / 'config.py').read_text()
|
||||
database = (ROOT / 'backend' / 'app' / 'database.py').read_text()
|
||||
|
||||
compose_keys = set(re.findall(r'\b(LINKLOG_[A-Z0-9_]+):', compose))
|
||||
settings_keys = set(re.findall(r"os\.getenv\('([^']+)'", settings + database))
|
||||
|
||||
assert {'LINKLOG_TOKEN_EXPIRY_MINUTES', 'LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS'} <= compose_keys
|
||||
assert compose_keys & settings_keys == compose_keys
|
||||
assert 'LINKLOG_TOKEN_EXPIRY_DAYS' not in compose_keys
|
||||
@@ -10,7 +10,7 @@ def test_database_migrations_are_versioned_and_idempotent():
|
||||
connection = sqlite3.connect(':memory:')
|
||||
|
||||
apply_migrations(connection)
|
||||
assert get_schema_version(connection) == 14
|
||||
assert get_schema_version(connection) == 17
|
||||
tables = {
|
||||
row[0]
|
||||
for row in connection.execute(
|
||||
@@ -27,6 +27,6 @@ def test_database_migrations_are_versioned_and_idempotent():
|
||||
assert set(DEFAULT_TAGS) <= seeded_tags
|
||||
|
||||
apply_migrations(connection)
|
||||
assert get_schema_version(connection) == 14
|
||||
assert get_schema_version(connection) == 17
|
||||
|
||||
connection.close()
|
||||
@@ -3,7 +3,7 @@
|
||||
|
||||
from unittest.mock import patch
|
||||
|
||||
from backend.app.services.email_service import send_test_email, send_verification_email
|
||||
from backend.app.services.email_service import send_password_reset_email, send_test_email, send_verification_email
|
||||
|
||||
|
||||
def test_send_verification_email_uses_smtp_settings(monkeypatch):
|
||||
@@ -15,6 +15,7 @@ def test_send_verification_email_uses_smtp_settings(monkeypatch):
|
||||
monkeypatch.setattr(settings, 'smtp_username', 'mailer')
|
||||
monkeypatch.setattr(settings, 'smtp_password', 'secret')
|
||||
monkeypatch.setattr(settings, 'smtp_use_tls', True)
|
||||
monkeypatch.setattr(settings, 'public_url', 'https://linklog.example')
|
||||
|
||||
with patch('backend.app.services.email_service.SMTP') as smtp_class:
|
||||
smtp = smtp_class.return_value.__enter__.return_value
|
||||
@@ -25,7 +26,22 @@ def test_send_verification_email_uses_smtp_settings(monkeypatch):
|
||||
smtp.login.assert_called_once_with('mailer', 'secret')
|
||||
message = smtp.send_message.call_args.args[0]
|
||||
assert message['To'] == 'user@example.com'
|
||||
assert 'https://linklog.example/verify' in message.get_content()
|
||||
assert 'https://linklog.example/verify' in message.get_body(preferencelist=('plain',)).get_content()
|
||||
html = message.get_body(preferencelist=('html',)).get_content()
|
||||
assert 'cid:linklog-logo' in html
|
||||
assert 'width="50" height="50"' in html
|
||||
assert 'font-family:\'Asset\',Georgia,serif' in html
|
||||
assert 'Hello, a message from' in html
|
||||
assert 'vertical-align:top' in html
|
||||
assert 'padding:20px 0 20px 12px' in html
|
||||
assert 'font-size:18px' in html
|
||||
assert 'href="https://linklog.example"' in html
|
||||
assert '>linklog.example</a>' in html
|
||||
assert any(
|
||||
part.get_content_type() == 'image/svg+xml'
|
||||
and part['Content-ID'] == '<linklog-logo>'
|
||||
for part in message.walk()
|
||||
)
|
||||
|
||||
|
||||
def test_send_test_email_uses_configured_recipient(monkeypatch):
|
||||
@@ -40,6 +56,23 @@ def test_send_test_email_uses_configured_recipient(monkeypatch):
|
||||
message = smtp.send_message.call_args.args[0]
|
||||
assert message['To'] == 'admin@example.com'
|
||||
assert message['Subject'] == 'LinkLog SMTP test'
|
||||
assert message.get_body(preferencelist=('html',)) is not None
|
||||
|
||||
|
||||
def test_password_reset_email_escapes_html_and_includes_logo(monkeypatch):
|
||||
from backend.app.core.config import settings
|
||||
|
||||
monkeypatch.setattr(settings, 'smtp_host', 'smtp.example.com')
|
||||
monkeypatch.setattr(settings, 'smtp_from', 'LinkLog <no-reply@example.com>')
|
||||
with patch('backend.app.services.email_service.SMTP') as smtp_class:
|
||||
smtp = smtp_class.return_value.__enter__.return_value
|
||||
send_password_reset_email('user@example.com', '<User>', 'https://linklog.example/reset?x=1&y=2')
|
||||
|
||||
message = smtp.send_message.call_args.args[0]
|
||||
html = message.get_body(preferencelist=('html',)).get_content()
|
||||
assert '<User>' in html
|
||||
assert 'x=1&y=2' in html
|
||||
assert 'cid:linklog-logo' in html
|
||||
|
||||
|
||||
def test_smtp_password_is_encrypted_at_rest():
|
||||
|
||||
@@ -1,7 +1,10 @@
|
||||
## Copyright © 2026 Olaf Kolkman
|
||||
## SPDX-License-Identifier: GPL-3.0-or-later
|
||||
|
||||
from io import BytesIO
|
||||
|
||||
from fastapi.testclient import TestClient
|
||||
from PIL import Image
|
||||
from unittest.mock import patch
|
||||
|
||||
from backend.app.main import app
|
||||
@@ -48,6 +51,8 @@ def test_user_config_api_and_profile_page():
|
||||
assert 'id="auth-avatar"' not in page_response.text
|
||||
assert 'name="new_password_confirmation"' in page_response.text
|
||||
assert 'id="additional-email-form"' in page_response.text
|
||||
assert 'If you have not downloaded the plugin yet' in page_response.text
|
||||
assert 'https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi' in page_response.text
|
||||
|
||||
bob_login = client.post('/api/auth/login', json={
|
||||
'email': 'bob@example.com',
|
||||
@@ -68,15 +73,29 @@ def test_user_config_api_and_profile_page():
|
||||
'new_password': 'secret123',
|
||||
}, headers=bob_headers).status_code == 200
|
||||
|
||||
image_buffer = BytesIO()
|
||||
Image.new('RGB', (2, 2), 'red').save(image_buffer, format='JPEG')
|
||||
upload_response = client.post(
|
||||
'/api/user/avatar',
|
||||
headers=headers,
|
||||
files={'avatar': ('avatar.png', b'fake-png-data', 'image/png')},
|
||||
files={'avatar': ('avatar.jpg', image_buffer.getvalue(), 'image/jpeg')},
|
||||
)
|
||||
assert upload_response.status_code == 200
|
||||
avatar_url = upload_response.json()['avatar_url']
|
||||
assert avatar_url.startswith('/media/user-1.png')
|
||||
assert client.get(avatar_url).content == b'fake-png-data'
|
||||
stored_avatar = client.get(avatar_url)
|
||||
assert stored_avatar.status_code == 200
|
||||
assert stored_avatar.headers['content-type'] == 'image/png'
|
||||
with Image.open(BytesIO(stored_avatar.content)) as image:
|
||||
assert image.format == 'PNG'
|
||||
assert image.size == (2, 2)
|
||||
|
||||
rejected_upload = client.post(
|
||||
'/api/user/avatar',
|
||||
headers=headers,
|
||||
files={'avatar': ('avatar.png', b'fake-png-data', 'image/png')},
|
||||
)
|
||||
assert rejected_upload.status_code == 415
|
||||
|
||||
updated_profile = client.get('/api/user/me', headers=headers).json()
|
||||
assert updated_profile['avatar_url'] == avatar_url
|
||||
@@ -89,6 +108,8 @@ def test_user_can_enable_and_use_otp():
|
||||
assert setup.status_code == 200
|
||||
secret = setup.json()['secret']
|
||||
assert setup.json()['otpauth_url'].startswith('otpauth://totp/')
|
||||
recovery_codes = setup.json()['recovery_codes']
|
||||
assert len(recovery_codes) == 10
|
||||
|
||||
enabled = client.post('/api/user/otp', headers=headers, json={
|
||||
'action': 'enable', 'code': current_code(secret),
|
||||
@@ -103,12 +124,36 @@ def test_user_can_enable_and_use_otp():
|
||||
assert otp_login.status_code == 200
|
||||
|
||||
disabled = client.post('/api/user/otp', headers=headers, json={
|
||||
'action': 'disable', 'code': current_code(secret),
|
||||
'action': 'disable', 'code': current_code(secret), 'current_password': 'secret123',
|
||||
})
|
||||
assert disabled.status_code == 200
|
||||
assert disabled.json()['enabled'] is False
|
||||
|
||||
|
||||
def test_otp_recovery_code_requires_password_and_is_single_use():
|
||||
login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json()
|
||||
headers = {'Authorization': f"Bearer {login['access_token']}"}
|
||||
setup = client.post('/api/user/otp/setup', headers=headers)
|
||||
secret = setup.json()['secret']
|
||||
recovery_code = setup.json()['recovery_codes'][0]
|
||||
assert client.post('/api/user/otp', headers=headers, json={
|
||||
'action': 'enable', 'code': current_code(secret),
|
||||
}).status_code == 200
|
||||
|
||||
rejected = client.post('/api/user/otp/recover', headers=headers, json={
|
||||
'current_password': 'wrong-password', 'recovery_code': recovery_code,
|
||||
})
|
||||
assert rejected.status_code == 400
|
||||
recovered = client.post('/api/user/otp/recover', headers=headers, json={
|
||||
'current_password': 'secret123', 'recovery_code': recovery_code,
|
||||
})
|
||||
assert recovered.status_code == 200
|
||||
reused = client.post('/api/user/otp/recover', headers=headers, json={
|
||||
'current_password': 'secret123', 'recovery_code': recovery_code,
|
||||
})
|
||||
assert reused.status_code == 400
|
||||
|
||||
|
||||
def test_verified_alternative_can_become_primary():
|
||||
login = client.post('/api/auth/login', json={'email': 'alice@example.com', 'password': 'secret123'}).json()
|
||||
headers = {'Authorization': f"Bearer {login['access_token']}"}
|
||||
|
||||
@@ -4,8 +4,6 @@ services:
|
||||
app:
|
||||
image: git.kolkman.org/olaf/link-log:development # or :latest or a version-tag
|
||||
container_name: ${APP_CONTAINER_NAME:-linklog-app}
|
||||
ports:
|
||||
- "${APP_PORT:-8000}:8000"
|
||||
volumes:
|
||||
- ./linklog_data:/app/backend/data
|
||||
environment:
|
||||
@@ -13,7 +11,8 @@ services:
|
||||
LINKLOG_APP_NAME: ${LINKLOG_APP_NAME:-LinkLog}
|
||||
LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db}
|
||||
LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env}
|
||||
LINKLOG_TOKEN_EXPIRY_DAYS: ${LINKLOG_TOKEN_EXPIRY_DAYS:-30}
|
||||
LINKLOG_TOKEN_EXPIRY_MINUTES: ${LINKLOG_TOKEN_EXPIRY_MINUTES:-15}
|
||||
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS: ${LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS:-30}
|
||||
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-linklog.example.com}
|
||||
LINKLOG_SMTP_HOST: ${LINKLOG_SMTP_HOST:-smtp.example.com}
|
||||
LINKLOG_SMTP_PORT: ${LINKLOG_SMTP_PORT:-587}
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
# Local development only. The production compose file intentionally does not publish port 8000.
|
||||
|
||||
services:
|
||||
app:
|
||||
build:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
container_name: ${APP_CONTAINER_NAME:-linklog-app-local}
|
||||
ports:
|
||||
- "${APP_PORT:-8000}:8000"
|
||||
volumes:
|
||||
- ./linklog_data:/app/backend/data
|
||||
environment:
|
||||
APP_ENV: ${APP_ENV:-development}
|
||||
LINKLOG_APP_NAME: ${LINKLOG_APP_NAME:-LinkLog}
|
||||
LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db}
|
||||
LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env}
|
||||
LINKLOG_DATA_ENCRYPTION_KEY: ${LINKLOG_DATA_ENCRYPTION_KEY:?Set LINKLOG_DATA_ENCRYPTION_KEY in .env}
|
||||
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-http://localhost:8000}
|
||||
LINKLOG_TOKEN_EXPIRY_MINUTES: ${LINKLOG_TOKEN_EXPIRY_MINUTES:-15}
|
||||
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS: ${LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS:-30}
|
||||
LINKLOG_LOG_LEVEL: ${LINKLOG_LOG_LEVEL:-DEBUG}
|
||||
LINKLOG_TRACKING_PARAMS: ${LINKLOG_TRACKING_PARAMS:-}
|
||||
restart: ${APP_RESTART_POLICY:-unless-stopped}
|
||||
healthcheck:
|
||||
test: ["CMD", "python", "-c", "from urllib.request import urlopen; urlopen('http://127.0.0.1:8000/health', timeout=3)"]
|
||||
interval: ${APP_HEALTHCHECK_INTERVAL:-30s}
|
||||
timeout: ${APP_HEALTHCHECK_TIMEOUT:-5s}
|
||||
start_period: ${APP_HEALTHCHECK_START_PERIOD:-10s}
|
||||
retries: ${APP_HEALTHCHECK_RETRIES:-3}
|
||||
+5
-6
@@ -7,8 +7,6 @@ services:
|
||||
context: .
|
||||
dockerfile: Dockerfile
|
||||
container_name: ${APP_CONTAINER_NAME:-linklog-app}
|
||||
ports:
|
||||
- "${APP_PORT:-8000}:8000"
|
||||
volumes:
|
||||
- ./linklog_data:/app/backend/data
|
||||
environment:
|
||||
@@ -17,9 +15,10 @@ services:
|
||||
LINKLOG_DATABASE_PATH: ${LINKLOG_DATABASE_PATH:-/app/backend/data/linklog.db}
|
||||
LINKLOG_SECRET_KEY: ${LINKLOG_SECRET_KEY:?Set LINKLOG_SECRET_KEY in .env}
|
||||
LINKLOG_DATA_ENCRYPTION_KEY: ${LINKLOG_DATA_ENCRYPTION_KEY:?Set LINKLOG_DATA_ENCRYPTION_KEY in .env}
|
||||
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-localhost}
|
||||
LINKLOG_PUBLIC_URL: ${LINKLOG_PUBLIC_URL:-linklog.example.com}
|
||||
LINKLOG_LOG_LEVEL: ${LINKLOG_LOG_LEVEL:-INFO}
|
||||
LINKLOG_TOKEN_EXPIRY_DAYS: ${LINKLOG_TOKEN_EXPIRY_DAYS:-30}
|
||||
LINKLOG_TOKEN_EXPIRY_MINUTES: ${LINKLOG_TOKEN_EXPIRY_MINUTES:-15}
|
||||
LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS: ${LINKLOG_REFRESH_TOKEN_EXPIRY_DAYS:-30}
|
||||
LINKLOG_TRACKING_PARAMS: ${LINKLOG_TRACKING_PARAMS:-}
|
||||
restart: ${APP_RESTART_POLICY:-unless-stopped}
|
||||
healthcheck:
|
||||
@@ -36,10 +35,10 @@ services:
|
||||
|
||||
|
||||
traefik.http.routers.linklog.entrypoints: web
|
||||
traefik.http.routers.linklog.rule: Host(`${LINKLOG_PUBLIC_URL:-localhost}`)
|
||||
traefik.http.routers.linklog.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
|
||||
traefik.http.routers.linklog.middlewares: web-https-redirect,servicests
|
||||
traefik.http.routers.linklog-secure.entrypoints: websecure
|
||||
traefik.http.routers.linklog-secure.rule: Host(`${LINKLOG_PUBLIC_URL:-localhost}`)
|
||||
traefik.http.routers.linklog-secure.rule: Host(`${LINKLOG_PUBLIC_URL:-linklog.example.com}`)
|
||||
traefik.http.routers.linklog-secure.tls: true
|
||||
traefik.http.routers.linklog-secure.middlewares: servicests
|
||||
|
||||
|
||||
@@ -152,6 +152,11 @@ function renderUsers(users) {
|
||||
privilegeLabel.append(privilegeCheckbox, document.createTextNode(' Administrator'));
|
||||
row.append(label, privilegeLabel);
|
||||
if (!isCurrentUser) {
|
||||
const otpButton = document.createElement('button');
|
||||
otpButton.type = 'button';
|
||||
otpButton.textContent = 'Reset OTP';
|
||||
otpButton.addEventListener('click', () => resetUserOtp(user, otpButton));
|
||||
row.append(otpButton);
|
||||
const button = document.createElement('button');
|
||||
button.type = 'button';
|
||||
button.className = 'danger-button';
|
||||
@@ -163,6 +168,27 @@ function renderUsers(users) {
|
||||
}));
|
||||
}
|
||||
|
||||
async function resetUserOtp(user, button) {
|
||||
if (!window.confirm(`Disable OTP for ${user.username}?`)) return;
|
||||
button.disabled = true;
|
||||
const status = document.querySelector('#user-status');
|
||||
try {
|
||||
const response = await fetch(`/api/admin/users/${encodeURIComponent(user.id)}/otp/reset`, {
|
||||
method: 'POST',
|
||||
headers: authHeaders(),
|
||||
});
|
||||
if (!response.ok) {
|
||||
throw new Error(await responseError(response, `Request failed (${response.status})`));
|
||||
}
|
||||
status.textContent = `OTP disabled for ${user.username}.`;
|
||||
status.style.color = '#94e2d5';
|
||||
} catch (error) {
|
||||
status.textContent = `Could not reset OTP for ${user.username}: ${error.message}`;
|
||||
status.style.color = '#f38ba8';
|
||||
button.disabled = false;
|
||||
}
|
||||
}
|
||||
|
||||
async function loadUsers() {
|
||||
const response = await fetch('/api/admin/users', {headers: authHeaders()});
|
||||
if (!response.ok) throw new Error('Could not load users');
|
||||
|
||||
@@ -12,8 +12,7 @@ logoutButton.addEventListener('click', async () => {
|
||||
if (token) {
|
||||
await fetch('/api/auth/logout', {
|
||||
method: 'POST',
|
||||
headers: {'Content-Type': 'application/json'},
|
||||
body: JSON.stringify({token}),
|
||||
headers: {Authorization: `Bearer ${token}`},
|
||||
}).catch(() => undefined);
|
||||
}
|
||||
|
||||
|
||||
@@ -12,11 +12,13 @@ const mastodonConnectButton = document.querySelector('#mastodon-connect');
|
||||
const otpSetupButton = document.querySelector('#otp-setup');
|
||||
const otpEnableButton = document.querySelector('#otp-enable');
|
||||
const otpDisableButton = document.querySelector('#otp-disable');
|
||||
const otpRecoverButton = document.querySelector('#otp-recover');
|
||||
const otpProvisioning = document.querySelector('#otp-provisioning');
|
||||
const otpDisabled = document.querySelector('#otp-disabled');
|
||||
const otpEnabled = document.querySelector('#otp-enabled');
|
||||
const otpSecret = document.querySelector('#otp-secret');
|
||||
const otpUri = document.querySelector('#otp-uri');
|
||||
const otpRecoveryCodes = document.querySelector('#otp-recovery-codes');
|
||||
const otpStatus = document.querySelector('#otp-status');
|
||||
const emailAddressList = document.querySelector('#email-address-list');
|
||||
const additionalEmailForm = document.querySelector('#additional-email-form');
|
||||
@@ -131,6 +133,7 @@ otpSetupButton.addEventListener('click', async () => {
|
||||
}
|
||||
otpSecret.textContent = result.secret;
|
||||
otpUri.href = result.otpauth_url;
|
||||
otpRecoveryCodes.textContent = result.recovery_codes.join('\n');
|
||||
otpProvisioning.classList.remove('hidden');
|
||||
setOtpStatus('Enter a code from your authenticator app to confirm setup.');
|
||||
});
|
||||
@@ -153,8 +156,9 @@ otpEnableButton.addEventListener('click', async () => {
|
||||
|
||||
otpDisableButton.addEventListener('click', async () => {
|
||||
const code = document.querySelector('#otp-disable-code').value.trim();
|
||||
const currentPassword = document.querySelector('#otp-current-password').value;
|
||||
const response = await fetch('/api/user/otp', {
|
||||
method: 'POST', headers: authHeaders(true), body: JSON.stringify({action: 'disable', code}),
|
||||
method: 'POST', headers: authHeaders(true), body: JSON.stringify({action: 'disable', code, current_password: currentPassword}),
|
||||
});
|
||||
const result = await response.json();
|
||||
if (!response.ok) {
|
||||
@@ -167,6 +171,24 @@ otpDisableButton.addEventListener('click', async () => {
|
||||
setOtpStatus('One-time password disabled.');
|
||||
});
|
||||
|
||||
otpRecoverButton.addEventListener('click', async () => {
|
||||
const currentPassword = document.querySelector('#otp-current-password').value;
|
||||
const recoveryCode = document.querySelector('#otp-recovery-code').value.trim();
|
||||
const response = await fetch('/api/user/otp/recover', {
|
||||
method: 'POST', headers: authHeaders(true), body: JSON.stringify({current_password: currentPassword, recovery_code: recoveryCode}),
|
||||
});
|
||||
const result = await response.json();
|
||||
if (!response.ok) {
|
||||
setOtpStatus(result.detail || 'Could not recover one-time password access.', true);
|
||||
return;
|
||||
}
|
||||
otpDisabled.classList.remove('hidden');
|
||||
otpEnabled.classList.add('hidden');
|
||||
document.querySelector('#otp-current-password').value = '';
|
||||
document.querySelector('#otp-recovery-code').value = '';
|
||||
setOtpStatus('One-time password access recovered.');
|
||||
});
|
||||
|
||||
async function loadProfile() {
|
||||
const response = await fetch('/api/user/me', {headers: authHeaders()});
|
||||
if (!response.ok) throw new Error('Could not load profile');
|
||||
|
||||
@@ -52,8 +52,14 @@
|
||||
<p>LinkLog is open source software. You can run your own instance, or contribute to the project on
|
||||
<a href="https://git.kolkman.org/olaf/Link-Log">my repository</a>.</p>
|
||||
</section>
|
||||
<section class="link-item">
|
||||
<h2>Plugin</h2>
|
||||
<p>Install the Firefox plugin to save links directly from your browser. <a
|
||||
href="https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi"
|
||||
download>Download and install the Plugin</a>.</p>
|
||||
</section>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<script src="/static/auth-header.js?v=3"></script>
|
||||
<script src="/static/logout.js?v=3"></script>
|
||||
<script src="/static/theme.js?v=1"></script>
|
||||
|
||||
@@ -115,7 +115,7 @@
|
||||
</section>
|
||||
</div>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<script src="/static/auth-header.js?v=3"></script>
|
||||
<script src="/static/logout.js?v=2"></script>
|
||||
<script src="/static/theme.js?v=1"></script>
|
||||
|
||||
@@ -76,7 +76,7 @@
|
||||
{% endif %}
|
||||
<section id="feed" class="feed" aria-live="polite"></section>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
|
||||
<script src="/static/auth-header.js?v=3"></script>
|
||||
<script src="/static/logout.js?v=3"></script>
|
||||
|
||||
@@ -44,7 +44,7 @@
|
||||
<div id="label-list" class="plugin-list"></div>
|
||||
</section>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<script src="/static/auth-header.js?v=3"></script>
|
||||
<script src="/static/logout.js?v=3"></script>
|
||||
<script src="/static/theme.js?v=1"></script>
|
||||
|
||||
@@ -55,7 +55,7 @@
|
||||
</form>
|
||||
</section>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<script src="/static/auth-header.js?v=3"></script>
|
||||
<script src="/static/logout.js?v=3"></script>
|
||||
<script src="/static/theme.js?v=1"></script>
|
||||
|
||||
@@ -42,7 +42,7 @@
|
||||
</form>
|
||||
</section>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman</footer>
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman</footer>
|
||||
<script src="/static/theme.js?v=1"></script>
|
||||
<script src="/static/setup.js"></script>
|
||||
</body>
|
||||
|
||||
@@ -59,6 +59,7 @@
|
||||
</label>
|
||||
<img id="avatar-preview" class="profile-avatar-preview hidden" alt="Avatar preview" />
|
||||
<button type="submit">Save profile</button>
|
||||
<p>If you have not downloaded the plugin yet, <a href="https://git.kolkman.org/olaf/Link-Log/raw/branch/main/XPI/signed/LinkLog-0.1.0.xpi" download>find it here</a>.</p>
|
||||
<p id="profile-status" class="status" role="status"></p>
|
||||
</form>
|
||||
</section>
|
||||
@@ -108,13 +109,19 @@
|
||||
<label>Verification code <input id="otp-setup-code" inputmode="numeric"
|
||||
autocomplete="one-time-code" /></label>
|
||||
<button id="otp-enable" type="button">Enable one-time password</button>
|
||||
<p>Save these recovery codes in a secure place. They are shown only once:</p>
|
||||
<code id="otp-recovery-codes"></code>
|
||||
</div>
|
||||
</div>
|
||||
<div id="otp-enabled" class="hidden">
|
||||
<p>One-time password is enabled.</p>
|
||||
<label>Current password <input id="otp-current-password" type="password" autocomplete="current-password" /></label>
|
||||
<label>Verification code <input id="otp-disable-code" inputmode="numeric"
|
||||
autocomplete="one-time-code" /></label>
|
||||
<button id="otp-disable" type="button">Disable one-time password</button>
|
||||
<p>Lost access to your authenticator? Use a saved recovery code.</p>
|
||||
<label>Recovery code <input id="otp-recovery-code" type="text" autocomplete="one-time-code" /></label>
|
||||
<button id="otp-recover" type="button">Recover and disable one-time password</button>
|
||||
</div>
|
||||
<p id="otp-status" class="status" role="status"></p>
|
||||
</section>
|
||||
@@ -138,7 +145,7 @@
|
||||
</form>
|
||||
</section>
|
||||
</main>
|
||||
<footer class="site-footer">Copyright © 2026 Olaf Kolkman · <a
|
||||
<footer class="site-footer">LinkLog Version {{ app_version }}. Copyright © 2026 Olaf Kolkman · <a
|
||||
href="https://git.kolkman.org/olaf/Link-Log">git.kolkman.org/LinkLog</a></footer>
|
||||
<script src="/static/auth-header.js?v=3"></script>
|
||||
<script src="/static/logout.js?v=2"></script>
|
||||
|
||||
Binary file not shown.
|
Before Width: | Height: | Size: 320 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 1.9 MiB |
@@ -9,61 +9,66 @@ from pathlib import Path
|
||||
|
||||
|
||||
ROOT = Path(__file__).resolve().parents[2]
|
||||
MANIFEST_PATH = ROOT / 'webextension' / 'manifest.json'
|
||||
FRONTEND_VERSION_PATH = ROOT / 'frontend' / 'version.json'
|
||||
SETTINGS_PATH = ROOT / 'backend' / 'app' / 'core' / 'config.py'
|
||||
UPDATES_PATH = ROOT / 'webextension' / 'updates.json'
|
||||
SIGNED_DIR = ROOT / 'XPI' / 'signed'
|
||||
VERSION_RE = re.compile(r'\d+\.\d+\.\d+')
|
||||
|
||||
|
||||
def fail(message: str) -> None:
|
||||
raise SystemExit(f'release validation failed: {message}')
|
||||
|
||||
|
||||
def version_key(version: str) -> tuple[int, int, int]:
|
||||
return tuple(int(part) for part in version.split('.'))
|
||||
|
||||
|
||||
def find_latest_signed_xpi() -> tuple[str, Path]:
|
||||
candidates = []
|
||||
for xpi_path in SIGNED_DIR.glob('LinkLog-*.xpi'):
|
||||
match = re.fullmatch(r'LinkLog-(\d+\.\d+\.\d+)\.xpi', xpi_path.name)
|
||||
if match:
|
||||
candidates.append((match.group(1), xpi_path))
|
||||
if not candidates:
|
||||
fail(f'no signed plugin artifacts found in {SIGNED_DIR.relative_to(ROOT)}')
|
||||
return max(candidates, key=lambda candidate: version_key(candidate[0]))
|
||||
|
||||
|
||||
def main() -> None:
|
||||
manifest = json.loads(MANIFEST_PATH.read_text())
|
||||
extension_version = manifest.get('version')
|
||||
if not isinstance(extension_version, str) or not re.fullmatch(r'\d+\.\d+\.\d+', extension_version):
|
||||
fail('webextension/manifest.json has no valid three-part version')
|
||||
|
||||
frontend_version = json.loads(FRONTEND_VERSION_PATH.read_text()).get('version')
|
||||
if frontend_version != extension_version:
|
||||
fail(f'frontend version {frontend_version} does not match extension version {extension_version}')
|
||||
|
||||
gecko_settings = manifest.get('browser_specific_settings', {}).get('gecko', {})
|
||||
data_permissions = gecko_settings.get('data_collection_permissions')
|
||||
if data_permissions != {'required': ['websiteActivity'], 'optional': []}:
|
||||
fail('Firefox data_collection_permissions must require websiteActivity and have no optional categories')
|
||||
|
||||
settings = SETTINGS_PATH.read_text()
|
||||
match = re.search(r"version: str = os\.getenv\('LINKLOG_VERSION', '([^']+)'\)", settings)
|
||||
if not match:
|
||||
fail('backend version default could not be found')
|
||||
backend_version = match.group(1)
|
||||
if backend_version != extension_version:
|
||||
fail(f'backend version {backend_version} does not match extension version {extension_version}')
|
||||
if not VERSION_RE.fullmatch(backend_version):
|
||||
fail(f'backend version {backend_version} is not a valid three-part version')
|
||||
|
||||
xpi_path = SIGNED_DIR / f'LinkLog-{extension_version}.xpi'
|
||||
if not xpi_path.is_file():
|
||||
fail(f'missing manually signed artifact: {xpi_path.relative_to(ROOT)}')
|
||||
extension_version, xpi_path = find_latest_signed_xpi()
|
||||
with zipfile.ZipFile(xpi_path) as archive:
|
||||
try:
|
||||
packaged_manifest = json.loads(archive.read('manifest.json'))
|
||||
except KeyError:
|
||||
fail('signed XPI does not contain manifest.json')
|
||||
if packaged_manifest.get('version') != extension_version:
|
||||
fail('signed XPI manifest version does not match webextension/manifest.json')
|
||||
fail('signed XPI manifest version does not match its filename')
|
||||
gecko_settings = packaged_manifest.get('browser_specific_settings', {}).get('gecko', {})
|
||||
data_permissions = gecko_settings.get('data_collection_permissions')
|
||||
if data_permissions != {'required': ['websiteActivity'], 'optional': []}:
|
||||
fail('Firefox data_collection_permissions must require websiteActivity and have no optional categories')
|
||||
if archive.testzip() is not None:
|
||||
fail('signed XPI contains a corrupt member')
|
||||
|
||||
updates = json.loads(UPDATES_PATH.read_text())
|
||||
addon_id = gecko_settings['id']
|
||||
update_entries = updates.get('addons', {}).get(addon_id, {}).get('updates', [])
|
||||
if not any(entry.get('version') == extension_version for entry in update_entries):
|
||||
fail(f'webextension/updates.json has no update entry for {extension_version}')
|
||||
signed_xpi = xpi_path.relative_to(ROOT)
|
||||
if len(sys.argv) == 3 and sys.argv[1] == '--github-output':
|
||||
with Path(sys.argv[2]).open('a') as output:
|
||||
print(f'backend_version={backend_version}', file=output)
|
||||
print(f'plugin_version={extension_version}', file=output)
|
||||
print(f'signed_xpi={signed_xpi}', file=output)
|
||||
elif len(sys.argv) != 1:
|
||||
fail('usage: validate_release.py [--github-output <path>]')
|
||||
|
||||
print(f'validated LinkLog release {frontend_version}')
|
||||
print(f'xpi={xpi_path.relative_to(ROOT)}')
|
||||
print(f'validated LinkLog backend release {backend_version}')
|
||||
print(f'plugin_version={extension_version}')
|
||||
print(f'signed_xpi={signed_xpi}')
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
|
||||
@@ -6,9 +6,15 @@
|
||||
"default_locale": "en-US",
|
||||
"permissions": [
|
||||
"activeTab",
|
||||
"storage",
|
||||
"tabs"
|
||||
"storage"
|
||||
],
|
||||
"optional_permissions": [
|
||||
"http://*/*",
|
||||
"https://*/*"
|
||||
],
|
||||
"content_security_policy": {
|
||||
"extension_pages": "script-src 'self'; object-src 'none'"
|
||||
},
|
||||
"action": {
|
||||
"default_title": "__MSG_extensionName__",
|
||||
"default_popup": "popup.html",
|
||||
@@ -24,7 +30,7 @@
|
||||
"browser_specific_settings": {
|
||||
"gecko": {
|
||||
"id": "linklog@kolkman.org",
|
||||
"strict_min_version": "109.0",
|
||||
"strict_min_version": "142.0",
|
||||
"data_collection_permissions": {
|
||||
"required": ["websiteActivity"],
|
||||
"optional": []
|
||||
|
||||
+64
-108
@@ -10,6 +10,7 @@ const otpInput = document.getElementById('otp');
|
||||
const session = document.getElementById('logged-in');
|
||||
const sessionSummary = document.getElementById('session-summary');
|
||||
const signOutButton = document.getElementById('sign-out');
|
||||
const sessionStore = browser.storage.session;
|
||||
|
||||
const t = window.linklogI18n;
|
||||
|
||||
@@ -25,18 +26,17 @@ function normalizeBackendOrigin(backendUrl) {
|
||||
}
|
||||
}
|
||||
|
||||
async function ensureExactBackendPermission(backendUrl) {
|
||||
async function hasBackendPermission(backendUrl) {
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin) {
|
||||
return false;
|
||||
}
|
||||
if (!origin) return false;
|
||||
return browser.permissions.contains({origins: [`${origin}/*`]});
|
||||
}
|
||||
|
||||
async function requestBackendPermission(backendUrl) {
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin) return false;
|
||||
try {
|
||||
const hasPermission = await browser.permissions.contains({ origins: [`${origin}/*`] });
|
||||
if (hasPermission) {
|
||||
return true;
|
||||
}
|
||||
return await browser.permissions.request({ origins: [`${origin}/*`] });
|
||||
return await browser.permissions.request({origins: [`${origin}/*`]});
|
||||
} catch (error) {
|
||||
return false;
|
||||
}
|
||||
@@ -49,104 +49,25 @@ function setStatus(message, isError = false) {
|
||||
statusEl.classList.toggle('success', !isError);
|
||||
}
|
||||
|
||||
async function getStoredSession() {
|
||||
const [localSettings, sessionSettings] = await Promise.all([
|
||||
browser.storage.local.get(['backendUrl', 'email', 'username']),
|
||||
browser.storage.session.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
|
||||
return {
|
||||
backendUrl: localSettings.backendUrl || '',
|
||||
email: localSettings.email || '',
|
||||
username: localSettings.username || '',
|
||||
deviceId: sessionSettings.deviceId || '',
|
||||
accessToken: sessionSettings.accessToken || '',
|
||||
refreshToken: sessionSettings.refreshToken || '',
|
||||
tokenExpiresAt: sessionSettings.tokenExpiresAt || '',
|
||||
};
|
||||
}
|
||||
|
||||
async function persistSession(session) {
|
||||
await browser.storage.local.set({
|
||||
backendUrl: session.backendUrl || '',
|
||||
email: session.email || '',
|
||||
username: session.username || '',
|
||||
});
|
||||
|
||||
await browser.storage.session.set({
|
||||
accessToken: session.accessToken || '',
|
||||
refreshToken: session.refreshToken || '',
|
||||
tokenExpiresAt: session.tokenExpiresAt || '',
|
||||
deviceId: session.deviceId || '',
|
||||
});
|
||||
}
|
||||
|
||||
async function refreshAccessToken() {
|
||||
const session = await getStoredSession();
|
||||
if (!session.backendUrl || !session.refreshToken || !session.deviceId) {
|
||||
return null;
|
||||
}
|
||||
|
||||
try {
|
||||
const response = await fetch(`${session.backendUrl}/api/auth/refresh`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({
|
||||
refresh_token: session.refreshToken,
|
||||
device_id: session.deviceId,
|
||||
}),
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
|
||||
const data = await response.json();
|
||||
const refreshedSession = {
|
||||
...session,
|
||||
accessToken: data.access_token,
|
||||
refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
deviceId: data.device_id || session.deviceId,
|
||||
};
|
||||
await persistSession(refreshedSession);
|
||||
return refreshedSession;
|
||||
} catch (error) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function loadSettings() {
|
||||
const settings = await getStoredSession();
|
||||
const [settings, sessionSettings] = await Promise.all([
|
||||
browser.storage.local.get(['backendUrl', 'email', 'username']),
|
||||
sessionStore.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
backendUrlInput.value = settings.backendUrl || '';
|
||||
emailInput.value = settings.email || '';
|
||||
|
||||
if (settings.accessToken && settings.backendUrl) {
|
||||
if (sessionSettings.accessToken && settings.backendUrl && await hasBackendPermission(settings.backendUrl)) {
|
||||
try {
|
||||
const response = await fetch(
|
||||
`${settings.backendUrl}/api/auth/me`,
|
||||
{headers: {Authorization: `Bearer ${settings.accessToken}`}},
|
||||
{headers: {Authorization: `Bearer ${sessionSettings.accessToken}`}},
|
||||
);
|
||||
if (response.ok) {
|
||||
const user = await response.json();
|
||||
showLoggedIn(user.username || settings.email, settings.backendUrl);
|
||||
return;
|
||||
}
|
||||
if (response.status === 401) {
|
||||
const refreshed = await refreshAccessToken();
|
||||
if (refreshed) {
|
||||
const userResponse = await fetch(
|
||||
`${refreshed.backendUrl}/api/auth/me`,
|
||||
{headers: {Authorization: `Bearer ${refreshed.accessToken}`}},
|
||||
);
|
||||
if (userResponse.ok) {
|
||||
const user = await userResponse.json();
|
||||
showLoggedIn(user.username || refreshed.email, refreshed.backendUrl);
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
} catch (error) {
|
||||
// Show the login form when the backend cannot validate the stored token.
|
||||
}
|
||||
@@ -168,27 +89,46 @@ function showLoggedOut() {
|
||||
|
||||
async function clearSession() {
|
||||
await Promise.all([
|
||||
sessionStore.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken', 'deviceId']),
|
||||
browser.storage.session.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
}
|
||||
|
||||
async function refreshAccessToken(settings) {
|
||||
if (!settings.backendUrl || !settings.refreshToken || !settings.deviceId) return null;
|
||||
try {
|
||||
const response = await fetch(`${settings.backendUrl}/api/auth/refresh`, {
|
||||
method: 'POST',
|
||||
headers: {'Content-Type': 'application/json'},
|
||||
body: JSON.stringify({refresh_token: settings.refreshToken, device_id: settings.deviceId}),
|
||||
});
|
||||
if (!response.ok) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
const data = await response.json();
|
||||
const refreshed = {accessToken: data.access_token, refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at, deviceId: data.device_id || settings.deviceId};
|
||||
await sessionStore.set(refreshed);
|
||||
return refreshed;
|
||||
} catch (error) {
|
||||
return null;
|
||||
}
|
||||
}
|
||||
|
||||
async function saveSettingsAndLogin(event) {
|
||||
event.preventDefault();
|
||||
const backendUrl = backendUrlInput.value.trim();
|
||||
const backendUrl = normalizeBackendOrigin(backendUrlInput.value.trim());
|
||||
const email = emailInput.value.trim();
|
||||
const password = passwordInput.value;
|
||||
const otp = otpInput.value.trim();
|
||||
const existingSession = await getStoredSession();
|
||||
const deviceId = existingSession.deviceId || crypto.randomUUID();
|
||||
|
||||
if (!backendUrl || !email || !password) {
|
||||
setStatus(t('fillAllFields'), true);
|
||||
return;
|
||||
}
|
||||
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin || !(await ensureExactBackendPermission(backendUrl))) {
|
||||
if (!(await requestBackendPermission(backendUrl))) {
|
||||
setStatus(t('unableToLogIn'), true);
|
||||
return;
|
||||
}
|
||||
@@ -197,7 +137,7 @@ async function saveSettingsAndLogin(event) {
|
||||
const response = await fetch(`${backendUrl}/api/auth/login`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ email, password, otp: otp || null, device_id: deviceId })
|
||||
body: JSON.stringify({ email, password, otp: otp || null })
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
@@ -205,14 +145,29 @@ async function saveSettingsAndLogin(event) {
|
||||
}
|
||||
|
||||
const data = await response.json();
|
||||
await persistSession({
|
||||
if (response.status === 401) {
|
||||
const refreshed = await refreshAccessToken({...settings, ...sessionSettings});
|
||||
if (refreshed) {
|
||||
const retry = await fetch(`${settings.backendUrl}/api/auth/me`, {
|
||||
headers: {Authorization: `Bearer ${refreshed.accessToken}`},
|
||||
});
|
||||
if (retry.ok) {
|
||||
const user = await retry.json();
|
||||
showLoggedIn(user.username || settings.email, settings.backendUrl);
|
||||
return;
|
||||
}
|
||||
}
|
||||
}
|
||||
await browser.storage.local.set({
|
||||
backendUrl,
|
||||
email,
|
||||
username: data.user?.username || email,
|
||||
});
|
||||
await sessionStore.set({
|
||||
accessToken: data.access_token,
|
||||
refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
deviceId: data.device_id || crypto.randomUUID(),
|
||||
deviceId: data.device_id || `device-${crypto.randomUUID()}`,
|
||||
});
|
||||
|
||||
showLoggedIn(data.user?.username || email, backendUrl);
|
||||
@@ -225,12 +180,13 @@ async function saveSettingsAndLogin(event) {
|
||||
}
|
||||
|
||||
async function signOut() {
|
||||
const settings = await getStoredSession();
|
||||
if (settings.accessToken && settings.backendUrl) {
|
||||
await fetch(`${settings.backendUrl}/api/auth/logout`, {
|
||||
const settings = await browser.storage.local.get(['backendUrl']);
|
||||
const sessionSettings = await sessionStore.get(['accessToken']);
|
||||
const backendUrl = normalizeBackendOrigin(backendUrlInput.value.trim());
|
||||
if (sessionSettings.accessToken && settings.backendUrl && await hasBackendPermission(backendUrl)) {
|
||||
await fetch(`${backendUrl}/api/auth/logout`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({ token: settings.accessToken }),
|
||||
headers: {Authorization: `Bearer ${sessionSettings.accessToken}`},
|
||||
}).catch(() => undefined);
|
||||
}
|
||||
await clearSession();
|
||||
|
||||
+38
-83
@@ -13,6 +13,7 @@ const feedLink = document.getElementById('feed-link');
|
||||
const authWarning = document.getElementById('auth-warning');
|
||||
const warningSettingsButton = document.getElementById('warning-settings');
|
||||
const authSession = document.getElementById('auth-session');
|
||||
const sessionStore = browser.storage.session;
|
||||
|
||||
const t = window.linklogI18n;
|
||||
|
||||
@@ -28,21 +29,10 @@ function normalizeBackendOrigin(backendUrl) {
|
||||
}
|
||||
}
|
||||
|
||||
async function ensureExactBackendPermission(backendUrl) {
|
||||
async function hasBackendPermission(backendUrl) {
|
||||
const origin = normalizeBackendOrigin(backendUrl);
|
||||
if (!origin) {
|
||||
return false;
|
||||
}
|
||||
|
||||
try {
|
||||
const hasPermission = await browser.permissions.contains({ origins: [`${origin}/*`] });
|
||||
if (hasPermission) {
|
||||
return true;
|
||||
}
|
||||
return await browser.permissions.request({ origins: [`${origin}/*`] });
|
||||
} catch (error) {
|
||||
return false;
|
||||
}
|
||||
if (!origin) return false;
|
||||
return browser.permissions.contains({origins: [`${origin}/*`]});
|
||||
}
|
||||
|
||||
function setStatus(message, isError = false) {
|
||||
@@ -53,69 +43,44 @@ function setStatus(message, isError = false) {
|
||||
}
|
||||
|
||||
async function getSettings() {
|
||||
const [localSettings, sessionSettings] = await Promise.all([
|
||||
browser.storage.local.get(['backendUrl']),
|
||||
browser.storage.session.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
const [settings, sessionSettings] = await Promise.all([
|
||||
browser.storage.local.get(['backendUrl', 'username']),
|
||||
sessionStore.get(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
|
||||
return {
|
||||
backendUrl: localSettings.backendUrl || '',
|
||||
deviceId: sessionSettings.deviceId || '',
|
||||
accessToken: sessionSettings.accessToken || '',
|
||||
refreshToken: sessionSettings.refreshToken || '',
|
||||
tokenExpiresAt: sessionSettings.tokenExpiresAt || '',
|
||||
};
|
||||
return {...settings, ...sessionSettings};
|
||||
}
|
||||
|
||||
async function persistSession(session) {
|
||||
await browser.storage.local.set({
|
||||
backendUrl: session.backendUrl || '',
|
||||
});
|
||||
|
||||
await browser.storage.session.set({
|
||||
accessToken: session.accessToken || '',
|
||||
refreshToken: session.refreshToken || '',
|
||||
tokenExpiresAt: session.tokenExpiresAt || '',
|
||||
deviceId: session.deviceId || '',
|
||||
async function persistSession(settings) {
|
||||
await sessionStore.set({
|
||||
accessToken: settings.accessToken,
|
||||
refreshToken: settings.refreshToken,
|
||||
tokenExpiresAt: settings.tokenExpiresAt,
|
||||
deviceId: settings.deviceId,
|
||||
});
|
||||
}
|
||||
|
||||
async function clearSession() {
|
||||
await Promise.all([
|
||||
sessionStore.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
browser.storage.local.remove(['accessToken', 'tokenType', 'tokenExpiresAt', 'refreshToken', 'deviceId']),
|
||||
browser.storage.session.remove(['accessToken', 'refreshToken', 'tokenExpiresAt', 'deviceId']),
|
||||
]);
|
||||
}
|
||||
|
||||
async function refreshAccessToken() {
|
||||
const settings = await getSettings();
|
||||
if (!settings.backendUrl || !settings.refreshToken || !settings.deviceId) {
|
||||
return null;
|
||||
}
|
||||
|
||||
async function refreshAccessToken(settings) {
|
||||
if (!settings.backendUrl || !settings.refreshToken || !settings.deviceId) return null;
|
||||
try {
|
||||
const response = await fetch(`${settings.backendUrl}/api/auth/refresh`, {
|
||||
method: 'POST',
|
||||
headers: { 'Content-Type': 'application/json' },
|
||||
body: JSON.stringify({
|
||||
refresh_token: settings.refreshToken,
|
||||
device_id: settings.deviceId,
|
||||
}),
|
||||
headers: {'Content-Type': 'application/json'},
|
||||
body: JSON.stringify({refresh_token: settings.refreshToken, device_id: settings.deviceId}),
|
||||
});
|
||||
|
||||
if (!response.ok) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
|
||||
const data = await response.json();
|
||||
const refreshed = {
|
||||
...settings,
|
||||
accessToken: data.access_token,
|
||||
refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at,
|
||||
deviceId: data.device_id || settings.deviceId,
|
||||
};
|
||||
const refreshed = {...settings, accessToken: data.access_token, refreshToken: data.refresh_token,
|
||||
tokenExpiresAt: data.expires_at, deviceId: data.device_id || settings.deviceId};
|
||||
await persistSession(refreshed);
|
||||
return refreshed;
|
||||
} catch (error) {
|
||||
@@ -124,25 +89,19 @@ async function refreshAccessToken() {
|
||||
}
|
||||
|
||||
async function validateSession(settings) {
|
||||
if (!settings.backendUrl || !settings.accessToken) return null;
|
||||
if (!(await ensureExactBackendPermission(settings.backendUrl))) {
|
||||
await clearSession();
|
||||
return null;
|
||||
}
|
||||
if (!settings.backendUrl || !settings.accessToken || !(await hasBackendPermission(settings.backendUrl))) return null;
|
||||
try {
|
||||
const response = await fetch(`${settings.backendUrl}/api/auth/me`, {
|
||||
headers: {'Authorization': `Bearer ${settings.accessToken}`},
|
||||
});
|
||||
if (!response.ok) {
|
||||
if (response.status === 401) {
|
||||
const refreshed = await refreshAccessToken();
|
||||
if (refreshed && refreshed.accessToken) {
|
||||
const refreshed = await refreshAccessToken(settings);
|
||||
if (refreshed) {
|
||||
const retry = await fetch(`${refreshed.backendUrl}/api/auth/me`, {
|
||||
headers: {'Authorization': `Bearer ${refreshed.accessToken}`},
|
||||
});
|
||||
if (retry.ok) {
|
||||
return await retry.json();
|
||||
}
|
||||
if (retry.ok) return await retry.json();
|
||||
}
|
||||
}
|
||||
await clearSession();
|
||||
@@ -186,11 +145,10 @@ function showSavedState(message) {
|
||||
|
||||
async function updateFeedLink() {
|
||||
const settings = await getSettings();
|
||||
if (!settings.backendUrl || !settings.accessToken) return;
|
||||
const username = await browser.storage.local.get(['username']);
|
||||
if (!settings.backendUrl || !settings.username || !settings.accessToken) return;
|
||||
try {
|
||||
const backend = new URL(settings.backendUrl);
|
||||
feedLink.href = `${backend.origin}/${encodeURIComponent(username.username || settings.deviceId || 'user')}/`;
|
||||
feedLink.href = `${backend.origin}/${encodeURIComponent(settings.username)}/`;
|
||||
feedLink.classList.remove('hidden');
|
||||
} catch (error) {
|
||||
feedLink.classList.add('hidden');
|
||||
@@ -208,9 +166,10 @@ async function loadExistingTags() {
|
||||
showSignedOutState();
|
||||
return;
|
||||
}
|
||||
showSignedInState(user, settings.backendUrl);
|
||||
const response = await fetch(`${settings.backendUrl}/api/tags`, {
|
||||
headers: {'Authorization': `Bearer ${settings.accessToken}`},
|
||||
const currentSettings = await getSettings();
|
||||
showSignedInState(user, currentSettings.backendUrl);
|
||||
const response = await fetch(`${currentSettings.backendUrl}/api/tags`, {
|
||||
headers: {'Authorization': `Bearer ${currentSettings.accessToken}`},
|
||||
});
|
||||
if (!response.ok) {
|
||||
if (response.status === 401) {
|
||||
@@ -264,7 +223,7 @@ async function populateCurrentTab() {
|
||||
|
||||
async function checkExistingLink() {
|
||||
const settings = await getSettings();
|
||||
if (!settings.backendUrl || !settings.accessToken || !titleInput.value || !urlInput.value) return;
|
||||
if (!settings.backendUrl || !settings.accessToken || !(await hasBackendPermission(settings.backendUrl)) || !titleInput.value || !urlInput.value) return;
|
||||
try {
|
||||
const response = await fetch(`${settings.backendUrl}/api/links/check?${new URLSearchParams({
|
||||
title: titleInput.value,
|
||||
@@ -288,13 +247,7 @@ async function handleSubmit(event) {
|
||||
const token = settings.accessToken;
|
||||
const backendUrl = settings.backendUrl;
|
||||
|
||||
if (!backendUrl || !(await ensureExactBackendPermission(backendUrl))) {
|
||||
setStatus(t('configureAndLogIn'), true);
|
||||
browser.runtime.openOptionsPage();
|
||||
return;
|
||||
}
|
||||
|
||||
if (!token || !backendUrl) {
|
||||
if (!token || !backendUrl || !(await hasBackendPermission(backendUrl))) {
|
||||
setStatus(t('configureAndLogIn'), true);
|
||||
browser.runtime.openOptionsPage();
|
||||
return;
|
||||
@@ -307,12 +260,14 @@ async function handleSubmit(event) {
|
||||
return;
|
||||
}
|
||||
|
||||
const currentSettings = await getSettings();
|
||||
|
||||
try {
|
||||
const response = await fetch(`${backendUrl}/api/links`, {
|
||||
const response = await fetch(`${currentSettings.backendUrl}/api/links`, {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/json',
|
||||
'Authorization': `Bearer ${token}`,
|
||||
'Authorization': `Bearer ${currentSettings.accessToken}`,
|
||||
},
|
||||
body: JSON.stringify({
|
||||
title: titleInput.value,
|
||||
@@ -335,7 +290,7 @@ async function handleSubmit(event) {
|
||||
}
|
||||
|
||||
const result = await response.json();
|
||||
const saveMessage = result.duplicate ? t('linkAlreadyExists') : t('linkSaved', backendUrl);
|
||||
const saveMessage = result.duplicate ? t('linkAlreadyExists') : t('linkSaved', currentSettings.backendUrl);
|
||||
if (result.plugin_errors?.length) {
|
||||
const errors = result.plugin_errors.map((error) => `${error.plugin}: ${error.reason}`).join(' ');
|
||||
showSavedState(`${saveMessage} ${t('publishingErrors', errors)}`);
|
||||
|
||||
Reference in New Issue
Block a user