Repository navigation
fix(auth): enforce the forced password change on the server - #217
Open
TartanLeGrand wants to merge 2 commits into
Open
TartanLeGrand wants to merge 2 commits into
TartanLeGrand wants to merge 2 commits into
Conversation
A user flagged mustChangePassword (bootstrap admin, users created or reset by an administrator) could call every RPC and protected route with their session: only the web UI redirected them to the password page. The flag is now carried by the principal and CheckPermission refuses every non-public permission with 403 "password change required". Public RPCs (Me, GetAuthConfig) and the unguarded login, logout and change-password handlers stay reachable. API keys, anonymous and OIDC principals never carry the flag. The refusal is counted as result="password_change_required" in tracker_auth_requests_total. Refs BananaOps#196
Document the password_change_required metric result, state precisely which calls stay reachable and what an administrator reset does to existing sessions, and assert the refused RPC code and message. Refs BananaOps#196
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
A user flagged
mustChangePassword(the bootstrapadmin, users created or reset by an administrator) could call every API endpoint with their session: only the web UI redirected them to the password page. The server now enforces it.PrincipalcarriesMustChangePassword, set from the user record when a session is resolved. API keys, anonymous callers and OpenID Connect users are never flagged.authz.CheckPermissionrefuses a flagged principal for every permission except public ones: HTTP 403{"error":"password change required"}, gRPCPermissionDenied. It covers every RPC (throughAuthorize) and every hand-written route wrapped byRequireHTTP(links, Homer).GET /auth/me,GET /auth/config, login, logout andPOST /auth/password(not wrapped by authz). Web assets,/config.jsand the API docs serve no data and are unchanged.tracker_auth_requests_total{result="password_change_required"}.Behaviour around the change
Checks
go test(serial, MongoDB 7): green. New tests: authz unit tests, resolver test, an end-to-end flow through the real mux (flagged admin gets 403 on data and admin endpoints, 200 on/auth/me, changes the password, new cookie works, old cookie 401, logout works while flagged), team API keys unaffected by their creator's flag.go vet,golangci-lint(0 issues),gosec(0 issues).Existing service tests that called admin RPCs as the (flagged) bootstrap admin now clear the flag on their test principal only; production behaviour is not relaxed.
Refs #196