fix(security): critical — repair PIN reset + enforce real prod secrets
C1: reset_user_pin wrote to a non-existent column (pin_failed_attempts);
the real column is failed_pin_attempts, so every PIN reset 500'd. Fixed
the column name; new e2e (pin-reset.spec.ts) proves a reset returns a
usable PIN and the target can recover with it.
C2: config.rs::validate_secrets now rejects placeholder-ish secrets
(change_me/dev_secret/placeholder), enforces len>=32 in prod, and
requires a real ADMIN_PASSWORD_HASH. docker-compose.yml sets
APP_ENV=production so the guard actually runs. Corrected the false
"fixed" claim in SECURITY-BACKLOG.md. .env.example documents the rule.
Riders in these files (documented here since git can't split hunks):
- host.rs also carries the event-scoped ban_user fix and the
close_event/open_event no-op broadcast guard (medium).
- docker-compose.yml also adds ORIGIN (H6), app/frontend healthchecks with
Caddy waiting on health, and per-service memory limits (medium).
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -117,6 +117,25 @@ export class ApiClient {
|
||||
});
|
||||
}
|
||||
|
||||
async unbanUser(token: string, userId: string, opts: { expectedStatus?: number | number[] } = {}) {
|
||||
return this.request<void>('POST', `/host/users/${userId}/unban`, {
|
||||
token,
|
||||
expectedStatus: opts.expectedStatus ?? [200, 204],
|
||||
});
|
||||
}
|
||||
|
||||
/** Reset another user's PIN. Returns the plaintext PIN the host must relay once. */
|
||||
async resetUserPin(
|
||||
token: string,
|
||||
userId: string,
|
||||
opts: { expectedStatus?: number | number[] } = {}
|
||||
): Promise<{ status: number; body: { pin?: string } }> {
|
||||
return this.request<{ pin?: string }>('POST', `/host/users/${userId}/pin-reset`, {
|
||||
token,
|
||||
expectedStatus: opts.expectedStatus ?? [200],
|
||||
});
|
||||
}
|
||||
|
||||
async closeEvent(token: string) {
|
||||
return this.request<void>('POST', '/host/event/close', { token, expectedStatus: [200, 204] });
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user