Remediate the HIGH and security-relevant findings from the 2026-07-11 audit. H1 — the per-env approval gate is now server-authoritative. The governing project is resolved from the target node's nearest-claimed ancestor (`governing_env_policy`/`_tree` + `governing_project_id` + `ProjectRepository::get_environments_by_id`), independent of the client-supplied `[project]`. Omitting or spoofing the project block can no longer skip a gate the owning project established; a to-create group resolves its declared parent's chain so a fresh subtree node inherits the gate. Fails closed on any read error. H2 — the API-key prefix slice (`&rest[..8]`) is now the boundary-safe `rest.get(..8)`, so an attacker-supplied multibyte bearer can't panic the request task (unauthenticated per-request DoS). Regression test added. C1 — admin sessions gain an absolute lifetime cap (migration 0070, `PICLOUD_SESSION_ABSOLUTE_TTL_HOURS`, default 30d): `lookup` filters it, `touch` clamps the sliding bump to it, so a continuously-used or stolen-but-warm token self-expires. Mirrors the data-plane app-user cap. C2 — `Cache-Control: no-store` on the login and API-key-mint responses (the two that return a raw credential), so a proxy/CDN/browser cache can't retain it. B8 — file downloads are header-safe: `sanitize_stored_filename` guarantees a valid `HeaderValue` (no panic on a control-char name) and BOTH the per-app and group download paths now set attachment + `X-Content-Type-Options: nosniff` + a restrictive CSP, closing a group-path stored-XSS gap. Also folds in the server-side plan-warning plumbing (`plan_warnings`, `PlanResult::warnings`) and the `app_only_reject` message helper that the CLI plan-preview change builds on, plus operator security notes (reads-open shared- topic SSE; the `--env` label is advisory, not a boundary). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
163 lines
5.3 KiB
Rust
163 lines
5.3 KiB
Rust
//! CRUD over the `admin_sessions` table.
|
|
//!
|
|
//! The token never appears in this module — only its SHA-256 hash. The
|
|
//! raw value lives in `auth::GeneratedToken` long enough to hit the
|
|
//! cookie and the JSON response, then is forgotten. Lookups also filter
|
|
//! expired rows at query time so a delayed prune sweep can never extend
|
|
//! a session's life.
|
|
|
|
use async_trait::async_trait;
|
|
use chrono::{DateTime, Utc};
|
|
use picloud_shared::AdminUserId;
|
|
use sqlx::PgPool;
|
|
|
|
#[derive(Debug, thiserror::Error)]
|
|
pub enum AdminSessionRepositoryError {
|
|
#[error("database error: {0}")]
|
|
Db(#[from] sqlx::Error),
|
|
}
|
|
|
|
/// Result of a session lookup. Includes the user id (for auth context),
|
|
/// the existing `expires_at` (so the middleware can decide whether the
|
|
/// sliding-window bump is worth a write), and the `absolute_expires_at`
|
|
/// hard cap the bump must clamp at (C1).
|
|
#[derive(Debug, Clone)]
|
|
pub struct AdminSessionLookup {
|
|
pub user_id: AdminUserId,
|
|
pub expires_at: DateTime<Utc>,
|
|
pub absolute_expires_at: DateTime<Utc>,
|
|
}
|
|
|
|
#[async_trait]
|
|
pub trait AdminSessionRepository: Send + Sync {
|
|
async fn create(
|
|
&self,
|
|
user_id: AdminUserId,
|
|
token_hash: &str,
|
|
expires_at: DateTime<Utc>,
|
|
absolute_expires_at: DateTime<Utc>,
|
|
) -> Result<(), AdminSessionRepositoryError>;
|
|
/// Look up a session by token hash. Returns `None` for missing or
|
|
/// already-expired rows — either the sliding `expires_at` OR the
|
|
/// absolute cap having passed (the query filters both).
|
|
async fn lookup(
|
|
&self,
|
|
token_hash: &str,
|
|
) -> Result<Option<AdminSessionLookup>, AdminSessionRepositoryError>;
|
|
/// Sliding-window bump. Sets `last_used_at = NOW()` and `expires_at`
|
|
/// to the supplied value.
|
|
async fn touch(
|
|
&self,
|
|
token_hash: &str,
|
|
new_expires_at: DateTime<Utc>,
|
|
) -> Result<(), AdminSessionRepositoryError>;
|
|
async fn delete(&self, token_hash: &str) -> Result<(), AdminSessionRepositoryError>;
|
|
/// Delete every session belonging to a user. Used when the user is
|
|
/// deactivated or has their password reset out-of-band — both
|
|
/// invalidate all current logins for that account.
|
|
async fn delete_for_user(
|
|
&self,
|
|
user_id: AdminUserId,
|
|
) -> Result<u64, AdminSessionRepositoryError>;
|
|
/// Sweep expired rows. The auth middleware filters expired rows on
|
|
/// lookup, so this is just bounded-growth hygiene, not correctness.
|
|
async fn prune_expired(&self) -> Result<u64, AdminSessionRepositoryError>;
|
|
}
|
|
|
|
pub struct PostgresAdminSessionRepository {
|
|
pool: PgPool,
|
|
}
|
|
|
|
impl PostgresAdminSessionRepository {
|
|
#[must_use]
|
|
pub fn new(pool: PgPool) -> Self {
|
|
Self { pool }
|
|
}
|
|
}
|
|
|
|
#[async_trait]
|
|
impl AdminSessionRepository for PostgresAdminSessionRepository {
|
|
async fn create(
|
|
&self,
|
|
user_id: AdminUserId,
|
|
token_hash: &str,
|
|
expires_at: DateTime<Utc>,
|
|
absolute_expires_at: DateTime<Utc>,
|
|
) -> Result<(), AdminSessionRepositoryError> {
|
|
sqlx::query(
|
|
"INSERT INTO admin_sessions (token_hash, user_id, expires_at, absolute_expires_at) \
|
|
VALUES ($1, $2, $3, $4)",
|
|
)
|
|
.bind(token_hash)
|
|
.bind(user_id.into_inner())
|
|
.bind(expires_at)
|
|
.bind(absolute_expires_at)
|
|
.execute(&self.pool)
|
|
.await?;
|
|
Ok(())
|
|
}
|
|
|
|
async fn lookup(
|
|
&self,
|
|
token_hash: &str,
|
|
) -> Result<Option<AdminSessionLookup>, AdminSessionRepositoryError> {
|
|
let row: Option<(uuid::Uuid, DateTime<Utc>, DateTime<Utc>)> = sqlx::query_as(
|
|
"SELECT user_id, expires_at, absolute_expires_at FROM admin_sessions \
|
|
WHERE token_hash = $1 AND expires_at > NOW() AND absolute_expires_at > NOW()",
|
|
)
|
|
.bind(token_hash)
|
|
.fetch_optional(&self.pool)
|
|
.await?;
|
|
Ok(row.map(|(uid, exp, abs)| AdminSessionLookup {
|
|
user_id: uid.into(),
|
|
expires_at: exp,
|
|
absolute_expires_at: abs,
|
|
}))
|
|
}
|
|
|
|
async fn touch(
|
|
&self,
|
|
token_hash: &str,
|
|
new_expires_at: DateTime<Utc>,
|
|
) -> Result<(), AdminSessionRepositoryError> {
|
|
sqlx::query(
|
|
"UPDATE admin_sessions SET last_used_at = NOW(), expires_at = $2 \
|
|
WHERE token_hash = $1",
|
|
)
|
|
.bind(token_hash)
|
|
.bind(new_expires_at)
|
|
.execute(&self.pool)
|
|
.await?;
|
|
Ok(())
|
|
}
|
|
|
|
async fn delete(&self, token_hash: &str) -> Result<(), AdminSessionRepositoryError> {
|
|
sqlx::query("DELETE FROM admin_sessions WHERE token_hash = $1")
|
|
.bind(token_hash)
|
|
.execute(&self.pool)
|
|
.await?;
|
|
Ok(())
|
|
}
|
|
|
|
async fn delete_for_user(
|
|
&self,
|
|
user_id: AdminUserId,
|
|
) -> Result<u64, AdminSessionRepositoryError> {
|
|
let res = sqlx::query("DELETE FROM admin_sessions WHERE user_id = $1")
|
|
.bind(user_id.into_inner())
|
|
.execute(&self.pool)
|
|
.await?;
|
|
Ok(res.rows_affected())
|
|
}
|
|
|
|
async fn prune_expired(&self) -> Result<u64, AdminSessionRepositoryError> {
|
|
let res = sqlx::query(
|
|
"DELETE FROM admin_sessions \
|
|
WHERE expires_at <= NOW() OR absolute_expires_at <= NOW()",
|
|
)
|
|
.execute(&self.pool)
|
|
.await?;
|
|
Ok(res.rows_affected())
|
|
}
|
|
}
|