Two layered changes shipped in this branch: == 1.0.0-22: app-level authentication == The dashboard previously had only an IP allowlist. Adds username + bcrypt password auth, signed-cookie sessions, and a "first user setup" flow. * New app/auth.py: User dataclass, bcrypt hash/verify, get_user_by_id/ username, create_user, touch_last_login, FastAPI `get_current_user` dependency. Session secret loaded from SESSION_SECRET env or persisted to /data/session_secret. * New app/auth_cli.py: `python -m app.auth_cli list|reset|add` for out-of-band user management. Passwords always read from a TTY prompt. * Schema: idempotent ALTER for `users` table (id, username unique, password_hash, full_name, is_admin, created_at, last_login_at). * main.py: SessionMiddleware (HMAC-signed cookie, max-age 7 days, SameSite=strict — see hardening section) + _AuthGateMiddleware that populates request.state.current_user and bounces unauth'd HTML GETs to /login while returning 401 JSON for everything else. * Routes: GET /login renders first-user-setup form when users table is empty otherwise sign-in form; POST /login; POST /api/v1/auth/setup (only works while empty); GET|POST /logout. * Bootstrap: env vars INITIAL_ADMIN_USERNAME + INITIAL_ADMIN_PASSWORD create the first admin on startup if both set AND users table empty. Ignored thereafter — change passwords via UI or CLI. * Layout: header shows current_user.full_name|username + Logout link. Modal operator field auto-fills from the logged-in user via <meta name="default-operator"> rendered in layout (replaces the localStorage-only previous behaviour). * requirements.txt: pinned bcrypt>=4.0,<5.0, itsdangerous>=2.1, python-multipart>=0.0.7. First step toward addressing the unpinned-deps gotcha. * New app/templates/login.html with first-user-setup variant. == 1.0.0-23: hardening sweep == Closes the eight-item gap audit: * DB retention + automated backup. New app/retention.py runs daily at 03:00 local. Nulls burnin_stages.log_text on stages older than retention_log_days (default 35), VACUUMs to reclaim pages, then runs `sqlite3 .backup` to /data/backups/app-YYYY-MM-DD.db keeping the retention_backup_keep most recent (default 14). Wired into the lifespan supervisor next to mailer/poller. * CSRF mitigation. SessionMiddleware bumped to SameSite=strict so the browser refuses to send the session cookie on cross-site POSTs — removes the actual CSRF vector. Trade-off: external links into the app require re-auth. * Login rate limiting. In-memory per-username AND per-source-IP failure counters in auth.py. 10 failures within 10 min trips a 15-min lockout for both keys. Returns HTTP 429 with a clear "try again in N min" message. Cleared on successful login. * Login audit events. New event types in audit_events: user_login, user_login_failed, user_login_locked_out, user_logout, user_password_changed. All include source IP. Recorded via auth.audit_auth_event(). * Password change UI. Header link "Change password" opens templates/components/modal_password.html (current/new/confirm). Posts to POST /api/v1/auth/change-password — bcrypt-verifies current, requires >=8 char new pw, writes audit event. * NVMe burn-in path. _stage_surface_validate now detects nvme* devnames and routes to _stage_surface_validate_nvme() which runs `nvme format -s 1 --force` (cryptographic erase). Seconds vs hours of badblocks, exercises the controller's secure-erase. Falls back to badblocks if nvme-cli isn't installed. Post-format SMART check. * Mounted-FS detection. ssh_client.get_mounted_drives() runs `findmnt -no SOURCE`, parses non-ZFS sources back to base devnames. Poller treats them as pool_name='(mounted)', pool_role='mounted'. Confirm token DESTROY MOUNTED FILESYSTEM, distinct purple styling, audit event mounted_drive_unlocked, daily-report banner picks it up. * Deeper /health. Real readiness check — DB write probe (PRAGMA journal_mode), poller freshness (age <= 3x stale_threshold), SSH test_connection() when configured. Returns 503 when any check fails so a proxy/orchestrator can take the container out of rotation. Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
99 lines
3 KiB
Python
99 lines
3 KiB
Python
"""Password reset / user management CLI.
|
|
|
|
Run inside the container:
|
|
docker exec -it truenas-burnin python -m app.auth_cli reset <username>
|
|
docker exec -it truenas-burnin python -m app.auth_cli list
|
|
docker exec -it truenas-burnin python -m app.auth_cli add <username>
|
|
|
|
Reads the password from a TTY prompt — never accept it on the command
|
|
line so it doesn't leak into shell history.
|
|
"""
|
|
|
|
from __future__ import annotations
|
|
|
|
import asyncio
|
|
import getpass
|
|
import sys
|
|
|
|
import aiosqlite
|
|
|
|
from app import auth
|
|
from app.config import settings
|
|
|
|
|
|
async def _reset(username: str) -> int:
|
|
found = await auth.get_user_by_username(username)
|
|
if not found:
|
|
print(f"No such user: {username}", file=sys.stderr)
|
|
return 1
|
|
pw1 = getpass.getpass(f"New password for {username}: ")
|
|
pw2 = getpass.getpass("Confirm: ")
|
|
if pw1 != pw2:
|
|
print("Passwords don't match.", file=sys.stderr)
|
|
return 2
|
|
if len(pw1) < 8:
|
|
print("Password must be at least 8 characters.", file=sys.stderr)
|
|
return 3
|
|
new_hash = auth.hash_password(pw1)
|
|
async with aiosqlite.connect(settings.db_path) as db:
|
|
await db.execute(
|
|
"UPDATE users SET password_hash = ? WHERE username = ? COLLATE NOCASE",
|
|
(new_hash, username),
|
|
)
|
|
await db.commit()
|
|
print(f"Password updated for {username}.")
|
|
return 0
|
|
|
|
|
|
async def _list() -> int:
|
|
async with aiosqlite.connect(settings.db_path) as db:
|
|
db.row_factory = aiosqlite.Row
|
|
cur = await db.execute(
|
|
"SELECT id, username, full_name, is_admin, created_at, last_login_at "
|
|
"FROM users ORDER BY username"
|
|
)
|
|
rows = list(await cur.fetchall())
|
|
if not rows:
|
|
print("(no users)")
|
|
return 0
|
|
for r in rows:
|
|
flag = "admin" if r["is_admin"] else "user "
|
|
print(f" [{flag}] {r['username']:24s} created={r['created_at'][:19]} "
|
|
f"last_login={(r['last_login_at'] or '-')[:19]}")
|
|
return 0
|
|
|
|
|
|
async def _add(username: str) -> int:
|
|
pw1 = getpass.getpass(f"Password for new user {username}: ")
|
|
pw2 = getpass.getpass("Confirm: ")
|
|
if pw1 != pw2:
|
|
print("Passwords don't match.", file=sys.stderr)
|
|
return 2
|
|
full = input("Full name (optional, press enter to skip): ").strip() or None
|
|
is_admin = input("Admin? [y/N]: ").strip().lower() == "y"
|
|
try:
|
|
u = await auth.create_user(username, pw1, full, is_admin=is_admin)
|
|
except ValueError as exc:
|
|
print(f"Failed: {exc}", file=sys.stderr)
|
|
return 1
|
|
print(f"Created user {u.username} (admin={u.is_admin}).")
|
|
return 0
|
|
|
|
|
|
def main() -> int:
|
|
if len(sys.argv) < 2:
|
|
print(__doc__, file=sys.stderr)
|
|
return 64
|
|
cmd = sys.argv[1]
|
|
if cmd == "list":
|
|
return asyncio.run(_list())
|
|
if cmd == "reset" and len(sys.argv) == 3:
|
|
return asyncio.run(_reset(sys.argv[2]))
|
|
if cmd == "add" and len(sys.argv) == 3:
|
|
return asyncio.run(_add(sys.argv[2]))
|
|
print(__doc__, file=sys.stderr)
|
|
return 64
|
|
|
|
|
|
if __name__ == "__main__":
|
|
sys.exit(main())
|