fix(auth): real client IP rate-limiting + remote default-password guard
- Add custom-server.js: inject unspoofable socket IP, strip client XFF (wired into Docker CMD + CLI spawn + build-cli copy) - loginLimiter: key on trusted x-9r-real-ip, TRUST_PROXY opt-in, global fallback - Force password change on first remote login while default is in use - Add /api/auth/reset-password (local-only) so CLI reset writes live SQLite - CLI settings: reset via API instead of stale db.json - Fix OAuth modals opening duplicate browser tabs on add-connection - Add cli:pack / cli:publish scripts Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
@@ -5,6 +5,7 @@ import { cookies } from "next/headers";
|
||||
import { setDashboardAuthCookie } from "@/lib/auth/dashboardSession";
|
||||
import { isOidcConfigured } from "@/lib/auth/oidc";
|
||||
import { checkLock, recordFail, recordSuccess, getClientIp } from "@/lib/auth/loginLimiter";
|
||||
import { isLocalRequest } from "@/dashboardGuard";
|
||||
|
||||
const RESET_HINT = "Forgot password? Reset to default via 9Router CLI → Settings → Reset Password to Default.";
|
||||
|
||||
@@ -55,7 +56,12 @@ export async function POST(request) {
|
||||
const cookieStore = await cookies();
|
||||
await setDashboardAuthCookie(cookieStore, request);
|
||||
|
||||
return NextResponse.json({ success: true });
|
||||
// Default password still in use on a remote client → force a password
|
||||
// change before the dashboard is exposed remotely (keeps local UX intact).
|
||||
const mustChangePassword =
|
||||
!storedHash && !process.env.INITIAL_PASSWORD && !isLocalRequest(request);
|
||||
|
||||
return NextResponse.json({ success: true, mustChangePassword });
|
||||
}
|
||||
|
||||
const { remainingBeforeLock } = recordFail(ip);
|
||||
|
||||
13
src/app/api/auth/reset-password/route.js
Normal file
13
src/app/api/auth/reset-password/route.js
Normal file
@@ -0,0 +1,13 @@
|
||||
import { NextResponse } from "next/server";
|
||||
import { updateSettings } from "@/lib/localDb";
|
||||
|
||||
// Reset dashboard password to default by clearing the stored hash.
|
||||
// Local-only (enforced by dashboardGuard). Never returns the default literal.
|
||||
export async function POST() {
|
||||
try {
|
||||
await updateSettings({ password: null });
|
||||
return NextResponse.json({ success: true });
|
||||
} catch (error) {
|
||||
return NextResponse.json({ error: error.message }, { status: 500 });
|
||||
}
|
||||
}
|
||||
@@ -14,6 +14,8 @@ export default function LoginPage() {
|
||||
const [authMode, setAuthMode] = useState("password");
|
||||
const [oidcConfigured, setOidcConfigured] = useState(false);
|
||||
const [oidcLoginLabel, setOidcLoginLabel] = useState("Sign in with OIDC");
|
||||
const [mustChange, setMustChange] = useState(false);
|
||||
const [newPassword, setNewPassword] = useState("");
|
||||
const router = useRouter();
|
||||
|
||||
// Countdown for rate-limit
|
||||
@@ -72,6 +74,11 @@ export default function LoginPage() {
|
||||
});
|
||||
|
||||
if (res.ok) {
|
||||
const data = await res.json();
|
||||
if (data.mustChangePassword) {
|
||||
setMustChange(true);
|
||||
return;
|
||||
}
|
||||
router.push("/dashboard");
|
||||
router.refresh();
|
||||
} else {
|
||||
@@ -87,6 +94,31 @@ export default function LoginPage() {
|
||||
}
|
||||
};
|
||||
|
||||
// Force a new password before entering the dashboard (default + remote).
|
||||
const handleSetNewPassword = async (e) => {
|
||||
e.preventDefault();
|
||||
setLoading(true);
|
||||
setError("");
|
||||
try {
|
||||
const res = await fetch("/api/settings", {
|
||||
method: "PATCH",
|
||||
headers: { "Content-Type": "application/json" },
|
||||
body: JSON.stringify({ currentPassword: password, newPassword }),
|
||||
});
|
||||
if (res.ok) {
|
||||
router.push("/dashboard");
|
||||
router.refresh();
|
||||
} else {
|
||||
const data = await res.json();
|
||||
setError(data.error || "Failed to set password");
|
||||
}
|
||||
} catch (err) {
|
||||
setError("An error occurred. Please try again.");
|
||||
} finally {
|
||||
setLoading(false);
|
||||
}
|
||||
};
|
||||
|
||||
const handleOidcLogin = () => {
|
||||
window.location.href = "/api/auth/oidc/start";
|
||||
};
|
||||
@@ -121,6 +153,28 @@ export default function LoginPage() {
|
||||
</div>
|
||||
|
||||
<Card>
|
||||
{mustChange ? (
|
||||
<form onSubmit={handleSetNewPassword} className="flex flex-col gap-4">
|
||||
<p className="text-sm text-amber-600 dark:text-amber-400 text-center">
|
||||
Set a new password before accessing the dashboard remotely.
|
||||
</p>
|
||||
<div className="flex flex-col gap-2">
|
||||
<label className="text-sm font-medium">New password</label>
|
||||
<Input
|
||||
type="password"
|
||||
placeholder="Enter new password"
|
||||
value={newPassword}
|
||||
onChange={(e) => setNewPassword(e.target.value)}
|
||||
required
|
||||
autoFocus
|
||||
/>
|
||||
{error && <p className="text-xs text-red-500">{error}</p>}
|
||||
</div>
|
||||
<Button type="submit" variant="primary" className="w-full" loading={loading} disabled={!newPassword}>
|
||||
Set password
|
||||
</Button>
|
||||
</form>
|
||||
) : (
|
||||
<div className="flex flex-col gap-4">
|
||||
{oidcAvailable && (
|
||||
<Button type="button" variant="primary" className="w-full" onClick={handleOidcLogin}>
|
||||
@@ -181,8 +235,8 @@ export default function LoginPage() {
|
||||
Default password is <code className="bg-sidebar px-1 rounded">123456</code>
|
||||
</p>
|
||||
{hasPassword === false && (
|
||||
<p className="text-xs text-center text-text-muted">
|
||||
No custom password is set yet. The default password above will work until you change it.
|
||||
<p className="text-xs text-center text-amber-600 dark:text-amber-400">
|
||||
Security risk: no password set. You will be asked to set one when logging in remotely.
|
||||
</p>
|
||||
)}
|
||||
</form>
|
||||
@@ -190,6 +244,7 @@ export default function LoginPage() {
|
||||
error && <p className="text-xs text-red-500">{error}</p>
|
||||
)}
|
||||
</div>
|
||||
)}
|
||||
</Card>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
Reference in New Issue
Block a user