fix(auth): build password-reset links from an operator-set public address, never the Host header (M462 #4981)
test-go / test (push) Successful in 1m29s
test-web / test (push) Successful in 1m37s
release / Build + push container image (push) Canceled after 0s
release / Verify release artifacts (tag releases only) (push) Canceled after 0s
test-go / integration (push) Canceled after 2m45s
release / Build signed APK (releases and dev) (push) Canceled after 3m40s

buildResetURL used r.Host and r.TLS, so a forgot-password request with a
forged Host emailed the victim a real reset token on a link to the
attacker's server. Links now come only from network_settings.public_url
(migration 0062), and no reset email is sent while it is empty; the response
stays the same opaque 200 and the log says why.

The address is set on a new "Public address" card under Admin → Integrations,
which offers the page's own origin and warns while unset. PUT
/api/admin/network-settings takes either field alone, so the proxy card and
this one can't overwrite each other.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 09:32:10 -04:00
co-authored by Claude Opus 5.5
parent d411693bb2
commit 46194a609d
16 changed files with 433 additions and 26 deletions
+37 -6
View File
@@ -23,10 +23,16 @@ type networkSettingsResp struct {
// arrived and count them rather than guess.
ForwardedChain string `json:"forwarded_chain"`
RemoteAddr string `json:"remote_addr"`
// PublicURL is where users reach Minstrel; reset emails link to it and
// are not sent while it is empty.
PublicURL string `json:"public_url"`
}
// Both fields are optional so the proxy card and the public-address card can
// each save their own value without overwriting the other's.
type updateNetworkSettingsReq struct {
TrustedProxyHops int `json:"trusted_proxy_hops"`
TrustedProxyHops *int `json:"trusted_proxy_hops"`
PublicURL *string `json:"public_url"`
}
func (h *handlers) handleGetNetworkSettings(w http.ResponseWriter, r *http.Request) {
@@ -39,13 +45,37 @@ func (h *handlers) handleUpdateNetworkSettings(w http.ResponseWriter, r *http.Re
writeErr(w, apierror.BadRequest("invalid_body", "malformed JSON"))
return
}
if err := h.netSettings.SetHops(r.Context(), req.TrustedProxyHops); err != nil {
if errors.Is(err, netsettings.ErrHopsOutOfRange) {
writeErr(w, apierror.BadRequest("invalid_hops", err.Error()))
if req.TrustedProxyHops == nil && req.PublicURL == nil {
writeErr(w, apierror.BadRequest("invalid_body", "nothing to update"))
return
}
// Validate everything before writing anything, so a bad public URL can't
// leave the hops half-saved.
if req.TrustedProxyHops != nil && (*req.TrustedProxyHops < 0 || *req.TrustedProxyHops > netsettings.MaxTrustedProxyHops) {
writeErr(w, apierror.BadRequest("invalid_hops", netsettings.ErrHopsOutOfRange.Error()))
return
}
if req.PublicURL != nil {
if _, err := netsettings.NormalizePublicURL(*req.PublicURL); err != nil {
writeErr(w, apierror.BadRequest("invalid_public_url", err.Error()))
return
}
}
if req.TrustedProxyHops != nil {
if err := h.netSettings.SetHops(r.Context(), *req.TrustedProxyHops); err != nil {
if errors.Is(err, netsettings.ErrHopsOutOfRange) {
writeErr(w, apierror.BadRequest("invalid_hops", err.Error()))
return
}
writeErrWithLog(w, h.logger, "admin network: update failed", apierror.Internal(err))
return
}
}
if req.PublicURL != nil {
if err := h.netSettings.SetPublicURL(r.Context(), *req.PublicURL); err != nil {
writeErrWithLog(w, h.logger, "admin network: public URL update failed", apierror.Internal(err))
return
}
writeErrWithLog(w, h.logger, "admin network: update failed", apierror.Internal(err))
return
}
// Echo the payload recomputed under the NEW value, so the card can show
// immediately what the change did to this request's own address rather
@@ -61,5 +91,6 @@ func (h *handlers) networkSettingsPayload(r *http.Request) networkSettingsResp {
DetectedClientIP: auth.ClientIP(r, hops),
ForwardedChain: r.Header.Get("X-Forwarded-For"),
RemoteAddr: r.RemoteAddr,
PublicURL: h.netSettings.PublicURL(),
}
}
+19 -12
View File
@@ -69,7 +69,7 @@ func (h *handlers) handleForgotPassword(w http.ResponseWriter, r *http.Request)
if err == nil && user.Email != nil && *user.Email != "" {
matched = true
auditTarget = user.ID
if sendErr := h.sendResetEmail(r.Context(), r, user); sendErr != nil {
if sendErr := h.sendResetEmail(r.Context(), user); sendErr != nil {
h.logger.Warn("forgot-password: send failed",
"email", email, "err", sendErr)
// fall through; response is still 200
@@ -89,7 +89,7 @@ func (h *handlers) handleForgotPassword(w http.ResponseWriter, r *http.Request)
// sendResetEmail generates a token, persists it, renders + sends the
// email. Returns the underlying error (caller logs it but doesn't
// surface to the HTTP response).
func (h *handlers) sendResetEmail(ctx context.Context, r *http.Request, user dbq.User) error {
func (h *handlers) sendResetEmail(ctx context.Context, user dbq.User) error {
if h.mailer == nil {
return errors.New("forgot-password: no mailer configured")
}
@@ -109,7 +109,10 @@ func (h *handlers) sendResetEmail(ctx context.Context, r *http.Request, user dbq
return err
}
resetURL := buildResetURL(r, token)
resetURL, err := buildResetURL(h.netSettings.PublicURL(), token)
if err != nil {
return err
}
textBody, htmlBody, err := mailer.RenderResetEmail(mailer.ResetEmailVars{
Username: user.Username,
ResetURL: resetURL,
@@ -127,14 +130,18 @@ func (h *handlers) sendResetEmail(ctx context.Context, r *http.Request, user dbq
return h.mailer.Send(ctx, *user.Email, mailer.ResetEmailSubject, textBody, htmlBody)
}
func buildResetURL(r *http.Request, token string) string {
scheme := "http"
if r.TLS != nil {
scheme = "https"
// errNoPublicURL stops a reset email from going out before the operator has
// said where Minstrel lives. It surfaces in the log, not the response, which
// stays the same opaque 200 either way.
var errNoPublicURL = errors.New("forgot-password: no public URL set (Admin → Integrations → Public address); reset email not sent")
// buildResetURL builds the emailed link from the operator-set public URL.
// It deliberately ignores the request: the Host header is whatever the
// requester sent, and building from it let a forged Host plant a real reset
// token on a link to someone else's server.
func buildResetURL(publicURL, token string) (string, error) {
if publicURL == "" {
return "", errNoPublicURL
}
host := r.Host
if host == "" {
host = "localhost"
}
return scheme + "://" + host + "/reset-password/" + token
return publicURL + "/reset-password/" + token, nil
}
+57 -1
View File
@@ -7,11 +7,59 @@ import (
"net/http"
"net/http/httptest"
"os"
"strings"
"testing"
"github.com/jackc/pgx/v5/pgxpool"
"git.fabledsword.com/bvandeusen/minstrel/internal/mailer"
"git.fabledsword.com/bvandeusen/minstrel/internal/netsettings"
)
// withPublicURL gives h a network-settings service holding url, restoring an
// empty value afterwards so other tests see the default.
func withPublicURL(t *testing.T, h *handlers, pool *pgxpool.Pool, url string) {
t.Helper()
ns, err := netsettings.New(context.Background(), pool, nil)
if err != nil {
t.Fatalf("netsettings: %v", err)
}
if err := ns.SetPublicURL(context.Background(), url); err != nil {
t.Fatalf("set public url: %v", err)
}
t.Cleanup(func() { _ = ns.SetPublicURL(context.Background(), "") })
h.netSettings = ns
}
// With no public URL set, a reset email is not sent at all, and the response
// is still the same opaque 200.
func TestForgotPassword_NoPublicURL_SendsNothing(t *testing.T) {
if os.Getenv("MINSTREL_TEST_DATABASE_URL") == "" {
t.Skip("MINSTREL_TEST_DATABASE_URL not set")
}
h, pool := testHandlers(t)
fake := &mailer.FakeSender{}
h.mailer = fake
withPublicURL(t, h, pool, "")
user := seedUser(t, pool, "nourl", "pw", false)
if _, err := pool.Exec(context.Background(),
"UPDATE users SET email = 'nourl@example.com' WHERE id = $1", user.ID); err != nil {
t.Fatalf("seed email: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/auth/forgot-password",
bytes.NewReader([]byte(`{"email":"nourl@example.com"}`)))
rec := httptest.NewRecorder()
h.handleForgotPassword(rec, req)
if rec.Code != http.StatusOK {
t.Errorf("status = %d, want 200", rec.Code)
}
if len(fake.Sent) != 0 {
t.Errorf("sent %d emails with no public URL set, want 0", len(fake.Sent))
}
}
func TestForgotPassword_KnownEmail_SendsMail(t *testing.T) {
if os.Getenv("MINSTREL_TEST_DATABASE_URL") == "" {
t.Skip("MINSTREL_TEST_DATABASE_URL not set")
@@ -19,6 +67,7 @@ func TestForgotPassword_KnownEmail_SendsMail(t *testing.T) {
h, pool := testHandlers(t)
fake := &mailer.FakeSender{}
h.mailer = fake
withPublicURL(t, h, pool, "https://music.example.com")
user := seedUser(t, pool, "forgotuser", "pw", false)
if _, err := pool.Exec(context.Background(),
@@ -29,7 +78,8 @@ func TestForgotPassword_KnownEmail_SendsMail(t *testing.T) {
body := `{"email":"forgot@example.com"}`
req := httptest.NewRequest(http.MethodPost, "/api/auth/forgot-password",
bytes.NewReader([]byte(body)))
req.Host = "minstrel.example.com"
// A forged Host must not reach the link: it comes from the public URL.
req.Host = "attacker.example.net"
rec := httptest.NewRecorder()
h.handleForgotPassword(rec, req)
@@ -43,6 +93,12 @@ func TestForgotPassword_KnownEmail_SendsMail(t *testing.T) {
if got.To != "forgot@example.com" {
t.Errorf("To = %q, want forgot@example.com", got.To)
}
if !strings.Contains(got.TextBody, "https://music.example.com/reset-password/") {
t.Errorf("reset link not built from the public URL:\n%s", got.TextBody)
}
if strings.Contains(got.TextBody+got.HTMLBody, "attacker.example.net") {
t.Error("the request's Host header reached the emailed link")
}
// Token row was inserted.
var tokenCount int
if err := pool.QueryRow(context.Background(),
+1
View File
@@ -430,6 +430,7 @@ type MissingReacquisition struct {
type NetworkSetting struct {
ID bool
TrustedProxyHops int32
PublicUrl string
}
type PasswordReset struct {
+15 -4
View File
@@ -10,23 +10,34 @@ import (
)
const getNetworkSettings = `-- name: GetNetworkSettings :one
SELECT id, trusted_proxy_hops FROM network_settings WHERE id = true
SELECT id, trusted_proxy_hops, public_url FROM network_settings WHERE id = true
`
func (q *Queries) GetNetworkSettings(ctx context.Context) (NetworkSetting, error) {
row := q.db.QueryRow(ctx, getNetworkSettings)
var i NetworkSetting
err := row.Scan(&i.ID, &i.TrustedProxyHops)
err := row.Scan(&i.ID, &i.TrustedProxyHops, &i.PublicUrl)
return i, err
}
const updatePublicURL = `-- name: UpdatePublicURL :one
UPDATE network_settings SET public_url = $1 WHERE id = true RETURNING id, trusted_proxy_hops, public_url
`
func (q *Queries) UpdatePublicURL(ctx context.Context, publicUrl string) (NetworkSetting, error) {
row := q.db.QueryRow(ctx, updatePublicURL, publicUrl)
var i NetworkSetting
err := row.Scan(&i.ID, &i.TrustedProxyHops, &i.PublicUrl)
return i, err
}
const updateTrustedProxyHops = `-- name: UpdateTrustedProxyHops :one
UPDATE network_settings SET trusted_proxy_hops = $1 WHERE id = true RETURNING id, trusted_proxy_hops
UPDATE network_settings SET trusted_proxy_hops = $1 WHERE id = true RETURNING id, trusted_proxy_hops, public_url
`
func (q *Queries) UpdateTrustedProxyHops(ctx context.Context, trustedProxyHops int32) (NetworkSetting, error) {
row := q.db.QueryRow(ctx, updateTrustedProxyHops, trustedProxyHops)
var i NetworkSetting
err := row.Scan(&i.ID, &i.TrustedProxyHops)
err := row.Scan(&i.ID, &i.TrustedProxyHops, &i.PublicUrl)
return i, err
}
@@ -0,0 +1 @@
ALTER TABLE network_settings DROP COLUMN IF EXISTS public_url;
@@ -0,0 +1,8 @@
-- The address users reach Minstrel at, e.g. https://music.example.com.
--
-- Password-reset links used to be built from the request's Host header,
-- which the requester controls: a forgot-password call with a forged Host
-- would email the victim a real reset token on a link to the attacker's
-- server. Links are now built only from this operator-set value, and none
-- are sent while it is empty (M462 #4981).
ALTER TABLE network_settings ADD COLUMN public_url text NOT NULL DEFAULT '';
+3
View File
@@ -3,3 +3,6 @@ SELECT * FROM network_settings WHERE id = true;
-- name: UpdateTrustedProxyHops :one
UPDATE network_settings SET trusted_proxy_hops = $1 WHERE id = true RETURNING *;
-- name: UpdatePublicURL :one
UPDATE network_settings SET public_url = $1 WHERE id = true RETURNING *;
+34
View File
@@ -0,0 +1,34 @@
package netsettings
import "testing"
func TestNormalizePublicURL(t *testing.T) {
ok := map[string]string{
"": "",
" ": "",
"https://music.example.com": "https://music.example.com",
"https://music.example.com/": "https://music.example.com",
"http://192.168.1.10:4533": "http://192.168.1.10:4533",
" https://Music.Example.com/ ": "https://Music.Example.com",
}
for in, want := range ok {
got, err := NormalizePublicURL(in)
if err != nil || got != want {
t.Errorf("NormalizePublicURL(%q) = %q, %v; want %q", in, got, err, want)
}
}
for _, in := range []string{
"music.example.com", // no scheme
"ftp://music.example.com", // wrong scheme
"https://", // no host
"https://music.example.com/app", // path
"https://music.example.com/?x=1", // query
"https://music.example.com/#frag", // fragment
"https://user:pw@music.example.com",
"javascript:alert(1)",
} {
if _, err := NormalizePublicURL(in); err == nil {
t.Errorf("NormalizePublicURL(%q) accepted, want ErrInvalidPublicURL", in)
}
}
}
+60 -2
View File
@@ -12,6 +12,8 @@ import (
"context"
"errors"
"log/slog"
"net/url"
"strings"
"sync"
"github.com/jackc/pgx/v5/pgxpool"
@@ -32,13 +34,18 @@ const (
// so the API layer can answer 400 instead of surfacing a constraint violation.
var ErrHopsOutOfRange = errors.New("trusted proxy hops must be between 0 and 10")
// ErrInvalidPublicURL is returned by SetPublicURL for anything that isn't a
// bare http(s) origin, so the API layer can answer 400.
var ErrInvalidPublicURL = errors.New("public URL must be an http:// or https:// address with a host and no path, query or fragment")
// Service caches the network settings and owns their persistence.
type Service struct {
pool *pgxpool.Pool
logger *slog.Logger
mu sync.RWMutex
hops int
mu sync.RWMutex
hops int
publicURL string
}
// New loads the settings once and caches them.
@@ -58,6 +65,7 @@ func New(ctx context.Context, pool *pgxpool.Pool, logger *slog.Logger) (*Service
return s, err
}
s.hops = int(row.TrustedProxyHops)
s.publicURL = row.PublicUrl
return s, nil
}
@@ -106,3 +114,53 @@ func (s *Service) SetHops(ctx context.Context, hops int) error {
}
return nil
}
// PublicURL returns the operator-set address users reach Minstrel at, with no
// trailing slash, or "" when it hasn't been set. Links that leave the app (a
// password-reset email) are built from this and never from the request's
// Host header, which the requester controls. Nil-safe like Hops.
func (s *Service) PublicURL() string {
if s == nil {
return ""
}
s.mu.RLock()
defer s.mu.RUnlock()
return s.publicURL
}
// NormalizePublicURL validates raw as a bare http(s) origin and returns it
// without a trailing slash. "" is valid and means unset.
func NormalizePublicURL(raw string) (string, error) {
raw = strings.TrimSpace(raw)
if raw == "" {
return "", nil
}
u, err := url.Parse(raw)
if err != nil || (u.Scheme != "http" && u.Scheme != "https") || u.Host == "" ||
u.User != nil || (u.Path != "" && u.Path != "/") || u.RawQuery != "" || u.Fragment != "" {
return "", ErrInvalidPublicURL
}
return u.Scheme + "://" + u.Host, nil
}
// SetPublicURL validates, persists and caches the public URL. "" clears it.
func (s *Service) SetPublicURL(ctx context.Context, raw string) error {
normalized, err := NormalizePublicURL(raw)
if err != nil {
return err
}
if s == nil || s.pool == nil {
return errors.New("network settings unavailable")
}
row, err := dbq.New(s.pool).UpdatePublicURL(ctx, normalized)
if err != nil {
return err
}
s.mu.Lock()
s.publicURL = row.PublicUrl
s.mu.Unlock()
if s.logger != nil {
s.logger.Info("netsettings: public URL updated", "public_url", normalized)
}
return nil
}