fix(auth): build password-reset links from an operator-set public address, never the Host header (M462 #4981)
test-go / test (push) Successful in 1m29s
test-web / test (push) Successful in 1m37s
release / Build + push container image (push) Canceled after 0s
release / Verify release artifacts (tag releases only) (push) Canceled after 0s
test-go / integration (push) Canceled after 2m45s
release / Build signed APK (releases and dev) (push) Canceled after 3m40s
test-go / test (push) Successful in 1m29s
test-web / test (push) Successful in 1m37s
release / Build + push container image (push) Canceled after 0s
release / Verify release artifacts (tag releases only) (push) Canceled after 0s
test-go / integration (push) Canceled after 2m45s
release / Build signed APK (releases and dev) (push) Canceled after 3m40s
buildResetURL used r.Host and r.TLS, so a forgot-password request with a forged Host emailed the victim a real reset token on a link to the attacker's server. Links now come only from network_settings.public_url (migration 0062), and no reset email is sent while it is empty; the response stays the same opaque 200 and the log says why. The address is set on a new "Public address" card under Admin → Integrations, which offers the page's own origin and warns while unset. PUT /api/admin/network-settings takes either field alone, so the proxy card and this one can't overwrite each other. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -708,6 +708,9 @@ export type NetworkSettings = {
|
||||
detected_client_ip: string;
|
||||
forwarded_chain: string;
|
||||
remote_addr: string;
|
||||
// Where users reach Minstrel. Password-reset emails link here and are not
|
||||
// sent while it is empty.
|
||||
public_url: string;
|
||||
};
|
||||
|
||||
export async function getNetworkSettings(): Promise<NetworkSettings> {
|
||||
@@ -722,6 +725,13 @@ export async function updateNetworkSettings(hops: number): Promise<NetworkSettin
|
||||
});
|
||||
}
|
||||
|
||||
// Saves only the public address; the proxy depth is left as it is.
|
||||
export async function updatePublicUrl(publicUrl: string): Promise<NetworkSettings> {
|
||||
return api.put<NetworkSettings>('/api/admin/network-settings', {
|
||||
public_url: publicUrl
|
||||
});
|
||||
}
|
||||
|
||||
// Duplicates report (#3912) -------------------------------------------------
|
||||
|
||||
export async function listDuplicates(
|
||||
|
||||
@@ -19,7 +19,9 @@ const DETAIL_CODES: ReadonlySet<string> = new Set([
|
||||
'library_not_writable',
|
||||
'file_delete_failed',
|
||||
// The server names the field and its range (#3913).
|
||||
'invalid_setting'
|
||||
'invalid_setting',
|
||||
// The server says what shape of address it wants (#4981).
|
||||
'invalid_public_url'
|
||||
]);
|
||||
|
||||
/**
|
||||
|
||||
@@ -0,0 +1,107 @@
|
||||
<script lang="ts">
|
||||
import { onMount } from 'svelte';
|
||||
import { Save, TriangleAlert } from 'lucide-svelte';
|
||||
import { getNetworkSettings, updatePublicUrl } from '$lib/api/admin';
|
||||
import { errMessage } from '$lib/api/errors';
|
||||
import { pushToast } from '$lib/stores/toast.svelte';
|
||||
|
||||
let saved = $state<string | null>(null);
|
||||
let value = $state('');
|
||||
let saving = $state(false);
|
||||
let loadError = $state(false);
|
||||
|
||||
const dirty = $derived(saved !== null && value.trim() !== saved);
|
||||
// The address this page was loaded from is almost always the right answer,
|
||||
// so offer it rather than making the operator type it.
|
||||
const here = typeof window !== 'undefined' ? window.location.origin : '';
|
||||
|
||||
async function load() {
|
||||
try {
|
||||
const s = await getNetworkSettings();
|
||||
saved = s.public_url;
|
||||
value = s.public_url;
|
||||
loadError = false;
|
||||
} catch {
|
||||
loadError = true;
|
||||
}
|
||||
}
|
||||
|
||||
onMount(load);
|
||||
|
||||
async function save() {
|
||||
saving = true;
|
||||
try {
|
||||
const s = await updatePublicUrl(value.trim());
|
||||
saved = s.public_url;
|
||||
value = s.public_url;
|
||||
pushToast(saved ? 'Public address saved.' : 'Public address cleared.');
|
||||
} catch (e) {
|
||||
pushToast(errMessage(e, "Couldn't save the public address."), 'error');
|
||||
} finally {
|
||||
saving = false;
|
||||
}
|
||||
}
|
||||
</script>
|
||||
|
||||
<section class="space-y-4 rounded-xl border border-border bg-surface p-5">
|
||||
<div>
|
||||
<h3 class="font-display text-lg font-medium text-text-primary">Public address</h3>
|
||||
<p class="mt-1 text-sm text-text-secondary">
|
||||
The address people use to reach Minstrel. Password-reset emails link here.
|
||||
</p>
|
||||
</div>
|
||||
|
||||
{#if loadError}
|
||||
<p class="text-sm text-action-destructive">
|
||||
Couldn't load network settings.
|
||||
<button type="button" class="underline hover:no-underline" onclick={load}>Try again</button>
|
||||
</p>
|
||||
{:else if saved === null}
|
||||
<p class="text-sm text-text-secondary">Loading…</p>
|
||||
{:else}
|
||||
<div class="flex flex-wrap items-end gap-3">
|
||||
<label class="flex min-w-0 flex-1 flex-col gap-1">
|
||||
<span class="text-sm text-text-secondary">Address</span>
|
||||
<input
|
||||
type="url"
|
||||
inputmode="url"
|
||||
placeholder="https://music.example.com"
|
||||
bind:value
|
||||
class="w-full rounded border border-border bg-background px-2 py-1 font-mono
|
||||
focus-visible:outline focus-visible:outline-2 focus-visible:outline-accent"
|
||||
/>
|
||||
</label>
|
||||
{#if here && value.trim() !== here}
|
||||
<button
|
||||
type="button"
|
||||
class="rounded-md border border-border px-3 py-1.5 text-sm hover:bg-surface-hover
|
||||
focus-visible:ring-2 focus-visible:ring-accent"
|
||||
onclick={() => (value = here)}
|
||||
>
|
||||
Use {here}
|
||||
</button>
|
||||
{/if}
|
||||
<button
|
||||
type="button"
|
||||
class="inline-flex items-center gap-1.5 rounded-md border border-border px-3 py-1.5
|
||||
text-sm hover:bg-surface-hover focus-visible:ring-2 focus-visible:ring-accent
|
||||
disabled:opacity-50"
|
||||
disabled={saving || !dirty}
|
||||
onclick={save}
|
||||
>
|
||||
<Save size={14} aria-hidden="true" />
|
||||
{saving ? 'Saving…' : 'Save'}
|
||||
</button>
|
||||
</div>
|
||||
|
||||
{#if !saved}
|
||||
<p class="flex items-start gap-2 text-sm text-text-secondary" role="status">
|
||||
<TriangleAlert size={14} class="mt-0.5 flex-shrink-0 text-action-destructive" aria-hidden="true" />
|
||||
<span>
|
||||
Not set, so password-reset emails are not being sent. Minstrel won't build the link from
|
||||
whatever address a request claims, because anyone can claim any address.
|
||||
</span>
|
||||
</p>
|
||||
{/if}
|
||||
{/if}
|
||||
</section>
|
||||
@@ -0,0 +1,75 @@
|
||||
import { describe, expect, test, vi, beforeEach } from 'vitest';
|
||||
import { render, screen, fireEvent, waitFor } from '@testing-library/svelte';
|
||||
import PublicAddressCard from './PublicAddressCard.svelte';
|
||||
|
||||
const getNetworkSettings = vi.fn();
|
||||
const updatePublicUrl = vi.fn();
|
||||
|
||||
vi.mock('$lib/api/admin', () => ({
|
||||
getNetworkSettings: () => getNetworkSettings(),
|
||||
updatePublicUrl: (url: string) => updatePublicUrl(url)
|
||||
}));
|
||||
|
||||
const pushToast = vi.fn();
|
||||
vi.mock('$lib/stores/toast.svelte', () => ({
|
||||
pushToast: (...args: unknown[]) => pushToast(...args)
|
||||
}));
|
||||
|
||||
function settings(publicUrl: string) {
|
||||
return {
|
||||
trusted_proxy_hops: 1,
|
||||
max_hops: 10,
|
||||
detected_client_ip: '198.51.100.7',
|
||||
forwarded_chain: '198.51.100.7',
|
||||
remote_addr: '172.18.0.1:40000',
|
||||
public_url: publicUrl
|
||||
};
|
||||
}
|
||||
|
||||
beforeEach(() => {
|
||||
vi.clearAllMocks();
|
||||
});
|
||||
|
||||
describe('PublicAddressCard', () => {
|
||||
test('warns that reset emails are not sent while the address is unset', async () => {
|
||||
getNetworkSettings.mockResolvedValue(settings(''));
|
||||
render(PublicAddressCard);
|
||||
expect(await screen.findByText(/password-reset emails are not being sent/i)).toBeTruthy();
|
||||
});
|
||||
|
||||
test('no warning once an address is saved', async () => {
|
||||
getNetworkSettings.mockResolvedValue(settings('https://music.example.com'));
|
||||
render(PublicAddressCard);
|
||||
await screen.findByDisplayValue('https://music.example.com');
|
||||
expect(screen.queryByText(/not being sent/i)).toBeNull();
|
||||
});
|
||||
|
||||
test('offers this page’s own origin and saves it trimmed', async () => {
|
||||
getNetworkSettings.mockResolvedValue(settings(''));
|
||||
updatePublicUrl.mockResolvedValue(settings(window.location.origin));
|
||||
render(PublicAddressCard);
|
||||
|
||||
await fireEvent.click(await screen.findByRole('button', { name: /^Use / }));
|
||||
await fireEvent.click(screen.getByRole('button', { name: /save/i }));
|
||||
|
||||
await waitFor(() => expect(updatePublicUrl).toHaveBeenCalledWith(window.location.origin));
|
||||
expect(pushToast).toHaveBeenCalledWith('Public address saved.');
|
||||
});
|
||||
|
||||
test('shows the server’s reason when an address is refused', async () => {
|
||||
getNetworkSettings.mockResolvedValue(settings(''));
|
||||
updatePublicUrl.mockRejectedValue({
|
||||
code: 'invalid_public_url',
|
||||
message: 'public URL must be an http:// or https:// address',
|
||||
status: 400
|
||||
});
|
||||
render(PublicAddressCard);
|
||||
|
||||
const input = await screen.findByPlaceholderText('https://music.example.com');
|
||||
await fireEvent.input(input, { target: { value: 'music.example.com' } });
|
||||
await fireEvent.click(screen.getByRole('button', { name: /save/i }));
|
||||
|
||||
await waitFor(() => expect(pushToast).toHaveBeenCalled());
|
||||
expect(pushToast.mock.calls[0][1]).toBe('error');
|
||||
});
|
||||
});
|
||||
@@ -47,6 +47,7 @@
|
||||
"duplicate_group_not_pending": "That group has already been resolved.",
|
||||
"survivor_not_in_group": "That copy isn't part of this group any more.",
|
||||
"invalid_setting": "That setting is out of range.",
|
||||
"invalid_public_url": "That address isn't valid.",
|
||||
"album_not_found": "That album no longer exists.",
|
||||
"artist_not_found": "That artist no longer exists.",
|
||||
"playlist_not_found": "That playlist no longer exists.",
|
||||
|
||||
@@ -28,6 +28,7 @@
|
||||
import { pushToast } from '$lib/stores/toast.svelte';
|
||||
import Modal from '$lib/components/Modal.svelte';
|
||||
import NetworkSettingsCard from '$lib/components/NetworkSettingsCard.svelte';
|
||||
import PublicAddressCard from '$lib/components/PublicAddressCard.svelte';
|
||||
import type { LidarrConfig, LidarrTestResult } from '$lib/api/types';
|
||||
|
||||
// Lidarr connection panel. The "saved api key" is masked as "***" on GET —
|
||||
@@ -827,6 +828,7 @@
|
||||
other card on this page, and it's an operator-wide setting rather than
|
||||
a per-user preference. -->
|
||||
<NetworkSettingsCard />
|
||||
<PublicAddressCard />
|
||||
</div>
|
||||
|
||||
<Modal
|
||||
|
||||
Reference in New Issue
Block a user