fix(auth): the Subsonic password is generated, never the login password (M462 #5026)
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped

`minstrel admin reset-password` copied the new login password into
subsonic_password, which is stored in plain text because Subsonic t/s
sign-in needs it. Every account recovered through the CLI had its login
password readable in the database, and changing the password later left
the copy behind.

- reset-password now changes only password_hash.
- Migration 0064 clears every subsonic_password, removing the copies.
- Settings gets a Subsonic password card: the server generates a random
  password, shows it once, and it can be regenerated or turned off
  (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather
  than user-chosen so it can never be a reused password.
- docs/security.md describes the separate password instead of the known
  issue.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 10:54:30 -04:00
co-authored by Claude Opus 5.5
parent 522503e011
commit edd9a3a6db
14 changed files with 456 additions and 31 deletions
+132
View File
@@ -0,0 +1,132 @@
package api
import (
"context"
"encoding/json"
"net/http"
"net/http/httptest"
"os"
"testing"
"github.com/go-chi/chi/v5"
"git.fabledsword.com/bvandeusen/minstrel/internal/db/dbq"
)
func newMeSubsonicPasswordRouter(h *handlers) chi.Router {
r := chi.NewRouter()
r.Get("/api/me/subsonic-password", h.handleGetMySubsonicPassword)
r.Post("/api/me/subsonic-password", h.handleGenerateMySubsonicPassword)
r.Delete("/api/me/subsonic-password", h.handleClearMySubsonicPassword)
return r
}
func readSubsonicPassword(t *testing.T, h *handlers, user dbq.User) *string {
t.Helper()
var pw *string
if err := h.pool.QueryRow(context.Background(),
"SELECT subsonic_password FROM users WHERE id = $1", user.ID).Scan(&pw); err != nil {
t.Fatalf("read subsonic_password: %v", err)
}
return pw
}
func TestSubsonicPassword_GenerateIsRandomAndNotTheLoginPassword(t *testing.T) {
if os.Getenv("MINSTREL_TEST_DATABASE_URL") == "" {
t.Skip("MINSTREL_TEST_DATABASE_URL not set")
}
h, pool := testHandlers(t)
user := seedUser(t, pool, "sspw1", "login-pw", false)
router := newMeSubsonicPasswordRouter(h)
generate := func() string {
req := withUser(httptest.NewRequest(http.MethodPost, "/api/me/subsonic-password", nil), user)
rec := httptest.NewRecorder()
router.ServeHTTP(rec, req)
if rec.Code != http.StatusOK {
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var resp subsonicPasswordResp
if err := json.Unmarshal(rec.Body.Bytes(), &resp); err != nil {
t.Fatalf("decode: %v", err)
}
return resp.Password
}
first := generate()
if len(first) != 24 {
t.Errorf("password length = %d, want 24", len(first))
}
if first == "login-pw" {
t.Errorf("generated password equals the login password")
}
if got := readSubsonicPassword(t, h, user); got == nil || *got != first {
t.Errorf("stored = %v, want the returned password", got)
}
second := generate()
if second == first {
t.Errorf("regenerate returned the same password")
}
if got := readSubsonicPassword(t, h, user); got == nil || *got != second {
t.Errorf("stored after regenerate = %v, want the new password", got)
}
}
func TestSubsonicPassword_StatusAndClear(t *testing.T) {
if os.Getenv("MINSTREL_TEST_DATABASE_URL") == "" {
t.Skip("MINSTREL_TEST_DATABASE_URL not set")
}
h, pool := testHandlers(t)
user := seedUser(t, pool, "sspw2", "login-pw", false)
router := newMeSubsonicPasswordRouter(h)
status := func(u dbq.User) bool {
req := withUser(httptest.NewRequest(http.MethodGet, "/api/me/subsonic-password", nil), u)
rec := httptest.NewRecorder()
router.ServeHTTP(rec, req)
if rec.Code != http.StatusOK {
t.Fatalf("GET status = %d, want 200; body=%s", rec.Code, rec.Body.String())
}
var resp subsonicPasswordStatusResp
if err := json.Unmarshal(rec.Body.Bytes(), &resp); err != nil {
t.Fatalf("decode: %v", err)
}
return resp.Enabled
}
if status(user) {
t.Errorf("enabled = true for a new account, want false")
}
pw := "set-by-test"
user.SubsonicPassword = &pw
if !status(user) {
t.Errorf("enabled = false with a password set, want true")
}
// The status response never carries the value itself.
req := withUser(httptest.NewRequest(http.MethodGet, "/api/me/subsonic-password", nil), user)
rec := httptest.NewRecorder()
router.ServeHTTP(rec, req)
var raw map[string]any
if err := json.Unmarshal(rec.Body.Bytes(), &raw); err != nil {
t.Fatalf("decode: %v", err)
}
if _, has := raw["password"]; has {
t.Errorf("GET response includes the password: %s", rec.Body.String())
}
if err := dbq.New(pool).SetSubsonicPassword(context.Background(), dbq.SetSubsonicPasswordParams{
ID: user.ID, SubsonicPassword: &pw,
}); err != nil {
t.Fatalf("seed subsonic_password: %v", err)
}
req = withUser(httptest.NewRequest(http.MethodDelete, "/api/me/subsonic-password", nil), user)
rec = httptest.NewRecorder()
router.ServeHTTP(rec, req)
if rec.Code != http.StatusNoContent {
t.Fatalf("DELETE status = %d, want 204; body=%s", rec.Code, rec.Body.String())
}
if got := readSubsonicPassword(t, h, user); got != nil {
t.Errorf("stored after clear = %q, want NULL", *got)
}
}