fix(auth): the Subsonic password is generated, never the login password (M462 #5026)
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped
`minstrel admin reset-password` copied the new login password into subsonic_password, which is stored in plain text because Subsonic t/s sign-in needs it. Every account recovered through the CLI had its login password readable in the database, and changing the password later left the copy behind. - reset-password now changes only password_hash. - Migration 0064 clears every subsonic_password, removing the copies. - Settings gets a Subsonic password card: the server generates a random password, shows it once, and it can be regenerated or turned off (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather than user-chosen so it can never be a reused password. - docs/security.md describes the separate password instead of the known issue. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -589,7 +589,8 @@ type SetSubsonicPasswordParams struct {
|
||||
}
|
||||
|
||||
// Stores (or clears with NULL) the per-user Subsonic legacy credential used
|
||||
// for t/s and p auth on /rest/*. Must be plaintext; see migration 0003.
|
||||
// for t/s and p auth on /rest/*. Must be plaintext; see migration 0003. Only
|
||||
// ever a server-generated value, never the login password (#5026).
|
||||
func (q *Queries) SetSubsonicPassword(ctx context.Context, arg SetSubsonicPasswordParams) error {
|
||||
_, err := q.db.Exec(ctx, setSubsonicPassword, arg.ID, arg.SubsonicPassword)
|
||||
return err
|
||||
|
||||
@@ -0,0 +1,2 @@
|
||||
-- The cleared values are gone and were never meant to be kept; nothing to undo.
|
||||
SELECT 1;
|
||||
@@ -0,0 +1,10 @@
|
||||
-- `minstrel admin reset-password` used to copy the new login password into
|
||||
-- subsonic_password, so every account recovered through the CLI had its login
|
||||
-- password stored in plain text, and a later password change in Settings left
|
||||
-- that copy behind (M462 #5026). The CLI no longer writes this column; a
|
||||
-- Subsonic password is now generated separately in Settings and is never the
|
||||
-- login password. Clearing every value here removes the copies already made.
|
||||
--
|
||||
-- Accounts whose Subsonic client signs in with t/s stop working until the user
|
||||
-- generates a Subsonic password (or switches the client to an API key).
|
||||
UPDATE users SET subsonic_password = NULL WHERE subsonic_password IS NOT NULL;
|
||||
@@ -36,7 +36,8 @@ SELECT count(*) FROM users;
|
||||
|
||||
-- name: SetSubsonicPassword :exec
|
||||
-- Stores (or clears with NULL) the per-user Subsonic legacy credential used
|
||||
-- for t/s and p auth on /rest/*. Must be plaintext; see migration 0003.
|
||||
-- for t/s and p auth on /rest/*. Must be plaintext; see migration 0003. Only
|
||||
-- ever a server-generated value, never the login password (#5026).
|
||||
UPDATE users SET subsonic_password = $2 WHERE id = $1;
|
||||
|
||||
-- name: GetUserByID :one
|
||||
|
||||
Reference in New Issue
Block a user