fix(auth): the Subsonic password is generated, never the login password (M462 #5026)
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped

`minstrel admin reset-password` copied the new login password into
subsonic_password, which is stored in plain text because Subsonic t/s
sign-in needs it. Every account recovered through the CLI had its login
password readable in the database, and changing the password later left
the copy behind.

- reset-password now changes only password_hash.
- Migration 0064 clears every subsonic_password, removing the copies.
- Settings gets a Subsonic password card: the server generates a random
  password, shows it once, and it can be regenerated or turned off
  (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather
  than user-chosen so it can never be a reused password.
- docs/security.md describes the separate password instead of the known
  issue.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 10:54:30 -04:00
co-authored by Claude Opus 5.5
parent 522503e011
commit edd9a3a6db
14 changed files with 456 additions and 31 deletions
+2 -1
View File
@@ -589,7 +589,8 @@ type SetSubsonicPasswordParams struct {
}
// Stores (or clears with NULL) the per-user Subsonic legacy credential used
// for t/s and p auth on /rest/*. Must be plaintext; see migration 0003.
// for t/s and p auth on /rest/*. Must be plaintext; see migration 0003. Only
// ever a server-generated value, never the login password (#5026).
func (q *Queries) SetSubsonicPassword(ctx context.Context, arg SetSubsonicPasswordParams) error {
_, err := q.db.Exec(ctx, setSubsonicPassword, arg.ID, arg.SubsonicPassword)
return err
@@ -0,0 +1,2 @@
-- The cleared values are gone and were never meant to be kept; nothing to undo.
SELECT 1;
@@ -0,0 +1,10 @@
-- `minstrel admin reset-password` used to copy the new login password into
-- subsonic_password, so every account recovered through the CLI had its login
-- password stored in plain text, and a later password change in Settings left
-- that copy behind (M462 #5026). The CLI no longer writes this column; a
-- Subsonic password is now generated separately in Settings and is never the
-- login password. Clearing every value here removes the copies already made.
--
-- Accounts whose Subsonic client signs in with t/s stop working until the user
-- generates a Subsonic password (or switches the client to an API key).
UPDATE users SET subsonic_password = NULL WHERE subsonic_password IS NOT NULL;
+2 -1
View File
@@ -36,7 +36,8 @@ SELECT count(*) FROM users;
-- name: SetSubsonicPassword :exec
-- Stores (or clears with NULL) the per-user Subsonic legacy credential used
-- for t/s and p auth on /rest/*. Must be plaintext; see migration 0003.
-- for t/s and p auth on /rest/*. Must be plaintext; see migration 0003. Only
-- ever a server-generated value, never the login password (#5026).
UPDATE users SET subsonic_password = $2 WHERE id = $1;
-- name: GetUserByID :one