fix(auth): the Subsonic password is generated, never the login password (M462 #5026)
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped

`minstrel admin reset-password` copied the new login password into
subsonic_password, which is stored in plain text because Subsonic t/s
sign-in needs it. Every account recovered through the CLI had its login
password readable in the database, and changing the password later left
the copy behind.

- reset-password now changes only password_hash.
- Migration 0064 clears every subsonic_password, removing the copies.
- Settings gets a Subsonic password card: the server generates a random
  password, shows it once, and it can be regenerated or turned off
  (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather
  than user-chosen so it can never be a reused password.
- docs/security.md describes the separate password instead of the known
  issue.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
2026-10-06 10:54:30 -04:00
co-authored by Claude Opus 5.5
parent 522503e011
commit edd9a3a6db
14 changed files with 456 additions and 31 deletions
+54 -3
View File
@@ -1,5 +1,5 @@
import { afterEach, describe, expect, test, vi } from 'vitest';
import { render, screen, fireEvent, waitFor } from '@testing-library/svelte';
import { render, screen, fireEvent, waitFor, within } from '@testing-library/svelte';
import { readable, writable } from 'svelte/store';
import type { LBStatus } from '$lib/api/listenbrainz';
@@ -16,7 +16,10 @@ vi.mock('$lib/api/me', () => ({
changePassword: vi.fn(),
// Default to a resolved value so the page's $effect doesn't crash
// on `.then()` of undefined when individual tests don't override.
regenerateAPIToken: vi.fn()
regenerateAPIToken: vi.fn(),
getSubsonicPasswordStatus: vi.fn(),
generateSubsonicPassword: vi.fn(),
clearSubsonicPassword: vi.fn()
}));
// Mutable holder so individual tests can inject populated metrics;
@@ -45,7 +48,10 @@ import {
import {
updateProfile,
changePassword,
regenerateAPIToken
regenerateAPIToken,
getSubsonicPasswordStatus,
generateSubsonicPassword,
clearSubsonicPassword
} from '$lib/api/me';
function mockStatusStore(data: LBStatus) {
@@ -361,3 +367,48 @@ describe('Settings page — API Token card', () => {
expect(screen.queryByRole('button', { name: /^copy$/i })).toBeNull();
});
});
describe('Settings page — Subsonic password card', () => {
function mockLB() {
(createLBStatusQuery as ReturnType<typeof vi.fn>).mockReturnValue(
mockStatusStore({ enabled: false, token_set: false, last_scrobbled_at: null })
);
(createTokenMutation as ReturnType<typeof vi.fn>).mockReturnValue(mockMutationStore());
(createEnabledMutation as ReturnType<typeof vi.fn>).mockReturnValue(mockMutationStore());
}
test('with none set, Generate creates one on the first click and shows it once', async () => {
mockLB();
(getSubsonicPasswordStatus as ReturnType<typeof vi.fn>).mockResolvedValue({ enabled: false });
(generateSubsonicPassword as ReturnType<typeof vi.fn>).mockResolvedValue({ password: 'gen_pw_123' });
render(SettingsPage);
await waitFor(() => expect(screen.getByText(/no subsonic password is set/i)).toBeInTheDocument());
expect(screen.queryByRole('button', { name: /turn off/i })).not.toBeInTheDocument();
await fireEvent.click(screen.getByRole('button', { name: /^generate$/i }));
await waitFor(() => expect(generateSubsonicPassword).toHaveBeenCalledTimes(1));
await waitFor(() => expect(screen.getByText('gen_pw_123')).toBeInTheDocument());
expect(screen.getByText(/a subsonic password is set/i)).toBeInTheDocument();
});
test('with one set, Regenerate and Turn off each need a second click', async () => {
mockLB();
(getSubsonicPasswordStatus as ReturnType<typeof vi.fn>).mockResolvedValue({ enabled: true });
(clearSubsonicPassword as ReturnType<typeof vi.fn>).mockResolvedValue(undefined);
render(SettingsPage);
// The API token card has a Regenerate button too; the Subsonic card's is
// the one beside Turn off.
const turnOff = await screen.findByRole('button', { name: /turn off/i });
const subsonicRegen = within(turnOff.parentElement!).getByRole('button', { name: /^regenerate$/i });
await fireEvent.click(subsonicRegen);
expect(generateSubsonicPassword).not.toHaveBeenCalled();
expect(subsonicRegen).toHaveTextContent(/click again to confirm/i);
await fireEvent.click(turnOff);
expect(clearSubsonicPassword).not.toHaveBeenCalled();
await fireEvent.click(turnOff);
await waitFor(() => expect(clearSubsonicPassword).toHaveBeenCalledTimes(1));
await waitFor(() => expect(screen.getByText(/no subsonic password is set/i)).toBeInTheDocument());
});
});