fix(auth): the Subsonic password is generated, never the login password (M462 #5026)
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped
`minstrel admin reset-password` copied the new login password into subsonic_password, which is stored in plain text because Subsonic t/s sign-in needs it. Every account recovered through the CLI had its login password readable in the database, and changing the password later left the copy behind. - reset-password now changes only password_hash. - Migration 0064 clears every subsonic_password, removing the copies. - Settings gets a Subsonic password card: the server generates a random password, shows it once, and it can be regenerated or turned off (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather than user-chosen so it can never be a reused password. - docs/security.md describes the separate password instead of the known issue. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
import { afterEach, describe, expect, test, vi } from 'vitest';
|
||||
import { render, screen, fireEvent, waitFor } from '@testing-library/svelte';
|
||||
import { render, screen, fireEvent, waitFor, within } from '@testing-library/svelte';
|
||||
import { readable, writable } from 'svelte/store';
|
||||
import type { LBStatus } from '$lib/api/listenbrainz';
|
||||
|
||||
@@ -16,7 +16,10 @@ vi.mock('$lib/api/me', () => ({
|
||||
changePassword: vi.fn(),
|
||||
// Default to a resolved value so the page's $effect doesn't crash
|
||||
// on `.then()` of undefined when individual tests don't override.
|
||||
regenerateAPIToken: vi.fn()
|
||||
regenerateAPIToken: vi.fn(),
|
||||
getSubsonicPasswordStatus: vi.fn(),
|
||||
generateSubsonicPassword: vi.fn(),
|
||||
clearSubsonicPassword: vi.fn()
|
||||
}));
|
||||
|
||||
// Mutable holder so individual tests can inject populated metrics;
|
||||
@@ -45,7 +48,10 @@ import {
|
||||
import {
|
||||
updateProfile,
|
||||
changePassword,
|
||||
regenerateAPIToken
|
||||
regenerateAPIToken,
|
||||
getSubsonicPasswordStatus,
|
||||
generateSubsonicPassword,
|
||||
clearSubsonicPassword
|
||||
} from '$lib/api/me';
|
||||
|
||||
function mockStatusStore(data: LBStatus) {
|
||||
@@ -361,3 +367,48 @@ describe('Settings page — API Token card', () => {
|
||||
expect(screen.queryByRole('button', { name: /^copy$/i })).toBeNull();
|
||||
});
|
||||
});
|
||||
|
||||
describe('Settings page — Subsonic password card', () => {
|
||||
function mockLB() {
|
||||
(createLBStatusQuery as ReturnType<typeof vi.fn>).mockReturnValue(
|
||||
mockStatusStore({ enabled: false, token_set: false, last_scrobbled_at: null })
|
||||
);
|
||||
(createTokenMutation as ReturnType<typeof vi.fn>).mockReturnValue(mockMutationStore());
|
||||
(createEnabledMutation as ReturnType<typeof vi.fn>).mockReturnValue(mockMutationStore());
|
||||
}
|
||||
|
||||
test('with none set, Generate creates one on the first click and shows it once', async () => {
|
||||
mockLB();
|
||||
(getSubsonicPasswordStatus as ReturnType<typeof vi.fn>).mockResolvedValue({ enabled: false });
|
||||
(generateSubsonicPassword as ReturnType<typeof vi.fn>).mockResolvedValue({ password: 'gen_pw_123' });
|
||||
render(SettingsPage);
|
||||
await waitFor(() => expect(screen.getByText(/no subsonic password is set/i)).toBeInTheDocument());
|
||||
expect(screen.queryByRole('button', { name: /turn off/i })).not.toBeInTheDocument();
|
||||
|
||||
await fireEvent.click(screen.getByRole('button', { name: /^generate$/i }));
|
||||
await waitFor(() => expect(generateSubsonicPassword).toHaveBeenCalledTimes(1));
|
||||
await waitFor(() => expect(screen.getByText('gen_pw_123')).toBeInTheDocument());
|
||||
expect(screen.getByText(/a subsonic password is set/i)).toBeInTheDocument();
|
||||
});
|
||||
|
||||
test('with one set, Regenerate and Turn off each need a second click', async () => {
|
||||
mockLB();
|
||||
(getSubsonicPasswordStatus as ReturnType<typeof vi.fn>).mockResolvedValue({ enabled: true });
|
||||
(clearSubsonicPassword as ReturnType<typeof vi.fn>).mockResolvedValue(undefined);
|
||||
render(SettingsPage);
|
||||
// The API token card has a Regenerate button too; the Subsonic card's is
|
||||
// the one beside Turn off.
|
||||
const turnOff = await screen.findByRole('button', { name: /turn off/i });
|
||||
const subsonicRegen = within(turnOff.parentElement!).getByRole('button', { name: /^regenerate$/i });
|
||||
|
||||
await fireEvent.click(subsonicRegen);
|
||||
expect(generateSubsonicPassword).not.toHaveBeenCalled();
|
||||
expect(subsonicRegen).toHaveTextContent(/click again to confirm/i);
|
||||
|
||||
await fireEvent.click(turnOff);
|
||||
expect(clearSubsonicPassword).not.toHaveBeenCalled();
|
||||
await fireEvent.click(turnOff);
|
||||
await waitFor(() => expect(clearSubsonicPassword).toHaveBeenCalledTimes(1));
|
||||
await waitFor(() => expect(screen.getByText(/no subsonic password is set/i)).toBeInTheDocument());
|
||||
});
|
||||
});
|
||||
|
||||
Reference in New Issue
Block a user