Files
minstrel/internal/api/me_subsonic_password.go
T
bvandeusenandClaude Opus 5.5 edd9a3a6db
release / govulncheck (push) Successful in 39s
release / web (push) Successful in 1m8s
release / go (push) Successful in 1m30s
release / integration (push) Successful in 4m37s
release / android (push) Successful in 5m56s
release / Build signed APK (releases and dev) (push) Successful in 5m55s
release / Attach APK to the Release (tag releases only) (push) Skipped
release / Build + push container image (push) Successful in 1m23s
release / Verify release artifacts (tag releases only) (push) Skipped
fix(auth): the Subsonic password is generated, never the login password (M462 #5026)
`minstrel admin reset-password` copied the new login password into
subsonic_password, which is stored in plain text because Subsonic t/s
sign-in needs it. Every account recovered through the CLI had its login
password readable in the database, and changing the password later left
the copy behind.

- reset-password now changes only password_hash.
- Migration 0064 clears every subsonic_password, removing the copies.
- Settings gets a Subsonic password card: the server generates a random
  password, shows it once, and it can be regenerated or turned off
  (GET/POST/DELETE /api/me/subsonic-password, audited). Generated rather
  than user-chosen so it can never be a reused password.
- docs/security.md describes the separate password instead of the known
  issue.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-06 10:54:30 -04:00

85 lines
3.0 KiB
Go

package api
import (
"crypto/rand"
"encoding/base64"
"net/http"
"git.fabledsword.com/bvandeusen/minstrel/internal/apierror"
"git.fabledsword.com/bvandeusen/minstrel/internal/audit"
"git.fabledsword.com/bvandeusen/minstrel/internal/db/dbq"
)
// The Subsonic password is for clients that sign in with Subsonic's t/s
// scheme (md5 of the password plus a salt). Checking that needs the password
// itself, so it is stored readable (migration 0003). That is why Minstrel
// generates it rather than letting the user choose one: a generated value
// can never be a login password reused from somewhere else, so a leaked
// users table gives up access to this server's /rest API and nothing more
// (M462 #5026).
const subsonicPasswordBytes = 18 // 24 base64url characters
type subsonicPasswordStatusResp struct {
Enabled bool `json:"enabled"`
}
type subsonicPasswordResp struct {
Password string `json:"password"`
}
// handleGetMySubsonicPassword implements GET /api/me/subsonic-password. It
// reports only whether one is set; the value is shown once, when generated.
func (h *handlers) handleGetMySubsonicPassword(w http.ResponseWriter, r *http.Request) {
user, ok := requireUser(w, r)
if !ok {
return
}
writeJSON(w, http.StatusOK, subsonicPasswordStatusResp{Enabled: user.SubsonicPassword != nil})
}
// handleGenerateMySubsonicPassword implements POST /api/me/subsonic-password:
// replaces any existing Subsonic password with a new random one and returns it.
func (h *handlers) handleGenerateMySubsonicPassword(w http.ResponseWriter, r *http.Request) {
user, ok := requireUser(w, r)
if !ok {
return
}
b := make([]byte, subsonicPasswordBytes)
if _, err := rand.Read(b); err != nil {
h.logger.Error("generate subsonic password: rand failed", "err", err)
writeErr(w, apierror.Internal(err))
return
}
pw := base64.RawURLEncoding.EncodeToString(b)
if err := dbq.New(h.pool).SetSubsonicPassword(r.Context(), dbq.SetSubsonicPasswordParams{
ID: user.ID,
SubsonicPassword: &pw,
}); err != nil {
h.logger.Error("generate subsonic password: update failed", "err", err)
writeErr(w, apierror.Internal(err))
return
}
audit.WriteOrLog(r.Context(), h.pool, h.logger, user.ID, user.ID, audit.ActionSubsonicPasswordSet, nil)
writeJSON(w, http.StatusOK, subsonicPasswordResp{Password: pw})
}
// handleClearMySubsonicPassword implements DELETE /api/me/subsonic-password,
// which turns t/s and p= sign-in off for the account.
func (h *handlers) handleClearMySubsonicPassword(w http.ResponseWriter, r *http.Request) {
user, ok := requireUser(w, r)
if !ok {
return
}
if err := dbq.New(h.pool).SetSubsonicPassword(r.Context(), dbq.SetSubsonicPasswordParams{
ID: user.ID,
SubsonicPassword: nil,
}); err != nil {
h.logger.Error("clear subsonic password: update failed", "err", err)
writeErr(w, apierror.Internal(err))
return
}
audit.WriteOrLog(r.Context(), h.pool, h.logger, user.ID, user.ID, audit.ActionSubsonicPasswordClear, nil)
w.WriteHeader(http.StatusNoContent)
}