mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-05 06:59:42 +02:00
fix: COD-29 fail closed for unauthenticated network binds
This commit is contained in:
+49
-19
@@ -3,12 +3,12 @@
|
||||
* 1. Timing-safe password comparison (timingSafeEqual)
|
||||
* 2. Hook event endpoint restricted to localhost
|
||||
* 3. Session cookie TTL refresh on access
|
||||
* 4. Startup warning when no password configured
|
||||
* 4. Startup fails closed when network-bound without auth
|
||||
* 5. SSE client limit enforcement
|
||||
* 6. Logout endpoint invalidates session
|
||||
* 7. Settings schema rejects unknown fields
|
||||
*
|
||||
* Port: 3160 (auth tests), 3161 (no-auth tests)
|
||||
* Port: 3160 (auth tests), 3161 (loopback no-auth tests), 3162 (network override tests)
|
||||
*/
|
||||
import { describe, it, expect, beforeAll, afterAll } from 'vitest';
|
||||
import { WebServer } from '../src/web/server.js';
|
||||
@@ -16,6 +16,7 @@ import { SettingsUpdateSchema } from '../src/web/schemas.js';
|
||||
|
||||
const AUTH_PORT = 3160;
|
||||
const NOAUTH_PORT = 3161;
|
||||
const NETWORK_OVERRIDE_PORT = 3162;
|
||||
const TEST_USER = 'admin';
|
||||
const TEST_PASS = 'test-password-12345';
|
||||
|
||||
@@ -220,7 +221,7 @@ describe('Settings Schema Security', () => {
|
||||
|
||||
it('should enforce tunnelEnabled as boolean', () => {
|
||||
const result = SettingsUpdateSchema.safeParse({
|
||||
tunnelEnabled: 'yes', // truthy string — should be rejected
|
||||
tunnelEnabled: 'yes', // truthy string — should be rejected
|
||||
});
|
||||
expect(result.success).toBe(false);
|
||||
});
|
||||
@@ -264,40 +265,69 @@ describe('Settings Schema Security', () => {
|
||||
expect(validResult.success).toBe(true);
|
||||
|
||||
const invalidResult = SettingsUpdateSchema.safeParse({
|
||||
nice: { enabled: true, niceValue: 100 }, // Out of range
|
||||
nice: { enabled: true, niceValue: 100 }, // Out of range
|
||||
});
|
||||
expect(invalidResult.success).toBe(false);
|
||||
});
|
||||
});
|
||||
|
||||
describe('No-Auth Server Warning', () => {
|
||||
describe('No-Auth Server Startup Policy', () => {
|
||||
let server: WebServer;
|
||||
let consoleWarnSpy: string[] = [];
|
||||
const originalWarn = console.warn;
|
||||
|
||||
beforeAll(async () => {
|
||||
delete process.env.CODEMAN_PASSWORD;
|
||||
delete process.env.CODEMAN_USERNAME;
|
||||
consoleWarnSpy = [];
|
||||
console.warn = (...args: unknown[]) => {
|
||||
consoleWarnSpy.push(args.map(String).join(' '));
|
||||
};
|
||||
server = new WebServer(NOAUTH_PORT, false, true);
|
||||
delete process.env.CODEMAN_ALLOW_UNAUTHENTICATED_NETWORK;
|
||||
server = new WebServer(NOAUTH_PORT, false, true, '127.0.0.1');
|
||||
await server.start();
|
||||
});
|
||||
|
||||
afterAll(async () => {
|
||||
console.warn = originalWarn;
|
||||
delete process.env.CODEMAN_PASSWORD;
|
||||
delete process.env.CODEMAN_USERNAME;
|
||||
delete process.env.CODEMAN_ALLOW_UNAUTHENTICATED_NETWORK;
|
||||
await server.stop();
|
||||
});
|
||||
|
||||
it('should warn when no CODEMAN_PASSWORD is set', () => {
|
||||
const hasWarning = consoleWarnSpy.some(msg => msg.includes('No CODEMAN_PASSWORD set'));
|
||||
expect(hasWarning).toBe(true);
|
||||
});
|
||||
|
||||
it('should allow requests without auth when no password configured', async () => {
|
||||
it('allows loopback requests without auth when no password is configured', async () => {
|
||||
const res = await fetch(`http://localhost:${NOAUTH_PORT}/api/status`);
|
||||
expect(res.status).toBe(200);
|
||||
});
|
||||
|
||||
it('rejects non-loopback startup without a password or explicit override', async () => {
|
||||
const networkServer = new WebServer(0, false, true, '0.0.0.0');
|
||||
|
||||
await expect(networkServer.start()).rejects.toThrow(/CODEMAN_PASSWORD/);
|
||||
|
||||
await networkServer.stop();
|
||||
});
|
||||
|
||||
it('allows non-loopback startup when CODEMAN_PASSWORD is configured', async () => {
|
||||
process.env.CODEMAN_PASSWORD = TEST_PASS;
|
||||
const networkServer = new WebServer(0, false, true, '0.0.0.0');
|
||||
|
||||
await networkServer.start();
|
||||
await networkServer.stop();
|
||||
|
||||
delete process.env.CODEMAN_PASSWORD;
|
||||
});
|
||||
|
||||
it('allows non-loopback startup with the explicit unauthenticated-network override', async () => {
|
||||
const networkServer = new WebServer(NETWORK_OVERRIDE_PORT, false, true, '0.0.0.0', undefined, true);
|
||||
|
||||
await networkServer.start();
|
||||
const res = await fetch(`http://localhost:${NETWORK_OVERRIDE_PORT}/api/status`);
|
||||
expect(res.status).toBe(200);
|
||||
await networkServer.stop();
|
||||
});
|
||||
|
||||
it('allows non-loopback startup with the explicit unauthenticated-network env override', async () => {
|
||||
process.env.CODEMAN_ALLOW_UNAUTHENTICATED_NETWORK = 'true';
|
||||
const networkServer = new WebServer(0, false, true, '0.0.0.0');
|
||||
|
||||
await networkServer.start();
|
||||
await networkServer.stop();
|
||||
|
||||
delete process.env.CODEMAN_ALLOW_UNAUTHENTICATED_NETWORK;
|
||||
});
|
||||
});
|
||||
|
||||
+34
-16
@@ -5,6 +5,7 @@
|
||||
*/
|
||||
|
||||
import { describe, it, expect } from 'vitest';
|
||||
import { program } from '../src/cli.js';
|
||||
|
||||
describe('CLI Command Parsing', () => {
|
||||
describe('Command Structure', () => {
|
||||
@@ -72,11 +73,11 @@ describe('CLI Command Parsing', () => {
|
||||
];
|
||||
|
||||
const findCommand = (name: string): Command | undefined => {
|
||||
return commands.find(c => c.name === name || c.aliases.includes(name));
|
||||
return commands.find((c) => c.name === name || c.aliases.includes(name));
|
||||
};
|
||||
|
||||
const findSubcommand = (parent: Command, name: string): Command | undefined => {
|
||||
return parent.subcommands?.find(c => c.name === name || c.aliases.includes(name));
|
||||
return parent.subcommands?.find((c) => c.name === name || c.aliases.includes(name));
|
||||
};
|
||||
|
||||
it('should find commands by name', () => {
|
||||
@@ -103,7 +104,7 @@ describe('CLI Command Parsing', () => {
|
||||
});
|
||||
|
||||
it('should have descriptions for all commands', () => {
|
||||
commands.forEach(cmd => {
|
||||
commands.forEach((cmd) => {
|
||||
expect(cmd.description).toBeTruthy();
|
||||
});
|
||||
});
|
||||
@@ -267,13 +268,13 @@ describe('CLI Command Parsing', () => {
|
||||
});
|
||||
|
||||
it('should have defaults for web flags', () => {
|
||||
webFlags.forEach(flag => {
|
||||
webFlags.forEach((flag) => {
|
||||
expect(flag.default).toBeDefined();
|
||||
});
|
||||
});
|
||||
|
||||
it('should have defaults for tui flags', () => {
|
||||
tuiFlags.forEach(flag => {
|
||||
tuiFlags.forEach((flag) => {
|
||||
expect(flag.default).toBeDefined();
|
||||
});
|
||||
});
|
||||
@@ -322,7 +323,7 @@ describe('CLI Command Parsing', () => {
|
||||
help += `${description}\n`;
|
||||
if (options.length > 0) {
|
||||
help += '\nOptions:\n';
|
||||
options.forEach(opt => {
|
||||
options.forEach((opt) => {
|
||||
help += ` ${opt}\n`;
|
||||
});
|
||||
}
|
||||
@@ -345,6 +346,15 @@ describe('CLI Command Parsing', () => {
|
||||
expect(help).toContain('--host');
|
||||
});
|
||||
|
||||
it('documents the unauthenticated network override in real web command help', () => {
|
||||
const webCommand = program.commands.find((command) => command.name() === 'web');
|
||||
expect(webCommand).toBeDefined();
|
||||
|
||||
const help = webCommand!.helpInformation();
|
||||
expect(help).toContain('--allow-unauthenticated-network');
|
||||
expect(help).toMatch(/without\s+CODEMAN_PASSWORD/);
|
||||
});
|
||||
|
||||
it('should format properly', () => {
|
||||
const help = generateHelp('test', 'Test command', ['--flag']);
|
||||
const lines = help.split('\n');
|
||||
@@ -474,22 +484,27 @@ describe('CLI Output Formatting', () => {
|
||||
}
|
||||
|
||||
const formatRow = (values: string[], columns: Column[]): string => {
|
||||
return values.map((val, i) => {
|
||||
const width = columns[i]?.width || 10;
|
||||
return val.padEnd(width).substring(0, width);
|
||||
}).join(' ');
|
||||
return values
|
||||
.map((val, i) => {
|
||||
const width = columns[i]?.width || 10;
|
||||
return val.padEnd(width).substring(0, width);
|
||||
})
|
||||
.join(' ');
|
||||
};
|
||||
|
||||
const formatTable = (headers: string[], rows: string[][], widths: number[]): string => {
|
||||
const columns = headers.map((h, i) => ({ header: h, width: widths[i] }));
|
||||
const headerRow = formatRow(headers, columns);
|
||||
const separator = columns.map(c => '-'.repeat(c.width)).join(' ');
|
||||
const dataRows = rows.map(row => formatRow(row, columns));
|
||||
const separator = columns.map((c) => '-'.repeat(c.width)).join(' ');
|
||||
const dataRows = rows.map((row) => formatRow(row, columns));
|
||||
return [headerRow, separator, ...dataRows].join('\n');
|
||||
};
|
||||
|
||||
it('should format single row', () => {
|
||||
const columns = [{ header: 'ID', width: 10 }, { header: 'Status', width: 8 }];
|
||||
const columns = [
|
||||
{ header: 'ID', width: 10 },
|
||||
{ header: 'Status', width: 8 },
|
||||
];
|
||||
const row = formatRow(['123', 'active'], columns);
|
||||
expect(row).toBe('123 active ');
|
||||
});
|
||||
@@ -503,7 +518,10 @@ describe('CLI Output Formatting', () => {
|
||||
it('should format complete table', () => {
|
||||
const table = formatTable(
|
||||
['ID', 'Status'],
|
||||
[['1', 'active'], ['2', 'idle']],
|
||||
[
|
||||
['1', 'active'],
|
||||
['2', 'idle'],
|
||||
],
|
||||
[5, 8]
|
||||
);
|
||||
expect(table).toContain('ID');
|
||||
@@ -587,7 +605,7 @@ describe('CLI Output Formatting', () => {
|
||||
});
|
||||
|
||||
it('should format normal costs with 2 decimals', () => {
|
||||
expect(formatCost(1.50)).toBe('$1.50');
|
||||
expect(formatCost(1.5)).toBe('$1.50');
|
||||
expect(formatCost(0.05)).toBe('$0.05');
|
||||
});
|
||||
|
||||
@@ -633,7 +651,7 @@ describe('CLI Output Formatting', () => {
|
||||
|
||||
describe('List Formatting', () => {
|
||||
const formatList = (items: string[], bullet: string = '-'): string => {
|
||||
return items.map(item => `${bullet} ${item}`).join('\n');
|
||||
return items.map((item) => `${bullet} ${item}`).join('\n');
|
||||
};
|
||||
|
||||
const formatNumberedList = (items: string[]): string => {
|
||||
|
||||
Reference in New Issue
Block a user