fix(multiuser): close cross-user web-layer scoping holes found in review

The opt-in multi-user feature's only enforcement is web-layer scoping
(all sessions share one OS account). An adversarial review found 8 critical
+ 7 high cross-user holes that defeated it, plus mediums; all fixed here.
Single-user (flag-off) behavior stays byte-identical apart from documented
consistency deltas.

Ownership / confinement:
- DELETE /api/sessions (bulk) + /:id now owner-scope / findSessionOrFail
- quick-start, cron (create+fire), scheduled runs confine workingDir to the
  owner's space; case link/docker-link/docker-import confine the host path
- resolveCasePath no longer resolves linked cases for non-admins; foreign
  remote/docker cases are skipped (fall through to the caller's own local case)
- history, subagents/workflows, mux-sessions, orchestrator, cron run-history,
  away-digest, and remote/docker host reads are owner- or admin-scoped

Permission policy (section 6.3):
- non-granted users are downgraded at every spawn site incl. legacy
  /api/scheduled, PlanOrchestrator one-shots, remote launch, and the cron-fire
  gemini/codex bypass switches; resolveClaudeModeForUsername now fails closed

Auth / store:
- verify-first login throttle (a correct password is never locked out),
  /ws terminal subject to the change-password lockbox, cookie fast-path
  re-validates identity live, role/grant changes revoke sessions, admin delete
  runs the last-admin guard before any teardown
- users.json: distinguish missing (ENOENT) from corrupt/unreadable so a bad
  read can't overwrite all accounts; unique per-process temp write path

Event streams:
- debounced session:updated + batched task:updated, clipboard, and push
  notifications route by owner (fail closed); getLightState hides machine-wide
  globalStats from non-admins

Tests: two suites updated to assert the fixed (secure) behavior. tsc, eslint,
and test:ci all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-07-20 12:33:12 +02:00
parent c3b0dc345b
commit ccb3afc9ee
29 changed files with 757 additions and 230 deletions
+13 -5
View File
@@ -134,8 +134,12 @@ export function registerAdminRoutes(app: FastifyInstance, ctx: SessionPort & Aut
}
try {
const user = await updateUser(username, parsed.data);
// Disabling revokes the user's cookie sessions.
if (parsed.data.disabled) revokeUserSessions(ctx.authSessions, username);
// Security: revoke the target's cookie sessions on ANY successful update. role,
// disabled, and canBypassPermissions are all authorization-relevant, and the
// cookie snapshots role, so a stale cookie could otherwise retain old privileges
// (a demoted admin staying admin). Idempotent, affects only the target, and
// forces a re-auth that re-snapshots the new record.
revokeUserSessions(ctx.authSessions, user.username);
audit(req, 'user.update', user.username, parsed.data);
ctx.broadcast(SseEvent.AdminUsersChanged, {});
return { success: true, data: { user: toPublicUser(user) } };
@@ -177,14 +181,18 @@ export function registerAdminRoutes(app: FastifyInstance, ctx: SessionPort & Aut
const parsed = DeleteUserSchema.safeParse(req.body ?? {});
const deleteSpace = parsed.success ? parsed.data.deleteSpace : false;
try {
// Kill the user's live sessions first (normal kill flow, incl. docker/remote
// teardown), before removing the record.
// Security: validate BEFORE any teardown. deleteUser runs the authoritative
// existence + last-admin guard under lock with no side effects, so a refusal
// (409 LAST_ADMIN / 404 USER_NOT_FOUND) leaves the user's live sessions and
// cookies untouched. Only after it succeeds do we irreversibly kill sessions and
// revoke cookies. (owned is captured from the in-memory map, independent of the
// record, so it is safe to read before the delete.)
const owned = [...ctx.sessions.values()].filter((s) => s.owner === username).map((s) => s.id);
await deleteUser(username); // throws LAST_ADMIN / USER_NOT_FOUND (no side effects)
for (const id of owned) {
await ctx.cleanupSession(id, true, 'admin_delete_user').catch(() => {});
}
revokeUserSessions(ctx.authSessions, username);
await deleteUser(username); // throws LAST_ADMIN / USER_NOT_FOUND
if (deleteSpace) await deleteUserSpace(username);
audit(req, 'user.delete', username, { deleteSpace, killedSessions: owned.length });
ctx.broadcast(SseEvent.AdminUsersChanged, {});