fix(multiuser): close cross-user web-layer scoping holes found in review

The opt-in multi-user feature's only enforcement is web-layer scoping
(all sessions share one OS account). An adversarial review found 8 critical
+ 7 high cross-user holes that defeated it, plus mediums; all fixed here.
Single-user (flag-off) behavior stays byte-identical apart from documented
consistency deltas.

Ownership / confinement:
- DELETE /api/sessions (bulk) + /:id now owner-scope / findSessionOrFail
- quick-start, cron (create+fire), scheduled runs confine workingDir to the
  owner's space; case link/docker-link/docker-import confine the host path
- resolveCasePath no longer resolves linked cases for non-admins; foreign
  remote/docker cases are skipped (fall through to the caller's own local case)
- history, subagents/workflows, mux-sessions, orchestrator, cron run-history,
  away-digest, and remote/docker host reads are owner- or admin-scoped

Permission policy (section 6.3):
- non-granted users are downgraded at every spawn site incl. legacy
  /api/scheduled, PlanOrchestrator one-shots, remote launch, and the cron-fire
  gemini/codex bypass switches; resolveClaudeModeForUsername now fails closed

Auth / store:
- verify-first login throttle (a correct password is never locked out),
  /ws terminal subject to the change-password lockbox, cookie fast-path
  re-validates identity live, role/grant changes revoke sessions, admin delete
  runs the last-admin guard before any teardown
- users.json: distinguish missing (ENOENT) from corrupt/unreadable so a bad
  read can't overwrite all accounts; unique per-process temp write path

Event streams:
- debounced session:updated + batched task:updated, clipboard, and push
  notifications route by owner (fail closed); getLightState hides machine-wide
  globalStats from non-admins

Tests: two suites updated to assert the fixed (secure) behavior. tsc, eslint,
and test:ci all green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
Codeman maintainer
2026-07-20 12:33:12 +02:00
parent c3b0dc345b
commit ccb3afc9ee
29 changed files with 757 additions and 230 deletions
+33 -11
View File
@@ -19,7 +19,8 @@
import { FastifyInstance } from 'fastify';
import { ApiErrorCode, createErrorResponse, getErrorMessage } from '../../types.js';
import { OrchestratorStartSchema, OrchestratorRejectSchema } from '../schemas.js';
import { parseBody } from '../route-helpers.js';
import { parseBody, requireAdmin } from '../route-helpers.js';
import { isMultiUserMode } from '../../config/multiuser.js';
import { SseEvent } from '../sse-events.js';
import type { EventPort, OrchestratorPort } from '../ports/index.js';
@@ -79,7 +80,10 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
// Start
// ═══════════════════════════════════════════════════════════════
app.post('/api/orchestrator/start', async (req) => {
app.post('/api/orchestrator/start', async (req, reply) => {
// Multi-user: the orchestrator is a process-wide singleton with no per-user
// isolation → admin-only (requireAdmin is a no-op allow-all in single-user mode).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const { goal, config } = parseBody(OrchestratorStartSchema, req.body, 'Invalid request body');
// Initialize loop if needed
@@ -115,7 +119,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
// Approve / Reject Plan
// ═══════════════════════════════════════════════════════════════
app.post('/api/orchestrator/approve', async () => {
app.post('/api/orchestrator/approve', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
try {
@@ -128,7 +134,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
}
});
app.post('/api/orchestrator/reject', async (req) => {
app.post('/api/orchestrator/reject', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
const { feedback } = parseBody(OrchestratorRejectSchema, req.body, 'Feedback is required');
@@ -147,7 +155,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
// Pause / Resume / Stop
// ═══════════════════════════════════════════════════════════════
app.post('/api/orchestrator/pause', async () => {
app.post('/api/orchestrator/pause', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
try {
@@ -158,7 +168,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
}
});
app.post('/api/orchestrator/resume', async () => {
app.post('/api/orchestrator/resume', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
try {
@@ -171,7 +183,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
}
});
app.post('/api/orchestrator/stop', async () => {
app.post('/api/orchestrator/stop', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
try {
@@ -186,7 +200,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
// Status / Plan
// ═══════════════════════════════════════════════════════════════
app.get('/api/orchestrator/status', async () => {
app.get('/api/orchestrator/status', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = ctx.orchestratorLoop;
if (!loop) {
return { ok: true, state: 'idle', plan: null, stats: null };
@@ -198,7 +214,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
};
});
app.get('/api/orchestrator/plan', async () => {
app.get('/api/orchestrator/plan', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = ctx.orchestratorLoop;
if (!loop) {
return { ok: true, plan: null };
@@ -215,7 +233,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
// Phase Operations
// ═══════════════════════════════════════════════════════════════
app.post('/api/orchestrator/phase/:id/skip', async (req) => {
app.post('/api/orchestrator/phase/:id/skip', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
const { id } = req.params as { id: string };
@@ -227,7 +247,9 @@ export function registerOrchestratorRoutes(app: FastifyInstance, ctx: Orchestrat
}
});
app.post('/api/orchestrator/phase/:id/retry', async (req) => {
app.post('/api/orchestrator/phase/:id/retry', async (req, reply) => {
// Multi-user: shared-singleton orchestrator → admin-only (no-op in single-user).
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
const loop = getLoop();
const { id } = req.params as { id: string };