HH-620: require authentication before exposing setup
Co-authored-by: multica-agent <github@multica.ai>
This commit is contained in:
@@ -16,7 +16,10 @@ import (
|
||||
"time"
|
||||
)
|
||||
|
||||
const maxSubscriptionSize = 16 << 20
|
||||
const (
|
||||
maxSubscriptionSize = 16 << 20
|
||||
minAdminPasswordLength = 12
|
||||
)
|
||||
|
||||
var errMihomoStateUncertain = errors.New("Mihomo subscription state could not be restored")
|
||||
|
||||
@@ -101,6 +104,63 @@ func Prepare(config Config) (Result, error) {
|
||||
return result, nil
|
||||
}
|
||||
|
||||
func EnsureAdminPassword(root, binary, password string) (bool, error) {
|
||||
root = filepath.Clean(root)
|
||||
if root == "." || root == string(filepath.Separator) || !filepath.IsAbs(root) {
|
||||
return false, fmt.Errorf("unsafe root %q", root)
|
||||
}
|
||||
passwordPath := filepath.Join(root, ".ssclash", "password")
|
||||
configured, err := adminPasswordConfigured(passwordPath)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
if configured {
|
||||
return false, nil
|
||||
}
|
||||
if password == "" {
|
||||
return false, errors.New("SSCLASH_PASSWORD is required to initialize a fresh volume")
|
||||
}
|
||||
if len(password) < minAdminPasswordLength {
|
||||
return false, fmt.Errorf("SSCLASH_PASSWORD must be at least %d characters", minAdminPasswordLength)
|
||||
}
|
||||
if err := validateSource(binary, "SSClash binary"); err != nil {
|
||||
return false, err
|
||||
}
|
||||
|
||||
command := exec.Command(binary, "setpass", password)
|
||||
command.Env = childEnvironment()
|
||||
command.Stdout = io.Discard
|
||||
command.Stderr = io.Discard
|
||||
if err := command.Run(); err != nil {
|
||||
return false, errors.New("SSClash password initialization failed")
|
||||
}
|
||||
configured, err = adminPasswordConfigured(passwordPath)
|
||||
if err != nil {
|
||||
return false, err
|
||||
}
|
||||
if !configured {
|
||||
return false, errors.New("SSClash password initialization did not create an authentication file")
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
|
||||
func adminPasswordConfigured(path string) (bool, error) {
|
||||
info, err := os.Lstat(path)
|
||||
if errors.Is(err, os.ErrNotExist) {
|
||||
return false, nil
|
||||
}
|
||||
if err != nil {
|
||||
return false, fmt.Errorf("inspect SSClash authentication file: %w", err)
|
||||
}
|
||||
if !info.Mode().IsRegular() || info.Size() == 0 {
|
||||
return false, errors.New("SSClash authentication file must be a non-empty regular file")
|
||||
}
|
||||
if info.Mode().Perm()&0o077 != 0 {
|
||||
return false, fmt.Errorf("SSClash authentication file permissions are %o; want 600", info.Mode().Perm())
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
|
||||
func Run(ctx context.Context, config RuntimeConfig) error {
|
||||
if err := validateSubscriptionURL(config.SubscriptionURL); err != nil {
|
||||
return err
|
||||
@@ -336,9 +396,10 @@ func childEnvironment() []string {
|
||||
environment := os.Environ()
|
||||
result := environment[:0]
|
||||
for _, entry := range environment {
|
||||
if !strings.HasPrefix(entry, "SUBSCRIPTION_URL=") {
|
||||
result = append(result, entry)
|
||||
if strings.HasPrefix(entry, "SUBSCRIPTION_URL=") || strings.HasPrefix(entry, "SSCLASH_PASSWORD=") {
|
||||
continue
|
||||
}
|
||||
result = append(result, entry)
|
||||
}
|
||||
return result
|
||||
}
|
||||
|
||||
@@ -90,6 +90,68 @@ func TestPreparePreservesUserDataAndForcesServerMode(t *testing.T) {
|
||||
assertFileContent(t, filepath.Join(root, ".ssclash", "settings"), "LOG_LEVEL=debug\nOPERATING_MODE=server\nPROXY_MODE=none\n")
|
||||
}
|
||||
|
||||
func TestEnsureAdminPasswordFailsClosedOnFreshVolume(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
_, err := EnsureAdminPassword(t.TempDir(), "unused", "")
|
||||
if err == nil || !strings.Contains(err.Error(), "SSCLASH_PASSWORD") {
|
||||
t.Fatalf("EnsureAdminPassword() error = %v, want missing password error", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureAdminPasswordInitializesOnlyWhenMissing(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
root := filepath.Join(t.TempDir(), "data")
|
||||
if err := os.MkdirAll(filepath.Join(root, ".ssclash"), 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
binary := writeFixture(t, filepath.Join(root, "bin"), "ssclash", `#!/bin/sh
|
||||
set -eu
|
||||
[ "$1" = setpass ]
|
||||
[ "$2" = fresh-volume-password ]
|
||||
password="$(dirname "$0")/../.ssclash/password"
|
||||
printf 'pbkdf2$test\n' > "$password"
|
||||
chmod 0600 "$password"
|
||||
`)
|
||||
if err := os.Chmod(binary, 0o755); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
initialized, err := EnsureAdminPassword(root, binary, "fresh-volume-password")
|
||||
if err != nil {
|
||||
t.Fatalf("EnsureAdminPassword() error = %v", err)
|
||||
}
|
||||
if !initialized {
|
||||
t.Fatal("EnsureAdminPassword() initialized = false, want true")
|
||||
}
|
||||
assertFileContent(t, filepath.Join(root, ".ssclash", "password"), "pbkdf2$test\n")
|
||||
|
||||
if err := os.Remove(binary); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
initialized, err = EnsureAdminPassword(root, binary, "replacement-password")
|
||||
if err != nil {
|
||||
t.Fatalf("EnsureAdminPassword() existing password error = %v", err)
|
||||
}
|
||||
if initialized {
|
||||
t.Fatal("EnsureAdminPassword() replaced existing password")
|
||||
}
|
||||
assertFileContent(t, filepath.Join(root, ".ssclash", "password"), "pbkdf2$test\n")
|
||||
}
|
||||
|
||||
func TestChildEnvironmentRemovesCredentials(t *testing.T) {
|
||||
t.Setenv("SUBSCRIPTION_URL", "https://subscription.example.invalid/?token=secret")
|
||||
t.Setenv("SSCLASH_PASSWORD", "secret-password")
|
||||
|
||||
environment := strings.Join(childEnvironment(), "\n")
|
||||
for _, key := range []string{"SUBSCRIPTION_URL=", "SSCLASH_PASSWORD="} {
|
||||
if strings.Contains(environment, key) {
|
||||
t.Errorf("childEnvironment() retained %s", key)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestPrepareRejectsUnsafeOrAmbiguousState(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
|
||||
Reference in New Issue
Block a user