Build ErsatzTV Image / Docs update reminder (pull_request) Successful in 8s
Build ErsatzTV Image / Build & test (.NET) (pull_request) Successful in 9m24s
Build ErsatzTV Image / EF migration integrity (SQLite + MySql) (pull_request) Successful in 11m9s
Build ErsatzTV Image / Build & push image (amd64) (pull_request) Has been skipped
Fix-commit re-review confirmed the 1st-round fixes resolved and caught a 2nd round: - HIGH — env-seed vs. setup race: an attacker could claim admin in the startup window before LocalAdminSeedService runs, and the seed's insert would then be swallowed (attacker credential persists, defeating env recovery). Fixed structurally: the setup-claim endpoint is CLOSED (409) whenever Auth:LocalAdmin:Password is configured — the env seed owns the credential, so there's no claim to race (also strengthens the setup-claim TOFU posture). Config.setupRequired reflects it. - LOW — a concurrent setup race-loser now returns 409 (not 422); ClaimLocalAdmin's DbUpdateException catch re-checks existence and rethrows genuine/transient DB errors instead of masking them as "already configured". - MEDIUM (accepted, documented) — two simultaneous authenticated password changes are a non-serializable lost-update; accepted for a single-admin system (self-healing via re-login, implausible timing). +3 AuthController tests (env-seed closes setup / setupRequired gating). Full ErsatzTV.Tests green (1506); no generated drift. Docs updated. Refs #295 Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
69 lines
3.0 KiB
C#
69 lines
3.0 KiB
C#
using ErsatzTV.Core;
|
|
using ErsatzTV.Core.Domain;
|
|
using ErsatzTV.Infrastructure.Data;
|
|
using Microsoft.EntityFrameworkCore;
|
|
|
|
namespace ErsatzTV.Application.Auth;
|
|
|
|
public class ClaimLocalAdminHandler(IDbContextFactory<TvContext> dbContextFactory, ILocalPasswordHasher passwordHasher)
|
|
: IRequestHandler<ClaimLocalAdmin, Either<BaseError, LocalAdminPrincipal>>
|
|
{
|
|
public async Task<Either<BaseError, LocalAdminPrincipal>> Handle(
|
|
ClaimLocalAdmin request,
|
|
CancellationToken cancellationToken)
|
|
{
|
|
foreach (BaseError error in LocalAdminHelpers.ValidateNewCredentials(request.Username, request.Password))
|
|
{
|
|
return error;
|
|
}
|
|
|
|
string username = request.Username.Trim();
|
|
|
|
await using TvContext dbContext = await dbContextFactory.CreateDbContextAsync(cancellationToken);
|
|
|
|
// Fast path for the common already-configured case (clean 409). The real first-claim-wins guard is
|
|
// the unique index on ConfigElement.Key + the single atomic SaveChanges below: two concurrent claims
|
|
// both pass this check, but only one INSERT of the three credential rows commits — the loser's
|
|
// SaveChanges violates the unique Key index and rolls back wholesale (no mixed-state credential).
|
|
bool alreadyConfigured = await dbContext.ConfigElements
|
|
.AnyAsync(c => c.Key == ConfigElementKey.AuthLocalAdminPasswordHash.Key, cancellationToken);
|
|
if (alreadyConfigured)
|
|
{
|
|
return BaseError.New("A local administrator has already been configured");
|
|
}
|
|
|
|
string stamp = LocalAdminHelpers.NewSecurityStamp();
|
|
dbContext.ConfigElements.AddRange(
|
|
new ConfigElement { Key = ConfigElementKey.AuthLocalAdminUsername.Key, Value = username },
|
|
new ConfigElement
|
|
{
|
|
Key = ConfigElementKey.AuthLocalAdminPasswordHash.Key,
|
|
Value = passwordHasher.Hash(request.Password)
|
|
},
|
|
new ConfigElement { Key = ConfigElementKey.AuthSecurityStamp.Key, Value = stamp });
|
|
|
|
try
|
|
{
|
|
await dbContext.SaveChangesAsync(cancellationToken);
|
|
}
|
|
catch (DbUpdateException)
|
|
{
|
|
// A write conflict here is (almost always) a lost first-claim race — a concurrent claim inserted
|
|
// these keys first (unique Key index). Confirm the row now exists on a fresh context before
|
|
// reporting "already configured"; otherwise this was a genuine/transient DB error → rethrow rather
|
|
// than mask it.
|
|
await using TvContext verifyContext = await dbContextFactory.CreateDbContextAsync(cancellationToken);
|
|
bool nowConfigured = await verifyContext.ConfigElements
|
|
.AnyAsync(c => c.Key == ConfigElementKey.AuthLocalAdminPasswordHash.Key, cancellationToken);
|
|
if (nowConfigured)
|
|
{
|
|
return BaseError.New("A local administrator has already been configured");
|
|
}
|
|
|
|
throw;
|
|
}
|
|
|
|
return new LocalAdminPrincipal(username, stamp);
|
|
}
|
|
}
|