mirror of
https://github.com/navidrome/navidrome.git
synced 2026-08-31 07:30:32 +00:00
* feat(auth): add per-user token_epoch column and bump method * feat(auth): add aud and ep claims, omitted when zero * feat(auth): add CreateAPIToken for non-expiring, audience-scoped tokens * feat(auth): add CheckClaims for epoch and audience validation * feat(jellyfin): issue non-expiring, jellyfin-scoped access tokens * fix(subsonic): reject API-scoped and revoked tokens on the jwt path * fix(server): reject API-scoped and revoked tokens on the native API * fix(server): pin the token-subject guard and stop leaking test config Adds a regression spec for the DevAutoLogin/ExtAuth guard in tokenAllowed, switches its comparison to case-insensitive to match the user lookup's own COLLATE NOCASE semantics, and restores Subsonic JWT test config after each spec instead of leaking SessionTimeout. * feat(request): add a token epoch holder for handler-to-middleware signalling * refactor(server): write the refreshed JWT header after the handler runs * feat(auth): revoke all tokens for a user when their password changes * fix(server): restore Unwrap on the JWT refresh writer so SSE write deadlines apply * test(auth): pin that non-session tokens reject API access tokens * test(jellyfin): pin token scoping and epoch revocation end to end Exercises auth.CreateAPIToken and CheckClaims against the real Jellyfin router and SQLite DB: the minted token has no exp and is aud-scoped to jellyfin, and bumping token_epoch through the real UserRepository revokes an already-issued token on the next protected request. * test(nativeapi): pin the token-epoch handoff through a real password-change request Drive a self password change through the real Authenticator/JWTRefresher chain and a real SQLite-backed userRepository, so the epoch handoff between Put and the refreshed-token writer is verified end to end, not as two separately-tested halves. Also fix tokenAllowed to read the enriched ctx it was given instead of r.Context(), so its warning log carries the username. * refactor(server): drop tokenAllowed's now-unused request parameter Finding-2 already moved every use to ctx; r was dead weight. Also note in the new nativeapi test why it must stay the package's only real-DB spec: db.Db() is a process-wide singleton its cleanup closes for good. * refactor(auth): remove duplication in claim decoding and token minting * refactor(auth): group aud with the standard JWT claims * refactor(auth): read aud with the standard-claim accessor pattern * fix(log): redact every api_key spelling the Jellyfin API accepts * fix(auth): bind session tokens to the user id, not just the username * fix(auth): return the token epoch from the same atomic increment * fix(auth): bump the token epoch in the same statement as the password write * chore(auth): trim comments to the why-only budget
67 lines
2.4 KiB
Go
67 lines
2.4 KiB
Go
package model
|
|
|
|
import (
|
|
"time"
|
|
)
|
|
|
|
type User struct {
|
|
ID string `structs:"id" json:"id"`
|
|
UserName string `structs:"user_name" json:"userName"`
|
|
Name string `structs:"name" json:"name"`
|
|
Email string `structs:"email" json:"email"`
|
|
IsAdmin bool `structs:"is_admin" json:"isAdmin"`
|
|
LastLoginAt *time.Time `structs:"last_login_at" json:"lastLoginAt"`
|
|
LastAccessAt *time.Time `structs:"last_access_at" json:"lastAccessAt"`
|
|
CreatedAt time.Time `structs:"created_at" json:"createdAt"`
|
|
UpdatedAt time.Time `structs:"updated_at" json:"updatedAt"`
|
|
// Smart-playlist criteria JSON; matching songs are not sent to external scrobblers
|
|
ScrobbleFilter string `structs:"scrobble_filter" json:"scrobbleFilter"`
|
|
|
|
// Library associations (many-to-many relationship)
|
|
Libraries Libraries `structs:"-" json:"libraries,omitempty"`
|
|
|
|
// This is only available on the backend, and it is never sent over the wire
|
|
Password string `structs:"-" json:"-"`
|
|
// Bumped on password change to invalidate every issued token for this user.
|
|
TokenEpoch int `structs:"-" json:"-"`
|
|
// This is used to set or change a password when calling Put. If it is empty, the password is not changed.
|
|
// It is received from the UI with the name "password"
|
|
NewPassword string `structs:"password,omitempty" json:"password,omitempty"` //nolint:gosec
|
|
// If changing the password, this is also required
|
|
CurrentPassword string `structs:"current_password,omitempty" json:"currentPassword,omitempty"`
|
|
}
|
|
|
|
func (u User) HasLibraryAccess(libraryID int) bool {
|
|
if u.IsAdmin {
|
|
return true // Admin users have access to all libraries
|
|
}
|
|
for _, lib := range u.Libraries {
|
|
if lib.ID == libraryID {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
type Users []User
|
|
|
|
type UserRepository interface {
|
|
ResourceRepository
|
|
CountAll(...QueryOptions) (int64, error)
|
|
Delete(id string) error
|
|
Get(id string) (*User, error)
|
|
GetAll(options ...QueryOptions) (Users, error)
|
|
Put(*User) error
|
|
UpdateLastLoginAt(id string) error
|
|
UpdateLastAccessAt(id string) error
|
|
FindFirstAdmin() (*User, error)
|
|
// FindByUsername must be case-insensitive
|
|
FindByUsername(username string) (*User, error)
|
|
// FindByUsernameWithPassword is the same as above, but also returns the decrypted password
|
|
FindByUsernameWithPassword(username string) (*User, error)
|
|
|
|
// Library association methods
|
|
GetUserLibraries(userID string) (Libraries, error)
|
|
SetUserLibraries(userID string, libraryIDs []int) error
|
|
}
|