mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 04:52:50 +08:00
Merge PR #80: feat(perm) fine-grained account permissions
Conflict resolution + cross-PR integration: - player.ts: kept #88's POST /:botId/fm route AND gated it with requirePermission('player.control') so the new control endpoint honors #80's permission model (it was added without gating). - bot.ts: kept #81's relocated /settings routes (the relocation fixes the GET /settings shadow bug) and dropped #80's now-duplicate bottom copy; gated POST /settings with requirePermission('bot.manage'). - Navbar.vue: composed #82's dedicated-link scope with #80's permission filter — displayedBots is now the INTERSECTION (scope ∩ controllable allow-list). - database.ts: kept BOTH new table sets (#87 favorite_playlists + #80 user_permissions/user_bot_access). - bot.test.ts: updated to createRequireAuth(sessions, permissions) for #80's new two-arg signature. #80 review fixes (credential exposure / IDOR, adversarially verified): - GET /:id/config now requires bot.manage + bot access AND redacts ts6ApiKey + identity from the response (was readable by any authenticated member). - GET /:id and GET /:id/avatar now require bot access (were ungated read oracles).
This commit is contained in:
commit
bea2f92508
32 files changed
+2225
-137
No files matched your search
+2
-1
@@ -6,7 +6,8 @@ export type AuditAction =
|
||||
| "user.deleted"
|
||||
| "user.password_reset"
|
||||
| "user.password_changed"
|
||||
| "user.role_changed";
|
||||
| "user.role_changed"
|
||||
| "user.permissions_changed";
|
||||
|
||||
export interface AuditEntry {
|
||||
id: number;
|
||||
|
||||
@@ -1,4 +1,5 @@
|
||||
import Database from "better-sqlite3";
|
||||
import { CAPABILITIES, BOTS_ALL } from "./permissions.js";
|
||||
|
||||
export interface PlayHistoryEntry {
|
||||
botId: string;
|
||||
@@ -194,15 +195,54 @@ function initTables(db: Database.Database): void {
|
||||
UNIQUE(userId, platform, playlistId)
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_favorites_userId ON favorite_playlists(userId);
|
||||
|
||||
CREATE TABLE IF NOT EXISTS user_permissions (
|
||||
userId TEXT NOT NULL,
|
||||
permission TEXT NOT NULL,
|
||||
PRIMARY KEY (userId, permission),
|
||||
FOREIGN KEY (userId) REFERENCES users(id) ON DELETE CASCADE
|
||||
);
|
||||
CREATE TABLE IF NOT EXISTS user_bot_access (
|
||||
userId TEXT NOT NULL,
|
||||
botId TEXT NOT NULL,
|
||||
PRIMARY KEY (userId, botId),
|
||||
FOREIGN KEY (userId) REFERENCES users(id) ON DELETE CASCADE
|
||||
);
|
||||
CREATE INDEX IF NOT EXISTS idx_user_bot_access_userId ON user_bot_access(userId);
|
||||
`);
|
||||
}
|
||||
|
||||
/**
|
||||
* One-time backfill: existing `member` users created before the
|
||||
* account-permissions feature are granted full access (all 5 capabilities +
|
||||
* the `bots.all` marker), exactly once per database. Admins are skipped (they
|
||||
* bypass permission checks). New members created after this runs are not
|
||||
* affected — they get the basic tier via POST /api/users. A marker row in
|
||||
* `schema_meta` makes this idempotent.
|
||||
*/
|
||||
export function backfillMemberPermissions(db: Database.Database): void {
|
||||
db.exec(`CREATE TABLE IF NOT EXISTS schema_meta (key TEXT PRIMARY KEY, value TEXT)`);
|
||||
const done = db.prepare("SELECT value FROM schema_meta WHERE key = 'perm_backfill_done'").get();
|
||||
if (done) return;
|
||||
const members = db.prepare("SELECT id FROM users WHERE role = 'member'").all() as { id: string }[];
|
||||
const insCap = db.prepare("INSERT OR IGNORE INTO user_permissions (userId, permission) VALUES (?, ?)");
|
||||
const tokens = [...CAPABILITIES, BOTS_ALL];
|
||||
const tx = db.transaction(() => {
|
||||
for (const m of members) {
|
||||
for (const t of tokens) insCap.run(m.id, t);
|
||||
}
|
||||
db.prepare("INSERT INTO schema_meta (key, value) VALUES ('perm_backfill_done', ?)").run(String(members.length));
|
||||
});
|
||||
tx();
|
||||
}
|
||||
|
||||
export function createDatabase(dbPath: string): BotDatabase {
|
||||
const db = new Database(dbPath);
|
||||
db.pragma("journal_mode = WAL");
|
||||
db.pragma("foreign_keys = ON");
|
||||
initTables(db);
|
||||
migrateSchema(db);
|
||||
backfillMemberPermissions(db);
|
||||
|
||||
const insertHistory = db.prepare(`
|
||||
INSERT INTO play_history (botId, songId, songName, artist, album, platform, coverUrl)
|
||||
|
||||
@@ -0,0 +1,58 @@
|
||||
import { describe, it, expect, afterEach } from "vitest";
|
||||
import fs from "node:fs";
|
||||
import path from "node:path";
|
||||
import os from "node:os";
|
||||
import { createDatabase, backfillMemberPermissions, type BotDatabase } from "./database.js";
|
||||
import { createPermissionStore, CAPABILITIES } from "./permissions.js";
|
||||
|
||||
describe("backfillMemberPermissions", () => {
|
||||
let dbFile: string;
|
||||
let db: BotDatabase;
|
||||
function fresh() {
|
||||
dbFile = path.join(os.tmpdir(), `mig-${Date.now()}-${Math.random().toString(36).slice(2)}.db`);
|
||||
db = createDatabase(dbFile);
|
||||
}
|
||||
afterEach(() => {
|
||||
db.close();
|
||||
for (const s of ["", "-wal", "-shm"]) {
|
||||
try {
|
||||
fs.rmSync(dbFile + s, { force: true });
|
||||
} catch {}
|
||||
}
|
||||
});
|
||||
|
||||
it("grants existing members full access + bots.all, skips admins, once", () => {
|
||||
fresh();
|
||||
// simulate a pre-feature DB: clear the marker that createDatabase set, add users, no perm rows
|
||||
db.db.prepare("DELETE FROM schema_meta WHERE key = 'perm_backfill_done'").run();
|
||||
const now = Date.now();
|
||||
const ins = db.db.prepare(
|
||||
"INSERT INTO users (id,username,passwordHash,createdAt,updatedAt,role) VALUES (?,?,?,?,?,?)"
|
||||
);
|
||||
ins.run("m1", "mem", "x", now, now, "member");
|
||||
ins.run("a1", "adm", "x", now, now, "admin");
|
||||
|
||||
backfillMemberPermissions(db.db);
|
||||
|
||||
const store = createPermissionStore(db.db);
|
||||
expect(store.getCapabilities("m1").sort()).toEqual([...CAPABILITIES].sort());
|
||||
expect(store.getBotAccess("m1")).toBe("all");
|
||||
expect(store.getCapabilities("a1")).toEqual([]);
|
||||
expect(store.getBotAccess("a1")).toEqual([]);
|
||||
});
|
||||
|
||||
it("is idempotent — running again does not change or re-grant", () => {
|
||||
fresh();
|
||||
db.db.prepare("DELETE FROM schema_meta WHERE key = 'perm_backfill_done'").run();
|
||||
const now = Date.now();
|
||||
db.db
|
||||
.prepare("INSERT INTO users (id,username,passwordHash,createdAt,updatedAt,role) VALUES (?,?,?,?,?,?)")
|
||||
.run("m1", "mem", "x", now, now, "member");
|
||||
backfillMemberPermissions(db.db);
|
||||
// member restricted afterwards
|
||||
createPermissionStore(db.db).setPermissions("m1", { capabilities: [], bots: [] });
|
||||
// second run must NOT re-grant (marker present)
|
||||
backfillMemberPermissions(db.db);
|
||||
expect(createPermissionStore(db.db).getCapabilities("m1")).toEqual([]);
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,90 @@
|
||||
import { describe, it, expect, beforeEach, afterEach } from "vitest";
|
||||
import fs from "node:fs";
|
||||
import path from "node:path";
|
||||
import os from "node:os";
|
||||
import { createDatabase, type BotDatabase } from "./database.js";
|
||||
import { createPermissionStore } from "./permissions.js";
|
||||
import { CAPABILITIES, BASIC_TIER_CAPABILITIES, resolvePermissionContext } from "./permissions.js";
|
||||
|
||||
describe("PermissionStore", () => {
|
||||
let dbFile: string;
|
||||
let db: BotDatabase;
|
||||
|
||||
beforeEach(() => {
|
||||
dbFile = path.join(os.tmpdir(), `perm-test-${Date.now()}-${Math.random().toString(36).slice(2)}.db`);
|
||||
db = createDatabase(dbFile);
|
||||
db.db.prepare(
|
||||
"INSERT INTO users (id, username, passwordHash, createdAt, updatedAt, role) VALUES (?,?,?,?,?,?)"
|
||||
).run("u1", "alice", "x", Date.now(), Date.now(), "member");
|
||||
});
|
||||
|
||||
afterEach(() => {
|
||||
db.close();
|
||||
try { fs.rmSync(dbFile, { force: true }); } catch {}
|
||||
try { fs.rmSync(dbFile + "-wal", { force: true }); } catch {}
|
||||
try { fs.rmSync(dbFile + "-shm", { force: true }); } catch {}
|
||||
});
|
||||
|
||||
it("exposes the five capability tokens and a basic tier", () => {
|
||||
expect(CAPABILITIES).toEqual([
|
||||
"player.control", "player.queue", "bot.manage", "platform.auth", "quality",
|
||||
]);
|
||||
expect(BASIC_TIER_CAPABILITIES).toEqual(["player.control", "player.queue"]);
|
||||
});
|
||||
|
||||
it("defaults to no capabilities and no bots", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
expect(store.getCapabilities("u1")).toEqual([]);
|
||||
expect(store.getBotAccess("u1")).toEqual([]);
|
||||
});
|
||||
|
||||
it("round-trips capabilities and a specific bot list", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
store.setPermissions("u1", { capabilities: ["player.control", "quality"], bots: ["botA", "botB"] });
|
||||
expect(store.getCapabilities("u1").sort()).toEqual(["player.control", "quality"]);
|
||||
expect(store.getBotAccess("u1")).toEqual(["botA", "botB"]);
|
||||
});
|
||||
|
||||
it("stores the all-bots flag as 'all'", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
store.setPermissions("u1", { capabilities: ["player.control"], bots: "all" });
|
||||
expect(store.getBotAccess("u1")).toBe("all");
|
||||
});
|
||||
|
||||
it("setPermissions replaces prior capabilities and bots", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
store.setPermissions("u1", { capabilities: ["player.control"], bots: ["botA"] });
|
||||
store.setPermissions("u1", { capabilities: ["quality"], bots: "all" });
|
||||
expect(store.getCapabilities("u1")).toEqual(["quality"]);
|
||||
expect(store.getBotAccess("u1")).toBe("all");
|
||||
});
|
||||
|
||||
it("ignores unknown capability tokens", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
store.setPermissions("u1", { capabilities: ["player.control", "bogus" as any], bots: [] });
|
||||
expect(store.getCapabilities("u1")).toEqual(["player.control"]);
|
||||
});
|
||||
|
||||
it("pruneBot removes a bot from every user's allow-list", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
store.setPermissions("u1", { capabilities: [], bots: ["botA", "botB"] });
|
||||
store.pruneBot("botA");
|
||||
expect(store.getBotAccess("u1")).toEqual(["botB"]);
|
||||
});
|
||||
|
||||
describe("resolvePermissionContext", () => {
|
||||
it("admin gets all capabilities and all bots regardless of stored rows", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
const ctx = resolvePermissionContext("admin", "u1", store);
|
||||
expect([...ctx.capabilities].sort()).toEqual([...CAPABILITIES].sort());
|
||||
expect(ctx.bots).toBe("all");
|
||||
});
|
||||
it("member reflects stored capabilities + bot access", () => {
|
||||
const store = createPermissionStore(db.db);
|
||||
store.setPermissions("u1", { capabilities: ["player.control"], bots: ["b1"] });
|
||||
const ctx = resolvePermissionContext("member", "u1", store);
|
||||
expect([...ctx.capabilities]).toEqual(["player.control"]);
|
||||
expect(ctx.bots).toEqual(new Set(["b1"]));
|
||||
});
|
||||
});
|
||||
});
|
||||
@@ -0,0 +1,89 @@
|
||||
import type Database from "better-sqlite3";
|
||||
|
||||
export const CAPABILITIES = [
|
||||
"player.control",
|
||||
"player.queue",
|
||||
"bot.manage",
|
||||
"platform.auth",
|
||||
"quality",
|
||||
] as const;
|
||||
export type Capability = (typeof CAPABILITIES)[number];
|
||||
|
||||
/** Marker token stored in user_permissions meaning "all bots, incl. future". */
|
||||
export const BOTS_ALL = "bots.all";
|
||||
|
||||
/** Capabilities granted to a newly-created member by default. */
|
||||
export const BASIC_TIER_CAPABILITIES: Capability[] = ["player.control", "player.queue"];
|
||||
|
||||
export function isCapability(x: string): x is Capability {
|
||||
return (CAPABILITIES as readonly string[]).includes(x);
|
||||
}
|
||||
|
||||
export type BotAccess = "all" | string[];
|
||||
|
||||
export interface PermissionStore {
|
||||
getCapabilities(userId: string): Capability[];
|
||||
getBotAccess(userId: string): BotAccess;
|
||||
setPermissions(userId: string, input: { capabilities: string[]; bots: BotAccess }): void;
|
||||
pruneBot(botId: string): void;
|
||||
}
|
||||
|
||||
export function createPermissionStore(db: Database.Database): PermissionStore {
|
||||
const selCaps = db.prepare("SELECT permission FROM user_permissions WHERE userId = ?");
|
||||
const delCaps = db.prepare("DELETE FROM user_permissions WHERE userId = ?");
|
||||
const insCap = db.prepare("INSERT OR IGNORE INTO user_permissions (userId, permission) VALUES (?, ?)");
|
||||
const selBots = db.prepare("SELECT botId FROM user_bot_access WHERE userId = ?");
|
||||
const delBots = db.prepare("DELETE FROM user_bot_access WHERE userId = ?");
|
||||
const insBot = db.prepare("INSERT OR IGNORE INTO user_bot_access (userId, botId) VALUES (?, ?)");
|
||||
const pruneBotStmt = db.prepare("DELETE FROM user_bot_access WHERE botId = ?");
|
||||
|
||||
return {
|
||||
getCapabilities(userId) {
|
||||
return (selCaps.all(userId) as { permission: string }[])
|
||||
.map((r) => r.permission)
|
||||
.filter((p): p is Capability => isCapability(p));
|
||||
},
|
||||
getBotAccess(userId) {
|
||||
const all = (selCaps.all(userId) as { permission: string }[]).some((r) => r.permission === BOTS_ALL);
|
||||
if (all) return "all";
|
||||
return (selBots.all(userId) as { botId: string }[]).map((r) => r.botId);
|
||||
},
|
||||
setPermissions(userId, input) {
|
||||
const caps = input.capabilities.filter(isCapability);
|
||||
const tx = db.transaction(() => {
|
||||
delCaps.run(userId);
|
||||
delBots.run(userId);
|
||||
for (const c of caps) insCap.run(userId, c);
|
||||
if (input.bots === "all") {
|
||||
insCap.run(userId, BOTS_ALL);
|
||||
} else {
|
||||
for (const b of input.bots) insBot.run(userId, b);
|
||||
}
|
||||
});
|
||||
tx();
|
||||
},
|
||||
pruneBot(botId) {
|
||||
pruneBotStmt.run(botId);
|
||||
},
|
||||
};
|
||||
}
|
||||
|
||||
export interface PermissionContext {
|
||||
capabilities: Set<string>;
|
||||
bots: "all" | Set<string>;
|
||||
}
|
||||
|
||||
export function resolvePermissionContext(
|
||||
role: "admin" | "member",
|
||||
userId: string,
|
||||
store: PermissionStore
|
||||
): PermissionContext {
|
||||
if (role === "admin") {
|
||||
return { capabilities: new Set(CAPABILITIES), bots: "all" };
|
||||
}
|
||||
const access = store.getBotAccess(userId);
|
||||
return {
|
||||
capabilities: new Set(store.getCapabilities(userId)),
|
||||
bots: access === "all" ? "all" : new Set(access),
|
||||
};
|
||||
}
|
||||
Reference in new issue
Block a user