mirror of
https://github.com/ZHANGTIANYAO1/teamspeak-music-bot.git
synced 2026-10-02 04:52:50 +08:00
fix(auth): race-safe first-run setup + rolling cookie max-age refresh
Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
1 parent
fb7feec5cf
commit
ceb24595e6
6 files changed
+82
-8
No files matched your search
@@ -72,4 +72,24 @@ describe("UserStore", () => {
|
|||||||
expect(users.countUsers()).toBe(0);
|
expect(users.countUsers()).toBe(0);
|
||||||
expect(users.deleteUser("not-a-real-id")).toBe(false);
|
expect(users.deleteUser("not-a-real-id")).toBe(false);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("createFirstUser succeeds on empty db, returns null when a user already exists", async () => {
|
||||||
|
const a = await users.createFirstUser("alice", "pw-alice");
|
||||||
|
expect(a).not.toBeNull();
|
||||||
|
expect(a!.username).toBe("alice");
|
||||||
|
const b = await users.createFirstUser("bob", "pw-bob-bob");
|
||||||
|
expect(b).toBeNull();
|
||||||
|
expect(users.countUsers()).toBe(1);
|
||||||
|
});
|
||||||
|
|
||||||
|
it("createFirstUser is race-safe: concurrent calls produce exactly one user", async () => {
|
||||||
|
const [a, b, c] = await Promise.all([
|
||||||
|
users.createFirstUser("alice", "pw-alice"),
|
||||||
|
users.createFirstUser("bob", "pw-bob-bob"),
|
||||||
|
users.createFirstUser("charlie", "pw-charlie-pw"),
|
||||||
|
]);
|
||||||
|
const created = [a, b, c].filter((u) => u !== null);
|
||||||
|
expect(created).toHaveLength(1);
|
||||||
|
expect(users.countUsers()).toBe(1);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
@@ -15,6 +15,7 @@ export interface UserRow {
|
|||||||
export interface UserStore {
|
export interface UserStore {
|
||||||
countUsers(): number;
|
countUsers(): number;
|
||||||
createUser(username: string, password: string): Promise<UserRow>;
|
createUser(username: string, password: string): Promise<UserRow>;
|
||||||
|
createFirstUser(username: string, password: string): Promise<UserRow | null>;
|
||||||
findByUsername(username: string): UserRow | null;
|
findByUsername(username: string): UserRow | null;
|
||||||
findById(id: string): UserRow | null;
|
findById(id: string): UserRow | null;
|
||||||
verifyPassword(plain: string, hash: string): Promise<boolean>;
|
verifyPassword(plain: string, hash: string): Promise<boolean>;
|
||||||
@@ -69,6 +70,26 @@ export function createUserStore(db: Database.Database): UserStore {
|
|||||||
return { id, username, passwordHash: hash, createdAt: now, updatedAt: now };
|
return { id, username, passwordHash: hash, createdAt: now, updatedAt: now };
|
||||||
},
|
},
|
||||||
|
|
||||||
|
async createFirstUser(username, password) {
|
||||||
|
const hash = await bcrypt.hash(password, BCRYPT_ROUNDS);
|
||||||
|
const id = randomUUID();
|
||||||
|
const now = Date.now();
|
||||||
|
const run = db.transaction(() => {
|
||||||
|
const count = (countStmt.get() as { n: number }).n;
|
||||||
|
if (count !== 0) return null;
|
||||||
|
try {
|
||||||
|
insertStmt.run(id, username, hash, now, now);
|
||||||
|
} catch (err) {
|
||||||
|
if (err && typeof err === "object" && (err as { code?: string }).code === "SQLITE_CONSTRAINT_UNIQUE") {
|
||||||
|
return null;
|
||||||
|
}
|
||||||
|
throw err;
|
||||||
|
}
|
||||||
|
return { id, username, passwordHash: hash, createdAt: now, updatedAt: now } as UserRow;
|
||||||
|
});
|
||||||
|
return run();
|
||||||
|
},
|
||||||
|
|
||||||
findByUsername(username) {
|
findByUsername(username) {
|
||||||
return (findByUsernameStmt.get(username) as UserRow | undefined) ?? null;
|
return (findByUsernameStmt.get(username) as UserRow | undefined) ?? null;
|
||||||
},
|
},
|
||||||
|
|||||||
@@ -2,10 +2,9 @@ import { Router } from "express";
|
|||||||
import type { Request, Response, NextFunction } from "express";
|
import type { Request, Response, NextFunction } from "express";
|
||||||
import type { Logger } from "../../logger.js";
|
import type { Logger } from "../../logger.js";
|
||||||
import type { UserStore } from "../../data/users.js";
|
import type { UserStore } from "../../data/users.js";
|
||||||
import { UsernameTakenError } from "../../data/users.js";
|
|
||||||
import type { SessionStore } from "../../data/sessions.js";
|
import type { SessionStore } from "../../data/sessions.js";
|
||||||
import { SESSION_TTL_MS } from "../../data/sessions.js";
|
import { SESSION_TTL_MS } from "../../data/sessions.js";
|
||||||
import { SESSION_COOKIE_NAME, validateSessionFromHeaders } from "../auth/validateSession.js";
|
import { SESSION_COOKIE_NAME, validateSessionFromHeaders, extractSessionToken } from "../auth/validateSession.js";
|
||||||
|
|
||||||
const FAILED_LOGIN_DELAY_MS = 250;
|
const FAILED_LOGIN_DELAY_MS = 250;
|
||||||
|
|
||||||
@@ -60,6 +59,8 @@ export function createSessionRouter(
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
req.user = { id: result.userId, username: result.username };
|
req.user = { id: result.userId, username: result.username };
|
||||||
|
const token = extractSessionToken(req.headers.cookie);
|
||||||
|
if (token) setSessionCookie(res, token);
|
||||||
next();
|
next();
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -78,16 +79,16 @@ export function createSessionRouter(
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
try {
|
try {
|
||||||
const user = await users.createUser(username, password);
|
const user = await users.createFirstUser(username, password);
|
||||||
|
if (!user) {
|
||||||
|
res.status(409).json({ error: "already initialized" });
|
||||||
|
return;
|
||||||
|
}
|
||||||
const { token } = sessions.createSession(user.id);
|
const { token } = sessions.createSession(user.id);
|
||||||
setSessionCookie(res, token);
|
setSessionCookie(res, token);
|
||||||
logger.info({ userId: user.id, username }, "First admin created");
|
logger.info({ userId: user.id, username }, "First admin created");
|
||||||
res.json({ id: user.id, username: user.username });
|
res.json({ id: user.id, username: user.username });
|
||||||
} catch (err) {
|
} catch (err) {
|
||||||
if (err instanceof UsernameTakenError) {
|
|
||||||
res.status(409).json({ error: "already initialized" });
|
|
||||||
return;
|
|
||||||
}
|
|
||||||
logger.error({ err }, "setup failed");
|
logger.error({ err }, "setup failed");
|
||||||
res.status(500).json({ error: "internal" });
|
res.status(500).json({ error: "internal" });
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -17,6 +17,11 @@ export function validateSessionFromHeaders(
|
|||||||
return sessions.validateAndTouch(token);
|
return sessions.validateAndTouch(token);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
export function extractSessionToken(rawCookieHeader: string | undefined): string | null {
|
||||||
|
if (!rawCookieHeader) return null;
|
||||||
|
return parseCookie(rawCookieHeader, SESSION_COOKIE_NAME);
|
||||||
|
}
|
||||||
|
|
||||||
function parseCookie(header: string, name: string): string | null {
|
function parseCookie(header: string, name: string): string | null {
|
||||||
for (const part of header.split(";")) {
|
for (const part of header.split(";")) {
|
||||||
const trimmed = part.trim();
|
const trimmed = part.trim();
|
||||||
|
|||||||
@@ -53,4 +53,16 @@ describe("requireAuth middleware", () => {
|
|||||||
expect(res.body.ok).toBe(true);
|
expect(res.body.ok).toBe(true);
|
||||||
expect(res.body.user.username).toBe("alice");
|
expect(res.body.user.username).toBe("alice");
|
||||||
});
|
});
|
||||||
|
|
||||||
|
it("rolls the cookie max-age forward on successful auth", async () => {
|
||||||
|
const res = await request(app)
|
||||||
|
.get("/protected")
|
||||||
|
.set("Cookie", `${SESSION_COOKIE_NAME}=${validToken}`);
|
||||||
|
expect(res.status).toBe(200);
|
||||||
|
const setCookieHeaders = res.headers["set-cookie"];
|
||||||
|
const arr = Array.isArray(setCookieHeaders) ? setCookieHeaders : setCookieHeaders ? [setCookieHeaders] : [];
|
||||||
|
const refreshed = arr.find((c) => c.startsWith(`${SESSION_COOKIE_NAME}=`));
|
||||||
|
expect(refreshed).toBeDefined();
|
||||||
|
expect(refreshed!).toMatch(/Max-Age=\d+/);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
@@ -1,6 +1,11 @@
|
|||||||
import type { Request, Response, NextFunction, RequestHandler } from "express";
|
import type { Request, Response, NextFunction, RequestHandler } from "express";
|
||||||
import type { SessionStore } from "../../data/sessions.js";
|
import type { SessionStore } from "../../data/sessions.js";
|
||||||
import { validateSessionFromHeaders, SESSION_COOKIE_NAME } from "../auth/validateSession.js";
|
import { SESSION_TTL_MS } from "../../data/sessions.js";
|
||||||
|
import {
|
||||||
|
validateSessionFromHeaders,
|
||||||
|
extractSessionToken,
|
||||||
|
SESSION_COOKIE_NAME,
|
||||||
|
} from "../auth/validateSession.js";
|
||||||
|
|
||||||
declare module "express-serve-static-core" {
|
declare module "express-serve-static-core" {
|
||||||
interface Request {
|
interface Request {
|
||||||
@@ -17,6 +22,16 @@ export function createRequireAuth(sessions: SessionStore): RequestHandler {
|
|||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
req.user = { id: result.userId, username: result.username };
|
req.user = { id: result.userId, username: result.username };
|
||||||
|
const token = extractSessionToken(req.headers.cookie);
|
||||||
|
if (token) {
|
||||||
|
res.cookie(SESSION_COOKIE_NAME, token, {
|
||||||
|
httpOnly: true,
|
||||||
|
sameSite: "lax",
|
||||||
|
secure: req.secure,
|
||||||
|
path: "/",
|
||||||
|
maxAge: SESSION_TTL_MS,
|
||||||
|
});
|
||||||
|
}
|
||||||
next();
|
next();
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
Reference in new issue
Block a user