-
-
Notifications
You must be signed in to change notification settings - Fork 33
security: secure session cookie flags + expiring password-reset tokens #225
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Changes from all commits
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -27,6 +27,8 @@ | |
| use App\Config\ConfigInterface; | ||
| use App\Helpers\UserDeviceTracker; | ||
| use App\CloudFlare\CloudFlareRealIP; | ||
| use App\Helpers\AccountLockoutHelper; | ||
| use App\Helpers\SessionCookieHelper; | ||
| use App\Plugins\Events\Events\AuthEvent; | ||
| use Symfony\Component\HttpFoundation\Request; | ||
| use Symfony\Component\HttpFoundation\Response; | ||
|
|
@@ -203,7 +205,13 @@ public function put(Request $request): Response | |
| ); | ||
| } | ||
|
|
||
| return ApiResponse::error('Invalid username or email address', 'INVALID_USERNAME_OR_EMAIL'); | ||
| // Run a dummy password_verify against a fixed bcrypt hash so that the | ||
| // response timing for "unknown user" is close to the "wrong password" | ||
| // path below, and return the same generic error/code in both cases | ||
| // to avoid leaking whether an account exists (account enumeration). | ||
| password_verify($data['password'], '$2y$12$hKs6swAiRf/kPjRDC6xEWun.GMew67fz3jytWTurlD/p4Ag7xyCf6'); | ||
|
|
||
| return ApiResponse::error('Invalid username, email address, or password', 'INVALID_CREDENTIALS'); | ||
| } | ||
| if ($userInfo['banned'] == 'true') { | ||
| // Emit login failed event | ||
|
|
@@ -226,6 +234,20 @@ public function put(Request $request): Response | |
| return ApiResponse::error('Account is deleted', 'ACCOUNT_DELETED', 403); | ||
| } | ||
|
|
||
| // Per-account lockout: independent of IP-based rate limiting so that | ||
| // rotating IPs (proxy/botnet) cannot be used to brute-force a single | ||
| // known account's password. | ||
| $lockoutId = 'login:' . $userInfo['uuid']; | ||
| $lockoutRemaining = AccountLockoutHelper::getLockoutRemaining($lockoutId); | ||
| if ($lockoutRemaining > 0) { | ||
| return ApiResponse::error( | ||
| 'Too many failed login attempts. Try again in ' . ceil($lockoutRemaining / 60) . ' minute(s).', | ||
| 'ACCOUNT_LOCKED', | ||
| 429, | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🗄️ Data Integrity & Integration | 🟡 Minor | ⚡ Quick win Document the new lockout response. Line 246 adds a 🤖 Prompt for AI Agents |
||
| ['retry_after' => $lockoutRemaining] | ||
| ); | ||
|
Comment on lines
+243
to
+248
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | ⚡ Quick win 🧩 Analysis chain🏁 Script executed: sed -n '200,270p' backend/app/Controllers/User/Auth/LoginController.phpRepository: MythicalLTD/FeatherPanel Length of output: 3429 🏁 Script executed: sed -n '1,130p' backend/app/Helpers/AccountLockoutHelper.phpRepository: MythicalLTD/FeatherPanel Length of output: 3702 Information Disclosure (CWE-203) Reachability: External · Exploitability: Moderate Keep lockout state indistinguishable before authentication. A known account returns Return the same generic credential response during lockout. Do not expose lockout metadata before authentication. 🤖 Prompt for AI Agents |
||
| } | ||
|
|
||
| // When OIDC has disabled local login, only allow local login for admins (before password check to avoid leaking valid-credential signal) | ||
| if ($config->getSetting(ConfigInterface::OIDC_DISABLE_LOCAL_LOGIN, 'false') === 'true') { | ||
| if (!\App\Helpers\PermissionHelper::hasPermission($userInfo['uuid'], \App\Permissions::ADMIN_ROOT)) { | ||
|
|
@@ -247,9 +269,15 @@ public function put(Request $request): Response | |
| ); | ||
| } | ||
|
|
||
| return ApiResponse::error('Invalid password', 'INVALID_PASSWORD'); | ||
| AccountLockoutHelper::recordFailure($lockoutId); | ||
|
Contributor
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. 🔒 Security & Privacy | 🟠 Major | 🏗️ Heavy lift 🧩 Analysis chain🏁 Script executed: #!/bin/bash
sed -n '235,285p' backend/app/Controllers/User/Auth/LoginController.php
printf '\n--- helper ---\n'
sed -n '35,105p' backend/app/Helpers/AccountLockoutHelper.phpRepository: MythicalLTD/FeatherPanel Length of output: 4858 Denial of Service (CWE-799) Reachability: External · Exploitability: Moderate Do not make a known account identifier an availability kill switch. For a known account, ten failed passwords within 15 minutes create a 15-minute account lock before password verification. An attacker can repeat this cycle and block the account owner from logging in. Replace the hard lock with an escalating challenge or delay that does not deny authentication to every client. IP-only controls do not stop distributed requests. 🤖 Prompt for AI Agents |
||
|
|
||
| return ApiResponse::error('Invalid username, email address, or password', 'INVALID_CREDENTIALS'); | ||
| } | ||
|
|
||
| // Successful password check: clear any prior failure count for this account. | ||
| AccountLockoutHelper::clear($lockoutId); | ||
|
|
||
|
|
||
| $requiresEmailVerification = $config->getSetting(ConfigInterface::REGISTRATION_REQUIRE_EMAIL_VERIFICATION, 'false') === 'true'; | ||
| $isEmailVerified = !isset($userInfo['mail_verify']) || $userInfo['mail_verify'] === null || trim((string) $userInfo['mail_verify']) === ''; | ||
| if ($requiresEmailVerification && !$isEmailVerified) { | ||
|
|
@@ -292,7 +320,7 @@ public function completeLogin(array $userInfo, ?string $redirectTo = null): Resp | |
| return ApiResponse::error('Remember token not set', 'REMEMBER_TOKEN_NOT_SET'); | ||
| } | ||
| $userInfo['remember_token'] = $token; | ||
| setcookie('remember_token', $token, time() + 60 * 60 * 24 * 30, '/'); | ||
| SessionCookieHelper::set($token, time() + 60 * 60 * 24 * 30); | ||
| User::updateUser($userInfo['uuid'], ['last_ip' => CloudFlareRealIP::getRealIP()]); | ||
| UserDeviceTracker::trackFromGlobals($userInfo); | ||
|
|
||
|
|
||
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
🎯 Functional Correctness | 🟡 Minor | ⚡ Quick win
Clear the cookie on the invalid-token path.
User::getUserByRememberToken()can returnnull, and that branch returns before thisSessionCookieHelper::clear()call. Logout then leaves a staleremember_tokenin the browser. Move the clear before that return so valid and invalid tokens are both removed.🤖 Prompt for AI Agents