1d154bd627
ci-pangolin / Redline Scan — 脱敏 (UI 文案) (push) Successful in 25s
ci-pangolin / Cleartext Scan — Android 禁明文 (push) Successful in 20s
ci-pangolin / Lint — shellcheck (push) Successful in 51s
ci-pangolin / Portable SQL — 可移植性 (mysql/sqlite) (push) Successful in 23s
ci-pangolin / OpenAPI Sync Check (push) Successful in 1m10s
ci-pangolin / Flutter — analyze + test (push) Successful in 3m44s
ci-pangolin / Codegen Drift — token 生成物未漂移 (push) Successful in 1m7s
ci-pangolin / DS-flow — 原型/跨端同源/代码色单源闸 (push) Successful in 24s
ci-pangolin / Go — build + test (push) Failing after 1m0s
ci-pangolin / E2E Smoke — L4 进程级端到端 (push) Failing after 40s
ci-pangolin / Go — integration (mysql/redis testcontainers) (push) Failing after 6m9s
ci-pangolin / Golden — 视觉回归 (全量:components/auth/desktop/tablet) (push) Successful in 42s
常用设备(已在 mTLS 白名单内)每次都要输 TOTP + 30 分钟就掉线,体验差。 新增登录页「记住此设备」勾选: - 勾选并成功登录(需完整 密码+TOTP)后,签发 30 天设备信任令牌(HttpOnly/ Secure/SameSite=Strict cookie,Redis 存储绑定 admin ID),并把会话延到 30 天 (持久 cookie + 服务端 TTL,滑动续期按会话自身 TTL)。 - 之后该设备重登只需 用户名+密码,**跳过 TOTP**;会话在有效期内保持登录。 安全不变量(均有测试覆盖): - 密码永远必验——即便持有效信任令牌,密码错一律拒(只跳过第二因子,不跳过密码); - 信任令牌绑定 admin,alice 的令牌不能给 bob 免 TOTP; - 无令牌 + 空 TOTP 一律拒(未记住设备仍强制二次验证); - 令牌过期/Redis 清空/未知令牌全部 fail-closed 回退到「要 TOTP」; - TrustedDeviceTTL=0 关闭整功能(勾选无效)。 实现:新增 TrustedStore(Redis, trusted.go);Authenticator.LoginDevice (旧 Login 保持签名,委托新方法,零行为变化);SessionStore.CreateWithTTL + Session.TTLSeconds 支持持久会话按自身 TTL 滑动;handler 读 cookie/勾选、 按 Persistent 设长短会话 cookie、下发信任 cookie;登录页加勾选、TOTP 去 required。配置项 ADMIN_TRUSTED_DEVICE_TTL(默认 720h)。 测试:trusted_test(签发/校验/绑定/吊销/过期/禁用)、login_device_test (跳过TOTP/仍需密码/绑定admin/无令牌需TOTP)、login_device_handler_test (端到端 勾选→双cookie→凭信任cookie免TOTP、无信任空TOTP 401); go test ./internal/admin 全绿,go vet 净。 Co-Authored-By: Claude Fable 5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01P9G7E3wmAYL9KeYCVZVsqu
109 lines
2.6 KiB
Go
109 lines
2.6 KiB
Go
package admin
|
|
|
|
import (
|
|
"context"
|
|
"testing"
|
|
"time"
|
|
|
|
"github.com/alicebob/miniredis/v2"
|
|
"github.com/redis/go-redis/v9"
|
|
)
|
|
|
|
func newTestTrustedStore(t *testing.T) (*TrustedStore, *miniredis.Miniredis) {
|
|
t.Helper()
|
|
mr, err := miniredis.Run()
|
|
if err != nil {
|
|
t.Fatalf("miniredis: %v", err)
|
|
}
|
|
t.Cleanup(mr.Close)
|
|
rdb := redis.NewClient(&redis.Options{Addr: mr.Addr()})
|
|
return NewTrustedStore(rdb, 30*24*time.Hour), mr
|
|
}
|
|
|
|
func TestTrustedStore_IssueThenCheck(t *testing.T) {
|
|
ts, _ := newTestTrustedStore(t)
|
|
ctx := context.Background()
|
|
|
|
tok, err := ts.Issue(ctx, 7)
|
|
if err != nil {
|
|
t.Fatalf("Issue: %v", err)
|
|
}
|
|
if tok == "" {
|
|
t.Fatal("Issue returned empty token")
|
|
}
|
|
// 正确 admin 命中
|
|
if !ts.Check(ctx, tok, 7) {
|
|
t.Error("Check should accept the token for the issuing admin")
|
|
}
|
|
// 令牌绑定 admin:换个 admin id 不认
|
|
if ts.Check(ctx, tok, 8) {
|
|
t.Error("Check must reject a token bound to a different admin")
|
|
}
|
|
// 未知令牌不认
|
|
if ts.Check(ctx, "bogus-token", 7) {
|
|
t.Error("Check must reject an unknown token")
|
|
}
|
|
// 空令牌不认
|
|
if ts.Check(ctx, "", 7) {
|
|
t.Error("Check must reject an empty token")
|
|
}
|
|
}
|
|
|
|
func TestTrustedStore_Revoke(t *testing.T) {
|
|
ts, _ := newTestTrustedStore(t)
|
|
ctx := context.Background()
|
|
tok, _ := ts.Issue(ctx, 7)
|
|
if !ts.Check(ctx, tok, 7) {
|
|
t.Fatal("precondition: token should be valid")
|
|
}
|
|
if err := ts.Revoke(ctx, tok); err != nil {
|
|
t.Fatalf("Revoke: %v", err)
|
|
}
|
|
if ts.Check(ctx, tok, 7) {
|
|
t.Error("Check must reject a revoked token")
|
|
}
|
|
}
|
|
|
|
func TestTrustedStore_Expires(t *testing.T) {
|
|
mr, err := miniredis.Run()
|
|
if err != nil {
|
|
t.Fatalf("miniredis: %v", err)
|
|
}
|
|
defer mr.Close()
|
|
rdb := redis.NewClient(&redis.Options{Addr: mr.Addr()})
|
|
ts := NewTrustedStore(rdb, time.Hour)
|
|
ctx := context.Background()
|
|
|
|
tok, _ := ts.Issue(ctx, 7)
|
|
if !ts.Check(ctx, tok, 7) {
|
|
t.Fatal("precondition: token valid before expiry")
|
|
}
|
|
mr.FastForward(2 * time.Hour) // 超过 TTL
|
|
if ts.Check(ctx, tok, 7) {
|
|
t.Error("Check must reject an expired token (fail-closed)")
|
|
}
|
|
}
|
|
|
|
// TTL<=0 视为功能关闭:Issue 返回空、Check 恒 false。
|
|
func TestTrustedStore_Disabled(t *testing.T) {
|
|
mr, err := miniredis.Run()
|
|
if err != nil {
|
|
t.Fatalf("miniredis: %v", err)
|
|
}
|
|
defer mr.Close()
|
|
rdb := redis.NewClient(&redis.Options{Addr: mr.Addr()})
|
|
ts := NewTrustedStore(rdb, 0)
|
|
ctx := context.Background()
|
|
|
|
tok, err := ts.Issue(ctx, 7)
|
|
if err != nil {
|
|
t.Fatalf("Issue: %v", err)
|
|
}
|
|
if tok != "" {
|
|
t.Error("disabled store should issue empty token")
|
|
}
|
|
if ts.Check(ctx, "anything", 7) {
|
|
t.Error("disabled store should never trust")
|
|
}
|
|
}
|