The server had no authentication: every /api route was open, CORS allowed any origin, and the identity written to the audit log came from the request body — the UI sent a hardcoded pf_user: 'admin', which any client could have set to anything it liked. Accounts live in pf.app_user with scrypt hashes from node's own crypto, so there is no native build step and the parameters travel with each hash. Sessions are express-session over connect-pg-simple in pf.session: a restart no longer signs everyone out, and a session can be revoked by deleting its row, which is how disable-user cuts off access immediately rather than at cookie expiry. Everything under /api except login/logout/me now requires a session, and the React app is mounted only once there is one — its load effects call the API on mount, so a logged-out mount would just fire a burst of 401s. A session that expires while the app is open lands back on the login screen: auth.jsx wraps fetch once rather than teaching every call site to check. Identity is now read from the session for pf_user, created_by and closed_by, and the body values are ignored. Hardened for an internet-facing deployment: trust proxy so req.ip and secure-cookie detection are right behind TLS termination, httpOnly + SameSite=Lax + Secure cookies, ten login failures per IP per fifteen minutes, one error message for unknown, wrong and disabled alike, and a fresh session id on success. CORS is off entirely unless CORS_ORIGIN names an origin — a wildcard alongside a session cookie would be CSRF by construction. The server refuses to boot without SESSION_SECRET rather than falling back to a guessable default. pf.sh grows add-user, passwd, list-users, disable-user and enable-user; passwords are read on stdin and hashed before they reach psql, so no plaintext in argv or shell history. install.sh generates the secret, applies 02_auth.sql, and creates the first account. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
22 lines
679 B
Plaintext
22 lines
679 B
Plaintext
DB_HOST=localhost
|
|
DB_PORT=5432
|
|
DB_NAME=your_database
|
|
DB_USER=your_user
|
|
DB_PASSWORD=your_password
|
|
PORT=3010
|
|
|
|
# Signs the session cookie. Generate with:
|
|
# node -e 'console.log(require("crypto").randomBytes(32).toString("hex"))'
|
|
# or let ./pf.sh config do it. Changing it signs everyone out.
|
|
SESSION_SECRET=
|
|
|
|
# Send the session cookie over HTTPS only. Keep true behind a TLS proxy;
|
|
# set false only to reach the app over plain HTTP on a trusted network.
|
|
COOKIE_SECURE=true
|
|
|
|
# Reverse proxy hops express should trust for req.ip / protocol. Default 1.
|
|
#TRUST_PROXY=1
|
|
|
|
# Only needed if the UI is served from a different origin than the API.
|
|
#CORS_ORIGIN=https://forecast.example.com
|