From ed6df4b46b93eea238d957df646ece517c863884 Mon Sep 17 00:00:00 2001 From: kisfenyo Date: Thu, 1 Oct 2026 12:49:39 +0200 Subject: [PATCH] CHANGELOG + REPORT: wger lockout fix, three apps measured (R-752) Co-Authored-By: Claude Opus 5.5 (1M context) Claude-Session: https://claude.ai/code/session_0159rPz1ZhFKsS53msqPYxtS --- CHANGELOG.md | 12 ++++++++++++ REPORT.md | 22 ++++++++++------------ 2 files changed, 22 insertions(+), 12 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 81674ba..d9a74e6 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,3 +1,15 @@ +## Strangers cannot lock a whole household out of wger; three other apps measured (2026-10-01, afternoon) + +- **wger** `82fff32` (R-752; `09` §3 decision 58, decided by CC unattended — operator may reverse): + `AXES_LOCKOUT_PARAMETERS=username`, `AXES_COOLOFF_TIME=5`, `AXES_HANDLER=axes.handlers.database.AxesDatabaseHandler`. + Behind the tunnel every visitor has one address (R-753), so axes' default (by address) let a stranger's 10 wrong tries + lock out EVERY member for 30 min — measured on 9202. Now only the targeted name, 5 min (wger 2.7 restarts the lock on + every try during it — measured at 15 min: retries kept it closed 40+ min). Settings only — no ladder entry (gates OK). + An installed wger takes it at its next Restart/Start, Update or backup restart (measured: the env changed at Restart). +- **BookStack** (1.0 min) and **Grafana** (5.0 min): measured, unchanged (decisions 59, 60). **calibre-web**: its 40-a-day + lock per name measured (only a restart clears it); waits for the operator. Evidence + `felhom.eu/documentation/audits/lockouts-2026-10-01/`. + ## The first full monthly re-test (decision 55); the digest resolver, the outline fixture, the re-test's start (2026-10-01) - **The monthly re-test now covers every app with a proven ladder** (`09` §3 decisions 54, 55; R-743). First full run: diff --git a/REPORT.md b/REPORT.md index 418a0f9..ffe7794 100644 --- a/REPORT.md +++ b/REPORT.md @@ -1,14 +1,12 @@ -# REPORT — the first full monthly re-test (decision 55); mealie's lockout; two harness fixes (2026-10-01) +# REPORT — strangers and lockouts: wger fixed, three apps measured (2026-10-01, afternoon) -Full session report: `felhom.eu/REPORT-rulings-2026-10-01.md`. +Full session report: `felhom.eu/REPORT-lockouts-2026-10-01.md`. -- **Re-test run** (`09` §3 decisions 54, 55): `retest-floating.py --push` over every app with a proven ladder. nextcloud - `34.0.4-apache` `3b59dfb` and linuxserver sonarr `4.0.20` `1a37032` — both DONE on both venues (bench 9401 swap 0 with the - 10-minute watch; 9202 through the guarded Update). ~17 min per app. Evidence `felhom.eu/documentation/audits/retest-2026-10/`. -- **R-749** `9e53205`: the re-test refused a fresh bench (checked `/opt/upg` before copying it). Fixed; the re-run started. -- **R-746** `804884a`: `image_digest.resolve` asks for a `@digest` by digest; `scripts/test_image_digest.py`; red: the old - resolver fails 3 of 4; live: an invented digest → HTTP 404 (was the tag's digest). -- **R-744** `9fc7052`: outline's fixture reads `__Host-csrfToken` (Outline 1.10 on HTTPS); proven on 9202 at 1.10.1. -- **R-747** `a4597cd` (decision 57, decided by CC unattended — operator may reverse): mealie `SECURITY_USER_LOCKOUT_TIME=1`; - 9202: locked 120 min after 5 wrong logins, then the right password works. -- Gates: `catalog_gates.py --fast` OK before each push; every push through the pre-push gates (no `--no-verify`). +- **wger** `82fff32` (decision 58, decided by CC unattended — operator may reverse): axes by username, 5 min, database + handler. 9202: control — the second member locked by a stranger's 10 tries on `admin`; fixed — the second member fine, + admin in again at 7.5 min after one retry; a wrong password still refused. +- **BookStack, Grafana**: measured 1.0 and 5.0 min — unchanged (decisions 59, 60). +- **calibre-web-automated**: 40 wrong tries a day per name lock the form for the day (measured; a restart clears it) — + operator decision (a generated login name, or the limiter off). +- Found, not changed: wger runs `manage.py runserver` (no `WGER_USE_GUNICORN`) — R-755. +- Gates: `catalog_gates.py --fast wger` OK; pushed through the pre-push gates (no `--no-verify`).