controller: customer-claim password gate v0.122.0 (closes DRILL-day0-vm F-4/F-5)
The customer sets + owns the dashboard password via a hub-emailed one-time claim code. An unclaimed box (code hash present, no password) serves ONLY the claim page — every other route → claim page (302) or 401, so a Day-0 box is never open on the internet. A set password disables the gate (auth wins). Reset rides the same code engine (login "Elfelejtett jelszó"). Legacy-open (no password, no hash) shows a red transition banner until the hub delivers a hash. Report ACK caches the code state idempotently by generation; report carries claimed (set-only). --print-reset-code root escape hatch. Requires hub v0.50.0. Gate-coverage signature test + 4 red-proofs proven.
This commit is contained in:
@@ -32,6 +32,13 @@ func (s *Server) CsrfProtect(next http.Handler) http.Handler {
|
||||
return
|
||||
}
|
||||
|
||||
// Claim/reset POSTs carry their OWN pre-auth HMAC CSRF (validated in the handler) — the
|
||||
// customer resetting a claimed box has no session yet, so the session-CSRF path can't apply.
|
||||
if r.URL.Path == "/claim" || r.URL.Path == "/claim/request-new-code" {
|
||||
next.ServeHTTP(w, r)
|
||||
return
|
||||
}
|
||||
|
||||
// Skip CSRF for Bearer-token authenticated requests.
|
||||
// Validate the token against the configured API key before skipping.
|
||||
if auth := r.Header.Get("Authorization"); strings.HasPrefix(auth, "Bearer ") {
|
||||
|
||||
Reference in New Issue
Block a user