Files
felhom.eu/documentation/audits/evidence-p1fixes-2026-09-15/B1-filebrowser-spike.txt
T
2026-09-15 10:06:43 +02:00

136 lines
7.9 KiB
Plaintext

# B.1 FileBrowser Quantum admin-password spike — 2026-09-15, scratch LXC 9202 on demo-hp
# Throwaway containers fbspike-fresh / fbspike-existing on 127.0.0.1:18089 inside the guest; config rendered like RenderFileBrowserConfig; same entrypoint wrapper as RenderFileBrowserCompose.
# Generated passwords redacted: only length printed. Login probe = POST /api/auth/login?username=admin, header X-Password.
# 'tr: write error: Broken pipe' lines are the password generator (harmless).
2026-09-15T07:36:38Z
image: gtstef/filebrowser:1.3.3-stable
sha256:095fd20d87be10c175a5fa614aa1d0a94aa07eafa80f251a3069640e0a7c51f7
== A1 FRESH db, config key auth.adminPassword
tr: write error: Broken pipe
pw len=16
admin/admin -> 401
admin/<P1> -> 200
admin/wrong -> 401
2026/09/15 07:36:39 [INFO ] Auth Methods : [password]
2026/09/15 07:36:39 [INFO ] Resetting admin user to default username and password.
2026/09/15 07:36:40 POST | 401 | 172.17.0.1 | N/A | 72ms | "/api/auth/login?username=admin"
2026/09/15 07:36:40 POST | 200 | 172.17.0.1 | N/A | 80ms | "/api/auth/login?username=admin"
2026/09/15 07:36:40 POST | 401 | 172.17.0.1 | N/A | 63ms | "/api/auth/login?username=admin"
== A2 FRESH db, env FILEBROWSER_ADMIN_PASSWORD (no config key)
tr: write error: Broken pipe
pw len=16
admin/admin -> 401
admin/<P2> -> 200
== A3 FRESH db, NO key, NO env (today's controller shape)
admin/admin -> 200
admin/wrong -> 401
== A4 short password via config key (length rule)
(not ready)
2026/09/15 07:36:45 [INFO ] cache directory setup successfully: tmp
2026/09/15 07:36:45 [FATAL] store.Users.Save: password must be at least 5 characters long
2026/09/15 07:36:45 [DEBUG] Default SQLite driver initialized
2026/09/15 07:36:45 [WARN ] database file could not be found. If this is unexpected, please set the FILEBROWSER_DATABASE environment variable to the correct path.
admin/abc -> 000
admin/admin -> 000
2026/09/15 07:36:45 [FATAL] store.Users.Save: password must be at least 5 characters long
== B0 EXISTING db: create with defaults
admin/admin -> 200 (baseline, expect 200)
== B1 EXISTING db + config key added, restart
tr: write error: Broken pipe
pw len=16
admin/admin -> 401
admin/<P3> -> 200
== B2 EXISTING db + env var, restart (config key removed)
tr: write error: Broken pipe
admin/admin -> 401
admin/<P3> -> 401
admin/<P3E env> -> 200
== B3 EXISTING db: CLI 'set -u admin,<pw>' with container stopped
tr: write error: Broken pipe
2026/09/15 07:37:51 [DEBUG] Default SQLite driver initialized
2026/09/15 07:37:51 [INFO ] cache directory setup successfully: tmp
successfully updated user: admin
rc=0
admin/admin -> 401
admin/<P3> -> 401
admin/<P3E> -> 401
admin/<P4> -> 200
== B4 EXISTING db: CLI 'set' via docker exec on RUNNING container
tr: write error: Broken pipe
2026/09/15 07:37:53 [DEBUG] Default SQLite driver initialized
2026/09/15 07:37:54 [INFO ] cache directory setup successfully: tmp
2026/09/15 07:37:54 the database is locked, please close all other instances of filebrowser before starting.
admin/<P4> -> 200
admin/<P5> -> 401
after restart: admin/<P4> -> 200
admin/<P5> -> 401
== C OVERWRITE: hand-set pw (current db state) + config key with a DIFFERENT value, restart
(db currently holds whichever of P4/P5 answered 200 above)
tr: write error: Broken pipe
admin/<P4> -> 401
admin/<P5> -> 401
admin/<P6 config> -> 200
admin/admin -> 401
== C2 same via env var with a DIFFERENT value
tr: write error: Broken pipe
admin/<P5> -> 401
admin/<P6> -> 401
admin/<P7 env> -> 200
== TEARDOWN
0
ls: cannot access '/tmp/fbspike': No such file or directory
filebrowser Up 35 hours (healthy)
2026-09-15T07:38:07Z
######## PART 2 — REST API change attempt WITHOUT X-Password (refused), restart survival
2026-09-15T07:38:40Z
== D0 existing db, defaults
admin/admin -> 200
token len=355
GET /api/users?id=self -> {"editorQuickSave":false,"hideSidebarFileActions":false,"disableQuickToggles":false,"disableSearchOptions":false,"deleteWithoutConfirming":false,"preview":{"disableHideSidebar":false,"image":true,"video":true,"audio":true,"motionVideoPreview":true,"office":true,"popup":true,"autoplayMedia":true,"defaultMediaPlayer":false,"folder":true,"models":true},"stickySidebar":true,"darkMode":true,"locale":"e
new pw len=13
PUT form1 /api/users?id=1 -> 401 {"status":401,"message":"X-Password header is required to confirm your password"}
admin/admin -> 200 admin/<new> -> 401
PUT form2 /api/users?id=1 -> 401 {"status":401,"message":"X-Password header is required to confirm your password"}
admin/admin -> 200 admin/<new> -> 401
PUT form3 /api/users?id=self -> 400 {"status":400,"message":"no user not found, please provide a valid id or username"}
admin/admin -> 200 admin/<new> -> 401
== D1 restart with NO key, NO env: does the API-set password survive?
admin/admin -> 200 admin/<new> -> 401
2026/09/15 07:38:40 [INFO ] Resetting admin user to default username and password.
== TEARDOWN
0
ls: cannot access '/tmp/fbspike2': No such file or directory
filebrowser Up 35 hours (healthy)
2026-09-15T07:38:44Z
######## PART 3 — REST API change WITH X-Password: <current>, restart with no key, then key with different value
# (the 'Resetting admin user' line under D1 is from the container's FIRST start — docker logs keeps history across restart; the measured logins show no reset)
2026-09-15T07:39:00Z
== D0 existing db, defaults
admin/admin -> 200
token len=355
GET /api/users?id=self -> {"editorQuickSave":false,"hideSidebarFileActions":false,"disableQuickToggles":false,"disableSearchOptions":false,"deleteWithoutConfirming":false,"preview":{"disableHideSidebar":false,"image":true,"video":true,"audio":true,"motionVideoPreview":true,"office":true,"popup":true,"autoplayMedia":true,"defaultMediaPlayer":false,"folder":true,"models":true},"stickySidebar":true,"darkMode":true,"locale":"e
new pw len=16
PUT form1 /api/users?id=1 -> 204
admin/admin -> 401 admin/<new> -> 200
== D1 restart with NO key, NO env (hand-set via API): does the API-set password survive?
admin/admin -> 401 admin/<new> -> 200
2026/09/15 07:39:01 [INFO ] Resetting admin user to default username and password.
== D2 same db, now add config key with DIFFERENT value, restart (operator hand-set vs key)
key pw len=16
admin/<hand-set> -> 401 admin/<key> -> 200 admin/admin -> 401
== TEARDOWN
0
ls: cannot access '/tmp/fbspike2': No such file or directory
filebrowser Up 35 hours (healthy)
2026-09-15T07:39:06Z
######## SUMMARY (measured, image gtstef/filebrowser:1.3.3-stable)
(a) FRESH db: config.yaml `auth: adminPassword: <pw>` (A1) OR env FILEBROWSER_ADMIN_PASSWORD (A2) sets it at first start: admin/admin 401, <pw> 200. No key/no env (today's shape, A3): admin/admin 200.
(b) EXISTING db (admin/admin 200 proven): the SAME config key (B1) or env var (B2) re-applies on restart: admin/admin 401, new 200. CLI `filebrowser set -u admin,<pw> -a` works only with the container STOPPED (B3: 200); on a running container it fails "database is locked" (B4, no change). REST: PUT /api/users?id=1 {"which":["password"],"data":{"id":1,"username":"admin","password":"<pw>"}} with Bearer token AND header X-Password: <current password> -> 204 (D0); without X-Password -> 401 "X-Password header is required".
OVERWRITE: with the key (C, D2) or env (C2) present, EVERY start resets the admin password to the configured value — a hand-set password (CLI or API) is overwritten (hand-set 401, key 200). With NO key/env, a hand-set password survives restart (B3->B4 restart, D1).
Length rule: min 5 chars; a shorter configured value is FATAL at start ("store.Users.Save: password must be at least 5 characters long", container never serves — A4). 16-char alphanumeric accepted.
TEARDOWN: fbspike-* containers removed, /tmp/fbspike* removed in 9202 (0 fbspike containers listed); 9202's own `filebrowser` untouched (Up 35 hours throughout).