Files
felhom.eu/documentation/audits/pg-calcom-claper-2026-09-28/tools/claperrestore.py
T
2026-09-28 19:02:06 +02:00

23 lines
1.5 KiB
Python

"""After a RESTORE of claper from its own unit: the default must still fail, the first password (read from
the page BEFORE the restore) must still work, and the page must not show a value that does not work."""
import re, html as H, os
import walk as w
w.login()
def pw_on_page():
m = re.search(r'name="ADMIN_PASSWORD"[^>]*value="([^"]*)"', w.page("/stacks/claper/deploy"))
return H.unescape(m.group(1)) if m else ""
before = pw_on_page()
print("before the restore: the page shows a first password:", bool(before))
res = w.restore("claper")
print("restore:", {k: res.get(k) for k in ("ok", "http", "seconds", "state_after")})
after = pw_on_page()
print("after the restore: the page shows a password value:", bool(after), "| same as before:", after == before and bool(after))
d = w.page("/stacks/claper/deploy")
print("after the restore: the page says the backup's login is the one that works:", "restored" in d.lower() or "mentésből" in d)
auth = 'IO.puts("ANS=#{Claper.Accounts.get_user_by_email_and_password("admin@claper.co", "PW") != nil}")'
script = "set -u\n" + "\n".join(
f"echo \"{l}: $(docker exec -e ELIXIR_ERL_OPTIONS=+fnu claper /app/bin/claper rpc '{auth.replace('PW', p)}' 2>&1 | grep -o 'ANS=[a-z]*')\""
for l, p in (("NEGATIVE the known default", "claper"), ("the first password from BEFORE the restore", before), ("CONTROL wrong", "wrongxyz123")))
print(w.guest(script))
print(w.guest("grep -E -A2 '^(after_install|restored_logins):' /opt/docker/stacks/claper/app.yaml"))