Files
edgeguard-native/internal/handlers/auth.go
Debian 8d83de6b0f feat(cluster): Fix "joining" status + cross-node auth federation
1. preRegisterJoiner now runs SYNCHRONOUSLY before IssueCert responds,
   so nftables @peer_ipv4 is updated before the joiner calls autoRegister.
   Previously it was a goroutine → race → autoRegister failed → "joining"
   forever.

2. Stable node ID for pre-registered placeholder (prenode-{fqdn}) instead
   of time-based ID — re-joins are now idempotent.

3. AgentRegisterPeer sets status="online" immediately (peer proved it is
   online by connecting via mTLS) and deletes the prenode-{fqdn} placeholder.

4. autoRegister retries 3× with 2s delay in case of transient nftables lag.

5. Auth federation: cluster nodes forward failed logins to the primary via
   mTLS /agent/auth/check so users can log in on any node with primary
   credentials (no PG replication needed).
   - SystemHandler.AgentAuthCheck: new endpoint on :8443
   - AuthHandler.checkWithPrimary: mTLS call to primary when local auth fails
   - AuthHandler.WithClusterTLS: inject cluster TLS store
   - startAgentListener now uses the wired systemHdl with Users repo

Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
2026-05-29 18:04:34 +02:00

364 lines
11 KiB
Go

package handlers
import (
"bytes"
"context"
"encoding/json"
"errors"
"io"
"log/slog"
"net/http"
"strings"
"time"
"github.com/gin-gonic/gin"
"git.netcell-it.de/projekte/edgeguard-native/internal/cluster/clustertls"
"git.netcell-it.de/projekte/edgeguard-native/internal/handlers/response"
"git.netcell-it.de/projekte/edgeguard-native/internal/services/audit"
"git.netcell-it.de/projekte/edgeguard-native/internal/services/session"
"git.netcell-it.de/projekte/edgeguard-native/internal/services/setup"
usersvc "git.netcell-it.de/projekte/edgeguard-native/internal/services/users"
)
// AuthHandler exposes login / me / logout.
// Login checks the DB users table first; falls back to the setup-store
// admin for backwards compatibility. On a successful setup-store login
// the account is auto-migrated into the DB (Upsert) so it shows up in
// user management from that point on.
type AuthHandler struct {
Setup *setup.Store
Signer *session.Signer
Audit *audit.Repo
NodeID string
Users *usersvc.Repo // optional — nil on first boot before DB is ready
ClusterTLS *clustertls.Store // optional — enables auth federation on cluster nodes
}
func NewAuthHandler(s *setup.Store, sig *session.Signer) *AuthHandler {
return &AuthHandler{Setup: s, Signer: sig}
}
// WithAudit: Audit-Repo + NodeID damit Password-Operationen (change,
// reset, login-success/fail) ins audit_log fließen.
func (h *AuthHandler) WithAudit(a *audit.Repo, nodeID string) *AuthHandler {
h.Audit = a
h.NodeID = nodeID
return h
}
// WithUsers injects the users repo so Login can verify against the DB.
func (h *AuthHandler) WithUsers(u *usersvc.Repo) *AuthHandler {
h.Users = u
return h
}
// WithClusterTLS enables auth federation: when local auth fails on a
// cluster node, Login tries the primary via mTLS /agent/auth/check.
func (h *AuthHandler) WithClusterTLS(store *clustertls.Store) *AuthHandler {
h.ClusterTLS = store
return h
}
// Register mounts /auth/login + /logout (public) and /auth/me
// (gated by requireAuth, passed in as a per-route middleware).
func (h *AuthHandler) Register(rg *gin.RouterGroup, requireAuth gin.HandlerFunc) {
g := rg.Group("/auth")
g.POST("/login", h.Login)
g.POST("/logout", h.Logout)
g.GET("/me", requireAuth, h.Me)
g.POST("/reset-password", h.ResetPassword)
g.POST("/change-password", requireAuth, h.ChangePassword)
}
type loginRequest struct {
Email string `json:"email" binding:"required,email"`
Password string `json:"password" binding:"required"`
}
type loginResponse struct {
Actor string `json:"actor"`
Role string `json:"role"`
ExpiresAt time.Time `json:"expires_at"`
}
func (h *AuthHandler) Login(c *gin.Context) {
var req loginRequest
if err := c.ShouldBindJSON(&req); err != nil {
response.BadRequest(c, err)
return
}
st, err := h.Setup.Load()
if err != nil {
response.Internal(c, err)
return
}
if !st.Completed {
response.Err(c, http.StatusServiceUnavailable, errors.New("setup_required"))
return
}
email := strings.TrimSpace(req.Email)
actor, role := "", "admin"
remote := c.ClientIP()
// 1. Try DB users table first.
if h.Users != nil {
u, hash, dbErr := h.Users.FindByEmail(c.Request.Context(), email)
if dbErr == nil {
if !u.Active {
if h.Audit != nil {
_ = h.Audit.Log(c.Request.Context(), email, "auth.login.failed",
email, gin.H{"reason": "account_disabled", "remote": remote}, h.NodeID)
}
response.Unauthorized(c, errors.New("account_disabled"))
return
}
if !usersvc.VerifyPassword(hash, req.Password) {
if h.Audit != nil {
_ = h.Audit.Log(c.Request.Context(), email, "auth.login.failed",
email, gin.H{"reason": "invalid_credentials", "remote": remote}, h.NodeID)
}
response.Unauthorized(c, errors.New("invalid_credentials"))
return
}
actor = u.Email
role = u.Role
h.Users.RecordLogin(c.Request.Context(), u.ID)
}
}
// 2. Fallback: setup-store admin (backwards compat for pre-DB installs).
if actor == "" && st.AdminEmail != "" {
if strings.EqualFold(st.AdminEmail, email) && st.VerifyAdminPassword(req.Password) {
actor = st.AdminEmail
role = "admin"
// Auto-migrate: insert the setup-store admin into the DB so it
// shows up in user management from this point on.
if h.Users != nil {
_, _ = h.Users.Upsert(c.Request.Context(), st.AdminEmail, req.Password, "admin", true)
}
}
}
// 3. Auth federation: cluster nodes forward failed auth to the primary
// via mTLS so users can log in with their primary credentials on any node.
if actor == "" && st.IsClusterNode && st.PrimaryFQDN != "" && h.ClusterTLS != nil {
if a, r, err := h.checkWithPrimary(c.Request.Context(), st.PrimaryFQDN, email, req.Password); err == nil {
actor = a
role = r
} else {
slog.Debug("auth: primary auth check failed", "primary", st.PrimaryFQDN, "error", err)
}
}
if actor == "" {
if h.Audit != nil {
_ = h.Audit.Log(c.Request.Context(), email, "auth.login.failed",
email, gin.H{"reason": "invalid_credentials", "remote": remote}, h.NodeID)
}
response.Unauthorized(c, errors.New("invalid_credentials"))
return
}
raw, tok, err := h.Signer.IssueWithRole(actor, role)
if err != nil {
response.Internal(c, err)
return
}
setSessionCookie(c, raw, tok.Exp)
if h.Audit != nil {
_ = h.Audit.Log(c.Request.Context(), actor, "auth.login.success",
actor, gin.H{"role": role, "remote": remote}, h.NodeID)
}
response.OK(c, loginResponse{
Actor: tok.Actor,
Role: tok.Role,
ExpiresAt: time.Unix(tok.Exp, 0).UTC(),
})
}
func (h *AuthHandler) Logout(c *gin.Context) {
clearSessionCookie(c)
response.OK(c, gin.H{"logged_out": true})
}
// Me returns the current actor + role (or 401 if no/invalid token).
func (h *AuthHandler) Me(c *gin.Context) {
tok := CurrentToken(c)
if tok == nil {
response.Unauthorized(c, nil)
return
}
response.OK(c, gin.H{
"actor": tok.Actor,
"role": tok.Role,
"expires_at": time.Unix(tok.Exp, 0).UTC(),
})
}
type resetPasswordRequest struct {
Token string `json:"token" binding:"required"`
NewPassword string `json:"new_password" binding:"required,min=12"`
}
// ResetPassword verifies the operator-generated token from
// /var/lib/edgeguard/.reset-token and sets a new admin password. The
// token is single-use — ConsumeResetToken löscht das File bei Erfolg.
func (h *AuthHandler) ResetPassword(c *gin.Context) {
var req resetPasswordRequest
if err := c.ShouldBindJSON(&req); err != nil {
response.BadRequest(c, err)
return
}
if err := h.Setup.ConsumeResetToken(req.Token); err != nil {
response.Err(c, http.StatusUnauthorized, err)
return
}
if err := h.Setup.SetAdminPassword(req.NewPassword); err != nil {
response.BadRequest(c, err)
return
}
if h.Audit != nil {
// ResetPassword: keine Session, deshalb "self-reset" als Actor
// damit der Audit-Trail zeigt dass es kein admin-mediated Reset war.
_ = h.Audit.Log(c.Request.Context(), "self-reset", "auth.password.reset",
"", gin.H{"remote": c.ClientIP()}, h.NodeID)
}
response.OK(c, gin.H{"ok": true})
}
type changePasswordRequest struct {
CurrentPassword string `json:"current_password" binding:"required"`
NewPassword string `json:"new_password" binding:"required,min=12"`
}
// ChangePassword: authenticated User wechselt sein eigenes Passwort.
// Anders als ResetPassword (CLI-Token-Flow für vergessenes Passwort)
// braucht das hier das current_password als Confirmation — verhindert
// dass eine kompromittierte Session den Account übernimmt ohne dass
// das alte Passwort bekannt ist.
//
// Lookup-Reihenfolge: 1) DB users-Tabelle (alle multi-user-Accounts),
// 2) setup-store Admin-Fallback (Legacy / pre-DB). Beim Setup-Admin
// werden beide Stores synchron gehalten.
func (h *AuthHandler) ChangePassword(c *gin.Context) {
var req changePasswordRequest
if err := c.ShouldBindJSON(&req); err != nil {
response.BadRequest(c, err)
return
}
tok := CurrentToken(c)
if tok == nil {
response.Unauthorized(c, nil)
return
}
// 1. DB-backed user (alle via User-Management erstellten Accounts).
if h.Users != nil {
u, hash, dbErr := h.Users.FindByEmail(c.Request.Context(), tok.Actor)
if dbErr == nil {
if !usersvc.VerifyPassword(hash, req.CurrentPassword) {
response.Unauthorized(c, errors.New("invalid_current_password"))
return
}
if err := h.Users.SetPassword(c.Request.Context(), u.ID, req.NewPassword); err != nil {
response.Internal(c, err)
return
}
// Setup-Store-Admin synchron halten, falls gleiche E-Mail.
if st, _ := h.Setup.Load(); st != nil && strings.EqualFold(st.AdminEmail, tok.Actor) {
_ = h.Setup.SetAdminPassword(req.NewPassword)
}
if h.Audit != nil {
_ = h.Audit.Log(c.Request.Context(), actorOf(c), "auth.password.change",
tok.Actor, gin.H{"actor": actorOf(c)}, h.NodeID)
}
response.OK(c, gin.H{"ok": true})
return
}
}
// 2. Fallback: setup-store Admin (vor DB-Migration oder nicht migriert).
st, err := h.Setup.Load()
if err != nil {
response.Internal(c, err)
return
}
if st == nil || !st.Completed {
response.Err(c, http.StatusServiceUnavailable, errors.New("setup_required"))
return
}
if !st.VerifyAdminPassword(req.CurrentPassword) {
response.Unauthorized(c, errors.New("invalid_current_password"))
return
}
if err := h.Setup.SetAdminPassword(req.NewPassword); err != nil {
response.BadRequest(c, err)
return
}
if h.Audit != nil {
_ = h.Audit.Log(c.Request.Context(), actorOf(c), "auth.password.change",
st.AdminEmail, gin.H{"actor": actorOf(c)}, h.NodeID)
}
response.OK(c, gin.H{"ok": true})
}
// checkWithPrimary verifies credentials against the primary node via mTLS.
// Returns actor+role on success, error on failure.
func (h *AuthHandler) checkWithPrimary(ctx context.Context, primaryFQDN, email, password string) (string, string, error) {
clientTLS, err := h.ClusterTLS.ClientTLSConfig()
if err != nil {
return "", "", err
}
tr := &http.Transport{TLSClientConfig: clientTLS, TLSHandshakeTimeout: 5 * time.Second}
client := &http.Client{Transport: tr, Timeout: 8 * time.Second}
body, _ := json.Marshal(map[string]string{"email": email, "password": password})
reqURL := "https://" + primaryFQDN + ":8443/agent/auth/check"
req, err := http.NewRequestWithContext(ctx, http.MethodPost, reqURL, bytes.NewReader(body))
if err != nil {
return "", "", err
}
req.Header.Set("Content-Type", "application/json")
resp, err := client.Do(req)
if err != nil {
return "", "", err
}
defer resp.Body.Close()
raw, _ := io.ReadAll(io.LimitReader(resp.Body, 64*1024))
if resp.StatusCode != http.StatusOK {
return "", "", errors.New("primary: " + strings.TrimSpace(string(raw)))
}
var env struct {
Data struct {
Actor string `json:"actor"`
Role string `json:"role"`
} `json:"data"`
}
if err := json.Unmarshal(raw, &env); err != nil {
return "", "", err
}
if env.Data.Actor == "" {
return "", "", errors.New("primary returned empty actor")
}
return env.Data.Actor, env.Data.Role, nil
}
func setSessionCookie(c *gin.Context, raw string, expUnix int64) {
maxAge := int(time.Until(time.Unix(expUnix, 0)).Seconds())
if maxAge < 0 {
maxAge = 0
}
c.SetSameSite(http.SameSiteStrictMode)
c.SetCookie(cookieName, raw, maxAge, "/", "", true, true)
}
func clearSessionCookie(c *gin.Context) {
c.SetSameSite(http.SameSiteStrictMode)
c.SetCookie(cookieName, "", -1, "/", "", true, true)
}