fix: clean up lazy import, dead var, whitespace; document WS session caveat
- Move get_all_credential_counts import to top-level in daemon/handlers/auth.py - Remove unused PROJECT_DIR in scripts/bootstrap_auth.py - Fix leading space in api.js tryRefreshToken function - Document WebSocket session binding limitation in docs/security.md
This commit is contained in:
@@ -56,6 +56,7 @@ from lib.auth_users import (
|
|||||||
from lib.webauthn import (
|
from lib.webauthn import (
|
||||||
create_authentication_options,
|
create_authentication_options,
|
||||||
create_registration_options,
|
create_registration_options,
|
||||||
|
get_all_credential_counts,
|
||||||
get_management_domains,
|
get_management_domains,
|
||||||
get_rp_name,
|
get_rp_name,
|
||||||
list_credentials,
|
list_credentials,
|
||||||
@@ -595,6 +596,4 @@ def webauthn_remove_credential(request: Any, body: Any) -> dict[str, Any]:
|
|||||||
@registry.register(GET_AUTH_WEBAUTHN_CREDENTIAL_COUNTS)
|
@registry.register(GET_AUTH_WEBAUTHN_CREDENTIAL_COUNTS)
|
||||||
def webauthn_credential_counts(_request: Any, body: Any) -> dict[str, int]:
|
def webauthn_credential_counts(_request: Any, body: Any) -> dict[str, int]:
|
||||||
"""Return credential counts for all users (admin endpoint)."""
|
"""Return credential counts for all users (admin endpoint)."""
|
||||||
from lib.webauthn import get_all_credential_counts
|
|
||||||
|
|
||||||
return get_all_credential_counts()
|
return get_all_credential_counts()
|
||||||
|
|||||||
@@ -104,6 +104,8 @@ Token theft protection:
|
|||||||
- Token blacklist prevents reuse after logout or password change
|
- Token blacklist prevents reuse after logout or password change
|
||||||
- XSS mitigations: CSP headers, `X-XSS-Protection` header on management domain
|
- XSS mitigations: CSP headers, `X-XSS-Protection` header on management domain
|
||||||
|
|
||||||
|
**WebSocket session binding limitation**: WebSocket connections skip `session_id` validation. Browsers cannot send custom headers during the WebSocket handshake — the token is passed via the `Sec-WebSocket-Protocol` subprotocol or an nginx-injected `X-Auth-Token` header. This means a stolen access token can be used to open WebSocket connections for the full 15-minute TTL without session verification. Short-lived TTL and management domain CSP headers mitigate this risk.
|
||||||
|
|
||||||
### WebAuthn Security
|
### WebAuthn Security
|
||||||
|
|
||||||
WebAuthn (passkeys) provides passwordless authentication via the browser's Web Authentication API. Security properties:
|
WebAuthn (passkeys) provides passwordless authentication via the browser's Web Authentication API. Security properties:
|
||||||
|
|||||||
@@ -17,7 +17,6 @@ import sys
|
|||||||
from pathlib import Path
|
from pathlib import Path
|
||||||
|
|
||||||
# Ensure project lib is importable
|
# Ensure project lib is importable
|
||||||
PROJECT_DIR = Path(".")
|
|
||||||
|
|
||||||
|
|
||||||
def main() -> None:
|
def main() -> None:
|
||||||
|
|||||||
Reference in New Issue
Block a user