fix(dsh-web-auth): Authentik-gated :80 login + non-disruptive token capture #73

Merged
abiba-bot merged 11 commits from fm/dsh-web-auth-restart-20260911 into master 2026-09-11 18:21:04 +00:00
Owner

Corrected dsh-web authentication (parent correction b34cd9a3d16422d3)

Re-implements the dsh-web auth fix after the first attempt was contained for an
unauthenticated bypass and a header regression.

Design

  1. No :8081 endpoint. The 0.0.0.0:8081 listener with no auth_request is removed; the script stashes any reappearing /etc/nginx/sites-enabled/dsh.token and never restores it (pending-reload marker on failure).
  2. Login inside the Authentik-gated :80 block as location = /dsh-web-login, guarded by auth_request /outpost.goauthentik.io/auth/nginx, proxying to dsh-web with Host: tankodhs.sysloggh.net so the 30-day cookie is bound to the public authority (never 127.0.0.1:3080).
  3. Non-disruptive token capture (scripts/capture-dsh-token.sh): reads candidates from the running service's journal scoped to the current systemd invocation, functionally verifies the live token (303), regenerates /etc/dsh-web/nginx-login.conf, reloads nginx only on change (nginx -t guarded, applied stamp, pending marker), flock-serialized. Never stops/starts dsh-web. Wired via dsh-web-token.service (ExecStartPost) + dsh-web-token.timer.
  4. Restores x-dsh-task-board-proxy-token and Host $ak_origin_host.

Live acceptance (CT 112, 2026-09-11)

  • Unauthenticated :80 /dsh-web-login -> 302 (Authentik); :8081 -> 000
  • Authenticated mint + cookie-jar replay -> 303 -> 200
  • Restart dsh-web: include auto-refreshed in ~30s; pre-restart cookie still 200; new token mints 303

Repo changes

  • scripts/capture-dsh-token.sh, zulip-health.prose.md (B4, v3.2.0), contract-registry.yaml

Validated by no-mistakes run 01M28P5XAZ5NKF9Q60DT3VWCCF (outcome passed).

## Corrected dsh-web authentication (parent correction b34cd9a3d16422d3) Re-implements the dsh-web auth fix after the first attempt was contained for an unauthenticated bypass and a header regression. ### Design 1. **No `:8081` endpoint.** The `0.0.0.0:8081` listener with no `auth_request` is removed; the script stashes any reappearing `/etc/nginx/sites-enabled/dsh.token` and never restores it (pending-reload marker on failure). 2. **Login inside the Authentik-gated `:80` block** as `location = /dsh-web-login`, guarded by `auth_request /outpost.goauthentik.io/auth/nginx`, proxying to dsh-web with `Host: tankodhs.sysloggh.net` so the 30-day cookie is bound to the public authority (never `127.0.0.1:3080`). 3. **Non-disruptive token capture** (`scripts/capture-dsh-token.sh`): reads candidates from the running service's journal scoped to the current systemd invocation, functionally verifies the live token (`303`), regenerates `/etc/dsh-web/nginx-login.conf`, reloads nginx only on change (`nginx -t` guarded, applied stamp, pending marker), `flock`-serialized. Never stops/starts dsh-web. Wired via `dsh-web-token.service` (`ExecStartPost`) + `dsh-web-token.timer`. 4. Restores `x-dsh-task-board-proxy-token` and `Host $ak_origin_host`. ### Live acceptance (CT 112, 2026-09-11) - Unauthenticated `:80 /dsh-web-login` -> 302 (Authentik); `:8081` -> 000 - Authenticated mint + cookie-jar replay -> 303 -> 200 - Restart `dsh-web`: include auto-refreshed in ~30s; pre-restart cookie still 200; new token mints 303 ### Repo changes - `scripts/capture-dsh-token.sh`, `zulip-health.prose.md` (B4, v3.2.0), `contract-registry.yaml` Validated by no-mistakes run `01M28P5XAZ5NKF9Q60DT3VWCCF` (outcome `passed`).
abiba-bot added 11 commits 2026-09-11 17:52:01 +00:00
- Add capture-dsh-token.sh script that captures the dsh-web launch token
- Add login endpoint (/dsh-web-login on :8081) that mints 30-day auth cookie
- Document the authentication flow in zulip-health.prose.md (Platform B4)
- Cookie is authority-bound to 127.0.0.1:3080 with 30-day expiry
- After first login, subsequent requests use the cookie — no token required
Correct the dsh-web authentication fix after parent correction:

- Remove the unauthenticated :8081 endpoint (0.0.0.0 bind with no
  auth_request = full Authentik bypass for the LAN). The script now removes
  /etc/nginx/sites-enabled/dsh.token automatically if it reappears.
- Put the login path inside the Authentik-gated :80 server block as
  location = /dsh-web-login; proxy to dsh-web with Host =
  tankodhs.sysloggh.net so the 30-day cookie is bound to the public
  authority, never to 127.0.0.1:3080.
- Isolate the rotating token in a generated include
  /etc/dsh-web/nginx-login.conf; reload nginx only when it changes.
- Replace the disruptive capture (systemctl stop/start dsh-web) with a
  non-disruptive read of the running service's journal, scoped to the
  current systemd invocation so a restarted process's stale token is never
  reused while the new banner is still pending.
- Keep x-dsh-task-board-proxy-token and Host $ak_origin_host intact in '/'.
- Document the corrected design (B4) in zulip-health.prose.md, v3.2.0.

Live-verified 2026-09-11: no auth bypass (302), :8081 refused (000), a
cookie minted before two dsh-web restarts still returns 200, the refreshed
token mints a fresh cookie, and the systemd ExecStartPost/timer refreshes
the token automatically without touching dsh-web.
no-mistakes(document): Align zulip-health v3.2.0 registry metadata and B4 formatting
PR Pipeline — Authorize → Validate → Review → Merge / auth (pull_request) Successful in 5s
PR Pipeline — Authorize → Validate → Review → Merge / validate (pull_request) Successful in 2s
PR Pipeline — Authorize → Validate → Review → Merge / lint (pull_request) Successful in 7s
PR Pipeline — Authorize → Validate → Review → Merge / ai-review (pull_request) Successful in 4s
PR Pipeline — Authorize → Validate → Review → Merge / gate (pull_request) Successful in 0s
767bd22d9c
abiba-bot merged commit 862356bcac into master 2026-09-11 18:21:04 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: SyslogSolution/prose-contracts#73