mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-06 04:43:43 +00:00
feat(dashboard): scoped API keys with rate limits and quotas
Bearer keys (dlk_...) are checked per request against their owner's current account (ban, lock, demotion, sign out everywhere stop or narrow them at once) and their scope: permission routes need the permission in scope, read-only keys only read, level-only routes need an all-permission key, and session-only paths (sign-in, password, 2FA, key management) are never reachable with a key. Per-key rate limit and daily quota with 429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in batches every minute. WebSocket subscriptions honour the scope too. Routes to list, make, rotate and revoke keys; staff with api_keys_manage can see and revoke others' keys under the rank rules. POST /api/auth/token now makes an all-permission key. Audit entries for create/rotate/revoke/denied, and actions done with a key are attributed to "user (key name)". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -96,6 +96,8 @@
|
||||
#include "Alerts.h"
|
||||
#include "DashboardAuthService.h"
|
||||
#include "AuthTokenHandler.h"
|
||||
#include "ApiKeyService.h"
|
||||
#include "ApiKeyRoutes.h"
|
||||
#include "JWTUtils.h"
|
||||
#include "GeneralUtils.h"
|
||||
#include <fstream>
|
||||
@@ -462,6 +464,13 @@ int main(int argc, char** argv) {
|
||||
// WebSocket connections carry the session cookie; the level gates which topics they may receive
|
||||
// Also called again for open sockets every minute and when an account changes (BroadcastTableChanged("accounts"))
|
||||
Game::web.SetWSAuthCallback([](const std::string& token) -> std::optional<WSAuth> {
|
||||
// An API key: its owner as of now, and its scope for the subscriptions
|
||||
if (ApiKeyService::LooksLikeKey(token)) {
|
||||
const auto key = ApiKeyService::Verify(token);
|
||||
if (!key) return std::nullopt;
|
||||
if (key->needsTwoFactorSetup) return WSAuth{ 0, key->accountId, key->scope };
|
||||
return WSAuth{ key->gmLevel, key->accountId, key->scope };
|
||||
}
|
||||
const auto result = AuthTokenHandler::ValidateToken(token);
|
||||
if (!result.isValid) return std::nullopt;
|
||||
// Until required two-factor login is set up the session only reaches its own account page
|
||||
@@ -504,6 +513,7 @@ int main(int argc, char** argv) {
|
||||
RegisterCharacterProgressRoutes();
|
||||
RegisterServerRoutes();
|
||||
RegisterLeaderboardRoutes();
|
||||
ApiKeyRoutes::RegisterRoutes();
|
||||
RequireAuthMiddleware::SetApiAccessCheck([](uint8_t gmLevel) { return Permissions::Allowed(gmLevel, "api_access"); });
|
||||
RequireAuthMiddleware::SetForbiddenPage([](const HTTPContext& context, HTTPReply& reply) {
|
||||
RouteUtils::RenderError(reply, context, eHTTPStatusCode::FORBIDDEN, "You don't have permission to open this page.");
|
||||
@@ -587,6 +597,7 @@ int main(int argc, char** argv) {
|
||||
ChallengeRoutes::Update();
|
||||
InstanceLoad::Update();
|
||||
Traffic::Update();
|
||||
ApiKeyService::Update();
|
||||
|
||||
// Broadcast dashboard updates periodically
|
||||
if (elapsedSinceBroadcast >= broadcastInterval) {
|
||||
@@ -602,6 +613,7 @@ int main(int argc, char** argv) {
|
||||
// Cleanup: the worker threads first (they answer deferred requests), then the web server's connections
|
||||
Workers::Stop();
|
||||
Game::web.Shutdown();
|
||||
ApiKeyService::Flush();
|
||||
Inspector::Shutdown();
|
||||
EmailService::Shutdown();
|
||||
ModeratorHelper::Shutdown();
|
||||
|
||||
Reference in New Issue
Block a user