mirror of
https://github.com/DarkflameUniverse/DarkflameServer.git
synced 2026-10-07 21:33:43 +00:00
feat(dashboard): scoped API keys with rate limits and quotas
Bearer keys (dlk_...) are checked per request against their owner's current account (ban, lock, demotion, sign out everywhere stop or narrow them at once) and their scope: permission routes need the permission in scope, read-only keys only read, level-only routes need an all-permission key, and session-only paths (sign-in, password, 2FA, key management) are never reachable with a key. Per-key rate limit and daily quota with 429 and X-RateLimit/X-Quota/Retry-After headers; usage is written in batches every minute. WebSocket subscriptions honour the scope too. Routes to list, make, rotate and revoke keys; staff with api_keys_manage can see and revoke others' keys under the rank rules. POST /api/auth/token now makes an all-permission key. Audit entries for create/rotate/revoke/denied, and actions done with a key are attributed to "user (key name)". Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -6,6 +6,7 @@
|
||||
#include <algorithm>
|
||||
#include "eHTTPStatusCode.h"
|
||||
#include "json.hpp"
|
||||
#include "ApiKeyScope.h"
|
||||
|
||||
/**
|
||||
* HTTP Request Context
|
||||
@@ -34,6 +35,9 @@ struct HTTPContext {
|
||||
std::string authenticatedUser{};
|
||||
uint32_t accountId = 0;
|
||||
uint8_t gmLevel = 0;
|
||||
// Set when an API key authenticated the request: the key's scope, on top of what the account may do (gmLevel).
|
||||
// Every permission check must honour it (RouteUtils::Can and friends do).
|
||||
std::shared_ptr<const ApiKeys::Scope> apiKey{};
|
||||
|
||||
// Custom data for middleware to communicate
|
||||
std::map<std::string, std::string> userData{};
|
||||
|
||||
25
dWeb/Web.cpp
25
dWeb/Web.cpp
@@ -29,6 +29,8 @@ namespace {
|
||||
std::vector<std::string> g_WSSubscriptions;
|
||||
// Minimum permission level per subscription, parallel to g_WSSubscriptions
|
||||
std::vector<std::function<uint8_t()>> g_WSSubscriptionLevels;
|
||||
// The permission guarding each subscription (empty: level only), parallel to g_WSSubscriptions
|
||||
std::vector<std::string> g_WSSubscriptionPermissions;
|
||||
// Authenticated WebSocket connections: their permission level, account and the token they connected with.
|
||||
// Entries are removed on MG_EV_CLOSE so a reused connection address is never treated as authenticated.
|
||||
struct WSClient {
|
||||
@@ -37,7 +39,16 @@ namespace {
|
||||
std::string token; // empty for trusted internal connections, which are never rechecked
|
||||
bool apiToken{}; // connected with Authorization: Bearer (subject to the API access rule)
|
||||
std::chrono::steady_clock::time_point nextCheck;
|
||||
std::shared_ptr<const ApiKeys::Scope> apiKey{}; // connected with an API key: its scope
|
||||
};
|
||||
|
||||
// Whether a connection may subscribe to (and receive) a subscription
|
||||
bool MayReceive(const WSClient& client, size_t index, uint8_t minLevel) {
|
||||
if (client.level < minLevel) return false;
|
||||
if (!client.apiKey) return true;
|
||||
const auto& permission = g_WSSubscriptionPermissions[index];
|
||||
return permission.empty() ? (minLevel == 0 || client.apiKey->allPermissions) : client.apiKey->Has(permission);
|
||||
}
|
||||
std::map<mg_connection*, WSClient> g_AuthenticatedWSConnections;
|
||||
constexpr uint8_t INTERNAL_WS_LEVEL = UINT8_MAX;
|
||||
constexpr auto WS_RECHECK_INTERVAL = std::chrono::seconds(60);
|
||||
@@ -66,6 +77,7 @@ namespace {
|
||||
continue;
|
||||
}
|
||||
client.level = auth->level;
|
||||
client.apiKey = auth->apiKey;
|
||||
}
|
||||
for (auto* connection : expired) {
|
||||
LOG_DEBUG("Closing a WebSocket whose session is no longer valid");
|
||||
@@ -357,7 +369,7 @@ void HandleHTTPMessage(mg_connection* connection, const mg_http_message* http_ms
|
||||
if (level) {
|
||||
mg_ws_upgrade(connection, const_cast<mg_http_message*>(http_msg), NULL);
|
||||
g_AuthenticatedWSConnections[connection] = { level->level, level->accountId, connectToken, apiToken,
|
||||
std::chrono::steady_clock::now() + WS_RECHECK_INTERVAL };
|
||||
std::chrono::steady_clock::now() + WS_RECHECK_INTERVAL, level->apiKey };
|
||||
const char* connType = isInternal ? "internal" : "external";
|
||||
LOG_DEBUG("Upgraded %s connection to websocket: %d.%d.%d.%d:%i", connType, MG_IPADDR_PARTS(&connection->rem.ip), connection->rem.port);
|
||||
} else {
|
||||
@@ -549,7 +561,7 @@ void HandleWSSubscribe(mg_connection* connection, json data) {
|
||||
// get index of subscription
|
||||
auto index = std::distance(g_WSSubscriptions.begin(), subItr);
|
||||
const auto connItr = g_AuthenticatedWSConnections.find(connection);
|
||||
if (connItr == g_AuthenticatedWSConnections.end() || connItr->second.level < g_WSSubscriptionLevels[index]()) {
|
||||
if (connItr == g_AuthenticatedWSConnections.end() || !MayReceive(connItr->second, index, g_WSSubscriptionLevels[index]())) {
|
||||
const std::string forbidden = "{\"error\":\"Forbidden\",\"subscription\":\"" + subscription + "\"}";
|
||||
mg_ws_send(connection, forbidden.c_str(), forbidden.size(), WEBSOCKET_OP_TEXT);
|
||||
return;
|
||||
@@ -664,6 +676,10 @@ void Web::RegisterWSSubscription(const std::string& subscription, uint8_t minLev
|
||||
}
|
||||
|
||||
void Web::RegisterWSSubscription(const std::string& subscription, std::function<uint8_t()> minLevel) {
|
||||
RegisterWSSubscription(subscription, std::move(minLevel), "");
|
||||
}
|
||||
|
||||
void Web::RegisterWSSubscription(const std::string& subscription, std::function<uint8_t()> minLevel, std::string permission) {
|
||||
if (!Game::web.enabled) {
|
||||
LOG_DEBUG("Failed to register WS subscription %s: web server not enabled", subscription.c_str());
|
||||
return;
|
||||
@@ -679,6 +695,7 @@ void Web::RegisterWSSubscription(const std::string& subscription, std::function<
|
||||
LOG_DEBUG("Registered WS subscription %s", subscription.c_str());
|
||||
g_WSSubscriptions.push_back(subscription);
|
||||
g_WSSubscriptionLevels.push_back(std::move(minLevel));
|
||||
g_WSSubscriptionPermissions.push_back(std::move(permission));
|
||||
}
|
||||
}
|
||||
|
||||
@@ -800,7 +817,7 @@ void Web::SendWSMessageToAccount(const std::string subscription, json& data, uin
|
||||
for (auto* wc = Game::web.GetManager().conns; wc != NULL; wc = wc->next) {
|
||||
if (!wc->is_websocket || wc->is_closing || wc->data[index] != SubscriptionStatus::SUBSCRIBED) continue;
|
||||
const auto connItr = g_AuthenticatedWSConnections.find(wc);
|
||||
if (connItr == g_AuthenticatedWSConnections.end() || connItr->second.accountId != accountId || connItr->second.level < minLevel) continue;
|
||||
if (connItr == g_AuthenticatedWSConnections.end() || connItr->second.accountId != accountId || !MayReceive(connItr->second, index, minLevel)) continue;
|
||||
mg_ws_send(wc, payload.c_str(), payload.size(), WEBSOCKET_OP_TEXT);
|
||||
}
|
||||
}
|
||||
@@ -823,7 +840,7 @@ void Web::SendWSMessage(const std::string subscription, json& data) {
|
||||
for (auto *wc = Game::web.GetManager().conns; wc != NULL; wc = wc->next) {
|
||||
if (!wc->is_websocket || wc->is_closing || wc->data[index] != SubscriptionStatus::SUBSCRIBED) continue;
|
||||
const auto connItr = g_AuthenticatedWSConnections.find(wc);
|
||||
if (connItr == g_AuthenticatedWSConnections.end() || connItr->second.level < minLevel) continue;
|
||||
if (connItr == g_AuthenticatedWSConnections.end() || !MayReceive(connItr->second, index, minLevel)) continue;
|
||||
mg_ws_send(wc, payload.c_str(), payload.size(), WEBSOCKET_OP_TEXT);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -56,6 +56,8 @@ enum SubscriptionStatus {
|
||||
struct WSAuth {
|
||||
uint8_t level{};
|
||||
uint32_t accountId{};
|
||||
// Connected with an API key: subscriptions also need their permission in its scope
|
||||
std::shared_ptr<const ApiKeys::Scope> apiKey{};
|
||||
};
|
||||
|
||||
// WebSocket authentication callback function type
|
||||
@@ -85,6 +87,9 @@ public:
|
||||
void RegisterWSSubscription(const std::string& subscription, uint8_t minLevel = 0);
|
||||
// The level is looked up each time (for permissions that can change while running)
|
||||
void RegisterWSSubscription(const std::string& subscription, std::function<uint8_t()> minLevel);
|
||||
// Guarded by a named permission (at its level): connections made with an API key also need it in the key's scope.
|
||||
// Level-only subscriptions above level 0 reach API keys only when they have all of their owner's permissions.
|
||||
void RegisterWSSubscription(const std::string& subscription, std::function<uint8_t()> minLevel, std::string permission);
|
||||
/**
|
||||
* Answer this request later (from any thread) instead of when the handler returns, for slow work that would hold
|
||||
* up every other request: the handler hands the returned DeferredReply to a worker and returns; the web thread
|
||||
|
||||
Reference in New Issue
Block a user