Files
website/server/.env.example
Claude d38c98ad9e Harden admin login: RBAC-safe controls, 2FA, bot-scoring, rate limits (#9)
Adds a layered set of protections around the admin login and the app edge.

Trust proxy (server/src/utils/trustProxy.js)
- Configurable via TRUST_PROXY; pin to the newt agent ("ptero") LAN IP so
  X-Forwarded-For is trusted ONLY from that peer. A blanket "true" is
  rejected (coerced to 1) to prevent XFF spoofing that would dodge every
  IP-based control. DEBUG_TRUST_PROXY logs peer/XFF/req.ip to re-verify the
  proxy IP without a redeploy. Documents the Omada static-reservation
  assumption.

Login throttling (server/src/middleware/loginProtection.js, rateLimit.js)
- express-slow-down progressive delay + the existing hard rate cap + a
  separate per-IP exponential backoff that persists across the rate window.
  All failures return one generic message (no user/pass disclosure).

Honeypot (login form + auth.controller)
- Hidden, plausibly-named field ("company"); a filled value fails
  generically and is scored as an unambiguous bot.

Optional per-user TOTP 2FA (speakeasy/qrcode)
- totp_secret/totp_enabled columns (+ idempotent migration). Self-service
  Account page: enroll via QR, confirm a code to enable, code-gated disable.
- Login is two-step for enrolled users: after the password, a short-lived
  signed challenge (stage:'totp', not a session) is required before the
  real session is issued.

Bot / scanner scoring + IP ban (server/src/middleware/botScore.js)
- Weighted CMS-scanner paths (this app uses none). Junk paths 404 FIRST,
  unconditionally — independent of score/ban state, so a scanner rotating
  through fresh Cloudflare IPs gets no free pass. /wp-admin/install.php is
  the top-weighted near-1-hit ban (worst offender in prod logs). Per-IP
  score with quiet-period decay temp-bans an IP from ALL routes once past a
  (deliberately low) threshold, to protect /admin from credential stuffing.
  Failed logins and honeypot hits feed the same score.
- Periodic sweep evicts stale, unbanned, quiet entries so the in-memory
  store can't grow unbounded; the interval is unref'd and cleared on
  graceful shutdown.

Tests: node --test suite (40) covering trust-proxy parsing + live req.ip
(incl. pinned-IP), rate limiter + exponential backoff, honeypot rejection,
TOTP verify (enabled/disabled) + challenge-isn't-a-session, bot-score
threshold/decay/ban + junk-404-independence + install.php + store sweep.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-07-02 23:22:35 -05:00

61 lines
2.2 KiB
Plaintext

# ─── UOMysticmoon server — local dev environment ───
# Copy to server/.env for running `npm run dev` outside Docker.
# (In Docker, the root .env / docker-compose provides these instead.)
NODE_ENV=development
PORT=3000
# Logging — written to BOTH the console and a log file (default <server>/logs/app.log).
LOG_LEVEL=debug # console verbosity: error | warn | info | debug
FILE_LOG_LEVEL=debug # file verbosity
LOG_TO_FILE=true # set false for console-only
# LOG_DIR= # defaults to server/logs
# LOG_FILE=app.log
# Point at a local or Dockerized MariaDB
DB_HOST=127.0.0.1
DB_PORT=3306
DB_NAME=uomysticmoon
DB_USER=uomm
DB_PASSWORD=change-me-db-password
JWT_SECRET=dev-only-change-me
JWT_EXPIRES_IN=1d
COOKIE_SECURE=auto
COOKIE_NAME=uomm_token
# Reverse-proxy trust. Request path: client -> Pangolin -> newt agent "ptero"
# (separate VM) -> this app. ptero is the hop that connects to us, so pin
# TRUST_PROXY to ptero's LAN IP: Express then honours X-Forwarded-For ONLY on
# connections from ptero, and req.ip / req.secure reflect the real client (used
# by rate limiting, backoff, bot-ban, activity log).
# <ptero LAN IP> -> e.g. 10.0.0.42 (RECOMMENDED in prod; requires a static
# DHCP reservation for ptero in Omada — a lease change would
# silently break IP trust)
# an integer -> that many hops (fallback if you can't pin an IP)
# false -> no proxy (direct connections)
# NOTE: a blanket "true" is intentionally rejected (coerced to 1) — it would let
# clients spoof their IP via a forged X-Forwarded-For and dodge rate limits/bans.
TRUST_PROXY=1
# Set to 1 to log each request's raw peer address + X-Forwarded-For + resolved
# req.ip, so you can verify/refresh ptero's IP without redeploying. Noisy —
# leave off in normal operation.
DEBUG_TRUST_PROXY=0
# Optional TOTP two-factor (opt-in per user).
TOTP_ISSUER=UOMysticmoon
# How long the "password verified, awaiting code" step stays valid.
TOTP_CHALLENGE_TTL=5m
# Created on first boot if the users table is empty
ADMIN_USERNAME=admin
ADMIN_PASSWORD=change-me-admin-password
SMTP_HOST=
SMTP_PORT=587
SMTP_USER=
SMTP_PASS=
CONTACT_TO=UOMysticmoon@gmail.com
CLIENT_ORIGIN=http://localhost:5173