Public Access
Add configuration, OIDC auth wiring and discovery endpoints (M1)
Options, JWT bearer validation, the /meta and .well-known endpoints, and a dev compose stack with Keycloak. Verified end to end: compose up, migrate, run, both discovery endpoints return correct payloads, and readiness reports the schema current. Configuration: - Strongly-typed options for Server, Oidc, Relay and Sync, all ValidateOnStart. A self-hosted server that boots half-configured and fails later per-request is far harder to diagnose than one that refuses to start and names the bad setting. - Cross-field validation the annotations cannot express: relay needs a WebSocketUrl when enabled, idle timeout must be under max session duration, item payload cap under batch cap. - Startup warnings for combinations that are individually valid but dangerous together: RequireHttpsMetadata false outside Development, and AllowEmailLinking (which turns any token bearing a victim's email into account takeover, hence default false). Auth: - JwtBearer with ClockSkew cut to 30s from the 5-minute default; five minutes of slack on a credential granting vault ciphertext access is more than any clock needs. - IncludeErrorDetails off, and a FallbackPolicy so an endpoint without an explicit policy still requires a caller rather than silently being public. Discovery, per ADR 0002: - /api/v1/meta reports versions, features and push caps. - /.well-known/dodossh-configuration is the onboarding story: the user types one server URL and the client discovers OIDC authority, client id, scopes and relay endpoint. Two environment problems found by actually running the stack: - PostgreSQL 18 changed its data mount point. Mounting /var/lib/postgresql/data — correct through 17 — makes the image refuse to start; 18+ wants a single mount at /var/lib/postgresql with the cluster in a subdirectory. - Keycloak moved to host port 18080. An unrelated Apache Tomcat on this machine holds 127.0.0.1:8080, and a loopback-specific bind beats Docker's 0.0.0.0 publish for "localhost". It presents as Keycloak 404ing every realm while its own log says the import succeeded, which is a genuinely misleading failure. Also: CA1848 is enforced, not advisory — warnings are errors, so the .editorconfig comment claiming otherwise was wrong. Startup and health logging now uses [LoggerMessage]. And a clean rebuild is back to zero warnings; the incremental build had been hiding 40 in test projects (banned Guid.NewGuid, an obsolete Testcontainers constructor, and two analyzer families that are genuinely noise under a test host). Verified: 0 warnings on a clean rebuild, 122 tests pass, format clean.
This commit is contained in:
@@ -0,0 +1,91 @@
|
||||
using System.Reflection;
|
||||
using DodoSSH.Api.Setup;
|
||||
using DodoSSH.Contracts;
|
||||
using DodoSSH.Crypto;
|
||||
using Microsoft.AspNetCore.Http.HttpResults;
|
||||
using Microsoft.Extensions.Options;
|
||||
|
||||
namespace DodoSSH.Api.Features.Meta;
|
||||
|
||||
/// <summary>
|
||||
/// Capability and discovery endpoints.
|
||||
/// </summary>
|
||||
/// <remarks>
|
||||
/// These replace URL-based API versioning. When client and server upgrade independently — which is
|
||||
/// the normal case for self-hosted software — a client needs to ask what this particular server
|
||||
/// supports rather than assume. See ADR 0002.
|
||||
/// </remarks>
|
||||
internal static class MetaEndpoints
|
||||
{
|
||||
/// <summary>Sync semantics version. Bumped when push or pull behaviour changes.</summary>
|
||||
internal const int SyncProtocolVersion = 1;
|
||||
|
||||
/// <summary>Feature flag for the relay.</summary>
|
||||
internal const string RelayFeature = "relay";
|
||||
|
||||
internal static IEndpointRouteBuilder MapMetaEndpoints(this IEndpointRouteBuilder app)
|
||||
{
|
||||
// Anonymous by necessity: a client must be able to discover how to authenticate before it
|
||||
// can authenticate.
|
||||
app.MapGet("/api/v1/meta", GetMeta)
|
||||
.AllowAnonymous()
|
||||
.WithName("GetMeta")
|
||||
.WithSummary("Server capabilities, versions and limits.");
|
||||
|
||||
app.MapGet("/.well-known/dodossh-configuration", GetConfiguration)
|
||||
.AllowAnonymous()
|
||||
.WithName("GetDodoSshConfiguration")
|
||||
.WithSummary("Everything a client needs to begin authenticating, from one URL.");
|
||||
|
||||
return app;
|
||||
}
|
||||
|
||||
private static Ok<MetaResponse> GetMeta(
|
||||
IOptions<SyncOptions> sync,
|
||||
IOptions<RelayOptions> relay,
|
||||
IOptions<ServerOptions> server)
|
||||
{
|
||||
List<string> features = ["teams"];
|
||||
if (relay.Value.Enabled)
|
||||
{
|
||||
features.Add(RelayFeature);
|
||||
}
|
||||
|
||||
return TypedResults.Ok(new MetaResponse(
|
||||
ServerVersion: ServerVersion,
|
||||
ApiVersions: [1],
|
||||
SyncProtocolVersion: SyncProtocolVersion,
|
||||
CryptoSpecVersion: CryptoSpec.CurrentAadVersion,
|
||||
Features: features,
|
||||
MinClientVersion: server.Value.MinClientVersion,
|
||||
MaxOperationsPerPush: sync.Value.MaxOperationsPerPush,
|
||||
MaxPayloadBytes: sync.Value.MaxPayloadBytes,
|
||||
MaxItemPayloadBytes: sync.Value.MaxItemPayloadBytes));
|
||||
}
|
||||
|
||||
private static Ok<DodoSshConfiguration> GetConfiguration(
|
||||
IOptions<OidcOptions> oidc,
|
||||
IOptions<RelayOptions> relay,
|
||||
IOptions<ServerOptions> server)
|
||||
{
|
||||
var relayOptions = relay.Value;
|
||||
|
||||
return TypedResults.Ok(new DodoSshConfiguration(
|
||||
ApiBaseUrl: new Uri(server.Value.PublicBaseUrl, UriKind.Absolute),
|
||||
Oidc: new OidcConfiguration(
|
||||
Authority: new Uri(oidc.Value.Authority, UriKind.Absolute),
|
||||
ClientId: oidc.Value.ClientId,
|
||||
Scopes: [.. oidc.Value.Scopes],
|
||||
LoopbackRedirectPattern: oidc.Value.LoopbackRedirectPattern),
|
||||
Relay: new RelayConfiguration(
|
||||
Enabled: relayOptions.Enabled,
|
||||
WebSocketUrl: relayOptions.Enabled && relayOptions.WebSocketUrl is not null
|
||||
? new Uri(relayOptions.WebSocketUrl, UriKind.Absolute)
|
||||
: null)));
|
||||
}
|
||||
|
||||
private static string ServerVersion { get; } =
|
||||
typeof(MetaEndpoints).Assembly
|
||||
.GetCustomAttribute<AssemblyInformationalVersionAttribute>()?.InformationalVersion
|
||||
?? "0.0.0";
|
||||
}
|
||||
Reference in New Issue
Block a user