Compare commits

...
9 changed files with 71 additions and 8 deletions
+5
View File
@@ -448,6 +448,11 @@ FLUXER_DISCOVERY_ENABLED=true
#FLUXER_SEAWEEDFS_GOMEMLIMIT=1536MiB
#FLUXER_SEAWEEDFS_TELEMETRY=false
# Volumes SeaweedFS creates at once when a bucket needs space. Each reserves 1 GB
# of free disk from the start, and SeaweedFS's own default of 7 fills a small
# disk before every bucket has one, so uploads fail with no free volumes left.
#FLUXER_SEAWEEDFS_VOLUME_GROWTH=1
# Node sizes its heap from the container limit by default. Leave these unset
# unless you need to pin it. A heap ceiling above the container limit gets the
# container OOM-killed instead of reporting a heap error. The values below are
+1
View File
@@ -353,6 +353,7 @@ services:
memory: ${FLUXER_SEAWEEDFS_MEMORY_LIMIT:-2gb}
environment:
GOMEMLIMIT: ${FLUXER_SEAWEEDFS_GOMEMLIMIT:-1536MiB}
WEED_MASTER_VOLUME_GROWTH_COPY_1: ${FLUXER_SEAWEEDFS_VOLUME_GROWTH:-1}
command: ["server", "-s3", "-dir=/data", "-master.telemetry=${FLUXER_SEAWEEDFS_TELEMETRY:-false}"]
volumes:
- seaweedfs-data:/data
+8 -3
View File
@@ -168,12 +168,17 @@ export async function verifyMfaCode(ctx: ApiContext, params: VerifyMfaCodeParams
return false;
}
type CredentialTransport = 'usb' | 'nfc' | 'ble' | 'internal' | 'cable' | 'hybrid';
const ALL_CREDENTIAL_TRANSPORTS: Array<CredentialTransport> = ['internal', 'hybrid', 'usb', 'nfc', 'ble'];
function toCredentialDescriptor(credential: WebAuthnCredential) {
return {
id: credential.credentialId,
transports: credential.transports
? (Array.from(credential.transports) as Array<'usb' | 'nfc' | 'ble' | 'internal' | 'cable' | 'hybrid'>)
: undefined,
transports:
credential.transports && credential.transports.size > 0
? (Array.from(credential.transports) as Array<CredentialTransport>)
: ALL_CREDENTIAL_TRANSPORTS,
};
}
@@ -65,6 +65,7 @@ describe('WebAuthn MFA login', () => {
expect(mfaOptions.userVerification).toBe('discouraged');
expect(mfaOptions.allowCredentials).toBeTruthy();
expect(mfaOptions.allowCredentials!.length).toBeGreaterThan(0);
expect(mfaOptions.allowCredentials![0]!.transports).toEqual(['internal']);
if (mfaOptions.rpId) {
device.rpId = mfaOptions.rpId;
}
@@ -87,6 +88,48 @@ describe('WebAuthn MFA login', () => {
.execute();
expect(userInfo.id).toBe(account.userId);
});
it('offers every transport for a passkey registered without transports', async () => {
const account = await createTestAccount(harness);
const device = createWebAuthnDevice();
device.transports = null;
const secret = createTotpSecret();
await createBuilder(harness, account.token)
.post('/users/@me/mfa/totp/enable')
.body({secret, code: generateTotpCode(secret), password: account.password})
.execute();
await registerWebAuthnCredential(harness, account.token, device, () => ({
mfa_method: 'totp',
mfa_code: generateTotpCode(secret),
}));
await setWebAuthnTwoFactor(harness, account.token, true, {
mfa_method: 'totp',
mfa_code: generateTotpCode(secret),
});
const loginResp = (await loginUser(harness, {
email: account.email,
password: account.password,
})) as LoginMfaResponse;
const mfaOptions = await createBuilderWithoutAuth<WebAuthnAuthenticationOptions>(harness)
.post('/auth/login/mfa/webauthn/authentication-options')
.body({ticket: loginResp.ticket})
.execute();
expect(mfaOptions.allowCredentials).toEqual([
{
id: device.credentialId.toString('base64url'),
type: 'public-key',
transports: ['internal', 'hybrid', 'usb', 'nfc', 'ble'],
},
]);
const webauthnMfaLogin = await createBuilderWithoutAuth<{token: string}>(harness)
.post('/auth/login/mfa/webauthn')
.body({
response: createAuthenticationResponse(device, mfaOptions),
challenge: mfaOptions.challenge,
ticket: loginResp.ticket,
})
.execute();
expect(webauthnMfaLogin.token).toBeTruthy();
});
it('issues a session token instead of an MFA ticket when passkey two-factor is left off', async () => {
const account = await createTestAccount(harness);
const device = createWebAuthnDevice();
@@ -21,6 +21,7 @@ export interface WebAuthnDevice {
rpId: string;
origin: string;
signCount: number;
transports?: Array<string> | null;
}
export interface WebAuthnRegistrationOptions {
@@ -47,6 +48,7 @@ export interface WebAuthnAuthenticationOptions {
allowCredentials?: Array<{
id: string;
type: string;
transports?: Array<string>;
}>;
userVerification: string;
}
@@ -75,7 +77,7 @@ export interface WebAuthnTwoFactorResult {
interface AuthenticatorAttestationResponse {
clientDataJSON: string;
attestationObject: string;
transports: Array<string>;
transports?: Array<string>;
}
interface AuthenticatorAssertionResponse {
@@ -363,7 +365,7 @@ export function createRegistrationResponse(
response: {
clientDataJSON: encodeBase64URL(clientDataJSON),
attestationObject: encodeBase64URL(attestationObject),
transports: ['internal'],
...(device.transports === null ? {} : {transports: device.transports ?? ['internal']}),
},
};
}
@@ -6,7 +6,7 @@ import type {User} from '@app/api/models/User';
import {UserChannelService} from '@app/api/user/services/UserChannelService';
import {getWorkerDependencies} from '@app/api/worker/WorkerContext';
import {UserFlags} from '@fluxer/constants/src/UserConstants';
import {JobCancelledError, type WorkerTaskHelpers} from '@pkgs/worker/src/contracts/WorkerTask';
import {JobCancelledError, type WorkerTaskHelpers, type WorkerTaskResult} from '@pkgs/worker/src/contracts/WorkerTask';
import {z} from 'zod';
const SYSTEM_USER_ID: UserID = createUserID(0n);
@@ -56,7 +56,7 @@ async function* listedRecipients(userIds: Array<string>): AsyncGenerator<UserID>
}
}
export async function sendSystemDm(payload: unknown, helpers: WorkerTaskHelpers): Promise<void> {
export async function sendSystemDm(payload: unknown, helpers: WorkerTaskHelpers): Promise<WorkerTaskResult> {
const parsed = PayloadSchema.parse(payload);
const {content} = parsed;
const total = 'user_ids' in parsed ? parsed.user_ids.length : null;
@@ -105,5 +105,7 @@ export async function sendSystemDm(payload: unknown, helpers: WorkerTaskHelpers)
}
}
requestCache.clear();
await helpers.reportProgress(sent + failed, sent + failed, `${sent} sent, ${failed} failed`);
helpers.logger.info({sent, failed, total: sent + failed}, 'System DM job complete');
return {sent_count: sent, failed_count: failed};
}
@@ -219,7 +219,7 @@ describe('System DM cancellation', () => {
await expect(runner.runJob(TASK_TYPE, createJobMessage({all_users: true}) as unknown as JsMsg)).resolves.toBe(true);
expect(recipientIds).toEqual([21n, 24n]);
expect(markSucceeded).toHaveBeenCalledTimes(1);
expect(markSucceeded).toHaveBeenCalledWith(LEDGER_JOB_ID, {sent_count: 2, failed_count: 0});
expect(kv.size).toBe(0);
});
});
@@ -1834,6 +1834,10 @@ Default `1536MiB`. The heap ceiling the Go runtime collects against. Go cannot s
Default `false`. Becomes the `-master.telemetry` flag of `seaweedfs`, which reports usage to the SeaweedFS project when on.
#### `FLUXER_SEAWEEDFS_VOLUME_GROWTH`
Default `1`. Becomes `WEED_MASTER_VOLUME_GROWTH_COPY_1`, the number of volumes SeaweedFS creates at once when a bucket runs out of room. Each volume reserves a 1 GB slot of free disk, and the stack writes to four buckets. SeaweedFS's own default of 7 needs about 28 GB free before every bucket has a volume, so on a smaller disk the first bucket takes every slot and uploads fail with `No writable volumes and no free volumes left`.
#### `FLUXER_SEAWEEDFS_INIT_MEMORY_LIMIT`
Default `128mb`. The ceiling for `seaweedfs-init`. A one-shot container that exits, so it never overlaps steady state.
@@ -49,6 +49,7 @@ const INPUT_NAMES: Record<string, string> = {
MEILI_NO_ANALYTICS: 'FLUXER_MEILISEARCH_NO_ANALYTICS',
MEILI_MAX_INDEXING_MEMORY: 'FLUXER_MEILISEARCH_MAX_INDEXING_MEMORY',
GOMEMLIMIT: 'FLUXER_SEAWEEDFS_GOMEMLIMIT',
WEED_MASTER_VOLUME_GROWTH_COPY_1: 'FLUXER_SEAWEEDFS_VOLUME_GROWTH',
LIVEKIT_KEYS: 'LIVEKIT_API_KEY',
NODE_EXTRA_CA_CERTS: 'FLUXER_NODE_EXTRA_CA_CERTS',
};