Implements #23 per ADR-0002. - Discord authorization code grant (identify + guilds.members.read), form-encoded token exchange - Guild membership gate via the single-guild endpoint; optional DISCORD_REQUIRED_ROLE (empty default) - Owner Discord ID is the only identity allowed to sign in - Sessions are DB rows with opaque random ids; cookie carries only the id; expiry enforced; delete = revoke - HMAC session signing, derived key, and WEB_PASSWORD removed; no replacement signing secret - Login rate limiting preserved on the callback - Full flow tested through the real router against a local Discord stub (DISCORD_API_BASE) - Env: DISCORD_CLIENT_ID/_CLIENT_SECRET/_GUILD_ID/_REQUIRED_ROLE/_API_BASE/_REDIRECT_URI; docs updated go test ./... passes. Reviewed-on: #31 Co-authored-by: Sulthan Zaki <sultankiki05@gmail.com> Co-committed-by: Sulthan Zaki <sultankiki05@gmail.com>
This commit was merged in pull request #31.
This commit is contained in:
@@ -52,8 +52,8 @@ POSTGRES_PASSWORD=<paste output of: openssl rand -hex 24>
|
||||
# DATABASE_URL=postgres://user:pass@host:5432/bookmarks?sslmode=require
|
||||
|
||||
# Required for the Traefik override. Both have no fallback — compose refuses
|
||||
# to start without them. BOOKMARK_WEB_HOST is required even if you never set
|
||||
# WEB_PASSWORD; see 1b.
|
||||
# to start without them. BOOKMARK_WEB_HOST is required even if the web UI
|
||||
# were unused; see 1b.
|
||||
BOOKMARK_API_HOST=bookmark-api.violetcrown.my.id
|
||||
BOOKMARK_WEB_HOST=bookmark.violetcrown.my.id
|
||||
|
||||
@@ -85,44 +85,56 @@ alone.
|
||||
|
||||
## 1b. Web UI
|
||||
|
||||
The browser UI is served by the same container on a second hostname.
|
||||
The browser UI is served by the same container on a second hostname. Sign-in
|
||||
is a Discord authorization code grant (ADR-0002): the owner's Discord account,
|
||||
gated by membership in one configured guild.
|
||||
|
||||
1. Add a DNS `A`/`AAAA` record for `bookmark.<yourdomain>` pointing at the server —
|
||||
the same address as `bookmark-api.<yourdomain>`.
|
||||
1. Add a DNS `A`/`AAAA` record for `bookmark.<yourdomain>` pointing at the
|
||||
server — the same address as `bookmark-api.<yourdomain>`.
|
||||
|
||||
2. Set both variables in `.env`:
|
||||
2. Create the Discord application at <https://discord.com/developers/applications>:
|
||||
- **OAuth2 → Redirects:** add the exact callback URL
|
||||
`https://bookmark.violetcrown.my.id/auth/discord/callback`. Discord
|
||||
matches it verbatim — a trailing slash or different hostname breaks
|
||||
sign-in.
|
||||
- **OAuth2 → General:** note the Client ID, and generate a Client Secret.
|
||||
- No scopes or bot setup are needed in the dashboard; the service requests
|
||||
`identify` and `guilds.members.read` itself, and checks the *user's*
|
||||
membership of the guild, not the application's.
|
||||
|
||||
3. Set the variables in `.env`:
|
||||
|
||||
```ini
|
||||
BOOKMARK_WEB_HOST=bookmark.violetcrown.my.id
|
||||
WEB_PASSWORD=<paste output of: openssl rand -base64 18>
|
||||
DISCORD_CLIENT_ID=<client id>
|
||||
DISCORD_CLIENT_SECRET=<client secret>
|
||||
DISCORD_GUILD_ID=<guild snowflake>
|
||||
DISCORD_REDIRECT_URI=https://bookmark.violetcrown.my.id/auth/discord/callback
|
||||
# Optional: only members holding this role may sign in.
|
||||
# DISCORD_REQUIRED_ROLE=<role snowflake>
|
||||
```
|
||||
|
||||
Generate and insert in one line:
|
||||
The guild id is in Discord's client with Developer Mode on: right-click the
|
||||
server name → Copy Server ID. The four uncommented variables are required —
|
||||
the backend refuses to start without them. `OWNER_DISCORD_ID` from §1 is the
|
||||
only Discord identity allowed to sign in while registration is closed.
|
||||
|
||||
```bash
|
||||
sed -i "s|^WEB_PASSWORD=.*|WEB_PASSWORD=$(openssl rand -base64 18)|" .env
|
||||
grep -E '^WEB_PASSWORD=' .env # this is what you type into the site
|
||||
```
|
||||
|
||||
3. Redeploy and check:
|
||||
4. Redeploy and check:
|
||||
|
||||
```bash
|
||||
docker compose -f docker-compose.yml -f docker-compose.prod.yml up -d --build
|
||||
curl -s -o /dev/null -w '%{http_code}\n' https://bookmark.violetcrown.my.id/
|
||||
```
|
||||
|
||||
Expected `200`, serving the login page.
|
||||
Expected `200`, serving the login page with the Discord button. Signing in
|
||||
lands on the library; an account outside the guild is refused with a message
|
||||
that names neither the guild nor its id.
|
||||
|
||||
Leaving `WEB_PASSWORD` unset is safe: the web routes are not registered and `/`
|
||||
returns 404. The userscript's API on `BOOKMARK_API_HOST` is unaffected either way.
|
||||
|
||||
`BOOKMARK_WEB_HOST` itself is required by the prod override regardless — like
|
||||
`BOOKMARK_API_HOST`, its Traefik label has no fallback, so `docker compose up`
|
||||
refuses to start without it even if `WEB_PASSWORD` is unset and the web UI is
|
||||
otherwise dormant.
|
||||
|
||||
Sessions are signed with a key derived from `API_TOKEN` and `WEB_PASSWORD`, so
|
||||
rotating either one logs every browser out. The session cookie lasts 60 days.
|
||||
Sessions are rows in the database: the cookie carries only an opaque id, and
|
||||
every request looks the row up and checks its expiry. Deleting a session row —
|
||||
or the whole `sessions` table — logs the browser out immediately; nothing is
|
||||
signed, so rotating `API_TOKEN` does not affect browser sessions. Sessions
|
||||
last 60 days.
|
||||
|
||||
---
|
||||
|
||||
|
||||
Reference in New Issue
Block a user