Files
Felis/cmd/felis/setup_panel.go
T
flyemoji 7860152f57 feat(auth)!: go fully passwordless and fix cross-check review findings
Remove password authentication everywhere; the only session doors are
passkey (WebAuthn), email OTP, in-game bind codes, QR scan-login, and
op-login vouching. Remediates the 33-finding cross-check review across
backend, CLI, panel, plugins, and docs.

Backend/CLI:
- Drop password routes and fields from account/user/onboard/auth
  handlers; align tests (new account subtests, naming reserves
  "console", op-login/onboard/qr-login test updates).
- Add migrations 0016_op_login.sql and 0017_drop_password.sql.
- Thread panel/admin hostnames from hostcfg through api.go,
  setup_panel.go, tui_root.go and tui_preflight.go instead of
  hardcoding; bootstrap.sh writes panel-hostname/admin-hostname
  into felis.toml.
- Reword breakglass and TUI copy for passwordless flows.

Panel:
- Delete the ChangePassword page and all password UI; align
  login/auth/api/types with the passwordless contract; add the
  migration and op-login approval flows.
- i18n: convert ImageBuildPage durations/status badges and
  ServerLuckPerms strings to translation keys; drop 72 orphan keys
  per locale; unify the title as "Felis - Console".

Plugins (all six rebuilt):
- Velocity waiting router returns 503 at_capacity during wake;
  MOTD/control-channel copy and config comments.
- Paper zh menu title; Limbo bind-code TTL 600s with panel_url
  preference; unified /link lines in fabric/forge/neoforge; shared
  link-client javadoc contract fixes.

Docs: openapi.yaml, sequence-diagrams.md, deploy/limbo/README.md and
plugins/README.md aligned with the implementation.

BREAKING CHANGE: migration 0017 irreversibly drops
users.password_hash and users.must_change_password; password login
cannot be restored after migrating.
2026-07-20 04:47:32 +09:00

109 lines
2.9 KiB
Go

package main
import (
"crypto/tls"
"encoding/json"
"fmt"
"net"
"net/http"
"net/url"
"os"
"strconv"
"strings"
"time"
)
const defaultPanelNodePort = 30443
type panelAccessResult struct {
url string
err error
}
func setupPanelNodePort() int {
raw := strings.TrimSpace(os.Getenv("FELIS_PANEL_NODEPORT"))
if raw == "" {
return defaultPanelNodePort
}
port, err := strconv.Atoi(raw)
if err != nil || port < 30000 || port > 32767 {
return defaultPanelNodePort
}
return port
}
func localPanelURL(rootDomain, adminHostname string) string {
if ip := rootDomainEmbeddedIP(rootDomain); ip != "" {
return fmt.Sprintf("https://%s:%d", ip, setupPanelNodePort())
}
host := defaultAdminHostname(rootDomain, adminHostname)
if host == "" {
return ""
}
return fmt.Sprintf("https://%s:%d", host, setupPanelNodePort())
}
func rootDomainEmbeddedIP(rootDomain string) string {
domain := strings.TrimSpace(strings.TrimSuffix(rootDomain, "."))
for _, suffix := range []string{".nip.io", ".sslip.io"} {
base := strings.TrimSuffix(domain, suffix)
if base == domain {
continue
}
if ip := net.ParseIP(base); ip != nil {
return ip.String()
}
}
return ""
}
func localPanelOrigin() string {
return fmt.Sprintf("https://127.0.0.1:%d", setupPanelNodePort())
}
func checkPanelAccess(rootDomain, adminHostname string) panelAccessResult {
base := localPanelURL(rootDomain, adminHostname)
if base == "" {
return panelAccessResult{err: fmt.Errorf("root domain is empty")}
}
hostURL, err := url.Parse(base)
if err != nil {
return panelAccessResult{url: base, err: err}
}
probeBase := fmt.Sprintf("https://127.0.0.1:%d", setupPanelNodePort())
client := &http.Client{
Timeout: 8 * time.Second,
Transport: &http.Transport{TLSClientConfig: &tls.Config{InsecureSkipVerify: true}}, //nolint:gosec
}
for _, target := range []string{probeBase + "/healthz", probeBase + "/", probeBase + "/config.json"} {
req, err := http.NewRequest(http.MethodGet, target, nil)
if err != nil {
return panelAccessResult{url: base, err: err}
}
req.Host = hostURL.Hostname()
resp, err := client.Do(req)
if err != nil {
return panelAccessResult{url: base, err: err}
}
if resp.Body != nil {
defer resp.Body.Close()
}
if resp.StatusCode < 200 || resp.StatusCode >= 300 {
return panelAccessResult{url: base, err: fmt.Errorf("%s returned HTTP %d", target, resp.StatusCode)}
}
if strings.HasSuffix(target, "/config.json") {
var cfg struct {
APIBase string `json:"apiBase"`
RootDomain string `json:"rootDomain"`
}
if err := json.NewDecoder(resp.Body).Decode(&cfg); err != nil {
return panelAccessResult{url: base, err: fmt.Errorf("decode config.json: %w", err)}
}
if cfg.APIBase != "/api/v1" || cfg.RootDomain == "" {
return panelAccessResult{url: base, err: fmt.Errorf("config.json is incomplete")}
}
}
}
return panelAccessResult{url: base}
}