feat(10-01): harden the admin cookie session and prefix boot guards

- refresh and logout read the Bearer header first, then the summer_admin
  cookie; a cookie refresh rotates the cookie without a token in the body and
  logout always expires the cookie
- backend.cookie_secure (default true) may drop Secure outside production only
- activation rejects controller vendor segments api, assets, login, settings
- BuildRouter rejects non-cabana routes at or under the admin prefix
- SPA single-flights refresh on 401, replays once, and refreshes proactively
  at 80 percent of expires_in; dist rebuilt
- scripts/check-admin-dist.sh rebuilds the SPA and fails on dist drift
- tests: TestPhase10CookieAuth, TestPhase10CSRF, TestPhase10Prefix,
  TestPhase10AdminPrefixCollision, boardwalk serving and header tests
This commit is contained in:
Jakub Zych
2026-09-27 15:34:19 +02:00
parent 5f9353841b
commit dafdb18234
15 changed files with 1283 additions and 18 deletions

View File

@@ -43,6 +43,9 @@ type service struct {
bl bouncer.BlacklistStore
prefix string
spa http.Handler
// insecureCookie drops Secure from the admin cookie (backend.cookie_secure
// false, development only); the zero value keeps the cookie Secure.
insecureCookie bool
}
// adminPrefix returns the mount path; a zero service uses the default.
@@ -68,6 +71,9 @@ func Activate(app *backpack.App, plugins []party.Plugin) (*Routes, error) {
if len(items) == 0 {
return nil, nil
}
if err := checkReservedSegments(items); err != nil {
return nil, err
}
secret, err := adminSecret(app)
if err != nil {
return nil, err
@@ -76,6 +82,10 @@ func Activate(app *backpack.App, plugins []party.Plugin) (*Routes, error) {
if err != nil {
return nil, err
}
secureCookie, err := adminCookieSecure(app)
if err != nil {
return nil, err
}
reg, err := compileRegistry(items)
if err != nil {
return nil, err
@@ -118,6 +128,8 @@ func Activate(app *backpack.App, plugins []party.Plugin) (*Routes, error) {
issuer: adminIssuer(app, prefix),
bl: bl,
prefix: prefix,
insecureCookie: !secureCookie,
}
spa, err := boardwalk.Handler(prefix, http.HandlerFunc(writeNotFound))
if err != nil {