diff --git a/.env.template b/.env.template index 5a7cce8d..43ed914f 100644 --- a/.env.template +++ b/.env.template @@ -180,7 +180,7 @@ ## Defaults to every minute. Set blank to disable this job. # AUTH_REQUEST_PURGE_SCHEDULE="30 * * * * *" ## -## Cron schedule of the job that cleans expired Duo contexts from the database. Does nothing if Duo MFA is disabled or set to use the legacy iframe prompt. +## Cron schedule of the job that cleans expired Duo contexts from the database. Does nothing if Duo MFA is disabled. ## Defaults to every minute. Set blank to disable this job. # DUO_CONTEXT_PURGE_SCHEDULE="30 * * * * *" # @@ -391,23 +391,10 @@ ## The following flags are available: ## - "pm-5594-safari-account-switching": Enable account switching in Safari. (Safari >= 2026.2.0) ## - "pm-32413-multi-client-password-management": Enable changing the master password directly in the client. (Desktop/Extension >= 2026.4.0) -## - "ssh-agent": Enable SSH agent support on Desktop. (Desktop >= 2024.12.0) ## - "ssh-agent-v2": Enable newer SSH agent support. (Desktop >= 2026.2.1) -## - "ssh-key-vault-item": Enable the creation and use of SSH key vault items. (Clients >= 2024.12.0) -## - "pm-25373-windows-biometrics-v2": Enable the new implementation of biometrics on Windows. (Desktop >= 2025.11.0) -## - "pm-26340-linux-biometrics-v2": Enable the new implementation of biometrics on Linux. (Desktop >= 2025.11.0) -## - "anon-addy-self-host-alias": Enable configuring self-hosted Anon Addy alias generator. (Android >= 2025.3.0, iOS >= 2025.4.0) -## - "simple-login-self-host-alias": Enable configuring self-hosted Simple Login alias generator. (Android >= 2025.3.0, iOS >= 2025.4.0) -## - "mutual-tls": Enable the use of mutual TLS on Android (Clients >= 2025.2.0) -## - "cxp-import-mobile": Enable the import via CXP on iOS (Clients >= 2025.9.2) -## - "cxp-export-mobile": Enable the export via CXP on iOS (Clients >= 2025.9.2) ## - "pm-30529-webauthn-related-origins": ## - "pm-32009-new-item-types": Enable new item types: Bank Account, Driver's License, and Passport (Clients >= 2026.4.0) ## - "pm-34171-card-scanner": Enable the new card scanner feature on mobile (Android >= 2026.4.1, iOS >= 2026.4.1) -## - "desktop-ui-migration-milestone-1": Special feature flag for desktop UI (Desktop >= 2026.2.0) -## - "desktop-ui-migration-milestone-2": Special feature flag for desktop UI (Desktop >= 2026.2.0) -## - "desktop-ui-migration-milestone-3": Special feature flag for desktop UI (Desktop >= 2026.2.0) -## - "desktop-ui-migration-milestone-4": Special feature flag for desktop UI (Desktop >= 2026.2.0) ## - "enable-basic-auth-response": Enable HTTP Basic Auth autofill in the browser extension (Browser >= 2026.9.0) ## - "undetermined-cipher-scenario-logic": Enable the rewritten add/update login notification triggering logic in the browser extension (Browser >= 2026.2.0) # EXPERIMENTAL_CLIENT_FEATURE_FLAGS= @@ -588,11 +575,6 @@ # DUO_HOST= ## After that, you should be able to follow the rest of the guide linked above, ## ignoring the fields that ask for the values that you already configured beforehand. -## -## If you want to attempt to use Duo's 'Traditional Prompt' (deprecated, iframe based) set DUO_USE_IFRAME to 'true'. -## Duo no longer supports this, but it still works for some integrations. -## If you aren't sure, leave this alone. -# DUO_USE_IFRAME=false ## Email 2FA settings ## Email token size diff --git a/src/api/admin.rs b/src/api/admin.rs index 69c018ee..2a84f611 100644 --- a/src/api/admin.rs +++ b/src/api/admin.rs @@ -508,6 +508,7 @@ async fn enable_user(user_id: UserId, _token: AdminToken, conn: DbConn) -> Empty async fn remove_2fa(user_id: UserId, token: AdminToken, conn: DbConn) -> EmptyResult { let mut user = get_user_or_404(&user_id, &conn).await?; TwoFactor::delete_all_by_user(&user.uuid, &conn).await?; + Device::clear_twofactor_remember_by_user(&user.uuid, &conn).await?; two_factor::enforce_2fa_policy(&user, &ACTING_ADMIN_USER.into(), 14, &token.ip.ip, &conn).await?; user.totp_recover = None; user.save(&conn).await diff --git a/src/api/core/accounts.rs b/src/api/core/accounts.rs index a6787da0..930107c9 100644 --- a/src/api/core/accounts.rs +++ b/src/api/core/accounts.rs @@ -59,7 +59,6 @@ pub fn routes() -> Vec { delete_account, revision_date, password_hint, - post_prelogin, verify_password, post_api_key, rotate_api_key, @@ -106,11 +105,8 @@ pub struct RegisterData { master_password_hint: Option, - name: Option, - organization_user_id: Option, - // Used only from the register/finish endpoint email_verification_token: Option, accept_emergency_access_id: Option, accept_emergency_access_invite_token: Option, @@ -163,7 +159,9 @@ struct RegisterDataOld { #[derive(Debug, Deserialize)] #[serde(rename_all = "camelCase")] struct RegisterDataCur { + #[serde(alias = "MasterPasswordAuthentication")] master_password_authentication: MasterPasswordAuthentication, + #[serde(alias = "MasterPasswordUnlock")] master_password_unlock: MasterPasswordUnlock, } @@ -197,10 +195,12 @@ struct KeysData { #[derive(Debug, Deserialize)] #[serde(rename_all = "camelCase")] pub struct MasterPasswordAuthentication { + #[serde(alias = "Kdf")] kdf: KDFData, + #[serde(alias = "Salt")] salt: String, - #[serde(alias = "masterPasswordAuthenticationHash")] + #[serde(alias = "masterPasswordAuthenticationHash", alias = "MasterPasswordAuthenticationHash")] hash: String, } @@ -257,12 +257,11 @@ async fn is_email_2fa_required(member_id: Option, conn: &DbConn) - false } -pub async fn register(data: Json, email_verification: bool, conn: DbConn) -> JsonResult { - let mut data: RegisterData = data.into_inner(); +pub async fn register(data: Json, conn: DbConn) -> JsonResult { + let data: RegisterData = data.into_inner(); let email = data.email.to_lowercase(); - let mut email_verified = false; - + let mut name = None; let mut pending_emergency_access = None; if data.unprocessable() { @@ -270,69 +269,65 @@ pub async fn register(data: Json, email_verification: bool, conn: } // First, validate the provided verification tokens - if email_verification { - match ( - &data.email_verification_token, - &data.accept_emergency_access_id, - &data.accept_emergency_access_invite_token, - &data.organization_user_id, - &data.org_invite_token, - ) { - // Normal user registration, when email verification is required - (Some(email_verification_token), None, None, None, None) => { - let claims = crate::auth::decode_register_verify(email_verification_token)?; - if claims.sub != data.email { - err!("Email verification token does not match email"); - } - - // During this call we don't get the name, so extract it from the claims - if claims.name.is_some() { - data.name = claims.name; - } - email_verified = claims.verified; + let mut email_verified = match ( + &data.email_verification_token, + &data.accept_emergency_access_id, + &data.accept_emergency_access_invite_token, + &data.organization_user_id, + &data.org_invite_token, + ) { + // Normal user registration, when email verification is required + (Some(email_verification_token), None, None, None, None) => { + let claims = crate::auth::decode_register_verify(email_verification_token)?; + if claims.sub != data.email { + err!("Email verification token does not match email"); } - // Emergency access registration - (None, Some(accept_emergency_access_id), Some(accept_emergency_access_invite_token), None, None) => { - if !CONFIG.emergency_access_allowed() { - err!("Emergency access is not enabled.") - } - let claims = crate::auth::decode_emergency_access_invite(accept_emergency_access_invite_token)?; + // During this call we don't get the name, so extract it from the claims + name = claims.name; + claims.verified + } + // Emergency access registration + (None, Some(accept_emergency_access_id), Some(accept_emergency_access_invite_token), None, None) => { + if !CONFIG.emergency_access_allowed() { + err!("Emergency access is not enabled.") + } - if claims.email != data.email { - err!("Claim email does not match email") - } - if &claims.emer_id != accept_emergency_access_id { - err!("Claim emer_id does not match accept_emergency_access_id") - } + let claims = crate::auth::decode_emergency_access_invite(accept_emergency_access_invite_token)?; - pending_emergency_access = Some((accept_emergency_access_id, claims)); - email_verified = true; + if claims.email != data.email { + err!("Claim email does not match email") + } + if &claims.emer_id != accept_emergency_access_id { + err!("Claim emer_id does not match accept_emergency_access_id") } - // Org invite - (None, None, None, Some(organization_user_id), Some(org_invite_token)) => { - let claims = decode_invite(org_invite_token)?; - - if claims.email != data.email { - err!("Claim email does not match email") - } - if &claims.member_id != organization_user_id { - err!("Claim org_user_id does not match organization_user_id") - } + pending_emergency_access = Some((accept_emergency_access_id, claims)); + true + } + // Org invite + (None, None, None, Some(organization_user_id), Some(org_invite_token)) => { + let claims = decode_invite(org_invite_token)?; - email_verified = true; + if claims.email != data.email { + err!("Claim email does not match email") } - _ => { - err!("Registration is missing required parameters") + if &claims.member_id != organization_user_id { + err!("Claim org_user_id does not match organization_user_id") } + + true } - } + + _ => { + err!("Registration is missing required parameters") + } + }; // Check if the length of the username exceeds 50 characters (Same is Upstream Bitwarden) // This also prevents issues with very long usernames causing to large JWT's. See #2419 - if let Some(ref name) = data.name + if let Some(ref name) = name && name.len() > 50 { err!("The field Name must be a string with a maximum length of 50."); @@ -394,7 +389,7 @@ pub async fn register(data: Json, email_verification: bool, conn: user.password_hint = password_hint; // Add extra fields if present - if let Some(name) = data.name { + if let Some(name) = name { user.name = name; } @@ -432,8 +427,7 @@ pub async fn register(data: Json, email_verification: bool, conn: } Ok(Json(json!({ - "object": "register", - "captchaBypassToken": "", + "object": "registerFinish", }))) } @@ -442,7 +436,7 @@ async fn post_set_password(data: Json, headers: Headers, conn: let data: SetPasswordData = data.into_inner(); let mut user = headers.user; - if user.private_key.is_some() { + if user.private_key.is_some() || !user.password_hash.is_empty() { err!("Account already initialized, cannot set password") } @@ -496,7 +490,6 @@ async fn post_set_password(data: Json, headers: Headers, conn: Ok(Json(json!({ "object": "set-password", - "captchaBypassToken": "", }))) } @@ -581,6 +574,10 @@ async fn post_keys(data: Json, headers: Headers, conn: DbConn) -> Json let mut user = headers.user; + if user.private_key.is_some() || user.public_key.is_some() { + err!("User has existing keypair") + } + user.private_key = Some(data.encrypted_private_key); user.public_key = Some(data.public_key); @@ -702,8 +699,11 @@ fn set_kdf_data(user: &mut User, data: &KDFData) -> EmptyResult { #[derive(Deserialize)] #[serde(rename_all = "camelCase")] struct AuthenticationData { + #[serde(alias = "Salt")] salt: String, + #[serde(alias = "Kdf")] kdf: KDFData, + #[serde(alias = "MasterPasswordAuthenticationHash")] master_password_authentication_hash: String, } @@ -1360,11 +1360,6 @@ pub struct PreloginData { email: String, } -#[post("/accounts/prelogin", data = "")] -async fn post_prelogin(data: Json, ip: ClientIp, conn: DbConn) -> JsonResult { - prelogin(data, ip, conn).await -} - pub async fn prelogin(data: Json, ip: ClientIp, conn: DbConn) -> JsonResult { crate::ratelimit::check_limit_unauthenticated(&ip.ip)?; @@ -1856,3 +1851,62 @@ pub async fn purge_auth_requests(pool: DbPool) { error!("Failed to get DB connection while purging auth requests"); } } + +#[cfg(test)] +mod tests { + use super::*; + + #[test] + fn test_register_data_current_format() { + // Web and iOS since the master password authentication/unlock split + let data: RegisterData = serde_json::from_str( + r#"{ + "email": "user@example.com", + "emailVerificationToken": "token", + "userAsymmetricKeys": {"publicKey": "pub", "encryptedPrivateKey": "priv"}, + "masterPasswordAuthentication": { + "kdf": {"kdfType": 0, "iterations": 600000}, + "salt": "user@example.com", + "masterPasswordAuthenticationHash": "hash" + }, + "masterPasswordUnlock": { + "kdf": {"kdfType": 0, "iterations": 600000}, + "salt": "user@example.com", + "masterKeyWrappedUserKey": "key" + } + }"#, + ) + .unwrap(); + + assert!(!data.unprocessable()); + assert_eq!(data.hash(), "hash"); + assert_eq!(data.key(), "key"); + assert_eq!(data.kdf().kdf_iterations, 600_000); + assert!(data.keys.is_some()); + assert_eq!(data.email_verification_token.as_deref(), Some("token")); + } + + #[test] + fn test_register_data_flat_format() { + // Android before 2026.9.0 + let data: RegisterData = serde_json::from_str( + r#"{ + "email": "user@example.com", + "emailVerificationToken": "token", + "masterPasswordHash": "hash", + "masterPasswordHint": null, + "userSymmetricKey": "key", + "userAsymmetricKeys": {"publicKey": "pub", "encryptedPrivateKey": "priv"}, + "kdf": 0, + "kdfIterations": 600000 + }"#, + ) + .unwrap(); + + assert!(!data.unprocessable()); + assert_eq!(data.hash(), "hash"); + assert_eq!(data.key(), "key"); + assert_eq!(data.kdf().kdf_iterations, 600_000); + assert!(data.keys.is_some()); + } +} diff --git a/src/api/core/ciphers.rs b/src/api/core/ciphers.rs index a8c6aea0..5010bd92 100644 --- a/src/api/core/ciphers.rs +++ b/src/api/core/ciphers.rs @@ -1869,7 +1869,7 @@ async fn delete_cipher_by_uuid( #[derive(Deserialize)] #[serde(rename_all = "camelCase")] struct CipherIdsData { - ids: Vec, + ids: HashSet, } async fn delete_multiple_ciphers( diff --git a/src/api/core/organizations.rs b/src/api/core/organizations.rs index 4a3ddcb9..f64b8c53 100644 --- a/src/api/core/organizations.rs +++ b/src/api/core/organizations.rs @@ -15,10 +15,10 @@ use crate::{ db::{ DbConn, models::{ - Cipher, CipherId, Collection, CollectionCipher, CollectionGroup, CollectionId, CollectionUser, EventType, - Group, GroupId, GroupUser, Invitation, Membership, MembershipId, MembershipStatus, MembershipType, - OrgPolicy, OrgPolicyType, Organization, OrganizationApiKey, OrganizationId, TwoFactor, TwoFactorType, User, - UserId, + Cipher, CipherId, Collection, CollectionCipher, CollectionGroup, CollectionId, CollectionUser, Device, + EventType, Group, GroupId, GroupUser, Invitation, Membership, MembershipId, MembershipStatus, + MembershipType, OrgPolicy, OrgPolicyType, Organization, OrganizationApiKey, OrganizationId, TwoFactor, + TwoFactorType, User, UserId, }, }, mail, @@ -31,7 +31,6 @@ pub fn routes() -> Vec { get_organization, create_organization, delete_organization, - post_delete_organization, leave_organization, get_user_collections, get_org_collections, @@ -39,13 +38,10 @@ pub fn routes() -> Vec { get_org_collection_detail, get_collection_users, put_organization, - post_organization, post_organization_collections, post_bulk_access_collections, - post_organization_collection_update, put_organization_collection_update, delete_organization_collection, - post_organization_collection_delete, bulk_delete_organization_collections, post_bulk_collections, get_org_details, @@ -60,7 +56,6 @@ pub fn routes() -> Vec { get_org_user_mini_details, get_user, edit_member, - put_member, delete_member, bulk_delete_member, post_org_import, @@ -70,7 +65,6 @@ pub fn routes() -> Vec { get_master_password_policy, get_policy, put_policy, - put_policy_vnext, get_plans, post_org_keys, get_organization_keys, @@ -86,22 +80,16 @@ pub fn routes() -> Vec { post_groups, get_group, put_group, - post_group, get_group_details, delete_group, - post_delete_group, bulk_delete_groups, get_group_members, - put_group_members, - post_delete_group_member, put_reset_password_enrollment, get_reset_password_details, - put_reset_password, put_recover_account, get_org_export, post_api_key, rotate_api_key, - get_billing_metadata, get_billing_warnings, get_auto_enroll_status, get_self_host_billing_metadata, @@ -245,16 +233,6 @@ async fn delete_organization( } } -#[post("/organizations//delete", data = "")] -async fn post_delete_organization( - org_id: OrganizationId, - data: Json, - headers: OwnerHeaders, - conn: DbConn, -) -> EmptyResult { - delete_organization(org_id, data, headers, conn).await -} - #[post("/organizations//leave")] async fn leave_organization(org_id: OrganizationId, headers: OrgMemberHeaders, conn: DbConn) -> EmptyResult { if headers.membership.status != MembershipStatus::Confirmed as i32 { @@ -300,16 +278,6 @@ async fn put_organization( headers: OwnerHeaders, data: Json, conn: DbConn, -) -> JsonResult { - post_organization(org_id, headers, data, conn).await -} - -#[post("/organizations/", data = "")] -async fn post_organization( - org_id: OrganizationId, - headers: OwnerHeaders, - data: Json, - conn: DbConn, ) -> JsonResult { if org_id != headers.org_id { err!("Organization not found", "Organization id's do not match"); @@ -640,17 +608,6 @@ async fn put_organization_collection_update( headers: ManagerHeaders, data: Json, conn: DbConn, -) -> JsonResult { - post_organization_collection_update(org_id, col_id, headers, data, conn).await -} - -#[post("/organizations//collections/", data = "", rank = 2)] -async fn post_organization_collection_update( - org_id: OrganizationId, - col_id: CollectionId, - headers: ManagerHeaders, - data: Json, - conn: DbConn, ) -> JsonResult { if org_id != headers.org_id { err!("Organization not found", "Organization id's do not match"); @@ -746,16 +703,6 @@ async fn delete_organization_collection( delete_organization_collection_impl(&org_id, &col_id, &headers, &conn).await } -#[post("/organizations//collections//delete")] -async fn post_organization_collection_delete( - org_id: OrganizationId, - col_id: CollectionId, - headers: ManagerHeaders, - conn: DbConn, -) -> EmptyResult { - delete_organization_collection_impl(&org_id, &col_id, &headers, &conn).await -} - #[derive(Deserialize, Debug)] #[serde(rename_all = "camelCase")] struct BulkCollectionIds { @@ -1532,17 +1479,6 @@ struct EditUserData { } #[put("/organizations//users/", data = "", rank = 1)] -async fn put_member( - org_id: OrganizationId, - member_id: MembershipId, - data: Json, - headers: AdminHeaders, - conn: DbConn, -) -> EmptyResult { - edit_member(org_id, member_id, data, headers, conn).await -} - -#[post("/organizations//users/", data = "", rank = 1)] async fn edit_member( org_id: OrganizationId, member_id: MembershipId, @@ -1922,7 +1858,7 @@ async fn post_org_import( #[serde(rename_all = "camelCase")] struct BulkCollectionsData { organization_id: OrganizationId, - cipher_ids: Vec, + cipher_ids: HashSet, collection_ids: HashSet, remove_collections: bool, } @@ -2201,18 +2137,6 @@ async fn put_policy( Ok(Json(policy.to_json())) } -// Deprecated with client v2026.5.0 -#[put("/organizations//policies//vnext", data = "")] -async fn put_policy_vnext( - org_id: OrganizationId, - pol_type: i32, - data: Json, - headers: AdminHeaders, - conn: DbConn, -) -> JsonResult { - put_policy(org_id, pol_type, data, headers, conn).await -} - #[get("/plans")] fn get_plans() -> Json { // Respond with a minimal json just enough to allow the creation of an new organization. @@ -2241,12 +2165,6 @@ fn get_plans() -> Json { })) } -#[get("/organizations/<_org_id>/billing/metadata")] -fn get_billing_metadata(_org_id: OrganizationId, _headers: OrgMemberHeaders) -> Json { - // Prevent a 404 error, which also causes Javascript errors. - Json(empty_data_json()) -} - #[get("/organizations/<_org_id>/billing/vnext/warnings")] fn get_billing_warnings(_org_id: OrganizationId, _headers: OrgMemberHeaders) -> Json { Json(json!({ @@ -2266,14 +2184,6 @@ fn get_self_host_billing_metadata(_org_id: OrganizationId, _headers: OrgMemberHe })) } -fn empty_data_json() -> Value { - json!({ - "object": "list", - "data": [], - "continuationToken": null - }) -} - #[derive(Deserialize, Debug)] #[serde(rename_all = "camelCase")] struct BulkRevokeMembershipIds { @@ -2592,17 +2502,6 @@ impl CollectionData { } } -#[post("/organizations//groups/", data = "")] -async fn post_group( - org_id: OrganizationId, - group_id: GroupId, - data: Json, - headers: AdminHeaders, - conn: DbConn, -) -> JsonResult { - put_group(org_id, group_id, data, headers, conn).await -} - #[post("/organizations//groups", data = "")] async fn post_groups( org_id: OrganizationId, @@ -2712,7 +2611,6 @@ async fn add_update_group( "id": group.uuid, "organizationId": group.organizations_uuid, "name": group.name, - "accessAll": group.access_all, "externalId": group.external_id, "object": "group" }))) @@ -2739,16 +2637,6 @@ async fn get_group_details( Ok(Json(group.to_json_details(&conn).await)) } -#[post("/organizations//groups//delete")] -async fn post_delete_group( - org_id: OrganizationId, - group_id: GroupId, - headers: AdminHeaders, - conn: DbConn, -) -> EmptyResult { - delete_group_impl(&org_id, &group_id, &headers, &conn).await -} - #[delete("/organizations//groups/")] async fn delete_group(org_id: OrganizationId, group_id: GroupId, headers: AdminHeaders, conn: DbConn) -> EmptyResult { delete_group_impl(&org_id, &group_id, &headers, &conn).await @@ -2850,90 +2738,6 @@ async fn get_group_members( Ok(Json(json!(group_members))) } -#[put("/organizations//groups//users", data = "")] -async fn put_group_members( - org_id: OrganizationId, - group_id: GroupId, - headers: AdminHeaders, - data: Json>, - conn: DbConn, -) -> EmptyResult { - if org_id != headers.org_id { - err!("Organization not found", "Organization id's do not match"); - } - if !CONFIG.org_groups_enabled() { - err!("Group support is disabled"); - } - - if Group::find_by_uuid_and_org(&group_id, &org_id, &conn).await.is_none() { - err!("Group could not be found!", "Group uuid is invalid or does not belong to the organization") - } - - let assigned_members = data.into_inner(); - - let org_memberships = Membership::find_by_org(&org_id, &conn).await; - let org_membership_ids: HashSet<&MembershipId> = org_memberships.iter().map(|m| &m.uuid).collect(); - if let Some(e) = assigned_members.iter().find(|m| !org_membership_ids.contains(m)) { - err!("Invalid member", format!("Member {} does not belong to organization {}!", e, org_id)) - } - - GroupUser::delete_all_by_group(&group_id, &org_id, &conn).await?; - for assigned_member in assigned_members { - let mut user_entry = GroupUser::new(group_id.clone(), assigned_member.clone()); - user_entry.save(&conn).await?; - - log_event( - EventType::OrganizationUserUpdatedGroups, - &assigned_member, - &org_id, - &headers.user.uuid, - headers.device.atype, - &headers.ip.ip, - &conn, - ) - .await; - } - - Ok(()) -} - -#[post("/organizations//groups//delete-user/")] -async fn post_delete_group_member( - org_id: OrganizationId, - group_id: GroupId, - member_id: MembershipId, - headers: AdminHeaders, - conn: DbConn, -) -> EmptyResult { - if org_id != headers.org_id { - err!("Organization not found", "Organization id's do not match"); - } - if !CONFIG.org_groups_enabled() { - err!("Group support is disabled"); - } - - if Membership::find_by_uuid_and_org(&member_id, &org_id, &conn).await.is_none() { - err!("User could not be found or does not belong to the organization."); - } - - if Group::find_by_uuid_and_org(&group_id, &org_id, &conn).await.is_none() { - err!("Group could not be found or does not belong to the organization."); - } - - log_event( - EventType::OrganizationUserUpdatedGroups, - &member_id, - &org_id, - &headers.user.uuid, - headers.device.atype, - &headers.ip.ip, - &conn, - ) - .await; - - GroupUser::delete_by_group_and_member(&group_id, &member_id, &conn).await -} - #[derive(Deserialize)] #[serde(rename_all = "camelCase")] struct OrganizationUserResetPasswordEnrollmentRequest { @@ -2993,19 +2797,6 @@ async fn put_recover_account( recover_account(org_id, member_id, headers, data.into_inner(), conn, nt).await } -// Deprecated since `v2026.4.2` -#[put("/organizations//users//reset-password", data = "")] -async fn put_reset_password( - org_id: OrganizationId, - member_id: MembershipId, - headers: AdminHeaders, - data: Json, - conn: DbConn, - nt: Notify<'_>, -) -> EmptyResult { - recover_account(org_id, member_id, headers, data.into_inner(), conn, nt).await -} - async fn recover_account( org_id: OrganizationId, member_id: MembershipId, @@ -3072,6 +2863,7 @@ async fn recover_account( if req.reset_two_factor { TwoFactor::delete_all_by_user(&user.uuid, &conn).await?; + Device::clear_twofactor_remember_by_user(&user.uuid, &conn).await?; if !fallback_2fa_email || two_factor::email::find_and_activate_email_2fa(&user.uuid, &conn).await.is_err() { two_factor::enforce_2fa_policy(&user, &headers.user.uuid, headers.device.atype, &headers.ip.ip, &conn) .await?; @@ -3240,7 +3032,7 @@ async fn api_key( org_id: &OrganizationId, data: Json, rotate: bool, - headers: AdminHeaders, + headers: OwnerHeaders, conn: DbConn, ) -> JsonResult { if org_id != &headers.org_id { @@ -3249,7 +3041,7 @@ async fn api_key( let data: PasswordOrOtpData = data.into_inner(); let user = headers.user; - // Validate the admin users password/otp + // Validate the owner users password/otp data.validate(&user, true, &conn).await?; let org_api_key = if let Some(mut org_api_key) = OrganizationApiKey::find_by_org_uuid(org_id, &conn).await { @@ -3277,7 +3069,7 @@ async fn api_key( async fn post_api_key( org_id: OrganizationId, data: Json, - headers: AdminHeaders, + headers: OwnerHeaders, conn: DbConn, ) -> JsonResult { api_key(&org_id, data, false, headers, conn).await @@ -3287,7 +3079,7 @@ async fn post_api_key( async fn rotate_api_key( org_id: OrganizationId, data: Json, - headers: AdminHeaders, + headers: OwnerHeaders, conn: DbConn, ) -> JsonResult { api_key(&org_id, data, true, headers, conn).await diff --git a/src/api/core/two_factor/authenticator.rs b/src/api/core/two_factor/authenticator.rs index 692e8248..99b5c67c 100644 --- a/src/api/core/two_factor/authenticator.rs +++ b/src/api/core/two_factor/authenticator.rs @@ -7,7 +7,7 @@ use crate::{ crypto, db::{ DbConn, - models::{EventType, TwoFactor, TwoFactorType, UserId}, + models::{Device, EventType, TwoFactor, TwoFactorType, UserId}, }, util::NumberOrString, }; @@ -200,6 +200,7 @@ async fn disable_authenticator(data: Json, headers: He if let Some(twofactor) = TwoFactor::find_by_user_and_type(&user.uuid, type_, &conn).await { if twofactor.data == data.key { twofactor.delete(&conn).await?; + Device::clear_twofactor_remember_by_user(&user.uuid, &conn).await?; log_user_event(EventType::UserDisabled2fa as i32, &user.uuid, headers.device.atype, &headers.ip.ip, &conn) .await; } else { diff --git a/src/api/core/two_factor/duo.rs b/src/api/core/two_factor/duo.rs index ed112eb9..860979ff 100644 --- a/src/api/core/two_factor/duo.rs +++ b/src/api/core/two_factor/duo.rs @@ -1,5 +1,4 @@ use chrono::Utc; -use data_encoding::BASE64; use rocket::{Route, serde::json::Json}; use crate::{ @@ -222,13 +221,6 @@ async fn duo_api_request(method: &str, path: &str, params: &str, data: &DuoData) Ok(()) } -const DUO_EXPIRE: i64 = 300; -const APP_EXPIRE: i64 = 3600; - -const AUTH_PREFIX: &str = "AUTH"; -const DUO_PREFIX: &str = "TX"; -const APP_PREFIX: &str = "APP"; - async fn get_user_duo_data(user_id: &UserId, conn: &DbConn) -> DuoStatus { let type_ = TwoFactorType::Duo as i32; @@ -251,118 +243,13 @@ async fn get_user_duo_data(user_id: &UserId, conn: &DbConn) -> DuoStatus { DuoStatus::Disabled(false) } -// let (ik, sk, ak, host) = get_duo_keys(); -pub(crate) async fn get_duo_keys_email(email: &str, conn: &DbConn) -> ApiResult<(String, String, String, String)> { +// let (ik, sk, host) = get_duo_keys_email(); +pub(crate) async fn get_duo_keys_email(email: &str, conn: &DbConn) -> ApiResult<(String, String, String)> { let data = match User::find_by_mail(email, conn).await { Some(u) => get_user_duo_data(&u.uuid, conn).await.data(), _ => DuoData::global(), } .map_res("Can't fetch Duo Keys")?; - Ok((data.ik, data.sk, CONFIG.get_duo_akey().await, data.host)) -} - -pub async fn generate_duo_signature(email: &str, conn: &DbConn) -> ApiResult<(String, String)> { - let now = Utc::now().timestamp(); - - let (ik, sk, ak, host) = get_duo_keys_email(email, conn).await?; - - let duo_sign = sign_duo_values(&sk, email, &ik, DUO_PREFIX, now + DUO_EXPIRE); - let app_sign = sign_duo_values(&ak, email, &ik, APP_PREFIX, now + APP_EXPIRE); - - Ok((format!("{duo_sign}:{app_sign}"), host)) -} - -fn sign_duo_values(key: &str, email: &str, ikey: &str, prefix: &str, expire: i64) -> String { - let val = format!("{email}|{ikey}|{expire}"); - let cookie = format!("{prefix}|{}", BASE64.encode(val.as_bytes())); - - format!("{cookie}|{}", crypto::hmac_sign(key, &cookie)) -} - -pub async fn validate_duo_login(email: &str, response: &str, conn: &DbConn) -> EmptyResult { - let split: Vec<&str> = response.split(':').collect(); - if split.len() != 2 { - err!( - "Invalid response length", - ErrorEvent { - event: EventType::UserFailedLogIn2fa - } - ); - } - - let auth_sig = split[0]; - let app_sig = split[1]; - - let now = Utc::now().timestamp(); - - let (ik, sk, ak, _host) = get_duo_keys_email(email, conn).await?; - - let auth_user = parse_duo_values(&sk, auth_sig, &ik, AUTH_PREFIX, now)?; - let app_user = parse_duo_values(&ak, app_sig, &ik, APP_PREFIX, now)?; - - if !crypto::ct_eq(&auth_user, app_user) || !crypto::ct_eq(&auth_user, email) { - err!( - "Error validating duo authentication", - ErrorEvent { - event: EventType::UserFailedLogIn2fa - } - ) - } - - Ok(()) -} - -fn parse_duo_values(key: &str, val: &str, ikey: &str, prefix: &str, time: i64) -> ApiResult { - let split: Vec<&str> = val.split('|').collect(); - if split.len() != 3 { - err!("Invalid value length") - } - - let u_prefix = split[0]; - let u_b64 = split[1]; - let u_sig = split[2]; - - let sig = crypto::hmac_sign(key, &format!("{u_prefix}|{u_b64}")); - - if !crypto::ct_eq(crypto::hmac_sign(key, &sig), crypto::hmac_sign(key, u_sig)) { - err!("Duo signatures don't match") - } - - if u_prefix != prefix { - err!("Prefixes don't match") - } - - let Ok(cookie_vec) = BASE64.decode(u_b64.as_bytes()) else { - err!("Invalid Duo cookie encoding") - }; - - let Ok(cookie) = String::from_utf8(cookie_vec) else { - err!("Invalid Duo cookie encoding") - }; - - let cookie_split: Vec<&str> = cookie.split('|').collect(); - if cookie_split.len() != 3 { - err!("Invalid cookie length") - } - - let username = cookie_split[0]; - let u_ikey = cookie_split[1]; - let expire = cookie_split[2]; - - if !crypto::ct_eq(ikey, u_ikey) { - err!("Invalid ikey") - } - - let expire: i64 = if let Ok(e) = expire.parse() { - e - } else { - err!("Invalid expire time") - }; - - if time >= expire { - err!("Expired authorization") - } - - Ok(username.into()) + Ok((data.ik, data.sk, data.host)) } diff --git a/src/api/core/two_factor/duo_oidc.rs b/src/api/core/two_factor/duo_oidc.rs index adb030af..e5e1df0f 100644 --- a/src/api/core/two_factor/duo_oidc.rs +++ b/src/api/core/two_factor/duo_oidc.rs @@ -383,7 +383,7 @@ pub async fn get_duo_auth_url( device_identifier: &DeviceId, conn: &DbConn, ) -> Result { - let (ik, sk, _, host) = get_duo_keys_email(email, conn).await?; + let (ik, sk, host) = get_duo_keys_email(email, conn).await?; let callback_url = match make_callback_url(client_id) { Ok(url) => url, @@ -435,7 +435,7 @@ pub async fn validate_duo_login( let code = split[0]; let state = split[1]; - let (ik, sk, _, host) = get_duo_keys_email(email, conn).await?; + let (ik, sk, host) = get_duo_keys_email(email, conn).await?; // Get the context by the state reported by the client. If we don't have one, // it means the context is either missing or expired. diff --git a/src/api/core/two_factor/email.rs b/src/api/core/two_factor/email.rs index 3667b871..836d1c47 100644 --- a/src/api/core/two_factor/email.rs +++ b/src/api/core/two_factor/email.rs @@ -65,7 +65,7 @@ async fn send_email_login(data: Json, client_headers: Client let Some(user) = User::find_by_mail(email, &conn).await else { err!( "Username or password is incorrect. Try again", - format!("IP: {}. Username: {email}.", client_headers.ip.ip) + format!("IP: {}. Username: {}.", client_headers.ip.ip, email.escape_debug()) ) }; @@ -74,7 +74,7 @@ async fn send_email_login(data: Json, client_headers: Client if !user.check_valid_password(master_password_hash) { err!( "Username or password is incorrect. Try again", - format!("IP: {}. Username: {email}.", client_headers.ip.ip) + format!("IP: {}. Username: {}.", client_headers.ip.ip, email.escape_debug()) ) } } else if let Some(auth_request_id) = auth_request_id { @@ -188,7 +188,7 @@ async fn send_email(data: Json, headers: Headers, conn: DbConn) - } let generated_token = crypto::generate_email_token(CONFIG.email_token_size()); - let twofactor_data = EmailTokenData::new(data.email, generated_token); + let twofactor_data = EmailTokenData::new(data.email, Some(generated_token)); // Uses EmailVerificationChallenge as type to show that it's not verified yet. let twofactor = TwoFactor::new(user.uuid, TwoFactorType::EmailVerificationChallenge, twofactor_data.to_json()); @@ -322,10 +322,10 @@ pub struct EmailTokenData { } impl EmailTokenData { - pub fn new(email: String, token: String) -> EmailTokenData { + pub fn new(email: String, token: Option) -> EmailTokenData { EmailTokenData { email, - last_token: Some(token), + last_token: token, token_sent: Utc::now().timestamp(), attempts: 0, } @@ -363,7 +363,8 @@ pub async fn activate_email_2fa(user: &User, conn: &DbConn) -> EmptyResult { if user.verified_at.is_none() { err!("Auto-enabling of email 2FA failed because the users email address has not been verified!"); } - let twofactor_data = EmailTokenData::new(user.email.clone(), String::new()); + // The token is set when the first code is sent + let twofactor_data = EmailTokenData::new(user.email.clone(), None); let twofactor = TwoFactor::new(user.uuid.clone(), TwoFactorType::Email, twofactor_data.to_json()); twofactor.save(conn).await } diff --git a/src/api/core/two_factor/mod.rs b/src/api/core/two_factor/mod.rs index 0eb6563e..14bdafd5 100644 --- a/src/api/core/two_factor/mod.rs +++ b/src/api/core/two_factor/mod.rs @@ -69,13 +69,7 @@ pub fn is_twofactor_provider_usable(provider_type: &TwoFactorType, provider_data } pub fn routes() -> Vec { - let mut routes = routes![ - get_twofactor, - get_recover, - disable_twofactor, - disable_twofactor_put, - get_device_verification_settings, - ]; + let mut routes = routes![get_twofactor, get_recover, disable_twofactor, get_device_verification_settings]; routes.append(&mut authenticator::routes()); routes.append(&mut duo::routes()); @@ -134,7 +128,7 @@ struct DisableTwoFactorData { r#type: NumberOrString, } -#[post("/two-factor/disable", data = "")] +#[put("/two-factor/disable", data = "")] async fn disable_twofactor(data: Json, headers: Headers, conn: DbConn) -> JsonResult { let data: DisableTwoFactorData = data.into_inner(); let user = headers.user; @@ -167,11 +161,6 @@ async fn disable_twofactor(data: Json, headers: Headers, c }))) } -#[put("/two-factor/disable", data = "")] -async fn disable_twofactor_put(data: Json, headers: Headers, conn: DbConn) -> JsonResult { - disable_twofactor(data, headers, conn).await -} - pub async fn enforce_2fa_policy( user: &User, act_user_id: &UserId, diff --git a/src/api/core/two_factor/webauthn.rs b/src/api/core/two_factor/webauthn.rs index 07b964e5..a3a9b21b 100644 --- a/src/api/core/two_factor/webauthn.rs +++ b/src/api/core/two_factor/webauthn.rs @@ -24,7 +24,7 @@ use crate::{ crypto::ct_eq, db::{ DbConn, - models::{EventType, TwoFactor, TwoFactorType, UserId}, + models::{Device, EventType, TwoFactor, TwoFactorType, UserId}, }, error::Error, util::NumberOrString, @@ -338,6 +338,7 @@ async fn delete_webauthn(data: Json, headers: Headers, conn: DbCo tf.data = serde_json::to_string(&data)?; tf.save(&conn).await?; drop(tf); + Device::clear_twofactor_remember_by_user(&headers.user.uuid, &conn).await?; // If entry is migrated from u2f, delete the u2f entry as well if let Some(mut u2f) = TwoFactor::find_by_user_and_type(&headers.user.uuid, TwoFactorType::U2f as i32, &conn).await diff --git a/src/api/identity.rs b/src/api/identity.rs index 6808ddde..702a0d0e 100644 --- a/src/api/identity.rs +++ b/src/api/identity.rs @@ -17,15 +17,14 @@ use crate::{ accounts::{PreloginData, RegisterData, kdf_upgrade, prelogin, register}, log_user_event, two_factor::{ - authenticator, duo, duo_oidc, email, enforce_2fa_policy, is_twofactor_provider_usable, webauthn, - yubikey, + authenticator, duo_oidc, email, enforce_2fa_policy, is_twofactor_provider_usable, webauthn, yubikey, }, }, master_password_policy, push::register_push_device, }, auth, - auth::{AuthMethod, ClientHeaders, ClientIp, ClientVersion, Secure, generate_organization_api_key_login_claims}, + auth::{AuthMethod, ClientHeaders, ClientIp, Secure, generate_organization_api_key_login_claims}, crypto, db::{ DbConn, @@ -46,7 +45,6 @@ pub fn routes() -> Vec { login, post_prelogin, prelogin_password, - identity_register, register_verification_email, register_finish, prevalidate, @@ -57,12 +55,7 @@ pub fn routes() -> Vec { } #[post("/connect/token", data = "")] -async fn login( - data: Form, - client_header: ClientHeaders, - client_version: Option, - conn: DbConn, -) -> JsonResult { +async fn login(data: Form, client_header: ClientHeaders, conn: DbConn) -> JsonResult { let data: ConnectData = data.into_inner(); let mut user_id: Option = None; @@ -83,7 +76,7 @@ async fn login( check_is_some(data.device_name.as_ref(), "device_name cannot be blank")?; check_is_some(data.device_type.as_ref(), "device_type cannot be blank")?; - password_login(data, &mut user_id, &conn, &client_header.ip, client_version.as_ref()).await + password_login(data, &mut user_id, &conn, &client_header.ip).await } "client_credentials" => { check_is_some(data.client_id.as_ref(), "client_id cannot be blank")?; @@ -105,7 +98,7 @@ async fn login( check_is_some(data.device_name.as_ref(), "device_name cannot be blank")?; check_is_some(data.device_type.as_ref(), "device_type cannot be blank")?; - sso_login(data, &mut user_id, &conn, &client_header.ip, client_version.as_ref()).await + sso_login(data, &mut user_id, &conn, &client_header.ip).await } "authorization_code" => err!("SSO sign-in is not available"), "send_access" => { @@ -190,13 +183,7 @@ async fn refresh_login(data: ConnectData, conn: &DbConn, ip: &ClientIp) -> JsonR } // After exchanging the code we need to check first if 2FA is needed before continuing -async fn sso_login( - data: ConnectData, - user_id: &mut Option, - conn: &DbConn, - ip: &ClientIp, - client_version: Option<&ClientVersion>, -) -> JsonResult { +async fn sso_login(data: ConnectData, user_id: &mut Option, conn: &DbConn, ip: &ClientIp) -> JsonResult { AuthMethod::Sso.check_scope(data.scope.as_ref())?; // Ratelimit the login @@ -353,7 +340,7 @@ async fn sso_login( Some((mut user, sso_user)) => { let mut device = get_device(&data, conn, &user).await?; - let twofactor_token = twofactor_auth(&mut user, &data, &mut device, ip, client_version, conn).await?; + let twofactor_token = twofactor_auth(&mut user, &data, &mut device, ip, conn).await?; if user.private_key.is_none() { // User was invited a stub was created @@ -385,13 +372,7 @@ async fn sso_login( authenticated_response(&user, &mut device, auth_tokens, twofactor_token, conn, ip).await } -async fn password_login( - data: ConnectData, - user_id: &mut Option, - conn: &DbConn, - ip: &ClientIp, - client_version: Option<&ClientVersion>, -) -> JsonResult { +async fn password_login(data: ConnectData, user_id: &mut Option, conn: &DbConn, ip: &ClientIp) -> JsonResult { // Validate scope AuthMethod::Password.check_scope(data.scope.as_ref())?; @@ -400,24 +381,14 @@ async fn password_login( // Get the user let username = data.username.as_ref().unwrap().trim(); + let log_username = username.escape_debug(); let Some(mut user) = User::find_by_mail(username, conn).await else { - err!("Username or password is incorrect. Try again", format!("IP: {}. Username: {username}.", ip.ip)) + err!("Username or password is incorrect. Try again", format!("IP: {}. Username: {log_username}.", ip.ip)) }; // Set the user_id here to be passed back used for event logging. *user_id = Some(user.uuid.clone()); - // Check if the user is disabled - if !user.enabled { - err!( - "This user has been disabled", - format!("IP: {}. Username: {username}.", ip.ip), - ErrorEvent { - event: EventType::UserFailedLogIn - } - ) - } - let password = data.password.as_ref().unwrap(); // If we get an auth request, we don't check the user's password, but the access code of the auth request @@ -425,7 +396,7 @@ async fn password_login( let Some(auth_request) = AuthRequest::find_by_uuid_and_user(auth_request_id, &user.uuid, conn).await else { err!( "Auth request not found. Try again.", - format!("IP: {}. Username: {username}.", ip.ip), + format!("IP: {}. Username: {log_username}.", ip.ip), ErrorEvent { event: EventType::UserFailedLogIn, } @@ -443,7 +414,7 @@ async fn password_login( { err!( "Username or access code is incorrect. Try again", - format!("IP: {}. Username: {username}.", ip.ip), + format!("IP: {}. Username: {log_username}.", ip.ip), ErrorEvent { event: EventType::UserFailedLogIn, } @@ -452,13 +423,24 @@ async fn password_login( } else if !user.check_valid_password(password) { err!( "Username or password is incorrect. Try again", - format!("IP: {}. Username: {username}.", ip.ip), + format!("IP: {}. Username: {log_username}.", ip.ip), ErrorEvent { event: EventType::UserFailedLogIn, } ) } + // Check if the user is disabled + if !user.enabled { + err!( + "This user has been disabled", + format!("IP: {}. Username: {log_username}.", ip.ip), + ErrorEvent { + event: EventType::UserFailedLogIn + } + ) + } + // Change the KDF Iterations (only when not logging in with an auth request) if data.auth_request.is_none() { kdf_upgrade(&mut user, password, conn).await?; @@ -491,7 +473,7 @@ async fn password_login( // We still want the login to fail until they actually verified the email address err!( "Please verify your email before trying again.", - format!("IP: {}. Username: {username}.", ip.ip), + format!("IP: {}. Username: {log_username}.", ip.ip), ErrorEvent { event: EventType::UserFailedLogIn } @@ -500,7 +482,7 @@ async fn password_login( let mut device = get_device(&data, conn, &user).await?; - let twofactor_token = twofactor_auth(&mut user, &data, &mut device, ip, client_version, conn).await?; + let twofactor_token = twofactor_auth(&mut user, &data, &mut device, ip, conn).await?; let auth_tokens = auth::AuthTokens::new(&device, &user, AuthMethod::Password, data.client_id); @@ -583,7 +565,6 @@ async fn authenticated_response( "KdfIterations": user.client_kdf_iter, "KdfMemory": user.client_kdf_memory, "KdfParallelism": user.client_kdf_parallelism, - "ResetMasterPassword": false, // TODO: Same as above "ForcePasswordReset": false, "MasterPasswordPolicy": master_password_policy, "scope": auth_tokens.scope(), @@ -737,7 +718,6 @@ async fn user_api_key_login( "KdfIterations": user.client_kdf_iter, "KdfMemory": user.client_kdf_memory, "KdfParallelism": user.client_kdf_parallelism, - "ResetMasterPassword": false, // TODO: according to official server seems something like: user.password_hash.is_empty(), but would need testing "ForcePasswordReset": false, "scope": AuthMethod::UserApiKey.scope(), "AccountKeys": account_keys, @@ -803,7 +783,6 @@ async fn twofactor_auth( data: &ConnectData, device: &mut Device, ip: &ClientIp, - client_version: Option<&ClientVersion>, conn: &DbConn, ) -> ApiResult> { let twofactors = TwoFactor::find_by_user(&user.uuid, conn).await; @@ -832,17 +811,12 @@ async fn twofactor_auth( if ![TwoFactorType::Remember as i32, TwoFactorType::RecoveryCode as i32].contains(&selected_id) && !twofactor_ids.contains(&selected_id) { - err_json!( - json_err_twofactor(&twofactor_ids, &user.uuid, data, client_version, conn).await?, - "Invalid two factor provider" - ) + err_json!(json_err_twofactor(&twofactor_ids, &user.uuid, data, conn).await?, "Invalid two factor provider") } - let Some(ref twofactor_code) = data.two_factor_token else { - err_json!( - json_err_twofactor(&twofactor_ids, &user.uuid, data, client_version, conn).await?, - "2FA token not provided" - ) + // Like upstream, a blank token counts as not provided + let Some(twofactor_code) = data.two_factor_token.as_deref().filter(|t| !t.trim().is_empty()) else { + err_json!(json_err_twofactor(&twofactor_ids, &user.uuid, data, conn).await?, "2FA token not provided") }; let selected_twofactor = twofactors.into_iter().find(|tf| tf.atype == selected_id && tf.enabled); @@ -856,20 +830,14 @@ async fn twofactor_auth( Some(TwoFactorType::Webauthn) => webauthn::validate_webauthn_login(&user.uuid, twofactor_code, conn).await?, Some(TwoFactorType::YubiKey) => yubikey::validate_yubikey_login(twofactor_code, &selected_data?).await?, Some(TwoFactorType::Duo) => { - if CONFIG.duo_use_iframe() { - // Legacy iframe prompt flow - duo::validate_duo_login(&user.email, twofactor_code, conn).await?; - } else { - // OIDC based flow - duo_oidc::validate_duo_login( - &user.email, - twofactor_code, - data.client_id.as_ref().unwrap(), - data.device_identifier.as_ref().unwrap(), - conn, - ) - .await?; - } + duo_oidc::validate_duo_login( + &user.email, + twofactor_code, + data.client_id.as_ref().unwrap(), + data.device_identifier.as_ref().unwrap(), + conn, + ) + .await?; } Some(TwoFactorType::Email) => { email::validate_email_code_str(&user.uuid, twofactor_code, &selected_data?, &ip.ip, conn).await?; @@ -891,7 +859,7 @@ async fn twofactor_auth( device.save(true, conn).await?; } err_json!( - json_err_twofactor(&twofactor_ids, &user.uuid, data, client_version, conn).await?, + json_err_twofactor(&twofactor_ids, &user.uuid, data, conn).await?, "2FA Remember token not provided or expired" ) } @@ -946,7 +914,6 @@ async fn json_err_twofactor( providers: &[i32], user_id: &UserId, data: &ConnectData, - client_version: Option<&ClientVersion>, conn: &DbConn, ) -> ApiResult { let mut result = json!({ @@ -975,27 +942,17 @@ async fn json_err_twofactor( err!("User does not exist") }; - if CONFIG.duo_use_iframe() { - // Legacy iframe prompt flow - let (signature, host) = duo::generate_duo_signature(&email, conn).await?; - result["TwoFactorProviders2"][provider.to_string()] = json!({ - "Host": host, - "Signature": signature, - }); - } else { - // OIDC based flow - let auth_url = duo_oidc::get_duo_auth_url( - &email, - data.client_id.as_ref().unwrap(), - data.device_identifier.as_ref().unwrap(), - conn, - ) - .await?; + let auth_url = duo_oidc::get_duo_auth_url( + &email, + data.client_id.as_ref().unwrap(), + data.device_identifier.as_ref().unwrap(), + conn, + ) + .await?; - result["TwoFactorProviders2"][provider.to_string()] = json!({ - "AuthUrl": auth_url, - }); - } + result["TwoFactorProviders2"][provider.to_string()] = json!({ + "AuthUrl": auth_url, + }); } Some(tf_type @ TwoFactorType::YubiKey) => { @@ -1015,19 +972,6 @@ async fn json_err_twofactor( err!("No twofactor email registered") }; - // Starting with version 2025.5.0 the client will call `/api/two-factor/send-email-login`. - let disabled_send = if let Some(cv) = client_version { - let ver_match = semver::VersionReq::parse(">=2025.5.0").unwrap(); - ver_match.matches(&cv.0) - } else { - false - }; - - // Send email immediately if email is the only 2FA option. - if providers.len() == 1 && !disabled_send { - email::send_token(user_id, conn).await?; - } - let email_data = email::EmailTokenData::from_json(&twofactor.data)?; result["TwoFactorProviders2"][provider.to_string()] = json!({ "Email": email::obscure_email(&email_data.email), @@ -1065,11 +1009,6 @@ async fn prelogin_password(data: Json, ip: ClientIp, conn: DbConn) prelogin(data, ip, conn).await } -#[post("/accounts/register", data = "")] -async fn identity_register(data: Json, conn: DbConn) -> JsonResult { - register(data, false, conn).await -} - #[derive(Debug, Deserialize)] #[serde(rename_all = "camelCase")] struct RegisterVerificationData { @@ -1141,8 +1080,9 @@ async fn register_verification_email( } #[post("/accounts/register/finish", data = "")] -async fn register_finish(data: Json, conn: DbConn) -> JsonResult { - register(data, true, conn).await +async fn register_finish(data: Json, ip: ClientIp, conn: DbConn) -> JsonResult { + crate::ratelimit::check_limit_unauthenticated(&ip.ip)?; + register(data, conn).await } // https://github.com/bitwarden/jslib/blob/master/common/src/models/request/tokenRequest.ts diff --git a/src/config.rs b/src/config.rs index 05b01bdd..b03e006c 100644 --- a/src/config.rs +++ b/src/config.rs @@ -561,7 +561,7 @@ make_config! { /// Auth Request cleanup schedule |> Cron schedule of the job that cleans old auth requests from the auth request. /// Defaults to every minute. Set blank to disable this job. auth_request_purge_schedule: String, false, def, "30 * * * * *".to_owned(); - /// Duo Auth context cleanup schedule |> Cron schedule of the job that cleans expired Duo contexts from the database. Does nothing if Duo MFA is disabled or set to use the legacy iframe prompt. + /// Duo Auth context cleanup schedule |> Cron schedule of the job that cleans expired Duo contexts from the database. Does nothing if Duo MFA is disabled. /// Defaults to once every minute. Set blank to disable this job. duo_context_purge_schedule: String, false, def, "30 * * * * *".to_owned(); /// Purge incomplete SSO auth. |> Cron schedule of the job that cleans leftover auth in db due to incomplete SSO login. @@ -865,16 +865,12 @@ make_config! { duo: _enable_duo { /// Enabled _enable_duo: bool, true, def, true; - /// Attempt to use deprecated iframe-based Traditional Prompt (Duo WebSDK 2) - duo_use_iframe: bool, false, def, false; /// Client Id duo_ikey: String, true, option; /// Client Secret duo_skey: Pass, true, option; /// Host duo_host: String, true, option; - /// Application Key (generated automatically) - _duo_akey: Pass, false, option; }, /// SMTP Email Settings @@ -1418,30 +1414,16 @@ pub enum PathType { // Android (v2026.2.1): https://github.com/bitwarden/android/blob/6902c19c0093fa476bbf74ccaa70c9f14afbb82f/core/src/main/kotlin/com/bitwarden/core/data/manager/model/FlagKey.kt#L31 // iOS (v2026.2.1): https://github.com/bitwarden/ios/blob/cdd9ba1770ca2ffc098d02d12cc3208e3a830454/BitwardenShared/Core/Platform/Models/Enum/FeatureFlag.swift#L7 pub const SUPPORTED_FEATURE_FLAGS: &[&str] = &[ - // Architecture - "desktop-ui-migration-milestone-1", - "desktop-ui-migration-milestone-2", - "desktop-ui-migration-milestone-3", - "desktop-ui-migration-milestone-4", // Auth Team "pm-5594-safari-account-switching", "pm-32413-multi-client-password-management", // Autofill Team "undetermined-cipher-scenario-logic", "enable-basic-auth-response", - "ssh-agent", "ssh-agent-v2", // Key Management Team - "ssh-key-vault-item", - "pm-25373-windows-biometrics-v2", - "pm-26340-linux-biometrics-v2", "windows-native-credential-sync", // Mobile Team - "anon-addy-self-host-alias", - "simple-login-self-host-alias", - "mutual-tls", - "cxp-import-mobile", - "cxp-export-mobile", "pm-34171-card-scanner", // Platform Team "pm-30529-webauthn-related-origins", @@ -1518,15 +1500,6 @@ impl Config { Ok(()) } - async fn update_config_partial(&self, other: ConfigBuilder) -> Result<(), Error> { - let builder = { - let usr = &self.inner.read().unwrap()._usr; - let mut overrides = Vec::new(); - usr.merge(&other, false, &mut overrides) - }; - self.update_config(builder, false).await - } - /// Tests whether an email's domain is allowed. A domain is allowed if it /// is in signups_domains_whitelist, or if no whitelist is set (so there /// are no domain restrictions in effect). @@ -1622,23 +1595,6 @@ impl Config { inner._enable_smtp && (inner.smtp_host.is_some() || inner.use_sendmail) } - pub async fn get_duo_akey(&self) -> String { - if let Some(akey) = self._duo_akey() { - akey - } else { - let akey_s = crate::crypto::encode_random_bytes::<64>(&data_encoding::BASE64); - - // Save the new value - let builder = ConfigBuilder { - _duo_akey: Some(akey_s.clone()), - ..Default::default() - }; - self.update_config_partial(builder).await.ok(); - - akey_s - } - } - pub fn is_webauthn_2fa_supported(&self) -> bool { Url::parse(&self.domain()).expect("DOMAIN not a valid URL").domain().is_some() } diff --git a/src/db/models/group.rs b/src/db/models/group.rs index 347b3235..007ad375 100644 --- a/src/db/models/group.rs +++ b/src/db/models/group.rs @@ -104,7 +104,6 @@ impl Group { "id": self.uuid, "organizationId": self.organizations_uuid, "name": self.name, - "accessAll": self.access_all, "externalId": self.external_id, "collections": collections_groups, "object": "groupDetails" @@ -574,26 +573,6 @@ impl GroupUser { } } - pub async fn delete_by_group_and_member( - group_uuid: &GroupId, - member_uuid: &MembershipId, - conn: &DbConn, - ) -> EmptyResult { - match Membership::find_by_uuid(member_uuid, conn).await { - Some(member) => User::update_uuid_revision(&member.user_uuid, conn).await, - None => warn!("Member could not be found!"), - } - - conn.run(move |conn| { - diesel::delete(groups_users::table) - .filter(groups_users::groups_uuid.eq(group_uuid)) - .filter(groups_users::users_organizations_uuid.eq(member_uuid)) - .execute(conn) - .map_res("Error deleting group users") - }) - .await - } - pub async fn delete_all_by_group(group_uuid: &GroupId, org_uuid: &OrganizationId, conn: &DbConn) -> EmptyResult { let group_users = GroupUser::find_by_group(group_uuid, org_uuid, conn).await; for group_user in group_users { diff --git a/src/db/models/organization.rs b/src/db/models/organization.rs index 353a406e..9816c579 100644 --- a/src/db/models/organization.rs +++ b/src/db/models/organization.rs @@ -515,8 +515,7 @@ impl Membership { "limitCollectionDeletion": true, "limitItemDeletion": false, "allowAdminAccessToAllCollectionItems": true, - "userIsManagedByOrganization": false, // Means not managed via the Members UI, like SSO - "userIsClaimedByOrganization": false, // The new key instead of the obsolete userIsManagedByOrganization + "userIsClaimedByOrganization": false, // Means not managed via the Members UI, like SSO "permissions": permissions, @@ -626,7 +625,6 @@ impl Membership { "status": status, "type": membership_type, - "accessAll": self.access_all, "twoFactorEnabled": twofactor_enabled, "resetPasswordEnrolled": self.reset_password_key.is_some(), "hasMasterPassword": !user.password_hash.is_empty(), @@ -634,7 +632,6 @@ impl Membership { "permissions": permissions, "ssoBound": false, // Not supported - "managedByOrganization": false, // This key is obsolete replaced by claimedByOrganization "claimedByOrganization": false, // Means not managed via the Members UI, like SSO "usesKeyConnector": false, // Not supported "accessSecretsManager": false, // Not supported (Not AGPLv3 Licensed) @@ -685,7 +682,6 @@ impl Membership { "status": status, "type": self.atype, - "accessAll": self.access_all, "collections": coll_uuids, "object": "organizationUserDetails", @@ -1028,6 +1024,7 @@ impl Membership { conn.run(move |conn| { users_organizations::table .filter(users_organizations::org_uuid.eq(org_uuid)) + .filter(users_organizations::status.eq(MembershipStatus::Confirmed as i32)) .left_join(users_collections::table.on(users_collections::user_uuid.eq(users_organizations::user_uuid))) .left_join( ciphers_collections::table.on(ciphers_collections::collection_uuid @@ -1054,6 +1051,7 @@ impl Membership { conn.run(move |conn| { users_organizations::table .filter(users_organizations::org_uuid.eq(org_uuid)) + .filter(users_organizations::status.eq(MembershipStatus::Confirmed as i32)) .inner_join( groups_users::table.on(groups_users::users_organizations_uuid.eq(users_organizations::uuid)), ) diff --git a/src/main.rs b/src/main.rs index 437354af..f27729d6 100644 --- a/src/main.rs +++ b/src/main.rs @@ -720,7 +720,7 @@ fn schedule_jobs(pool: db::DbPool) { } // Clean unused, expired Duo authentication contexts. - if !CONFIG.duo_context_purge_schedule().is_empty() && CONFIG._enable_duo() && !CONFIG.duo_use_iframe() { + if !CONFIG.duo_context_purge_schedule().is_empty() && CONFIG._enable_duo() { sched.add(Job::new(CONFIG.duo_context_purge_schedule().parse().unwrap(), || { runtime.spawn(purge_duo_contexts(pool.clone())); })); diff --git a/src/static/templates/scss/vaultwarden.scss.hbs b/src/static/templates/scss/vaultwarden.scss.hbs index 4b83ba04..d062c026 100644 --- a/src/static/templates/scss/vaultwarden.scss.hbs +++ b/src/static/templates/scss/vaultwarden.scss.hbs @@ -42,45 +42,27 @@ a[href$="/settings/sponsored-families"] { {{/if}} /* Hide the `Enterprise Single Sign-On` button on the login page */ -{{#if (webver ">=2025.5.1")}} {{#if (not sso_enabled)}} .vw-sso-login { @extend %vw-hide; } {{/if}} -{{else}} -app-root ng-component > form > div:nth-child(1) > div > button[buttontype="secondary"].\!tw-text-primary-600:nth-child(4) { - @extend %vw-hide; -} -{{/if}} /* Hide the `Log in with passkey` settings */ app-user-layout app-password-settings app-webauthn-login-settings { @extend %vw-hide; } /* Hide Log in with passkey on the login page */ -{{#if (webver ">=2025.5.1")}} .vw-passkey-login { @extend %vw-hide; } -{{else}} -app-root ng-component > form > div:nth-child(1) > div > button[buttontype="secondary"].\!tw-text-primary-600:nth-child(3) { - @extend %vw-hide; -} -{{/if}} /* Hide the or text followed by the two buttons hidden above */ -{{#if (webver ">=2025.5.1")}} {{#if (or (not sso_enabled) sso_only)}} .vw-or-text { @extend %vw-hide; } {{/if}} -{{else}} -app-root ng-component > form > div:nth-child(1) > div:nth-child(3) > div:nth-child(2) { - @extend %vw-hide; -} -{{/if}} /* Hide the `Other` button on the login page */ {{#if (or (not sso_enabled) sso_only)}} @@ -154,17 +136,10 @@ ng-dropdown-panel div.ng-dropdown-panel-items div:has(> [title="DuckDuckGo"]) { take a while for the change to take effect. To avoid the button appearing when it shouldn't, we'll keep this style in place for a couple of versions */ /* Hide the register link on the login screen */ -{{#if (webver "<2025.3.0")}} -app-login form div + div + div + div + hr, -app-login form div + div + div + div + hr + p { - @extend %vw-hide; -} -{{else}} app-root a[routerlink="/signup"] { @extend %vw-hide; } {{/if}} -{{/if}} {{#if remember_2fa_disabled}} /* Hide checkbox to remember 2FA token for 30 days */