mirror of
https://github.com/dani-garcia/vaultwarden.wiki.git
synced 2026-07-28 19:45:05 +03:00
Compare commits
6
Commits
6a0c75320d
...
1.37.0
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
46ae59eaf4 | ||
|
|
a6a88e7929 | ||
|
|
5040bcb7c0 | ||
|
|
660faee68e | ||
|
|
683a23e43c | ||
|
|
4a9bcb0694 |
@@ -324,6 +324,14 @@
|
||||
## Set to the string "none" (without quotes), to disable any headers and just use the remote IP
|
||||
# IP_HEADER=X-Real-IP
|
||||
|
||||
## Which addresses the header above is accepted from, defaults to "local".
|
||||
## Anyone able to reach Vaultwarden can set the header, and the client IP is used for the login and
|
||||
## admin rate limits, so it is only trusted when the request comes from a proxy listed here.
|
||||
## "local" accepts it from any non global address, which covers a reverse proxy running on the same
|
||||
## host or container network. Use "all" to accept it from anywhere, or list the addresses of your
|
||||
## proxy as IPs and CIDR ranges if it connects from a public address.
|
||||
# IP_HEADER_TRUSTED_PROXIES=local
|
||||
|
||||
## Icon service
|
||||
## The predefined icon services are: internal, bitwarden, duckduckgo, google.
|
||||
## To specify a custom icon service, set a URL template with exactly one instance of `{}`,
|
||||
@@ -461,6 +469,13 @@
|
||||
## Note that this applies to both the login and the 2FA, so it's recommended to allow a burst size of at least 2.
|
||||
# LOGIN_RATELIMIT_MAX_BURST=10
|
||||
|
||||
## Number of seconds, on average, between requests from the same IP address to one of the rate limited
|
||||
## unauthenticated endpoints, like the password hint, the account recovery mails or accessing a Send.
|
||||
# UNAUTHENTICATED_RATELIMIT_SECONDS=60
|
||||
## Allow a burst of requests of up to this size, while maintaining the average indicated by `UNAUTHENTICATED_RATELIMIT_SECONDS`.
|
||||
## This budget is shared between all of those endpoints, so it is more lenient than the login one.
|
||||
# UNAUTHENTICATED_RATELIMIT_MAX_BURST=50
|
||||
|
||||
## BETA FEATURE: Groups
|
||||
## Controls whether group support is enabled for organizations
|
||||
## This setting applies to organizations.
|
||||
|
||||
@@ -62,7 +62,7 @@ jobs:
|
||||
|
||||
# Checkout the repo
|
||||
- name: "Checkout"
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
fetch-depth: 0
|
||||
|
||||
@@ -20,7 +20,7 @@ jobs:
|
||||
steps:
|
||||
# Checkout the repo
|
||||
- name: "Checkout"
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
# End Checkout the repo
|
||||
|
||||
@@ -32,7 +32,7 @@ jobs:
|
||||
|
||||
# Checkout the repo
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
# End Checkout the repo
|
||||
|
||||
@@ -77,7 +77,7 @@ jobs:
|
||||
|
||||
# Checkout the repo
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
# We need fetch-depth of 0 so we also get all the tag metadata
|
||||
with:
|
||||
persist-credentials: false
|
||||
@@ -106,7 +106,7 @@ jobs:
|
||||
|
||||
# Login to Docker Hub
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
|
||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
@@ -121,7 +121,7 @@ jobs:
|
||||
|
||||
# Login to GitHub Container Registry
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
|
||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.repository_owner }}
|
||||
@@ -137,7 +137,7 @@ jobs:
|
||||
|
||||
# Login to Quay.io
|
||||
- name: Login to Quay.io
|
||||
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
|
||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
||||
with:
|
||||
registry: quay.io
|
||||
username: ${{ secrets.QUAY_USERNAME }}
|
||||
@@ -237,7 +237,7 @@ jobs:
|
||||
|
||||
# Upload artifacts to Github Actions and Attest the binaries
|
||||
- name: Attest binaries
|
||||
uses: actions/attest@a1948c3f048ba23858d222213b7c278aabede763 # v4.1.1
|
||||
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
|
||||
with:
|
||||
subject-path: vaultwarden-${{ env.NORMALIZED_ARCH }}
|
||||
|
||||
@@ -272,7 +272,7 @@ jobs:
|
||||
|
||||
# Login to Docker Hub
|
||||
- name: Login to Docker Hub
|
||||
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
|
||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
||||
with:
|
||||
username: ${{ secrets.DOCKERHUB_USERNAME }}
|
||||
password: ${{ secrets.DOCKERHUB_TOKEN }}
|
||||
@@ -287,7 +287,7 @@ jobs:
|
||||
|
||||
# Login to GitHub Container Registry
|
||||
- name: Login to GitHub Container Registry
|
||||
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
|
||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
||||
with:
|
||||
registry: ghcr.io
|
||||
username: ${{ github.repository_owner }}
|
||||
@@ -303,7 +303,7 @@ jobs:
|
||||
|
||||
# Login to Quay.io
|
||||
- name: Login to Quay.io
|
||||
uses: docker/login-action@af1e73f918a031802d376d3c8bbc3fe56130a9b0 # v4.4.0
|
||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
||||
with:
|
||||
registry: quay.io
|
||||
username: ${{ secrets.QUAY_USERNAME }}
|
||||
@@ -365,7 +365,7 @@ jobs:
|
||||
# Attest container images
|
||||
- name: Attest - docker.io - ${{ matrix.base_image }}
|
||||
if: ${{ vars.DOCKERHUB_REPO != '' && env.DIGEST_SHA != ''}}
|
||||
uses: actions/attest@a1948c3f048ba23858d222213b7c278aabede763 # v4.1.1
|
||||
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
|
||||
with:
|
||||
subject-name: ${{ vars.DOCKERHUB_REPO }}
|
||||
subject-digest: ${{ env.DIGEST_SHA }}
|
||||
@@ -373,7 +373,7 @@ jobs:
|
||||
|
||||
- name: Attest - ghcr.io - ${{ matrix.base_image }}
|
||||
if: ${{ vars.GHCR_REPO != '' && env.DIGEST_SHA != ''}}
|
||||
uses: actions/attest@a1948c3f048ba23858d222213b7c278aabede763 # v4.1.1
|
||||
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
|
||||
with:
|
||||
subject-name: ${{ vars.GHCR_REPO }}
|
||||
subject-digest: ${{ env.DIGEST_SHA }}
|
||||
@@ -381,7 +381,7 @@ jobs:
|
||||
|
||||
- name: Attest - quay.io - ${{ matrix.base_image }}
|
||||
if: ${{ vars.QUAY_REPO != '' && env.DIGEST_SHA != ''}}
|
||||
uses: actions/attest@a1948c3f048ba23858d222213b7c278aabede763 # v4.1.1
|
||||
uses: actions/attest@f7c74d28b9d84cb8768d0b8ca14a4bac6ef463e6 # v4.2.0
|
||||
with:
|
||||
subject-name: ${{ vars.QUAY_REPO }}
|
||||
subject-digest: ${{ env.DIGEST_SHA }}
|
||||
|
||||
@@ -33,7 +33,7 @@ jobs:
|
||||
|
||||
steps:
|
||||
- name: Checkout code
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
@@ -50,6 +50,6 @@ jobs:
|
||||
severity: CRITICAL,HIGH
|
||||
|
||||
- name: Upload Trivy scan results to GitHub Security tab
|
||||
uses: github/codeql-action/upload-sarif@99df26d4f13ea111d4ec1a7dddef6063f76b97e9 # v4.37.0
|
||||
uses: github/codeql-action/upload-sarif@e4fba868fa4b1b91e1fdab776edc8cfbe6e9fb81 # v4.37.3
|
||||
with:
|
||||
sarif_file: 'trivy-results.sarif'
|
||||
|
||||
@@ -16,7 +16,7 @@ jobs:
|
||||
steps:
|
||||
# Checkout the repo
|
||||
- name: Checkout
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
# End Checkout the repo
|
||||
|
||||
@@ -19,12 +19,12 @@ jobs:
|
||||
security-events: write # To write the security report
|
||||
steps:
|
||||
- name: Checkout repository
|
||||
uses: actions/checkout@9c091bb21b7c1c1d1991bb908d89e4e9dddfe3e0 # v7.0.0
|
||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Run zizmor
|
||||
uses: zizmorcore/zizmor-action@192e21d79ab29983730a13d1382995c2307fbcaa # v0.5.7
|
||||
uses: zizmorcore/zizmor-action@6fc4b006235f201fdab3722e17240ab420d580e5 # v0.6.1
|
||||
with:
|
||||
# intentionally not scanning the entire repository,
|
||||
# since it contains integration tests.
|
||||
|
||||
Generated
+325
-392
File diff suppressed because it is too large
Load Diff
+23
-20
@@ -1,6 +1,6 @@
|
||||
[workspace.package]
|
||||
edition = "2024"
|
||||
rust-version = "1.94.1"
|
||||
rust-version = "1.95.0"
|
||||
license = "AGPL-3.0-only"
|
||||
repository = "https://github.com/dani-garcia/vaultwarden"
|
||||
publish = false
|
||||
@@ -75,7 +75,7 @@ dotenvy = { version = "0.15.7", default-features = false }
|
||||
|
||||
# Numerical libraries
|
||||
num-traits = "0.2.19"
|
||||
num-derive = "0.4.2"
|
||||
num-derive = "0.5.1"
|
||||
bigdecimal = "0.4.10"
|
||||
|
||||
# Web framework
|
||||
@@ -89,8 +89,8 @@ rmpv = "1.3.1" # MessagePack library
|
||||
dashmap = "6.2.1"
|
||||
|
||||
# Async futures
|
||||
futures = "0.3.32"
|
||||
tokio = { version = "1.52.3", features = [
|
||||
futures = "0.3.33"
|
||||
tokio = { version = "1.53.1", features = [
|
||||
"fs",
|
||||
"io-util",
|
||||
"net",
|
||||
@@ -99,14 +99,14 @@ tokio = { version = "1.52.3", features = [
|
||||
"signal",
|
||||
"time",
|
||||
] }
|
||||
tokio-util = { version = "0.7.18", features = ["compat"] }
|
||||
tokio-util = { version = "0.7.19", features = ["compat"] }
|
||||
|
||||
# A generic serialization/deserialization framework
|
||||
serde = { version = "1.0.228", features = ["derive"] }
|
||||
serde_json = "1.0.150"
|
||||
serde = { version = "1.0.229", features = ["derive"] }
|
||||
serde_json = "1.0.151"
|
||||
|
||||
# A safe, extensible ORM and Query builder
|
||||
diesel = { version = "2.3.10", features = ["chrono", "r2d2", "numeric"] }
|
||||
diesel = { version = "2.3.11", features = ["chrono", "r2d2", "numeric"] }
|
||||
diesel_migrations = "2.3.2"
|
||||
|
||||
derive_more = { version = "2.1.1", features = [
|
||||
@@ -124,16 +124,16 @@ libsqlite3-sys = { version = "0.37.0", optional = true }
|
||||
# Crypto-related libraries
|
||||
rand = "0.10.2"
|
||||
ring = "0.17.14"
|
||||
rustls = { version = "0.23.41", features = ["ring", "std"], default-features = false }
|
||||
rustls = { version = "0.23.42", features = ["ring", "std"], default-features = false }
|
||||
subtle = "2.6.1"
|
||||
|
||||
# UUID generation
|
||||
uuid = { version = "1.23.4", features = ["v4"] }
|
||||
uuid = { version = "1.24.0", features = ["v4"] }
|
||||
|
||||
# Date and time libraries
|
||||
chrono = { version = "0.4.45", default-features = false, features = ["clock", "serde"] }
|
||||
chrono-tz = "0.10.4"
|
||||
time = "0.3.53"
|
||||
time = "0.3.54"
|
||||
|
||||
# Job scheduler
|
||||
job_scheduler_ng = "2.4.0"
|
||||
@@ -142,7 +142,7 @@ job_scheduler_ng = "2.4.0"
|
||||
data-encoding = "2.11.0"
|
||||
|
||||
# JWT library
|
||||
jsonwebtoken = { version = "10.4.0", default-features = false, features = ["rust_crypto", "use_pem"] }
|
||||
jsonwebtoken = { version = "11.0.0", default-features = false, features = ["rust_crypto", "use_pem"] }
|
||||
|
||||
# TOTP library
|
||||
totp-lite = "2.0.1"
|
||||
@@ -179,7 +179,7 @@ percent-encoding = "2.3.2" # URL encoding library used for URL's in the emails
|
||||
email_address = "0.2.9"
|
||||
|
||||
# HTML Template library
|
||||
handlebars = { version = "6.4.2", features = ["dir_source"] }
|
||||
handlebars = { version = "6.4.3", features = ["dir_source"] }
|
||||
|
||||
# HTTP client (Used for favicons, version check, DUO and HIBP API)
|
||||
reqwest = { version = "0.13.4", default-features = false, features = [
|
||||
@@ -204,7 +204,7 @@ hickory-resolver = "0.26.1"
|
||||
|
||||
# Favicon extraction libraries
|
||||
html5gum = "0.8.4"
|
||||
regex = { version = "1.12.4", default-features = false, features = [
|
||||
regex = { version = "1.13.1", default-features = false, features = [
|
||||
"perf",
|
||||
"std",
|
||||
"unicode-perl",
|
||||
@@ -230,6 +230,9 @@ pico-args = "0.5.0"
|
||||
pastey = "0.2.3"
|
||||
governor = "0.10.4"
|
||||
|
||||
# CIDR parsing for the trusted proxies of the client IP header
|
||||
ipnet = "2.12.0"
|
||||
|
||||
# OIDC for SSO
|
||||
openidconnect = { version = "4.0.1", default-features = false }
|
||||
moka = { version = "0.12.15", features = ["future"] }
|
||||
@@ -241,7 +244,7 @@ semver = "1.0.28"
|
||||
# Mainly used for the musl builds, since the default musl malloc is very slow
|
||||
mimalloc = { version = "0.1.52", optional = true, default-features = false, features = ["secure"] }
|
||||
|
||||
which = "8.0.4"
|
||||
which = "8.0.5"
|
||||
|
||||
# Argon2 library with support for the PHC format
|
||||
argon2 = "0.5.3"
|
||||
@@ -256,17 +259,17 @@ grass_compiler = { version = "0.13.4", default-features = false }
|
||||
opendal = { version = "0.57.0", default-features = false, features = ["services-fs"] }
|
||||
|
||||
# For retrieving AWS credentials, including temporary SSO credentials
|
||||
aws-config = { version = "1.8.18", optional = true, default-features = false, features = [
|
||||
aws-config = { version = "1.10.0", optional = true, default-features = false, features = [
|
||||
"behavior-version-latest",
|
||||
"credentials-process",
|
||||
"rt-tokio",
|
||||
"sso",
|
||||
] }
|
||||
aws-credential-types = { version = "1.2.14", optional = true }
|
||||
aws-smithy-runtime-api = { version = "1.13.0", optional = true }
|
||||
aws-credential-types = { version = "1.3.0", optional = true }
|
||||
aws-smithy-runtime-api = { version = "1.14.0", optional = true }
|
||||
http = { version = "1.4.2", optional = true }
|
||||
reqsign-aws-v4 = { version = "3.0.1", optional = true }
|
||||
reqsign-core = { version = "3.0.1", optional = true }
|
||||
reqsign-aws-v4 = { version = "3.0.2", optional = true }
|
||||
reqsign-core = { version = "3.1.0", optional = true }
|
||||
|
||||
# Strip debuginfo from the release builds
|
||||
# The debug symbols are to provide better panic traces
|
||||
|
||||
@@ -1,11 +1,11 @@
|
||||
---
|
||||
vault_version: "v2026.6.2"
|
||||
vault_image_digest: "sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a"
|
||||
vault_version: "v2026.6.4"
|
||||
vault_image_digest: "sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427"
|
||||
# Cross Compile Docker Helper Scripts v1.9.0
|
||||
# We use the linux/amd64 platform shell scripts since there is no difference between the different platform scripts
|
||||
# https://github.com/tonistiigi/xx | https://hub.docker.com/r/tonistiigi/xx/tags
|
||||
xx_image_digest: "sha256:c64defb9ed5a91eacb37f96ccc3d4cd72521c4bd18d5442905b95e2226b0e707"
|
||||
rust_version: 1.96.1 # Rust version to be used
|
||||
rust_version: 1.97.1 # Rust version to be used
|
||||
debian_version: trixie # Debian release name to be used
|
||||
alpine_version: "3.24" # Alpine version to be used
|
||||
# For which platforms/architectures will we try to build images
|
||||
|
||||
+11
-11
@@ -19,23 +19,23 @@
|
||||
# - From https://hub.docker.com/r/vaultwarden/web-vault/tags,
|
||||
# click the tag name to view the digest of the image it currently points to.
|
||||
# - From the command line:
|
||||
# $ docker pull docker.io/vaultwarden/web-vault:v2026.6.2
|
||||
# $ docker image inspect --format "{{.RepoDigests}}" docker.io/vaultwarden/web-vault:v2026.6.2
|
||||
# [docker.io/vaultwarden/web-vault@sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a]
|
||||
# $ docker pull docker.io/vaultwarden/web-vault:v2026.6.4
|
||||
# $ docker image inspect --format "{{.RepoDigests}}" docker.io/vaultwarden/web-vault:v2026.6.4
|
||||
# [docker.io/vaultwarden/web-vault@sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427]
|
||||
#
|
||||
# - Conversely, to get the tag name from the digest:
|
||||
# $ docker image inspect --format "{{.RepoTags}}" docker.io/vaultwarden/web-vault@sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a
|
||||
# [docker.io/vaultwarden/web-vault:v2026.6.2]
|
||||
# $ docker image inspect --format "{{.RepoTags}}" docker.io/vaultwarden/web-vault@sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427
|
||||
# [docker.io/vaultwarden/web-vault:v2026.6.4]
|
||||
#
|
||||
FROM --platform=linux/amd64 docker.io/vaultwarden/web-vault@sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a AS vault
|
||||
FROM --platform=linux/amd64 docker.io/vaultwarden/web-vault@sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427 AS vault
|
||||
|
||||
########################## ALPINE BUILD IMAGES ##########################
|
||||
## NOTE: The Alpine Base Images do not support other platforms then linux/amd64 and linux/arm64
|
||||
## And for Alpine we define all build images here, they will only be loaded when actually used
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:x86_64-musl-stable-1.96.1 AS build_amd64
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:aarch64-musl-stable-1.96.1 AS build_arm64
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:armv7-musleabihf-stable-1.96.1 AS build_armv7
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:arm-musleabi-stable-1.96.1 AS build_armv6
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:x86_64-musl-stable-1.97.1 AS build_amd64
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:aarch64-musl-stable-1.97.1 AS build_arm64
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:armv7-musleabihf-stable-1.97.1 AS build_armv7
|
||||
FROM --platform=$BUILDPLATFORM ghcr.io/blackdex/rust-musl:arm-musleabi-stable-1.97.1 AS build_armv6
|
||||
|
||||
########################## BUILD IMAGE ##########################
|
||||
# hadolint ignore=DL3006
|
||||
@@ -66,7 +66,7 @@ RUN USER=root cargo new --bin /app
|
||||
WORKDIR /app
|
||||
|
||||
# Environment variables for Cargo on Alpine based builds
|
||||
RUN echo "export CARGO_TARGET=${RUST_MUSL_CROSS_TARGET}" >> /env-cargo && \
|
||||
RUN echo "export CARGO_TARGET=${CARGO_BUILD_TARGET}" >> /env-cargo && \
|
||||
# Output the current contents of the file
|
||||
cat /env-cargo
|
||||
|
||||
|
||||
@@ -19,15 +19,15 @@
|
||||
# - From https://hub.docker.com/r/vaultwarden/web-vault/tags,
|
||||
# click the tag name to view the digest of the image it currently points to.
|
||||
# - From the command line:
|
||||
# $ docker pull docker.io/vaultwarden/web-vault:v2026.6.2
|
||||
# $ docker image inspect --format "{{.RepoDigests}}" docker.io/vaultwarden/web-vault:v2026.6.2
|
||||
# [docker.io/vaultwarden/web-vault@sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a]
|
||||
# $ docker pull docker.io/vaultwarden/web-vault:v2026.6.4
|
||||
# $ docker image inspect --format "{{.RepoDigests}}" docker.io/vaultwarden/web-vault:v2026.6.4
|
||||
# [docker.io/vaultwarden/web-vault@sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427]
|
||||
#
|
||||
# - Conversely, to get the tag name from the digest:
|
||||
# $ docker image inspect --format "{{.RepoTags}}" docker.io/vaultwarden/web-vault@sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a
|
||||
# [docker.io/vaultwarden/web-vault:v2026.6.2]
|
||||
# $ docker image inspect --format "{{.RepoTags}}" docker.io/vaultwarden/web-vault@sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427
|
||||
# [docker.io/vaultwarden/web-vault:v2026.6.4]
|
||||
#
|
||||
FROM --platform=linux/amd64 docker.io/vaultwarden/web-vault@sha256:f004f72a5d357b87483839500a517da3d1b4ea0a57b9731989d298cccea7d02a AS vault
|
||||
FROM --platform=linux/amd64 docker.io/vaultwarden/web-vault@sha256:e7d3b31ec6a991a6bf447721ea341b4192ce5d3b920929211672fd4f3f891427 AS vault
|
||||
|
||||
########################## Cross Compile Docker Helper Scripts ##########################
|
||||
## We use the linux/amd64 no matter which Build Platform, since these are all bash scripts
|
||||
@@ -36,7 +36,7 @@ FROM --platform=linux/amd64 docker.io/tonistiigi/xx@sha256:c64defb9ed5a91eacb37f
|
||||
|
||||
########################## BUILD IMAGE ##########################
|
||||
# hadolint ignore=DL3006
|
||||
FROM --platform=$BUILDPLATFORM docker.io/library/rust:1.96.1-slim-trixie AS build
|
||||
FROM --platform=$BUILDPLATFORM docker.io/library/rust:1.97.1-slim-trixie AS build
|
||||
COPY --from=xx / /
|
||||
ARG TARGETARCH
|
||||
ARG TARGETVARIANT
|
||||
|
||||
@@ -106,7 +106,7 @@ WORKDIR /app
|
||||
|
||||
{% if base == "alpine" %}
|
||||
# Environment variables for Cargo on Alpine based builds
|
||||
RUN echo "export CARGO_TARGET=${RUST_MUSL_CROSS_TARGET}" >> /env-cargo && \
|
||||
RUN echo "export CARGO_TARGET=${CARGO_BUILD_TARGET}" >> /env-cargo && \
|
||||
# Output the current contents of the file
|
||||
cat /env-cargo
|
||||
|
||||
|
||||
+2
-2
@@ -13,8 +13,8 @@ path = "src/lib.rs"
|
||||
proc-macro = true
|
||||
|
||||
[dependencies]
|
||||
quote = "1.0.46"
|
||||
syn = "2.0.118"
|
||||
quote = "1.0.47"
|
||||
syn = "3.0.3"
|
||||
|
||||
[lints]
|
||||
workspace = true
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
[toolchain]
|
||||
channel = "1.96.1"
|
||||
channel = "1.97.1"
|
||||
components = [ "rustfmt", "clippy" ]
|
||||
profile = "minimal"
|
||||
|
||||
+19
-10
@@ -15,7 +15,7 @@ use crate::{
|
||||
core::{accept_org_invite, log_user_event, two_factor::email},
|
||||
master_password_policy, register_push_device, unregister_push_device,
|
||||
},
|
||||
auth::{ClientHeaders, Headers, decode_delete, decode_invite, decode_verify_email},
|
||||
auth::{ClientHeaders, ClientIp, Headers, decode_delete, decode_invite, decode_verify_email},
|
||||
crypto,
|
||||
db::{
|
||||
DbConn, DbPool,
|
||||
@@ -693,10 +693,6 @@ struct UnlockData {
|
||||
#[derive(Deserialize)]
|
||||
#[serde(rename_all = "camelCase")]
|
||||
struct ChangeKdfData {
|
||||
#[allow(dead_code)]
|
||||
new_master_password_hash: String,
|
||||
#[allow(dead_code)]
|
||||
key: String,
|
||||
authentication_data: AuthenticationData,
|
||||
unlock_data: UnlockData,
|
||||
master_password_hash: String,
|
||||
@@ -1197,7 +1193,9 @@ struct DeleteRecoverData {
|
||||
}
|
||||
|
||||
#[post("/accounts/delete-recover", data = "<data>")]
|
||||
async fn post_delete_recover(data: Json<DeleteRecoverData>, conn: DbConn) -> EmptyResult {
|
||||
async fn post_delete_recover(data: Json<DeleteRecoverData>, ip: ClientIp, conn: DbConn) -> EmptyResult {
|
||||
crate::ratelimit::check_limit_unauthenticated(&ip.ip)?;
|
||||
|
||||
let data: DeleteRecoverData = data.into_inner();
|
||||
|
||||
if CONFIG.mail_enabled() {
|
||||
@@ -1270,9 +1268,11 @@ struct PasswordHintData {
|
||||
}
|
||||
|
||||
#[post("/accounts/password-hint", data = "<data>")]
|
||||
async fn password_hint(data: Json<PasswordHintData>, conn: DbConn) -> EmptyResult {
|
||||
async fn password_hint(data: Json<PasswordHintData>, ip: ClientIp, conn: DbConn) -> EmptyResult {
|
||||
const NO_HINT: &str = "Sorry, you have no password hint...";
|
||||
|
||||
crate::ratelimit::check_limit_unauthenticated(&ip.ip)?;
|
||||
|
||||
if !CONFIG.password_hints_allowed() || (!CONFIG.mail_enabled() && !CONFIG.show_password_hint()) {
|
||||
err!("This server is not configured to provide password hints.");
|
||||
}
|
||||
@@ -1334,6 +1334,13 @@ pub async fn prelogin(data: Json<PreloginData>, conn: DbConn) -> Json<Value> {
|
||||
"kdfIterations": kdf_iter,
|
||||
"kdfMemory": kdf_mem,
|
||||
"kdfParallelism": kdf_para,
|
||||
"kdfSettings": {
|
||||
"iterations": kdf_iter,
|
||||
"kdfType": kdf_type,
|
||||
"memory": kdf_mem,
|
||||
"parallelism": kdf_para
|
||||
},
|
||||
"salt": null,
|
||||
}))
|
||||
}
|
||||
|
||||
@@ -1510,7 +1517,9 @@ async fn put_device_token(device_id: DeviceId, data: Json<PushToken>, headers: H
|
||||
}
|
||||
|
||||
#[put("/devices/identifier/<device_id>/clear-token")]
|
||||
async fn put_clear_device_token(device_id: DeviceId, conn: DbConn) -> EmptyResult {
|
||||
async fn put_clear_device_token(device_id: DeviceId, ip: ClientIp, conn: DbConn) -> EmptyResult {
|
||||
crate::ratelimit::check_limit_unauthenticated(&ip.ip)?;
|
||||
|
||||
// This only clears push token
|
||||
// https://github.com/bitwarden/server/blob/9ebe16587175b1c0e9208f84397bb75d0d595510/src/Api/Controllers/DevicesController.cs#L215
|
||||
// https://github.com/bitwarden/server/blob/9ebe16587175b1c0e9208f84397bb75d0d595510/src/Core/Services/Implementations/DeviceService.cs#L37
|
||||
@@ -1532,8 +1541,8 @@ async fn put_clear_device_token(device_id: DeviceId, conn: DbConn) -> EmptyResul
|
||||
|
||||
// On upstream server, both PUT and POST are declared. Implementing the POST method in case it would be useful somewhere
|
||||
#[post("/devices/identifier/<device_id>/clear-token")]
|
||||
async fn post_clear_device_token(device_id: DeviceId, conn: DbConn) -> EmptyResult {
|
||||
put_clear_device_token(device_id, conn).await
|
||||
async fn post_clear_device_token(device_id: DeviceId, ip: ClientIp, conn: DbConn) -> EmptyResult {
|
||||
put_clear_device_token(device_id, ip, conn).await
|
||||
}
|
||||
|
||||
#[get("/tasks")]
|
||||
|
||||
+11
-2
@@ -450,7 +450,9 @@ pub async fn update_cipher_from_data(
|
||||
match Membership::find_confirmed_by_user_and_org(&headers.user.uuid, &org_id, conn).await {
|
||||
None => err!("You don't have permission to add item to organization"),
|
||||
Some(member) => {
|
||||
if shared_to_collections.is_some()
|
||||
// A non-empty list of collections implies the caller already validated the user's write
|
||||
// access to them, so we can move the cipher into the organization on that basis.
|
||||
if shared_to_collections.as_ref().is_some_and(|cols| !cols.is_empty())
|
||||
|| member.has_full_access()
|
||||
|| cipher.is_write_accessible_to_user(&headers.user.uuid, conn).await
|
||||
{
|
||||
@@ -629,7 +631,7 @@ async fn post_ciphers_import(data: Json<ImportData>, headers: Headers, conn: DbC
|
||||
|
||||
// Read and create the ciphers
|
||||
for (index, mut cipher_data) in data.ciphers.into_iter().enumerate() {
|
||||
let folder_id = relations_map.get(&index).map(|i| folders[*i].clone());
|
||||
let folder_id = relations_map.get(&index).and_then(|i| folders.get(*i).cloned());
|
||||
cipher_data.folder_id = folder_id;
|
||||
|
||||
let mut cipher = Cipher::new(cipher_data.r#type, cipher_data.name.clone());
|
||||
@@ -1043,6 +1045,13 @@ async fn share_cipher_by_uuid(
|
||||
err!("Cipher doesn't exist")
|
||||
};
|
||||
|
||||
// `update_cipher_from_data()` rejects this too, but only after the collections below were
|
||||
// already linked. There are no transactions, so that would leave the cipher linked to a
|
||||
// collection of another organization.
|
||||
if cipher.organization_uuid.is_some() && cipher.organization_uuid != data.cipher.organization_id {
|
||||
err!("Organization mismatch. Please resync the client before updating the cipher")
|
||||
}
|
||||
|
||||
let mut shared_to_collections = vec![];
|
||||
|
||||
if let Some(organization_id) = &data.cipher.organization_id {
|
||||
|
||||
@@ -182,7 +182,10 @@ async fn post_events_collect(data: Json<Vec<EventCollection>>, headers: Headers,
|
||||
.await;
|
||||
}
|
||||
1600..=1699 => {
|
||||
if let Some(org_id) = &event.organization_id {
|
||||
// Only allow logging events for an organization the user is actually a member of.
|
||||
if let Some(org_id) = &event.organization_id
|
||||
&& Membership::find_confirmed_by_user_and_org(&headers.user.uuid, org_id, &conn).await.is_some()
|
||||
{
|
||||
log_event_impl(
|
||||
event.r#type,
|
||||
org_id,
|
||||
@@ -197,8 +200,11 @@ async fn post_events_collect(data: Json<Vec<EventCollection>>, headers: Headers,
|
||||
}
|
||||
}
|
||||
_ => {
|
||||
// The cipher determines the organization the event is logged to, so make sure the
|
||||
// user can actually access it instead of trusting the provided cipher uuid.
|
||||
if let Some(cipher_uuid) = &event.cipher_id
|
||||
&& let Some(cipher) = Cipher::find_by_uuid(cipher_uuid, &conn).await
|
||||
&& cipher.is_accessible_to_user(&headers.user.uuid, &conn).await
|
||||
&& let Some(org_id) = cipher.organization_uuid
|
||||
{
|
||||
log_event_impl(
|
||||
|
||||
+9
-2
@@ -228,14 +228,17 @@ fn config() -> Json<Value> {
|
||||
// Version history:
|
||||
// - Individual cipher key encryption: 2024.2.0
|
||||
// - Mobile app support for MasterPasswordUnlockData: 2025.8.0
|
||||
"version": "2025.12.0",
|
||||
"version": "2026.6.0",
|
||||
"gitHash": option_env!("GIT_REV"),
|
||||
"server": {
|
||||
"name": "Vaultwarden",
|
||||
"url": "https://github.com/dani-garcia/vaultwarden"
|
||||
},
|
||||
"settings": {
|
||||
"disableUserRegistration": CONFIG.is_signup_disabled()
|
||||
"disableUserRegistration": CONFIG.is_signup_disabled(),
|
||||
// When enabled, this setting signals to clients that onboarding interstitials
|
||||
// (post-login welcome dialogs, extension install prompts, setup extension redirects, and premium upsell modals) should be suppressed
|
||||
"suppressOnboardingInterstitials": false
|
||||
},
|
||||
"environment": {
|
||||
"vault": domain,
|
||||
@@ -251,6 +254,10 @@ fn config() -> Json<Value> {
|
||||
"vapidPublicKey": null
|
||||
},
|
||||
"featureStates": feature_states,
|
||||
// Not supported right now
|
||||
// Used for by clients to learn if the server requires extra work to establish a connection.
|
||||
// See: https://github.com/bitwarden/server/pull/6892 | https://github.com/bitwarden/server/commit/52955d1860b4dfb905f67bbe39d9b10bbd61ded0
|
||||
"communication": null,
|
||||
"object": "config",
|
||||
}))
|
||||
}
|
||||
|
||||
@@ -577,6 +577,13 @@ async fn post_bulk_access_collections(
|
||||
err!("Can't find organization details")
|
||||
}
|
||||
|
||||
// The collections and members are checked below, the groups only here.
|
||||
let org_groups = Group::find_by_organization(&org_id, &conn).await;
|
||||
let org_group_ids: HashSet<&GroupId> = org_groups.iter().map(|g| &g.uuid).collect();
|
||||
if let Some(g) = data.groups.iter().find(|g| !org_group_ids.contains(&g.id)) {
|
||||
err!("Invalid group", format!("Group {} does not belong to organization {}!", g.id, org_id))
|
||||
}
|
||||
|
||||
for col_id in data.collection_ids {
|
||||
let Some(collection) = Collection::find_by_uuid_and_org(&col_id, &org_id, &conn).await else {
|
||||
err!("Collection not found")
|
||||
@@ -946,6 +953,11 @@ async fn get_members(
|
||||
if org_id != headers.membership.org_uuid {
|
||||
err!("Organization not found", "Organization id's do not match");
|
||||
}
|
||||
|
||||
if !headers.membership.has_full_access() {
|
||||
err_code!("Resource not found.", "User does not have full access", rocket::http::Status::NotFound.code);
|
||||
}
|
||||
|
||||
let mut users_json = Vec::new();
|
||||
for u in Membership::find_by_org(&org_id, &conn).await {
|
||||
users_json.push(
|
||||
@@ -1167,6 +1179,9 @@ async fn send_invite(
|
||||
}
|
||||
|
||||
for group_id in &data.groups {
|
||||
if Group::find_by_uuid_and_org(group_id, &org_id, &conn).await.is_none() {
|
||||
err!("Group not found in Organization")
|
||||
}
|
||||
let mut group_entry = GroupUser::new(group_id.clone(), new_member.uuid.clone());
|
||||
group_entry.save(&conn).await?;
|
||||
}
|
||||
@@ -1614,6 +1629,9 @@ async fn edit_member(
|
||||
GroupUser::delete_all_by_member(&member_to_edit.uuid, &conn).await?;
|
||||
|
||||
for group_id in data.groups.iter().flatten() {
|
||||
if Group::find_by_uuid_and_org(group_id, &org_id, &conn).await.is_none() {
|
||||
err!("Group not found in Organization")
|
||||
}
|
||||
let mut group_entry = GroupUser::new(group_id.clone(), member_to_edit.uuid.clone());
|
||||
group_entry.save(&conn).await?;
|
||||
}
|
||||
@@ -1813,19 +1831,19 @@ async fn post_org_import(
|
||||
// TODO: See if we can optimize the whole cipher adding/importing and prevent duplicate code and checks.
|
||||
Cipher::validate_cipher_data(&data.ciphers)?;
|
||||
|
||||
let existing_collections: HashSet<Option<CollectionId>> =
|
||||
Collection::find_by_organization(&org_id, &conn).await.into_iter().map(|c| Some(c.uuid)).collect();
|
||||
let existing_collections: HashMap<CollectionId, Collection> =
|
||||
Collection::find_by_organization(&org_id, &conn).await.into_iter().map(|c| (c.uuid.clone(), c)).collect();
|
||||
let mut collections: Vec<CollectionId> = Vec::with_capacity(data.collections.len());
|
||||
for col in data.collections {
|
||||
let collection_uuid = if existing_collections.contains(&col.id) {
|
||||
let col_id = col.id.unwrap();
|
||||
// When not an Owner or Admin, check if the member is allowed to access the collection.
|
||||
let existing = col.id.as_ref().and_then(|col_id| existing_collections.get(col_id));
|
||||
let collection_uuid = if let Some(collection) = existing {
|
||||
// When not an Owner or Admin, check if the member is allowed to write to the collection.
|
||||
if headers.membership.atype < MembershipType::Admin
|
||||
&& !Collection::can_access_collection(&headers.membership, &col_id, &conn).await
|
||||
&& !collection.is_writable_by_user(&headers.membership.user_uuid, &conn).await
|
||||
{
|
||||
err!(Compact, "The current user isn't allowed to manage this collection")
|
||||
}
|
||||
col_id
|
||||
collection.uuid.clone()
|
||||
} else {
|
||||
// We do not allow users or managers which can not manage all collections to create new collections
|
||||
// If there is any collection other than an existing import collection, abort the import.
|
||||
@@ -1853,6 +1871,8 @@ async fn post_org_import(
|
||||
for mut cipher_data in data.ciphers {
|
||||
// Always clear folder_id's via an organization import
|
||||
cipher_data.folder_id = None;
|
||||
// Replace the client-provided, unvalidated organizationId with the real target org
|
||||
cipher_data.organization_id = Some(org_id.clone());
|
||||
let mut cipher = Cipher::new(cipher_data.r#type, cipher_data.name.clone());
|
||||
update_cipher_from_data(
|
||||
&mut cipher,
|
||||
@@ -1870,8 +1890,9 @@ async fn post_org_import(
|
||||
|
||||
// Assign the collections
|
||||
for (cipher_index, col_index) in relations {
|
||||
let cipher_id = &ciphers[cipher_index];
|
||||
let col_id = &collections[col_index];
|
||||
let (Some(cipher_id), Some(col_id)) = (ciphers.get(cipher_index), collections.get(col_index)) else {
|
||||
err!(Compact, "Invalid collection relationship")
|
||||
};
|
||||
CollectionCipher::save(cipher_id, col_id, &conn).await?;
|
||||
}
|
||||
|
||||
@@ -2441,6 +2462,23 @@ async fn get_groups_data(
|
||||
if org_id != headers.membership.org_uuid {
|
||||
err!("Organization not found", "Organization id's do not match");
|
||||
}
|
||||
|
||||
// The details view (group→collection/user mappings) needs full org access; the plain list only
|
||||
// needs manage access to a collection, so a manager of a collection (directly or via a group)
|
||||
// can load it to assign groups.
|
||||
let has_full_access = headers.membership.has_full_access()
|
||||
|| (CONFIG.org_groups_enabled()
|
||||
&& GroupUser::has_full_access_by_member(&org_id, &headers.membership.uuid, &conn).await);
|
||||
let allowed = if details {
|
||||
has_full_access
|
||||
} else {
|
||||
has_full_access
|
||||
|| Collection::has_manageable_collection_by_user(&org_id, &headers.membership.user_uuid, &conn).await
|
||||
};
|
||||
if !allowed {
|
||||
err_code!("Resource not found.", "User does not have access", rocket::http::Status::NotFound.code);
|
||||
}
|
||||
|
||||
let groups: Vec<Value> = if CONFIG.org_groups_enabled() {
|
||||
let groups = Group::find_by_organization(&org_id, &conn).await;
|
||||
let mut groups_json = Vec::with_capacity(groups.len());
|
||||
|
||||
@@ -14,7 +14,7 @@ use crate::{
|
||||
db::{
|
||||
DbConn,
|
||||
models::{
|
||||
Group, GroupUser, Invitation, Membership, MembershipStatus, MembershipType, Organization,
|
||||
Group, GroupUser, Invitation, Membership, MembershipStatus, MembershipType, OrgPolicy, Organization,
|
||||
OrganizationApiKey, OrganizationId, User,
|
||||
},
|
||||
},
|
||||
@@ -84,8 +84,15 @@ async fn ldap_import(data: Json<OrgImportData>, token: PublicToken, conn: DbConn
|
||||
}
|
||||
// If user is part of the organization, restore it
|
||||
} else if let Some(mut member) = Membership::find_by_email_and_org(&user_data.email, &org_id, &conn).await {
|
||||
let restored = member.restore();
|
||||
let mut restored = member.restore();
|
||||
let ext_modified = member.set_external_id(Some(user_data.external_id.clone()));
|
||||
// Enforce org policies as every other restore path does.
|
||||
// If the user is not allowed, we revoke again and continue so the external_id is still updated.
|
||||
if restored && let Err(e) = OrgPolicy::check_user_allowed(&member, "restore", &conn).await {
|
||||
warn!("Not restoring {}: {e:?}", user_data.email);
|
||||
member.revoke();
|
||||
restored = false;
|
||||
}
|
||||
if restored || ext_modified {
|
||||
member.save(&conn).await?;
|
||||
}
|
||||
|
||||
+21
-28
@@ -453,6 +453,9 @@ async fn post_access(headers: SendHeaders, conn: DbConn, nt: Notify<'_>) -> Json
|
||||
let Some(send) = Send::find_by_uuid(&headers.send_id, &conn).await else {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
};
|
||||
if !send.is_accessible() {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
process_access(send, conn, nt).await
|
||||
}
|
||||
|
||||
@@ -471,6 +474,8 @@ async fn post_access_legacy(
|
||||
ip: ClientIp,
|
||||
nt: Notify<'_>,
|
||||
) -> JsonResult {
|
||||
crate::ratelimit::check_limit_unauthenticated(&ip.ip)?;
|
||||
|
||||
let Some(mut send) = Send::find_by_access_id(access_id, &conn).await else {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
};
|
||||
@@ -481,17 +486,7 @@ async fn post_access_legacy(
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404);
|
||||
}
|
||||
|
||||
if let Some(expiration) = send.expiration_date
|
||||
&& Utc::now().naive_utc() >= expiration
|
||||
{
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
if Utc::now().naive_utc() >= send.deletion_date {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
if send.disabled {
|
||||
if !send.is_accessible() {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
@@ -505,11 +500,13 @@ async fn post_access_legacy(
|
||||
|
||||
// Files are incremented during the download
|
||||
if send.atype == SendType::Text as i32 {
|
||||
send.access_count += 1;
|
||||
if !send.register_access(&conn).await? {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
} else {
|
||||
send.save(&conn).await?;
|
||||
}
|
||||
|
||||
send.save(&conn).await?;
|
||||
|
||||
process_access(send, conn, nt).await
|
||||
}
|
||||
|
||||
@@ -537,6 +534,9 @@ async fn post_access_file(
|
||||
let Some(send) = Send::find_by_uuid(&headers.send_id, &conn).await else {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
};
|
||||
if !send.is_accessible() {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
process_access_file(send, file_id, host, conn, nt).await
|
||||
}
|
||||
|
||||
@@ -548,8 +548,11 @@ async fn post_access_file_legacy(
|
||||
data: Json<SendAccessData>,
|
||||
host: Host,
|
||||
conn: DbConn,
|
||||
ip: ClientIp,
|
||||
nt: Notify<'_>,
|
||||
) -> JsonResult {
|
||||
crate::ratelimit::check_limit_unauthenticated(&ip.ip)?;
|
||||
|
||||
let Some(mut send) = Send::find_by_uuid(&send_id, &conn).await else {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
};
|
||||
@@ -560,17 +563,7 @@ async fn post_access_file_legacy(
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
if let Some(expiration) = send.expiration_date
|
||||
&& Utc::now().naive_utc() >= expiration
|
||||
{
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
if Utc::now().naive_utc() >= send.deletion_date {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
if send.disabled {
|
||||
if !send.is_accessible() {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
@@ -582,9 +575,9 @@ async fn post_access_file_legacy(
|
||||
}
|
||||
}
|
||||
|
||||
send.access_count += 1;
|
||||
|
||||
send.save(&conn).await?;
|
||||
if !send.register_access(&conn).await? {
|
||||
err_code!(SEND_INACCESSIBLE_MSG, 404)
|
||||
}
|
||||
|
||||
process_access_file(send, file_id, host, conn, nt).await
|
||||
}
|
||||
|
||||
@@ -405,6 +405,22 @@ async fn get_page(url: &str) -> Result<Response, Error> {
|
||||
}
|
||||
|
||||
async fn get_page_with_referer(url: &str, referer: &str) -> Result<Response, Error> {
|
||||
// The resolver only sees hosts needing name resolution, so IP-literal hrefs from
|
||||
// attacker-controlled HTML never reach `post_resolve()`. Check them here.
|
||||
let Ok(parsed_url) = url::Url::parse(url) else {
|
||||
err_silent!("Invalid URL", url)
|
||||
};
|
||||
|
||||
if !matches!(parsed_url.scheme(), "http" | "https") {
|
||||
err_silent!("Invalid scheme", url)
|
||||
}
|
||||
|
||||
let Some(host) = parsed_url.host() else {
|
||||
err_silent!("Invalid host", url)
|
||||
};
|
||||
|
||||
should_block_host(&host)?;
|
||||
|
||||
let mut client = CLIENT.get(url);
|
||||
if !referer.is_empty() {
|
||||
client = client.header("Referer", referer);
|
||||
|
||||
@@ -109,6 +109,7 @@ async fn login(
|
||||
}
|
||||
"authorization_code" => err!("SSO sign-in is not available"),
|
||||
"send_access" => {
|
||||
crate::ratelimit::check_limit_unauthenticated(&client_header.ip.ip)?;
|
||||
check_is_some(data.client_id.as_ref(), "client_id cannot be blank")?;
|
||||
check_is_some(data.send_id.as_ref(), "send_id cannot be blank")?;
|
||||
|
||||
@@ -1055,8 +1056,11 @@ enum RegisterVerificationResponse {
|
||||
#[post("/accounts/register/send-verification-email", data = "<data>")]
|
||||
async fn register_verification_email(
|
||||
data: Json<RegisterVerificationData>,
|
||||
ip: ClientIp,
|
||||
conn: DbConn,
|
||||
) -> ApiResult<RegisterVerificationResponse> {
|
||||
crate::ratelimit::check_limit_unauthenticated(&ip.ip)?;
|
||||
|
||||
let data = data.into_inner();
|
||||
|
||||
// the registration can only continue if signup is allowed or there exists an invitation
|
||||
|
||||
+60
-10
@@ -33,9 +33,14 @@ pub static WS_USERS: LazyLock<Arc<WebSocketUsers>> = LazyLock::new(|| {
|
||||
pub static WS_ANONYMOUS_SUBSCRIPTIONS: LazyLock<Arc<AnonymousWebSocketSubscriptions>> = LazyLock::new(|| {
|
||||
Arc::new(AnonymousWebSocketSubscriptions {
|
||||
map: Arc::new(dashmap::DashMap::new()),
|
||||
connections: Arc::new(dashmap::DashMap::new()),
|
||||
})
|
||||
});
|
||||
|
||||
/// The anonymous hub needs no authentication, so bound how much a single client can hold open.
|
||||
/// One connection is needed per pending login request, several at once are only expected behind NAT.
|
||||
const MAX_ANONYMOUS_CONNECTIONS_PER_IP: u32 = 25;
|
||||
|
||||
static NOTIFICATIONS_DISABLED: LazyLock<bool> = LazyLock::new(|| !CONFIG.enable_websocket() && !CONFIG.push_enabled());
|
||||
|
||||
pub fn routes() -> Vec<Route> {
|
||||
@@ -82,14 +87,21 @@ impl Drop for WSEntryMapGuard {
|
||||
struct WSAnonymousEntryMapGuard {
|
||||
subscriptions: Arc<AnonymousWebSocketSubscriptions>,
|
||||
token: String,
|
||||
entry_uuid: uuid::Uuid,
|
||||
addr: IpAddr,
|
||||
}
|
||||
|
||||
impl WSAnonymousEntryMapGuard {
|
||||
fn new(subscriptions: Arc<AnonymousWebSocketSubscriptions>, token: String, addr: IpAddr) -> Self {
|
||||
fn new(
|
||||
subscriptions: Arc<AnonymousWebSocketSubscriptions>,
|
||||
token: String,
|
||||
entry_uuid: uuid::Uuid,
|
||||
addr: IpAddr,
|
||||
) -> Self {
|
||||
Self {
|
||||
subscriptions,
|
||||
token,
|
||||
entry_uuid,
|
||||
addr,
|
||||
}
|
||||
}
|
||||
@@ -98,7 +110,11 @@ impl WSAnonymousEntryMapGuard {
|
||||
impl Drop for WSAnonymousEntryMapGuard {
|
||||
fn drop(&mut self) {
|
||||
info!("Closing WS connection from {}", self.addr);
|
||||
self.subscriptions.map.remove(&self.token);
|
||||
if let Some(mut entry) = self.subscriptions.map.get_mut(&self.token) {
|
||||
entry.retain(|(uuid, _)| uuid != &self.entry_uuid);
|
||||
}
|
||||
self.subscriptions.map.remove_if(&self.token, |_, senders| senders.is_empty());
|
||||
self.subscriptions.release(self.addr);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -194,12 +210,19 @@ fn anonymous_websockets_hub<'r>(ws: WebSocket, token: String, ip: ClientIp) -> R
|
||||
let (mut rx, guard) = {
|
||||
let subscriptions = Arc::clone(&WS_ANONYMOUS_SUBSCRIPTIONS);
|
||||
|
||||
// Add a channel to send messages to this client to the map
|
||||
if !subscriptions.try_reserve(ip.ip) {
|
||||
err_code!("Too many connections", 429)
|
||||
}
|
||||
|
||||
// Add a channel to send messages to this client to the map.
|
||||
// Clients reconnect with the same token while a login request is still pending, so keep
|
||||
// every subscriber instead of replacing, otherwise the older one takes the newer one down.
|
||||
let (tx, rx) = tokio::sync::mpsc::channel::<Message>(100);
|
||||
subscriptions.map.insert(token.clone(), tx);
|
||||
let entry_uuid = uuid::Uuid::new_v4();
|
||||
subscriptions.map.entry(token.clone()).or_default().push((entry_uuid, tx));
|
||||
|
||||
// Once the guard goes out of scope, the connection will have been closed and the entry will be deleted from the map
|
||||
(rx, WSAnonymousEntryMapGuard::new(subscriptions, token, ip.ip))
|
||||
(rx, WSAnonymousEntryMapGuard::new(subscriptions, token, entry_uuid, ip.ip))
|
||||
};
|
||||
|
||||
Ok({
|
||||
@@ -534,15 +557,42 @@ impl WebSocketUsers {
|
||||
|
||||
#[derive(Clone)]
|
||||
pub struct AnonymousWebSocketSubscriptions {
|
||||
map: Arc<dashmap::DashMap<String, Sender<Message>>>,
|
||||
map: Arc<dashmap::DashMap<String, Vec<UserSenders>>>,
|
||||
connections: Arc<dashmap::DashMap<IpAddr, u32>>,
|
||||
}
|
||||
|
||||
impl AnonymousWebSocketSubscriptions {
|
||||
/// Takes a connection slot for this address, returns false when it already reached the limit.
|
||||
fn try_reserve(&self, addr: IpAddr) -> bool {
|
||||
let mut count = self.connections.entry(addr).or_insert(0);
|
||||
if *count >= MAX_ANONYMOUS_CONNECTIONS_PER_IP {
|
||||
return false;
|
||||
}
|
||||
*count += 1;
|
||||
true
|
||||
}
|
||||
|
||||
/// Releases a slot taken by `try_reserve`.
|
||||
fn release(&self, addr: IpAddr) {
|
||||
let empty = if let Some(mut count) = self.connections.get_mut(&addr) {
|
||||
*count = count.saturating_sub(1);
|
||||
*count == 0
|
||||
} else {
|
||||
false
|
||||
};
|
||||
// Only remove once the guard above is dropped, otherwise this deadlocks.
|
||||
if empty {
|
||||
self.connections.remove_if(&addr, |_, count| *count == 0);
|
||||
}
|
||||
}
|
||||
|
||||
async fn send_update(&self, token: &str, data: &[u8]) {
|
||||
if let Some(sender) = self.map.get(token).map(|v| v.clone())
|
||||
&& let Err(e) = sender.send(Message::binary(data)).await
|
||||
{
|
||||
error!("Error sending WS update {e}");
|
||||
// Clone the senders so the map isn't kept locked while sending.
|
||||
let senders = self.map.get(token).map(|v| v.clone()).unwrap_or_default();
|
||||
for (_, sender) in senders {
|
||||
if let Err(e) = sender.send(Message::binary(data)).await {
|
||||
error!("Error sending WS update {e}");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
+42
-16
@@ -10,6 +10,7 @@ use std::{
|
||||
};
|
||||
|
||||
use chrono::{DateTime, TimeDelta, Utc};
|
||||
use ipnet::IpNet;
|
||||
use jsonwebtoken::{Algorithm, DecodingKey, EncodingKey, Header, errors::ErrorKind};
|
||||
use num_traits::FromPrimitive;
|
||||
use openssl::rsa::Rsa;
|
||||
@@ -1054,12 +1055,44 @@ pub struct ClientIp {
|
||||
pub ip: IpAddr,
|
||||
}
|
||||
|
||||
/// Parses a single entry of `ip_header_trusted_proxies`, which can be a CIDR range or a plain IP.
|
||||
pub fn parse_trusted_proxy(entry: &str) -> Option<IpNet> {
|
||||
let entry = entry.trim();
|
||||
match entry.parse::<IpNet>() {
|
||||
Ok(net) => Some(net),
|
||||
// Without a prefix length it is a single address, which is a valid way to write this.
|
||||
Err(_) => entry.parse::<IpAddr>().ok().map(IpNet::from),
|
||||
}
|
||||
}
|
||||
|
||||
/// The client IP header can be set by anyone able to reach us, so only accept it from a proxy we trust.
|
||||
fn ip_header_is_trusted(remote: Option<IpAddr>) -> bool {
|
||||
let trusted = CONFIG.ip_header_trusted_proxies();
|
||||
let trusted = trusted.trim();
|
||||
if trusted.eq_ignore_ascii_case("all") {
|
||||
return true;
|
||||
}
|
||||
|
||||
let Some(remote) = remote else {
|
||||
return false;
|
||||
};
|
||||
// A dual stack listener reports IPv4 clients as IPv4-mapped IPv6, which `is_global()` reports as
|
||||
// non global. That is what we want when blocking outgoing requests, but here it would trust them.
|
||||
let remote = remote.to_canonical();
|
||||
if trusted.eq_ignore_ascii_case("local") {
|
||||
return !crate::util::is_global(remote);
|
||||
}
|
||||
trusted.split(',').filter_map(parse_trusted_proxy).any(|net| net.contains(&remote))
|
||||
}
|
||||
|
||||
#[rocket::async_trait]
|
||||
impl<'r> FromRequest<'r> for ClientIp {
|
||||
type Error = ();
|
||||
|
||||
async fn from_request(req: &'r Request<'_>) -> Outcome<Self, Self::Error> {
|
||||
let ip = if CONFIG._ip_header_enabled() {
|
||||
let remote = req.remote().map(|r| r.ip());
|
||||
|
||||
let ip = if CONFIG._ip_header_enabled() && ip_header_is_trusted(remote) {
|
||||
req.headers().get_one(&CONFIG.ip_header()).and_then(|ip| {
|
||||
match ip.find(',') {
|
||||
Some(idx) => &ip[..idx],
|
||||
@@ -1070,10 +1103,15 @@ impl<'r> FromRequest<'r> for ClientIp {
|
||||
.ok()
|
||||
})
|
||||
} else {
|
||||
if CONFIG._ip_header_enabled() && req.headers().get_one(&CONFIG.ip_header()).is_some() {
|
||||
// Log the canonical IP, which is what the user filter will need to match against
|
||||
let remote = remote.map(|ip| ip.to_canonical());
|
||||
debug!("Ignoring the '{}' header, {remote:?} is not a trusted proxy", CONFIG.ip_header());
|
||||
}
|
||||
None
|
||||
};
|
||||
|
||||
let ip = ip.or_else(|| req.remote().map(|r| r.ip())).unwrap_or_else(|| "0.0.0.0".parse().unwrap());
|
||||
let ip = ip.or(remote).unwrap_or_else(|| "0.0.0.0".parse().unwrap());
|
||||
|
||||
Outcome::Success(ClientIp {
|
||||
ip,
|
||||
@@ -1268,20 +1306,8 @@ pub async fn refresh_tokens(
|
||||
) -> ApiResult<(Device, AuthTokens)> {
|
||||
let refresh_claims = match decode_refresh(refresh_token) {
|
||||
Err(err) => {
|
||||
error!("Failed to decode {} refresh_token: {refresh_token}: {err:?}", ip.ip);
|
||||
//err_silent!(format!("Impossible to read refresh_token: {}", err.message()))
|
||||
|
||||
// If the token failed to decode, it was probably one of the old style tokens that was just a Base64 string.
|
||||
// We can generate a claim for them for backwards compatibility. Note that the password refresh claims don't
|
||||
// check expiration or issuer, so they're not included here.
|
||||
RefreshJwtClaims {
|
||||
nbf: 0,
|
||||
exp: 0,
|
||||
iss: String::new(),
|
||||
sub: AuthMethod::Password,
|
||||
device_token: refresh_token.into(),
|
||||
token: None,
|
||||
}
|
||||
error!("Failed to decode refresh_token from {}: {err:?}", ip.ip);
|
||||
err_silent!("Invalid refresh token")
|
||||
}
|
||||
Ok(claims) => claims,
|
||||
};
|
||||
|
||||
+5
-14
@@ -85,18 +85,8 @@ impl SendTokens {
|
||||
return Self::invalid_error(&format!("Send {send_id}, max access reached"), "send_id_invalid", true);
|
||||
}
|
||||
|
||||
if let Some(expiration) = send.expiration_date
|
||||
&& Utc::now().naive_utc() >= expiration
|
||||
{
|
||||
return Self::invalid_error(&format!("Send {send_id}, expired"), "send_id_invalid", true);
|
||||
}
|
||||
|
||||
if Utc::now().naive_utc() >= send.deletion_date {
|
||||
return Self::invalid_error(&format!("Send {send_id}, past deletion"), "send_id_invalid", true);
|
||||
}
|
||||
|
||||
if send.disabled {
|
||||
return Self::invalid_error(&format!("Send {send_id}, disabled"), "send_id_invalid", true);
|
||||
if !send.is_accessible() {
|
||||
return Self::invalid_error(&format!("Send {send_id}, not accessible"), "send_id_invalid", true);
|
||||
}
|
||||
|
||||
if send.password_hash.is_some() {
|
||||
@@ -113,8 +103,9 @@ impl SendTokens {
|
||||
}
|
||||
}
|
||||
|
||||
send.access_count += 1;
|
||||
send.save(conn).await?;
|
||||
if !send.register_access(conn).await? {
|
||||
return Self::invalid_error(&format!("Send {send_id}, max access reached"), "send_id_invalid", true);
|
||||
}
|
||||
|
||||
Ok(Self {
|
||||
access_claims: generate_send_access_claims(&send_id),
|
||||
|
||||
@@ -666,6 +666,12 @@ make_config! {
|
||||
ip_header: String, true, def, "X-Real-IP".to_owned();
|
||||
/// Internal IP header property, used to avoid recomputing each time
|
||||
_ip_header_enabled: bool, false, generated, |c| &c.ip_header.trim().to_lowercase() != "none";
|
||||
/// Trusted proxies |> Which addresses the client IP header is accepted from. Requests from any
|
||||
/// other address use the remote IP instead, so a client can't spoof the header.
|
||||
/// Either the string "local" (the default, any non-global address, which covers a reverse proxy
|
||||
/// running on the same host or container network), the string "all" to accept it from anywhere,
|
||||
/// or a comma separated list of IPs and CIDR ranges.
|
||||
ip_header_trusted_proxies: String, true, def, "local".to_owned();
|
||||
/// Icon service |> The predefined icon services are: internal, bitwarden, duckduckgo, google.
|
||||
/// To specify a custom icon service, set a URL template with exactly one instance of `{}`,
|
||||
/// which is replaced with the domain. For example: `https://icon.example.com/domain/{}`.
|
||||
@@ -768,6 +774,11 @@ make_config! {
|
||||
/// Max burst size for login requests |> Allow a burst of requests of up to this size, while maintaining the average indicated by `login_ratelimit_seconds`. Note that this applies to both the login and the 2FA, so it's recommended to allow a burst size of at least 2
|
||||
login_ratelimit_max_burst: u32, false, def, 10;
|
||||
|
||||
/// Seconds between unauthenticated requests |> Number of seconds, on average, between requests from the same IP address to any of the rate limited unauthenticated endpoints
|
||||
unauthenticated_ratelimit_seconds: u64, false, def, 60;
|
||||
/// Max burst size for unauthenticated requests |> Allow a burst of requests of up to this size, while maintaining the average indicated by `unauthenticated_ratelimit_seconds`. This is shared between several endpoints, so it needs to be more lenient than the login one
|
||||
unauthenticated_ratelimit_max_burst: u32, false, def, 50;
|
||||
|
||||
/// Seconds between admin login requests |> Number of seconds, on average, between admin requests from the same IP address before rate limiting kicks in
|
||||
admin_ratelimit_seconds: u64, false, def, 300;
|
||||
/// Max burst size for admin login requests |> Allow a burst of requests of up to this size, while maintaining the average indicated by `admin_ratelimit_seconds`
|
||||
@@ -942,6 +953,18 @@ fn validate_config(cfg: &ConfigItems, on_update: bool) -> Result<(), Error> {
|
||||
}
|
||||
}
|
||||
|
||||
let trusted_proxies = cfg.ip_header_trusted_proxies.trim();
|
||||
if !trusted_proxies.eq_ignore_ascii_case("all") && !trusted_proxies.eq_ignore_ascii_case("local") {
|
||||
for entry in trusted_proxies.split(',').filter(|e| !e.trim().is_empty()) {
|
||||
if crate::auth::parse_trusted_proxy(entry).is_none() {
|
||||
err!(format!(
|
||||
"Invalid IP_HEADER_TRUSTED_PROXIES entry `{}`, expected an IP or CIDR range",
|
||||
entry.trim()
|
||||
));
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
if cfg.password_iterations < 100_000 {
|
||||
err!("PASSWORD_ITERATIONS should be at least 100000 or higher. The default is 600000!");
|
||||
}
|
||||
|
||||
+15
-19
@@ -42,13 +42,15 @@ pub struct Cipher {
|
||||
|
||||
pub key: Option<String>,
|
||||
|
||||
/*
|
||||
Login = 1,
|
||||
SecureNote = 2,
|
||||
Card = 3,
|
||||
Identity = 4,
|
||||
SshKey = 5
|
||||
*/
|
||||
// See (v2026.7.0): https://github.com/bitwarden/server/blob/5d4461aa42cadbacfef8fe2166c5453a5c52773a/src/Core/Vault/Enums/CipherType.cs
|
||||
// Login = 1,
|
||||
// SecureNote = 2,
|
||||
// Card = 3,
|
||||
// Identity = 4,
|
||||
// SSHKey = 5
|
||||
// BankAccount = 6,
|
||||
// DriversLicense = 7,
|
||||
// Passport = 8,
|
||||
pub atype: i32,
|
||||
pub name: String,
|
||||
pub notes: Option<String>,
|
||||
@@ -306,16 +308,6 @@ impl Cipher {
|
||||
type_data_json = Value::Null;
|
||||
}
|
||||
|
||||
// Clone the type_data and add some default value.
|
||||
let mut data_json = type_data_json.clone();
|
||||
|
||||
// NOTE: This was marked as *Backwards Compatibility Code*, but as of January 2021 this is still being used by upstream
|
||||
// data_json should always contain the following keys with every atype
|
||||
data_json["fields"] = json!(fields_json);
|
||||
data_json["name"] = json!(self.name);
|
||||
data_json["notes"] = json!(self.notes);
|
||||
data_json["passwordHistory"] = Value::Array(password_history_json.clone());
|
||||
|
||||
let collection_ids = if let Some(cipher_sync_data) = cipher_sync_data {
|
||||
if let Some(cipher_collections) = cipher_sync_data.cipher_collections.get(&self.uuid) {
|
||||
Cow::from(cipher_collections)
|
||||
@@ -355,8 +347,6 @@ impl Cipher {
|
||||
"notes": self.notes,
|
||||
"fields": fields_json,
|
||||
|
||||
"data": data_json,
|
||||
|
||||
"passwordHistory": password_history_json,
|
||||
|
||||
// All Cipher types are included by default as null, but only the matching one will be populated
|
||||
@@ -365,6 +355,9 @@ impl Cipher {
|
||||
"card": null,
|
||||
"identity": null,
|
||||
"sshKey": null,
|
||||
"bankAccount": null,
|
||||
"driversLicense": null,
|
||||
"passport": null,
|
||||
});
|
||||
|
||||
// These values are only needed for user/default syncs
|
||||
@@ -404,6 +397,9 @@ impl Cipher {
|
||||
3 => "card",
|
||||
4 => "identity",
|
||||
5 => "sshKey",
|
||||
6 => "bankAccount",
|
||||
7 => "driversLicense",
|
||||
8 => "passport",
|
||||
_ => err!(format!("Cipher {} has an invalid type {}", self.uuid, self.atype)),
|
||||
};
|
||||
|
||||
|
||||
@@ -21,6 +21,7 @@ use super::{
|
||||
User, UserId,
|
||||
};
|
||||
|
||||
// See (v2026.7.0): https://github.com/bitwarden/server/blob/5d4461aa42cadbacfef8fe2166c5453a5c52773a/src/Core/AdminConsole/Entities/Collection.cs
|
||||
#[derive(Identifiable, Queryable, Insertable, AsChangeset)]
|
||||
#[diesel(table_name = collections)]
|
||||
#[diesel(treat_none_as_null = true)]
|
||||
@@ -71,6 +72,11 @@ impl Collection {
|
||||
"id": self.uuid,
|
||||
"organizationId": self.org_uuid,
|
||||
"name": self.name,
|
||||
// Collection types are either 0: SharedCollection or 1: DefaultUserCollection, of which we do not yet support DefaultUserCollection.
|
||||
// See (v2026.7.0): https://github.com/bitwarden/server/blob/5d4461aa42cadbacfef8fe2166c5453a5c52773a/src/Core/AdminConsole/Enums/CollectionType.cs
|
||||
"type": 0,
|
||||
// This is only used together with MyItems/DefaultUserCollection, which we do not yet support.
|
||||
"defaultUserCollectionEmail": null,
|
||||
"object": "collection",
|
||||
})
|
||||
}
|
||||
@@ -623,6 +629,47 @@ impl Collection {
|
||||
pub async fn is_manageable_by_user(&self, user_uuid: &UserId, conn: &DbConn) -> bool {
|
||||
Self::is_coll_manageable_by_user(&self.uuid, user_uuid, conn).await
|
||||
}
|
||||
|
||||
// Whether the user has manage access to at least one collection in the org, directly or via a
|
||||
// group. Org-scoped counterpart of is_coll_manageable_by_user.
|
||||
pub async fn has_manageable_collection_by_user(
|
||||
org_uuid: &OrganizationId,
|
||||
user_uuid: &UserId,
|
||||
conn: &DbConn,
|
||||
) -> bool {
|
||||
let org_uuid = org_uuid.to_string();
|
||||
let user_uuid = user_uuid.to_string();
|
||||
conn.run(move |conn| {
|
||||
collections::table
|
||||
.left_join(
|
||||
users_collections::table.on(users_collections::collection_uuid
|
||||
.eq(collections::uuid)
|
||||
.and(users_collections::user_uuid.eq(user_uuid.clone()))),
|
||||
)
|
||||
.left_join(
|
||||
users_organizations::table.on(collections::org_uuid
|
||||
.eq(users_organizations::org_uuid)
|
||||
.and(users_organizations::user_uuid.eq(user_uuid))),
|
||||
)
|
||||
.left_join(groups_users::table.on(groups_users::users_organizations_uuid.eq(users_organizations::uuid)))
|
||||
.left_join(
|
||||
collections_groups::table.on(collections_groups::groups_uuid
|
||||
.eq(groups_users::groups_uuid)
|
||||
.and(collections_groups::collections_uuid.eq(collections::uuid))),
|
||||
)
|
||||
.filter(collections::org_uuid.eq(&org_uuid))
|
||||
.filter(
|
||||
// Manage permission on a collection assigned directly or via a group.
|
||||
users_collections::manage.eq(true).or(collections_groups::manage.eq(true)),
|
||||
)
|
||||
.count()
|
||||
.first::<i64>(conn)
|
||||
.ok()
|
||||
.unwrap_or(0)
|
||||
!= 0
|
||||
})
|
||||
.await
|
||||
}
|
||||
}
|
||||
|
||||
/// Database methods
|
||||
|
||||
@@ -271,7 +271,9 @@ impl Group {
|
||||
groups::table
|
||||
.inner_join(groups_users::table.on(groups_users::groups_uuid.eq(groups::uuid)))
|
||||
.inner_join(
|
||||
users_organizations::table.on(users_organizations::uuid.eq(groups_users::users_organizations_uuid)),
|
||||
users_organizations::table.on(users_organizations::uuid
|
||||
.eq(groups_users::users_organizations_uuid)
|
||||
.and(users_organizations::org_uuid.eq(groups::organizations_uuid))),
|
||||
)
|
||||
.filter(users_organizations::user_uuid.eq(user_uuid))
|
||||
.filter(groups::organizations_uuid.eq(org_uuid))
|
||||
|
||||
@@ -217,11 +217,18 @@ impl Organization {
|
||||
"useSecretsManager": false, // Not supported (Not AGPLv3 Licensed)
|
||||
"selfHost": true,
|
||||
"useApi": true,
|
||||
"useDisableSMAdsForUsers": true, // Hide Secrets Manager ads
|
||||
"useInviteLinks": false, // Not (yet) supported
|
||||
"useMyItems": false, // Not (yet) supported
|
||||
"useOrganizationDomains": false, // Not supported (Linked to SSO)
|
||||
"usePam": false, // Not supported
|
||||
"usePhishingBlocker": false,
|
||||
"hasPublicAndPrivateKeys": self.private_key.is_some() && self.public_key.is_some(),
|
||||
"useResetPassword": CONFIG.mail_enabled(),
|
||||
"allowAdminAccessToAllCollectionItems": true,
|
||||
"limitCollectionCreation": true,
|
||||
"limitCollectionDeletion": true,
|
||||
"limitItemDeletion": false,
|
||||
|
||||
"businessName": self.name,
|
||||
"businessAddress1": null,
|
||||
@@ -495,6 +502,12 @@ impl Membership {
|
||||
"useActivateAutofillPolicy": false,
|
||||
"useAdminSponsoredFamilies": false,
|
||||
"useRiskInsights": false, // Not supported (Not AGPLv3 Licensed)
|
||||
"useDisableSMAdsForUsers": true, // Hide Secrets Manager ads
|
||||
"useInviteLinks": false, // Not (yet) supported
|
||||
"useMyItems": false, // Not (yet) supported
|
||||
"useOrganizationDomains": false, // Not supported (Linked to SSO)
|
||||
"usePam": false, // Not supported
|
||||
"usePhishingBlocker": false,
|
||||
|
||||
"organizationUserId": self.uuid,
|
||||
"providerId": null,
|
||||
|
||||
@@ -231,6 +231,53 @@ impl Send {
|
||||
}
|
||||
}
|
||||
|
||||
/// Registers an access, incrementing `access_count` only while below `max_access_count`.
|
||||
/// Returns false when the limit was already reached. The check and the increment are a single
|
||||
/// statement, otherwise concurrent accesses can both pass the check and exceed the limit.
|
||||
pub async fn register_access(&mut self, conn: &DbConn) -> Result<bool, crate::Error> {
|
||||
self.update_users_revision(conn).await;
|
||||
|
||||
let revision_date = Utc::now().naive_utc();
|
||||
let uuid = self.uuid.clone();
|
||||
let updated = conn
|
||||
.run(move |conn| {
|
||||
diesel::update(sends::table)
|
||||
.filter(sends::uuid.eq(uuid))
|
||||
.filter(
|
||||
sends::max_access_count
|
||||
.is_null()
|
||||
.or(sends::access_count.nullable().lt(sends::max_access_count)),
|
||||
)
|
||||
.set((sends::access_count.eq(sends::access_count + 1), sends::revision_date.eq(revision_date)))
|
||||
.execute(conn)
|
||||
})
|
||||
.await?;
|
||||
|
||||
if updated == 0 {
|
||||
return Ok(false);
|
||||
}
|
||||
|
||||
self.access_count += 1;
|
||||
self.revision_date = revision_date;
|
||||
Ok(true)
|
||||
}
|
||||
|
||||
/// Whether the Send is currently within its validity window: not disabled, not past its
|
||||
/// expiration date, and not past its deletion date. Does not consider `max_access_count`
|
||||
/// (consumed at token issuance) or the password.
|
||||
pub fn is_accessible(&self) -> bool {
|
||||
let now = Utc::now().naive_utc();
|
||||
if self.disabled {
|
||||
return false;
|
||||
}
|
||||
if let Some(expiration) = self.expiration_date
|
||||
&& now >= expiration
|
||||
{
|
||||
return false;
|
||||
}
|
||||
now < self.deletion_date
|
||||
}
|
||||
|
||||
pub async fn delete(&self, conn: &DbConn) -> EmptyResult {
|
||||
self.update_users_revision(conn).await;
|
||||
|
||||
|
||||
@@ -268,8 +268,25 @@ impl User {
|
||||
UserStatus::Enabled
|
||||
};
|
||||
|
||||
let account_keys = if self.private_key.is_some() {
|
||||
json!({
|
||||
"publicKeyEncryptionKeyPair": {
|
||||
"wrappedPrivateKey": self.private_key,
|
||||
"publicKey": self.public_key,
|
||||
"signedPublicKey": null,
|
||||
"object": "publicKeyEncryptionKeyPair",
|
||||
},
|
||||
"securityState": null,
|
||||
"signatureKeyPair": null,
|
||||
"object": "privateKeys"
|
||||
})
|
||||
} else {
|
||||
Value::Null
|
||||
};
|
||||
|
||||
json!({
|
||||
"_status": status as i32,
|
||||
"accountKeys": account_keys,
|
||||
"id": self.uuid,
|
||||
"name": self.name,
|
||||
"email": self.email,
|
||||
|
||||
+27
-8
@@ -174,6 +174,27 @@ pub enum CustomHttpClientError {
|
||||
}
|
||||
|
||||
impl CustomHttpClientError {
|
||||
/// Attach the domain that resolved to this address, which `should_block_host()` can't know.
|
||||
fn with_domain(self, name: &str) -> Self {
|
||||
match self {
|
||||
Self::NonGlobalIp {
|
||||
ip,
|
||||
..
|
||||
} => Self::NonGlobalIp {
|
||||
domain: Some(name.to_owned()),
|
||||
ip,
|
||||
},
|
||||
Self::Blocked {
|
||||
domain,
|
||||
} => Self::Blocked {
|
||||
domain: format!("{name} ({domain})"),
|
||||
},
|
||||
other @ Self::Invalid {
|
||||
..
|
||||
} => other,
|
||||
}
|
||||
}
|
||||
|
||||
pub fn downcast_ref(e: &dyn std::error::Error) -> Option<&Self> {
|
||||
let mut source = e.source();
|
||||
|
||||
@@ -285,14 +306,12 @@ fn pre_resolve(name: &str, enforce_block: bool) -> Result<(), CustomHttpClientEr
|
||||
}
|
||||
|
||||
fn post_resolve(name: &str, ip: IpAddr) -> Result<(), CustomHttpClientError> {
|
||||
if should_block_ip(ip) {
|
||||
Err(CustomHttpClientError::NonGlobalIp {
|
||||
domain: Some(name.to_owned()),
|
||||
ip,
|
||||
})
|
||||
} else {
|
||||
Ok(())
|
||||
}
|
||||
let host: Host<&str> = match ip {
|
||||
IpAddr::V4(ip) => Host::Ipv4(ip),
|
||||
IpAddr::V6(ip) => Host::Ipv6(ip),
|
||||
};
|
||||
|
||||
should_block_host(&host).map_err(|e| e.with_domain(name))
|
||||
}
|
||||
|
||||
impl Resolve for CustomDns {
|
||||
|
||||
+1
-1
@@ -2,7 +2,7 @@
|
||||
// The recursion_limit is mainly triggered by the json!() macro.
|
||||
// The more key/value pairs there are the more recursion occurs.
|
||||
// We want to keep this as low as possible!
|
||||
#![recursion_limit = "165"]
|
||||
#![recursion_limit = "192"]
|
||||
|
||||
// When enabled use MiMalloc as malloc instead of the default malloc
|
||||
#[cfg(feature = "enable_mimalloc")]
|
||||
|
||||
@@ -18,6 +18,24 @@ static LIMITER_ADMIN: LazyLock<Limiter> = LazyLock::new(|| {
|
||||
RateLimiter::keyed(Quota::with_period(seconds).expect("Non-zero admin ratelimit seconds").allow_burst(burst))
|
||||
});
|
||||
|
||||
static LIMITER_UNAUTHENTICATED: LazyLock<Limiter> = LazyLock::new(|| {
|
||||
let seconds = Duration::from_secs(CONFIG.unauthenticated_ratelimit_seconds());
|
||||
let burst = NonZeroU32::new(CONFIG.unauthenticated_ratelimit_max_burst())
|
||||
.expect("Non-zero unauthenticated ratelimit burst");
|
||||
RateLimiter::keyed(
|
||||
Quota::with_period(seconds).expect("Non-zero unauthenticated ratelimit seconds").allow_burst(burst),
|
||||
)
|
||||
});
|
||||
|
||||
pub fn check_limit_unauthenticated(ip: &IpAddr) -> Result<(), Error> {
|
||||
match LIMITER_UNAUTHENTICATED.check_key(ip) {
|
||||
Ok(()) => Ok(()),
|
||||
Err(_e) => {
|
||||
err_code!("Too many requests", 429);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
pub fn check_limit_login(ip: &IpAddr) -> Result<(), Error> {
|
||||
match LIMITER_LOGIN.check_key(ip) {
|
||||
Ok(()) => Ok(()),
|
||||
|
||||
+3
-1
@@ -95,7 +95,9 @@ impl<'c> AsyncHttpClient<'c> for OidcHttpClient {
|
||||
}
|
||||
|
||||
let body = response.bytes().await.map_err(Box::new)?;
|
||||
debug!("Response body {}", String::from_utf8_lossy(&body));
|
||||
if CONFIG.sso_debug_tokens() {
|
||||
debug!("Response body {}", String::from_utf8_lossy(&body));
|
||||
}
|
||||
builder.body(body.to_vec()).map_err(HttpClientError::Http)
|
||||
})
|
||||
}
|
||||
|
||||
@@ -116,8 +116,8 @@ app-security > app-two-factor-setup > form {
|
||||
}
|
||||
|
||||
/* Hide unsupported Custom Role options */
|
||||
bit-dialog div.tw-ml-4:has(bit-form-control input),
|
||||
bit-dialog div.tw-col-span-4:has(input[formcontrolname*="access"], input[formcontrolname*="manage"]) {
|
||||
:is(bit-dialog, [bit-dialog]) div.tw-ml-4:has(bit-form-control input),
|
||||
:is(bit-dialog, [bit-dialog]) div.tw-col-span-4:has(input[formcontrolname*="access"], input[formcontrolname*="manage"]) {
|
||||
@extend %vw-hide;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user