mirror of
https://github.com/multica-ai/multica.git
synced 2026-07-26 20:45:37 +02:00
* feat(auth): support mcn_ Cloud Node PATs verified via Fleet
Adds a new token kind, mcn_ (multica cloud node), recognized in both
the regular Auth and DaemonAuth middlewares. mcn_ tokens are minted
and owned by Multica Cloud (not the local personal_access_tokens
table); the server validates them by POSTing to the Fleet's
/api/v1/pat/verify endpoint and uses the returned owner_id as
X-User-ID for downstream handlers.
Cloud is the authoritative owner of token status, so this is a
verifier-only path with no DB fallback:
* Fleet says valid:false -> 401 (token genuinely bad)
* Fleet unreachable / 5xx -> 503 (transient, retry)
* No MULTICA_CLOUD_FLEET_URL configured -> 401 (fail closed)
Verification results are cached in Redis for 60s under
mul:auth:mcn:<sha256> to bound the per-request load on Fleet without
extending the revocation window beyond what the Cloud doc allows.
Negative results are NOT cached, so a freshly minted token doesn't
get locked out by a stale 'token_not_found'.
Reuses MULTICA_CLOUD_FLEET_URL (the same env the cloud-runtime proxy
already uses) so deployments don't need a second config knob.
Tests cover the happy path, every documented invalid reason, 4xx/5xx
mapping, network error, decode error, ctx cancellation, the
fail-closed valid:true-without-owner_id case, trailing-slash URL
normalization, and the Redis cache short-circuit + negative
no-cache contract. Middleware tests pin the four 401/503/200 outcomes
in both Auth and DaemonAuth.
* auth(mcn): require owner_id to map to a real local user; drop X-User-PAT plumbing
Two related changes:
1. Cloud-verified owner_id is now checked against our local users table.
The Cloud owner_id and our users.id share the same UUID space by
contract; a missing local user means either the row was deleted
under an active node or something is forging owner_ids — either
way, fail closed.
CloudPATVerifier.Verify takes a new OwnerLookupFunc:
- returns (true, nil) -> success, cache + return
- returns (false, nil) -> ErrCloudPATInvalid (reason='owner_unknown'),
NOT cached (so a freshly-created user
doesn't get locked out for a TTL window)
- returns (_, error) -> ErrCloudPATUnavailable (transient,
middleware emits 503)
Both Auth and DaemonAuth wire ownerLookupFor(queries), a new shared
helper that wraps queries.GetUser, mapping pgx.ErrNoRows / unparseable
UUIDs to (false, nil) and other errors to a real Go error.
2. Removed all X-User-PAT plumbing. Cloud now mints node-scoped mcn_
PATs itself during /api/v1/nodes (see multica-cloud
docs/api/node-pat.md) and ships them into the EC2 instance via SSM,
so multica-api no longer needs to forward the caller's mul_ PAT.
Propagating a long-lived user PAT into a remote machine widened
the blast radius of any node compromise; that's gone now.
Removed:
- cloud_runtime.go: withUserPAT option, cloudRuntimeUserPAT,
generateCloudRuntimePAT, revokeGeneratedPAT
- cloudruntime/Request.UserPAT field + X-User-PAT header
- X-User-PAT from CORS allowed headers
- obsolete handler tests:
TestCreateCloudRuntimeNodeForwardsValidatedPAT
TestCreateCloudRuntimeNodeRejectsUnownedPAT
TestCreateCloudRuntimeNodeRejectsExpiredPAT
TestCreateCloudRuntimeNodeAutoGeneratesPAT
replaced with TestCreateCloudRuntimeNodeForwardsBody
- X-User-PAT references in packages/core/api/client.test.ts
Tests:
* 3 new verifier-level tests (owner_unknown not cached, lookup error
-> Unavailable, success path is cached for both fleet AND lookup)
* 5 new owner_lookup_test.go tests (nil queries, existing user,
missing user, malformed UUID, DB error)
* 1 new end-to-end DaemonAuth test (cloud says valid, no local user
-> 401)
* Existing X-User-PAT TS assertions removed; full vitest run passes.
* go test ./... and go vet ./... clean on the server module.
60 lines
2.2 KiB
Go
60 lines
2.2 KiB
Go
package middleware
|
|
|
|
import (
|
|
"context"
|
|
"errors"
|
|
|
|
"github.com/jackc/pgx/v5"
|
|
"github.com/multica-ai/multica/server/internal/auth"
|
|
"github.com/multica-ai/multica/server/internal/util"
|
|
db "github.com/multica-ai/multica/server/pkg/db/generated"
|
|
)
|
|
|
|
// ownerLookupFor returns an auth.OwnerLookupFunc that asks the
|
|
// generated GetUser query whether `ownerID` is a real row in our
|
|
// `user` table. It is used by the mcn_ branches of Auth and
|
|
// DaemonAuth to confirm that Cloud's owner_id maps to a known local
|
|
// user before the verifier returns success / caches the result.
|
|
//
|
|
// Behaviour:
|
|
// - queries==nil → returns nil (no lookup; verifier skips step 3).
|
|
// This path only kicks in when a middleware is constructed
|
|
// without a DB handle, which only happens in tests that exercise
|
|
// the verifier wiring without a real database.
|
|
// - GetUser hits → (true, nil): owner_id is a known user.
|
|
// - pgx.ErrNoRows → (false, nil): owner_id is unknown.
|
|
// The verifier maps this to ErrCloudPATInvalid (reason
|
|
// "owner_unknown") without caching.
|
|
// - any other error → (_, err): treated as infrastructure failure;
|
|
// the verifier maps this to ErrCloudPATUnavailable so the
|
|
// middleware returns 503 (transient).
|
|
//
|
|
// Parsing the UUID is done via util.ParseUUID, which returns a zero
|
|
// UUID on a malformed input. A zero UUID will not match any real row,
|
|
// so the eventual GetUser call cleanly resolves to (false, nil) and
|
|
// the request is rejected — there is no need for a separate "looks
|
|
// like a UUID" precheck here. Cloud has already vetted the format
|
|
// before signing the verify response.
|
|
func ownerLookupFor(queries *db.Queries) auth.OwnerLookupFunc {
|
|
if queries == nil {
|
|
return nil
|
|
}
|
|
return func(ctx context.Context, ownerID string) (bool, error) {
|
|
uuid, err := util.ParseUUID(ownerID)
|
|
if err != nil {
|
|
// Cloud returned something that doesn't parse as a UUID.
|
|
// That's a contract violation, not a transient failure —
|
|
// reject the token like any owner_unknown.
|
|
return false, nil
|
|
}
|
|
_, err = queries.GetUser(ctx, uuid)
|
|
if err != nil {
|
|
if errors.Is(err, pgx.ErrNoRows) {
|
|
return false, nil
|
|
}
|
|
return false, err
|
|
}
|
|
return true, nil
|
|
}
|
|
}
|