Problem
The install wizard has to save settings before any admin exists, so PATCH /api/v1/settings (and the wizard's image upload) accept anonymous requests while IsWizardMode is true, which means "there is no row in admin_users".
That window stays open from the moment the database step is saved until someone completes the GitHub login. On a server that is reachable from the internet during install, anyone who finds it can change the settings, including custom_header_code and custom_footer_code, which are printed into every page as raw HTML. The window has no time limit: an install that is abandoned at the auth step stays open.
The install smoke test (#652) relies on this, since it saves the site title without logging in.
Ideas
- Tie the wizard to the browser that started it: mint a setup token when the database step is saved, keep it in the session, and require it on the pre-admin endpoints.
- Or print a one-time setup code to the server log and ask for it on the first wizard page.
- At minimum, document that the install should be finished before the site is exposed.
Related: #654 (first admin without a GitHub OAuth app).
Found while scoping #651.
Problem
The install wizard has to save settings before any admin exists, so
PATCH /api/v1/settings(and the wizard's image upload) accept anonymous requests whileIsWizardModeis true, which means "there is no row inadmin_users".That window stays open from the moment the database step is saved until someone completes the GitHub login. On a server that is reachable from the internet during install, anyone who finds it can change the settings, including
custom_header_codeandcustom_footer_code, which are printed into every page as raw HTML. The window has no time limit: an install that is abandoned at the auth step stays open.The install smoke test (#652) relies on this, since it saves the site title without logging in.
Ideas
Related: #654 (first admin without a GitHub OAuth app).
Found while scoping #651.