Skip to content

Settings can be changed by anyone until the first admin logs in #658

Description

@compscidr

Problem

The install wizard has to save settings before any admin exists, so PATCH /api/v1/settings (and the wizard's image upload) accept anonymous requests while IsWizardMode is true, which means "there is no row in admin_users".

That window stays open from the moment the database step is saved until someone completes the GitHub login. On a server that is reachable from the internet during install, anyone who finds it can change the settings, including custom_header_code and custom_footer_code, which are printed into every page as raw HTML. The window has no time limit: an install that is abandoned at the auth step stays open.

The install smoke test (#652) relies on this, since it saves the site title without logging in.

Ideas

  • Tie the wizard to the browser that started it: mint a setup token when the database step is saved, keep it in the session, and require it on the pre-admin endpoints.
  • Or print a one-time setup code to the server log and ask for it on the first wizard page.
  • At minimum, document that the install should be finished before the site is exposed.

Related: #654 (first admin without a GitHub OAuth app).

Found while scoping #651.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions