From a26680f4607a6ea47c7d5cbf3b2f0381629de600 Mon Sep 17 00:00:00 2001 From: elky Date: Mon, 7 Sep 2026 12:07:53 +0800 Subject: [PATCH] fix(modules): restore legacy SMTP password migration --- .../handlers/shared/system_config_values.rs | 181 +++++++++++++++++- .../src/important_notification.rs | 49 ++++- .../src/tests/control/admin/health_access.rs | 151 ++++++++++++++- 3 files changed, 369 insertions(+), 12 deletions(-) diff --git a/apps/aether-gateway/src/handlers/shared/system_config_values.rs b/apps/aether-gateway/src/handlers/shared/system_config_values.rs index 293eac0e1..2997a6baa 100644 --- a/apps/aether-gateway/src/handlers/shared/system_config_values.rs +++ b/apps/aether-gateway/src/handlers/shared/system_config_values.rs @@ -120,8 +120,16 @@ pub(crate) async fn decrypt_or_migrate_smtp_password( } let plaintext = decrypt_system_config_secret(state, "smtp_password", stored.trim()) .or_else(|| { - (!stored.trim().is_empty() && !looks_like_python_fernet_ciphertext(stored.trim())) - .then(|| stored.trim().to_string()) + if stored_secret_uses_known_envelope_family(stored.trim()) { + return None; + } + decrypt_catalog_secret_with_fallbacks(state.encryption_key(), stored.trim()).or_else( + || { + (!stored.trim().is_empty() + && !looks_like_python_fernet_ciphertext(stored.trim())) + .then(|| stored.trim().to_string()) + }, + ) }) .ok_or_else(|| system_config_secret_error("stored SMTP password cannot be decrypted"))?; if plaintext.contains('\0') { @@ -700,11 +708,13 @@ mod tests { use super::{ bark_device_key_binding, decrypt_bark_device_key_v2, decrypt_ldap_bind_password_v2, decrypt_ldap_bind_password_v3, decrypt_or_migrate_bark_device_key, - decrypt_or_migrate_ldap_bind_password, decrypt_or_migrate_system_config_secret, + decrypt_or_migrate_ldap_bind_password, decrypt_or_migrate_smtp_password, + decrypt_or_migrate_system_config_secret, decrypt_or_migrate_system_config_secret_with_before_compare, decrypt_system_config_secret, - encrypt_bark_device_key, encrypt_ldap_bind_password, encrypt_system_config_secret, - ldap_module_config_is_valid, normalize_ldap_transport_server_url, - LDAP_BIND_PASSWORD_V2_PREFIX, LDAP_BIND_PASSWORD_V3_PREFIX, SYSTEM_CONFIG_SECRET_V2_PREFIX, + encrypt_bark_device_key, encrypt_ldap_bind_password, encrypt_smtp_password, + encrypt_system_config_secret, ldap_module_config_is_valid, + normalize_ldap_transport_server_url, smtp_password_binding, LDAP_BIND_PASSWORD_V2_PREFIX, + LDAP_BIND_PASSWORD_V3_PREFIX, SMTP_PASSWORD_V3_PREFIX, SYSTEM_CONFIG_SECRET_V2_PREFIX, }; use crate::data::GatewayDataState; use crate::AppState; @@ -740,6 +750,165 @@ mod tests { state } + #[tokio::test] + async fn smtp_password_migrates_legacy_formats_to_bound_v3() { + let binding = smtp_password_binding( + "smtp.example.com", + 587, + Some("ops@example.com"), + true, + false, + ) + .expect("SMTP binding should build"); + let fixture_state = state_with_stored_secret(TEST_SECRET); + let legacy_values = [ + TEST_SECRET.to_string(), + encrypt_python_fernet_plaintext(DEVELOPMENT_ENCRYPTION_KEY, TEST_SECRET) + .expect("legacy SMTP password should encrypt"), + encrypt_system_config_secret(&fixture_state, TEST_KEY, TEST_SECRET) + .expect("v2 SMTP password should encrypt"), + ]; + + for legacy in legacy_values { + let state = state_with_stored_secret(&legacy); + let plaintext = decrypt_or_migrate_smtp_password(&state, &binding, legacy.clone()) + .await + .expect("legacy SMTP password should migrate"); + assert_eq!(plaintext, TEST_SECRET); + let migrated = state + .read_system_config_json_value_strong(TEST_KEY) + .await + .expect("SMTP password should read") + .and_then(|value| value.as_str().map(ToOwned::to_owned)) + .expect("SMTP password should be a string"); + assert!(migrated.starts_with(SMTP_PASSWORD_V3_PREFIX)); + assert_ne!(migrated, legacy); + assert_eq!( + decrypt_or_migrate_smtp_password(&state, &binding, migrated.clone()) + .await + .expect("migrated SMTP password should decrypt"), + TEST_SECRET + ); + assert_eq!( + state + .read_system_config_json_value_strong(TEST_KEY) + .await + .unwrap(), + Some(json!(migrated)) + ); + } + } + + #[tokio::test] + async fn smtp_password_rejects_invalid_ciphertext_without_rewriting() { + let binding = smtp_password_binding( + "smtp.example.com", + 587, + Some("ops@example.com"), + true, + false, + ) + .expect("SMTP binding should build"); + let fixture_state = state_with_stored_secret(TEST_SECRET); + let mut tampered = encrypt_python_fernet_plaintext(DEVELOPMENT_ENCRYPTION_KEY, TEST_SECRET) + .expect("legacy SMTP password should encrypt"); + tampered.replace_range(tampered.len() - 2.., "AA"); + let invalid_values = [ + tampered, + encrypt_python_fernet_plaintext("unavailable-historical-key", TEST_SECRET) + .expect("wrong-key SMTP password should encrypt"), + encrypt_system_config_secret(&fixture_state, "other_secret", TEST_SECRET) + .expect("wrong-purpose secret should encrypt"), + "aether-system-config-secret-v2:invalid".to_string(), + "aether-smtp-password-v3:invalid".to_string(), + "aether-runtime-secret-v1:invalid".to_string(), + "aether-unknown-secret-v4:invalid".to_string(), + ]; + + for stored in invalid_values { + let state = state_with_stored_secret(&stored); + let error = decrypt_or_migrate_smtp_password(&state, &binding, stored.clone()) + .await + .expect_err("invalid ciphertext must not become an SMTP password"); + assert_eq!( + error.into_message(), + "stored SMTP password cannot be decrypted" + ); + assert_eq!( + state + .read_system_config_json_value_strong(TEST_KEY) + .await + .unwrap(), + Some(json!(stored)) + ); + } + } + + #[tokio::test] + async fn smtp_password_v3_rejects_changed_transport_binding() { + let binding = smtp_password_binding( + "smtp.example.com", + 587, + Some("ops@example.com"), + true, + false, + ) + .expect("SMTP binding should build"); + let stored = encrypt_smtp_password( + &state_with_stored_secret(TEST_SECRET), + &binding, + TEST_SECRET, + ) + .expect("SMTP password should encrypt"); + let state = state_with_stored_secret(&stored); + for changed_binding in [ + smtp_password_binding( + "other.example.com", + 587, + Some("ops@example.com"), + true, + false, + ), + smtp_password_binding( + "smtp.example.com", + 465, + Some("ops@example.com"), + true, + false, + ), + smtp_password_binding( + "smtp.example.com", + 587, + Some("other@example.com"), + true, + false, + ), + smtp_password_binding( + "smtp.example.com", + 587, + Some("ops@example.com"), + false, + false, + ), + smtp_password_binding("smtp.example.com", 587, Some("ops@example.com"), true, true), + ] { + assert!(decrypt_or_migrate_smtp_password( + &state, + &changed_binding.expect("changed binding should build"), + stored.clone(), + ) + .await + .is_err()); + } + assert_eq!( + state + .read_system_config_json_value_strong(TEST_KEY) + .await + .unwrap(), + Some(json!(stored)) + ); + } + fn ldap_config(bind_password: &str) -> StoredLdapModuleConfig { StoredLdapModuleConfig { server_url: "ldaps://ldap.example.com".to_string(), diff --git a/apps/aether-gateway/src/important_notification.rs b/apps/aether-gateway/src/important_notification.rs index 70f2fcd79..775c6d059 100644 --- a/apps/aether-gateway/src/important_notification.rs +++ b/apps/aether-gateway/src/important_notification.rs @@ -238,9 +238,11 @@ async fn read_notification_channel_readiness( state: &AppState, config: &ImportantNotificationConfig, ) -> Result { - let smtp_config = read_smtp_delivery_config(state).await?; + let email = config.email_enabled + && !config.email_recipients.is_empty() + && matches!(read_smtp_delivery_config(state).await, Ok(Some(_))); Ok(NotificationChannelReadiness { - email: config.email_enabled && !config.email_recipients.is_empty() && smtp_config.is_some(), + email, server_chan: config.server_chan.enabled && config.server_chan.send_key.is_some(), bark: config.bark.enabled && config.bark.device_key.is_some(), }) @@ -840,13 +842,50 @@ fn escape_html(value: &str) -> String { #[cfg(test)] mod tests { use super::{ - apply_notification_item_template, parse_channel_filter, parse_notification_items, - parse_recipient_list, ImportantNotification, ImportantNotificationChannelFilter, - MAX_NOTIFICATION_ITEMS, MAX_NOTIFICATION_RECIPIENTS, MAX_NOTIFICATION_RECIPIENT_BYTES, + apply_notification_item_template, important_notification_configured, parse_channel_filter, + parse_notification_items, parse_recipient_list, ImportantNotification, + ImportantNotificationChannelFilter, IMPORTANT_NOTIFICATION_EMAIL_ENABLED_KEY, + IMPORTANT_NOTIFICATION_EMAIL_RECIPIENTS_KEY, MAX_NOTIFICATION_ITEMS, + MAX_NOTIFICATION_RECIPIENTS, MAX_NOTIFICATION_RECIPIENT_BYTES, MAX_NOTIFICATION_TEMPLATE_BYTES, }; + use crate::{data::GatewayDataState, AppState}; + use aether_crypto::DEVELOPMENT_ENCRYPTION_KEY; use serde_json::json; + #[tokio::test] + async fn unused_email_channel_does_not_load_or_migrate_smtp_password() { + for (email_enabled, recipients) in [(false, "ops@example.com"), (true, "")] { + let data = GatewayDataState::disabled() + .with_encryption_key_for_tests(DEVELOPMENT_ENCRYPTION_KEY) + .with_system_config_values_for_tests(vec![ + ( + IMPORTANT_NOTIFICATION_EMAIL_ENABLED_KEY.to_string(), + json!(email_enabled), + ), + ( + IMPORTANT_NOTIFICATION_EMAIL_RECIPIENTS_KEY.to_string(), + json!(recipients), + ), + ("smtp_host".to_string(), json!("smtp.example.com")), + ("smtp_user".to_string(), json!("ops@example.com")), + ("smtp_password".to_string(), json!("unused-smtp-password")), + ("smtp_from_email".to_string(), json!("ops@example.com")), + ]); + let state = AppState::new() + .expect("gateway state should build") + .with_data_state_for_tests(data); + assert!(!important_notification_configured(&state).await.unwrap()); + assert_eq!( + state + .read_system_config_json_value_strong("smtp_password") + .await + .unwrap(), + Some(json!("unused-smtp-password")) + ); + } + } + #[test] fn parse_recipient_list_accepts_arrays_and_delimiters() { assert_eq!( diff --git a/apps/aether-gateway/src/tests/control/admin/health_access.rs b/apps/aether-gateway/src/tests/control/admin/health_access.rs index a42db2a2e..36d50a955 100644 --- a/apps/aether-gateway/src/tests/control/admin/health_access.rs +++ b/apps/aether-gateway/src/tests/control/admin/health_access.rs @@ -1,7 +1,7 @@ use std::sync::{Arc, Mutex}; use std::time::{SystemTime, UNIX_EPOCH}; -use aether_crypto::DEVELOPMENT_ENCRYPTION_KEY; +use aether_crypto::{encrypt_python_fernet_plaintext, DEVELOPMENT_ENCRYPTION_KEY}; use aether_data::repository::auth_modules::InMemoryAuthModuleReadRepository; use aether_data::repository::candidates::InMemoryRequestCandidateRepository; use aether_data::repository::management_tokens::{ @@ -32,6 +32,155 @@ use crate::data::GatewayDataState; const ADMIN_ENDPOINT_HEALTH_DATA_UNAVAILABLE_DETAIL: &str = "Admin endpoint health data unavailable"; +async fn assert_admin_modules_status_with_smtp_password( + stored_password: &str, + notification_ready: bool, + server_chan_enabled: bool, +) -> AppState { + let data = GatewayDataState::with_auth_module_reader_for_tests(Arc::new( + InMemoryAuthModuleReadRepository::seed(Vec::new(), None), + )) + .with_provider_catalog_reader(Arc::new(InMemoryProviderCatalogReadRepository::seed( + Vec::new(), + Vec::new(), + Vec::new(), + ))) + .with_encryption_key_for_tests(DEVELOPMENT_ENCRYPTION_KEY) + .with_system_config_values_for_tests(vec![ + ("module.management_tokens.enabled".to_string(), json!(true)), + ( + "module.important_notification.enabled".to_string(), + json!(true), + ), + ( + "module.important_notification.email_enabled".to_string(), + json!(true), + ), + ( + "module.important_notification.email_recipients".to_string(), + json!("ops@example.com"), + ), + ( + "module.server_chan_push.enabled".to_string(), + json!(server_chan_enabled), + ), + ( + "module.server_chan_push.send_key".to_string(), + json!(if server_chan_enabled { + "SCT-test-send-key" + } else { + "" + }), + ), + ("smtp_host".to_string(), json!("smtp.example.com")), + ("smtp_port".to_string(), json!(587)), + ("smtp_user".to_string(), json!("ops@example.com")), + ("smtp_password".to_string(), json!(stored_password)), + ("smtp_use_tls".to_string(), json!(true)), + ("smtp_from_email".to_string(), json!("ops@example.com")), + ]); + let state = AppState::new() + .expect("gateway should build") + .with_data_state_for_tests(data); + let (gateway_url, gateway_handle) = start_server(build_router_with_state(state.clone())).await; + let client = reqwest::Client::new(); + + for path in [ + "/api/admin/modules/status", + "/api/admin/modules/status/important_notification", + ] { + let response = client + .get(format!("{gateway_url}{path}")) + .header(GATEWAY_HEADER, "rust-phase3b") + .header(TRUSTED_ADMIN_USER_ID_HEADER, "admin-user-123") + .header(TRUSTED_ADMIN_USER_ROLE_HEADER, "admin") + .header(TRUSTED_ADMIN_SESSION_ID_HEADER, "session-123") + .send() + .await + .expect("module status request should succeed"); + assert_eq!(response.status(), StatusCode::OK); + let payload: serde_json::Value = response.json().await.expect("module status should parse"); + assert!(!payload.to_string().contains(stored_password)); + let notification = if path == "/api/admin/modules/status" { + assert_eq!( + payload + .as_object() + .expect("module list should be an object") + .len(), + 14 + ); + assert_eq!(payload["management_tokens"]["active"], json!(true)); + &payload["important_notification"] + } else { + &payload + }; + assert_eq!(notification["enabled"], json!(true)); + assert_eq!(notification["config_validated"], json!(notification_ready)); + assert_eq!(notification["active"], json!(notification_ready)); + assert_eq!(notification["config_error"].is_null(), notification_ready); + } + gateway_handle.abort(); + + assert_eq!( + crate::important_notification::important_notification_dispatch_ready_for_item( + &state, + crate::important_notification::PROVIDER_QUOTA_ALERT_ITEM_KEY, + ) + .await + .expect("SMTP errors should not abort notification readiness"), + notification_ready + ); + let summary = crate::maintenance::perform_provider_quota_alert_once(&state) + .await + .expect("SMTP errors should not abort the quota alert worker"); + assert_eq!(summary.failed, 0); + assert_eq!(summary.alerted, 0); + state +} + +#[tokio::test] +async fn gateway_handles_admin_modules_status_with_legacy_smtp_password() { + let ciphertext = + encrypt_python_fernet_plaintext(DEVELOPMENT_ENCRYPTION_KEY, "legacy-smtp-password") + .expect("legacy SMTP password should encrypt"); + let state = assert_admin_modules_status_with_smtp_password(&ciphertext, true, false).await; + let stored = state + .read_system_config_json_value_strong("smtp_password") + .await + .unwrap() + .unwrap(); + assert!(stored + .as_str() + .unwrap() + .starts_with("aether-smtp-password-v3:")); + let smtp = crate::email_delivery::read_smtp_delivery_config(&state) + .await + .expect("migrated SMTP config should load") + .expect("SMTP should be configured"); + assert_eq!(smtp.password.as_deref(), Some("legacy-smtp-password")); +} + +#[tokio::test] +async fn gateway_handles_admin_modules_status_with_invalid_smtp_password() { + let ciphertext = + encrypt_python_fernet_plaintext("unavailable-historical-key", "legacy-smtp-password") + .expect("unknown-key SMTP password should encrypt"); + let state = assert_admin_modules_status_with_smtp_password(&ciphertext, false, false).await; + assert_eq!( + state + .read_system_config_json_value_strong("smtp_password") + .await + .unwrap(), + Some(json!(ciphertext)) + ); +} + +#[tokio::test] +async fn gateway_handles_admin_modules_status_with_invalid_smtp_and_working_push() { + assert_admin_modules_status_with_smtp_password("aether-smtp-password-v3:invalid", true, true) + .await; +} + #[tokio::test] async fn gateway_returns_service_unavailable_for_admin_health_api_formats_when_readers_unavailable() {