From fd716e4807c1d3d1bbeb162c37e981a83bc28a25 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 11:07:48 -0400 Subject: [PATCH 01/34] Phase 1 --- server/config.go | 2 +- user/magic_link_test.go | 269 ++++++++++++++++++++++++++++++++ user/manager.go | 208 +++++++++++++++++++++++- user/manager_postgres.go | 32 +++- user/manager_postgres_schema.go | 44 +++++- user/manager_sqlite.go | 32 +++- user/manager_sqlite_schema.go | 50 +++++- user/manager_test.go | 77 +++++++++ user/types.go | 43 ++++- user/util.go | 22 +++ util/util.go | 36 +++-- util/util_test.go | 24 +++ 12 files changed, 816 insertions(+), 23 deletions(-) create mode 100644 user/magic_link_test.go diff --git a/server/config.go b/server/config.go index b7dadddf..de94b4ca 100644 --- a/server/config.go +++ b/server/config.go @@ -71,7 +71,7 @@ const ( DefaultVisitorEmailLimitReplenish = time.Hour DefaultVisitorTopicCreationLimitBurst = 100 DefaultVisitorTopicCreationLimitReplenish = time.Minute - DefaultVisitorAccountCreationLimitBurst = 3 + DefaultVisitorAccountCreationLimitBurst = 6 // Shared by signup and password-reset requests (same per-visitor bucket) DefaultVisitorAccountCreationLimitReplenish = 24 * time.Hour DefaultVisitorAuthFailureLimitBurst = 30 DefaultVisitorAuthFailureLimitReplenish = time.Minute diff --git a/user/magic_link_test.go b/user/magic_link_test.go new file mode 100644 index 00000000..4be1fe55 --- /dev/null +++ b/user/magic_link_test.go @@ -0,0 +1,269 @@ +package user + +import ( + "testing" + "time" + + "github.com/stretchr/testify/require" +) + +// addVerifyLink generates a raw token, stores an email-verification magic link for it, and +// returns the raw token so the test can "click" it via VerifyEmail. +func addVerifyLink(t *testing.T, a *Manager, userID, email string, expires int64) string { + raw := generateLinkToken() + require.Nil(t, a.AddMagicLink(&MagicLink{ + TokenHash: hashToken(raw), + Kind: MagicLinkKindEmailVerify, + UserID: userID, + Email: email, + Expires: expires, + Created: time.Now().Unix(), + })) + return raw +} + +func TestUser_MagicLink_VerifyEmail_SetsPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) + + // Before verifying: pending, not yet verified, no primary + pending, err := a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"phil@example.com"}, pending) + emails, err := a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(emails)) + primary, err := a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "", primary) + + // Verify: the first verified email auto-becomes primary + m, err := a.VerifyEmail(hashToken(raw)) + require.Nil(t, err) + require.Equal(t, "phil@example.com", m.Email) + + emails, err = a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"phil@example.com"}, emails) + primary, err = a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "phil@example.com", primary) + pending, err = a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(pending)) + + // Reset-by-email lookup resolves to the account + userID, err := a.UserIDByPrimaryEmail("phil@example.com") + require.Nil(t, err) + require.Equal(t, phil.ID, userID) + }) +} + +func TestUser_MagicLink_VerifyEmail_SecondStaysSecondary(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw1 := addVerifyLink(t, a, phil.ID, "first@example.com", time.Now().Add(24*time.Hour).Unix()) + _, err = a.VerifyEmail(hashToken(raw1)) + require.Nil(t, err) + + raw2 := addVerifyLink(t, a, phil.ID, "second@example.com", time.Now().Add(24*time.Hour).Unix()) + _, err = a.VerifyEmail(hashToken(raw2)) + require.Nil(t, err) + + // Both verified, but primary is still the first + emails, err := a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"first@example.com", "second@example.com"}, emails) + primary, err := a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "first@example.com", primary) + }) +} + +func TestUser_MagicLink_PrimaryGlobalUniqueness(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + require.Nil(t, a.AddUser("ben", "ben", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + ben, err := a.User("ben") + require.Nil(t, err) + + // phil verifies shared@ first -> becomes his primary + rawPhil := addVerifyLink(t, a, phil.ID, "shared@example.com", time.Now().Add(24*time.Hour).Unix()) + _, err = a.VerifyEmail(hashToken(rawPhil)) + require.Nil(t, err) + primary, err := a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "shared@example.com", primary) + + // ben verifies the same address -> allowed as secondary, but NOT his primary + rawBen := addVerifyLink(t, a, ben.ID, "shared@example.com", time.Now().Add(24*time.Hour).Unix()) + _, err = a.VerifyEmail(hashToken(rawBen)) + require.Nil(t, err) + emails, err := a.Emails(ben.ID) + require.Nil(t, err) + require.Equal(t, []string{"shared@example.com"}, emails) + primary, err = a.PrimaryEmail(ben.ID) + require.Nil(t, err) + require.Equal(t, "", primary) + + // Explicitly promoting ben's copy to primary collides with phil's + require.ErrorIs(t, a.SetPrimaryEmail(ben.ID, "shared@example.com"), ErrEmailPrimaryElsewhere) + // ...and phil keeps his primary (the failed promotion rolled back ben's clear, which was a no-op anyway) + primary, err = a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "shared@example.com", primary) + }) +} + +func TestUser_MagicLink_SetPrimary_NotVerified(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + require.ErrorIs(t, a.SetPrimaryEmail(phil.ID, "nope@example.com"), ErrEmailNotFound) + }) +} + +func TestUser_MagicLink_Expired(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(-time.Minute).Unix()) + _, err = a.VerifyEmail(hashToken(raw)) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + // Nothing got verified + emails, err := a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(emails)) + }) +} + +func TestUser_MagicLink_SingleUse(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) + _, err = a.VerifyEmail(hashToken(raw)) + require.Nil(t, err) + // Second click: token already consumed + _, err = a.VerifyEmail(hashToken(raw)) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + }) +} + +func TestUser_MagicLink_ReplaceOnReRequest(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw1 := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) + raw2 := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) + + // Only one pending row remains; the old token no longer works + pending, err := a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"phil@example.com"}, pending) + _, err = a.MagicLinkByHash(hashToken(raw1)) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + m, err := a.MagicLinkByHash(hashToken(raw2)) + require.Nil(t, err) + require.Equal(t, "phil@example.com", m.Email) + }) +} + +func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := generateLinkToken() + require.Nil(t, a.AddMagicLink(&MagicLink{ + TokenHash: hashToken(raw), + Kind: MagicLinkKindPasswordReset, + UserID: phil.ID, + Expires: time.Now().Add(time.Hour).Unix(), + Created: time.Now().Unix(), + })) + + m, err := a.MagicLinkByHash(hashToken(raw)) + require.Nil(t, err) + require.Equal(t, MagicLinkKindPasswordReset, m.Kind) + require.Equal(t, phil.ID, m.UserID) + require.Equal(t, "", m.Email) // reset rows carry no email + + // Reset rows do not appear as pending emails + pending, err := a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(pending)) + + // New request replaces the old token + raw2 := generateLinkToken() + require.Nil(t, a.AddMagicLink(&MagicLink{ + TokenHash: hashToken(raw2), + Kind: MagicLinkKindPasswordReset, + UserID: phil.ID, + Expires: time.Now().Add(time.Hour).Unix(), + Created: time.Now().Unix(), + })) + _, err = a.MagicLinkByHash(hashToken(raw)) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + // Single use: deleting consumes it + require.Nil(t, a.DeleteMagicLink(hashToken(raw2))) + _, err = a.MagicLinkByHash(hashToken(raw2)) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + }) +} + +func TestUser_MagicLink_Reaper(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + expired := addVerifyLink(t, a, phil.ID, "expired@example.com", time.Now().Add(-time.Hour).Unix()) + valid := addVerifyLink(t, a, phil.ID, "valid@example.com", time.Now().Add(time.Hour).Unix()) + + require.Nil(t, a.deleteExpiredMagicLinks()) + + _, err = a.MagicLinkByHash(hashToken(expired)) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + m, err := a.MagicLinkByHash(hashToken(valid)) + require.Nil(t, err) + require.Equal(t, "valid@example.com", m.Email) + }) +} + +func TestUser_MagicLink_UserIDByPrimaryEmail_NotFound(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + _, err := a.UserIDByPrimaryEmail("ghost@example.com") + require.ErrorIs(t, err, ErrUserNotFound) + }) +} diff --git a/user/manager.go b/user/manager.go index 34d96403..e6df6910 100644 --- a/user/manager.go +++ b/user/manager.go @@ -40,6 +40,7 @@ const ( DefaultUserPasswordBcryptCost = 10 DefaultAccessCacheEnabled = false DefaultAccessCacheReloadInterval = 87 * time.Second + DefaultExpiredMagicLinkReapInterval = time.Hour // How often expired email-verify/password-reset links are swept ) var ( @@ -91,6 +92,7 @@ func newManager(d *db.DB, queries queries, config *Config) (*Manager, error) { go manager.asyncAccessCacheReloadLoop(manager.config.AccessCacheReloadInterval) } go manager.asyncQueueWriteLoop(manager.config.QueueWriterInterval) + go manager.asyncExpiredMagicLinkReapLoop(DefaultExpiredMagicLinkReapInterval) return manager, nil } @@ -128,6 +130,25 @@ func (a *Manager) asyncAccessCacheReloadLoop(interval time.Duration) { } } +// asyncExpiredMagicLinkReapLoop periodically deletes expired email-verification and +// password-reset links so the user_magic_link table does not accumulate dead rows. Expiry is +// already enforced on read, so this is housekeeping only; it replaces the old in-memory +// expireLoop that lived in mail.Sender. +func (a *Manager) asyncExpiredMagicLinkReapLoop(interval time.Duration) { + ticker := time.NewTicker(interval) + defer ticker.Stop() + for { + select { + case <-a.quit: + return + case <-ticker.C: + if err := a.deleteExpiredMagicLinks(); err != nil { + log.Tag(tag).Err(err).Warn("Reaping expired magic links failed") + } + } + } +} + // Authenticate checks username and password and returns a User if correct, and the user has not been // marked as deleted. The method returns in constant-ish time, regardless of whether the user exists or // the password is correct or incorrect. @@ -1451,12 +1472,197 @@ func (a *Manager) AddEmail(userID, email string) error { return nil } -// RemoveEmail deletes a verified email address from the user with the given user ID +// RemoveEmail deletes a verified email address from the user with the given user ID. +// Removing the primary email leaves the account with no primary -- there is deliberately +// no auto-promotion of another verified address; the user is nudged to pick a new one. func (a *Manager) RemoveEmail(userID, email string) error { _, err := a.db.Exec(a.queries.deleteEmail, userID, email) return err } +// PrimaryEmail returns the user's primary (recovery) email address, or an empty string if +// the user has not designated one. +func (a *Manager) PrimaryEmail(userID string) (string, error) { + var email sql.NullString + err := a.db.ReadOnly().QueryRow(a.queries.selectPrimaryEmail, userID).Scan(&email) + if errors.Is(err, sql.ErrNoRows) { + return "", nil + } else if err != nil { + return "", err + } + return email.String, nil +} + +// UserIDByPrimaryEmail returns the ID of the (at most one) account for which the given address +// is the primary email. Returns ErrUserNotFound if no account claims it as primary. Used by the +// password-reset request flow to resolve an email identifier to a single account. +func (a *Manager) UserIDByPrimaryEmail(email string) (string, error) { + var userID string + err := a.db.ReadOnly().QueryRow(a.queries.selectUserIDByPrimary, email).Scan(&userID) + if errors.Is(err, sql.ErrNoRows) { + return "", ErrUserNotFound + } else if err != nil { + return "", err + } + return userID, nil +} + +// PendingEmails returns the user's unverified (pending) email addresses, i.e. addresses with +// an outstanding email-verification magic link. +func (a *Manager) PendingEmails(userID string) ([]string, error) { + rows, err := a.db.ReadOnly().Query(a.queries.selectPendingEmails, userID) + if err != nil { + return nil, err + } + defer rows.Close() + emails := make([]string, 0) + for rows.Next() { + var email string + if err := rows.Scan(&email); err != nil { + return nil, err + } + emails = append(emails, email) + } + if err := rows.Err(); err != nil { + return nil, err + } + return emails, nil +} + +// SetPrimaryEmail marks a verified email address as the user's primary (recovery) email, +// clearing any previous primary in the same transaction. Returns ErrEmailNotFound if the +// address is not verified on the account, or ErrEmailPrimaryElsewhere if it is already the +// primary email on another account (enforced by the global partial unique index). +func (a *Manager) SetPrimaryEmail(userID, email string) error { + return db.ExecTx(a.db, func(tx *sql.Tx) error { + if _, err := tx.Exec(a.queries.updateEmailClearPrimary, userID); err != nil { + return err + } + res, err := tx.Exec(a.queries.updateEmailSetPrimary, userID, email) + if err != nil { + if isUniqueConstraintError(err) { + return ErrEmailPrimaryElsewhere + } + return err + } + affected, err := res.RowsAffected() + if err != nil { + return err + } + if affected == 0 { + return ErrEmailNotFound // Address not verified on this account + } + return nil + }) +} + +// AddMagicLink stores a pending magic link, replacing any existing link in the same scope: +// for email_verify that is the (user_id, email) pair (one pending verification per address); +// for password_reset that is the user_id (one active reset per account). The replace-delete and +// the insert run in one transaction so a re-request atomically supersedes the old token. +func (a *Manager) AddMagicLink(m *MagicLink) error { + return db.ExecTx(a.db, func(tx *sql.Tx) error { + switch m.Kind { + case MagicLinkKindEmailVerify: + if _, err := tx.Exec(a.queries.deleteVerifyScope, m.UserID, m.Email); err != nil { + return err + } + case MagicLinkKindPasswordReset: + if _, err := tx.Exec(a.queries.deleteResetScope, m.UserID); err != nil { + return err + } + default: + return ErrInvalidArgument + } + if _, err := tx.Exec(a.queries.insertMagicLink, m.TokenHash, string(m.Kind), m.UserID, nullString(m.Email), m.Expires, m.Created); err != nil { + return err + } + return nil + }) +} + +// MagicLinkByHash looks up a magic link by the hex SHA-256 of its raw token, returning +// ErrMagicLinkNotFound if none exists. Callers must assert the returned Kind matches the flow +// they serve and check Expires themselves. +func (a *Manager) MagicLinkByHash(tokenHash string) (*MagicLink, error) { + var m MagicLink + var kind string + var email sql.NullString + err := a.db.ReadOnly().QueryRow(a.queries.selectMagicLinkByHash, tokenHash).Scan(&m.TokenHash, &kind, &m.UserID, &email, &m.Expires, &m.Created) + if errors.Is(err, sql.ErrNoRows) { + return nil, ErrMagicLinkNotFound + } else if err != nil { + return nil, err + } + m.Kind = MagicLinkKind(kind) + m.Email = email.String + return &m, nil +} + +// DeleteMagicLink deletes a magic link by its token hash. Used to enforce single use after a +// reset is performed (email verification deletes the row inside VerifyEmail's transaction). +func (a *Manager) DeleteMagicLink(tokenHash string) error { + _, err := a.db.Exec(a.queries.deleteMagicLinkByHash, tokenHash) + return err +} + +// VerifyEmail consumes an email-verification magic link: after validating the token (kind + +// expiry), it deletes the link, adds the address to the user's verified emails, and -- if the +// user has no primary email yet and the address is not already primary on another account -- +// promotes the new address to primary. All mutations run in one transaction. A primary +// collision simply leaves the address verified but non-primary. Returns the consumed link. +func (a *Manager) VerifyEmail(tokenHash string) (*MagicLink, error) { + m, err := a.MagicLinkByHash(tokenHash) + if err != nil { + return nil, err + } + if m.Kind != MagicLinkKindEmailVerify || time.Now().Unix() > m.Expires { + return nil, ErrMagicLinkNotFound + } + err = db.ExecTx(a.db, func(tx *sql.Tx) error { + // Single use: delete the link, then add the (idempotent) verified address + if _, err := tx.Exec(a.queries.deleteMagicLinkByHash, tokenHash); err != nil { + return err + } + if _, err := tx.Exec(a.queries.insertEmailIgnore, m.UserID, m.Email); err != nil { + return err + } + // Promote to primary only if the user has none yet and the address is globally free. + // We check with SELECTs rather than catching a unique violation, because Postgres aborts + // the whole transaction on any constraint error (which would undo the verified-email add). + var primary sql.NullString + err := tx.QueryRow(a.queries.selectPrimaryEmail, m.UserID).Scan(&primary) + if err != nil && !errors.Is(err, sql.ErrNoRows) { + return err + } + if primary.String != "" { + return nil // User already has a primary -- leave it + } + var owner string + err = tx.QueryRow(a.queries.selectUserIDByPrimary, m.Email).Scan(&owner) + if errors.Is(err, sql.ErrNoRows) { + if _, err := tx.Exec(a.queries.updateEmailSetPrimary, m.UserID, m.Email); err != nil { + return err + } + } else if err != nil { + return err + } + // owner found -> address is primary elsewhere -> stays a verified secondary + return nil + }) + if err != nil { + return nil, err + } + return m, nil +} + +// deleteExpiredMagicLinks removes magic links whose expiry has passed. Expiry is also enforced +// on read, so this is purely housekeeping to bound table growth; it runs from the reaper loop. +func (a *Manager) deleteExpiredMagicLinks() error { + _, err := a.db.Exec(a.queries.deleteExpiredMagicLinks, time.Now().Unix()) + return err +} + func (a *Manager) readEmail(rows *sql.Rows) (string, error) { var email string if !rows.Next() { diff --git a/user/manager_postgres.go b/user/manager_postgres.go index 0395baae..9cedf5fd 100644 --- a/user/manager_postgres.go +++ b/user/manager_postgres.go @@ -217,9 +217,23 @@ const ( postgresDeletePhoneNumberQuery = `DELETE FROM user_phone WHERE user_id = $1 AND phone_number = $2` // Email queries - postgresSelectEmailsQuery = `SELECT email FROM user_email WHERE user_id = $1 ORDER BY email` - postgresInsertEmailQuery = `INSERT INTO user_email (user_id, email) VALUES ($1, $2)` - postgresDeleteEmailQuery = `DELETE FROM user_email WHERE user_id = $1 AND email = $2` + postgresSelectEmailsQuery = `SELECT email FROM user_email WHERE user_id = $1 ORDER BY email` + postgresInsertEmailQuery = `INSERT INTO user_email (user_id, email) VALUES ($1, $2)` + postgresInsertEmailIgnoreQuery = `INSERT INTO user_email (user_id, email) VALUES ($1, $2) ON CONFLICT (user_id, email) DO NOTHING` + postgresDeleteEmailQuery = `DELETE FROM user_email WHERE user_id = $1 AND email = $2` + postgresSelectPrimaryEmailQuery = `SELECT email FROM user_email WHERE user_id = $1 AND is_primary` + postgresSelectUserIDByPrimaryQuery = `SELECT user_id FROM user_email WHERE email = $1 AND is_primary` + postgresUpdateEmailSetPrimaryQuery = `UPDATE user_email SET is_primary = TRUE WHERE user_id = $1 AND email = $2` + postgresUpdateEmailClearPrimaryQuery = `UPDATE user_email SET is_primary = FALSE WHERE user_id = $1 AND is_primary` + + // Magic link queries (email verification + password reset) + postgresInsertMagicLinkQuery = `INSERT INTO user_magic_link (token_hash, kind, user_id, email, expires, created) VALUES ($1, $2, $3, $4, $5, $6)` + postgresSelectMagicLinkByHashQuery = `SELECT token_hash, kind, user_id, email, expires, created FROM user_magic_link WHERE token_hash = $1` + postgresDeleteMagicLinkByHashQuery = `DELETE FROM user_magic_link WHERE token_hash = $1` + postgresDeleteVerifyScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'email_verify' AND user_id = $1 AND email = $2` + postgresDeleteResetScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'password_reset' AND user_id = $1` + postgresSelectPendingEmailsQuery = `SELECT email FROM user_magic_link WHERE kind = 'email_verify' AND user_id = $1 ORDER BY email` + postgresDeleteExpiredMagicLinksQuery = `DELETE FROM user_magic_link WHERE expires < $1` // Billing queries postgresUpdateBillingQuery = ` @@ -306,7 +320,19 @@ var postgresQueries = queries{ deletePhoneNumber: postgresDeletePhoneNumberQuery, selectEmails: postgresSelectEmailsQuery, insertEmail: postgresInsertEmailQuery, + insertEmailIgnore: postgresInsertEmailIgnoreQuery, deleteEmail: postgresDeleteEmailQuery, + selectPrimaryEmail: postgresSelectPrimaryEmailQuery, + selectUserIDByPrimary: postgresSelectUserIDByPrimaryQuery, + updateEmailSetPrimary: postgresUpdateEmailSetPrimaryQuery, + updateEmailClearPrimary: postgresUpdateEmailClearPrimaryQuery, + insertMagicLink: postgresInsertMagicLinkQuery, + selectMagicLinkByHash: postgresSelectMagicLinkByHashQuery, + deleteMagicLinkByHash: postgresDeleteMagicLinkByHashQuery, + deleteVerifyScope: postgresDeleteVerifyScopeQuery, + deleteResetScope: postgresDeleteResetScopeQuery, + selectPendingEmails: postgresSelectPendingEmailsQuery, + deleteExpiredMagicLinks: postgresDeleteExpiredMagicLinksQuery, updateBilling: postgresUpdateBillingQuery, } diff --git a/user/manager_postgres_schema.go b/user/manager_postgres_schema.go index ba8502f2..a855dc66 100644 --- a/user/manager_postgres_schema.go +++ b/user/manager_postgres_schema.go @@ -75,8 +75,21 @@ const ( CREATE TABLE IF NOT EXISTS user_email ( user_id TEXT NOT NULL REFERENCES "user"(id) ON DELETE CASCADE, email TEXT NOT NULL, + is_primary BOOLEAN NOT NULL DEFAULT FALSE, PRIMARY KEY (user_id, email) ); + CREATE UNIQUE INDEX idx_user_email_primary_user ON user_email (user_id) WHERE is_primary; + CREATE UNIQUE INDEX idx_user_email_primary_addr ON user_email (email) WHERE is_primary; + CREATE TABLE IF NOT EXISTS user_magic_link ( + token_hash TEXT NOT NULL, + kind TEXT NOT NULL, + user_id TEXT NOT NULL REFERENCES "user"(id) ON DELETE CASCADE, + email TEXT, + expires BIGINT NOT NULL, + created BIGINT NOT NULL, + PRIMARY KEY (token_hash) + ); + CREATE INDEX idx_magic_link_user_kind ON user_magic_link (user_id, kind); CREATE TABLE IF NOT EXISTS schema_version ( store TEXT PRIMARY KEY, version INT NOT NULL @@ -89,7 +102,7 @@ const ( // Schema table management queries for Postgres const ( - postgresCurrentSchemaVersion = 7 + postgresCurrentSchemaVersion = 8 postgresSelectSchemaVersionQuery = `SELECT version FROM schema_version WHERE store = 'user'` postgresInsertSchemaVersionQuery = `INSERT INTO schema_version (store, version) VALUES ('user', $1)` ) @@ -102,11 +115,30 @@ const ( PRIMARY KEY (user_id, email) ); ` + + // 7 -> 8: primary (recovery) email + magic-link table for verification/reset. + // No backfill -- existing verified emails stay non-primary. + postgresMigrate7To8UpdateQueries = ` + ALTER TABLE user_email ADD COLUMN is_primary BOOLEAN NOT NULL DEFAULT FALSE; + CREATE UNIQUE INDEX idx_user_email_primary_user ON user_email (user_id) WHERE is_primary; + CREATE UNIQUE INDEX idx_user_email_primary_addr ON user_email (email) WHERE is_primary; + CREATE TABLE IF NOT EXISTS user_magic_link ( + token_hash TEXT NOT NULL, + kind TEXT NOT NULL, + user_id TEXT NOT NULL REFERENCES "user"(id) ON DELETE CASCADE, + email TEXT, + expires BIGINT NOT NULL, + created BIGINT NOT NULL, + PRIMARY KEY (token_hash) + ); + CREATE INDEX idx_magic_link_user_kind ON user_magic_link (user_id, kind); + ` postgresUpdateSchemaVersionQuery = `UPDATE schema_version SET version = $1 WHERE store = 'user'` ) var postgresMigrations = map[int]func(db *sql.DB) error{ 6: postgresMigrateFrom6, + 7: postgresMigrateFrom7, } func setupPostgres(db *sql.DB) error { @@ -141,6 +173,16 @@ func postgresMigrateFrom6(db *sql.DB) error { return nil } +func postgresMigrateFrom7(db *sql.DB) error { + if _, err := db.Exec(postgresMigrate7To8UpdateQueries); err != nil { + return err + } + if _, err := db.Exec(postgresUpdateSchemaVersionQuery, 8); err != nil { + return err + } + return nil +} + func setupNewPostgres(db *sql.DB) error { if _, err := db.Exec(postgresCreateTablesQueries); err != nil { return err diff --git a/user/manager_sqlite.go b/user/manager_sqlite.go index 62652ce3..61bafc94 100644 --- a/user/manager_sqlite.go +++ b/user/manager_sqlite.go @@ -214,9 +214,23 @@ const ( sqliteDeletePhoneNumberQuery = `DELETE FROM user_phone WHERE user_id = ? AND phone_number = ?` // Email queries - sqliteSelectEmailsQuery = `SELECT email FROM user_email WHERE user_id = ? ORDER BY email` - sqliteInsertEmailQuery = `INSERT INTO user_email (user_id, email) VALUES (?, ?)` - sqliteDeleteEmailQuery = `DELETE FROM user_email WHERE user_id = ? AND email = ?` + sqliteSelectEmailsQuery = `SELECT email FROM user_email WHERE user_id = ? ORDER BY email` + sqliteInsertEmailQuery = `INSERT INTO user_email (user_id, email) VALUES (?, ?)` + sqliteInsertEmailIgnoreQuery = `INSERT INTO user_email (user_id, email) VALUES (?, ?) ON CONFLICT (user_id, email) DO NOTHING` + sqliteDeleteEmailQuery = `DELETE FROM user_email WHERE user_id = ? AND email = ?` + sqliteSelectPrimaryEmailQuery = `SELECT email FROM user_email WHERE user_id = ? AND is_primary = 1` + sqliteSelectUserIDByPrimaryQuery = `SELECT user_id FROM user_email WHERE email = ? AND is_primary = 1` + sqliteUpdateEmailSetPrimaryQuery = `UPDATE user_email SET is_primary = 1 WHERE user_id = ? AND email = ?` + sqliteUpdateEmailClearPrimaryQuery = `UPDATE user_email SET is_primary = 0 WHERE user_id = ? AND is_primary = 1` + + // Magic link queries (email verification + password reset) + sqliteInsertMagicLinkQuery = `INSERT INTO user_magic_link (token_hash, kind, user_id, email, expires, created) VALUES (?, ?, ?, ?, ?, ?)` + sqliteSelectMagicLinkByHashQuery = `SELECT token_hash, kind, user_id, email, expires, created FROM user_magic_link WHERE token_hash = ?` + sqliteDeleteMagicLinkByHashQuery = `DELETE FROM user_magic_link WHERE token_hash = ?` + sqliteDeleteVerifyScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'email_verify' AND user_id = ? AND email = ?` + sqliteDeleteResetScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'password_reset' AND user_id = ?` + sqliteSelectPendingEmailsQuery = `SELECT email FROM user_magic_link WHERE kind = 'email_verify' AND user_id = ? ORDER BY email` + sqliteDeleteExpiredMagicLinksQuery = `DELETE FROM user_magic_link WHERE expires < ?` // Billing queries sqliteUpdateBillingQuery = ` @@ -302,7 +316,19 @@ var sqliteQueries = queries{ deletePhoneNumber: sqliteDeletePhoneNumberQuery, selectEmails: sqliteSelectEmailsQuery, insertEmail: sqliteInsertEmailQuery, + insertEmailIgnore: sqliteInsertEmailIgnoreQuery, deleteEmail: sqliteDeleteEmailQuery, + selectPrimaryEmail: sqliteSelectPrimaryEmailQuery, + selectUserIDByPrimary: sqliteSelectUserIDByPrimaryQuery, + updateEmailSetPrimary: sqliteUpdateEmailSetPrimaryQuery, + updateEmailClearPrimary: sqliteUpdateEmailClearPrimaryQuery, + insertMagicLink: sqliteInsertMagicLinkQuery, + selectMagicLinkByHash: sqliteSelectMagicLinkByHashQuery, + deleteMagicLinkByHash: sqliteDeleteMagicLinkByHashQuery, + deleteVerifyScope: sqliteDeleteVerifyScopeQuery, + deleteResetScope: sqliteDeleteResetScopeQuery, + selectPendingEmails: sqliteSelectPendingEmailsQuery, + deleteExpiredMagicLinks: sqliteDeleteExpiredMagicLinksQuery, updateBilling: sqliteUpdateBillingQuery, } diff --git a/user/manager_sqlite_schema.go b/user/manager_sqlite_schema.go index 6ee24f8c..5b389627 100644 --- a/user/manager_sqlite_schema.go +++ b/user/manager_sqlite_schema.go @@ -88,9 +88,23 @@ const ( CREATE TABLE IF NOT EXISTS user_email ( user_id TEXT NOT NULL, email TEXT NOT NULL, + is_primary INT NOT NULL DEFAULT (0), PRIMARY KEY (user_id, email), FOREIGN KEY (user_id) REFERENCES user (id) ON DELETE CASCADE ); + CREATE UNIQUE INDEX idx_user_email_primary_user ON user_email (user_id) WHERE is_primary = 1; + CREATE UNIQUE INDEX idx_user_email_primary_addr ON user_email (email) WHERE is_primary = 1; + CREATE TABLE IF NOT EXISTS user_magic_link ( + token_hash TEXT NOT NULL, + kind TEXT NOT NULL, + user_id TEXT NOT NULL, + email TEXT, + expires INT NOT NULL, + created INT NOT NULL, + PRIMARY KEY (token_hash), + FOREIGN KEY (user_id) REFERENCES user (id) ON DELETE CASCADE + ); + CREATE INDEX idx_magic_link_user_kind ON user_magic_link (user_id, kind); CREATE TABLE IF NOT EXISTS schemaVersion ( id INT PRIMARY KEY, version INT NOT NULL @@ -107,7 +121,7 @@ const ( // Schema version table management for SQLite const ( - sqliteCurrentSchemaVersion = 7 + sqliteCurrentSchemaVersion = 8 sqliteInsertSchemaVersionQuery = `INSERT INTO schemaVersion VALUES (1, ?)` sqliteUpdateSchemaVersionQuery = `UPDATE schemaVersion SET version = ? WHERE id = 1` sqliteSelectSchemaVersionQuery = `SELECT version FROM schemaVersion WHERE id = 1` @@ -236,6 +250,26 @@ const ( ); ` + // 7 -> 8: primary (recovery) email + magic-link table for verification/reset. + // No backfill -- existing verified emails stay non-primary, so the ALTER cannot + // conflict and no old notification address becomes a recovery channel. + sqliteMigrate7To8UpdateQueries = ` + ALTER TABLE user_email ADD COLUMN is_primary INT NOT NULL DEFAULT (0); + CREATE UNIQUE INDEX idx_user_email_primary_user ON user_email (user_id) WHERE is_primary = 1; + CREATE UNIQUE INDEX idx_user_email_primary_addr ON user_email (email) WHERE is_primary = 1; + CREATE TABLE IF NOT EXISTS user_magic_link ( + token_hash TEXT NOT NULL, + kind TEXT NOT NULL, + user_id TEXT NOT NULL, + email TEXT, + expires INT NOT NULL, + created INT NOT NULL, + PRIMARY KEY (token_hash), + FOREIGN KEY (user_id) REFERENCES user (id) ON DELETE CASCADE + ); + CREATE INDEX idx_magic_link_user_kind ON user_magic_link (user_id, kind); + ` + // 5 -> 6 sqliteMigrate5To6UpdateQueries = ` PRAGMA foreign_keys=off; @@ -339,6 +373,7 @@ var ( 4: sqliteMigrateFrom4, 5: sqliteMigrateFrom5, 6: sqliteMigrateFrom6, + 7: sqliteMigrateFrom7, } ) @@ -493,3 +528,16 @@ func sqliteMigrateFrom6(sqlDB *sql.DB) error { return nil }) } + +func sqliteMigrateFrom7(sqlDB *sql.DB) error { + log.Tag(tag).Info("Migrating user database schema: from 7 to 8") + return db.ExecTx(sqlDB, func(tx *sql.Tx) error { + if _, err := tx.Exec(sqliteMigrate7To8UpdateQueries); err != nil { + return err + } + if _, err := tx.Exec(sqliteUpdateSchemaVersionQuery, 8); err != nil { + return err + } + return nil + }) +} diff --git a/user/manager_test.go b/user/manager_test.go index 6d13929e..3845752e 100644 --- a/user/manager_test.go +++ b/user/manager_test.go @@ -1789,6 +1789,83 @@ func TestMigrationFrom4(t *testing.T) { require.Nil(t, a.Authorize(nil, "up", PermissionRead)) // % matches 0 or more characters } +func TestMigrationFrom7(t *testing.T) { + filename := filepath.Join(t.TempDir(), "user.db") + rawDB, err := sql.Open("sqlite3", filename) + require.Nil(t, err) + + // Create a "version 7" schema: user_email exists but has no is_primary column, and there + // is no user_magic_link table yet. (Mirrors the production schema right before v8.) + _, err = rawDB.Exec(` + BEGIN; + CREATE TABLE IF NOT EXISTS tier ( + id TEXT PRIMARY KEY, code TEXT NOT NULL, name TEXT NOT NULL, + messages_limit INT NOT NULL, messages_expiry_duration INT NOT NULL, emails_limit INT NOT NULL, + calls_limit INT NOT NULL, reservations_limit INT NOT NULL, attachment_file_size_limit INT NOT NULL, + attachment_total_size_limit INT NOT NULL, attachment_expiry_duration INT NOT NULL, + attachment_bandwidth_limit INT NOT NULL, stripe_monthly_price_id TEXT, stripe_yearly_price_id TEXT + ); + CREATE TABLE IF NOT EXISTS user ( + id TEXT PRIMARY KEY, tier_id TEXT, user TEXT NOT NULL, pass TEXT NOT NULL, + role TEXT CHECK (role IN ('anonymous', 'admin', 'user')) NOT NULL, + prefs JSON NOT NULL DEFAULT '{}', sync_topic TEXT NOT NULL, provisioned INT NOT NULL, + stats_messages INT NOT NULL DEFAULT (0), stats_emails INT NOT NULL DEFAULT (0), + stats_calls INT NOT NULL DEFAULT (0), stripe_customer_id TEXT, stripe_subscription_id TEXT, + stripe_subscription_status TEXT, stripe_subscription_interval TEXT, + stripe_subscription_paid_until INT, stripe_subscription_cancel_at INT, created INT NOT NULL, deleted INT, + FOREIGN KEY (tier_id) REFERENCES tier (id) + ); + CREATE UNIQUE INDEX idx_user ON user (user); + CREATE TABLE IF NOT EXISTS user_email ( + user_id TEXT NOT NULL, + email TEXT NOT NULL, + PRIMARY KEY (user_id, email), + FOREIGN KEY (user_id) REFERENCES user (id) ON DELETE CASCADE + ); + CREATE TABLE IF NOT EXISTS schemaVersion (id INT PRIMARY KEY, version INT NOT NULL); + INSERT INTO user (id, user, pass, role, sync_topic, provisioned, created) + VALUES ('u_everyone', '*', '', 'anonymous', '', 0, UNIXEPOCH()); + INSERT INTO user (id, user, pass, role, sync_topic, provisioned, created) + VALUES ('u_phil', 'phil', '', 'user', 'st_phil', 0, UNIXEPOCH()); + INSERT INTO user_email (user_id, email) VALUES ('u_phil', 'old@example.com'); + INSERT INTO schemaVersion (id, version) VALUES (1, 7); + COMMIT; + `) + require.Nil(t, err) + require.Nil(t, rawDB.Close()) + + // Opening the manager triggers the 7 -> 8 migration + a := newTestManagerFromFile(t, filename, "", PermissionDenyAll, bcrypt.MinCost, DefaultUserStatsQueueWriterInterval) + checkSchemaVersion(t, testDB(a)) + + // The pre-existing verified email survives and stays NON-primary (no backfill) + emails, err := a.Emails("u_phil") + require.Nil(t, err) + require.Equal(t, []string{"old@example.com"}, emails) + primary, err := a.PrimaryEmail("u_phil") + require.Nil(t, err) + require.Equal(t, "", primary) + + // The new magic-link machinery works post-migration + raw := generateLinkToken() + require.Nil(t, a.AddMagicLink(&MagicLink{ + TokenHash: hashToken(raw), + Kind: MagicLinkKindEmailVerify, + UserID: "u_phil", + Email: "new@example.com", + Expires: time.Now().Add(24 * time.Hour).Unix(), + Created: time.Now().Unix(), + })) + m, err := a.VerifyEmail(hashToken(raw)) + require.Nil(t, err) + require.Equal(t, "new@example.com", m.Email) + + // new@ becomes primary because the user had none (old@ was a pre-existing non-primary) + primary, err = a.PrimaryEmail("u_phil") + require.Nil(t, err) + require.Equal(t, "new@example.com", primary) +} + func checkSchemaVersion(t *testing.T, d *db.DB) { rows, err := d.Query(`SELECT version FROM schemaVersion`) require.Nil(t, err) diff --git a/user/types.go b/user/types.go index c400e48f..44aecd5d 100644 --- a/user/types.go +++ b/user/types.go @@ -73,6 +73,27 @@ type TokenUpdate struct { LastOrigin netip.Addr } +// MagicLinkKind discriminates the two link-token flows stored in the user_magic_link table. +type MagicLinkKind string + +// Magic link kinds +const ( + MagicLinkKindEmailVerify MagicLinkKind = "email_verify" + MagicLinkKindPasswordReset MagicLinkKind = "password_reset" +) + +// MagicLink is a pending, single-use link token -- either an email verification or a +// password reset, distinguished by Kind. The raw token travels in the emailed link; +// only its TokenHash (hex SHA-256) is persisted. +type MagicLink struct { + TokenHash string + Kind MagicLinkKind + UserID string + Email string // Address being verified for email_verify; empty (NULL) for password_reset + Expires int64 + Created int64 +} + // Prefs represents a user's configuration settings type Prefs struct { Language *string `json:"language,omitempty"` @@ -275,6 +296,8 @@ var ( ErrPhoneNumberExists = errors.New("phone number already exists") ErrEmailNotFound = errors.New("email not found") ErrEmailExists = errors.New("email already exists") + ErrEmailPrimaryElsewhere = errors.New("email is the recovery email on another account") + ErrMagicLinkNotFound = errors.New("magic link not found") ErrProvisionedUserChange = errors.New("cannot change or delete provisioned user") ErrProvisionedTokenChange = errors.New("cannot change or delete provisioned token") ) @@ -350,9 +373,23 @@ type queries struct { deletePhoneNumber string // Email queries - selectEmails string - insertEmail string - deleteEmail string + selectEmails string + insertEmail string + insertEmailIgnore string // Idempotent insert (ON CONFLICT DO NOTHING) used inside VerifyEmail + deleteEmail string + selectPrimaryEmail string + selectUserIDByPrimary string + updateEmailSetPrimary string + updateEmailClearPrimary string + + // Magic link queries (email verification + password reset) + insertMagicLink string + selectMagicLinkByHash string + deleteMagicLinkByHash string + deleteVerifyScope string // Delete pending email_verify rows for (user_id, email) + deleteResetScope string // Delete the active password_reset row for user_id + selectPendingEmails string // Pending (unverified) email addresses for a user + deleteExpiredMagicLinks string // Billing queries updateBilling string diff --git a/user/util.go b/user/util.go index 16f6cc09..5157b95f 100644 --- a/user/util.go +++ b/user/util.go @@ -1,7 +1,9 @@ package user import ( + "crypto/sha256" "database/sql" + "encoding/hex" "regexp" "strings" @@ -9,6 +11,11 @@ import ( "heckel.io/ntfy/v2/util" ) +// linkTokenLength is the length of a raw magic-link token. At 48 base62 characters +// it carries ~285 bits of entropy, well above the ~256-bit target, so the tokens +// need no brute-force cap -- just expiry and single-use. +const linkTokenLength = 48 + var ( allowedUsernameRegex = regexp.MustCompile(`^[-_.+@a-zA-Z0-9]+$`) // Does not include Everyone (*) allowedTopicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No '*' @@ -67,6 +74,21 @@ func GenerateToken() string { return util.RandomLowerStringPrefix(tokenPrefix, tokenLength) } +// generateLinkToken returns a fresh high-entropy raw token for a magic link +// (email verification or password reset). The raw token is carried in the emailed +// link; only its hashToken digest is persisted. +func generateLinkToken() string { + return util.RandomString(linkTokenLength) +} + +// hashToken returns the hex-encoded SHA-256 digest of a raw magic-link token. +// Tokens are stored hashed so a database read cannot yield working links; a high-entropy +// token makes a fast (unsalted) hash sufficient, unlike a password. +func hashToken(raw string) string { + sum := sha256.Sum256([]byte(raw)) + return hex.EncodeToString(sum[:]) +} + // HashPassword hashes the given password using bcrypt with the configured cost func HashPassword(password string) (string, error) { return hashPassword(password, DefaultUserPasswordBcryptCost) diff --git a/util/util.go b/util/util.go index be349691..1c924e2b 100644 --- a/util/util.go +++ b/util/util.go @@ -2,20 +2,19 @@ package util import ( "bytes" + crand "crypto/rand" "encoding/base64" "encoding/json" "errors" "fmt" "io" "math" - "math/rand" "net/netip" "os" "regexp" "slices" "strconv" "strings" - "sync" "time" "unicode/utf8" @@ -30,8 +29,6 @@ const ( ) var ( - random = rand.New(rand.NewSource(time.Now().UnixNano())) - randomMutex = sync.Mutex{} sizeStrRegex = regexp.MustCompile(`(?i)^(\d+)([gmkb])?$`) errInvalidPriority = errors.New("invalid priority") noQuotesRegex = regexp.MustCompile(`^[-_./:@a-zA-Z0-9]+$`) @@ -144,14 +141,33 @@ func RandomLowerStringPrefix(prefix string, length int) string { return randomStringPrefixWithCharset(prefix, length, randomStringLowerCaseCharset) } +// randomStringPrefixWithCharset builds a random string from charset using crypto/rand. +// We use rejection sampling (dropping the few highest byte values that would skew the +// distribution) so every character is uniformly distributed -- important because these +// strings back security tokens (access tokens, magic-link tokens, IDs), not just labels. func randomStringPrefixWithCharset(prefix string, length int, charset string) string { - randomMutex.Lock() // Who would have thought that random.Intn() is not thread-safe?! - defer randomMutex.Unlock() - b := make([]byte, length-len(prefix)) - for i := range b { - b[i] = charset[random.Intn(len(charset))] + n := length - len(prefix) + if n <= 0 { + return prefix[:length] } - return prefix + string(b) + result := make([]byte, n) + limit := 256 - (256 % len(charset)) // reject byte values >= limit to avoid modulo bias + buf := make([]byte, n) + for i := 0; i < n; { + if _, err := crand.Read(buf); err != nil { + panic("crypto/rand failed: " + err.Error()) // Should never happen on a sane system + } + for _, c := range buf { + if i >= n { + break + } + if int(c) < limit { + result[i] = charset[int(c)%len(charset)] + i++ + } + } + } + return prefix + string(result) } // ValidRandomString returns true if the given string matches the format created by RandomString diff --git a/util/util_test.go b/util/util_test.go index ae855147..8de18b66 100644 --- a/util/util_test.go +++ b/util/util_test.go @@ -25,6 +25,30 @@ func TestRandomString(t *testing.T) { require.NotEqual(t, s1, s2) } +// TestRandomString_CSPRNG guards the crypto/rand-backed generator: every character must come +// from the expected charset (rejection sampling correctness) and a large batch must be unique +// (no clock-seeded PRNG collapsing to a predictable stream). +func TestRandomString_CSPRNG(t *testing.T) { + const charset = "abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ0123456789" + seen := make(map[string]bool) + charCounts := make(map[rune]int) + for i := 0; i < 5000; i++ { + s := RandomString(48) + require.Equal(t, 48, len(s)) + require.False(t, seen[s], "duplicate random string generated") + seen[s] = true + for _, c := range s { + require.Contains(t, charset, string(c)) + charCounts[c]++ + } + } + // Every charset character should appear at least once across 5000*48 draws; a heavily + // biased or broken generator would leave gaps. + for _, c := range charset { + require.Greater(t, charCounts[c], 0, "character %q never appeared", string(c)) + } +} + func TestFileExists(t *testing.T) { filename := filepath.Join(t.TempDir(), "somefile.txt") require.Nil(t, os.WriteFile(filename, []byte{0x25, 0x86}, 0600)) From 44dac47d76156e2247399400ef79bf2378b92c73 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 11:12:26 -0400 Subject: [PATCH 02/34] Phsae 2 fix tesPhsae 2 fix testt --- server/server_account_test.go | 6 ++++-- 1 file changed, 4 insertions(+), 2 deletions(-) diff --git a/server/server_account_test.go b/server/server_account_test.go index 9aea7d4d..f2f36168 100644 --- a/server/server_account_test.go +++ b/server/server_account_test.go @@ -78,7 +78,8 @@ func TestAccount_Signup_LimitReached(t *testing.T) { s := newTestServer(t, conf) defer s.closeDatabases() - for i := 0; i < 3; i++ { + // Burst is DefaultVisitorAccountCreationLimitBurst (shared with password-reset requests) + for i := 0; i < 6; i++ { rr := request(t, s, "POST", "/v1/account", fmt.Sprintf(`{"username":"phil%d", "password":"mypass"}`, i), nil) require.Equal(t, 200, rr.Code) } @@ -131,7 +132,8 @@ func TestAccount_Signup_Rate_Limit(t *testing.T) { conf.EnableSignup = true s := newTestServer(t, conf) - for i := 0; i < 3; i++ { + // Burst is DefaultVisitorAccountCreationLimitBurst (shared with password-reset requests) + for i := 0; i < 6; i++ { rr := request(t, s, "POST", "/v1/account", fmt.Sprintf(`{"username":"phil%d", "password":"mypass"}`, i), nil) require.Equal(t, 200, rr.Code, "failed on iteration %d", i) } From 30dd4840a21862338c40720226c493941d4cb4e5 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 11:40:59 -0400 Subject: [PATCH 03/34] Phase 2, email verification rework, ui stuff --- mail/sender.go | 93 ++++-------- server/errors.go | 3 +- server/server.go | 71 ++++++--- server/server_account.go | 163 +++++++++++++++++---- server/server_account_email_test.go | 190 ++++++++++++++++++++++++ server/server_test.go | 8 +- server/smtp_sender.go | 8 + server/types.go | 44 +++--- user/magic_link_test.go | 91 +++++------- user/manager.go | 52 ++++++- user/manager_test.go | 13 +- web/public/static/langs/en.json | 29 +++- web/src/app/AccountApi.js | 46 +++++- web/src/app/errors.js | 12 +- web/src/app/utils.js | 2 + web/src/components/Account.jsx | 219 +++++++++++++++------------- web/src/components/App.jsx | 2 + web/src/components/EmailVerify.jsx | 74 ++++++++++ web/src/components/routes.js | 1 + 19 files changed, 789 insertions(+), 332 deletions(-) create mode 100644 server/server_account_email_test.go create mode 100644 web/src/components/EmailVerify.jsx diff --git a/mail/sender.go b/mail/sender.go index 5511cb04..b840adf1 100644 --- a/mail/sender.go +++ b/mail/sender.go @@ -6,17 +6,14 @@ import ( "net" "net/smtp" "strings" - "sync" "time" "heckel.io/ntfy/v2/log" - "heckel.io/ntfy/v2/util" ) const ( - verifyCodeExpiry = 10 * time.Minute - verifyCodeLength = 6 - verifyCodeSubject = "ntfy email verification" + emailVerificationSubject = "Verify your email for ntfy" + passwordResetSubject = "Reset your ntfy password" ) // Config holds the SMTP configuration for the mail sender @@ -27,33 +24,22 @@ type Config struct { From string // Sender email address } -// Sender sends emails and manages email verification codes +// Sender sends emails via SMTP, including the magic-link emails for email verification and +// password reset. Pending verification/reset state lives in the database (see user.Manager), +// not in this struct. type Sender struct { - config *Config - codes map[string]verifyCode // Verification codes, keyed by email - mu sync.Mutex - closeChan chan struct{} -} - -type verifyCode struct { - code string - expires time.Time + config *Config } // NewSender creates a new mail Sender with the given SMTP config func NewSender(config *Config) *Sender { - s := &Sender{ - config: config, - codes: make(map[string]verifyCode), - closeChan: make(chan struct{}), - } - go s.expireLoop() - return s + return &Sender{config: config} } -// Close stops the background expiry loop +// Close is a no-op, kept so callers don't need to special-case the sender. The sender holds +// no background goroutines (magic-link expiry is swept by the user.Manager reaper). func (s *Sender) Close() { - close(s.closeChan) + // Nothing to do } // Addr returns the SMTP server address @@ -104,51 +90,24 @@ Content-Type: text/plain; charset="utf-8" return s.SendRaw(to, []byte(message)) } -// SendVerification generates a random code, stores it in-memory, and sends a verification email -func (s *Sender) SendVerification(to string) error { - code := util.RandomString(verifyCodeLength) - s.mu.Lock() - s.codes[to] = verifyCode{ - code: code, - expires: time.Now().Add(verifyCodeExpiry), - } - s.mu.Unlock() - body := fmt.Sprintf("Your ntfy email verification code is: %s\n\nThis code expires in 10 minutes.", code) - return s.Send(to, verifyCodeSubject, body) +// SendEmailVerification sends an email containing a magic link to verify ownership of the +// recipient address. The link carries a one-time token validated against the database. +func (s *Sender) SendEmailVerification(to, link string) error { + body := fmt.Sprintf(`Click the link below to verify this email address for your ntfy account: + +%s + +This link expires in 24 hours. If you did not request this, you can safely ignore this email.`, link) + return s.Send(to, emailVerificationSubject, body) } -// CheckVerification checks if the code matches and hasn't expired. Removes the entry on success. -func (s *Sender) CheckVerification(email, code string) bool { - s.mu.Lock() - defer s.mu.Unlock() - vc, ok := s.codes[email] - if !ok || time.Now().After(vc.expires) || vc.code != code { - return false - } - delete(s.codes, email) - return true -} +// SendPasswordReset sends an email containing a magic link to set a new password. The link +// carries a one-time token validated against the database. +func (s *Sender) SendPasswordReset(to, link string) error { + body := fmt.Sprintf(`Click the link below to set a new password for your ntfy account: -func (s *Sender) expireLoop() { - ticker := time.NewTicker(time.Minute) - defer ticker.Stop() - for { - select { - case <-ticker.C: - s.expireVerificationCodes() - case <-s.closeChan: - return - } - } -} +%s -func (s *Sender) expireVerificationCodes() { - s.mu.Lock() - defer s.mu.Unlock() - now := time.Now() - for email, vc := range s.codes { - if now.After(vc.expires) { - delete(s.codes, email) - } - } +This link expires in 1 hour. If you did not request this, you can safely ignore this email -- your password will not change.`, link) + return s.Send(to, passwordResetSubject, body) } diff --git a/server/errors.go b/server/errors.go index 3197d6ca..5ac6ce38 100644 --- a/server/errors.go +++ b/server/errors.go @@ -143,7 +143,7 @@ var ( errHTTPBadRequestTemplateFileInvalid = &errHTTP{40048, http.StatusBadRequest, "invalid request: template file invalid", "https://ntfy.sh/docs/publish/#message-templating", nil} errHTTPBadRequestSequenceIDInvalid = &errHTTP{40049, http.StatusBadRequest, "invalid request: sequence ID invalid", "https://ntfy.sh/docs/publish/#updating-deleting-notifications", nil} errHTTPBadRequestEmailAddressInvalid = &errHTTP{40050, http.StatusBadRequest, "invalid request: invalid e-mail address", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} - errHTTPBadRequestEmailVerificationCodeInvalid = &errHTTP{40051, http.StatusBadRequest, "invalid request: email verification code invalid or expired", "", nil} + errHTTPBadRequestEmailVerificationCodeInvalid = &errHTTP{40051, http.StatusBadRequest, "invalid request: email verification link invalid or expired", "", nil} errHTTPBadRequestEmailAddressNotVerified = &errHTTP{40052, http.StatusBadRequest, "invalid request: email address not verified", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} errHTTPBadRequestAnonymousEmailNotAllowed = &errHTTP{40053, http.StatusBadRequest, "invalid request: anonymous email sending is not allowed", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} errHTTPNotFound = &errHTTP{40401, http.StatusNotFound, "page not found", "", nil} @@ -156,6 +156,7 @@ var ( errHTTPConflictProvisionedUserChange = &errHTTP{40905, http.StatusConflict, "conflict: cannot change or delete provisioned user", "", nil} errHTTPConflictProvisionedTokenChange = &errHTTP{40906, http.StatusConflict, "conflict: cannot change or delete provisioned token", "", nil} errHTTPConflictEmailExists = &errHTTP{40907, http.StatusConflict, "conflict: email address already exists", "", nil} + errHTTPConflictEmailPrimaryElsewhere = &errHTTP{40908, http.StatusConflict, "conflict: email address is the recovery email on another account", "", nil} errHTTPGonePhoneVerificationExpired = &errHTTP{41001, http.StatusGone, "phone number verification expired or does not exist", "", nil} errHTTPEntityTooLargeAttachment = &errHTTP{41301, http.StatusRequestEntityTooLarge, "attachment too large, or bandwidth limit reached", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPEntityTooLargeMatrixRequest = &errHTTP{41302, http.StatusRequestEntityTooLarge, "Matrix request is larger than the max allowed length", "", nil} diff --git a/server/server.go b/server/server.go index c380bd26..95d2ecf7 100644 --- a/server/server.go +++ b/server/server.go @@ -58,7 +58,7 @@ type Server struct { smtpServer *smtp.Server smtpServerBackend *smtpBackend smtpSender mailer - mailSender *mail.Sender + mailSender emailVerifier topics map[string]*topic visitors map[string]*visitor // ip: or user: firebaseClient *firebaseClient @@ -80,9 +80,10 @@ type handleFunc func(http.ResponseWriter, *http.Request, *visitor) error var ( // If changed, don't forget to update Android App and auth_sqlite.go - topicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No /! - topicPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}$`) // Regex must match JS & Android app! - externalTopicPathRegex = regexp.MustCompile(`^/[^/]+\.[^/]+/[-_A-Za-z0-9]{1,64}$`) // Extended topic path, for web-app, e.g. /example.com/mytopic + topicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No /! + topicPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}$`) // Regex must match JS & Android app! + externalTopicPathRegex = regexp.MustCompile(`^/[^/]+\.[^/]+/[-_A-Za-z0-9]{1,64}$`) // Extended topic path, for web-app, e.g. /example.com/mytopic + webAppEmailVerifyRegex = regexp.MustCompile(`^/account/email/verify/[-_A-Za-z0-9]+$`) // Magic-link landing (served by the web app) jsonPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/json$`) ssePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/sse$`) rawPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/raw$`) @@ -116,6 +117,9 @@ var ( apiAccountPhoneVerifyPath = "/v1/account/phone/verify" apiAccountEmailPath = "/v1/account/email" apiAccountEmailVerifyPath = "/v1/account/email/verify" + apiAccountEmailPrimaryPath = "/v1/account/email/primary" + apiAccountEmailResendPath = "/v1/account/email/resend" + webAppEmailVerifyPathPrefix = "/account/email/verify/" // Browser landing route; raw token appended apiAccountBillingPortalPath = "/v1/account/billing/portal" apiAccountBillingWebhookPath = "/v1/account/billing/webhook" apiAccountBillingSubscriptionPath = "/v1/account/billing/subscription" @@ -177,15 +181,16 @@ const ( // subscriber (if configured). func New(conf *Config) (*Server, error) { var mailer mailer - var mailSender *mail.Sender + var emailSender emailVerifier // Stays untyped-nil when SMTP is unconfigured, so ensureEmailsEnabled gates correctly if conf.SMTPSenderAddr != "" { - mailSender = mail.NewSender(&mail.Config{ + mailSender := mail.NewSender(&mail.Config{ SMTPAddr: conf.SMTPSenderAddr, SMTPUser: conf.SMTPSenderUser, SMTPPass: conf.SMTPSenderPass, From: conf.SMTPSenderFrom, }) mailer = &smtpSender{config: conf, sender: mailSender} + emailSender = mailSender } var stripe stripeAPI if payments.Available && conf.StripeSecretKey != "" { @@ -291,7 +296,7 @@ func New(conf *Config) (*Server, error) { attachment: attachmentStore, firebaseClient: firebaseClient, smtpSender: mailer, - mailSender: mailSender, + mailSender: emailSender, topics: topics, userManager: userManager, messages: messages, @@ -611,12 +616,16 @@ func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visit return s.ensureUser(s.ensureCallsEnabled(s.withAccountSync(s.handleAccountPhoneNumberAdd)))(w, r, v) } else if r.Method == http.MethodDelete && r.URL.Path == apiAccountPhonePath { return s.ensureUser(s.ensureCallsEnabled(s.withAccountSync(s.handleAccountPhoneNumberDelete)))(w, r, v) - } else if r.Method == http.MethodPut && r.URL.Path == apiAccountEmailVerifyPath { - return s.ensureUser(s.ensureEmailsEnabled(s.withAccountSync(s.handleAccountEmailVerify)))(w, r, v) } else if r.Method == http.MethodPut && r.URL.Path == apiAccountEmailPath { return s.ensureUser(s.ensureEmailsEnabled(s.withAccountSync(s.handleAccountEmailAdd)))(w, r, v) + } else if r.Method == http.MethodPost && r.URL.Path == apiAccountEmailVerifyPath { + return s.ensureEmailsEnabled(s.limitRequests(s.handleAccountEmailVerify))(w, r, v) // No ensureUser: clicked from a mail client, possibly logged out } else if r.Method == http.MethodDelete && r.URL.Path == apiAccountEmailPath { return s.ensureUser(s.ensureEmailsEnabled(s.withAccountSync(s.handleAccountEmailDelete)))(w, r, v) + } else if r.Method == http.MethodPost && r.URL.Path == apiAccountEmailPrimaryPath { + return s.ensureUser(s.withAccountSync(s.handleAccountEmailSetPrimary))(w, r, v) + } else if r.Method == http.MethodPost && r.URL.Path == apiAccountEmailResendPath { + return s.ensureUser(s.ensureEmailsEnabled(s.handleAccountEmailResend))(w, r, v) } else if r.Method == http.MethodPost && apiWebPushPath == r.URL.Path { return s.ensureWebPushEnabled(s.limitRequests(s.handleWebPushUpdate))(w, r, v) } else if r.Method == http.MethodDelete && apiWebPushPath == r.URL.Path { @@ -659,12 +668,25 @@ func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visit return s.limitRequests(s.authorizeTopicRead(s.handleSubscribeWS))(w, r, v) } else if r.Method == http.MethodGet && authPathRegex.MatchString(r.URL.Path) { return s.limitRequests(s.authorizeTopicRead(s.handleTopicAuth))(w, r, v) + } else if r.Method == http.MethodGet && webAppEmailVerifyRegex.MatchString(r.URL.Path) { + return s.ensureWebEnabled(s.handleWebAppIndex)(w, r, v) // Magic-link landing page (client-side route) } else if r.Method == http.MethodGet && (topicPathRegex.MatchString(r.URL.Path) || externalTopicPathRegex.MatchString(r.URL.Path)) { return s.ensureWebEnabled(s.handleTopic)(w, r, v) } return errHTTPNotFound } +// handleWebAppIndex serves the embedded web app's index for client-side (SPA) routes the +// browser router resolves, such as the magic-link landing pages. Because these URLs carry a +// one-time token in the path, the response is marked no-referrer (so the token can't leak to +// third parties via the Referer header) and noindex (so it never gets indexed). +func (s *Server) handleWebAppIndex(w http.ResponseWriter, r *http.Request, v *visitor) error { + w.Header().Set("Referrer-Policy", "no-referrer") + w.Header().Set("X-Robots-Tag", "noindex") + r.URL.Path = webAppIndex + return s.handleStatic(w, r, v) +} + func (s *Server) handleRoot(w http.ResponseWriter, r *http.Request, v *visitor) error { r.URL.Path = webAppIndex return s.handleStatic(w, r, v) @@ -715,21 +737,22 @@ func (s *Server) handleWebConfig(w http.ResponseWriter, _ *http.Request, _ *visi func (s *Server) configResponse() *apiConfigResponse { return &apiConfigResponse{ - BaseURL: "", // Will translate to window.location.origin - AppRoot: s.config.WebRoot, - EnableLogin: s.config.EnableLogin, - RequireLogin: s.config.RequireLogin, - EnableSignup: s.config.EnableSignup, - EnablePayments: s.config.StripeSecretKey != "", - EnableCalls: s.config.TwilioAccount != "", - EnableEmails: s.config.SMTPSenderFrom != "", - EnableEmailVerify: s.config.SMTPSenderVerify, - EnableReservations: s.config.EnableReservations, - EnableWebPush: s.config.WebPushPublicKey != "", - BillingContact: s.config.BillingContact, - WebPushPublicKey: s.config.WebPushPublicKey, - DisallowedTopics: s.config.DisallowedTopics, - ConfigHash: s.config.Hash(), + BaseURL: "", // Will translate to window.location.origin + AppRoot: s.config.WebRoot, + EnableLogin: s.config.EnableLogin, + RequireLogin: s.config.RequireLogin, + EnableSignup: s.config.EnableSignup, + EnablePayments: s.config.StripeSecretKey != "", + EnableCalls: s.config.TwilioAccount != "", + EnableEmails: s.config.SMTPSenderFrom != "", + EnableEmailVerify: s.config.SMTPSenderVerify, + EnableResetPassword: s.config.SMTPSenderFrom != "" && s.config.BaseURL != "", // Reset links need SMTP + an absolute base-url + EnableReservations: s.config.EnableReservations, + EnableWebPush: s.config.WebPushPublicKey != "", + BillingContact: s.config.BillingContact, + WebPushPublicKey: s.config.WebPushPublicKey, + DisallowedTopics: s.config.DisallowedTopics, + ConfigHash: s.config.Hash(), } } diff --git a/server/server_account.go b/server/server_account.go index 7c5c03c3..fd3a5eba 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -15,8 +15,9 @@ import ( ) const ( - syncTopicAccountSyncEvent = "sync" - tokenExpiryDuration = 72 * time.Hour // Extend tokens by this much + syncTopicAccountSyncEvent = "sync" + tokenExpiryDuration = 72 * time.Hour // Extend tokens by this much + emailVerificationTokenExpiry = 24 * time.Hour // Magic-link lifetime for email verification ) func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v *visitor) error { @@ -168,6 +169,18 @@ func (s *Server) handleAccountGet(w http.ResponseWriter, r *http.Request, v *vis if len(emails) > 0 { response.Emails = emails } + primaryEmail, err := s.userManager.PrimaryEmail(u.ID) + if err != nil { + return err + } + response.PrimaryEmail = primaryEmail + pendingEmails, err := s.userManager.PendingEmails(u.ID) + if err != nil { + return err + } + if len(pendingEmails) > 0 { + response.PendingEmails = pendingEmails + } } } else { response.Username = user.Everyone @@ -615,74 +628,149 @@ func (s *Server) handleAccountPhoneNumberDelete(w http.ResponseWriter, r *http.R return s.writeJSON(w, newSuccessResponse()) } -func (s *Server) handleAccountEmailVerify(w http.ResponseWriter, r *http.Request, v *visitor) error { +// handleAccountEmailAdd starts email verification (PUT /v1/account/email): it generates a +// magic-link token, stores a pending verification, and emails the link. The address is NOT +// added to the verified list until the user clicks the link (handleAccountEmailVerify). +func (s *Server) handleAccountEmailAdd(w http.ResponseWriter, r *http.Request, v *visitor) error { u := v.User() - req, err := readJSONWithLimit[apiAccountEmailVerifyRequest](r.Body, jsonBodyBytesLimit, false) + req, err := readJSONWithLimit[apiAccountEmailRequest](r.Body, jsonBodyBytesLimit, false) if err != nil { return err } else if !emailAddressRegex.MatchString(req.Email) { return errHTTPBadRequestEmailAddressInvalid } - // Check user is allowed to add emails - if u == nil { - return errHTTPUnauthorized - } else if u.IsUser() && u.Tier != nil && u.Tier.EmailLimit == 0 { + // Check user is allowed to add emails (the tier email limit gates the feature) + if u.IsUser() && u.Tier != nil && u.Tier.EmailLimit == 0 { return errHTTPUnauthorized } else if u.IsUser() && u.Tier == nil && s.config.VisitorEmailLimitBurst == 0 { return errHTTPUnauthorized } - // Check if email already exists + // Reject if already verified on this account (pending re-requests are fine -- they replace) emails, err := s.userManager.Emails(u.ID) if err != nil { return err } else if util.Contains(emails, req.Email) { return errHTTPConflictEmailExists } - // Check email rate limit (counts against the user's email quota) + // Rate limit (counts against the user's email quota) if !v.EmailAllowed() { return errHTTPTooManyRequestsLimitEmails } - // Send verification email - logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Sending email verification") - if err := s.mailSender.SendVerification(req.Email); err != nil { + logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Starting email verification") + if err := s.enqueueEmailVerification(u.ID, req.Email); err != nil { return err } return s.writeJSON(w, newSuccessResponse()) } -func (s *Server) handleAccountEmailAdd(w http.ResponseWriter, r *http.Request, v *visitor) error { +// handleAccountEmailVerify performs verification from the (unauthenticated) landing page +// (POST /v1/account/email/verify): it validates the raw token, adds the address to the user's +// verified emails, and -- if the user has no primary yet -- promotes it. No auth is required; +// the token binds the action to a user, so the click works from a logged-out mail client. +func (s *Server) handleAccountEmailVerify(w http.ResponseWriter, r *http.Request, v *visitor) error { + req, err := readJSONWithLimit[apiAccountEmailVerifyRequest](r.Body, jsonBodyBytesLimit, false) + if err != nil { + return err + } else if req.Token == "" { + return errHTTPBadRequestEmailVerificationCodeInvalid + } + m, err := s.userManager.VerifyEmail(req.Token) + if errors.Is(err, user.ErrMagicLinkNotFound) { + return errHTTPBadRequestEmailVerificationCodeInvalid + } else if err != nil { + return err + } + logvr(v, r).Tag(tagAccount).Field("email", m.Email).Info("Email verified") + // Refresh the verified user's other sessions. The request is unauthenticated (v.User() is + // usually nil), so resolve the user from the token row and publish to their sync topic. + s.publishSyncEventForUserIDAsync(v, m.UserID) + return s.writeJSON(w, newSuccessResponse()) +} + +// handleAccountEmailDelete removes an email address, whether verified or still pending +// (DELETE /v1/account/email). Removing the primary leaves the account with no primary. +func (s *Server) handleAccountEmailDelete(w http.ResponseWriter, r *http.Request, v *visitor) error { u := v.User() - req, err := readJSONWithLimit[apiAccountEmailAddRequest](r.Body, jsonBodyBytesLimit, false) + req, err := readJSONWithLimit[apiAccountEmailRequest](r.Body, jsonBodyBytesLimit, false) if err != nil { return err } else if !emailAddressRegex.MatchString(req.Email) { return errHTTPBadRequestEmailAddressInvalid - } else if !s.mailSender.CheckVerification(req.Email, req.Code) { - return errHTTPBadRequestEmailVerificationCodeInvalid } - logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Adding email as verified") - if err := s.userManager.AddEmail(u.ID, req.Email); err != nil { + logvr(v, r).Tag(tagAccount).Field("email", req.Email).Debug("Deleting email (verified or pending)") + if err := s.userManager.RemoveEmail(u.ID, req.Email); err != nil { + return err + } + // Also drop any pending verification for the address (no-op if there is none) + if err := s.userManager.DeleteEmailVerification(u.ID, req.Email); err != nil { return err } return s.writeJSON(w, newSuccessResponse()) } -func (s *Server) handleAccountEmailDelete(w http.ResponseWriter, r *http.Request, v *visitor) error { +// handleAccountEmailSetPrimary marks an already-verified email as the user's primary (recovery) +// email (POST /v1/account/email/primary). +func (s *Server) handleAccountEmailSetPrimary(w http.ResponseWriter, r *http.Request, v *visitor) error { u := v.User() - req, err := readJSONWithLimit[apiAccountEmailVerifyRequest](r.Body, jsonBodyBytesLimit, false) + req, err := readJSONWithLimit[apiAccountEmailRequest](r.Body, jsonBodyBytesLimit, false) if err != nil { return err - } - if !emailAddressRegex.MatchString(req.Email) { + } else if !emailAddressRegex.MatchString(req.Email) { return errHTTPBadRequestEmailAddressInvalid } - logvr(v, r).Tag(tagAccount).Field("email", req.Email).Debug("Deleting verified email") - if err := s.userManager.RemoveEmail(u.ID, req.Email); err != nil { + logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Setting primary email") + err = s.userManager.SetPrimaryEmail(u.ID, req.Email) + if errors.Is(err, user.ErrEmailPrimaryElsewhere) { + return errHTTPConflictEmailPrimaryElsewhere + } else if errors.Is(err, user.ErrEmailNotFound) { + return errHTTPBadRequestEmailAddressNotVerified + } else if err != nil { return err } return s.writeJSON(w, newSuccessResponse()) } +// handleAccountEmailResend re-sends a pending email verification (POST /v1/account/email/resend). +func (s *Server) handleAccountEmailResend(w http.ResponseWriter, r *http.Request, v *visitor) error { + u := v.User() + req, err := readJSONWithLimit[apiAccountEmailRequest](r.Body, jsonBodyBytesLimit, false) + if err != nil { + return err + } else if !emailAddressRegex.MatchString(req.Email) { + return errHTTPBadRequestEmailAddressInvalid + } + // Only resend for an address that is actually pending on this account + pending, err := s.userManager.PendingEmails(u.ID) + if err != nil { + return err + } else if !util.Contains(pending, req.Email) { + return errHTTPBadRequestEmailAddressInvalid + } + if !v.EmailAllowed() { + return errHTTPTooManyRequestsLimitEmails + } + logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Resending email verification") + if err := s.enqueueEmailVerification(u.ID, req.Email); err != nil { + return err + } + return s.writeJSON(w, newSuccessResponse()) +} + +// enqueueEmailVerification generates a magic-link token for the given address, stores the +// pending verification (replacing any existing one), and emails the link. Shared by the add, +// resend, signup, and Stripe paths. Requires base-url to build an absolute link. +func (s *Server) enqueueEmailVerification(userID, email string) error { + if s.config.BaseURL == "" { + return errHTTPInternalErrorMissingBaseURL + } + token, err := s.userManager.CreateMagicLink(user.MagicLinkKindEmailVerify, userID, email, emailVerificationTokenExpiry) + if err != nil { + return err + } + link := s.config.BaseURL + webAppEmailVerifyPathPrefix + token + return s.mailSender.SendEmailVerification(email, link) +} + // convertEmailAddress checks the email address against the user's verified email list. // If smtp-sender-verify is false (default), the email is passed through as-is for // backwards compatibility. If true, the user must be authenticated and the email must be @@ -721,9 +809,30 @@ func (s *Server) publishSyncEventAsync(v *visitor) { }() } -// publishSyncEvent publishes a sync message to the user's sync topic +// publishSyncEvent publishes a sync message to the authenticated user's sync topic func (s *Server) publishSyncEvent(v *visitor) error { - u := v.User() + return s.publishSyncEventForUser(v, v.User()) +} + +// publishSyncEventForUserIDAsync publishes a sync event to the sync topic of the user with the +// given ID, resolving the user first. Used by the unauthenticated email-verify handler, where +// the request visitor has no associated user but the token identifies the account to refresh. +func (s *Server) publishSyncEventForUserIDAsync(v *visitor, userID string) { + go func() { + u, err := s.userManager.UserByID(userID) + if err != nil { + logv(v).Err(err).Trace("Error loading user for sync event") + return + } + if err := s.publishSyncEventForUser(v, u); err != nil { + logv(v).Err(err).Trace("Error publishing to user's sync topic") + } + }() +} + +// publishSyncEventForUser publishes a sync message to the given user's sync topic, using v as +// the publishing visitor (for rate-limit accounting). No-op if the user has no sync topic. +func (s *Server) publishSyncEventForUser(v *visitor, u *user.User) error { if u == nil || u.SyncTopic == "" { return nil } diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go new file mode 100644 index 00000000..b594684d --- /dev/null +++ b/server/server_account_email_test.go @@ -0,0 +1,190 @@ +package server + +import ( + "fmt" + "io" + "strings" + "testing" + + "github.com/stretchr/testify/require" + "heckel.io/ntfy/v2/user" + "heckel.io/ntfy/v2/util" +) + +// captureMailer is a fake emailVerifier that records the magic links it is asked to send, so +// tests can "click" them without a real SMTP server. +type captureMailer struct { + verifyLinks map[string]string // email -> verification link + resetLinks map[string]string // email -> reset link +} + +func newCaptureMailer() *captureMailer { + return &captureMailer{verifyLinks: map[string]string{}, resetLinks: map[string]string{}} +} + +func (c *captureMailer) SendEmailVerification(to, link string) error { + c.verifyLinks[to] = link + return nil +} + +func (c *captureMailer) SendPasswordReset(to, link string) error { + c.resetLinks[to] = link + return nil +} + +func (c *captureMailer) Close() {} + +// newEmailTestServer creates a server with email sending "enabled" (SMTP + base-url configured) +// and a capturing mailer injected, plus a tier-less user "ben" logged in via basic auth. +func newEmailTestServer(t *testing.T, databaseURL string) (*Server, *captureMailer, map[string]string) { + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.SMTPSenderAddr = "localhost:25" + conf.SMTPSenderFrom = "noreply@example.com" + conf.BaseURL = "https://ntfy.example.com" + s := newTestServer(t, conf) + mailer := newCaptureMailer() + s.mailSender = mailer + require.Nil(t, s.userManager.AddUser("ben", "ben", user.RoleUser, false)) + auth := map[string]string{"Authorization": util.BasicAuth("ben", "ben")} + return s, mailer, auth +} + +func getAccount(t *testing.T, s *Server, auth map[string]string) *apiAccountResponse { + rr := request(t, s, "GET", "/v1/account", "", auth) + require.Equal(t, 200, rr.Code) + account, err := util.UnmarshalJSON[apiAccountResponse](io.NopCloser(rr.Body)) + require.Nil(t, err) + return account +} + +func tokenFromLink(t *testing.T, link, prefix string) string { + require.True(t, strings.HasPrefix(link, prefix), "link %q missing prefix %q", link, prefix) + return strings.TrimPrefix(link, prefix) +} + +func TestAccount_Email_AddVerifySetsPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + // Start verification + rr := request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, auth) + require.Equal(t, 200, rr.Code) + + // Pending, not yet verified, no primary + account := getAccount(t, s, auth) + require.Equal(t, []string{"ben@example.com"}, account.PendingEmails) + require.Empty(t, account.Emails) + require.Equal(t, "", account.PrimaryEmail) + + // "Click" the captured link (unauthenticated POST) + token := tokenFromLink(t, mailer.verifyLinks["ben@example.com"], "https://ntfy.example.com/account/email/verify/") + rr = request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, token), nil) + require.Equal(t, 200, rr.Code) + + // Now verified + primary, no longer pending + account = getAccount(t, s, auth) + require.Equal(t, []string{"ben@example.com"}, account.Emails) + require.Equal(t, "ben@example.com", account.PrimaryEmail) + require.Empty(t, account.PendingEmails) + }) +} + +func TestAccount_Email_VerifyInvalidToken(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, _, _ := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + rr := request(t, s, "POST", "/v1/account/email/verify", `{"token":"doesnotexist"}`, nil) + require.Equal(t, 400, rr.Code) + require.Equal(t, 40051, toHTTPError(t, rr.Body.String()).Code) + + // Empty token also rejected + rr = request(t, s, "POST", "/v1/account/email/verify", `{"token":""}`, nil) + require.Equal(t, 400, rr.Code) + }) +} + +func TestAccount_Email_DeletePending(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, _, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, auth).Code) + require.Equal(t, []string{"ben@example.com"}, getAccount(t, s, auth).PendingEmails) + + // Deleting the pending address clears it (no verification ever happened) + require.Equal(t, 200, request(t, s, "DELETE", "/v1/account/email", `{"email":"ben@example.com"}`, auth).Code) + account := getAccount(t, s, auth) + require.Empty(t, account.PendingEmails) + require.Empty(t, account.Emails) + }) +} + +func TestAccount_Email_Resend(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, auth).Code) + firstLink := mailer.verifyLinks["ben@example.com"] + require.NotEmpty(t, firstLink) + + // Resend issues a fresh link (the old one is replaced) + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/resend", `{"email":"ben@example.com"}`, auth).Code) + require.NotEqual(t, firstLink, mailer.verifyLinks["ben@example.com"]) + + // The old token no longer verifies; the new one does + oldToken := tokenFromLink(t, firstLink, "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 400, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, oldToken), nil).Code) + newToken := tokenFromLink(t, mailer.verifyLinks["ben@example.com"], "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, newToken), nil).Code) + + // Resending for a non-pending address is rejected + require.Equal(t, 400, request(t, s, "POST", "/v1/account/email/resend", `{"email":"never@example.com"}`, auth).Code) + }) +} + +func TestAccount_Email_SetPrimaryCollision(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + // ben verifies shared@ -> becomes his primary + require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"shared@example.com"}`, auth).Code) + benToken := tokenFromLink(t, mailer.verifyLinks["shared@example.com"], "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, benToken), nil).Code) + require.Equal(t, "shared@example.com", getAccount(t, s, auth).PrimaryEmail) + + // alice verifies the same address -> allowed as secondary, but it is not her primary + require.Nil(t, s.userManager.AddUser("alice", "alice", user.RoleUser, false)) + aliceAuth := map[string]string{"Authorization": util.BasicAuth("alice", "alice")} + require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"shared@example.com"}`, aliceAuth).Code) + aliceToken := tokenFromLink(t, mailer.verifyLinks["shared@example.com"], "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, aliceToken), nil).Code) + aliceAccount := getAccount(t, s, aliceAuth) + require.Equal(t, []string{"shared@example.com"}, aliceAccount.Emails) + require.Equal(t, "", aliceAccount.PrimaryEmail) + + // alice trying to promote it to primary collides with ben's + rr := request(t, s, "POST", "/v1/account/email/primary", `{"email":"shared@example.com"}`, aliceAuth) + require.Equal(t, 409, rr.Code) + require.Equal(t, 40908, toHTTPError(t, rr.Body.String()).Code) + }) +} + +func TestAccount_Email_AddDuplicateVerified(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, auth).Code) + token := tokenFromLink(t, mailer.verifyLinks["ben@example.com"], "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, token), nil).Code) + + // Adding the same already-verified address is a conflict + rr := request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, auth) + require.Equal(t, 409, rr.Code) + require.Equal(t, 40907, toHTTPError(t, rr.Body.String()).Code) + }) +} diff --git a/server/server_test.go b/server/server_test.go index bb4ddfba..1d19815b 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -1706,11 +1706,11 @@ func TestServer_AccountEmailVerify_UserWithoutTier(t *testing.T) { // Create a user without a tier require.Nil(t, s.userManager.AddUser("ben", "ben", user.RoleUser, false)) - // Verify email request should NOT return 401 - response := request(t, s, "PUT", "/v1/account/email/verify", `{"email":"ben@example.com"}`, map[string]string{ + // Starting email verification should NOT return 401 + response := request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, map[string]string{ "Authorization": util.BasicAuth("ben", "ben"), }) - // The request will fail (SMTP not available), but it must NOT be a 401 + // The request may fail (SMTP not available), but it must NOT be a 401 require.NotEqual(t, 401, response.Code) }) } @@ -1731,7 +1731,7 @@ func TestServer_AccountEmailVerify_UserWithoutTier_EmailLimitZero(t *testing.T) require.Nil(t, s.userManager.AddUser("ben", "ben", user.RoleUser, false)) // Should be rejected with 401 since email sending is disabled - response := request(t, s, "PUT", "/v1/account/email/verify", `{"email":"ben@example.com"}`, map[string]string{ + response := request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, map[string]string{ "Authorization": util.BasicAuth("ben", "ben"), }) require.Equal(t, 401, response.Code) diff --git a/server/smtp_sender.go b/server/smtp_sender.go index 885f806b..1e7460e8 100644 --- a/server/smtp_sender.go +++ b/server/smtp_sender.go @@ -20,6 +20,14 @@ type mailer interface { Counts() (total int64, success int64, failure int64) } +// emailVerifier sends the magic-link emails for email verification and password reset. +// *mail.Sender implements it; tests inject a fake to capture the generated links. +type emailVerifier interface { + SendEmailVerification(to, link string) error + SendPasswordReset(to, link string) error + Close() +} + type smtpSender struct { config *Config sender *mail.Sender diff --git a/server/types.go b/server/types.go index 1f69d3de..b51e9f00 100644 --- a/server/types.go +++ b/server/types.go @@ -226,13 +226,16 @@ type apiAccountPhoneNumberAddRequest struct { Code string `json:"code"` // Only set when adding a phone number } -type apiAccountEmailVerifyRequest struct { +// apiAccountEmailRequest carries an email address for the add/delete/set-primary/resend +// endpoints (all of which identify an email by address in the JSON body). +type apiAccountEmailRequest struct { Email string `json:"email"` } -type apiAccountEmailAddRequest struct { - Email string `json:"email"` - Code string `json:"code"` +// apiAccountEmailVerifyRequest carries the raw magic-link token submitted (unauthenticated) +// from the verification landing page. +type apiAccountEmailVerifyRequest struct { + Token string `json:"token"` } type apiAccountTier struct { @@ -292,6 +295,8 @@ type apiAccountResponse struct { Tokens []*apiAccountTokenResponse `json:"tokens,omitempty"` PhoneNumbers []string `json:"phone_numbers,omitempty"` Emails []string `json:"emails,omitempty"` + PrimaryEmail string `json:"primary_email,omitempty"` // The verified recovery email, if set + PendingEmails []string `json:"pending_emails,omitempty"` // Unverified addresses awaiting a magic-link click Tier *apiAccountTier `json:"tier,omitempty"` Limits *apiAccountLimits `json:"limits,omitempty"` Stats *apiAccountStats `json:"stats,omitempty"` @@ -304,21 +309,22 @@ type apiAccountReservationRequest struct { } type apiConfigResponse struct { - BaseURL string `json:"base_url"` - AppRoot string `json:"app_root"` - EnableLogin bool `json:"enable_login"` - RequireLogin bool `json:"require_login"` - EnableSignup bool `json:"enable_signup"` - EnablePayments bool `json:"enable_payments"` - EnableCalls bool `json:"enable_calls"` - EnableEmails bool `json:"enable_emails"` - EnableEmailVerify bool `json:"enable_email_verify"` - EnableReservations bool `json:"enable_reservations"` - EnableWebPush bool `json:"enable_web_push"` - BillingContact string `json:"billing_contact"` - WebPushPublicKey string `json:"web_push_public_key"` - DisallowedTopics []string `json:"disallowed_topics"` - ConfigHash string `json:"config_hash"` + BaseURL string `json:"base_url"` + AppRoot string `json:"app_root"` + EnableLogin bool `json:"enable_login"` + RequireLogin bool `json:"require_login"` + EnableSignup bool `json:"enable_signup"` + EnablePayments bool `json:"enable_payments"` + EnableCalls bool `json:"enable_calls"` + EnableEmails bool `json:"enable_emails"` + EnableEmailVerify bool `json:"enable_email_verify"` + EnableResetPassword bool `json:"enable_reset_password"` + EnableReservations bool `json:"enable_reservations"` + EnableWebPush bool `json:"enable_web_push"` + BillingContact string `json:"billing_contact"` + WebPushPublicKey string `json:"web_push_public_key"` + DisallowedTopics []string `json:"disallowed_topics"` + ConfigHash string `json:"config_hash"` } type apiAccountBillingPrices struct { diff --git a/user/magic_link_test.go b/user/magic_link_test.go index 4be1fe55..fd96bb1a 100644 --- a/user/magic_link_test.go +++ b/user/magic_link_test.go @@ -7,18 +7,11 @@ import ( "github.com/stretchr/testify/require" ) -// addVerifyLink generates a raw token, stores an email-verification magic link for it, and -// returns the raw token so the test can "click" it via VerifyEmail. -func addVerifyLink(t *testing.T, a *Manager, userID, email string, expires int64) string { - raw := generateLinkToken() - require.Nil(t, a.AddMagicLink(&MagicLink{ - TokenHash: hashToken(raw), - Kind: MagicLinkKindEmailVerify, - UserID: userID, - Email: email, - Expires: expires, - Created: time.Now().Unix(), - })) +// addVerifyLink stores an email-verification magic link and returns the raw token so the test +// can "click" it via VerifyEmail. +func addVerifyLink(t *testing.T, a *Manager, userID, email string, ttl time.Duration) string { + raw, err := a.CreateMagicLink(MagicLinkKindEmailVerify, userID, email, ttl) + require.Nil(t, err) return raw } @@ -29,7 +22,7 @@ func TestUser_MagicLink_VerifyEmail_SetsPrimary(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) // Before verifying: pending, not yet verified, no primary pending, err := a.PendingEmails(phil.ID) @@ -43,7 +36,7 @@ func TestUser_MagicLink_VerifyEmail_SetsPrimary(t *testing.T) { require.Equal(t, "", primary) // Verify: the first verified email auto-becomes primary - m, err := a.VerifyEmail(hashToken(raw)) + m, err := a.VerifyEmail(raw) require.Nil(t, err) require.Equal(t, "phil@example.com", m.Email) @@ -71,12 +64,12 @@ func TestUser_MagicLink_VerifyEmail_SecondStaysSecondary(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw1 := addVerifyLink(t, a, phil.ID, "first@example.com", time.Now().Add(24*time.Hour).Unix()) - _, err = a.VerifyEmail(hashToken(raw1)) + raw1 := addVerifyLink(t, a, phil.ID, "first@example.com", 24*time.Hour) + _, err = a.VerifyEmail(raw1) require.Nil(t, err) - raw2 := addVerifyLink(t, a, phil.ID, "second@example.com", time.Now().Add(24*time.Hour).Unix()) - _, err = a.VerifyEmail(hashToken(raw2)) + raw2 := addVerifyLink(t, a, phil.ID, "second@example.com", 24*time.Hour) + _, err = a.VerifyEmail(raw2) require.Nil(t, err) // Both verified, but primary is still the first @@ -100,16 +93,14 @@ func TestUser_MagicLink_PrimaryGlobalUniqueness(t *testing.T) { require.Nil(t, err) // phil verifies shared@ first -> becomes his primary - rawPhil := addVerifyLink(t, a, phil.ID, "shared@example.com", time.Now().Add(24*time.Hour).Unix()) - _, err = a.VerifyEmail(hashToken(rawPhil)) + _, err = a.VerifyEmail(addVerifyLink(t, a, phil.ID, "shared@example.com", 24*time.Hour)) require.Nil(t, err) primary, err := a.PrimaryEmail(phil.ID) require.Nil(t, err) require.Equal(t, "shared@example.com", primary) // ben verifies the same address -> allowed as secondary, but NOT his primary - rawBen := addVerifyLink(t, a, ben.ID, "shared@example.com", time.Now().Add(24*time.Hour).Unix()) - _, err = a.VerifyEmail(hashToken(rawBen)) + _, err = a.VerifyEmail(addVerifyLink(t, a, ben.ID, "shared@example.com", 24*time.Hour)) require.Nil(t, err) emails, err := a.Emails(ben.ID) require.Nil(t, err) @@ -120,7 +111,7 @@ func TestUser_MagicLink_PrimaryGlobalUniqueness(t *testing.T) { // Explicitly promoting ben's copy to primary collides with phil's require.ErrorIs(t, a.SetPrimaryEmail(ben.ID, "shared@example.com"), ErrEmailPrimaryElsewhere) - // ...and phil keeps his primary (the failed promotion rolled back ben's clear, which was a no-op anyway) + // ...and phil keeps his primary (the failed promotion rolled back ben's clear) primary, err = a.PrimaryEmail(phil.ID) require.Nil(t, err) require.Equal(t, "shared@example.com", primary) @@ -144,8 +135,8 @@ func TestUser_MagicLink_Expired(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(-time.Minute).Unix()) - _, err = a.VerifyEmail(hashToken(raw)) + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", -time.Minute) + _, err = a.VerifyEmail(raw) require.ErrorIs(t, err, ErrMagicLinkNotFound) // Nothing got verified @@ -162,11 +153,11 @@ func TestUser_MagicLink_SingleUse(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) - _, err = a.VerifyEmail(hashToken(raw)) + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) + _, err = a.VerifyEmail(raw) require.Nil(t, err) // Second click: token already consumed - _, err = a.VerifyEmail(hashToken(raw)) + _, err = a.VerifyEmail(raw) require.ErrorIs(t, err, ErrMagicLinkNotFound) }) } @@ -178,17 +169,17 @@ func TestUser_MagicLink_ReplaceOnReRequest(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw1 := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) - raw2 := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Now().Add(24*time.Hour).Unix()) + raw1 := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) + raw2 := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) // Only one pending row remains; the old token no longer works pending, err := a.PendingEmails(phil.ID) require.Nil(t, err) require.Equal(t, []string{"phil@example.com"}, pending) - _, err = a.MagicLinkByHash(hashToken(raw1)) + _, err = a.MagicLinkByToken(raw1) require.ErrorIs(t, err, ErrMagicLinkNotFound) - m, err := a.MagicLinkByHash(hashToken(raw2)) + m, err := a.MagicLinkByToken(raw2) require.Nil(t, err) require.Equal(t, "phil@example.com", m.Email) }) @@ -201,16 +192,10 @@ func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw := generateLinkToken() - require.Nil(t, a.AddMagicLink(&MagicLink{ - TokenHash: hashToken(raw), - Kind: MagicLinkKindPasswordReset, - UserID: phil.ID, - Expires: time.Now().Add(time.Hour).Unix(), - Created: time.Now().Unix(), - })) + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) - m, err := a.MagicLinkByHash(hashToken(raw)) + m, err := a.MagicLinkByToken(raw) require.Nil(t, err) require.Equal(t, MagicLinkKindPasswordReset, m.Kind) require.Equal(t, phil.ID, m.UserID) @@ -222,20 +207,14 @@ func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { require.Equal(t, 0, len(pending)) // New request replaces the old token - raw2 := generateLinkToken() - require.Nil(t, a.AddMagicLink(&MagicLink{ - TokenHash: hashToken(raw2), - Kind: MagicLinkKindPasswordReset, - UserID: phil.ID, - Expires: time.Now().Add(time.Hour).Unix(), - Created: time.Now().Unix(), - })) - _, err = a.MagicLinkByHash(hashToken(raw)) + raw2, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + _, err = a.MagicLinkByToken(raw) require.ErrorIs(t, err, ErrMagicLinkNotFound) // Single use: deleting consumes it - require.Nil(t, a.DeleteMagicLink(hashToken(raw2))) - _, err = a.MagicLinkByHash(hashToken(raw2)) + require.Nil(t, a.DeleteMagicLinkByToken(raw2)) + _, err = a.MagicLinkByToken(raw2) require.ErrorIs(t, err, ErrMagicLinkNotFound) }) } @@ -247,14 +226,14 @@ func TestUser_MagicLink_Reaper(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - expired := addVerifyLink(t, a, phil.ID, "expired@example.com", time.Now().Add(-time.Hour).Unix()) - valid := addVerifyLink(t, a, phil.ID, "valid@example.com", time.Now().Add(time.Hour).Unix()) + expired := addVerifyLink(t, a, phil.ID, "expired@example.com", -time.Hour) + valid := addVerifyLink(t, a, phil.ID, "valid@example.com", time.Hour) require.Nil(t, a.deleteExpiredMagicLinks()) - _, err = a.MagicLinkByHash(hashToken(expired)) + _, err = a.MagicLinkByToken(expired) require.ErrorIs(t, err, ErrMagicLinkNotFound) - m, err := a.MagicLinkByHash(hashToken(valid)) + m, err := a.MagicLinkByToken(valid) require.Nil(t, err) require.Equal(t, "valid@example.com", m.Email) }) diff --git a/user/manager.go b/user/manager.go index e6df6910..4c62f940 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1556,6 +1556,37 @@ func (a *Manager) SetPrimaryEmail(userID, email string) error { }) } +// CreateMagicLink generates a fresh magic-link token of the given kind, stores it (hashed, +// replacing any existing link in the same scope), and returns the RAW token for use in the +// emailed link. Only the hash is persisted; the raw token is never stored. email is the +// address being verified for email_verify, and "" for password_reset. +func (a *Manager) CreateMagicLink(kind MagicLinkKind, userID, email string, ttl time.Duration) (string, error) { + raw := generateLinkToken() + now := time.Now() + m := &MagicLink{ + TokenHash: hashToken(raw), + Kind: kind, + UserID: userID, + Email: email, + Expires: now.Add(ttl).Unix(), + Created: now.Unix(), + } + if err := a.AddMagicLink(m); err != nil { + return "", err + } + return raw, nil +} + +// MagicLinkByToken looks up a magic link by its raw token (hashing it first). See MagicLinkByHash. +func (a *Manager) MagicLinkByToken(rawToken string) (*MagicLink, error) { + return a.MagicLinkByHash(hashToken(rawToken)) +} + +// DeleteMagicLinkByToken deletes a magic link identified by its raw token (single-use consume). +func (a *Manager) DeleteMagicLinkByToken(rawToken string) error { + return a.DeleteMagicLink(hashToken(rawToken)) +} + // AddMagicLink stores a pending magic link, replacing any existing link in the same scope: // for email_verify that is the (user_id, email) pair (one pending verification per address); // for password_reset that is the user_id (one active reset per account). The replace-delete and @@ -1606,12 +1637,21 @@ func (a *Manager) DeleteMagicLink(tokenHash string) error { return err } -// VerifyEmail consumes an email-verification magic link: after validating the token (kind + -// expiry), it deletes the link, adds the address to the user's verified emails, and -- if the -// user has no primary email yet and the address is not already primary on another account -- -// promotes the new address to primary. All mutations run in one transaction. A primary -// collision simply leaves the address verified but non-primary. Returns the consumed link. -func (a *Manager) VerifyEmail(tokenHash string) (*MagicLink, error) { +// DeleteEmailVerification removes any pending email verification for (userID, email). Used when +// an unverified (pending) address is cancelled/deleted from the account. +func (a *Manager) DeleteEmailVerification(userID, email string) error { + _, err := a.db.Exec(a.queries.deleteVerifyScope, userID, email) + return err +} + +// VerifyEmail consumes an email-verification magic link, identified by its raw token: after +// validating the token (kind + expiry), it deletes the link, adds the address to the user's +// verified emails, and -- if the user has no primary email yet and the address is not already +// primary on another account -- promotes the new address to primary. All mutations run in one +// transaction. A primary collision simply leaves the address verified but non-primary. Returns +// the consumed link. +func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { + tokenHash := hashToken(rawToken) m, err := a.MagicLinkByHash(tokenHash) if err != nil { return nil, err diff --git a/user/manager_test.go b/user/manager_test.go index 3845752e..7e05f5db 100644 --- a/user/manager_test.go +++ b/user/manager_test.go @@ -1847,16 +1847,9 @@ func TestMigrationFrom7(t *testing.T) { require.Equal(t, "", primary) // The new magic-link machinery works post-migration - raw := generateLinkToken() - require.Nil(t, a.AddMagicLink(&MagicLink{ - TokenHash: hashToken(raw), - Kind: MagicLinkKindEmailVerify, - UserID: "u_phil", - Email: "new@example.com", - Expires: time.Now().Add(24 * time.Hour).Unix(), - Created: time.Now().Unix(), - })) - m, err := a.VerifyEmail(hashToken(raw)) + raw, err := a.CreateMagicLink(MagicLinkKindEmailVerify, "u_phil", "new@example.com", 24*time.Hour) + require.Nil(t, err) + m, err := a.VerifyEmail(raw) require.Nil(t, err) require.Equal(t, "new@example.com", m.Email) diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 2e06cc64..2dff3100 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -3,8 +3,15 @@ "common_save": "Save", "common_add": "Add", "common_back": "Back", + "common_close": "Close", "common_copy_to_clipboard": "Copy to clipboard", "common_refresh": "Refresh", + "email_verify_progress_title": "Verifying your email...", + "email_verify_success_title": "Email verified", + "email_verify_success_description": "Your email address has been verified and added to your account.", + "email_verify_error_title": "Verification failed", + "email_verify_error_description": "This verification link is invalid or has expired. You can request a new one from your account settings.", + "email_verify_button_account": "Go to account", "version_update_available_title": "New version available", "version_update_available_description": "The ntfy server has been updated. Please refresh the page.", "signup_title": "Create a ntfy account", @@ -216,18 +223,24 @@ "account_basics_phone_numbers_dialog_channel_sms": "SMS", "account_basics_phone_numbers_dialog_channel_call": "Call", "account_basics_emails_title": "Email addresses", - "account_basics_emails_description": "For email notifications", - "account_basics_emails_no_emails_yet": "No verified emails yet", + "account_basics_emails_description": "For email notifications and password reset", + "account_basics_emails_no_emails_yet": "No emails yet", "account_basics_emails_copied_to_clipboard": "Email address copied to clipboard", + "account_basics_emails_primary_badge": "Primary", + "account_basics_emails_unverified": "unverified", + "account_basics_emails_set_primary": "Set as recovery email", + "account_basics_emails_delete": "Remove", + "account_basics_emails_cancel": "Cancel", + "account_basics_emails_resend": "Resend verification email", + "account_basics_emails_resent": "Verification email sent, check your inbox", + "account_basics_emails_primary_elsewhere": "This email is the recovery email on another account", + "account_basics_emails_no_recovery_warning": "No recovery email set. You will not be able to reset your password. Add and verify an email below, then set it as your recovery email.", "account_basics_emails_dialog_title": "Add email address", - "account_basics_emails_dialog_description": "To receive email notifications, you need to add and verify at least one email address. A verification code will be sent to your email.", + "account_basics_emails_dialog_description": "Enter an email address to add it to your account. We will send a verification link to confirm it is yours.", "account_basics_emails_dialog_email_label": "Email address", "account_basics_emails_dialog_email_placeholder": "e.g. user@example.com", - "account_basics_emails_dialog_verify_button": "Add email", - "account_basics_emails_dialog_code_label": "Verification code", - "account_basics_emails_dialog_code_placeholder": "e.g. 123456", - "account_basics_emails_dialog_code_invalid": "Verification code is invalid or expired", - "account_basics_emails_dialog_check_verification_button": "Confirm", + "account_basics_emails_dialog_verify_button": "Send verification link", + "account_basics_emails_dialog_check_inbox": "Check your inbox and click the verification link to confirm this email address. It will appear as unverified until you do.", "account_basics_cannot_edit_or_delete_provisioned_user": "A provisioned user cannot be edited or deleted", "account_usage_title": "Usage", "account_usage_of_limit": "of {{limit}}", diff --git a/web/src/app/AccountApi.js b/web/src/app/AccountApi.js index 4fadb8c5..e9d21d65 100644 --- a/web/src/app/AccountApi.js +++ b/web/src/app/AccountApi.js @@ -4,6 +4,8 @@ import { accountBillingSubscriptionUrl, accountEmailUrl, accountEmailVerifyUrl, + accountEmailPrimaryUrl, + accountEmailResendUrl, accountPasswordUrl, accountPhoneUrl, accountPhoneVerifyUrl, @@ -342,9 +344,11 @@ class AccountApi { }); } - async verifyEmail(email) { - const url = accountEmailVerifyUrl(config.base_url); - console.log(`[AccountApi] Sending email verification ${url}`); + // startEmailVerification begins adding an email: the server stores a pending verification and + // emails a magic link. The address is not verified until the link is clicked. + async startEmailVerification(email) { + const url = accountEmailUrl(config.base_url); + console.log(`[AccountApi] Starting email verification ${url}`); await fetchOrThrow(url, { method: "PUT", headers: withBearerAuth({}, session.token()), @@ -354,15 +358,41 @@ class AccountApi { }); } - async addEmail(email, code) { - const url = accountEmailUrl(config.base_url); - console.log(`[AccountApi] Adding email with verification code ${url}`); + // verifyEmailToken performs verification from the magic-link landing page. It is unauthenticated: + // the token identifies the account, so this works even when clicked from a logged-out browser. + async verifyEmailToken(token) { + const url = accountEmailVerifyUrl(config.base_url); + console.log(`[AccountApi] Verifying email token ${url}`); await fetchOrThrow(url, { - method: "PUT", + method: "POST", + body: JSON.stringify({ + token, + }), + }); + } + + // resendEmailVerification re-sends the magic link for a pending (unverified) address. + async resendEmailVerification(email) { + const url = accountEmailResendUrl(config.base_url); + console.log(`[AccountApi] Resending email verification ${url}`); + await fetchOrThrow(url, { + method: "POST", + headers: withBearerAuth({}, session.token()), + body: JSON.stringify({ + email, + }), + }); + } + + // setPrimaryEmail marks an already-verified address as the primary (recovery) email. + async setPrimaryEmail(email) { + const url = accountEmailPrimaryUrl(config.base_url); + console.log(`[AccountApi] Setting primary email ${url}`); + await fetchOrThrow(url, { + method: "POST", headers: withBearerAuth({}, session.token()), body: JSON.stringify({ email, - code, }), }); } diff --git a/web/src/app/errors.js b/web/src/app/errors.js index 4214ad84..5b749d14 100644 --- a/web/src/app/errors.js +++ b/web/src/app/errors.js @@ -51,7 +51,15 @@ export class EmailVerificationCodeInvalidError extends Error { static CODE = 40051; // errHTTPBadRequestEmailVerificationCodeInvalid constructor() { - super("Email verification code invalid or expired"); + super("Email verification link invalid or expired"); + } +} + +export class EmailPrimaryElsewhereError extends Error { + static CODE = 40908; // errHTTPConflictEmailPrimaryElsewhere + + constructor() { + super("Email address is the recovery email on another account"); } } @@ -73,6 +81,8 @@ export const throwAppError = async (response) => { throw new IncorrectPasswordError(); } else if (error.code === EmailVerificationCodeInvalidError.CODE) { throw new EmailVerificationCodeInvalidError(); + } else if (error.code === EmailPrimaryElsewhereError.CODE) { + throw new EmailPrimaryElsewhereError(); } else if (error?.error) { throw new Error(`Error ${error.code}: ${error.error}`); } diff --git a/web/src/app/utils.js b/web/src/app/utils.js index db38801b..9bad68bf 100644 --- a/web/src/app/utils.js +++ b/web/src/app/utils.js @@ -35,6 +35,8 @@ export const accountPhoneUrl = (baseUrl) => `${baseUrl}/v1/account/phone`; export const accountPhoneVerifyUrl = (baseUrl) => `${baseUrl}/v1/account/phone/verify`; export const accountEmailUrl = (baseUrl) => `${baseUrl}/v1/account/email`; export const accountEmailVerifyUrl = (baseUrl) => `${baseUrl}/v1/account/email/verify`; +export const accountEmailPrimaryUrl = (baseUrl) => `${baseUrl}/v1/account/email/primary`; +export const accountEmailResendUrl = (baseUrl) => `${baseUrl}/v1/account/email/resend`; export const validUrl = (url) => url.match(/^https?:\/\/.+/); diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index 42402d41..a45dce09 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -2,6 +2,7 @@ import * as React from "react"; import { useContext, useState } from "react"; import { Alert, + Box, CardActions, CardContent, Chip, @@ -38,6 +39,9 @@ import { import EditIcon from "@mui/icons-material/Edit"; import { Trans, useTranslation } from "react-i18next"; import DeleteOutlineIcon from "@mui/icons-material/DeleteOutline"; +import StarIcon from "@mui/icons-material/Star"; +import StarBorderIcon from "@mui/icons-material/StarBorder"; +import RefreshIcon from "@mui/icons-material/Refresh"; import InfoOutlinedIcon from "@mui/icons-material/InfoOutlined"; import CelebrationIcon from "@mui/icons-material/Celebration"; import CloseIcon from "@mui/icons-material/Close"; @@ -52,7 +56,7 @@ import UpgradeDialog from "./UpgradeDialog"; import { AccountContext } from "./App"; import DialogFooter from "./DialogFooter"; import { Paragraph } from "./styles"; -import { EmailVerificationCodeInvalidError, IncorrectPasswordError, UnauthorizedError } from "../app/errors"; +import { EmailPrimaryElsewhereError, IncorrectPasswordError, UnauthorizedError } from "../app/errors"; import { ProChip } from "./SubscriptionPopup"; import session from "../app/Session"; @@ -359,7 +363,7 @@ const Emails = () => { const { account } = useContext(AccountContext); const [dialogKey, setDialogKey] = useState(0); const [dialogOpen, setDialogOpen] = useState(false); - const [snackOpen, setSnackOpen] = useState(false); + const [snack, setSnack] = useState(""); // Non-empty shows a transient snackbar message const labelId = "prefVerifiedEmails"; const handleDialogOpen = () => { @@ -373,20 +377,34 @@ const Emails = () => { const handleCopy = (email) => { copyToClipboard(email); - setSnackOpen(true); + setSnack(t("account_basics_emails_copied_to_clipboard")); }; - const handleDelete = async (email) => { + // runEmailAction wraps an account API call with the shared error handling (redirect on + // unauthorized, surface a message otherwise). The account list refreshes via the sync event. + const runEmailAction = async (fn, errorMessage) => { try { - await accountApi.deleteEmail(email); + await fn(); } catch (e) { - console.log(`[Account] Error deleting email`, e); + console.log(`[Account] Email action failed`, e); if (e instanceof UnauthorizedError) { await session.resetAndRedirect(routes.login); + } else if (e instanceof EmailPrimaryElsewhereError) { + setSnack(t("account_basics_emails_primary_elsewhere")); + } else { + setSnack(errorMessage ?? e.message); } } }; + const handleDelete = (email) => runEmailAction(() => accountApi.deleteEmail(email)); + const handleSetPrimary = (email) => runEmailAction(() => accountApi.setPrimaryEmail(email)); + const handleResend = (email) => + runEmailAction(async () => { + await accountApi.resendEmailVerification(email); + setSnack(t("account_basics_emails_resent")); + }); + if (!config.enable_email_verify) { return null; } @@ -407,35 +425,73 @@ const Emails = () => { ); } + const verifiedEmails = account?.emails ?? []; + const pendingEmails = account?.pending_emails ?? []; + const primaryEmail = account?.primary_email ?? ""; + const showNoRecoveryWarning = config.enable_reset_password && primaryEmail === ""; + return (
- {account?.emails?.map((email) => ( - - {email} + {showNoRecoveryWarning && ( + + {t("account_basics_emails_no_recovery_warning")} + + )} + + {verifiedEmails.map((email) => { + const isPrimary = email === primaryEmail; + return ( + + {email} + {isPrimary && } + {!isPrimary && ( + + handleSetPrimary(email)}> + + + + )} + {isPrimary && } + + handleCopy(email)}> + + + + + handleDelete(email)}> + + + + + ); + })} + {pendingEmails.map((email) => ( + + + {email} ({t("account_basics_emails_unverified")}) + + + handleResend(email)}> + + - } - variant="outlined" - onClick={() => handleCopy(email)} - onDelete={() => handleDelete(email)} - /> - ))} - {!account?.emails && {t("account_basics_emails_no_emails_yet")}} - + + handleDelete(email)}> + + + + + ))} + {verifiedEmails.length === 0 && pendingEmails.length === 0 && {t("account_basics_emails_no_emails_yet")}} + +
- setSnackOpen(false)} - message={t("account_basics_emails_copied_to_clipboard")} - /> + setSnack("")} message={snack} />
); @@ -446,18 +502,19 @@ const AddEmailDialog = (props) => { const { t } = useTranslation(); const [error, setError] = useState(""); const [email, setEmail] = useState(""); - const [code, setCode] = useState(""); const [sending, setSending] = useState(false); - const [verificationCodeSent, setVerificationCodeSent] = useState(false); + const [sent, setSent] = useState(false); const fullScreen = useMediaQuery(theme.breakpoints.down("sm")); - const verifyEmail = async () => { + // handleSubmit starts verification: the server emails a magic link. The pending address shows + // up in the account list as "(unverified)" once the account refreshes. + const handleSubmit = async () => { try { setSending(true); - await accountApi.verifyEmail(email); - setVerificationCodeSent(true); + await accountApi.startEmailVerification(email); + setSent(true); } catch (e) { - console.log(`[Account] Error sending email verification`, e); + console.log(`[Account] Error starting email verification`, e); if (e instanceof UnauthorizedError) { await session.resetAndRedirect(routes.login); } else { @@ -468,81 +525,41 @@ const AddEmailDialog = (props) => { } }; - const checkVerifyEmail = async () => { - try { - setSending(true); - await accountApi.addEmail(email, code); - props.onClose(); - } catch (e) { - console.log(`[Account] Error confirming email verification`, e); - if (e instanceof UnauthorizedError) { - await session.resetAndRedirect(routes.login); - } else if (e instanceof EmailVerificationCodeInvalidError) { - setError(t("account_basics_emails_dialog_code_invalid")); - } else { - setError(e.message); - } - } finally { - setSending(false); - } - }; - - const handleDialogSubmit = async () => { - if (!verificationCodeSent) { - await verifyEmail(); - } else { - await checkVerifyEmail(); - } - }; - - const handleCancel = () => { - if (verificationCodeSent) { - setVerificationCodeSent(false); - setCode(""); - } else { - props.onClose(); - } - }; - return ( - + {t("account_basics_emails_dialog_title")} - {t("account_basics_emails_dialog_description")} - {!verificationCodeSent && ( - setEmail(ev.target.value)} - fullWidth - variant="standard" - /> - )} - {verificationCodeSent && ( - setCode(ev.target.value)} - fullWidth - inputProps={{ inputMode: "numeric", pattern: "[0-9]*" }} - variant="standard" - /> + {sent ? ( + {t("account_basics_emails_dialog_check_inbox")} + ) : ( + <> + {t("account_basics_emails_dialog_description")} + setEmail(ev.target.value)} + fullWidth + variant="standard" + /> + )} - - + {sent ? ( + + ) : ( + <> + + + + )} ); diff --git a/web/src/components/App.jsx b/web/src/components/App.jsx index 575304d4..ed1fff99 100644 --- a/web/src/components/App.jsx +++ b/web/src/components/App.jsx @@ -20,6 +20,7 @@ import Messaging from "./Messaging"; import Login from "./Login"; import Signup from "./Signup"; import Account from "./Account"; +import EmailVerify from "./EmailVerify"; import initI18n from "../app/i18n"; // Translations! import prefs from "../app/Prefs"; import RTLCacheProvider from "./RTLCacheProvider"; @@ -63,6 +64,7 @@ const App = () => { } /> } /> + } /> }> } /> } /> diff --git a/web/src/components/EmailVerify.jsx b/web/src/components/EmailVerify.jsx new file mode 100644 index 00000000..ce70a8d5 --- /dev/null +++ b/web/src/components/EmailVerify.jsx @@ -0,0 +1,74 @@ +import * as React from "react"; +import { useEffect, useRef, useState } from "react"; +import { Typography, Button, Box, CircularProgress } from "@mui/material"; +import CheckCircleOutlineIcon from "@mui/icons-material/CheckCircleOutline"; +import ErrorOutlineIcon from "@mui/icons-material/ErrorOutline"; +import { useParams, NavLink } from "react-router-dom"; +import { useTranslation } from "react-i18next"; +import accountApi from "../app/AccountApi"; +import AvatarBox from "./AvatarBox"; +import routes from "./routes"; + +// EmailVerify is the magic-link landing page for email verification. It performs the verification +// via a POST (the GET that loads this page has no side effects, so link prefetchers / scanners +// cannot consume the single-use token). The raw token is stripped from the URL on load to keep +// it out of browser history and Referer headers. +const EmailVerify = () => { + const { t } = useTranslation(); + const { token } = useParams(); + const [status, setStatus] = useState("verifying"); // "verifying" | "success" | "error" + const ran = useRef(false); + + useEffect(() => { + if (ran.current) { + return; // Guard against double-invoke (e.g. React StrictMode) consuming the token twice + } + ran.current = true; + // Strip the token from the URL immediately (keep it out of history / Referer) + window.history.replaceState(null, "", routes.account); + (async () => { + try { + await accountApi.verifyEmailToken(token); + setStatus("success"); + } catch (e) { + console.log(`[EmailVerify] Verification failed`, e); + setStatus("error"); + } + })(); + }, [token]); + + return ( + + {status === "verifying" && ( + <> + + {t("email_verify_progress_title")} + + )} + {status === "success" && ( + <> + + {t("email_verify_success_title")} + {t("email_verify_success_description")} + + + )} + {status === "error" && ( + <> + + {t("email_verify_error_title")} + {t("email_verify_error_description")} + + + + + )} + + ); +}; + +export default EmailVerify; diff --git a/web/src/components/routes.js b/web/src/components/routes.js index 17e0eac6..d9c371eb 100644 --- a/web/src/components/routes.js +++ b/web/src/components/routes.js @@ -7,6 +7,7 @@ const routes = { app: config.app_root, account: "/account", settings: "/settings", + emailVerify: "/account/email/verify/:token", subscription: "/:topic", subscriptionExternal: "/:baseUrl/:topic", forSubscription: (subscription) => { From 33ae31055cc7d8681ec6689660de5d5340697a18 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 14:23:32 -0400 Subject: [PATCH 04/34] Phase 3+4 --- cmd/user.go | 86 ++++++++++++++++++++ cmd/user_test.go | 43 ++++++++++ docs/releases.md | 17 ++++ server/errors.go | 1 + server/server.go | 40 ++++++---- server/server_account.go | 72 +++++++++++++++++ server/server_account_email_test.go | 83 +++++++++++++++++++ server/server_payments.go | 30 +++++++ server/server_payments_email_test.go | 114 +++++++++++++++++++++++++++ server/types.go | 13 +++ user/magic_link_test.go | 65 +++++++++++++++ user/manager.go | 31 ++++++++ web/public/static/langs/en.json | 15 ++++ web/src/app/AccountApi.js | 28 +++++++ web/src/app/utils.js | 2 + web/src/components/App.jsx | 2 + web/src/components/Login.jsx | 82 ++++++++++++++++++- web/src/components/PasswordReset.jsx | 105 ++++++++++++++++++++++++ web/src/components/routes.js | 1 + 19 files changed, 812 insertions(+), 18 deletions(-) create mode 100644 server/server_payments_email_test.go create mode 100644 web/src/components/PasswordReset.jsx diff --git a/cmd/user.go b/cmd/user.go index 2e5af5f4..84cba345 100644 --- a/cmd/user.go +++ b/cmd/user.go @@ -8,11 +8,13 @@ import ( "fmt" "os" "strings" + "time" "github.com/urfave/cli/v2" "github.com/urfave/cli/v2/altsrc" "heckel.io/ntfy/v2/db" "heckel.io/ntfy/v2/db/pg" + "heckel.io/ntfy/v2/mail" "heckel.io/ntfy/v2/server" "heckel.io/ntfy/v2/user" "heckel.io/ntfy/v2/util" @@ -32,6 +34,11 @@ var flagsUser = append( altsrc.NewStringFlag(&cli.StringFlag{Name: "auth-file", Aliases: []string{"auth_file", "H"}, EnvVars: []string{"NTFY_AUTH_FILE"}, Usage: "auth database file used for access control"}), altsrc.NewStringFlag(&cli.StringFlag{Name: "auth-default-access", Aliases: []string{"auth_default_access", "p"}, EnvVars: []string{"NTFY_AUTH_DEFAULT_ACCESS"}, Value: "read-write", Usage: "default permissions if no matching entries in the auth database are found"}), altsrc.NewStringFlag(&cli.StringFlag{Name: "database-url", Aliases: []string{"database_url"}, EnvVars: []string{"NTFY_DATABASE_URL"}, Usage: "PostgreSQL connection string for database-backed stores"}), + altsrc.NewStringFlag(&cli.StringFlag{Name: "base-url", Aliases: []string{"base_url", "B"}, EnvVars: []string{"NTFY_BASE_URL"}, Usage: "externally visible base URL for this host (e.g. https://ntfy.sh)"}), + altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-addr", Aliases: []string{"smtp_sender_addr"}, EnvVars: []string{"NTFY_SMTP_SENDER_ADDR"}, Usage: "SMTP server address (host:port) for outgoing emails"}), + altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-user", Aliases: []string{"smtp_sender_user"}, EnvVars: []string{"NTFY_SMTP_SENDER_USER"}, Usage: "SMTP user (if e-mail sending is enabled)"}), + altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-pass", Aliases: []string{"smtp_sender_pass"}, EnvVars: []string{"NTFY_SMTP_SENDER_PASS"}, Usage: "SMTP password (if e-mail sending is enabled)"}), + altsrc.NewStringFlag(&cli.StringFlag{Name: "smtp-sender-from", Aliases: []string{"smtp_sender_from"}, EnvVars: []string{"NTFY_SMTP_SENDER_FROM"}, Usage: "SMTP sender address (if e-mail sending is enabled)"}), ) var cmdUser = &cli.Command{ @@ -98,6 +105,32 @@ Example: You may set the NTFY_PASSWORD environment variable to pass the new password or NTFY_PASSWORD_HASH to pass directly the bcrypt hash. This is useful if you are updating users via scripts. +`, + }, + { + Name: "password-reset", + Aliases: []string{"reset"}, + Usage: "Generates a password reset link for a user", + UsageText: "ntfy user password-reset [--send-email] USERNAME", + Action: execUserPasswordReset, + Flags: []cli.Flag{ + &cli.BoolFlag{Name: "send-email", Aliases: []string{"e"}, Usage: "also email the reset link to the user's primary email"}, + }, + Description: `Generate a password reset link for the given user and print it to stdout. + +The user completes the reset by opening the link in a browser and choosing a new password; +the admin never learns or chooses the new password. The link is single-use and expires after +one hour. This is an admin override of the self-service reset flow -- unlike self-service, it +does not require the user to have a verified primary email (the token is bound to the user). + +With --send-email, the link is additionally emailed to the user's primary email address (this +requires SMTP to be configured and the user to have a verified primary email). + +Requires base-url to be configured so an absolute link can be generated. + +Example: + ntfy user password-reset phil # Print a reset link for user phil + ntfy user password-reset --send-email phil # Print and email the reset link `, }, { @@ -286,6 +319,59 @@ func execUserChangePass(c *cli.Context) error { return nil } +func execUserPasswordReset(c *cli.Context) error { + username := c.Args().Get(0) + sendEmail := c.Bool("send-email") + baseURL := strings.TrimSuffix(c.String("base-url"), "/") + if username == "" { + return errors.New("username expected, type 'ntfy user password-reset --help' for help") + } else if username == userEveryone || username == user.Everyone { + return errors.New("username not allowed") + } else if baseURL == "" { + return errors.New("base-url must be configured to generate a reset link") + } + manager, err := createUserManager(c) + if err != nil { + return err + } + u, err := manager.User(username) + if errors.Is(err, user.ErrUserNotFound) { + return fmt.Errorf("user %s does not exist", username) + } else if err != nil { + return err + } + // Resolve the primary email up front if we need to send -- fail before creating a token + var primaryEmail string + if sendEmail { + primaryEmail, err = manager.PrimaryEmail(u.ID) + if err != nil { + return err + } else if primaryEmail == "" { + return fmt.Errorf("user %s has no primary email; cannot send reset link (omit --send-email to just print it)", username) + } + } + // The reset token is bound to the user, not an email -- so this works even with no SMTP + token, err := manager.CreateMagicLink(user.MagicLinkKindPasswordReset, u.ID, "", time.Hour) + if err != nil { + return err + } + link := baseURL + "/account/password/reset/" + token + fmt.Fprintln(c.App.Writer, link) + if sendEmail { + sender := mail.NewSender(&mail.Config{ + SMTPAddr: c.String("smtp-sender-addr"), + SMTPUser: c.String("smtp-sender-user"), + SMTPPass: c.String("smtp-sender-pass"), + From: c.String("smtp-sender-from"), + }) + if err := sender.SendPasswordReset(primaryEmail, link); err != nil { + return fmt.Errorf("failed to send reset email to %s: %w", primaryEmail, err) + } + fmt.Fprintf(c.App.ErrWriter, "reset link emailed to %s\n", primaryEmail) + } + return nil +} + func execUserChangeRole(c *cli.Context) error { username := c.Args().Get(0) role := user.Role(c.Args().Get(1)) diff --git a/cmd/user_test.go b/cmd/user_test.go index a6250b72..4dbca550 100644 --- a/cmd/user_test.go +++ b/cmd/user_test.go @@ -122,6 +122,49 @@ func TestCLI_User_Delete(t *testing.T) { require.Contains(t, err.Error(), "user phil does not exist") } +func TestCLI_User_PasswordReset(t *testing.T) { + s, conf, port := newTestServerWithAuth(t) + defer test.StopServer(t, s, port) + + app, stdin, stdout, _ := newTestApp() + stdin.WriteString("mypass\nmypass") + require.Nil(t, runUserCommand(app, conf, "add", "phil")) + + // Prints a working-looking reset link when base-url is set + app, _, stdout, _ = newTestApp() + require.Nil(t, runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "password-reset", "phil")) + require.Contains(t, stdout.String(), "https://ntfy.example.com/account/password/reset/") +} + +func TestCLI_User_PasswordReset_NoBaseURL(t *testing.T) { + s, conf, port := newTestServerWithAuth(t) + defer test.StopServer(t, s, port) + + app, stdin, _, _ := newTestApp() + stdin.WriteString("mypass\nmypass") + require.Nil(t, runUserCommand(app, conf, "add", "phil")) + + app, _, _, _ = newTestApp() + err := runUserCommand(app, conf, "password-reset", "phil") + require.Error(t, err) + require.Contains(t, err.Error(), "base-url") +} + +func TestCLI_User_PasswordReset_SendEmailNoPrimary(t *testing.T) { + s, conf, port := newTestServerWithAuth(t) + defer test.StopServer(t, s, port) + + app, stdin, _, _ := newTestApp() + stdin.WriteString("mypass\nmypass") + require.Nil(t, runUserCommand(app, conf, "add", "phil")) + + // --send-email requires a primary email; phil has none + app, _, _, _ = newTestApp() + err := runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "password-reset", "--send-email", "phil") + require.Error(t, err) + require.Contains(t, err.Error(), "no primary email") +} + func newTestServerWithAuth(t *testing.T) (s *server.Server, conf *server.Config, port int) { configFile := filepath.Join(t.TempDir(), "server-dummy.yml") require.Nil(t, os.WriteFile(configFile, []byte(""), 0600)) // Dummy config file to avoid lookup of real server.yml diff --git a/docs/releases.md b/docs/releases.md index 5af903d7..d2de3d07 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -1948,6 +1948,23 @@ and the [ntfy Android app](https://github.com/binwiederhier/ntfy-android/release ## Not released yet +### ntfy server v2.25.0 (UNRELEASED) + +This release adds **password reset** via email, and reworks email verification to use durable, +link-based magic links (replacing the old in-memory 6-digit codes). Email stays optional at +signup; a user can reset their password only once they have a verified "primary" (recovery) +email. All of this rides on the existing SMTP configuration -- no new config flag. + +**Features:** + +* Add password reset via emailed magic link, with a "Forgot password?" link on the login page and a `ntfy user password-reset` CLI command for admins +* Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" (recovery) email with verified/unverified state in the account UI +* Auto-send a verification link to the billing email after a Stripe checkout, so paying users can set up password recovery + +**Bug fixes + maintenance:** + +* Generate access tokens, IDs, and magic-link tokens with a cryptographically secure RNG (`crypto/rand`) instead of a clock-seeded PRNG + ### ntfy Android v1.25.x (UNRELEASED) This release makes the "connection lost" alert configurable and turns it off by default. Folks did not like it and many reached out diff --git a/server/errors.go b/server/errors.go index 5ac6ce38..51bfbe21 100644 --- a/server/errors.go +++ b/server/errors.go @@ -146,6 +146,7 @@ var ( errHTTPBadRequestEmailVerificationCodeInvalid = &errHTTP{40051, http.StatusBadRequest, "invalid request: email verification link invalid or expired", "", nil} errHTTPBadRequestEmailAddressNotVerified = &errHTTP{40052, http.StatusBadRequest, "invalid request: email address not verified", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} errHTTPBadRequestAnonymousEmailNotAllowed = &errHTTP{40053, http.StatusBadRequest, "invalid request: anonymous email sending is not allowed", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} + errHTTPBadRequestResetLinkInvalid = &errHTTP{40054, http.StatusBadRequest, "invalid request: password reset link invalid or expired", "", nil} errHTTPNotFound = &errHTTP{40401, http.StatusNotFound, "page not found", "", nil} errHTTPUnauthorized = &errHTTP{40101, http.StatusUnauthorized, "unauthorized", "https://ntfy.sh/docs/publish/#authentication", nil} errHTTPForbidden = &errHTTP{40301, http.StatusForbidden, "forbidden", "https://ntfy.sh/docs/publish/#authentication", nil} diff --git a/server/server.go b/server/server.go index 95d2ecf7..3184478a 100644 --- a/server/server.go +++ b/server/server.go @@ -80,19 +80,20 @@ type handleFunc func(http.ResponseWriter, *http.Request, *visitor) error var ( // If changed, don't forget to update Android App and auth_sqlite.go - topicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No /! - topicPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}$`) // Regex must match JS & Android app! - externalTopicPathRegex = regexp.MustCompile(`^/[^/]+\.[^/]+/[-_A-Za-z0-9]{1,64}$`) // Extended topic path, for web-app, e.g. /example.com/mytopic - webAppEmailVerifyRegex = regexp.MustCompile(`^/account/email/verify/[-_A-Za-z0-9]+$`) // Magic-link landing (served by the web app) - jsonPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/json$`) - ssePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/sse$`) - rawPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/raw$`) - wsPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/ws$`) - authPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/auth$`) - publishPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/(publish|send|trigger)$`) - updatePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}$`) - clearPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}/(read|clear)$`) - sequenceIDRegex = topicRegex + topicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No /! + topicPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}$`) // Regex must match JS & Android app! + externalTopicPathRegex = regexp.MustCompile(`^/[^/]+\.[^/]+/[-_A-Za-z0-9]{1,64}$`) // Extended topic path, for web-app, e.g. /example.com/mytopic + webAppEmailVerifyRegex = regexp.MustCompile(`^/account/email/verify/[-_A-Za-z0-9]+$`) // Magic-link landing (served by the web app) + webAppPasswordResetRegex = regexp.MustCompile(`^/account/password/reset/[-_A-Za-z0-9]+$`) // Password-reset landing (served by the web app) + jsonPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/json$`) + ssePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/sse$`) + rawPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/raw$`) + wsPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/ws$`) + authPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/auth$`) + publishPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/(publish|send|trigger)$`) + updatePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}$`) + clearPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}/(read|clear)$`) + sequenceIDRegex = topicRegex webConfigPath = "/config.js" webManifestPath = "/manifest.webmanifest" @@ -119,7 +120,10 @@ var ( apiAccountEmailVerifyPath = "/v1/account/email/verify" apiAccountEmailPrimaryPath = "/v1/account/email/primary" apiAccountEmailResendPath = "/v1/account/email/resend" - webAppEmailVerifyPathPrefix = "/account/email/verify/" // Browser landing route; raw token appended + apiAccountPasswordResetRequestPath = "/v1/account/password/reset/request" + apiAccountPasswordResetPath = "/v1/account/password/reset" + webAppEmailVerifyPathPrefix = "/account/email/verify/" // Browser landing route; raw token appended + webAppPasswordResetPathPrefix = "/account/password/reset/" // Browser landing route; raw token appended apiAccountBillingPortalPath = "/v1/account/billing/portal" apiAccountBillingWebhookPath = "/v1/account/billing/webhook" apiAccountBillingSubscriptionPath = "/v1/account/billing/subscription" @@ -626,6 +630,10 @@ func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visit return s.ensureUser(s.withAccountSync(s.handleAccountEmailSetPrimary))(w, r, v) } else if r.Method == http.MethodPost && r.URL.Path == apiAccountEmailResendPath { return s.ensureUser(s.ensureEmailsEnabled(s.handleAccountEmailResend))(w, r, v) + } else if r.Method == http.MethodPost && r.URL.Path == apiAccountPasswordResetRequestPath { + return s.ensureEmailsEnabled(s.limitRequests(s.handleAccountPasswordResetRequest))(w, r, v) // Unauthenticated + } else if r.Method == http.MethodPost && r.URL.Path == apiAccountPasswordResetPath { + return s.ensureEmailsEnabled(s.limitRequests(s.handleAccountPasswordReset))(w, r, v) // Unauthenticated } else if r.Method == http.MethodPost && apiWebPushPath == r.URL.Path { return s.ensureWebPushEnabled(s.limitRequests(s.handleWebPushUpdate))(w, r, v) } else if r.Method == http.MethodDelete && apiWebPushPath == r.URL.Path { @@ -668,8 +676,8 @@ func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visit return s.limitRequests(s.authorizeTopicRead(s.handleSubscribeWS))(w, r, v) } else if r.Method == http.MethodGet && authPathRegex.MatchString(r.URL.Path) { return s.limitRequests(s.authorizeTopicRead(s.handleTopicAuth))(w, r, v) - } else if r.Method == http.MethodGet && webAppEmailVerifyRegex.MatchString(r.URL.Path) { - return s.ensureWebEnabled(s.handleWebAppIndex)(w, r, v) // Magic-link landing page (client-side route) + } else if r.Method == http.MethodGet && (webAppEmailVerifyRegex.MatchString(r.URL.Path) || webAppPasswordResetRegex.MatchString(r.URL.Path)) { + return s.ensureWebEnabled(s.handleWebAppIndex)(w, r, v) // Magic-link landing pages (client-side routes) } else if r.Method == http.MethodGet && (topicPathRegex.MatchString(r.URL.Path) || externalTopicPathRegex.MatchString(r.URL.Path)) { return s.ensureWebEnabled(s.handleTopic)(w, r, v) } diff --git a/server/server_account.go b/server/server_account.go index fd3a5eba..f006f1ac 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -18,6 +18,7 @@ const ( syncTopicAccountSyncEvent = "sync" tokenExpiryDuration = 72 * time.Hour // Extend tokens by this much emailVerificationTokenExpiry = 24 * time.Hour // Magic-link lifetime for email verification + passwordResetTokenExpiry = time.Hour // Magic-link lifetime for password reset (higher-privilege -> shorter) ) func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v *visitor) error { @@ -771,6 +772,77 @@ func (s *Server) enqueueEmailVerification(userID, email string) error { return s.mailSender.SendEmailVerification(email, link) } +// handleAccountPasswordResetRequest starts a password reset (POST /v1/account/password/reset/request, +// unauthenticated). It resolves the identifier (username or primary email) to at most one account +// and emails a reset link to that account's primary email. The response is always a uniform 200, +// regardless of whether anything matched, so it cannot be used to probe for accounts. +func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *http.Request, v *visitor) error { + req, err := readJSONWithLimit[apiAccountPasswordResetRequest](r.Body, jsonBodyBytesLimit, false) + if err != nil { + return err + } + // Rate limit via the shared per-visitor account-creation bucket (no new limiter/config) + if !v.AccountCreationAllowed() { + return errHTTPTooManyRequestsLimitAccountCreation + } + v.AccountCreated() // Consume a token on every request (including no-match), to throttle probing + identifier := strings.TrimSpace(req.Identifier) + if identifier != "" && s.config.BaseURL != "" { + if userID, email, ok := s.resolveResetTarget(identifier); ok { + token, err := s.userManager.CreateMagicLink(user.MagicLinkKindPasswordReset, userID, "", passwordResetTokenExpiry) + if err != nil { + logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to create password reset token") + } else { + link := s.config.BaseURL + webAppPasswordResetPathPrefix + token + logvr(v, r).Tag(tagAccount).Field("user_id", userID).Info("Sending password reset link") + if err := s.mailSender.SendPasswordReset(email, link); err != nil { + logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to send password reset email") + } + } + } else { + logvr(v, r).Tag(tagAccount).Debug("Password reset requested for unknown identifier (uniform response)") + } + } + return s.writeJSON(w, newSuccessResponse()) +} + +// resolveResetTarget resolves a reset identifier to a single account and its primary email. +// The identifier is tried first as a username, then as a primary email address. It returns +// ok=false if no account with a primary email matches (reset requires a verified primary email). +func (s *Server) resolveResetTarget(identifier string) (userID string, email string, ok bool) { + if u, err := s.userManager.User(identifier); err == nil && u != nil { + if primary, perr := s.userManager.PrimaryEmail(u.ID); perr == nil && primary != "" { + return u.ID, primary, true + } + } + if uid, err := s.userManager.UserIDByPrimaryEmail(identifier); err == nil { + return uid, identifier, true + } + return "", "", false +} + +// handleAccountPasswordReset performs the reset (POST /v1/account/password/reset, unauthenticated): +// it validates the token and sets the new password. Existing access tokens stay valid. +func (s *Server) handleAccountPasswordReset(w http.ResponseWriter, r *http.Request, v *visitor) error { + req, err := readJSONWithLimit[apiAccountPasswordResetConfirmRequest](r.Body, jsonBodyBytesLimit, false) + if err != nil { + return err + } + if req.Token == "" { + return errHTTPBadRequestResetLinkInvalid + } else if req.Password == "" { + return errHTTPBadRequest + } + err = s.userManager.ResetPassword(req.Token, req.Password) + if errors.Is(err, user.ErrMagicLinkNotFound) { + return errHTTPBadRequestResetLinkInvalid + } else if err != nil { + return err + } + logvr(v, r).Tag(tagAccount).Info("Password reset performed") + return s.writeJSON(w, newSuccessResponse()) +} + // convertEmailAddress checks the email address against the user's verified email list. // If smtp-sender-verify is false (default), the email is passed through as-is for // backwards compatibility. If true, the user must be authenticated and the email must be diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index b594684d..e8bbc920 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -173,6 +173,89 @@ func TestAccount_Email_SetPrimaryCollision(t *testing.T) { }) } +// verifyEmailFor runs the full add->click flow so the user ends up with a verified primary email. +func verifyEmailFor(t *testing.T, s *Server, mailer *captureMailer, auth map[string]string, email string) { + require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", fmt.Sprintf(`{"email":"%s"}`, email), auth).Code) + token := tokenFromLink(t, mailer.verifyLinks[email], "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, token), nil).Code) +} + +// canLogin returns true if username/password authenticates (via the token-create endpoint). +func canLogin(t *testing.T, s *Server, username, password string) bool { + rr := request(t, s, "POST", "/v1/account/token", "", map[string]string{"Authorization": util.BasicAuth(username, password)}) + return rr.Code == 200 +} + +func TestAccount_PasswordReset_ByUsername(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + verifyEmailFor(t, s, mailer, auth, "ben@example.com") + + // Request reset by username + rr := request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"ben"}`, nil) + require.Equal(t, 200, rr.Code) + token := tokenFromLink(t, mailer.resetLinks["ben@example.com"], "https://ntfy.example.com/account/password/reset/") + + // Confirm with a new password + rr = request(t, s, "POST", "/v1/account/password/reset", fmt.Sprintf(`{"token":"%s","password":"brandnew"}`, token), nil) + require.Equal(t, 200, rr.Code) + + require.True(t, canLogin(t, s, "ben", "brandnew")) + require.False(t, canLogin(t, s, "ben", "ben")) + }) +} + +func TestAccount_PasswordReset_ByEmail(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + verifyEmailFor(t, s, mailer, auth, "ben@example.com") + + rr := request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"ben@example.com"}`, nil) + require.Equal(t, 200, rr.Code) + token := tokenFromLink(t, mailer.resetLinks["ben@example.com"], "https://ntfy.example.com/account/password/reset/") + rr = request(t, s, "POST", "/v1/account/password/reset", fmt.Sprintf(`{"token":"%s","password":"brandnew"}`, token), nil) + require.Equal(t, 200, rr.Code) + require.True(t, canLogin(t, s, "ben", "brandnew")) + }) +} + +func TestAccount_PasswordReset_UnknownIdentifierUniform(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, _ := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + // Unknown identifier still returns a uniform 200, and no email is sent + rr := request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"ghost"}`, nil) + require.Equal(t, 200, rr.Code) + require.Empty(t, mailer.resetLinks) + }) +} + +func TestAccount_PasswordReset_NoPrimaryEmailNoSend(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, _ := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + // ben exists but has no verified primary email -> uniform 200, nothing sent + rr := request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"ben"}`, nil) + require.Equal(t, 200, rr.Code) + require.Empty(t, mailer.resetLinks) + }) +} + +func TestAccount_PasswordReset_InvalidToken(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, _, _ := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + rr := request(t, s, "POST", "/v1/account/password/reset", `{"token":"nope","password":"brandnew"}`, nil) + require.Equal(t, 400, rr.Code) + require.Equal(t, 40054, toHTTPError(t, rr.Body.String()).Code) + }) +} + func TestAccount_Email_AddDuplicateVerified(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s, mailer, auth := newEmailTestServer(t, databaseURL) diff --git a/server/server_payments.go b/server/server_payments.go index 0226df4f..76d0b5ac 100644 --- a/server/server_payments.go +++ b/server/server_payments.go @@ -237,10 +237,40 @@ func (s *Server) handleAccountBillingSubscriptionCreateSuccess(w http.ResponseWr if err := s.updateSubscriptionAndTier(r, v, u, tier, sess.Customer.ID, sub.ID, string(sub.Status), string(interval), sub.CurrentPeriodEnd, sub.CancelAt); err != nil { return err } + // Offer email recovery: auto-send a verification link to the billing email (best-effort). + if sess.CustomerDetails != nil { + s.maybeEnqueueBillingEmailVerification(r, v, u.ID, sess.CustomerDetails.Email) + } http.Redirect(w, r, s.config.BaseURL+accountPath, http.StatusSeeOther) return nil } +// maybeEnqueueBillingEmailVerification sends an email-verification link to a paying user's +// billing email, so they can use it for password recovery -- but only if they have no verified +// email yet and the billing email is not already the recovery email on another account. On a +// collision (or any other skip), the generic "no recovery email set" warning on the account page +// nudges the user to add one. This is best-effort: failures are logged, never surfaced. +func (s *Server) maybeEnqueueBillingEmailVerification(r *http.Request, v *visitor, userID, billingEmail string) { + if s.mailSender == nil || s.config.BaseURL == "" || billingEmail == "" || !emailAddressRegex.MatchString(billingEmail) { + return + } + emails, err := s.userManager.Emails(userID) + if err != nil { + logvr(v, r).Tag(tagStripe).Err(err).Warn("Failed to load emails for billing verification") + return + } else if len(emails) > 0 { + return // User already has a verified email -- don't nag + } + if _, err := s.userManager.UserIDByPrimaryEmail(billingEmail); err == nil { + logvr(v, r).Tag(tagStripe).Debug("Billing email is primary on another account, skipping auto-verification") + return // Collision: skip + let the generic no-recovery-email warning nudge instead + } + logvr(v, r).Tag(tagStripe).Field("email", billingEmail).Info("Sending verification link to billing email") + if err := s.enqueueEmailVerification(userID, billingEmail); err != nil { + logvr(v, r).Tag(tagStripe).Err(err).Warn("Failed to enqueue billing email verification") + } +} + // handleAccountBillingSubscriptionUpdate updates an existing Stripe subscription to a new price, and updates // a user's tier accordingly. This endpoint only works if there is an existing subscription. func (s *Server) handleAccountBillingSubscriptionUpdate(w http.ResponseWriter, r *http.Request, v *visitor) error { diff --git a/server/server_payments_email_test.go b/server/server_payments_email_test.go new file mode 100644 index 00000000..24fa7bb2 --- /dev/null +++ b/server/server_payments_email_test.go @@ -0,0 +1,114 @@ +//go:build !nopayments + +package server + +import ( + "fmt" + "testing" + "time" + + "github.com/stretchr/testify/mock" + "github.com/stretchr/testify/require" + "github.com/stripe/stripe-go/v74" + "heckel.io/ntfy/v2/user" +) + +// stripeCheckoutMock wires up a testStripeAPI for a successful checkout of user u, with the given +// billing email on the session's CustomerDetails. +func stripeCheckoutMock(u *user.User, billingEmail string) *testStripeAPI { + m := &testStripeAPI{} + m.On("GetSession", "SOMETOKEN").Return(&stripe.CheckoutSession{ + ClientReferenceID: u.ID, + Customer: &stripe.Customer{ID: "acct_5555"}, + Subscription: &stripe.Subscription{ID: "sub_1234"}, + CustomerDetails: &stripe.CheckoutSessionCustomerDetails{Email: billingEmail}, + }, nil) + m.On("GetSubscription", "sub_1234").Return(&stripe.Subscription{ + ID: "sub_1234", + Status: stripe.SubscriptionStatusActive, + CurrentPeriodEnd: 123456789, + Items: &stripe.SubscriptionItemList{ + Data: []*stripe.SubscriptionItem{ + {Price: &stripe.Price{ID: "price_1234", Recurring: &stripe.PriceRecurring{Interval: stripe.PriceRecurringIntervalMonth}}}, + }, + }, + }, nil) + m.On("UpdateCustomer", "acct_5555", mock.Anything).Return(&stripe.Customer{}, nil) + return m +} + +func newCheckoutEmailTestServer(t *testing.T, databaseURL string) (*Server, *captureMailer, *user.User) { + c := newTestConfigWithAuthFile(t, databaseURL) + c.StripeSecretKey = "secret key" + c.BaseURL = "https://ntfy.example.com" + c.SMTPSenderAddr = "localhost:25" + c.SMTPSenderFrom = "noreply@example.com" + s := newTestServer(t, c) + mailer := newCaptureMailer() + s.mailSender = mailer + require.Nil(t, s.userManager.AddTier(&user.Tier{ + ID: "ti_123", Code: "starter", StripeMonthlyPriceID: "price_1234", MessageLimit: 100, MessageExpiryDuration: time.Hour, + })) + require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) + u, err := s.userManager.User("phil") + require.Nil(t, err) + return s, mailer, u +} + +func TestPayments_Checkout_SendsBillingEmailVerification(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, u := newCheckoutEmailTestServer(t, databaseURL) + defer s.closeDatabases() + s.stripe = stripeCheckoutMock(u, "billing@example.com") + + rr := request(t, s, "GET", "/v1/account/billing/subscription/success/SOMETOKEN", "", nil) + require.Equal(t, 303, rr.Code) + + // A verification link was auto-sent to the billing email; clicking it verifies + sets primary + link := mailer.verifyLinks["billing@example.com"] + require.NotEmpty(t, link) + token := tokenFromLink(t, link, "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, token), nil).Code) + + emails, err := s.userManager.Emails(u.ID) + require.Nil(t, err) + require.Equal(t, []string{"billing@example.com"}, emails) + primary, err := s.userManager.PrimaryEmail(u.ID) + require.Nil(t, err) + require.Equal(t, "billing@example.com", primary) + }) +} + +func TestPayments_Checkout_SkipsBillingEmailWhenAlreadyVerified(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, u := newCheckoutEmailTestServer(t, databaseURL) + defer s.closeDatabases() + s.stripe = stripeCheckoutMock(u, "billing@example.com") + + // User already has a verified email -> no auto-send on checkout + require.Nil(t, s.userManager.AddEmail(u.ID, "existing@example.com")) + + rr := request(t, s, "GET", "/v1/account/billing/subscription/success/SOMETOKEN", "", nil) + require.Equal(t, 303, rr.Code) + require.Empty(t, mailer.verifyLinks) + }) +} + +func TestPayments_Checkout_SkipsBillingEmailWhenPrimaryElsewhere(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, u := newCheckoutEmailTestServer(t, databaseURL) + defer s.closeDatabases() + s.stripe = stripeCheckoutMock(u, "billing@example.com") + + // The billing email is already the recovery email on another account -> skip + require.Nil(t, s.userManager.AddUser("alice", "alice", user.RoleUser, false)) + alice, err := s.userManager.User("alice") + require.Nil(t, err) + require.Nil(t, s.userManager.AddEmail(alice.ID, "billing@example.com")) + require.Nil(t, s.userManager.SetPrimaryEmail(alice.ID, "billing@example.com")) + + rr := request(t, s, "GET", "/v1/account/billing/subscription/success/SOMETOKEN", "", nil) + require.Equal(t, 303, rr.Code) + require.Empty(t, mailer.verifyLinks) + }) +} diff --git a/server/types.go b/server/types.go index b51e9f00..963cb127 100644 --- a/server/types.go +++ b/server/types.go @@ -238,6 +238,19 @@ type apiAccountEmailVerifyRequest struct { Token string `json:"token"` } +// apiAccountPasswordResetRequest is the body of the (unauthenticated) reset-request endpoint. +// The identifier is a username or a primary email address. +type apiAccountPasswordResetRequest struct { + Identifier string `json:"identifier"` +} + +// apiAccountPasswordResetConfirmRequest is the body of the (unauthenticated) reset-confirm +// endpoint, submitted from the set-new-password landing page. +type apiAccountPasswordResetConfirmRequest struct { + Token string `json:"token"` + Password string `json:"password"` +} + type apiAccountTier struct { Code string `json:"code"` Name string `json:"name"` diff --git a/user/magic_link_test.go b/user/magic_link_test.go index fd96bb1a..33053c05 100644 --- a/user/magic_link_test.go +++ b/user/magic_link_test.go @@ -239,6 +239,71 @@ func TestUser_MagicLink_Reaper(t *testing.T) { }) } +func TestUser_MagicLink_ResetPassword(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + + // Old password works before reset + _, err = a.Authenticate("phil", "oldpass") + require.Nil(t, err) + + require.Nil(t, a.ResetPassword(raw, "newpass")) + + // New password works, old does not + _, err = a.Authenticate("phil", "newpass") + require.Nil(t, err) + _, err = a.Authenticate("phil", "oldpass") + require.ErrorIs(t, err, ErrUnauthenticated) + + // Token is single-use + require.ErrorIs(t, a.ResetPassword(raw, "againpass"), ErrMagicLinkNotFound) + }) +} + +func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + // An email-verification token must not be usable for password reset... + verifyToken := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Hour) + require.ErrorIs(t, a.ResetPassword(verifyToken, "newpass"), ErrMagicLinkNotFound) + + // ...and a reset token must not be usable for email verification + resetToken, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + _, err = a.VerifyEmail(resetToken) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + // Old password unchanged + _, err = a.Authenticate("phil", "oldpass") + require.Nil(t, err) + }) +} + +func TestUser_MagicLink_ResetPassword_Expired(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", -time.Minute) + require.Nil(t, err) + require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrMagicLinkNotFound) + _, err = a.Authenticate("phil", "oldpass") + require.Nil(t, err) + }) +} + func TestUser_MagicLink_UserIDByPrimaryEmail_NotFound(t *testing.T) { forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { a := newTestManager(t, newManager, PermissionDenyAll) diff --git a/user/manager.go b/user/manager.go index 4c62f940..4a7866c1 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1696,6 +1696,37 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { return m, nil } +// ResetPassword consumes a password-reset magic link, identified by its raw token: after +// validating the token (kind + expiry), it sets the user's password and deletes the link in one +// transaction. Existing access tokens are intentionally left valid (only the password changes). +// Returns ErrMagicLinkNotFound if the token is invalid, expired, or not a reset token. +func (a *Manager) ResetPassword(rawToken, password string) error { + m, err := a.MagicLinkByHash(hashToken(rawToken)) + if err != nil { + return err + } + if m.Kind != MagicLinkKindPasswordReset || time.Now().Unix() > m.Expires { + return ErrMagicLinkNotFound + } + u, err := a.UserByID(m.UserID) + if err != nil { + return err + } + hash, err := a.maybeHashPassword(password, false) + if err != nil { + return err + } + return db.ExecTx(a.db, func(tx *sql.Tx) error { + if err := a.changePasswordHashTx(tx, u.Name, hash); err != nil { + return err + } + if _, err := tx.Exec(a.queries.deleteMagicLinkByHash, m.TokenHash); err != nil { + return err + } + return nil + }) +} + // deleteExpiredMagicLinks removes magic links whose expiry has passed. Expiry is also enforced // on read, so this is purely housekeeping to bound table growth; it runs from the reaper loop. func (a *Manager) deleteExpiredMagicLinks() error { diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 2dff3100..ecae6954 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -27,6 +27,21 @@ "login_title": "Sign in to your ntfy account", "login_form_button_submit": "Sign in", "login_link_signup": "Sign up", + "login_link_forgot_password": "Forgot password?", + "login_reset_dialog_title": "Reset password", + "login_reset_dialog_description": "Enter your username or email address. If an account exists, we'll email a link to reset your password.", + "login_reset_dialog_identifier_label": "Username or email", + "login_reset_dialog_button_submit": "Send reset link", + "login_reset_dialog_sent": "If an account exists, we've emailed a link to reset your password. Please check your inbox.", + "reset_password_title": "Set a new password", + "reset_password_form_password": "New password", + "reset_password_form_confirm": "Confirm new password", + "reset_password_form_button_submit": "Set password", + "reset_password_form_passwords_no_match": "Passwords do not match", + "reset_password_form_error_invalid": "This reset link is invalid or has expired. Please request a new one.", + "reset_password_success_title": "Password changed", + "reset_password_success_description": "Your password has been changed. You can now sign in with your new password.", + "reset_password_button_login": "Sign in", "login_disabled": "Login is disabled", "action_bar_show_menu": "Show menu", "action_bar_logo_alt": "ntfy logo", diff --git a/web/src/app/AccountApi.js b/web/src/app/AccountApi.js index e9d21d65..823eba53 100644 --- a/web/src/app/AccountApi.js +++ b/web/src/app/AccountApi.js @@ -6,6 +6,8 @@ import { accountEmailVerifyUrl, accountEmailPrimaryUrl, accountEmailResendUrl, + accountPasswordResetRequestUrl, + accountPasswordResetUrl, accountPasswordUrl, accountPhoneUrl, accountPhoneVerifyUrl, @@ -397,6 +399,32 @@ class AccountApi { }); } + // requestPasswordReset starts the (unauthenticated) reset flow. The identifier is a username or + // primary email. The server always responds uniformly, regardless of whether an account matched. + async requestPasswordReset(identifier) { + const url = accountPasswordResetRequestUrl(config.base_url); + console.log(`[AccountApi] Requesting password reset ${url}`); + await fetchOrThrow(url, { + method: "POST", + body: JSON.stringify({ + identifier, + }), + }); + } + + // resetPassword performs the (unauthenticated) reset from the set-new-password landing page. + async resetPassword(token, password) { + const url = accountPasswordResetUrl(config.base_url); + console.log(`[AccountApi] Resetting password ${url}`); + await fetchOrThrow(url, { + method: "POST", + body: JSON.stringify({ + token, + password, + }), + }); + } + async deleteEmail(email) { const url = accountEmailUrl(config.base_url); console.log(`[AccountApi] Deleting email ${url}`); diff --git a/web/src/app/utils.js b/web/src/app/utils.js index 9bad68bf..13f50ffd 100644 --- a/web/src/app/utils.js +++ b/web/src/app/utils.js @@ -37,6 +37,8 @@ export const accountEmailUrl = (baseUrl) => `${baseUrl}/v1/account/email`; export const accountEmailVerifyUrl = (baseUrl) => `${baseUrl}/v1/account/email/verify`; export const accountEmailPrimaryUrl = (baseUrl) => `${baseUrl}/v1/account/email/primary`; export const accountEmailResendUrl = (baseUrl) => `${baseUrl}/v1/account/email/resend`; +export const accountPasswordResetRequestUrl = (baseUrl) => `${baseUrl}/v1/account/password/reset/request`; +export const accountPasswordResetUrl = (baseUrl) => `${baseUrl}/v1/account/password/reset`; export const validUrl = (url) => url.match(/^https?:\/\/.+/); diff --git a/web/src/components/App.jsx b/web/src/components/App.jsx index ed1fff99..d9eb2d0b 100644 --- a/web/src/components/App.jsx +++ b/web/src/components/App.jsx @@ -21,6 +21,7 @@ import Login from "./Login"; import Signup from "./Signup"; import Account from "./Account"; import EmailVerify from "./EmailVerify"; +import PasswordReset from "./PasswordReset"; import initI18n from "../app/i18n"; // Translations! import prefs from "../app/Prefs"; import RTLCacheProvider from "./RTLCacheProvider"; @@ -65,6 +66,7 @@ const App = () => { } /> } /> } /> + } /> }> } /> } /> diff --git a/web/src/components/Login.jsx b/web/src/components/Login.jsx index 5c1af249..a95f9a14 100644 --- a/web/src/components/Login.jsx +++ b/web/src/components/Login.jsx @@ -1,6 +1,18 @@ import * as React from "react"; import { useState } from "react"; -import { Typography, TextField, Button, Box, IconButton, InputAdornment } from "@mui/material"; +import { + Typography, + TextField, + Button, + Box, + IconButton, + InputAdornment, + Dialog, + DialogTitle, + DialogContent, + DialogContentText, + DialogActions, +} from "@mui/material"; import WarningAmberIcon from "@mui/icons-material/WarningAmber"; import { NavLink } from "react-router-dom"; import { useTranslation } from "react-i18next"; @@ -17,6 +29,7 @@ const Login = () => { const [username, setUsername] = useState(""); const [password, setPassword] = useState(""); const [showPassword, setShowPassword] = useState(false); + const [resetOpen, setResetOpen] = useState(false); const handleSubmit = async (event) => { event.preventDefault(); @@ -100,7 +113,13 @@ const Login = () => { )} - {/* This is where the password reset link would go */} + {config.enable_reset_password && ( +
+ +
+ )} {config.enable_signup && (
@@ -110,8 +129,67 @@ const Login = () => { )} + setResetOpen(false)} /> ); }; +// ForgotPasswordDialog collects a username/email and asks the server to email a reset link. The +// response is uniform, so the dialog always shows the same "if an account exists" confirmation. +const ForgotPasswordDialog = (props) => { + const { t } = useTranslation(); + const [identifier, setIdentifier] = useState(""); + const [sending, setSending] = useState(false); + const [sent, setSent] = useState(false); + + const handleSubmit = async () => { + try { + setSending(true); + await accountApi.requestPasswordReset(identifier); + } catch (e) { + console.log(`[Login] Password reset request failed`, e); + } finally { + setSending(false); + setSent(true); // Uniform outcome regardless of success/failure (enumeration-safe) + } + }; + + return ( + + {t("login_reset_dialog_title")} + + {sent ? ( + {t("login_reset_dialog_sent")} + ) : ( + <> + {t("login_reset_dialog_description")} + setIdentifier(ev.target.value.trim())} + fullWidth + variant="standard" + /> + + )} + + + {sent ? ( + + ) : ( + <> + + + + )} + + + ); +}; + export default Login; diff --git a/web/src/components/PasswordReset.jsx b/web/src/components/PasswordReset.jsx new file mode 100644 index 00000000..0e004d04 --- /dev/null +++ b/web/src/components/PasswordReset.jsx @@ -0,0 +1,105 @@ +import * as React from "react"; +import { useEffect, useRef, useState } from "react"; +import { Typography, TextField, Button, Box } from "@mui/material"; +import WarningAmberIcon from "@mui/icons-material/WarningAmber"; +import CheckCircleOutlineIcon from "@mui/icons-material/CheckCircleOutline"; +import { useParams, NavLink } from "react-router-dom"; +import { useTranslation } from "react-i18next"; +import accountApi from "../app/AccountApi"; +import AvatarBox from "./AvatarBox"; +import routes from "./routes"; + +// PasswordReset is the magic-link landing page for setting a new password. There is no +// pre-validation: the form renders directly and an invalid/expired token surfaces as an error on +// submit. The raw token is stripped from the URL on load (kept out of history / Referer). +const PasswordReset = () => { + const { t } = useTranslation(); + const { token: tokenParam } = useParams(); + const token = useRef(tokenParam); + const [password, setPassword] = useState(""); + const [confirm, setConfirm] = useState(""); + const [error, setError] = useState(""); + const [sending, setSending] = useState(false); + const [done, setDone] = useState(false); + + useEffect(() => { + // Strip the token from the URL bar immediately (keep it out of history / Referer) + window.history.replaceState(null, "", routes.login); + }, []); + + const handleSubmit = async (event) => { + event.preventDefault(); + if (password !== confirm) { + setError(t("reset_password_form_passwords_no_match")); + return; + } + try { + setSending(true); + setError(""); + await accountApi.resetPassword(token.current, password); + setDone(true); + } catch (e) { + console.log(`[PasswordReset] Reset failed`, e); + setError(t("reset_password_form_error_invalid")); + } finally { + setSending(false); + } + }; + + if (done) { + return ( + + + {t("reset_password_success_title")} + {t("reset_password_success_description")} + + + ); + } + + return ( + + {t("reset_password_title")} + + setPassword(ev.target.value.trim())} + autoComplete="new-password" + autoFocus + /> + setConfirm(ev.target.value.trim())} + autoComplete="new-password" + /> + + {error && ( + + + {error} + + )} + + + ); +}; + +export default PasswordReset; diff --git a/web/src/components/routes.js b/web/src/components/routes.js index d9c371eb..6e649df3 100644 --- a/web/src/components/routes.js +++ b/web/src/components/routes.js @@ -8,6 +8,7 @@ const routes = { account: "/account", settings: "/settings", emailVerify: "/account/email/verify/:token", + passwordReset: "/account/password/reset/:token", subscription: "/:topic", subscriptionExternal: "/:baseUrl/:topic", forSubscription: (subscription) => { From 4516adea368df7dc056906004f5bce3a00fbaa76 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 17:36:40 -0400 Subject: [PATCH 05/34] Lots of refinement --- cmd/user.go | 20 ++-- cmd/user_test.go | 32 ++++-- server/server_account.go | 28 +++-- server/server_account_email_test.go | 112 +++++++++++++++++--- server/server_payments.go | 3 +- server/types.go | 13 ++- user/magic_link_test.go | 47 ++++++++ user/manager.go | 15 ++- web/public/static/langs/en.json | 18 ++-- web/src/components/Account.jsx | 153 +++++++++++++++++---------- web/src/components/App.jsx | 2 + web/src/components/EmailVerify.jsx | 31 +++--- web/src/components/Login.jsx | 78 +------------- web/src/components/PasswordReset.jsx | 11 +- web/src/components/ResetPassword.jsx | 95 +++++++++++++++++ web/src/components/routes.js | 1 + 16 files changed, 460 insertions(+), 199 deletions(-) create mode 100644 web/src/components/ResetPassword.jsx diff --git a/cmd/user.go b/cmd/user.go index 84cba345..8c65221d 100644 --- a/cmd/user.go +++ b/cmd/user.go @@ -44,7 +44,7 @@ var flagsUser = append( var cmdUser = &cli.Command{ Name: "user", Usage: "Manage/show users", - UsageText: "ntfy user [list|add|remove|change-pass|change-role] ...", + UsageText: "ntfy user [list|add|remove|change-pass|reset-pass|change-role] ...", Flags: flagsUser, Before: initConfigFileInputSourceFunc("config", flagsUser, initLogFunc), Category: categoryServer, @@ -108,11 +108,11 @@ directly the bcrypt hash. This is useful if you are updating users via scripts. `, }, { - Name: "password-reset", - Aliases: []string{"reset"}, + Name: "reset-pass", + Aliases: []string{"rp"}, Usage: "Generates a password reset link for a user", - UsageText: "ntfy user password-reset [--send-email] USERNAME", - Action: execUserPasswordReset, + UsageText: "ntfy user reset-pass [--send-email] USERNAME", + Action: execUserResetPass, Flags: []cli.Flag{ &cli.BoolFlag{Name: "send-email", Aliases: []string{"e"}, Usage: "also email the reset link to the user's primary email"}, }, @@ -129,8 +129,8 @@ requires SMTP to be configured and the user to have a verified primary email). Requires base-url to be configured so an absolute link can be generated. Example: - ntfy user password-reset phil # Print a reset link for user phil - ntfy user password-reset --send-email phil # Print and email the reset link + ntfy user reset-pass phil # Print a reset link for user phil + ntfy user reset-pass --send-email phil # Print and email the reset link `, }, { @@ -319,12 +319,12 @@ func execUserChangePass(c *cli.Context) error { return nil } -func execUserPasswordReset(c *cli.Context) error { +func execUserResetPass(c *cli.Context) error { username := c.Args().Get(0) sendEmail := c.Bool("send-email") baseURL := strings.TrimSuffix(c.String("base-url"), "/") if username == "" { - return errors.New("username expected, type 'ntfy user password-reset --help' for help") + return errors.New("username expected, type 'ntfy user reset-pass --help' for help") } else if username == userEveryone || username == user.Everyone { return errors.New("username not allowed") } else if baseURL == "" { @@ -339,6 +339,8 @@ func execUserPasswordReset(c *cli.Context) error { return fmt.Errorf("user %s does not exist", username) } else if err != nil { return err + } else if u.Provisioned { + return fmt.Errorf("user %s is provisioned in the config file; its password cannot be reset", username) } // Resolve the primary email up front if we need to send -- fail before creating a token var primaryEmail string diff --git a/cmd/user_test.go b/cmd/user_test.go index 4dbca550..c5e1c44c 100644 --- a/cmd/user_test.go +++ b/cmd/user_test.go @@ -122,7 +122,7 @@ func TestCLI_User_Delete(t *testing.T) { require.Contains(t, err.Error(), "user phil does not exist") } -func TestCLI_User_PasswordReset(t *testing.T) { +func TestCLI_User_ResetPass(t *testing.T) { s, conf, port := newTestServerWithAuth(t) defer test.StopServer(t, s, port) @@ -132,11 +132,11 @@ func TestCLI_User_PasswordReset(t *testing.T) { // Prints a working-looking reset link when base-url is set app, _, stdout, _ = newTestApp() - require.Nil(t, runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "password-reset", "phil")) + require.Nil(t, runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "reset-pass", "phil")) require.Contains(t, stdout.String(), "https://ntfy.example.com/account/password/reset/") } -func TestCLI_User_PasswordReset_NoBaseURL(t *testing.T) { +func TestCLI_User_ResetPass_NoBaseURL(t *testing.T) { s, conf, port := newTestServerWithAuth(t) defer test.StopServer(t, s, port) @@ -145,12 +145,12 @@ func TestCLI_User_PasswordReset_NoBaseURL(t *testing.T) { require.Nil(t, runUserCommand(app, conf, "add", "phil")) app, _, _, _ = newTestApp() - err := runUserCommand(app, conf, "password-reset", "phil") + err := runUserCommand(app, conf, "reset-pass", "phil") require.Error(t, err) require.Contains(t, err.Error(), "base-url") } -func TestCLI_User_PasswordReset_SendEmailNoPrimary(t *testing.T) { +func TestCLI_User_ResetPass_SendEmailNoPrimary(t *testing.T) { s, conf, port := newTestServerWithAuth(t) defer test.StopServer(t, s, port) @@ -160,11 +160,31 @@ func TestCLI_User_PasswordReset_SendEmailNoPrimary(t *testing.T) { // --send-email requires a primary email; phil has none app, _, _, _ = newTestApp() - err := runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "password-reset", "--send-email", "phil") + err := runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "reset-pass", "--send-email", "phil") require.Error(t, err) require.Contains(t, err.Error(), "no primary email") } +func TestCLI_User_ResetPass_ProvisionedRejected(t *testing.T) { + s, conf, port := newTestServerWithAuth(t) + defer test.StopServer(t, s, port) + + // Seed a provisioned user into the auth database via config provisioning + m, err := user.NewSQLiteManager(conf.AuthFile, "", &user.Config{ + ProvisionEnabled: true, + Users: []*user.User{ + {Name: "provuser", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: user.RoleUser}, + }, + }) + require.Nil(t, err) + require.Nil(t, m.Close()) + + app, _, _, _ := newTestApp() + err = runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "reset-pass", "provuser") + require.Error(t, err) + require.Contains(t, err.Error(), "provisioned") +} + func newTestServerWithAuth(t *testing.T) (s *server.Server, conf *server.Config, port int) { configFile := filepath.Join(t.TempDir(), "server-dummy.yml") require.Nil(t, os.WriteFile(configFile, []byte(""), 0600)) // Dummy config file to avoid lookup of real server.yml diff --git a/server/server_account.go b/server/server_account.go index f006f1ac..214a71ba 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -167,20 +167,24 @@ func (s *Server) handleAccountGet(w http.ResponseWriter, r *http.Request, v *vis if err != nil { return err } - if len(emails) > 0 { - response.Emails = emails - } primaryEmail, err := s.userManager.PrimaryEmail(u.ID) if err != nil { return err } - response.PrimaryEmail = primaryEmail pendingEmails, err := s.userManager.PendingEmails(u.ID) if err != nil { return err } - if len(pendingEmails) > 0 { - response.PendingEmails = pendingEmails + // Combine verified (with primary flag) and pending (unverified) into one list + emailInfos := make([]*apiAccountEmailInfo, 0, len(emails)+len(pendingEmails)) + for _, email := range emails { + emailInfos = append(emailInfos, &apiAccountEmailInfo{Address: email, Primary: email == primaryEmail}) + } + for _, email := range pendingEmails { + emailInfos = append(emailInfos, &apiAccountEmailInfo{Address: email, Pending: true}) + } + if len(emailInfos) > 0 { + response.Emails = emailInfos } } } else { @@ -718,6 +722,8 @@ func (s *Server) handleAccountEmailSetPrimary(w http.ResponseWriter, r *http.Req return err } else if !emailAddressRegex.MatchString(req.Email) { return errHTTPBadRequestEmailAddressInvalid + } else if u.Provisioned { + return errHTTPConflictProvisionedUserChange // Provisioned users can't reset, so a recovery email is meaningless } logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Setting primary email") err = s.userManager.SetPrimaryEmail(u.ID, req.Email) @@ -810,13 +816,15 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt // The identifier is tried first as a username, then as a primary email address. It returns // ok=false if no account with a primary email matches (reset requires a verified primary email). func (s *Server) resolveResetTarget(identifier string) (userID string, email string, ok bool) { - if u, err := s.userManager.User(identifier); err == nil && u != nil { + if u, err := s.userManager.User(identifier); err == nil && u != nil && !u.Provisioned { if primary, perr := s.userManager.PrimaryEmail(u.ID); perr == nil && primary != "" { return u.ID, primary, true } } if uid, err := s.userManager.UserIDByPrimaryEmail(identifier); err == nil { - return uid, identifier, true + if u, uerr := s.userManager.UserByID(uid); uerr == nil && !u.Provisioned { + return uid, identifier, true + } } return "", "", false } @@ -834,8 +842,8 @@ func (s *Server) handleAccountPasswordReset(w http.ResponseWriter, r *http.Reque return errHTTPBadRequest } err = s.userManager.ResetPassword(req.Token, req.Password) - if errors.Is(err, user.ErrMagicLinkNotFound) { - return errHTTPBadRequestResetLinkInvalid + if errors.Is(err, user.ErrMagicLinkNotFound) || errors.Is(err, user.ErrProvisionedUserChange) { + return errHTTPBadRequestResetLinkInvalid // Generic 400 (provisioned users can't be reset; don't leak that) } else if err != nil { return err } diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index e8bbc920..38ed8d84 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -57,6 +57,37 @@ func getAccount(t *testing.T, s *Server, auth map[string]string) *apiAccountResp return account } +// verifiedAddrs / pendingAddrs / primaryAddr extract the addresses from the structured email +// list returned by GET /v1/account, so assertions stay readable. +func verifiedAddrs(account *apiAccountResponse) []string { + addrs := make([]string, 0) + for _, e := range account.Emails { + if !e.Pending { + addrs = append(addrs, e.Address) + } + } + return addrs +} + +func pendingAddrs(account *apiAccountResponse) []string { + addrs := make([]string, 0) + for _, e := range account.Emails { + if e.Pending { + addrs = append(addrs, e.Address) + } + } + return addrs +} + +func primaryAddr(account *apiAccountResponse) string { + for _, e := range account.Emails { + if e.Primary { + return e.Address + } + } + return "" +} + func tokenFromLink(t *testing.T, link, prefix string) string { require.True(t, strings.HasPrefix(link, prefix), "link %q missing prefix %q", link, prefix) return strings.TrimPrefix(link, prefix) @@ -73,9 +104,9 @@ func TestAccount_Email_AddVerifySetsPrimary(t *testing.T) { // Pending, not yet verified, no primary account := getAccount(t, s, auth) - require.Equal(t, []string{"ben@example.com"}, account.PendingEmails) - require.Empty(t, account.Emails) - require.Equal(t, "", account.PrimaryEmail) + require.Equal(t, []string{"ben@example.com"}, pendingAddrs(account)) + require.Empty(t, verifiedAddrs(account)) + require.Equal(t, "", primaryAddr(account)) // "Click" the captured link (unauthenticated POST) token := tokenFromLink(t, mailer.verifyLinks["ben@example.com"], "https://ntfy.example.com/account/email/verify/") @@ -84,9 +115,9 @@ func TestAccount_Email_AddVerifySetsPrimary(t *testing.T) { // Now verified + primary, no longer pending account = getAccount(t, s, auth) - require.Equal(t, []string{"ben@example.com"}, account.Emails) - require.Equal(t, "ben@example.com", account.PrimaryEmail) - require.Empty(t, account.PendingEmails) + require.Equal(t, []string{"ben@example.com"}, verifiedAddrs(account)) + require.Equal(t, "ben@example.com", primaryAddr(account)) + require.Empty(t, pendingAddrs(account)) }) } @@ -111,13 +142,13 @@ func TestAccount_Email_DeletePending(t *testing.T) { defer s.closeDatabases() require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"ben@example.com"}`, auth).Code) - require.Equal(t, []string{"ben@example.com"}, getAccount(t, s, auth).PendingEmails) + require.Equal(t, []string{"ben@example.com"}, pendingAddrs(getAccount(t, s, auth))) // Deleting the pending address clears it (no verification ever happened) require.Equal(t, 200, request(t, s, "DELETE", "/v1/account/email", `{"email":"ben@example.com"}`, auth).Code) account := getAccount(t, s, auth) - require.Empty(t, account.PendingEmails) - require.Empty(t, account.Emails) + require.Empty(t, pendingAddrs(account)) + require.Empty(t, verifiedAddrs(account)) }) } @@ -154,7 +185,7 @@ func TestAccount_Email_SetPrimaryCollision(t *testing.T) { require.Equal(t, 200, request(t, s, "PUT", "/v1/account/email", `{"email":"shared@example.com"}`, auth).Code) benToken := tokenFromLink(t, mailer.verifyLinks["shared@example.com"], "https://ntfy.example.com/account/email/verify/") require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, benToken), nil).Code) - require.Equal(t, "shared@example.com", getAccount(t, s, auth).PrimaryEmail) + require.Equal(t, "shared@example.com", primaryAddr(getAccount(t, s, auth))) // alice verifies the same address -> allowed as secondary, but it is not her primary require.Nil(t, s.userManager.AddUser("alice", "alice", user.RoleUser, false)) @@ -163,8 +194,8 @@ func TestAccount_Email_SetPrimaryCollision(t *testing.T) { aliceToken := tokenFromLink(t, mailer.verifyLinks["shared@example.com"], "https://ntfy.example.com/account/email/verify/") require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, aliceToken), nil).Code) aliceAccount := getAccount(t, s, aliceAuth) - require.Equal(t, []string{"shared@example.com"}, aliceAccount.Emails) - require.Equal(t, "", aliceAccount.PrimaryEmail) + require.Equal(t, []string{"shared@example.com"}, verifiedAddrs(aliceAccount)) + require.Equal(t, "", primaryAddr(aliceAccount)) // alice trying to promote it to primary collides with ben's rr := request(t, s, "POST", "/v1/account/email/primary", `{"email":"shared@example.com"}`, aliceAuth) @@ -245,6 +276,63 @@ func TestAccount_PasswordReset_NoPrimaryEmailNoSend(t *testing.T) { }) } +func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + hash, err := user.HashPassword("provpass") + require.Nil(t, err) + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.SMTPSenderAddr = "localhost:25" + conf.SMTPSenderFrom = "noreply@example.com" + conf.BaseURL = "https://ntfy.example.com" + conf.AuthUsers = []*user.User{{Name: "prov", Hash: hash, Role: user.RoleUser}} + s := newTestServer(t, conf) + mailer := newCaptureMailer() + s.mailSender = mailer + defer s.closeDatabases() + auth := map[string]string{"Authorization": util.BasicAuth("prov", "provpass")} + + // A provisioned user can verify an email, but it must NOT become their primary + verifyEmailFor(t, s, mailer, auth, "prov@example.com") + account := getAccount(t, s, auth) + require.Equal(t, []string{"prov@example.com"}, verifiedAddrs(account)) + require.Equal(t, "", primaryAddr(account)) + + // Explicitly setting it primary is rejected + rr := request(t, s, "POST", "/v1/account/email/primary", `{"email":"prov@example.com"}`, auth) + require.Equal(t, 409, rr.Code) + require.Equal(t, 40905, toHTTPError(t, rr.Body.String()).Code) + }) +} + +func TestAccount_PasswordReset_ProvisionedUserNoSend(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + // Provision a user via config (AuthUsers), with email sending enabled + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.SMTPSenderAddr = "localhost:25" + conf.SMTPSenderFrom = "noreply@example.com" + conf.BaseURL = "https://ntfy.example.com" + conf.AuthUsers = []*user.User{ + {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: user.RoleUser}, + } + s := newTestServer(t, conf) + mailer := newCaptureMailer() + s.mailSender = mailer + defer s.closeDatabases() + + // Give the provisioned user a verified primary email anyway + prov, err := s.userManager.User("prov") + require.Nil(t, err) + require.True(t, prov.Provisioned) + require.Nil(t, s.userManager.AddEmail(prov.ID, "prov@example.com")) + require.Nil(t, s.userManager.SetPrimaryEmail(prov.ID, "prov@example.com")) + + // Reset request by username and by email -> uniform 200, but no email sent (can't reset) + require.Equal(t, 200, request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"prov"}`, nil).Code) + require.Equal(t, 200, request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"prov@example.com"}`, nil).Code) + require.Empty(t, mailer.resetLinks) + }) +} + func TestAccount_PasswordReset_InvalidToken(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s, _, _ := newEmailTestServer(t, databaseURL) diff --git a/server/server_payments.go b/server/server_payments.go index 76d0b5ac..4b19a091 100644 --- a/server/server_payments.go +++ b/server/server_payments.go @@ -238,7 +238,8 @@ func (s *Server) handleAccountBillingSubscriptionCreateSuccess(w http.ResponseWr return err } // Offer email recovery: auto-send a verification link to the billing email (best-effort). - if sess.CustomerDetails != nil { + // Provisioned users can't reset their password, so recovery setup doesn't apply to them. + if sess.CustomerDetails != nil && !u.Provisioned { s.maybeEnqueueBillingEmailVerification(r, v, u.ID, sess.CustomerDetails.Email) } http.Redirect(w, r, s.config.BaseURL+accountPath, http.StatusSeeOther) diff --git a/server/types.go b/server/types.go index 963cb127..08687fbb 100644 --- a/server/types.go +++ b/server/types.go @@ -287,6 +287,15 @@ type apiAccountReservation struct { Everyone string `json:"everyone"` } +// apiAccountEmailInfo describes one email address on the account, as returned by GET /v1/account. +// Verified addresses have pending=false; exactly one verified address may be primary (the +// recovery email). Pending addresses are awaiting a magic-link click and are never primary. +type apiAccountEmailInfo struct { + Address string `json:"address"` + Primary bool `json:"primary,omitempty"` + Pending bool `json:"pending,omitempty"` +} + type apiAccountBilling struct { Customer bool `json:"customer"` Subscription bool `json:"subscription"` @@ -307,9 +316,7 @@ type apiAccountResponse struct { Reservations []*apiAccountReservation `json:"reservations,omitempty"` Tokens []*apiAccountTokenResponse `json:"tokens,omitempty"` PhoneNumbers []string `json:"phone_numbers,omitempty"` - Emails []string `json:"emails,omitempty"` - PrimaryEmail string `json:"primary_email,omitempty"` // The verified recovery email, if set - PendingEmails []string `json:"pending_emails,omitempty"` // Unverified addresses awaiting a magic-link click + Emails []*apiAccountEmailInfo `json:"emails,omitempty"` Tier *apiAccountTier `json:"tier,omitempty"` Limits *apiAccountLimits `json:"limits,omitempty"` Stats *apiAccountStats `json:"stats,omitempty"` diff --git a/user/magic_link_test.go b/user/magic_link_test.go index 33053c05..4a2506c4 100644 --- a/user/magic_link_test.go +++ b/user/magic_link_test.go @@ -289,6 +289,53 @@ func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) { }) } +func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManagerFromConfig(t, newManager, &Config{ + DefaultAccess: PermissionDenyAll, + ProvisionEnabled: true, + Users: []*User{ + {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: RoleUser}, + }, + }) + prov, err := a.User("prov") + require.Nil(t, err) + + // A provisioned user can verify an email (for notifications), but it must NOT become primary + _, err = a.VerifyEmail(addVerifyLink(t, a, prov.ID, "prov@example.com", time.Hour)) + require.Nil(t, err) + + emails, err := a.Emails(prov.ID) + require.Nil(t, err) + require.Equal(t, []string{"prov@example.com"}, emails) + primary, err := a.PrimaryEmail(prov.ID) + require.Nil(t, err) + require.Equal(t, "", primary) + }) +} + +func TestUser_MagicLink_ResetPassword_ProvisionedRejected(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + // Provisioned users come from the config file (ProvisionEnabled), not AddUser + a := newTestManagerFromConfig(t, newManager, &Config{ + DefaultAccess: PermissionDenyAll, + ProvisionEnabled: true, + Users: []*User{ + {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: RoleUser}, + }, + }) + prov, err := a.User("prov") + require.Nil(t, err) + require.True(t, prov.Provisioned) + + // A reset token can be created, but consuming it must be rejected for a provisioned user + // (their password comes from the config file, like change-pass). + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, prov.ID, "", time.Hour) + require.Nil(t, err) + require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrProvisionedUserChange) + }) +} + func TestUser_MagicLink_ResetPassword_Expired(t *testing.T) { forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { a := newTestManager(t, newManager, PermissionDenyAll) diff --git a/user/manager.go b/user/manager.go index 4a7866c1..0f0064d5 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1648,8 +1648,9 @@ func (a *Manager) DeleteEmailVerification(userID, email string) error { // validating the token (kind + expiry), it deletes the link, adds the address to the user's // verified emails, and -- if the user has no primary email yet and the address is not already // primary on another account -- promotes the new address to primary. All mutations run in one -// transaction. A primary collision simply leaves the address verified but non-primary. Returns -// the consumed link. +// transaction. A primary collision simply leaves the address verified but non-primary. Provisioned +// users never get a primary (the recovery email is meaningless for them -- they can't reset). +// Returns the consumed link. func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { tokenHash := hashToken(rawToken) m, err := a.MagicLinkByHash(tokenHash) @@ -1659,6 +1660,10 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { if m.Kind != MagicLinkKindEmailVerify || time.Now().Unix() > m.Expires { return nil, ErrMagicLinkNotFound } + u, err := a.UserByID(m.UserID) + if err != nil { + return nil, err + } err = db.ExecTx(a.db, func(tx *sql.Tx) error { // Single use: delete the link, then add the (idempotent) verified address if _, err := tx.Exec(a.queries.deleteMagicLinkByHash, tokenHash); err != nil { @@ -1667,6 +1672,9 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { if _, err := tx.Exec(a.queries.insertEmailIgnore, m.UserID, m.Email); err != nil { return err } + if u.Provisioned { + return nil // Provisioned users don't get a primary (recovery) email + } // Promote to primary only if the user has none yet and the address is globally free. // We check with SELECTs rather than catching a unique violation, because Postgres aborts // the whole transaction on any constraint error (which would undo the verified-email add). @@ -1712,6 +1720,9 @@ func (a *Manager) ResetPassword(rawToken, password string) error { if err != nil { return err } + if u.Provisioned { + return ErrProvisionedUserChange // Provisioned users get their password from the config file, not reset + } hash, err := a.maybeHashPassword(password, false) if err != nil { return err diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index ecae6954..cc78f3d4 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -28,11 +28,14 @@ "login_form_button_submit": "Sign in", "login_link_signup": "Sign up", "login_link_forgot_password": "Forgot password?", - "login_reset_dialog_title": "Reset password", - "login_reset_dialog_description": "Enter your username or email address. If an account exists, we'll email a link to reset your password.", - "login_reset_dialog_identifier_label": "Username or email", - "login_reset_dialog_button_submit": "Send reset link", - "login_reset_dialog_sent": "If an account exists, we've emailed a link to reset your password. Please check your inbox.", + "reset_password_request_title": "Reset password", + "reset_password_request_description": "Enter your username or email address. If an account exists, we'll email a link to reset your password.", + "reset_password_request_identifier_label": "Username or email", + "reset_password_request_button_submit": "Send reset link", + "reset_password_sent_title": "Check your inbox", + "reset_password_sent_description": "If an account exists, we've emailed a link to reset your password.", + "reset_password_back_to_login": "Back to sign-in", + "reset_password_disabled": "Password reset is not enabled on this server.", "reset_password_title": "Set a new password", "reset_password_form_password": "New password", "reset_password_form_confirm": "Confirm new password", @@ -242,6 +245,7 @@ "account_basics_emails_no_emails_yet": "No emails yet", "account_basics_emails_copied_to_clipboard": "Email address copied to clipboard", "account_basics_emails_primary_badge": "Primary", + "account_basics_emails_chip_actions": "Click for actions", "account_basics_emails_unverified": "unverified", "account_basics_emails_set_primary": "Set as recovery email", "account_basics_emails_delete": "Remove", @@ -249,7 +253,8 @@ "account_basics_emails_resend": "Resend verification email", "account_basics_emails_resent": "Verification email sent, check your inbox", "account_basics_emails_primary_elsewhere": "This email is the recovery email on another account", - "account_basics_emails_no_recovery_warning": "No recovery email set. You will not be able to reset your password. Add and verify an email below, then set it as your recovery email.", + "account_basics_emails_no_recovery_warning": "Add a recovery email address to ensure you can reset your password.", + "account_basics_emails_provisioned_info": "Provisioned users cannot add a recovery email address.", "account_basics_emails_dialog_title": "Add email address", "account_basics_emails_dialog_description": "Enter an email address to add it to your account. We will send a verification link to confirm it is yours.", "account_basics_emails_dialog_email_label": "Email address", @@ -267,6 +272,7 @@ "account_basics_tier_admin_suffix_with_tier": "(with {{tier}} tier)", "account_basics_tier_admin_suffix_no_tier": "(no tier)", "account_basics_tier_basic": "Basic", + "account_basics_tier_provisioned": "Provisioned", "account_basics_tier_free": "Free", "account_basics_tier_interval_monthly": "monthly", "account_basics_tier_interval_yearly": "annually", diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index a45dce09..e9e2168e 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -2,7 +2,6 @@ import * as React from "react"; import { useContext, useState } from "react"; import { Alert, - Box, CardActions, CardContent, Chip, @@ -32,7 +31,10 @@ import { DialogContent, TextField, IconButton, + Menu, MenuItem, + ListItemIcon, + ListItemText, DialogContentText, useTheme, } from "@mui/material"; @@ -294,6 +296,7 @@ const AccountType = () => { >
{accountType} + {account.provisioned && } {account.billing?.paid_until && !account.billing?.cancel_at && ( { const [dialogKey, setDialogKey] = useState(0); const [dialogOpen, setDialogOpen] = useState(false); const [snack, setSnack] = useState(""); // Non-empty shows a transient snackbar message + const [menuAnchor, setMenuAnchor] = useState(null); // Chip element the actions menu is anchored to + const [menuEmail, setMenuEmail] = useState(null); // The email the open menu acts on const labelId = "prefVerifiedEmails"; + const openMenu = (ev, email) => { + setMenuAnchor(ev.currentTarget); + setMenuEmail(email); + }; + const closeMenu = () => { + setMenuAnchor(null); + setMenuEmail(null); + }; + const runMenuAction = (fn) => { + closeMenu(); + fn(menuEmail.address); + }; + const handleDialogOpen = () => { setDialogKey((prev) => prev + 1); setDialogOpen(true); @@ -381,10 +399,12 @@ const Emails = () => { }; // runEmailAction wraps an account API call with the shared error handling (redirect on - // unauthorized, surface a message otherwise). The account list refreshes via the sync event. + // unauthorized, surface a message otherwise). On success it refetches the account so the email + // list reflects the change immediately, rather than waiting for the async sync event. const runEmailAction = async (fn, errorMessage) => { try { await fn(); + await accountApi.sync(); } catch (e) { console.log(`[Account] Email action failed`, e); if (e instanceof UnauthorizedError) { @@ -425,70 +445,82 @@ const Emails = () => { ); } - const verifiedEmails = account?.emails ?? []; - const pendingEmails = account?.pending_emails ?? []; - const primaryEmail = account?.primary_email ?? ""; - const showNoRecoveryWarning = config.enable_reset_password && primaryEmail === ""; + const emails = account?.emails ?? []; + const verifiedEmails = emails.filter((e) => !e.pending); + const pendingEmails = emails.filter((e) => e.pending); + const primaryEmail = verifiedEmails.find((e) => e.primary)?.address ?? ""; + // Provisioned users get their password from the server config and cannot reset it, so they don't + // get the "no recovery email" nudge (the Add-email dialog explains the recovery-email limitation). + const showNoRecoveryWarning = config.enable_reset_password && primaryEmail === "" && !account?.provisioned; return ( - +
- {showNoRecoveryWarning && ( - - {t("account_basics_emails_no_recovery_warning")} - - )} - - {verifiedEmails.map((email) => { - const isPrimary = email === primaryEmail; - return ( - - {email} - {isPrimary && } - {!isPrimary && ( - - handleSetPrimary(email)}> - - - - )} - {isPrimary && } - - handleCopy(email)}> - - - - - handleDelete(email)}> - - - - - ); - })} - {pendingEmails.map((email) => ( - - - {email} ({t("account_basics_emails_unverified")}) - - - handleResend(email)}> - - + {verifiedEmails.map((email) => ( + : undefined} + label={ + + {email.address} - - handleDelete(email)}> - - + } + variant="outlined" + onClick={(ev) => openMenu(ev, email)} + onDelete={() => handleDelete(email.address)} + sx={email.primary ? { "& .MuiChip-icon": { color: "primary.main" } } : undefined} + /> + ))} + {pendingEmails.map((email) => ( + + + {email.address} ({t("account_basics_emails_unverified")}) + - - ))} - {verifiedEmails.length === 0 && pendingEmails.length === 0 && {t("account_basics_emails_no_emails_yet")}} - + } + variant="outlined" + onClick={(ev) => openMenu(ev, email)} + onDelete={() => handleDelete(email.address)} + sx={{ opacity: 0.7 }} + /> + ))} + {verifiedEmails.length === 0 && pendingEmails.length === 0 && {t("account_basics_emails_no_emails_yet")}} + {showNoRecoveryWarning && ( + + {t("account_basics_emails_no_recovery_warning")} + + )}
+ + runMenuAction(handleCopy)}> + + + + {t("common_copy_to_clipboard")} + + {menuEmail && !menuEmail.pending && !menuEmail.primary && !account?.provisioned && ( + runMenuAction(handleSetPrimary)}> + + + + {t("account_basics_emails_set_primary")} + + )} + {menuEmail && menuEmail.pending && ( + runMenuAction(handleResend)}> + + + + {t("account_basics_emails_resend")} + + )} + setSnack("")} message={snack} /> @@ -500,6 +532,7 @@ const Emails = () => { const AddEmailDialog = (props) => { const theme = useTheme(); const { t } = useTranslation(); + const { account } = useContext(AccountContext); const [error, setError] = useState(""); const [email, setEmail] = useState(""); const [sending, setSending] = useState(false); @@ -512,6 +545,7 @@ const AddEmailDialog = (props) => { try { setSending(true); await accountApi.startEmailVerification(email); + await accountApi.sync(); // Refresh so the new "(unverified)" address shows up immediately setSent(true); } catch (e) { console.log(`[Account] Error starting email verification`, e); @@ -534,6 +568,11 @@ const AddEmailDialog = (props) => { ) : ( <> {t("account_basics_emails_dialog_description")} + {config.enable_reset_password && account?.provisioned && ( + + {t("account_basics_emails_provisioned_info")} + + )} { } /> } /> + } /> } /> } /> }> diff --git a/web/src/components/EmailVerify.jsx b/web/src/components/EmailVerify.jsx index ce70a8d5..8013652e 100644 --- a/web/src/components/EmailVerify.jsx +++ b/web/src/components/EmailVerify.jsx @@ -3,7 +3,7 @@ import { useEffect, useRef, useState } from "react"; import { Typography, Button, Box, CircularProgress } from "@mui/material"; import CheckCircleOutlineIcon from "@mui/icons-material/CheckCircleOutline"; import ErrorOutlineIcon from "@mui/icons-material/ErrorOutline"; -import { useParams, NavLink } from "react-router-dom"; +import { useParams, useNavigate } from "react-router-dom"; import { useTranslation } from "react-i18next"; import accountApi from "../app/AccountApi"; import AvatarBox from "./AvatarBox"; @@ -16,6 +16,7 @@ import routes from "./routes"; const EmailVerify = () => { const { t } = useTranslation(); const { token } = useParams(); + const navigate = useNavigate(); const [status, setStatus] = useState("verifying"); // "verifying" | "success" | "error" const ran = useRef(false); @@ -40,31 +41,33 @@ const EmailVerify = () => { return ( {status === "verifying" && ( - <> - + + {t("email_verify_progress_title")} - + )} {status === "success" && ( <> - - {t("email_verify_success_title")} + + + {t("email_verify_success_title")} + {t("email_verify_success_description")} - )} {status === "error" && ( <> - - {t("email_verify_error_title")} - {t("email_verify_error_description")} - - + + + {t("email_verify_error_title")} + {t("email_verify_error_description")} + )} diff --git a/web/src/components/Login.jsx b/web/src/components/Login.jsx index a95f9a14..9bf8e1c5 100644 --- a/web/src/components/Login.jsx +++ b/web/src/components/Login.jsx @@ -1,18 +1,6 @@ import * as React from "react"; import { useState } from "react"; -import { - Typography, - TextField, - Button, - Box, - IconButton, - InputAdornment, - Dialog, - DialogTitle, - DialogContent, - DialogContentText, - DialogActions, -} from "@mui/material"; +import { Typography, TextField, Button, Box, IconButton, InputAdornment } from "@mui/material"; import WarningAmberIcon from "@mui/icons-material/WarningAmber"; import { NavLink } from "react-router-dom"; import { useTranslation } from "react-i18next"; @@ -29,7 +17,6 @@ const Login = () => { const [username, setUsername] = useState(""); const [password, setPassword] = useState(""); const [showPassword, setShowPassword] = useState(false); - const [resetOpen, setResetOpen] = useState(false); const handleSubmit = async (event) => { event.preventDefault(); @@ -115,9 +102,9 @@ const Login = () => { {config.enable_reset_password && (
- +
)} {config.enable_signup && ( @@ -129,67 +116,8 @@ const Login = () => { )}
- setResetOpen(false)} /> ); }; -// ForgotPasswordDialog collects a username/email and asks the server to email a reset link. The -// response is uniform, so the dialog always shows the same "if an account exists" confirmation. -const ForgotPasswordDialog = (props) => { - const { t } = useTranslation(); - const [identifier, setIdentifier] = useState(""); - const [sending, setSending] = useState(false); - const [sent, setSent] = useState(false); - - const handleSubmit = async () => { - try { - setSending(true); - await accountApi.requestPasswordReset(identifier); - } catch (e) { - console.log(`[Login] Password reset request failed`, e); - } finally { - setSending(false); - setSent(true); // Uniform outcome regardless of success/failure (enumeration-safe) - } - }; - - return ( - - {t("login_reset_dialog_title")} - - {sent ? ( - {t("login_reset_dialog_sent")} - ) : ( - <> - {t("login_reset_dialog_description")} - setIdentifier(ev.target.value.trim())} - fullWidth - variant="standard" - /> - - )} - - - {sent ? ( - - ) : ( - <> - - - - )} - - - ); -}; - export default Login; diff --git a/web/src/components/PasswordReset.jsx b/web/src/components/PasswordReset.jsx index 0e004d04..c2a2613e 100644 --- a/web/src/components/PasswordReset.jsx +++ b/web/src/components/PasswordReset.jsx @@ -3,7 +3,7 @@ import { useEffect, useRef, useState } from "react"; import { Typography, TextField, Button, Box } from "@mui/material"; import WarningAmberIcon from "@mui/icons-material/WarningAmber"; import CheckCircleOutlineIcon from "@mui/icons-material/CheckCircleOutline"; -import { useParams, NavLink } from "react-router-dom"; +import { useParams, useNavigate } from "react-router-dom"; import { useTranslation } from "react-i18next"; import accountApi from "../app/AccountApi"; import AvatarBox from "./AvatarBox"; @@ -15,6 +15,7 @@ import routes from "./routes"; const PasswordReset = () => { const { t } = useTranslation(); const { token: tokenParam } = useParams(); + const navigate = useNavigate(); const token = useRef(tokenParam); const [password, setPassword] = useState(""); const [confirm, setConfirm] = useState(""); @@ -49,10 +50,12 @@ const PasswordReset = () => { if (done) { return ( - - {t("reset_password_success_title")} + + + {t("reset_password_success_title")} + {t("reset_password_success_description")} - diff --git a/web/src/components/ResetPassword.jsx b/web/src/components/ResetPassword.jsx new file mode 100644 index 00000000..05d95e21 --- /dev/null +++ b/web/src/components/ResetPassword.jsx @@ -0,0 +1,95 @@ +import * as React from "react"; +import { useState } from "react"; +import { TextField, Button, Box, Typography } from "@mui/material"; +import CheckCircleOutlineIcon from "@mui/icons-material/CheckCircleOutline"; +import { NavLink } from "react-router-dom"; +import { useTranslation } from "react-i18next"; +import accountApi from "../app/AccountApi"; +import AvatarBox from "./AvatarBox"; +import routes from "./routes"; + +// ResetPassword is the standalone "request a password reset" page, reached from the login page. +// It collects a username/email and asks the server to email a reset link. The response is uniform, +// so the page always shows the same confirmation. Completing the reset happens on the separate +// PasswordReset landing page that the emailed link points to. +const ResetPassword = () => { + const { t } = useTranslation(); + const [identifier, setIdentifier] = useState(""); + const [sending, setSending] = useState(false); + const [sent, setSent] = useState(false); + + const handleSubmit = async (event) => { + event.preventDefault(); + try { + setSending(true); + await accountApi.requestPasswordReset(identifier); + } catch (e) { + console.log(`[ResetPassword] Request failed`, e); + } finally { + setSending(false); + setSent(true); // Uniform outcome regardless of success/failure (enumeration-safe) + } + }; + + if (!config.enable_reset_password) { + return ( + + {t("reset_password_disabled")} + + + {t("reset_password_back_to_login")} + + + + ); + } + + if (sent) { + return ( + + + + {t("reset_password_sent_title")} + + {t("reset_password_sent_description")} + + + {t("reset_password_back_to_login")} + + + + ); + } + + return ( + + {t("reset_password_request_title")} + + {t("reset_password_request_description")} + setIdentifier(ev.target.value.trim())} + autoFocus + /> + + + {config.enable_login && ( + + + {t("reset_password_back_to_login")} + + + )} + + ); +}; + +export default ResetPassword; diff --git a/web/src/components/routes.js b/web/src/components/routes.js index 6e649df3..463fb237 100644 --- a/web/src/components/routes.js +++ b/web/src/components/routes.js @@ -4,6 +4,7 @@ import { shortUrl } from "../app/utils"; const routes = { login: "/login", signup: "/signup", + resetPassword: "/reset-password", app: config.app_root, account: "/account", settings: "/settings", From f558935c1e28ee9bdfe3772e9a700451bcda5278 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 22:33:09 -0400 Subject: [PATCH 06/34] Re-wording, chips --- server/errors.go | 2 +- user/types.go | 2 +- web/public/static/langs/en.json | 19 ++++++++------- web/src/components/Account.jsx | 35 ++++++++++++++++++---------- web/src/components/EmailVerify.jsx | 4 ++-- web/src/components/PasswordReset.jsx | 2 +- web/src/components/ResetPassword.jsx | 2 +- 7 files changed, 39 insertions(+), 27 deletions(-) diff --git a/server/errors.go b/server/errors.go index 51bfbe21..d204aa53 100644 --- a/server/errors.go +++ b/server/errors.go @@ -157,7 +157,7 @@ var ( errHTTPConflictProvisionedUserChange = &errHTTP{40905, http.StatusConflict, "conflict: cannot change or delete provisioned user", "", nil} errHTTPConflictProvisionedTokenChange = &errHTTP{40906, http.StatusConflict, "conflict: cannot change or delete provisioned token", "", nil} errHTTPConflictEmailExists = &errHTTP{40907, http.StatusConflict, "conflict: email address already exists", "", nil} - errHTTPConflictEmailPrimaryElsewhere = &errHTTP{40908, http.StatusConflict, "conflict: email address is the recovery email on another account", "", nil} + errHTTPConflictEmailPrimaryElsewhere = &errHTTP{40908, http.StatusConflict, "conflict: email address is the primary email on another account", "", nil} errHTTPGonePhoneVerificationExpired = &errHTTP{41001, http.StatusGone, "phone number verification expired or does not exist", "", nil} errHTTPEntityTooLargeAttachment = &errHTTP{41301, http.StatusRequestEntityTooLarge, "attachment too large, or bandwidth limit reached", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPEntityTooLargeMatrixRequest = &errHTTP{41302, http.StatusRequestEntityTooLarge, "Matrix request is larger than the max allowed length", "", nil} diff --git a/user/types.go b/user/types.go index 44aecd5d..ce7efe36 100644 --- a/user/types.go +++ b/user/types.go @@ -296,7 +296,7 @@ var ( ErrPhoneNumberExists = errors.New("phone number already exists") ErrEmailNotFound = errors.New("email not found") ErrEmailExists = errors.New("email already exists") - ErrEmailPrimaryElsewhere = errors.New("email is the recovery email on another account") + ErrEmailPrimaryElsewhere = errors.New("email is the primary email on another account") ErrMagicLinkNotFound = errors.New("magic link not found") ErrProvisionedUserChange = errors.New("cannot change or delete provisioned user") ErrProvisionedTokenChange = errors.New("cannot change or delete provisioned token") diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index cc78f3d4..278d6466 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -29,11 +29,11 @@ "login_link_signup": "Sign up", "login_link_forgot_password": "Forgot password?", "reset_password_request_title": "Reset password", - "reset_password_request_description": "Enter your username or email address. If an account exists, we'll email a link to reset your password.", + "reset_password_request_description": "Enter your username or email address. If an account exists, a link to reset your password will be emailed.", "reset_password_request_identifier_label": "Username or email", "reset_password_request_button_submit": "Send reset link", "reset_password_sent_title": "Check your inbox", - "reset_password_sent_description": "If an account exists, we've emailed a link to reset your password.", + "reset_password_sent_description": "If an account exists, a link to reset your password has been emailed.", "reset_password_back_to_login": "Back to sign-in", "reset_password_disabled": "Password reset is not enabled on this server.", "reset_password_title": "Set a new password", @@ -247,16 +247,17 @@ "account_basics_emails_primary_badge": "Primary", "account_basics_emails_chip_actions": "Click for actions", "account_basics_emails_unverified": "unverified", - "account_basics_emails_set_primary": "Set as recovery email", + "account_basics_emails_set_primary": "Set as primary email", "account_basics_emails_delete": "Remove", "account_basics_emails_cancel": "Cancel", "account_basics_emails_resend": "Resend verification email", "account_basics_emails_resent": "Verification email sent, check your inbox", - "account_basics_emails_primary_elsewhere": "This email is the recovery email on another account", - "account_basics_emails_no_recovery_warning": "Add a recovery email address to ensure you can reset your password.", - "account_basics_emails_provisioned_info": "Provisioned users cannot add a recovery email address.", + "account_basics_emails_primary_elsewhere": "This email is the primary email on another account", + "account_basics_emails_no_recovery_warning": "Add at least one email address to ensure you can recover your account if you lose your password.", + "account_basics_emails_no_primary_warning": "Add a primary email address to ensure you can recover your account if you lose your password.", + "account_basics_emails_provisioned_info": "Provisioned users cannot add a primary email address, but you can still add an email address for notifications.", "account_basics_emails_dialog_title": "Add email address", - "account_basics_emails_dialog_description": "Enter an email address to add it to your account. We will send a verification link to confirm it is yours.", + "account_basics_emails_dialog_description": "Enter an email address to add it to your account. A verification link will be sent to confirm it is yours.", "account_basics_emails_dialog_email_label": "Email address", "account_basics_emails_dialog_email_placeholder": "e.g. user@example.com", "account_basics_emails_dialog_verify_button": "Send verification link", @@ -269,8 +270,8 @@ "account_basics_tier_title": "Account type", "account_basics_tier_description": "Your account's power level", "account_basics_tier_admin": "Admin", - "account_basics_tier_admin_suffix_with_tier": "(with {{tier}} tier)", - "account_basics_tier_admin_suffix_no_tier": "(no tier)", + "account_basics_tier_admin_suffix_with_tier": "with {{tier}} tier", + "account_basics_tier_admin_suffix_no_tier": "no tier", "account_basics_tier_basic": "Basic", "account_basics_tier_provisioned": "Provisioned", "account_basics_tier_free": "Free", diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index e9e2168e..0024c70f 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -269,22 +269,23 @@ const AccountType = () => { } }; + // The account type is a base label ("Admin", "Basic", "Free", or the tier name) plus an optional + // qualifier chip (admin tier status, or the billing interval). let accountType; + let qualifierChip; if (account.role === Role.ADMIN) { - const tierSuffix = account.tier - ? t("account_basics_tier_admin_suffix_with_tier", { - tier: account.tier.name, - }) + accountType = t("account_basics_tier_admin"); + qualifierChip = account.tier + ? t("account_basics_tier_admin_suffix_with_tier", { tier: account.tier.name }) : t("account_basics_tier_admin_suffix_no_tier"); - accountType = `${t("account_basics_tier_admin")} ${tierSuffix}`; } else if (!account.tier) { accountType = config.enable_payments ? t("account_basics_tier_free") : t("account_basics_tier_basic"); } else { accountType = account.tier.name; if (account.billing?.interval === SubscriptionInterval.MONTH) { - accountType += ` (${t("account_basics_tier_interval_monthly")})`; + qualifierChip = t("account_basics_tier_interval_monthly"); } else if (account.billing?.interval === SubscriptionInterval.YEAR) { - accountType += ` (${t("account_basics_tier_interval_yearly")})`; + qualifierChip = t("account_basics_tier_interval_yearly"); } } @@ -296,6 +297,7 @@ const AccountType = () => { >
{accountType} + {qualifierChip && } {account.provisioned && } {account.billing?.paid_until && !account.billing?.cancel_at && ( { const verifiedEmails = emails.filter((e) => !e.pending); const pendingEmails = emails.filter((e) => e.pending); const primaryEmail = verifiedEmails.find((e) => e.primary)?.address ?? ""; - // Provisioned users get their password from the server config and cannot reset it, so they don't - // get the "no recovery email" nudge (the Add-email dialog explains the recovery-email limitation). - const showNoRecoveryWarning = config.enable_reset_password && primaryEmail === "" && !account?.provisioned; + // Recovery nudges (skipped for provisioned users -- they can't reset, and the Add-email dialog + // explains the limitation): prompt for a first email when there are none, or for a primary when + // there are emails but none is primary. + const recoveryRelevant = config.enable_reset_password && !account?.provisioned; + const hasNoEmails = verifiedEmails.length === 0 && pendingEmails.length === 0; + const showNoEmailWarning = recoveryRelevant && hasNoEmails; + const showNoPrimaryWarning = recoveryRelevant && !hasNoEmails && primaryEmail === ""; return ( @@ -468,7 +474,7 @@ const Emails = () => { variant="outlined" onClick={(ev) => openMenu(ev, email)} onDelete={() => handleDelete(email.address)} - sx={email.primary ? { "& .MuiChip-icon": { color: "primary.main" } } : undefined} + sx={email.primary ? { "& .MuiChip-icon": { color: "#fbc02d" } } : undefined} /> ))} {pendingEmails.map((email) => ( @@ -491,11 +497,16 @@ const Emails = () => { - {showNoRecoveryWarning && ( + {showNoEmailWarning && ( {t("account_basics_emails_no_recovery_warning")} )} + {showNoPrimaryWarning && ( + + {t("account_basics_emails_no_primary_warning")} + + )}
runMenuAction(handleCopy)}> diff --git a/web/src/components/EmailVerify.jsx b/web/src/components/EmailVerify.jsx index 8013652e..d1f09783 100644 --- a/web/src/components/EmailVerify.jsx +++ b/web/src/components/EmailVerify.jsx @@ -49,7 +49,7 @@ const EmailVerify = () => { {status === "success" && ( <> - + {t("email_verify_success_title")} {t("email_verify_success_description")} @@ -61,7 +61,7 @@ const EmailVerify = () => { {status === "error" && ( <> - + {t("email_verify_error_title")} {t("email_verify_error_description")} diff --git a/web/src/components/PasswordReset.jsx b/web/src/components/PasswordReset.jsx index c2a2613e..091a22c6 100644 --- a/web/src/components/PasswordReset.jsx +++ b/web/src/components/PasswordReset.jsx @@ -51,7 +51,7 @@ const PasswordReset = () => { return ( - + {t("reset_password_success_title")} {t("reset_password_success_description")} diff --git a/web/src/components/ResetPassword.jsx b/web/src/components/ResetPassword.jsx index 05d95e21..6b765d5f 100644 --- a/web/src/components/ResetPassword.jsx +++ b/web/src/components/ResetPassword.jsx @@ -48,7 +48,7 @@ const ResetPassword = () => { return ( - + {t("reset_password_sent_title")} {t("reset_password_sent_description")} From 1215e99098e50b09bbc2c116f2a8884e5d67d2f6 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Fri, 12 Jun 2026 23:13:01 -0400 Subject: [PATCH 07/34] Provide email during signup --- server/server_account.go | 13 ++++++++ server/server_account_email_test.go | 50 +++++++++++++++++++++++++++++ server/types.go | 1 + web/public/static/langs/en.json | 8 +++-- web/src/app/AccountApi.js | 3 +- web/src/components/Account.jsx | 15 +++++++-- web/src/components/Signup.jsx | 15 ++++++++- 7 files changed, 98 insertions(+), 7 deletions(-) diff --git a/server/server_account.go b/server/server_account.go index 214a71ba..644a9283 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -37,6 +37,9 @@ func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v * if err != nil { return err } + if newAccount.Email != "" && !emailAddressRegex.MatchString(newAccount.Email) { + return errHTTPBadRequestEmailAddressInvalid + } if existingUser, _ := s.userManager.User(newAccount.Username); existingUser != nil { return errHTTPConflictUserExists } @@ -48,6 +51,16 @@ func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v * return err } v.AccountCreated() + // If an email was provided and email sending is configured, start verification (best-effort). + // The address becomes the primary email on verify (the new account has no primary yet); a + // failure to send must not fail signup, so we only log it. + if newAccount.Email != "" && s.mailSender != nil { + if u, err := s.userManager.User(newAccount.Username); err != nil { + logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to load new user for email verification") + } else if err := s.enqueueEmailVerification(u.ID, newAccount.Email); err != nil { + logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to send signup email verification") + } + } return s.writeJSON(w, newSuccessResponse()) } diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index 38ed8d84..1b216c12 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -276,6 +276,56 @@ func TestAccount_PasswordReset_NoPrimaryEmailNoSend(t *testing.T) { }) } +func TestAccount_Signup_WithEmail_SendsVerification(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.EnableSignup = true + conf.SMTPSenderAddr = "localhost:25" + conf.SMTPSenderFrom = "noreply@example.com" + conf.BaseURL = "https://ntfy.example.com" + s := newTestServer(t, conf) + mailer := newCaptureMailer() + s.mailSender = mailer + defer s.closeDatabases() + + // Sign up with an optional email -> account created and a verification link sent + rr := request(t, s, "POST", "/v1/account", `{"username":"emma","password":"emmapass","email":"emma@example.com"}`, nil) + require.Equal(t, 200, rr.Code) + link := mailer.verifyLinks["emma@example.com"] + require.NotEmpty(t, link) + + // Verifying the link makes it the (first) primary email + token := tokenFromLink(t, link, "https://ntfy.example.com/account/email/verify/") + require.Equal(t, 200, request(t, s, "POST", "/v1/account/email/verify", fmt.Sprintf(`{"token":"%s"}`, token), nil).Code) + account := getAccount(t, s, map[string]string{"Authorization": util.BasicAuth("emma", "emmapass")}) + require.Equal(t, []string{"emma@example.com"}, verifiedAddrs(account)) + require.Equal(t, "emma@example.com", primaryAddr(account)) + }) +} + +func TestAccount_Signup_WithoutEmail_NoSend(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.EnableSignup = true + conf.SMTPSenderAddr = "localhost:25" + conf.SMTPSenderFrom = "noreply@example.com" + conf.BaseURL = "https://ntfy.example.com" + s := newTestServer(t, conf) + mailer := newCaptureMailer() + s.mailSender = mailer + defer s.closeDatabases() + + // No email -> account created, nothing sent + require.Equal(t, 200, request(t, s, "POST", "/v1/account", `{"username":"emma","password":"emmapass"}`, nil).Code) + require.Empty(t, mailer.verifyLinks) + + // Invalid email -> rejected + rr := request(t, s, "POST", "/v1/account", `{"username":"otto","password":"ottopass","email":"not-an-email"}`, nil) + require.Equal(t, 400, rr.Code) + require.Equal(t, 40050, toHTTPError(t, rr.Body.String()).Code) + }) +} + func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { hash, err := user.HashPassword("provpass") diff --git a/server/types.go b/server/types.go index 08687fbb..4b0c738d 100644 --- a/server/types.go +++ b/server/types.go @@ -185,6 +185,7 @@ type apiAccessResetRequest struct { type apiAccountCreateRequest struct { Username string `json:"username"` Password string `json:"password"` + Email string `json:"email"` // Optional; if set (and SMTP configured), a verification link is sent } type apiAccountPasswordChangeRequest struct { diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 278d6466..6b207f2d 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -16,6 +16,7 @@ "version_update_available_description": "The ntfy server has been updated. Please refresh the page.", "signup_title": "Create a ntfy account", "signup_form_username": "Username", + "signup_form_email": "Email (optional, for account recovery)", "signup_form_password": "Password", "signup_form_confirm_password": "Confirm password", "signup_form_button_submit": "Sign up", @@ -246,13 +247,16 @@ "account_basics_emails_copied_to_clipboard": "Email address copied to clipboard", "account_basics_emails_primary_badge": "Primary", "account_basics_emails_chip_actions": "Click for actions", + "account_basics_emails_chip_actions_primary": "Primary address, can be used for account recovery and notifications. Click for actions.", + "account_basics_emails_chip_actions_verified": "Can be used for notifications. Click for actions.", + "account_basics_emails_chip_actions_unverified": "Unverified address, check your inbox to verify. Click for actions.", "account_basics_emails_unverified": "unverified", "account_basics_emails_set_primary": "Set as primary email", - "account_basics_emails_delete": "Remove", + "account_basics_emails_delete": "Remove address", "account_basics_emails_cancel": "Cancel", "account_basics_emails_resend": "Resend verification email", "account_basics_emails_resent": "Verification email sent, check your inbox", - "account_basics_emails_primary_elsewhere": "This email is the primary email on another account", + "account_basics_emails_primary_elsewhere": "This email address is used as the primary address on another account", "account_basics_emails_no_recovery_warning": "Add at least one email address to ensure you can recover your account if you lose your password.", "account_basics_emails_no_primary_warning": "Add a primary email address to ensure you can recover your account if you lose your password.", "account_basics_emails_provisioned_info": "Provisioned users cannot add a primary email address, but you can still add an email address for notifications.", diff --git a/web/src/app/AccountApi.js b/web/src/app/AccountApi.js index 823eba53..10facafd 100644 --- a/web/src/app/AccountApi.js +++ b/web/src/app/AccountApi.js @@ -69,11 +69,12 @@ class AccountApi { }); } - async create(username, password) { + async create(username, password, email) { const url = accountUrl(config.base_url); const body = JSON.stringify({ username, password, + email: email || "", }); console.log(`[AccountApi] Creating user account ${url}`); await fetchOrThrow(url, { diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index 0024c70f..0134224a 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -448,7 +448,8 @@ const Emails = () => { } const emails = account?.emails ?? []; - const verifiedEmails = emails.filter((e) => !e.pending); + // Verified addresses, primary always first + const verifiedEmails = emails.filter((e) => !e.pending).sort((a, b) => (b.primary ? 1 : 0) - (a.primary ? 1 : 0)); const pendingEmails = emails.filter((e) => e.pending); const primaryEmail = verifiedEmails.find((e) => e.primary)?.address ?? ""; // Recovery nudges (skipped for provisioned users -- they can't reset, and the Add-email dialog @@ -467,7 +468,9 @@ const Emails = () => { key={email.address} icon={email.primary ? : undefined} label={ - + {email.address} } @@ -481,7 +484,7 @@ const Emails = () => { + {email.address} ({t("account_basics_emails_unverified")}) @@ -531,6 +534,12 @@ const Emails = () => { {t("account_basics_emails_resend")} )} + runMenuAction(handleDelete)}> + + + + {t("account_basics_emails_delete")} + diff --git a/web/src/components/Signup.jsx b/web/src/components/Signup.jsx index 7da54c49..cd3a3d87 100644 --- a/web/src/components/Signup.jsx +++ b/web/src/components/Signup.jsx @@ -15,6 +15,7 @@ const Signup = () => { const { t } = useTranslation(); const [error, setError] = useState(""); const [username, setUsername] = useState(""); + const [email, setEmail] = useState(""); const [password, setPassword] = useState(""); const [confirm, setConfirm] = useState(""); const [showPassword, setShowPassword] = useState(false); @@ -24,7 +25,7 @@ const Signup = () => { event.preventDefault(); const user = { username, password }; try { - await accountApi.create(user.username, user.password); + await accountApi.create(user.username, user.password, email); const token = await accountApi.login(user); console.log(`[Signup] User signup for user ${user.username} successful, token is ${token}`); await session.store(user.username, token); @@ -64,6 +65,18 @@ const Signup = () => { onChange={(ev) => setUsername(ev.target.value.trim())} autoFocus /> + {config.enable_emails && ( + setEmail(ev.target.value.trim())} + /> + )} Date: Fri, 12 Jun 2026 23:22:37 -0400 Subject: [PATCH 08/34] Make chips look better --- web/src/components/Account.jsx | 111 +++++++++++++++++---------------- 1 file changed, 58 insertions(+), 53 deletions(-) diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index 0134224a..016d97e4 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -2,6 +2,7 @@ import * as React from "react"; import { useContext, useState } from "react"; import { Alert, + Box, CardActions, CardContent, Chip, @@ -463,43 +464,45 @@ const Emails = () => { return (
- {verifiedEmails.map((email) => ( - : undefined} - label={ - - {email.address} - - } - variant="outlined" - onClick={(ev) => openMenu(ev, email)} - onDelete={() => handleDelete(email.address)} - sx={email.primary ? { "& .MuiChip-icon": { color: "#fbc02d" } } : undefined} - /> - ))} - {pendingEmails.map((email) => ( - - - {email.address} ({t("account_basics_emails_unverified")}) - - - } - variant="outlined" - onClick={(ev) => openMenu(ev, email)} - onDelete={() => handleDelete(email.address)} - sx={{ opacity: 0.7 }} - /> - ))} - {verifiedEmails.length === 0 && pendingEmails.length === 0 && {t("account_basics_emails_no_emails_yet")}} - - - + + {verifiedEmails.map((email) => ( + : undefined} + label={ + + {email.address} + + } + variant="outlined" + onClick={(ev) => openMenu(ev, email)} + onDelete={() => handleDelete(email.address)} + sx={email.primary ? { "& .MuiChip-icon": { color: "#fbc02d" } } : undefined} + /> + ))} + {pendingEmails.map((email) => ( + + + {email.address} ({t("account_basics_emails_unverified")}) + + + } + variant="outlined" + onClick={(ev) => openMenu(ev, email)} + onDelete={() => handleDelete(email.address)} + sx={{ opacity: 0.7 }} + /> + ))} + {verifiedEmails.length === 0 && pendingEmails.length === 0 && {t("account_basics_emails_no_emails_yet")}} + + + + {showNoEmailWarning && ( {t("account_basics_emails_no_recovery_warning")} @@ -680,22 +683,24 @@ const PhoneNumbers = () => { return (
- {account?.phone_numbers?.map((phoneNumber) => ( - - {phoneNumber} - - } - variant="outlined" - onClick={() => handleCopy(phoneNumber)} - onDelete={() => handleDelete(phoneNumber)} - /> - ))} - {!account?.phone_numbers && {t("account_basics_phone_numbers_no_phone_numbers_yet")}} - - - + + {account?.phone_numbers?.map((phoneNumber) => ( + + {phoneNumber} + + } + variant="outlined" + onClick={() => handleCopy(phoneNumber)} + onDelete={() => handleDelete(phoneNumber)} + /> + ))} + {!account?.phone_numbers && {t("account_basics_phone_numbers_no_phone_numbers_yet")}} + + + +
From eff808d0f8a130d01dc12d5dc09ecde90e2e8acd Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 13 Jun 2026 09:35:09 -0400 Subject: [PATCH 09/34] Lint --- cmd/user.go | 3 - cmd/user_test.go | 4 +- user/magic_link_test.go | 360 ---------------------------------------- user/manager_test.go | 352 +++++++++++++++++++++++++++++++++++++++ 4 files changed, 354 insertions(+), 365 deletions(-) delete mode 100644 user/magic_link_test.go diff --git a/cmd/user.go b/cmd/user.go index 8c65221d..d9d5b0fc 100644 --- a/cmd/user.go +++ b/cmd/user.go @@ -126,8 +126,6 @@ does not require the user to have a verified primary email (the token is bound t With --send-email, the link is additionally emailed to the user's primary email address (this requires SMTP to be configured and the user to have a verified primary email). -Requires base-url to be configured so an absolute link can be generated. - Example: ntfy user reset-pass phil # Print a reset link for user phil ntfy user reset-pass --send-email phil # Print and email the reset link @@ -290,7 +288,6 @@ func execUserDel(c *cli.Context) error { func execUserChangePass(c *cli.Context) error { username := c.Args().Get(0) password, hashed := os.LookupEnv("NTFY_PASSWORD_HASH") - if !hashed { password = os.Getenv("NTFY_PASSWORD") } diff --git a/cmd/user_test.go b/cmd/user_test.go index c5e1c44c..bde0fa1f 100644 --- a/cmd/user_test.go +++ b/cmd/user_test.go @@ -126,12 +126,12 @@ func TestCLI_User_ResetPass(t *testing.T) { s, conf, port := newTestServerWithAuth(t) defer test.StopServer(t, s, port) - app, stdin, stdout, _ := newTestApp() + app, stdin, _, _ := newTestApp() stdin.WriteString("mypass\nmypass") require.Nil(t, runUserCommand(app, conf, "add", "phil")) // Prints a working-looking reset link when base-url is set - app, _, stdout, _ = newTestApp() + app, _, stdout, _ := newTestApp() require.Nil(t, runUserCommand(app, conf, "--base-url=https://ntfy.example.com", "reset-pass", "phil")) require.Contains(t, stdout.String(), "https://ntfy.example.com/account/password/reset/") } diff --git a/user/magic_link_test.go b/user/magic_link_test.go deleted file mode 100644 index 4a2506c4..00000000 --- a/user/magic_link_test.go +++ /dev/null @@ -1,360 +0,0 @@ -package user - -import ( - "testing" - "time" - - "github.com/stretchr/testify/require" -) - -// addVerifyLink stores an email-verification magic link and returns the raw token so the test -// can "click" it via VerifyEmail. -func addVerifyLink(t *testing.T, a *Manager, userID, email string, ttl time.Duration) string { - raw, err := a.CreateMagicLink(MagicLinkKindEmailVerify, userID, email, ttl) - require.Nil(t, err) - return raw -} - -func TestUser_MagicLink_VerifyEmail_SetsPrimary(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) - - // Before verifying: pending, not yet verified, no primary - pending, err := a.PendingEmails(phil.ID) - require.Nil(t, err) - require.Equal(t, []string{"phil@example.com"}, pending) - emails, err := a.Emails(phil.ID) - require.Nil(t, err) - require.Equal(t, 0, len(emails)) - primary, err := a.PrimaryEmail(phil.ID) - require.Nil(t, err) - require.Equal(t, "", primary) - - // Verify: the first verified email auto-becomes primary - m, err := a.VerifyEmail(raw) - require.Nil(t, err) - require.Equal(t, "phil@example.com", m.Email) - - emails, err = a.Emails(phil.ID) - require.Nil(t, err) - require.Equal(t, []string{"phil@example.com"}, emails) - primary, err = a.PrimaryEmail(phil.ID) - require.Nil(t, err) - require.Equal(t, "phil@example.com", primary) - pending, err = a.PendingEmails(phil.ID) - require.Nil(t, err) - require.Equal(t, 0, len(pending)) - - // Reset-by-email lookup resolves to the account - userID, err := a.UserIDByPrimaryEmail("phil@example.com") - require.Nil(t, err) - require.Equal(t, phil.ID, userID) - }) -} - -func TestUser_MagicLink_VerifyEmail_SecondStaysSecondary(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw1 := addVerifyLink(t, a, phil.ID, "first@example.com", 24*time.Hour) - _, err = a.VerifyEmail(raw1) - require.Nil(t, err) - - raw2 := addVerifyLink(t, a, phil.ID, "second@example.com", 24*time.Hour) - _, err = a.VerifyEmail(raw2) - require.Nil(t, err) - - // Both verified, but primary is still the first - emails, err := a.Emails(phil.ID) - require.Nil(t, err) - require.Equal(t, []string{"first@example.com", "second@example.com"}, emails) - primary, err := a.PrimaryEmail(phil.ID) - require.Nil(t, err) - require.Equal(t, "first@example.com", primary) - }) -} - -func TestUser_MagicLink_PrimaryGlobalUniqueness(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - require.Nil(t, a.AddUser("ben", "ben", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - ben, err := a.User("ben") - require.Nil(t, err) - - // phil verifies shared@ first -> becomes his primary - _, err = a.VerifyEmail(addVerifyLink(t, a, phil.ID, "shared@example.com", 24*time.Hour)) - require.Nil(t, err) - primary, err := a.PrimaryEmail(phil.ID) - require.Nil(t, err) - require.Equal(t, "shared@example.com", primary) - - // ben verifies the same address -> allowed as secondary, but NOT his primary - _, err = a.VerifyEmail(addVerifyLink(t, a, ben.ID, "shared@example.com", 24*time.Hour)) - require.Nil(t, err) - emails, err := a.Emails(ben.ID) - require.Nil(t, err) - require.Equal(t, []string{"shared@example.com"}, emails) - primary, err = a.PrimaryEmail(ben.ID) - require.Nil(t, err) - require.Equal(t, "", primary) - - // Explicitly promoting ben's copy to primary collides with phil's - require.ErrorIs(t, a.SetPrimaryEmail(ben.ID, "shared@example.com"), ErrEmailPrimaryElsewhere) - // ...and phil keeps his primary (the failed promotion rolled back ben's clear) - primary, err = a.PrimaryEmail(phil.ID) - require.Nil(t, err) - require.Equal(t, "shared@example.com", primary) - }) -} - -func TestUser_MagicLink_SetPrimary_NotVerified(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - require.ErrorIs(t, a.SetPrimaryEmail(phil.ID, "nope@example.com"), ErrEmailNotFound) - }) -} - -func TestUser_MagicLink_Expired(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw := addVerifyLink(t, a, phil.ID, "phil@example.com", -time.Minute) - _, err = a.VerifyEmail(raw) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - - // Nothing got verified - emails, err := a.Emails(phil.ID) - require.Nil(t, err) - require.Equal(t, 0, len(emails)) - }) -} - -func TestUser_MagicLink_SingleUse(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) - _, err = a.VerifyEmail(raw) - require.Nil(t, err) - // Second click: token already consumed - _, err = a.VerifyEmail(raw) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - }) -} - -func TestUser_MagicLink_ReplaceOnReRequest(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw1 := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) - raw2 := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) - - // Only one pending row remains; the old token no longer works - pending, err := a.PendingEmails(phil.ID) - require.Nil(t, err) - require.Equal(t, []string{"phil@example.com"}, pending) - _, err = a.MagicLinkByToken(raw1) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - - m, err := a.MagicLinkByToken(raw2) - require.Nil(t, err) - require.Equal(t, "phil@example.com", m.Email) - }) -} - -func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) - require.Nil(t, err) - - m, err := a.MagicLinkByToken(raw) - require.Nil(t, err) - require.Equal(t, MagicLinkKindPasswordReset, m.Kind) - require.Equal(t, phil.ID, m.UserID) - require.Equal(t, "", m.Email) // reset rows carry no email - - // Reset rows do not appear as pending emails - pending, err := a.PendingEmails(phil.ID) - require.Nil(t, err) - require.Equal(t, 0, len(pending)) - - // New request replaces the old token - raw2, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) - require.Nil(t, err) - _, err = a.MagicLinkByToken(raw) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - - // Single use: deleting consumes it - require.Nil(t, a.DeleteMagicLinkByToken(raw2)) - _, err = a.MagicLinkByToken(raw2) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - }) -} - -func TestUser_MagicLink_Reaper(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - expired := addVerifyLink(t, a, phil.ID, "expired@example.com", -time.Hour) - valid := addVerifyLink(t, a, phil.ID, "valid@example.com", time.Hour) - - require.Nil(t, a.deleteExpiredMagicLinks()) - - _, err = a.MagicLinkByToken(expired) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - m, err := a.MagicLinkByToken(valid) - require.Nil(t, err) - require.Equal(t, "valid@example.com", m.Email) - }) -} - -func TestUser_MagicLink_ResetPassword(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) - require.Nil(t, err) - - // Old password works before reset - _, err = a.Authenticate("phil", "oldpass") - require.Nil(t, err) - - require.Nil(t, a.ResetPassword(raw, "newpass")) - - // New password works, old does not - _, err = a.Authenticate("phil", "newpass") - require.Nil(t, err) - _, err = a.Authenticate("phil", "oldpass") - require.ErrorIs(t, err, ErrUnauthenticated) - - // Token is single-use - require.ErrorIs(t, a.ResetPassword(raw, "againpass"), ErrMagicLinkNotFound) - }) -} - -func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - // An email-verification token must not be usable for password reset... - verifyToken := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Hour) - require.ErrorIs(t, a.ResetPassword(verifyToken, "newpass"), ErrMagicLinkNotFound) - - // ...and a reset token must not be usable for email verification - resetToken, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) - require.Nil(t, err) - _, err = a.VerifyEmail(resetToken) - require.ErrorIs(t, err, ErrMagicLinkNotFound) - - // Old password unchanged - _, err = a.Authenticate("phil", "oldpass") - require.Nil(t, err) - }) -} - -func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManagerFromConfig(t, newManager, &Config{ - DefaultAccess: PermissionDenyAll, - ProvisionEnabled: true, - Users: []*User{ - {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: RoleUser}, - }, - }) - prov, err := a.User("prov") - require.Nil(t, err) - - // A provisioned user can verify an email (for notifications), but it must NOT become primary - _, err = a.VerifyEmail(addVerifyLink(t, a, prov.ID, "prov@example.com", time.Hour)) - require.Nil(t, err) - - emails, err := a.Emails(prov.ID) - require.Nil(t, err) - require.Equal(t, []string{"prov@example.com"}, emails) - primary, err := a.PrimaryEmail(prov.ID) - require.Nil(t, err) - require.Equal(t, "", primary) - }) -} - -func TestUser_MagicLink_ResetPassword_ProvisionedRejected(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - // Provisioned users come from the config file (ProvisionEnabled), not AddUser - a := newTestManagerFromConfig(t, newManager, &Config{ - DefaultAccess: PermissionDenyAll, - ProvisionEnabled: true, - Users: []*User{ - {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: RoleUser}, - }, - }) - prov, err := a.User("prov") - require.Nil(t, err) - require.True(t, prov.Provisioned) - - // A reset token can be created, but consuming it must be rejected for a provisioned user - // (their password comes from the config file, like change-pass). - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, prov.ID, "", time.Hour) - require.Nil(t, err) - require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrProvisionedUserChange) - }) -} - -func TestUser_MagicLink_ResetPassword_Expired(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) - phil, err := a.User("phil") - require.Nil(t, err) - - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", -time.Minute) - require.Nil(t, err) - require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrMagicLinkNotFound) - _, err = a.Authenticate("phil", "oldpass") - require.Nil(t, err) - }) -} - -func TestUser_MagicLink_UserIDByPrimaryEmail_NotFound(t *testing.T) { - forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { - a := newTestManager(t, newManager, PermissionDenyAll) - _, err := a.UserIDByPrimaryEmail("ghost@example.com") - require.ErrorIs(t, err, ErrUserNotFound) - }) -} diff --git a/user/manager_test.go b/user/manager_test.go index 7e05f5db..6bc0bccd 100644 --- a/user/manager_test.go +++ b/user/manager_test.go @@ -2897,3 +2897,355 @@ func TestStoreOtherAccessCount(t *testing.T) { require.Equal(t, 2, count) // ben's owner entry + everyone entry }) } + +// addVerifyLink stores an email-verification magic link and returns the raw token so the test +// can "click" it via VerifyEmail. +func addVerifyLink(t *testing.T, a *Manager, userID, email string, ttl time.Duration) string { + raw, err := a.CreateMagicLink(MagicLinkKindEmailVerify, userID, email, ttl) + require.Nil(t, err) + return raw +} + +func TestUser_MagicLink_VerifyEmail_SetsPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) + + // Before verifying: pending, not yet verified, no primary + pending, err := a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"phil@example.com"}, pending) + emails, err := a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(emails)) + primary, err := a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "", primary) + + // Verify: the first verified email auto-becomes primary + m, err := a.VerifyEmail(raw) + require.Nil(t, err) + require.Equal(t, "phil@example.com", m.Email) + + emails, err = a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"phil@example.com"}, emails) + primary, err = a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "phil@example.com", primary) + pending, err = a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(pending)) + + // Reset-by-email lookup resolves to the account + userID, err := a.UserIDByPrimaryEmail("phil@example.com") + require.Nil(t, err) + require.Equal(t, phil.ID, userID) + }) +} + +func TestUser_MagicLink_VerifyEmail_SecondStaysSecondary(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw1 := addVerifyLink(t, a, phil.ID, "first@example.com", 24*time.Hour) + _, err = a.VerifyEmail(raw1) + require.Nil(t, err) + + raw2 := addVerifyLink(t, a, phil.ID, "second@example.com", 24*time.Hour) + _, err = a.VerifyEmail(raw2) + require.Nil(t, err) + + // Both verified, but primary is still the first + emails, err := a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"first@example.com", "second@example.com"}, emails) + primary, err := a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "first@example.com", primary) + }) +} + +func TestUser_MagicLink_PrimaryGlobalUniqueness(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + require.Nil(t, a.AddUser("ben", "ben", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + ben, err := a.User("ben") + require.Nil(t, err) + + // phil verifies shared@ first -> becomes his primary + _, err = a.VerifyEmail(addVerifyLink(t, a, phil.ID, "shared@example.com", 24*time.Hour)) + require.Nil(t, err) + primary, err := a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "shared@example.com", primary) + + // ben verifies the same address -> allowed as secondary, but NOT his primary + _, err = a.VerifyEmail(addVerifyLink(t, a, ben.ID, "shared@example.com", 24*time.Hour)) + require.Nil(t, err) + emails, err := a.Emails(ben.ID) + require.Nil(t, err) + require.Equal(t, []string{"shared@example.com"}, emails) + primary, err = a.PrimaryEmail(ben.ID) + require.Nil(t, err) + require.Equal(t, "", primary) + + // Explicitly promoting ben's copy to primary collides with phil's + require.ErrorIs(t, a.SetPrimaryEmail(ben.ID, "shared@example.com"), ErrEmailPrimaryElsewhere) + // ...and phil keeps his primary (the failed promotion rolled back ben's clear) + primary, err = a.PrimaryEmail(phil.ID) + require.Nil(t, err) + require.Equal(t, "shared@example.com", primary) + }) +} + +func TestUser_MagicLink_SetPrimary_NotVerified(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + require.ErrorIs(t, a.SetPrimaryEmail(phil.ID, "nope@example.com"), ErrEmailNotFound) + }) +} + +func TestUser_MagicLink_Expired(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", -time.Minute) + _, err = a.VerifyEmail(raw) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + // Nothing got verified + emails, err := a.Emails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(emails)) + }) +} + +func TestUser_MagicLink_SingleUse(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) + _, err = a.VerifyEmail(raw) + require.Nil(t, err) + // Second click: token already consumed + _, err = a.VerifyEmail(raw) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + }) +} + +func TestUser_MagicLink_ReplaceOnReRequest(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw1 := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) + raw2 := addVerifyLink(t, a, phil.ID, "phil@example.com", 24*time.Hour) + + // Only one pending row remains; the old token no longer works + pending, err := a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, []string{"phil@example.com"}, pending) + _, err = a.MagicLinkByToken(raw1) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + m, err := a.MagicLinkByToken(raw2) + require.Nil(t, err) + require.Equal(t, "phil@example.com", m.Email) + }) +} + +func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + + m, err := a.MagicLinkByToken(raw) + require.Nil(t, err) + require.Equal(t, MagicLinkKindPasswordReset, m.Kind) + require.Equal(t, phil.ID, m.UserID) + require.Equal(t, "", m.Email) // reset rows carry no email + + // Reset rows do not appear as pending emails + pending, err := a.PendingEmails(phil.ID) + require.Nil(t, err) + require.Equal(t, 0, len(pending)) + + // New request replaces the old token + raw2, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + _, err = a.MagicLinkByToken(raw) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + // Single use: deleting consumes it + require.Nil(t, a.DeleteMagicLinkByToken(raw2)) + _, err = a.MagicLinkByToken(raw2) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + }) +} + +func TestUser_MagicLink_Reaper(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + expired := addVerifyLink(t, a, phil.ID, "expired@example.com", -time.Hour) + valid := addVerifyLink(t, a, phil.ID, "valid@example.com", time.Hour) + + require.Nil(t, a.deleteExpiredMagicLinks()) + + _, err = a.MagicLinkByToken(expired) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + m, err := a.MagicLinkByToken(valid) + require.Nil(t, err) + require.Equal(t, "valid@example.com", m.Email) + }) +} + +func TestUser_MagicLink_ResetPassword(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + + // Old password works before reset + _, err = a.Authenticate("phil", "oldpass") + require.Nil(t, err) + + require.Nil(t, a.ResetPassword(raw, "newpass")) + + // New password works, old does not + _, err = a.Authenticate("phil", "newpass") + require.Nil(t, err) + _, err = a.Authenticate("phil", "oldpass") + require.ErrorIs(t, err, ErrUnauthenticated) + + // Token is single-use + require.ErrorIs(t, a.ResetPassword(raw, "againpass"), ErrMagicLinkNotFound) + }) +} + +func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + // An email-verification token must not be usable for password reset... + verifyToken := addVerifyLink(t, a, phil.ID, "phil@example.com", time.Hour) + require.ErrorIs(t, a.ResetPassword(verifyToken, "newpass"), ErrMagicLinkNotFound) + + // ...and a reset token must not be usable for email verification + resetToken, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + require.Nil(t, err) + _, err = a.VerifyEmail(resetToken) + require.ErrorIs(t, err, ErrMagicLinkNotFound) + + // Old password unchanged + _, err = a.Authenticate("phil", "oldpass") + require.Nil(t, err) + }) +} + +func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManagerFromConfig(t, newManager, &Config{ + DefaultAccess: PermissionDenyAll, + ProvisionEnabled: true, + Users: []*User{ + {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: RoleUser}, + }, + }) + prov, err := a.User("prov") + require.Nil(t, err) + + // A provisioned user can verify an email (for notifications), but it must NOT become primary + _, err = a.VerifyEmail(addVerifyLink(t, a, prov.ID, "prov@example.com", time.Hour)) + require.Nil(t, err) + + emails, err := a.Emails(prov.ID) + require.Nil(t, err) + require.Equal(t, []string{"prov@example.com"}, emails) + primary, err := a.PrimaryEmail(prov.ID) + require.Nil(t, err) + require.Equal(t, "", primary) + }) +} + +func TestUser_MagicLink_ResetPassword_ProvisionedRejected(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + // Provisioned users come from the config file (ProvisionEnabled), not AddUser + a := newTestManagerFromConfig(t, newManager, &Config{ + DefaultAccess: PermissionDenyAll, + ProvisionEnabled: true, + Users: []*User{ + {Name: "prov", Hash: "$2a$10$YLiO8U21sX1uhZamTLJXHuxgVC0Z/GKISibrKCLohPgtG7yIxSk4C", Role: RoleUser}, + }, + }) + prov, err := a.User("prov") + require.Nil(t, err) + require.True(t, prov.Provisioned) + + // A reset token can be created, but consuming it must be rejected for a provisioned user + // (their password comes from the config file, like change-pass). + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, prov.ID, "", time.Hour) + require.Nil(t, err) + require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrProvisionedUserChange) + }) +} + +func TestUser_MagicLink_ResetPassword_Expired(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + require.Nil(t, a.AddUser("phil", "oldpass", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", -time.Minute) + require.Nil(t, err) + require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrMagicLinkNotFound) + _, err = a.Authenticate("phil", "oldpass") + require.Nil(t, err) + }) +} + +func TestUser_MagicLink_UserIDByPrimaryEmail_NotFound(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManager(t, newManager, PermissionDenyAll) + _, err := a.UserIDByPrimaryEmail("ghost@example.com") + require.ErrorIs(t, err, ErrUserNotFound) + }) +} From 9fa8550ef67bf59c77f32a94d6756713c90a6dc4 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 13 Jun 2026 13:42:32 -0400 Subject: [PATCH 10/34] Remove Close() on Sender; words on password dialog --- mail/sender.go | 6 ------ server/errors.go | 2 +- server/server.go | 3 --- server/server_account.go | 4 ++-- server/server_account_email_test.go | 2 -- server/smtp_sender.go | 1 - web/public/static/langs/en.json | 2 +- 7 files changed, 4 insertions(+), 16 deletions(-) diff --git a/mail/sender.go b/mail/sender.go index b840adf1..3215c332 100644 --- a/mail/sender.go +++ b/mail/sender.go @@ -36,12 +36,6 @@ func NewSender(config *Config) *Sender { return &Sender{config: config} } -// Close is a no-op, kept so callers don't need to special-case the sender. The sender holds -// no background goroutines (magic-link expiry is swept by the user.Manager reaper). -func (s *Sender) Close() { - // Nothing to do -} - // Addr returns the SMTP server address func (s *Sender) Addr() string { return s.config.SMTPAddr diff --git a/server/errors.go b/server/errors.go index d204aa53..6a7bd769 100644 --- a/server/errors.go +++ b/server/errors.go @@ -143,7 +143,7 @@ var ( errHTTPBadRequestTemplateFileInvalid = &errHTTP{40048, http.StatusBadRequest, "invalid request: template file invalid", "https://ntfy.sh/docs/publish/#message-templating", nil} errHTTPBadRequestSequenceIDInvalid = &errHTTP{40049, http.StatusBadRequest, "invalid request: sequence ID invalid", "https://ntfy.sh/docs/publish/#updating-deleting-notifications", nil} errHTTPBadRequestEmailAddressInvalid = &errHTTP{40050, http.StatusBadRequest, "invalid request: invalid e-mail address", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} - errHTTPBadRequestEmailVerificationCodeInvalid = &errHTTP{40051, http.StatusBadRequest, "invalid request: email verification link invalid or expired", "", nil} + errHTTPBadRequestEmailVerificationLinkInvalid = &errHTTP{40051, http.StatusBadRequest, "invalid request: email verification link invalid or expired", "", nil} errHTTPBadRequestEmailAddressNotVerified = &errHTTP{40052, http.StatusBadRequest, "invalid request: email address not verified", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} errHTTPBadRequestAnonymousEmailNotAllowed = &errHTTP{40053, http.StatusBadRequest, "invalid request: anonymous email sending is not allowed", "https://ntfy.sh/docs/publish/#e-mail-notifications", nil} errHTTPBadRequestResetLinkInvalid = &errHTTP{40054, http.StatusBadRequest, "invalid request: password reset link invalid or expired", "", nil} diff --git a/server/server.go b/server/server.go index 3184478a..4cbc7984 100644 --- a/server/server.go +++ b/server/server.go @@ -452,9 +452,6 @@ func (s *Server) Stop() { if s.smtpServer != nil { s.smtpServer.Close() } - if s.mailSender != nil { - s.mailSender.Close() - } if s.attachment != nil { s.attachment.Close() } diff --git a/server/server_account.go b/server/server_account.go index 644a9283..621fe63b 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -690,11 +690,11 @@ func (s *Server) handleAccountEmailVerify(w http.ResponseWriter, r *http.Request if err != nil { return err } else if req.Token == "" { - return errHTTPBadRequestEmailVerificationCodeInvalid + return errHTTPBadRequestEmailVerificationLinkInvalid } m, err := s.userManager.VerifyEmail(req.Token) if errors.Is(err, user.ErrMagicLinkNotFound) { - return errHTTPBadRequestEmailVerificationCodeInvalid + return errHTTPBadRequestEmailVerificationLinkInvalid } else if err != nil { return err } diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index 1b216c12..eb66ba2c 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -32,8 +32,6 @@ func (c *captureMailer) SendPasswordReset(to, link string) error { return nil } -func (c *captureMailer) Close() {} - // newEmailTestServer creates a server with email sending "enabled" (SMTP + base-url configured) // and a capturing mailer injected, plus a tier-less user "ben" logged in via basic auth. func newEmailTestServer(t *testing.T, databaseURL string) (*Server, *captureMailer, map[string]string) { diff --git a/server/smtp_sender.go b/server/smtp_sender.go index 1e7460e8..199cecd9 100644 --- a/server/smtp_sender.go +++ b/server/smtp_sender.go @@ -25,7 +25,6 @@ type mailer interface { type emailVerifier interface { SendEmailVerification(to, link string) error SendPasswordReset(to, link string) error - Close() } type smtpSender struct { diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 6b207f2d..e8926227 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -30,7 +30,7 @@ "login_link_signup": "Sign up", "login_link_forgot_password": "Forgot password?", "reset_password_request_title": "Reset password", - "reset_password_request_description": "Enter your username or email address. If an account exists, a link to reset your password will be emailed.", + "reset_password_request_description": "Enter your username or email address. If an account exists, a link to reset your password will be emailed. This only works if you already added a primary email address and verified it.", "reset_password_request_identifier_label": "Username or email", "reset_password_request_button_submit": "Send reset link", "reset_password_sent_title": "Check your inbox", From fc59339f86445728b847248bbe7b19a6bfb0f6d5 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 15 Jun 2026 21:47:09 -0400 Subject: [PATCH 11/34] Rename --- server/server.go | 94 ++++++++++++++-------------- server/server_account.go | 8 +-- server/server_account_email_test.go | 12 ++-- server/server_account_test.go | 2 +- server/server_manager.go | 4 +- server/server_middleware.go | 2 +- server/server_payments.go | 2 +- server/server_payments_email_test.go | 2 +- server/server_test.go | 26 ++++---- server/smtp_sender.go | 18 +++--- 10 files changed, 87 insertions(+), 83 deletions(-) diff --git a/server/server.go b/server/server.go index 4cbc7984..ade5aebe 100644 --- a/server/server.go +++ b/server/server.go @@ -48,31 +48,31 @@ import ( // Server is the main server, providing the UI and API for ntfy type Server struct { - config *Config - db *db.DB // Shared PostgreSQL connection pool (with optional replicas), nil when using SQLite - httpServer *http.Server - httpsServer *http.Server - httpMetricsServer *http.Server - httpProfileServer *http.Server - unixListener net.Listener - smtpServer *smtp.Server - smtpServerBackend *smtpBackend - smtpSender mailer - mailSender emailVerifier - topics map[string]*topic - visitors map[string]*visitor // ip: or user: - firebaseClient *firebaseClient - messages int64 // Total number of messages (persisted if messageCache enabled) - messagesHistory []int64 // Last n values of the messages counter, used to determine rate - userManager *user.Manager // Might be nil! - messageCache *message.Cache // Database that stores the messages - webPush *webpush.Store // Database that stores web push subscriptions - attachment *attachment.Store // Attachment store (file system or S3) - stripe stripeAPI // Stripe API, can be replaced with a mock - priceCache *util.LookupCache[map[string]int64] // Stripe price ID -> price as cents (USD implied!) - metricsHandler http.Handler // Handles /metrics if enable-metrics set, and listen-metrics-http not set - closeChan chan bool - mu sync.RWMutex + config *Config + db *db.DB // Shared PostgreSQL connection pool (with optional replicas), nil when using SQLite + httpServer *http.Server + httpsServer *http.Server + httpMetricsServer *http.Server + httpProfileServer *http.Server + unixListener net.Listener + smtpServer *smtp.Server + smtpServerBackend *smtpBackend + notificationMailer messageMailer + accountMailer magicLinkMailer + topics map[string]*topic + visitors map[string]*visitor // ip: or user: + firebaseClient *firebaseClient + messages int64 // Total number of messages (persisted if messageCache enabled) + messagesHistory []int64 // Last n values of the messages counter, used to determine rate + userManager *user.Manager // Might be nil! + messageCache *message.Cache // Database that stores the messages + webPush *webpush.Store // Database that stores web push subscriptions + attachment *attachment.Store // Attachment store (file system or S3) + stripe stripeAPI // Stripe API, can be replaced with a mock + priceCache *util.LookupCache[map[string]int64] // Stripe price ID -> price as cents (USD implied!) + metricsHandler http.Handler // Handles /metrics if enable-metrics set, and listen-metrics-http not set + closeChan chan bool + mu sync.RWMutex } // handleFunc extends the normal http.HandlerFunc to be able to easily return errors @@ -184,17 +184,17 @@ const ( // New instantiates a new Server. It creates the cache and adds a Firebase // subscriber (if configured). func New(conf *Config) (*Server, error) { - var mailer mailer - var emailSender emailVerifier // Stays untyped-nil when SMTP is unconfigured, so ensureEmailsEnabled gates correctly + var notificationMailer messageMailer + var accountEmailer magicLinkMailer // Stays untyped-nil when SMTP is unconfigured, so ensureEmailsEnabled gates correctly if conf.SMTPSenderAddr != "" { - mailSender := mail.NewSender(&mail.Config{ + sender := mail.NewSender(&mail.Config{ SMTPAddr: conf.SMTPSenderAddr, SMTPUser: conf.SMTPSenderUser, SMTPPass: conf.SMTPSenderPass, From: conf.SMTPSenderFrom, }) - mailer = &smtpSender{config: conf, sender: mailSender} - emailSender = mailSender + notificationMailer = ¬ificationSender{config: conf, sender: sender} + accountEmailer = sender } var stripe stripeAPI if payments.Available && conf.StripeSecretKey != "" { @@ -293,20 +293,20 @@ func New(conf *Config) (*Server, error) { firebaseClient = newFirebaseClient(sender, auther) } s := &Server{ - config: conf, - db: pool, - messageCache: messageCache, - webPush: wp, - attachment: attachmentStore, - firebaseClient: firebaseClient, - smtpSender: mailer, - mailSender: emailSender, - topics: topics, - userManager: userManager, - messages: messages, - messagesHistory: []int64{messages}, - visitors: make(map[string]*visitor), - stripe: stripe, + config: conf, + db: pool, + messageCache: messageCache, + webPush: wp, + attachment: attachmentStore, + firebaseClient: firebaseClient, + notificationMailer: notificationMailer, + accountMailer: accountEmailer, + topics: topics, + userManager: userManager, + messages: messages, + messagesHistory: []int64{messages}, + visitors: make(map[string]*visitor), + stripe: stripe, } s.priceCache = util.NewLookupCache(s.fetchStripePrices, conf.StripePriceCacheDuration) return s, nil @@ -974,7 +974,7 @@ func (s *Server) handlePublishInternal(r *http.Request, v *visitor) (*model.Mess if s.firebaseClient != nil && firebase { go s.sendToFirebase(v, m) } - if s.smtpSender != nil && email != "" { + if s.notificationMailer != nil && email != "" { go s.sendEmail(v, m, email) } if s.config.TwilioAccount != "" && call != "" { @@ -1136,7 +1136,7 @@ func (s *Server) sendToFirebase(v *visitor, m *model.Message) { func (s *Server) sendEmail(v *visitor, m *model.Message, email string) { logvm(v, m).Tag(tagEmail).Field("email", email).Info("Sending email to %s", email) - if err := s.smtpSender.Send(v, m, email); err != nil { + if err := s.notificationMailer.Send(v, m, email); err != nil { logvm(v, m).Tag(tagEmail).Field("email", email).Err(err).Warn("Unable to send email to %s: %v", email, err.Error()) minc(metricEmailsPublishedFailure) return @@ -1236,7 +1236,7 @@ func (s *Server) parsePublishParams(r *http.Request, m *model.Message) (cache bo if email != "" && !emailAddressRegex.MatchString(email) && !toBool(email) { return false, false, "", "", "", false, "", errHTTPBadRequestEmailAddressInvalid } - if s.smtpSender == nil && email != "" { + if s.notificationMailer == nil && email != "" { return false, false, "", "", "", false, "", errHTTPBadRequestEmailDisabled } call = readParam(r, "x-call", "call") diff --git a/server/server_account.go b/server/server_account.go index 621fe63b..79c43866 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -54,7 +54,7 @@ func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v * // If an email was provided and email sending is configured, start verification (best-effort). // The address becomes the primary email on verify (the new account has no primary yet); a // failure to send must not fail signup, so we only log it. - if newAccount.Email != "" && s.mailSender != nil { + if newAccount.Email != "" && s.accountMailer != nil { if u, err := s.userManager.User(newAccount.Username); err != nil { logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to load new user for email verification") } else if err := s.enqueueEmailVerification(u.ID, newAccount.Email); err != nil { @@ -175,7 +175,7 @@ func (s *Server) handleAccountGet(w http.ResponseWriter, r *http.Request, v *vis response.PhoneNumbers = phoneNumbers } } - if s.mailSender != nil { + if s.accountMailer != nil { emails, err := s.userManager.Emails(u.ID) if err != nil { return err @@ -788,7 +788,7 @@ func (s *Server) enqueueEmailVerification(userID, email string) error { return err } link := s.config.BaseURL + webAppEmailVerifyPathPrefix + token - return s.mailSender.SendEmailVerification(email, link) + return s.accountMailer.SendEmailVerification(email, link) } // handleAccountPasswordResetRequest starts a password reset (POST /v1/account/password/reset/request, @@ -814,7 +814,7 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt } else { link := s.config.BaseURL + webAppPasswordResetPathPrefix + token logvr(v, r).Tag(tagAccount).Field("user_id", userID).Info("Sending password reset link") - if err := s.mailSender.SendPasswordReset(email, link); err != nil { + if err := s.accountMailer.SendPasswordReset(email, link); err != nil { logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to send password reset email") } } diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index eb66ba2c..f2ca2d3a 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -11,7 +11,7 @@ import ( "heckel.io/ntfy/v2/util" ) -// captureMailer is a fake emailVerifier that records the magic links it is asked to send, so +// captureMailer is a fake magicLinkMailer that records the magic links it is asked to send, so // tests can "click" them without a real SMTP server. type captureMailer struct { verifyLinks map[string]string // email -> verification link @@ -41,7 +41,7 @@ func newEmailTestServer(t *testing.T, databaseURL string) (*Server, *captureMail conf.BaseURL = "https://ntfy.example.com" s := newTestServer(t, conf) mailer := newCaptureMailer() - s.mailSender = mailer + s.accountMailer = mailer require.Nil(t, s.userManager.AddUser("ben", "ben", user.RoleUser, false)) auth := map[string]string{"Authorization": util.BasicAuth("ben", "ben")} return s, mailer, auth @@ -283,7 +283,7 @@ func TestAccount_Signup_WithEmail_SendsVerification(t *testing.T) { conf.BaseURL = "https://ntfy.example.com" s := newTestServer(t, conf) mailer := newCaptureMailer() - s.mailSender = mailer + s.accountMailer = mailer defer s.closeDatabases() // Sign up with an optional email -> account created and a verification link sent @@ -310,7 +310,7 @@ func TestAccount_Signup_WithoutEmail_NoSend(t *testing.T) { conf.BaseURL = "https://ntfy.example.com" s := newTestServer(t, conf) mailer := newCaptureMailer() - s.mailSender = mailer + s.accountMailer = mailer defer s.closeDatabases() // No email -> account created, nothing sent @@ -335,7 +335,7 @@ func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { conf.AuthUsers = []*user.User{{Name: "prov", Hash: hash, Role: user.RoleUser}} s := newTestServer(t, conf) mailer := newCaptureMailer() - s.mailSender = mailer + s.accountMailer = mailer defer s.closeDatabases() auth := map[string]string{"Authorization": util.BasicAuth("prov", "provpass")} @@ -364,7 +364,7 @@ func TestAccount_PasswordReset_ProvisionedUserNoSend(t *testing.T) { } s := newTestServer(t, conf) mailer := newCaptureMailer() - s.mailSender = mailer + s.accountMailer = mailer defer s.closeDatabases() // Give the provisioned user a verified primary email anyway diff --git a/server/server_account_test.go b/server/server_account_test.go index f2f36168..b74aac0d 100644 --- a/server/server_account_test.go +++ b/server/server_account_test.go @@ -151,7 +151,7 @@ func TestAccount_Get_Anonymous(t *testing.T) { conf.VisitorAttachmentTotalSizeLimit = 5123 conf.AttachmentFileSizeLimit = 512 s := newTestServer(t, conf) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} defer s.closeDatabases() rr := request(t, s, "GET", "/v1/account", "", nil) diff --git a/server/server_manager.go b/server/server_manager.go index 387ad2b8..e2fb66e9 100644 --- a/server/server_manager.go +++ b/server/server_manager.go @@ -54,8 +54,8 @@ func (s *Server) execManager() { receivedMailTotal, receivedMailSuccess, receivedMailFailure = s.smtpServerBackend.Counts() } var sentMailTotal, sentMailSuccess, sentMailFailure int64 - if s.smtpSender != nil { - sentMailTotal, sentMailSuccess, sentMailFailure = s.smtpSender.Counts() + if s.notificationMailer != nil { + sentMailTotal, sentMailSuccess, sentMailFailure = s.notificationMailer.Counts() } // Users diff --git a/server/server_middleware.go b/server/server_middleware.go index b8e650c5..7f76ae4c 100644 --- a/server/server_middleware.go +++ b/server/server_middleware.go @@ -105,7 +105,7 @@ func (s *Server) ensureCallsEnabled(next handleFunc) handleFunc { func (s *Server) ensureEmailsEnabled(next handleFunc) handleFunc { return func(w http.ResponseWriter, r *http.Request, v *visitor) error { - if s.mailSender == nil || s.userManager == nil { + if s.accountMailer == nil || s.userManager == nil { return errHTTPNotFound } return next(w, r, v) diff --git a/server/server_payments.go b/server/server_payments.go index 4b19a091..56a0026b 100644 --- a/server/server_payments.go +++ b/server/server_payments.go @@ -252,7 +252,7 @@ func (s *Server) handleAccountBillingSubscriptionCreateSuccess(w http.ResponseWr // collision (or any other skip), the generic "no recovery email set" warning on the account page // nudges the user to add one. This is best-effort: failures are logged, never surfaced. func (s *Server) maybeEnqueueBillingEmailVerification(r *http.Request, v *visitor, userID, billingEmail string) { - if s.mailSender == nil || s.config.BaseURL == "" || billingEmail == "" || !emailAddressRegex.MatchString(billingEmail) { + if s.accountMailer == nil || s.config.BaseURL == "" || billingEmail == "" || !emailAddressRegex.MatchString(billingEmail) { return } emails, err := s.userManager.Emails(userID) diff --git a/server/server_payments_email_test.go b/server/server_payments_email_test.go index 24fa7bb2..ff7727da 100644 --- a/server/server_payments_email_test.go +++ b/server/server_payments_email_test.go @@ -45,7 +45,7 @@ func newCheckoutEmailTestServer(t *testing.T, databaseURL string) (*Server, *cap c.SMTPSenderFrom = "noreply@example.com" s := newTestServer(t, c) mailer := newCaptureMailer() - s.mailSender = mailer + s.accountMailer = mailer require.Nil(t, s.userManager.AddTier(&user.Tier{ ID: "ti_123", Code: "starter", StripeMonthlyPriceID: "price_1234", MessageLimit: 100, MessageExpiryDuration: time.Hour, })) diff --git a/server/server_test.go b/server/server_test.go index 1d19815b..04a4a8da 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -740,7 +740,7 @@ func TestServer_PublishMessageInHeaderWithNewlines(t *testing.T) { func TestServer_PublishInvalidTopic(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} response := request(t, s, "PUT", "/docs", "fail", nil) require.Equal(t, 40010, toHTTPError(t, response.Body.String()).Code) }) @@ -1231,7 +1231,7 @@ func TestServer_StatsResetter_MessageLimiter_EmailsLimiter(t *testing.T) { c := newTestConfigWithAuthFile(t, databaseURL) s := newTestServer(t, c) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} // Publish some messages, and check stats for i := 0; i < 3; i++ { @@ -1461,7 +1461,7 @@ func TestServer_PublishTooManyRequests_ShortReplenish(t *testing.T) { func TestServer_PublishTooManyEmails_Defaults(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} for i := 0; i < 16; i++ { response := request(t, s, "PUT", "/mytopic", fmt.Sprintf("message %d", i), map[string]string{ "E-Mail": "test@example.com", @@ -1481,7 +1481,7 @@ func TestServer_PublishTooManyEmails_Replenish(t *testing.T) { c := newTestConfig(t, databaseURL) c.VisitorEmailLimitReplenish = 500 * time.Millisecond s := newTestServer(t, c) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} for i := 0; i < 16; i++ { response := request(t, s, "PUT", "/mytopic", fmt.Sprintf("message %d", i), map[string]string{ "E-Mail": "test@example.com", @@ -1509,7 +1509,7 @@ func TestServer_PublishTooManyEmails_Replenish(t *testing.T) { func TestServer_PublishDelayedEmail_Fail(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} response := request(t, s, "PUT", "/mytopic", "fail", map[string]string{ "E-Mail": "test@example.com", "Delay": "20 min", @@ -1546,7 +1546,7 @@ func TestServer_PublishEmailNoMailer_Fail(t *testing.T) { func TestServer_PublishEmailAddressInvalid(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} addresses := []string{ "test@example.com, other@example.com", "invalidaddress", @@ -1572,7 +1572,7 @@ func TestServer_PublishEmailVerify_VerifiedAddress(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} defer s.closeDatabases() require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) @@ -1602,7 +1602,7 @@ func TestServer_PublishEmailVerify_BoolValue(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} defer s.closeDatabases() require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) @@ -1631,7 +1631,7 @@ func TestServer_PublishEmailVerify_BoolValue(t *testing.T) { func TestServer_PublishEmailVerify_BoolValue_NoVerify(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} // "yes" without smtp-sender-verify should fail with invalid address response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ @@ -1647,7 +1647,7 @@ func TestServer_PublishEmailVerify_Anonymous(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} defer s.closeDatabases() // Anonymous user should be rejected @@ -1664,7 +1664,7 @@ func TestServer_PublishEmailVerify_NoVerifiedEmails(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} defer s.closeDatabases() require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) @@ -1682,7 +1682,7 @@ func TestServer_PublishEmailVerify_NoVerifiedEmails(t *testing.T) { func TestServer_PublishEmailVerify_Disabled_Backwards_Compatible(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = &testMailer{} + s.notificationMailer = &testMailer{} // Without smtp-sender-verify, any email address should work (backwards compatible) response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ @@ -2139,7 +2139,7 @@ func TestServer_PublishAsJSON_WithEmail(t *testing.T) { t.Parallel() mailer := &testMailer{} s := newTestServer(t, newTestConfig(t, databaseURL)) - s.smtpSender = mailer + s.notificationMailer = mailer body := `{"topic":"mytopic","message":"A message","email":"phil@example.com"}` response := request(t, s, "PUT", "/", body, nil) require.Equal(t, 200, response.Code) diff --git a/server/smtp_sender.go b/server/smtp_sender.go index 199cecd9..9ef7c000 100644 --- a/server/smtp_sender.go +++ b/server/smtp_sender.go @@ -15,19 +15,23 @@ import ( "heckel.io/ntfy/v2/util" ) -type mailer interface { +// messageMailer sends notification emails (the email-on-publish feature). It formats a ntfy +// message into an email. Implemented by *notificationSender; tests inject testMailer. +type messageMailer interface { Send(v *visitor, m *model.Message, to string) error Counts() (total int64, success int64, failure int64) } -// emailVerifier sends the magic-link emails for email verification and password reset. +// magicLinkMailer sends the magic-link emails for email verification and password reset. // *mail.Sender implements it; tests inject a fake to capture the generated links. -type emailVerifier interface { +type magicLinkMailer interface { SendEmailVerification(to, link string) error SendPasswordReset(to, link string) error } -type smtpSender struct { +// notificationSender adapts a *mail.Sender for notification emails: it formats a model.Message +// into an email and tracks success/failure counts. +type notificationSender struct { config *Config sender *mail.Sender success int64 @@ -35,7 +39,7 @@ type smtpSender struct { mu sync.Mutex } -func (s *smtpSender) Send(v *visitor, m *model.Message, to string) error { +func (s *notificationSender) Send(v *visitor, m *model.Message, to string) error { return s.withCount(v, m, func() error { message, err := formatMail(s.config.BaseURL, v.ip.String(), s.sender.From(), to, m) if err != nil { @@ -56,13 +60,13 @@ func (s *smtpSender) Send(v *visitor, m *model.Message, to string) error { }) } -func (s *smtpSender) Counts() (total int64, success int64, failure int64) { +func (s *notificationSender) Counts() (total int64, success int64, failure int64) { s.mu.Lock() defer s.mu.Unlock() return s.success + s.failure, s.success, s.failure } -func (s *smtpSender) withCount(v *visitor, m *model.Message, fn func() error) error { +func (s *notificationSender) withCount(v *visitor, m *model.Message, fn func() error) error { err := fn() s.mu.Lock() defer s.mu.Unlock() From 44d5bcf8751ce563316441866a2311d2bff6a54f Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 15 Jun 2026 22:21:22 -0400 Subject: [PATCH 12/34] Fix mail mess --- mail/format.go | 95 +++++++++++ .../format_test.go | 2 +- {server => mail}/mailer_emoji_map.json | 0 mail/sender.go | 137 +++++++++------ server/server.go | 90 +++++----- server/server_account.go | 8 +- server/server_account_email_test.go | 23 ++- server/server_account_test.go | 2 +- server/server_manager.go | 4 +- server/server_middleware.go | 2 +- server/server_payments.go | 2 +- server/server_payments_email_test.go | 2 +- server/server_test.go | 32 ++-- server/smtp_sender.go | 160 ------------------ 14 files changed, 268 insertions(+), 291 deletions(-) create mode 100644 mail/format.go rename server/smtp_sender_test.go => mail/format_test.go (99%) rename {server => mail}/mailer_emoji_map.json (100%) delete mode 100644 server/smtp_sender.go diff --git a/mail/format.go b/mail/format.go new file mode 100644 index 00000000..e68ec8ea --- /dev/null +++ b/mail/format.go @@ -0,0 +1,95 @@ +package mail + +import ( + _ "embed" // required by go:embed + "encoding/json" + "fmt" + "mime" + "strings" + "time" + + "heckel.io/ntfy/v2/model" + "heckel.io/ntfy/v2/util" +) + +var ( + //go:embed "mailer_emoji_map.json" + emojisJSON string + + // emojiMap maps ntfy tag names to emoji, parsed once from the embedded JSON in init + emojiMap map[string]string +) + +func init() { + if err := json.Unmarshal([]byte(emojisJSON), &emojiMap); err != nil { + panic("mail: invalid embedded emoji map: " + err.Error()) + } +} + +func formatMail(baseURL, senderIP, from, to string, m *model.Message) (string, error) { + topicURL := baseURL + "/" + m.Topic + subject := m.Title + if subject == "" { + subject = m.Message + } + subject = strings.ReplaceAll(strings.ReplaceAll(subject, "\r", ""), "\n", " ") + message := m.Message + trailer := "" + if len(m.Tags) > 0 { + emojis, tags := toEmojis(m.Tags) + if len(emojis) > 0 { + subject = strings.Join(emojis, " ") + " " + subject + } + if len(tags) > 0 { + trailer = "Tags: " + strings.Join(tags, ", ") + } + } + if m.Priority != 0 && m.Priority != 3 { + priority, err := util.PriorityString(m.Priority) + if err != nil { + return "", err + } + if trailer != "" { + trailer += "\n" + } + trailer += fmt.Sprintf("Priority: %s", priority) + } + if trailer != "" { + message += "\n\n" + trailer + } + date := time.Unix(m.Time, 0).UTC().Format(time.RFC1123Z) + subject = mime.BEncoding.Encode("utf-8", subject) + body := `From: "{shortTopicURL}" <{from}> +To: {to} +Date: {date} +Subject: {subject} +Content-Type: text/plain; charset="utf-8" + +{message} + +-- +This message was sent by {ip} at {time} via {topicURL}` + body = strings.ReplaceAll(body, "{from}", from) + body = strings.ReplaceAll(body, "{to}", to) + body = strings.ReplaceAll(body, "{date}", date) + body = strings.ReplaceAll(body, "{subject}", subject) + body = strings.ReplaceAll(body, "{message}", message) + body = strings.ReplaceAll(body, "{topicURL}", topicURL) + body = strings.ReplaceAll(body, "{shortTopicURL}", util.ShortTopicURL(topicURL)) + body = strings.ReplaceAll(body, "{time}", time.Unix(m.Time, 0).UTC().Format(time.RFC1123)) + body = strings.ReplaceAll(body, "{ip}", senderIP) + return body, nil +} + +func toEmojis(tags []string) (emojisOut []string, tagsOut []string) { + tagsOut = make([]string, 0) + emojisOut = make([]string, 0) + for _, t := range tags { + if emoji, ok := emojiMap[t]; ok { + emojisOut = append(emojisOut, emoji) + } else { + tagsOut = append(tagsOut, t) + } + } + return +} diff --git a/server/smtp_sender_test.go b/mail/format_test.go similarity index 99% rename from server/smtp_sender_test.go rename to mail/format_test.go index 4f97b128..4c4c4613 100644 --- a/server/smtp_sender_test.go +++ b/mail/format_test.go @@ -1,4 +1,4 @@ -package server +package mail import ( "testing" diff --git a/server/mailer_emoji_map.json b/mail/mailer_emoji_map.json similarity index 100% rename from server/mailer_emoji_map.json rename to mail/mailer_emoji_map.json diff --git a/mail/sender.go b/mail/sender.go index 3215c332..5463285f 100644 --- a/mail/sender.go +++ b/mail/sender.go @@ -6,66 +6,98 @@ import ( "net" "net/smtp" "strings" + "sync" "time" "heckel.io/ntfy/v2/log" + "heckel.io/ntfy/v2/model" ) const ( + tagMail = "mail" + emailVerificationSubject = "Verify your email for ntfy" passwordResetSubject = "Reset your ntfy password" ) // Config holds the SMTP configuration for the mail sender type Config struct { + BaseURL string // ntfy base URL, used to build topic URLs in notification emails SMTPAddr string // SMTP server address (host:port) SMTPUser string // SMTP auth username SMTPPass string // SMTP auth password From string // Sender email address } -// Sender sends emails via SMTP, including the magic-link emails for email verification and -// password reset. Pending verification/reset state lives in the database (see user.Manager), -// not in this struct. -type Sender struct { - config *Config +// Sender sends all of ntfy's outgoing email: notification emails (the email-on-publish feature) +// as well as the magic-link emails for email verification and password reset. realSender is the +// SMTP-backed implementation; tests inject a fake. +type Sender interface { + SendNotification(to string, m *model.Message, senderIP string) error + Counts() (total int64, success int64, failure int64) + SendEmailVerification(to, link string) error + SendPasswordReset(to, link string) error +} + +// realSender is the SMTP-backed implementation of Sender. Pending verification/reset state lives +// in the database (see user.Manager), not in this struct. +type realSender struct { + config *Config + success int64 + failure int64 + mu sync.Mutex } // NewSender creates a new mail Sender with the given SMTP config -func NewSender(config *Config) *Sender { - return &Sender{config: config} +func NewSender(config *Config) Sender { + return &realSender{config: config} } -// Addr returns the SMTP server address -func (s *Sender) Addr() string { - return s.config.SMTPAddr -} - -// User returns the SMTP username -func (s *Sender) User() string { - return s.config.SMTPUser -} - -// From returns the sender email address -func (s *Sender) From() string { - return s.config.From -} - -// SendRaw sends a raw email message via SMTP -func (s *Sender) SendRaw(to string, message []byte) error { - host, _, err := net.SplitHostPort(s.config.SMTPAddr) +// SendNotification formats a ntfy message into a notification email and sends it via SMTP. It +// tracks success/failure counts, exposed via Counts (used for the server stats). +func (s *realSender) SendNotification(to string, m *model.Message, senderIP string) error { + message, err := formatMail(s.config.BaseURL, senderIP, s.config.From, to, m) if err != nil { + s.count(false) return err } - var auth smtp.Auth - if s.config.SMTPUser != "" { - auth = smtp.PlainAuth("", s.config.SMTPUser, s.config.SMTPPass, host) - } - return smtp.SendMail(s.config.SMTPAddr, auth, s.config.From, []string{to}, message) + log.Tag(tagMail).Field("email_to", to).Debug("Sending notification email") + err = s.sendRaw(to, []byte(message)) + s.count(err == nil) + return err } -// Send sends a plain text email via SMTP -func (s *Sender) Send(to, subject, body string) error { +// Counts returns the number of notification emails sent, broken down into total, success and failure +func (s *realSender) Counts() (total int64, success int64, failure int64) { + s.mu.Lock() + defer s.mu.Unlock() + return s.success + s.failure, s.success, s.failure +} + +// SendEmailVerification sends an email containing a magic link to verify ownership of the +// recipient address. The link carries a one-time token validated against the database. +func (s *realSender) SendEmailVerification(to, link string) error { + body := fmt.Sprintf(`Click the link below to verify this email address for your ntfy account: + +%s + +This link expires in 24 hours. If you did not request this, you can safely ignore this email.`, link) + return s.send(to, emailVerificationSubject, body) +} + +// SendPasswordReset sends an email containing a magic link to set a new password. The link +// carries a one-time token validated against the database. +func (s *realSender) SendPasswordReset(to, link string) error { + body := fmt.Sprintf(`Click the link below to set a new password for your ntfy account: + +%s + +This link expires in 1 hour. If you did not request this, you can safely ignore this email -- your password will not change.`, link) + return s.send(to, passwordResetSubject, body) +} + +// send sends a plain text email via SMTP +func (s *realSender) send(to, subject, body string) error { date := time.Now().UTC().Format(time.RFC1123Z) encodedSubject := mime.BEncoding.Encode("utf-8", subject) message := `From: ntfy <{from}> @@ -80,28 +112,29 @@ Content-Type: text/plain; charset="utf-8" message = strings.ReplaceAll(message, "{date}", date) message = strings.ReplaceAll(message, "{subject}", encodedSubject) message = strings.ReplaceAll(message, "{body}", body) - log.Tag("mail").Field("email_to", to).Debug("Sending email") - return s.SendRaw(to, []byte(message)) + log.Tag(tagMail).Field("email_to", to).Debug("Sending email") + return s.sendRaw(to, []byte(message)) } -// SendEmailVerification sends an email containing a magic link to verify ownership of the -// recipient address. The link carries a one-time token validated against the database. -func (s *Sender) SendEmailVerification(to, link string) error { - body := fmt.Sprintf(`Click the link below to verify this email address for your ntfy account: - -%s - -This link expires in 24 hours. If you did not request this, you can safely ignore this email.`, link) - return s.Send(to, emailVerificationSubject, body) +// sendRaw sends a raw email message via SMTP +func (s *realSender) sendRaw(to string, message []byte) error { + host, _, err := net.SplitHostPort(s.config.SMTPAddr) + if err != nil { + return err + } + var auth smtp.Auth + if s.config.SMTPUser != "" { + auth = smtp.PlainAuth("", s.config.SMTPUser, s.config.SMTPPass, host) + } + return smtp.SendMail(s.config.SMTPAddr, auth, s.config.From, []string{to}, message) } -// SendPasswordReset sends an email containing a magic link to set a new password. The link -// carries a one-time token validated against the database. -func (s *Sender) SendPasswordReset(to, link string) error { - body := fmt.Sprintf(`Click the link below to set a new password for your ntfy account: - -%s - -This link expires in 1 hour. If you did not request this, you can safely ignore this email -- your password will not change.`, link) - return s.Send(to, passwordResetSubject, body) +func (s *realSender) count(ok bool) { + s.mu.Lock() + defer s.mu.Unlock() + if ok { + s.success++ + } else { + s.failure++ + } } diff --git a/server/server.go b/server/server.go index ade5aebe..db338a22 100644 --- a/server/server.go +++ b/server/server.go @@ -48,31 +48,30 @@ import ( // Server is the main server, providing the UI and API for ntfy type Server struct { - config *Config - db *db.DB // Shared PostgreSQL connection pool (with optional replicas), nil when using SQLite - httpServer *http.Server - httpsServer *http.Server - httpMetricsServer *http.Server - httpProfileServer *http.Server - unixListener net.Listener - smtpServer *smtp.Server - smtpServerBackend *smtpBackend - notificationMailer messageMailer - accountMailer magicLinkMailer - topics map[string]*topic - visitors map[string]*visitor // ip: or user: - firebaseClient *firebaseClient - messages int64 // Total number of messages (persisted if messageCache enabled) - messagesHistory []int64 // Last n values of the messages counter, used to determine rate - userManager *user.Manager // Might be nil! - messageCache *message.Cache // Database that stores the messages - webPush *webpush.Store // Database that stores web push subscriptions - attachment *attachment.Store // Attachment store (file system or S3) - stripe stripeAPI // Stripe API, can be replaced with a mock - priceCache *util.LookupCache[map[string]int64] // Stripe price ID -> price as cents (USD implied!) - metricsHandler http.Handler // Handles /metrics if enable-metrics set, and listen-metrics-http not set - closeChan chan bool - mu sync.RWMutex + config *Config + db *db.DB // Shared PostgreSQL connection pool (with optional replicas), nil when using SQLite + httpServer *http.Server + httpsServer *http.Server + httpMetricsServer *http.Server + httpProfileServer *http.Server + unixListener net.Listener + smtpServer *smtp.Server + smtpServerBackend *smtpBackend + mailer mail.Sender + topics map[string]*topic + visitors map[string]*visitor // ip: or user: + firebaseClient *firebaseClient + messages int64 // Total number of messages (persisted if messageCache enabled) + messagesHistory []int64 // Last n values of the messages counter, used to determine rate + userManager *user.Manager // Might be nil! + messageCache *message.Cache // Database that stores the messages + webPush *webpush.Store // Database that stores web push subscriptions + attachment *attachment.Store // Attachment store (file system or S3) + stripe stripeAPI // Stripe API, can be replaced with a mock + priceCache *util.LookupCache[map[string]int64] // Stripe price ID -> price as cents (USD implied!) + metricsHandler http.Handler // Handles /metrics if enable-metrics set, and listen-metrics-http not set + closeChan chan bool + mu sync.RWMutex } // handleFunc extends the normal http.HandlerFunc to be able to easily return errors @@ -184,17 +183,15 @@ const ( // New instantiates a new Server. It creates the cache and adds a Firebase // subscriber (if configured). func New(conf *Config) (*Server, error) { - var notificationMailer messageMailer - var accountEmailer magicLinkMailer // Stays untyped-nil when SMTP is unconfigured, so ensureEmailsEnabled gates correctly + var sender mail.Sender if conf.SMTPSenderAddr != "" { - sender := mail.NewSender(&mail.Config{ + sender = mail.NewSender(&mail.Config{ + BaseURL: conf.BaseURL, SMTPAddr: conf.SMTPSenderAddr, SMTPUser: conf.SMTPSenderUser, SMTPPass: conf.SMTPSenderPass, From: conf.SMTPSenderFrom, }) - notificationMailer = ¬ificationSender{config: conf, sender: sender} - accountEmailer = sender } var stripe stripeAPI if payments.Available && conf.StripeSecretKey != "" { @@ -293,20 +290,19 @@ func New(conf *Config) (*Server, error) { firebaseClient = newFirebaseClient(sender, auther) } s := &Server{ - config: conf, - db: pool, - messageCache: messageCache, - webPush: wp, - attachment: attachmentStore, - firebaseClient: firebaseClient, - notificationMailer: notificationMailer, - accountMailer: accountEmailer, - topics: topics, - userManager: userManager, - messages: messages, - messagesHistory: []int64{messages}, - visitors: make(map[string]*visitor), - stripe: stripe, + config: conf, + db: pool, + messageCache: messageCache, + webPush: wp, + attachment: attachmentStore, + firebaseClient: firebaseClient, + mailer: sender, + topics: topics, + userManager: userManager, + messages: messages, + messagesHistory: []int64{messages}, + visitors: make(map[string]*visitor), + stripe: stripe, } s.priceCache = util.NewLookupCache(s.fetchStripePrices, conf.StripePriceCacheDuration) return s, nil @@ -974,7 +970,7 @@ func (s *Server) handlePublishInternal(r *http.Request, v *visitor) (*model.Mess if s.firebaseClient != nil && firebase { go s.sendToFirebase(v, m) } - if s.notificationMailer != nil && email != "" { + if s.mailer != nil && email != "" { go s.sendEmail(v, m, email) } if s.config.TwilioAccount != "" && call != "" { @@ -1136,7 +1132,7 @@ func (s *Server) sendToFirebase(v *visitor, m *model.Message) { func (s *Server) sendEmail(v *visitor, m *model.Message, email string) { logvm(v, m).Tag(tagEmail).Field("email", email).Info("Sending email to %s", email) - if err := s.notificationMailer.Send(v, m, email); err != nil { + if err := s.mailer.SendNotification(email, m, v.ip.String()); err != nil { logvm(v, m).Tag(tagEmail).Field("email", email).Err(err).Warn("Unable to send email to %s: %v", email, err.Error()) minc(metricEmailsPublishedFailure) return @@ -1236,7 +1232,7 @@ func (s *Server) parsePublishParams(r *http.Request, m *model.Message) (cache bo if email != "" && !emailAddressRegex.MatchString(email) && !toBool(email) { return false, false, "", "", "", false, "", errHTTPBadRequestEmailAddressInvalid } - if s.notificationMailer == nil && email != "" { + if s.mailer == nil && email != "" { return false, false, "", "", "", false, "", errHTTPBadRequestEmailDisabled } call = readParam(r, "x-call", "call") diff --git a/server/server_account.go b/server/server_account.go index 79c43866..c7ba5335 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -54,7 +54,7 @@ func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v * // If an email was provided and email sending is configured, start verification (best-effort). // The address becomes the primary email on verify (the new account has no primary yet); a // failure to send must not fail signup, so we only log it. - if newAccount.Email != "" && s.accountMailer != nil { + if newAccount.Email != "" && s.mailer != nil { if u, err := s.userManager.User(newAccount.Username); err != nil { logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to load new user for email verification") } else if err := s.enqueueEmailVerification(u.ID, newAccount.Email); err != nil { @@ -175,7 +175,7 @@ func (s *Server) handleAccountGet(w http.ResponseWriter, r *http.Request, v *vis response.PhoneNumbers = phoneNumbers } } - if s.accountMailer != nil { + if s.mailer != nil { emails, err := s.userManager.Emails(u.ID) if err != nil { return err @@ -788,7 +788,7 @@ func (s *Server) enqueueEmailVerification(userID, email string) error { return err } link := s.config.BaseURL + webAppEmailVerifyPathPrefix + token - return s.accountMailer.SendEmailVerification(email, link) + return s.mailer.SendEmailVerification(email, link) } // handleAccountPasswordResetRequest starts a password reset (POST /v1/account/password/reset/request, @@ -814,7 +814,7 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt } else { link := s.config.BaseURL + webAppPasswordResetPathPrefix + token logvr(v, r).Tag(tagAccount).Field("user_id", userID).Info("Sending password reset link") - if err := s.accountMailer.SendPasswordReset(email, link); err != nil { + if err := s.mailer.SendPasswordReset(email, link); err != nil { logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to send password reset email") } } diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index f2ca2d3a..a71d5979 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -7,12 +7,13 @@ import ( "testing" "github.com/stretchr/testify/require" + "heckel.io/ntfy/v2/model" "heckel.io/ntfy/v2/user" "heckel.io/ntfy/v2/util" ) -// captureMailer is a fake magicLinkMailer that records the magic links it is asked to send, so -// tests can "click" them without a real SMTP server. +// captureMailer is a fake mailer that records the magic links it is asked to send, so tests can +// "click" them without a real SMTP server. The notification side is a no-op. type captureMailer struct { verifyLinks map[string]string // email -> verification link resetLinks map[string]string // email -> reset link @@ -32,6 +33,14 @@ func (c *captureMailer) SendPasswordReset(to, link string) error { return nil } +func (c *captureMailer) SendNotification(to string, m *model.Message, senderIP string) error { + return nil +} + +func (c *captureMailer) Counts() (total int64, success int64, failure int64) { + return 0, 0, 0 +} + // newEmailTestServer creates a server with email sending "enabled" (SMTP + base-url configured) // and a capturing mailer injected, plus a tier-less user "ben" logged in via basic auth. func newEmailTestServer(t *testing.T, databaseURL string) (*Server, *captureMailer, map[string]string) { @@ -41,7 +50,7 @@ func newEmailTestServer(t *testing.T, databaseURL string) (*Server, *captureMail conf.BaseURL = "https://ntfy.example.com" s := newTestServer(t, conf) mailer := newCaptureMailer() - s.accountMailer = mailer + s.mailer = mailer require.Nil(t, s.userManager.AddUser("ben", "ben", user.RoleUser, false)) auth := map[string]string{"Authorization": util.BasicAuth("ben", "ben")} return s, mailer, auth @@ -283,7 +292,7 @@ func TestAccount_Signup_WithEmail_SendsVerification(t *testing.T) { conf.BaseURL = "https://ntfy.example.com" s := newTestServer(t, conf) mailer := newCaptureMailer() - s.accountMailer = mailer + s.mailer = mailer defer s.closeDatabases() // Sign up with an optional email -> account created and a verification link sent @@ -310,7 +319,7 @@ func TestAccount_Signup_WithoutEmail_NoSend(t *testing.T) { conf.BaseURL = "https://ntfy.example.com" s := newTestServer(t, conf) mailer := newCaptureMailer() - s.accountMailer = mailer + s.mailer = mailer defer s.closeDatabases() // No email -> account created, nothing sent @@ -335,7 +344,7 @@ func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { conf.AuthUsers = []*user.User{{Name: "prov", Hash: hash, Role: user.RoleUser}} s := newTestServer(t, conf) mailer := newCaptureMailer() - s.accountMailer = mailer + s.mailer = mailer defer s.closeDatabases() auth := map[string]string{"Authorization": util.BasicAuth("prov", "provpass")} @@ -364,7 +373,7 @@ func TestAccount_PasswordReset_ProvisionedUserNoSend(t *testing.T) { } s := newTestServer(t, conf) mailer := newCaptureMailer() - s.accountMailer = mailer + s.mailer = mailer defer s.closeDatabases() // Give the provisioned user a verified primary email anyway diff --git a/server/server_account_test.go b/server/server_account_test.go index b74aac0d..3c4f1787 100644 --- a/server/server_account_test.go +++ b/server/server_account_test.go @@ -151,7 +151,7 @@ func TestAccount_Get_Anonymous(t *testing.T) { conf.VisitorAttachmentTotalSizeLimit = 5123 conf.AttachmentFileSizeLimit = 512 s := newTestServer(t, conf) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} defer s.closeDatabases() rr := request(t, s, "GET", "/v1/account", "", nil) diff --git a/server/server_manager.go b/server/server_manager.go index e2fb66e9..51a46078 100644 --- a/server/server_manager.go +++ b/server/server_manager.go @@ -54,8 +54,8 @@ func (s *Server) execManager() { receivedMailTotal, receivedMailSuccess, receivedMailFailure = s.smtpServerBackend.Counts() } var sentMailTotal, sentMailSuccess, sentMailFailure int64 - if s.notificationMailer != nil { - sentMailTotal, sentMailSuccess, sentMailFailure = s.notificationMailer.Counts() + if s.mailer != nil { + sentMailTotal, sentMailSuccess, sentMailFailure = s.mailer.Counts() } // Users diff --git a/server/server_middleware.go b/server/server_middleware.go index 7f76ae4c..cc77b6df 100644 --- a/server/server_middleware.go +++ b/server/server_middleware.go @@ -105,7 +105,7 @@ func (s *Server) ensureCallsEnabled(next handleFunc) handleFunc { func (s *Server) ensureEmailsEnabled(next handleFunc) handleFunc { return func(w http.ResponseWriter, r *http.Request, v *visitor) error { - if s.accountMailer == nil || s.userManager == nil { + if s.mailer == nil || s.userManager == nil { return errHTTPNotFound } return next(w, r, v) diff --git a/server/server_payments.go b/server/server_payments.go index 56a0026b..76216bbe 100644 --- a/server/server_payments.go +++ b/server/server_payments.go @@ -252,7 +252,7 @@ func (s *Server) handleAccountBillingSubscriptionCreateSuccess(w http.ResponseWr // collision (or any other skip), the generic "no recovery email set" warning on the account page // nudges the user to add one. This is best-effort: failures are logged, never surfaced. func (s *Server) maybeEnqueueBillingEmailVerification(r *http.Request, v *visitor, userID, billingEmail string) { - if s.accountMailer == nil || s.config.BaseURL == "" || billingEmail == "" || !emailAddressRegex.MatchString(billingEmail) { + if s.mailer == nil || s.config.BaseURL == "" || billingEmail == "" || !emailAddressRegex.MatchString(billingEmail) { return } emails, err := s.userManager.Emails(userID) diff --git a/server/server_payments_email_test.go b/server/server_payments_email_test.go index ff7727da..42a7aa43 100644 --- a/server/server_payments_email_test.go +++ b/server/server_payments_email_test.go @@ -45,7 +45,7 @@ func newCheckoutEmailTestServer(t *testing.T, databaseURL string) (*Server, *cap c.SMTPSenderFrom = "noreply@example.com" s := newTestServer(t, c) mailer := newCaptureMailer() - s.accountMailer = mailer + s.mailer = mailer require.Nil(t, s.userManager.AddTier(&user.Tier{ ID: "ti_123", Code: "starter", StripeMonthlyPriceID: "price_1234", MessageLimit: 100, MessageExpiryDuration: time.Hour, })) diff --git a/server/server_test.go b/server/server_test.go index 04a4a8da..ea47dacb 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -740,7 +740,7 @@ func TestServer_PublishMessageInHeaderWithNewlines(t *testing.T) { func TestServer_PublishInvalidTopic(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} response := request(t, s, "PUT", "/docs", "fail", nil) require.Equal(t, 40010, toHTTPError(t, response.Body.String()).Code) }) @@ -1231,7 +1231,7 @@ func TestServer_StatsResetter_MessageLimiter_EmailsLimiter(t *testing.T) { c := newTestConfigWithAuthFile(t, databaseURL) s := newTestServer(t, c) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} // Publish some messages, and check stats for i := 0; i < 3; i++ { @@ -1319,7 +1319,7 @@ type testMailer struct { mu sync.Mutex } -func (t *testMailer) Send(v *visitor, m *model.Message, to string) error { +func (t *testMailer) SendNotification(to string, m *model.Message, senderIP string) error { t.mu.Lock() defer t.mu.Unlock() t.count++ @@ -1336,6 +1336,10 @@ func (t *testMailer) Count() int { return t.count } +func (t *testMailer) SendEmailVerification(to, link string) error { return nil } + +func (t *testMailer) SendPasswordReset(to, link string) error { return nil } + func TestServer_PublishTooManyRequests_Defaults(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) @@ -1461,7 +1465,7 @@ func TestServer_PublishTooManyRequests_ShortReplenish(t *testing.T) { func TestServer_PublishTooManyEmails_Defaults(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} for i := 0; i < 16; i++ { response := request(t, s, "PUT", "/mytopic", fmt.Sprintf("message %d", i), map[string]string{ "E-Mail": "test@example.com", @@ -1481,7 +1485,7 @@ func TestServer_PublishTooManyEmails_Replenish(t *testing.T) { c := newTestConfig(t, databaseURL) c.VisitorEmailLimitReplenish = 500 * time.Millisecond s := newTestServer(t, c) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} for i := 0; i < 16; i++ { response := request(t, s, "PUT", "/mytopic", fmt.Sprintf("message %d", i), map[string]string{ "E-Mail": "test@example.com", @@ -1509,7 +1513,7 @@ func TestServer_PublishTooManyEmails_Replenish(t *testing.T) { func TestServer_PublishDelayedEmail_Fail(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} response := request(t, s, "PUT", "/mytopic", "fail", map[string]string{ "E-Mail": "test@example.com", "Delay": "20 min", @@ -1546,7 +1550,7 @@ func TestServer_PublishEmailNoMailer_Fail(t *testing.T) { func TestServer_PublishEmailAddressInvalid(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} addresses := []string{ "test@example.com, other@example.com", "invalidaddress", @@ -1572,7 +1576,7 @@ func TestServer_PublishEmailVerify_VerifiedAddress(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} defer s.closeDatabases() require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) @@ -1602,7 +1606,7 @@ func TestServer_PublishEmailVerify_BoolValue(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} defer s.closeDatabases() require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) @@ -1631,7 +1635,7 @@ func TestServer_PublishEmailVerify_BoolValue(t *testing.T) { func TestServer_PublishEmailVerify_BoolValue_NoVerify(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} // "yes" without smtp-sender-verify should fail with invalid address response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ @@ -1647,7 +1651,7 @@ func TestServer_PublishEmailVerify_Anonymous(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} defer s.closeDatabases() // Anonymous user should be rejected @@ -1664,7 +1668,7 @@ func TestServer_PublishEmailVerify_NoVerifiedEmails(t *testing.T) { conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderVerify = true s := newTestServer(t, conf) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} defer s.closeDatabases() require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) @@ -1682,7 +1686,7 @@ func TestServer_PublishEmailVerify_NoVerifiedEmails(t *testing.T) { func TestServer_PublishEmailVerify_Disabled_Backwards_Compatible(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = &testMailer{} + s.mailer = &testMailer{} // Without smtp-sender-verify, any email address should work (backwards compatible) response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ @@ -2139,7 +2143,7 @@ func TestServer_PublishAsJSON_WithEmail(t *testing.T) { t.Parallel() mailer := &testMailer{} s := newTestServer(t, newTestConfig(t, databaseURL)) - s.notificationMailer = mailer + s.mailer = mailer body := `{"topic":"mytopic","message":"A message","email":"phil@example.com"}` response := request(t, s, "PUT", "/", body, nil) require.Equal(t, 200, response.Code) diff --git a/server/smtp_sender.go b/server/smtp_sender.go deleted file mode 100644 index 9ef7c000..00000000 --- a/server/smtp_sender.go +++ /dev/null @@ -1,160 +0,0 @@ -package server - -import ( - _ "embed" // required by go:embed - "encoding/json" - "fmt" - "mime" - "strings" - "sync" - "time" - - "heckel.io/ntfy/v2/log" - "heckel.io/ntfy/v2/mail" - "heckel.io/ntfy/v2/model" - "heckel.io/ntfy/v2/util" -) - -// messageMailer sends notification emails (the email-on-publish feature). It formats a ntfy -// message into an email. Implemented by *notificationSender; tests inject testMailer. -type messageMailer interface { - Send(v *visitor, m *model.Message, to string) error - Counts() (total int64, success int64, failure int64) -} - -// magicLinkMailer sends the magic-link emails for email verification and password reset. -// *mail.Sender implements it; tests inject a fake to capture the generated links. -type magicLinkMailer interface { - SendEmailVerification(to, link string) error - SendPasswordReset(to, link string) error -} - -// notificationSender adapts a *mail.Sender for notification emails: it formats a model.Message -// into an email and tracks success/failure counts. -type notificationSender struct { - config *Config - sender *mail.Sender - success int64 - failure int64 - mu sync.Mutex -} - -func (s *notificationSender) Send(v *visitor, m *model.Message, to string) error { - return s.withCount(v, m, func() error { - message, err := formatMail(s.config.BaseURL, v.ip.String(), s.sender.From(), to, m) - if err != nil { - return err - } - ev := logvm(v, m). - Tag(tagEmail). - Fields(log.Context{ - "email_via": s.sender.Addr(), - "email_user": s.sender.User(), - "email_to": to, - }) - if ev.IsTrace() { - ev.Field("email_body", message).Trace("Sending email") - } - ev.Info("Sending email") - return s.sender.SendRaw(to, []byte(message)) - }) -} - -func (s *notificationSender) Counts() (total int64, success int64, failure int64) { - s.mu.Lock() - defer s.mu.Unlock() - return s.success + s.failure, s.success, s.failure -} - -func (s *notificationSender) withCount(v *visitor, m *model.Message, fn func() error) error { - err := fn() - s.mu.Lock() - defer s.mu.Unlock() - if err != nil { - logvm(v, m).Err(err).Debug("Sending mail failed") - s.failure++ - } else { - s.success++ - } - return err -} - -func formatMail(baseURL, senderIP, from, to string, m *model.Message) (string, error) { - topicURL := baseURL + "/" + m.Topic - subject := m.Title - if subject == "" { - subject = m.Message - } - subject = strings.ReplaceAll(strings.ReplaceAll(subject, "\r", ""), "\n", " ") - message := m.Message - trailer := "" - if len(m.Tags) > 0 { - emojis, tags, err := toEmojis(m.Tags) - if err != nil { - return "", err - } - if len(emojis) > 0 { - subject = strings.Join(emojis, " ") + " " + subject - } - if len(tags) > 0 { - trailer = "Tags: " + strings.Join(tags, ", ") - } - } - if m.Priority != 0 && m.Priority != 3 { - priority, err := util.PriorityString(m.Priority) - if err != nil { - return "", err - } - if trailer != "" { - trailer += "\n" - } - trailer += fmt.Sprintf("Priority: %s", priority) - } - if trailer != "" { - message += "\n\n" + trailer - } - date := time.Unix(m.Time, 0).UTC().Format(time.RFC1123Z) - subject = mime.BEncoding.Encode("utf-8", subject) - body := `From: "{shortTopicURL}" <{from}> -To: {to} -Date: {date} -Subject: {subject} -Content-Type: text/plain; charset="utf-8" - -{message} - --- -This message was sent by {ip} at {time} via {topicURL}` - body = strings.ReplaceAll(body, "{from}", from) - body = strings.ReplaceAll(body, "{to}", to) - body = strings.ReplaceAll(body, "{date}", date) - body = strings.ReplaceAll(body, "{subject}", subject) - body = strings.ReplaceAll(body, "{message}", message) - body = strings.ReplaceAll(body, "{topicURL}", topicURL) - body = strings.ReplaceAll(body, "{shortTopicURL}", util.ShortTopicURL(topicURL)) - body = strings.ReplaceAll(body, "{time}", time.Unix(m.Time, 0).UTC().Format(time.RFC1123)) - body = strings.ReplaceAll(body, "{ip}", senderIP) - return body, nil -} - -var ( - //go:embed "mailer_emoji_map.json" - emojisJSON string -) - -func toEmojis(tags []string) (emojisOut []string, tagsOut []string, err error) { - var emojiMap map[string]string - if err = json.Unmarshal([]byte(emojisJSON), &emojiMap); err != nil { - return nil, nil, err - } - tagsOut = make([]string, 0) - emojisOut = make([]string, 0) - for _, t := range tags { - if emoji, ok := emojiMap[t]; ok { - emojisOut = append(emojisOut, emoji) - } else { - tagsOut = append(tagsOut, t) - } - } - return -} From b75d0e582c403ee20d712150530c8c8d256ad44c Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 15 Jun 2026 22:33:30 -0400 Subject: [PATCH 13/34] Rename --- mail/sender.go | 6 ++--- server/server.go | 41 +++++++++++++++-------------- server/server_account_email_test.go | 2 +- server/server_manager.go | 2 +- server/server_test.go | 2 +- 5 files changed, 27 insertions(+), 26 deletions(-) diff --git a/mail/sender.go b/mail/sender.go index 5463285f..7e0c4063 100644 --- a/mail/sender.go +++ b/mail/sender.go @@ -34,7 +34,7 @@ type Config struct { // SMTP-backed implementation; tests inject a fake. type Sender interface { SendNotification(to string, m *model.Message, senderIP string) error - Counts() (total int64, success int64, failure int64) + NotificationCounts() (total int64, success int64, failure int64) SendEmailVerification(to, link string) error SendPasswordReset(to, link string) error } @@ -67,8 +67,8 @@ func (s *realSender) SendNotification(to string, m *model.Message, senderIP stri return err } -// Counts returns the number of notification emails sent, broken down into total, success and failure -func (s *realSender) Counts() (total int64, success int64, failure int64) { +// NotificationCounts returns the number of notification emails sent, broken down into total, success and failure +func (s *realSender) NotificationCounts() (total int64, success int64, failure int64) { s.mu.Lock() defer s.mu.Unlock() return s.success + s.failure, s.success, s.failure diff --git a/server/server.go b/server/server.go index db338a22..de9c21b1 100644 --- a/server/server.go +++ b/server/server.go @@ -79,23 +79,26 @@ type handleFunc func(http.ResponseWriter, *http.Request, *visitor) error var ( // If changed, don't forget to update Android App and auth_sqlite.go - topicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No /! - topicPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}$`) // Regex must match JS & Android app! - externalTopicPathRegex = regexp.MustCompile(`^/[^/]+\.[^/]+/[-_A-Za-z0-9]{1,64}$`) // Extended topic path, for web-app, e.g. /example.com/mytopic - webAppEmailVerifyRegex = regexp.MustCompile(`^/account/email/verify/[-_A-Za-z0-9]+$`) // Magic-link landing (served by the web app) - webAppPasswordResetRegex = regexp.MustCompile(`^/account/password/reset/[-_A-Za-z0-9]+$`) // Password-reset landing (served by the web app) - jsonPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/json$`) - ssePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/sse$`) - rawPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/raw$`) - wsPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/ws$`) - authPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/auth$`) - publishPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/(publish|send|trigger)$`) - updatePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}$`) - clearPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}/(read|clear)$`) - sequenceIDRegex = topicRegex + topicRegex = regexp.MustCompile(`^[-_A-Za-z0-9]{1,64}$`) // No /! + topicPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}$`) // Regex must match JS & Android app! + externalTopicPathRegex = regexp.MustCompile(`^/[^/]+\.[^/]+/[-_A-Za-z0-9]{1,64}$`) // Extended topic path, for web-app, e.g. /example.com/mytopic + jsonPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/json$`) + ssePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/sse$`) + rawPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/raw$`) + wsPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/ws$`) + authPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}(,[-_A-Za-z0-9]{1,64})*/auth$`) + publishPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/(publish|send|trigger)$`) + updatePathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}$`) + clearPathRegex = regexp.MustCompile(`^/[-_A-Za-z0-9]{1,64}/[-_A-Za-z0-9]{1,64}/(read|clear)$`) + sequenceIDRegex = topicRegex + + webAppConfigPath = "/config.js" + webAppManifestPath = "/manifest.webmanifest" + webAppEmailVerifyPathPrefix = "/account/email/verify/" // Browser landing route; raw token appended + webAppEmailVerifyRegex = regexp.MustCompile(`^/account/email/verify/[-_A-Za-z0-9]+$`) // Magic-link landing (served by the web app) + webAppPasswordResetPathPrefix = "/account/password/reset/" // Browser landing route; raw token appended + webAppPasswordResetRegex = regexp.MustCompile(`^/account/password/reset/[-_A-Za-z0-9]+$`) // Password-reset landing (served by the web app) - webConfigPath = "/config.js" - webManifestPath = "/manifest.webmanifest" accountPath = "/account" matrixPushPath = "/_matrix/push/v1/notify" metricsPath = "/metrics" @@ -121,8 +124,6 @@ var ( apiAccountEmailResendPath = "/v1/account/email/resend" apiAccountPasswordResetRequestPath = "/v1/account/password/reset/request" apiAccountPasswordResetPath = "/v1/account/password/reset" - webAppEmailVerifyPathPrefix = "/account/email/verify/" // Browser landing route; raw token appended - webAppPasswordResetPathPrefix = "/account/password/reset/" // Browser landing route; raw token appended apiAccountBillingPortalPath = "/v1/account/billing/portal" apiAccountBillingWebhookPath = "/v1/account/billing/webhook" apiAccountBillingSubscriptionPath = "/v1/account/billing/subscription" @@ -553,9 +554,9 @@ func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visit return s.ensureAdmin(s.handleVersion)(w, r, v) } else if r.Method == http.MethodGet && r.URL.Path == apiConfigPath { return s.handleConfig(w, r, v) - } else if r.Method == http.MethodGet && r.URL.Path == webConfigPath { + } else if r.Method == http.MethodGet && r.URL.Path == webAppConfigPath { return s.ensureWebEnabled(s.handleWebConfig)(w, r, v) - } else if r.Method == http.MethodGet && r.URL.Path == webManifestPath { + } else if r.Method == http.MethodGet && r.URL.Path == webAppManifestPath { return s.ensureWebPushEnabled(s.handleWebManifest)(w, r, v) } else if r.Method == http.MethodGet && r.URL.Path == apiUsersPath { return s.ensureAdmin(s.handleUsersGet)(w, r, v) diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index a71d5979..e5168cfe 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -37,7 +37,7 @@ func (c *captureMailer) SendNotification(to string, m *model.Message, senderIP s return nil } -func (c *captureMailer) Counts() (total int64, success int64, failure int64) { +func (c *captureMailer) NotificationCounts() (total int64, success int64, failure int64) { return 0, 0, 0 } diff --git a/server/server_manager.go b/server/server_manager.go index 51a46078..f9334d7e 100644 --- a/server/server_manager.go +++ b/server/server_manager.go @@ -55,7 +55,7 @@ func (s *Server) execManager() { } var sentMailTotal, sentMailSuccess, sentMailFailure int64 if s.mailer != nil { - sentMailTotal, sentMailSuccess, sentMailFailure = s.mailer.Counts() + sentMailTotal, sentMailSuccess, sentMailFailure = s.mailer.NotificationCounts() } // Users diff --git a/server/server_test.go b/server/server_test.go index ea47dacb..646cd393 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -1326,7 +1326,7 @@ func (t *testMailer) SendNotification(to string, m *model.Message, senderIP stri return nil } -func (t *testMailer) Counts() (total int64, success int64, failure int64) { +func (t *testMailer) NotificationCounts() (total int64, success int64, failure int64) { return 0, 0, 0 } From d8c87d04e755ba9349a9d8785cbeaa2518db7c7c Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Tue, 16 Jun 2026 20:56:22 -0400 Subject: [PATCH 14/34] Update privacy policy, code review --- docs/privacy.md | 14 ++++++++------ server/errors.go | 2 +- server/server_account.go | 12 ++++++------ server/visitor.go | 12 +++++++----- user/manager.go | 6 +++--- web/public/static/langs/en.json | 2 +- web/src/app/errors.js | 10 +++++----- web/src/components/Signup.jsx | 4 ++-- 8 files changed, 33 insertions(+), 29 deletions(-) diff --git a/docs/privacy.md b/docs/privacy.md index 055e3a35..322e4f34 100644 --- a/docs/privacy.md +++ b/docs/privacy.md @@ -1,6 +1,6 @@ # Privacy policy -**Last updated:** March 31, 2026 +**Last updated:** June 15, 2026 This privacy policy describes how ntfy ("we", "us", or "our") collects, uses, and handles your information when you use the ntfy.sh service, web app, and mobile applications (Android and iOS). @@ -19,8 +19,9 @@ If you create an account on ntfy.sh, we collect: - **Username** - A unique identifier you choose - **Password** - Stored as a secure bcrypt hash (we never store your plaintext password) -- **Email address** - If you subscribe to a paid plan (for billing purposes via Stripe), or if you add a verified - email address for use with the email notification feature +- **Email address** - If you add an email address to your account for account recovery and password resets, for use + with the email notification feature, or if you subscribe to a paid plan (for billing purposes via Stripe). Email + addresses you add to your account are verified by sending a confirmation link. - **Phone number** - Only if you enable the phone call notification feature (verified via SMS/call) You can use ntfy without creating an account. Anonymous usage is fully supported. @@ -77,9 +78,10 @@ Your phone number is shared with Twilio to deliver these services. Twilio's ### Amazon SES (email delivery) -If you use the email notification feature (`X-Email` header), we use Amazon Simple Email Service (SES) to -deliver emails. The recipient email address and message content are transmitted through Amazon's infrastructure. -Amazon's [privacy policy](https://aws.amazon.com/privacy/) applies. +If you use the email notification feature (`X-Email` header), or when ntfy sends account-related emails (email +address verification and password reset links), we use Amazon Simple Email Service (SES) to deliver emails. The +recipient email address and message content are transmitted through Amazon's infrastructure. Amazon's +[privacy policy](https://aws.amazon.com/privacy/) applies. ### Stripe (payments) diff --git a/server/errors.go b/server/errors.go index 6a7bd769..caf1abc0 100644 --- a/server/errors.go +++ b/server/errors.go @@ -167,7 +167,7 @@ var ( errHTTPTooManyRequestsLimitSubscriptions = &errHTTP{42903, http.StatusTooManyRequests, "limit reached: too many active subscriptions", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPTooManyRequestsLimitTotalTopics = &errHTTP{42904, http.StatusTooManyRequests, "limit reached: the total number of topics on the server has been reached, please contact the admin", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPTooManyRequestsLimitAttachmentBandwidth = &errHTTP{42905, http.StatusTooManyRequests, "limit reached: daily bandwidth reached", "https://ntfy.sh/docs/publish/#limitations", nil} - errHTTPTooManyRequestsLimitAccountCreation = &errHTTP{42906, http.StatusTooManyRequests, "limit reached: too many accounts created", "https://ntfy.sh/docs/publish/#limitations", nil} // FIXME document limit + errHTTPTooManyRequestsLimitAccountActions = &errHTTP{42906, http.StatusTooManyRequests, "limit reached: too many account requests", "https://ntfy.sh/docs/publish/#limitations", nil} // FIXME document limit errHTTPTooManyRequestsLimitReservations = &errHTTP{42907, http.StatusTooManyRequests, "limit reached: too many topic reservations for this user", "", nil} errHTTPTooManyRequestsLimitMessages = &errHTTP{42908, http.StatusTooManyRequests, "limit reached: daily message quota reached", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPTooManyRequestsLimitAuthFailure = &errHTTP{42909, http.StatusTooManyRequests, "limit reached: too many auth failures", "https://ntfy.sh/docs/publish/#limitations", nil} // FIXME document limit diff --git a/server/server_account.go b/server/server_account.go index c7ba5335..517fb938 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -29,8 +29,8 @@ func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v * } else if u != nil { return errHTTPUnauthorized // Cannot create account from user context } - if !v.AccountCreationAllowed() { - return errHTTPTooManyRequestsLimitAccountCreation + if !v.AccountActionAllowed() { + return errHTTPTooManyRequestsLimitAccountActions } } newAccount, err := readJSONWithLimit[apiAccountCreateRequest](r.Body, jsonBodyBytesLimit, false) @@ -50,7 +50,7 @@ func (s *Server) handleAccountCreate(w http.ResponseWriter, r *http.Request, v * } return err } - v.AccountCreated() + v.AccountActionPerformed() // If an email was provided and email sending is configured, start verification (best-effort). // The address becomes the primary email on verify (the new account has no primary yet); a // failure to send must not fail signup, so we only log it. @@ -801,10 +801,10 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt return err } // Rate limit via the shared per-visitor account-creation bucket (no new limiter/config) - if !v.AccountCreationAllowed() { - return errHTTPTooManyRequestsLimitAccountCreation + if !v.AccountActionAllowed() { + return errHTTPTooManyRequestsLimitAccountActions } - v.AccountCreated() // Consume a token on every request (including no-match), to throttle probing + v.AccountActionPerformed() // Consume a token on every request (including no-match), to throttle probing identifier := strings.TrimSpace(req.Identifier) if identifier != "" && s.config.BaseURL != "" { if userID, email, ok := s.resolveResetTarget(identifier); ok { diff --git a/server/visitor.go b/server/visitor.go index 3d4622dd..2f07d273 100644 --- a/server/visitor.go +++ b/server/visitor.go @@ -66,7 +66,7 @@ type visitor struct { subscriptionLimiter *util.FixedLimiter // Fixed limiter for active subscriptions (ongoing connections) topicCreationLimiter *rate.Limiter // Rate limiter for inserting new topics into the in-memory topic map bandwidthLimiter *util.RateLimiter // Limiter for attachment bandwidth downloads - accountLimiter *rate.Limiter // Rate limiter for account creation, may be nil + accountLimiter *rate.Limiter // Rate limiter for account actions (signup, password-reset requests), may be nil authLimiter *rate.Limiter // Limiter for incorrect login attempts, may be nil firebase time.Time // Next allowed Firebase message seen time.Time // Last seen time of this visitor (needed for removal of stale visitors) @@ -280,8 +280,9 @@ func (v *visitor) AuthFailed() { } } -// AccountCreationAllowed returns true if a new account can be created -func (v *visitor) AccountCreationAllowed() bool { +// AccountActionAllowed returns true if a rate-limited account action (signup or password-reset +// request) is currently allowed for this visitor +func (v *visitor) AccountActionAllowed() bool { v.mu.RLock() // limiters could be replaced! defer v.mu.RUnlock() if v.accountLimiter == nil || (v.accountLimiter != nil && v.accountLimiter.Tokens() < 1) { @@ -290,8 +291,9 @@ func (v *visitor) AccountCreationAllowed() bool { return true } -// AccountCreated decreases the account limiter. This is to be called after an account was created. -func (v *visitor) AccountCreated() { +// AccountActionPerformed decreases the account limiter. This is to be called after a rate-limited +// account action (signup or password-reset request). +func (v *visitor) AccountActionPerformed() { v.mu.RLock() // limiters could be replaced! defer v.mu.RUnlock() if v.accountLimiter != nil { diff --git a/user/manager.go b/user/manager.go index 0f0064d5..40b61647 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1561,10 +1561,10 @@ func (a *Manager) SetPrimaryEmail(userID, email string) error { // emailed link. Only the hash is persisted; the raw token is never stored. email is the // address being verified for email_verify, and "" for password_reset. func (a *Manager) CreateMagicLink(kind MagicLinkKind, userID, email string, ttl time.Duration) (string, error) { - raw := generateLinkToken() + token := generateLinkToken() now := time.Now() m := &MagicLink{ - TokenHash: hashToken(raw), + TokenHash: hashToken(token), Kind: kind, UserID: userID, Email: email, @@ -1574,7 +1574,7 @@ func (a *Manager) CreateMagicLink(kind MagicLinkKind, userID, email string, ttl if err := a.AddMagicLink(m); err != nil { return "", err } - return raw, nil + return token, nil } // MagicLinkByToken looks up a magic link by its raw token (hashing it first). See MagicLinkByHash. diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index e8926227..0e1ce85f 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -28,7 +28,7 @@ "login_title": "Sign in to your ntfy account", "login_form_button_submit": "Sign in", "login_link_signup": "Sign up", - "login_link_forgot_password": "Forgot password?", + "login_link_forgot_password": "Forgot password", "reset_password_request_title": "Reset password", "reset_password_request_description": "Enter your username or email address. If an account exists, a link to reset your password will be emailed. This only works if you already added a primary email address and verified it.", "reset_password_request_identifier_label": "Username or email", diff --git a/web/src/app/errors.js b/web/src/app/errors.js index 5b749d14..34c86f8d 100644 --- a/web/src/app/errors.js +++ b/web/src/app/errors.js @@ -31,11 +31,11 @@ export class TopicReservedError extends Error { } } -export class AccountCreateLimitReachedError extends Error { - static CODE = 42906; // errHTTPTooManyRequestsLimitAccountCreation +export class AccountActionLimitReachedError extends Error { + static CODE = 42906; // errHTTPTooManyRequestsLimitAccountActions constructor() { - super("Account creation limit reached"); + super("Account action limit reached"); } } @@ -75,8 +75,8 @@ export const throwAppError = async (response) => { throw new UserExistsError(); } else if (error.code === TopicReservedError.CODE) { throw new TopicReservedError(); - } else if (error.code === AccountCreateLimitReachedError.CODE) { - throw new AccountCreateLimitReachedError(); + } else if (error.code === AccountActionLimitReachedError.CODE) { + throw new AccountActionLimitReachedError(); } else if (error.code === IncorrectPasswordError.CODE) { throw new IncorrectPasswordError(); } else if (error.code === EmailVerificationCodeInvalidError.CODE) { diff --git a/web/src/components/Signup.jsx b/web/src/components/Signup.jsx index cd3a3d87..8dcd4ea2 100644 --- a/web/src/components/Signup.jsx +++ b/web/src/components/Signup.jsx @@ -9,7 +9,7 @@ import accountApi from "../app/AccountApi"; import AvatarBox from "./AvatarBox"; import session from "../app/Session"; import routes from "./routes"; -import { AccountCreateLimitReachedError, UserExistsError } from "../app/errors"; +import { AccountActionLimitReachedError, UserExistsError } from "../app/errors"; const Signup = () => { const { t } = useTranslation(); @@ -34,7 +34,7 @@ const Signup = () => { console.log(`[Signup] Signup for user ${user.username} failed`, e); if (e instanceof UserExistsError) { setError(t("signup_error_username_taken", { username: e.username })); - } else if (e instanceof AccountCreateLimitReachedError) { + } else if (e instanceof AccountActionLimitReachedError) { setError(t("signup_error_creation_limit_reached")); } else { setError(e.message); From 99bc80327140d680fcad0ceb3cd95a29e1f5c320 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Tue, 16 Jun 2026 21:18:58 -0400 Subject: [PATCH 15/34] Code review --- server/errors.go | 2 +- server/server_account.go | 23 ++++++++++----------- server/server_account_email_test.go | 31 +++++++++++++++++++++++++++++ user/manager.go | 13 ++++++++++++ 4 files changed, 56 insertions(+), 13 deletions(-) diff --git a/server/errors.go b/server/errors.go index caf1abc0..0b0f790d 100644 --- a/server/errors.go +++ b/server/errors.go @@ -167,7 +167,7 @@ var ( errHTTPTooManyRequestsLimitSubscriptions = &errHTTP{42903, http.StatusTooManyRequests, "limit reached: too many active subscriptions", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPTooManyRequestsLimitTotalTopics = &errHTTP{42904, http.StatusTooManyRequests, "limit reached: the total number of topics on the server has been reached, please contact the admin", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPTooManyRequestsLimitAttachmentBandwidth = &errHTTP{42905, http.StatusTooManyRequests, "limit reached: daily bandwidth reached", "https://ntfy.sh/docs/publish/#limitations", nil} - errHTTPTooManyRequestsLimitAccountActions = &errHTTP{42906, http.StatusTooManyRequests, "limit reached: too many account requests", "https://ntfy.sh/docs/publish/#limitations", nil} // FIXME document limit + errHTTPTooManyRequestsLimitAccountActions = &errHTTP{42906, http.StatusTooManyRequests, "limit reached: too many account requests", "https://ntfy.sh/docs/publish/#limitations", nil} // FIXME document limit errHTTPTooManyRequestsLimitReservations = &errHTTP{42907, http.StatusTooManyRequests, "limit reached: too many topic reservations for this user", "", nil} errHTTPTooManyRequestsLimitMessages = &errHTTP{42908, http.StatusTooManyRequests, "limit reached: daily message quota reached", "https://ntfy.sh/docs/publish/#limitations", nil} errHTTPTooManyRequestsLimitAuthFailure = &errHTTP{42909, http.StatusTooManyRequests, "limit reached: too many auth failures", "https://ntfy.sh/docs/publish/#limitations", nil} // FIXME document limit diff --git a/server/server_account.go b/server/server_account.go index 517fb938..c1556cf1 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -825,21 +825,20 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt return s.writeJSON(w, newSuccessResponse()) } -// resolveResetTarget resolves a reset identifier to a single account and its primary email. -// The identifier is tried first as a username, then as a primary email address. It returns -// ok=false if no account with a primary email matches (reset requires a verified primary email). +// resolveResetTarget resolves a reset identifier (username or primary email) to a single account +// and its primary email. It applies the reset policy on top of the lookup: provisioned users are +// excluded, and ok=false is returned unless the account has a verified primary email (reset +// requires one, and that is where the link is sent). func (s *Server) resolveResetTarget(identifier string) (userID string, email string, ok bool) { - if u, err := s.userManager.User(identifier); err == nil && u != nil && !u.Provisioned { - if primary, perr := s.userManager.PrimaryEmail(u.ID); perr == nil && primary != "" { - return u.ID, primary, true - } + u, err := s.userManager.UserByEmailOrUsername(identifier) + if err != nil || u == nil || u.Provisioned { + return "", "", false } - if uid, err := s.userManager.UserIDByPrimaryEmail(identifier); err == nil { - if u, uerr := s.userManager.UserByID(uid); uerr == nil && !u.Provisioned { - return uid, identifier, true - } + primary, err := s.userManager.PrimaryEmail(u.ID) + if err != nil || primary == "" { + return "", "", false } - return "", "", false + return u.ID, primary, true } // handleAccountPasswordReset performs the reset (POST /v1/account/password/reset, unauthenticated): diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index e5168cfe..9bbcccd5 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -259,6 +259,37 @@ func TestAccount_PasswordReset_ByEmail(t *testing.T) { }) } +func TestAccount_PasswordReset_EmailLookalikeUsernameDoesNotShadow(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s, mailer, auth := newEmailTestServer(t, databaseURL) + defer s.closeDatabases() + + // Account A (the email owner): user "ben" with verified primary email "phil@example.com" + verifyEmailFor(t, s, mailer, auth, "phil@example.com") + + // Account B (the squatter): a different account whose USERNAME looks like A's email, with + // its own, different verified primary email + require.Nil(t, s.userManager.AddUser("phil@example.com", "squatterpass", user.RoleUser, false)) + squatter, err := s.userManager.User("phil@example.com") + require.Nil(t, err) + require.Nil(t, s.userManager.AddEmail(squatter.ID, "squatter@example.com")) + require.Nil(t, s.userManager.SetPrimaryEmail(squatter.ID, "squatter@example.com")) + + // Reset by the ambiguous identifier: the verified email must win over the look-alike username + rr := request(t, s, "POST", "/v1/account/password/reset/request", `{"identifier":"phil@example.com"}`, nil) + require.Equal(t, 200, rr.Code) + require.NotEmpty(t, mailer.resetLinks["phil@example.com"]) // sent to the email owner (account A) + require.Empty(t, mailer.resetLinks["squatter@example.com"]) // NOT the username squatter (account B) + + // The token resets account A (ben); the squatter's password is untouched + token := tokenFromLink(t, mailer.resetLinks["phil@example.com"], "https://ntfy.example.com/account/password/reset/") + rr = request(t, s, "POST", "/v1/account/password/reset", fmt.Sprintf(`{"token":"%s","password":"brandnew"}`, token), nil) + require.Equal(t, 200, rr.Code) + require.True(t, canLogin(t, s, "ben", "brandnew")) // account A was reset + require.True(t, canLogin(t, s, "phil@example.com", "squatterpass")) // account B unaffected + }) +} + func TestAccount_PasswordReset_UnknownIdentifierUniform(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s, mailer, _ := newEmailTestServer(t, databaseURL) diff --git a/user/manager.go b/user/manager.go index 40b61647..1c20367c 100644 --- a/user/manager.go +++ b/user/manager.go @@ -515,6 +515,19 @@ func (a *Manager) UserByID(id string) (*User, error) { return a.readUser(rows) } +// UserByEmailOrUsername resolves an identifier to a single user, trying it first as a primary +// email address and then as a username. A verified, owned email takes precedence over a +// freely-chosen username, so a look-alike username cannot shadow the email's real owner. Returns +// ErrUserNotFound if neither matches. +func (a *Manager) UserByEmailOrUsername(identifier string) (*User, error) { + if userID, err := a.UserIDByPrimaryEmail(identifier); err == nil { + if u, err := a.UserByID(userID); err == nil { + return u, nil + } + } + return a.User(identifier) +} + // userByToken returns the user with the given token if it exists and is not expired, or ErrUserNotFound otherwise func (a *Manager) userByToken(token string) (*User, error) { rows, err := a.db.Query(a.queries.selectUserByToken, token, time.Now().Unix()) From 01eabb288acaa960dc6b3e8247caa60935478118 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Tue, 16 Jun 2026 21:35:03 -0400 Subject: [PATCH 16/34] Review --- server/server.go | 27 +++++++++++++-------------- server/server_test.go | 21 +++++++++++++++++++++ 2 files changed, 34 insertions(+), 14 deletions(-) diff --git a/server/server.go b/server/server.go index de9c21b1..d79d7ad0 100644 --- a/server/server.go +++ b/server/server.go @@ -545,7 +545,7 @@ func (s *Server) handleError(w http.ResponseWriter, r *http.Request, v *visitor, func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visitor) error { if r.Method == http.MethodGet && r.URL.Path == "/" && s.config.WebRoot == "/" { - return s.ensureWebEnabled(s.handleRoot)(w, r, v) + return s.ensureWebEnabled(s.handleWebApp)(w, r, v) } else if r.Method == http.MethodHead && r.URL.Path == "/" { return s.ensureWebEnabled(s.handleEmpty)(w, r, v) } else if r.Method == http.MethodGet && r.URL.Path == apiHealthPath { @@ -671,27 +671,27 @@ func (s *Server) handleInternal(w http.ResponseWriter, r *http.Request, v *visit } else if r.Method == http.MethodGet && authPathRegex.MatchString(r.URL.Path) { return s.limitRequests(s.authorizeTopicRead(s.handleTopicAuth))(w, r, v) } else if r.Method == http.MethodGet && (webAppEmailVerifyRegex.MatchString(r.URL.Path) || webAppPasswordResetRegex.MatchString(r.URL.Path)) { - return s.ensureWebEnabled(s.handleWebAppIndex)(w, r, v) // Magic-link landing pages (client-side routes) + return s.ensureWebEnabled(s.handleWebAppNoIndex)(w, r, v) // Magic-link landing pages (client-side routes) } else if r.Method == http.MethodGet && (topicPathRegex.MatchString(r.URL.Path) || externalTopicPathRegex.MatchString(r.URL.Path)) { return s.ensureWebEnabled(s.handleTopic)(w, r, v) } return errHTTPNotFound } -// handleWebAppIndex serves the embedded web app's index for client-side (SPA) routes the -// browser router resolves, such as the magic-link landing pages. Because these URLs carry a -// one-time token in the path, the response is marked no-referrer (so the token can't leak to -// third parties via the Referer header) and noindex (so it never gets indexed). -func (s *Server) handleWebAppIndex(w http.ResponseWriter, r *http.Request, v *visitor) error { - w.Header().Set("Referrer-Policy", "no-referrer") - w.Header().Set("X-Robots-Tag", "noindex") +// handleWebApp serves the embedded web app's index for client-side (SPA) routes that the +// browser router resolves, so the app shell loads and the client-side router takes over. +func (s *Server) handleWebApp(w http.ResponseWriter, r *http.Request, v *visitor) error { r.URL.Path = webAppIndex return s.handleStatic(w, r, v) } -func (s *Server) handleRoot(w http.ResponseWriter, r *http.Request, v *visitor) error { - r.URL.Path = webAppIndex - return s.handleStatic(w, r, v) +// handleWebAppNoIndex serves the web app index for the magic-link landing pages, whose path +// carries a one-time token. The response is marked no-referrer (so the token can't leak to third +// parties via the Referer header) and noindex (so it never gets indexed). +func (s *Server) handleWebAppNoIndex(w http.ResponseWriter, r *http.Request, v *visitor) error { + w.Header().Set("Referrer-Policy", "no-referrer") + w.Header().Set("X-Robots-Tag", "noindex") + return s.handleWebApp(w, r, v) } func (s *Server) handleTopic(w http.ResponseWriter, r *http.Request, v *visitor) error { @@ -702,8 +702,7 @@ func (s *Server) handleTopic(w http.ResponseWriter, r *http.Request, v *visitor) _, err := io.WriteString(w, `{"unifiedpush":{"version":1}}`+"\n") return err } - r.URL.Path = webAppIndex - return s.handleStatic(w, r, v) + return s.handleWebApp(w, r, v) } func (s *Server) handleEmpty(_ http.ResponseWriter, _ *http.Request, _ *visitor) error { diff --git a/server/server_test.go b/server/server_test.go index 646cd393..eec41e03 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -264,6 +264,27 @@ func TestServer_StaticSites(t *testing.T) { }) } +func TestServer_WebApp_MagicLinkLandingPagesNoIndexHeaders(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + s := newTestServer(t, newTestConfig(t, databaseURL)) + + // Magic-link landing pages carry a one-time token in the path, so the response must not + // leak the token via the Referer header and must not be indexed + for _, path := range []string{"/account/email/verify/sometoken", "/account/password/reset/sometoken"} { + rr := request(t, s, "GET", path, "", nil) + require.Equal(t, 200, rr.Code, path) + require.Equal(t, "no-referrer", rr.Header().Get("Referrer-Policy"), path) + require.Equal(t, "noindex", rr.Header().Get("X-Robots-Tag"), path) + } + + // Ordinary web app routes do not set these headers + rr := request(t, s, "GET", "/", "", nil) + require.Equal(t, 200, rr.Code) + require.Empty(t, rr.Header().Get("Referrer-Policy")) + require.Empty(t, rr.Header().Get("X-Robots-Tag")) + }) +} + func TestServer_WebEnabled(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { conf := newTestConfig(t, databaseURL) From 2ee8717e0c7c41381a32d68e9dfb4ae614902338 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 13:58:23 -0400 Subject: [PATCH 17/34] Don't use consts in queries --- user/manager.go | 8 ++++---- user/manager_postgres.go | 6 +++--- user/manager_sqlite.go | 6 +++--- 3 files changed, 10 insertions(+), 10 deletions(-) diff --git a/user/manager.go b/user/manager.go index 1c20367c..e98adee0 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1523,7 +1523,7 @@ func (a *Manager) UserIDByPrimaryEmail(email string) (string, error) { // PendingEmails returns the user's unverified (pending) email addresses, i.e. addresses with // an outstanding email-verification magic link. func (a *Manager) PendingEmails(userID string) ([]string, error) { - rows, err := a.db.ReadOnly().Query(a.queries.selectPendingEmails, userID) + rows, err := a.db.ReadOnly().Query(a.queries.selectPendingEmails, string(MagicLinkKindEmailVerify), userID) if err != nil { return nil, err } @@ -1608,11 +1608,11 @@ func (a *Manager) AddMagicLink(m *MagicLink) error { return db.ExecTx(a.db, func(tx *sql.Tx) error { switch m.Kind { case MagicLinkKindEmailVerify: - if _, err := tx.Exec(a.queries.deleteVerifyScope, m.UserID, m.Email); err != nil { + if _, err := tx.Exec(a.queries.deleteVerifyScope, string(MagicLinkKindEmailVerify), m.UserID, m.Email); err != nil { return err } case MagicLinkKindPasswordReset: - if _, err := tx.Exec(a.queries.deleteResetScope, m.UserID); err != nil { + if _, err := tx.Exec(a.queries.deleteResetScope, string(MagicLinkKindPasswordReset), m.UserID); err != nil { return err } default: @@ -1653,7 +1653,7 @@ func (a *Manager) DeleteMagicLink(tokenHash string) error { // DeleteEmailVerification removes any pending email verification for (userID, email). Used when // an unverified (pending) address is cancelled/deleted from the account. func (a *Manager) DeleteEmailVerification(userID, email string) error { - _, err := a.db.Exec(a.queries.deleteVerifyScope, userID, email) + _, err := a.db.Exec(a.queries.deleteVerifyScope, string(MagicLinkKindEmailVerify), userID, email) return err } diff --git a/user/manager_postgres.go b/user/manager_postgres.go index 9cedf5fd..57fcf312 100644 --- a/user/manager_postgres.go +++ b/user/manager_postgres.go @@ -230,9 +230,9 @@ const ( postgresInsertMagicLinkQuery = `INSERT INTO user_magic_link (token_hash, kind, user_id, email, expires, created) VALUES ($1, $2, $3, $4, $5, $6)` postgresSelectMagicLinkByHashQuery = `SELECT token_hash, kind, user_id, email, expires, created FROM user_magic_link WHERE token_hash = $1` postgresDeleteMagicLinkByHashQuery = `DELETE FROM user_magic_link WHERE token_hash = $1` - postgresDeleteVerifyScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'email_verify' AND user_id = $1 AND email = $2` - postgresDeleteResetScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'password_reset' AND user_id = $1` - postgresSelectPendingEmailsQuery = `SELECT email FROM user_magic_link WHERE kind = 'email_verify' AND user_id = $1 ORDER BY email` + postgresDeleteVerifyScopeQuery = `DELETE FROM user_magic_link WHERE kind = $1 AND user_id = $2 AND email = $3` + postgresDeleteResetScopeQuery = `DELETE FROM user_magic_link WHERE kind = $1 AND user_id = $2` + postgresSelectPendingEmailsQuery = `SELECT email FROM user_magic_link WHERE kind = $1 AND user_id = $2 ORDER BY email` postgresDeleteExpiredMagicLinksQuery = `DELETE FROM user_magic_link WHERE expires < $1` // Billing queries diff --git a/user/manager_sqlite.go b/user/manager_sqlite.go index 61bafc94..9bcf13df 100644 --- a/user/manager_sqlite.go +++ b/user/manager_sqlite.go @@ -227,9 +227,9 @@ const ( sqliteInsertMagicLinkQuery = `INSERT INTO user_magic_link (token_hash, kind, user_id, email, expires, created) VALUES (?, ?, ?, ?, ?, ?)` sqliteSelectMagicLinkByHashQuery = `SELECT token_hash, kind, user_id, email, expires, created FROM user_magic_link WHERE token_hash = ?` sqliteDeleteMagicLinkByHashQuery = `DELETE FROM user_magic_link WHERE token_hash = ?` - sqliteDeleteVerifyScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'email_verify' AND user_id = ? AND email = ?` - sqliteDeleteResetScopeQuery = `DELETE FROM user_magic_link WHERE kind = 'password_reset' AND user_id = ?` - sqliteSelectPendingEmailsQuery = `SELECT email FROM user_magic_link WHERE kind = 'email_verify' AND user_id = ? ORDER BY email` + sqliteDeleteVerifyScopeQuery = `DELETE FROM user_magic_link WHERE kind = ? AND user_id = ? AND email = ?` + sqliteDeleteResetScopeQuery = `DELETE FROM user_magic_link WHERE kind = ? AND user_id = ?` + sqliteSelectPendingEmailsQuery = `SELECT email FROM user_magic_link WHERE kind = ? AND user_id = ? ORDER BY email` sqliteDeleteExpiredMagicLinksQuery = `DELETE FROM user_magic_link WHERE expires < ?` // Billing queries From bb2ca0facf0c3d55721f32702aec9d00c975b505 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 14:15:12 -0400 Subject: [PATCH 18/34] Send "X-Email: yes" to primary --- docs/config.md | 3 ++- docs/publish.md | 5 +++-- server/server_account.go | 11 +++++++++-- server/server_test.go | 39 +++++++++++++++++++++++++++++++++++++-- 4 files changed, 51 insertions(+), 7 deletions(-) diff --git a/docs/config.md b/docs/config.md index bc241a4f..f51ad537 100644 --- a/docs/config.md +++ b/docs/config.md @@ -1049,7 +1049,8 @@ configured for `ntfy.sh`): By default, any user (including anonymous users) can send email notifications to any address. To require email address verification, set `smtp-sender-verify` to `true`. When enabled, anonymous users cannot send emails, and authenticated users can only send to email addresses they have verified in their account settings. Users can -also use `yes`/`true`/`1` as the `X-Email` value to send to their first verified address. +also use `yes`/`true`/`1` as the `X-Email` value to send to their primary verified address (falling back to their +first verified address if no primary is designated). Please also refer to the [rate limiting](#rate-limiting) settings below, specifically `visitor-email-limit-burst` and `visitor-email-limit-burst`. Setting these conservatively is necessary to avoid abuse. diff --git a/docs/publish.md b/docs/publish.md index 0060cdcc..95354362 100644 --- a/docs/publish.md +++ b/docs/publish.md @@ -3252,7 +3252,8 @@ you'd like to persist longer, or to blast-notify yourself on all possible channe Usage is easy: Simply pass the `X-Email` header (or any of its aliases: `X-E-mail`, `Email`, `E-mail`, `Mail`, or `e`). Only one e-mail address is supported. If the server has [`smtp-sender-verify`](config.md#e-mail-notifications) enabled (ntfy.sh has this enabled), -you can also pass `yes`, `true`, or `1` to send to your first verified email address. +you can also pass `yes`, `true`, or `1` to send to your **primary email address** (the one marked primary in the web app's +[Account section](https://ntfy.sh/account)). If you haven't designated a primary address, it falls back to your first verified address. ntfy allows anonymous email sending (if enabled), so the rate limiting is pretty strict (see [limitations](#limitations)). In the default configuration, you get **16 e-mails per visitor** (IP address) and then after that one per hour. On top of @@ -3702,7 +3703,7 @@ all the supported fields: | `icon` | - | *string* | `https://example.com/icon.png` | URL to use as notification [icon](#icons) | | `filename` | - | *string* | `file.jpg` | File name of the attachment | | `delay` | - | *string* | `30min`, `9am` | Timestamp or duration for delayed delivery | -| `email` | - | *e-mail address or 'yes'* | `phil@example.com` or `yes` | E-mail address for e-mail notifications, or `yes` to use first verified address | +| `email` | - | *e-mail address or 'yes'* | `phil@example.com` or `yes` | E-mail address for e-mail notifications, or `yes` to use your primary verified address | | `call` | - | *phone number or 'yes'* | `+1222334444` or `yes` | Phone number to use for [voice call](#phone-calls) | | `sequence_id` | - | *string* | `my-sequence-123` | Sequence ID for [updating/deleting notifications](#updating-deleting-notifications) | diff --git a/server/server_account.go b/server/server_account.go index c1556cf1..7598a91f 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -866,7 +866,8 @@ func (s *Server) handleAccountPasswordReset(w http.ResponseWriter, r *http.Reque // convertEmailAddress checks the email address against the user's verified email list. // If smtp-sender-verify is false (default), the email is passed through as-is for // backwards compatibility. If true, the user must be authenticated and the email must be -// in their verified list. "yes"/"true"/"1" resolves to the first verified email. +// in their verified list. "yes"/"true"/"1" resolves to the user's primary email (falling +// back to the first verified email if no primary is designated). func (s *Server) convertEmailAddress(u *user.User, email string) (string, *errHTTP) { if !s.config.SMTPSenderVerify { if toBool(email) { @@ -885,7 +886,13 @@ func (s *Server) convertEmailAddress(u *user.User, email string) (string, *errHT return "", errHTTPBadRequestEmailAddressNotVerified } if toBool(email) { - return emails[0], nil + primary, err := s.userManager.PrimaryEmail(u.ID) + if err != nil { + return "", errHTTPInternalError + } else if primary != "" { + return primary, nil + } + return emails[0], nil // No primary designated (e.g. provisioned user); fall back to first verified } else if util.Contains(emails, email) { return email, nil } diff --git a/server/server_test.go b/server/server_test.go index eec41e03..a6106a93 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -1336,14 +1336,16 @@ func TestServer_DailyMessageQuotaFromDatabase(t *testing.T) { } type testMailer struct { - count int - mu sync.Mutex + count int + lastTo string + mu sync.Mutex } func (t *testMailer) SendNotification(to string, m *model.Message, senderIP string) error { t.mu.Lock() defer t.mu.Unlock() t.count++ + t.lastTo = to return nil } @@ -1357,6 +1359,12 @@ func (t *testMailer) Count() int { return t.count } +func (t *testMailer) LastTo() string { + t.mu.Lock() + defer t.mu.Unlock() + return t.lastTo +} + func (t *testMailer) SendEmailVerification(to, link string) error { return nil } func (t *testMailer) SendPasswordReset(to, link string) error { return nil } @@ -1653,6 +1661,33 @@ func TestServer_PublishEmailVerify_BoolValue(t *testing.T) { }) } +func TestServer_PublishEmailVerify_BoolValueUsesPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.SMTPSenderVerify = true + s := newTestServer(t, conf) + mailer := &testMailer{} + s.mailer = mailer + defer s.closeDatabases() + + require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) + u, err := s.userManager.User("phil") + require.Nil(t, err) + // Two verified emails; the primary is NOT the alphabetically-first one + require.Nil(t, s.userManager.AddEmail(u.ID, "aaa@example.com")) + require.Nil(t, s.userManager.AddEmail(u.ID, "zzz@example.com")) + require.Nil(t, s.userManager.SetPrimaryEmail(u.ID, "zzz@example.com")) + + // "yes" must resolve to the primary email, not emails[0] (alphabetically first) + response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ + "Email": "yes", + "Authorization": util.BasicAuth("phil", "phil"), + }) + require.Equal(t, 200, response.Code) + require.Equal(t, "zzz@example.com", mailer.LastTo()) + }) +} + func TestServer_PublishEmailVerify_BoolValue_NoVerify(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) From 8a7b73cc7e5027a5c0bbd427162dd08d4fb0953c Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 14:20:36 -0400 Subject: [PATCH 19/34] Remove dead strings --- web/public/static/langs/en.json | 2 -- 1 file changed, 2 deletions(-) diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 0e1ce85f..b9ec613c 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -245,7 +245,6 @@ "account_basics_emails_description": "For email notifications and password reset", "account_basics_emails_no_emails_yet": "No emails yet", "account_basics_emails_copied_to_clipboard": "Email address copied to clipboard", - "account_basics_emails_primary_badge": "Primary", "account_basics_emails_chip_actions": "Click for actions", "account_basics_emails_chip_actions_primary": "Primary address, can be used for account recovery and notifications. Click for actions.", "account_basics_emails_chip_actions_verified": "Can be used for notifications. Click for actions.", @@ -253,7 +252,6 @@ "account_basics_emails_unverified": "unverified", "account_basics_emails_set_primary": "Set as primary email", "account_basics_emails_delete": "Remove address", - "account_basics_emails_cancel": "Cancel", "account_basics_emails_resend": "Resend verification email", "account_basics_emails_resent": "Verification email sent, check your inbox", "account_basics_emails_primary_elsewhere": "This email address is used as the primary address on another account", From 36d7d3bd241ccc973a1fbc9dd5761be5c3181cb1 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 14:55:27 -0400 Subject: [PATCH 20/34] Rename --- web/src/components/Account.jsx | 1 + web/src/components/App.jsx | 6 +++--- web/src/components/Login.jsx | 2 +- .../{ResetPassword.jsx => PasswordResetRequest.jsx} | 8 ++++---- web/src/components/routes.js | 6 +++--- 5 files changed, 12 insertions(+), 11 deletions(-) rename web/src/components/{ResetPassword.jsx => PasswordResetRequest.jsx} (93%) diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index 016d97e4..f37089e0 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -567,6 +567,7 @@ const AddEmailDialog = (props) => { const handleSubmit = async () => { try { setSending(true); + setError(""); // Clear any error from a previous attempt await accountApi.startEmailVerification(email); await accountApi.sync(); // Refresh so the new "(unverified)" address shows up immediately setSent(true); diff --git a/web/src/components/App.jsx b/web/src/components/App.jsx index bfa38d42..d386fedd 100644 --- a/web/src/components/App.jsx +++ b/web/src/components/App.jsx @@ -22,7 +22,7 @@ import Signup from "./Signup"; import Account from "./Account"; import EmailVerify from "./EmailVerify"; import PasswordReset from "./PasswordReset"; -import ResetPassword from "./ResetPassword"; +import PasswordResetRequest from "./PasswordResetRequest"; import initI18n from "../app/i18n"; // Translations! import prefs from "../app/Prefs"; import RTLCacheProvider from "./RTLCacheProvider"; @@ -66,9 +66,9 @@ const App = () => { } /> } /> - } /> - } /> + } /> } /> + } /> }> } /> } /> diff --git a/web/src/components/Login.jsx b/web/src/components/Login.jsx index 9bf8e1c5..ad14ebb9 100644 --- a/web/src/components/Login.jsx +++ b/web/src/components/Login.jsx @@ -102,7 +102,7 @@ const Login = () => { {config.enable_reset_password && (
- + {t("login_link_forgot_password")}
diff --git a/web/src/components/ResetPassword.jsx b/web/src/components/PasswordResetRequest.jsx similarity index 93% rename from web/src/components/ResetPassword.jsx rename to web/src/components/PasswordResetRequest.jsx index 6b765d5f..3a93ba14 100644 --- a/web/src/components/ResetPassword.jsx +++ b/web/src/components/PasswordResetRequest.jsx @@ -8,11 +8,11 @@ import accountApi from "../app/AccountApi"; import AvatarBox from "./AvatarBox"; import routes from "./routes"; -// ResetPassword is the standalone "request a password reset" page, reached from the login page. +// PasswordResetRequest is the standalone "request a password reset" page, reached from the login page. // It collects a username/email and asks the server to email a reset link. The response is uniform, // so the page always shows the same confirmation. Completing the reset happens on the separate // PasswordReset landing page that the emailed link points to. -const ResetPassword = () => { +const PasswordResetRequest = () => { const { t } = useTranslation(); const [identifier, setIdentifier] = useState(""); const [sending, setSending] = useState(false); @@ -24,7 +24,7 @@ const ResetPassword = () => { setSending(true); await accountApi.requestPasswordReset(identifier); } catch (e) { - console.log(`[ResetPassword] Request failed`, e); + console.log(`[PasswordResetRequest] Request failed`, e); } finally { setSending(false); setSent(true); // Uniform outcome regardless of success/failure (enumeration-safe) @@ -92,4 +92,4 @@ const ResetPassword = () => { ); }; -export default ResetPassword; +export default PasswordResetRequest; diff --git a/web/src/components/routes.js b/web/src/components/routes.js index 463fb237..e81d077b 100644 --- a/web/src/components/routes.js +++ b/web/src/components/routes.js @@ -4,12 +4,12 @@ import { shortUrl } from "../app/utils"; const routes = { login: "/login", signup: "/signup", - resetPassword: "/reset-password", app: config.app_root, account: "/account", settings: "/settings", - emailVerify: "/account/email/verify/:token", + passwordResetRequest: "/reset-password", passwordReset: "/account/password/reset/:token", + emailVerify: "/account/email/verify/:token", subscription: "/:topic", subscriptionExternal: "/:baseUrl/:topic", forSubscription: (subscription) => { @@ -17,7 +17,7 @@ const routes = { return `/${shortUrl(subscription.baseUrl)}/${subscription.topic}`; } return `/${subscription.topic}`; - }, + } }; export default routes; From 3d02c99394407e12972285ca868c4dbb8452a1c5 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 15:11:54 -0400 Subject: [PATCH 21/34] Strings --- web/public/static/langs/en.json | 1 - web/src/components/PasswordReset.jsx | 2 +- 2 files changed, 1 insertion(+), 2 deletions(-) diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index b9ec613c..53c913f1 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -45,7 +45,6 @@ "reset_password_form_error_invalid": "This reset link is invalid or has expired. Please request a new one.", "reset_password_success_title": "Password changed", "reset_password_success_description": "Your password has been changed. You can now sign in with your new password.", - "reset_password_button_login": "Sign in", "login_disabled": "Login is disabled", "action_bar_show_menu": "Show menu", "action_bar_logo_alt": "ntfy logo", diff --git a/web/src/components/PasswordReset.jsx b/web/src/components/PasswordReset.jsx index 091a22c6..4f9b857d 100644 --- a/web/src/components/PasswordReset.jsx +++ b/web/src/components/PasswordReset.jsx @@ -56,7 +56,7 @@ const PasswordReset = () => {
{t("reset_password_success_description")} ); From 74332fa302c9b30b18ccccd344755c8f7199c4d9 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 15:18:58 -0400 Subject: [PATCH 22/34] Remove unused strings --- web/public/static/langs/en.json | 3 --- 1 file changed, 3 deletions(-) diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 53c913f1..9c5793b6 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -244,7 +244,6 @@ "account_basics_emails_description": "For email notifications and password reset", "account_basics_emails_no_emails_yet": "No emails yet", "account_basics_emails_copied_to_clipboard": "Email address copied to clipboard", - "account_basics_emails_chip_actions": "Click for actions", "account_basics_emails_chip_actions_primary": "Primary address, can be used for account recovery and notifications. Click for actions.", "account_basics_emails_chip_actions_verified": "Can be used for notifications. Click for actions.", "account_basics_emails_chip_actions_unverified": "Unverified address, check your inbox to verify. Click for actions.", @@ -322,7 +321,6 @@ "account_upgrade_dialog_tier_features_calls_other": "{{calls}} daily phone calls", "account_upgrade_dialog_tier_features_no_calls": "No phone calls", "account_upgrade_dialog_tier_features_attachment_file_size": "{{filesize}} per file", - "account_upgrade_dialog_tier_features_attachment_total_size": "{{totalsize}} total storage", "account_upgrade_dialog_tier_price_per_month": "month", "account_upgrade_dialog_tier_price_billed_monthly": "{{price}} per year. Billed monthly.", "account_upgrade_dialog_tier_price_billed_yearly": "{{price}} billed annually. Save {{save}}.", @@ -454,7 +452,6 @@ "error_boundary_button_copy_stack_trace": "Copy stack trace", "error_boundary_button_reload_ntfy": "Reload ntfy", "error_boundary_stack_trace": "Stack trace", - "error_boundary_gathering_info": "Gather more info …", "error_boundary_unsupported_indexeddb_title": "Private browsing not supported", "error_boundary_unsupported_indexeddb_description": "The ntfy web app needs IndexedDB to function, and your browser does not support IndexedDB in private browsing mode.

While this is unfortunate, it also doesn't really make a lot of sense to use the ntfy web app in private browsing mode anyway, because everything is stored in the browser storage. You can read more about it in this GitHub issue, or talk to us on Discord or Matrix.", "web_push_subscription_expiring_title": "Notifications will be paused", From c45744558b2d3824a247091dd0c09fe741696c3d Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sat, 20 Jun 2026 15:27:14 -0400 Subject: [PATCH 23/34] , --- web/src/components/routes.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/src/components/routes.js b/web/src/components/routes.js index e81d077b..fe395d1d 100644 --- a/web/src/components/routes.js +++ b/web/src/components/routes.js @@ -17,7 +17,7 @@ const routes = { return `/${shortUrl(subscription.baseUrl)}/${subscription.topic}`; } return `/${subscription.topic}`; - } + }, }; export default routes; From 914bf3b0c4091c57a66bd4d250c38bf28111d05d Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sun, 21 Jun 2026 09:52:39 -0400 Subject: [PATCH 24/34] Manual refinement --- web/public/static/langs/en.json | 4 ++-- web/src/components/EmailVerify.jsx | 17 +++++++++++------ web/src/components/PasswordReset.jsx | 12 +++++++----- web/src/components/PasswordResetRequest.jsx | 3 ++- web/src/components/routes.js | 4 ++-- 5 files changed, 24 insertions(+), 16 deletions(-) diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index 9c5793b6..c456aa3c 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -30,7 +30,8 @@ "login_link_signup": "Sign up", "login_link_forgot_password": "Forgot password", "reset_password_request_title": "Reset password", - "reset_password_request_description": "Enter your username or email address. If an account exists, a link to reset your password will be emailed. This only works if you already added a primary email address and verified it.", + "reset_password_request_description": "Enter your username or email address. If an account exists, a link to reset your password will be emailed.", + "reset_password_request_primary_required": "This only works if you already added a primary email address and verified it.", "reset_password_request_identifier_label": "Username or email", "reset_password_request_button_submit": "Send reset link", "reset_password_sent_title": "Check your inbox", @@ -41,7 +42,6 @@ "reset_password_form_password": "New password", "reset_password_form_confirm": "Confirm new password", "reset_password_form_button_submit": "Set password", - "reset_password_form_passwords_no_match": "Passwords do not match", "reset_password_form_error_invalid": "This reset link is invalid or has expired. Please request a new one.", "reset_password_success_title": "Password changed", "reset_password_success_description": "Your password has been changed. You can now sign in with your new password.", diff --git a/web/src/components/EmailVerify.jsx b/web/src/components/EmailVerify.jsx index d1f09783..8ada6886 100644 --- a/web/src/components/EmailVerify.jsx +++ b/web/src/components/EmailVerify.jsx @@ -9,6 +9,11 @@ import accountApi from "../app/AccountApi"; import AvatarBox from "./AvatarBox"; import routes from "./routes"; +// Verification states for the email-verify landing page +const STATUS_VERIFYING = "verifying"; +const STATUS_SUCCESS = "success"; +const STATUS_ERROR = "error"; + // EmailVerify is the magic-link landing page for email verification. It performs the verification // via a POST (the GET that loads this page has no side effects, so link prefetchers / scanners // cannot consume the single-use token). The raw token is stripped from the URL on load to keep @@ -17,7 +22,7 @@ const EmailVerify = () => { const { t } = useTranslation(); const { token } = useParams(); const navigate = useNavigate(); - const [status, setStatus] = useState("verifying"); // "verifying" | "success" | "error" + const [status, setStatus] = useState(STATUS_VERIFYING); const ran = useRef(false); useEffect(() => { @@ -30,23 +35,23 @@ const EmailVerify = () => { (async () => { try { await accountApi.verifyEmailToken(token); - setStatus("success"); + setStatus(STATUS_SUCCESS); } catch (e) { console.log(`[EmailVerify] Verification failed`, e); - setStatus("error"); + setStatus(STATUS_ERROR); } })(); }, [token]); return ( - {status === "verifying" && ( + {status === STATUS_VERIFYING && ( {t("email_verify_progress_title")} )} - {status === "success" && ( + {status === STATUS_SUCCESS && ( <> @@ -58,7 +63,7 @@ const EmailVerify = () => { )} - {status === "error" && ( + {status === STATUS_ERROR && ( <> diff --git a/web/src/components/PasswordReset.jsx b/web/src/components/PasswordReset.jsx index 4f9b857d..68a86eed 100644 --- a/web/src/components/PasswordReset.jsx +++ b/web/src/components/PasswordReset.jsx @@ -30,10 +30,6 @@ const PasswordReset = () => { const handleSubmit = async (event) => { event.preventDefault(); - if (password !== confirm) { - setError(t("reset_password_form_passwords_no_match")); - return; - } try { setSending(true); setError(""); @@ -91,7 +87,13 @@ const PasswordReset = () => { onChange={(ev) => setConfirm(ev.target.value.trim())} autoComplete="new-password" /> - {error && ( diff --git a/web/src/components/PasswordResetRequest.jsx b/web/src/components/PasswordResetRequest.jsx index 3a93ba14..f268dd62 100644 --- a/web/src/components/PasswordResetRequest.jsx +++ b/web/src/components/PasswordResetRequest.jsx @@ -65,7 +65,8 @@ const PasswordResetRequest = () => { {t("reset_password_request_title")} - {t("reset_password_request_description")} + {t("reset_password_request_description")} + {t("reset_password_request_primary_required")} Date: Sun, 21 Jun 2026 09:53:39 -0400 Subject: [PATCH 25/34] fmt --- web/src/components/routes.js | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/src/components/routes.js b/web/src/components/routes.js index 68638cbc..09ffa8fd 100644 --- a/web/src/components/routes.js +++ b/web/src/components/routes.js @@ -17,7 +17,7 @@ const routes = { return `/${shortUrl(subscription.baseUrl)}/${subscription.topic}`; } return `/${subscription.topic}`; - } + }, }; export default routes; From eab3988304b747bfec0f52eaef64f91b82891512 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sun, 21 Jun 2026 10:01:07 -0400 Subject: [PATCH 26/34] Words --- web/public/static/langs/en.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index c456aa3c..d24e9936 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -37,7 +37,7 @@ "reset_password_sent_title": "Check your inbox", "reset_password_sent_description": "If an account exists, a link to reset your password has been emailed.", "reset_password_back_to_login": "Back to sign-in", - "reset_password_disabled": "Password reset is not enabled on this server.", + "reset_password_disabled": "Password reset is disabled", "reset_password_title": "Set a new password", "reset_password_form_password": "New password", "reset_password_form_confirm": "Confirm new password", From d7dea6d250b19389ddd3ed83a5dae223fce8558c Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sun, 21 Jun 2026 11:19:49 -0400 Subject: [PATCH 27/34] Review --- cmd/user.go | 4 +- server/server_account.go | 4 +- server/server_account_email_test.go | 2 +- user/manager.go | 70 ++++++++++++++--------------- user/manager_postgres.go | 4 +- user/manager_sqlite.go | 4 +- user/manager_test.go | 48 ++++++++++++++++---- user/types.go | 39 ++++++++-------- user/util.go | 8 +--- user/util_test.go | 12 ++--- 10 files changed, 110 insertions(+), 85 deletions(-) diff --git a/cmd/user.go b/cmd/user.go index d9d5b0fc..9e33e1da 100644 --- a/cmd/user.go +++ b/cmd/user.go @@ -350,7 +350,7 @@ func execUserResetPass(c *cli.Context) error { } } // The reset token is bound to the user, not an email -- so this works even with no SMTP - token, err := manager.CreateMagicLink(user.MagicLinkKindPasswordReset, u.ID, "", time.Hour) + token, err := manager.AddMagicLink(user.MagicLinkKindPasswordReset, u.ID, "", time.Hour) if err != nil { return err } @@ -398,7 +398,7 @@ func execUserHash(c *cli.Context) error { if err != nil { return err } - hash, err := user.HashPassword(password) + hash, err := user.HashPassword(password, user.DefaultUserPasswordBcryptCost) if err != nil { return fmt.Errorf("failed to hash password: %w", err) } diff --git a/server/server_account.go b/server/server_account.go index 7598a91f..807ad453 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -783,7 +783,7 @@ func (s *Server) enqueueEmailVerification(userID, email string) error { if s.config.BaseURL == "" { return errHTTPInternalErrorMissingBaseURL } - token, err := s.userManager.CreateMagicLink(user.MagicLinkKindEmailVerify, userID, email, emailVerificationTokenExpiry) + token, err := s.userManager.AddMagicLink(user.MagicLinkKindEmailVerify, userID, email, emailVerificationTokenExpiry) if err != nil { return err } @@ -808,7 +808,7 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt identifier := strings.TrimSpace(req.Identifier) if identifier != "" && s.config.BaseURL != "" { if userID, email, ok := s.resolveResetTarget(identifier); ok { - token, err := s.userManager.CreateMagicLink(user.MagicLinkKindPasswordReset, userID, "", passwordResetTokenExpiry) + token, err := s.userManager.AddMagicLink(user.MagicLinkKindPasswordReset, userID, "", passwordResetTokenExpiry) if err != nil { logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to create password reset token") } else { diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index 9bbcccd5..88ebf1cb 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -366,7 +366,7 @@ func TestAccount_Signup_WithoutEmail_NoSend(t *testing.T) { func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { - hash, err := user.HashPassword("provpass") + hash, err := user.HashPassword("provpass", user.DefaultUserPasswordBcryptCost) require.Nil(t, err) conf := newTestConfigWithAuthFile(t, databaseURL) conf.SMTPSenderAddr = "localhost:25" diff --git a/user/manager.go b/user/manager.go index e98adee0..8aea195a 100644 --- a/user/manager.go +++ b/user/manager.go @@ -73,6 +73,9 @@ func newManager(d *db.DB, queries queries, config *Config) (*Manager, error) { if config.AccessCacheReloadInterval <= 0 { config.AccessCacheReloadInterval = DefaultAccessCacheReloadInterval } + if config.ExpiredMagicLinkReapInterval <= 0 { + config.ExpiredMagicLinkReapInterval = DefaultExpiredMagicLinkReapInterval + } manager := &Manager{ config: config, db: d, @@ -92,7 +95,7 @@ func newManager(d *db.DB, queries queries, config *Config) (*Manager, error) { go manager.asyncAccessCacheReloadLoop(manager.config.AccessCacheReloadInterval) } go manager.asyncQueueWriteLoop(manager.config.QueueWriterInterval) - go manager.asyncExpiredMagicLinkReapLoop(DefaultExpiredMagicLinkReapInterval) + go manager.asyncExpiredMagicLinkReapLoop(manager.config.ExpiredMagicLinkReapInterval) return manager, nil } @@ -664,7 +667,7 @@ func (a *Manager) maybeHashPassword(password string, hashed bool) (string, error } return password, nil } - return hashPassword(password, a.config.BcryptCost) + return HashPassword(password, a.config.BcryptCost) } // Authorize returns nil if the given user has access to the given topic using the desired @@ -1569,11 +1572,15 @@ func (a *Manager) SetPrimaryEmail(userID, email string) error { }) } -// CreateMagicLink generates a fresh magic-link token of the given kind, stores it (hashed, -// replacing any existing link in the same scope), and returns the RAW token for use in the -// emailed link. Only the hash is persisted; the raw token is never stored. email is the -// address being verified for email_verify, and "" for password_reset. -func (a *Manager) CreateMagicLink(kind MagicLinkKind, userID, email string, ttl time.Duration) (string, error) { +// AddMagicLink generates a fresh magic-link token of the given kind, stores it (hashed, replacing +// any existing link in the same scope), and returns the RAW token for use in the emailed link. +// Only the hash is persisted; the raw token is never stored. email is the address being verified +// for email_verify, and "" for password_reset. +// +// The scope replaced is, for email_verify, the (user_id, email) pair (one pending verification per +// address); for password_reset, the user_id (one active reset per account). The replace-delete and +// the insert run in one transaction so a re-request atomically supersedes the old token. +func (a *Manager) AddMagicLink(kind MagicLinkKind, userID, email string, ttl time.Duration) (string, error) { token := generateLinkToken() now := time.Now() m := &MagicLink{ @@ -1584,35 +1591,14 @@ func (a *Manager) CreateMagicLink(kind MagicLinkKind, userID, email string, ttl Expires: now.Add(ttl).Unix(), Created: now.Unix(), } - if err := a.AddMagicLink(m); err != nil { - return "", err - } - return token, nil -} - -// MagicLinkByToken looks up a magic link by its raw token (hashing it first). See MagicLinkByHash. -func (a *Manager) MagicLinkByToken(rawToken string) (*MagicLink, error) { - return a.MagicLinkByHash(hashToken(rawToken)) -} - -// DeleteMagicLinkByToken deletes a magic link identified by its raw token (single-use consume). -func (a *Manager) DeleteMagicLinkByToken(rawToken string) error { - return a.DeleteMagicLink(hashToken(rawToken)) -} - -// AddMagicLink stores a pending magic link, replacing any existing link in the same scope: -// for email_verify that is the (user_id, email) pair (one pending verification per address); -// for password_reset that is the user_id (one active reset per account). The replace-delete and -// the insert run in one transaction so a re-request atomically supersedes the old token. -func (a *Manager) AddMagicLink(m *MagicLink) error { - return db.ExecTx(a.db, func(tx *sql.Tx) error { + err := db.ExecTx(a.db, func(tx *sql.Tx) error { switch m.Kind { case MagicLinkKindEmailVerify: - if _, err := tx.Exec(a.queries.deleteVerifyScope, string(MagicLinkKindEmailVerify), m.UserID, m.Email); err != nil { + if _, err := tx.Exec(a.queries.deleteMagicLinkEmailVerify, string(MagicLinkKindEmailVerify), m.UserID, m.Email); err != nil { return err } case MagicLinkKindPasswordReset: - if _, err := tx.Exec(a.queries.deleteResetScope, string(MagicLinkKindPasswordReset), m.UserID); err != nil { + if _, err := tx.Exec(a.queries.deleteMagicLinkResetPassword, string(MagicLinkKindPasswordReset), m.UserID); err != nil { return err } default: @@ -1623,6 +1609,15 @@ func (a *Manager) AddMagicLink(m *MagicLink) error { } return nil }) + if err != nil { + return "", err + } + return token, nil +} + +// MagicLinkByToken looks up a magic link by its raw token (hashing it first). See MagicLinkByHash. +func (a *Manager) MagicLinkByToken(rawToken string) (*MagicLink, error) { + return a.MagicLinkByHash(hashToken(rawToken)) } // MagicLinkByHash looks up a magic link by the hex SHA-256 of its raw token, returning @@ -1643,17 +1638,18 @@ func (a *Manager) MagicLinkByHash(tokenHash string) (*MagicLink, error) { return &m, nil } -// DeleteMagicLink deletes a magic link by its token hash. Used to enforce single use after a -// reset is performed (email verification deletes the row inside VerifyEmail's transaction). -func (a *Manager) DeleteMagicLink(tokenHash string) error { - _, err := a.db.Exec(a.queries.deleteMagicLinkByHash, tokenHash) +// DeleteMagicLinkByToken deletes a magic link identified by its raw token (single-use consume). +// Used to enforce single use after a reset is performed (email verification deletes the row +// inside VerifyEmail's transaction). +func (a *Manager) DeleteMagicLinkByToken(rawToken string) error { + _, err := a.db.Exec(a.queries.deleteMagicLinkByHash, hashToken(rawToken)) return err } // DeleteEmailVerification removes any pending email verification for (userID, email). Used when // an unverified (pending) address is cancelled/deleted from the account. func (a *Manager) DeleteEmailVerification(userID, email string) error { - _, err := a.db.Exec(a.queries.deleteVerifyScope, string(MagicLinkKindEmailVerify), userID, email) + _, err := a.db.Exec(a.queries.deleteMagicLinkEmailVerify, string(MagicLinkKindEmailVerify), userID, email) return err } @@ -1736,7 +1732,7 @@ func (a *Manager) ResetPassword(rawToken, password string) error { if u.Provisioned { return ErrProvisionedUserChange // Provisioned users get their password from the config file, not reset } - hash, err := a.maybeHashPassword(password, false) + hash, err := HashPassword(password, a.config.BcryptCost) if err != nil { return err } diff --git a/user/manager_postgres.go b/user/manager_postgres.go index 57fcf312..a9e12d50 100644 --- a/user/manager_postgres.go +++ b/user/manager_postgres.go @@ -329,8 +329,8 @@ var postgresQueries = queries{ insertMagicLink: postgresInsertMagicLinkQuery, selectMagicLinkByHash: postgresSelectMagicLinkByHashQuery, deleteMagicLinkByHash: postgresDeleteMagicLinkByHashQuery, - deleteVerifyScope: postgresDeleteVerifyScopeQuery, - deleteResetScope: postgresDeleteResetScopeQuery, + deleteMagicLinkEmailVerify: postgresDeleteVerifyScopeQuery, + deleteMagicLinkResetPassword: postgresDeleteResetScopeQuery, selectPendingEmails: postgresSelectPendingEmailsQuery, deleteExpiredMagicLinks: postgresDeleteExpiredMagicLinksQuery, updateBilling: postgresUpdateBillingQuery, diff --git a/user/manager_sqlite.go b/user/manager_sqlite.go index 9bcf13df..a2a46e18 100644 --- a/user/manager_sqlite.go +++ b/user/manager_sqlite.go @@ -325,8 +325,8 @@ var sqliteQueries = queries{ insertMagicLink: sqliteInsertMagicLinkQuery, selectMagicLinkByHash: sqliteSelectMagicLinkByHashQuery, deleteMagicLinkByHash: sqliteDeleteMagicLinkByHashQuery, - deleteVerifyScope: sqliteDeleteVerifyScopeQuery, - deleteResetScope: sqliteDeleteResetScopeQuery, + deleteMagicLinkEmailVerify: sqliteDeleteVerifyScopeQuery, + deleteMagicLinkResetPassword: sqliteDeleteResetScopeQuery, selectPendingEmails: sqliteSelectPendingEmailsQuery, deleteExpiredMagicLinks: sqliteDeleteExpiredMagicLinksQuery, updateBilling: sqliteUpdateBillingQuery, diff --git a/user/manager_test.go b/user/manager_test.go index 6bc0bccd..c6dd2467 100644 --- a/user/manager_test.go +++ b/user/manager_test.go @@ -2,6 +2,7 @@ package user import ( "database/sql" + "errors" "fmt" "net/netip" "path/filepath" @@ -1847,7 +1848,7 @@ func TestMigrationFrom7(t *testing.T) { require.Equal(t, "", primary) // The new magic-link machinery works post-migration - raw, err := a.CreateMagicLink(MagicLinkKindEmailVerify, "u_phil", "new@example.com", 24*time.Hour) + raw, err := a.AddMagicLink(MagicLinkKindEmailVerify, "u_phil", "new@example.com", 24*time.Hour) require.Nil(t, err) m, err := a.VerifyEmail(raw) require.Nil(t, err) @@ -2901,7 +2902,7 @@ func TestStoreOtherAccessCount(t *testing.T) { // addVerifyLink stores an email-verification magic link and returns the raw token so the test // can "click" it via VerifyEmail. func addVerifyLink(t *testing.T, a *Manager, userID, email string, ttl time.Duration) string { - raw, err := a.CreateMagicLink(MagicLinkKindEmailVerify, userID, email, ttl) + raw, err := a.AddMagicLink(MagicLinkKindEmailVerify, userID, email, ttl) require.Nil(t, err) return raw } @@ -3083,7 +3084,7 @@ func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + raw, err := a.AddMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) require.Nil(t, err) m, err := a.MagicLinkByToken(raw) @@ -3098,7 +3099,7 @@ func TestUser_MagicLink_PasswordReset_RoundTrip(t *testing.T) { require.Equal(t, 0, len(pending)) // New request replaces the old token - raw2, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + raw2, err := a.AddMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) require.Nil(t, err) _, err = a.MagicLinkByToken(raw) require.ErrorIs(t, err, ErrMagicLinkNotFound) @@ -3130,6 +3131,37 @@ func TestUser_MagicLink_Reaper(t *testing.T) { }) } +// TestUser_MagicLink_ReaperLoop proves the background reap goroutine actually runs on its +// configured interval: an expired link inserted into a manager with a tiny reap interval is +// deleted without anyone calling deleteExpiredMagicLinks directly. Mirrors the loop-coverage +// pattern of TestAccessCacheReloadInterval_PicksUpExternalWrite. +func TestUser_MagicLink_ReaperLoop(t *testing.T) { + forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { + a := newTestManagerFromConfig(t, newManager, &Config{ + DefaultAccess: PermissionDenyAll, + BcryptCost: bcrypt.MinCost, + ExpiredMagicLinkReapInterval: 25 * time.Millisecond, + }) + require.Nil(t, a.AddUser("phil", "phil", RoleUser, false)) + phil, err := a.User("phil") + require.Nil(t, err) + + expired := addVerifyLink(t, a, phil.ID, "expired@example.com", -time.Hour) + valid := addVerifyLink(t, a, phil.ID, "valid@example.com", time.Hour) + + // The background loop (not a direct call) must reap the expired link within a few intervals + require.Eventually(t, func() bool { + _, err := a.MagicLinkByToken(expired) + return errors.Is(err, ErrMagicLinkNotFound) + }, 2*time.Second, 10*time.Millisecond, "reaper loop never deleted the expired magic link") + + // The unexpired link must survive + m, err := a.MagicLinkByToken(valid) + require.Nil(t, err) + require.Equal(t, "valid@example.com", m.Email) + }) +} + func TestUser_MagicLink_ResetPassword(t *testing.T) { forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { a := newTestManager(t, newManager, PermissionDenyAll) @@ -3137,7 +3169,7 @@ func TestUser_MagicLink_ResetPassword(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + raw, err := a.AddMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) require.Nil(t, err) // Old password works before reset @@ -3169,7 +3201,7 @@ func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) { require.ErrorIs(t, a.ResetPassword(verifyToken, "newpass"), ErrMagicLinkNotFound) // ...and a reset token must not be usable for email verification - resetToken, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) + resetToken, err := a.AddMagicLink(MagicLinkKindPasswordReset, phil.ID, "", time.Hour) require.Nil(t, err) _, err = a.VerifyEmail(resetToken) require.ErrorIs(t, err, ErrMagicLinkNotFound) @@ -3221,7 +3253,7 @@ func TestUser_MagicLink_ResetPassword_ProvisionedRejected(t *testing.T) { // A reset token can be created, but consuming it must be rejected for a provisioned user // (their password comes from the config file, like change-pass). - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, prov.ID, "", time.Hour) + raw, err := a.AddMagicLink(MagicLinkKindPasswordReset, prov.ID, "", time.Hour) require.Nil(t, err) require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrProvisionedUserChange) }) @@ -3234,7 +3266,7 @@ func TestUser_MagicLink_ResetPassword_Expired(t *testing.T) { phil, err := a.User("phil") require.Nil(t, err) - raw, err := a.CreateMagicLink(MagicLinkKindPasswordReset, phil.ID, "", -time.Minute) + raw, err := a.AddMagicLink(MagicLinkKindPasswordReset, phil.ID, "", -time.Minute) require.Nil(t, err) require.ErrorIs(t, a.ResetPassword(raw, "newpass"), ErrMagicLinkNotFound) _, err = a.Authenticate("phil", "oldpass") diff --git a/user/types.go b/user/types.go index ce7efe36..e198b273 100644 --- a/user/types.go +++ b/user/types.go @@ -266,18 +266,19 @@ const ( // Config holds the configuration for the user Manager type Config struct { - Filename string // Database filename, e.g. "/var/lib/ntfy/user.db" (SQLite) - DatabaseURL string // Database connection string (PostgreSQL) - StartupQueries string // Queries to run on startup, e.g. to create initial users or tiers (SQLite only) - DefaultAccess Permission // Default permission if no ACL matches - ProvisionEnabled bool // Hack: Enable auto-provisioning of users and access grants, disabled for "ntfy user" commands - Users []*User // Predefined users to create on startup - Access map[string][]*Grant // Predefined access grants to create on startup (username -> []*Grant) - Tokens map[string][]*Token // Predefined users to create on startup (username -> []*Token) - QueueWriterInterval time.Duration // Interval for the async queue writer to flush stats and token updates to the database - BcryptCost int // Cost of generated passwords; lowering makes testing faster - AccessCacheEnabled bool // Enables the in-memory ACL cache (high volume servers only) - AccessCacheReloadInterval time.Duration // Reload interval for access cache, relevant for ACL writes from CLI + Filename string // Database filename, e.g. "/var/lib/ntfy/user.db" (SQLite) + DatabaseURL string // Database connection string (PostgreSQL) + StartupQueries string // Queries to run on startup, e.g. to create initial users or tiers (SQLite only) + DefaultAccess Permission // Default permission if no ACL matches + ProvisionEnabled bool // Hack: Enable auto-provisioning of users and access grants, disabled for "ntfy user" commands + Users []*User // Predefined users to create on startup + Access map[string][]*Grant // Predefined access grants to create on startup (username -> []*Grant) + Tokens map[string][]*Token // Predefined users to create on startup (username -> []*Token) + QueueWriterInterval time.Duration // Interval for the async queue writer to flush stats and token updates to the database + BcryptCost int // Cost of generated passwords; lowering makes testing faster + AccessCacheEnabled bool // Enables the in-memory ACL cache (high volume servers only) + AccessCacheReloadInterval time.Duration // Reload interval for access cache, relevant for ACL writes from CLI + ExpiredMagicLinkReapInterval time.Duration // Interval for sweeping expired email-verify/password-reset links } // Error constants used by the package @@ -383,13 +384,13 @@ type queries struct { updateEmailClearPrimary string // Magic link queries (email verification + password reset) - insertMagicLink string - selectMagicLinkByHash string - deleteMagicLinkByHash string - deleteVerifyScope string // Delete pending email_verify rows for (user_id, email) - deleteResetScope string // Delete the active password_reset row for user_id - selectPendingEmails string // Pending (unverified) email addresses for a user - deleteExpiredMagicLinks string + insertMagicLink string + selectMagicLinkByHash string + deleteMagicLinkByHash string + deleteMagicLinkEmailVerify string // Delete pending email_verify rows for (user_id, email) + deleteMagicLinkResetPassword string // Delete the active password_reset row for user_id + selectPendingEmails string // Pending (unverified) email addresses for a user + deleteExpiredMagicLinks string // Billing queries updateBilling string diff --git a/user/util.go b/user/util.go index 5157b95f..50d0c012 100644 --- a/user/util.go +++ b/user/util.go @@ -89,12 +89,8 @@ func hashToken(raw string) string { return hex.EncodeToString(sum[:]) } -// HashPassword hashes the given password using bcrypt with the configured cost -func HashPassword(password string) (string, error) { - return hashPassword(password, DefaultUserPasswordBcryptCost) -} - -func hashPassword(password string, cost int) (string, error) { +// HashPassword hashes the given password using bcrypt with the given cost +func HashPassword(password string, cost int) (string, error) { hash, err := bcrypt.GenerateFromPassword([]byte(password), cost) if err != nil { return "", err diff --git a/user/util_test.go b/user/util_test.go index 97c4bc4a..2fa542ab 100644 --- a/user/util_test.go +++ b/user/util_test.go @@ -176,7 +176,7 @@ func TestHashPassword(t *testing.T) { password := "test-password-123" // Hash the password - hash, err := HashPassword(password) + hash, err := HashPassword(password, DefaultUserPasswordBcryptCost) require.Nil(t, err) require.NotEmpty(t, hash) @@ -187,12 +187,12 @@ func TestHashPassword(t *testing.T) { require.True(t, strings.HasPrefix(hash, "$2a$")) // Hash the same password again - should produce different hash - hash2, err := HashPassword(password) + hash2, err := HashPassword(password, DefaultUserPasswordBcryptCost) require.Nil(t, err) require.NotEqual(t, hash, hash2, "Same password should produce different hashes (salt)") // Empty password should still work - emptyHash, err := HashPassword("") + emptyHash, err := HashPassword("", DefaultUserPasswordBcryptCost) require.Nil(t, err) require.NotEmpty(t, emptyHash) require.Nil(t, ValidPasswordHash(emptyHash, DefaultUserPasswordBcryptCost)) @@ -202,15 +202,15 @@ func TestHashPassword_WithCost(t *testing.T) { password := "test-password" // Test with different costs - hash4, err := hashPassword(password, 4) + hash4, err := HashPassword(password, 4) require.Nil(t, err) require.True(t, strings.HasPrefix(hash4, "$2a$04$")) - hash10, err := hashPassword(password, 10) + hash10, err := HashPassword(password, 10) require.Nil(t, err) require.True(t, strings.HasPrefix(hash10, "$2a$10$")) - hash12, err := hashPassword(password, 12) + hash12, err := HashPassword(password, 12) require.Nil(t, err) require.True(t, strings.HasPrefix(hash12, "$2a$12$")) From 1979dbc7c3e058a8d8f13fd79337fbb1d2adc669 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sun, 21 Jun 2026 11:27:02 -0400 Subject: [PATCH 28/34] Rename --- server/server_account.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/server/server_account.go b/server/server_account.go index 807ad453..5951d72f 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -807,7 +807,7 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt v.AccountActionPerformed() // Consume a token on every request (including no-match), to throttle probing identifier := strings.TrimSpace(req.Identifier) if identifier != "" && s.config.BaseURL != "" { - if userID, email, ok := s.resolveResetTarget(identifier); ok { + if userID, email, ok := s.resolveResetPasswordTarget(identifier); ok { token, err := s.userManager.AddMagicLink(user.MagicLinkKindPasswordReset, userID, "", passwordResetTokenExpiry) if err != nil { logvr(v, r).Tag(tagAccount).Err(err).Warn("Failed to create password reset token") @@ -825,11 +825,11 @@ func (s *Server) handleAccountPasswordResetRequest(w http.ResponseWriter, r *htt return s.writeJSON(w, newSuccessResponse()) } -// resolveResetTarget resolves a reset identifier (username or primary email) to a single account +// resolveResetPasswordTarget resolves a reset identifier (username or primary email) to a single account // and its primary email. It applies the reset policy on top of the lookup: provisioned users are // excluded, and ok=false is returned unless the account has a verified primary email (reset // requires one, and that is where the link is sent). -func (s *Server) resolveResetTarget(identifier string) (userID string, email string, ok bool) { +func (s *Server) resolveResetPasswordTarget(identifier string) (userID string, email string, ok bool) { u, err := s.userManager.UserByEmailOrUsername(identifier) if err != nil || u == nil || u.Provisioned { return "", "", false From 954fae44dc865b2ab8b7201afd0261759932e6fb Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sun, 21 Jun 2026 11:47:14 -0400 Subject: [PATCH 29/34] Make more readable --- user/manager.go | 18 ++++++++++-------- 1 file changed, 10 insertions(+), 8 deletions(-) diff --git a/user/manager.go b/user/manager.go index 8aea195a..4a4aa75f 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1681,6 +1681,7 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { if _, err := tx.Exec(a.queries.insertEmailIgnore, m.UserID, m.Email); err != nil { return err } + // Must stay before the promotion block; covered by TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary if u.Provisioned { return nil // Provisioned users don't get a primary (recovery) email } @@ -1695,16 +1696,17 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { if primary.String != "" { return nil // User already has a primary -- leave it } - var owner string - err = tx.QueryRow(a.queries.selectUserIDByPrimary, m.Email).Scan(&owner) - if errors.Is(err, sql.ErrNoRows) { - if _, err := tx.Exec(a.queries.updateEmailSetPrimary, m.UserID, m.Email); err != nil { - return err - } - } else if err != nil { + // If the address is already another account's primary, leave it a verified secondary here + var ownerUserID string + if err = tx.QueryRow(a.queries.selectUserIDByPrimary, m.Email).Scan(&ownerUserID); err == nil { + return nil // Address is primary elsewhere -> not promoted + } else if !errors.Is(err, sql.ErrNoRows) { + return err // Real query error + } + // Address is globally free -> promote it to this user's primary + if _, err := tx.Exec(a.queries.updateEmailSetPrimary, m.UserID, m.Email); err != nil { return err } - // owner found -> address is primary elsewhere -> stays a verified secondary return nil }) if err != nil { From 5808c4d4c0948b35f145ba103b5f9cd185e39b28 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Sun, 21 Jun 2026 11:53:25 -0400 Subject: [PATCH 30/34] Rename variable --- user/manager.go | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/user/manager.go b/user/manager.go index 4a4aa75f..6378ab60 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1719,7 +1719,7 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { // validating the token (kind + expiry), it sets the user's password and deletes the link in one // transaction. Existing access tokens are intentionally left valid (only the password changes). // Returns ErrMagicLinkNotFound if the token is invalid, expired, or not a reset token. -func (a *Manager) ResetPassword(rawToken, password string) error { +func (a *Manager) ResetPassword(rawToken, newPassword string) error { m, err := a.MagicLinkByHash(hashToken(rawToken)) if err != nil { return err @@ -1734,7 +1734,7 @@ func (a *Manager) ResetPassword(rawToken, password string) error { if u.Provisioned { return ErrProvisionedUserChange // Provisioned users get their password from the config file, not reset } - hash, err := HashPassword(password, a.config.BcryptCost) + hash, err := HashPassword(newPassword, a.config.BcryptCost) if err != nil { return err } From d8666b66ecd65a1a5cd3c0219506276819b9b482 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 22 Jun 2026 10:13:27 -0400 Subject: [PATCH 31/34] Change "Email: yes" behavior to make more sense --- docs/config.md | 10 ++++--- docs/publish.md | 10 +++++-- docs/releases.md | 3 +- server/server.go | 1 - server/server_account.go | 50 +++++++++++++++++++++------------- server/server_test.go | 32 ++++++++++++++++++++-- server/types.go | 1 - web/src/components/Account.jsx | 2 +- 8 files changed, 76 insertions(+), 33 deletions(-) diff --git a/docs/config.md b/docs/config.md index f51ad537..0f72557b 100644 --- a/docs/config.md +++ b/docs/config.md @@ -1047,10 +1047,12 @@ configured for `ntfy.sh`): ``` By default, any user (including anonymous users) can send email notifications to any address. To require email -address verification, set `smtp-sender-verify` to `true`. When enabled, anonymous users cannot send emails, -and authenticated users can only send to email addresses they have verified in their account settings. Users can -also use `yes`/`true`/`1` as the `X-Email` value to send to their primary verified address (falling back to their -first verified address if no primary is designated). +address verification, set `smtp-sender-verify` to `true`. When enabled, anonymous users cannot send emails, and +authenticated users can only send to *literal* email addresses they have verified in their account settings. + +Regardless of this setting, a logged-in user can pass `yes`/`true`/`1` as the `X-Email` value to send to their primary +verified address (falling back to their first verified address if no primary is designated). `smtp-sender-verify` only +governs whether arbitrary literal addresses are allowed. Please also refer to the [rate limiting](#rate-limiting) settings below, specifically `visitor-email-limit-burst` and `visitor-email-limit-burst`. Setting these conservatively is necessary to avoid abuse. diff --git a/docs/publish.md b/docs/publish.md index 95354362..46f2d80a 100644 --- a/docs/publish.md +++ b/docs/publish.md @@ -3251,9 +3251,13 @@ You can forward messages to e-mail by specifying an address in the header. This you'd like to persist longer, or to blast-notify yourself on all possible channels. Usage is easy: Simply pass the `X-Email` header (or any of its aliases: `X-E-mail`, `Email`, `E-mail`, `Mail`, or `e`). -Only one e-mail address is supported. If the server has [`smtp-sender-verify`](config.md#e-mail-notifications) enabled (ntfy.sh has this enabled), -you can also pass `yes`, `true`, or `1` to send to your **primary email address** (the one marked primary in the web app's -[Account section](https://ntfy.sh/account)). If you haven't designated a primary address, it falls back to your first verified address. +Only one e-mail address is supported. + +If you are logged in and have a verified email address on your account, you can pass `yes`, `true`, or `1` instead of an +address to send to your **primary email address** (the one marked primary in the web app's +[Account section](https://ntfy.sh/account)); if you haven't designated a primary, it falls back to your first verified +address. This works regardless of the [`smtp-sender-verify`](config.md#e-mail-notifications) setting -- that setting only +controls whether *literal* addresses must already be verified on your account. ntfy allows anonymous email sending (if enabled), so the rate limiting is pretty strict (see [limitations](#limitations)). In the default configuration, you get **16 e-mails per visitor** (IP address) and then after that one per hour. On top of diff --git a/docs/releases.md b/docs/releases.md index d2de3d07..d0551d6b 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -1957,13 +1957,14 @@ email. All of this rides on the existing SMTP configuration -- no new config fla **Features:** -* Add password reset via emailed magic link, with a "Forgot password?" link on the login page and a `ntfy user password-reset` CLI command for admins +* Add password reset via emailed magic link, with a "Forgot password?" link on the login page and a `ntfy user reset-pass` CLI command for admins * Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" (recovery) email with verified/unverified state in the account UI * Auto-send a verification link to the billing email after a Stripe checkout, so paying users can set up password recovery **Bug fixes + maintenance:** * Generate access tokens, IDs, and magic-link tokens with a cryptographically secure RNG (`crypto/rand`) instead of a clock-seeded PRNG +* `X-Email: yes` (also `true`/`1`) now sends to your primary verified email regardless of the `smtp-sender-verify` setting (previously it was rejected unless verification was enabled); it requires being logged in with a verified address ### ntfy Android v1.25.x (UNRELEASED) diff --git a/server/server.go b/server/server.go index d79d7ad0..fb5d5d37 100644 --- a/server/server.go +++ b/server/server.go @@ -746,7 +746,6 @@ func (s *Server) configResponse() *apiConfigResponse { EnablePayments: s.config.StripeSecretKey != "", EnableCalls: s.config.TwilioAccount != "", EnableEmails: s.config.SMTPSenderFrom != "", - EnableEmailVerify: s.config.SMTPSenderVerify, EnableResetPassword: s.config.SMTPSenderFrom != "" && s.config.BaseURL != "", // Reset links need SMTP + an absolute base-url EnableReservations: s.config.EnableReservations, EnableWebPush: s.config.WebPushPublicKey != "", diff --git a/server/server_account.go b/server/server_account.go index 5951d72f..ac79b05a 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -863,16 +863,39 @@ func (s *Server) handleAccountPasswordReset(w http.ResponseWriter, r *http.Reque return s.writeJSON(w, newSuccessResponse()) } -// convertEmailAddress checks the email address against the user's verified email list. -// If smtp-sender-verify is false (default), the email is passed through as-is for -// backwards compatibility. If true, the user must be authenticated and the email must be -// in their verified list. "yes"/"true"/"1" resolves to the user's primary email (falling -// back to the first verified email if no primary is designated). +// convertEmailAddress resolves the X-Email value to the address ntfy should send to. +// +// "yes"/"true"/"1" resolves to the user's primary verified address -- or, if no primary is +// designated (e.g. a provisioned user), the first verified address (alphabetically). This is +// independent of smtp-sender-verify: it only requires an authenticated user with a verified +// address, since it means "send to my own email". +// +// A literal address is sent as-is when smtp-sender-verify is false (the default, backwards +// compatible); when true, the address must be one the user has verified. func (s *Server) convertEmailAddress(u *user.User, email string) (string, *errHTTP) { - if !s.config.SMTPSenderVerify { - if toBool(email) { - return "", errHTTPBadRequestEmailAddressInvalid + if toBool(email) { + if u == nil { + return "", errHTTPBadRequestAnonymousEmailNotAllowed + } else if s.userManager == nil { + return "", errHTTPBadRequestEmailAddressNotVerified } + primary, err := s.userManager.PrimaryEmail(u.ID) + if err != nil { + return "", errHTTPInternalError + } else if primary != "" { + return primary, nil + } + // No primary designated -> fall back to the first verified address, if any + emails, err := s.userManager.Emails(u.ID) + if err != nil { + return "", errHTTPInternalError + } else if len(emails) > 0 { + return emails[0], nil + } + return "", errHTTPBadRequestEmailAddressNotVerified + } + // A literal address + if !s.config.SMTPSenderVerify { return email, nil } else if u == nil { return "", errHTTPBadRequestAnonymousEmailNotAllowed @@ -882,17 +905,6 @@ func (s *Server) convertEmailAddress(u *user.User, email string) (string, *errHT emails, err := s.userManager.Emails(u.ID) if err != nil { return "", errHTTPInternalError - } else if len(emails) == 0 { - return "", errHTTPBadRequestEmailAddressNotVerified - } - if toBool(email) { - primary, err := s.userManager.PrimaryEmail(u.ID) - if err != nil { - return "", errHTTPInternalError - } else if primary != "" { - return primary, nil - } - return emails[0], nil // No primary designated (e.g. provisioned user); fall back to first verified } else if util.Contains(emails, email) { return email, nil } diff --git a/server/server_test.go b/server/server_test.go index a6106a93..eaa7f350 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -1688,17 +1688,43 @@ func TestServer_PublishEmailVerify_BoolValueUsesPrimary(t *testing.T) { }) } -func TestServer_PublishEmailVerify_BoolValue_NoVerify(t *testing.T) { +func TestServer_PublishEmailVerify_BoolValueNoVerifyUsesPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + conf := newTestConfigWithAuthFile(t, databaseURL) + // smtp-sender-verify intentionally left false (the default) + s := newTestServer(t, conf) + mailer := &testMailer{} + s.mailer = mailer + defer s.closeDatabases() + + require.Nil(t, s.userManager.AddUser("phil", "phil", user.RoleUser, false)) + u, err := s.userManager.User("phil") + require.Nil(t, err) + require.Nil(t, s.userManager.AddEmail(u.ID, "aaa@example.com")) + require.Nil(t, s.userManager.AddEmail(u.ID, "zzz@example.com")) + require.Nil(t, s.userManager.SetPrimaryEmail(u.ID, "zzz@example.com")) + + // Even with smtp-sender-verify off, "yes" resolves to the user's primary verified address + response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ + "Email": "yes", + "Authorization": util.BasicAuth("phil", "phil"), + }) + require.Equal(t, 200, response.Code) + require.Equal(t, "zzz@example.com", mailer.LastTo()) + }) +} + +func TestServer_PublishEmailVerify_BoolValueAnonymousRejected(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { s := newTestServer(t, newTestConfig(t, databaseURL)) s.mailer = &testMailer{} - // "yes" without smtp-sender-verify should fail with invalid address + // "yes" requires an authenticated user (it means "my primary"); anonymous is rejected response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ "Email": "yes", }) require.Equal(t, 400, response.Code) - require.Equal(t, 40050, toHTTPError(t, response.Body.String()).Code) + require.Equal(t, 40053, toHTTPError(t, response.Body.String()).Code) }) } diff --git a/server/types.go b/server/types.go index 4b0c738d..5b254c4d 100644 --- a/server/types.go +++ b/server/types.go @@ -338,7 +338,6 @@ type apiConfigResponse struct { EnablePayments bool `json:"enable_payments"` EnableCalls bool `json:"enable_calls"` EnableEmails bool `json:"enable_emails"` - EnableEmailVerify bool `json:"enable_email_verify"` EnableResetPassword bool `json:"enable_reset_password"` EnableReservations bool `json:"enable_reservations"` EnableWebPush bool `json:"enable_web_push"` diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index f37089e0..f225cc81 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -428,7 +428,7 @@ const Emails = () => { setSnack(t("account_basics_emails_resent")); }); - if (!config.enable_email_verify) { + if (!config.enable_emails) { return null; } From 4313b02fc6f62aca622b1504241e7f536c4d1775 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 22 Jun 2026 12:59:50 -0400 Subject: [PATCH 32/34] Allow primary email for provisioend users --- docs/releases.md | 2 +- server/server_account.go | 2 -- server/server_account_email_test.go | 17 ++++++++++------- server/server_test.go | 27 +++++++++++++++++++++++++++ user/manager.go | 8 -------- user/manager_test.go | 7 ++++--- web/public/static/langs/en.json | 3 +-- web/src/components/Account.jsx | 8 +------- 8 files changed, 44 insertions(+), 30 deletions(-) diff --git a/docs/releases.md b/docs/releases.md index d0551d6b..30490217 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -1958,7 +1958,7 @@ email. All of this rides on the existing SMTP configuration -- no new config fla **Features:** * Add password reset via emailed magic link, with a "Forgot password?" link on the login page and a `ntfy user reset-pass` CLI command for admins -* Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" (recovery) email with verified/unverified state in the account UI +* Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" email (used for account recovery and as the `X-Email: yes` target) with verified/unverified state in the account UI * Auto-send a verification link to the billing email after a Stripe checkout, so paying users can set up password recovery **Bug fixes + maintenance:** diff --git a/server/server_account.go b/server/server_account.go index ac79b05a..e28df08d 100644 --- a/server/server_account.go +++ b/server/server_account.go @@ -735,8 +735,6 @@ func (s *Server) handleAccountEmailSetPrimary(w http.ResponseWriter, r *http.Req return err } else if !emailAddressRegex.MatchString(req.Email) { return errHTTPBadRequestEmailAddressInvalid - } else if u.Provisioned { - return errHTTPConflictProvisionedUserChange // Provisioned users can't reset, so a recovery email is meaningless } logvr(v, r).Tag(tagAccount).Field("email", req.Email).Info("Setting primary email") err = s.userManager.SetPrimaryEmail(u.ID, req.Email) diff --git a/server/server_account_email_test.go b/server/server_account_email_test.go index 88ebf1cb..793c89be 100644 --- a/server/server_account_email_test.go +++ b/server/server_account_email_test.go @@ -364,7 +364,7 @@ func TestAccount_Signup_WithoutEmail_NoSend(t *testing.T) { }) } -func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { +func TestAccount_Email_ProvisionedPrimary(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { hash, err := user.HashPassword("provpass", user.DefaultUserPasswordBcryptCost) require.Nil(t, err) @@ -379,16 +379,19 @@ func TestAccount_Email_ProvisionedNoPrimary(t *testing.T) { defer s.closeDatabases() auth := map[string]string{"Authorization": util.BasicAuth("prov", "provpass")} - // A provisioned user can verify an email, but it must NOT become their primary + // A provisioned user's first verified email becomes their primary (used by X-Email: yes; + // password reset stays blocked separately for provisioned users) verifyEmailFor(t, s, mailer, auth, "prov@example.com") account := getAccount(t, s, auth) require.Equal(t, []string{"prov@example.com"}, verifiedAddrs(account)) - require.Equal(t, "", primaryAddr(account)) + require.Equal(t, "prov@example.com", primaryAddr(account)) - // Explicitly setting it primary is rejected - rr := request(t, s, "POST", "/v1/account/email/primary", `{"email":"prov@example.com"}`, auth) - require.Equal(t, 409, rr.Code) - require.Equal(t, 40905, toHTTPError(t, rr.Body.String()).Code) + // Verify a second address and explicitly set it primary -> allowed, star moves + verifyEmailFor(t, s, mailer, auth, "prov2@example.com") + rr := request(t, s, "POST", "/v1/account/email/primary", `{"email":"prov2@example.com"}`, auth) + require.Equal(t, 200, rr.Code) + account = getAccount(t, s, auth) + require.Equal(t, "prov2@example.com", primaryAddr(account)) }) } diff --git a/server/server_test.go b/server/server_test.go index eaa7f350..5ebde045 100644 --- a/server/server_test.go +++ b/server/server_test.go @@ -1728,6 +1728,33 @@ func TestServer_PublishEmailVerify_BoolValueAnonymousRejected(t *testing.T) { }) } +func TestServer_PublishEmailVerify_BoolValueProvisionedUsesPrimary(t *testing.T) { + forEachBackend(t, func(t *testing.T, databaseURL string) { + hash, err := user.HashPassword("provpass", user.DefaultUserPasswordBcryptCost) + require.Nil(t, err) + conf := newTestConfigWithAuthFile(t, databaseURL) + conf.AuthUsers = []*user.User{{Name: "prov", Hash: hash, Role: user.RoleUser}} + s := newTestServer(t, conf) + mailer := &testMailer{} + s.mailer = mailer + defer s.closeDatabases() + + prov, err := s.userManager.User("prov") + require.Nil(t, err) + require.Nil(t, s.userManager.AddEmail(prov.ID, "aaa@example.com")) + require.Nil(t, s.userManager.AddEmail(prov.ID, "zzz@example.com")) + require.Nil(t, s.userManager.SetPrimaryEmail(prov.ID, "zzz@example.com")) + + // A provisioned user's "yes" resolves to their chosen primary, not the alphabetically-first + response := request(t, s, "PUT", "/mytopic", "hi", map[string]string{ + "Email": "yes", + "Authorization": util.BasicAuth("prov", "provpass"), + }) + require.Equal(t, 200, response.Code) + require.Equal(t, "zzz@example.com", mailer.LastTo()) + }) +} + func TestServer_PublishEmailVerify_Anonymous(t *testing.T) { forEachBackend(t, func(t *testing.T, databaseURL string) { conf := newTestConfigWithAuthFile(t, databaseURL) diff --git a/user/manager.go b/user/manager.go index 6378ab60..c8b1d39e 100644 --- a/user/manager.go +++ b/user/manager.go @@ -1669,10 +1669,6 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { if m.Kind != MagicLinkKindEmailVerify || time.Now().Unix() > m.Expires { return nil, ErrMagicLinkNotFound } - u, err := a.UserByID(m.UserID) - if err != nil { - return nil, err - } err = db.ExecTx(a.db, func(tx *sql.Tx) error { // Single use: delete the link, then add the (idempotent) verified address if _, err := tx.Exec(a.queries.deleteMagicLinkByHash, tokenHash); err != nil { @@ -1681,10 +1677,6 @@ func (a *Manager) VerifyEmail(rawToken string) (*MagicLink, error) { if _, err := tx.Exec(a.queries.insertEmailIgnore, m.UserID, m.Email); err != nil { return err } - // Must stay before the promotion block; covered by TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary - if u.Provisioned { - return nil // Provisioned users don't get a primary (recovery) email - } // Promote to primary only if the user has none yet and the address is globally free. // We check with SELECTs rather than catching a unique violation, because Postgres aborts // the whole transaction on any constraint error (which would undo the verified-email add). diff --git a/user/manager_test.go b/user/manager_test.go index c6dd2467..e7073773 100644 --- a/user/manager_test.go +++ b/user/manager_test.go @@ -3212,7 +3212,7 @@ func TestUser_MagicLink_ResetPassword_WrongKindRejected(t *testing.T) { }) } -func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) { +func TestUser_MagicLink_VerifyEmail_ProvisionedGetsPrimary(t *testing.T) { forEachBackend(t, func(t *testing.T, newManager newManagerFunc) { a := newTestManagerFromConfig(t, newManager, &Config{ DefaultAccess: PermissionDenyAll, @@ -3224,7 +3224,8 @@ func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) { prov, err := a.User("prov") require.Nil(t, err) - // A provisioned user can verify an email (for notifications), but it must NOT become primary + // A provisioned user's first verified email becomes their primary, just like a regular user + // (the primary is also the X-Email: yes target; password reset stays blocked separately). _, err = a.VerifyEmail(addVerifyLink(t, a, prov.ID, "prov@example.com", time.Hour)) require.Nil(t, err) @@ -3233,7 +3234,7 @@ func TestUser_MagicLink_VerifyEmail_ProvisionedNoPrimary(t *testing.T) { require.Equal(t, []string{"prov@example.com"}, emails) primary, err := a.PrimaryEmail(prov.ID) require.Nil(t, err) - require.Equal(t, "", primary) + require.Equal(t, "prov@example.com", primary) }) } diff --git a/web/public/static/langs/en.json b/web/public/static/langs/en.json index d24e9936..a6e942a0 100644 --- a/web/public/static/langs/en.json +++ b/web/public/static/langs/en.json @@ -244,7 +244,7 @@ "account_basics_emails_description": "For email notifications and password reset", "account_basics_emails_no_emails_yet": "No emails yet", "account_basics_emails_copied_to_clipboard": "Email address copied to clipboard", - "account_basics_emails_chip_actions_primary": "Primary address, can be used for account recovery and notifications. Click for actions.", + "account_basics_emails_chip_actions_primary": "Primary address, used as your default email address. Click for actions.", "account_basics_emails_chip_actions_verified": "Can be used for notifications. Click for actions.", "account_basics_emails_chip_actions_unverified": "Unverified address, check your inbox to verify. Click for actions.", "account_basics_emails_unverified": "unverified", @@ -255,7 +255,6 @@ "account_basics_emails_primary_elsewhere": "This email address is used as the primary address on another account", "account_basics_emails_no_recovery_warning": "Add at least one email address to ensure you can recover your account if you lose your password.", "account_basics_emails_no_primary_warning": "Add a primary email address to ensure you can recover your account if you lose your password.", - "account_basics_emails_provisioned_info": "Provisioned users cannot add a primary email address, but you can still add an email address for notifications.", "account_basics_emails_dialog_title": "Add email address", "account_basics_emails_dialog_description": "Enter an email address to add it to your account. A verification link will be sent to confirm it is yours.", "account_basics_emails_dialog_email_label": "Email address", diff --git a/web/src/components/Account.jsx b/web/src/components/Account.jsx index f225cc81..24631dc9 100644 --- a/web/src/components/Account.jsx +++ b/web/src/components/Account.jsx @@ -521,7 +521,7 @@ const Emails = () => { {t("common_copy_to_clipboard")} - {menuEmail && !menuEmail.pending && !menuEmail.primary && !account?.provisioned && ( + {menuEmail && !menuEmail.pending && !menuEmail.primary && ( runMenuAction(handleSetPrimary)}> @@ -555,7 +555,6 @@ const Emails = () => { const AddEmailDialog = (props) => { const theme = useTheme(); const { t } = useTranslation(); - const { account } = useContext(AccountContext); const [error, setError] = useState(""); const [email, setEmail] = useState(""); const [sending, setSending] = useState(false); @@ -592,11 +591,6 @@ const AddEmailDialog = (props) => { ) : ( <> {t("account_basics_emails_dialog_description")} - {config.enable_reset_password && account?.provisioned && ( - - {t("account_basics_emails_provisioned_info")} - - )} Date: Mon, 22 Jun 2026 17:02:47 -0400 Subject: [PATCH 33/34] Remove migration test --- user/manager_test.go | 70 -------------------------------------------- 1 file changed, 70 deletions(-) diff --git a/user/manager_test.go b/user/manager_test.go index e7073773..88d7d122 100644 --- a/user/manager_test.go +++ b/user/manager_test.go @@ -1790,76 +1790,6 @@ func TestMigrationFrom4(t *testing.T) { require.Nil(t, a.Authorize(nil, "up", PermissionRead)) // % matches 0 or more characters } -func TestMigrationFrom7(t *testing.T) { - filename := filepath.Join(t.TempDir(), "user.db") - rawDB, err := sql.Open("sqlite3", filename) - require.Nil(t, err) - - // Create a "version 7" schema: user_email exists but has no is_primary column, and there - // is no user_magic_link table yet. (Mirrors the production schema right before v8.) - _, err = rawDB.Exec(` - BEGIN; - CREATE TABLE IF NOT EXISTS tier ( - id TEXT PRIMARY KEY, code TEXT NOT NULL, name TEXT NOT NULL, - messages_limit INT NOT NULL, messages_expiry_duration INT NOT NULL, emails_limit INT NOT NULL, - calls_limit INT NOT NULL, reservations_limit INT NOT NULL, attachment_file_size_limit INT NOT NULL, - attachment_total_size_limit INT NOT NULL, attachment_expiry_duration INT NOT NULL, - attachment_bandwidth_limit INT NOT NULL, stripe_monthly_price_id TEXT, stripe_yearly_price_id TEXT - ); - CREATE TABLE IF NOT EXISTS user ( - id TEXT PRIMARY KEY, tier_id TEXT, user TEXT NOT NULL, pass TEXT NOT NULL, - role TEXT CHECK (role IN ('anonymous', 'admin', 'user')) NOT NULL, - prefs JSON NOT NULL DEFAULT '{}', sync_topic TEXT NOT NULL, provisioned INT NOT NULL, - stats_messages INT NOT NULL DEFAULT (0), stats_emails INT NOT NULL DEFAULT (0), - stats_calls INT NOT NULL DEFAULT (0), stripe_customer_id TEXT, stripe_subscription_id TEXT, - stripe_subscription_status TEXT, stripe_subscription_interval TEXT, - stripe_subscription_paid_until INT, stripe_subscription_cancel_at INT, created INT NOT NULL, deleted INT, - FOREIGN KEY (tier_id) REFERENCES tier (id) - ); - CREATE UNIQUE INDEX idx_user ON user (user); - CREATE TABLE IF NOT EXISTS user_email ( - user_id TEXT NOT NULL, - email TEXT NOT NULL, - PRIMARY KEY (user_id, email), - FOREIGN KEY (user_id) REFERENCES user (id) ON DELETE CASCADE - ); - CREATE TABLE IF NOT EXISTS schemaVersion (id INT PRIMARY KEY, version INT NOT NULL); - INSERT INTO user (id, user, pass, role, sync_topic, provisioned, created) - VALUES ('u_everyone', '*', '', 'anonymous', '', 0, UNIXEPOCH()); - INSERT INTO user (id, user, pass, role, sync_topic, provisioned, created) - VALUES ('u_phil', 'phil', '', 'user', 'st_phil', 0, UNIXEPOCH()); - INSERT INTO user_email (user_id, email) VALUES ('u_phil', 'old@example.com'); - INSERT INTO schemaVersion (id, version) VALUES (1, 7); - COMMIT; - `) - require.Nil(t, err) - require.Nil(t, rawDB.Close()) - - // Opening the manager triggers the 7 -> 8 migration - a := newTestManagerFromFile(t, filename, "", PermissionDenyAll, bcrypt.MinCost, DefaultUserStatsQueueWriterInterval) - checkSchemaVersion(t, testDB(a)) - - // The pre-existing verified email survives and stays NON-primary (no backfill) - emails, err := a.Emails("u_phil") - require.Nil(t, err) - require.Equal(t, []string{"old@example.com"}, emails) - primary, err := a.PrimaryEmail("u_phil") - require.Nil(t, err) - require.Equal(t, "", primary) - - // The new magic-link machinery works post-migration - raw, err := a.AddMagicLink(MagicLinkKindEmailVerify, "u_phil", "new@example.com", 24*time.Hour) - require.Nil(t, err) - m, err := a.VerifyEmail(raw) - require.Nil(t, err) - require.Equal(t, "new@example.com", m.Email) - - // new@ becomes primary because the user had none (old@ was a pre-existing non-primary) - primary, err = a.PrimaryEmail("u_phil") - require.Nil(t, err) - require.Equal(t, "new@example.com", primary) -} - func checkSchemaVersion(t *testing.T, d *db.DB) { rows, err := d.Query(`SELECT version FROM schemaVersion`) require.Nil(t, err) From 2b30ce9ee022f8dfde9736570f09a160f74e64c9 Mon Sep 17 00:00:00 2001 From: binwiederhier Date: Mon, 22 Jun 2026 21:07:55 -0400 Subject: [PATCH 34/34] Changelog update --- docs/releases.md | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/docs/releases.md b/docs/releases.md index 30490217..a3c7db5c 100644 --- a/docs/releases.md +++ b/docs/releases.md @@ -1953,13 +1953,15 @@ and the [ntfy Android app](https://github.com/binwiederhier/ntfy-android/release This release adds **password reset** via email, and reworks email verification to use durable, link-based magic links (replacing the old in-memory 6-digit codes). Email stays optional at signup; a user can reset their password only once they have a verified "primary" (recovery) -email. All of this rides on the existing SMTP configuration -- no new config flag. +email. + +All of this work is probably not useful for self-hosters, but it hopefully will be useful for me, +since I do have to reset emails on a regular basis. **Features:** -* Add password reset via emailed magic link, with a "Forgot password?" link on the login page and a `ntfy user reset-pass` CLI command for admins +* Add password reset via emailed magic link, with a "Forgot password" link on the login page and a `ntfy user reset-pass` CLI command for admins * Rework email verification to use durable, single-use, expiring magic links instead of in-memory 6-digit codes, and add a "primary" email (used for account recovery and as the `X-Email: yes` target) with verified/unverified state in the account UI -* Auto-send a verification link to the billing email after a Stripe checkout, so paying users can set up password recovery **Bug fixes + maintenance:**