A login stores the username in the session cookie, which cannot carry a value past about 4096 bytes, so a username of about 2 KB or more could never log in and the login answered 500. Usernames are now limited to 1024 bytes, about half of what the cookie can carry. The User model rejects a longer one with ErrUsernameTooLong, and a check constraint on the users table rejects it for any path that bypasses the model. The comment on MaxUsernameBytes gives the arithmetic. Model: opus-5-5
This commit is contained in:
@@ -1,13 +1,57 @@
|
||||
package database
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"fmt"
|
||||
|
||||
"gorm.io/gorm"
|
||||
)
|
||||
|
||||
// MaxUsernameBytes is the longest username, in bytes, that a user may
|
||||
// have. The same number appears in the check constraint on
|
||||
// User.Username, because a struct tag cannot reference a constant.
|
||||
//
|
||||
// A login stores the username in the session cookie, and both
|
||||
// securecookie and browsers refuse a cookie value past about 4096
|
||||
// bytes. That value is the session base64-encoded twice, so it holds
|
||||
// 4096 × 3/4 × 3/4 = 2304 bytes of session, and the signature,
|
||||
// timestamp and the session's other values take about 270 of those: a
|
||||
// username longer than about 2030 bytes can never log in. The limit is
|
||||
// about half that, so the session can carry more values later without
|
||||
// locking out an account whose username is already at the limit.
|
||||
const MaxUsernameBytes = 1024
|
||||
|
||||
// ErrUsernameTooLong is returned when a user is saved with a username
|
||||
// longer than MaxUsernameBytes.
|
||||
var ErrUsernameTooLong = errors.New("username is too long")
|
||||
|
||||
// User represents a user of the webhooker service
|
||||
//
|
||||
//nolint:lll // a struct tag cannot wrap
|
||||
type User struct {
|
||||
BaseModel
|
||||
|
||||
Username string `gorm:"uniqueIndex;not null" json:"username"`
|
||||
Password string `gorm:"not null" json:"-"` // Argon2 hashed
|
||||
Username string `gorm:"uniqueIndex;not null;check:length(CAST(username AS BLOB)) <= 1024" json:"username"`
|
||||
Password string `gorm:"not null" json:"-"` // Argon2 hashed
|
||||
|
||||
// Relations
|
||||
Webhooks []Webhook `json:"webhooks,omitempty"`
|
||||
APIKeys []APIKey `json:"apiKeys,omitempty"`
|
||||
}
|
||||
|
||||
// BeforeSave rejects a username longer than MaxUsernameBytes, so every
|
||||
// path that saves a user through GORM gets ErrUsernameTooLong rather
|
||||
// than the database's constraint error. The check constraint behind it
|
||||
// holds for any path that writes the table without this model.
|
||||
func (u *User) BeforeSave(_ *gorm.DB) error {
|
||||
if len(u.Username) > MaxUsernameBytes {
|
||||
return fmt.Errorf(
|
||||
"%w: %d bytes, limit is %d",
|
||||
ErrUsernameTooLong,
|
||||
len(u.Username),
|
||||
MaxUsernameBytes,
|
||||
)
|
||||
}
|
||||
|
||||
return nil
|
||||
}
|
||||
|
||||
@@ -0,0 +1,65 @@
|
||||
package database_test
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/google/uuid"
|
||||
"github.com/stretchr/testify/assert"
|
||||
"github.com/stretchr/testify/require"
|
||||
"sneak.berlin/go/webhooker/internal/database"
|
||||
)
|
||||
|
||||
// usernameAtLimit is exactly MaxUsernameBytes long, built from a
|
||||
// two-byte character. A check that counted characters rather than bytes
|
||||
// would see half the length and let the one-byte-longer name through.
|
||||
func usernameAtLimit() string {
|
||||
return strings.Repeat("é", database.MaxUsernameBytes/2)
|
||||
}
|
||||
|
||||
func TestUserCreate_RejectsOverlongUsername(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
db := startedTestDB(t)
|
||||
|
||||
err := db.Create(&database.User{
|
||||
Username: usernameAtLimit() + "x",
|
||||
Password: "hash",
|
||||
}).Error
|
||||
|
||||
require.ErrorIs(t, err, database.ErrUsernameTooLong)
|
||||
}
|
||||
|
||||
func TestUserCreate_AcceptsUsernameAtLimit(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
db := startedTestDB(t)
|
||||
|
||||
require.NoError(t, db.Create(&database.User{
|
||||
Username: usernameAtLimit(),
|
||||
Password: "hash",
|
||||
}).Error)
|
||||
}
|
||||
|
||||
// TestUsersTable_EnforcesUsernameLimitWithoutTheModel inserts with raw
|
||||
// SQL, as a path that bypassed User.BeforeSave would, so only the
|
||||
// table's check constraint stands between it and an over-long
|
||||
// username. Accepting the name at the limit and refusing the next byte
|
||||
// also pins the constraint's number to MaxUsernameBytes.
|
||||
func TestUsersTable_EnforcesUsernameLimitWithoutTheModel(t *testing.T) {
|
||||
t.Parallel()
|
||||
|
||||
db := startedTestDB(t)
|
||||
|
||||
insert := "INSERT INTO users (id, username, password) VALUES (?, ?, ?)"
|
||||
|
||||
require.NoError(t, db.Exec(
|
||||
insert, uuid.New().String(), usernameAtLimit(), "hash",
|
||||
).Error)
|
||||
|
||||
err := db.Exec(
|
||||
insert, uuid.New().String(), usernameAtLimit()+"x", "hash",
|
||||
).Error
|
||||
require.Error(t, err)
|
||||
assert.Contains(t, err.Error(), "CHECK constraint failed")
|
||||
}
|
||||
Reference in New Issue
Block a user