Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
5 changes: 5 additions & 0 deletions docs/install/configuration.md
Original file line number Diff line number Diff line change
Expand Up @@ -12,6 +12,11 @@ The configuration is made through environment variables.
| `RM_HTTPS_COOKIE` | For the UI, force cookies to be available only via https |
| `RM_TRUST_PROXY` | Trust the proxy for client ip addresses (X-Forwarded-For/X-Real-IP) default false |
| `HASH_SCHEMA_VERSION` | Hash tree schema version: "3" or "4" (default: 3) |
| `RMFAKECLOUD_WEBAUTHN` | Enable **passkeys** (WebAuthn) for the web UI (default: `false`). Additive to password login. Requires a real HTTPS browser origin (not `http://hostname:port` or raw IPs). |
| `RMFAKECLOUD_WEBAUTHN_RPID` | Relying Party ID — hostname without scheme or port (e.g. `www.example.com`). If empty and `STORAGE_URL` is `https://…`, derived from that host. |
| `RMFAKECLOUD_WEBAUTHN_ORIGINS` | Comma-separated allowed origins (e.g. `https://www.example.com:3000`). If empty and `STORAGE_URL` is `https://…`, derived as a single origin from it. |

Manual verification steps: [passkeys checklist](passkeys-checklist.md).

## Handwriting recognition

Expand Down
11 changes: 11 additions & 0 deletions docs/install/passkeys-checklist.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
# Passkeys (WebAuthn) — manual checklist

Requires `RMFAKECLOUD_WEBAUTHN=true` and HTTPS origin matching `RMFAKECLOUD_WEBAUTHN_RPID` / `ORIGINS` (or derived from https `STORAGE_URL`).

1. Open the web UI over HTTPS (not `http://acorn:3000` / raw IP).
2. Sign in with email/password.
3. Profile → **Passkeys** → Add passkey (optional label). Complete browser/OS prompt.
4. Sign out. Login page should show **Sign in with passkey**.
5. Use passkey to sign in; land on Documents; cookie/JWT works as usual.
6. Confirm password login still works.
7. Profile → remove passkey; optional: set `RMFAKECLOUD_WEBAUTHN=false` and restart → status/`Passkeys` UI hidden, login button gone.
7 changes: 7 additions & 0 deletions go.mod
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,7 @@ require (
github.com/danjacques/gofslock v0.0.0-20240212154529-d899e02bfe22
github.com/dropbox/dropbox-sdk-go-unofficial/v6 v6.0.5
github.com/gin-gonic/gin v1.9.1
github.com/go-webauthn/webauthn v0.11.2
github.com/golang-jwt/jwt/v4 v4.5.2
github.com/google/uuid v1.6.0
github.com/gorilla/websocket v1.5.1
Expand All @@ -34,20 +35,25 @@ require (
github.com/chenzhuoyu/base64x v0.0.0-20230717121745-296ad89f973d // indirect
github.com/chenzhuoyu/iasm v0.9.1 // indirect
github.com/davecgh/go-spew v1.1.1 // indirect
github.com/fxamacker/cbor/v2 v2.7.0 // indirect
github.com/gabriel-vasile/mimetype v1.4.3 // indirect
github.com/gin-contrib/sse v0.1.0 // indirect
github.com/go-playground/locales v0.14.1 // indirect
github.com/go-playground/universal-translator v0.18.1 // indirect
github.com/go-playground/validator/v10 v10.19.0 // indirect
github.com/go-webauthn/x v0.1.14 // indirect
github.com/goccy/go-json v0.10.2 // indirect
github.com/golang-jwt/jwt/v5 v5.2.1 // indirect
github.com/golang/protobuf v1.5.4 // indirect
github.com/google/go-cmp v0.6.0 // indirect
github.com/google/go-tpm v0.9.1 // indirect
github.com/gorilla/i18n v0.0.0-20150820051429-8b358169da46 // indirect
github.com/json-iterator/go v1.1.12 // indirect
github.com/jung-kurt/gofpdf v1.16.2 // indirect
github.com/klauspost/cpuid/v2 v2.2.7 // indirect
github.com/leodido/go-urn v1.4.0 // indirect
github.com/mattn/go-isatty v0.0.20 // indirect
github.com/mitchellh/mapstructure v1.5.0 // indirect
github.com/modern-go/concurrent v0.0.0-20180306012644-bacd9c7ef1dd // indirect
github.com/modern-go/reflect2 v1.0.2 // indirect
github.com/nfnt/resize v0.0.0-20180221191011-83c6a9932646 // indirect
Expand All @@ -62,6 +68,7 @@ require (
github.com/unidoc/timestamp v0.0.0-20200412005513-91597fd3793a // indirect
github.com/unidoc/unichart v0.3.0 // indirect
github.com/unidoc/unitype v0.4.0 // indirect
github.com/x448/float16 v0.8.4 // indirect
golang.org/x/arch v0.7.0 // indirect
golang.org/x/image v0.18.0 // indirect
golang.org/x/net v0.38.0 // indirect
Expand Down
14 changes: 14 additions & 0 deletions go.sum
Original file line number Diff line number Diff line change
Expand Up @@ -76,6 +76,8 @@ github.com/envoyproxy/go-control-plane v0.9.0/go.mod h1:YTl/9mNaCwkRvm6d1a2C3ymF
github.com/envoyproxy/go-control-plane v0.9.1-0.20191026205805-5f8ba28d4473/go.mod h1:YTl/9mNaCwkRvm6d1a2C3ymFceY/DCBVvsKhRF0iEA4=
github.com/envoyproxy/go-control-plane v0.9.4/go.mod h1:6rpuAdCZL397s3pYoYcLgu1mIlRU8Am5FuJP05cCM98=
github.com/envoyproxy/protoc-gen-validate v0.1.0/go.mod h1:iSmxcyjqTsJpI2R4NaDN7+kN2VEUnK/pcBlmesArF7c=
github.com/fxamacker/cbor/v2 v2.7.0 h1:iM5WgngdRBanHcxugY4JySA0nk1wZorNOpTgCMedv5E=
github.com/fxamacker/cbor/v2 v2.7.0/go.mod h1:pxXPTn3joSm21Gbwsv0w9OSA2y1HFR9qXEeXQVeNoDQ=
github.com/gabriel-vasile/mimetype v1.4.3 h1:in2uUcidCuFcDKtdcBxlR0rJ1+fsokWf+uqxgUFjbI0=
github.com/gabriel-vasile/mimetype v1.4.3/go.mod h1:d8uq/6HKRL6CGdk+aubisF/M5GcPfT7nKyLpA0lbSSk=
github.com/gin-contrib/sse v0.1.0 h1:Y/yl/+YNO8GZSjAhjMsSuLt29uWRFHdHYUb5lYOV9qE=
Expand All @@ -93,10 +95,16 @@ github.com/go-playground/universal-translator v0.18.1 h1:Bcnm0ZwsGyWbCzImXv+pAJn
github.com/go-playground/universal-translator v0.18.1/go.mod h1:xekY+UJKNuX9WP91TpwSH2VMlDf28Uj24BCp08ZFTUY=
github.com/go-playground/validator/v10 v10.19.0 h1:ol+5Fu+cSq9JD7SoSqe04GMI92cbn0+wvQ3bZ8b/AU4=
github.com/go-playground/validator/v10 v10.19.0/go.mod h1:dbuPbCMFw/DrkbEynArYaCwl3amGuJotoKCe95atGMM=
github.com/go-webauthn/webauthn v0.11.2 h1:Fgx0/wlmkClTKlnOsdOQ+K5HcHDsDcYIvtYmfhEOSUc=
github.com/go-webauthn/webauthn v0.11.2/go.mod h1:aOtudaF94pM71g3jRwTYYwQTG1KyTILTcZqN1srkmD0=
github.com/go-webauthn/x v0.1.14 h1:1wrB8jzXAofojJPAaRxnZhRgagvLGnLjhCAwg3kTpT0=
github.com/go-webauthn/x v0.1.14/go.mod h1:UuVvFZ8/NbOnkDz3y1NaxtUN87pmtpC1PQ+/5BBQRdc=
github.com/goccy/go-json v0.10.2 h1:CrxCmQqYDkv1z7lO7Wbh2HN93uovUHgrECaO5ZrCXAU=
github.com/goccy/go-json v0.10.2/go.mod h1:6MelG93GURQebXPDq3khkgXZkazVtN9CRI+MGFi0w8I=
github.com/golang-jwt/jwt/v4 v4.5.2 h1:YtQM7lnr8iZ+j5q71MGKkNw9Mn7AjHM68uc9g5fXeUI=
github.com/golang-jwt/jwt/v4 v4.5.2/go.mod h1:m21LjoU+eqJr34lmDMbreY2eSTRJ1cv77w39/MY0Ch0=
github.com/golang-jwt/jwt/v5 v5.2.1 h1:OuVbFODueb089Lh128TAcimifWaLhJwVflnrgM17wHk=
github.com/golang-jwt/jwt/v5 v5.2.1/go.mod h1:pqrtFR0X4osieyHYxtmOUWsAWrfe1Q5UVIyoH402zdk=
github.com/golang/glog v0.0.0-20160126235308-23def4e6c14b/go.mod h1:SBH7ygxi8pfUlaOkMMuAQtPIUF8ecWP5IEl/CR7VP2Q=
github.com/golang/groupcache v0.0.0-20190702054246-869f871628b6/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
github.com/golang/groupcache v0.0.0-20191227052852-215e87163ea7/go.mod h1:cIg4eruTrX1D+g88fzRXU5OdNfaM+9IcxsU14FzY7Hc=
Expand Down Expand Up @@ -137,6 +145,8 @@ github.com/google/go-cmp v0.5.1/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/
github.com/google/go-cmp v0.5.5/go.mod h1:v8dTdLbMG2kIc/vJvl+f65V22dbkXbowE6jgT/gNBxE=
github.com/google/go-cmp v0.6.0 h1:ofyhxvXcZhMsU5ulbFiLKl/XBFqE1GSq7atu8tAmTRI=
github.com/google/go-cmp v0.6.0/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY=
github.com/google/go-tpm v0.9.1 h1:0pGc4X//bAlmZzMKf8iz6IsDo1nYTbYJ6FZN/rg4zdM=
github.com/google/go-tpm v0.9.1/go.mod h1:h9jEsEECg7gtLis0upRBQU+GhYVH6jMjrFxI8u6bVUY=
github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg=
github.com/google/martian v2.1.0+incompatible/go.mod h1:9I4somxYTbIHy5NJKHRl3wXiIaQGbYVAs8BPL6v8lEs=
github.com/google/martian/v3 v3.0.0/go.mod h1:y5Zk1BBys9G+gd6Jrk0W3cC1+ELVxBWuIGO+w/tUAp0=
Expand Down Expand Up @@ -186,6 +196,8 @@ github.com/leodido/go-urn v1.4.0 h1:WT9HwE9SGECu3lg4d/dIA+jxlljEa1/ffXKmRjqdmIQ=
github.com/leodido/go-urn v1.4.0/go.mod h1:bvxc+MVxLKB4z00jd1z+Dvzr47oO32F/QSNjSBOlFxI=
github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWEY=
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
github.com/mitchellh/mapstructure v1.5.0 h1:jeMsZIYE/09sWLaz43PL7Gy6RuMjD2eJVyuac5Z2hdY=
github.com/mitchellh/mapstructure v1.5.0/go.mod h1:bFUtVrKA4DC2yAKiSyO/QUcy7e+RRV2QTWOzhPopBRo=
github.com/mochi-mqtt/server/v2 v2.7.9 h1:y0g4vrSLAag7T07l2oCzOa/+nKVLoazKEWAArwqBNYI=
github.com/mochi-mqtt/server/v2 v2.7.9/go.mod h1:lZD3j35AVNqJL5cezlnSkuG05c0FCHSsfAKSPBOSbqc=
github.com/modern-go/concurrent v0.0.0-20180228061459-e0a39a4cb421/go.mod h1:6dJC0mAP4ikYIbvyc7fijjWJddQyLn8Ig3JB5CqoB9Q=
Expand Down Expand Up @@ -251,6 +263,8 @@ github.com/unidoc/unipdf/v3 v3.56.0 h1:15Lt+AZvELP03PH23ypV0y5reKZxCRKSq46SZg+vx
github.com/unidoc/unipdf/v3 v3.56.0/go.mod h1:iBr/OsbLnJ49WhJlpfpYS3VmXrkTG05O7rKe9crppmc=
github.com/unidoc/unitype v0.4.0 h1:/TMZ3wgwfWWX64mU5x2O9no9UmoBqYCB089LYYqHyQQ=
github.com/unidoc/unitype v0.4.0/go.mod h1:HV5zuUeqMKA4QgYQq3KDlJY/P96XF90BQB+6czK6LVA=
github.com/x448/float16 v0.8.4 h1:qLwI1I70+NjRFUR3zs1JPUCgaCXSh3SW62uAKT1mSBM=
github.com/x448/float16 v0.8.4/go.mod h1:14CWIYCyZA/cWjXOioeEpHeN/83MdbZDRQHoFcYsOfg=
github.com/yuin/goldmark v1.1.25/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
github.com/yuin/goldmark v1.1.27/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
github.com/yuin/goldmark v1.1.32/go.mod h1:3hX8gzYuyVAZsxl0MRgGTJEmQBFcNTphYh9decYSb74=
Expand Down
73 changes: 73 additions & 0 deletions internal/config/config.go
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@ import (
"os"
"path/filepath"
"strconv"
"strings"

"github.com/ddvk/rmfakecloud/internal/email"
log "github.com/sirupsen/logrus"
Expand Down Expand Up @@ -81,6 +82,10 @@ const (
envMQTTPort = "MQTT_PORT"
envICEServers = "ICE_SERVERS"
envHashSchemaVersion = "HASH_SCHEMA_VERSION"

envWebAuthn = "RMFAKECLOUD_WEBAUTHN"
envWebAuthnRPID = "RMFAKECLOUD_WEBAUTHN_RPID"
envWebAuthnOrigins = "RMFAKECLOUD_WEBAUTHN_ORIGINS"
)

// Config config
Expand All @@ -106,6 +111,12 @@ type Config struct {
MQTTPort string
ICEServers []interface{}
HashSchemaVersion string
// WebAuthn enables passkey login for the web UI (RMFAKECLOUD_WEBAUTHN). Default false.
WebAuthn bool
// WebAuthnRPID is the Relying Party ID (hostname without scheme/port).
WebAuthnRPID string
// WebAuthnOrigins are allowed browser origins for WebAuthn ceremonies.
WebAuthnOrigins []string
}

// Verify verify
Expand Down Expand Up @@ -142,6 +153,9 @@ func (cfg *Config) Verify() {
} else {
log.Info("No ICE servers configured - screenshare will only work on local networks")
}
if cfg.WebAuthn {
log.Infof("web UI passkeys enabled (rpid=%q origins=%v)", cfg.WebAuthnRPID, cfg.WebAuthnOrigins)
}
}

// FromEnv config from environment values
Expand Down Expand Up @@ -265,6 +279,29 @@ func FromEnv() *Config {
log.Fatalf("%s must be either '3' or '4', got: %s", envHashSchemaVersion, hashSchemaVersion)
}

webAuthnWanted, _ := strconv.ParseBool(os.Getenv(envWebAuthn))
webAuthnRPID := strings.TrimSpace(os.Getenv(envWebAuthnRPID))
webAuthnOrigins := splitCSV(os.Getenv(envWebAuthnOrigins))
webAuthnEnabled := false
if webAuthnWanted {
if webAuthnRPID == "" || len(webAuthnOrigins) == 0 {
if derivedRPID, derivedOrigins, ok := deriveWebAuthnFromStorageURL(uploadURL); ok {
if webAuthnRPID == "" {
webAuthnRPID = derivedRPID
}
if len(webAuthnOrigins) == 0 {
webAuthnOrigins = derivedOrigins
}
}
}
if webAuthnRPID == "" || len(webAuthnOrigins) == 0 {
log.Errorf("%s=true but %s / %s not set and could not derive from https %s; passkeys disabled",
envWebAuthn, envWebAuthnRPID, envWebAuthnOrigins, EnvStorageURL)
} else {
webAuthnEnabled = true
}
}

cfg := Config{
Port: port,
StorageURL: uploadURL,
Expand All @@ -284,10 +321,36 @@ func FromEnv() *Config {
MQTTPort: mqttPort,
ICEServers: iceServers,
HashSchemaVersion: hashSchemaVersion,
WebAuthn: webAuthnEnabled,
WebAuthnRPID: webAuthnRPID,
WebAuthnOrigins: webAuthnOrigins,
}
return &cfg
}

func splitCSV(s string) []string {
parts := strings.Split(s, ",")
out := make([]string, 0, len(parts))
for _, p := range parts {
p = strings.TrimSpace(p)
if p != "" {
out = append(out, p)
}
}
return out
}

// deriveWebAuthnFromStorageURL returns RPID (hostname without port) and a single origin
// when STORAGE_URL is https with a host. http / empty host returns ok=false.
func deriveWebAuthnFromStorageURL(storageURL string) (rpid string, origins []string, ok bool) {
u, err := url.Parse(storageURL)
if err != nil || u.Scheme != "https" || u.Hostname() == "" {
return "", nil, false
}
origin := "https://" + u.Host
return u.Hostname(), []string{origin}, true
}

// normalizeICEServers expands "urls" arrays into singular "url" entries; xochitl rejects anything else
func normalizeICEServers(servers []interface{}) []interface{} {
normalized := make([]interface{}, 0, len(servers))
Expand Down Expand Up @@ -378,6 +441,12 @@ General:
%s Trust the proxy for X-Forwarded-For/X-Real-IP (set only if behind a proxy)
%s Hash tree schema version: "3" or "4" (default: 3)

Web UI passkeys (WebAuthn):
%s Enable passkey register/login for the web UI (default: false). Requires HTTPS browser origin.
%s Relying Party ID (hostname without scheme/port). If empty, derived from https STORAGE_URL.
%s Comma-separated allowed origins (e.g. https://example.com:3000). If empty, derived from https STORAGE_URL.
http://hostname, LAN names, and raw IPs do not work for real passkeys.

MQTT (for screenshare):
%s MQTT TCP port (default: 8883)
%s ICE servers for WebRTC (JSON array format)
Expand Down Expand Up @@ -415,6 +484,10 @@ myScript hwr (needs a developer account):
envTrustProxy,
envHashSchemaVersion,

envWebAuthn,
envWebAuthnRPID,
envWebAuthnOrigins,

envMQTTPort,
envICEServers,

Expand Down
23 changes: 23 additions & 0 deletions internal/config/webauthn_config_test.go
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
package config

import "testing"

func TestDeriveWebAuthnFromStorageURL(t *testing.T) {
rpid, origins, ok := deriveWebAuthnFromStorageURL("https://www.example.com:3000")
if !ok || rpid != "www.example.com" || len(origins) != 1 || origins[0] != "https://www.example.com:3000" {
t.Fatalf("got rpid=%q origins=%v ok=%v", rpid, origins, ok)
}
if _, _, ok := deriveWebAuthnFromStorageURL("http://acorn:3000"); ok {
t.Fatal("http should not derive")
}
if _, _, ok := deriveWebAuthnFromStorageURL("not-a-url"); ok {
t.Fatal("invalid should not derive")
}
}

func TestSplitCSV(t *testing.T) {
got := splitCSV(" https://a.com ,https://b.com, ")
if len(got) != 2 || got[0] != "https://a.com" || got[1] != "https://b.com" {
t.Fatalf("%v", got)
}
}
2 changes: 2 additions & 0 deletions internal/model/user.go
Original file line number Diff line number Diff line change
Expand Up @@ -55,6 +55,8 @@ type User struct {
AdditionalScopes []string
// Integrations stores the list of "Integrations" as shown on the tablet.
Integrations []IntegrationConfig
// WebAuthnCredentials are passkeys registered for the web UI.
WebAuthnCredentials []WebAuthnCredential `yaml:"webauthncredentials,omitempty"`
}

// IntegrationConfig config for various integrations
Expand Down
Loading