clusev/tests/Feature
boban 9a6c09e488 fix(2fa): close two re-view holes in backup-codes show-once
Stored recovery codes were re-viewable two ways after their one-time
reveal. Both paths are now closed so codes are only viewable/downloadable
right after a fresh generation (enrollment or regenerate).

HOLE 1 — RecoveryCodes::$revealed was a mutable public Livewire prop, so
a crafted /livewire/update could flip it to true and make render() emit
stored codes. Annotated with #[Locked]; Livewire now rejects any
client-side write (set still happens server-side in mount()/regenerate()).

HOLE 2 — two-factor.recovery.download was auth-gated only, so any authed
user could GET it anytime to re-download stored codes. Added a one-time
session grant (2fa.download_grant) put alongside the existing
2fa.codes_fresh wherever codes are freshly generated (TwoFactorSetup,
WebauthnKeys, RecoveryCodes::regenerate); the route now
abort_unless(pull(grant), 403) before streaming — one download per fresh
generation, later direct hits 403.

Tests: lock rejection + download-grant lifecycle (forbidden → granted ok
→ consumed forbidden). Full suite 137 passed.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-15 06:21:45 +02:00
..
AuditRetentionTest.php feat(audit): configurable retention + scheduled clusev:prune-audit 2026-06-14 23:40:17 +02:00
ButtonComponentTest.php feat(ui): uniform bordered button kit; retire ghost variants 2026-06-14 10:18:47 +02:00
ChallengeFactorAdaptTest.php fix(2fa): memoize challenge pending-user lookup; assert key-only view; tidy hint wording 2026-06-14 21:17:18 +02:00
CommandPaletteServerSearchTest.php fix(services): live journal poll + command-palette server search 2026-06-14 20:13:08 +02:00
CreateServerTest.php feat(servers): verify SSH on create + start in "Initialisierung" 2026-06-14 10:26:15 +02:00
EmailResetTest.php feat(auth): email reset-link path (gated on a configured mailer) 2026-06-14 16:57:05 +02:00
ExternalTlsModeTest.php feat(tls): external reverse-proxy mode core — no ACME + no forced HTTPS redirect (host check kept) 2026-06-14 22:31:04 +02:00
Fail2banBansModalTest.php feat(fail2ban): lazy-load Gesperrte IPs modal behind a skeleton 2026-06-15 03:05:35 +02:00
FirstFactorCodesTest.php Reveal backup codes only when freshly generated 2026-06-15 06:14:59 +02:00
FleetTestConnectionTest.php feat(ssh): add FleetService::testConnection credential probe 2026-06-14 10:24:42 +02:00
ForgotPasswordKeyOnlyTest.php feat(2fa): forgot-password is key-only safe + states the no-2FA recovery path 2026-06-14 21:26:59 +02:00
ForgotPasswordTest.php fix(auth): rotate remember_token on reset + atomic recovery-code use 2026-06-14 17:04:12 +02:00
HardeningServiceTest.php feat(hardening): treat auto-updates as a neutral operator preference 2026-06-14 10:23:28 +02:00
MultiUserTest.php feat(accounts): multi-user admin management — create (temp pw), list, remove, force-logout 2026-06-14 23:39:34 +02:00
OptionalOnboardingTest.php feat(2fa): onboarding no longer forces 2FA (only password rotation) 2026-06-14 20:44:12 +02:00
PersistentSecurityGateTest.php fix(security): register EnsureSecurityOnboarded as persistent Livewire middleware 2026-06-14 22:40:31 +02:00
RecoveryCodesModalTest.php fix(2fa): close two re-view holes in backup-codes show-once 2026-06-15 06:21:45 +02:00
ResetAdminCommandTest.php fix(webauthn): counter zero only when stored is zero + CLI clears keys 2026-06-14 18:47:07 +02:00
RestartSentinelTest.php feat(system): auto-restart sentinel — one-click restart via host watcher (no docker socket) 2026-06-14 23:42:50 +02:00
ServerContextSyncTest.php fix(ui): set active server at mount only (race-free) 2026-06-14 19:43:24 +02:00
ServerShowPanelsTest.php fix(servers): keep read-error panels visible + pending header support 2026-06-14 10:41:04 +02:00
ServerShowSshHintTest.php feat(servers): hint that disabling password login leaves key-only access 2026-06-14 10:30:07 +02:00
ServicesJournalPollTest.php fix(services): cap live journal at 200 rows in a scrollable, auto-sticking box 2026-06-14 20:58:48 +02:00
SessionManagementTest.php feat(sessions): database sessions + list/revoke (other devices, per-user, global) with remember-token rotation 2026-06-14 23:34:00 +02:00
SettingsFactorManagementTest.php refactor(settings): split into per-tab nested components (Profile, Security) + tab hosts for Users/Sessions/Email 2026-06-14 23:23:25 +02:00
SmtpConfigTest.php feat(mail): SMTP configuration in Settings (encrypted password, runtime override, test-send) 2026-06-14 23:42:19 +02:00
SshKeyProvisionModalTest.php fix(ssh): best-effort audit + exception-safe switch/verify and modal run(); lock serverId 2026-06-14 22:16:54 +02:00
SshKeyProvisionerTest.php fix(ssh): graceful failure if password-disable throws post-switch; document privateKey-on-failure contract 2026-06-14 22:04:56 +02:00
StatusComponentTest.php feat(ui): add "Initialisierung" (pending) server status 2026-06-14 10:20:32 +02:00
TlsModeToggleTest.php fix(tls): audit TLS-mode changes in applyTlsMode (covers direct Livewire calls, no double-audit) 2026-06-14 22:49:31 +02:00
TwoFactorChallengeRecoveryTest.php feat(auth): accept a 2FA backup code at the login challenge 2026-06-14 16:50:36 +02:00
TwoFactorWebauthnTest.php feat(webauthn): use a security key at the login challenge 2026-06-14 18:26:58 +02:00
UserFactorSemanticsTest.php feat(2fa): pluggable factor semantics on User (hasTotp, either-factor, resetIfNoFactor) 2026-06-14 20:38:36 +02:00
UserRecoveryCodesTest.php feat(auth): store 2FA recovery codes (encrypted) on users 2026-06-14 16:48:21 +02:00
ValidationMessagesTest.php feat(i18n): custom bilingual validation messages (DE + EN) 2026-06-14 15:45:02 +02:00
VerifyTotpTest.php fix(2fa): TwoFactorSetup back to auth layout; exception-safe User::verifyTotp at all call sites 2026-06-14 21:40:15 +02:00
WebauthnAvailableTest.php feat(webauthn): WebauthnService::available gate (domain + https) 2026-06-14 18:18:43 +02:00
WebauthnCredentialTest.php feat(webauthn): install web-auth/webauthn-lib + credential storage 2026-06-14 18:18:05 +02:00
WebauthnKeysTest.php fix(webauthn): tolerate zero-counter authenticators + recheck 2FA on register 2026-06-14 18:44:24 +02:00
WebauthnOptionsTest.php feat(webauthn): registration/assertion options + ceremony verification 2026-06-14 18:24:10 +02:00