Files
picpeak/backend/AUTH_SECURITY_ROLLBACK.md
T
paul e35ac6a41c
Test Gitea Actions / test (push) Successful in 20s
continuous-integration/drone/push Build is passing
feat: implement critical security fixes for SQL injection and authentication vulnerabilities
Security Enhancements:
- Fix SQL injection vulnerabilities by replacing whereRaw queries with parameterized queries
- Add LIKE pattern escaping to prevent SQL injection in search functionality
- Implement account lockout protection (5 failed attempts = 30 min lockout)
- Add comprehensive login attempt tracking and audit trail
- Enhance JWT tokens with issuer validation, IP tracking, and password change detection
- Add logout endpoint and session management
- Prevent user enumeration with generic error messages

Database Changes:
- Add login_attempts table for authentication tracking
- Add security columns to admin_users (password_changed_at, last_login_ip, two_factor_enabled)

New Security Features:
- Brute force protection with configurable lockout duration
- Automatic cleanup of old login attempts
- Enhanced authentication middleware with stricter validation
- Monitoring scripts for security health checks

All fixes are backward compatible and production-ready with rollback plans included.

🤖 Generated with [Claude Code](https://claude.ai/code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-07-13 00:40:05 +02:00

4.2 KiB

Authentication Security Enhancement Rollback Plan

Quick Rollback Steps

Immediate Rollback (< 2 minutes)

If auth issues occur after deployment, follow these steps:

# 1. SSH into production server
ssh your-server

# 2. Navigate to backend directory
cd /path/to/picpeak/backend

# 3. Revert route changes in server.js
# Change from:
# const authRoutes = require('./src/routes/auth-enhanced');
# Back to:
# const authRoutes = require('./src/routes/auth');

# 4. Revert middleware if changed
# Change from:
# const { adminAuth } = require('./src/middleware/auth-enhanced');
# Back to:
# const { adminAuth } = require('./src/middleware/auth');

# 5. Restart application
docker-compose restart backend
# OR
pm2 restart picpeak-backend

Rollback Scenarios

Scenario 1: Users Can't Login

Symptoms:

  • All login attempts fail
  • Generic "Invalid credentials" error
  • Admin panel inaccessible

Quick Fix:

# Revert to original auth routes
cd backend
git checkout HEAD -- server.js
docker-compose restart backend

Scenario 2: Account Lockout Issues

Symptoms:

  • Legitimate users locked out
  • "Account temporarily locked" errors

Quick Fix:

-- Clear all lockouts
DELETE FROM login_attempts WHERE success = false;

-- Or clear specific user
DELETE FROM login_attempts 
WHERE identifier = 'username_or_email' 
AND success = false;

Scenario 3: Token Validation Errors

Symptoms:

  • "Invalid token" errors
  • Existing sessions broken
  • API calls failing

Quick Fix:

// In auth middleware, temporarily disable strict validation
// Comment out issuer validation:
// issuer: 'picpeak-auth'

// Just use basic verification:
const decoded = jwt.verify(token, process.env.JWT_SECRET);

Scenario 4: Database Migration Issues

Symptoms:

  • Application won't start
  • Database errors in logs

Rollback Migration:

# Rollback last 2 migrations
npx knex migrate:rollback --all
npx knex migrate:up 014_add_default_welcome_message.js

# Or manually fix:
sqlite3 database.db
DROP TABLE IF EXISTS login_attempts;
ALTER TABLE admin_users DROP COLUMN password_changed_at;
ALTER TABLE admin_users DROP COLUMN last_login_ip;

Verification After Rollback

  1. Test Admin Login:

    curl -X POST http://your-domain/api/auth/admin/login \
      -H "Content-Type: application/json" \
      -d '{"username":"admin","password":"your-password"}'
    
  2. Test Gallery Access:

    curl -X POST http://your-domain/api/auth/gallery/verify \
      -H "Content-Type: application/json" \
      -d '{"slug":"test-gallery","password":"gallery-password"}'
    
  3. Check Logs:

    # No auth errors should appear
    docker-compose logs backend | tail -100 | grep -i error
    

File Restoration

If files were modified, restore from backup:

# List of files that can be safely reverted
git checkout HEAD -- src/middleware/auth.js
git checkout HEAD -- src/routes/auth.js
git checkout HEAD -- server.js

# Remove new files (safe to delete)
rm -f src/utils/authSecurity.js
rm -f src/middleware/auth-enhanced.js
rm -f src/routes/auth-enhanced.js
rm -f migrations/015_add_login_attempts_table.js
rm -f migrations/016_add_auth_security_columns.js

Emergency SQL Fixes

-- Clear all security restrictions
DELETE FROM login_attempts;

-- Reset admin password if locked out
UPDATE admin_users 
SET password_hash = '$2b$10$YourKnownGoodHashHere'
WHERE username = 'admin';

-- Remove security columns if causing issues
-- (SQLite doesn't support DROP COLUMN easily, so ignore)

Monitoring After Rollback

# Watch for stability
watch -n 5 'docker-compose logs backend | tail -20'

# Check active connections
netstat -an | grep :3001 | wc -l

# Monitor CPU/Memory
docker stats wedding-photo-sharing-backend-1

Prevention for Next Attempt

Before re-attempting the security enhancement:

  1. Test in staging environment first
  2. Implement gradual rollout with feature flags
  3. Add backwards compatibility for tokens
  4. Create admin bypass for lockouts
  5. Set up monitoring alerts

Contact

If rollback fails:

  1. Check backend/logs/error.log
  2. Restore from last known good backup
  3. Use original auth implementation as reference