jfjoch_broker: /start takes an optional `tokens` list (any number, all equivalent; writeOnly in the
API). While the current dataset has any, the endpoints that expose it - /statistics/data_collection,
/result/scan, /image_buffer/{start.cbor,image.cbor,image.jpeg,image.tiff}, /preview/plot{,.bin} -
answer 401 unless the request carries `Authorization: Bearer <token>`; /statistics keeps serving
the instrument view and only omits its `measurement` block. Enforcement is one pre-routing hook
over a named path set (the same set carries `bearerAuth` in jfjoch_api.yaml); tokens are compared
in constant time and never read back or logged. The tokens are replaced only by an accepted start,
and atomically with clearing the previous run's status, plots and image buffer, in this order:
clear, swap, import the new settings - so no moment serves the old run under the new tokens or the
new run's name under the old ones. Settings are validated on a copy first so a refused start
changes nothing.
jfjoch_viewer: a Token field (password echo) next to the http/https scheme in Open HTTP Connection,
JUNGFRAUJOCH_HTTP_TOKEN, and D-Bus LoadFile(..., token) / SetHttpToken; the dialog overrides the
others, nothing is persisted. A 401 clears the display, stops following and puts a line on the
status bar - no dialog, since a dataset changing hands is the normal cause.
Web frontend: key button in the top bar (token in sessionStorage, applied to the bearerAuth
operations by the generated client, and to the raw preview fetch), a tokens field in the start
form, and a "token required" hint on the plots. Python client: Configuration(access_token=...)
after regeneration.
Viewer: reference dataset accepts a structure-factor mmCIF (already read by content; the dialog
now offers it) and a model file can be chosen next to it (ProcessConfig::model_path, as
rugnux --model); the job also carries the reference's free-R flags, cell and setting, and the
copied command line states -z / --reference-column / --model. A grid scan keeps its own preferred
dataset-info plot and "Spots + background" means the spot count there. Dark theme: the navy hero
buttons, checked segments, warning texts and chart guide lines follow the theme instead of their
light-theme colours.
Docs: SECURITY.md section 3 is now the implemented scheme; a guided tour with four screenshots
in JFJOCH_VIEWER.md; broker, OpenAPI, Python client and frontend pages mention the token.
Tests: BearerTokens unit test and an HTTP round trip over the real broker HTTP layer (jfjoch_test
now compiles JFJochBrokerHttp.cpp and links httplib).
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
131 lines
6.2 KiB
C++
131 lines
6.2 KiB
C++
// SPDX-FileCopyrightText: 2026 Filip Leonarski, Paul Scherrer Institute <filip.leonarski@psi.ch>
|
|
// SPDX-License-Identifier: GPL-3.0-only
|
|
|
|
#include <catch2/catch_all.hpp>
|
|
#include <httplib.h>
|
|
#include <nlohmann/json.hpp>
|
|
#include <chrono>
|
|
#include <thread>
|
|
|
|
#include "../broker/JFJochBrokerHttp.h"
|
|
|
|
// The tokens given to /start guard the endpoints that expose the dataset, and nothing else, for as
|
|
// long as that dataset is the current one. Runs the real HTTP layer against a broker with no
|
|
// receiver: /start is then accepted and finishes at once with nothing to acquire.
|
|
TEST_CASE("JFJochBrokerHttp_BearerTokens", "[broker]") {
|
|
DiffractionExperiment experiment;
|
|
SpotFindingSettings spot_finding;
|
|
JFJochBrokerHttp broker(experiment, spot_finding);
|
|
broker.AddDetectorSetup(DetJF4M());
|
|
|
|
httplib::Server server;
|
|
broker.attach(server);
|
|
const int port = server.bind_to_any_port("127.0.0.1");
|
|
REQUIRE(port > 0);
|
|
// Stopped and joined however the test ends, so a failed REQUIRE does not abort on a joinable thread.
|
|
struct ServerThread {
|
|
httplib::Server &server;
|
|
std::thread thread;
|
|
explicit ServerThread(httplib::Server &s) : server(s), thread([&s] { s.listen_after_bind(); }) {}
|
|
~ServerThread() { server.stop(); thread.join(); }
|
|
} server_thread(server);
|
|
server.wait_until_ready();
|
|
|
|
httplib::Client client("127.0.0.1", port);
|
|
const httplib::Headers good{{"Authorization", "Bearer secret-1"}};
|
|
const httplib::Headers other{{"Authorization", "Bearer secret-2"}};
|
|
const httplib::Headers wrong{{"Authorization", "Bearer nope"}};
|
|
|
|
auto start = [&](const nlohmann::json &extra) {
|
|
nlohmann::json body = {{"beam_x_pxl", 1000}, {"beam_y_pxl", 1000},
|
|
{"detector_distance_mm", 100}, {"incident_energy_keV", 12.4},
|
|
{"images_per_trigger", 1}, {"ntrigger", 1},
|
|
{"file_prefix", "protected_run"}};
|
|
body.update(extra);
|
|
auto res = client.Post("/start", body.dump(), "application/json");
|
|
REQUIRE(res);
|
|
REQUIRE(res->status == 200);
|
|
// With no receiver the measurement thread idles for 30 s before the run ends; wait it out.
|
|
for (int i = 0; i < 120; i++) {
|
|
auto status = client.Get("/status");
|
|
REQUIRE(status);
|
|
if (nlohmann::json::parse(status->body).at("state") == "Idle")
|
|
return;
|
|
std::this_thread::sleep_for(std::chrono::milliseconds(500));
|
|
}
|
|
FAIL("broker did not return to Idle after the start");
|
|
};
|
|
|
|
REQUIRE(client.Post("/initialize")->status == 200);
|
|
|
|
// Nothing started yet: open, whatever the header says.
|
|
REQUIRE(client.Get("/statistics/data_collection")->status == 200);
|
|
REQUIRE(client.Get("/statistics/data_collection", wrong)->status == 200);
|
|
REQUIRE(client.Get("/statistics")->status == 200);
|
|
|
|
start({{"tokens", {"secret-1", "secret-2"}}});
|
|
|
|
SECTION("protected endpoints refuse without a token and say nothing about the dataset") {
|
|
for (const char *path: {"/statistics/data_collection", "/result/scan", "/image_buffer/start.cbor",
|
|
"/image_buffer/image.cbor?id=0", "/image_buffer/image.tiff?id=0",
|
|
"/image_buffer/image.jpeg?id=0", "/preview/plot?type=bkg_estimate",
|
|
"/preview/plot.bin?type=bkg_estimate"}) {
|
|
INFO(path);
|
|
auto res = client.Get(path);
|
|
REQUIRE(res);
|
|
REQUIRE(res->status == 401);
|
|
REQUIRE(res->get_header_value("WWW-Authenticate") == "Bearer");
|
|
REQUIRE(res->body.find("protected_run") == std::string::npos);
|
|
REQUIRE(client.Get(path, wrong)->status == 401);
|
|
}
|
|
}
|
|
|
|
SECTION("either token opens them") {
|
|
auto res = client.Get("/statistics/data_collection", good);
|
|
REQUIRE(res->status == 200);
|
|
REQUIRE(res->body.find("protected_run") != std::string::npos);
|
|
REQUIRE(client.Get("/statistics/data_collection", other)->status == 200);
|
|
REQUIRE(client.Get("/preview/plot?type=bkg_estimate", good)->status == 200);
|
|
}
|
|
|
|
SECTION("the aggregate statistics drop the measurement block instead of refusing") {
|
|
auto res = client.Get("/statistics");
|
|
REQUIRE(res->status == 200);
|
|
REQUIRE_FALSE(nlohmann::json::parse(res->body).contains("measurement"));
|
|
REQUIRE(res->body.find("protected_run") == std::string::npos);
|
|
|
|
auto with_token = client.Get("/statistics", good);
|
|
REQUIRE(with_token->status == 200);
|
|
REQUIRE(nlohmann::json::parse(with_token->body).contains("measurement"));
|
|
}
|
|
|
|
SECTION("the control plane and the broker status stay open") {
|
|
REQUIRE(client.Get("/status")->status == 200);
|
|
REQUIRE(client.Get("/image_buffer/status")->status == 200);
|
|
REQUIRE(client.Get("/config/detector")->status == 200);
|
|
}
|
|
|
|
SECTION("a refused start keeps the current tokens, an accepted one replaces them") {
|
|
// Not idle: /start is refused, the dataset stays protected by its own tokens.
|
|
REQUIRE(client.Post("/deactivate")->status == 200);
|
|
nlohmann::json body = {{"beam_x_pxl", 1000}, {"beam_y_pxl", 1000},
|
|
{"detector_distance_mm", 100}, {"incident_energy_keV", 12.4}};
|
|
REQUIRE(client.Post("/start", body.dump(), "application/json")->status == 500);
|
|
REQUIRE(client.Post("/initialize")->status == 200);
|
|
REQUIRE(client.Get("/statistics/data_collection")->status == 401);
|
|
REQUIRE(client.Get("/statistics/data_collection", good)->status == 200);
|
|
|
|
// The next start without tokens lifts the protection.
|
|
start(nlohmann::json::object());
|
|
REQUIRE(client.Get("/statistics/data_collection")->status == 200);
|
|
REQUIRE(client.Get("/statistics/data_collection", wrong)->status == 200);
|
|
|
|
// And with new tokens, the old ones no longer open it.
|
|
start({{"tokens", {"secret-3"}}});
|
|
const httplib::Headers newer{{"Authorization", "Bearer secret-3"}};
|
|
REQUIRE(client.Get("/statistics/data_collection", good)->status == 401);
|
|
REQUIRE(client.Get("/statistics/data_collection", newer)->status == 200);
|
|
}
|
|
|
|
}
|