Commit graph

727 commits

Author SHA1 Message Date
f938b263cd
Mikrotik backup and gettext start 2026-02-02 09:11:22 -06:00
a48cb292da
update org settings layout 2026-02-01 17:42:14 -06:00
1414f087fc
bug fix 2026-02-01 17:25:16 -06:00
1790db8d5a
update mikrotik port with/without ssl 2026-02-01 17:09:52 -06:00
6b63dc9295
encryption updates 2026-02-01 17:05:55 -06:00
23af86ba73
add mikrotik device handling 2026-02-01 16:42:39 -06:00
bcd2570b10
user settings test update 2026-02-01 15:02:35 -06:00
a66aec675e Merge branch 'gmcintire/user-first-last-name' into 'main'
Replace single name field with first_name and last_name

See merge request towerops/towerops!3
2026-02-01 15:00:24 -06:00
e46ecbfca2 Replace single name field with first_name and last_name 2026-02-01 15:00:23 -06:00
91517aa934 Merge branch 'gmcintire/security-audit' into 'main'
Add rate limiting to auth and API endpoints using Hammer

See merge request towerops/towerops!2
2026-02-01 14:59:54 -06:00
02833d0b44 Add rate limiting to auth and API endpoints using Hammer 2026-02-01 14:59:54 -06:00
f0d6ae42d0
feat: update UserAuth to redirect to sudo verify page 2026-02-01 14:58:07 -06:00
9ff9c4ddc8
fix: address UserSudoController critical issues
Critical fixes:
- Renamed controller actions to follow Phoenix conventions (verify→new, create→verify)
- Added sudo mode check in GET action using last_sudo_at timestamp
- Added TOTP enrollment check in GET action with redirect
- Changed default return path from /orgs to /users/settings
- Updated route paths from /users/sudo/verify to /users/sudo-verify (dash separator)
- Added success flash message "Identity verified."

Implementation details:
- new/2 (GET): Checks recently_verified_sudo?/1 helper that examines last_sudo_at
  instead of authenticated_at to distinguish sudo verification from regular login
- verify/2 (POST): Adds info flash and defaults to /users/settings
- recently_verified_sudo?/1: Private helper checking last_sudo_at within 10 minutes
- Updated all routes, templates, and tests to use new paths and action names

Tests:
- Added tests for already-in-sudo-mode redirect behavior
- Added test for TOTP enrollment requirement
- Updated all test assertions for new route paths and success messages
- All 15 controller tests passing
- Full test suite passing (4076 tests, 0 failures)
2026-02-01 14:45:05 -06:00
264154a3d8
feat: implement sudo mode MFA-only verification controller
- Add UserSudoController with GET and POST /users/sudo/verify routes
- Create verify.html.heex template for TOTP verification form
- Only accept TOTP codes (6 numeric digits), reject recovery codes
- Update grant_sudo_mode to set authenticated_at virtual field
- Exclude /users/sudo paths from return_to overwriting
- Add comprehensive controller tests (12 test cases)
- Verify redirect behavior, error handling, and session management

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Sonnet 4.5 <noreply@anthropic.com>
2026-02-01 14:34:17 -06:00
d7234e02a3
fix: improve verify_totp_only validation logic 2026-02-01 14:24:19 -06:00
42565779bc
feat: add Accounts.verify_totp_only/2 function 2026-02-01 14:17:09 -06:00
92350173b0
feat: add audit logging to grant_sudo_mode/1 2026-02-01 14:09:40 -06:00
ada851e7ed
feat: add Accounts.grant_sudo_mode/1 function 2026-02-01 14:02:41 -06:00
303196bb8e
Add design doc for sudo mode MFA-only verification 2026-02-01 13:50:34 -06:00
b241d9df91
show cloud poller device count 2026-02-01 13:41:01 -06:00
2a5622d95a
impersonate fix and change log level for device polling 2026-02-01 13:33:36 -06:00
04c33b0719
paginate audit logs 2026-02-01 13:27:56 -06:00
7232dab601
live device polling 2026-02-01 13:19:32 -06:00
6bdd90fd97
add admin links 2026-02-01 12:37:50 -06:00
612bed2dd5
mikrotik version upgrade tracking 2026-02-01 12:35:41 -06:00
7ca07010ab
Use detected timezone from session in user registration 2026-02-01 12:18:33 -06:00
9dd5d8c0ac
force non-ssl 2026-02-01 12:03:14 -06:00
c856b2142c
Add timezone validation to reject invalid IANA timezone strings
Prevents invalid timezone values from being stored in the database
by validating against Elixir's time zone database during registration.
2026-02-01 11:56:04 -06:00
923fb4a9ed
exclude healthcheck from ssl redirect 2026-02-01 11:27:08 -06:00
0037f18848
Accept timezone parameter in user registration changeset 2026-02-01 11:21:50 -06:00
77e62df9da
Move CaptureTimezone plug to browser pipeline
The plug was incorrectly placed in the endpoint, causing it to run on
all requests including APIs. Moved to :browser pipeline where it belongs,
and removed redundant fetch_session call since the pipeline handles it.
2026-02-01 11:15:51 -06:00
d05c493943
Add CaptureTimezone plug to browser pipeline 2026-02-01 11:10:34 -06:00
d9876d8217
Remove misleading duplicate header test from CaptureTimezone
The test incorrectly suggested the plug handles duplicate headers,
but put_req_header replaces values. Cloudflare only sends one
cf-timezone header, making this test unnecessary.
2026-02-01 11:08:12 -06:00
c4e8c70e7d
Add CaptureTimezone plug to extract cf-timezone header 2026-02-01 11:02:57 -06:00
45f8bc7459
Add design for Cloudflare timezone detection on signup
Documents approach to automatically populate user timezone from cf-timezone
header during registration, with UTC fallback when header is not present.
2026-02-01 10:56:07 -06:00
ad753cf0c6
add headers debug in prod 2026-02-01 10:54:13 -06:00
ee5852ecc0
Add manual firmware check trigger instructions to README 2026-02-01 10:50:21 -06:00
fcf3ce154f
Add firmware update indicator to device detail page
- Load available firmware in DeviceLive.Show
- Add firmware_update_available? and format_date helpers
- Display blue indicator banner when newer firmware available
- Show current vs latest version with release date
- Add download link and release notes link
- Support MikroTik initially, extensible to other vendors

Phase 6 (final) of firmware tracking complete. All phases implemented:
 Database schema (firmware_releases, device_firmware_history)
 Version comparison logic (VersionComparator)
 RSS fetching worker (daily Oban cron)
 Firmware context with logging and PubSub
 Version change detection in Discovery
 LiveView UI indicators
2026-02-01 10:49:00 -06:00
61a06fc11c
Add firmware version tracking system
- Add firmware context module with upsert, query, and logging functions
- Add FirmwareVersionFetcherWorker to fetch MikroTik RSS daily
- Add Oban cron schedules (2 AM dev, 4 AM prod)
- Add version change detection to Discovery module
- Track firmware history with PubSub broadcasts
- All tests passing

Phase 3-5 of firmware tracking implementation complete.
Next: LiveView UI indicators.
2026-02-01 10:46:27 -06:00
d392c2d788
Add VersionComparator module for semantic version comparison
Implements compare/2 and newer?/2 functions for comparing semantic versions.

Parsing rules:
- Supports 0-3 part versions (e.g., '7', '7.14', '7.14.1')
- Strips v/V prefix and whitespace
- Ignores suffixes after hyphen or space
- Pads missing parts with 0
- Invalid versions (4+ parts, non-numeric, negative) fall back to 0.0.0

Part of firmware version tracking feature (Phase 2).
2026-02-01 10:24:13 -06:00
004189aaf9
Add firmware tracking database schema
- Create firmware_releases table to store latest available firmware versions
- Create device_firmware_history table to track version changes over time
- Add FirmwareRelease and DeviceFirmwareHistory Ecto schemas with validations
- Add comprehensive tests for both schemas (23 tests, 100% coverage)

firmware_releases stores one record per vendor/product_line with latest version.
device_firmware_history is append-only audit log of device firmware changes.

Part of firmware version tracking system for MikroTik (extensible to other vendors).
2026-02-01 10:13:16 -06:00
b30f2cf5af
filter more honeybadger alerts, format dates to users time zone, email template cleanup 2026-02-01 09:27:42 -06:00
b08daf9a88
paginate login history and improve user settings 2026-02-01 09:08:48 -06:00
feed25080c
add HIBP password check 2026-02-01 08:57:01 -06:00
43fe8cd326
Add design document for HIBP password breach checking 2026-01-31 17:16:58 -06:00
2fab08f5f8
forgot password flow 2026-01-31 17:03:22 -06:00
021c86a130
more tests and fixes 2026-01-31 16:00:07 -06:00
dff9c26905
fix TOTP enrollment with recovery codes 2026-01-31 14:54:44 -06:00
c690827ee0 user setting re-auth redirect hopeful fix 2026-01-31 13:32:26 -06:00
4bcac595ad about wording 2026-01-31 13:22:38 -06:00