mirror of
https://github.com/CyberMind-FR/secubox-deb.git
synced 2026-07-28 21:17:36 +00:00
/login/mfa and /totp/confirm both hardcoded "ip": "" and omitted user_agent entirely, while only the password path captured them. admin is forced-TOTP, so EVERY real admin login took the MFA path — every session row landed unauditable (who logged in, from where, with what), and the users webui sessions tab rendered blanks for data it was already asking for. Factor the extraction into _client_meta(request) (X-Forwarded-For first: nginx and HAProxy front every login, so request.client.host is only ever the proxy) and use it on all three paths. Verified by driving the real /login/mfa handler in-process with SECUBOX_AUTH_SESSIONS pointed at a temp file: the session row now records ip=192.168.1.77 (the first XFF hop, not the proxy) and the full user-agent. Co-Authored-By: Gerald KERMA <devel@cybermind.fr> |
||
|---|---|---|
| .. | ||
| api | ||
| debian | ||
| menu.d | ||
| nginx | ||
| tests | ||
| www | ||
| README.md | ||
🔐 Auth Guardian
Unified authentication management
Category: Security
Screenshot
Features
- OAuth2
- LDAP
- 2FA/TOTP
- Session management
Installation
# Add SecuBox repository
curl -fsSL https://apt.secubox.in/install.sh | sudo bash
# Install package
sudo apt install secubox-auth
Configuration
Configuration file: /etc/secubox/auth.toml
API Endpoints
GET /api/v1/auth/status- Module statusGET /api/v1/auth/health- Health check
License
LicenseRef-CMSD-1.0 (Source-Disclosed License) — CyberMind © 2024-2026. See LICENCE-CMSD-1.0.md.
