diff --git a/docs/mqtt-app-user-auth.md b/docs/mqtt-app-user-auth.md index 6e8fbfd..6455fe2 100644 --- a/docs/mqtt-app-user-auth.md +++ b/docs/mqtt-app-user-auth.md @@ -111,14 +111,36 @@ When those lines stop appearing, set `MQTT_ALLOW_LEGACY_PASSWORD=false`. auth_opt_acl_jitter_seconds 10 # r allow_anonymous false # R -4. **Check the files ACL file** (`auth_opt_files_acl_path`). go-auth allows a request if - *any* backend allows it, so general rules in that file apply to app users too and - bypass the per-device ACL. Only lines under a `user admin` / `user bonamin` / - `user NodeRED` block are safe. A `pattern ...` line, or a `topic ...` line placed - before the first `user` line, applies to every user. Such lines must not cover - `vesper/...`. +4. **Files-backend ACL: verified OK (2026-09-30).** The VPS config sets no + `auth_opt_files_acl_path` (nor `acl_file`). A live test confirmed the files backend + does **not** grant ACLs to everyone, so every ACL check reaches the Console. If an + ACL file is ever added, only lines under `user admin` / `user bonamin` / + `user NodeRED` are safe. A `pattern` line, or a `topic` line placed before the first + `user` line, applies to every user (app users included) and must not cover `vesper/...`. + Re-run the isolation test after any broker config change (on the VPS host): + + A=PV25L22BP01R01; B=PV26B02BP01R01 + PW=$(docker exec bellsystems-backend python -c "from mqtt.auth import _derive_password; print(_derive_password('$A'))") + # own topics -> should print messages + docker exec mosquitto mosquitto_sub -h localhost -i acl-test-own -u "$A" -P "$PW" -t "vesper/$A/#" -v -W 5 + # foreign topics -> must say "All subscription requests were denied." + docker exec mosquitto mosquitto_sub -h localhost -i acl-test-foreign -u "$A" -P "$PW" -t "vesper/$B/#" -v -W 5 + 5. **Enable a TLS listener** in Mosquitto for the app (certificate on the VPS). +### Current VPS broker setup (as of 2026-09-30) + +- Container `mosquitto`, image `iegomez/mosquitto-go-auth:latest`. +- Config: host `/home/bellsystems/stacks/mosquitto/config/mosquitto.conf`, mounted at + `/etc/mosquitto/mosquitto.conf` (Docker images usually use `/mosquitto/config`; this + one does not). Passwd file: `/home/bellsystems/stacks/mosquitto/passwd`. +- Already set correctly: `backends files,http`, `http_host 172.20.0.1` (Docker bridge), + `http_port 8000`, both URIs, `http_method post`, `params_mode form`, + `response_mode status`, `cache true`, `cache_reset true`. +- Still to change: `auth_cache_seconds` and `acl_cache_seconds` are **300**. Lower + both to 60 before app users go live, or a block/unassign can take up to 5 minutes + to apply. + ## Known gaps / decisions - **FlutterFlow writes to `user_list`.** If the app changes `user_list` directly in