docs(mqtt-auth): record verified VPS broker setup and ACL isolation test
Checked the live broker on 2026-09-30: - mosquitto.conf sets no files-backend ACL path. A live test (device A subscribing to device B's topics) was denied while A's own topics were delivered, so the files backend does not grant-all and every ACL check reaches the Console. The missing ACL file is therefore harmless. - Recorded the container/image, config and passwd locations, which lines already match the new code, and the one change still pending (auth/acl cache 300s -> 60s before app users go live). - Added the copy-paste isolation test so it can be re-run after any broker config change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -111,14 +111,36 @@ When those lines stop appearing, set `MQTT_ALLOW_LEGACY_PASSWORD=false`.
|
|||||||
auth_opt_acl_jitter_seconds 10 # r
|
auth_opt_acl_jitter_seconds 10 # r
|
||||||
allow_anonymous false # R
|
allow_anonymous false # R
|
||||||
|
|
||||||
4. **Check the files ACL file** (`auth_opt_files_acl_path`). go-auth allows a request if
|
4. **Files-backend ACL: verified OK (2026-09-30).** The VPS config sets no
|
||||||
*any* backend allows it, so general rules in that file apply to app users too and
|
`auth_opt_files_acl_path` (nor `acl_file`). A live test confirmed the files backend
|
||||||
bypass the per-device ACL. Only lines under a `user admin` / `user bonamin` /
|
does **not** grant ACLs to everyone, so every ACL check reaches the Console. If an
|
||||||
`user NodeRED` block are safe. A `pattern ...` line, or a `topic ...` line placed
|
ACL file is ever added, only lines under `user admin` / `user bonamin` /
|
||||||
before the first `user` line, applies to every user. Such lines must not cover
|
`user NodeRED` are safe. A `pattern` line, or a `topic` line placed before the first
|
||||||
`vesper/...`.
|
`user` line, applies to every user (app users included) and must not cover `vesper/...`.
|
||||||
|
Re-run the isolation test after any broker config change (on the VPS host):
|
||||||
|
|
||||||
|
A=PV25L22BP01R01; B=PV26B02BP01R01
|
||||||
|
PW=$(docker exec bellsystems-backend python -c "from mqtt.auth import _derive_password; print(_derive_password('$A'))")
|
||||||
|
# own topics -> should print messages
|
||||||
|
docker exec mosquitto mosquitto_sub -h localhost -i acl-test-own -u "$A" -P "$PW" -t "vesper/$A/#" -v -W 5
|
||||||
|
# foreign topics -> must say "All subscription requests were denied."
|
||||||
|
docker exec mosquitto mosquitto_sub -h localhost -i acl-test-foreign -u "$A" -P "$PW" -t "vesper/$B/#" -v -W 5
|
||||||
|
|
||||||
5. **Enable a TLS listener** in Mosquitto for the app (certificate on the VPS).
|
5. **Enable a TLS listener** in Mosquitto for the app (certificate on the VPS).
|
||||||
|
|
||||||
|
### Current VPS broker setup (as of 2026-09-30)
|
||||||
|
|
||||||
|
- Container `mosquitto`, image `iegomez/mosquitto-go-auth:latest`.
|
||||||
|
- Config: host `/home/bellsystems/stacks/mosquitto/config/mosquitto.conf`, mounted at
|
||||||
|
`/etc/mosquitto/mosquitto.conf` (Docker images usually use `/mosquitto/config`; this
|
||||||
|
one does not). Passwd file: `/home/bellsystems/stacks/mosquitto/passwd`.
|
||||||
|
- Already set correctly: `backends files,http`, `http_host 172.20.0.1` (Docker bridge),
|
||||||
|
`http_port 8000`, both URIs, `http_method post`, `params_mode form`,
|
||||||
|
`response_mode status`, `cache true`, `cache_reset true`.
|
||||||
|
- Still to change: `auth_cache_seconds` and `acl_cache_seconds` are **300**. Lower
|
||||||
|
both to 60 before app users go live, or a block/unassign can take up to 5 minutes
|
||||||
|
to apply.
|
||||||
|
|
||||||
## Known gaps / decisions
|
## Known gaps / decisions
|
||||||
|
|
||||||
- **FlutterFlow writes to `user_list`.** If the app changes `user_list` directly in
|
- **FlutterFlow writes to `user_list`.** If the app changes `user_list` directly in
|
||||||
|
|||||||
Reference in New Issue
Block a user