Skip to content

feat: rate limit auth endpoints and scope user proxy host permissions - #5908

Open
auzcoder wants to merge 1 commit into
NginxProxyManager:developfrom
auzcoder:fix/auth-rate-limit-and-permissions
Open

auzcoder wants to merge 1 commit into
NginxProxyManager:developfrom
auzcoder:fix/auth-rate-limit-and-permissions

Conversation

@auzcoder

Copy link
Copy Markdown

Description

This pull request introduces authentication endpoint rate limiting, adds granular proxy host permission scoping for non-admin users, and hardens security around advanced Nginx configurations.

Key Changes:

  1. Authentication Rate Limiting (�ackend/lib/express/rate-limit.js, �ackend/routes/tokens.js):

    • In-memory sliding window rate limiter applied to POST /tokens and POST /tokens/2fa.
    • Excludes successful logins (skipSuccessfulRequests: true) so legitimate users are not penalized.
    • Bypasses rate limiting in CI and test environments (isCI(), process.env.CI, process.env.NODE_ENV === 'test', or DISABLE_RATE_LIMIT === 'true').
    • Cleanup interval unrefs timer to prevent hanging Node process.
  2. Scoped Proxy Host Permissions (�ackend/migrations/20260906220000_user_permission_meta.js, �ackend/lib/access.js, �ackend/internal/proxy-host.js, rontend/src/modals/PermissionsModal.tsx):

    • Adds nullable meta JSON column to user_permission table.
    • Allows admins to designate specific allowed proxy hosts (meta.proxy_host_ids) when a user's visibility is set to "Created Items Only" (user).
    • Interactive checkbox list in PermissionsModal to select allowed proxy hosts.
  3. Security Hardening on Host Advanced Configs (�ackend/internal/*.js, rontend/src/modals/*Modal.tsx):

    • Restricts custom �dvanced_config modification to admin users only (�ccess.hasRole?.('admin') || access.token.hasScope('admin')) for proxy hosts, redirection hosts, and dead hosts.
    • Frontend modals hide the "Advanced" settings tab for non-admin users and strip the field upon submission.
  4. Bugfix on User Permission Updates (�ackend/internal/user.js, �ackend/routes/users.js):

    • Fixes ID comparison mismatch (Number(user.id) !== Number(data.id)).
    • Omits id from the permission payload when patching/inserting user_permission records so primary key values are not corrupted.
  5. UI & Usability Enhancements ( rontend/src/pages/Users/Table.tsx, rontend/src/components/Form/LocationsFields.tsx, rontend/src/modals/ProxyHostModal.tsx):

    • Adds a "Permissions" column in the Users management table to view assigned user permission badges at a glance.
    • Uses small-screen column classes and ext-nowrap labels to prevent wrapping in proxy host and location forwarding fields.

Testing

  • Verified all permissions schemas and knex migrations.
  • Tested user permission update endpoints and role resolution.
  • Validated rate limiter behavior with both failed and successful login requests.

@auzcoder
auzcoder force-pushed the fix/auth-rate-limit-and-permissions branch from 00bbcdf to 48f6676 Compare September 28, 2026 19:51
- Add in-memory sliding window rate limiter for auth token endpoints with CI/test bypass and successful request exclusion
- Add user_permission meta column migration and Objection model configuration
- Support scoping allowed proxy hosts per user when in 'Created Items Only' visibility mode
- Restrict advanced nginx configuration editing on hosts to admin users only
- Fix user permissions route ID parsing and omit id from permission update payloads
- Add allowed proxy hosts selector in permissions modal and display permissions summary badges in users table
@auzcoder
auzcoder force-pushed the fix/auth-rate-limit-and-permissions branch from 48f6676 to 8888455 Compare September 28, 2026 20:16
@nginxproxymanagerci

Copy link
Copy Markdown

Docker Image for build 3 is available on DockerHub:

nginxproxymanager/nginx-proxy-manager-dev:pr-5908

Note

Ensure you backup your NPM instance before testing this image! Especially if there are database changes.
This is a different docker image namespace than the official image.

Warning

Changes and additions to DNS Providers require verification by at least 2 members of the community!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant