Audit fixes: batch recompute, negative-baseline percentages, key-ring persistence
ci / build-test (push) Successful in 1m17s
ci / build-test (push) Successful in 1m17s
Three defects found reviewing the last few commits. Deriving consumption on ingest made the batch reading endpoint quadratic. A recompute rewrites a meter's entire consumption series, and POST /api/v1/readings ran one per reading -- 500 readings for one meter meant 500 full rewrites. IngestByMeterAsync takes renormalize:false and the endpoint normalizes each touched meter once after the batch. Percentage change divided by a possibly negative baseline. A net-export meter going from -100 to -150 exported half again as much and would have been reported as "+50%", reading as more consumption. A non-positive baseline now reports no basis rather than a confident lie. The data-protection key ring had no persistent home outside Docker Compose. The LXC installer now creates /var/lib/metervault/keys at 0700 -- the app would otherwise create it under the default umask, leaving a key ring world-readable -- and the Unraid template maps it, since without that every UI-entered secret was lost whenever the container was recreated. README documents the variable and the trust boundary: keys on disk protect against leaked database content, not against an attacker who already has the host. Claude-Session: https://claude.ai/code/session_01V6joyergfvVLFEizH1hJLd
This commit is contained in:
@@ -23,6 +23,7 @@
|
||||
: "${INSTALL_DIR:=/opt/metervault}"
|
||||
: "${SOURCE_DIR:=/opt/metervault-src}"
|
||||
: "${ENV_FILE:=/etc/metervault/environment}"
|
||||
: "${KEYRING_DIR:=/var/lib/metervault/keys}"
|
||||
: "${DB_NAME:=metervault}"
|
||||
: "${DB_USER:=metervault}"
|
||||
|
||||
@@ -203,6 +204,13 @@ EOF
|
||||
chmod 600 "${ENV_FILE}"
|
||||
}
|
||||
|
||||
# Key ring for connector secrets typed into the admin UI (SDD §6.4). The app creates this itself if
|
||||
# missing, but with the default umask — created here instead so it is 0700 from the start, and so it
|
||||
# is visibly outside /opt/metervault, which the updater republishes on every run.
|
||||
write_keyring_dir() {
|
||||
install -d -m 0700 "${KEYRING_DIR}"
|
||||
}
|
||||
|
||||
write_systemd() {
|
||||
cat <<'EOF' >/etc/systemd/system/metervault.service
|
||||
[Unit]
|
||||
@@ -246,6 +254,7 @@ main() {
|
||||
install_dotnet_sdk
|
||||
build_metervault
|
||||
write_env
|
||||
write_keyring_dir
|
||||
write_systemd
|
||||
|
||||
systemctl daemon-reload 2>/dev/null || true
|
||||
|
||||
@@ -23,4 +23,6 @@
|
||||
<Config Name="API key" Target="MeterVault__ApiKeys__0" Default="" Mode="" Description="API key for the REST API (X-Api-Key header). Leave blank to leave the API open." Type="Variable" Display="always" Required="false" Mask="true"/>
|
||||
|
||||
<Config Name="Reverse-proxy trust" Target="MeterVault__ReverseProxyTrust" Default="false" Mode="" Description="Honour X-Forwarded-User from a trusted auth proxy" Type="Variable" Display="advanced" Required="false">false</Config>
|
||||
|
||||
<Config Name="Secret key ring" Target="/var/lib/metervault/keys" Default="/mnt/user/appdata/metervault/keys" Mode="rw" Description="Encryption keys for connector secrets entered in the web UI. Must persist: without this mapping every stored token is lost when the container is recreated." Type="Path" Display="always" Required="true">/mnt/user/appdata/metervault/keys</Config>
|
||||
</Container>
|
||||
|
||||
Reference in New Issue
Block a user