create_account is reachable without the admin allowlist (allowNewKeys hardcoded true) and has no throttling #57

Open
opened 2026-10-09 17:17:57 +00:00 by padreug · 0 comments
Owner

src/daemon/admin/index.ts:44 const allowNewKeys = true; and :267-270 return early from validateRequest for create_account, skipping validateRequestFromAdmin. The admin transport subscribes #p = admin pubkey on kinds 24133/24134 from anyone, so any nostr client can drive the account-creation flow: key generation, config write, nip05 file rewrite, DB rows and an immediate kind:'all' grant to the caller. The anti-spam // TODO: require some POW is still open. Today the only brake is that validateDomain throws when no domains are configured.

Impact: unauthenticated, unbounded resource creation and namespace pollution on any deployment with a domain configured; each created key is also a plaintext custodial secret (separate issue).

Fix direction: make open signup a config flag defaulting to off (e.g. admin.allowOpenSignup or per-domain), and when on, require NIP-13 PoW on the request event plus a per-pubkey rate limit and a global/domain account cap. Our operator-IdP path uses create_new_key over the admin channel and does not need create_account at all, so default-off costs nothing.

Found during reforge run #1 (sandbox nsecbunkerd#8).

`src/daemon/admin/index.ts:44` `const allowNewKeys = true;` and `:267-270` return early from `validateRequest` for `create_account`, skipping `validateRequestFromAdmin`. The admin transport subscribes `#p = admin pubkey` on kinds 24133/24134 from anyone, so any nostr client can drive the account-creation flow: key generation, config write, nip05 file rewrite, DB rows and an immediate `kind:'all'` grant to the caller. The anti-spam `// TODO: require some POW` is still open. Today the only brake is that `validateDomain` throws when no `domains` are configured. Impact: unauthenticated, unbounded resource creation and namespace pollution on any deployment with a domain configured; each created key is also a plaintext custodial secret (separate issue). Fix direction: make open signup a config flag defaulting to off (e.g. `admin.allowOpenSignup` or per-domain), and when on, require NIP-13 PoW on the request event plus a per-pubkey rate limit and a global/domain account cap. Our operator-IdP path uses `create_new_key` over the admin channel and does not need `create_account` at all, so default-off costs nothing. Found during reforge run #1 (sandbox nsecbunkerd#8).
Sign in to join this conversation.
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
aiolabs/nsecbunkerd#57
No description provided.