Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat: rework login authentication and add API token support by Nonary · Pull Request #3999 · LizardByte/Sunshine · GitHub
Skip to content

feat: rework login authentication and add API token support - #3999

Closed
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth
Closed

feat: rework login authentication and add API token support#3999
Nonary wants to merge 53 commits into
LizardByte:masterfrom
Nonary:token_auth

Conversation

@Nonary

@NonaryNonary commented Jun 22, 2025

Copy link
Copy Markdown
Contributor

Description

Adds token-based authentication to Sunshine’s API and admin UI.
Adds token based sessions as an alternative to basic authentication.
Admins can now create, view, and revoke login-free API tokens that grant only the routes they choose.
The existing Basic-Auth flow is untouched, this adds on top of the existing code; therefore there is no breaking changes.

Why this is secure

MeasureWhat it means
Hash-only storageRaw token is shown once, then discarded; only its SHA-256 hash is stored, so a leaked state file reveals nothing usable.
Least-privilege scopesEach token carries an allow-list of API routes + verbs; any request outside that list is rejected.
One-click revocationTokens can be invalidated instantly from the new API Tokens page or via the API.
Non-breakingToken logic is additive; Basic-Auth requests are processed exactly as before.

Benefits

  • Safe automation & integrations – third-party scripts and apps can call the Sunshine API without embedding the admin’s full credentials.
  • Minimal blast-radius – each token can be limited to just the endpoints it needs (e.g., /api/apps GET only), reducing risk, where as using basic auth would give full access to everything in Sunshine.
  • ** Password manager support ** - Browsers can now safely autofill the login.

Screenshot

image

Issues Fixed or Closed

None – this is a new capability.

Type of Change

  • Bug fix
  • New feature
  • Breaking change
  • Dependency update
  • Documentation update
  • Repository update

Checklist

  • Code follows project style guidelines
  • Self-review completed
  • Security-critical sections are commented
  • Docs and inline docstrings updated

@Nonary
Nonary marked this pull request as draft June 23, 2025 01:22
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 04:34
@Nonary
Nonary marked this pull request as draft June 23, 2025 05:42
@Nonary
Nonary marked this pull request as ready for review June 23, 2025 05:52
@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

There appears to be a weird bug in current master branch where there is like a ghost session showing in Moonlight. Thought this may have caused it but it does not.

Nevermind, only happens when you add a blank app to Sunshine... still a weird bug though

@Nonary
Nonary marked this pull request as draft June 24, 2025 08:14
@Nonary
Nonary marked this pull request as ready for review June 26, 2025 19:53
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I removed the frontend unit tests, did another sweep through in cleanup some dead code and comments. I've run through a lot of manual testing and automated testing, so I believe it is ready.

@ReenigneArcherReenigneArcher added roadmap This PR closes a roadmap entry ai PR has signs of heavy ai usage (either indicated by user or assumed) labels Jul 17, 2025
@NonaryNonary closed this Jul 18, 2025
@Nonary

Copy link
Copy Markdown
ContributorAuthor

I was going to re-submit this one with it being stripped down to just the login portion to reduce PR size, since it technically was not asked for specifically in the roadmap. Putting back in draft for now, right now my top priority is WGC capture so not sure when I will come back to this one.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

After reviewing this again nothing needs to be split but there is one more feature I need to add. The frontend should redirect to login screen when an auth error is encountered, so will add that in over the weekend.

@Nonary

Copy link
Copy Markdown
ContributorAuthor

Added better session timeouts, cleaned up the dead code. Login redirects are now working properly, added a new config option for users to define the session ttl for login sessions. Improved UX of the API token page, it's looks much better compared to the original version.

I think that covers everything this needed

@sonarqubecloud

Copy link
Copy Markdown

Quality Gate FailedQuality Gate failed

Failed conditions
16 New issues
1 Security Hotspot
5.0% Duplication on New Code (required ≤ 2%)
C Reliability Rating on New Code (required ≥ A)
15 New Code Smells (required ≤ 0)
1 New Bugs (required ≤ 0)
14 Duplicated Blocks on New Code (required ≤ 0)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

aiPR has signs of heavy ai usage (either indicated by user or assumed)roadmapThis PR closes a roadmap entry

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants

@Nonary@ReenigneArcher@github-advanced-security