Add self-service API tokens (PATs) — the UI had no way to create one
jump-host had zero API-token support: no model, no route, no UI, and Auth.checkApiToken was explicitly absent from the createOidcClient() call (per the comment it left behind). proxy and sso-manager-node both have this; jump-host didn't. Ports proxy's models/api_token.js + routes/api_token.js pattern (jmp_ prefix instead of prx_), wires checkApiToken into createOidcClient(), adds Bearer-token support to middleware/auth.js, and adds a token management card to dashboard.ejs (create/list/rotate/revoke) using app.modal/ app.messages. Scope note: a jump-host token carries no group claims (unlike proxy's, which snapshots the creator's groups), so it authenticates as its creator for non-admin routes (e.g. GET /api/user/hosts) but can never pass requireAdmin — a deliberate, conservative default rather than recomputing live admin status per-request. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -9,6 +9,24 @@ const { Auth } = require('../models');
|
||||
|
||||
async function auth(req, res, next){
|
||||
try{
|
||||
// API-only token: `Authorization: Bearer jmp_<id>_<secret>`. Carries no
|
||||
// group claims (see models/api_token.js), so it authenticates as its
|
||||
// creator but never passes requireAdmin below.
|
||||
const authz = req.header('authorization') || '';
|
||||
if(authz.slice(0, 7).toLowerCase() === 'bearer '){
|
||||
const t = await Auth.checkApiToken(authz.slice(7));
|
||||
req.token = {
|
||||
user: {username: t.created_by},
|
||||
created_by: t.created_by,
|
||||
groupsArray: () => [],
|
||||
check: () => true,
|
||||
is_valid: true,
|
||||
};
|
||||
req.user = req.token.user;
|
||||
req.groups = [];
|
||||
return next();
|
||||
}
|
||||
|
||||
req.token = await Auth.checkToken(req.header('auth-token'));
|
||||
req.user = req.token.user;
|
||||
req.groups = typeof req.token.groupsArray === 'function' ? req.token.groupsArray() : [];
|
||||
|
||||
Reference in New Issue
Block a user