Add super/jump admin, per-host connection tracking; move stats to Audit
- app_super_admin (cross-app, also recognized by sso-manager-node/proxy) and a new app_jump_admin group are added to conf.auth: super admins are full admins here same as app_sso_admin; jump admins get audit page/data access without other admin rights (isJumpAdmin/requireJumpAdmin in middleware/auth.js, wired into routes/api.js's audit-data gate and the /audit page's client-side forceLogin -- previously the page shell rendered for any logged-in user, only the data was gated). - Dashboard: moved the stat boxes and Top hosts/Top users cards to the Audit page (audit is now the admin-facing metrics home; dashboard stays focused on "hosts I can reach"). Renamed "All hosts" to "My hosts". - Host list now shows Last connection/Last failed connection columns and highlights rows green (live session, from session_registry) or yellow (most recent attempt failed) -- backed by new per-host last-success/ last-fail timestamps in models/metrics.js, populated by ssh_server.js (which now attributes grammar/TUI connect failures to the resolved host when one was found, not just aggregate counters) and surfaced through GET /api/user/hosts (routes/user.js).
This commit is contained in:
+18
-2
@@ -4,14 +4,17 @@
|
||||
// browser who it is and whether it's an admin (drives login state + nav).
|
||||
|
||||
const router = require('express').Router();
|
||||
const { isAdmin } = require('../middleware/auth');
|
||||
const { isAdmin, isJumpAdmin } = require('../middleware/auth');
|
||||
const access = require('../utils/access');
|
||||
const metrics = require('../models/metrics');
|
||||
const registry = require('../services/session_registry');
|
||||
|
||||
router.get('/me', (req, res) => {
|
||||
res.json({
|
||||
username: req.user && req.user.username,
|
||||
groups: req.groups || [],
|
||||
isAdmin: isAdmin(req),
|
||||
isJumpAdmin: isJumpAdmin(req),
|
||||
});
|
||||
});
|
||||
|
||||
@@ -23,7 +26,20 @@ router.get('/hosts', async (req, res, next) => {
|
||||
const hosts = isAdmin(req)
|
||||
? await access.allHosts()
|
||||
: await access.accessibleHosts({ uid: req.user && req.user.username, groups: req.groups || [] });
|
||||
res.json({ results: hosts });
|
||||
|
||||
// Enrich with connection state for the dashboard's host list: whether a
|
||||
// session is live right now (active bridges, session_registry), plus the
|
||||
// last successful/failed connection times (models/metrics).
|
||||
const connectedSlugs = new Set(registry.list().map((s) => s.slug));
|
||||
const last = await metrics.lastForHosts(hosts.map((h) => h.slug));
|
||||
const enriched = hosts.map((h) => ({
|
||||
...h,
|
||||
connected: connectedSlugs.has(h.slug),
|
||||
lastConnected: (last[h.slug] && last[h.slug].lastConnected) || null,
|
||||
lastFailed: (last[h.slug] && last[h.slug].lastFailed) || null,
|
||||
}));
|
||||
|
||||
res.json({ results: enriched });
|
||||
} catch (err) { next(err); }
|
||||
});
|
||||
|
||||
|
||||
Reference in New Issue
Block a user