Compare commits
7 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 9db530565d | |||
| fe6306b7d3 | |||
| 240563e093 | |||
| 047e54ce50 | |||
| ee76088f86 | |||
| 8db46bd9d9 | |||
| 67e2fc54c2 |
@@ -4,6 +4,45 @@ All notable changes to this project are documented here. Format loosely
|
||||
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions
|
||||
correspond to git tags (`vX.Y.Z`) and `nodejs/package.json`'s `version`.
|
||||
|
||||
## [1.3.0] - 2026-07-26
|
||||
|
||||
### Changed
|
||||
- **Unified the front-end UI shell across the three theta42 apps.** `views/top.ejs`, `views/bottom.ejs` and `public/lib/js/app-base.js` are now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a new `nodejs/utils/ui.js`, exposed to every render as `ui` via `app.locals`: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all.
|
||||
- **One nav-gating model everywhere.** `app-base.js` reveals `.group-required-<cn>` elements for each group the current user is in, read from `GET /api/user/me`. sso-manager-node reports LDAP DNs in `memberOf` and the OIDC clients report CNs in `groups`; both normalise to CNs client-side, and the clients' effective-rights `isAdmin` flag is exposed as a synthetic `admin` group — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape.
|
||||
- **`GET /api/user/me` is fetched once per page load and cached** (`app.auth.loadUser`). The nav, per-view `forceLogin` and every group-gated element read that one promise instead of issuing their own request.
|
||||
- `app.auth.isLoggedIn` is dual-mode: it returns a Promise **and** invokes an optional node-style callback, so the async and callback call styles both work against one shared `top.ejs`.
|
||||
- `app.auth.forceLogin` no longer uses `$.holdReady` (removed in jQuery 4). An unauthenticated user is redirected to `/login?redirect=<path>`; group requirements are still enforced, and `logOut` now only clears the session, leaving the destination to the caller (`ui.logoutRedirect`).
|
||||
- Dependency alignment across all three apps: `jquery` `^4.0.0` and `ejs` `^3.1.10`.
|
||||
|
||||
### Fixed
|
||||
- **`app.api.delete` dropped its callback when called by `formAJAX`.** `formAJAX` always passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran. `delete` now accepts both `(url, callback)` and `(url, data, callback)`.
|
||||
- **`app.api.post`/`put` referenced an undefined `callback2`** and threw when handed a non-function callback. Both are now dual-mode Promise/callback.
|
||||
- **The login page's "reveal the card once we know you're logged out" branch threw** (`Cannot read properties of null`) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready.
|
||||
- **`logInRedirect` on the legacy `/login/<path>` form kept only the path.** The OIDC provider routes an unauthenticated authorization request through `/login/oauth/authorize?client_id=…&state=…`; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
|
||||
|
||||
### Added
|
||||
- `.group-required { display: none }` in `public/css/styles.css`, the base rule the shared gating model reveals against.
|
||||
- `#spa-shell` dropped its inline `margin-top`; `styles.css` already sets it and the shared shell adjusts it when a banner is shown.
|
||||
|
||||
### Verified
|
||||
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin; `forceLogin`'s onboarding and group gates fire; `val.js` blocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
|
||||
|
||||
## [1.2.0] - 2026-07-25
|
||||
|
||||
### Added
|
||||
- Adopted the shared `@simpleworkjs/*` packages published under the simpleworkjs org, replacing this app's byte-identical forks of the same code so the theta42 apps share one codebase and API schema:
|
||||
- `@simpleworkjs/oidc-client` — the OIDC client (session models, auth router, OIDC utils, safe-redirect, local-admin bootstrap). Deleted the local `utils/oidc.js`, `utils/safe_redirect.js`, `models/oidc_state.js`, `models/token.js`, `models/auth.js`, `routes/auth.js`; `models/index.js` wires the factory and the local-admin bootstrap.
|
||||
- `@simpleworkjs/directory-schema` — the sso↔jump-host directory contract. `utils/access.js` now fetches reachable hosts through the shared `createDirectoryClient` (`getResourcesByGroup`).
|
||||
- `@simpleworkjs/ldap` — `models/user_ldap.js` is now a thin wrapper over `createLdapClient`, preserving this app's loose TLS default (`rejectUnauthorized: false`) and the exact export shape.
|
||||
- `@simpleworkjs/app-stack` — unified `build_info` (`{buildVersion, buildHash, buildYear}`) and the `static-modules` mounting helper. `build_info` moved from `models/` to `utils/`; `routes/render.js` uses `mountStaticModules`.
|
||||
|
||||
### Fixed
|
||||
- **Directory envelope drift was silently treated as "no reachable hosts".** `utils/access.js` previously read `data.results || []`, so if the SSO directory ever returned a bare array (envelope drift) every per-group query collapsed to `[]` and no user could bridge. The shared client now validates the `{ results }` envelope on every call and treats an envelope violation as a failed group fetch rather than silently returning `[]`.
|
||||
|
||||
### Changed
|
||||
- Dependency alignment: `ldapts` `^8.1.2` → `^8.1.8`, `redis` `^4.7` → `^6.1.0` (the direct `redis` dep is unused — only `model-redis` is used, which already brings `redis` ^6.1.0). The new `@simpleworkjs/*` deps resolve from the npm registry (`^1.0.0`); no `file:`/`link:` entries in the lockfile, so `npm ci` is clean in docker builds.
|
||||
- `build_info` export shape changed from `{commit, version}` to `{buildVersion, buildHash, buildYear}` (the shared shape used by all three apps). The `/health` endpoint and footer now report `buildVersion`/`buildHash`.
|
||||
|
||||
## [1.1.0] - 2026-07-23
|
||||
|
||||
### Changed
|
||||
|
||||
@@ -10,6 +10,11 @@ const app = express();
|
||||
app.set('view engine', 'ejs');
|
||||
app.set('views', require('path').join(__dirname, 'views'));
|
||||
|
||||
// Per-app values for the shared UI shell (views/top.ejs + views/bottom.ejs).
|
||||
// Set as an app local so every res.render has it, including routes that don't
|
||||
// spread the render router's `values` object.
|
||||
app.locals.ui = require('./utils/ui');
|
||||
|
||||
app.use(compression());
|
||||
app.use(express.json());
|
||||
app.use(express.urlencoded({extended: false}));
|
||||
|
||||
@@ -5,7 +5,7 @@
|
||||
// callback. The token carries the group snapshot captured at login.
|
||||
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const { Auth } = require('../models/auth');
|
||||
const { Auth } = require('../models');
|
||||
|
||||
async function auth(req, res, next){
|
||||
try{
|
||||
|
||||
@@ -1,118 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
const Table = require('../models');
|
||||
const {User, AuthToken} = Table.models;
|
||||
|
||||
/**
|
||||
* Auth Model
|
||||
*
|
||||
* Handles authentication operations for the application.
|
||||
* Manages user login, token validation, and logout processes.
|
||||
*
|
||||
* Dependencies:
|
||||
* - User model: Validates user credentials
|
||||
* - AuthToken model: Creates and manages authentication tokens
|
||||
*
|
||||
* All methods throw standardized login errors on failure to avoid
|
||||
* leaking information about whether usernames exist or tokens are valid.
|
||||
*/
|
||||
class Auth{
|
||||
/**
|
||||
* Standardized error responses for authentication failures.
|
||||
* Returns generic "Invalid Credentials" message for security.
|
||||
*/
|
||||
static errors = {
|
||||
login: function(){
|
||||
let error = new Error('LoginFailed');
|
||||
error.name = 'LoginFailed';
|
||||
error.message = `Invalid Credentials, login failed.`;
|
||||
error.status = 401;
|
||||
|
||||
return error;
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Authenticate user and create session token.
|
||||
*
|
||||
* @param {Object} data - Login credentials {username, password}
|
||||
* @returns {Object} {user, token} - User object and auth token
|
||||
* @throws {Error} Generic login error on any failure
|
||||
*
|
||||
* Flow:
|
||||
* 1. Validate credentials via User.login()
|
||||
* 2. Create new AuthToken for the user
|
||||
* 3. Return both user data and token
|
||||
*/
|
||||
static async login(data){
|
||||
try{
|
||||
let user = await User.login(data);
|
||||
// Backends may attach group membership to the user (LDAP); default
|
||||
// to none for local/redis users.
|
||||
let groups = Array.isArray(user.groups) ? user.groups : [];
|
||||
let token = await AuthToken.create({username: user.username, groups});
|
||||
|
||||
return {user, token}
|
||||
}catch(error){
|
||||
console.log('login error', error);
|
||||
throw this.errors.login();
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Establish a session for an OIDC-authenticated identity: JIT-provision the
|
||||
* local user (redis-backed) and mint an AuthToken carrying the SSO groups.
|
||||
*
|
||||
* @param {Object} identity - {username, groups} from utils/oidc claims
|
||||
* @returns {Object} {user, token}
|
||||
*/
|
||||
static async oidcSession(identity){
|
||||
let user = typeof User.upsertOidc === 'function'
|
||||
? await User.upsertOidc(identity)
|
||||
: await User.get(identity.username);
|
||||
let token = await AuthToken.create({
|
||||
username: user.username,
|
||||
groups: identity.groups || [],
|
||||
});
|
||||
|
||||
return {user, token};
|
||||
}
|
||||
|
||||
/**
|
||||
* Validate an authentication token.
|
||||
*
|
||||
* @param {string} token - Token string to validate
|
||||
* @returns {Object} Token object if valid
|
||||
* @throws {Error} Generic login error if token invalid or expired
|
||||
*
|
||||
* Checks:
|
||||
* 1. Token exists in database
|
||||
* 2. Token has not expired (via token.check())
|
||||
*/
|
||||
static async checkToken(token){
|
||||
try{
|
||||
token = await AuthToken.get(token);
|
||||
if(token && token.check()) return token;
|
||||
|
||||
throw this.errors.login();
|
||||
}catch(error){
|
||||
console.log('check error', error);
|
||||
throw this.errors.login();
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Destroy an authentication token (logout).
|
||||
*
|
||||
* @param {string} data - Token string to destroy
|
||||
* @returns {void}
|
||||
*
|
||||
* Removes token from database, invalidating the session.
|
||||
*/
|
||||
static async logout(data){
|
||||
let token = await AuthToken.get(data);
|
||||
await token.destroy();
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = {Auth};
|
||||
@@ -1,24 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
// Short git commit, baked into /app/.build_commit at image build time (see
|
||||
// Dockerfile gitinfo stage) or resolved from git on bare metal.
|
||||
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const { execSync } = require('child_process');
|
||||
|
||||
function resolve() {
|
||||
try {
|
||||
const baked = path.join(__dirname, '../../.build_commit');
|
||||
if (fs.existsSync(baked)) return fs.readFileSync(baked, 'utf8').trim();
|
||||
} catch (_) {}
|
||||
try {
|
||||
return execSync('git rev-parse --short HEAD', { stdio: ['ignore', 'pipe', 'ignore'] }).toString().trim();
|
||||
} catch (_) {}
|
||||
return 'unknown';
|
||||
}
|
||||
|
||||
let version = 'unknown';
|
||||
try { version = require('../package.json').version; } catch (_) {}
|
||||
|
||||
module.exports = { commit: resolve(), version };
|
||||
+17
-3
@@ -6,6 +6,7 @@
|
||||
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const { setUpTable } = require('model-redis');
|
||||
const { createOidcClient, bootstrapLocalAdmin } = require('@simpleworkjs/oidc-client');
|
||||
|
||||
const Table = setUpTable(conf.redis);
|
||||
|
||||
@@ -32,7 +33,20 @@ async function getRedis() {
|
||||
module.exports.getRedis = getRedis;
|
||||
|
||||
// Register models (order matters: User before AuthToken's relation resolves).
|
||||
require('./user_redis');
|
||||
require('./token');
|
||||
require('./oidc_state');
|
||||
require('./user_redis'); // User (redis-backed local + OIDC JIT)
|
||||
|
||||
// Shared OIDC client (authorization-code + PKCE): session models (Token,
|
||||
// AuthToken, OidcState), the Auth service, and the /login /logout /oidc/start
|
||||
// /oidc/callback router — all created on this app's Table/redis. jump-host has
|
||||
// no Bearer PATs, so checkApiToken is omitted (Auth.checkApiToken is absent).
|
||||
const oidcClient = createOidcClient({ Table });
|
||||
module.exports.Token = oidcClient.Token;
|
||||
module.exports.AuthToken = oidcClient.AuthToken;
|
||||
module.exports.OidcState = oidcClient.OidcState;
|
||||
module.exports.Auth = oidcClient.Auth;
|
||||
module.exports.authRouter = oidcClient.router;
|
||||
|
||||
require('./audit_event');
|
||||
|
||||
// Idempotent anti-lockout local admin (was the IIFE in user_redis.js).
|
||||
bootstrapLocalAdmin(Table.models.User, { defaultName: 'jumpadmin' });
|
||||
@@ -1,31 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
const Table = require('.');
|
||||
|
||||
/**
|
||||
* OidcState
|
||||
*
|
||||
* Short-lived store for an in-flight OpenID Connect authorization request.
|
||||
* Keyed by the random `state` value; holds the PKCE `code_verifier` and the
|
||||
* post-login redirect target until the SSO calls us back.
|
||||
*
|
||||
* The record auto-expires via model-redis per-key TTL (static _ttl), so an
|
||||
* abandoned login attempt leaves nothing behind and there is no cleanup job.
|
||||
*/
|
||||
class OidcState extends Table{
|
||||
static _key = 'state';
|
||||
|
||||
// Auth round-trips are quick; 5 minutes is plenty and bounds replay.
|
||||
static _ttl = 300;
|
||||
|
||||
static _keyMap = {
|
||||
'created_on': {default: function(){return (new Date).getTime()}},
|
||||
'state': {isRequired: true, type: 'string', min: 8, max: 500},
|
||||
'codeVerifier': {isRequired: true, type: 'string', min: 8, max: 500},
|
||||
'redirect': {default: '/', isRequired: false, type: 'string'},
|
||||
}
|
||||
}
|
||||
|
||||
OidcState.register();
|
||||
|
||||
module.exports = {OidcState};
|
||||
@@ -1,64 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
const Table = require('.');
|
||||
const UUID = function b(a){return a?(a^Math.random()*16>>a/4).toString(16):([1e7]+-1e3+-4e3+-8e3+-1e11).replace(/[018]/g,b)};
|
||||
|
||||
|
||||
class Token extends Table{
|
||||
static _key = 'token';
|
||||
static _keyMap = {
|
||||
'created_by': {isRequired: true, type: 'string', min: 3, max: 500},
|
||||
'created_on': {default: function(){return (new Date).getTime()}},
|
||||
'updated_on': {default: function(){return (new Date).getTime()}, always: true},
|
||||
'token': {default: UUID, type: 'string', min: 36, max: 36, isPrivate: true},
|
||||
'is_valid': {default: true, type: 'boolean'},
|
||||
}
|
||||
|
||||
constructor(...args){
|
||||
super(...args);
|
||||
}
|
||||
|
||||
async check(){
|
||||
try{
|
||||
return this.is_valid;
|
||||
}catch(error){
|
||||
return false
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
Token.register();
|
||||
|
||||
class AuthToken extends Token{
|
||||
static _keyMap = {
|
||||
...super._keyMap,
|
||||
user: {model: 'User', rel: 'one', localKey: 'created_by'},
|
||||
// Group memberships captured at login (OIDC `groups` claim or LDAP
|
||||
// group membership), stored as a JSON string. Drives authorization for
|
||||
// the life of the session without re-querying the IdP on every request.
|
||||
groups: {default: '[]', isRequired: false, type: 'string'},
|
||||
}
|
||||
|
||||
static async create(data){
|
||||
data.created_by = data.username;
|
||||
if(Array.isArray(data.groups)){
|
||||
data.groups = JSON.stringify(data.groups);
|
||||
}
|
||||
return super.create(data)
|
||||
|
||||
}
|
||||
|
||||
// Parse the stored groups JSON back into an array, tolerating bad/missing
|
||||
// data so authorization never crashes on a malformed token.
|
||||
groupsArray(){
|
||||
try{
|
||||
let parsed = JSON.parse(this.groups);
|
||||
return Array.isArray(parsed) ? parsed : [];
|
||||
}catch(error){
|
||||
return [];
|
||||
}
|
||||
}
|
||||
}
|
||||
AuthToken.register();
|
||||
|
||||
module.exports = {Token, AuthToken};
|
||||
+12
-99
@@ -1,109 +1,22 @@
|
||||
'use strict';
|
||||
|
||||
// Thin LDAP helpers — the jump host's entire LDAP surface:
|
||||
// Thin LDAP helpers — the jump host's entire LDAP surface, now backed by the
|
||||
// shared @simpleworkjs/ldap package:
|
||||
// getUser(uid) -> { dn, uid, sshPublicKeys: [] } or null
|
||||
// getGroups(dn) -> [cn, ...] (groupOfNames membership)
|
||||
// checkPassword(dn, pw) -> bool (simple bind as the user)
|
||||
// addSshKey(dn, keyLine) -> void (idempotent multi-value add)
|
||||
//
|
||||
// Mirrors the patterns in sso-manager-node/nodejs/models/user_ldap.js and
|
||||
// group_ldap.js (ldapts, admin-bound search, bind-as-user password check,
|
||||
// TypeOrValueExists treated as success on key add).
|
||||
// Behavior is unchanged from the previous in-tree implementation: posixAccount
|
||||
// user filter, groupOfNames group filter, bind-as-user password check,
|
||||
// TypeOrValueExists treated as success on key add, and the same loose TLS
|
||||
// default ({ rejectUnauthorized: false } when conf.ldap omits tlsOptions).
|
||||
|
||||
const { Client, Change, Attribute } = require('ldapts');
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const { createLdapClient } = require('@simpleworkjs/ldap');
|
||||
|
||||
function ldapConf() {
|
||||
return conf.ldap || {};
|
||||
}
|
||||
|
||||
function makeClient() {
|
||||
const c = ldapConf();
|
||||
return new Client({
|
||||
url: c.url,
|
||||
tlsOptions: c.tlsOptions || { rejectUnauthorized: false },
|
||||
});
|
||||
}
|
||||
|
||||
// Escape a value being interpolated into an LDAP filter (RFC 4515).
|
||||
function escapeFilter(value) {
|
||||
return String(value).replace(/[\\*()\0]/g, (ch) => ({
|
||||
'\\': '\\5c', '*': '\\2a', '(': '\\28', ')': '\\29', '\0': '\\00',
|
||||
}[ch]));
|
||||
}
|
||||
|
||||
async function withClient(fn) {
|
||||
const c = ldapConf();
|
||||
const client = makeClient();
|
||||
try {
|
||||
await client.bind(c.bindDN, c.bindPassword);
|
||||
return await fn(client);
|
||||
} finally {
|
||||
await client.unbind().catch(() => {});
|
||||
}
|
||||
}
|
||||
|
||||
async function getUser(uid) {
|
||||
const c = ldapConf();
|
||||
const attr = c.userNameAttribute || 'uid';
|
||||
return withClient(async (client) => {
|
||||
const { searchEntries } = await client.search(c.userBase, {
|
||||
scope: 'sub',
|
||||
filter: `(&(objectClass=posixAccount)(${attr}=${escapeFilter(uid)}))`,
|
||||
attributes: ['dn', attr, 'cn', 'sshPublicKey'],
|
||||
});
|
||||
if (!searchEntries.length) return null;
|
||||
const e = searchEntries[0];
|
||||
let keys = e.sshPublicKey || [];
|
||||
if (!Array.isArray(keys)) keys = [keys];
|
||||
return {
|
||||
dn: e.dn,
|
||||
uid: String(e[attr]),
|
||||
sshPublicKeys: keys.map(String),
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
async function getGroups(dn) {
|
||||
const c = ldapConf();
|
||||
return withClient(async (client) => {
|
||||
const { searchEntries } = await client.search(c.groupBase, {
|
||||
scope: 'sub',
|
||||
filter: `(&(objectClass=groupOfNames)(member=${escapeFilter(dn)}))`,
|
||||
attributes: ['cn'],
|
||||
});
|
||||
return searchEntries.map((e) => String(e.cn));
|
||||
});
|
||||
}
|
||||
|
||||
async function checkPassword(dn, password) {
|
||||
if (!password) return false;
|
||||
const client = makeClient();
|
||||
try {
|
||||
await client.bind(dn, password);
|
||||
return true;
|
||||
} catch (_) {
|
||||
return false;
|
||||
} finally {
|
||||
await client.unbind().catch(() => {});
|
||||
}
|
||||
}
|
||||
|
||||
async function addSshKey(dn, keyLine) {
|
||||
return withClient(async (client) => {
|
||||
try {
|
||||
await client.modify(dn, [
|
||||
new Change({
|
||||
operation: 'add',
|
||||
modification: new Attribute({ type: 'sshPublicKey', values: [keyLine] }),
|
||||
}),
|
||||
]);
|
||||
} catch (error) {
|
||||
// Same de-dup semantics as the SSO's User.addSSHkey.
|
||||
if (error.name === 'TypeOrValueExistsError') return;
|
||||
throw error;
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
module.exports = { getUser, getGroups, checkPassword, addSshKey, escapeFilter, makeClient };
|
||||
const ldapConf = conf.ldap || {};
|
||||
module.exports = createLdapClient({
|
||||
...ldapConf,
|
||||
tlsOptions: ldapConf.tlsOptions || { rejectUnauthorized: false },
|
||||
});
|
||||
@@ -3,7 +3,6 @@
|
||||
const Table = require('.');
|
||||
const bcrypt = require('bcrypt');
|
||||
const crypto = require('crypto');
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const saltRounds = 10;
|
||||
|
||||
class User extends Table{
|
||||
@@ -86,38 +85,6 @@ class User extends Table{
|
||||
|
||||
User.register();
|
||||
|
||||
(async function(){
|
||||
// The anti-lockout local admin: the first entry in conf.auth.adminUsers
|
||||
// (default 'jumpadmin'). A local login that works even if the SSO/OIDC is
|
||||
// unreachable — the whole point of "OIDC + internal users".
|
||||
var defaultUser = (conf.auth && conf.auth.adminUsers && conf.auth.adminUsers[0]) || 'jumpadmin';
|
||||
// Optional: an orchestrator (e.g. theta-env's setup.sh) can set
|
||||
// auth.localAdminPass in jump-secrets.js to a generated password so this
|
||||
// bootstrap account isn't left at a well-known default. Only used on first
|
||||
// creation -- once the account exists this is never read again, so it's
|
||||
// safe to leave set. If unset, a random password is generated and printed
|
||||
// once; save it from the log or set auth.localAdminPass explicitly.
|
||||
var defaultPass = (conf.auth && conf.auth.localAdminPass);
|
||||
if (!defaultPass) {
|
||||
defaultPass = crypto.randomBytes(16).toString('hex');
|
||||
console.warn(`====================================================================`);
|
||||
console.warn(`Bootstrap admin "${defaultUser}" created with random password:`);
|
||||
console.warn(`${defaultPass}`);
|
||||
console.warn(`Set auth.localAdminPass in your secrets file to make this deterministic.`);
|
||||
console.warn(`====================================================================`);
|
||||
}
|
||||
try{
|
||||
let user = await User.get(defaultUser);
|
||||
}catch(error){
|
||||
try{
|
||||
let user = await User.create({
|
||||
username:defaultUser,
|
||||
password: defaultPass,
|
||||
created_by: defaultUser
|
||||
});
|
||||
console.log(defaultUser, 'created');
|
||||
}catch(error){
|
||||
console.error(error)
|
||||
}
|
||||
}
|
||||
})();
|
||||
// Anti-lockout local-admin bootstrap moved to @simpleworkjs/oidc-client
|
||||
// (bootstrapLocalAdmin); invoked once from models/index.js after User is
|
||||
// registered. See the package lib/bootstrap.js for the original logic.
|
||||
|
||||
Generated
+114
-154
@@ -1,16 +1,20 @@
|
||||
{
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.1.0",
|
||||
"version": "1.3.0",
|
||||
"lockfileVersion": 3,
|
||||
"requires": true,
|
||||
"packages": {
|
||||
"": {
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.1.0",
|
||||
"version": "1.3.0",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@fortawesome/fontawesome-free": "^7.3.0",
|
||||
"@simpleworkjs/app-stack": "^1.0.0",
|
||||
"@simpleworkjs/conf": "^1.2.0",
|
||||
"@simpleworkjs/directory-schema": "^1.0.0",
|
||||
"@simpleworkjs/ldap": "^1.0.0",
|
||||
"@simpleworkjs/oidc-client": "^1.0.0",
|
||||
"bcrypt": "^6.0.0",
|
||||
"bootstrap": "^5.3.8",
|
||||
"compression": "^1.8.1",
|
||||
@@ -18,12 +22,12 @@
|
||||
"express": "^5.2.1",
|
||||
"express-rate-limit": "^8.5.2",
|
||||
"jq-repeat": "^2.2.0",
|
||||
"jquery": "^3.7.1",
|
||||
"ldapts": "^8.1.2",
|
||||
"jquery": "^4.0.0",
|
||||
"ldapts": "^8.1.8",
|
||||
"model-redis": "^1.6.0",
|
||||
"moment": "^2.30.1",
|
||||
"mustache": "^4.2.0",
|
||||
"redis": "^4.7.0",
|
||||
"redis": "^6.1.0",
|
||||
"socket.io": "^4.8.3",
|
||||
"ssh2": "^1.16.0"
|
||||
},
|
||||
@@ -55,62 +59,87 @@
|
||||
}
|
||||
},
|
||||
"node_modules/@redis/bloom": {
|
||||
"version": "1.2.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/bloom/-/bloom-1.2.0.tgz",
|
||||
"integrity": "sha512-HG2DFjYKbpNmVXsa0keLHp/3leGJz1mjh09f2RLGGLQZzSHpkmZWuwJbAvo3QcRY8p80m5+ZdXZdYOSBLlp7Cg==",
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/bloom/-/bloom-6.1.0.tgz",
|
||||
"integrity": "sha512-Rzascjd9J9bJsM45T/Z9CTg1QY/B63B6YO8QorLVMeXnbBDsKiSCVR/+GQ061hYPk8FpTzWmPY8tAv2sT+JEtQ==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^1.0.0"
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@redis/client": {
|
||||
"version": "1.6.1",
|
||||
"resolved": "https://registry.npmjs.org/@redis/client/-/client-1.6.1.tgz",
|
||||
"integrity": "sha512-/KCsg3xSlR+nCK8/8ZYSknYxvXHwubJrU82F3Lm1Fp6789VQ0/3RJKfsmRXjqfaTA++23CvC3hqmqe/2GEt6Kw==",
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/client/-/client-6.1.0.tgz",
|
||||
"integrity": "sha512-7u1LefkezJF0HESlhO7ZFLEPfyY+NejP3SGv+Z4pGaT3oM5GVVLa0u3f4rDLUrcw+SRo8IlX9Y8JAONeDdg1Ag==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"cluster-key-slot": "1.1.2",
|
||||
"generic-pool": "3.9.0",
|
||||
"yallist": "4.0.0"
|
||||
"cluster-key-slot": "1.1.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=14"
|
||||
}
|
||||
},
|
||||
"node_modules/@redis/graph": {
|
||||
"version": "1.1.1",
|
||||
"resolved": "https://registry.npmjs.org/@redis/graph/-/graph-1.1.1.tgz",
|
||||
"integrity": "sha512-FEMTcTHZozZciLRl6GiiIB4zGm5z5F3F6a6FZCyrfxdKOhFlGkiAqlexWMBzCi4DcRoyiOsuLfW+cjlGWyExOw==",
|
||||
"license": "MIT",
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^1.0.0"
|
||||
"@node-rs/xxhash": "^1.1.0",
|
||||
"@opentelemetry/api": ">=1 <2"
|
||||
},
|
||||
"peerDependenciesMeta": {
|
||||
"@node-rs/xxhash": {
|
||||
"optional": true
|
||||
},
|
||||
"@opentelemetry/api": {
|
||||
"optional": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"node_modules/@redis/json": {
|
||||
"version": "1.0.7",
|
||||
"resolved": "https://registry.npmjs.org/@redis/json/-/json-1.0.7.tgz",
|
||||
"integrity": "sha512-6UyXfjVaTBTJtKNG4/9Z8PSpKE6XgSyEb8iwaqDcy+uKrd/DGYHTWkUdnQDyzm727V7p21WUMhsqz5oy65kPcQ==",
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/json/-/json-6.1.0.tgz",
|
||||
"integrity": "sha512-/GFjQA6bu5pG9ClCJAI5Xx4bNXe7UTpxBBlIupBNTrn1+nY860apGnYJuaSCDV2BmEbTidpa7O2qa28oxKx+rg==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^1.0.0"
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@redis/search": {
|
||||
"version": "1.2.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/search/-/search-1.2.0.tgz",
|
||||
"integrity": "sha512-tYoDBbtqOVigEDMAcTGsRlMycIIjwMCgD8eR2t0NANeQmgK/lvxNAvYyb6bZDD4frHRhIHkJu2TBRvB0ERkOmw==",
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/search/-/search-6.1.0.tgz",
|
||||
"integrity": "sha512-kS5agg+3yZbrdrt8omrew7FLCD8eOm7tarG1CROekPBRe+QGDR9aOpnHIQaYsYi6wPRTH70nQiF06AIjgURefQ==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^1.0.0"
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@redis/time-series": {
|
||||
"version": "1.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/time-series/-/time-series-1.1.0.tgz",
|
||||
"integrity": "sha512-c1Q99M5ljsIuc4YdaCwfUEXsofakb9c8+Zse2qxTadu8TalLXuAESzLvFAvNVbkmSlvlzIQOLpBCmWI9wTOt+g==",
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/time-series/-/time-series-6.1.0.tgz",
|
||||
"integrity": "sha512-uIDBtV8MmG/xpJsRqbGSO4iX6ryj37MLMP82lRpFvI7ykAVe5GyqgxigEbU+uZNv9kDPNMKw3dvI/S/J1BNBzA==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^1.0.0"
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/app-stack": {
|
||||
"version": "1.0.0",
|
||||
"resolved": "https://registry.npmjs.org/@simpleworkjs/app-stack/-/app-stack-1.0.0.tgz",
|
||||
"integrity": "sha512-Hg/mouA87WruKeZqhqtJgAaLabjHY8Z9POO6U+DB7sGGDhy1jgZXT31hyxLUDV+InByOPhz48NIkGiWNwoesXQ==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"express": "^5.2.1"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/conf": {
|
||||
@@ -125,6 +154,41 @@
|
||||
"node": ">=16.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/directory-schema": {
|
||||
"version": "1.0.0",
|
||||
"resolved": "https://registry.npmjs.org/@simpleworkjs/directory-schema/-/directory-schema-1.0.0.tgz",
|
||||
"integrity": "sha512-thZhPGNdDYlD8rlhXidnbCHTKjdSkj9ag1zE/gz1AwuclYypsKAP+v3BAvcZ/YDQP8RBDJNPXof5EpVheLovTg==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">=18.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/ldap": {
|
||||
"version": "1.0.0",
|
||||
"resolved": "https://registry.npmjs.org/@simpleworkjs/ldap/-/ldap-1.0.0.tgz",
|
||||
"integrity": "sha512-saDmwk+KJ6kIWj9/MF37d+BM9KQisy6DsI9umyt1FWNyx6+wnEEat/1RUTwXKBd4IKJK+zPT5lC/B6gfa2CuAA==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"ldapts": "^8.1.8"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@simpleworkjs/oidc-client": {
|
||||
"version": "1.0.0",
|
||||
"resolved": "https://registry.npmjs.org/@simpleworkjs/oidc-client/-/oidc-client-1.0.0.tgz",
|
||||
"integrity": "sha512-AzxIaE32p4yKDlp0mWvZp1wmXi8tMFckcPwMiQyZrDgEC0IybGhbjppPa+vNGx1AoVLp64vRL/zR3yXb/19NPg==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@simpleworkjs/conf": "^1.2.0",
|
||||
"express": "^5.2.1",
|
||||
"express-rate-limit": "^8.5.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">=18.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/@socket.io/component-emitter": {
|
||||
"version": "3.1.2",
|
||||
"resolved": "https://registry.npmjs.org/@socket.io/component-emitter/-/component-emitter-3.1.2.tgz",
|
||||
@@ -876,15 +940,6 @@
|
||||
"url": "https://github.com/sponsors/ljharb"
|
||||
}
|
||||
},
|
||||
"node_modules/generic-pool": {
|
||||
"version": "3.9.0",
|
||||
"resolved": "https://registry.npmjs.org/generic-pool/-/generic-pool-3.9.0.tgz",
|
||||
"integrity": "sha512-hymDOu5B53XvN4QT9dBmZxPX4CWhBPPLguTZ9MMFeFa/Kg0xWVfylOVNlJji/E7yTZWFd/q9GO5TxDLq156D7g==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 4"
|
||||
}
|
||||
},
|
||||
"node_modules/get-intrinsic": {
|
||||
"version": "1.3.0",
|
||||
"resolved": "https://registry.npmjs.org/get-intrinsic/-/get-intrinsic-1.3.0.tgz",
|
||||
@@ -1131,9 +1186,9 @@
|
||||
}
|
||||
},
|
||||
"node_modules/jquery": {
|
||||
"version": "3.7.1",
|
||||
"resolved": "https://registry.npmjs.org/jquery/-/jquery-3.7.1.tgz",
|
||||
"integrity": "sha512-m4avr8yL8kmFN8psrbFFFmB/If14iN5o9nw/NgnnM+kybDJpRsAynV2BsfpTYrTRysYUdADVD7CkUUizgkpLfg==",
|
||||
"version": "4.0.0",
|
||||
"resolved": "https://registry.npmjs.org/jquery/-/jquery-4.0.0.tgz",
|
||||
"integrity": "sha512-TXCHVR3Lb6TZdtw1l3RTLf8RBWVGexdxL6AC8/e0xZKEpBflBsjh9/8LXw+dkNFuOyW9B7iB3O1sP7hS0Kiacg==",
|
||||
"license": "MIT"
|
||||
},
|
||||
"node_modules/ldapts": {
|
||||
@@ -1224,94 +1279,6 @@
|
||||
"redis": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/model-redis/node_modules/@redis/bloom": {
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/bloom/-/bloom-6.1.0.tgz",
|
||||
"integrity": "sha512-Rzascjd9J9bJsM45T/Z9CTg1QY/B63B6YO8QorLVMeXnbBDsKiSCVR/+GQ061hYPk8FpTzWmPY8tAv2sT+JEtQ==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/model-redis/node_modules/@redis/client": {
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/client/-/client-6.1.0.tgz",
|
||||
"integrity": "sha512-7u1LefkezJF0HESlhO7ZFLEPfyY+NejP3SGv+Z4pGaT3oM5GVVLa0u3f4rDLUrcw+SRo8IlX9Y8JAONeDdg1Ag==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"cluster-key-slot": "1.1.2"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@node-rs/xxhash": "^1.1.0",
|
||||
"@opentelemetry/api": ">=1 <2"
|
||||
},
|
||||
"peerDependenciesMeta": {
|
||||
"@node-rs/xxhash": {
|
||||
"optional": true
|
||||
},
|
||||
"@opentelemetry/api": {
|
||||
"optional": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"node_modules/model-redis/node_modules/@redis/json": {
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/json/-/json-6.1.0.tgz",
|
||||
"integrity": "sha512-/GFjQA6bu5pG9ClCJAI5Xx4bNXe7UTpxBBlIupBNTrn1+nY860apGnYJuaSCDV2BmEbTidpa7O2qa28oxKx+rg==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/model-redis/node_modules/@redis/search": {
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/search/-/search-6.1.0.tgz",
|
||||
"integrity": "sha512-kS5agg+3yZbrdrt8omrew7FLCD8eOm7tarG1CROekPBRe+QGDR9aOpnHIQaYsYi6wPRTH70nQiF06AIjgURefQ==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/model-redis/node_modules/@redis/time-series": {
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/@redis/time-series/-/time-series-6.1.0.tgz",
|
||||
"integrity": "sha512-uIDBtV8MmG/xpJsRqbGSO4iX6ryj37MLMP82lRpFvI7ykAVe5GyqgxigEbU+uZNv9kDPNMKw3dvI/S/J1BNBzA==",
|
||||
"license": "MIT",
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
},
|
||||
"peerDependencies": {
|
||||
"@redis/client": "^6.1.0"
|
||||
}
|
||||
},
|
||||
"node_modules/model-redis/node_modules/redis": {
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/redis/-/redis-6.1.0.tgz",
|
||||
"integrity": "sha512-0kvUPM8RHP/ZMa0xYaDTcG5e8tIGW6kz6MToVT0V8iOnk6bkXp2jncGRGe2bZEk41lZwiDspUqjZCSk5ohjcKw==",
|
||||
"license": "MIT",
|
||||
"dependencies": {
|
||||
"@redis/bloom": "6.1.0",
|
||||
"@redis/client": "6.1.0",
|
||||
"@redis/json": "6.1.0",
|
||||
"@redis/search": "6.1.0",
|
||||
"@redis/time-series": "6.1.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/moment": {
|
||||
"version": "2.30.1",
|
||||
"resolved": "https://registry.npmjs.org/moment/-/moment-2.30.1.tgz",
|
||||
@@ -1617,20 +1584,19 @@
|
||||
}
|
||||
},
|
||||
"node_modules/redis": {
|
||||
"version": "4.7.1",
|
||||
"resolved": "https://registry.npmjs.org/redis/-/redis-4.7.1.tgz",
|
||||
"integrity": "sha512-S1bJDnqLftzHXHP8JsT5II/CtHWQrASX5K96REjWjlmWKrviSOLWmM7QnRLstAWsu1VBBV1ffV6DzCvxNP0UJQ==",
|
||||
"version": "6.1.0",
|
||||
"resolved": "https://registry.npmjs.org/redis/-/redis-6.1.0.tgz",
|
||||
"integrity": "sha512-0kvUPM8RHP/ZMa0xYaDTcG5e8tIGW6kz6MToVT0V8iOnk6bkXp2jncGRGe2bZEk41lZwiDspUqjZCSk5ohjcKw==",
|
||||
"license": "MIT",
|
||||
"workspaces": [
|
||||
"./packages/*"
|
||||
],
|
||||
"dependencies": {
|
||||
"@redis/bloom": "1.2.0",
|
||||
"@redis/client": "1.6.1",
|
||||
"@redis/graph": "1.1.1",
|
||||
"@redis/json": "1.0.7",
|
||||
"@redis/search": "1.2.0",
|
||||
"@redis/time-series": "1.1.0"
|
||||
"@redis/bloom": "6.1.0",
|
||||
"@redis/client": "6.1.0",
|
||||
"@redis/json": "6.1.0",
|
||||
"@redis/search": "6.1.0",
|
||||
"@redis/time-series": "6.1.0"
|
||||
},
|
||||
"engines": {
|
||||
"node": ">= 20.0.0"
|
||||
}
|
||||
},
|
||||
"node_modules/router": {
|
||||
@@ -2079,12 +2045,6 @@
|
||||
"optional": true
|
||||
}
|
||||
}
|
||||
},
|
||||
"node_modules/yallist": {
|
||||
"version": "4.0.0",
|
||||
"resolved": "https://registry.npmjs.org/yallist/-/yallist-4.0.0.tgz",
|
||||
"integrity": "sha512-3wdGidZyq5PB084XLES5TpOSRA3wjXAlIWMhum2kRcv/41Sn2emQ0dycQW4uZXLejwKvg6EsvbdlVL+FYEct7A==",
|
||||
"license": "ISC"
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
+8
-4
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.1.0",
|
||||
"version": "1.3.0",
|
||||
"description": "SSH jump host for the theta42 stack — LDAP-authenticated, directory-driven host bridging with audit and metrics",
|
||||
"author": [
|
||||
{
|
||||
@@ -21,6 +21,10 @@
|
||||
"dependencies": {
|
||||
"@fortawesome/fontawesome-free": "^7.3.0",
|
||||
"@simpleworkjs/conf": "^1.2.0",
|
||||
"@simpleworkjs/app-stack": "^1.0.0",
|
||||
"@simpleworkjs/ldap": "^1.0.0",
|
||||
"@simpleworkjs/directory-schema": "^1.0.0",
|
||||
"@simpleworkjs/oidc-client": "^1.0.0",
|
||||
"bcrypt": "^6.0.0",
|
||||
"bootstrap": "^5.3.8",
|
||||
"compression": "^1.8.1",
|
||||
@@ -28,12 +32,12 @@
|
||||
"express": "^5.2.1",
|
||||
"express-rate-limit": "^8.5.2",
|
||||
"jq-repeat": "^2.2.0",
|
||||
"jquery": "^3.7.1",
|
||||
"ldapts": "^8.1.2",
|
||||
"jquery": "^4.0.0",
|
||||
"ldapts": "^8.1.8",
|
||||
"model-redis": "^1.6.0",
|
||||
"moment": "^2.30.1",
|
||||
"mustache": "^4.2.0",
|
||||
"redis": "^4.7.0",
|
||||
"redis": "^6.1.0",
|
||||
"socket.io": "^4.8.3",
|
||||
"ssh2": "^1.16.0"
|
||||
},
|
||||
|
||||
@@ -18,3 +18,7 @@ body {
|
||||
.card-title{
|
||||
font-weight: bold;
|
||||
}
|
||||
|
||||
.group-required{
|
||||
display: none;
|
||||
}
|
||||
|
||||
@@ -1,3 +1,12 @@
|
||||
// Shared client framework for the theta42 apps.
|
||||
//
|
||||
// This file is byte-identical across sso-manager-node, proxy and jump-host —
|
||||
// per-app behaviour comes from the server (the `ui` locals in views/top.ejs and
|
||||
// the /api/user/me response), never from edits to this file. Edit all three
|
||||
// copies together.
|
||||
//
|
||||
// jQuery 4 safe: no $.isFunction, no $.holdReady.
|
||||
|
||||
var app = {};
|
||||
|
||||
app.pubsub = (function(){
|
||||
@@ -45,7 +54,7 @@ app.pubsub = (function(){
|
||||
app.socket = (function(app){
|
||||
// $.getScript('/socket.io/socket.io.js')
|
||||
// <script type="text/javascript" src="/socket.io/socket.io.js"></script>
|
||||
|
||||
|
||||
var socket;
|
||||
$(document).ready(function(){
|
||||
socket = io({
|
||||
@@ -75,10 +84,26 @@ app.socket = (function(app){
|
||||
app.api = (function(app){
|
||||
var baseURL = '/api/'
|
||||
|
||||
function post(url, data, callback){
|
||||
if(typeof callback !== 'function') callback = callback2;
|
||||
// post/put/delete are dual-mode: pass a callback for the node-style
|
||||
// (error, data, status) form, or omit it to get a Promise that resolves
|
||||
// with the parsed body and rejects with the error body. get/options return
|
||||
// the jqXHR, which is itself thenable, so `await app.api.get(...)` works.
|
||||
|
||||
function body(method, url, data, callback){
|
||||
if(typeof callback !== 'function'){
|
||||
return new Promise(function(resolve, reject){
|
||||
$.ajax({
|
||||
type: method,
|
||||
url: baseURL+url,
|
||||
headers: { 'auth-token': app.auth.getToken() },
|
||||
data: JSON.stringify(data),
|
||||
contentType: 'application/json; charset=utf-8',
|
||||
dataType: 'json',
|
||||
}).done(resolve).fail(function(xhr){ reject(xhr.responseJSON || {}); });
|
||||
});
|
||||
}
|
||||
return $.ajax({
|
||||
type: 'POST',
|
||||
type: method,
|
||||
url: baseURL+url,
|
||||
headers:{
|
||||
'auth-token': app.auth.getToken()
|
||||
@@ -87,40 +112,44 @@ app.api = (function(app){
|
||||
contentType: "application/json; charset=utf-8",
|
||||
dataType: "json",
|
||||
complete: function(res, text){
|
||||
callback ? callback(
|
||||
callback(
|
||||
text !== 'success' ? res.statusText : null,
|
||||
JSON.parse(res.responseText),
|
||||
res.status
|
||||
) : function(){}
|
||||
);
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
function post(url, data, callback){
|
||||
return body('POST', url, data, callback);
|
||||
}
|
||||
|
||||
function put(url, data, callback){
|
||||
if(typeof callback !== 'function') callback = callback2;
|
||||
return $.ajax({
|
||||
type: 'PUT',
|
||||
url: baseURL+url,
|
||||
headers:{
|
||||
'auth-token': app.auth.getToken()
|
||||
},
|
||||
data: JSON.stringify(data),
|
||||
contentType: "application/json; charset=utf-8",
|
||||
dataType: "json",
|
||||
complete: function(res, text){
|
||||
callback ? callback(
|
||||
text !== 'success' ? res.statusText : null,
|
||||
JSON.parse(res.responseText),
|
||||
res.status
|
||||
) : function(){}
|
||||
}
|
||||
});
|
||||
return body('PUT', url, data, callback);
|
||||
}
|
||||
|
||||
function remove(url, callback, callback2){
|
||||
if(typeof callback !== 'function') callback = callback2;
|
||||
// Called both as (url, callback) and — from formAJAX, which always passes
|
||||
// the serialized form as the second argument — as (url, data, callback).
|
||||
// No request body is sent either way.
|
||||
function remove(url, data, callback){
|
||||
if(typeof data === 'function'){
|
||||
callback = data;
|
||||
data = undefined;
|
||||
}
|
||||
if(typeof callback !== 'function'){
|
||||
return new Promise(function(resolve, reject){
|
||||
$.ajax({
|
||||
type: 'DELETE',
|
||||
url: baseURL+url,
|
||||
headers: { 'auth-token': app.auth.getToken() },
|
||||
contentType: 'application/json; charset=utf-8',
|
||||
dataType: 'json',
|
||||
}).done(resolve).fail(function(xhr){ reject(xhr.responseJSON || {}); });
|
||||
});
|
||||
}
|
||||
return $.ajax({
|
||||
type: 'delete',
|
||||
type: 'DELETE',
|
||||
url: baseURL+url,
|
||||
headers:{
|
||||
'auth-token': app.auth.getToken()
|
||||
@@ -128,11 +157,11 @@ app.api = (function(app){
|
||||
contentType: "application/json; charset=utf-8",
|
||||
dataType: "json",
|
||||
complete: function(res, text){
|
||||
callback ? callback(
|
||||
callback(
|
||||
text !== 'success' ? res.statusText : null,
|
||||
JSON.parse(res.responseText),
|
||||
res.status
|
||||
) : function(){}
|
||||
);
|
||||
}
|
||||
});
|
||||
}
|
||||
@@ -179,7 +208,11 @@ app.api = (function(app){
|
||||
})(app)
|
||||
|
||||
app.auth = (function(app){
|
||||
var user = {}
|
||||
// One in-flight/cached GET /api/user/me per page load. Every gating
|
||||
// decision (nav items, per-view forceLogin, group-required elements) reads
|
||||
// this same promise instead of re-fetching.
|
||||
var userPromise = null;
|
||||
|
||||
function setToken(token){
|
||||
localStorage.setItem('APIToken', token);
|
||||
}
|
||||
@@ -188,18 +221,95 @@ app.auth = (function(app){
|
||||
return localStorage.getItem('APIToken');
|
||||
}
|
||||
|
||||
function isLoggedIn(callback){
|
||||
if(getToken()){
|
||||
return app.api.get('user/me', function(error, data){
|
||||
// data now carries effective rights (isAdmin, global, domains).
|
||||
if(!error) app.auth.user = app.auth.perms = data;
|
||||
return callback(error, data);
|
||||
});
|
||||
}else{
|
||||
callback(null, false);
|
||||
async function getUser(){
|
||||
try{
|
||||
return await app.api.get('user/me');
|
||||
}catch(error){
|
||||
if(error && error.status === 401) return null;
|
||||
throw error;
|
||||
}
|
||||
}
|
||||
|
||||
// Cached current user, or false when there's no token at all. Callers that
|
||||
// need a fresh copy (after a login or a profile change) pass force.
|
||||
function loadUser(force){
|
||||
if(force || !userPromise){
|
||||
userPromise = getToken() ? getUser() : Promise.resolve(null);
|
||||
userPromise = userPromise.then(function(user){
|
||||
app.auth.user = app.auth.perms = user || null;
|
||||
return user;
|
||||
});
|
||||
}
|
||||
return userPromise;
|
||||
}
|
||||
|
||||
// The apps report group membership two ways: sso-manager-node returns LDAP
|
||||
// DNs in `memberOf`, the OIDC clients return plain CNs in `groups`. Both
|
||||
// normalise to a list of CNs. `isAdmin` (the clients' effective-rights flag)
|
||||
// is exposed as a synthetic `admin` group so one gating model covers both.
|
||||
function groupCNs(user){
|
||||
var raw = (user && (user.memberOf || user.groups)) || [];
|
||||
if(!Array.isArray(raw)) raw = [raw];
|
||||
var names = raw.map(function(group){
|
||||
return String(group).split(',')[0].replace(/^cn=/i, '');
|
||||
});
|
||||
if(user && user.isAdmin && names.indexOf('admin') === -1) names.push('admin');
|
||||
return names;
|
||||
}
|
||||
|
||||
async function memberOf(groupNameToFind, user){
|
||||
user = user || await loadUser();
|
||||
if(!user) return false;
|
||||
groupNameToFind = Array.isArray(groupNameToFind) ? groupNameToFind : [groupNameToFind];
|
||||
|
||||
return groupCNs(user).some(function(group){
|
||||
return groupNameToFind.includes(group);
|
||||
});
|
||||
}
|
||||
|
||||
// True when the logged-in user is a global admin (per user/me). Sync — only
|
||||
// meaningful once isLoggedIn/forceLogin has resolved.
|
||||
function isAdmin(){
|
||||
return !!(app.auth.perms && app.auth.perms.isAdmin);
|
||||
}
|
||||
|
||||
// Dual-mode: returns a Promise resolving to the user (or false), and calls
|
||||
// an optional node-style callback with the same result.
|
||||
function isLoggedIn(callback){
|
||||
var promise = loadUser().then(function(user){
|
||||
return user || false;
|
||||
});
|
||||
|
||||
if(typeof callback === 'function'){
|
||||
promise.then(function(user){
|
||||
callback(null, user);
|
||||
}, function(error){
|
||||
callback(error, false);
|
||||
});
|
||||
}
|
||||
|
||||
return promise;
|
||||
}
|
||||
|
||||
function logIn(args, callback){
|
||||
app.api.post('auth/login', args, function(error, data){
|
||||
if(data.login){
|
||||
setToken(data.token);
|
||||
}
|
||||
loadUser(true);
|
||||
callback(error, !!data.token);
|
||||
});
|
||||
}
|
||||
|
||||
// Clears the session only — the caller decides where to go next (the nav's
|
||||
// Log Out button uses ui.logoutRedirect).
|
||||
function logOut(callback){
|
||||
localStorage.removeItem('APIToken');
|
||||
userPromise = null;
|
||||
app.auth.user = app.auth.perms = null;
|
||||
if(typeof callback === 'function') callback();
|
||||
}
|
||||
|
||||
// Constrain a redirect target to a same-origin absolute path. Rejects
|
||||
// absolute URLs (open redirect), protocol-relative "//host" and "/\host",
|
||||
// and non-path schemes like "javascript:" (XSS). Falls back to "/".
|
||||
@@ -230,46 +340,68 @@ app.auth = (function(app){
|
||||
return true;
|
||||
}
|
||||
|
||||
// True when the logged-in user is a global admin (per user/me).
|
||||
function isAdmin(){
|
||||
return !!(app.auth.perms && app.auth.perms.isAdmin);
|
||||
}
|
||||
|
||||
function logIn(args, callback){
|
||||
app.api.post('auth/login', args, function(error, data){
|
||||
if(data.login){
|
||||
setToken(data.token);
|
||||
}
|
||||
callback(error, !!data.token);
|
||||
});
|
||||
}
|
||||
|
||||
function logOut(callback){
|
||||
localStorage.removeItem('APIToken');
|
||||
callback();
|
||||
}
|
||||
|
||||
function forceLogin(){
|
||||
// jQuery 4 removed $.holdReady; rely on the redirect below to keep an
|
||||
// unauthenticated user off the page instead of pausing document ready.
|
||||
app.auth.isLoggedIn(function(error, isLoggedIn){
|
||||
if(error || !isLoggedIn){
|
||||
app.auth.logOut(function(){})
|
||||
location.replace(`/login${location.href.replace(location.origin, '')}`);
|
||||
}
|
||||
});
|
||||
// Page-level gate. jQuery 4 removed $.holdReady, so an unauthenticated or
|
||||
// unauthorised user is kept off the page by a redirect / an error panel
|
||||
// rather than by pausing document ready.
|
||||
//
|
||||
// `requiredGroups` is a group CN or an OR-list of them; the synthetic
|
||||
// `admin` group covers the OIDC clients' isAdmin flag.
|
||||
async function forceLogin(requiredGroups){
|
||||
var user = await loadUser();
|
||||
|
||||
if(!user){
|
||||
logOut(function(){});
|
||||
location.replace('/login?redirect=' + encodeURIComponent(
|
||||
location.pathname + location.search
|
||||
));
|
||||
return false;
|
||||
}
|
||||
|
||||
if(user.onboardingRequired && location.pathname !== '/onboarding'){
|
||||
location.replace('/onboarding');
|
||||
return false;
|
||||
}
|
||||
|
||||
if(requiredGroups && !await memberOf(requiredGroups, user)){
|
||||
app.util.actionMessage(
|
||||
`<h1>
|
||||
<i class="fa-solid fa-triangle-exclamation"></i>
|
||||
<b>You do not have permission to be here.</b>
|
||||
<i class="fa-solid fa-triangle-exclamation"></i>
|
||||
</h1>`,
|
||||
$('#spa-shell'),
|
||||
'danger',
|
||||
);
|
||||
throw new Error("User does not have permission");
|
||||
}
|
||||
|
||||
return user;
|
||||
}
|
||||
|
||||
// Where to go after a successful login: the ?redirect= query param, or the
|
||||
// legacy /login/<path> suffix form, constrained to a same-origin path. The
|
||||
// suffix form keeps its query string — /login/oauth/authorize?client_id=…
|
||||
// is how the OIDC provider sends an unauthenticated user through login.
|
||||
function logInRedirect(){
|
||||
window.location.href = safeInternalPath(location.href.replace(location.origin+'/login', '') || '/')
|
||||
var params = new URLSearchParams(location.search);
|
||||
var target = params.get('redirect')
|
||||
|| location.href.replace(location.origin + '/login', '')
|
||||
|| '/';
|
||||
window.location.href = safeInternalPath(target);
|
||||
}
|
||||
|
||||
return {
|
||||
getToken: getToken,
|
||||
setToken: setToken,
|
||||
isLoggedIn: isLoggedIn,
|
||||
consumeTokenFragment: consumeTokenFragment,
|
||||
getUser: getUser,
|
||||
loadUser: loadUser,
|
||||
groupCNs: groupCNs,
|
||||
memberOf: memberOf,
|
||||
isAdmin: isAdmin,
|
||||
isLoggedIn: isLoggedIn,
|
||||
safeInternalPath: safeInternalPath,
|
||||
consumeTokenFragment: consumeTokenFragment,
|
||||
user: null,
|
||||
perms: null,
|
||||
logIn: logIn,
|
||||
logOut: logOut,
|
||||
@@ -279,6 +411,11 @@ app.auth = (function(app){
|
||||
|
||||
})(app);
|
||||
|
||||
// Back-compat alias for views that awaited the cached user directly.
|
||||
Object.defineProperty(app.auth, 'asyncUser', {
|
||||
get: function(){ return app.auth.loadUser(); },
|
||||
});
|
||||
|
||||
app.user = (function(app){
|
||||
function list(callback){
|
||||
app.api.get('user/?detail=true', function(error, data){
|
||||
@@ -308,6 +445,8 @@ app.user = (function(app){
|
||||
|
||||
})(app);
|
||||
|
||||
// Local (app-managed) permissions and groups. Only the OIDC-client apps serve
|
||||
// these endpoints; the calls are inert elsewhere.
|
||||
app.permission = (function(app){
|
||||
function list(callback){
|
||||
app.api.get('permission/', function(error, data){
|
||||
@@ -381,9 +520,12 @@ app.util = (function(app){
|
||||
return results === null ? '' : decodeURIComponent(results[1].replace(/\+/g, ' '));
|
||||
};
|
||||
|
||||
function actionMessage(message, $target, type, callback){
|
||||
function actionMessage(message, $targetPassed, type, callback){
|
||||
message = message || '';
|
||||
$target = $target.closest('div.card').find('.actionMessage');
|
||||
|
||||
let $target = $targetPassed.closest('div.card').find('.actionMessage');
|
||||
if(!$target.length) $target = $($targetPassed.find('.actionMessage')[0]);
|
||||
|
||||
type = type || 'info';
|
||||
callback = callback || function(){};
|
||||
|
||||
@@ -400,12 +542,48 @@ app.util = (function(app){
|
||||
})
|
||||
}else{
|
||||
if(type) $target.addClass('bg-' + type);
|
||||
message = '<span class="align-middle">' + message + '</span><button class="action-close btn btn-sm btn-outline-dark float-end"><i class="fa-solid fa-xmark"></i></button>'
|
||||
|
||||
// Messages that bring their own buttons (actionConfirm) are left
|
||||
// alone; everything else gets the standard dismiss button.
|
||||
if(!message.includes('<button')) message = `
|
||||
<span class="align-middle">${message}</span>
|
||||
<button class="action-close btn btn-sm btn-outline-dark float-end">
|
||||
<i class="fa-solid fa-xmark"></i>
|
||||
</button>
|
||||
`
|
||||
$target.html(message).slideDown('fast');
|
||||
}
|
||||
setTimeout(callback,10)
|
||||
}
|
||||
|
||||
function actionConfirm(message, $target, type, callback){
|
||||
return new Promise((resolve, reject) =>{
|
||||
let id = crypto.randomUUID();
|
||||
message = `
|
||||
<h4 class"align-middle" >
|
||||
<i class="fa-solid fa-triangle-exclamation"></i>
|
||||
<b>${message}</b>
|
||||
<span class="float-end">
|
||||
<button type="button" class="btn btn-success confirm-${id}" data-confirm="true">
|
||||
<i class="fa-solid fa-circle-check"></i>
|
||||
Confirm
|
||||
</button>
|
||||
<button type="button" class="btn btn-danger confirm-${id}">
|
||||
<i class="fa-solid fa-circle-stop"></i>
|
||||
Cancel
|
||||
</button>
|
||||
</span>
|
||||
</h4>
|
||||
`
|
||||
actionMessage(message, $target, type);
|
||||
$("body").on('click', `.confirm-${id}`, function(){
|
||||
actionMessage('', $target, type);
|
||||
resolve(!!$(this).data('confirm'));
|
||||
});
|
||||
});
|
||||
|
||||
}
|
||||
|
||||
$.fn.serializeObject = function() {
|
||||
var obj = {};
|
||||
|
||||
@@ -462,11 +640,42 @@ app.util = (function(app){
|
||||
return {
|
||||
downloadFile: downloadFile,
|
||||
getUrlParameter: getUrlParameter,
|
||||
actionMessage: actionMessage
|
||||
actionMessage: actionMessage,
|
||||
actionConfirm,
|
||||
}
|
||||
})(app);
|
||||
|
||||
$( document ).ready(function(){
|
||||
// Reveal every .group-required-<cn> element the current user's groups entitle
|
||||
// them to. Elements carrying .group-required start hidden (styles.css), so a
|
||||
// user who is in no groups — or who isn't logged in — simply never sees them.
|
||||
app.auth.applyGroupVisibility = function(user){
|
||||
var groups = app.auth.groupCNs(user);
|
||||
if(!groups.length) return;
|
||||
|
||||
var style = document.getElementById('group-required-rules');
|
||||
if(!style){
|
||||
style = document.createElement('style');
|
||||
style.id = 'group-required-rules';
|
||||
document.head.appendChild(style);
|
||||
}
|
||||
|
||||
for(var group of groups){
|
||||
try{
|
||||
style.sheet.insertRule(
|
||||
`.group-required-${CSS.escape(group)} { display: revert !important; }`,
|
||||
style.sheet.cssRules.length
|
||||
);
|
||||
}catch(error){
|
||||
// A group whose CN isn't a usable CSS identifier just gates nothing.
|
||||
}
|
||||
}
|
||||
};
|
||||
|
||||
$( document ).ready(async function(){
|
||||
|
||||
// Show content the user's groups entitle them to.
|
||||
app.auth.applyGroupVisibility(await app.auth.loadUser());
|
||||
|
||||
$('div.row').fadeIn('slow'); //show the page
|
||||
|
||||
//panel button's
|
||||
@@ -520,12 +729,14 @@ function formAJAX(btn){
|
||||
var method = ($form.attr('method') || 'post').toLowerCase();
|
||||
|
||||
if($form.validate && !$form.validate()){
|
||||
app.util.actionMessage('Please fix the form errors.', $form, 'danger');
|
||||
app.util.actionMessage('Please fix the form errors.', $form, 'danger')
|
||||
return false;
|
||||
}
|
||||
|
||||
app.util.actionMessage(
|
||||
'<div class="spinner-border" role="status"><span class="sr-only">Loading...</span></div>',
|
||||
|
||||
app.util.actionMessage(
|
||||
`<div class="spinner-border" role="status">
|
||||
<span class="visually-hidden">Loading...</span>
|
||||
</div>`,
|
||||
$form,
|
||||
'info'
|
||||
);
|
||||
|
||||
@@ -4,7 +4,7 @@ const router = require('express').Router();
|
||||
const middleware = require('../middleware/auth');
|
||||
|
||||
// Authentication (local login + OIDC handshake). Unauthenticated by design.
|
||||
router.use('/auth', require('./auth'));
|
||||
router.use('/auth', require('../models').authRouter);
|
||||
|
||||
// Who am I — needs a valid session but no admin gate (drives the login state).
|
||||
router.use('/user', middleware.auth, require('./user'));
|
||||
|
||||
@@ -1,111 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
const router = require('express').Router();
|
||||
const { rateLimit } = require('express-rate-limit');
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const { Auth } = require('../models/auth');
|
||||
const { OidcState } = require('../models/oidc_state');
|
||||
const oidc = require('../utils/oidc');
|
||||
const { safeInternalPath } = require('../utils/safe_redirect');
|
||||
|
||||
// Throttle unauthenticated auth endpoints (credential login + the OIDC
|
||||
// handshake) to blunt brute-force / callback abuse. Keyed per IP.
|
||||
const authLimiter = rateLimit({
|
||||
windowMs: 15 * 60 * 1000, // 15 minutes
|
||||
max: 60, // 60 attempts per IP per window
|
||||
standardHeaders: true,
|
||||
legacyHeaders: false,
|
||||
message: {name: 'TooManyRequests', message: 'Too many attempts, please try again later.'},
|
||||
});
|
||||
|
||||
|
||||
router.post('/login', authLimiter, async function(req, res, next){
|
||||
try{
|
||||
let auth = await Auth.login(req.body);
|
||||
return res.json({
|
||||
login: true,
|
||||
token: auth.token.token,
|
||||
message:`${req.body.username} logged in!`,
|
||||
});
|
||||
}catch(error){
|
||||
next(error);
|
||||
}
|
||||
});
|
||||
|
||||
router.all('/logout', async function(req, res, next){
|
||||
try{
|
||||
if(req.user){
|
||||
await req.user.logout();
|
||||
}
|
||||
|
||||
res.json({message: 'Bye'})
|
||||
}catch(error){
|
||||
next(error);
|
||||
}
|
||||
});
|
||||
|
||||
/**
|
||||
* OIDC login start: create a PKCE + state challenge, persist it (auto-expiring
|
||||
* via OidcState TTL), and redirect the browser to the SSO authorize endpoint.
|
||||
*/
|
||||
router.get('/oidc/start', authLimiter, async function(req, res, next){
|
||||
try{
|
||||
if(!conf.oidc || !conf.oidc.enabled){
|
||||
let error = new Error('OidcDisabled');
|
||||
error.status = 404;
|
||||
error.message = 'OIDC login is not enabled.';
|
||||
throw error;
|
||||
}
|
||||
|
||||
let {state, codeVerifier, codeChallenge} = oidc.createAuthRequest();
|
||||
await OidcState.create({
|
||||
state,
|
||||
codeVerifier,
|
||||
// Sanitize now so a hostile ?redirect= can't be stored and later
|
||||
// reflected into the login page's navigation.
|
||||
redirect: safeInternalPath(req.query.redirect || '/'),
|
||||
});
|
||||
|
||||
return res.redirect(oidc.buildAuthUrl(state, codeChallenge));
|
||||
}catch(error){
|
||||
next(error);
|
||||
}
|
||||
});
|
||||
|
||||
/**
|
||||
* OIDC callback: validate state (consuming the one-time record), exchange the
|
||||
* code for tokens, read identity from userinfo, establish a session, and hand
|
||||
* the app token back to the browser via a URL fragment for the login page to
|
||||
* store in localStorage.
|
||||
*/
|
||||
router.get('/oidc/callback', authLimiter, async function(req, res, next){
|
||||
try{
|
||||
let {code, state} = req.query;
|
||||
if(!code || !state){
|
||||
let error = new Error('OidcCallbackInvalid');
|
||||
error.status = 400;
|
||||
error.message = 'Missing code or state.';
|
||||
throw error;
|
||||
}
|
||||
|
||||
// get() throws if the state is unknown or has expired — this both binds
|
||||
// the callback to our request and bounds replay.
|
||||
let saved = await OidcState.get(state);
|
||||
await saved.remove();
|
||||
|
||||
let tokens = await oidc.exchangeCode(code, saved.codeVerifier);
|
||||
let claims = await oidc.fetchUserInfo(tokens.access_token);
|
||||
let identity = oidc.claimsToIdentity(claims);
|
||||
|
||||
let {token} = await Auth.oidcSession(identity);
|
||||
|
||||
let redirect = safeInternalPath(saved.redirect || '/');
|
||||
return res.redirect(
|
||||
`/login#token=${encodeURIComponent(token.token)}&redirect=${encodeURIComponent(redirect)}`
|
||||
);
|
||||
}catch(error){
|
||||
next(error);
|
||||
}
|
||||
});
|
||||
|
||||
module.exports = router;
|
||||
@@ -4,8 +4,10 @@ const path = require('path');
|
||||
const express = require('express');
|
||||
const router = require('express').Router();
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const buildInfo = require('../models/build_info');
|
||||
const buildInfo = require('../utils/build_info');
|
||||
const registry = require('../services/session_registry');
|
||||
const { safeInternalPath } = require('@simpleworkjs/oidc-client');
|
||||
const { mountStaticModules } = require('@simpleworkjs/app-stack');
|
||||
|
||||
const values = {
|
||||
title: conf.environment !== 'production' ? 'dev' : '',
|
||||
@@ -17,15 +19,14 @@ const values = {
|
||||
|
||||
// Serve front-end vendor libraries straight from node_modules (same convention
|
||||
// as the sibling apps), and the app's own JS/CSS/img from public/.
|
||||
const frontEndModules = ['bootstrap', 'mustache', 'jquery', '@fortawesome', 'moment', 'jq-repeat'];
|
||||
frontEndModules.forEach(dep => {
|
||||
router.use(`/static-modules/${dep}`, express.static(path.join(__dirname, `../node_modules/${dep}`), {maxAge: '7d'}));
|
||||
mountStaticModules(router, {
|
||||
root: path.join(__dirname, '..'),
|
||||
deps: ['bootstrap', 'mustache', 'jquery', '@fortawesome', 'moment', 'jq-repeat'],
|
||||
});
|
||||
router.use('/static', express.static(path.join(__dirname, '../public'), {maxAge: '1h'}));
|
||||
|
||||
// Liveness probe — no auth.
|
||||
router.get('/health', (req, res) => {
|
||||
res.json({status: 'ok', activeSessions: registry.count(), version: buildInfo.version, commit: buildInfo.commit});
|
||||
res.json({status: 'ok', activeSessions: registry.count(), buildVersion: buildInfo.buildVersion, buildHash: buildInfo.buildHash});
|
||||
});
|
||||
|
||||
router.get('/', (req, res) => res.redirect(302, '/dashboard'));
|
||||
@@ -36,7 +37,7 @@ router.get('/', (req, res) => res.redirect(302, '/dashboard'));
|
||||
// /login when there's no valid session.
|
||||
router.get('/login', (req, res) => res.render('login', {
|
||||
...values,
|
||||
redirect: '/',
|
||||
redirect: safeInternalPath(req.query.redirect || '/'),
|
||||
oidcEnabled: !!(conf.oidc && conf.oidc.enabled),
|
||||
}));
|
||||
router.get('/dashboard', (req, res) => res.render('dashboard', {...values}));
|
||||
|
||||
@@ -53,3 +53,17 @@ test('caches per uid', async () => {
|
||||
await accessibleHosts(user, { fetchImpl, ldap });
|
||||
assert.strictEqual(calls, 1);
|
||||
});
|
||||
|
||||
test('a bare-array response (envelope drift) is treated as a failed group, not silently []', async () => {
|
||||
clearCache();
|
||||
const user = { uid: 'dave', dn: 'd' };
|
||||
// drift shape: a bare array instead of { results: [...] }. The shared client
|
||||
// throws DirectoryEnvelopeViolation; access.js must catch + continue, so a
|
||||
// good group alongside still yields its hosts.
|
||||
const fetchImpl = async (url) => {
|
||||
if (url.includes('drift')) return { ok: true, json: async () => [{ id: '7', kind: 'host' }] };
|
||||
return { ok: true, json: async () => ({ results: [{ id: '8', kind: 'host' }] }) };
|
||||
};
|
||||
const hosts = await accessibleHosts(user, { fetchImpl, ldap: stubLdap(['drift_access', 'good_access']) });
|
||||
assert.deepStrictEqual(hosts.map((h) => h.id), ['8']);
|
||||
});
|
||||
|
||||
+11
-8
@@ -16,20 +16,23 @@
|
||||
// unit testing.
|
||||
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
const { createDirectoryClient } = require('@simpleworkjs/directory-schema');
|
||||
const userLdap = require('../models/user_ldap');
|
||||
|
||||
const CACHE_TTL_MS = 30 * 1000;
|
||||
const cache = new Map(); // uid -> {at, hosts}
|
||||
|
||||
async function fetchResourcesByGroup(group, { fetchImpl = fetch } = {}) {
|
||||
// Build a directory client bound to conf.sso. fetchImpl is injectable so the
|
||||
// unit tests can stub the transport; the shared client validates the
|
||||
// `{ results }` envelope on every call (turns the old bare-array drift into a
|
||||
// thrown error instead of a silent `[]`).
|
||||
function directoryClient({ fetchImpl = fetch } = {}) {
|
||||
const sso = conf.sso || {};
|
||||
const url = `${sso.url}/api/discovery/resources?group=${encodeURIComponent(group)}`;
|
||||
const res = await fetchImpl(url, {
|
||||
headers: { Authorization: `Bearer ${sso.apiToken}` },
|
||||
});
|
||||
if (!res.ok) throw new Error(`directory query failed (${res.status}) for group ${group}`);
|
||||
const data = await res.json();
|
||||
return (data && data.results) || [];
|
||||
return createDirectoryClient({ baseUrl: sso.url, apiToken: sso.apiToken, fetch: fetchImpl });
|
||||
}
|
||||
|
||||
async function fetchResourcesByGroup(group, { fetchImpl = fetch } = {}) {
|
||||
return directoryClient({ fetchImpl }).getResourcesByGroup(group);
|
||||
}
|
||||
|
||||
async function accessibleHosts(user, { fetchImpl = fetch, ldap = userLdap } = {}) {
|
||||
|
||||
@@ -0,0 +1,19 @@
|
||||
'use strict';
|
||||
|
||||
// Unified build-info shape ({ buildVersion, buildHash, buildYear }) via the
|
||||
// shared @simpleworkjs/app-stack. Previously this lived in models/build_info.js
|
||||
// and exported { commit, version }; the shape is now aligned with sso + proxy.
|
||||
//
|
||||
// The baked commit file lives at the jump-host repo root (../../ from here in
|
||||
// utils/), matching the Dockerfile gitinfo stage. cwd is utils/ for the
|
||||
// bare-metal git fallback.
|
||||
|
||||
const path = require('path');
|
||||
const { createBuildInfo } = require('@simpleworkjs/app-stack');
|
||||
const { version } = require('../package.json');
|
||||
|
||||
module.exports = createBuildInfo({
|
||||
version,
|
||||
buildCommitPath: path.join(__dirname, '../../.build_commit'),
|
||||
cwd: __dirname,
|
||||
});
|
||||
@@ -1,127 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
const crypto = require('crypto');
|
||||
const conf = require('@simpleworkjs/conf');
|
||||
|
||||
/**
|
||||
* Minimal OpenID Connect authorization-code + PKCE client.
|
||||
*
|
||||
* The SSO publishes no jwks_uri, so we do not verify ID-token signatures;
|
||||
* instead we treat the flow as opaque and read identity from the userinfo
|
||||
* endpoint (the access token is exchanged server-side over TLS). Uses Node's
|
||||
* global fetch (Node 18+) and crypto — no external dependency.
|
||||
*
|
||||
* All endpoints and client config come from conf.oidc (+ clientSecret from
|
||||
* secrets.js, deep-merged by @simpleworkjs/conf).
|
||||
*/
|
||||
|
||||
const base64url = buf => buf.toString('base64')
|
||||
.replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '');
|
||||
|
||||
// A high-entropy random string for `state` / PKCE verifier.
|
||||
function randomToken(bytes = 32){
|
||||
return base64url(crypto.randomBytes(bytes));
|
||||
}
|
||||
|
||||
// PKCE S256 challenge derived from the verifier.
|
||||
function codeChallengeS256(verifier){
|
||||
return base64url(crypto.createHash('sha256').update(verifier).digest());
|
||||
}
|
||||
|
||||
// Generate the {state, codeVerifier, codeChallenge} triple for a new login.
|
||||
function createAuthRequest(){
|
||||
let state = randomToken(32);
|
||||
let codeVerifier = randomToken(32);
|
||||
let codeChallenge = codeChallengeS256(codeVerifier);
|
||||
return {state, codeVerifier, codeChallenge};
|
||||
}
|
||||
|
||||
// Build the SSO authorize URL the browser is redirected to. `redirectUri`
|
||||
// overrides conf.oidc.redirectUri (per-host SSO uses a per-host callback).
|
||||
function buildAuthUrl(state, codeChallenge, redirectUri){
|
||||
let o = conf.oidc;
|
||||
let params = new URLSearchParams({
|
||||
response_type: 'code',
|
||||
client_id: o.clientId,
|
||||
redirect_uri: redirectUri || o.redirectUri,
|
||||
scope: (o.scopes || ['openid', 'profile', 'email', 'groups']).join(' '),
|
||||
state,
|
||||
code_challenge: codeChallenge,
|
||||
code_challenge_method: 'S256',
|
||||
});
|
||||
return `${o.authorizationEndpoint}?${params.toString()}`;
|
||||
}
|
||||
|
||||
// Exchange an authorization code for tokens at the token endpoint. `redirectUri`
|
||||
// must match the one used in buildAuthUrl (per-host for per-host SSO).
|
||||
async function exchangeCode(code, codeVerifier, redirectUri){
|
||||
let o = conf.oidc;
|
||||
let body = new URLSearchParams({
|
||||
grant_type: 'authorization_code',
|
||||
code,
|
||||
redirect_uri: redirectUri || o.redirectUri,
|
||||
client_id: o.clientId,
|
||||
client_secret: o.clientSecret,
|
||||
code_verifier: codeVerifier,
|
||||
});
|
||||
|
||||
let res = await fetch(o.tokenEndpoint, {
|
||||
method: 'POST',
|
||||
headers: {
|
||||
'Content-Type': 'application/x-www-form-urlencoded',
|
||||
'Accept': 'application/json',
|
||||
},
|
||||
body: body.toString(),
|
||||
});
|
||||
|
||||
if(!res.ok){
|
||||
let text = await res.text().catch(() => '');
|
||||
let error = new Error('OidcTokenExchangeFailed');
|
||||
error.name = 'OidcTokenExchangeFailed';
|
||||
error.message = `Token exchange failed (${res.status}): ${text}`;
|
||||
error.status = 502;
|
||||
throw error;
|
||||
}
|
||||
|
||||
return res.json();
|
||||
}
|
||||
|
||||
// Fetch the userinfo claims for an access token.
|
||||
async function fetchUserInfo(accessToken){
|
||||
let o = conf.oidc;
|
||||
let res = await fetch(o.userinfoEndpoint, {
|
||||
headers: {
|
||||
'Authorization': `Bearer ${accessToken}`,
|
||||
'Accept': 'application/json',
|
||||
},
|
||||
});
|
||||
|
||||
if(!res.ok){
|
||||
let error = new Error('OidcUserInfoFailed');
|
||||
error.name = 'OidcUserInfoFailed';
|
||||
error.message = `Userinfo request failed (${res.status})`;
|
||||
error.status = 502;
|
||||
throw error;
|
||||
}
|
||||
|
||||
return res.json();
|
||||
}
|
||||
|
||||
// Pull the app username and group list out of userinfo claims per conf.
|
||||
function claimsToIdentity(claims){
|
||||
let o = conf.oidc;
|
||||
let username = claims[o.usernameClaim || 'preferred_username'] || claims.sub;
|
||||
let groups = claims[o.groupsClaim || 'groups'] || [];
|
||||
if(!Array.isArray(groups)) groups = [groups].filter(Boolean);
|
||||
return {username, groups, claims};
|
||||
}
|
||||
|
||||
module.exports = {
|
||||
randomToken,
|
||||
codeChallengeS256,
|
||||
createAuthRequest,
|
||||
buildAuthUrl,
|
||||
exchangeCode,
|
||||
fetchUserInfo,
|
||||
claimsToIdentity,
|
||||
};
|
||||
@@ -1,23 +0,0 @@
|
||||
'use strict';
|
||||
|
||||
/**
|
||||
* Constrain a post-login redirect target to a same-origin path.
|
||||
*
|
||||
* Rejects anything that could leave the site or execute script:
|
||||
* - absolute URLs ("https://evil.com") -> not a "/" path
|
||||
* - protocol-relative ("//evil.com", "/\\evil.com") -> host takeover
|
||||
* - scheme targets ("javascript:...", "data:...") -> XSS
|
||||
* Anything not a plain "/path" falls back to "/".
|
||||
*
|
||||
* The browser has its own copy of this in public/lib/js/app-base.js; keep the
|
||||
* two in sync.
|
||||
*/
|
||||
function safeInternalPath(path){
|
||||
if(typeof path !== 'string' || path.charAt(0) !== '/'
|
||||
|| path.charAt(1) === '/' || path.charAt(1) === '\\'){
|
||||
return '/';
|
||||
}
|
||||
return path;
|
||||
}
|
||||
|
||||
module.exports = {safeInternalPath};
|
||||
@@ -0,0 +1,42 @@
|
||||
'use strict';
|
||||
|
||||
// Per-app values for the shared UI shell (views/top.ejs + views/bottom.ejs).
|
||||
//
|
||||
// Those two partials are byte-identical across sso-manager-node, proxy and
|
||||
// jump-host — everything that differs between the apps lives here and is
|
||||
// exposed to every render as `ui` via app.locals (see app.js). Keep the key set
|
||||
// in sync across the three apps; a missing key is a render-time ReferenceError,
|
||||
// not a silent fallback.
|
||||
|
||||
module.exports = {
|
||||
// --- footer -------------------------------------------------------------
|
||||
repoUrl: 'https://github.com/theta42/jump-host',
|
||||
licenseUrl: 'https://github.com/theta42/jump-host/blob/master/LICENSE',
|
||||
// No in-app /docs route here — point at the published docs site.
|
||||
docsUrl: 'https://theta42.github.io/jump-host/',
|
||||
docsExternal: true,
|
||||
// Only sso-manager-node serves a Terms of Service page; null hides the link.
|
||||
tosUrl: null,
|
||||
|
||||
// --- header / nav -------------------------------------------------------
|
||||
faviconUrl: '/static/favicon.svg',
|
||||
// Where the current-user chip links. null renders it as a plain span (for
|
||||
// apps with no profile page).
|
||||
profileUrl: null,
|
||||
// Where "Log Out" lands.
|
||||
logoutRedirect: '/login',
|
||||
// Admin-only "a newer release is available" banner, backed by
|
||||
// GET /api/update-check. Apps without that endpoint set false.
|
||||
updateCheck: false,
|
||||
updateLabel: 'the jump host',
|
||||
|
||||
// Nav items, in order. `groups` is an OR-list of group CNs that may see the
|
||||
// item; an empty list means "always visible". Gating is done client-side by
|
||||
// app-base.js, which reveals .group-required-<cn> for each group the user is
|
||||
// in (plus the synthetic `admin` group when user/me reports isAdmin).
|
||||
nav: [
|
||||
{href: '/dashboard', icon: 'fa-solid fa-gauge-high', label: 'Dashboard', groups: []},
|
||||
{href: '/sessions', icon: 'fa-solid fa-plug-circle-bolt', label: 'Sessions', groups: []},
|
||||
{href: '/audit', icon: 'fa-solid fa-clipboard-list', label: 'Audit', groups: []},
|
||||
],
|
||||
};
|
||||
+27
-21
@@ -1,24 +1,30 @@
|
||||
</div>
|
||||
</div><!-- end spa-shell -->
|
||||
|
||||
<footer class="py-2 bg-dark text-light mt-4">
|
||||
<div class="container-fluid d-flex flex-wrap justify-content-between align-items-center small gap-2">
|
||||
<span class="d-flex align-items-center gap-2">
|
||||
<a href="https://theta42.com" target="_blank">
|
||||
<img width="64" src="/static/img/theta42.svg"/>
|
||||
</a>
|
||||
© <%- (new Date()).getFullYear() %> theta42 ·
|
||||
<a href="https://github.com/theta42/jump-host/blob/master/LICENSE" target="_blank" class="text-light">MIT License</a>
|
||||
</span>
|
||||
<span class="d-flex align-items-center gap-3">
|
||||
<a href="https://theta42.github.io/jump-host/" target="_blank" class="text-light text-decoration-none">
|
||||
<i class="fa-solid fa-book"></i> Docs
|
||||
</a>
|
||||
<a href="https://github.com/theta42/jump-host" target="_blank" class="text-light text-decoration-none">
|
||||
<i class="fa-brands fa-github"></i> GitHub
|
||||
</a>
|
||||
</span>
|
||||
<span>v<%- version %> (<%- commit %>)</span>
|
||||
</div>
|
||||
</footer>
|
||||
<!-- Shared UI shell — byte-identical across sso-manager-node, proxy and
|
||||
jump-host. Everything per-app comes from `ui` (utils/ui.js, exposed via
|
||||
app.locals in app.js). Edit all three copies together. -->
|
||||
<footer class="py-2 bg-dark text-light mt-4">
|
||||
<div class="container-fluid d-flex flex-wrap justify-content-between align-items-center small gap-2">
|
||||
<span class="d-flex align-items-center gap-2">
|
||||
<a href="https://theta42.com" target="_blank">
|
||||
<img width="64" src="/static/img/theta42.svg"/>
|
||||
</a>
|
||||
© <%- buildYear %> theta42 ·
|
||||
<a href="<%- ui.licenseUrl %>" target="_blank" class="text-light">MIT License</a>
|
||||
</span>
|
||||
<span class="d-flex align-items-center gap-3">
|
||||
<a href="<%- ui.docsUrl %>"<%- ui.docsExternal ? ' target="_blank"' : '' %> class="text-light text-decoration-none">
|
||||
<i class="fa-solid fa-book"></i> Docs
|
||||
</a>
|
||||
<a href="<%- ui.repoUrl %>" target="_blank" class="text-light text-decoration-none">
|
||||
<i class="fa-brands fa-github"></i> GitHub
|
||||
</a>
|
||||
<% if(ui.tosUrl){ %>
|
||||
<a href="<%- ui.tosUrl %>" class="text-light text-decoration-none">Terms of Service</a>
|
||||
<% } %>
|
||||
</span>
|
||||
<span>v<%- buildVersion %> (<%- buildHash %>)</span>
|
||||
</div>
|
||||
</footer>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+12
-8
@@ -4,14 +4,18 @@
|
||||
// If we arrived from the OIDC callback with a token in the URL fragment,
|
||||
// store it and forward on before doing anything else.
|
||||
if(!app.auth.consumeTokenFragment()){
|
||||
app.auth.isLoggedIn(function(error, isLoggedIn){
|
||||
if(isLoggedIn){
|
||||
app.auth.logInRedirect();
|
||||
}else{
|
||||
// Reveal the login card once we know the user is not logged in.
|
||||
document.getElementById('login-card-row').style.display = '';
|
||||
}
|
||||
})
|
||||
// The reveal below touches an element further down this page, so wait
|
||||
// for the DOM — isLoggedIn can answer before the parser gets there.
|
||||
$(document).ready(function(){
|
||||
app.auth.isLoggedIn(function(error, isLoggedIn){
|
||||
if(isLoggedIn){
|
||||
app.auth.logInRedirect();
|
||||
}else{
|
||||
// Reveal the login card once we know the user is not logged in.
|
||||
document.getElementById('login-card-row').style.display = '';
|
||||
}
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
</script>
|
||||
|
||||
+94
-23
@@ -4,10 +4,17 @@
|
||||
<meta charset="utf-8">
|
||||
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
||||
<title><%- name %> <%- title %></title>
|
||||
<link rel="icon" type="image/svg+xml" href="/static/favicon.svg">
|
||||
<!-- Shared UI shell — byte-identical across sso-manager-node, proxy and
|
||||
jump-host. Everything per-app comes from `ui` (utils/ui.js, exposed
|
||||
via app.locals in app.js). Edit all three copies together. -->
|
||||
<!-- Favicon -->
|
||||
<link rel="icon" type="image/svg+xml" href="<%- ui.faviconUrl %>">
|
||||
<!-- CSS are placed here -->
|
||||
<link rel="stylesheet" href="/static-modules/bootstrap/dist/css/bootstrap.min.css">
|
||||
<link rel="stylesheet" href="/static-modules/@fortawesome/fontawesome-free/css/all.min.css">
|
||||
|
||||
<link rel='stylesheet' href='/static/css/styles.css' />
|
||||
<!-- Scripts are placed here -->
|
||||
<script type="text/javascript" src="/socket.io/socket.io.js"></script>
|
||||
<script type="text/javascript" src='/static-modules/jquery/dist/jquery.js'></script>
|
||||
<script type="text/javascript" src="/static-modules/bootstrap/dist/js/bootstrap.bundle.min.js"></script>
|
||||
@@ -28,51 +35,115 @@
|
||||
</button>
|
||||
<div class="collapse navbar-collapse justify-content-end" id="navbarSupportedContent">
|
||||
<ul class="navbar-nav top-nav">
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/dashboard"><i class="fa-solid fa-gauge-high"></i> Dashboard</a>
|
||||
</li>
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/sessions"><i class="fa-solid fa-plug-circle-bolt"></i> Sessions</a>
|
||||
</li>
|
||||
<li class="nav-item">
|
||||
<a class="nav-link" href="/audit"><i class="fa-solid fa-clipboard-list"></i> Audit</a>
|
||||
<%# Items gated on a group start hidden (.group-required) and are
|
||||
revealed by app-base.js for the groups the user is in. %>
|
||||
<% for(const item of ui.nav){ %>
|
||||
<li class="nav-item<%- item.groups.length ? ' group-required' : '' %><%- item.groups.map(group => ' group-required-' + group).join('') %>">
|
||||
<a class="nav-link" href="<%- item.href %>"><i class="<%- item.icon %>"></i>
|
||||
<%- item.label %>
|
||||
</a>
|
||||
</li>
|
||||
<% } %>
|
||||
</ul>
|
||||
<div class="form-inline mt-2 mt-md-0">
|
||||
<% if(ui.profileUrl){ %>
|
||||
<a id="cl-username" class="navbar-text text-light me-3" href="<%- ui.profileUrl %>" style="display: none;">
|
||||
<i class="fa-solid fa-user me-1"></i><span id="cl-username-text"></span>
|
||||
</a>
|
||||
<% } else { %>
|
||||
<span id="cl-username" class="navbar-text text-light me-3" style="display: none;">
|
||||
<i class="fa-solid fa-user me-1"></i><span id="cl-username-text"></span>
|
||||
</span>
|
||||
<a id="cl-login-button" class="btn btn-outline-danger my-2 my-sm-0" href="/login" style="display: none;">
|
||||
<i class="fas fa-sign-in"></i> Login
|
||||
<% } %>
|
||||
<a id="cl-login-button" class="btn btn-outline-danger my-2 my-sm-0" onclick="app.auth.forceLogin()" style="display: none;">
|
||||
<i class="fas fa-sign-in"></i>
|
||||
Login
|
||||
</a>
|
||||
<button id="cl-logout-button" class="btn btn-outline-danger my-2 my-sm-0" onclick="app.auth.logOut(function(){ window.location.href='/login'; })" style="display: none;">
|
||||
<i class="fas fa-sign-out"></i> Log Out
|
||||
|
||||
<button id="cl-logout-button" class="btn btn-outline-danger my-2 my-sm-0" onclick="app.auth.logOut(function(){ window.location.href = '<%- ui.logoutRedirect %>'; })" style="display: none;">
|
||||
<i class="fas fa-sign-out"></i>
|
||||
Log Out
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
</nav>
|
||||
|
||||
<% if(ui.updateCheck){ %>
|
||||
<!-- Admin-only "a newer release is available" notice (services/update_check.js).
|
||||
Dismissal is per-browser-session only (sessionStorage), not persisted server-side.
|
||||
Fixed-positioned below the fixed navbar (a plain in-flow div here would render
|
||||
UNDER the nav, since fixed elements are taken out of document flow) -- shown/hidden
|
||||
dynamically, so #spa-shell's margin-top is adjusted in JS to make room for it. -->
|
||||
<div id="update-banner" class="alert alert-info alert-dismissible mb-0 rounded-0 text-center" style="display:none; position:fixed; left:0; right:0; z-index:1029;">
|
||||
<span id="update-banner-text"></span>
|
||||
<button type="button" class="btn-close" onclick="dismissUpdateBanner()"></button>
|
||||
</div>
|
||||
|
||||
<script type="text/javascript">
|
||||
function showUpdateBanner(){
|
||||
let $nav = $('nav.fixed-top');
|
||||
let $banner = $('#update-banner');
|
||||
$banner.css('top', $nav.outerHeight() + 'px').show();
|
||||
$('#spa-shell').css('margin-top', ($nav.outerHeight() + $banner.outerHeight()) + 'px');
|
||||
}
|
||||
|
||||
function dismissUpdateBanner(){
|
||||
$('#update-banner').hide();
|
||||
$('#spa-shell').css('margin-top', '');
|
||||
sessionStorage.setItem('update-banner-dismissed', '1');
|
||||
}
|
||||
|
||||
function checkForUpdate(){
|
||||
if(sessionStorage.getItem('update-banner-dismissed')) return;
|
||||
app.api.get('update-check', function(error, info){
|
||||
if(error || !info || !info.updateAvailable) return;
|
||||
$('#update-banner-text').html(
|
||||
'A newer version of <%- ui.updateLabel %> is available: <b>v' + info.latestVersion + '</b> ' +
|
||||
'(running v' + info.currentVersion + ') — ' +
|
||||
'<a href="' + info.releaseUrl + '" target="_blank" class="alert-link">see what changed</a>.'
|
||||
);
|
||||
showUpdateBanner();
|
||||
});
|
||||
}
|
||||
</script>
|
||||
<% } %>
|
||||
|
||||
<script type="text/javascript">
|
||||
$(document).ready(function(){
|
||||
$('.top-nav a').each(function(){
|
||||
var $this = $(this);
|
||||
|
||||
// Set the correct link to active in the top nav bar
|
||||
$('.top-nav a').each(function(index){
|
||||
let $this = $(this);
|
||||
$this.removeClass('active');
|
||||
if($this.attr('href').toLowerCase() === window.location.pathname.toLowerCase()){
|
||||
$this.addClass('active');
|
||||
if($this.attr('href').toLocaleLowerCase() === window.location.pathname.toLocaleLowerCase()){
|
||||
$this.addClass('active')
|
||||
}
|
||||
});
|
||||
app.auth.isLoggedIn(function(error, data){
|
||||
if(data){
|
||||
})
|
||||
|
||||
// Set the correct login/logout button, and reveal the current user's
|
||||
// name once we know who they are. Group-gated nav items are revealed
|
||||
// by app-base.js off the same cached user/me.
|
||||
app.auth.isLoggedIn(function(error, me){
|
||||
if(me){
|
||||
$('#cl-logout-button').show();
|
||||
if(data.username){
|
||||
$('#cl-username-text').text(data.username);
|
||||
let username = me.uid || me.username;
|
||||
if(username){
|
||||
$('#cl-username-text').text(username);
|
||||
$('#cl-username').css('display', '');
|
||||
}
|
||||
|
||||
<% if(ui.updateCheck){ %>
|
||||
if(me.isAdmin) checkForUpdate();
|
||||
<% } %>
|
||||
}else{
|
||||
$('#cl-login-button').show();
|
||||
}
|
||||
});
|
||||
|
||||
});
|
||||
</script>
|
||||
|
||||
<div id="spa-shell" class="container-fluid" style="margin-top: 4.5rem;">
|
||||
|
||||
<!-- Container -->
|
||||
<div id="spa-shell" class="container-fluid">
|
||||
<div class="actionMessage" style="display:none;"></div>
|
||||
|
||||
Reference in New Issue
Block a user