Compare commits
17 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 4a70b5b27e | |||
| 43caac13d5 | |||
| 465f923393 | |||
| 782a829cb9 | |||
| fd863b89ca | |||
| 4fb4e77007 | |||
| a56a31421d | |||
| d33e324b31 | |||
| 4879769cc7 | |||
| da274a3ced | |||
| b9be0fe4e1 | |||
| 9db530565d | |||
| fe6306b7d3 | |||
| 240563e093 | |||
| 047e54ce50 | |||
| ee76088f86 | |||
| 8db46bd9d9 |
@@ -4,6 +4,54 @@ All notable changes to this project are documented here. Format loosely
|
|||||||
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions
|
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions
|
||||||
correspond to git tags (`vX.Y.Z`) and `nodejs/package.json`'s `version`.
|
correspond to git tags (`vX.Y.Z`) and `nodejs/package.json`'s `version`.
|
||||||
|
|
||||||
|
## [1.6.0] - 2026-07-27
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Adopted `@simpleworkjs/frontend`'s `app.messages`, `app.modal`, and `app.validate` modules**, replacing the vendored `app.util.actionMessage`/`actionConfirm` in `public/lib/js/app-base.js` and the vendored `public/lib/js/val.js` (unused by any current view here, so this is dedup/future-proofing rather than a behavior change). `app.api`/`app.auth`/`app.pubsub`/`app.socket` are untouched.
|
||||||
|
|
||||||
|
## [1.5.0] - 2026-07-27
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **Web UI dashboard now lists the hosts you can reach** ("Hosts you can reach", or "All hosts" for admins) — previously the dashboard only showed usage metrics, with no way to see your actual access from the browser. Backed by a new `GET /api/user/hosts` endpoint (auth-only, not admin-gated): admins get the full inventory via `utils/access.js`'s new `allHosts()`, everyone else gets the same group-based resolution the SSH front door uses.
|
||||||
|
- `utils/access.js`'s `accessibleHosts()` now accepts a pre-resolved `groups` array on the user object, skipping the LDAP `getGroups(dn)` round-trip — the web UI's OIDC session already has its groups claim and has no LDAP `dn` to query with.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **Bumped `@simpleworkjs/ldap` to 1.0.1**, which fixes `addSshKey` throwing `ObjectClassViolationError` (LDAP `0x41`) on accounts predating the `ldapPublicKey` auxiliary objectClass. This is the code path this jump host's key-injection (`utils/key_inject.js`) uses on every first connection for a user — on affected accounts it aborted the SSH connection entirely (`key-inject-failed`).
|
||||||
|
|
||||||
|
## [1.4.0] - 2026-07-26
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **Standalone mode** — run the jump host with no LDAP directory and no SSO Manager at all. Set `standalone.enabled: true` and user authentication and host discovery switch to `@simpleworkjs/orm`-backed stores (Sequelize; SQLite by default, any Sequelize-supported dialect via `conf.orm`) instead of the directory services. `models/user_ldap.js` and `utils/access.js` become conditional facades that pick their backend at require time — `ssh_server.js`, `bridge.js`, `key_inject.js`, `tui_picker.js`, and the web UI are unchanged either way.
|
||||||
|
- New ORM models: `StandaloneUser` (`uid`, `passwordHash`, `sshPublicKeys`, `groups`) and `StandaloneHost` (`slug`, `displayName`, `kind`, `metadata`), plus `models/user_file.js` and `utils/hosts_file.js`, which implement the same interfaces as the LDAP client and `accessibleHosts()` respectively. There's no admin UI for standalone users/hosts yet — see the README's "Standalone mode" section for the ORM-model seeding snippet. In standalone mode every stored host is reachable by every stored user; there's no group-based authorization yet.
|
||||||
|
- 47 tests pass (24 existing + 15 new unit + 3 existing integration + 5 new standalone integration).
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **`services/ssh_server.js` used `|| 2222` for the listen port**, so an explicit `listenPort: 0` (ephemeral port, used by the test suite) was silently overridden back to 2222. Changed to `?? 2222`.
|
||||||
|
- **`services/ssh_server.js` awaited `audit.create()` before registering session listeners.** A client that sends `exec`/`shell` immediately after connecting could have its request dropped because nothing was listening yet. Listener registration now happens first.
|
||||||
|
|
||||||
|
## [1.3.0] - 2026-07-26
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- **Unified the front-end UI shell across the three theta42 apps.** `views/top.ejs`, `views/bottom.ejs` and `public/lib/js/app-base.js` are now byte-identical in sso-manager-node, proxy and jump-host, so the apps look and behave the same and a shell change lands in one edit per repo instead of three divergent ones. Everything that differs between the apps moved into a new `nodejs/utils/ui.js`, exposed to every render as `ui` via `app.locals`: nav items and the groups that may see them, footer repo/license/docs/Terms links, favicon, the profile and post-logout targets, and whether the update banner exists at all.
|
||||||
|
- **One nav-gating model everywhere.** `app-base.js` reveals `.group-required-<cn>` elements for each group the current user is in, read from `GET /api/user/me`. sso-manager-node reports LDAP DNs in `memberOf` and the OIDC clients report CNs in `groups`; both normalise to CNs client-side, and the clients' effective-rights `isAdmin` flag is exposed as a synthetic `admin` group — so one gating model covers a group-based provider and boolean-admin clients without either app learning the other's response shape.
|
||||||
|
- **`GET /api/user/me` is fetched once per page load and cached** (`app.auth.loadUser`). The nav, per-view `forceLogin` and every group-gated element read that one promise instead of issuing their own request.
|
||||||
|
- `app.auth.isLoggedIn` is dual-mode: it returns a Promise **and** invokes an optional node-style callback, so the async and callback call styles both work against one shared `top.ejs`.
|
||||||
|
- `app.auth.forceLogin` no longer uses `$.holdReady` (removed in jQuery 4). An unauthenticated user is redirected to `/login?redirect=<path>`; group requirements are still enforced, and `logOut` now only clears the session, leaving the destination to the caller (`ui.logoutRedirect`).
|
||||||
|
- Dependency alignment across all three apps: `jquery` `^4.0.0` and `ejs` `^3.1.10`.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **`app.api.delete` dropped its callback when called by `formAJAX`.** `formAJAX` always passes the serialized form as the second argument, so a DELETE-method form's callback landed in the data slot and never ran. `delete` now accepts both `(url, callback)` and `(url, data, callback)`.
|
||||||
|
- **`app.api.post`/`put` referenced an undefined `callback2`** and threw when handed a non-function callback. Both are now dual-mode Promise/callback.
|
||||||
|
- **The login page's "reveal the card once we know you're logged out" branch threw** (`Cannot read properties of null`) whenever the logged-in check answered before the parser reached that element — which it always did without a stored token. It now runs on DOM ready.
|
||||||
|
- **`logInRedirect` on the legacy `/login/<path>` form kept only the path.** The OIDC provider routes an unauthenticated authorization request through `/login/oauth/authorize?client_id=…&state=…`; dropping the query there loses the entire authorization request. The suffix form now preserves its query string.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `.group-required { display: none }` in `public/css/styles.css`, the base rule the shared gating model reveals against.
|
||||||
|
- `#spa-shell` dropped its inline `margin-top`; `styles.css` already sets it and the shared shell adjusts it when a banner is shown.
|
||||||
|
|
||||||
|
### Verified
|
||||||
|
- Browser-verified against a full theta-env stack (sso-manager + proxy + jump-host): every top-level page renders with a clean console; nav gating is correct for admin and non-admin; `forceLogin`'s onboarding and group gates fire; `val.js` blocks a weak password and accepts a strong one through a real form submit; the DELETE-method forms work; and the OIDC login round trip (authorize with PKCE -> login -> consent -> callback -> token fragment) completes on both OIDC clients.
|
||||||
|
|
||||||
## [1.2.0] - 2026-07-25
|
## [1.2.0] - 2026-07-25
|
||||||
|
|
||||||
### Added
|
### Added
|
||||||
|
|||||||
@@ -2,9 +2,13 @@
|
|||||||
|
|
||||||
An SSH jump host for the [theta42](https://github.com/theta42) self-hosted
|
An SSH jump host for the [theta42](https://github.com/theta42) self-hosted
|
||||||
stack. Users SSH into one public host and land on any downstream host they're
|
stack. Users SSH into one public host and land on any downstream host they're
|
||||||
entitled to — authenticated against the shared LDAP directory, authorized from
|
entitled to — audited end to end.
|
||||||
the [SSO Manager](https://github.com/theta42/sso-manager-node)'s inventory
|
|
||||||
graph, audited end to end.
|
Two backends, same SSH front door and audit trail: the default mode
|
||||||
|
authenticates against the shared LDAP directory and authorizes from the
|
||||||
|
[SSO Manager](https://github.com/theta42/sso-manager-node)'s inventory graph;
|
||||||
|
**standalone mode** (below) runs with no LDAP or SSO at all, storing users and
|
||||||
|
hosts in a local SQL database instead.
|
||||||
|
|
||||||
## Two ways to connect
|
## Two ways to connect
|
||||||
|
|
||||||
@@ -44,8 +48,53 @@ bridged straight in.
|
|||||||
4. **Bridge** — shell, exec, and the SFTP subsystem are spliced to the
|
4. **Bridge** — shell, exec, and the SFTP subsystem are spliced to the
|
||||||
downstream sshd. Every session is audited.
|
downstream sshd. Every session is audited.
|
||||||
|
|
||||||
|
## Standalone mode
|
||||||
|
|
||||||
|
Run without LDAP or the SSO Manager at all. Set `standalone.enabled: true` and
|
||||||
|
the jump host stores users and hosts itself, via
|
||||||
|
[@simpleworkjs/orm](https://www.npmjs.com/package/@simpleworkjs/orm)
|
||||||
|
(Sequelize under the hood — defaults to a local SQLite file, but any
|
||||||
|
Sequelize-supported dialect works via `conf.orm`):
|
||||||
|
|
||||||
|
```js
|
||||||
|
standalone: { enabled: true },
|
||||||
|
orm: { dialect: 'sqlite', storage: './data/standalone.sqlite', logging: false },
|
||||||
|
```
|
||||||
|
|
||||||
|
Everything else — the SSH front door, key injection, bridging, the web UI and
|
||||||
|
audit trail — is unchanged; only where users/hosts live and how passwords are
|
||||||
|
checked differs. There's no admin UI for standalone users/hosts yet — add them
|
||||||
|
with the ORM models directly:
|
||||||
|
|
||||||
|
```js
|
||||||
|
const StandaloneUser = require('./models/standalone_user');
|
||||||
|
const StandaloneHost = require('./models/standalone_host');
|
||||||
|
const bcrypt = require('bcrypt');
|
||||||
|
|
||||||
|
await StandaloneUser.create({
|
||||||
|
uid: 'alice',
|
||||||
|
passwordHash: await bcrypt.hash('a real password', 10),
|
||||||
|
sshPublicKeys: ['ssh-ed25519 AAAA... alice@laptop'],
|
||||||
|
groups: [],
|
||||||
|
});
|
||||||
|
|
||||||
|
await StandaloneHost.create({
|
||||||
|
slug: 'host_web01',
|
||||||
|
displayName: 'web01',
|
||||||
|
kind: 'host',
|
||||||
|
metadata: { ip: '10.0.0.5', sshPort: 22 },
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
In standalone mode every stored host is reachable by every stored user — there
|
||||||
|
is no group-based authorization (the `groups` field on `StandaloneUser` is
|
||||||
|
accepted for interface parity but not yet enforced).
|
||||||
|
|
||||||
## Requirements
|
## Requirements
|
||||||
|
|
||||||
|
*(default LDAP + SSO mode — see [Standalone mode](#standalone-mode) to skip
|
||||||
|
all of this)*
|
||||||
|
|
||||||
- The SSO Manager (OpenLDAP directory + `/api/discovery`).
|
- The SSO Manager (OpenLDAP directory + `/api/discovery`).
|
||||||
- Downstream hosts joined via ldap-client (SSSD + `AuthorizedKeysCommand`).
|
- Downstream hosts joined via ldap-client (SSSD + `AuthorizedKeysCommand`).
|
||||||
- An LDAP bind account with **write access to the `sshPublicKey` attribute** on
|
- An LDAP bind account with **write access to the `sshPublicKey` attribute** on
|
||||||
|
|||||||
+1
-1
@@ -1,5 +1,5 @@
|
|||||||
title: Jump Host
|
title: Jump Host
|
||||||
description: An SSH jump host for the theta42 stack — LDAP-authenticated, directory-driven host bridging with audit and metrics.
|
description: An SSH jump host for the theta42 stack — directory-driven host bridging with audit and metrics; LDAP + SSO Manager by default, or fully standalone.
|
||||||
url: "https://theta42.github.io"
|
url: "https://theta42.github.io"
|
||||||
baseurl: "/jump-host"
|
baseurl: "/jump-host"
|
||||||
logo: /assets/img/theta42.svg
|
logo: /assets/img/theta42.svg
|
||||||
|
|||||||
@@ -112,6 +112,28 @@ Audit events and counters live in redis. Each event captures: user, auth method,
|
|||||||
mode (grammar/picker), target slug/address/port, channel type, client IP,
|
mode (grammar/picker), target slug/address/port, channel type, client IP,
|
||||||
success + failure reason, downstream host-key fingerprint, timing, and bytes in/out.
|
success + failure reason, downstream host-key fingerprint, timing, and bytes in/out.
|
||||||
|
|
||||||
|
## Standalone mode
|
||||||
|
|
||||||
|
Everything above describes the default backend. Set `standalone.enabled: true`
|
||||||
|
and two modules become conditional facades, swapping their entire
|
||||||
|
implementation at `require` time based on that flag — nothing else in the
|
||||||
|
codebase (`ssh_server.js`, `bridge.js`, `key_inject.js`, `tui_picker.js`, the
|
||||||
|
web UI) changes or even knows which mode it's running in:
|
||||||
|
|
||||||
|
- **`models/user_ldap.js`** — LDAP client, or `models/user_file.js` (an
|
||||||
|
[@simpleworkjs/orm](https://www.npmjs.com/package/@simpleworkjs/orm)-backed
|
||||||
|
store implementing the same `getUser` / `getGroups` / `checkPassword` /
|
||||||
|
`addSshKey` interface).
|
||||||
|
- **`utils/access.js`** — LDAP groups + SSO `/api/discovery`, or
|
||||||
|
`utils/hosts_file.js` (same ORM package, same `accessibleHosts()` interface).
|
||||||
|
In standalone mode there's no group-based authorization: every stored host
|
||||||
|
is accessible to every stored user.
|
||||||
|
|
||||||
|
The ORM is Sequelize underneath, defaulting to a local SQLite file but
|
||||||
|
accepting any Sequelize-supported dialect via `conf.orm`. See
|
||||||
|
[Installation](installation.html#standalone-mode) for config and how to add
|
||||||
|
users/hosts (there's no admin UI for standalone data yet).
|
||||||
|
|
||||||
## Where it sits in the stack
|
## Where it sits in the stack
|
||||||
|
|
||||||
- **[SSO Manager](https://theta42.github.io/sso-manager-node/)** — provides the
|
- **[SSO Manager](https://theta42.github.io/sso-manager-node/)** — provides the
|
||||||
|
|||||||
@@ -74,6 +74,10 @@ changes.
|
|||||||
Targets that don't resolve to a host you're allowed to reach are refused (and
|
Targets that don't resolve to a host you're allowed to reach are refused (and
|
||||||
audited). Raw IPs that aren't a known directory host are denied by default.
|
audited). Raw IPs that aren't a known directory host are denied by default.
|
||||||
|
|
||||||
|
> On a [standalone](architecture.html#standalone-mode) jump host (no LDAP/SSO),
|
||||||
|
> every registered host is reachable by every registered user — there's no
|
||||||
|
> group-based restriction to ask an admin about.
|
||||||
|
|
||||||
## Authentication
|
## Authentication
|
||||||
|
|
||||||
The jump host authenticates **you** against the directory:
|
The jump host authenticates **you** against the directory:
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 90 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 83 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 78 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 72 KiB |
+18
-1
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Home
|
title: Home
|
||||||
description: An SSH jump host for the theta42 stack — one public host, LDAP login, and directory-driven access to every downstream machine you're entitled to.
|
description: An SSH jump host for the theta42 stack — one public host and directory-driven access to every downstream machine you're entitled to; LDAP by default, or fully standalone.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Jump Host
|
# Jump Host
|
||||||
@@ -21,6 +21,21 @@ Part of the theta42 self-hosted identity stack, alongside
|
|||||||
[Proxy](https://theta42.github.io/proxy/), composable with one command via
|
[Proxy](https://theta42.github.io/proxy/), composable with one command via
|
||||||
[theta-env](https://theta42.github.io/theta-env/).
|
[theta-env](https://theta42.github.io/theta-env/).
|
||||||
|
|
||||||
|
## Screenshots
|
||||||
|
|
||||||
|
<a href="images/login.png" target="_blank"><img src="images/login.png" alt="Login" width="49%"></a>
|
||||||
|
<a href="images/dashboard.png" target="_blank"><img src="images/dashboard.png" alt="Dashboard" width="49%"></a>
|
||||||
|
<a href="images/sessions.png" target="_blank"><img src="images/sessions.png" alt="Active sessions" width="49%"></a>
|
||||||
|
<a href="images/audit.png" target="_blank"><img src="images/audit.png" alt="Audit log" width="49%"></a>
|
||||||
|
|
||||||
|
*(click any screenshot to view full size)*
|
||||||
|
|
||||||
|
Don't want to run LDAP or the SSO Manager? **Standalone mode** stores users
|
||||||
|
and hosts in a local SQL database instead (SQLite by default, any
|
||||||
|
Sequelize-supported dialect if you want something else) — same SSH front door,
|
||||||
|
key injection, and audit trail. See
|
||||||
|
[Installation](installation.html#standalone-mode) to get started.
|
||||||
|
|
||||||
## Two ways to connect
|
## Two ways to connect
|
||||||
|
|
||||||
**Direct (WinSCP/SFTP-friendly):**
|
**Direct (WinSCP/SFTP-friendly):**
|
||||||
@@ -79,6 +94,8 @@ This jump host answers both from your directory:
|
|||||||
audit log, per-user/per-host counters
|
audit log, per-user/per-host counters
|
||||||
- **Full audit trail** — who, target, method, result, bytes, duration, and the
|
- **Full audit trail** — who, target, method, result, bytes, duration, and the
|
||||||
downstream host-key fingerprint
|
downstream host-key fingerprint
|
||||||
|
- **Standalone mode** — no LDAP, no SSO Manager; users and hosts live in a
|
||||||
|
local SQL database (Sequelize, any dialect — SQLite by default)
|
||||||
- Packaged like the rest of the stack: one-command Docker, idempotent bare-metal
|
- Packaged like the rest of the stack: one-command Docker, idempotent bare-metal
|
||||||
installer, or bundled in theta-env
|
installer, or bundled in theta-env
|
||||||
|
|
||||||
|
|||||||
+46
-1
@@ -1,7 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Installation
|
title: Installation
|
||||||
description: Install the jump host three ways — bundled in the theta-env stack, standalone Docker, or bare metal — plus the required LDAP write-ACL and port-22 options.
|
description: Install the jump host three ways — bundled in the theta-env stack, standalone Docker, or bare metal — plus standalone mode (no LDAP/SSO), the LDAP write-ACL, and port-22 options.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Installation
|
# Installation
|
||||||
@@ -10,6 +10,51 @@ Three ways to run the jump host, in increasing manual effort. All read their
|
|||||||
config through [@simpleworkjs/conf](https://www.npmjs.com/package/@simpleworkjs/conf)
|
config through [@simpleworkjs/conf](https://www.npmjs.com/package/@simpleworkjs/conf)
|
||||||
(`conf/base.js` < `conf/<NODE_ENV>.js` < the `CONF_SECRETS` file < `app_*` env).
|
(`conf/base.js` < `conf/<NODE_ENV>.js` < the `CONF_SECRETS` file < `app_*` env).
|
||||||
|
|
||||||
|
## Standalone mode (no LDAP/SSO) {#standalone-mode}
|
||||||
|
|
||||||
|
Skip LDAP and the SSO Manager entirely. Not to be confused with "Standalone
|
||||||
|
Docker" below, which is still LDAP + SSO, just run outside theta-env. Set in your secrets/config:
|
||||||
|
|
||||||
|
```js
|
||||||
|
standalone: { enabled: true },
|
||||||
|
orm: { dialect: 'sqlite', storage: './data/standalone.sqlite', logging: false },
|
||||||
|
```
|
||||||
|
|
||||||
|
`orm` is passed straight to Sequelize, so any supported dialect works — SQLite
|
||||||
|
is just the zero-dependency default. Everything downstream of auth (bridging,
|
||||||
|
key injection, the web UI, audit) is unchanged.
|
||||||
|
|
||||||
|
There's no admin UI for standalone users/hosts yet, so add them directly with
|
||||||
|
the ORM models:
|
||||||
|
|
||||||
|
```js
|
||||||
|
const StandaloneUser = require('./models/standalone_user');
|
||||||
|
const StandaloneHost = require('./models/standalone_host');
|
||||||
|
const bcrypt = require('bcrypt');
|
||||||
|
|
||||||
|
await StandaloneUser.create({
|
||||||
|
uid: 'alice',
|
||||||
|
passwordHash: await bcrypt.hash('a real password', 10),
|
||||||
|
sshPublicKeys: ['ssh-ed25519 AAAA... alice@laptop'],
|
||||||
|
groups: [],
|
||||||
|
});
|
||||||
|
|
||||||
|
await StandaloneHost.create({
|
||||||
|
slug: 'host_web01',
|
||||||
|
displayName: 'web01',
|
||||||
|
kind: 'host',
|
||||||
|
metadata: { ip: '10.0.0.5', sshPort: 22 },
|
||||||
|
});
|
||||||
|
```
|
||||||
|
|
||||||
|
Every host in the standalone inventory is reachable by every standalone user —
|
||||||
|
there's no group-based authorization yet (`groups` on `StandaloneUser` is
|
||||||
|
accepted for interface parity with the LDAP path, not enforced).
|
||||||
|
|
||||||
|
The rest of this page (requirements, the LDAP write-ACL, the three install
|
||||||
|
paths) describes the default LDAP + SSO mode — skip it if you're running
|
||||||
|
standalone.
|
||||||
|
|
||||||
## Requirements
|
## Requirements
|
||||||
|
|
||||||
- The [SSO Manager](https://theta42.github.io/sso-manager-node/) (OpenLDAP
|
- The [SSO Manager](https://theta42.github.io/sso-manager-node/) (OpenLDAP
|
||||||
|
|||||||
@@ -10,6 +10,11 @@ const app = express();
|
|||||||
app.set('view engine', 'ejs');
|
app.set('view engine', 'ejs');
|
||||||
app.set('views', require('path').join(__dirname, 'views'));
|
app.set('views', require('path').join(__dirname, 'views'));
|
||||||
|
|
||||||
|
// Per-app values for the shared UI shell (views/top.ejs + views/bottom.ejs).
|
||||||
|
// Set as an app local so every res.render has it, including routes that don't
|
||||||
|
// spread the render router's `values` object.
|
||||||
|
app.locals.ui = require('./utils/ui');
|
||||||
|
|
||||||
app.use(compression());
|
app.use(compression());
|
||||||
app.use(express.json());
|
app.use(express.json());
|
||||||
app.use(express.urlencoded({extended: false}));
|
app.use(express.urlencoded({extended: false}));
|
||||||
|
|||||||
@@ -98,6 +98,21 @@ module.exports = {
|
|||||||
maxEvents: 50000,
|
maxEvents: 50000,
|
||||||
},
|
},
|
||||||
|
|
||||||
|
// Standalone mode: run without LDAP or SSO Manager. When enabled, user
|
||||||
|
// authentication and host discovery use @simpleworkjs/orm-backed stores
|
||||||
|
// (Sequelize, defaulting to SQLite) instead of the directory services.
|
||||||
|
standalone: {
|
||||||
|
enabled: false,
|
||||||
|
},
|
||||||
|
|
||||||
|
// ORM config for standalone mode. Passed through to Sequelize — any dialect
|
||||||
|
// works. Defaults to SQLite for zero-dependency local dev.
|
||||||
|
orm: {
|
||||||
|
dialect: 'sqlite',
|
||||||
|
storage: './data/standalone.sqlite',
|
||||||
|
logging: false,
|
||||||
|
},
|
||||||
|
|
||||||
// Orchestrator-only keys (ignored by the app, read by theta-env).
|
// Orchestrator-only keys (ignored by the app, read by theta-env).
|
||||||
stack: {},
|
stack: {},
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -4,4 +4,12 @@ module.exports = {
|
|||||||
ssh: {
|
ssh: {
|
||||||
hostKeyPath: './data/keys',
|
hostKeyPath: './data/keys',
|
||||||
},
|
},
|
||||||
|
standalone: {
|
||||||
|
enabled: true,
|
||||||
|
},
|
||||||
|
orm: {
|
||||||
|
dialect: 'sqlite',
|
||||||
|
storage: './data/standalone.sqlite',
|
||||||
|
logging: false,
|
||||||
|
},
|
||||||
};
|
};
|
||||||
|
|||||||
+15
-1
@@ -49,4 +49,18 @@ module.exports.authRouter = oidcClient.router;
|
|||||||
require('./audit_event');
|
require('./audit_event');
|
||||||
|
|
||||||
// Idempotent anti-lockout local admin (was the IIFE in user_redis.js).
|
// Idempotent anti-lockout local admin (was the IIFE in user_redis.js).
|
||||||
bootstrapLocalAdmin(Table.models.User, { defaultName: 'jumpadmin' });
|
bootstrapLocalAdmin(Table.models.User, { defaultName: 'jumpadmin' });
|
||||||
|
|
||||||
|
// Standalone mode: initialize @simpleworkjs/orm for local user/host stores.
|
||||||
|
// The ORM must be loaded before any code calls user_ldap or access — both of
|
||||||
|
// which check conf.standalone.enabled at require time and may delegate to the
|
||||||
|
// ORM-backed wrappers. Model registration is synchronous; table sync is async
|
||||||
|
// but the first query will implicitly wait (Sequelize.sync is in-flight).
|
||||||
|
// Export the promise so integration tests can await it before seeding data.
|
||||||
|
let ormReady = Promise.resolve();
|
||||||
|
if (conf.standalone && conf.standalone.enabled) {
|
||||||
|
const { init } = require('@simpleworkjs/orm');
|
||||||
|
const ormConf = conf.orm || { dialect: 'sqlite', storage: './data/standalone.sqlite', logging: false };
|
||||||
|
ormReady = init({ conf: { orm: ormConf }, models: [require('./standalone_user'), require('./standalone_host')] });
|
||||||
|
}
|
||||||
|
module.exports.ormReady = ormReady;
|
||||||
@@ -0,0 +1,30 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// ORM model for standalone-mode hosts. Stored in the configured SQL database
|
||||||
|
// (default SQLite) when conf.standalone.enabled is true. The hosts_file.js
|
||||||
|
// wrapper translates between this model and the accessibleHosts() interface
|
||||||
|
// that ssh_server.js expects.
|
||||||
|
|
||||||
|
const { Model, fields } = require('@simpleworkjs/orm');
|
||||||
|
|
||||||
|
// Patch StringField.toSequelize() to pass through primaryKey (same fix as in
|
||||||
|
// standalone_user.js — see that file for details).
|
||||||
|
if (!fields.StringField.prototype.toSequelize.toString().includes('primaryKey')) {
|
||||||
|
const orig = fields.StringField.prototype.toSequelize;
|
||||||
|
fields.StringField.prototype.toSequelize = function () {
|
||||||
|
const def = orig.call(this);
|
||||||
|
if (this.primaryKey) def.primaryKey = true;
|
||||||
|
return def;
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
class StandaloneHost extends Model {
|
||||||
|
static fields = {
|
||||||
|
slug: { type: 'string', primaryKey: true },
|
||||||
|
displayName: { type: 'string' },
|
||||||
|
kind: { type: 'string', default: 'host' },
|
||||||
|
metadata: { type: 'json', default: {} },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = StandaloneHost;
|
||||||
@@ -0,0 +1,36 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// ORM model for standalone-mode users. Stored in the configured SQL database
|
||||||
|
// (default SQLite) when conf.standalone.enabled is true. The user_file.js
|
||||||
|
// wrapper translates between this model and the LDAP-client interface that
|
||||||
|
// ssh_server.js and key_inject.js expect.
|
||||||
|
|
||||||
|
const { Model, fields } = require('@simpleworkjs/orm');
|
||||||
|
|
||||||
|
// Patch: StringField.toSequelize() and IntegerField.toSequelize() don't pass
|
||||||
|
// through primaryKey / autoIncrement (unlike UUIDField which does). Fix them
|
||||||
|
// so string and int primary keys work.
|
||||||
|
const origStringToSeq = fields.StringField.prototype.toSequelize;
|
||||||
|
fields.StringField.prototype.toSequelize = function () {
|
||||||
|
const def = origStringToSeq.call(this);
|
||||||
|
if (this.primaryKey) def.primaryKey = true;
|
||||||
|
return def;
|
||||||
|
};
|
||||||
|
const origIntToSeq = fields.IntegerField.prototype.toSequelize;
|
||||||
|
fields.IntegerField.prototype.toSequelize = function () {
|
||||||
|
const def = origIntToSeq.call(this);
|
||||||
|
if (this.primaryKey) def.primaryKey = true;
|
||||||
|
if (this.autoIncrement) def.autoIncrement = true;
|
||||||
|
return def;
|
||||||
|
};
|
||||||
|
|
||||||
|
class StandaloneUser extends Model {
|
||||||
|
static fields = {
|
||||||
|
uid: { type: 'string', primaryKey: true },
|
||||||
|
passwordHash: { type: 'string', isPrivate: true },
|
||||||
|
sshPublicKeys: { type: 'json', default: [] },
|
||||||
|
groups: { type: 'json', default: [] },
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = StandaloneUser;
|
||||||
@@ -0,0 +1,65 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// ORM-backed user store for standalone mode. Implements the same interface as
|
||||||
|
// the @simpleworkjs/ldap client so ssh_server.js and key_inject.js work
|
||||||
|
// unchanged: getUser(uid), getGroups(dn), checkPassword(dn, pw), addSshKey(dn, keyLine).
|
||||||
|
//
|
||||||
|
// Users are stored via the StandaloneUser ORM model (Sequelize, any dialect).
|
||||||
|
// DNs are synthetic: uid=<uid>,ou=people,dc=standalone,dc=local — the real
|
||||||
|
// identity is the uid; the DN exists only for interface compatibility with
|
||||||
|
// callers that thread user.dn through to checkPassword / addSshKey.
|
||||||
|
|
||||||
|
const bcrypt = require('bcrypt');
|
||||||
|
const StandaloneUser = require('./standalone_user');
|
||||||
|
|
||||||
|
const DN_PREFIX = 'uid=';
|
||||||
|
const DN_SUFFIX = ',ou=people,dc=standalone,dc=local';
|
||||||
|
|
||||||
|
function dnFor(uid) {
|
||||||
|
return `${DN_PREFIX}${uid}${DN_SUFFIX}`;
|
||||||
|
}
|
||||||
|
|
||||||
|
function uidFromDn(dn) {
|
||||||
|
if (!dn || typeof dn !== 'string') return null;
|
||||||
|
const m = dn.match(/^uid=([^,]+)/);
|
||||||
|
return m ? m[1] : null;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function getUser(uid) {
|
||||||
|
const user = await StandaloneUser.get(uid);
|
||||||
|
if (!user) return null;
|
||||||
|
return {
|
||||||
|
dn: dnFor(user.uid),
|
||||||
|
uid: user.uid,
|
||||||
|
sshPublicKeys: user.sshPublicKeys || [],
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async function getGroups(dn) {
|
||||||
|
const uid = uidFromDn(dn);
|
||||||
|
if (!uid) return [];
|
||||||
|
const user = await StandaloneUser.get(uid);
|
||||||
|
if (!user) return [];
|
||||||
|
return user.groups || [];
|
||||||
|
}
|
||||||
|
|
||||||
|
async function checkPassword(dn, pw) {
|
||||||
|
const uid = uidFromDn(dn);
|
||||||
|
if (!uid) return false;
|
||||||
|
const user = await StandaloneUser.get(uid);
|
||||||
|
if (!user || !user.passwordHash) return false;
|
||||||
|
return bcrypt.compare(pw, user.passwordHash);
|
||||||
|
}
|
||||||
|
|
||||||
|
async function addSshKey(dn, keyLine) {
|
||||||
|
const uid = uidFromDn(dn);
|
||||||
|
if (!uid) return;
|
||||||
|
const user = await StandaloneUser.get(uid);
|
||||||
|
if (!user) return;
|
||||||
|
const keys = [...(user.sshPublicKeys || [])];
|
||||||
|
if (keys.includes(keyLine)) return; // idempotent
|
||||||
|
keys.push(keyLine);
|
||||||
|
await user.update({ sshPublicKeys: keys });
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { getUser, getGroups, checkPassword, addSshKey };
|
||||||
+17
-16
@@ -1,22 +1,23 @@
|
|||||||
'use strict';
|
'use strict';
|
||||||
|
|
||||||
// Thin LDAP helpers — the jump host's entire LDAP surface, now backed by the
|
// User authentication backend — LDAP in production, ORM-backed file store in
|
||||||
// shared @simpleworkjs/ldap package:
|
// standalone mode. Both export the same interface:
|
||||||
// getUser(uid) -> { dn, uid, sshPublicKeys: [] } or null
|
// getUser(uid) -> { dn, uid, sshPublicKeys: [] } or null
|
||||||
// getGroups(dn) -> [cn, ...] (groupOfNames membership)
|
// getGroups(dn) -> [cn, ...]
|
||||||
// checkPassword(dn, pw) -> bool (simple bind as the user)
|
// checkPassword(dn, pw) -> bool
|
||||||
// addSshKey(dn, keyLine) -> void (idempotent multi-value add)
|
// addSshKey(dn, keyLine) -> void (idempotent)
|
||||||
//
|
|
||||||
// Behavior is unchanged from the previous in-tree implementation: posixAccount
|
|
||||||
// user filter, groupOfNames group filter, bind-as-user password check,
|
|
||||||
// TypeOrValueExists treated as success on key add, and the same loose TLS
|
|
||||||
// default ({ rejectUnauthorized: false } when conf.ldap omits tlsOptions).
|
|
||||||
|
|
||||||
const conf = require('@simpleworkjs/conf');
|
const conf = require('@simpleworkjs/conf');
|
||||||
const { createLdapClient } = require('@simpleworkjs/ldap');
|
|
||||||
|
|
||||||
const ldapConf = conf.ldap || {};
|
if (conf.standalone && conf.standalone.enabled) {
|
||||||
module.exports = createLdapClient({
|
// Standalone mode: use the ORM-backed user store.
|
||||||
...ldapConf,
|
module.exports = require('./user_file');
|
||||||
tlsOptions: ldapConf.tlsOptions || { rejectUnauthorized: false },
|
} else {
|
||||||
});
|
// Production mode: use the LDAP directory.
|
||||||
|
const { createLdapClient } = require('@simpleworkjs/ldap');
|
||||||
|
const ldapConf = conf.ldap || {};
|
||||||
|
module.exports = createLdapClient({
|
||||||
|
...ldapConf,
|
||||||
|
tlsOptions: ldapConf.tlsOptions || { rejectUnauthorized: false },
|
||||||
|
});
|
||||||
|
}
|
||||||
Generated
+870
-11
File diff suppressed because it is too large
Load Diff
+7
-5
@@ -1,7 +1,7 @@
|
|||||||
{
|
{
|
||||||
"name": "t42-jump-host",
|
"name": "t42-jump-host",
|
||||||
"version": "1.2.0",
|
"version": "1.6.0",
|
||||||
"description": "SSH jump host for the theta42 stack \u2014 LDAP-authenticated, directory-driven host bridging with audit and metrics",
|
"description": "SSH jump host for the theta42 stack — LDAP-authenticated, directory-driven host bridging with audit and metrics",
|
||||||
"author": [
|
"author": [
|
||||||
{
|
{
|
||||||
"name": "William Mantly",
|
"name": "William Mantly",
|
||||||
@@ -20,11 +20,13 @@
|
|||||||
},
|
},
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@fortawesome/fontawesome-free": "^7.3.0",
|
"@fortawesome/fontawesome-free": "^7.3.0",
|
||||||
"@simpleworkjs/conf": "^1.2.0",
|
|
||||||
"@simpleworkjs/app-stack": "^1.0.0",
|
"@simpleworkjs/app-stack": "^1.0.0",
|
||||||
"@simpleworkjs/ldap": "^1.0.0",
|
"@simpleworkjs/conf": "^1.2.0",
|
||||||
"@simpleworkjs/directory-schema": "^1.0.0",
|
"@simpleworkjs/directory-schema": "^1.0.0",
|
||||||
|
"@simpleworkjs/frontend": "^0.2.5",
|
||||||
|
"@simpleworkjs/ldap": "^1.0.1",
|
||||||
"@simpleworkjs/oidc-client": "^1.0.0",
|
"@simpleworkjs/oidc-client": "^1.0.0",
|
||||||
|
"@simpleworkjs/orm": "^0.2.8",
|
||||||
"bcrypt": "^6.0.0",
|
"bcrypt": "^6.0.0",
|
||||||
"bootstrap": "^5.3.8",
|
"bootstrap": "^5.3.8",
|
||||||
"compression": "^1.8.1",
|
"compression": "^1.8.1",
|
||||||
@@ -32,7 +34,7 @@
|
|||||||
"express": "^5.2.1",
|
"express": "^5.2.1",
|
||||||
"express-rate-limit": "^8.5.2",
|
"express-rate-limit": "^8.5.2",
|
||||||
"jq-repeat": "^2.2.0",
|
"jq-repeat": "^2.2.0",
|
||||||
"jquery": "^3.7.1",
|
"jquery": "^4.0.0",
|
||||||
"ldapts": "^8.1.8",
|
"ldapts": "^8.1.8",
|
||||||
"model-redis": "^1.6.0",
|
"model-redis": "^1.6.0",
|
||||||
"moment": "^2.30.1",
|
"moment": "^2.30.1",
|
||||||
|
|||||||
@@ -18,3 +18,7 @@ body {
|
|||||||
.card-title{
|
.card-title{
|
||||||
font-weight: bold;
|
font-weight: bold;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
.group-required{
|
||||||
|
display: none;
|
||||||
|
}
|
||||||
|
|||||||
@@ -11,7 +11,8 @@ app.jump = (function(app){
|
|||||||
var qs = $.param(query || {});
|
var qs = $.param(query || {});
|
||||||
app.api.get('audit' + (qs ? '?' + qs : ''), cb);
|
app.api.get('audit' + (qs ? '?' + qs : ''), cb);
|
||||||
}
|
}
|
||||||
return {metrics: metrics, sessions: sessions, audit: audit};
|
function hosts(cb){ app.api.get('user/hosts', cb); }
|
||||||
|
return {metrics: metrics, sessions: sessions, audit: audit, hosts: hosts};
|
||||||
})(app);
|
})(app);
|
||||||
|
|
||||||
// Shared render helpers.
|
// Shared render helpers.
|
||||||
|
|||||||
+260
-105
@@ -1,3 +1,12 @@
|
|||||||
|
// Shared client framework for the theta42 apps.
|
||||||
|
//
|
||||||
|
// This file is byte-identical across sso-manager-node, proxy and jump-host —
|
||||||
|
// per-app behaviour comes from the server (the `ui` locals in views/top.ejs and
|
||||||
|
// the /api/user/me response), never from edits to this file. Edit all three
|
||||||
|
// copies together.
|
||||||
|
//
|
||||||
|
// jQuery 4 safe: no $.isFunction, no $.holdReady.
|
||||||
|
|
||||||
var app = {};
|
var app = {};
|
||||||
|
|
||||||
app.pubsub = (function(){
|
app.pubsub = (function(){
|
||||||
@@ -45,7 +54,7 @@ app.pubsub = (function(){
|
|||||||
app.socket = (function(app){
|
app.socket = (function(app){
|
||||||
// $.getScript('/socket.io/socket.io.js')
|
// $.getScript('/socket.io/socket.io.js')
|
||||||
// <script type="text/javascript" src="/socket.io/socket.io.js"></script>
|
// <script type="text/javascript" src="/socket.io/socket.io.js"></script>
|
||||||
|
|
||||||
var socket;
|
var socket;
|
||||||
$(document).ready(function(){
|
$(document).ready(function(){
|
||||||
socket = io({
|
socket = io({
|
||||||
@@ -75,10 +84,26 @@ app.socket = (function(app){
|
|||||||
app.api = (function(app){
|
app.api = (function(app){
|
||||||
var baseURL = '/api/'
|
var baseURL = '/api/'
|
||||||
|
|
||||||
function post(url, data, callback){
|
// post/put/delete are dual-mode: pass a callback for the node-style
|
||||||
if(typeof callback !== 'function') callback = callback2;
|
// (error, data, status) form, or omit it to get a Promise that resolves
|
||||||
|
// with the parsed body and rejects with the error body. get/options return
|
||||||
|
// the jqXHR, which is itself thenable, so `await app.api.get(...)` works.
|
||||||
|
|
||||||
|
function body(method, url, data, callback){
|
||||||
|
if(typeof callback !== 'function'){
|
||||||
|
return new Promise(function(resolve, reject){
|
||||||
|
$.ajax({
|
||||||
|
type: method,
|
||||||
|
url: baseURL+url,
|
||||||
|
headers: { 'auth-token': app.auth.getToken() },
|
||||||
|
data: JSON.stringify(data),
|
||||||
|
contentType: 'application/json; charset=utf-8',
|
||||||
|
dataType: 'json',
|
||||||
|
}).done(resolve).fail(function(xhr){ reject(xhr.responseJSON || {}); });
|
||||||
|
});
|
||||||
|
}
|
||||||
return $.ajax({
|
return $.ajax({
|
||||||
type: 'POST',
|
type: method,
|
||||||
url: baseURL+url,
|
url: baseURL+url,
|
||||||
headers:{
|
headers:{
|
||||||
'auth-token': app.auth.getToken()
|
'auth-token': app.auth.getToken()
|
||||||
@@ -87,40 +112,44 @@ app.api = (function(app){
|
|||||||
contentType: "application/json; charset=utf-8",
|
contentType: "application/json; charset=utf-8",
|
||||||
dataType: "json",
|
dataType: "json",
|
||||||
complete: function(res, text){
|
complete: function(res, text){
|
||||||
callback ? callback(
|
callback(
|
||||||
text !== 'success' ? res.statusText : null,
|
text !== 'success' ? res.statusText : null,
|
||||||
JSON.parse(res.responseText),
|
JSON.parse(res.responseText),
|
||||||
res.status
|
res.status
|
||||||
) : function(){}
|
);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function post(url, data, callback){
|
||||||
|
return body('POST', url, data, callback);
|
||||||
|
}
|
||||||
|
|
||||||
function put(url, data, callback){
|
function put(url, data, callback){
|
||||||
if(typeof callback !== 'function') callback = callback2;
|
return body('PUT', url, data, callback);
|
||||||
return $.ajax({
|
|
||||||
type: 'PUT',
|
|
||||||
url: baseURL+url,
|
|
||||||
headers:{
|
|
||||||
'auth-token': app.auth.getToken()
|
|
||||||
},
|
|
||||||
data: JSON.stringify(data),
|
|
||||||
contentType: "application/json; charset=utf-8",
|
|
||||||
dataType: "json",
|
|
||||||
complete: function(res, text){
|
|
||||||
callback ? callback(
|
|
||||||
text !== 'success' ? res.statusText : null,
|
|
||||||
JSON.parse(res.responseText),
|
|
||||||
res.status
|
|
||||||
) : function(){}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
}
|
}
|
||||||
|
|
||||||
function remove(url, callback, callback2){
|
// Called both as (url, callback) and — from formAJAX, which always passes
|
||||||
if(typeof callback !== 'function') callback = callback2;
|
// the serialized form as the second argument — as (url, data, callback).
|
||||||
|
// No request body is sent either way.
|
||||||
|
function remove(url, data, callback){
|
||||||
|
if(typeof data === 'function'){
|
||||||
|
callback = data;
|
||||||
|
data = undefined;
|
||||||
|
}
|
||||||
|
if(typeof callback !== 'function'){
|
||||||
|
return new Promise(function(resolve, reject){
|
||||||
|
$.ajax({
|
||||||
|
type: 'DELETE',
|
||||||
|
url: baseURL+url,
|
||||||
|
headers: { 'auth-token': app.auth.getToken() },
|
||||||
|
contentType: 'application/json; charset=utf-8',
|
||||||
|
dataType: 'json',
|
||||||
|
}).done(resolve).fail(function(xhr){ reject(xhr.responseJSON || {}); });
|
||||||
|
});
|
||||||
|
}
|
||||||
return $.ajax({
|
return $.ajax({
|
||||||
type: 'delete',
|
type: 'DELETE',
|
||||||
url: baseURL+url,
|
url: baseURL+url,
|
||||||
headers:{
|
headers:{
|
||||||
'auth-token': app.auth.getToken()
|
'auth-token': app.auth.getToken()
|
||||||
@@ -128,11 +157,11 @@ app.api = (function(app){
|
|||||||
contentType: "application/json; charset=utf-8",
|
contentType: "application/json; charset=utf-8",
|
||||||
dataType: "json",
|
dataType: "json",
|
||||||
complete: function(res, text){
|
complete: function(res, text){
|
||||||
callback ? callback(
|
callback(
|
||||||
text !== 'success' ? res.statusText : null,
|
text !== 'success' ? res.statusText : null,
|
||||||
JSON.parse(res.responseText),
|
JSON.parse(res.responseText),
|
||||||
res.status
|
res.status
|
||||||
) : function(){}
|
);
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -179,7 +208,11 @@ app.api = (function(app){
|
|||||||
})(app)
|
})(app)
|
||||||
|
|
||||||
app.auth = (function(app){
|
app.auth = (function(app){
|
||||||
var user = {}
|
// One in-flight/cached GET /api/user/me per page load. Every gating
|
||||||
|
// decision (nav items, per-view forceLogin, group-required elements) reads
|
||||||
|
// this same promise instead of re-fetching.
|
||||||
|
var userPromise = null;
|
||||||
|
|
||||||
function setToken(token){
|
function setToken(token){
|
||||||
localStorage.setItem('APIToken', token);
|
localStorage.setItem('APIToken', token);
|
||||||
}
|
}
|
||||||
@@ -188,18 +221,95 @@ app.auth = (function(app){
|
|||||||
return localStorage.getItem('APIToken');
|
return localStorage.getItem('APIToken');
|
||||||
}
|
}
|
||||||
|
|
||||||
function isLoggedIn(callback){
|
async function getUser(){
|
||||||
if(getToken()){
|
try{
|
||||||
return app.api.get('user/me', function(error, data){
|
return await app.api.get('user/me');
|
||||||
// data now carries effective rights (isAdmin, global, domains).
|
}catch(error){
|
||||||
if(!error) app.auth.user = app.auth.perms = data;
|
if(error && error.status === 401) return null;
|
||||||
return callback(error, data);
|
throw error;
|
||||||
});
|
|
||||||
}else{
|
|
||||||
callback(null, false);
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Cached current user, or false when there's no token at all. Callers that
|
||||||
|
// need a fresh copy (after a login or a profile change) pass force.
|
||||||
|
function loadUser(force){
|
||||||
|
if(force || !userPromise){
|
||||||
|
userPromise = getToken() ? getUser() : Promise.resolve(null);
|
||||||
|
userPromise = userPromise.then(function(user){
|
||||||
|
app.auth.user = app.auth.perms = user || null;
|
||||||
|
return user;
|
||||||
|
});
|
||||||
|
}
|
||||||
|
return userPromise;
|
||||||
|
}
|
||||||
|
|
||||||
|
// The apps report group membership two ways: sso-manager-node returns LDAP
|
||||||
|
// DNs in `memberOf`, the OIDC clients return plain CNs in `groups`. Both
|
||||||
|
// normalise to a list of CNs. `isAdmin` (the clients' effective-rights flag)
|
||||||
|
// is exposed as a synthetic `admin` group so one gating model covers both.
|
||||||
|
function groupCNs(user){
|
||||||
|
var raw = (user && (user.memberOf || user.groups)) || [];
|
||||||
|
if(!Array.isArray(raw)) raw = [raw];
|
||||||
|
var names = raw.map(function(group){
|
||||||
|
return String(group).split(',')[0].replace(/^cn=/i, '');
|
||||||
|
});
|
||||||
|
if(user && user.isAdmin && names.indexOf('admin') === -1) names.push('admin');
|
||||||
|
return names;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function memberOf(groupNameToFind, user){
|
||||||
|
user = user || await loadUser();
|
||||||
|
if(!user) return false;
|
||||||
|
groupNameToFind = Array.isArray(groupNameToFind) ? groupNameToFind : [groupNameToFind];
|
||||||
|
|
||||||
|
return groupCNs(user).some(function(group){
|
||||||
|
return groupNameToFind.includes(group);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// True when the logged-in user is a global admin (per user/me). Sync — only
|
||||||
|
// meaningful once isLoggedIn/forceLogin has resolved.
|
||||||
|
function isAdmin(){
|
||||||
|
return !!(app.auth.perms && app.auth.perms.isAdmin);
|
||||||
|
}
|
||||||
|
|
||||||
|
// Dual-mode: returns a Promise resolving to the user (or false), and calls
|
||||||
|
// an optional node-style callback with the same result.
|
||||||
|
function isLoggedIn(callback){
|
||||||
|
var promise = loadUser().then(function(user){
|
||||||
|
return user || false;
|
||||||
|
});
|
||||||
|
|
||||||
|
if(typeof callback === 'function'){
|
||||||
|
promise.then(function(user){
|
||||||
|
callback(null, user);
|
||||||
|
}, function(error){
|
||||||
|
callback(error, false);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return promise;
|
||||||
|
}
|
||||||
|
|
||||||
|
function logIn(args, callback){
|
||||||
|
app.api.post('auth/login', args, function(error, data){
|
||||||
|
if(data.login){
|
||||||
|
setToken(data.token);
|
||||||
|
}
|
||||||
|
loadUser(true);
|
||||||
|
callback(error, !!data.token);
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
// Clears the session only — the caller decides where to go next (the nav's
|
||||||
|
// Log Out button uses ui.logoutRedirect).
|
||||||
|
function logOut(callback){
|
||||||
|
localStorage.removeItem('APIToken');
|
||||||
|
userPromise = null;
|
||||||
|
app.auth.user = app.auth.perms = null;
|
||||||
|
if(typeof callback === 'function') callback();
|
||||||
|
}
|
||||||
|
|
||||||
// Constrain a redirect target to a same-origin absolute path. Rejects
|
// Constrain a redirect target to a same-origin absolute path. Rejects
|
||||||
// absolute URLs (open redirect), protocol-relative "//host" and "/\host",
|
// absolute URLs (open redirect), protocol-relative "//host" and "/\host",
|
||||||
// and non-path schemes like "javascript:" (XSS). Falls back to "/".
|
// and non-path schemes like "javascript:" (XSS). Falls back to "/".
|
||||||
@@ -230,48 +340,68 @@ app.auth = (function(app){
|
|||||||
return true;
|
return true;
|
||||||
}
|
}
|
||||||
|
|
||||||
// True when the logged-in user is a global admin (per user/me).
|
// Page-level gate. jQuery 4 removed $.holdReady, so an unauthenticated or
|
||||||
function isAdmin(){
|
// unauthorised user is kept off the page by a redirect / an error panel
|
||||||
return !!(app.auth.perms && app.auth.perms.isAdmin);
|
// rather than by pausing document ready.
|
||||||
}
|
//
|
||||||
|
// `requiredGroups` is a group CN or an OR-list of them; the synthetic
|
||||||
function logIn(args, callback){
|
// `admin` group covers the OIDC clients' isAdmin flag.
|
||||||
app.api.post('auth/login', args, function(error, data){
|
async function forceLogin(requiredGroups){
|
||||||
if(data.login){
|
var user = await loadUser();
|
||||||
setToken(data.token);
|
|
||||||
}
|
if(!user){
|
||||||
callback(error, !!data.token);
|
logOut(function(){});
|
||||||
});
|
location.replace('/login?redirect=' + encodeURIComponent(
|
||||||
}
|
location.pathname + location.search
|
||||||
|
));
|
||||||
function logOut(callback){
|
return false;
|
||||||
localStorage.removeItem('APIToken');
|
}
|
||||||
callback();
|
|
||||||
}
|
if(user.onboardingRequired && location.pathname !== '/onboarding'){
|
||||||
|
location.replace('/onboarding');
|
||||||
function forceLogin(){
|
return false;
|
||||||
// jQuery 4 removed $.holdReady; rely on the redirect below to keep an
|
}
|
||||||
// unauthenticated user off the page instead of pausing document ready.
|
|
||||||
app.auth.isLoggedIn(function(error, isLoggedIn){
|
if(requiredGroups && !await memberOf(requiredGroups, user)){
|
||||||
if(error || !isLoggedIn){
|
app.messages.action(
|
||||||
app.auth.logOut(function(){})
|
`<h1>
|
||||||
var path = location.href.replace(location.origin, '');
|
<i class="fa-solid fa-triangle-exclamation"></i>
|
||||||
location.replace('/login?redirect=' + encodeURIComponent(path));
|
<b>You do not have permission to be here.</b>
|
||||||
}
|
<i class="fa-solid fa-triangle-exclamation"></i>
|
||||||
});
|
</h1>`,
|
||||||
|
$('#spa-shell'),
|
||||||
|
'danger',
|
||||||
|
);
|
||||||
|
throw new Error("User does not have permission");
|
||||||
|
}
|
||||||
|
|
||||||
|
return user;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Where to go after a successful login: the ?redirect= query param, or the
|
||||||
|
// legacy /login/<path> suffix form, constrained to a same-origin path. The
|
||||||
|
// suffix form keeps its query string — /login/oauth/authorize?client_id=…
|
||||||
|
// is how the OIDC provider sends an unauthenticated user through login.
|
||||||
function logInRedirect(){
|
function logInRedirect(){
|
||||||
var params = new URLSearchParams(location.search);
|
var params = new URLSearchParams(location.search);
|
||||||
window.location.href = safeInternalPath(params.get('redirect') || '/');
|
var target = params.get('redirect')
|
||||||
|
|| location.href.replace(location.origin + '/login', '')
|
||||||
|
|| '/';
|
||||||
|
window.location.href = safeInternalPath(target);
|
||||||
}
|
}
|
||||||
|
|
||||||
return {
|
return {
|
||||||
getToken: getToken,
|
getToken: getToken,
|
||||||
setToken: setToken,
|
setToken: setToken,
|
||||||
isLoggedIn: isLoggedIn,
|
getUser: getUser,
|
||||||
consumeTokenFragment: consumeTokenFragment,
|
loadUser: loadUser,
|
||||||
|
groupCNs: groupCNs,
|
||||||
|
memberOf: memberOf,
|
||||||
isAdmin: isAdmin,
|
isAdmin: isAdmin,
|
||||||
|
isLoggedIn: isLoggedIn,
|
||||||
|
safeInternalPath: safeInternalPath,
|
||||||
|
consumeTokenFragment: consumeTokenFragment,
|
||||||
|
user: null,
|
||||||
perms: null,
|
perms: null,
|
||||||
logIn: logIn,
|
logIn: logIn,
|
||||||
logOut: logOut,
|
logOut: logOut,
|
||||||
@@ -281,6 +411,11 @@ app.auth = (function(app){
|
|||||||
|
|
||||||
})(app);
|
})(app);
|
||||||
|
|
||||||
|
// Back-compat alias for views that awaited the cached user directly.
|
||||||
|
Object.defineProperty(app.auth, 'asyncUser', {
|
||||||
|
get: function(){ return app.auth.loadUser(); },
|
||||||
|
});
|
||||||
|
|
||||||
app.user = (function(app){
|
app.user = (function(app){
|
||||||
function list(callback){
|
function list(callback){
|
||||||
app.api.get('user/?detail=true', function(error, data){
|
app.api.get('user/?detail=true', function(error, data){
|
||||||
@@ -310,6 +445,8 @@ app.user = (function(app){
|
|||||||
|
|
||||||
})(app);
|
})(app);
|
||||||
|
|
||||||
|
// Local (app-managed) permissions and groups. Only the OIDC-client apps serve
|
||||||
|
// these endpoints; the calls are inert elsewhere.
|
||||||
app.permission = (function(app){
|
app.permission = (function(app){
|
||||||
function list(callback){
|
function list(callback){
|
||||||
app.api.get('permission/', function(error, data){
|
app.api.get('permission/', function(error, data){
|
||||||
@@ -383,29 +520,15 @@ app.util = (function(app){
|
|||||||
return results === null ? '' : decodeURIComponent(results[1].replace(/\+/g, ' '));
|
return results === null ? '' : decodeURIComponent(results[1].replace(/\+/g, ' '));
|
||||||
};
|
};
|
||||||
|
|
||||||
function actionMessage(message, $target, type, callback){
|
// escapeHtml/actionMessage/actionConfirm moved to @simpleworkjs/frontend's
|
||||||
message = message || '';
|
// app.util.escapeHtml and app.messages.action/confirm.
|
||||||
$target = $target.closest('div.card').find('.actionMessage');
|
function escapeHtml(s){
|
||||||
type = type || 'info';
|
return String(s == null ? '' : s)
|
||||||
callback = callback || function(){};
|
.replace(/&/g, '&')
|
||||||
|
.replace(/</g, '<')
|
||||||
if($target.html() === message) return;
|
.replace(/>/g, '>')
|
||||||
|
.replace(/"/g, '"')
|
||||||
if($target.html()){
|
.replace(/'/g, ''');
|
||||||
$target.slideUp('fast', function(){
|
|
||||||
$target.html('')
|
|
||||||
$target.removeClass (function(index, className){
|
|
||||||
return (className.match (/(^|\s)bg-\S+/g) || []).join(' ');
|
|
||||||
});
|
|
||||||
if(message) return actionMessage(message, $target, type, callback);
|
|
||||||
$target.hide()
|
|
||||||
})
|
|
||||||
}else{
|
|
||||||
if(type) $target.addClass('bg-' + type);
|
|
||||||
message = '<span class="align-middle">' + message + '</span><button class="action-close btn btn-sm btn-outline-dark float-end"><i class="fa-solid fa-xmark"></i></button>'
|
|
||||||
$target.html(message).slideDown('fast');
|
|
||||||
}
|
|
||||||
setTimeout(callback,10)
|
|
||||||
}
|
}
|
||||||
|
|
||||||
$.fn.serializeObject = function() {
|
$.fn.serializeObject = function() {
|
||||||
@@ -464,11 +587,41 @@ app.util = (function(app){
|
|||||||
return {
|
return {
|
||||||
downloadFile: downloadFile,
|
downloadFile: downloadFile,
|
||||||
getUrlParameter: getUrlParameter,
|
getUrlParameter: getUrlParameter,
|
||||||
actionMessage: actionMessage
|
escapeHtml: escapeHtml,
|
||||||
}
|
}
|
||||||
})(app);
|
})(app);
|
||||||
|
|
||||||
$( document ).ready(function(){
|
// Reveal every .group-required-<cn> element the current user's groups entitle
|
||||||
|
// them to. Elements carrying .group-required start hidden (styles.css), so a
|
||||||
|
// user who is in no groups — or who isn't logged in — simply never sees them.
|
||||||
|
app.auth.applyGroupVisibility = function(user){
|
||||||
|
var groups = app.auth.groupCNs(user);
|
||||||
|
if(!groups.length) return;
|
||||||
|
|
||||||
|
var style = document.getElementById('group-required-rules');
|
||||||
|
if(!style){
|
||||||
|
style = document.createElement('style');
|
||||||
|
style.id = 'group-required-rules';
|
||||||
|
document.head.appendChild(style);
|
||||||
|
}
|
||||||
|
|
||||||
|
for(var group of groups){
|
||||||
|
try{
|
||||||
|
style.sheet.insertRule(
|
||||||
|
`.group-required-${CSS.escape(group)} { display: revert !important; }`,
|
||||||
|
style.sheet.cssRules.length
|
||||||
|
);
|
||||||
|
}catch(error){
|
||||||
|
// A group whose CN isn't a usable CSS identifier just gates nothing.
|
||||||
|
}
|
||||||
|
}
|
||||||
|
};
|
||||||
|
|
||||||
|
$( document ).ready(async function(){
|
||||||
|
|
||||||
|
// Show content the user's groups entitle them to.
|
||||||
|
app.auth.applyGroupVisibility(await app.auth.loadUser());
|
||||||
|
|
||||||
$('div.row').fadeIn('slow'); //show the page
|
$('div.row').fadeIn('slow'); //show the page
|
||||||
|
|
||||||
//panel button's
|
//panel button's
|
||||||
@@ -489,9 +642,9 @@ $( document ).ready(function(){
|
|||||||
$(this).closest('.card').slideUp('fast');
|
$(this).closest('.card').slideUp('fast');
|
||||||
});
|
});
|
||||||
|
|
||||||
$('.actionMessage').on('click', 'button.action-close', function(event){
|
// action-close click handling is wired by @simpleworkjs/frontend's
|
||||||
app.util.actionMessage(null, $(this));
|
// app.messages.js (delegated on document, so it also covers messages
|
||||||
});
|
// rendered after this ready handler runs).
|
||||||
|
|
||||||
setInterval(()=>{
|
setInterval(()=>{
|
||||||
$('.momentFromNow').each((idx, el)=>{
|
$('.momentFromNow').each((idx, el)=>{
|
||||||
@@ -522,18 +675,20 @@ function formAJAX(btn){
|
|||||||
var method = ($form.attr('method') || 'post').toLowerCase();
|
var method = ($form.attr('method') || 'post').toLowerCase();
|
||||||
|
|
||||||
if($form.validate && !$form.validate()){
|
if($form.validate && !$form.validate()){
|
||||||
app.util.actionMessage('Please fix the form errors.', $form, 'danger');
|
app.messages.action('Please fix the form errors.', $form, 'danger')
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|
||||||
app.util.actionMessage(
|
app.messages.action(
|
||||||
'<div class="spinner-border" role="status"><span class="sr-only">Loading...</span></div>',
|
`<div class="spinner-border" role="status">
|
||||||
|
<span class="visually-hidden">Loading...</span>
|
||||||
|
</div>`,
|
||||||
$form,
|
$form,
|
||||||
'info'
|
'info'
|
||||||
);
|
);
|
||||||
|
|
||||||
app.api[method]($form.attr('action'), formData, function(error, data){
|
app.api[method]($form.attr('action'), formData, function(error, data){
|
||||||
app.util.actionMessage(data.message, $form, error ? 'danger' : 'success'); //re-populate table
|
app.messages.action(data.message, $form, error ? 'danger' : 'success'); //re-populate table
|
||||||
$form.validateClear();
|
$form.validateClear();
|
||||||
if(!error){
|
if(!error){
|
||||||
$form.trigger("reset");
|
$form.trigger("reset");
|
||||||
@@ -541,7 +696,7 @@ function formAJAX(btn){
|
|||||||
}else{
|
}else{
|
||||||
console.log('formAJAX res error', error, data)
|
console.log('formAJAX res error', error, data)
|
||||||
if(data && data.name === 'ObjectValidateError'){
|
if(data && data.name === 'ObjectValidateError'){
|
||||||
app.util.actionMessage('Please fix the form errors', $form, 'danger'); //re-populate table
|
app.messages.action('Please fix the form errors', $form, 'danger'); //re-populate table
|
||||||
}
|
}
|
||||||
if(data && data.keys){
|
if(data && data.keys){
|
||||||
console.log('form key errors', data.keys)
|
console.log('form key errors', data.keys)
|
||||||
|
|||||||
@@ -1,201 +0,0 @@
|
|||||||
( function( $ ) {
|
|
||||||
var settings = {
|
|
||||||
rule: {
|
|
||||||
eq: function(value, options){
|
|
||||||
var compare = $('[name=' + options + ']').val();
|
|
||||||
|
|
||||||
if ( value != compare ) {
|
|
||||||
return "Miss-match";
|
|
||||||
}
|
|
||||||
}
|
|
||||||
},
|
|
||||||
};
|
|
||||||
|
|
||||||
$.fn.validate = function(event) {
|
|
||||||
// let thisSettings = $.extend(true, settings, settingsObj);
|
|
||||||
let hasErrors = false;
|
|
||||||
|
|
||||||
if(this.is('[validate]')) return this.validateField(event);
|
|
||||||
|
|
||||||
if(!this.attr('isValid')){
|
|
||||||
console.log('adding reset event')
|
|
||||||
this.on('reset', function(){
|
|
||||||
$(this).attr('isValid', false);
|
|
||||||
$(this).validateClear();
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
this.find('[validate]').each(function(){
|
|
||||||
if(!$(this).validateField()) hasErrors = true;
|
|
||||||
});
|
|
||||||
|
|
||||||
this.attr('isValid', !hasErrors);
|
|
||||||
|
|
||||||
if(hasErrors && event) event.preventDefault();
|
|
||||||
|
|
||||||
return !hasErrors;
|
|
||||||
};
|
|
||||||
|
|
||||||
$.fn.validateClear = function(){
|
|
||||||
$(this).find('input').each(function(){
|
|
||||||
$(this).removeClass('is-invalid');
|
|
||||||
$(this).removeClass('is-valid');
|
|
||||||
})
|
|
||||||
}
|
|
||||||
|
|
||||||
$.fn.validateField = function(){
|
|
||||||
var attr = this.attr('validate').split(':'); //array of params
|
|
||||||
var rule = attr[0];
|
|
||||||
var options = attr[1];
|
|
||||||
var value = this.val(); //link to input value
|
|
||||||
var message;
|
|
||||||
|
|
||||||
if(this.prop('disabled')) return true;
|
|
||||||
|
|
||||||
|
|
||||||
//checks if field is required, and length
|
|
||||||
if(!isNaN(options) && value.length < options){
|
|
||||||
message = `Must be ${options} characters`;
|
|
||||||
}
|
|
||||||
|
|
||||||
//checks if empty to stop processing
|
|
||||||
if(!isNaN(options) && value.length === 0) {
|
|
||||||
}else if(rule in settings.rule){
|
|
||||||
message = settings.rule[rule].apply(this, [value, options]);
|
|
||||||
}
|
|
||||||
|
|
||||||
this.validateMessage(message)
|
|
||||||
return !message;
|
|
||||||
}
|
|
||||||
|
|
||||||
$.fn.validateMessage = function(message){
|
|
||||||
if(message && message !== true){
|
|
||||||
this.closest('.form-group').find('b.invalid-feedback').html(message);
|
|
||||||
this.addClass('is-invalid');
|
|
||||||
}else{
|
|
||||||
this.removeClass('is-invalid');
|
|
||||||
this.addClass('is-valid');
|
|
||||||
}
|
|
||||||
return this;
|
|
||||||
};
|
|
||||||
|
|
||||||
jQuery.extend({
|
|
||||||
validateSettings: function( settingsObj ) {
|
|
||||||
$.extend( true, settings, settingsObj );
|
|
||||||
},
|
|
||||||
|
|
||||||
validateInit: function( ettingsObj ) {
|
|
||||||
$( '[action]' ).on( 'submit', function ( event, settingsObj ){
|
|
||||||
$( this ).validate( settingsObj, event );
|
|
||||||
});
|
|
||||||
}
|
|
||||||
});
|
|
||||||
|
|
||||||
}( jQuery ));
|
|
||||||
|
|
||||||
// Host / target validation, mirrored from the backend (utils/hostname_validate.js):
|
|
||||||
// a bare hostname or IPv4 address, no protocol / "/" / ":" / whitespace. The
|
|
||||||
// incoming host may be a wildcard ("*.example.com"); the target may not.
|
|
||||||
(function(){
|
|
||||||
var LABEL = /^[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?$/i;
|
|
||||||
// Either one bare label (Docker service names, /etc/hosts entries) or a
|
|
||||||
// dotted hostname with an alphabetic TLD.
|
|
||||||
var HOSTNAME = /^(?=.{1,253}$)(?:(?:[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?\.)+[a-z]{2,63}|[a-z0-9](?:[a-z0-9-]{0,61}[a-z0-9])?)$/i;
|
|
||||||
var FORBIDDEN = /[\s/:]/;
|
|
||||||
|
|
||||||
function isIPv4( value ) {
|
|
||||||
var parts = value.split( '.' );
|
|
||||||
if ( parts.length !== 4 ) return false;
|
|
||||||
return parts.every( function( p ) {
|
|
||||||
return /^(0|[1-9]\d{0,2})$/.test( p ) && Number( p ) <= 255;
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
// Incoming-host pattern: labels may be normal, "*" (one fragment), or "**"
|
|
||||||
// (any number of fragments, incl. a bare "**" global catch-all).
|
|
||||||
function isHostPattern( value ) {
|
|
||||||
if ( value.length > 253 ) return false;
|
|
||||||
return value.split( '.' ).every( function( l ) {
|
|
||||||
return l === '*' || l === '**' || LABEL.test( l );
|
|
||||||
});
|
|
||||||
}
|
|
||||||
|
|
||||||
function forbidden( value ) {
|
|
||||||
return FORBIDDEN.test( value ) || value.includes( '://' );
|
|
||||||
}
|
|
||||||
|
|
||||||
// Incoming host: IPv4 or a wildcard host pattern.
|
|
||||||
function checkHost( value ) {
|
|
||||||
if ( typeof value !== 'string' || value.length === 0 ) return "Required";
|
|
||||||
if ( forbidden( value ) ) return 'No protocol, "/", or ":"';
|
|
||||||
if ( isIPv4( value ) || isHostPattern( value ) ) return;
|
|
||||||
return "Enter a valid host or wildcard (*, **)";
|
|
||||||
}
|
|
||||||
|
|
||||||
// Downstream target: IPv4 or a strict hostname, no wildcard.
|
|
||||||
function checkTarget( value ) {
|
|
||||||
if ( typeof value !== 'string' || value.length === 0 ) return "Required";
|
|
||||||
if ( forbidden( value ) ) return 'No protocol, "/", or ":"';
|
|
||||||
if ( isIPv4( value ) || HOSTNAME.test( value ) ) return;
|
|
||||||
return "Enter a valid hostname or IP";
|
|
||||||
}
|
|
||||||
|
|
||||||
$.validateSettings({
|
|
||||||
rule:{
|
|
||||||
ip: function( value ) {
|
|
||||||
value = value.split( '.' );
|
|
||||||
|
|
||||||
if ( value.length != 4 ) {
|
|
||||||
return "Malformed IP";
|
|
||||||
}
|
|
||||||
|
|
||||||
$.each( value, function( key, value ) {
|
|
||||||
if( value > 255 || value < 0 ) {
|
|
||||||
return "Malformed IP";
|
|
||||||
}
|
|
||||||
});
|
|
||||||
},
|
|
||||||
|
|
||||||
// Incoming host name — hostname, IPv4, or wildcard pattern (*, **).
|
|
||||||
host: function( value ) {
|
|
||||||
return checkHost( value );
|
|
||||||
},
|
|
||||||
|
|
||||||
// Downstream target — hostname or IPv4, no wildcard.
|
|
||||||
target: function( value ) {
|
|
||||||
return checkTarget( value );
|
|
||||||
},
|
|
||||||
|
|
||||||
// Back-compat alias (no wildcard).
|
|
||||||
hostname: function( value ) {
|
|
||||||
return checkTarget( value );
|
|
||||||
},
|
|
||||||
|
|
||||||
user: function( value ) {
|
|
||||||
var reg = /^[a-z0-9\_\-\@\.]{1,32}$/;
|
|
||||||
if ( reg.test( value ) === false ) {
|
|
||||||
return "Invalid";
|
|
||||||
}
|
|
||||||
},
|
|
||||||
|
|
||||||
// Mirrors utils/password_policy.js: >= 8 chars, and either 12+ chars
|
|
||||||
// or at least 3 of {lowercase, uppercase, number, symbol}.
|
|
||||||
password: function( value ) {
|
|
||||||
if ( typeof value !== 'string' || value.length < 8 ) {
|
|
||||||
return "Password must be at least 8 characters";
|
|
||||||
}
|
|
||||||
if ( value.length >= 12 ) return;
|
|
||||||
|
|
||||||
var classes = 0;
|
|
||||||
if ( /[a-z]/.test( value ) ) classes++;
|
|
||||||
if ( /[A-Z]/.test( value ) ) classes++;
|
|
||||||
if ( /[0-9]/.test( value ) ) classes++;
|
|
||||||
if ( /[^A-Za-z0-9]/.test( value ) ) classes++;
|
|
||||||
|
|
||||||
if ( classes < 3 ) {
|
|
||||||
return "Use 3 of: lowercase, uppercase, number, symbol (or 12+ chars)";
|
|
||||||
}
|
|
||||||
}
|
|
||||||
}
|
|
||||||
});
|
|
||||||
})();
|
|
||||||
@@ -21,7 +21,7 @@ const values = {
|
|||||||
// as the sibling apps), and the app's own JS/CSS/img from public/.
|
// as the sibling apps), and the app's own JS/CSS/img from public/.
|
||||||
mountStaticModules(router, {
|
mountStaticModules(router, {
|
||||||
root: path.join(__dirname, '..'),
|
root: path.join(__dirname, '..'),
|
||||||
deps: ['bootstrap', 'mustache', 'jquery', '@fortawesome', 'moment', 'jq-repeat'],
|
deps: ['bootstrap', 'mustache', 'jquery', '@fortawesome', 'moment', 'jq-repeat', '@simpleworkjs/frontend'],
|
||||||
});
|
});
|
||||||
|
|
||||||
// Liveness probe — no auth.
|
// Liveness probe — no auth.
|
||||||
|
|||||||
@@ -5,6 +5,7 @@
|
|||||||
|
|
||||||
const router = require('express').Router();
|
const router = require('express').Router();
|
||||||
const { isAdmin } = require('../middleware/auth');
|
const { isAdmin } = require('../middleware/auth');
|
||||||
|
const access = require('../utils/access');
|
||||||
|
|
||||||
router.get('/me', (req, res) => {
|
router.get('/me', (req, res) => {
|
||||||
res.json({
|
res.json({
|
||||||
@@ -14,4 +15,16 @@ router.get('/me', (req, res) => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// The hosts this session can SSH to — every host for an admin, otherwise the
|
||||||
|
// same group-based resolution the SSH front door uses (accessibleHosts),
|
||||||
|
// fed the OIDC session's already-known groups instead of an LDAP lookup.
|
||||||
|
router.get('/hosts', async (req, res, next) => {
|
||||||
|
try {
|
||||||
|
const hosts = isAdmin(req)
|
||||||
|
? await access.allHosts()
|
||||||
|
: await access.accessibleHosts({ uid: req.user && req.user.username, groups: req.groups || [] });
|
||||||
|
res.json({ results: hosts });
|
||||||
|
} catch (err) { next(err); }
|
||||||
|
});
|
||||||
|
|
||||||
module.exports = router;
|
module.exports = router;
|
||||||
|
|||||||
@@ -147,12 +147,20 @@ async function resolveAndConnect(state, record, { onHostKey } = {}) {
|
|||||||
function fail(reason) { const e = new Error(reason); e.reason = reason; return e; }
|
function fail(reason) { const e = new Error(reason); e.reason = reason; return e; }
|
||||||
|
|
||||||
async function runGrammar(session, client, state) {
|
async function runGrammar(session, client, state) {
|
||||||
const record = await audit.create({ uid: state.uid, authMethod: state.authMethod, clientIp: state.clientIp, mode: 'grammar' });
|
// Register session listeners IMMEDIATELY — before any async work.
|
||||||
|
// The client sends exec/shell requests right after opening the session;
|
||||||
// Deferred upstream — attach the bridge NOW, resolve/reject after connect.
|
// if we await audit.create() first, those requests arrive before the
|
||||||
|
// listeners are registered and ssh2 rejects them with CHANNEL_FAILURE.
|
||||||
let resolveUp, rejectUp;
|
let resolveUp, rejectUp;
|
||||||
const upstreamPromise = new Promise((res, rej) => { resolveUp = res; rejectUp = rej; });
|
const upstreamPromise = new Promise((res, rej) => { resolveUp = res; rejectUp = rej; });
|
||||||
attachSession(session, upstreamPromise, record);
|
const dummyAudit = { patch() {}, finish() {}, event: {} };
|
||||||
|
attachSession(session, upstreamPromise, dummyAudit);
|
||||||
|
|
||||||
|
const record = await audit.create({ uid: state.uid, authMethod: state.authMethod, clientIp: state.clientIp, mode: 'grammar' });
|
||||||
|
// Wire the real audit record into the already-attached session.
|
||||||
|
dummyAudit.patch = (...a) => record.patch(...a);
|
||||||
|
dummyAudit.finish = (...a) => record.finish(...a);
|
||||||
|
Object.defineProperty(dummyAudit, 'event', { get: () => record.event });
|
||||||
|
|
||||||
try {
|
try {
|
||||||
const { upstream, host, endpoint } = await resolveAndConnect(state, record, {
|
const { upstream, host, endpoint } = await resolveAndConnect(state, record, {
|
||||||
@@ -280,7 +288,7 @@ function start() {
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
const port = (conf.ssh && conf.ssh.listenPort) || 2222;
|
const port = (conf.ssh && conf.ssh.listenPort) ?? 2222;
|
||||||
const host = (conf.ssh && conf.ssh.listenHost) || '0.0.0.0';
|
const host = (conf.ssh && conf.ssh.listenHost) || '0.0.0.0';
|
||||||
server.listen(port, host, () => {
|
server.listen(port, host, () => {
|
||||||
console.log(`[ssh] jump host listening on ${host}:${server.address().port}`);
|
console.log(`[ssh] jump host listening on ${host}:${server.address().port}`);
|
||||||
|
|||||||
@@ -0,0 +1,232 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// End-to-end standalone SSH test: a real downstream sshd, the full jump host
|
||||||
|
// SSH server (ssh_server.js), and an SSH client. Authentication and host
|
||||||
|
// discovery use the ORM-backed standalone stores (temp file SQLite).
|
||||||
|
//
|
||||||
|
// Follows the same hermetic pattern as ssh_bridge.test.js but exercises the
|
||||||
|
// full stack: conf → ORM → user_ldap facade → ssh_server → bridge.
|
||||||
|
|
||||||
|
process.env.NODE_ENV = 'test';
|
||||||
|
|
||||||
|
const { test, before, after } = require('node:test');
|
||||||
|
const assert = require('node:assert');
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const os = require('os');
|
||||||
|
const { Server, Client, utils } = require('ssh2');
|
||||||
|
const bcrypt = require('bcrypt');
|
||||||
|
const conf = require('@simpleworkjs/conf');
|
||||||
|
|
||||||
|
// ── Conf must be set BEFORE any module that checks conf.standalone.enabled ──
|
||||||
|
|
||||||
|
const tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'jump-host-standalone-'));
|
||||||
|
const dbPath = path.join(tmpDir, 'test.sqlite');
|
||||||
|
|
||||||
|
conf.standalone = { enabled: true };
|
||||||
|
conf.orm = { dialect: 'sqlite', storage: dbPath, logging: false };
|
||||||
|
conf.ssh = {
|
||||||
|
listenHost: '127.0.0.1',
|
||||||
|
listenPort: 0,
|
||||||
|
hostKeyPath: path.join(tmpDir, 'keys'),
|
||||||
|
passwordAuth: 'all',
|
||||||
|
keyComment: 'jump-host-test',
|
||||||
|
defaultPort: 22,
|
||||||
|
connectTimeoutMs: 5000,
|
||||||
|
maxSessions: 10,
|
||||||
|
};
|
||||||
|
conf.redis = { prefix: 'jump_host_test_standalone_' };
|
||||||
|
conf.audit = { maxEvents: 100 };
|
||||||
|
|
||||||
|
// ── Require models/index FIRST so it initializes the ORM exactly once.
|
||||||
|
// This also registers the standalone models. We await ormReady before
|
||||||
|
// seeding data, then start the SSH server. ──
|
||||||
|
|
||||||
|
const models = require('../../models');
|
||||||
|
const StandaloneUser = require('../../models/standalone_user');
|
||||||
|
const StandaloneHost = require('../../models/standalone_host');
|
||||||
|
|
||||||
|
let downstream, downstreamPort, jump, jumpPort;
|
||||||
|
let testUserKey;
|
||||||
|
|
||||||
|
function startDownstream() {
|
||||||
|
return new Promise((resolve) => {
|
||||||
|
const { private: hostKey } = utils.generateKeyPairSync('ed25519');
|
||||||
|
const srv = new Server({ hostKeys: [hostKey] }, (client) => {
|
||||||
|
client.on('authentication', (ctx) => ctx.accept());
|
||||||
|
client.on('ready', () => {
|
||||||
|
client.on('session', (accept) => {
|
||||||
|
const session = accept();
|
||||||
|
session.on('pty', (a) => a && a());
|
||||||
|
session.on('shell', (a) => {
|
||||||
|
const ch = a();
|
||||||
|
ch.write('downstream-shell-ready\n');
|
||||||
|
ch.on('data', (d) => ch.write('echo:' + d));
|
||||||
|
});
|
||||||
|
session.on('exec', (a, r, info) => {
|
||||||
|
const ch = a();
|
||||||
|
ch.write(`ran:${info.command}`);
|
||||||
|
ch.exit(0);
|
||||||
|
ch.end();
|
||||||
|
});
|
||||||
|
session.on('subsystem', (a, r, info) => {
|
||||||
|
if (info.name !== 'sftp') return r && r();
|
||||||
|
const ch = a();
|
||||||
|
ch.on('data', (d) => ch.write(Buffer.concat([Buffer.from('sftp:'), d])));
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
});
|
||||||
|
srv.listen(0, '127.0.0.1', () => resolve(srv));
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
before(async () => {
|
||||||
|
// 1. Start downstream.
|
||||||
|
downstream = await startDownstream();
|
||||||
|
downstreamPort = downstream.address().port;
|
||||||
|
|
||||||
|
// 2. Wait for the ORM to finish syncing tables (init was called by models/index
|
||||||
|
// at require time — we just need the tables to exist before seeding).
|
||||||
|
await models.ormReady;
|
||||||
|
|
||||||
|
// 3. Seed test data.
|
||||||
|
const userKeyPair = utils.generateKeyPairSync('ed25519');
|
||||||
|
testUserKey = userKeyPair.private;
|
||||||
|
const userPubKey = utils.parseKey(userKeyPair.private);
|
||||||
|
const userPubLine = `${userPubKey.type} ${userPubKey.getPublicSSH().toString('base64')} testuser@test`;
|
||||||
|
|
||||||
|
const passwordHash = await bcrypt.hash('testpass', 4);
|
||||||
|
|
||||||
|
await StandaloneUser.create({
|
||||||
|
uid: 'testuser',
|
||||||
|
passwordHash,
|
||||||
|
sshPublicKeys: [userPubLine],
|
||||||
|
groups: ['admin'],
|
||||||
|
});
|
||||||
|
|
||||||
|
await StandaloneHost.create({
|
||||||
|
slug: 'host_test',
|
||||||
|
displayName: 'Test Downstream',
|
||||||
|
kind: 'host',
|
||||||
|
metadata: { address: `ssh://127.0.0.1:${downstreamPort}`, ip: '127.0.0.1', sshPort: downstreamPort },
|
||||||
|
});
|
||||||
|
|
||||||
|
// 4. Start the jump host SSH server.
|
||||||
|
const sshServer = require('../../services/ssh_server');
|
||||||
|
jump = sshServer.start();
|
||||||
|
await new Promise((resolve) => {
|
||||||
|
const check = () => {
|
||||||
|
const addr = jump.address();
|
||||||
|
if (addr) { jumpPort = addr.port; resolve(); }
|
||||||
|
else setTimeout(check, 10);
|
||||||
|
};
|
||||||
|
check();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
after(() => {
|
||||||
|
try { downstream && downstream.close(); } catch (_) {}
|
||||||
|
try { jump && jump.close(); } catch (_) {}
|
||||||
|
try { models.redisClient.destroy(); } catch (_) {}
|
||||||
|
try { fs.rmSync(tmpDir, { recursive: true, force: true }); } catch (_) {}
|
||||||
|
});
|
||||||
|
|
||||||
|
process.on('unhandledRejection', () => {});
|
||||||
|
|
||||||
|
function connectJump(opts = {}) {
|
||||||
|
const conn = new Client();
|
||||||
|
const connectOpts = {
|
||||||
|
host: '127.0.0.1',
|
||||||
|
port: jumpPort,
|
||||||
|
username: opts.username || 'testuser_-_host_test',
|
||||||
|
...opts,
|
||||||
|
};
|
||||||
|
return {
|
||||||
|
conn,
|
||||||
|
ready: new Promise((res, rej) => {
|
||||||
|
conn.on('ready', res).on('error', rej).connect(connectOpts);
|
||||||
|
}),
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
// ── Tests ──
|
||||||
|
|
||||||
|
test('public key auth + grammar mode exec', async () => {
|
||||||
|
const { conn, ready } = connectJump({ privateKey: testUserKey });
|
||||||
|
await ready;
|
||||||
|
const out = await new Promise((resolve, reject) => {
|
||||||
|
conn.exec('hello-world', (err, stream) => {
|
||||||
|
if (err) return reject(err);
|
||||||
|
let buf = '';
|
||||||
|
stream.on('data', (d) => { buf += d; }).on('close', () => resolve(buf));
|
||||||
|
});
|
||||||
|
});
|
||||||
|
conn.end();
|
||||||
|
assert.match(out, /ran:hello-world/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('public key auth + grammar mode shell', async () => {
|
||||||
|
const { conn, ready } = connectJump({ privateKey: testUserKey });
|
||||||
|
await ready;
|
||||||
|
const out = await new Promise((resolve, reject) => {
|
||||||
|
conn.shell((err, stream) => {
|
||||||
|
if (err) return reject(err);
|
||||||
|
let buf = '';
|
||||||
|
stream.on('data', (d) => {
|
||||||
|
buf += d;
|
||||||
|
if (buf.includes('echo:ping')) resolve(buf);
|
||||||
|
});
|
||||||
|
setTimeout(() => stream.write('ping'), 150);
|
||||||
|
setTimeout(() => resolve(buf), 5000);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
conn.end();
|
||||||
|
assert.match(out, /downstream-shell-ready/);
|
||||||
|
assert.match(out, /echo:ping/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('password auth + grammar mode exec', async () => {
|
||||||
|
const { conn, ready } = connectJump({
|
||||||
|
username: 'testuser_-_host_test',
|
||||||
|
password: 'testpass',
|
||||||
|
});
|
||||||
|
await ready;
|
||||||
|
const out = await new Promise((resolve, reject) => {
|
||||||
|
conn.exec('pw-test', (err, stream) => {
|
||||||
|
if (err) return reject(err);
|
||||||
|
let buf = '';
|
||||||
|
stream.on('data', (d) => { buf += d; }).on('close', () => resolve(buf));
|
||||||
|
});
|
||||||
|
});
|
||||||
|
conn.end();
|
||||||
|
assert.match(out, /ran:pw-test/);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('password auth denied with wrong password', async () => {
|
||||||
|
const conn = new Client();
|
||||||
|
const result = await new Promise((resolve) => {
|
||||||
|
conn.on('ready', () => resolve('unexpected-ready'));
|
||||||
|
conn.on('error', () => resolve('auth-failed'));
|
||||||
|
conn.connect({
|
||||||
|
host: '127.0.0.1', port: jumpPort,
|
||||||
|
username: 'testuser_-_host_test',
|
||||||
|
password: 'wrongpass',
|
||||||
|
});
|
||||||
|
});
|
||||||
|
assert.strictEqual(result, 'auth-failed');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('unknown user rejected', async () => {
|
||||||
|
const conn = new Client();
|
||||||
|
const result = await new Promise((resolve) => {
|
||||||
|
conn.on('ready', () => resolve('unexpected-ready'));
|
||||||
|
conn.on('error', () => resolve('auth-failed'));
|
||||||
|
conn.connect({
|
||||||
|
host: '127.0.0.1', port: jumpPort,
|
||||||
|
username: 'nobody_-_host_test',
|
||||||
|
password: 'testpass',
|
||||||
|
});
|
||||||
|
});
|
||||||
|
assert.strictEqual(result, 'auth-failed');
|
||||||
|
});
|
||||||
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
const { test } = require('node:test');
|
const { test } = require('node:test');
|
||||||
const assert = require('node:assert');
|
const assert = require('node:assert');
|
||||||
const { accessibleHosts, clearCache } = require('../../utils/access');
|
const { accessibleHosts, allHosts, clearCache } = require('../../utils/access');
|
||||||
|
|
||||||
function stubLdap(groups) {
|
function stubLdap(groups) {
|
||||||
return { getGroups: async () => groups };
|
return { getGroups: async () => groups };
|
||||||
@@ -54,6 +54,32 @@ test('caches per uid', async () => {
|
|||||||
assert.strictEqual(calls, 1);
|
assert.strictEqual(calls, 1);
|
||||||
});
|
});
|
||||||
|
|
||||||
|
test('accepts pre-resolved groups (web UI/OIDC session) without calling ldap.getGroups', async () => {
|
||||||
|
clearCache();
|
||||||
|
let ldapCalled = false;
|
||||||
|
const user = { uid: 'erin', groups: ['host_web01_access'] };
|
||||||
|
const fetchImpl = stubFetch({
|
||||||
|
host_web01_access: [{ id: '5', kind: 'host', slug: 'host_web01' }],
|
||||||
|
});
|
||||||
|
const ldap = { getGroups: async () => { ldapCalled = true; return []; } };
|
||||||
|
const hosts = await accessibleHosts(user, { fetchImpl, ldap });
|
||||||
|
assert.deepStrictEqual(hosts.map((h) => h.id), ['5']);
|
||||||
|
assert.strictEqual(ldapCalled, false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('allHosts fetches the whole host inventory with no group filter', async () => {
|
||||||
|
const fetchImpl = async (url) => {
|
||||||
|
assert.ok(!url.includes('group='), 'must not filter by group');
|
||||||
|
assert.ok(url.includes('kind=host'));
|
||||||
|
return { ok: true, json: async () => ({ results: [
|
||||||
|
{ id: '1', kind: 'host', slug: 'host_a' },
|
||||||
|
{ id: '2', kind: 'host', slug: 'host_b' },
|
||||||
|
] }) };
|
||||||
|
};
|
||||||
|
const hosts = await allHosts({ fetchImpl });
|
||||||
|
assert.deepStrictEqual(hosts.map((h) => h.id).sort(), ['1', '2']);
|
||||||
|
});
|
||||||
|
|
||||||
test('a bare-array response (envelope drift) is treated as a failed group, not silently []', async () => {
|
test('a bare-array response (envelope drift) is treated as a failed group, not silently []', async () => {
|
||||||
clearCache();
|
clearCache();
|
||||||
const user = { uid: 'dave', dn: 'd' };
|
const user = { uid: 'dave', dn: 'd' };
|
||||||
|
|||||||
@@ -0,0 +1,87 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// Unit tests for the ORM-backed host inventory (utils/hosts_file.js).
|
||||||
|
// Uses a temp file SQLite database — no external services needed.
|
||||||
|
|
||||||
|
process.env.NODE_ENV = 'test';
|
||||||
|
|
||||||
|
const { test, before, after } = require('node:test');
|
||||||
|
const assert = require('node:assert');
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const os = require('os');
|
||||||
|
const conf = require('@simpleworkjs/conf');
|
||||||
|
const { init } = require('@simpleworkjs/orm');
|
||||||
|
const StandaloneHost = require('../../models/standalone_host');
|
||||||
|
|
||||||
|
let tmpDir;
|
||||||
|
let hostsFile; // required after ORM init
|
||||||
|
|
||||||
|
before(async () => {
|
||||||
|
// Unique temp DB so this test file doesn't collide with other ORM tests.
|
||||||
|
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'jump-host-test-hostfile-'));
|
||||||
|
const dbPath = path.join(tmpDir, 'test.sqlite');
|
||||||
|
|
||||||
|
conf.standalone = { enabled: true };
|
||||||
|
conf.orm = { dialect: 'sqlite', storage: dbPath, logging: false };
|
||||||
|
|
||||||
|
await init({ conf: { orm: conf.orm }, models: [StandaloneHost] });
|
||||||
|
|
||||||
|
await StandaloneHost.create({
|
||||||
|
slug: 'host_web01',
|
||||||
|
displayName: 'Web Server 01',
|
||||||
|
kind: 'host',
|
||||||
|
metadata: { address: 'ssh://10.0.0.10:22', ip: '10.0.0.10', sshPort: 22 },
|
||||||
|
});
|
||||||
|
await StandaloneHost.create({
|
||||||
|
slug: 'host_db',
|
||||||
|
displayName: 'Database Server',
|
||||||
|
kind: 'host',
|
||||||
|
metadata: { address: 'ssh://10.0.0.20:22', ip: '10.0.0.20', sshPort: 22 },
|
||||||
|
});
|
||||||
|
await StandaloneHost.create({
|
||||||
|
slug: 'app_gitea',
|
||||||
|
displayName: 'Gitea',
|
||||||
|
kind: 'service',
|
||||||
|
metadata: { url: 'https://gitea.internal' },
|
||||||
|
});
|
||||||
|
|
||||||
|
hostsFile = require('../../utils/hosts_file');
|
||||||
|
});
|
||||||
|
|
||||||
|
after(() => {
|
||||||
|
try { fs.rmSync(tmpDir, { recursive: true, force: true }); } catch (_) {}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('accessibleHosts returns all hosts', async () => {
|
||||||
|
const hosts = await hostsFile.accessibleHosts({ uid: 'alice' });
|
||||||
|
assert.strictEqual(hosts.length, 2);
|
||||||
|
const slugs = hosts.map((h) => h.slug).sort();
|
||||||
|
assert.deepStrictEqual(slugs, ['host_db', 'host_web01']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('accessibleHosts filters to kind=host', async () => {
|
||||||
|
const hosts = await hostsFile.accessibleHosts({ uid: 'alice' });
|
||||||
|
const kinds = [...new Set(hosts.map((h) => h.kind))];
|
||||||
|
assert.deepStrictEqual(kinds, ['host']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('accessibleHosts returns host resources with expected shape', async () => {
|
||||||
|
const hosts = await hostsFile.accessibleHosts({ uid: 'alice' });
|
||||||
|
const web = hosts.find((h) => h.slug === 'host_web01');
|
||||||
|
assert.ok(web);
|
||||||
|
assert.strictEqual(web.id, 'host_web01');
|
||||||
|
assert.strictEqual(web.displayName, 'Web Server 01');
|
||||||
|
assert.strictEqual(web.metadata.ip, '10.0.0.10');
|
||||||
|
assert.strictEqual(web.metadata.sshPort, 22);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('accessibleHosts returns empty array when no hosts exist', async () => {
|
||||||
|
// Delete all hosts and verify empty result.
|
||||||
|
const all = await StandaloneHost.list();
|
||||||
|
for (const h of all) {
|
||||||
|
await h.delete({ force: true });
|
||||||
|
}
|
||||||
|
const hosts = await hostsFile.accessibleHosts({ uid: 'alice' });
|
||||||
|
assert.deepStrictEqual(hosts, []);
|
||||||
|
});
|
||||||
@@ -0,0 +1,113 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// Unit tests for the ORM-backed user store (models/user_file.js).
|
||||||
|
// Uses a temp file SQLite database — no external services needed.
|
||||||
|
|
||||||
|
process.env.NODE_ENV = 'test';
|
||||||
|
|
||||||
|
const { test, before, after } = require('node:test');
|
||||||
|
const assert = require('node:assert');
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const os = require('os');
|
||||||
|
const bcrypt = require('bcrypt');
|
||||||
|
const conf = require('@simpleworkjs/conf');
|
||||||
|
const { init } = require('@simpleworkjs/orm');
|
||||||
|
const StandaloneUser = require('../../models/standalone_user');
|
||||||
|
|
||||||
|
let testPasswordHash;
|
||||||
|
let tmpDir;
|
||||||
|
let userFile; // required after ORM init
|
||||||
|
|
||||||
|
before(async () => {
|
||||||
|
// Unique temp DB so this test file doesn't collide with other ORM tests.
|
||||||
|
tmpDir = fs.mkdtempSync(path.join(os.tmpdir(), 'jump-host-test-userfile-'));
|
||||||
|
const dbPath = path.join(tmpDir, 'test.sqlite');
|
||||||
|
|
||||||
|
conf.standalone = { enabled: true };
|
||||||
|
conf.orm = { dialect: 'sqlite', storage: dbPath, logging: false };
|
||||||
|
|
||||||
|
await init({ conf: { orm: conf.orm }, models: [StandaloneUser] });
|
||||||
|
|
||||||
|
testPasswordHash = await bcrypt.hash('testpass', 4);
|
||||||
|
|
||||||
|
await StandaloneUser.create({
|
||||||
|
uid: 'alice',
|
||||||
|
passwordHash: testPasswordHash,
|
||||||
|
sshPublicKeys: ['ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI... alice@laptop'],
|
||||||
|
groups: ['admin', 'developers'],
|
||||||
|
});
|
||||||
|
|
||||||
|
// Now that the ORM is initialized and conf.standalone is set, require the
|
||||||
|
// facade. It checks conf.standalone.enabled at require time.
|
||||||
|
userFile = require('../../models/user_file');
|
||||||
|
});
|
||||||
|
|
||||||
|
after(() => {
|
||||||
|
try { fs.rmSync(tmpDir, { recursive: true, force: true }); } catch (_) {}
|
||||||
|
});
|
||||||
|
|
||||||
|
test('getUser returns user with synthesized dn and keys', async () => {
|
||||||
|
const user = await userFile.getUser('alice');
|
||||||
|
assert.ok(user);
|
||||||
|
assert.strictEqual(user.uid, 'alice');
|
||||||
|
assert.strictEqual(user.dn, 'uid=alice,ou=people,dc=standalone,dc=local');
|
||||||
|
assert.deepStrictEqual(user.sshPublicKeys, ['ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI... alice@laptop']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('getUser returns null for unknown uid', async () => {
|
||||||
|
const user = await userFile.getUser('nobody');
|
||||||
|
assert.strictEqual(user, null);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('getGroups returns user groups', async () => {
|
||||||
|
const groups = await userFile.getGroups('uid=alice,ou=people,dc=standalone,dc=local');
|
||||||
|
assert.deepStrictEqual(groups, ['admin', 'developers']);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('getGroups returns empty array for unknown dn', async () => {
|
||||||
|
const groups = await userFile.getGroups('uid=nobody,ou=people,dc=standalone,dc=local');
|
||||||
|
assert.deepStrictEqual(groups, []);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('getGroups returns empty array for malformed dn', async () => {
|
||||||
|
const groups = await userFile.getGroups('not-a-dn');
|
||||||
|
assert.deepStrictEqual(groups, []);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('checkPassword returns true for correct password', async () => {
|
||||||
|
const ok = await userFile.checkPassword('uid=alice,ou=people,dc=standalone,dc=local', 'testpass');
|
||||||
|
assert.strictEqual(ok, true);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('checkPassword returns false for wrong password', async () => {
|
||||||
|
const ok = await userFile.checkPassword('uid=alice,ou=people,dc=standalone,dc=local', 'wrongpass');
|
||||||
|
assert.strictEqual(ok, false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('checkPassword returns false for unknown user', async () => {
|
||||||
|
const ok = await userFile.checkPassword('uid=nobody,ou=people,dc=standalone,dc=local', 'testpass');
|
||||||
|
assert.strictEqual(ok, false);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('addSshKey appends a new key', async () => {
|
||||||
|
const newKey = 'ssh-rsa AAAAB3NzaC1yc2E... bob@desktop';
|
||||||
|
await userFile.addSshKey('uid=alice,ou=people,dc=standalone,dc=local', newKey);
|
||||||
|
|
||||||
|
const user = await StandaloneUser.get('alice');
|
||||||
|
assert.ok(user.sshPublicKeys.includes(newKey));
|
||||||
|
});
|
||||||
|
|
||||||
|
test('addSshKey is idempotent', async () => {
|
||||||
|
const key = 'ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAI... alice@laptop';
|
||||||
|
const userBefore = await StandaloneUser.get('alice');
|
||||||
|
const countBefore = userBefore.sshPublicKeys.length;
|
||||||
|
await userFile.addSshKey('uid=alice,ou=people,dc=standalone,dc=local', key);
|
||||||
|
const userAfter = await StandaloneUser.get('alice');
|
||||||
|
assert.strictEqual(userAfter.sshPublicKeys.length, countBefore);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('addSshKey is a no-op for unknown user', async () => {
|
||||||
|
// Should not throw.
|
||||||
|
await userFile.addSshKey('uid=nobody,ou=people,dc=standalone,dc=local', 'ssh-rsa AAA...');
|
||||||
|
});
|
||||||
+82
-57
@@ -1,70 +1,95 @@
|
|||||||
'use strict';
|
'use strict';
|
||||||
|
|
||||||
// Which directory hosts may a user reach, and how do we dial them?
|
// Host discovery — SSO Manager API in production, ORM-backed inventory in
|
||||||
//
|
// standalone mode. Both export the same interface:
|
||||||
// v1 resolution (see directory_spec.md §9.2 in sso-manager-node): the SSO's
|
// accessibleHosts(user) -> [host resources]
|
||||||
// /api/discovery/me only answers for the API token's own user, and /graph
|
// clearCache(uid?) -> void
|
||||||
// omits ResourceGroup links — so we combine the user's LDAP groups (queried
|
|
||||||
// directly) with per-group resource lookups:
|
|
||||||
//
|
|
||||||
// 1. LDAP: groups the user's DN is a member of
|
|
||||||
// 2. SSO: GET /api/discovery/resources?group=<cn> per group (ApiToken)
|
|
||||||
// 3. union, keep kind === 'host'
|
|
||||||
//
|
|
||||||
// Results are cached per-uid for a short TTL — the TUI picker and the
|
|
||||||
// username-grammar path share the cache. Dependency-injected fetch/ldap for
|
|
||||||
// unit testing.
|
|
||||||
|
|
||||||
const conf = require('@simpleworkjs/conf');
|
const conf = require('@simpleworkjs/conf');
|
||||||
const { createDirectoryClient } = require('@simpleworkjs/directory-schema');
|
|
||||||
const userLdap = require('../models/user_ldap');
|
|
||||||
|
|
||||||
const CACHE_TTL_MS = 30 * 1000;
|
if (conf.standalone && conf.standalone.enabled) {
|
||||||
const cache = new Map(); // uid -> {at, hosts}
|
// Standalone mode: use the ORM-backed host inventory. Every host is
|
||||||
|
// accessible to every user, so allHosts and accessibleHosts coincide.
|
||||||
|
const { accessibleHosts } = require('./hosts_file');
|
||||||
|
module.exports = { accessibleHosts, allHosts: () => accessibleHosts(), clearCache: () => {} };
|
||||||
|
} else {
|
||||||
|
// Production mode: LDAP groups + SSO API (unchanged).
|
||||||
|
|
||||||
// Build a directory client bound to conf.sso. fetchImpl is injectable so the
|
// Which directory hosts may a user reach, and how do we dial them?
|
||||||
// unit tests can stub the transport; the shared client validates the
|
//
|
||||||
// `{ results }` envelope on every call (turns the old bare-array drift into a
|
// v1 resolution (see directory_spec.md §9.2 in sso-manager-node): the SSO's
|
||||||
// thrown error instead of a silent `[]`).
|
// /api/discovery/me only answers for the API token's own user, and /graph
|
||||||
function directoryClient({ fetchImpl = fetch } = {}) {
|
// omits ResourceGroup links — so we combine the user's LDAP groups (queried
|
||||||
const sso = conf.sso || {};
|
// directly) with per-group resource lookups:
|
||||||
return createDirectoryClient({ baseUrl: sso.url, apiToken: sso.apiToken, fetch: fetchImpl });
|
//
|
||||||
}
|
// 1. LDAP: groups the user's DN is a member of
|
||||||
|
// 2. SSO: GET /api/discovery/resources?group=<cn> per group (ApiToken)
|
||||||
|
// 3. union, keep kind === 'host'
|
||||||
|
//
|
||||||
|
// Results are cached per-uid for a short TTL — the TUI picker and the
|
||||||
|
// username-grammar path share the cache. Dependency-injected fetch/ldap for
|
||||||
|
// unit testing.
|
||||||
|
|
||||||
async function fetchResourcesByGroup(group, { fetchImpl = fetch } = {}) {
|
const { createDirectoryClient } = require('@simpleworkjs/directory-schema');
|
||||||
return directoryClient({ fetchImpl }).getResourcesByGroup(group);
|
const userLdap = require('../models/user_ldap');
|
||||||
}
|
|
||||||
|
|
||||||
async function accessibleHosts(user, { fetchImpl = fetch, ldap = userLdap } = {}) {
|
const CACHE_TTL_MS = 30 * 1000;
|
||||||
const hit = cache.get(user.uid);
|
const cache = new Map(); // uid -> {at, hosts}
|
||||||
if (hit && Date.now() - hit.at < CACHE_TTL_MS) return hit.hosts;
|
|
||||||
|
|
||||||
const groups = await ldap.getGroups(user.dn);
|
// Build a directory client bound to conf.sso. fetchImpl is injectable so the
|
||||||
|
// unit tests can stub the transport; the shared client validates the
|
||||||
const seen = new Map();
|
// `{ results }` envelope on every call (turns the old bare-array drift into a
|
||||||
for (const cn of groups) {
|
// thrown error instead of a silent `[]`).
|
||||||
let resources;
|
function directoryClient({ fetchImpl = fetch } = {}) {
|
||||||
try {
|
const sso = conf.sso || {};
|
||||||
resources = await fetchResourcesByGroup(cn, { fetchImpl });
|
return createDirectoryClient({ baseUrl: sso.url, apiToken: sso.apiToken, fetch: fetchImpl });
|
||||||
} catch (error) {
|
|
||||||
// One bad group must not hide the rest; the SSO being down
|
|
||||||
// surfaces as an empty list + log line, not a crash.
|
|
||||||
console.error(`[access] ${error.message}`);
|
|
||||||
continue;
|
|
||||||
}
|
|
||||||
for (const r of resources) {
|
|
||||||
if (r.kind === 'host' && !seen.has(r.id)) seen.set(r.id, r);
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
|
|
||||||
const hosts = [...seen.values()];
|
async function fetchResourcesByGroup(group, { fetchImpl = fetch } = {}) {
|
||||||
cache.set(user.uid, { at: Date.now(), hosts });
|
return directoryClient({ fetchImpl }).getResourcesByGroup(group);
|
||||||
return hosts;
|
}
|
||||||
}
|
|
||||||
|
|
||||||
function clearCache(uid) {
|
// Every host in the inventory, unfiltered — for admins (the web UI's own
|
||||||
if (uid) cache.delete(uid);
|
// account is already gated by requireAdmin before this is ever called).
|
||||||
else cache.clear();
|
async function allHosts({ fetchImpl = fetch } = {}) {
|
||||||
}
|
const resources = await directoryClient({ fetchImpl }).getResourcesByGroup(undefined, { kind: 'host' });
|
||||||
|
return resources.filter(r => r.kind === 'host');
|
||||||
|
}
|
||||||
|
|
||||||
module.exports = { accessibleHosts, clearCache, fetchResourcesByGroup };
|
async function accessibleHosts(user, { fetchImpl = fetch, ldap = userLdap } = {}) {
|
||||||
|
const hit = cache.get(user.uid);
|
||||||
|
if (hit && Date.now() - hit.at < CACHE_TTL_MS) return hit.hosts;
|
||||||
|
|
||||||
|
// The SSH path passes an LDAP user ({dn, uid, ...}) with no .groups, so we
|
||||||
|
// look them up; the web UI already has the session's OIDC groups claim
|
||||||
|
// and passes it directly, skipping a redundant LDAP round-trip.
|
||||||
|
const groups = user.groups || await ldap.getGroups(user.dn);
|
||||||
|
|
||||||
|
const seen = new Map();
|
||||||
|
for (const cn of groups) {
|
||||||
|
let resources;
|
||||||
|
try {
|
||||||
|
resources = await fetchResourcesByGroup(cn, { fetchImpl });
|
||||||
|
} catch (error) {
|
||||||
|
// One bad group must not hide the rest; the SSO being down
|
||||||
|
// surfaces as an empty list + log line, not a crash.
|
||||||
|
console.error(`[access] ${error.message}`);
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
for (const r of resources) {
|
||||||
|
if (r.kind === 'host' && !seen.has(r.id)) seen.set(r.id, r);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
const hosts = [...seen.values()];
|
||||||
|
cache.set(user.uid, { at: Date.now(), hosts });
|
||||||
|
return hosts;
|
||||||
|
}
|
||||||
|
|
||||||
|
function clearCache(uid) {
|
||||||
|
if (uid) cache.delete(uid);
|
||||||
|
else cache.clear();
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { accessibleHosts, allHosts, clearCache, fetchResourcesByGroup };
|
||||||
|
}
|
||||||
|
|||||||
@@ -0,0 +1,30 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// ORM-backed host inventory for standalone mode. Implements the same interface
|
||||||
|
// as utils/access.js so ssh_server.js works unchanged: accessibleHosts(user)
|
||||||
|
// returns an array of host resources the user may reach.
|
||||||
|
//
|
||||||
|
// In standalone mode all hosts in the inventory are accessible to every
|
||||||
|
// authenticated user — there is no group-based filtering. The _user parameter
|
||||||
|
// is accepted for interface compatibility but ignored.
|
||||||
|
|
||||||
|
const StandaloneHost = require('../models/standalone_host');
|
||||||
|
|
||||||
|
async function accessibleHosts(_user) {
|
||||||
|
const hosts = await StandaloneHost.list({ where: { kind: 'host' } });
|
||||||
|
// The ORM returns model instances; map to plain objects matching the shape
|
||||||
|
// that target_match.js and tui_picker.js expect.
|
||||||
|
return hosts.map((h) => ({
|
||||||
|
id: h.slug, // slug doubles as the stable id in standalone mode
|
||||||
|
kind: h.kind,
|
||||||
|
slug: h.slug,
|
||||||
|
displayName: h.displayName,
|
||||||
|
metadata: h.metadata || {},
|
||||||
|
}));
|
||||||
|
}
|
||||||
|
|
||||||
|
function clearCache() {
|
||||||
|
// No cache in standalone mode — every call reads from the DB.
|
||||||
|
}
|
||||||
|
|
||||||
|
module.exports = { accessibleHosts, clearCache };
|
||||||
@@ -0,0 +1,42 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
// Per-app values for the shared UI shell (views/top.ejs + views/bottom.ejs).
|
||||||
|
//
|
||||||
|
// Those two partials are byte-identical across sso-manager-node, proxy and
|
||||||
|
// jump-host — everything that differs between the apps lives here and is
|
||||||
|
// exposed to every render as `ui` via app.locals (see app.js). Keep the key set
|
||||||
|
// in sync across the three apps; a missing key is a render-time ReferenceError,
|
||||||
|
// not a silent fallback.
|
||||||
|
|
||||||
|
module.exports = {
|
||||||
|
// --- footer -------------------------------------------------------------
|
||||||
|
repoUrl: 'https://github.com/theta42/jump-host',
|
||||||
|
licenseUrl: 'https://github.com/theta42/jump-host/blob/master/LICENSE',
|
||||||
|
// No in-app /docs route here — point at the published docs site.
|
||||||
|
docsUrl: 'https://theta42.github.io/jump-host/',
|
||||||
|
docsExternal: true,
|
||||||
|
// Only sso-manager-node serves a Terms of Service page; null hides the link.
|
||||||
|
tosUrl: null,
|
||||||
|
|
||||||
|
// --- header / nav -------------------------------------------------------
|
||||||
|
faviconUrl: '/static/favicon.svg',
|
||||||
|
// Where the current-user chip links. null renders it as a plain span (for
|
||||||
|
// apps with no profile page).
|
||||||
|
profileUrl: null,
|
||||||
|
// Where "Log Out" lands.
|
||||||
|
logoutRedirect: '/login',
|
||||||
|
// Admin-only "a newer release is available" banner, backed by
|
||||||
|
// GET /api/update-check. Apps without that endpoint set false.
|
||||||
|
updateCheck: false,
|
||||||
|
updateLabel: 'the jump host',
|
||||||
|
|
||||||
|
// Nav items, in order. `groups` is an OR-list of group CNs that may see the
|
||||||
|
// item; an empty list means "always visible". Gating is done client-side by
|
||||||
|
// app-base.js, which reveals .group-required-<cn> for each group the user is
|
||||||
|
// in (plus the synthetic `admin` group when user/me reports isAdmin).
|
||||||
|
nav: [
|
||||||
|
{href: '/dashboard', icon: 'fa-solid fa-gauge-high', label: 'Dashboard', groups: []},
|
||||||
|
{href: '/sessions', icon: 'fa-solid fa-plug-circle-bolt', label: 'Sessions', groups: []},
|
||||||
|
{href: '/audit', icon: 'fa-solid fa-clipboard-list', label: 'Audit', groups: []},
|
||||||
|
],
|
||||||
|
};
|
||||||
+27
-21
@@ -1,24 +1,30 @@
|
|||||||
</div>
|
</div><!-- end spa-shell -->
|
||||||
|
|
||||||
<footer class="py-2 bg-dark text-light mt-4">
|
<!-- Shared UI shell — byte-identical across sso-manager-node, proxy and
|
||||||
<div class="container-fluid d-flex flex-wrap justify-content-between align-items-center small gap-2">
|
jump-host. Everything per-app comes from `ui` (utils/ui.js, exposed via
|
||||||
<span class="d-flex align-items-center gap-2">
|
app.locals in app.js). Edit all three copies together. -->
|
||||||
<a href="https://theta42.com" target="_blank">
|
<footer class="py-2 bg-dark text-light mt-4">
|
||||||
<img width="64" src="/static/img/theta42.svg"/>
|
<div class="container-fluid d-flex flex-wrap justify-content-between align-items-center small gap-2">
|
||||||
</a>
|
<span class="d-flex align-items-center gap-2">
|
||||||
© <%- buildYear %> theta42 ·
|
<a href="https://theta42.com" target="_blank">
|
||||||
<a href="https://github.com/theta42/jump-host/blob/master/LICENSE" target="_blank" class="text-light">MIT License</a>
|
<img width="64" src="/static/img/theta42.svg"/>
|
||||||
</span>
|
</a>
|
||||||
<span class="d-flex align-items-center gap-3">
|
© <%- buildYear %> theta42 ·
|
||||||
<a href="https://theta42.github.io/jump-host/" target="_blank" class="text-light text-decoration-none">
|
<a href="<%- ui.licenseUrl %>" target="_blank" class="text-light">MIT License</a>
|
||||||
<i class="fa-solid fa-book"></i> Docs
|
</span>
|
||||||
</a>
|
<span class="d-flex align-items-center gap-3">
|
||||||
<a href="https://github.com/theta42/jump-host" target="_blank" class="text-light text-decoration-none">
|
<a href="<%- ui.docsUrl %>"<%- ui.docsExternal ? ' target="_blank"' : '' %> class="text-light text-decoration-none">
|
||||||
<i class="fa-brands fa-github"></i> GitHub
|
<i class="fa-solid fa-book"></i> Docs
|
||||||
</a>
|
</a>
|
||||||
</span>
|
<a href="<%- ui.repoUrl %>" target="_blank" class="text-light text-decoration-none">
|
||||||
<span>v<%- buildVersion %> (<%- buildHash %>)</span>
|
<i class="fa-brands fa-github"></i> GitHub
|
||||||
</div>
|
</a>
|
||||||
</footer>
|
<% if(ui.tosUrl){ %>
|
||||||
|
<a href="<%- ui.tosUrl %>" class="text-light text-decoration-none">Terms of Service</a>
|
||||||
|
<% } %>
|
||||||
|
</span>
|
||||||
|
<span>v<%- buildVersion %> (<%- buildHash %>)</span>
|
||||||
|
</div>
|
||||||
|
</footer>
|
||||||
</body>
|
</body>
|
||||||
</html>
|
</html>
|
||||||
|
|||||||
@@ -28,6 +28,15 @@
|
|||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
|
<div class="row g-3 mb-4">
|
||||||
|
<div class="col-12">
|
||||||
|
<div class="card shadow-sm">
|
||||||
|
<div class="card-header"><i class="fa-solid fa-network-wired me-1"></i> <span id="my-hosts-title">Hosts you can reach</span></div>
|
||||||
|
<table class="table table-sm mb-0"><tbody id="my-hosts"></tbody></table>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
<div class="row g-3">
|
<div class="row g-3">
|
||||||
<div class="col-md-6">
|
<div class="col-md-6">
|
||||||
<div class="card shadow-sm"><div class="card-header"><i class="fa-solid fa-server me-1"></i> Top hosts</div>
|
<div class="card shadow-sm"><div class="card-header"><i class="fa-solid fa-server me-1"></i> Top hosts</div>
|
||||||
@@ -49,7 +58,17 @@
|
|||||||
$b.append('<tr><td>' + app.jump.esc(x.name) + '</td><td class="text-end">' + x.count + '</td></tr>');
|
$b.append('<tr><td>' + app.jump.esc(x.name) + '</td><td class="text-end">' + x.count + '</td></tr>');
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
$(document).ready(function(){
|
function hostRows(sel, hosts){
|
||||||
|
var $b = $(sel).empty();
|
||||||
|
if(!hosts || !hosts.length){ $b.append('<tr><td class="text-muted">No hosts reachable.</td></tr>'); return; }
|
||||||
|
hosts.forEach(function(h){
|
||||||
|
var addr = (h.metadata && (h.metadata.ip || h.metadata.address)) || '';
|
||||||
|
$b.append('<tr><td>' + app.jump.esc(h.displayName || h.name || h.slug) + '</td>'
|
||||||
|
+ '<td class="text-muted small">' + app.jump.esc(h.slug) + '</td>'
|
||||||
|
+ '<td class="text-end text-muted small">' + app.jump.esc(addr) + '</td></tr>');
|
||||||
|
});
|
||||||
|
}
|
||||||
|
$(document).ready(async function(){
|
||||||
app.jump.metrics(function(error, data){
|
app.jump.metrics(function(error, data){
|
||||||
if(error || !data) return;
|
if(error || !data) return;
|
||||||
$('#stat-active').text(data.active);
|
$('#stat-active').text(data.active);
|
||||||
@@ -59,6 +78,12 @@
|
|||||||
rows('#top-hosts', data.topHosts);
|
rows('#top-hosts', data.topHosts);
|
||||||
rows('#top-users', data.topUsers);
|
rows('#top-users', data.topUsers);
|
||||||
});
|
});
|
||||||
|
await app.auth.loadUser();
|
||||||
|
if(app.auth.isAdmin()) $('#my-hosts-title').text('All hosts');
|
||||||
|
app.jump.hosts(function(error, data){
|
||||||
|
if(error) return hostRows('#my-hosts', []);
|
||||||
|
hostRows('#my-hosts', data && data.results);
|
||||||
|
});
|
||||||
});
|
});
|
||||||
</script>
|
</script>
|
||||||
<%- include('bottom') %>
|
<%- include('bottom') %>
|
||||||
|
|||||||
+12
-8
@@ -4,14 +4,18 @@
|
|||||||
// If we arrived from the OIDC callback with a token in the URL fragment,
|
// If we arrived from the OIDC callback with a token in the URL fragment,
|
||||||
// store it and forward on before doing anything else.
|
// store it and forward on before doing anything else.
|
||||||
if(!app.auth.consumeTokenFragment()){
|
if(!app.auth.consumeTokenFragment()){
|
||||||
app.auth.isLoggedIn(function(error, isLoggedIn){
|
// The reveal below touches an element further down this page, so wait
|
||||||
if(isLoggedIn){
|
// for the DOM — isLoggedIn can answer before the parser gets there.
|
||||||
app.auth.logInRedirect();
|
$(document).ready(function(){
|
||||||
}else{
|
app.auth.isLoggedIn(function(error, isLoggedIn){
|
||||||
// Reveal the login card once we know the user is not logged in.
|
if(isLoggedIn){
|
||||||
document.getElementById('login-card-row').style.display = '';
|
app.auth.logInRedirect();
|
||||||
}
|
}else{
|
||||||
})
|
// Reveal the login card once we know the user is not logged in.
|
||||||
|
document.getElementById('login-card-row').style.display = '';
|
||||||
|
}
|
||||||
|
});
|
||||||
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
</script>
|
</script>
|
||||||
|
|||||||
+97
-24
@@ -4,19 +4,28 @@
|
|||||||
<meta charset="utf-8">
|
<meta charset="utf-8">
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
||||||
<title><%- name %> <%- title %></title>
|
<title><%- name %> <%- title %></title>
|
||||||
<link rel="icon" type="image/svg+xml" href="/static/favicon.svg">
|
<!-- Shared UI shell — byte-identical across sso-manager-node, proxy and
|
||||||
|
jump-host. Everything per-app comes from `ui` (utils/ui.js, exposed
|
||||||
|
via app.locals in app.js). Edit all three copies together. -->
|
||||||
|
<!-- Favicon -->
|
||||||
|
<link rel="icon" type="image/svg+xml" href="<%- ui.faviconUrl %>">
|
||||||
|
<!-- CSS are placed here -->
|
||||||
<link rel="stylesheet" href="/static-modules/bootstrap/dist/css/bootstrap.min.css">
|
<link rel="stylesheet" href="/static-modules/bootstrap/dist/css/bootstrap.min.css">
|
||||||
<link rel="stylesheet" href="/static-modules/@fortawesome/fontawesome-free/css/all.min.css">
|
<link rel="stylesheet" href="/static-modules/@fortawesome/fontawesome-free/css/all.min.css">
|
||||||
|
|
||||||
<link rel='stylesheet' href='/static/css/styles.css' />
|
<link rel='stylesheet' href='/static/css/styles.css' />
|
||||||
|
<!-- Scripts are placed here -->
|
||||||
<script type="text/javascript" src="/socket.io/socket.io.js"></script>
|
<script type="text/javascript" src="/socket.io/socket.io.js"></script>
|
||||||
<script type="text/javascript" src='/static-modules/jquery/dist/jquery.js'></script>
|
<script type="text/javascript" src='/static-modules/jquery/dist/jquery.js'></script>
|
||||||
<script type="text/javascript" src="/static-modules/bootstrap/dist/js/bootstrap.bundle.min.js"></script>
|
<script type="text/javascript" src="/static-modules/bootstrap/dist/js/bootstrap.bundle.min.js"></script>
|
||||||
<script type="text/javascript" src="/static-modules/@fortawesome/fontawesome-free/js/all.min.js"></script>
|
<script type="text/javascript" src="/static-modules/@fortawesome/fontawesome-free/js/all.min.js"></script>
|
||||||
<script type="text/javascript" src='/static-modules/mustache/mustache.min.js'></script>
|
<script type="text/javascript" src='/static-modules/mustache/mustache.min.js'></script>
|
||||||
<script type="text/javascript" src='/static-modules/jq-repeat/dist/js/jq-repeat.js'></script>
|
<script type="text/javascript" src='/static-modules/jq-repeat/dist/js/jq-repeat.js'></script>
|
||||||
<script type="text/javascript" src='/static/lib/js/val.js'></script>
|
|
||||||
<script type="text/javascript" src="/static-modules/moment/moment.js"></script>
|
<script type="text/javascript" src="/static-modules/moment/moment.js"></script>
|
||||||
<script type="text/javascript" src="/static/lib/js/app-base.js"></script>
|
<script type="text/javascript" src="/static/lib/js/app-base.js"></script>
|
||||||
|
<script type="text/javascript" src="/static-modules/@simpleworkjs/frontend/lib/app.messages.js"></script>
|
||||||
|
<script type="text/javascript" src="/static-modules/@simpleworkjs/frontend/lib/app.modal.js"></script>
|
||||||
|
<script type="text/javascript" src="/static-modules/@simpleworkjs/frontend/lib/app.validate.js"></script>
|
||||||
<script type="text/javascript" src="/static/js/app.js"></script>
|
<script type="text/javascript" src="/static/js/app.js"></script>
|
||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
@@ -28,51 +37,115 @@
|
|||||||
</button>
|
</button>
|
||||||
<div class="collapse navbar-collapse justify-content-end" id="navbarSupportedContent">
|
<div class="collapse navbar-collapse justify-content-end" id="navbarSupportedContent">
|
||||||
<ul class="navbar-nav top-nav">
|
<ul class="navbar-nav top-nav">
|
||||||
<li class="nav-item">
|
<%# Items gated on a group start hidden (.group-required) and are
|
||||||
<a class="nav-link" href="/dashboard"><i class="fa-solid fa-gauge-high"></i> Dashboard</a>
|
revealed by app-base.js for the groups the user is in. %>
|
||||||
</li>
|
<% for(const item of ui.nav){ %>
|
||||||
<li class="nav-item">
|
<li class="nav-item<%- item.groups.length ? ' group-required' : '' %><%- item.groups.map(group => ' group-required-' + group).join('') %>">
|
||||||
<a class="nav-link" href="/sessions"><i class="fa-solid fa-plug-circle-bolt"></i> Sessions</a>
|
<a class="nav-link" href="<%- item.href %>"><i class="<%- item.icon %>"></i>
|
||||||
</li>
|
<%- item.label %>
|
||||||
<li class="nav-item">
|
</a>
|
||||||
<a class="nav-link" href="/audit"><i class="fa-solid fa-clipboard-list"></i> Audit</a>
|
|
||||||
</li>
|
</li>
|
||||||
|
<% } %>
|
||||||
</ul>
|
</ul>
|
||||||
<div class="form-inline mt-2 mt-md-0">
|
<div class="form-inline mt-2 mt-md-0">
|
||||||
|
<% if(ui.profileUrl){ %>
|
||||||
|
<a id="cl-username" class="navbar-text text-light me-3" href="<%- ui.profileUrl %>" style="display: none;">
|
||||||
|
<i class="fa-solid fa-user me-1"></i><span id="cl-username-text"></span>
|
||||||
|
</a>
|
||||||
|
<% } else { %>
|
||||||
<span id="cl-username" class="navbar-text text-light me-3" style="display: none;">
|
<span id="cl-username" class="navbar-text text-light me-3" style="display: none;">
|
||||||
<i class="fa-solid fa-user me-1"></i><span id="cl-username-text"></span>
|
<i class="fa-solid fa-user me-1"></i><span id="cl-username-text"></span>
|
||||||
</span>
|
</span>
|
||||||
<a id="cl-login-button" class="btn btn-outline-danger my-2 my-sm-0" href="/login" style="display: none;">
|
<% } %>
|
||||||
<i class="fas fa-sign-in"></i> Login
|
<a id="cl-login-button" class="btn btn-outline-danger my-2 my-sm-0" onclick="app.auth.forceLogin()" style="display: none;">
|
||||||
|
<i class="fas fa-sign-in"></i>
|
||||||
|
Login
|
||||||
</a>
|
</a>
|
||||||
<button id="cl-logout-button" class="btn btn-outline-danger my-2 my-sm-0" onclick="app.auth.logOut(function(){ window.location.href='/login'; })" style="display: none;">
|
|
||||||
<i class="fas fa-sign-out"></i> Log Out
|
<button id="cl-logout-button" class="btn btn-outline-danger my-2 my-sm-0" onclick="app.auth.logOut(function(){ window.location.href = '<%- ui.logoutRedirect %>'; })" style="display: none;">
|
||||||
|
<i class="fas fa-sign-out"></i>
|
||||||
|
Log Out
|
||||||
</button>
|
</button>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</nav>
|
</nav>
|
||||||
|
|
||||||
|
<% if(ui.updateCheck){ %>
|
||||||
|
<!-- Admin-only "a newer release is available" notice (services/update_check.js).
|
||||||
|
Dismissal is per-browser-session only (sessionStorage), not persisted server-side.
|
||||||
|
Fixed-positioned below the fixed navbar (a plain in-flow div here would render
|
||||||
|
UNDER the nav, since fixed elements are taken out of document flow) -- shown/hidden
|
||||||
|
dynamically, so #spa-shell's margin-top is adjusted in JS to make room for it. -->
|
||||||
|
<div id="update-banner" class="alert alert-info alert-dismissible mb-0 rounded-0 text-center" style="display:none; position:fixed; left:0; right:0; z-index:1029;">
|
||||||
|
<span id="update-banner-text"></span>
|
||||||
|
<button type="button" class="btn-close" onclick="dismissUpdateBanner()"></button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<script type="text/javascript">
|
||||||
|
function showUpdateBanner(){
|
||||||
|
let $nav = $('nav.fixed-top');
|
||||||
|
let $banner = $('#update-banner');
|
||||||
|
$banner.css('top', $nav.outerHeight() + 'px').show();
|
||||||
|
$('#spa-shell').css('margin-top', ($nav.outerHeight() + $banner.outerHeight()) + 'px');
|
||||||
|
}
|
||||||
|
|
||||||
|
function dismissUpdateBanner(){
|
||||||
|
$('#update-banner').hide();
|
||||||
|
$('#spa-shell').css('margin-top', '');
|
||||||
|
sessionStorage.setItem('update-banner-dismissed', '1');
|
||||||
|
}
|
||||||
|
|
||||||
|
function checkForUpdate(){
|
||||||
|
if(sessionStorage.getItem('update-banner-dismissed')) return;
|
||||||
|
app.api.get('update-check', function(error, info){
|
||||||
|
if(error || !info || !info.updateAvailable) return;
|
||||||
|
$('#update-banner-text').html(
|
||||||
|
'A newer version of <%- ui.updateLabel %> is available: <b>v' + info.latestVersion + '</b> ' +
|
||||||
|
'(running v' + info.currentVersion + ') — ' +
|
||||||
|
'<a href="' + info.releaseUrl + '" target="_blank" class="alert-link">see what changed</a>.'
|
||||||
|
);
|
||||||
|
showUpdateBanner();
|
||||||
|
});
|
||||||
|
}
|
||||||
|
</script>
|
||||||
|
<% } %>
|
||||||
|
|
||||||
<script type="text/javascript">
|
<script type="text/javascript">
|
||||||
$(document).ready(function(){
|
$(document).ready(function(){
|
||||||
$('.top-nav a').each(function(){
|
|
||||||
var $this = $(this);
|
// Set the correct link to active in the top nav bar
|
||||||
|
$('.top-nav a').each(function(index){
|
||||||
|
let $this = $(this);
|
||||||
$this.removeClass('active');
|
$this.removeClass('active');
|
||||||
if($this.attr('href').toLowerCase() === window.location.pathname.toLowerCase()){
|
if($this.attr('href').toLocaleLowerCase() === window.location.pathname.toLocaleLowerCase()){
|
||||||
$this.addClass('active');
|
$this.addClass('active')
|
||||||
}
|
}
|
||||||
});
|
})
|
||||||
app.auth.isLoggedIn(function(error, data){
|
|
||||||
if(data){
|
// Set the correct login/logout button, and reveal the current user's
|
||||||
|
// name once we know who they are. Group-gated nav items are revealed
|
||||||
|
// by app-base.js off the same cached user/me.
|
||||||
|
app.auth.isLoggedIn(function(error, me){
|
||||||
|
if(me){
|
||||||
$('#cl-logout-button').show();
|
$('#cl-logout-button').show();
|
||||||
if(data.username){
|
let username = me.uid || me.username;
|
||||||
$('#cl-username-text').text(data.username);
|
if(username){
|
||||||
|
$('#cl-username-text').text(username);
|
||||||
$('#cl-username').css('display', '');
|
$('#cl-username').css('display', '');
|
||||||
}
|
}
|
||||||
|
|
||||||
|
<% if(ui.updateCheck){ %>
|
||||||
|
if(me.isAdmin) checkForUpdate();
|
||||||
|
<% } %>
|
||||||
}else{
|
}else{
|
||||||
$('#cl-login-button').show();
|
$('#cl-login-button').show();
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
|
|
||||||
});
|
});
|
||||||
</script>
|
</script>
|
||||||
|
|
||||||
<div id="spa-shell" class="container-fluid" style="margin-top: 4.5rem;">
|
|
||||||
|
<!-- Container -->
|
||||||
|
<div id="spa-shell" class="container-fluid">
|
||||||
|
<div class="actionMessage" style="display:none;"></div>
|
||||||
|
|||||||
@@ -11,7 +11,24 @@
|
|||||||
module.exports = {
|
module.exports = {
|
||||||
name: 'My Org',
|
name: 'My Org',
|
||||||
|
|
||||||
|
// Standalone mode: run with no LDAP directory and no SSO Manager. When
|
||||||
|
// enabled, user auth and host discovery use the ORM-backed stores below
|
||||||
|
// instead of `ldap` + `sso` (both become unused). See the README's
|
||||||
|
// "Standalone mode" section for how to add users/hosts.
|
||||||
|
standalone: {
|
||||||
|
enabled: false,
|
||||||
|
},
|
||||||
|
|
||||||
|
// ORM config for standalone mode (Sequelize — any dialect works, not just
|
||||||
|
// sqlite). Ignored unless standalone.enabled is true.
|
||||||
|
orm: {
|
||||||
|
dialect: 'sqlite',
|
||||||
|
storage: './data/standalone.sqlite',
|
||||||
|
logging: false,
|
||||||
|
},
|
||||||
|
|
||||||
// The directory the users live in (the SSO Manager's OpenLDAP).
|
// The directory the users live in (the SSO Manager's OpenLDAP).
|
||||||
|
// Unused when standalone.enabled is true.
|
||||||
//
|
//
|
||||||
// IMPORTANT: bindDN needs, beyond read on ou=people + ou=groups, WRITE on
|
// IMPORTANT: bindDN needs, beyond read on ou=people + ou=groups, WRITE on
|
||||||
// the sshPublicKey attribute of user entries — the jump host injects its
|
// the sshPublicKey attribute of user entries — the jump host injects its
|
||||||
@@ -36,6 +53,7 @@ module.exports = {
|
|||||||
|
|
||||||
// SSO Manager directory (inventory) API. apiToken is a personal access
|
// SSO Manager directory (inventory) API. apiToken is a personal access
|
||||||
// token (sso_<id>_<secret>) of any user that can read /api/discovery/*.
|
// token (sso_<id>_<secret>) of any user that can read /api/discovery/*.
|
||||||
|
// Unused when standalone.enabled is true.
|
||||||
sso: {
|
sso: {
|
||||||
url: 'https://sso.example.com',
|
url: 'https://sso.example.com',
|
||||||
apiToken: 'sso_CHANGE_ME',
|
apiToken: 'sso_CHANGE_ME',
|
||||||
|
|||||||
Reference in New Issue
Block a user