Compare commits
4 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 8a76f71edd | |||
| e482f52f10 | |||
| a6af160627 | |||
| 8c9646b65c |
@@ -4,6 +4,16 @@ All notable changes to this project are documented here. Format loosely
|
||||
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions
|
||||
correspond to git tags (`vX.Y.Z`) and `nodejs/package.json`'s `version`.
|
||||
|
||||
## [1.9.0] - 2026-07-28
|
||||
|
||||
### Added
|
||||
- **"Quick Jump" copy-to-clipboard section on the dashboard** — the `uid_-_target` grammar-mode SSH command was documented in the README but nowhere in the UI. A new card gives a one-click-copy command for interactive-picker mode, and every row in "Hosts you can reach" has its own copy button for the exact grammar-mode command to that host, ready to paste and run as-is (uses the logged-in user's own uid).
|
||||
|
||||
## [1.8.2] - 2026-07-28
|
||||
|
||||
### Fixed
|
||||
- **Audit records for a failed upstream connection only ever said `upstream-unreachable`** — `resolveAndConnect` discarded the real error from `connectUpstream` (ECONNREFUSED, ETIMEDOUT, an ssh2 auth-failure message, etc.) and replaced it with that one generic string, so there was no way to tell a network-layer failure from an auth failure from the audit log alone. This is what blocked root-causing the "Could not reach 192.168.1.206" (emby host) report — the real error is now captured and surfaced as a new `failDetail` field on the audit record, shown as a tooltip on the fail badge in the admin audit table.
|
||||
|
||||
## [1.8.1] - 2026-07-28
|
||||
|
||||
### Fixed
|
||||
|
||||
+1
-1
@@ -1,6 +1,6 @@
|
||||
{
|
||||
"name": "t42-jump-host",
|
||||
"version": "1.8.1",
|
||||
"version": "1.9.0",
|
||||
"description": "SSH jump host for the theta42 stack — LDAP-authenticated, directory-driven host bridging with audit and metrics",
|
||||
"author": [
|
||||
{
|
||||
|
||||
@@ -27,5 +27,6 @@ app.apiToken = (function(app){
|
||||
// Shared render helpers.
|
||||
app.jump.fmtTime = function(ts){ return ts ? moment(Number(ts)).format('YYYY-MM-DD HH:mm:ss') : '—'; };
|
||||
app.jump.esc = function(s){ return $('<div>').text(s == null ? '' : String(s)).html(); };
|
||||
app.jump.result = function(e){ return e.success ? '<span class="badge bg-success">ok</span>'
|
||||
: '<span class="badge bg-danger">' + app.jump.esc(e.failReason || 'fail') + '</span>'; };
|
||||
app.jump.result = function(e){ if (e.success) return '<span class="badge bg-success">ok</span>';
|
||||
var title = e.failDetail ? ' title="' + app.jump.esc(e.failDetail) + '"' : '';
|
||||
return '<span class="badge bg-danger"' + title + '>' + app.jump.esc(e.failReason || 'fail') + '</span>'; };
|
||||
|
||||
@@ -14,6 +14,10 @@ const values = {
|
||||
titleIcon: conf.environment !== 'production' ? '<i class="fa-brands fa-dev"></i>' : '',
|
||||
name: conf.name,
|
||||
logo: conf.logo,
|
||||
// The SSH front door's port -- the dashboard's "quick jump" copy buttons
|
||||
// need this to build a real, working `ssh ...` command (the web UI and
|
||||
// SSH front door share a hostname but not a port).
|
||||
sshPort: (conf.ssh && conf.ssh.listenPort) || 22,
|
||||
...buildInfo,
|
||||
};
|
||||
|
||||
|
||||
@@ -130,7 +130,7 @@ async function resolveAndConnect(state, record, { onHostKey } = {}) {
|
||||
|
||||
let justInjected = false;
|
||||
try { justInjected = await ensureKeyInjected(state.user, JUMP_KEYS.publicLine); }
|
||||
catch (_) { throw fail('key-inject-failed'); }
|
||||
catch (err) { throw fail('key-inject-failed', err.message); }
|
||||
|
||||
let upstream;
|
||||
try {
|
||||
@@ -139,12 +139,16 @@ async function resolveAndConnect(state, record, { onHostKey } = {}) {
|
||||
username: state.uid, privateKey: JUMP_KEYS.clientKey,
|
||||
uid: state.uid, justInjected, onHostKey,
|
||||
});
|
||||
} catch (_) { throw fail('upstream-unreachable'); }
|
||||
} catch (err) { throw fail('upstream-unreachable', err.message); }
|
||||
|
||||
return { upstream, host, endpoint };
|
||||
}
|
||||
|
||||
function fail(reason) { const e = new Error(reason); e.reason = reason; return e; }
|
||||
// detail carries the real underlying error message (e.g. ECONNREFUSED,
|
||||
// ETIMEDOUT, an ssh2 auth-failure string) so audit records aren't reduced to
|
||||
// just the generic reason code -- without it, a network-layer failure and an
|
||||
// SSH auth failure both looked identical in the audit log.
|
||||
function fail(reason, detail) { const e = new Error(reason); e.reason = reason; e.detail = detail; return e; }
|
||||
|
||||
async function runGrammar(session, client, state) {
|
||||
// Register session listeners IMMEDIATELY — before any async work.
|
||||
@@ -174,7 +178,7 @@ async function runGrammar(session, client, state) {
|
||||
} catch (err) {
|
||||
const reason = err.reason || 'error';
|
||||
rejectUp(new Error(reasonMessage(reason)));
|
||||
await record.finish({ success: false, failReason: reason });
|
||||
await record.finish({ success: false, failReason: reason, failDetail: err.detail });
|
||||
await metrics.bump({ uid: state.uid, success: false });
|
||||
}
|
||||
}
|
||||
@@ -199,8 +203,8 @@ async function runTuiSession(session, client, state) {
|
||||
|
||||
const record = await audit.create({ uid: state.uid, authMethod: state.authMethod, clientIp: state.clientIp, mode: 'tui' });
|
||||
|
||||
const finishFail = async (reason) => {
|
||||
await record.finish({ success: false, failReason: reason });
|
||||
const finishFail = async (reason, detail) => {
|
||||
await record.finish({ success: false, failReason: reason, failDetail: detail });
|
||||
await metrics.bump({ uid: state.uid, success: false });
|
||||
try { client.end(); } catch (_) {}
|
||||
};
|
||||
@@ -223,7 +227,7 @@ async function runTuiSession(session, client, state) {
|
||||
|
||||
let justInjected = false;
|
||||
try { justInjected = await ensureKeyInjected(state.user, JUMP_KEYS.publicLine); }
|
||||
catch (_) { return finishFail('key-inject-failed'); }
|
||||
catch (err) { return finishFail('key-inject-failed', err.message); }
|
||||
|
||||
let upstream;
|
||||
try {
|
||||
@@ -232,9 +236,9 @@ async function runTuiSession(session, client, state) {
|
||||
username: state.uid, privateKey: JUMP_KEYS.clientKey,
|
||||
uid: state.uid, justInjected, onHostKey: (fp) => record.patch({ hostKeyFp: fp }),
|
||||
});
|
||||
} catch (_) {
|
||||
} catch (err) {
|
||||
try { tui.channel.write(`\r\n Could not reach ${endpoint.address}.\r\n`); tui.channel.close(); } catch (_) {}
|
||||
return finishFail('upstream-unreachable');
|
||||
return finishFail('upstream-unreachable', err.message);
|
||||
}
|
||||
|
||||
registry.add(record.id, { uid: state.uid, target: endpoint.address, slug: tui.host.slug });
|
||||
|
||||
@@ -156,6 +156,29 @@ test('shell bridges and echoes', async () => {
|
||||
assert.match(out, /echo:ping/);
|
||||
});
|
||||
|
||||
test('connectUpstream rejects with a specific, non-generic error when the target refuses the connection', async () => {
|
||||
// Regression coverage for ssh_server.js's resolveAndConnect: it used to
|
||||
// discard this error entirely (catch (_) { throw fail('upstream-unreachable') }),
|
||||
// so the audit log recorded the same generic reason for a refused port, a
|
||||
// timeout, or a bad key alike. Now the real message is threaded through as
|
||||
// failDetail, so this must stay meaningful.
|
||||
// Bind a server just to reserve a free port, then close it immediately so
|
||||
// nothing is listening there — guarantees ECONNREFUSED rather than relying
|
||||
// on a hardcoded port number that might be in use.
|
||||
const closedPort = await new Promise((resolve) => {
|
||||
const probe = require('net').createServer();
|
||||
probe.listen(0, '127.0.0.1', () => { const p = probe.address().port; probe.close(() => resolve(p)); });
|
||||
});
|
||||
await assert.rejects(
|
||||
connectUpstream({ host: '127.0.0.1', port: closedPort, username: 'test', privateKey: jumpKey, uid: 'test', justInjected: false }),
|
||||
(err) => {
|
||||
assert.ok(err.message && err.message.length > 0);
|
||||
assert.notStrictEqual(err.message, 'upstream-unreachable');
|
||||
return true;
|
||||
},
|
||||
);
|
||||
});
|
||||
|
||||
test('sftp subsystem bytes pass through', async () => {
|
||||
const { conn, ready } = connectJump();
|
||||
await ready;
|
||||
|
||||
@@ -28,6 +28,27 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row g-3 mb-4">
|
||||
<div class="col-12">
|
||||
<div class="card shadow-sm">
|
||||
<div class="card-header"><i class="fa-solid fa-terminal me-1"></i> Quick Jump</div>
|
||||
<div class="card-body">
|
||||
<p class="text-muted small mb-2">
|
||||
Skip the picker: <code>ssh <your-username>_-_<host-slug>@<this-jump-host></code>
|
||||
connects straight to a host. Or just <code>ssh <your-username>@<this-jump-host></code>
|
||||
for the interactive picker.
|
||||
</p>
|
||||
<div class="input-group">
|
||||
<input type="text" class="form-control font-monospace" id="quick-jump-cmd" readonly>
|
||||
<button class="btn btn-outline-secondary" onclick="copySshCommand('#quick-jump-cmd')" title="Copy">
|
||||
<i class="fa-solid fa-copy"></i>
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="row g-3 mb-4">
|
||||
<div class="col-12">
|
||||
<div class="card shadow-sm">
|
||||
@@ -79,14 +100,38 @@
|
||||
$b.append('<tr><td>' + app.jump.esc(x.name) + '</td><td class="text-end">' + x.count + '</td></tr>');
|
||||
});
|
||||
}
|
||||
// The web UI and the SSH front door share a hostname, just not a port.
|
||||
var SSH_PORT = <%- JSON.stringify(sshPort) %>;
|
||||
function sshCommand(target){
|
||||
var uid = app.auth.user && app.auth.user.username;
|
||||
if(!uid) return '';
|
||||
var portFlag = SSH_PORT === 22 ? '' : ' -p ' + SSH_PORT;
|
||||
return 'ssh ' + uid + (target ? '_-_' + target : '') + '@' + location.hostname + portFlag;
|
||||
}
|
||||
function copySshCommand(sel){
|
||||
var $el = $(sel);
|
||||
var text = $el.val();
|
||||
if(!text) return;
|
||||
navigator.clipboard.writeText(text).then(function(){
|
||||
app.messages.toast('Copied to clipboard', 'success');
|
||||
}, function(){
|
||||
app.messages.toast('Could not copy — select and copy manually', 'danger');
|
||||
});
|
||||
}
|
||||
|
||||
function hostRows(sel, hosts){
|
||||
var $b = $(sel).empty();
|
||||
if(!hosts || !hosts.length){ $b.append('<tr><td class="text-muted">No hosts reachable.</td></tr>'); return; }
|
||||
hosts.forEach(function(h){
|
||||
var addr = (h.metadata && (h.metadata.ip || h.metadata.address)) || '';
|
||||
var rowId = 'host-cmd-' + h.slug.replace(/[^a-zA-Z0-9_-]/g, '');
|
||||
$b.append('<tr><td>' + app.jump.esc(h.displayName || h.name || h.slug) + '</td>'
|
||||
+ '<td class="text-muted small">' + app.jump.esc(h.slug) + '</td>'
|
||||
+ '<td class="text-end text-muted small">' + app.jump.esc(addr) + '</td></tr>');
|
||||
+ '<td class="text-end text-muted small">' + app.jump.esc(addr) + '</td>'
|
||||
+ '<td class="text-end">'
|
||||
+ '<input type="hidden" id="' + rowId + '" value="' + app.jump.esc(sshCommand(h.slug)) + '">'
|
||||
+ '<button class="btn btn-sm btn-outline-secondary" onclick="copySshCommand(\'#' + rowId + '\')" title="Copy quick-jump command"><i class="fa-solid fa-copy"></i></button>'
|
||||
+ '</td></tr>');
|
||||
});
|
||||
}
|
||||
function tokenRows(tokens){
|
||||
@@ -185,6 +230,7 @@
|
||||
});
|
||||
await app.auth.loadUser();
|
||||
if(app.auth.isAdmin()) $('#my-hosts-title').text('All hosts');
|
||||
$('#quick-jump-cmd').val(sshCommand());
|
||||
app.jump.hosts(function(error, data){
|
||||
if(error) return hostRows('#my-hosts', []);
|
||||
hostRows('#my-hosts', data && data.results);
|
||||
|
||||
Reference in New Issue
Block a user