972f9ace0a
Two real bugs found while live-testing the new GET /api/mesh/self
endpoint with two actual jump-host containers (mesh-joined for real,
not mocked):
1. routes/api.js mounted `/` (routes/jump.js, admin-session-gated)
before `/mesh`. Since router.use('/', ...) matches every /api/*
path, EVERY /api/mesh/* request -- including /register, which is
authenticated by a bearer mesh join token, not an admin session --
hit that admin gate first and 401'd before routes/mesh.js ever ran.
Confirmed live: a real gateway-to-gateway /join call failed with a
checkApiToken/LoginFailed error instead of ever reaching /register.
Reordered so /mesh is mounted first.
2. POST /register (the receiving side of a join) persists a `(self)`
registry entry via ensureOwnMeshIndex(), but POST /join (the
initiating side) never did -- so GET /api/mesh/self and the mesh
UI's own-entry handling silently saw nothing on whichever gateway
called /join. Fixed by registering a self-entry there too, using
the exact meshIndex the remote assigned (models/mesh_gateway.js's
register() now accepts an explicit meshIndex instead of always
auto-picking one from the local registry, which has no reason to
agree with what's actually configured on the live wg0 interface).
Verified with two real containers joined over a live network: both
sides now report their own correct mesh IP via GET /api/mesh/self,
and both appear correctly in GET /api/mesh/gateways.
34 lines
1.6 KiB
JavaScript
34 lines
1.6 KiB
JavaScript
'use strict';
|
|
|
|
const router = require('express').Router();
|
|
const middleware = require('../middleware/auth');
|
|
|
|
// Authentication (local login + OIDC handshake). Unauthenticated by design.
|
|
router.use('/auth', require('../models').authRouter);
|
|
|
|
// Who am I — needs a valid session but no admin gate (drives the login state).
|
|
router.use('/user', middleware.auth, require('./user'));
|
|
|
|
// Self-service API token (PAT) management — any authenticated user, no
|
|
// admin gate (see routes/api_token.js for why a token can't reach admin routes).
|
|
router.use('/api-token', middleware.auth, require('./api_token'));
|
|
|
|
// WireGuard peer + site management — admin only.
|
|
router.use('/wireguard', middleware.auth, middleware.requireJumpAdmin, require('./wireguard'));
|
|
|
|
// Gateway-to-gateway mesh — mixed auth (register/register-* are called by a
|
|
// remote gateway with a bearer join token, not an admin session; join-tokens
|
|
// mint + join are admin-gated). See routes/mesh.js for the per-route gates.
|
|
// MUST be registered before the '/' mount below: '/' matches every /api/*
|
|
// path (it's the catch-all for routes/jump.js), so registering it first
|
|
// would shadow every /api/mesh/* route with admin-session auth before
|
|
// routes/mesh.js's own per-route gates ever ran -- confirmed live, this
|
|
// silently 401'd /register's bearer-join-token callers with a
|
|
// checkApiToken/LoginFailed error instead of ever reaching mesh.js.
|
|
router.use('/mesh', require('./mesh'));
|
|
|
|
// Jump-host data — jump admin only (audit log, active sessions, metrics).
|
|
router.use('/', middleware.auth, middleware.requireJumpAdmin, require('./jump'));
|
|
|
|
module.exports = router;
|