36e9d5b0b3
An SSH jump host that authenticates users against the shared LDAP directory, authorizes them from the SSO Manager's inventory graph, and bridges them to downstream hosts — auditing everything. - Username-grammar routing (uid_-_target@jump) + interactive TUI picker - Inbound LDAP auth (publickey / password with off|local|all policy) - Directory-driven access (LDAP groups x /api/discovery/resources?group=) - Per-user key injection into sshPublicKey, connects downstream as the user - Shell / exec / SFTP-subsystem bridging (WinSCP works) - Web UI + HTTP API (:3002) for audit + metrics; LDAP-admin gated - Packaged like proxy: ops/install.sh + systemd, all-in-one Docker, compose - Tests: 23 unit + 3 integration (node --test), all green Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
25 lines
735 B
JavaScript
25 lines
735 B
JavaScript
'use strict';
|
|
|
|
// Short git commit, baked into /app/.build_commit at image build time (see
|
|
// Dockerfile gitinfo stage) or resolved from git on bare metal.
|
|
|
|
const fs = require('fs');
|
|
const path = require('path');
|
|
const { execSync } = require('child_process');
|
|
|
|
function resolve() {
|
|
try {
|
|
const baked = path.join(__dirname, '../../.build_commit');
|
|
if (fs.existsSync(baked)) return fs.readFileSync(baked, 'utf8').trim();
|
|
} catch (_) {}
|
|
try {
|
|
return execSync('git rev-parse --short HEAD', { stdio: ['ignore', 'pipe', 'ignore'] }).toString().trim();
|
|
} catch (_) {}
|
|
return 'unknown';
|
|
}
|
|
|
|
let version = 'unknown';
|
|
try { version = require('../package.json').version; } catch (_) {}
|
|
|
|
module.exports = { commit: resolve(), version };
|