36e9d5b0b3
An SSH jump host that authenticates users against the shared LDAP directory, authorizes them from the SSO Manager's inventory graph, and bridges them to downstream hosts — auditing everything. - Username-grammar routing (uid_-_target@jump) + interactive TUI picker - Inbound LDAP auth (publickey / password with off|local|all policy) - Directory-driven access (LDAP groups x /api/discovery/resources?group=) - Per-user key injection into sshPublicKey, connects downstream as the user - Shell / exec / SFTP-subsystem bridging (WinSCP works) - Web UI + HTTP API (:3002) for audit + metrics; LDAP-admin gated - Packaged like proxy: ops/install.sh + systemd, all-in-one Docker, compose - Tests: 23 unit + 3 integration (node --test), all green Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
43 lines
1.1 KiB
JavaScript
43 lines
1.1 KiB
JavaScript
'use strict';
|
|
|
|
// Web UI sessions — a signed-in admin's browser token. model-redis Table with
|
|
// a TTL so entries expire and survive restarts.
|
|
|
|
const crypto = require('crypto');
|
|
const Table = require('.');
|
|
|
|
class Session extends Table {
|
|
static _key = 'token';
|
|
static _keyMap = {
|
|
'token': {default: function(){ return crypto.randomUUID() }, type: 'string'},
|
|
'uid': {isRequired: true, type: 'string'},
|
|
'groups': {default: '[]', type: 'string'},
|
|
'created_on': {default: function(){ return (new Date).getTime() }},
|
|
'expires_at': {default: 0, type: 'number'},
|
|
}
|
|
}
|
|
|
|
Session.register();
|
|
|
|
Session.start = async function (uid, groups, ttlMs) {
|
|
return Session.create({
|
|
uid,
|
|
groups: JSON.stringify(groups || []),
|
|
expires_at: Date.now() + ttlMs,
|
|
}, { ttl: Math.ceil(ttlMs / 1000) });
|
|
};
|
|
|
|
Session.verify = async function (token) {
|
|
if (!token) return null;
|
|
let session;
|
|
try {
|
|
session = await Session.get(token);
|
|
} catch (_) {
|
|
return null;
|
|
}
|
|
if (!session || session.expires_at < Date.now()) return null;
|
|
return session;
|
|
};
|
|
|
|
module.exports = Session;
|