36e9d5b0b3
An SSH jump host that authenticates users against the shared LDAP directory, authorizes them from the SSO Manager's inventory graph, and bridges them to downstream hosts — auditing everything. - Username-grammar routing (uid_-_target@jump) + interactive TUI picker - Inbound LDAP auth (publickey / password with off|local|all policy) - Directory-driven access (LDAP groups x /api/discovery/resources?group=) - Per-user key injection into sshPublicKey, connects downstream as the user - Shell / exec / SFTP-subsystem bridging (WinSCP works) - Web UI + HTTP API (:3002) for audit + metrics; LDAP-admin gated - Packaged like proxy: ops/install.sh + systemd, all-in-one Docker, compose - Tests: 23 unit + 3 integration (node --test), all green Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
20 lines
747 B
Plaintext
20 lines
747 B
Plaintext
<!doctype html>
|
|
<html lang="en">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
<title><%= name %> — Jump Host login</title>
|
|
<link rel="stylesheet" href="/public/css/app.css">
|
|
</head>
|
|
<body class="center">
|
|
<form method="post" action="/login" class="card login">
|
|
<h1><%= name %> <small>jump host</small></h1>
|
|
<% if (error) { %><p class="err"><%= error %></p><% } %>
|
|
<label>Username <input name="uid" autofocus autocomplete="username"></label>
|
|
<label>Password <input name="password" type="password" autocomplete="current-password"></label>
|
|
<button type="submit">Sign in</button>
|
|
<p class="hint">Admin group required. Uses your directory (LDAP) credentials.</p>
|
|
</form>
|
|
</body>
|
|
</html>
|