67e2fc54c2
Rewire onto the shared @simpleworkjs/oidc-client, /directory-schema, /ldap, and
/app-stack packages (deleting the byte-identical local forks). utils/access.js
now fetches reachable hosts through the shared directory client, which
validates the {results} envelope and treats envelope drift as a failed group
rather than silently returning []. models/user_ldap.js is a thin wrapper over
createLdapClient (loose TLS default preserved). build_info moves to utils/ with
the shared {buildVersion,buildHash,buildYear} shape. Align ldapts ^8.1.8 and
redis ^6.1.0. Lockfile regenerated from the registry (no file:/link:).
Co-Authored-By: Claude <noreply@anthropic.com>
52 lines
1.9 KiB
JavaScript
52 lines
1.9 KiB
JavaScript
'use strict';
|
|
|
|
// model-redis backing (same store the sibling apps use). Table is the base
|
|
// class; getRedis() exposes the underlying node-redis client for the counters
|
|
// and sorted-set index in models/metrics.js and models/audit_event.js.
|
|
|
|
const conf = require('@simpleworkjs/conf');
|
|
const { setUpTable } = require('model-redis');
|
|
const { createOidcClient, bootstrapLocalAdmin } = require('@simpleworkjs/oidc-client');
|
|
|
|
const Table = setUpTable(conf.redis);
|
|
|
|
module.exports = Table;
|
|
|
|
// The raw node-redis client (created + connecting inside model-redis) — used
|
|
// for the INCR counters and the sorted-set audit index. model-redis connects
|
|
// it asynchronously; ensure it's open before first use.
|
|
let readyPromise;
|
|
async function getRedis() {
|
|
const client = Table.redisClient;
|
|
if (!readyPromise) {
|
|
readyPromise = (async () => {
|
|
if (!client.isOpen) {
|
|
try { await client.connect(); } catch (_) { /* already connecting */ }
|
|
}
|
|
return client;
|
|
})();
|
|
}
|
|
await readyPromise;
|
|
return client;
|
|
}
|
|
|
|
module.exports.getRedis = getRedis;
|
|
|
|
// Register models (order matters: User before AuthToken's relation resolves).
|
|
require('./user_redis'); // User (redis-backed local + OIDC JIT)
|
|
|
|
// Shared OIDC client (authorization-code + PKCE): session models (Token,
|
|
// AuthToken, OidcState), the Auth service, and the /login /logout /oidc/start
|
|
// /oidc/callback router — all created on this app's Table/redis. jump-host has
|
|
// no Bearer PATs, so checkApiToken is omitted (Auth.checkApiToken is absent).
|
|
const oidcClient = createOidcClient({ Table });
|
|
module.exports.Token = oidcClient.Token;
|
|
module.exports.AuthToken = oidcClient.AuthToken;
|
|
module.exports.OidcState = oidcClient.OidcState;
|
|
module.exports.Auth = oidcClient.Auth;
|
|
module.exports.authRouter = oidcClient.router;
|
|
|
|
require('./audit_event');
|
|
|
|
// Idempotent anti-lockout local admin (was the IIFE in user_redis.js).
|
|
bootstrapLocalAdmin(Table.models.User, { defaultName: 'jumpadmin' }); |