4326d5588e
jump-host had zero API-token support: no model, no route, no UI, and Auth.checkApiToken was explicitly absent from the createOidcClient() call (per the comment it left behind). proxy and sso-manager-node both have this; jump-host didn't. Ports proxy's models/api_token.js + routes/api_token.js pattern (jmp_ prefix instead of prx_), wires checkApiToken into createOidcClient(), adds Bearer-token support to middleware/auth.js, and adds a token management card to dashboard.ejs (create/list/rotate/revoke) using app.modal/ app.messages. Scope note: a jump-host token carries no group claims (unlike proxy's, which snapshots the creator's groups), so it authenticates as its creator for non-admin routes (e.g. GET /api/user/hosts) but can never pass requireAdmin — a deliberate, conservative default rather than recomputing live admin status per-request. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
20 lines
782 B
JavaScript
20 lines
782 B
JavaScript
'use strict';
|
|
|
|
const router = require('express').Router();
|
|
const middleware = require('../middleware/auth');
|
|
|
|
// Authentication (local login + OIDC handshake). Unauthenticated by design.
|
|
router.use('/auth', require('../models').authRouter);
|
|
|
|
// Who am I — needs a valid session but no admin gate (drives the login state).
|
|
router.use('/user', middleware.auth, require('./user'));
|
|
|
|
// Self-service API token (PAT) management — any authenticated user, no
|
|
// admin gate (see routes/api_token.js for why a token can't reach admin routes).
|
|
router.use('/api-token', middleware.auth, require('./api_token'));
|
|
|
|
// Jump-host data — admin only (audit log, active sessions, metrics).
|
|
router.use('/', middleware.auth, middleware.requireAdmin, require('./jump'));
|
|
|
|
module.exports = router;
|