Release 1.3.0: adopt shared @simpleworkjs/* packages; fix LDAP filter injection

Rewire onto the shared @simpleworkjs/oidc-client, /ldap, and /app-stack
packages (deleting the byte-identical local forks of the same code), close the
LDAP filter-injection in User.get by routing the username through escapeFilter
(RFC 4515), align model-redis ^1.6.0 and ldapts ^8.1.8, and unify build_info to
{buildVersion, buildHash, buildYear}. package-lock regenerated from the npm
registry (no file:/link:), so npm ci is clean in docker builds.

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
2026-07-25 15:53:30 -04:00
parent 60dbfe5b9b
commit f4efdfb957
20 changed files with 121 additions and 587 deletions
+3 -2
View File
@@ -3,7 +3,8 @@
/**
* Per-host SSO endpoints (#57), served under /__proxy_auth on EVERY proxied host
* (nginx routes that path here; see ops/nginx_conf/proxy.conf). These run the
* OIDC authorization-code flow (reusing utils/oidc.js and conf.oidc) and, on a
* OIDC authorization-code flow (reusing @simpleworkjs/oidc-client's pure oidc
* utils and conf.oidc) and, on a
* successful + authorized login, mint a Redis-backed SsoSession and set the
* `__proxy_sso` cookie for the host. OpenResty then gates the host on that
* session (ops/nginx_conf/hostfeatures.lua).
@@ -15,7 +16,7 @@
const router = require('express').Router();
const conf = require('@simpleworkjs/conf');
const oidc = require('../utils/oidc');
const {oidc} = require('@simpleworkjs/oidc-client');
const {Host} = require('../models').models;
const {HostSsoState, SsoSession} = require('../models/sso_session');
const {identityAllowed} = require('../utils/host_sso');