Compare commits
31 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 876ea6cfd0 | |||
| 9100e92549 | |||
| 9a83fb8252 | |||
| 17b903e228 | |||
| 11f44176c0 | |||
| b4d971b508 | |||
| 28f1c53d06 | |||
| 8c3a263937 | |||
| e249b4e168 | |||
| 34b1413c96 | |||
| eded87b6f9 | |||
| a57f3f03f6 | |||
| 5b08eecca9 | |||
| 7c0cb5eabd | |||
| 3f0d6fb438 | |||
| 6cd3a5bc58 | |||
| 88cf5cf281 | |||
| 526545ee68 | |||
| ecf064b9ae | |||
| fd71485960 | |||
| 1c29ba7206 | |||
| 17e9ef2783 | |||
| 983f2a71f0 | |||
| edf60b3e3d | |||
| 1f10d0db14 | |||
| 4bf1768529 | |||
| ed275acbe7 | |||
| 8565f4aa27 | |||
| 8c22d69e44 | |||
| c71b23ef82 | |||
| 7d9c63b049 |
+6
-2
@@ -14,8 +14,6 @@ ops/cookbooks/
|
|||||||
ops/roles/
|
ops/roles/
|
||||||
ops/proxy.service
|
ops/proxy.service
|
||||||
|
|
||||||
# Docs site (served via GitHub Pages, not from the image).
|
|
||||||
docs/
|
|
||||||
.github/
|
.github/
|
||||||
|
|
||||||
# Git + editor + secrets.
|
# Git + editor + secrets.
|
||||||
@@ -24,8 +22,14 @@ docs/
|
|||||||
# nodejs/utils/build_info.js), then it's discarded before the final stage.
|
# nodejs/utils/build_info.js), then it's discarded before the final stage.
|
||||||
# It never ends up in the final image.
|
# It never ends up in the final image.
|
||||||
.gitignore
|
.gitignore
|
||||||
|
# docs/ and the doc files below ARE needed in the image now — served in-app
|
||||||
|
# at /docs (routes/docs.js) so they're readable without internet access.
|
||||||
*.md
|
*.md
|
||||||
!README.md
|
!README.md
|
||||||
|
!CHANGELOG.md
|
||||||
|
!DEPLOYMENT.md
|
||||||
|
!nodejs/api.md
|
||||||
|
!docs/**/*.md
|
||||||
secrets.js
|
secrets.js
|
||||||
secrets.json
|
secrets.json
|
||||||
*.env
|
*.env
|
||||||
|
|||||||
@@ -0,0 +1,84 @@
|
|||||||
|
# Changelog
|
||||||
|
|
||||||
|
All notable changes to this project are documented here. Format loosely
|
||||||
|
follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/); versions
|
||||||
|
correspond to git tags (`vX.Y.Z`) and `nodejs/package.json`'s `version`.
|
||||||
|
|
||||||
|
## [Unreleased]
|
||||||
|
|
||||||
|
## [1.1.9] - 2026-07-17
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- The host list now shows who created each host, and when.
|
||||||
|
- Plain (non-wildcard) hosts can now be renamed after creation — the hostname field is no longer permanently locked. Wildcard hosts, wildcard children, and auto-created subdomain cache entries stay locked, since other records reference them by name.
|
||||||
|
- More inline help text on the host create/edit form (Target SSL, wildcard matching behavior).
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- The host create/edit modal's tabs could overflow awkwardly on narrow (mobile) screens — they now scroll horizontally instead.
|
||||||
|
- Fixed a bug in the vendored `model-redis` library's record-rename path: renaming a record's primary key while another `always`-type field (e.g. `updated_on`) is defined earlier in the schema left a stray, incomplete hash behind under the old key, making that name permanently unavailable for reuse. Worked around in `Host.prototype.update()`.
|
||||||
|
|
||||||
|
Bumps to v1.1.9.
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **Couldn't attach an existing host to a parent wildcard.** The host edit form's "Parent Wildcard" option submitted correctly, but `Host.prototype.update()` had no `challengeType` handling at all (only `Host.create()` did) — selecting it and saving silently did nothing. Added the same wildcard-parent lookup to `update()`.
|
||||||
|
- **Couldn't register a wildcard's own base domain as a host.** A wildcard cert's `altNames` already cover both the base domain and `*.base domain`, but the lookup tree stores the wildcard one level below its base domain, and a lookup for the bare base domain landed on that empty parent node and found nothing — even though the already-issued cert covers it. `buildLookUpObj()` now also stamps the parent node so this resolves correctly, without re-issuing or duplicating the cert.
|
||||||
|
|
||||||
|
Both required a corrected lookup: attaching an *existing* host (which already has its own tree leaf) needed a new `Host.lookUpWildcardParent()` that checks the sibling wildcard slot instead of resolving to the host's own record.
|
||||||
|
|
||||||
|
### Changed
|
||||||
|
- Redesigned the GitHub Pages docs site to match the app's own look (dark navbar/footer, Bootstrap 5, Font Awesome) instead of the generic `jekyll-theme-cayman` theme, added a real cross-page nav, SEO (`jekyll-seo-tag` + `jekyll-sitemap`, per-page descriptions, OG/Twitter tags, sitemap.xml, robots.txt), and mobile-responsive layout.
|
||||||
|
|
||||||
|
## [1.1.6] - 2026-07-16
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Hosts admin UI's Authentication tab radios (Off / Basic / SSO) had no shared `name`, so clicking one didn't uncheck the others -- multiple options could appear selected at once. Added `name="auth_mode"` to restore standard exclusive radio-group behavior.
|
||||||
|
|
||||||
|
## [1.1.5] - 2026-07-16
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- Bumped `jq-repeat` 2.0.1 -> 2.1.0. Fixed real breakage: `users.ejs`/`groups.ejs`/`permissions.ejs` called the removed `$.scope.X.__setPut(fn)`/`__setTake(fn)` setter-method API; insert/remove row hooks are now set via direct property assignment (`$.scope.X.__put = fn`), matching 2.1.0's API.
|
||||||
|
|
||||||
|
## [1.1.4] - 2026-07-16
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **White-label**: `<title>`, the navbar brand text, and the nav logo image were hardcoded "Proxy - Theta 42"/"Dynamic Proxy". Now driven by new `conf.name`/`conf.logo` keys (defaults unchanged). Footer attribution (copyright, `theta42.com` link, GitHub/license links) and favicon are left as-is. Closes [#45](https://github.com/theta42/proxy/issues/45).
|
||||||
|
|
||||||
|
## [1.1.3] - 2026-07-16
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- `CHANGELOG.md` (this file), backfilled from the release notes for every tag so far and served in-app at `/docs/changelog`. Closes [theta-env#43](https://github.com/theta42/theta-env/issues/43).
|
||||||
|
|
||||||
|
## [1.1.2] - 2026-07-16
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **Air-gap**: `DynamicRecord.refreshAll()` called the public-IP resolvers (`api.ipify.org`, `icanhazip.com`, `ifconfig.me`) every 4h on a timer regardless of whether any dynamic DNS records were configured — the one background network call in the repo not actually gated by feature use. Now skips the lookup entirely when there's nothing to refresh.
|
||||||
|
- Removed the stray, unauthenticated `GET /test` page (a leftover jq-repeat demo) that loaded jQuery + Mustache from external CDNs.
|
||||||
|
- Removed a dead IE<9-only `html5shim` script tag pointing at a domain that no longer resolves.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- **In-app documentation**: `GET /docs` and `GET /docs/:slug` render this project's own README, DEPLOYMENT, `api.md`, and `docs/*.md` server-side — readable from the running app with no dependency on GitHub Pages, which requires internet access to view. Public, no auth, rate-limited.
|
||||||
|
|
||||||
|
## [1.1.1] - 2026-07-16
|
||||||
|
|
||||||
|
### Fixed
|
||||||
|
- **DuckDNS provider**: adding a DuckDNS provider no longer pushes this host's public IP to the domain's live A/AAAA record as a side effect of token validation. Validation now writes a fixed marker to the TXT record instead, leaving routing untouched. ([#142](https://github.com/theta42/proxy/pull/142))
|
||||||
|
|
||||||
|
## [1.1.0] - 2026-07-16
|
||||||
|
|
||||||
|
First tagged release. Establishes the `vX.Y.Z` tag convention that the in-app update-check banner polls against going forward.
|
||||||
|
|
||||||
|
### Added
|
||||||
|
- Standalone backup script (`ops/backup.sh`) for deployments not using theta-env's orchestrator — snapshots Redis and `./config`, with retention.
|
||||||
|
- Admin-only in-app banner that checks GitHub releases every 24h and surfaces available updates.
|
||||||
|
|
||||||
|
[Unreleased]: https://github.com/theta42/proxy/compare/v1.1.9...HEAD
|
||||||
|
[1.1.9]: https://github.com/theta42/proxy/compare/v1.1.8...v1.1.9
|
||||||
|
[1.1.8]: https://github.com/theta42/proxy/compare/v1.1.7...v1.1.8
|
||||||
|
[1.1.7]: https://github.com/theta42/proxy/compare/v1.1.6...v1.1.7
|
||||||
|
[1.1.6]: https://github.com/theta42/proxy/compare/v1.1.5...v1.1.6
|
||||||
|
[1.1.5]: https://github.com/theta42/proxy/compare/v1.1.4...v1.1.5
|
||||||
|
[1.1.4]: https://github.com/theta42/proxy/compare/v1.1.3...v1.1.4
|
||||||
|
[1.1.3]: https://github.com/theta42/proxy/compare/v1.1.2...v1.1.3
|
||||||
|
[1.1.2]: https://github.com/theta42/proxy/compare/v1.1.1...v1.1.2
|
||||||
|
[1.1.1]: https://github.com/theta42/proxy/compare/v1.1.0...v1.1.1
|
||||||
|
[1.1.0]: https://github.com/theta42/proxy/releases/tag/v1.1.0
|
||||||
+10
@@ -106,6 +106,16 @@ COPY nodejs/services ./services
|
|||||||
COPY nodejs/utils ./utils
|
COPY nodejs/utils ./utils
|
||||||
COPY nodejs/views ./views
|
COPY nodejs/views ./views
|
||||||
COPY nodejs/public ./public
|
COPY nodejs/public ./public
|
||||||
|
COPY nodejs/api.md ./api.md
|
||||||
|
|
||||||
|
# Documentation, served in-app at /docs (routes/docs.js) so it's readable
|
||||||
|
# without internet access. README.md/DEPLOYMENT.md land one level above the
|
||||||
|
# flattened /app (mirrors sso-manager-node's tos.md -> /tos.md convention);
|
||||||
|
# docs/ mirrors the repo's own top-level docs/ folder.
|
||||||
|
COPY README.md /README.md
|
||||||
|
COPY CHANGELOG.md /CHANGELOG.md
|
||||||
|
COPY DEPLOYMENT.md /DEPLOYMENT.md
|
||||||
|
COPY docs /docs
|
||||||
|
|
||||||
# Baked commit hash from the gitinfo stage (see build_info.js).
|
# Baked commit hash from the gitinfo stage (see build_info.js).
|
||||||
COPY --from=gitinfo /commit.txt ./.build_commit
|
COPY --from=gitinfo /commit.txt ./.build_commit
|
||||||
|
|||||||
@@ -17,6 +17,8 @@ proxy serves them over TLS with auto-renewing certs and no downtime on changes.
|
|||||||
> the proxy and the SSO find each other without manual config.
|
> the proxy and the SSO find each other without manual config.
|
||||||
|
|
||||||
**Documentation:** [https://theta42.github.io/proxy/](https://theta42.github.io/proxy/)
|
**Documentation:** [https://theta42.github.io/proxy/](https://theta42.github.io/proxy/)
|
||||||
|
([CHANGELOG.md](CHANGELOG.md) for what changed in each release) — also
|
||||||
|
readable from the running app itself at `/docs`, no internet access required.
|
||||||
|
|
||||||
## Screenshots
|
## Screenshots
|
||||||
|
|
||||||
|
|||||||
+41
-3
@@ -1,9 +1,47 @@
|
|||||||
title: Proxy
|
title: Proxy
|
||||||
description: A reverse proxy and HTTPS termination service using OpenResty/nginx with a management API and web GUI
|
description: A reverse proxy and HTTPS termination service built on OpenResty/nginx, with an OIDC + LDAP-aware management API and web GUI.
|
||||||
theme: jekyll-theme-cayman
|
url: "https://theta42.github.io"
|
||||||
show_downloads: false
|
baseurl: "/proxy"
|
||||||
|
logo: /assets/img/theta42.svg
|
||||||
|
lang: en_US
|
||||||
|
|
||||||
|
plugins:
|
||||||
|
- jekyll-seo-tag
|
||||||
|
- jekyll-sitemap
|
||||||
|
|
||||||
github:
|
github:
|
||||||
repository_url: https://github.com/theta42/proxy
|
repository_url: https://github.com/theta42/proxy
|
||||||
zip_url: https://github.com/theta42/proxy/archive/refs/heads/master.zip
|
zip_url: https://github.com/theta42/proxy/archive/refs/heads/master.zip
|
||||||
tar_url: https://github.com/theta42/proxy/archive/refs/heads/master.tar.gz
|
tar_url: https://github.com/theta42/proxy/archive/refs/heads/master.tar.gz
|
||||||
repository_name: theta42/proxy
|
repository_name: theta42/proxy
|
||||||
|
|
||||||
|
nav:
|
||||||
|
- title: Home
|
||||||
|
page: /
|
||||||
|
icon: fa-house
|
||||||
|
- title: Installation
|
||||||
|
page: /installation.html
|
||||||
|
icon: fa-download
|
||||||
|
- title: Architecture
|
||||||
|
page: /architecture.html
|
||||||
|
icon: fa-sitemap
|
||||||
|
- title: API
|
||||||
|
page: /api.html
|
||||||
|
icon: fa-code
|
||||||
|
- title: Docker
|
||||||
|
page: /docker.html
|
||||||
|
icon: fa-box
|
||||||
|
- title: Contributing
|
||||||
|
page: /contributing.html
|
||||||
|
icon: fa-code-branch
|
||||||
|
- title: Changelog
|
||||||
|
url: https://github.com/theta42/proxy/blob/master/CHANGELOG.md
|
||||||
|
icon: fa-list
|
||||||
|
|
||||||
|
defaults:
|
||||||
|
- scope:
|
||||||
|
path: ""
|
||||||
|
type: "pages"
|
||||||
|
values:
|
||||||
|
layout: default
|
||||||
|
image: /assets/img/theta42.svg
|
||||||
|
|||||||
@@ -0,0 +1,82 @@
|
|||||||
|
<!doctype html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
||||||
|
<link rel="icon" type="image/svg+xml" href="{{ '/assets/img/favicon.svg' | relative_url }}">
|
||||||
|
|
||||||
|
{% seo title=false %}
|
||||||
|
<title>{% if page.title %}{{ page.title }} · {% endif %}{{ site.title }}</title>
|
||||||
|
|
||||||
|
<link rel="stylesheet" href="https://cdn.jsdelivr.net/npm/bootstrap@5.3.3/dist/css/bootstrap.min.css">
|
||||||
|
<link rel="stylesheet" href="https://cdnjs.cloudflare.com/ajax/libs/font-awesome/6.5.2/css/all.min.css">
|
||||||
|
<link rel="stylesheet" href="{{ '/assets/css/style.css' | relative_url }}">
|
||||||
|
</head>
|
||||||
|
<body class="d-flex flex-column min-vh-100">
|
||||||
|
|
||||||
|
<nav class="navbar navbar-expand-md navbar-dark bg-dark fixed-top">
|
||||||
|
<div class="container-fluid px-3">
|
||||||
|
<a class="navbar-brand d-flex align-items-center" href="{{ '/' | relative_url }}">
|
||||||
|
<img src="{{ '/assets/img/theta42.svg' | relative_url }}" height="28" class="me-2" alt="">
|
||||||
|
{{ site.title }}
|
||||||
|
</a>
|
||||||
|
<button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navMain" aria-controls="navMain" aria-expanded="false" aria-label="Toggle navigation">
|
||||||
|
<span class="navbar-toggler-icon"></span>
|
||||||
|
</button>
|
||||||
|
<div class="collapse navbar-collapse justify-content-end" id="navMain">
|
||||||
|
<ul class="navbar-nav">
|
||||||
|
{% for item in site.nav %}
|
||||||
|
<li class="nav-item">
|
||||||
|
{% if item.page %}
|
||||||
|
<a class="nav-link{% if page.url == item.page %} active{% endif %}" href="{{ item.page | relative_url }}">
|
||||||
|
{% if item.icon %}<i class="fa-solid {{ item.icon }}"></i>{% endif %} {{ item.title }}
|
||||||
|
</a>
|
||||||
|
{% else %}
|
||||||
|
<a class="nav-link" href="{{ item.url }}" target="_blank" rel="noopener">
|
||||||
|
{% if item.icon %}<i class="fa-solid {{ item.icon }}"></i>{% endif %} {{ item.title }}
|
||||||
|
</a>
|
||||||
|
{% endif %}
|
||||||
|
</li>
|
||||||
|
{% endfor %}
|
||||||
|
</ul>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</nav>
|
||||||
|
|
||||||
|
<main class="flex-grow-1" style="margin-top: 4.5rem;">
|
||||||
|
<div class="container-fluid py-4 py-md-5">
|
||||||
|
<div class="row justify-content-center">
|
||||||
|
<div class="col-12 col-lg-10 col-xl-8">
|
||||||
|
<div class="card shadow-lg">
|
||||||
|
<div class="card-body p-4 p-md-5 site-content">
|
||||||
|
{{ content }}
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</main>
|
||||||
|
|
||||||
|
<footer class="py-3 bg-dark text-light mt-auto">
|
||||||
|
<div class="container-fluid d-flex flex-wrap justify-content-between align-items-center small gap-2 px-3">
|
||||||
|
<span class="d-flex align-items-center gap-2">
|
||||||
|
<a href="https://theta42.com" target="_blank" rel="noopener">
|
||||||
|
<img width="40" src="{{ '/assets/img/theta42.svg' | relative_url }}" alt="theta42">
|
||||||
|
</a>
|
||||||
|
© {{ 'now' | date: '%Y' }} theta42 ·
|
||||||
|
<a href="{{ site.github.repository_url }}/blob/master/LICENSE" target="_blank" rel="noopener" class="text-light">MIT License</a>
|
||||||
|
</span>
|
||||||
|
<span class="d-flex align-items-center gap-3">
|
||||||
|
<a href="{{ site.github.repository_url }}" target="_blank" rel="noopener" class="text-light text-decoration-none">
|
||||||
|
<i class="fa-brands fa-github"></i> GitHub
|
||||||
|
</a>
|
||||||
|
<a href="{{ site.github.repository_url }}/blob/master/CHANGELOG.md" target="_blank" rel="noopener" class="text-light text-decoration-none">
|
||||||
|
<i class="fa-solid fa-list"></i> Changelog
|
||||||
|
</a>
|
||||||
|
</span>
|
||||||
|
</div>
|
||||||
|
</footer>
|
||||||
|
|
||||||
|
<script src="https://cdn.jsdelivr.net/npm/bootstrap@5.3.3/dist/js/bootstrap.bundle.min.js"></script>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: API Reference
|
title: API Reference
|
||||||
|
description: The proxy's management REST API — hosts, DNS providers, users, groups, and permissions.
|
||||||
---
|
---
|
||||||
|
|
||||||
# API Documentation
|
# API Documentation
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Architecture
|
title: Architecture
|
||||||
|
description: How the proxy's OIDC client, LDAP client, and OpenResty routing fit together.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Architecture
|
# Architecture
|
||||||
|
|||||||
@@ -0,0 +1,116 @@
|
|||||||
|
/* theta42 docs site — shares the in-app dark navbar/footer + card look
|
||||||
|
(Bootstrap 5 + Font Awesome, same as the running apps) rather than a
|
||||||
|
generic Jekyll theme. */
|
||||||
|
|
||||||
|
body {
|
||||||
|
background-color: #f4f5f6;
|
||||||
|
}
|
||||||
|
|
||||||
|
.navbar-brand img {
|
||||||
|
filter: drop-shadow(0 0 2px rgba(0, 0, 0, .4));
|
||||||
|
}
|
||||||
|
|
||||||
|
.navbar-nav .nav-link.active {
|
||||||
|
color: #fff;
|
||||||
|
font-weight: 600;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Markdown content typography, scoped to the card body so it doesn't leak
|
||||||
|
into the nav/footer. */
|
||||||
|
.site-content h1:first-child {
|
||||||
|
margin-top: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content h1,
|
||||||
|
.site-content h2,
|
||||||
|
.site-content h3 {
|
||||||
|
font-weight: 700;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content h2 {
|
||||||
|
margin-top: 2.5rem;
|
||||||
|
padding-bottom: .4rem;
|
||||||
|
border-bottom: 1px solid #e9ecef;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content h3 {
|
||||||
|
margin-top: 1.75rem;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content a {
|
||||||
|
color: #a3671f;
|
||||||
|
text-decoration-color: rgba(163, 103, 31, .35);
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content a:hover {
|
||||||
|
color: #8a5a16;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content pre {
|
||||||
|
background-color: #212529;
|
||||||
|
color: #f8f9fa;
|
||||||
|
padding: 1rem 1.25rem;
|
||||||
|
border-radius: .375rem;
|
||||||
|
overflow-x: auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content code {
|
||||||
|
color: #a3671f;
|
||||||
|
background-color: #f4f0e8;
|
||||||
|
padding: .15em .4em;
|
||||||
|
border-radius: .25rem;
|
||||||
|
font-size: .875em;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content pre code {
|
||||||
|
color: inherit;
|
||||||
|
background: none;
|
||||||
|
padding: 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content table {
|
||||||
|
display: block;
|
||||||
|
overflow-x: auto;
|
||||||
|
width: 100%;
|
||||||
|
border-collapse: collapse;
|
||||||
|
margin: 1.25rem 0;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content table th,
|
||||||
|
.site-content table td {
|
||||||
|
border: 1px solid #dee2e6;
|
||||||
|
padding: .5rem .75rem;
|
||||||
|
text-align: left;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content table th {
|
||||||
|
background-color: #f8f9fa;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content blockquote {
|
||||||
|
border-left: 4px solid #C59341;
|
||||||
|
padding: .5rem 1rem;
|
||||||
|
margin: 1.25rem 0;
|
||||||
|
background-color: #f8f6f1;
|
||||||
|
color: #495057;
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content img {
|
||||||
|
max-width: 100%;
|
||||||
|
height: auto;
|
||||||
|
}
|
||||||
|
|
||||||
|
/* Screenshot grids in the markdown use width="49%" inline attrs for a
|
||||||
|
two-up desktop layout -- stack them on narrow screens instead of
|
||||||
|
squeezing to illegibility. */
|
||||||
|
@media (max-width: 576px) {
|
||||||
|
.site-content img[width] {
|
||||||
|
width: 100% !important;
|
||||||
|
margin-bottom: .75rem;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
.site-content hr {
|
||||||
|
margin: 2rem 0;
|
||||||
|
border-top: 1px solid #e9ecef;
|
||||||
|
}
|
||||||
@@ -0,0 +1,17 @@
|
|||||||
|
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 100 100">
|
||||||
|
<!-- Background circle -->
|
||||||
|
<circle cx="50" cy="50" r="48" fill="#1a1a1a" stroke="#4a9eff" stroke-width="3"/>
|
||||||
|
|
||||||
|
<!-- Network nodes -->
|
||||||
|
<circle cx="30" cy="30" r="8" fill="#4a9eff"/>
|
||||||
|
<circle cx="70" cy="30" r="8" fill="#4a9eff"/>
|
||||||
|
<circle cx="50" cy="50" r="10" fill="#66b3ff"/>
|
||||||
|
<circle cx="30" cy="70" r="8" fill="#4a9eff"/>
|
||||||
|
<circle cx="70" cy="70" r="8" fill="#4a9eff"/>
|
||||||
|
|
||||||
|
<!-- Connection lines -->
|
||||||
|
<line x1="30" y1="30" x2="50" y2="50" stroke="#4a9eff" stroke-width="2"/>
|
||||||
|
<line x1="70" y1="30" x2="50" y2="50" stroke="#4a9eff" stroke-width="2"/>
|
||||||
|
<line x1="30" y1="70" x2="50" y2="50" stroke="#4a9eff" stroke-width="2"/>
|
||||||
|
<line x1="70" y1="70" x2="50" y2="50" stroke="#4a9eff" stroke-width="2"/>
|
||||||
|
</svg>
|
||||||
|
After Width: | Height: | Size: 788 B |
@@ -0,0 +1,51 @@
|
|||||||
|
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 400 400" width="100%" height="100%">
|
||||||
|
<defs>
|
||||||
|
<linearGradient id="gold-grad" x1="0%" y1="0%" x2="100%" y2="100%">
|
||||||
|
<stop offset="0%" stop-color="#C59341" />
|
||||||
|
<stop offset="20%" stop-color="#E4B869" />
|
||||||
|
<stop offset="40%" stop-color="#FBF0B9" />
|
||||||
|
<stop offset="60%" stop-color="#DFB260" />
|
||||||
|
<stop offset="80%" stop-color="#BC8837" />
|
||||||
|
<stop offset="100%" stop-color="#A36F28" />
|
||||||
|
</linearGradient>
|
||||||
|
|
||||||
|
<linearGradient id="text-grad" x1="0%" y1="100%" x2="100%" y2="0%">
|
||||||
|
<stop offset="0%" stop-color="#FFFFFF" />
|
||||||
|
<stop offset="40%" stop-color="#F5E3B5" />
|
||||||
|
<stop offset="70%" stop-color="#D4A343" />
|
||||||
|
<stop offset="100%" stop-color="#8A5A16" />
|
||||||
|
</linearGradient>
|
||||||
|
|
||||||
|
<filter id="drop-shadow" x="-20%" y="-20%" width="140%" height="140%">
|
||||||
|
<feDropShadow dx="0" dy="8" stdDeviation="6" flood-color="#000000" flood-opacity="0.4"/>
|
||||||
|
</filter>
|
||||||
|
</defs>
|
||||||
|
|
||||||
|
<g filter="url(#drop-shadow)">
|
||||||
|
<g fill="url(#gold-grad)">
|
||||||
|
<path d="M 200,40
|
||||||
|
C 290,40 350,110 350,200
|
||||||
|
C 350,290 290,360 200,360
|
||||||
|
C 110,360 50,290 50,200
|
||||||
|
C 50,110 110,40 200,40 Z
|
||||||
|
M 200,75
|
||||||
|
C 130,75 88,130 88,200
|
||||||
|
C 88,270 130,325 200,325
|
||||||
|
C 270,325 312,270 312,200
|
||||||
|
C 312,130 270,75 200,75 Z"
|
||||||
|
fill-rule="evenodd" />
|
||||||
|
|
||||||
|
<path d="M 88,190 L 140,190 C 140,190 142,210 140,210 L 88,210 Z" />
|
||||||
|
|
||||||
|
<path d="M 260,190 L 312,190 C 312,190 310,210 260,210 Z" />
|
||||||
|
</g>
|
||||||
|
|
||||||
|
<text x="200" y="222"
|
||||||
|
font-family="system-ui, -apple-system, 'Segoe UI', Roboto, Helvetica, Arial, sans-serif"
|
||||||
|
font-size="78"
|
||||||
|
font-weight="900"
|
||||||
|
fill="url(#text-grad)"
|
||||||
|
text-anchor="middle"
|
||||||
|
letter-spacing="-2">42</text>
|
||||||
|
</g>
|
||||||
|
</svg>
|
||||||
|
After Width: | Height: | Size: 1.9 KiB |
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Contributing
|
title: Contributing
|
||||||
|
description: How to contribute to the proxy — dev setup, tests, and code conventions.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Contributing Guide
|
# Contributing Guide
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Docker
|
title: Docker
|
||||||
|
description: Running the proxy's all-in-one Docker image — OpenResty, the management app, and Redis in one container.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Docker Deployment
|
# Docker Deployment
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Home
|
title: Home
|
||||||
|
description: A reverse proxy and HTTPS termination service built on OpenResty/nginx, with automatic Let's Encrypt certs, OIDC login, and direct LDAP access control per host.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Proxy
|
# Proxy
|
||||||
|
|||||||
@@ -1,6 +1,7 @@
|
|||||||
---
|
---
|
||||||
layout: default
|
layout: default
|
||||||
title: Installation
|
title: Installation
|
||||||
|
description: Installing the proxy — Docker, bare metal, or as part of the unified theta-env stack.
|
||||||
---
|
---
|
||||||
|
|
||||||
# Installation Guide
|
# Installation Guide
|
||||||
|
|||||||
@@ -0,0 +1,4 @@
|
|||||||
|
User-agent: *
|
||||||
|
Allow: /
|
||||||
|
|
||||||
|
Sitemap: https://theta42.github.io/proxy/sitemap.xml
|
||||||
@@ -77,6 +77,11 @@ app.use('/__proxy_auth', require('./routes/host_auth'));
|
|||||||
// Routes for front end content.
|
// Routes for front end content.
|
||||||
app.use('/', require('./routes/render'));
|
app.use('/', require('./routes/render'));
|
||||||
|
|
||||||
|
// Local, in-app copy of the project's documentation (README, DEPLOYMENT,
|
||||||
|
// api.md, docs/*) -- public, no auth, so it's readable even by a locked-out
|
||||||
|
// admin or an air-gapped operator with no route to GitHub Pages.
|
||||||
|
app.use('/docs', require('./routes/docs'));
|
||||||
|
|
||||||
// Routes for API
|
// Routes for API
|
||||||
app.use('/api', require('./routes/api'));
|
app.use('/api', require('./routes/api'));
|
||||||
|
|
||||||
|
|||||||
@@ -2,6 +2,8 @@
|
|||||||
// Using https://github.com/simpleworkjs/conf to handle configuration
|
// Using https://github.com/simpleworkjs/conf to handle configuration
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
|
name: "Dynamic Proxy", // displayed in the UI
|
||||||
|
logo: "/static/img/theta42.svg", // shown in the nav; point at your own file under public/ (or an absolute URL) to white-label
|
||||||
userModel: 'redis', // pam, redis, ldap
|
userModel: 'redis', // pam, redis, ldap
|
||||||
ldap: {
|
ldap: {
|
||||||
url: 'ldap://192.168.1.55:389',
|
url: 'ldap://192.168.1.55:389',
|
||||||
|
|||||||
@@ -14,6 +14,14 @@ async function getCert(host){
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
async function setCert(host, cert){
|
||||||
|
try{
|
||||||
|
return await client.SET(`${host}:latest`, JSON.stringify(cert));
|
||||||
|
}catch(error){
|
||||||
|
return {}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
async function deleteCert(host){
|
async function deleteCert(host){
|
||||||
try{
|
try{
|
||||||
console.log('looking for', host);
|
console.log('looking for', host);
|
||||||
@@ -23,4 +31,4 @@ async function deleteCert(host){
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
module.exports = {getCert, deleteCert};
|
module.exports = {getCert, setCert, deleteCert};
|
||||||
|
|||||||
@@ -76,8 +76,17 @@ class DynamicRecord extends Table{
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Resolve the public IP once, then reconcile every record to it.
|
// Resolve the public IP once, then reconcile every record to it. Checked
|
||||||
|
// BEFORE the public-IP lookup: on a stock install with zero dynamic
|
||||||
|
// records configured, this runs on a timer regardless (services/dynamic_dns.js)
|
||||||
|
// -- without this guard it would still reach out to the public-IP
|
||||||
|
// resolvers (utils/public_ip.js) every cycle for nothing, which is
|
||||||
|
// exactly the kind of always-on external call an air-gapped deployment
|
||||||
|
// can't have.
|
||||||
static async refreshAll(){
|
static async refreshAll(){
|
||||||
|
let records = await this.listDetail();
|
||||||
|
if(!records.length) return {count: 0};
|
||||||
|
|
||||||
let ip;
|
let ip;
|
||||||
try{
|
try{
|
||||||
ip = await getPublicIp();
|
ip = await getPublicIp();
|
||||||
@@ -86,7 +95,6 @@ class DynamicRecord extends Table{
|
|||||||
return {error: error.message};
|
return {error: error.message};
|
||||||
}
|
}
|
||||||
|
|
||||||
let records = await this.listDetail();
|
|
||||||
for(let record of records){
|
for(let record of records){
|
||||||
await record.apply(ip);
|
await record.apply(ip);
|
||||||
}
|
}
|
||||||
|
|||||||
+96
-3
@@ -2,7 +2,7 @@
|
|||||||
|
|
||||||
const Table = require('.');
|
const Table = require('.');
|
||||||
const {Domain} = require('.').models;
|
const {Domain} = require('.').models;
|
||||||
const {deleteCert} = require('./cert');
|
const {getCert, setCert, deleteCert} = require('./cert');
|
||||||
const ModelPs = require('../utils/model_pubsub');
|
const ModelPs = require('../utils/model_pubsub');
|
||||||
|
|
||||||
const tldExtract = require('tld-extract').parse_host;
|
const tldExtract = require('tld-extract').parse_host;
|
||||||
@@ -320,12 +320,66 @@ class Host extends Table{
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
async update(...args){
|
async update(data, ...args){
|
||||||
try{
|
try{
|
||||||
let out = await super.update(...args)
|
// Mirror Host.create()'s challengeType handling (lines above) so an
|
||||||
|
// existing HTTP-01 host can be attached to a parent wildcard's cert
|
||||||
|
// after creation -- previously this was silently dropped since only
|
||||||
|
// create() understood challengeType, leaving no way to convert an
|
||||||
|
// existing host onto a wildcard once one was issued.
|
||||||
|
if(data && data.challengeType === 'wildcardChild'){
|
||||||
|
// Not Host.lookUp() -- this.host already has its own leaf in the
|
||||||
|
// tree (it already exists), so a plain lookUp() would just find
|
||||||
|
// itself. lookUpWildcardParent() checks the sibling "*" slot
|
||||||
|
// instead. See its comment for why create()'s own wildcardChild
|
||||||
|
// branch doesn't need this (a host being newly created hasn't
|
||||||
|
// claimed its own leaf yet, so plain lookUp() already falls
|
||||||
|
// through to the wildcard correctly there).
|
||||||
|
let parentHost = Host.lookUpWildcardParent(this.host);
|
||||||
|
if(parentHost && parentHost.is_wildcard){
|
||||||
|
data.wildcard_parent = parentHost.host;
|
||||||
|
}else{
|
||||||
|
throw new Error(`No parent wild card for ${this.host}`);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// Real hostname rename. model-redis's own update() (see super.update()
|
||||||
|
// below) already handles the Redis primary-key RENAME + collision
|
||||||
|
// check, and Host.buildLookUpObj() below already rebuilds the lookup
|
||||||
|
// tree afterward -- but the cert cache (models/cert.js, `${host}:latest`)
|
||||||
|
// is a separate record keyed by hostname string that the generic field
|
||||||
|
// system doesn't know about, so it doesn't move on its own. Only
|
||||||
|
// wildcard hosts (createWildcardCert) ever populate this key -- for a
|
||||||
|
// plain HTTP-01 host this is a no-op (nothing to migrate; auto-ssl
|
||||||
|
// transparently issues a fresh cert under the new name on first
|
||||||
|
// access, same as it does for any newly-created host).
|
||||||
|
let oldHost = this.host;
|
||||||
|
let renaming = data && typeof data.host === 'string' && data.host !== oldHost;
|
||||||
|
if(renaming){
|
||||||
|
let cert = await getCert(oldHost);
|
||||||
|
if(cert && Object.keys(cert).length) await setCert(data.host, cert);
|
||||||
|
}
|
||||||
|
|
||||||
|
let out = await super.update(data, ...args)
|
||||||
await this.bustCache(this.host);
|
await this.bustCache(this.host);
|
||||||
await Host.buildLookUpObj();
|
await Host.buildLookUpObj();
|
||||||
|
|
||||||
|
if(renaming){
|
||||||
|
await deleteCert(oldHost);
|
||||||
|
|
||||||
|
// Work around a model-redis bug (as of ^1.5.0): super.update()'s
|
||||||
|
// field-application loop iterates _keyMap's definition order and
|
||||||
|
// only reassigns this[_key] (this.host) to the NEW value once it
|
||||||
|
// reaches the `host` field itself -- but `updated_on` (always:
|
||||||
|
// true, so always included) is defined BEFORE `host` in _keyMap,
|
||||||
|
// so it gets HSET while this.host is still the OLD name. Redis's
|
||||||
|
// HSET on a non-existent key (the old hash, just RENAMEd away)
|
||||||
|
// silently recreates it -- leaving a stray, incomplete hash under
|
||||||
|
// the old hostname that makes Host.exists(oldHost) wrongly return
|
||||||
|
// true forever, blocking that name from ever being reused.
|
||||||
|
await this.constructor.redisClient.DEL(`${conf.redis.prefix || ''}Host_${oldHost}`);
|
||||||
|
}
|
||||||
|
|
||||||
return out;
|
return out;
|
||||||
} catch(error){
|
} catch(error){
|
||||||
throw error;
|
throw error;
|
||||||
@@ -385,6 +439,25 @@ class Host extends Table{
|
|||||||
// #record denotes a leaf node on this tree.
|
// #record denotes a leaf node on this tree.
|
||||||
if(fragments.length === 0){
|
if(fragments.length === 0){
|
||||||
pointer[fragment]['#record'] = await this.get(host)
|
pointer[fragment]['#record'] = await this.get(host)
|
||||||
|
|
||||||
|
// A single-level wildcard's issued cert also covers its own
|
||||||
|
// base domain (createWildcardCert requests altNames:
|
||||||
|
// [domain, *.domain] -- see utils/letsencrypt.js), but the
|
||||||
|
// base domain sits one level ABOVE the wildcard's own leaf
|
||||||
|
// in this tree (e.g. "*.cool.mysite.com" is a child of the
|
||||||
|
// node for "cool.mysite.com"). Without this, looking up the
|
||||||
|
// bare base domain when it has no host of its own falls
|
||||||
|
// through to nothing, even though the already-issued cert
|
||||||
|
// covers it. `pointer` here is still that parent node
|
||||||
|
// (reassigned to the child only below) -- stamp it too, but
|
||||||
|
// only if a real, explicitly-created host at that exact
|
||||||
|
// name hasn't already claimed this leaf (order-independent:
|
||||||
|
// this only ever fills a gap -- a real host's own pass
|
||||||
|
// through this loop always overwrites #record
|
||||||
|
// unconditionally when it's finalized, see above).
|
||||||
|
if(fragment === '*' && !pointer['#record']){
|
||||||
|
pointer['#record'] = pointer[fragment]['#record'];
|
||||||
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
// Advance the pointer to the next level of the tree.
|
// Advance the pointer to the next level of the tree.
|
||||||
@@ -445,6 +518,26 @@ class Host extends Table{
|
|||||||
if(parent && parent['*'] && parent['*']['#record']) return parent['*']['#record'];
|
if(parent && parent['*'] && parent['*']['#record']) return parent['*']['#record'];
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// Find the wildcard covering @host as its own base domain (e.g.
|
||||||
|
// "*.cool.mysite.com" for host="cool.mysite.com"), regardless of whether
|
||||||
|
// @host is already registered as its own host. Unlike lookUp(), which
|
||||||
|
// walks to and returns @host's own exact-match leaf when one exists, this
|
||||||
|
// walks to that exact position and looks one level deeper at its "*"
|
||||||
|
// child -- the sibling wildcard slot -- so it still finds the parent
|
||||||
|
// wildcard even when @host already has its own (non-wildcard) record.
|
||||||
|
// Used when attaching an already-created host to a wildcard after the
|
||||||
|
// fact (see update() below); Host.create()'s own wildcardChild handling
|
||||||
|
// can keep using plain lookUp() since a host being newly created hasn't
|
||||||
|
// claimed its own leaf yet.
|
||||||
|
static lookUpWildcardParent(host){
|
||||||
|
let place = this.lookUpObj;
|
||||||
|
for(let fragment of host.split('.').reverse()){
|
||||||
|
if(!place[fragment]) return undefined;
|
||||||
|
place = place[fragment];
|
||||||
|
}
|
||||||
|
if(place['*'] && place['*']['#record']) return place['*']['#record'];
|
||||||
|
}
|
||||||
|
|
||||||
static async lookUpReady(){
|
static async lookUpReady(){
|
||||||
/*
|
/*
|
||||||
Wait for the lookup tree to be built.
|
Wait for the lookup tree to be built.
|
||||||
|
|||||||
Generated
+19
-6
@@ -1,12 +1,12 @@
|
|||||||
{
|
{
|
||||||
"name": "proxy-api",
|
"name": "proxy-api",
|
||||||
"version": "1.1.1",
|
"version": "1.1.9",
|
||||||
"lockfileVersion": 3,
|
"lockfileVersion": 3,
|
||||||
"requires": true,
|
"requires": true,
|
||||||
"packages": {
|
"packages": {
|
||||||
"": {
|
"": {
|
||||||
"name": "proxy-api",
|
"name": "proxy-api",
|
||||||
"version": "1.1.1",
|
"version": "1.1.9",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"dependencies": {
|
"dependencies": {
|
||||||
"@fortawesome/fontawesome-free": "^7.3.0",
|
"@fortawesome/fontawesome-free": "^7.3.0",
|
||||||
@@ -21,10 +21,11 @@
|
|||||||
"express": "^5.2.1",
|
"express": "^5.2.1",
|
||||||
"express-rate-limit": "^8.5.2",
|
"express-rate-limit": "^8.5.2",
|
||||||
"extend": "^3.0.2",
|
"extend": "^3.0.2",
|
||||||
"jq-repeat": "^2.0.1",
|
"jq-repeat": "^2.1.0",
|
||||||
"jquery": "^4.0.0",
|
"jquery": "^4.0.0",
|
||||||
"ldapts": "^8.1.8",
|
"ldapts": "^8.1.8",
|
||||||
"linux-sys-user": "^1.2.0",
|
"linux-sys-user": "^1.2.0",
|
||||||
|
"marked": "^9.1.6",
|
||||||
"model-redis": "^1.5.0",
|
"model-redis": "^1.5.0",
|
||||||
"moment": "^2.30.1",
|
"moment": "^2.30.1",
|
||||||
"mustache": "^4.2.0",
|
"mustache": "^4.2.0",
|
||||||
@@ -1374,9 +1375,9 @@
|
|||||||
"license": "MIT"
|
"license": "MIT"
|
||||||
},
|
},
|
||||||
"node_modules/jq-repeat": {
|
"node_modules/jq-repeat": {
|
||||||
"version": "2.0.1",
|
"version": "2.1.0",
|
||||||
"resolved": "https://registry.npmjs.org/jq-repeat/-/jq-repeat-2.0.1.tgz",
|
"resolved": "https://registry.npmjs.org/jq-repeat/-/jq-repeat-2.1.0.tgz",
|
||||||
"integrity": "sha512-ATI25tKQG3uHW8f8XPqBe85JsH4PNGHA/YLy1KgMVeYDoUSf9cqGNBum+4A+Pg1WKh9PA6bYyWfYNsgktwIbSg==",
|
"integrity": "sha512-e1OmSWeBEHEtyOhNVysx0bnT5wd6HlZ37JZgPcGPmACJ0K9bXDPq0xOwrM1slQMSTw7FOSNDX+MD6VwvPeeZyQ==",
|
||||||
"license": "MIT",
|
"license": "MIT",
|
||||||
"engines": {
|
"engines": {
|
||||||
"node": ">=14.0.0"
|
"node": ">=14.0.0"
|
||||||
@@ -1410,6 +1411,18 @@
|
|||||||
"integrity": "sha512-TyPFnk3kp9kplKPjWtYYbezYzj+Xe47bGu3YZs2Jg3xxLUw/ny0AHL252jpR1c8q32vIQxWK8qLpFZ+qHHC0MQ==",
|
"integrity": "sha512-TyPFnk3kp9kplKPjWtYYbezYzj+Xe47bGu3YZs2Jg3xxLUw/ny0AHL252jpR1c8q32vIQxWK8qLpFZ+qHHC0MQ==",
|
||||||
"license": "MIT"
|
"license": "MIT"
|
||||||
},
|
},
|
||||||
|
"node_modules/marked": {
|
||||||
|
"version": "9.1.6",
|
||||||
|
"resolved": "https://registry.npmjs.org/marked/-/marked-9.1.6.tgz",
|
||||||
|
"integrity": "sha512-jcByLnIFkd5gSXZmjNvS1TlmRhCXZjIzHYlaGkPlLIekG55JDR2Z4va9tZwCiP+/RDERiNhMOFu01xd6O5ct1Q==",
|
||||||
|
"license": "MIT",
|
||||||
|
"bin": {
|
||||||
|
"marked": "bin/marked.js"
|
||||||
|
},
|
||||||
|
"engines": {
|
||||||
|
"node": ">= 16"
|
||||||
|
}
|
||||||
|
},
|
||||||
"node_modules/math-intrinsics": {
|
"node_modules/math-intrinsics": {
|
||||||
"version": "1.1.0",
|
"version": "1.1.0",
|
||||||
"resolved": "https://registry.npmjs.org/math-intrinsics/-/math-intrinsics-1.1.0.tgz",
|
"resolved": "https://registry.npmjs.org/math-intrinsics/-/math-intrinsics-1.1.0.tgz",
|
||||||
|
|||||||
+3
-2
@@ -1,6 +1,6 @@
|
|||||||
{
|
{
|
||||||
"name": "proxy-api",
|
"name": "proxy-api",
|
||||||
"version": "1.1.1",
|
"version": "1.1.9",
|
||||||
"private": true,
|
"private": true,
|
||||||
"author": [
|
"author": [
|
||||||
{
|
{
|
||||||
@@ -32,10 +32,11 @@
|
|||||||
"express": "^5.2.1",
|
"express": "^5.2.1",
|
||||||
"express-rate-limit": "^8.5.2",
|
"express-rate-limit": "^8.5.2",
|
||||||
"extend": "^3.0.2",
|
"extend": "^3.0.2",
|
||||||
"jq-repeat": "^2.0.1",
|
"jq-repeat": "^2.1.0",
|
||||||
"jquery": "^4.0.0",
|
"jquery": "^4.0.0",
|
||||||
"ldapts": "^8.1.8",
|
"ldapts": "^8.1.8",
|
||||||
"linux-sys-user": "^1.2.0",
|
"linux-sys-user": "^1.2.0",
|
||||||
|
"marked": "^9.1.6",
|
||||||
"model-redis": "^1.5.0",
|
"model-redis": "^1.5.0",
|
||||||
"moment": "^2.30.1",
|
"moment": "^2.30.1",
|
||||||
"mustache": "^4.2.0",
|
"mustache": "^4.2.0",
|
||||||
|
|||||||
@@ -0,0 +1,81 @@
|
|||||||
|
'use strict';
|
||||||
|
|
||||||
|
const fs = require('fs');
|
||||||
|
const path = require('path');
|
||||||
|
const router = require('express').Router();
|
||||||
|
const {rateLimit} = require('express-rate-limit');
|
||||||
|
const {marked} = require('marked');
|
||||||
|
const conf = require('@simpleworkjs/conf');
|
||||||
|
const buildInfo = require('../utils/build_info');
|
||||||
|
|
||||||
|
// Public, unauthenticated, and reads from disk on every request -- throttle
|
||||||
|
// per IP so it can't be used to hammer the filesystem (mirrors the pattern
|
||||||
|
// in routes/auth.js/routes/host.js), generous since this is just docs.
|
||||||
|
const docsLimiter = rateLimit({
|
||||||
|
windowMs: 60 * 1000,
|
||||||
|
max: 120,
|
||||||
|
standardHeaders: true,
|
||||||
|
legacyHeaders: false,
|
||||||
|
message: {name: 'TooManyRequests', message: 'Too many requests, please try again later.'},
|
||||||
|
});
|
||||||
|
|
||||||
|
const values = {
|
||||||
|
title: conf.environment !== 'production' ? `dev` : '',
|
||||||
|
titleIcon: conf.environment !== 'production' ? `<i class="fa-brands fa-dev"></i>` : '',
|
||||||
|
name: conf.name,
|
||||||
|
logo: conf.logo,
|
||||||
|
...buildInfo,
|
||||||
|
};
|
||||||
|
|
||||||
|
// Full local copy of the project's documentation, rendered server-side --
|
||||||
|
// so an operator running air-gapped (no route to GitHub Pages, where this
|
||||||
|
// content otherwise only lives) can still read it from the running app.
|
||||||
|
// An explicit slug -> file allowlist, never a user-suppliable path, so
|
||||||
|
// there's no way to make this read outside the doc set below.
|
||||||
|
const DOCS = {
|
||||||
|
overview: {title: 'Overview', file: path.join(__dirname, '../../README.md')},
|
||||||
|
changelog: {title: 'Changelog', file: path.join(__dirname, '../../CHANGELOG.md')},
|
||||||
|
deployment: {title: 'Deployment', file: path.join(__dirname, '../../DEPLOYMENT.md')},
|
||||||
|
api: {title: 'API Reference', file: path.join(__dirname, '../api.md')},
|
||||||
|
installation: {title: 'Installation', file: path.join(__dirname, '../../docs/installation.md')},
|
||||||
|
architecture: {title: 'Architecture', file: path.join(__dirname, '../../docs/architecture.md')},
|
||||||
|
docker: {title: 'Docker', file: path.join(__dirname, '../../docs/docker.md')},
|
||||||
|
contributing: {title: 'Contributing', file: path.join(__dirname, '../../docs/contributing.md')},
|
||||||
|
};
|
||||||
|
|
||||||
|
const docList = Object.entries(DOCS).map(([slug, d]) => ({slug, title: d.title}));
|
||||||
|
|
||||||
|
// README.md links its screenshots as repo-relative "docs/images/...", which
|
||||||
|
// only resolves correctly on GitHub. Serve that same folder here and rewrite
|
||||||
|
// the rendered markup to point at it absolutely, so the images work when
|
||||||
|
// read from /docs/overview too.
|
||||||
|
router.use('/images', require('express').static(path.join(__dirname, '../../docs/images')));
|
||||||
|
function fixImagePaths(html) {
|
||||||
|
return html.replace(/(["(])docs\/images\//g, '$1/docs/images/');
|
||||||
|
}
|
||||||
|
|
||||||
|
router.use(docsLimiter);
|
||||||
|
|
||||||
|
router.get('/', function(req, res) {
|
||||||
|
res.render('docs_index', {...values, docs: docList});
|
||||||
|
});
|
||||||
|
|
||||||
|
router.get('/:slug', function(req, res, next) {
|
||||||
|
const doc = DOCS[req.params.slug];
|
||||||
|
if (!doc) return next({status: 404, message: 'Doc not found'});
|
||||||
|
|
||||||
|
try {
|
||||||
|
const content = fs.readFileSync(doc.file, 'utf8');
|
||||||
|
res.render('docs_page', {
|
||||||
|
...values,
|
||||||
|
docs: docList,
|
||||||
|
currentSlug: req.params.slug,
|
||||||
|
docTitle: doc.title,
|
||||||
|
docHtml: fixImagePaths(marked(content)),
|
||||||
|
});
|
||||||
|
} catch (error) {
|
||||||
|
next(error);
|
||||||
|
}
|
||||||
|
});
|
||||||
|
|
||||||
|
module.exports = router;
|
||||||
@@ -9,6 +9,8 @@ const buildInfo = require('../utils/build_info');
|
|||||||
const values ={
|
const values ={
|
||||||
title: conf.environment !== 'production' ? `dev` : '',
|
title: conf.environment !== 'production' ? `dev` : '',
|
||||||
titleIcon: conf.environment !== 'production' ? `<i class="fa-brands fa-dev"></i>` : '',
|
titleIcon: conf.environment !== 'production' ? `<i class="fa-brands fa-dev"></i>` : '',
|
||||||
|
name: conf.name,
|
||||||
|
logo: conf.logo,
|
||||||
...buildInfo,
|
...buildInfo,
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -80,7 +82,4 @@ router.get('/login/*splat', async function(req, res, next) {
|
|||||||
res.render('login', {...values, redirect: req.query.redirect});
|
res.render('login', {...values, redirect: req.query.redirect});
|
||||||
});
|
});
|
||||||
|
|
||||||
router.get('/test', async function(req, res, next) {
|
|
||||||
res.render('test', {...values, redirect: req.query.redirect});
|
|
||||||
});
|
|
||||||
module.exports = router;
|
module.exports = router;
|
||||||
|
|||||||
@@ -136,6 +136,125 @@ describe('Host Lookup Algorithm', () => {
|
|||||||
});
|
});
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Tests for the wildcard's-own-base-domain fix: a single-level wildcard's
|
||||||
|
* issued cert also covers its own base domain (altNames: [domain, *.domain],
|
||||||
|
* see utils/letsencrypt.js), but that base domain sits one tree level ABOVE
|
||||||
|
* the wildcard's own leaf. buildLookUpObj() now also stamps that parent
|
||||||
|
* node's #record, and lookUpWildcardParent() finds it even when the base
|
||||||
|
* domain is ALSO separately registered as its own plain host (the "attach an
|
||||||
|
* existing host to a parent wildcard" case, unlike lookUp() which would just
|
||||||
|
* resolve to that host's own record).
|
||||||
|
*/
|
||||||
|
describe('Host wildcard base-domain lookup', () => {
|
||||||
|
|
||||||
|
let Host;
|
||||||
|
|
||||||
|
before(async () => {
|
||||||
|
Host = createMockHostClassWithWildcardParentFix();
|
||||||
|
});
|
||||||
|
|
||||||
|
test('lookUp finds the wildcard record for its own bare base domain when no plain host exists', async () => {
|
||||||
|
await populateTree(Host, ['*.cool.mysite.com']);
|
||||||
|
const result = Host.lookUp('cool.mysite.com');
|
||||||
|
assert.ok(result, 'Should find a match');
|
||||||
|
assert.strictEqual(result.host, '*.cool.mysite.com');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('lookUp still prefers an explicitly-created plain host over the wildcard, regardless of population order', async () => {
|
||||||
|
await populateTree(Host, ['*.cool.mysite.com', 'cool.mysite.com']);
|
||||||
|
assert.strictEqual(Host.lookUp('cool.mysite.com').host, 'cool.mysite.com');
|
||||||
|
|
||||||
|
await populateTree(Host, ['cool.mysite.com', '*.cool.mysite.com']);
|
||||||
|
assert.strictEqual(Host.lookUp('cool.mysite.com').host, 'cool.mysite.com');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('lookUpWildcardParent finds the wildcard even when the base domain already has its own plain host', async () => {
|
||||||
|
await populateTree(Host, ['*.cool.mysite.com', 'cool.mysite.com']);
|
||||||
|
const result = Host.lookUpWildcardParent('cool.mysite.com');
|
||||||
|
assert.ok(result, 'Should find the sibling wildcard');
|
||||||
|
assert.strictEqual(result.host, '*.cool.mysite.com');
|
||||||
|
});
|
||||||
|
|
||||||
|
test('lookUpWildcardParent returns undefined when there is no wildcard sibling', async () => {
|
||||||
|
await populateTree(Host, ['cool.mysite.com']);
|
||||||
|
assert.strictEqual(Host.lookUpWildcardParent('cool.mysite.com'), undefined);
|
||||||
|
});
|
||||||
|
|
||||||
|
test('lookUpWildcardParent returns undefined for an unrelated host', async () => {
|
||||||
|
await populateTree(Host, ['*.cool.mysite.com']);
|
||||||
|
assert.strictEqual(Host.lookUpWildcardParent('other.example.com'), undefined);
|
||||||
|
});
|
||||||
|
});
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Same mock shape as createMockHostClass() above, plus the parent-record
|
||||||
|
* stamp in the tree-population loop and the lookUpWildcardParent() method --
|
||||||
|
* both copied from the real implementation in models/host.js.
|
||||||
|
*/
|
||||||
|
function createMockHostClassWithWildcardParentFix() {
|
||||||
|
return class MockHost {
|
||||||
|
static lookUpObj = {};
|
||||||
|
|
||||||
|
static lookUp(host) {
|
||||||
|
let place = this.lookUpObj;
|
||||||
|
let last_resort = {};
|
||||||
|
let parent = undefined;
|
||||||
|
|
||||||
|
for(let fragment of host.split('.').reverse()){
|
||||||
|
parent = place;
|
||||||
|
if(place['**']) last_resort = place['**'];
|
||||||
|
if({...last_resort, ...place}[fragment]){
|
||||||
|
place = {...last_resort, ...place}[fragment];
|
||||||
|
}else if(place['*']){
|
||||||
|
place = place['*']
|
||||||
|
}else if(last_resort){
|
||||||
|
place = last_resort;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
if(place && place['#record']) return place['#record'];
|
||||||
|
if(parent && parent['*'] && parent['*']['#record']) return parent['*']['#record'];
|
||||||
|
}
|
||||||
|
|
||||||
|
static lookUpWildcardParent(host) {
|
||||||
|
let place = this.lookUpObj;
|
||||||
|
for(let fragment of host.split('.').reverse()){
|
||||||
|
if(!place[fragment]) return undefined;
|
||||||
|
place = place[fragment];
|
||||||
|
}
|
||||||
|
if(place['*'] && place['*']['#record']) return place['*']['#record'];
|
||||||
|
}
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
|
async function populateTree(Host, hosts) {
|
||||||
|
Host.lookUpObj = {};
|
||||||
|
|
||||||
|
for(let host of hosts){
|
||||||
|
let fragments = host.split('.');
|
||||||
|
let pointer = Host.lookUpObj;
|
||||||
|
|
||||||
|
while(fragments.length){
|
||||||
|
let fragment = fragments.pop();
|
||||||
|
|
||||||
|
if(!pointer[fragment]){
|
||||||
|
pointer[fragment] = {};
|
||||||
|
}
|
||||||
|
|
||||||
|
if(fragments.length === 0){
|
||||||
|
pointer[fragment]['#record'] = {host};
|
||||||
|
|
||||||
|
if(fragment === '*' && !pointer['#record']){
|
||||||
|
pointer['#record'] = pointer[fragment]['#record'];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
pointer = pointer[fragment];
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
/**
|
/**
|
||||||
* Creates a mock Host class with just the lookUp functionality
|
* Creates a mock Host class with just the lookUp functionality
|
||||||
* This allows us to test the algorithm without Redis dependencies
|
* This allows us to test the algorithm without Redis dependencies
|
||||||
|
|||||||
@@ -10,6 +10,9 @@
|
|||||||
<a href="https://github.com/theta42/proxy/blob/master/LICENSE" target="_blank" class="text-light">MIT License</a>
|
<a href="https://github.com/theta42/proxy/blob/master/LICENSE" target="_blank" class="text-light">MIT License</a>
|
||||||
</span>
|
</span>
|
||||||
<span class="d-flex align-items-center gap-3">
|
<span class="d-flex align-items-center gap-3">
|
||||||
|
<a href="/docs" class="text-light text-decoration-none">
|
||||||
|
<i class="fa-solid fa-book"></i> Docs
|
||||||
|
</a>
|
||||||
<a href="https://github.com/theta42/proxy" target="_blank" class="text-light text-decoration-none">
|
<a href="https://github.com/theta42/proxy" target="_blank" class="text-light text-decoration-none">
|
||||||
<i class="fa-brands fa-github"></i> GitHub
|
<i class="fa-brands fa-github"></i> GitHub
|
||||||
</a>
|
</a>
|
||||||
|
|||||||
@@ -0,0 +1,26 @@
|
|||||||
|
<%- include('top') %>
|
||||||
|
|
||||||
|
<div class="row justify-content-center">
|
||||||
|
<div class="col-md-8">
|
||||||
|
<div class="card shadow-lg mt-4 mb-4">
|
||||||
|
<div class="card-header shadow">
|
||||||
|
<i class="fa-solid fa-book"></i> Documentation
|
||||||
|
</div>
|
||||||
|
<div class="card-body">
|
||||||
|
<p class="text-muted">
|
||||||
|
A local copy of this project's documentation, readable from the
|
||||||
|
running app -- no internet access required.
|
||||||
|
</p>
|
||||||
|
<ul class="list-group">
|
||||||
|
<% docs.forEach(function(doc){ %>
|
||||||
|
<li class="list-group-item">
|
||||||
|
<a href="/docs/<%= doc.slug %>"><%= doc.title %></a>
|
||||||
|
</li>
|
||||||
|
<% }) %>
|
||||||
|
</ul>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<%- include('bottom') %>
|
||||||
@@ -0,0 +1,31 @@
|
|||||||
|
<%- include('top') %>
|
||||||
|
|
||||||
|
<div class="row">
|
||||||
|
<div class="col-md-3 d-none d-md-block">
|
||||||
|
<div class="card shadow-lg mt-4 mb-4">
|
||||||
|
<div class="card-header shadow">
|
||||||
|
<i class="fa-solid fa-book"></i> Documentation
|
||||||
|
</div>
|
||||||
|
<div class="list-group list-group-flush">
|
||||||
|
<% docs.forEach(function(doc){ %>
|
||||||
|
<a href="/docs/<%= doc.slug %>"
|
||||||
|
class="list-group-item list-group-item-action<%= doc.slug === currentSlug ? ' active' : '' %>">
|
||||||
|
<%= doc.title %>
|
||||||
|
</a>
|
||||||
|
<% }) %>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
<div class="col-md-9">
|
||||||
|
<div class="card shadow-lg mt-4 mb-4">
|
||||||
|
<div class="card-header shadow">
|
||||||
|
<i class="fa-solid fa-file-lines"></i> <%= docTitle %>
|
||||||
|
</div>
|
||||||
|
<div class="card-body markdown-body">
|
||||||
|
<%- docHtml %>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<%- include('bottom') %>
|
||||||
@@ -60,10 +60,10 @@
|
|||||||
|
|
||||||
loadUserSuggestions();
|
loadUserSuggestions();
|
||||||
|
|
||||||
$.scope.LocalGroup.__setTake(function($el){
|
$.scope.LocalGroup.__take = function($el){
|
||||||
$el.addClass('bg-danger');
|
$el.addClass('bg-danger');
|
||||||
$el.fadeOut(600, function(){ $el.remove(); });
|
$el.fadeOut(600, function(){ $el.remove(); });
|
||||||
});
|
};
|
||||||
|
|
||||||
app.subscribe(/^model:LocalGroup:create/, function(data){
|
app.subscribe(/^model:LocalGroup:create/, function(data){
|
||||||
$.scope.LocalGroup.remove(data.name);
|
$.scope.LocalGroup.remove(data.name);
|
||||||
|
|||||||
+43
-11
@@ -39,6 +39,7 @@
|
|||||||
|
|
||||||
// Parse the JSON object for a host to something the UI wants
|
// Parse the JSON object for a host to something the UI wants
|
||||||
function hostParseRow(host) {
|
function hostParseRow(host) {
|
||||||
|
host['created_on_text'] = moment(host['created_on'], "x").fromNow();
|
||||||
host['updated_on_text'] = moment(host['updated_on'], "x").fromNow();
|
host['updated_on_text'] = moment(host['updated_on'], "x").fromNow();
|
||||||
host['wildcard_expires_text'] = moment(host['wildcard_expires'], "x").fromNow();
|
host['wildcard_expires_text'] = moment(host['wildcard_expires'], "x").fromNow();
|
||||||
host['targetssl_text'] = host['targetssl'] ? 'https://' : 'http://';
|
host['targetssl_text'] = host['targetssl'] ? 'https://' : 'http://';
|
||||||
@@ -115,10 +116,13 @@
|
|||||||
// attach users to).
|
// attach users to).
|
||||||
let hostFormCurrentHost = null;
|
let hostFormCurrentHost = null;
|
||||||
|
|
||||||
// The auth_mode radios aren't real form fields (no [name]); this keeps the
|
// The auth_mode radios share a name so the browser enforces mutual
|
||||||
// two hidden basicauth_enabled/sso_enabled inputs — the ones actually
|
// exclusivity, but auth_mode itself isn't in Host's _keyMap -- the model
|
||||||
// submitted — in sync so only one can ever be true, and shows/hides the
|
// layer strips unrecognized fields on save (see model-redis's
|
||||||
// matching field group.
|
// processKeys), so it's never actually persisted. This keeps the two
|
||||||
|
// hidden basicauth_enabled/sso_enabled inputs -- the real, submitted
|
||||||
|
// fields -- in sync with whichever radio is selected, and shows/hides
|
||||||
|
// the matching field group.
|
||||||
function hostAuthModeChanged(mode){
|
function hostAuthModeChanged(mode){
|
||||||
$('#basicauth_enabled-hidden').val(mode === 'basic' ? 'true' : 'false');
|
$('#basicauth_enabled-hidden').val(mode === 'basic' ? 'true' : 'false');
|
||||||
$('#sso_enabled-hidden').val(mode === 'sso' ? 'true' : 'false');
|
$('#sso_enabled-hidden').val(mode === 'sso' ? 'true' : 'false');
|
||||||
@@ -188,6 +192,7 @@
|
|||||||
let $f = $(form);
|
let $f = $(form);
|
||||||
$f.attr('method', 'POST').attr('action', 'host').attr('evalAJAX', 'hostModalClose()');
|
$f.attr('method', 'POST').attr('action', 'host').attr('evalAJAX', 'hostModalClose()');
|
||||||
$f.find('[name=host]').prop('disabled', false);
|
$f.find('[name=host]').prop('disabled', false);
|
||||||
|
$('#host-rename-help').hide();
|
||||||
if($f.validateClear) $f.validateClear();
|
if($f.validateClear) $f.validateClear();
|
||||||
|
|
||||||
// A fresh host only qualifies for HTTP-01 until the name says otherwise.
|
// A fresh host only qualifies for HTTP-01 until the name says otherwise.
|
||||||
@@ -244,9 +249,15 @@
|
|||||||
hostAuthModeChanged(authMode);
|
hostAuthModeChanged(authMode);
|
||||||
hostRenderBasicAuthUsers(host, h.basicauth_users);
|
hostRenderBasicAuthUsers(host, h.basicauth_users);
|
||||||
|
|
||||||
// The host name is the key; it can't change on edit. Wildcard hosts can
|
// The host name is the Redis record's key -- renaming it is a real
|
||||||
// still toggle their matching mode.
|
// migration (see Host.prototype.update() in models/host.js), scoped
|
||||||
$f.find('[name=host]').prop('disabled', true);
|
// there to plain hosts only: a wildcard's children reference it by
|
||||||
|
// name (wildcard_parent) and a cache entry's parent likewise, so
|
||||||
|
// renaming either would orphan those pointers. Keep the field locked
|
||||||
|
// for those cases; a plain host can be renamed freely.
|
||||||
|
let hostRenameable = !h.is_wildcard && !h.wildcard_parent && !h.is_cache;
|
||||||
|
$f.find('[name=host]').prop('disabled', !hostRenameable);
|
||||||
|
$('#host-rename-help').toggle(!hostRenameable);
|
||||||
if(h.is_wildcard){
|
if(h.is_wildcard){
|
||||||
$('#wildcard_matchAny-container').removeClass('challengeType-container');
|
$('#wildcard_matchAny-container').removeClass('challengeType-container');
|
||||||
}
|
}
|
||||||
@@ -420,6 +431,7 @@
|
|||||||
<th>SSL Expire</th>
|
<th>SSL Expire</th>
|
||||||
<th>Host Name</th>
|
<th>Host Name</th>
|
||||||
<th>target</th>
|
<th>target</th>
|
||||||
|
<th class="hidden-xs">Created</th>
|
||||||
<th class="hidden-xs">Updated</th>
|
<th class="hidden-xs">Updated</th>
|
||||||
<th>Actions</th>
|
<th>Actions</th>
|
||||||
</thead>
|
</thead>
|
||||||
@@ -451,6 +463,11 @@
|
|||||||
<td>
|
<td>
|
||||||
{{{ targetssl_text }}}{{ ip }}:{{ targetPort }}
|
{{{ targetssl_text }}}{{ ip }}:{{ targetPort }}
|
||||||
</td>
|
</td>
|
||||||
|
<td class="hidden-xs momentFromNow" data-date="{{ created_on }}" title="Created by {{ created_by }}">
|
||||||
|
{{ created_on_text }}
|
||||||
|
<br />
|
||||||
|
<small class="text-muted">{{ created_by }}</small>
|
||||||
|
</td>
|
||||||
<td class="hidden-xs momentFromNow" data-date="{{ updated_on }}" >
|
<td class="hidden-xs momentFromNow" data-date="{{ updated_on }}" >
|
||||||
{{ updated_on_text }}
|
{{ updated_on_text }}
|
||||||
</td>
|
</td>
|
||||||
@@ -516,7 +533,7 @@
|
|||||||
<div class="card-header actionMessage m-0" style="display:none"></div>
|
<div class="card-header actionMessage m-0" style="display:none"></div>
|
||||||
|
|
||||||
<div class="modal-body">
|
<div class="modal-body">
|
||||||
<ul class="nav nav-tabs" role="tablist">
|
<ul class="nav nav-tabs flex-nowrap overflow-x-auto" role="tablist">
|
||||||
<li class="nav-item"><button class="nav-link active" id="hostTab-general-btn" data-bs-toggle="tab" data-bs-target="#hostTab-general" type="button" role="tab">General</button></li>
|
<li class="nav-item"><button class="nav-link active" id="hostTab-general-btn" data-bs-toggle="tab" data-bs-target="#hostTab-general" type="button" role="tab">General</button></li>
|
||||||
<li class="nav-item"><button class="nav-link" id="hostTab-tls-btn" data-bs-toggle="tab" data-bs-target="#hostTab-tls" type="button" role="tab">TLS & Wildcard</button></li>
|
<li class="nav-item"><button class="nav-link" id="hostTab-tls-btn" data-bs-toggle="tab" data-bs-target="#hostTab-tls" type="button" role="tab">TLS & Wildcard</button></li>
|
||||||
<li class="nav-item"><button class="nav-link" id="hostTab-traffic-btn" data-bs-toggle="tab" data-bs-target="#hostTab-traffic" type="button" role="tab">Traffic</button></li>
|
<li class="nav-item"><button class="nav-link" id="hostTab-traffic-btn" data-bs-toggle="tab" data-bs-target="#hostTab-traffic" type="button" role="tab">Traffic</button></li>
|
||||||
@@ -539,6 +556,12 @@
|
|||||||
for one subdomain level, <code>**.example.com</code> for any depth,
|
for one subdomain level, <code>**.example.com</code> for any depth,
|
||||||
or <code>**</code> as a catch-all.
|
or <code>**</code> as a catch-all.
|
||||||
</small>
|
</small>
|
||||||
|
<small id="host-rename-help" class="field-help text-muted d-block" style="display:none">
|
||||||
|
Wildcard hosts, their children, and auto-created subdomain cache
|
||||||
|
entries can't be renamed here — the name is referenced elsewhere
|
||||||
|
(the wildcard's own children, or the cache entry's parent). Delete
|
||||||
|
and recreate instead.
|
||||||
|
</small>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
@@ -579,6 +602,7 @@
|
|||||||
<input type="radio" name="targetssl" id="targetssl-true" value="true">
|
<input type="radio" name="targetssl" id="targetssl-true" value="true">
|
||||||
Proxy to HTTPS
|
Proxy to HTTPS
|
||||||
</label></div>
|
</label></div>
|
||||||
|
<small class="field-help text-muted d-block">Whether the proxy talks to the target over HTTP or HTTPS. Independent of Incoming SSL above — clients can use HTTPS to reach the proxy while it still talks plain HTTP to the target, or vice versa.</small>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
@@ -617,6 +641,14 @@
|
|||||||
<input type="radio" name="wildcard_matchAny" id="wildcard_matchAny-true" value="true">
|
<input type="radio" name="wildcard_matchAny" id="wildcard_matchAny-true" value="true">
|
||||||
Match any subdomain and proxy to this host
|
Match any subdomain and proxy to this host
|
||||||
</label></div>
|
</label></div>
|
||||||
|
<small class="field-help text-muted d-block">
|
||||||
|
"Recommended" only routes subdomains you've explicitly registered
|
||||||
|
as their own host (optionally as a "Parent Wildcard" child of this
|
||||||
|
one, to reuse this cert). "Match any" auto-creates a temporary
|
||||||
|
route to this host's target for <i>any</i> undefined subdomain the
|
||||||
|
first time it's requested — convenient, but it means every subdomain
|
||||||
|
typo or scan attempt also gets routed here.
|
||||||
|
</small>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
@@ -713,15 +745,15 @@
|
|||||||
|
|
||||||
<div class="form-group">
|
<div class="form-group">
|
||||||
<div class="radio"><label>
|
<div class="radio"><label>
|
||||||
<input type="radio" id="auth_mode-none" value="none" checked onchange="hostAuthModeChanged('none')">
|
<input type="radio" name="auth_mode" id="auth_mode-none" value="none" checked onchange="hostAuthModeChanged('none')">
|
||||||
Off (public)
|
Off (public)
|
||||||
</label></div>
|
</label></div>
|
||||||
<div class="radio"><label>
|
<div class="radio"><label>
|
||||||
<input type="radio" id="auth_mode-basic" value="basic" onchange="hostAuthModeChanged('basic')">
|
<input type="radio" name="auth_mode" id="auth_mode-basic" value="basic" onchange="hostAuthModeChanged('basic')">
|
||||||
Basic authentication
|
Basic authentication
|
||||||
</label></div>
|
</label></div>
|
||||||
<div class="radio"><label>
|
<div class="radio"><label>
|
||||||
<input type="radio" id="auth_mode-sso" value="sso" onchange="hostAuthModeChanged('sso')">
|
<input type="radio" name="auth_mode" id="auth_mode-sso" value="sso" onchange="hostAuthModeChanged('sso')">
|
||||||
Single sign-on (SSO)
|
Single sign-on (SSO)
|
||||||
</label></div>
|
</label></div>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -57,10 +57,10 @@
|
|||||||
|
|
||||||
loadSubjectSuggestions();
|
loadSubjectSuggestions();
|
||||||
|
|
||||||
$.scope.Permission.__setTake(function($el, item, list){
|
$.scope.Permission.__take = function($el, item, list){
|
||||||
$el.addClass('bg-danger');
|
$el.addClass('bg-danger');
|
||||||
$el.fadeOut(600, function(){ $el.remove(); });
|
$el.fadeOut(600, function(){ $el.remove(); });
|
||||||
});
|
};
|
||||||
|
|
||||||
// Live updates (model:Permission:*), so adds/removes reflect for everyone.
|
// Live updates (model:Permission:*), so adds/removes reflect for everyone.
|
||||||
app.subscribe(/^model:Permission:create/, function(data){
|
app.subscribe(/^model:Permission:create/, function(data){
|
||||||
|
|||||||
@@ -1,74 +0,0 @@
|
|||||||
<!DOCTYPE html>
|
|
||||||
<html lang="en">
|
|
||||||
<!-- need to load jq-query cdn or file. -->
|
|
||||||
<script src="https://code.jquery.com/jquery-3.7.1.min.js"
|
|
||||||
integrity="sha256-/JqT3SQfawRcv/BIHPThkBvs0OEvtFFmqPF/lYI/Cxo=" crossorigin="anonymous"></script>
|
|
||||||
|
|
||||||
<!-- need to load mustache cdn or file. -->
|
|
||||||
<script src="
|
|
||||||
https://cdn.jsdelivr.net/npm/mustache@4.2.0/mustache.min.js
|
|
||||||
"></script>
|
|
||||||
|
|
||||||
<!-- need to load jq-repeat cdn or file -->
|
|
||||||
<script type="text/javascript" src='/static/lib/js/jq-repeat_new.js'></script>
|
|
||||||
<script>
|
|
||||||
//on document ready. the logic would execute.
|
|
||||||
$(document).ready(function () {
|
|
||||||
$.scope.toDo.__setPut(function($el, item, list){
|
|
||||||
$el.slideDown('slow');
|
|
||||||
})
|
|
||||||
|
|
||||||
// $.scope.toDo.__setUpdate(function($el, $render, item, list){
|
|
||||||
// $el.fadeOut(2000, function() {
|
|
||||||
// $(this).html($render.html()).fadeIn(2000);
|
|
||||||
// });
|
|
||||||
// });
|
|
||||||
|
|
||||||
// $.scope.toDo.__setUpdate(function($el, $render, item, list){
|
|
||||||
// $el.animate({'opacity': 0}, 400, function(){
|
|
||||||
// $(this).html($render.html()).animate({'opacity': 1}, 400);
|
|
||||||
// });
|
|
||||||
// });
|
|
||||||
|
|
||||||
$.scope.toDo.__setUpdate(function($el, $render, item, list){
|
|
||||||
$el.slideUp(function(){
|
|
||||||
$(this).replaceWith($render)
|
|
||||||
$render.slideDown()
|
|
||||||
})
|
|
||||||
});
|
|
||||||
|
|
||||||
|
|
||||||
$.scope.toDo.push({ item: "Get milk", done: "Yes" }); // 0
|
|
||||||
$.scope.toDo.push({ item: "Do laundry", done: "No" }); // 1
|
|
||||||
//should take array id or array key
|
|
||||||
|
|
||||||
// - **howMany** _Type: Number_
|
|
||||||
// Number of repeat objects that will be removed. If there are non to be removed, it is not required to use this argument.
|
|
||||||
// - **update** _Type: Array_
|
|
||||||
// This is the array of repeat objects to add. If there are none to this is not required.
|
|
||||||
|
|
||||||
//remove works
|
|
||||||
// $.scope.toDo.splice("Get milk" , "1")
|
|
||||||
|
|
||||||
//update
|
|
||||||
$.scope.toDo.splice(-1,0, { item: "Get Bread", done: "Yes" })
|
|
||||||
|
|
||||||
|
|
||||||
});
|
|
||||||
|
|
||||||
|
|
||||||
</script>
|
|
||||||
|
|
||||||
<head>
|
|
||||||
<meta charset="UTF-8" />
|
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1.0" />
|
|
||||||
<title>Document</title>
|
|
||||||
</head>
|
|
||||||
|
|
||||||
<body>
|
|
||||||
<ul>
|
|
||||||
<li jq-repeat="toDo" jq-repeat-index="item" style="display:none;"><span class="item">{{ item }}</span>: {{ done }}</li>
|
|
||||||
</ul>
|
|
||||||
</body>
|
|
||||||
|
|
||||||
</html>
|
|
||||||
@@ -3,7 +3,7 @@
|
|||||||
<head>
|
<head>
|
||||||
<meta charset="utf-8">
|
<meta charset="utf-8">
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no">
|
||||||
<title>Proxy - Theta 42 <%- title %></title>
|
<title><%- name %> <%- title %></title>
|
||||||
<!-- Favicon -->
|
<!-- Favicon -->
|
||||||
<link rel="icon" type="image/svg+xml" href="/static/favicon.svg">
|
<link rel="icon" type="image/svg+xml" href="/static/favicon.svg">
|
||||||
<!-- CSS are placed here -->
|
<!-- CSS are placed here -->
|
||||||
@@ -24,17 +24,11 @@
|
|||||||
<script type="text/javascript" src="/static-modules/moment/moment.js"></script>
|
<script type="text/javascript" src="/static-modules/moment/moment.js"></script>
|
||||||
<script type="text/javascript" src="/static/lib/js/app-base.js"></script>
|
<script type="text/javascript" src="/static/lib/js/app-base.js"></script>
|
||||||
<script type="text/javascript" src="/static/js/app.js"></script>
|
<script type="text/javascript" src="/static/js/app.js"></script>
|
||||||
|
|
||||||
|
|
||||||
<!-- HTML5 shim, for IE6-8 support of HTML5 elements -->
|
|
||||||
<!--[if lt IE 9]>
|
|
||||||
<script src="http://html5shim.googlecode.com/svn/trunk/html5.js"></script>
|
|
||||||
<![endif]-->
|
|
||||||
</head>
|
</head>
|
||||||
<body>
|
<body>
|
||||||
|
|
||||||
<nav class="navbar navbar-expand-md navbar-dark fixed-top bg-dark">
|
<nav class="navbar navbar-expand-md navbar-dark fixed-top bg-dark">
|
||||||
<a class="navbar-brand" href="#">Dynamic Proxy <%- titleIcon %></a>
|
<a class="navbar-brand" href="#"><img src="<%- logo %>" height="28" class="me-2" alt=""><%- name %> <%- titleIcon %></a>
|
||||||
<button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navbarSupportedContent" aria-controls="navbarSupportedContent" aria-expanded="false" aria-label="Toggle navigation">
|
<button class="navbar-toggler" type="button" data-bs-toggle="collapse" data-bs-target="#navbarSupportedContent" aria-controls="navbarSupportedContent" aria-expanded="false" aria-label="Toggle navigation">
|
||||||
<span class="navbar-toggler-icon"></span>
|
<span class="navbar-toggler-icon"></span>
|
||||||
</button>
|
</button>
|
||||||
|
|||||||
@@ -26,12 +26,12 @@
|
|||||||
for(let user of data.results){
|
for(let user of data.results){
|
||||||
$.scope.users.push(user);
|
$.scope.users.push(user);
|
||||||
}
|
}
|
||||||
$.scope.users.__setPut(function($el, item, list){
|
$.scope.users.__put = function($el, item, list){
|
||||||
$el.addClass('bg-success');
|
$el.addClass('bg-success');
|
||||||
$el.fadeIn(3000, function(){
|
$el.fadeIn(3000, function(){
|
||||||
$el.removeClass('bg-success');
|
$el.removeClass('bg-success');
|
||||||
});
|
});
|
||||||
})
|
};
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -45,12 +45,12 @@
|
|||||||
$(document).ready(function(){
|
$(document).ready(function(){
|
||||||
populateUsers(); //populate the table
|
populateUsers(); //populate the table
|
||||||
|
|
||||||
$.scope.users.__setTake(function($el, item, list){
|
$.scope.users.__take = function($el, item, list){
|
||||||
$el.addClass('bg-danger');
|
$el.addClass('bg-danger');
|
||||||
$el.fadeOut(1000, function(){
|
$el.fadeOut(1000, function(){
|
||||||
$el.remove()
|
$el.remove()
|
||||||
});
|
});
|
||||||
});
|
};
|
||||||
|
|
||||||
});
|
});
|
||||||
</script>
|
</script>
|
||||||
|
|||||||
@@ -18,6 +18,9 @@
|
|||||||
// theta-env orchestrator (setup.sh) and ignored by the app.
|
// theta-env orchestrator (setup.sh) and ignored by the app.
|
||||||
|
|
||||||
module.exports = {
|
module.exports = {
|
||||||
|
name: 'Dynamic Proxy', // shown in the UI
|
||||||
|
logo: '/static/img/theta42.svg', // nav image; point at your own file under public/ to white-label
|
||||||
|
|
||||||
// OpenID Connect — point at your SSO Manager. Issuer + authorization/
|
// OpenID Connect — point at your SSO Manager. Issuer + authorization/
|
||||||
// endSession are browser-facing URLs; token/userinfo can be the internal
|
// endSession are browser-facing URLs; token/userinfo can be the internal
|
||||||
// URL if the SSO is on the same docker network (avoids a TLS hairpin).
|
// URL if the SSO is on the same docker network (avoids a TLS hairpin).
|
||||||
|
|||||||
Reference in New Issue
Block a user