ad2cacf094
- Auth tab is now a single choice (Off / Basic auth / SSO) instead of two independent toggles that could both be on at once, which made it ambiguous which gate actually protected a request. Enforced both in the UI and server-side (POST/PUT), accounting for partial PUT updates against the existing record. - Add per-user basic-auth management (change password, delete) so an admin no longer has to blow away and retype the whole user list to remove or rotate one account. - Fix: `Model.errors.ObjectValidateError(...)` is a constructor and was being called without `new` everywhere in this codebase. Without `new`, `this` inside it was the module's shared `errors` object (mutated in place) and the call evaluated to `undefined` — so every `throw Model.errors.ObjectValidateError(...)` actually threw `undefined`, which Express's `next(undefined)` treats as "no error" and silently falls through to the catch-all 404 handler. Every host/user/group/ permission/dns-provider validation error (bad hostname, bad IP, etc.) was showing a confusing "Page not found" instead of the real message. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
87 lines
2.8 KiB
JavaScript
87 lines
2.8 KiB
JavaScript
'use strict';
|
|
|
|
const path = require('path');
|
|
const express = require('express');
|
|
const router = require('express').Router();
|
|
const conf = require('@simpleworkjs/conf');
|
|
const buildInfo = require('../utils/build_info');
|
|
|
|
const values ={
|
|
title: conf.environment !== 'production' ? `dev` : '',
|
|
titleIcon: conf.environment !== 'production' ? `<i class="fa-brands fa-dev"></i>` : '',
|
|
...buildInfo,
|
|
}
|
|
|
|
// List of front end node modules to be served
|
|
const frontEndModules = ['bootstrap', 'mustache', 'jquery', '@fortawesome',
|
|
'moment', '@popper', 'jq-repeat',
|
|
];
|
|
|
|
// Server front end modules
|
|
// https://stackoverflow.com/a/55700773/3140931
|
|
// Vendor libraries only change when package versions are bumped (a rebuild),
|
|
// so they're safe to cache aggressively; ETag/Last-Modified (on by default)
|
|
// still cover that rare case with a cheap 304 instead of a stale asset.
|
|
frontEndModules.forEach(dep => {
|
|
router.use(`/static-modules/${dep}`, express.static(path.join(__dirname, `../node_modules/${dep}`), {maxAge: '7d'}))
|
|
});
|
|
|
|
// Have express server static content( images, CSS, browser JS) from the public
|
|
// local folder. Shorter maxAge than /static-modules since this is the app's
|
|
// own JS/CSS, which changes on every deploy and isn't cache-busted/fingerprinted.
|
|
router.use('/static', express.static(path.join(__dirname, '../public'), {maxAge: '1h'}))
|
|
|
|
router.get('/', (req, res) => {
|
|
res.redirect(301, '/hosts');
|
|
});
|
|
|
|
// Lightweight liveness probe for container healthchecks / monitoring. No auth,
|
|
// no dependencies — just confirms the Express process is up and routing.
|
|
router.get('/health', (req, res) => {
|
|
res.json({status: 'ok'});
|
|
});
|
|
|
|
router.get('/hosts', async function(req, res, next) {
|
|
res.render('hosts', {...values});
|
|
});
|
|
|
|
router.get('/dns', async function(req, res, next) {
|
|
res.render('dns', {...values});
|
|
});
|
|
|
|
|
|
router.get('/users', async function(req, res, next) {
|
|
res.render('users', {...values});
|
|
});
|
|
|
|
router.get('/permissions', async function(req, res, next) {
|
|
res.render('permissions', {...values});
|
|
});
|
|
|
|
router.get('/groups', async function(req, res, next) {
|
|
res.render('groups', {...values});
|
|
});
|
|
|
|
router.get('/profile', async function(req, res, next) {
|
|
res.render('profile', {...values});
|
|
});
|
|
|
|
// API Tokens is now a section on the Profile page.
|
|
router.get('/api-tokens', (req, res) => {
|
|
res.redirect(301, '/profile');
|
|
});
|
|
|
|
// Bare /login (the OIDC callback redirect target) and /login/<path>.
|
|
router.get('/login', async function(req, res, next) {
|
|
res.render('login', {...values, redirect: req.query.redirect});
|
|
});
|
|
|
|
router.get('/login/*splat', async function(req, res, next) {
|
|
res.render('login', {...values, redirect: req.query.redirect});
|
|
});
|
|
|
|
router.get('/test', async function(req, res, next) {
|
|
res.render('test', {...values, redirect: req.query.redirect});
|
|
});
|
|
module.exports = router;
|