208762f0d1
views/top.ejs, views/bottom.ejs and public/lib/js/app-base.js are now byte-identical across sso-manager-node, proxy and jump-host. Everything per-app moved into utils/ui.js, exposed to every render as `ui` via app.locals (nav items + their group gates, footer repo/docs/ToS links, favicon, profile/logout targets, update-banner on/off + label). Client framework changes: - One gating model everywhere: app-base.js reveals .group-required-<cn> for each of the current user user/me groups. sso-manager-node sends LDAP DNs in memberOf, the OIDC clients send CNs in groups; both normalise to CNs, and the clients isAdmin flag becomes a synthetic `admin` group, so proxy nav-admin items are now group-required-admin. - user/me is fetched once per page load and cached (app.auth.loadUser); nav, forceLogin and group-required elements all read that one promise. - isLoggedIn is dual-mode (Promise + node-style callback), so the async and callback call styles both work from one shared top.ejs. - forceLogin no longer uses $.holdReady (removed in jQuery 4): it redirects to /login?redirect=<path>, and still enforces required groups. - logOut only clears the session; the caller decides where to go next. - post/put/delete are dual-mode Promise/callback, which also removes the undefined `callback2` reference that threw on a non-function callback. Dependencies: jquery ^4.0.0 and ejs ^3.1.10 in all three apps. sso-manager-node specifics: - val.js adopts the shared superset (adds the target/hostname rules and the password policy, and fixes the let-shadowed `message` that stopped custom rule messages from reaching validateMessage). - GET /api/user/me now also reports isAdmin (membership in app_sso_admin). - public/js/app.js: $.isFunction -> typeof (removed in jQuery 4). Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
130 lines
4.8 KiB
JavaScript
Executable File
130 lines
4.8 KiB
JavaScript
Executable File
'use strict';
|
|
|
|
const path = require('path');
|
|
const ejs = require('ejs')
|
|
const express = require('express');
|
|
const compression = require('compression');
|
|
|
|
// Set up the express app.
|
|
const app = express();
|
|
|
|
// Hold list of functions to run when the server is ready
|
|
app.onListen = [];
|
|
|
|
// Allow the express app to be exported into other files.
|
|
module.exports = app;
|
|
|
|
// Hold onto the auth middleware
|
|
const middleware = require('./middleware/auth');
|
|
|
|
// OAuth routes
|
|
const { router: oauthRouter, authRouter: oauthApiRouter, discovery } = require('./routes/oauth');
|
|
|
|
// Grab the projects PubSub
|
|
app.contoller = require('./controller');
|
|
|
|
// Background services (self-initializing on require).
|
|
require('./services/update_check');
|
|
require('./services/ldap_monitor');
|
|
|
|
// Push pubsub over the socket and back.
|
|
app.onListen.push(function(){
|
|
app.io.use(middleware.authIO);
|
|
|
|
app.contoller.ps.subscribe(/./g, function(data, topic){
|
|
app.io.emit('P2PSub', { topic, data });
|
|
});
|
|
|
|
app.io.on('connection', (socket) => {
|
|
// console.log('socket', socket)
|
|
var user = socket.user;
|
|
socket.on('P2PSub', (msg) => {
|
|
app.contoller.ps.publish(msg.topic, {...msg.data, __from:socket.user});
|
|
// socket.broadcast.emit('P2PSub', msg);
|
|
});
|
|
});
|
|
});
|
|
|
|
// Gzip text responses (HTML/JS/CSS/JSON). The admin UI loads ~13 separate,
|
|
// uncompressed vendor JS/CSS files on every full page navigation (a
|
|
// traditional multi-page app, not an SPA) — this alone meaningfully cuts
|
|
// bytes-over-the-wire and perceived load time on a real network, where it
|
|
// matters far more than on localhost.
|
|
app.use(compression());
|
|
|
|
// load the JSON parser middleware. Express will parse JSON into native objects
|
|
// for any request that has JSON in its content type.
|
|
app.use(express.json());
|
|
app.set('trust proxy', 1);
|
|
|
|
// Set up the templating engine to build HTML for the front end.
|
|
app.set('views', path.join(__dirname, 'views'));
|
|
app.set('view engine', 'ejs');
|
|
|
|
// Per-app values for the shared UI shell (views/top.ejs + views/bottom.ejs).
|
|
// Set as an app local so every res.render has it, including routes that don't
|
|
// spread the routers' `values` object.
|
|
app.locals.ui = require('./utils/ui');
|
|
|
|
// Have express server static content( images, CSS, browser JS) from the public
|
|
// local folder. maxAge is short since this is the app's own JS/CSS, which
|
|
// changes on every deploy and isn't cache-busted/fingerprinted.
|
|
app.use('/static', express.static(path.join(__dirname, 'public'), {maxAge: '1h'}))
|
|
|
|
// Routes for front end content.
|
|
app.use('/', require('./routes/index'));
|
|
|
|
// Local, in-app copy of the project's documentation (README, DEPLOYMENT,
|
|
// API.md, docs/*) -- public, no auth, so it's readable even by a locked-out
|
|
// admin or an air-gapped operator with no route to GitHub Pages.
|
|
app.use('/docs', require('./routes/docs'));
|
|
|
|
// API routes for authentication.
|
|
app.use('/api/auth', require('./routes/auth'));
|
|
|
|
// API routes for working with users. All endpoints need to be have valid user.
|
|
app.use('/api/user', middleware.auth, require('./routes/user'));
|
|
|
|
app.use('/api/token', middleware.auth, require('./routes/token'));
|
|
|
|
app.use('/api/group', middleware.auth, require('./routes/group'));
|
|
app.use('/api/notification', middleware.auth, require('./routes/notification'));
|
|
app.use('/api/discovery', middleware.auth, require('./routes/discovery'));
|
|
app.use('/api/directory-admin', middleware.auth, require('./routes/api_directory_admin'));
|
|
app.use('/api/update-check', middleware.auth, require('./routes/update_check'));
|
|
app.use('/api/tos', middleware.auth, require('./routes/tos'));
|
|
app.use('/api/metrics', middleware.auth, require('./routes/api_metrics'));
|
|
// Self-service API tokens (PATs) — owner-scoped, no admin group required.
|
|
app.use('/api/api-token', middleware.auth, require('./routes/api_token'));
|
|
|
|
// OAuth 2.0 / OpenID Connect
|
|
app.use('/oauth', oauthRouter);
|
|
app.use('/api/oauth', middleware.auth, oauthApiRouter);
|
|
app.use('/api/oauth/client', middleware.auth, require('./routes/oauth_client'));
|
|
app.get('/.well-known/openid-configuration', discovery);
|
|
|
|
|
|
// Catch 404 and forward to error handler. If none of the above routes are
|
|
// used, this is what will be called.
|
|
app.use(function(req, res, next) {
|
|
var err = new Error('Not Found');
|
|
err.message = 'Page not found'
|
|
err.status = 404;
|
|
next(err);
|
|
});
|
|
|
|
// Error handling
|
|
app.use(function(err, req, res, next) {
|
|
const SILENT_404S = ['/.well-known/'];
|
|
const isSilent404 = err.status === 404 && SILENT_404S.some(p => req.url.startsWith(p));
|
|
if (!isSilent404) console.error(err.status || res.status, err.name, req.method, req.url);
|
|
if(![401, 404].includes(err.status || res.status)){
|
|
console.error(err.message);
|
|
console.error(err.stack);
|
|
console.error('=========================================');
|
|
}
|
|
|
|
res.status(err.status || 500);
|
|
res.json({name: err.name, message: err.message});
|
|
});
|