cec0d92c25
Generalize the half-built discovery plugins into a real plugin system: plugin TYPES (the plugins/<category>/<type>.js modules with manifests) and loadable, configurable, multi-copy plugin INSTANCES (PluginInstance ORM model) managed from a dedicated /plugins page and /api/plugins API, with per-instance secrets in OpenBao at secret/plugins/<id>/conf. - plugin_registry.js: getTypes/getModule/splitConfig/mask + required-field helpers - PluginInstance model (Sequelize): id/pluginType/category/name/slug(unique)/ enabled/cron/config(json, non-secret)/lastRun*; registered in models/index.js - plugin_secrets.js: read/write/remove/mergeForRun over @simpleworkjs/bao-conf - scheduler.js: schedules from the DB registry; per-instance stable BullMQ JobScheduler ids (plugin:<id>) for load/unload; legacy migration from conf.discovery.plugins on first boot (idempotent, empty-table-guarded) - api_plugins.js (replaces routes/plugins.js): types/list/get/create/update/ secrets/test/load/unload/run/delete/runs; admin-gated; secrets always masked - /plugins page (plugins.ejs) + nav; Agents & Scheduler tab removed from /directory; /docs/agents aliased to /docs/plugins - proxmox/unifi/nmap gained manifests (configSchema/validate/run alias) - tests/plugins.test.js: registry unit + plugin_secrets (mocked bao-conf) + PluginInstance model round-trip/unique-slug - docs (plugins.md, vault.md, _config.yml, API.md) + 1.16.1 -> 1.17.0 Requires theta-suite >= v1.30.1 for the sso-broker secret/plugins/* grant; fails-soft with a clear error if absent. Co-Authored-By: Claude <noreply@anthropic.com>
80 lines
2.9 KiB
JavaScript
80 lines
2.9 KiB
JavaScript
const nmap = require('node-nmap');
|
|
nmap.nmapLocation = "nmap"; // default
|
|
|
|
module.exports = {
|
|
// Plugin manifest — see nodejs/services/plugin_registry.js. `targetRange` is
|
|
// not secret (it's a network range to scan), so it lives in the DB row, not
|
|
// OpenBao. nmap itself has no credentials to test, so `validate` only checks
|
|
// the range parses — running a real scan is what `run` does.
|
|
type: 'nmap',
|
|
category: 'discovery',
|
|
name: 'Nmap Network Scan',
|
|
description: 'Discover hosts and services on a network range using nmap OS + port scans.',
|
|
configSchema: [
|
|
{ key: 'targetRange', label: 'Target Range', type: 'text', required: true, placeholder: '192.168.1.0/24' }
|
|
],
|
|
|
|
validate: async (config) => {
|
|
const { targetRange } = config;
|
|
if (!targetRange) return { ok: false, error: 'Missing targetRange' };
|
|
// nmap accepts CIDR (a.b.c.d/24), ranges (a.b.c.d-50), and host lists. We
|
|
// only sanity-check shape here — reject anything with shell metacharacters
|
|
// or whitespace, since node-nmap passes this straight to the nmap binary.
|
|
if (/\s|[;|&$`<>]/.test(targetRange)) {
|
|
return { ok: false, error: 'targetRange must not contain whitespace or shell metacharacters' };
|
|
}
|
|
return { ok: true };
|
|
},
|
|
|
|
discover: async (config) => {
|
|
const { targetRange } = config;
|
|
if (!targetRange) throw new Error("Missing targetRange for Nmap");
|
|
|
|
return new Promise((resolve, reject) => {
|
|
const scan = new nmap.OsAndPortScan(targetRange);
|
|
scan.on('complete', function(data) {
|
|
const resources = [];
|
|
const edges = [];
|
|
|
|
for (const host of data) {
|
|
if (!host.mac || !host.ip) continue;
|
|
const hostSlug = `nmap-host-${host.mac.replace(/:/g, '')}`;
|
|
|
|
const interfaces = [{ mac: host.mac, ip: host.ip }];
|
|
|
|
resources.push({
|
|
kind: 'host',
|
|
name: host.hostname || host.ip,
|
|
slug: hostSlug,
|
|
metadata: { interfaces, os: host.osNmap }
|
|
});
|
|
|
|
if (host.openPorts && host.openPorts.length > 0) {
|
|
for (const port of host.openPorts) {
|
|
const svcSlug = `nmap-svc-${host.mac.replace(/:/g, '')}-${port.port}`;
|
|
resources.push({
|
|
kind: 'service',
|
|
name: `${port.service} on ${port.port}`,
|
|
slug: svcSlug,
|
|
metadata: { port: port.port, protocol: port.protocol }
|
|
});
|
|
edges.push({ parentSlug: hostSlug, childSlug: svcSlug, relation: 'exposes' });
|
|
}
|
|
}
|
|
}
|
|
resolve({ resources, edges });
|
|
});
|
|
|
|
scan.on('error', function(error) {
|
|
reject(error);
|
|
});
|
|
|
|
scan.startScan();
|
|
});
|
|
},
|
|
|
|
// Generalized plugin contract alias for `discover`. See proxmox.js for why
|
|
// this references module.exports rather than `this`.
|
|
run: async (config) => module.exports.discover(config)
|
|
};
|