[glm-grade=B] fix: dead dashboard WS, corrupted error.log, auth-polling storm, re-auth freeze + CVE bumps
Adversarial audit 2026-08-16 (GLM-5.3 delegate, 2 rounds, 141 tool calls):
P0-1: Dashboard WebSocket (/api/v1/ws) dead on EVERY boot since DC-076.
server.js passed module exports (DependencyManager class, {AutoRestartManager}
namespace, SSLMonitor class) instead of createApp()'s live instances — first
.on() threw ERR_INVALID_ARG_TYPE, catch swallowed it. Fix: app.locals.ctx
exposed in src/app.js; server.js passes all 8 real EventEmitter instances.
P0-2: error.log corrupted since 2026-07-14. errorMiddleware called
logError(FILE, SIZE, path, err, meta) — 5 args into a 3-arg wrapper —
logging 'Error: 5242880' garbage every ~60s and DISCARDING the real error
object. Fix: correct 3-arg call + legacy-shape guard in logErrorWrapper +
~74 log.error sites swept to pass real error objects (AST-verified scope-
safe 71/71, 29/29 modules load clean).
P0-3: auth-polling storm (stranded grade=B commit never landed in prod):
401/403 behind TOTP gate hammered /api/v1/services/status + SSE reconnect
every 2-8s, with misleading direct-probe fallback marking services 'up'.
Fix landed + B-round MEDIUM follow-up: TOTP re-auth success now clears
_dcAuthLost, resumes SSE (new _sseResume clears the latch), and refreshes.
Also: eslintignore static-sites/ (33→0 errors); nodemailer 8→9.0.5 and
sharp 0.33→0.35.3 (3 high CVEs killed; jest green on new majors);
dockerode@5/uuid deferred (semver-major, Docker API surface).
Verification: 80/80 suites, 1837/1837 tests; ESLint 0 errors/743 warnings;
node --check all changed files; bundles rebuilt + SW cache bumped.
Judges: Codex quota-dead until Aug 19 (verified live) — GLM adversarial
delegate per operator directive 2026-08-07. Round 1: 98-call mechanical
verification (timed out pre-verdict). Round 2 (this grade): B, one MEDIUM
(re-auth freeze) — fixed in this commit as prescribed.
This commit is contained in:
Vendored
+89
-89
File diff suppressed because one or more lines are too long
Vendored
+2
-2
File diff suppressed because one or more lines are too long
+18
-1
@@ -365,6 +365,9 @@
|
||||
}
|
||||
|
||||
async function refreshAll() {
|
||||
// Skip if auth has been lost (e.g. TOTP gate activated externally).
|
||||
// The polling interval in init.js also checks this flag.
|
||||
if (window._dcAuthLost) return;
|
||||
if (refreshInFlight) {
|
||||
refreshQueued = true;
|
||||
return refreshInFlight;
|
||||
@@ -417,9 +420,21 @@
|
||||
refreshInFlight = (async () => {
|
||||
try {
|
||||
const response = await fetch('/api/v1/services/status', { cache: 'no-store' });
|
||||
if (response.status === 401 || response.status === 403) {
|
||||
// Auth lost — stop the polling loop and close SSE; do NOT fall
|
||||
// through to direct probes (those would misleadingly mark
|
||||
// services as healthy since /probe/ treats 401/403 as "up").
|
||||
window._dcAuthLost = true;
|
||||
if (window._sseReconnect && window._sseClose) {
|
||||
window._sseClose(); // tell SSE to stop reconnecting
|
||||
}
|
||||
updateStamp('auth required');
|
||||
return; // skip the fallback entirely
|
||||
}
|
||||
if (!response.ok) {
|
||||
throw new Error(`Status refresh failed (${response.status})`);
|
||||
}
|
||||
window._dcAuthLost = false; // auth working again
|
||||
const data = await response.json();
|
||||
applyBatchResults(data.statuses || {});
|
||||
updateStamp('last check', data.checkedAt || new Date());
|
||||
@@ -434,9 +449,11 @@
|
||||
}
|
||||
} finally {
|
||||
refreshInFlight = null;
|
||||
if (refreshQueued) {
|
||||
if (refreshQueued && !window._dcAuthLost) {
|
||||
refreshQueued = false;
|
||||
setTimeout(() => { window.refreshAll(); }, 0);
|
||||
} else {
|
||||
refreshQueued = false;
|
||||
}
|
||||
}
|
||||
})();
|
||||
|
||||
@@ -63,7 +63,12 @@
|
||||
window.buildGrid();
|
||||
animateTopCards();
|
||||
window.refreshAll();
|
||||
setInterval(window.refreshAll, DC.POLL.DASHBOARD);
|
||||
setInterval(() => {
|
||||
// Stop polling if the session has been invalidated (e.g. TOTP gate
|
||||
// now active, or user logged out). Avoids relentless 401/403 noise.
|
||||
if (window._dcAuthLost) return;
|
||||
window.refreshAll();
|
||||
}, DC.POLL.DASHBOARD);
|
||||
if (typeof window.refreshCredsButtons === 'function') window.refreshCredsButtons();
|
||||
if (typeof window.refreshMonitoringWidgets === 'function') window.refreshMonitoringWidgets();
|
||||
// Update auth card (may have already been updated by the auto-load IIFE but ensure it's correct)
|
||||
|
||||
@@ -3,14 +3,18 @@
|
||||
let es = null;
|
||||
let reconnectDelay = 1000;
|
||||
const MAX_RECONNECT = 30000;
|
||||
let _sseFailCount = 0;
|
||||
let _sseManuallyClosed = false;
|
||||
|
||||
function connect() {
|
||||
if (es) { try { es.close(); } catch (_) {} }
|
||||
if (_sseManuallyClosed) return; // auth-lost: don't reconnect
|
||||
|
||||
es = new EventSource('/api/v1/events/stream');
|
||||
|
||||
es.addEventListener('connected', () => {
|
||||
reconnectDelay = 1000; // reset backoff
|
||||
_sseFailCount = 0; // reset failure counter
|
||||
debug('[SSE] Connected to event stream');
|
||||
});
|
||||
|
||||
@@ -101,15 +105,46 @@
|
||||
// Reconnect on error
|
||||
es.onerror = () => {
|
||||
es.close();
|
||||
// If auth was explicitly lost (401/403 from the polling loop),
|
||||
// don't attempt reconnection at all.
|
||||
if (window._dcAuthLost || _sseManuallyClosed) {
|
||||
console.warn('[SSE] Auth lost — stopping reconnection');
|
||||
return;
|
||||
}
|
||||
// Transient failures: retry with exponential backoff, stop after 5
|
||||
_sseFailCount++;
|
||||
if (_sseFailCount > 5) {
|
||||
console.warn('[SSE] Max reconnect attempts reached — stopping (server unreachable)');
|
||||
return;
|
||||
}
|
||||
console.warn(`[SSE] Disconnected, reconnecting in ${reconnectDelay / 1000}s...`);
|
||||
setTimeout(connect, reconnectDelay);
|
||||
reconnectDelay = Math.min(reconnectDelay * 2, MAX_RECONNECT);
|
||||
};
|
||||
}
|
||||
|
||||
// Called by grid.js when the polling loop detects auth loss (401/403)
|
||||
function closeAndStop() {
|
||||
_sseManuallyClosed = true;
|
||||
if (es) { try { es.close(); } catch (_) {} }
|
||||
}
|
||||
|
||||
// Called by totp-auth.js after a successful mid-session re-auth:
|
||||
// clears the latch so connect() can proceed again and resets the
|
||||
// failure backoff. (Plain _sseReconnect/connect() would early-return
|
||||
// on the latch forever — the user would need a manual F5.)
|
||||
function resumeAfterReauth() {
|
||||
_sseManuallyClosed = false;
|
||||
_sseFailCount = 0;
|
||||
reconnectDelay = 1000;
|
||||
connect();
|
||||
}
|
||||
|
||||
// Start on page load
|
||||
connect();
|
||||
|
||||
// Expose for debugging
|
||||
// Expose for debugging and cross-module coordination
|
||||
window._sseReconnect = connect;
|
||||
window._sseClose = closeAndStop;
|
||||
window._sseResume = resumeAfterReauth;
|
||||
})();
|
||||
|
||||
@@ -125,6 +125,15 @@
|
||||
if (typeof window.initializeDashboard === 'function') {
|
||||
window.initializeDashboard();
|
||||
}
|
||||
// Resume live updates after mid-session re-auth. The auth-loss
|
||||
// handlers latched polling + SSE off when the session expired
|
||||
// (grid.js sets _dcAuthLost, live-events.js latches the stream
|
||||
// closed); a fresh login must clear both and reconnect, or the
|
||||
// dashboard stays frozen on stale data until a manual F5.
|
||||
window._dcAuthLost = false;
|
||||
if (typeof window._sseResume === 'function') window._sseResume();
|
||||
else if (typeof window._sseReconnect === 'function') window._sseReconnect();
|
||||
if (typeof window.refreshAll === 'function') window.refreshAll();
|
||||
} else {
|
||||
errorEl.textContent = data.error || 'Invalid code';
|
||||
errorEl.className = 'totp-error';
|
||||
|
||||
+1
-1
@@ -1,4 +1,4 @@
|
||||
const CACHE = 'dashcaddy-shell-4a75cb88af';
|
||||
const CACHE = 'dashcaddy-shell-78eab743c2';
|
||||
const PRECACHE = [
|
||||
'/',
|
||||
'/index.html',
|
||||
|
||||
Reference in New Issue
Block a user