Files
dashcaddy/status/build.js
hermes 321334cd33
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
DC-048: multi-user bootstrap + admin invites (opt-in)
Implements the user-store + invite-store + admin routes. The whole
system is opt-in via siteConfig.authProviders.email.enabled = true;
single-user TOTP-only installs see zero behavior change.

Backend:
- src/security/user-store.js: users + allowlist + bootstrap sentinel,
  atomic writes, last-admin protection, defensive dataDir resolver.
- src/security/invite-store.js: single-use tokens (SHA-256 hashed on
  disk), TTL, auto-prune, defensive dataDir resolver.
- routes/auth/admin.js: /me, /admin/users (CRUD), /admin/allowlist,
  /admin/invites (CRUD), public /invites/:token (peek + accept).
- routes/auth/index.js: wires userStore, gates admin router on
  email auth being enabled.
- src/auth/providers/email.js: verify() enforces allowlist, creates
  user record, tags req.user; default-enabled flipped to opt-in.
- src/auth/providers/totp.js: bootstraps system@totp.local admin on
  first verify so current DNS2 operator shows in /admin/users.
- src/security/audit-logger.js: middleware adds userId/userEmail/
  userRole/viaProvider to log details when req.user is tagged.
- PUBLIC_ROUTES + CSRF allowlists updated for invite redemption.

Frontend:
- status/js/admin.js: modal overlay with users list (role-edit,
  delete), invite form (email/role/TTL), copy-link button,
  outstanding-invites list with revoke. Exports window.AdminPanel.
- status/js/core/init.js: calls AdminPanel.attachTrigger so the
  Admin button only appears when /me returns isAdmin=true.

Tests: 35 new tests across 3 files (user-store, invite-store, auth
multistore integration). Full suite: 1298/1298 passing.

Docs: BACKLOG.md marks DC-048 done. CHANGELOG.md [Unreleased]
section gets the DC-048 entry.
2026-07-20 17:44:11 -07:00

219 lines
7.7 KiB
JavaScript

const fs = require('fs');
const path = require('path');
const crypto = require('crypto');
const esbuild = require('esbuild');
const JS = (...parts) => path.join(__dirname, 'js', ...parts);
const DIST = path.join(__dirname, 'dist');
const INDEX_HTML = path.join(__dirname, 'index.html');
const SW_JS = path.join(__dirname, 'sw.js');
// Bundle definitions — files are concatenated in order, then minified
const bundles = {
'core.js': [
// error-handler.js MUST be first — globals.js below does
// `const errorHandler = new ErrorHandler()` at top level, which throws
// ReferenceError if the ErrorHandler class isn't already on `window`.
JS('error-handler.js'),
JS('globals.js'),
JS('skeleton-loader.js'),
JS('theme.js'),
// DC-049: pluggable auth gate — claims ownership of the
// ?auth=required flow by setting window.__dc_049_handled BEFORE
// totp-auth.js runs, so the legacy TOTP-only overlay doesn't flicker
// in for multi-provider installs. Single-provider TOTP-only installs
// work because this module delegates back to window._showTotpOverlay().
JS('auth-gate.js'),
JS('totp-auth.js'),
// totp-recovery.js registers window._refreshRecoveryLink which totp-auth.js
// calls from showTotpOverlay(). Must come after totp-auth.js.
JS('totp-recovery.js'),
JS('service-credentials.js'),
JS('totp-settings.js'),
// DC-048 admin panel — modal-overlay UI for user/invite management.
// Renders the "Admin" trigger button into the top bar; only visible
// when /api/v1/auth/me returns isAdmin=true.
JS('admin.js'),
JS('core', 'credentials.js'),
JS('core', 'grid.js'),
JS('core', 'dns.js'),
JS('core', 'logs.js'),
JS('core', 'service-modals.js'),
JS('core', 'service-infrastructure.js'),
JS('core', 'service-crud.js'),
JS('core', 'service-create.js'),
JS('live-events.js'),
JS('service-filter.js'),
JS('batch-operations.js'),
],
'features.js': [
JS('logo-customization.js'),
JS('setup-wizard.js'),
JS('app-selector.js'),
JS('recipes.js'),
JS('import-export.js'),
JS('error-logs.js'),
JS('container-logs.js'),
JS('snapshot.js'),
JS('smart-arr-connect.js'),
JS('notification-settings.js'),
JS('panel-tabs.js'),
JS('backup-restore.js'),
JS('resource-monitor.js'),
JS('health-check.js'),
JS('update-management.js'),
JS('docker-resources.js'),
JS('compose-import.js'),
JS('container-exec.js'),
JS('audit-log.js'),
JS('security-center.js'),
JS('weather.js'),
JS('clock.js'),
JS('card-badges.js'),
JS('theme-builder.js'),
JS('license.js'),
],
'onboarding.js': [
JS('driver.min.js'),
// error-handler.js moved to core.js bundle; window.ErrorHandler is already
// set before this bundle runs.
JS('progress-tracker.js'),
JS('theme-adapter.js'),
JS('tooltip-definitions.js'),
JS('dns-template-selector.js'),
JS('tour-manager.js'),
JS('onboarding.js'),
],
'init.js': [
JS('core', 'init.js'),
JS('monitoring-widgets.js'),
JS('keyboard-shortcuts.js'),
],
};
function updateInlineScriptCspHash() {
const html = fs.readFileSync(INDEX_HTML, 'utf8');
// The hash MUST match what the browser computes from the served bytes.
// git's text normalization + tar transport strip CRLF on the Linux side,
// so the deployed file is always LF-only — even when the dev copy is CRLF
// (e.g. cloned on Windows). Normalize before hashing so a Windows-built
// index.html produces a CSP allowlist that matches the served LF version.
const normalized = html.replace(/\r\n/g, '\n');
const scripts = [...normalized.matchAll(/<script>([\s\S]*?)<\/script>/g)];
const target = scripts.find(match => {
const block = match[1] || '';
return block.includes("license-topbar-version") || block.includes("openVersionInfo") || block.includes("widget-");
});
if (!target) {
throw new Error('Could not find inline dashboard bootstrap script in index.html');
}
const scriptContent = target[1];
const hash = crypto.createHash('sha256').update(scriptContent).digest('base64');
// Write the CSP update back into the original (possibly CRLF) file so we
// don't churn the working copy's line endings just because we read it.
const updatedHtml = html.replace(
/script-src 'self' 'sha256-[^']+';/,
`script-src 'self' 'sha256-${hash}';`
);
if (updatedHtml !== html) {
fs.writeFileSync(INDEX_HTML, updatedHtml);
}
return hash;
}
async function build() {
// Ensure dist/ exists
if (!fs.existsSync(DIST)) fs.mkdirSync(DIST);
const results = {};
for (const [outName, files] of Object.entries(bundles)) {
// Read and concatenate
const parts = [];
for (const file of files) {
if (!fs.existsSync(file)) {
console.warn(` WARN: ${path.relative(__dirname, file)} not found, skipping`);
continue;
}
parts.push(fs.readFileSync(file, 'utf8'));
}
const concatenated = parts.join(';\n');
// Minify with esbuild (safe to re-minify already-minified code like driver.min.js)
const { code } = await esbuild.transform(concatenated, {
minify: true,
target: 'es2020',
});
const outPath = path.join(DIST, outName);
fs.writeFileSync(outPath, code);
const rawSize = (Buffer.byteLength(concatenated) / 1024).toFixed(1);
const minSize = (Buffer.byteLength(code) / 1024).toFixed(1);
results[outName] = { rawSize, minSize, fileCount: files.length };
}
const cspHash = updateInlineScriptCspHash();
const cacheTag = updateServiceWorkerCache();
// Summary
console.log('\n DashCaddy Frontend Build\n');
console.log(' Bundle Files Raw Min');
console.log(' ─────────────────────────────────────────');
let totalRaw = 0, totalMin = 0;
for (const [name, r] of Object.entries(results)) {
console.log(` ${name.padEnd(18)} ${String(r.fileCount).padStart(3)} ${r.rawSize.padStart(6)} KB ${r.minSize.padStart(6)} KB`);
totalRaw += parseFloat(r.rawSize);
totalMin += parseFloat(r.minSize);
}
console.log(' ─────────────────────────────────────────');
console.log(` ${'Total'.padEnd(18)} ${totalRaw.toFixed(1).padStart(6)} KB ${totalMin.toFixed(1).padStart(6)} KB`);
console.log(`\n Output: ${DIST}`);
console.log(` CSP Hash: sha256-${cspHash}`);
console.log(` SW Cache: dashcaddy-shell-${cacheTag}\n`);
}
// Rewrites the CACHE constant in sw.js to a tag derived from the bundle
// contents. Every change in dist/ produces a new cache name; on next load
// the SW's activate handler wipes all older caches, so users never get
// stuck on stale precached bundles after a release.
function updateServiceWorkerCache() {
const sw = fs.readFileSync(SW_JS, 'utf8');
const hash = crypto.createHash('sha256');
for (const name of Object.keys(bundles)) {
hash.update(fs.readFileSync(path.join(DIST, name)));
}
const tag = hash.digest('hex').slice(0, 10);
const updated = sw.replace(
/const CACHE = 'dashcaddy-shell-[^']+';/,
`const CACHE = 'dashcaddy-shell-${tag}';`
);
if (updated !== sw) {
fs.writeFileSync(SW_JS, updated);
}
return tag;
}
// Watch mode
if (process.argv.includes('--watch')) {
console.log(' Watching for changes...\n');
build();
const jsDir = path.join(__dirname, 'js');
let debounce = null;
fs.watch(jsDir, { recursive: true }, (event, filename) => {
if (!filename || !filename.endsWith('.js')) return;
clearTimeout(debounce);
debounce = setTimeout(() => {
console.log(` Changed: ${filename}`);
build();
}, 200);
});
} else {
build();
}