Files
dashcaddy/status/sw.js
T
hermes 321334cd33
CI / Test & Lint (push) Has been cancelled
CI / Security audit (push) Has been cancelled
DC-048: multi-user bootstrap + admin invites (opt-in)
Implements the user-store + invite-store + admin routes. The whole
system is opt-in via siteConfig.authProviders.email.enabled = true;
single-user TOTP-only installs see zero behavior change.

Backend:
- src/security/user-store.js: users + allowlist + bootstrap sentinel,
  atomic writes, last-admin protection, defensive dataDir resolver.
- src/security/invite-store.js: single-use tokens (SHA-256 hashed on
  disk), TTL, auto-prune, defensive dataDir resolver.
- routes/auth/admin.js: /me, /admin/users (CRUD), /admin/allowlist,
  /admin/invites (CRUD), public /invites/:token (peek + accept).
- routes/auth/index.js: wires userStore, gates admin router on
  email auth being enabled.
- src/auth/providers/email.js: verify() enforces allowlist, creates
  user record, tags req.user; default-enabled flipped to opt-in.
- src/auth/providers/totp.js: bootstraps system@totp.local admin on
  first verify so current DNS2 operator shows in /admin/users.
- src/security/audit-logger.js: middleware adds userId/userEmail/
  userRole/viaProvider to log details when req.user is tagged.
- PUBLIC_ROUTES + CSRF allowlists updated for invite redemption.

Frontend:
- status/js/admin.js: modal overlay with users list (role-edit,
  delete), invite form (email/role/TTL), copy-link button,
  outstanding-invites list with revoke. Exports window.AdminPanel.
- status/js/core/init.js: calls AdminPanel.attachTrigger so the
  Admin button only appears when /me returns isAdmin=true.

Tests: 35 new tests across 3 files (user-store, invite-store, auth
multistore integration). Full suite: 1298/1298 passing.

Docs: BACKLOG.md marks DC-048 done. CHANGELOG.md [Unreleased]
section gets the DC-048 entry.
2026-07-20 17:44:11 -07:00

119 lines
3.5 KiB
JavaScript

const CACHE = 'dashcaddy-shell-1b7c08184e';
const PRECACHE = [
'/',
'/index.html',
'/css/themes.css',
'/css/dashboard.css',
'/css/driver.min.css',
'/css/onboarding.css',
'/dist/core.js',
'/dist/features.js',
'/dist/init.js',
'/dist/onboarding.js',
'/assets/fonts.css',
'/assets/site.webmanifest',
'/assets/favicon.svg',
'/assets/dashcaddy-favicon.ico',
'/assets/icon-192.png',
'/assets/icon-512.png',
'/assets/apple-touch-icon.png',
'/assets/dashcaddy-logo-dark.png',
'/assets/dashcaddy-logo-light.png',
'/assets/sami7777-logo.png',
'/assets/fonts/sami-grotesk/SamiGrotesk-Regular.woff2',
'/assets/fonts/sami-grotesk/SamiGrotesk-Medium.woff2',
'/assets/fonts/sami-grotesk/SamiGrotesk-Bold.woff2',
'/assets/fonts/DSEG7Classic-Bold.woff2',
'/assets/weather/clear-day.svg',
'/assets/weather/clear-night.svg',
'/assets/weather/partly-cloudy-day.svg',
'/assets/weather/partly-cloudy-night.svg',
'/assets/weather/cloudy.svg',
'/assets/weather/fog.svg',
'/assets/weather/drizzle.svg',
'/assets/weather/rain.svg',
'/assets/weather/sleet.svg',
'/assets/weather/snow.svg',
'/assets/weather/thunderstorm.svg',
'/assets/weather/wind.svg'
];
function isNavigationRequest(request) {
return request.mode === 'navigate';
}
function isStaticAsset(pathname) {
return pathname.startsWith('/assets/')
|| pathname.startsWith('/css/')
|| pathname.startsWith('/dist/');
}
async function networkFirst(request, preloadResponsePromise) {
const cache = await caches.open(CACHE);
try {
const preloadResponse = preloadResponsePromise ? await preloadResponsePromise : null;
if (preloadResponse) {
cache.put(request, preloadResponse.clone()).catch(() => {});
return preloadResponse;
}
const response = await fetch(request);
cache.put(request, response.clone()).catch(() => {});
return response;
} catch (_) {
return caches.match(request) || caches.match('/index.html');
}
}
async function staleWhileRevalidate(request) {
const cache = await caches.open(CACHE);
const cached = await cache.match(request);
const networkPromise = fetch(request)
.then((response) => {
cache.put(request, response.clone()).catch(() => {});
return response;
})
.catch(() => null);
if (cached) return cached;
return networkPromise.then((response) => response || Response.error());
}
self.addEventListener('install', (event) => {
self.skipWaiting();
event.waitUntil(
caches.open(CACHE).then((cache) =>
cache.addAll(PRECACHE.map((url) => new Request(url, { cache: 'reload' })))
)
);
});
self.addEventListener('activate', (event) => {
event.waitUntil((async () => {
const keys = await caches.keys();
await Promise.all(keys.filter((key) => key !== CACHE).map((key) => caches.delete(key)));
if ('navigationPreload' in self.registration) {
await self.registration.navigationPreload.enable();
}
await self.clients.claim();
})());
});
self.addEventListener('fetch', (event) => {
const { request } = event;
if (request.method !== 'GET') return;
const url = new URL(request.url);
if (url.origin !== self.location.origin) return;
if (url.pathname.startsWith('/api/v1/') || url.pathname.startsWith('/probe/')) return;
if (isNavigationRequest(request) || url.pathname === '/' || url.pathname.endsWith('/index.html')) {
event.respondWith(networkFirst(request, event.preloadResponse));
return;
}
if (isStaticAsset(url.pathname)) {
event.respondWith(staleWhileRevalidate(request));
}
});