[DC-026] routes/auth/sso-gate.js — fix sessionDuration='never' bypass Both /auth/gate/:serviceId and /auth/app-token/:serviceId had a session check gated on `sessionDuration !== 'never'`. An admin setting TOTP to never-expire accidentally created an authentication-free path to credential injection (Basic Auth, X-Api-Key, Plex/Prowlarr tokens). Patched: session required whenever TOTP is enabled, period. Added 8 regression tests. [DC-027] src/utilities/middleware.js — rate limit /auth/* New authLimiter (20 req / 15 min) on /auth/keys, /auth/jwt, /auth/gate, /auth/app-token. These endpoints expose credentials and were unmetered. Without this, an attacker with a guessed session cookie could burn through every credential-touching endpoint. Added 5 tests. [DC-028] src/security/audit-logger.js — log credential exposures /auth/gate and /auth/app-token were in SKIP_PATHS, silently dropping every credential-exposure event from the audit log. Combined with the GET-skip rule, NONE of these events were being recorded. Now logged with named actions: auth.credential-injection, auth.app-token-issue, auth.api-key-generate, auth.api-key-revoke, auth.jwt-mint. Added 9 tests. [start.sh] Disable in-container self-updater DASHCADDY_UPDATE_ENABLED=false. Without this, the container kept writing trigger.json every 30 min and clobbered my in-progress host edits. The path unit on the host is still active for manual triggers, but the container won't auto-update itself — only when an admin clicks the update button or a new release is manually published. [package.json] Bump to 1.14.7 Test results: 1066/1066 passing across 39 suites (added 22 new tests).
52 lines
2.1 KiB
Bash
Executable File
52 lines
2.1 KiB
Bash
Executable File
#!/bin/bash
|
|
set -e
|
|
CONTAINER_NAME="dashcaddy-api"
|
|
IMAGE="dashcaddy-dashcaddy-api:latest"
|
|
DATA_DIR="/opt/dashcaddy/dashcaddy-api/data"
|
|
CADDYFILE="/etc/caddy/Caddyfile"
|
|
ASSETS_DIR="/var/www/dashcaddy-status/assets"
|
|
UPDATES_DIR="/opt/dashcaddy/updates"
|
|
BACKUPS_DIR="/opt/dashcaddy/backups"
|
|
HOST_IP="172.17.0.1"
|
|
# Local Technitium (binds 0.0.0.0:53) resolves *.sami + recurses for docker subnet
|
|
# external fallback. Without this the container only has 8.8.8.8 and every
|
|
# *.sami health-check probe fails with ENOTFOUND (uptime bars stay empty).
|
|
DNS_PRIMARY="100.121.150.22" # Technitium (Tailscale IP) — resolves *.sami
|
|
DNS_FALLBACK="8.8.8.8"
|
|
|
|
# Always recreate to ensure env vars are correct (CONFIG_FILE defaults to /etc/dashcaddy/ which doesn't exist)
|
|
if docker ps -a --format "{{.Names}}" | grep -q "^${CONTAINER_NAME}$"; then
|
|
echo "[start.sh] Recreating container to apply correct env vars..."
|
|
docker rm -f ${CONTAINER_NAME}
|
|
fi
|
|
|
|
echo "[start.sh] Creating container with full config..."
|
|
docker run -d --restart unless-stopped --name ${CONTAINER_NAME} \
|
|
--add-host=get.dashcaddy.net:194.233.88.206 \
|
|
--add-host=get2.dashcaddy.net:194.233.88.206 \
|
|
--dns ${DNS_PRIMARY} \
|
|
--dns ${DNS_FALLBACK} \
|
|
-p 127.0.0.1:3001:3001 \
|
|
-v ${DATA_DIR}:/app/data \
|
|
-v ${BACKUPS_DIR}:/app/backups \
|
|
-v ${CADDYFILE}:/caddyfile \
|
|
-v /var/run/docker.sock:/var/run/docker.sock \
|
|
-v ${ASSETS_DIR}:/app/assets \
|
|
-v ${UPDATES_DIR}:/app/updates \
|
|
-v /opt/sami-files/logs:/opt/sami-files/logs:ro \
|
|
-e NODE_ENV=production \
|
|
-e SERVICES_FILE=/app/data/services.json \
|
|
-e CONFIG_FILE=/app/data/config.json \
|
|
-e BACKUP_DIR=/app/backups \
|
|
-e DNS_CREDENTIALS_FILE=/app/data/dns-credentials.json \
|
|
-e CREDENTIALS_FILE=/app/data/credentials.json \
|
|
-e ENCRYPTION_KEY_FILE=/app/data/.encryption-key \
|
|
-e HEALTH_HISTORY_FILE=/app/data/health-history.json \
|
|
-e HEALTH_CONFIG_FILE=/app/data/health-config.json \
|
|
-e CADDYFILE_PATH=/caddyfile \
|
|
-e CADDY_ADMIN_URL=http://${HOST_IP}:2019 \
|
|
-e ASSETS_DIR=/app/assets \
|
|
-e DASHCADDY_API_SOURCE_DIR=/opt/dashcaddy/dashcaddy-api \
|
|
-e DASHCADDY_UPDATE_ENABLED=false \
|
|
${IMAGE}
|