Commit Graph

25 Commits

Author SHA1 Message Date
UNITRONIX 5de22d8ce6 Enhance agent source management and update process
- Added functionality to track the remote SHA of the agent source, improving consistency during updates.
- Implemented a new method to sync the full support-agent source from GitHub, ensuring all necessary files are staged for rebuilds.
- Introduced a mechanism to check for agent source drift, allowing for automatic repairs when discrepancies are detected.
- Updated the update service to trigger agent source synchronization and rebuilds based on specific file changes, streamlining the update workflow.
2026-06-04 03:18:28 +02:00
UNITRONIX fc8ac44baf Enhance support agent staging and rebuild process
- Implemented a conditional staging process for the Go support-agent source during updates, creating a rebuild flag for generator bundles.
- Added functions to handle the requeuing of builds and marking rebuilds as pending, improving the update workflow.
- Updated the update service to stage support-agent files and trigger rebuilds after in-app updates.
- Removed the obsolete GitHub Actions workflow for the support agent, streamlining CI/CD processes.
2026-06-04 03:13:43 +02:00
UNITRONIX d07da4951a Implement support agent staging and enhance connection handling
- Added a new function to stage the Go support-agent source for Generator builds, ensuring proper setup without a full git checkout.
- Refactored connection handling to improve TLS configuration, allowing for insecure connections based on environment variables.
- Updated UI elements for better user experience, including resizing and wrapping labels for status messages.
- Enhanced the enrollment process with improved error handling and status updates.
- Introduced new environment variables and command-line options for running the agent without a GUI, catering to environments like VMs or RDP.
- Updated README and build scripts to reflect new features and requirements.
2026-06-04 03:08:17 +02:00
UNITRONIX 3484ef68be Enhance support agent with audio handling and consent management
- Added audio stream handling to the agent, including support for audio start and stop messages.
- Introduced lifecycle callbacks for consent and session management in the agent configuration.
- Updated desktop handling to utilize new consent handler and session start/end callbacks.
- Improved UI to reflect enrollment status and consent requests, enhancing user experience.
- Refactored branding structure to include additional color properties for better theming.
2026-06-04 02:09:19 +02:00
UNITRONIX 43e0b6f40a Integrate P2P/relay controls for issue #157.
Expose global connection strategy in the web panel with systemd/Docker persistence, extend server health diagnostics, enforce org network policy in the signal handler, and document when relay fallback is expected vs misconfiguration.
2026-06-04 00:26:58 +02:00
UNITRONIX 207a7467d0 fix(update): preserve operator config and passwords on upgrade (#158)
Merge .env keys instead of replacing files, patch systemd/NSSM in place,
block panel updates when the server cannot be rebuilt, and stop routine
updates from syncing admin passwords from .env into auth.db/PostgreSQL.
2026-06-04 00:13:12 +02:00
UNITRONIX b703db5e5f fix(auth): sync LDAP/OIDC provider and role from Go to panel (#148)
Node now persists auth_provider on SSO provisioning and re-syncs role/provider after Go login success, including SQLite auth.db backfill. Go login returns auth_provider; LDAP group mapping accepts CN keys and newlines. Default agent build cache under dataDir to avoid EACCES.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-02 02:42:25 +02:00
UNITRONIX 0f161181f1 feat(installers): run services under unprivileged accounts by default
Privilege separation across all installers so the long-running services no longer run with full administrative rights:

betterdesk.sh: installer keeps root but systemd units now run as a dedicated unprivileged 'betterdesk' system account by default (auto-created via ensure_service_user). Added full systemd hardening for the Go server (NoNewPrivileges, ProtectSystem=strict, ProtectHome, PrivateTmp, ReadWritePaths) and light hardening for the Node.js console. chown migrates existing root-owned data to the service account on update. Opt-out via --run-as-root / BETTERDESK_RUN_AS_ROOT=1; custom account via BETTERDESK_SERVICE_USER. Minimal mode covered too.

betterdesk.ps1: NSSM services now run under their per-service low-privilege virtual accounts (NT SERVICE\<service>) instead of LocalSystem, with scoped icacls grants on the install/data dirs (Set-ServiceLeastPrivilege helper). Applied to the Go server, Node.js console and minimal-mode service. Opt-out via -RunAsRoot / BETTERDESK_RUN_AS_ROOT=1.

Docker: verified already privilege-separated (supervisord drops both programs to user=betterdesk; multi-container images drop via su-exec).

Also bundles in-progress changes to the Go server API, Node.js console services and Docker compose/Dockerfiles.

This commit was made possible thanks to Insolve.
2026-05-31 00:35:28 +02:00
UNITRONIX 321e49b7f7 fix: polish folder tiles and Available Devices payload (#138) 2026-05-22 02:29:16 +02:00
UNITRONIX 99add5d434 fix: improve device folder tiles and RustDesk group sync (#138) 2026-05-19 18:56:09 +02:00
UNITRONIX 41616fa121 Fix RustDesk tag and folder filters 2026-05-19 00:06:54 +02:00
UNITRONIX bdbf09edc6 feat: add user groups management functionality
- Implemented user groups creation, editing, and deletion features.
- Added API endpoints for managing user groups: create, update, and delete.
- Enhanced user interface with a dedicated user groups manager section.
- Updated translations for user groups related strings in multiple languages.
- Improved CSS styles for user groups display and actions.
- Added tests for user groups API functionality.
2026-05-18 23:58:56 +02:00
UNITRONIX c30d1a86aa Fix RustDesk folder tag sync 2026-05-18 02:34:38 +02:00
UNITRONIX 87e9251d31 feat: Implement user group management and access control
- Added user group membership functionality, allowing users to be assigned to groups.
- Introduced validation for group GUIDs and enhanced error handling in user routes.
- Updated device group routes to support allowed user groups, enabling better access control for devices.
- Enhanced database schema to include user group memberships and device group user group access.
- Updated services and database adapters to handle user group data and relationships.
- Modified front-end views to display and manage user groups effectively.
- Added tests to ensure proper functionality of user group assignments and device access control.
2026-05-18 02:23:57 +02:00
UNITRONIX 1460b55951 fix: separate RustDesk folder groups from tags (#138) 2026-05-15 01:19:21 +02:00
UNITRONIX 1f3b310a11 fix: keep RustDesk address books user-owned (#137)
Prevent the RustDesk Client API address-book response from auto-creating peers from console inventory. Existing address-book peers still receive console-side tag synchronization, while /api/peers remains the inventory endpoint.

Refs: #137

Reported-by: @boruto79

Also-reported-by: @karabelnikov
2026-05-15 01:05:32 +02:00
UNITRONIX 241d367ea7 fix: add tag-based dynamic device groups (#140) 2026-05-15 00:57:59 +02:00
UNITRONIX 96858c187b fix: scope RustDesk API peers to address books (#143)
Limit RustDesk client peer inventory for non-edit roles to peers already present in the authenticated user's legacy or personal address book. Keep editable operator/admin inventory sync unchanged and add route regression coverage for viewer accounts.

Reported-by: Henry-739
Refs: #143
Co-authored-by: GitHub Copilot <copilot@github.com>
2026-05-15 00:30:15 +02:00
UNITRONIX b9d4c77076 fix: update address book sync logic to exclude folder tags and enhance tag handling 2026-05-14 02:00:10 +02:00
UNITRONIX 783f2a8a43 fix: sync device tags with RustDesk client API
Refs #138

Reported-by: Skansmer (#138)
2026-05-11 22:56:19 +02:00
UNITRONIX 74300c916c Fix user recovery after update
Reported-by: @SterlynKong

Refs: #136
2026-05-09 01:02:00 +02:00
UNITRONIX c249f63317 fix(web): polish dashboard and accessibility layout 2026-05-03 03:11:49 +02:00
UNITRONIX 1ce11348b3 chore: update dependencies, fix tests and compilation errors
Go server:
- Update pgx v5.8.0->v5.9.1, crypto v0.48->v0.49, sqlite v1.46.1->v1.48.1
- Update libc, sys, sync, text, isatty, exp to latest minor/patch
- govulncheck: 0 vulnerabilities
- Fix stale TestRelayPairing test (removed RelayResponse expectation that
  conflicts with E2E encryption handshake design)

Node.js console:
- Apply minor/patch dependency updates via npm update
- npm audit: 0 vulnerabilities
- Fix auth.routes.test.js: add missing recordAttempt mock to authService
- All 61 tests passing across 10 test suites

Rust agent-client:
- Fix 5 async Tauri commands: scope MutexGuard in blocks to prevent
  !Send future errors with tauri 2.10.x (reconnect_agent, send_diagnostics,
  register_device, request_help, cancel_help_request, send_chat_message)
- Add missing icons/ directory (required by tauri-build for Windows resources)
- cargo check: 0 errors, 2 dead_code warnings

Rust MGMT client:
- cargo check: 0 errors
2026-04-09 10:55:52 +02:00
UNITRONIX bbf839754e Harden bd-mgmt, API key, and WS security
Add multiple security hardenings across the server and web console: enforce proof-of-possession for /ws/bd-mgmt using Ed25519-signed headers with timestamp/nonce and replay protection (public key binding, canonicalization, storage, verification, and tests); remove legacy API key query param and config-table fallback in favor of scoped api_keys (migrate bootstrap key into api_keys); tighten WebSocket origin handling for relay and signal servers to allow only localhost origins by default unless an explicit allowlist is set; update auth middleware public paths and test helpers to use X-API-Key header; add ensureScopedAPIKey migration and related helpers; add a GitHub Secret Scan workflow and an audit report. Misc: propagate audit logging on bd-mgmt connect/disconnect and validate enrollment public keys during device register.
2026-03-29 01:48:14 +01:00
UNITRONIX d39110b2ae Add tests, i18n updates, chat & remote fixes
Add unit tests and test helpers (5 suites, 41 tests) and test npm scripts; introduce deviceStatusPush service and WS real-time device status push integration. Fix chatRelay to acknowledge connections (send `welcome`), and apply multiple web remote/rdclient fixes (video ack/timing, keyframe refresh, SourceBuffer trimming, input focus handling) to improve FPS and control. Add new server route file (system.routes.js), new device-status service, update server.js and package.json, and modify various frontend CSS/JS/views. Update English and Polish locale files with many new widget/i18n keys and remove the Russian locale file (ru.json). Also include assorted UI/desktop-widget dashboard tweaks and documentation status updates in .github/copilot-instructions.md.
2026-03-27 00:34:12 +01:00