Commit Graph

72 Commits

Author SHA1 Message Date
UNITRONIX 577fc79a97 chore: update Docker Compose image tags to 3.2.12 and enhance documentation for versioning 2026-06-11 18:36:48 +02:00
UNITRONIX aea7b30b29 fix(security): enhance path validation and rate limiting for file access
Updated CodeQL configuration to exclude additional paths for security checks. Introduced a new file access rate limiter to prevent abuse of file download endpoints. Improved path resolution functions to ensure confined access and added validation in body scalar functions to reject non-scalar types. Enhanced error handling in API endpoint validation to prevent invalid inputs.
2026-06-11 18:33:14 +02:00
UNITRONIX c2e0e2e784 fix(security): harden CodeQL findings across console and Go server
Address GitHub code scanning alerts with OIDC SSRF guards, confined path
helpers, safer client routing, branding sanitization, upload rate limits,
and CodeQL config exclusions for dev-only and protocol-intentional hashes.
2026-06-11 06:57:58 +02:00
UNITRONIX 556f0a2a3f fix(ci): grant pull-requests write for stable version bump workflow
Fixes automated release PR creation after merge to main (was failing with
Resource not accessible by integration).
2026-06-10 03:03:22 +02:00
UNITRONIX 6d7692ea6a fix(security): phase-A log redaction, font/transfer paths, CI permissions
Stop logging generated admin passwords, redact API login usernames,
confine font and file-transfer temp paths with safePath, and scope
GitHub Actions permissions in build.yml.
2026-06-09 02:42:56 +02:00
UNITRONIX cf6f70f6cd fix(ci): correct find precedence in server release checksum step
The migrate artifact directory was matched without -type f, causing
sha256sum to fail on tag pushes (e.g. v3.1.3-dev).
2026-06-09 02:08:40 +02:00
UNITRONIX c219f3be68 fix(security): patch CVE-2026-50575 and harden deps, SSRF, shell exec
Complete GHSA-3v82-3gf8-fxx8 WebSocket replay fix for soft-deleted peers,
bump vulnerable Go/Rust dependencies, and apply CodeQL-driven hardening
(OIDC URL validation, path confinement, execFileSync, rate limits).
2026-06-09 02:05:17 +02:00
UNITRONIX 8ae17f38ec fix(ci): restore direct dev version bump after relaxing branch protection
GitHub Actions cannot create PRs in this repo; dev no longer requires
pre-push status checks so the bump bot can push [version-bump] commits.
2026-06-07 17:01:03 +02:00
UNITRONIX ef62317927 fix(ci): dev version bump via PR to satisfy branch protection
Direct pushes to protected dev were rejected (GH006). Create bump/vX.Y.Z
PR and admin-merge; skip re-run on bot merge commits to avoid loops.
2026-06-07 16:59:41 +02:00
UNITRONIX 3076c009c6 fix(ci): release bump via PR to satisfy protected main branch
Direct pushes from version-bump-main were rejected by branch protection;
create release/vX.Y.Z PR and admin-merge instead.
2026-06-07 16:57:30 +02:00
UNITRONIX 317365c766 Add dev/main branching, automated versioning, and update channel switcher.
Introduce bump-version.js with CI workflows for patch bumps on dev and
stable releases on main, plus panel and installer UI to choose stable vs
development GitHub update branches.
2026-06-07 16:48:31 +02:00
UNITRONIX 73d614b338 fix(console): migrate legacy auth.db token_hash on SQLite upgrade (#158)
Existing Docker volumes crashed at startup because ensureAuthTables indexed
token_hash before the column existed on upgraded auth.db files. Bump images to 3.0.0.
2026-06-07 00:26:48 +02:00
UNITRONIX 9c6490f6ab fix(ci,update): unblock Web Console CI and non-root in-app updates.
Use npm install without a lockfile in CI, treat root-owned installer scripts as non-critical update failures, and skip privileged H-7 hooks when betterdesk already exists without sudo.
2026-06-06 14:46:41 +02:00
UNITRONIX 647a3221f9 Harden console security and wire fixes into the update flow.
Hash RustDesk access tokens at rest (phase 1), add SSRF guards for admin network tools with LAN monitoring support, run dedicated console service user on Linux, and hook post-update verification plus service patching into both betterdesk.sh and the in-app updater.
2026-06-06 14:40:51 +02:00
UNITRONIX e067a5a865 fix(update): disable in-app updates for Docker GHCR deployments (#158)
The panel updater assumed a native install with Go source on disk. In
Compose/GHCR mode it now uses the embedded image commit, clears stale
binary markers, and directs operators to pull new container images instead.
2026-06-06 14:09:57 +02:00
UNITRONIX fc8ac44baf Enhance support agent staging and rebuild process
- Implemented a conditional staging process for the Go support-agent source during updates, creating a rebuild flag for generator bundles.
- Added functions to handle the requeuing of builds and marking rebuilds as pending, improving the update workflow.
- Updated the update service to stage support-agent files and trigger rebuilds after in-app updates.
- Removed the obsolete GitHub Actions workflow for the support agent, streamlining CI/CD processes.
2026-06-04 03:13:43 +02:00
UNITRONIX 3484ef68be Enhance support agent with audio handling and consent management
- Added audio stream handling to the agent, including support for audio start and stop messages.
- Introduced lifecycle callbacks for consent and session management in the agent configuration.
- Updated desktop handling to utilize new consent handler and session start/end callbacks.
- Improved UI to reflect enrollment status and consent requests, enhancing user experience.
- Refactored branding structure to include additional color properties for better theming.
2026-06-04 02:09:19 +02:00
UNITRONIX 196a6addfd ci: stop desktop client builds on version tags
Desktop client is still in development. Version tags (v*) now only
trigger Docker image publish (server, console, all-in-one). Desktop
builds remain available via manual workflow_dispatch.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-03 00:55:05 +02:00
UNITRONIX 3ee1cd8062 feat(docker): publish versioned GHCR tags aligned with CHANGELOG
Wire docker-publish to git tags v*, workflow_dispatch tag input, and
semver prereleases; pin quick-start compose to 3.0.0-alpha by default.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-03 00:46:15 +02:00
UNITRONIX 83f3617f98 fix(update): fix infinite update loop and add GitHub-pull update to ALL-IN-ONE scripts (#154)
updateService.js: distinguish critical vs non-critical failures in SHA tracking. Server binary compile/download failures are non-critical — SHA is saved so the same update is not shown again on restart. update-cli.js: match same logic, non-critical failures don't set exit code 1. betterdesk.sh: new update_from_github() with git clone + tarball fallback, 3-method menu. betterdesk.ps1: new Update-FromGitHub with git clone + ZIP fallback, 3-method menu. betterdesk-docker.sh: new update_docker_from_github() with 2-method menu.

This commit was made possible thanks to Insolve.
2026-05-29 02:28:57 +02:00
Knienartowicz ee0c2e1dc7 docs(copilot): require Insolve attribution footer in every commit
Add mandatory commit convention to .github/copilot-instructions.md so future AI-generated commits always include the 'This commit was made possible thanks to Insolve.' footer.

This commit was made possible thanks to Insolve.
2026-05-26 14:08:52 +02:00
UNITRONIX f98bc50b21 feat: add funding options to README and create funding.yml 2026-05-26 03:12:54 +02:00
UNITRONIX 4eed88673c fix(updates): atomic binary replace + accurate modal status
- deployServerBinary: use rename(2) for atomic replace, fixes ETXTBSY
  when target Go binary is busy (Linux kernel handles inode swap).
  Falls back to copyFileSync on cross-device rename or non-Linux.
  Windows: rename target out of the way first, then move new in.
- settings.js: mark 'server' phase as error when build succeeded but
  deploy failed (was incorrectly marking 'done' from build alone).
- settings.js: completion modal now shows error title, error message
  and pre-formatted stderr when serverDeploy.success === false.
- i18n: added complete_with_errors, modal_done_with_errors_title in
  en/pl.
2026-04-26 01:23:18 +02:00
UNITRONIX 6b145938c0 Fix CSRF token retrieval in frontend JS
Use the layout-provided CSRF token (window.BetterDesk?.csrfToken) instead of a non-existent meta tag. This fixes failing PUT requests for organization policy saves (Issue #112), and resolves attestation verify/revoke failures. Also replace toolkit's cached meta lookup with a getCsrfToken() helper so API calls always read the current token. Updated .github/copilot-instructions.md to document the Phase 53 CSRF fixes.
2026-04-17 06:42:53 +02:00
UNITRONIX 45e5fda9d0 Implement RBAC v52, org scoping and assorted fixes
Adds a full Phase-52 RBAC implementation and multiple server/frontend fixes. Key changes: new auth/permissions.go with 28 granular permissions and DefaultRolePermissions, expanded 7-role hierarchy and helpers in auth/roles.go, JWT org context and GenerateOrgToken, requirePermission/requireOrgMembership middlewares (Go + Node.js), DB schema & adapter changes for role_permissions and is_server_admin, org role boundary checks and peer org scoping, and guards for last-admin demotion and self-demotion. Also: TCP EOF/connection-reset log filtering in signal/relay servers, improved startup banner port display, KEYS_PATH auto-detect warning, CSS hover/transition layout fixes, admin password race mitigation, ID-change ghost peer cleanup, added Tauri ACL schema files, and a new RBAC_PHASE52.md doc. Misc: numerous web-nodejs i18n, CSS, JS and route updates and an updated .github/copilot-instructions.md timestamp/summary.
2026-04-10 23:40:55 +02:00
UNITRONIX a3202515d6 Fix Node.js 20 deprecation and Docker secrets lint warnings
GitHub Actions:
- actions/checkout: v4 -> v6 (Node.js 24 native)
- docker/login-action: v3 -> v4 (Node.js 24 native)
- docker/metadata-action: v5 -> v6 (Node.js 24 native)

Docker lint:
- Add check=skip=SecretsUsedInArgOrEnv to Dockerfile + Dockerfile.console
  (PUB_KEY_PATH and API_KEY_PATH are file paths, not secrets)
2026-04-06 17:19:30 +02:00
UNITRONIX 23567a7042 Update GitHub Actions to Node.js 24 compatibility
- docker/setup-buildx-action: v3 -> v4
- docker/build-push-action: v5 -> v6
- Add FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true env var
  (Node.js 20 deprecated June 2, 2026)
2026-04-06 17:09:56 +02:00
UNITRONIX 66c46f7d93 Fix SBOM/Trivy GHCR auth for private packages 2026-04-05 14:28:28 +02:00
UNITRONIX dd0889e3d6 Add SessionManager; update docs, i18n & CI
Introduce a SessionManager for relay-based remote sessions in the Tauri MGMT client: new SessionCommand API, start/stop/session input routing, clipboard/recording/quality controls, and notification read/dismiss state. Wire AppState with new mutexes and show main window on startup. CI: add SBOM generation (anchore) and Trivy vulnerability scan steps. Misc: change console Docker DB path, large README/CHANGELOG updates (chat E2E, unattended access/WOL, i18n expansion, CDAP/SDK docs), and many web-nodejs assets/locales/routes/views/services and server-side changes.
2026-04-05 13:42:07 +02:00
UNITRONIX be9e65dcae Add MGMT and Agent Tauri clients
Introduce two new desktop apps: betterdesk-mgmt (operator/admin console) and betterdesk-agent-client (lightweight endpoint agent).

Key changes:
- Add complete betterdesk-agent-client scaffold: frontend (index.html, TSX components, i18n, styles, Vite/TS configs, package.json) and Rust Tauri backend (Cargo.toml, build.rs, tauri.conf.json, commands.rs, config.rs, registration.rs, sysinfo_collect.rs, NSIS language file).
- Add betterdesk-mgmt entries and assets (registered in docs) and update repo docs to describe both MGMT and Agent clients.
- Update .github/copilot-instructions.md to reflect MGMT/Agent client split and add detailed TODO/feature lists.
- Update .gitignore to exclude build artifacts for both new Tauri apps.
- Add docs/new_agents/client1.md and docs/new_agents/client2.md.
- Minor changes to server DB files and web-nodejs i18n/asset files.

This commit adds the initial scaffolding and core IPC/registration/diag features for the agent and registers the MGMT client in repository docs; further implementation and testing remain.
2026-04-03 00:41:49 +02:00
UNITRONIX bbf839754e Harden bd-mgmt, API key, and WS security
Add multiple security hardenings across the server and web console: enforce proof-of-possession for /ws/bd-mgmt using Ed25519-signed headers with timestamp/nonce and replay protection (public key binding, canonicalization, storage, verification, and tests); remove legacy API key query param and config-table fallback in favor of scoped api_keys (migrate bootstrap key into api_keys); tighten WebSocket origin handling for relay and signal servers to allow only localhost origins by default unless an explicit allowlist is set; update auth middleware public paths and test helpers to use X-API-Key header; add ensureScopedAPIKey migration and related helpers; add a GitHub Secret Scan workflow and an audit report. Misc: propagate audit logging on bd-mgmt connect/disconnect and validate enrollment public keys during device register.
2026-03-29 01:48:14 +01:00
UNITRONIX af28d0d766 Add draggable zone borders, access policies, WOL fix, i18n 2026-03-28 00:08:42 +01:00
UNITRONIX d39110b2ae Add tests, i18n updates, chat & remote fixes
Add unit tests and test helpers (5 suites, 41 tests) and test npm scripts; introduce deviceStatusPush service and WS real-time device status push integration. Fix chatRelay to acknowledge connections (send `welcome`), and apply multiple web remote/rdclient fixes (video ack/timing, keyframe refresh, SourceBuffer trimming, input focus handling) to improve FPS and control. Add new server route file (system.routes.js), new device-status service, update server.js and package.json, and modify various frontend CSS/JS/views. Update English and Polish locale files with many new widget/i18n keys and remove the Russian locale file (ru.json). Also include assorted UI/desktop-widget dashboard tweaks and documentation status updates in .github/copilot-instructions.md.
2026-03-27 00:34:12 +01:00
UNITRONIX 95f2beb744 feat: organizations, desktop mode, i18n (ja/ko/ru), security docs, client i18n integration 2026-03-25 20:27:04 +01:00
UNITRONIX 1e2047c033 BetterDesk 3.0.0 Alpha 2026-03-24 00:26:25 +01:00
UNITRONIX 9c3631c1e8 Disable API TLS, escape $ in systemd, fix ports
Prevent breaking RustDesk clients by keeping the API port HTTP-only and removing automatic API TLS: update APITLSEnabled logic (config.go) and remove/add-removal of -tls-api / -force-https from install scripts and service updates (betterdesk.sh, betterdesk.ps1). Fix systemd escaping for admin password and PostgreSQL URL by converting $ → $$ before writing ExecStart/Environment so credentials with $ are preserved. Add MainThread to port diagnostic patterns to avoid false positives for Node.js on newer Linux (betterdesk.sh). Also include minor struct/tag formatting and response key alignment in CDAP Go code and update changelog and copilot instructions. These changes restore client compatibility, harden installer/service writes, and improve diagnostics.
2026-03-21 00:20:53 +01:00
UNITRONIX a957f3fe2a Add CDAP gateway & redesign devices UI
Introduce full CDAP subsystem and devices UI overhaul. Adds a new CDAP WebSocket gateway (cdap/gateway.go) with auth, connection lifecycle, message loop, heartbeat monitor and APIs (cdap/api.go, cdap/auth.go, cdap/handler.go, cdap/manifest.go, cdap/messages.go). Wire CDAP into the server (api/server.go + handlers in api/cdap_handlers.go) exposing REST endpoints for status, device list, info, manifest, state and sending commands. Enhance peer handling: CDAP-connected overlay in peer list/get, device revocation/cascade support in handleDeletePeer (blocklist, connection teardown, events + audit), and new audit action ActionPeerRevoked. Frontend updates include CDAP device page, widgets, commands, styles and services; major devices page UI redesign (responsive folder chips, toolbar, slim table, kebab menu) plus related CSS/JS/views, translations, docs and assets. Overall adds CDAP features, revocation workflow, and a responsive devices UI.
2026-03-20 02:01:48 +01:00
UNITRONIX 98209249f3 Fix ForceRelay UUID mismatch; add GHCR notes
Change ForceRelay TCP path to return a PunchHoleResponse with NatType=SYMMETRIC instead of sending a server-generated RelayResponse, so clients will send RequestRelay with their own UUIDs and both sides use the same UUID (resolves relay pairing mismatch, Issue #66). Add diagnostic log.Printf calls in handleRequestRelay (UDP) and handleRequestRelayTCP to aid relay pairing debugging. Update docs and CI: add GHCR "pull access denied" troubleshooting and package visibility guidance to DOCKER_QUICKSTART.md, docker-compose.quick.yml, and the docker-publish workflow summary (addresses Issue #67). Also update changelog entry in .github/copilot-instructions.md and add related files to .gitignore.
2026-03-19 22:41:24 +01:00
UNITRONIX 511971b3ce PS1 RNG fix and Rust→Go upgrade detection
Replace .NET 6-only RandomNumberGenerator::Fill() with RNGCryptoServiceProvider.GetBytes() in betterdesk.ps1 to restore API key generation on Windows PowerShell 5.1 (fixes issue #38). Add Rust→Go upgrade detection and handling to both betterdesk.ps1 and betterdesk.sh: detect SERVER_TYPE=rust, warn users that migration requires a fresh install, redirect in auto mode or prompt interactively, and avoid a broken upgrade path from legacy Rust (hbbs/hbbr) to the Go server (addresses issues #66 and #38). Update .github/copilot-instructions.md changelog and last-updated footer to document the changes.
2026-03-19 17:55:46 +01:00
UNITRONIX 2d6b730f99 Add Docker quickstart and GHCR publish workflow
Add Docker quickstart flow and CI to publish images to GitHub Container Registry. Creates a new GitHub Actions workflow (.github/workflows/docker-publish.yml) that builds multi-arch images (server, console, all-in-one) and pushes to ghcr.io. Adds docker-compose.quick.yml using pre-built GHCR images and a DOCKER_QUICKSTART.md with a 30s one‑line quick start, troubleshooting, and configuration notes. Update README Docker section to surface the quick start and adjust docker-compose.yml header to reference the quick file. Also update .github/copilot-instructions.md to document the Docker quick start and publishing phase.
2026-03-19 06:47:18 +01:00
UNITRONIX 199a321fe5 Add peer metrics, PATCH updates & relay fixes
Introduce peer metrics persistence and partial peer updates, plus relay UUID recovery and soft-delete protections.

- DB: add PeerMetric type and new Database methods (SavePeerMetric, GetPeerMetrics, GetLatestPeerMetric, CleanupOldMetrics, UpdatePeerFields, IsPeerSoftDeleted). Add peer_metrics table and indexes in SQLite and PostgreSQL migrations; implement all methods for both backends.
- API: handleClientHeartbeat now parses cpu/memory/disk and saves metrics; new endpoints PATCH /api/peers/{id} to update note/user/tags and GET /api/peers/{id}/metrics for historical metrics. handleSetPeerTags now accepts either string or array JSON payloads. Added audit.ActionPeerUpdated.
- Signal server: add pendingRelayUUIDs store (with TTL cleanup, store/get helpers) to recover missing UUIDs from old clients when RelayResponse contains empty uuid; store pending UUIDs when forwarding RequestRelay/PunchHole. Add IsPeerSoftDeleted checks to reject re-registration of soft-deleted devices.
- Node.js panel: betterdeskApi.setPeerTags now sends tags as array and exposes updatePeer() for PATCH; serverBackend.updateDevice routes note/user updates through Go PATCH endpoint and preserves local auth.db writes as fallback; devices.routes deletes now call cleanupDeletedPeerData.
- dbAdapter: add cleanupDeletedPeerData implementations for SQLite and Postgres to remove related auth.db rows when a peer is deleted.

These changes fix zombie device re-registration, ensure metrics are stored & retrievable, centralize peer metadata updates through the Go API, and recover relay pairing failures with legacy clients.

Co-Authored-By: boruto79 <176351662+boruto79@users.noreply.github.com>
Co-Authored-By: БлагоЯр <3672314+blagoyar@users.noreply.github.com>
2026-03-18 22:09:48 +01:00
UNITRONIX c461a1aa13 Improve web client cursor, video and input handling
Fix several stability and UX issues in the web remote client: prevent ImageData crashes by validating and normalizing cursor bytes (skip zstd/compressed or truncated data) and wrapping updateCursor in try/catch; avoid unhandled promise rejections by adding a .catch() around renderer.updateCursor calls; reduce JMuxer-induced stutter and unnecessary seeks by increasing seek thresholds and offsets and tuning health-check intervals/playback-rate logic; send preferred FPS to the peer after login (default 30fps) and negotiate supported codecs dynamically based on WebCodecs/JMuxer availability; ensure focus management after login (blur hidden password input and focus canvas) and toggle a .streaming CSS class on the viewer container for cursor visibility. These changes improve robustness against malformed cursor payloads, reduce playback stutter, and improve input focus behavior.
2026-03-17 00:41:59 +01:00
UNITRONIX 9ff8968e3f Make API TLS opt-in via --tls-api flag
Fix automatic API HTTPS behavior by making HTTP API TLS opt-in. Add TLSApi config field, APITLSEnabled() helper and --tls-api CLI flag (implied by --force-https). Use APITLSEnabled() in api/server.go so the API stays HTTP unless explicitly requested, avoiding Node.js -> Go HTTPS handshake errors with self-signed certs. Update logging to show API scheme, and add TLS API handling across installers and scripts: betterdesk.sh and betterdesk.ps1 now only enable -tls-api and switch .env/API URLs to https for proper (non-self-signed) certs; self-signed certs keep API on http while still enabling TLS for signal/relay. Also update diagnostics to detect --tls-api/--force-https, remove stale legacy services, and add migration-tool auto-compilation and basic version validation.
2026-03-17 00:09:25 +01:00
UNITRONIX 352d85a0a2 Preserve auth/keys and harden installer services
Stop wiping credentials on update and make service setup more resilient. Changes:
- Preserve existing .api_key, admin credentials and auth.db during updates in betterdesk-docker.sh; only regenerate on fresh installs.
- Preserve SESSION_SECRET, DEFAULT_ADMIN_PASSWORD and avoid removing auth.db on updates in betterdesk.sh and betterdesk.ps1; only force-reset on fresh installs via sentinel file.
- Add safety-net re-read of .env in Linux and Windows Setup-Services to recover PostgreSQL config (prevents PG→SQLite regression).
- Remove legacy Flask betterdesk-api service cleanup (systemd/NSSM) and propagate DB_TYPE/DATABASE_URL to NSSM env.
- Detect node binary dynamically in systemd service and route stdout/stderr to journal (SyslogIdentifier set) for better logs.
- Fix Windows update/service flow (Do-Update now calls Setup-Services) and Repair-Binaries checks for betterdesk-server.exe with hbbs.exe fallback.
- Update .github/copilot-instructions.md summary to reflect these installer stability fixes.
2026-03-16 23:34:35 +01:00
UNITRONIX 3390c75547 Fix relay empty-UUID & Docker apk retries
Generate a UUID when RequestRelay/RelayResponse messages contain an empty uuid to prevent relay pairing failures (updates in signal/handler.go: handleRequestRelay, handleRequestRelayTCP, handleRelayResponseForward). Add validation in config.GetRelayServers to reject obviously invalid/too-short hosts (prevents relay entries like "a:21117"). Add retry wrappers to apk add commands in Dockerfile, Dockerfile.server, and Dockerfile.console to work around transient DNS failures during image builds. Update changelog (.github/copilot-instructions.md) with these fixes and related notes.
2026-03-16 23:00:14 +01:00
UNITRONIX 60657da980 Add Address Book API, relay env & UI fixes
Implement address book support and related fixes: add address_books table and Get/SaveAddressBook to DB interface with SQLite/Postgres migrations and upsert, add handlers for /api/ab, /api/ab/personal and /api/ab/tags (GET/POST) and normalize/limit incoming data. Signal server: generate relay UUIDs, send RelayResponse (with UUID and signed PK) and forward RequestRelay to targets to ensure hbbr pairing. Docker/compose/supervisord/entrypoint: introduce RELAY_SERVERS env, expose it in Dockerfile and supervisord, add docker-compose hint, and add entrypoint auto-detection/warnings for public IP inside containers. Web UI fixes: align settings password field names and include confirmPassword, modal input supports inputType, fix change-id request body key, add i18n strings for device actions/errors, and improve device delete route error handling. Also update changelog (.github/copilot-instructions.md) and add some API logging and validations.
2026-03-16 22:30:44 +01:00
UNITRONIX 8a7fd86424 Fix relay IP detection, logging, and build scripts
Call startIPDetectionRetry and improve public IP detection to avoid returning an unusable bare :port; prefer LAN IP and log clear warnings when no public IP is available. Add retry goroutine (60s ticker) and extend detectPublicIP with HTTPS then HTTP fallbacks and longer timeout. Throttle frequent sysinfo log messages (per-device 5min cooldown) in heartbeat handler to prevent spam. Accept numeric IDs from RustDesk by coercing host_id/host_uuid/peer_id to strings in /api/audit/conn to fix 400 errors. Add force-recompile logic to PowerShell and shell install/update scripts so binaries are rebuilt when sources are newer (and expose ForceRecompile flag). Minor docs and .gitignore updates.
2026-03-15 19:50:57 +01:00
UNITRONIX e548f207bb Auto-generate API key + runtime reload on 401
Fix Docker single-container auth gap by ensuring an API key exists and is discoverable by both the Go server and Node.js console. Changes:
- betterdesk-server/main.go: loadAPIKey() now checks the server_config DB entry and, if absent, auto-generates a 32-byte hex API key, writes it to .api_key (with logging) and continues to sync to the DB.
- docker/entrypoint.sh: generates/persists a 32-byte hex API key at container startup (uses openssl with /dev/urandom fallback) and writes API_KEY env to file if provided.
- web-nodejs/services/betterdeskApi.js: adds fs import and an Axios 401 interceptor that reloads .api_key from disk once and retries the failed request to handle race conditions where the Go server generates the key after Node cached an empty value.
- .github/copilot-instructions.md: documents the Docker API key auto-generation (Phase 16) and related fixes.
- tasks/lessons.md and tasks/todo.md: add lightweight triage notes and actions.
This resolves the issue where the Devices page returned empty results due to missing X-API-Key in the single-container Docker setup and improves resilience during first-run key generation.
2026-03-15 19:20:11 +01:00
UNITRONIX 5b4408a190 Harden API/installer security & opt-in creds
Security hardening and installer fixes across the Go API, installers and Node console.

Key changes:
- WebSocket: removed InsecureSkipVerify and added API_WS_ALLOWED_ORIGINS allowlist (parsed in config) used by the API events WS endpoint.
- Node.js console: added HOST and API_HOST envs and used apiHost in the server; docker-compose and installer templates updated accordingly.
- Admin credentials: plaintext .admin_credentials persistence is now opt-in via STORE_ADMIN_CREDENTIALS (default false); installers and reset flows no longer persist creds unless explicitly enabled.
- Installer hardening: added sql_escape_literal for safe SQL literals, PostgreSQL identifier validation, and safer CREATE/ALTER/psql invocations; API key and password updates now pass secrets via environment variables to Python/Node fallbacks to avoid unsafe shell interpolation.
- Docker compose/scripts: preserve_compose_database_config to keep DB mode during regen, escaped API key insertion into sqlite, and various compose generation formatting fixes.
- Go toolchain & checks: go.mod toolchain set to go1.26.1 and installers now reject known-vulnerable Go 1.26.0 stdlib.
- Dependency: bumped web-nodejs tar override to ^7.5.11.

These changes reduce attack surface for cross-origin WS usage, eliminate unsafe credential persistence by default, and harden installer DB operations and password reset paths.
2026-03-15 14:53:55 +01:00
UNITRONIX a85e3cb557 Add get_public_ip and relay fixes
Add a reusable get_public_ip() to betterdesk.sh and betterdesk-docker.sh (prefers IPv4) and replace inline curl-based IP detection with calls to it. Warns when a private/loopback IP is detected and adds RELAY_SERVERS env var override in both shell and PowerShell installers to allow manual public-IP configuration. Update betterdesk-server/config.GetRelayServers() to auto-append the default relay port when missing and correctly handle IPv6 addresses using net.SplitHostPort/net.JoinHostPort. Update documentation (.github/copilot-instructions.md) and last-updated note. Addresses Issue #58 and improves relay compatibility.
2026-03-15 13:49:08 +01:00