mirror of
https://github.com/UNITRONIX/BetterDesk.git
synced 2026-09-10 09:35:39 +00:00
0f161181f1
Privilege separation across all installers so the long-running services no longer run with full administrative rights: betterdesk.sh: installer keeps root but systemd units now run as a dedicated unprivileged 'betterdesk' system account by default (auto-created via ensure_service_user). Added full systemd hardening for the Go server (NoNewPrivileges, ProtectSystem=strict, ProtectHome, PrivateTmp, ReadWritePaths) and light hardening for the Node.js console. chown migrates existing root-owned data to the service account on update. Opt-out via --run-as-root / BETTERDESK_RUN_AS_ROOT=1; custom account via BETTERDESK_SERVICE_USER. Minimal mode covered too. betterdesk.ps1: NSSM services now run under their per-service low-privilege virtual accounts (NT SERVICE\<service>) instead of LocalSystem, with scoped icacls grants on the install/data dirs (Set-ServiceLeastPrivilege helper). Applied to the Go server, Node.js console and minimal-mode service. Opt-out via -RunAsRoot / BETTERDESK_RUN_AS_ROOT=1. Docker: verified already privilege-separated (supervisord drops both programs to user=betterdesk; multi-container images drop via su-exec). Also bundles in-progress changes to the Go server API, Node.js console services and Docker compose/Dockerfiles. This commit was made possible thanks to Insolve.
161 lines
4.9 KiB
Markdown
161 lines
4.9 KiB
Markdown
# BetterDesk Console v2.0 (Node.js)
|
|
|
|
Modern web management console for RustDesk/BetterDesk server.
|
|
|
|
## Features
|
|
|
|
- 🎨 **Modern UI** - Dark theme, responsive design, Google Material Icons
|
|
- 🌍 **Multilingual** - English and Polish support, easy to add more
|
|
- 🔐 **Secure** - Session-based authentication, bcrypt password hashing, rate limiting
|
|
- 📱 **Devices** - View, search, filter, ban/unban, change ID, bulk delete
|
|
- 🔑 **Keys** - View public key, download file, QR code for mobile
|
|
- ⚙️ **Generator** - Generate client configuration strings
|
|
- 📊 **Dashboard** - Server status, device statistics
|
|
|
|
## Requirements
|
|
|
|
- **Node.js** 18.x or 20.x
|
|
- **npm** 9.x or later
|
|
- **SQLite3** (for better-sqlite3)
|
|
|
|
## Installation
|
|
|
|
### Development
|
|
|
|
```bash
|
|
cd web-nodejs
|
|
npm install
|
|
npm run dev
|
|
```
|
|
|
|
### Production
|
|
|
|
```bash
|
|
cd web-nodejs
|
|
npm install --production
|
|
npm start
|
|
```
|
|
|
|
### Docker
|
|
|
|
```bash
|
|
docker build -f Dockerfile.console.node -t betterdesk-console .
|
|
docker run -d -p 5000:5000 \
|
|
-v /opt/rustdesk:/opt/rustdesk \
|
|
-e SESSION_SECRET=your-secret-here \
|
|
betterdesk-console
|
|
```
|
|
|
|
## Environment Variables
|
|
|
|
| Variable | Default | Description |
|
|
|----------|---------|-------------|
|
|
| `PORT` | `5000` | HTTP server port |
|
|
| `NODE_ENV` | `development` | Environment (`development` / `production`) |
|
|
| `DB_PATH` | `/opt/rustdesk/db_v2.sqlite3` | Path to SQLite database |
|
|
| `KEYS_PATH` | `/opt/rustdesk` | Path to key files directory |
|
|
| `SESSION_SECRET` | auto-generated | Session cookie secret |
|
|
| `BETTERDESK_API_URL` | `http://127.0.0.1:21121` | BetterDesk Go server API endpoint |
|
|
| `DEFAULT_LANG` | `en` | Default language code |
|
|
|
|
## Project Structure
|
|
|
|
```
|
|
web-nodejs/
|
|
├── config/
|
|
│ └── config.js # Environment configuration
|
|
├── lang/
|
|
│ ├── en.json # English translations
|
|
│ └── pl.json # Polish translations
|
|
├── middleware/
|
|
│ ├── auth.js # Authentication middleware
|
|
│ ├── i18n.js # Language detection
|
|
│ ├── rateLimiter.js # Rate limiting
|
|
│ └── security.js # Security headers
|
|
├── public/
|
|
│ ├── css/ # Stylesheets
|
|
│ ├── js/ # Client-side JavaScript
|
|
│ └── favicon.svg # App icon
|
|
├── routes/
|
|
│ ├── auth.routes.js # Login/logout endpoints
|
|
│ ├── dashboard.routes.js
|
|
│ ├── devices.routes.js
|
|
│ ├── generator.routes.js
|
|
│ ├── i18n.routes.js
|
|
│ ├── index.js # Route mounting
|
|
│ ├── keys.routes.js
|
|
│ └── settings.routes.js
|
|
├── services/
|
|
│ ├── authService.js # Password hashing
|
|
│ ├── database.js # SQLite operations
|
|
│ ├── betterdeskApi.js # BetterDesk Go server REST API client
|
|
│ ├── i18nService.js # Translation manager
|
|
│ └── keyService.js # Key file operations
|
|
├── views/
|
|
│ ├── errors/ # Error pages
|
|
│ ├── layouts/ # Base templates
|
|
│ ├── partials/ # Reusable components
|
|
│ └── *.ejs # Page templates
|
|
├── package.json
|
|
└── server.js # Application entry point
|
|
```
|
|
|
|
## API Endpoints
|
|
|
|
### Authentication
|
|
|
|
| Method | Endpoint | Description |
|
|
|--------|----------|-------------|
|
|
| POST | `/api/auth/login` | Login with username/password |
|
|
| POST | `/api/auth/logout` | Logout current session |
|
|
| GET | `/api/auth/verify` | Verify current session |
|
|
| POST | `/api/auth/password` | Change password |
|
|
|
|
### Devices
|
|
|
|
| Method | Endpoint | Description |
|
|
|--------|----------|-------------|
|
|
| GET | `/api/devices` | List all devices |
|
|
| GET | `/api/devices/:id` | Get device details |
|
|
| DELETE | `/api/devices/:id` | Delete device |
|
|
| POST | `/api/devices/:id/ban` | Ban device |
|
|
| POST | `/api/devices/:id/unban` | Unban device |
|
|
| POST | `/api/devices/:id/change-id` | Change device ID |
|
|
| POST | `/api/devices/bulk-delete` | Delete multiple devices |
|
|
|
|
### Keys
|
|
|
|
| Method | Endpoint | Description |
|
|
|--------|----------|-------------|
|
|
| GET | `/api/keys/public` | Get public key |
|
|
| GET | `/api/keys/qr` | Get public key as QR code |
|
|
| GET | `/api/keys/download` | Download key file |
|
|
|
|
### Other
|
|
|
|
| Method | Endpoint | Description |
|
|
|--------|----------|-------------|
|
|
| GET | `/api/stats` | Device statistics |
|
|
| GET | `/api/server/status` | Server status |
|
|
| POST | `/api/sync-status` | Sync online status from HBBS |
|
|
| GET | `/api/settings/server-info` | Server information |
|
|
| GET | `/api/settings/audit-log` | Audit log entries |
|
|
|
|
## Default Credentials
|
|
|
|
- **Username:** `admin`
|
|
- **Password:** `admin`
|
|
|
|
⚠️ **Change the default password immediately after installation!**
|
|
|
|
## Adding Languages
|
|
|
|
1. Copy `lang/en.json` to `lang/xx.json` (where `xx` is language code)
|
|
2. Translate all values (keep keys unchanged)
|
|
3. Update `meta.lang`, `meta.name`, `meta.native_name`
|
|
4. Restart the application
|
|
|
|
## License
|
|
|
|
Apache-2.0 License - see LICENSE file for details.
|