mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-09-02 21:58:06 +00:00
fix(ws): fix remote node console by delegating console session tokens
When the gateway proxied a WebSocket upgrade for a remote node's interactive terminal (host console or container exec), it injected the long-lived api_token (scope: 'node_proxy') as the Bearer token. The remote's WS upgrade handler correctly blocked this token via its isProxyToken guard (added in a prior security hardening commit), causing a 403 → socket destroy → "connection error, session ended" on the client. Fix: introduce a POST /api/system/console-token endpoint that issues a short-lived JWT (scope: 'console_session', 60 s TTL). Before forwarding an interactive WS upgrade to a remote node, the gateway calls this endpoint using the api_token, then substitutes the returned console_session token as the Bearer header for the WS upgrade. The remote's isProxyToken guard (scope === 'node_proxy') continues to block the long-lived api_token from spawning shells directly while allowing gateway-delegated console sessions through. Non-interactive WS paths (stack logs) continue to use the api_token unchanged.
This commit is contained in:
@@ -5,6 +5,7 @@ The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/),
|
||||
and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
|
||||
|
||||
## [Unreleased]
|
||||
- **Fixed:** Remote node host console and container exec WebSocket connections now succeed — the gateway exchanges the long-lived `node_proxy` api_token for a short-lived `console_session` JWT (60 s TTL) via a new `POST /api/system/console-token` endpoint before forwarding the WS upgrade to the remote. Previously the remote's `isProxyToken` guard correctly blocked `node_proxy` tokens from interactive terminals, which also blocked legitimate user-initiated console sessions routed through the gateway.
|
||||
- **Fixed:** `StackAlertSheet` now fetches notification agent status from the active node on open and displays a contextual banner: green checkmark with active channel names when agents are enabled, amber warning with a link to Settings → Notifications when none are configured, and a blue info callout on remote nodes explaining that alerts are evaluated and dispatched by that remote Sencho instance.
|
||||
- **Fixed:** `SettingsModal` Notifications tab is no longer hidden when a remote node is active — users can now configure Discord/Slack/Webhook channels directly on any remote node. The section header shows the remote node name and a "Remote" badge with a tooltip explaining that channels are saved on the remote instance.
|
||||
- **Fixed:** `StackAlertSheet` form error handling now surfaces the actual server error message (`err.error`) instead of a generic "Failed to add alert rule." string; console error logging added for all failure paths to aid debugging.
|
||||
|
||||
Reference in New Issue
Block a user