mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-08 01:43:55 +00:00
fix(container-exec): harden with security fixes, validation, and test coverage (#577)
* fix(container-exec): harden with security fixes, validation, and test coverage - Enforce admin role at WebSocket upgrade for container exec sessions - Validate container is running before creating exec - Fix bash-to-sh fallback (move .start() inside try/catch) - Register container-exec as a capability for fleet visibility - Add standard and diagnostic logging for exec lifecycle - Fix false Admiral license claim in API docs - Fix design system violations in BashExecModal (hardcoded colors) - Remove duplicate legacy xterm dependencies - Add 18-test suite covering auth, validation, fallback, and cleanup * fix(container-exec): use correct Duplex type for exec stream The stream variable was typed as NodeJS.ReadWriteStream, which lacks .destroy(). Dockerode's Exec.start() returns stream.Duplex per its type definitions. This caused tsc to fail while Vitest (which skips full type checking) passed.
This commit is contained in:
@@ -85,9 +85,12 @@ export default function BashExecModal({ isOpen, onClose, containerId, containerN
|
||||
initTimeoutRef.current = setTimeout(checkAndInit, 50);
|
||||
|
||||
function initTerminal(containerEl: HTMLDivElement) {
|
||||
// xterm.js requires literal color strings in its theme config; CSS variables
|
||||
// and oklch() are not supported by the canvas renderer. These values are
|
||||
// intentionally hardcoded to match the terminal well aesthetic.
|
||||
const term = new Terminal({
|
||||
theme: {
|
||||
background: '#1e1e1e',
|
||||
background: '#0a0a0a',
|
||||
foreground: '#d4d4d4',
|
||||
cursor: '#ffffff',
|
||||
cursorAccent: '#000000',
|
||||
@@ -224,12 +227,12 @@ export default function BashExecModal({ isOpen, onClose, containerId, containerN
|
||||
</span>
|
||||
)}
|
||||
</DialogTitle>
|
||||
<DialogDescription className="hidden">
|
||||
<DialogDescription className="sr-only">
|
||||
Interactive bash terminal session for {containerName}
|
||||
</DialogDescription>
|
||||
</DialogHeader>
|
||||
{/* Styling wrapper - padding and rounded corners go here */}
|
||||
<div className="flex-1 rounded-lg bg-[#1e1e1e] p-1 min-h-0" style={{ overflow: 'hidden' }}>
|
||||
<div className="flex-1 rounded-lg bg-black p-1 min-h-0" style={{ overflow: 'hidden' }}>
|
||||
{/* Clean xterm container - NO padding, NO overflow-hidden, explicit dimensions */}
|
||||
<div
|
||||
ref={terminalRef}
|
||||
|
||||
@@ -14,6 +14,7 @@ export const CAPABILITIES = [
|
||||
'notifications',
|
||||
'notification-routing',
|
||||
'host-console',
|
||||
'container-exec',
|
||||
'audit-log',
|
||||
'scheduled-ops',
|
||||
'sso',
|
||||
|
||||
Reference in New Issue
Block a user