Anso
|
718c1eb1ea
|
fix(host-console): harden with security fixes, validation, and test coverage (#580)
Security:
- Enforce RBAC (system:console permission) on WebSocket upgrade
- Validate token_version for user sessions on WS connections
- Expand env var sanitization to cover additional secret patterns
(PRIVATE, AUTH, PASSPHRASE, ENCRYPT, SIGNING) and connection
strings (REDIS_URL, MONGO_URI, AMQP_URL, DSN)
Reliability:
- Add session tracking with max 5 concurrent console sessions
- Add WebSocket heartbeat (30s ping, 60s pong timeout) to detect
and clean up dead connections and orphaned PTY processes
- Differentiate PTY spawn error messages (shell not found,
permission denied, generic failure)
- Guard against duplicate cleanup when both WS close and PTY exit
fire
Observability:
- Add structured logging with [HostConsole] prefix for session
lifecycle (open, close, duration, user, pid)
- Add diagnostic logging behind developer_mode for terminal resize
events and message parse errors
Frontend:
- Replace hardcoded hex colors with oklch CSS custom properties
(--terminal-bg, --terminal-fg, --terminal-cursor, etc.)
- Apply design system material tokens (shadow-card-bevel, recessed
well shadow, card border hierarchy, strokeWidth 1.5)
Tests:
- Add 20 tests covering env sanitization patterns (10 keyword
categories + safe vars + case insensitivity), session tracking,
and console-token RBAC (admin, viewer, deployer, API tokens)
Docs:
- Document admin role requirement and session limits
- Add troubleshooting section (session limits, shell not found,
proxy timeouts, missing console tab)
- Update security section with expanded env var coverage
|
2026-04-14 10:06:59 -04:00 |
|