mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-08-07 01:14:14 +00:00
dc3699189d
Phase 3 of the index.ts refactor. Pulls the remote HTTP/WS proxy plumbing,
the WebSocket upgrade dispatcher, and the http/WSS construction out of the
monolith. index.ts drops roughly 620 lines.
New modules:
- proxy/websocketProxy.ts: shared httpProxy.createProxyServer singleton
(used by both the HTTP proxy middleware and the remote WS forwarder)
- proxy/remoteNodeProxy.ts: createRemoteProxyMiddleware() factory; consumes
the isProxyExemptPath helper instead of open-coding the prefix list
- server.ts: createServer(app) returns { server, wss, pilotTunnelWss }
- services/FleetUpdateTrackerService.ts: singleton wrapping the in-flight
fleet update tracker Map with create()/resolve() helpers
- helpers/consoleSession.ts: mintConsoleSession(), isConsoleSessionScope()
- websocket/upgradeHandler.ts: attachUpgrade(server, deps) dispatcher that
runs the manual cookie/JWT verify and delegates to sub-handlers
- websocket/pilotTunnel.ts: handlePilotTunnel (pilot_enroll consumption and
pilot_tunnel registration)
- websocket/notifications.ts: /ws/notifications local subscriber
- websocket/remoteForwarder.ts: remote-node WS proxy with console_session
token exchange for interactive paths
- websocket/logs.ts: /api/stacks/:name/logs supervisor stream
- websocket/hostConsole.ts: /api/system/host-console PTY, Admiral-gated
- websocket/generic.ts: /ws exec + streamStats action dispatch, owns the
terminalWs single-instance reference
- websocket/reject.ts: shared rejectUpgrade helper (replaces five copies)
Service extension:
- NotificationService: setBroadcaster(fn) replaced by subscribe(ws) that
returns an unsubscriber; broadcastToSubscribers is now internal. Subscriber
set lives on the service rather than in index.ts.
Wiring in index.ts:
- const app = createApp() already in place from Phase 2
- const { server, wss, pilotTunnelWss } = createServer(app)
- attachUpgrade(server, { wss, pilotTunnelWss })
- app.use('/api/', createRemoteProxyMiddleware())
- /api/system/console-token route now uses mintConsoleSession()
- deploy/down/update routes read the streaming target via getTerminalWs()
(return type is WebSocket | undefined so the || undefined fallback is gone)
Code review fixes: five duplicated reject helpers collapsed into
websocket/reject.ts; dropped the createTracker/resolveTracker bind
aliases in index.ts so call sites go through the service directly;
removed em dashes; replaced req.url! with req.url || '/'.
37 lines
1.4 KiB
TypeScript
37 lines
1.4 KiB
TypeScript
import jwt from 'jsonwebtoken';
|
|
import { DatabaseService } from '../services/DatabaseService';
|
|
|
|
/**
|
|
* Console session token lifetime. Short on purpose: these tokens are only
|
|
* used to bridge an already-authenticated HTTP request into a WebSocket
|
|
* upgrade, and each one is consumed by a single `wss:ws(target)` call.
|
|
*/
|
|
const CONSOLE_SESSION_TTL_SECONDS = 60;
|
|
const CONSOLE_SESSION_SCOPE = 'console_session';
|
|
|
|
export interface ConsoleSessionClaims {
|
|
scope: typeof CONSOLE_SESSION_SCOPE;
|
|
username?: string;
|
|
}
|
|
|
|
/**
|
|
* Mint a short-lived JWT that grants interactive console access on the remote
|
|
* instance without leaking the long-lived node api_token onto a
|
|
* machine-to-machine WebSocket. Throws if the JWT secret is not configured.
|
|
*/
|
|
export function mintConsoleSession(username?: string): string {
|
|
const jwtSecret = DatabaseService.getInstance().getGlobalSettings().auth_jwt_secret;
|
|
if (!jwtSecret) throw new Error('No JWT secret configured');
|
|
const payload: ConsoleSessionClaims = username
|
|
? { scope: CONSOLE_SESSION_SCOPE, username }
|
|
: { scope: CONSOLE_SESSION_SCOPE };
|
|
return jwt.sign(payload, jwtSecret, { expiresIn: CONSOLE_SESSION_TTL_SECONDS });
|
|
}
|
|
|
|
/** True when `decoded.scope` is the console_session scope. */
|
|
export function isConsoleSessionScope(scope: unknown): boolean {
|
|
return scope === CONSOLE_SESSION_SCOPE;
|
|
}
|
|
|
|
export { CONSOLE_SESSION_SCOPE };
|