mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 11:49:16 +00:00
dd54a2e483
* feat: graduate Host Console to Community admins Make Host Console available to Community and Admiral admins (system:console), add host-console-community for mixed fleets, and keep opaque API tokens off the host shell. * docs: document Host Console deep links Cover root and stack-scoped Console URLs, correct the phone treatment note, and pin parse/build round-trips in senchoRoute tests. * fix: bind Host Console socket to the resolved node Treat unresolved activeNode as loading, target the WebSocket with an explicit nodeId, and wait for stack deep-link hydration so the shell cannot open on the wrong node or compose root. Add regression coverage for node/stack retargeting and fail-closed directory resolution. * fix: harden Host Console node binding, audit acting_as, and console_session tokens Reject unknown or malformed nodeIds before spawning a PTY. Record hub operators in audit_log.acting_as for remote console_session bridges. Path-scope and one-time-consume console_session JWTs so Host Console mints cannot open container exec or be replayed. * test: expect acting_as in audit CSV export header Align the CSV export assertion with the P0-2B acting_as column added to audit log exports.
53 lines
1.6 KiB
TypeScript
53 lines
1.6 KiB
TypeScript
/** Must stay in sync with backend/src/services/CapabilityRegistry.ts */
|
|
export const CAPABILITIES = [
|
|
'stacks',
|
|
'containers',
|
|
'resources',
|
|
'templates',
|
|
'global-logs',
|
|
'system-stats',
|
|
'fleet',
|
|
'auto-updates',
|
|
'labels',
|
|
'webhooks',
|
|
'network-topology',
|
|
'notifications',
|
|
'notification-routing',
|
|
'notification-suppression',
|
|
'notification-suppression-schedule',
|
|
'host-console',
|
|
'host-console-community',
|
|
'container-exec',
|
|
'audit-log',
|
|
'scheduled-ops',
|
|
'sso',
|
|
'api-tokens',
|
|
'users',
|
|
'registries',
|
|
'self-update',
|
|
'vulnerability-scanning',
|
|
'compose-doctor',
|
|
'update-guard',
|
|
'compose-networking',
|
|
'env-inventory',
|
|
'container-label-inventory',
|
|
'project-env-files',
|
|
'compose-storage',
|
|
'cross-node-rbac',
|
|
'stack-down-remove-volumes',
|
|
'guided-external-network-preflight',
|
|
'service-scoped-update',
|
|
] as const;
|
|
|
|
export type Capability = (typeof CAPABILITIES)[number];
|
|
|
|
/** Legacy Host Console advertisement (Admiral hubs still accept this on remotes). */
|
|
export const HOST_CONSOLE_CAPABILITY = 'host-console' as const satisfies Capability;
|
|
|
|
/** Host Console works without a paid license on this node. */
|
|
export const HOST_CONSOLE_COMMUNITY_CAPABILITY = 'host-console-community' as const satisfies Capability;
|
|
|
|
export const STACK_DOWN_REMOVE_VOLUMES_CAPABILITY = 'stack-down-remove-volumes' as const satisfies Capability;
|
|
export const GUIDED_EXTERNAL_NETWORK_PREFLIGHT_CAPABILITY = 'guided-external-network-preflight' as const satisfies Capability;
|
|
export const SERVICE_SCOPED_UPDATE_CAPABILITY = 'service-scoped-update' as const satisfies Capability;
|