0ed275835d
Refresh/logout and token robustness - drop the post-rotation refresh_tokens row delete in auth_refresh so logout blacklists the current (rotated) refresh token; remove the dead _clear_refresh_token_after_rotation helper and clear_active_refresh_token - reject non-object JWT payloads in _extract_unverified_sub so crafted Authorization headers return 401 instead of crashing with 500 SQLite user store - make builtin-admin seeding idempotent: on a concurrent first start the losing seeder re-checks, finds the winner, and returns instead of raising IntegrityError - per-thread sqlite connections + busy_timeout so Flask worker threads don't hit cross-thread ProgrammingError / SQLITE_BUSY - add LogsDirectory + /var/log/vacuum-wall to ReadWritePaths in both systemd units so the fallback admin password actually lands on disk Frontend - skip apiFetch 401-recovery for public auth endpoints so a failed login no longer logs out a valid session - add /passkeys to the nav (passkey registration was unreachable); remove the dead checkWebAuthnCapable export - drop the CSP-blocked inline WS-URL script and the __WS_URL_PLACEHOLDER__ plumbing; the WS URL is derived from location Daemon / WS - parse Sec-WebSocket-Protocol manually (web.Request.get_subprotocols does not exist in aiohttp 3.13); X-Auth-Token is a custom-nginx fallback only — docstring and security docs corrected Install / system - bootstrap_auth.py is now idempotent: preserves existing auth config and syncs the admin password on re-runs (new reset_password helper) - WebUI server block renders auth_basic off (the UI is JWT-protected) - install.sh chown/chmod skips .git to avoid git dubious-ownership breakage - tolerate unreadable /etc/wireguard during system import Contracts / docs - create_user returns 409 on duplicate username per docs/api.md - correct docs/api.md response shapes, docs/security.md blacklist cleanup wording + one-refresh-per-user caveat, stale WS-URL references, and the .htpasswd description Tests: +7 regression tests (rotation/logout revocation, crafted-token 401, concurrent seeding); placeholder-substitution tests replaced with serve-as-is SPA root tests.
63 lines
4.5 KiB
JavaScript
63 lines
4.5 KiB
JavaScript
/**
|
|
* Hoover — index.js
|
|
*
|
|
* Barrel export of all public Hoover APIs.
|
|
*/
|
|
|
|
/* ── Reactivity ──────────────────────────────────────────────── */
|
|
export { reactive, requestUpdate } from './reactivity.js';
|
|
|
|
/* ── VDOM ────────────────────────────────────────────────────── */
|
|
export { h } from './vdom.js';
|
|
|
|
/* ── HTM ──────────────────────────────────────────────────────── */
|
|
export { html } from './html.js';
|
|
|
|
/* ── Render ──────────────────────────────────────────────────── */
|
|
export { render } from './render.js';
|
|
|
|
/* ── Component ───────────────────────────────────────────────── */
|
|
export { definePage, hComp } from './component.js';
|
|
|
|
/* ── Router ──────────────────────────────────────────────────── */
|
|
export { createRouter, Link } from './router.js';
|
|
|
|
/* ── WebSocket ───────────────────────────────────────────────── */
|
|
export { connect, onMessage, disconnect } from './websocket.js';
|
|
|
|
/* ── API & Toast ─────────────────────────────────────────────── */
|
|
export { apiFetch, toast, dismissToast, apiSubmit, checkAbort, poll, refactorLoad, formAction }
|
|
from './api.js';
|
|
|
|
/* ── UI Components: Auth ──────────────────────────────────────── */
|
|
export { logout, doLogin, webauthnSupported,
|
|
startRegistration, startAuthentication } from './components/auth.js';
|
|
|
|
/* ── Auth model ───────────────────────────────────────────────── */
|
|
export { createAuthModel, getAuthToken, isAuthenticated, refreshAuth, getAuthData }
|
|
from './auth_model.js';
|
|
|
|
/* ── Model ───────────────────────────────────────────────────── */
|
|
export { modelRegister, getModel, modelFetch, collectLoadingModels } from './model.js';
|
|
|
|
/* ── Helpers ─────────────────────────────────────────────────── */
|
|
export { esc, att_esc, enc, $val, parseZones, fmtBytes, csvToArr, downloadBlob } from './helpers.js';
|
|
|
|
/* ── UI Components: Layout ───────────────────────────────────── */
|
|
export { PageHeader, renderGuard, renderGuardMulti, Tabs, SectionTitle, ActionGroup, DataTableSection } from './components/layout.js';
|
|
|
|
/* ── UI Components: Data ─────────────────────────────────────── */
|
|
export { Badge, StatusDot, Empty, Card, ConfirmDelete, Table, ActionButton, certStatusBadge, serviceStatusBadge, StatCard, StatusText, ServiceStatus, ActionCell, MonoText, ZoneSelect } from './components/data.js';
|
|
|
|
/* ── UI Components: Modal ────────────────────────────────────── */
|
|
export { openModal, closeModal, closeAllModals, modalVNodes, refreshModals, formModal, MultiSelectModal, QuickModal, isModalProcessing, setModalProcessing } from './components/modal.js';
|
|
|
|
/* ── UI Components: Apply ────────────────────────────────────── */
|
|
export { ApplyConfirm } from './components/applyconfirm.js';
|
|
|
|
/* ── UI Components: Toast ────────────────────────────────────── */
|
|
export { ToastContainer } from './components/toast.js';
|
|
|
|
/* ── UI Components: QR Code ──────────────────────────────────── */
|
|
export { qrSVG, QRCodeVNode, LogoUpload } from './components/qr.js';
|