mirror of
https://github.com/fosrl/pangolin.git
synced 2026-09-02 09:19:08 +02:00
Compare commits
90 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 2f013335f9 | |||
| b4f6ae74d7 | |||
| f1711ee0b0 | |||
| 780d767a65 | |||
| d6d923e972 | |||
| 41139f2fd0 | |||
| ebcdeab414 | |||
| 2cc7d03ace | |||
| c36cf698c1 | |||
| 34671c6b13 | |||
| 8dfc95347f | |||
| 22db0319c2 | |||
| 39722d30af | |||
| 8aef14cf9f | |||
| 0dece5fef1 | |||
| e7f38c089f | |||
| dd0a5a359a | |||
| 1650ece0c3 | |||
| 7f94d99455 | |||
| 1f9e99219d | |||
| bc56a2bed0 | |||
| 49dcc590ce | |||
| da3e3ff33f | |||
| 69d539f107 | |||
| 872e0f9ae1 | |||
| 5b3713a72f | |||
| f02be1fdbf | |||
| 0bf04cf0cd | |||
| 7cda28d685 | |||
| 60bc74c4df | |||
| 48ab6c501f | |||
| 7a95e543d8 | |||
| b87b7c7e80 | |||
| a47a68d8e1 | |||
| ed0d6fb6b9 | |||
| a02d16fd58 | |||
| 331fee24d4 | |||
| 5bdb12dafe | |||
| e57826d6e0 | |||
| 3d4e143c1f | |||
| 10a25c184d | |||
| 906099d1e1 | |||
| 9a5824900d | |||
| f3474dac98 | |||
| 72d2c79793 | |||
| 23764feb4f | |||
| d2809fbfd1 | |||
| d00b9478a2 | |||
| 4ddf36ebcc | |||
| 7319bf84f7 | |||
| 9ec9908ed7 | |||
| 28b32fe6f7 | |||
| adfb6003d9 | |||
| 6a5ecab013 | |||
| 2c197fab9f | |||
| 65e4fe91b9 | |||
| fd0a0818c1 | |||
| 929acc5b1c | |||
| 71348f45b2 | |||
| 21eb4d2876 | |||
| 52c078a489 | |||
| 18270381c1 | |||
| 195f67c6eb | |||
| 8e938a2723 | |||
| 197f8f7ba5 | |||
| 10b528642d | |||
| 60d6fff085 | |||
| c664b3da91 | |||
| 492282e758 | |||
| 47f4aefc25 | |||
| 7c0ff9ede7 | |||
| 44e81ea979 | |||
| 56dc10330a | |||
| eb8ad6a181 | |||
| 4edd2e4d32 | |||
| 813c3abe54 | |||
| 668a04bcd2 | |||
| 048e4fc73c | |||
| 923371e5b4 | |||
| 81430ba3d3 | |||
| e4aaadc9f9 | |||
| d04740fede | |||
| 4677a0d501 | |||
| b4463f0e1a | |||
| b7c0669c38 | |||
| 152d2fb1d6 | |||
| d374b4f66e | |||
| cb3f0b49a8 | |||
| 192542629f | |||
| 84d5a4b86c |
@@ -77,7 +77,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
- name: Log in to Docker Hub
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: docker.io
|
registry: docker.io
|
||||||
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
||||||
@@ -149,7 +149,7 @@ jobs:
|
|||||||
fi
|
fi
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
- name: Log in to Docker Hub
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: docker.io
|
registry: docker.io
|
||||||
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
||||||
@@ -204,7 +204,7 @@ jobs:
|
|||||||
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1
|
||||||
|
|
||||||
- name: Log in to Docker Hub
|
- name: Log in to Docker Hub
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: docker.io
|
registry: docker.io
|
||||||
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
username: ${{ secrets.DOCKER_HUB_USERNAME }}
|
||||||
@@ -407,7 +407,7 @@ jobs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
|
|
||||||
- name: Login to GitHub Container Registry (for cosign)
|
- name: Login to GitHub Container Registry (for cosign)
|
||||||
uses: docker/login-action@abd2ef45e78c5afb21d64d4ca52ee8550d9572c7 # v4.5.1
|
uses: docker/login-action@dbcb813823bdd20940b903addbd779551569679f # v4.6.0
|
||||||
with:
|
with:
|
||||||
registry: ghcr.io
|
registry: ghcr.io
|
||||||
username: ${{ github.actor }}
|
username: ${{ github.actor }}
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ jobs:
|
|||||||
stale:
|
stale:
|
||||||
runs-on: ubuntu-latest
|
runs-on: ubuntu-latest
|
||||||
steps:
|
steps:
|
||||||
- uses: actions/stale@1e223db275d687790206a7acac4d1a11bd6fe629 # v10.4.0
|
- uses: actions/stale@4391f3da665fdf50b6810c1a66712fb9ba21aa93 # v11.0.0
|
||||||
with:
|
with:
|
||||||
days-before-stale: 14
|
days-before-stale: 14
|
||||||
days-before-close: 14
|
days-before-close: 14
|
||||||
|
|||||||
@@ -99,6 +99,19 @@ Access private resources like SSH servers, databases, RDP, and entire network ra
|
|||||||
|
|
||||||
<img src="public/screenshots/private-resources.png" alt="Private resources" width="100%" />
|
<img src="public/screenshots/private-resources.png" alt="Private resources" width="100%" />
|
||||||
|
|
||||||
|
### Identity-aware AI gateway
|
||||||
|
|
||||||
|
Put an identity-aware proxy in front of public cloud (OpenAI, Anthropic, Gemini, etc.) and self-hosted model servers (Ollama, vLLM, Mistral, etc.) so coding agents and AI clients call a single Pangolin URL. Publish it as a public resource with personal API keys, or keep it private on a client tunnel where the connected client is the credential for keyless access. Budgets, session history, and usage analytics sit in front of every call.
|
||||||
|
|
||||||
|
* Access self-hosted models (vLLM, Ollama, etc) alongside cloud models (OpenAI, Anthropic, etc) in one place
|
||||||
|
* Keyless access by authenticating users with the Pangolin desktop client
|
||||||
|
* Or, provide users with personal API keys
|
||||||
|
* Control costs and token usage by setting budgets
|
||||||
|
* Audit with detailed session history and analytics
|
||||||
|
* Integrate AI clients and coding agents (Claude Code, Codex, OpenCode, etc)
|
||||||
|
|
||||||
|
<img src="public/screenshots/expanded-session-logs.png" alt="AI Session Logs" width="100%" />
|
||||||
|
|
||||||
### Give users and roles access to resources
|
### Give users and roles access to resources
|
||||||
|
|
||||||
Use Pangolin's built-in users or bring your own identity provider and set up role-based access control (RBAC). Grant users access to specific resources, not entire networks. Unlike traditional VPNs that expose full network access, Pangolin's zero-trust model ensures users can only reach the applications, services, and routes you explicitly define.
|
Use Pangolin's built-in users or bring your own identity provider and set up role-based access control (RBAC). Grant users access to specific resources, not entire networks. Unlike traditional VPNs that expose full network access, Pangolin's zero-trust model ensures users can only reach the applications, services, and routes you explicitly define.
|
||||||
|
|||||||
@@ -16,7 +16,7 @@ experimental:
|
|||||||
version: "{{.BadgerVersion}}"
|
version: "{{.BadgerVersion}}"
|
||||||
crowdsec: # CrowdSec plugin configuration added
|
crowdsec: # CrowdSec plugin configuration added
|
||||||
moduleName: "github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
moduleName: "github.com/maxlerebourg/crowdsec-bouncer-traefik-plugin"
|
||||||
version: "v1.4.4"
|
version: "v1.7.1"
|
||||||
|
|
||||||
log:
|
log:
|
||||||
level: "INFO"
|
level: "INFO"
|
||||||
|
|||||||
+8
-1
@@ -1176,6 +1176,10 @@
|
|||||||
"idpJmespathAboutDescriptionLink": "Learn more about JMESPath",
|
"idpJmespathAboutDescriptionLink": "Learn more about JMESPath",
|
||||||
"idpJmespathLabel": "Identifier Path",
|
"idpJmespathLabel": "Identifier Path",
|
||||||
"idpJmespathLabelDescription": "The path to the user identifier in the ID token",
|
"idpJmespathLabelDescription": "The path to the user identifier in the ID token",
|
||||||
|
"idpIdentifierChangeTitle": "Identifier Path Change Warning",
|
||||||
|
"idpIdentifierChangeDescription": "You are about to change the identifier path. This will affect how existing users are mapped. Users who previously signed in through this identity provider may no longer be recognized as the same users.",
|
||||||
|
"idpIdentifierChangeConfirmMessage": "I confirm",
|
||||||
|
"idpIdentifierChangeWarningText": "This will affect how existing users are mapped",
|
||||||
"idpJmespathEmailPathOptional": "Email Path (Optional)",
|
"idpJmespathEmailPathOptional": "Email Path (Optional)",
|
||||||
"idpJmespathEmailPathOptionalDescription": "The path to the user's email in the ID token",
|
"idpJmespathEmailPathOptionalDescription": "The path to the user's email in the ID token",
|
||||||
"idpJmespathNamePathOptional": "Name Path (Optional)",
|
"idpJmespathNamePathOptional": "Name Path (Optional)",
|
||||||
@@ -1573,6 +1577,8 @@
|
|||||||
"search": "Search…",
|
"search": "Search…",
|
||||||
"searchPlaceholder": "Search...",
|
"searchPlaceholder": "Search...",
|
||||||
"emptySearchOptions": "No options found",
|
"emptySearchOptions": "No options found",
|
||||||
|
"ipFilterSearchPlaceholder": "Enter an IP address…",
|
||||||
|
"ipFilterEmptyMessage": "Enter an IP address to filter by",
|
||||||
"create": "Create",
|
"create": "Create",
|
||||||
"orgs": "Organizations",
|
"orgs": "Organizations",
|
||||||
"loginError": "An unexpected error occurred. Please try again.",
|
"loginError": "An unexpected error occurred. Please try again.",
|
||||||
@@ -2596,6 +2602,7 @@
|
|||||||
"createDomainType": "Type:",
|
"createDomainType": "Type:",
|
||||||
"createDomainName": "Name:",
|
"createDomainName": "Name:",
|
||||||
"createDomainValue": "Value:",
|
"createDomainValue": "Value:",
|
||||||
|
"multiSelectFilterCount": "{count} selected",
|
||||||
"createDomainCnameRecords": "CNAME Records",
|
"createDomainCnameRecords": "CNAME Records",
|
||||||
"createDomainARecords": "A Records",
|
"createDomainARecords": "A Records",
|
||||||
"createDomainRecordNumber": "Record {number}",
|
"createDomainRecordNumber": "Record {number}",
|
||||||
@@ -2993,7 +3000,7 @@
|
|||||||
"remoteExitNodeNetworkingSubnetsPlaceholder": "Add a CIDR range (e.g. 10.0.0.0/8)",
|
"remoteExitNodeNetworkingSubnetsPlaceholder": "Add a CIDR range (e.g. 10.0.0.0/8)",
|
||||||
"remoteExitNodeNetworkingSubnetsLoadError": "Failed to load subnets",
|
"remoteExitNodeNetworkingSubnetsLoadError": "Failed to load subnets",
|
||||||
"remoteExitNodeNetworkingLabelsTitle": "Preference Labels",
|
"remoteExitNodeNetworkingLabelsTitle": "Preference Labels",
|
||||||
"remoteExitNodeNetworkingLabelsDescription": "Sites with these labels will be enforced to connect through this remote exit node.",
|
"remoteExitNodeNetworkingLabelsDescription": "Sites with these labels will prefer to connect through this remote exit node.",
|
||||||
"remoteExitNodeNetworkingLabelsButtonText": "Select labels...",
|
"remoteExitNodeNetworkingLabelsButtonText": "Select labels...",
|
||||||
"remoteExitNodeNetworkingLabelsSearchPlaceholder": "Search labels...",
|
"remoteExitNodeNetworkingLabelsSearchPlaceholder": "Search labels...",
|
||||||
"remoteExitNodeNetworkingLabelsLoadError": "Failed to load labels",
|
"remoteExitNodeNetworkingLabelsLoadError": "Failed to load labels",
|
||||||
|
|||||||
+2213
-788
File diff suppressed because it is too large
Load Diff
Generated
+394
-307
File diff suppressed because it is too large
Load Diff
+5
-5
@@ -94,12 +94,12 @@
|
|||||||
"input-otp": "1.4.2",
|
"input-otp": "1.4.2",
|
||||||
"ioredis": "5.11.0",
|
"ioredis": "5.11.0",
|
||||||
"jmespath": "0.16.0",
|
"jmespath": "0.16.0",
|
||||||
"js-yaml": "4.3.0",
|
"js-yaml": "4.3.1",
|
||||||
"jsonwebtoken": "9.0.3",
|
"jsonwebtoken": "9.0.3",
|
||||||
"lucide-react": "1.17.0",
|
"lucide-react": "1.17.0",
|
||||||
"maxmind": "5.0.6",
|
"maxmind": "5.0.6",
|
||||||
"moment": "2.30.1",
|
"moment": "2.30.1",
|
||||||
"next": "16.2.11",
|
"next": "16.3.1",
|
||||||
"next-intl": "4.13.0",
|
"next-intl": "4.13.0",
|
||||||
"next-themes": "0.4.6",
|
"next-themes": "0.4.6",
|
||||||
"nextjs-toploader": "3.9.17",
|
"nextjs-toploader": "3.9.17",
|
||||||
@@ -139,7 +139,7 @@
|
|||||||
"devDependencies": {
|
"devDependencies": {
|
||||||
"@dotenvx/dotenvx": "1.69.1",
|
"@dotenvx/dotenvx": "1.69.1",
|
||||||
"@esbuild-plugins/tsconfig-paths": "0.1.2",
|
"@esbuild-plugins/tsconfig-paths": "0.1.2",
|
||||||
"@react-email/ui": "^6.5.0",
|
"@react-email/ui": "^6.9.2",
|
||||||
"@tailwindcss/postcss": "4.3.0",
|
"@tailwindcss/postcss": "4.3.0",
|
||||||
"@tanstack/react-query-devtools": "5.100.14",
|
"@tanstack/react-query-devtools": "5.100.14",
|
||||||
"@types/better-sqlite3": "7.6.13",
|
"@types/better-sqlite3": "7.6.13",
|
||||||
@@ -170,7 +170,7 @@
|
|||||||
"esbuild-node-externals": "1.22.0",
|
"esbuild-node-externals": "1.22.0",
|
||||||
"eslint": "10.4.0",
|
"eslint": "10.4.0",
|
||||||
"eslint-config-next": "16.2.6",
|
"eslint-config-next": "16.2.6",
|
||||||
"postcss": "8.5.15",
|
"postcss": "8.5.23",
|
||||||
"prettier": "3.8.3",
|
"prettier": "3.8.3",
|
||||||
"react-email": "6.5.0",
|
"react-email": "6.5.0",
|
||||||
"tailwindcss": "4.3.0",
|
"tailwindcss": "4.3.0",
|
||||||
@@ -182,6 +182,6 @@
|
|||||||
"overrides": {
|
"overrides": {
|
||||||
"esbuild": "0.28.0",
|
"esbuild": "0.28.0",
|
||||||
"dompurify": "3.4.0",
|
"dompurify": "3.4.0",
|
||||||
"postcss": "8.5.15"
|
"postcss": "8.5.23"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
Binary file not shown.
|
After Width: | Height: | Size: 790 KiB |
@@ -262,7 +262,9 @@ export const resourceAiModels = pgTable(
|
|||||||
(t) => [primaryKey({ columns: [t.resourceId, t.modelId] })]
|
(t) => [primaryKey({ columns: [t.resourceId, t.modelId] })]
|
||||||
);
|
);
|
||||||
|
|
||||||
export const labels = pgTable("labels", {
|
export const labels = pgTable(
|
||||||
|
"labels",
|
||||||
|
{
|
||||||
labelId: serial("labelId").primaryKey(),
|
labelId: serial("labelId").primaryKey(),
|
||||||
name: varchar("name").notNull(),
|
name: varchar("name").notNull(),
|
||||||
color: varchar("color").notNull(),
|
color: varchar("color").notNull(),
|
||||||
@@ -271,7 +273,9 @@ export const labels = pgTable("labels", {
|
|||||||
onDelete: "cascade"
|
onDelete: "cascade"
|
||||||
})
|
})
|
||||||
.notNull()
|
.notNull()
|
||||||
});
|
},
|
||||||
|
(t) => [index("idx_labels_orgid").on(t.orgId)]
|
||||||
|
);
|
||||||
|
|
||||||
export const launcherViews = pgTable("launcherViews", {
|
export const launcherViews = pgTable("launcherViews", {
|
||||||
viewId: serial("viewId").primaryKey(),
|
viewId: serial("viewId").primaryKey(),
|
||||||
@@ -693,7 +697,9 @@ export const twoFactorBackupCodes = pgTable("twoFactorBackupCodes", {
|
|||||||
codeHash: varchar("codeHash").notNull()
|
codeHash: varchar("codeHash").notNull()
|
||||||
});
|
});
|
||||||
|
|
||||||
export const sessions = pgTable("session", {
|
export const sessions = pgTable(
|
||||||
|
"session",
|
||||||
|
{
|
||||||
sessionId: varchar("id").primaryKey(),
|
sessionId: varchar("id").primaryKey(),
|
||||||
userId: varchar("userId")
|
userId: varchar("userId")
|
||||||
.notNull()
|
.notNull()
|
||||||
@@ -701,7 +707,9 @@ export const sessions = pgTable("session", {
|
|||||||
expiresAt: bigint("expiresAt", { mode: "number" }).notNull(),
|
expiresAt: bigint("expiresAt", { mode: "number" }).notNull(),
|
||||||
issuedAt: bigint("issuedAt", { mode: "number" }),
|
issuedAt: bigint("issuedAt", { mode: "number" }),
|
||||||
deviceAuthUsed: boolean("deviceAuthUsed").notNull().default(false)
|
deviceAuthUsed: boolean("deviceAuthUsed").notNull().default(false)
|
||||||
});
|
},
|
||||||
|
(t) => [index("idx_sessions_userid").on(t.userId)]
|
||||||
|
);
|
||||||
|
|
||||||
export const newtSessions = pgTable("newtSession", {
|
export const newtSessions = pgTable("newtSession", {
|
||||||
sessionId: varchar("id").primaryKey(),
|
sessionId: varchar("id").primaryKey(),
|
||||||
@@ -711,7 +719,9 @@ export const newtSessions = pgTable("newtSession", {
|
|||||||
expiresAt: bigint("expiresAt", { mode: "number" }).notNull()
|
expiresAt: bigint("expiresAt", { mode: "number" }).notNull()
|
||||||
});
|
});
|
||||||
|
|
||||||
export const userOrgs = pgTable("userOrgs", {
|
export const userOrgs = pgTable(
|
||||||
|
"userOrgs",
|
||||||
|
{
|
||||||
userId: varchar("userId")
|
userId: varchar("userId")
|
||||||
.notNull()
|
.notNull()
|
||||||
.references(() => users.userId, { onDelete: "cascade" }),
|
.references(() => users.userId, { onDelete: "cascade" }),
|
||||||
@@ -723,7 +733,12 @@ export const userOrgs = pgTable("userOrgs", {
|
|||||||
isOwner: boolean("isOwner").notNull().default(false),
|
isOwner: boolean("isOwner").notNull().default(false),
|
||||||
autoProvisioned: boolean("autoProvisioned").default(false),
|
autoProvisioned: boolean("autoProvisioned").default(false),
|
||||||
pamUsername: varchar("pamUsername") // cleaned username for ssh and such
|
pamUsername: varchar("pamUsername") // cleaned username for ssh and such
|
||||||
});
|
},
|
||||||
|
(t) => [
|
||||||
|
index("idx_userOrgs_userid").on(t.userId),
|
||||||
|
index("idx_userOrgs_orgid").on(t.orgId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const emailVerificationCodes = pgTable("emailVerificationCodes", {
|
export const emailVerificationCodes = pgTable("emailVerificationCodes", {
|
||||||
codeId: serial("id").primaryKey(),
|
codeId: serial("id").primaryKey(),
|
||||||
@@ -751,7 +766,9 @@ export const actions = pgTable("actions", {
|
|||||||
description: varchar("description")
|
description: varchar("description")
|
||||||
});
|
});
|
||||||
|
|
||||||
export const roles = pgTable("roles", {
|
export const roles = pgTable(
|
||||||
|
"roles",
|
||||||
|
{
|
||||||
roleId: serial("roleId").primaryKey(),
|
roleId: serial("roleId").primaryKey(),
|
||||||
orgId: varchar("orgId")
|
orgId: varchar("orgId")
|
||||||
.references(() => orgs.orgId, {
|
.references(() => orgs.orgId, {
|
||||||
@@ -766,7 +783,9 @@ export const roles = pgTable("roles", {
|
|||||||
sshSudoCommands: text("sshSudoCommands").default("[]"),
|
sshSudoCommands: text("sshSudoCommands").default("[]"),
|
||||||
sshCreateHomeDir: boolean("sshCreateHomeDir").default(true),
|
sshCreateHomeDir: boolean("sshCreateHomeDir").default(true),
|
||||||
sshUnixGroups: text("sshUnixGroups").default("[]")
|
sshUnixGroups: text("sshUnixGroups").default("[]")
|
||||||
});
|
},
|
||||||
|
(t) => [index("idx_roles_orgid").on(t.orgId)]
|
||||||
|
);
|
||||||
|
|
||||||
export const userOrgRoles = pgTable(
|
export const userOrgRoles = pgTable(
|
||||||
"userOrgRoles",
|
"userOrgRoles",
|
||||||
@@ -1409,7 +1428,10 @@ export const olms = pgTable(
|
|||||||
}),
|
}),
|
||||||
archived: boolean("archived").notNull().default(false)
|
archived: boolean("archived").notNull().default(false)
|
||||||
},
|
},
|
||||||
(t) => [index("idx_olms_clientid").on(t.clientId)]
|
(t) => [
|
||||||
|
index("idx_olms_clientid").on(t.clientId),
|
||||||
|
index("idx_olms_userid").on(t.userId)
|
||||||
|
]
|
||||||
);
|
);
|
||||||
|
|
||||||
export const currentFingerprint = pgTable("currentFingerprint", {
|
export const currentFingerprint = pgTable("currentFingerprint", {
|
||||||
@@ -1984,7 +2006,7 @@ export const aiSessionLog = pgTable(
|
|||||||
// were cut short at AI_SESSION_LOG_MAX_BODY_CHARS before storage.
|
// were cut short at AI_SESSION_LOG_MAX_BODY_CHARS before storage.
|
||||||
truncated: boolean("truncated").notNull().default(false),
|
truncated: boolean("truncated").notNull().default(false),
|
||||||
statusCode: integer("statusCode"),
|
statusCode: integer("statusCode"),
|
||||||
createdAt: bigint("createdAt", { mode: "number" }).notNull() // epoch ms
|
createdAt: bigint("createdAt", { mode: "number" }).notNull() // epoch seconds
|
||||||
},
|
},
|
||||||
(t) => [
|
(t) => [
|
||||||
index("idx_ai_session_log_org_created").on(t.orgId, t.createdAt),
|
index("idx_ai_session_log_org_created").on(t.orgId, t.createdAt),
|
||||||
|
|||||||
@@ -99,7 +99,9 @@ export const orgDomains = sqliteTable("orgDomains", {
|
|||||||
.references(() => domains.domainId, { onDelete: "cascade" })
|
.references(() => domains.domainId, { onDelete: "cascade" })
|
||||||
});
|
});
|
||||||
|
|
||||||
export const sites = sqliteTable("sites", {
|
export const sites = sqliteTable(
|
||||||
|
"sites",
|
||||||
|
{
|
||||||
siteId: integer("siteId").primaryKey({ autoIncrement: true }),
|
siteId: integer("siteId").primaryKey({ autoIncrement: true }),
|
||||||
orgId: text("orgId")
|
orgId: text("orgId")
|
||||||
.references(() => orgs.orgId, {
|
.references(() => orgs.orgId, {
|
||||||
@@ -141,10 +143,18 @@ export const sites = sqliteTable("sites", {
|
|||||||
})
|
})
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(false),
|
.default(false),
|
||||||
status: text("status").$type<"pending" | "approved">().default("approved")
|
status: text("status")
|
||||||
});
|
.$type<"pending" | "approved">()
|
||||||
|
.default("approved")
|
||||||
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_sites_orgId").on(table.orgId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const resources = sqliteTable("resources", {
|
export const resources = sqliteTable(
|
||||||
|
"resources",
|
||||||
|
{
|
||||||
resourceId: integer("resourceId").primaryKey({ autoIncrement: true }),
|
resourceId: integer("resourceId").primaryKey({ autoIncrement: true }),
|
||||||
resourcePolicyId: integer("resourcePolicyId").references(
|
resourcePolicyId: integer("resourcePolicyId").references(
|
||||||
() => resourcePolicies.resourcePolicyId,
|
() => resourcePolicies.resourcePolicyId,
|
||||||
@@ -222,8 +232,14 @@ export const resources = sqliteTable("resources", {
|
|||||||
.$type<"site" | "remote" | "native">()
|
.$type<"site" | "remote" | "native">()
|
||||||
.default("site"),
|
.default("site"),
|
||||||
authDaemonPort: integer("authDaemonPort").default(22123),
|
authDaemonPort: integer("authDaemonPort").default(22123),
|
||||||
status: text("status").$type<"pending" | "approved">().default("approved")
|
status: text("status")
|
||||||
});
|
.$type<"pending" | "approved">()
|
||||||
|
.default("approved")
|
||||||
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_resources_orgId").on(table.orgId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const resourceAiProviders = sqliteTable(
|
export const resourceAiProviders = sqliteTable(
|
||||||
"resourceAiProviders",
|
"resourceAiProviders",
|
||||||
@@ -260,7 +276,9 @@ export const resourceAiModels = sqliteTable(
|
|||||||
(t) => [primaryKey({ columns: [t.resourceId, t.modelId] })]
|
(t) => [primaryKey({ columns: [t.resourceId, t.modelId] })]
|
||||||
);
|
);
|
||||||
|
|
||||||
export const labels = sqliteTable("labels", {
|
export const labels = sqliteTable(
|
||||||
|
"labels",
|
||||||
|
{
|
||||||
labelId: integer("labelId").primaryKey({ autoIncrement: true }),
|
labelId: integer("labelId").primaryKey({ autoIncrement: true }),
|
||||||
name: text("name").notNull(),
|
name: text("name").notNull(),
|
||||||
color: text("color").notNull(),
|
color: text("color").notNull(),
|
||||||
@@ -269,7 +287,11 @@ export const labels = sqliteTable("labels", {
|
|||||||
onDelete: "cascade"
|
onDelete: "cascade"
|
||||||
})
|
})
|
||||||
.notNull()
|
.notNull()
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_labels_orgId").on(table.orgId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const launcherViews = sqliteTable("launcherViews", {
|
export const launcherViews = sqliteTable("launcherViews", {
|
||||||
viewId: integer("viewId").primaryKey({ autoIncrement: true }),
|
viewId: integer("viewId").primaryKey({ autoIncrement: true }),
|
||||||
@@ -366,14 +388,18 @@ export const clientLabels = sqliteTable(
|
|||||||
(t) => [unique("client_label_uniq").on(t.clientId, t.labelId)]
|
(t) => [unique("client_label_uniq").on(t.clientId, t.labelId)]
|
||||||
);
|
);
|
||||||
|
|
||||||
export const targets = sqliteTable("targets", {
|
export const targets = sqliteTable(
|
||||||
|
"targets",
|
||||||
|
{
|
||||||
targetId: integer("targetId").primaryKey({ autoIncrement: true }),
|
targetId: integer("targetId").primaryKey({ autoIncrement: true }),
|
||||||
resourceId: integer("resourceId").references(() => resources.resourceId, {
|
resourceId: integer("resourceId").references(
|
||||||
onDelete: "cascade"
|
() => resources.resourceId,
|
||||||
}),
|
{ onDelete: "cascade" }
|
||||||
providerId: integer("providerId").references(() => aiProviders.providerId, {
|
),
|
||||||
onDelete: "cascade"
|
providerId: integer("providerId").references(
|
||||||
}),
|
() => aiProviders.providerId,
|
||||||
|
{ onDelete: "cascade" }
|
||||||
|
),
|
||||||
siteId: integer("siteId")
|
siteId: integer("siteId")
|
||||||
.references(() => sites.siteId, {
|
.references(() => sites.siteId, {
|
||||||
onDelete: "cascade"
|
onDelete: "cascade"
|
||||||
@@ -394,7 +420,12 @@ export const targets = sqliteTable("targets", {
|
|||||||
.notNull()
|
.notNull()
|
||||||
.default("http"),
|
.default("http"),
|
||||||
authToken: text("authToken")
|
authToken: text("authToken")
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_targets_resourceId").on(table.resourceId),
|
||||||
|
index("idx_targets_siteId").on(table.siteId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const targetHealthCheck = sqliteTable("targetHealthCheck", {
|
export const targetHealthCheck = sqliteTable("targetHealthCheck", {
|
||||||
targetHealthCheckId: integer("targetHealthCheckId").primaryKey({
|
targetHealthCheckId: integer("targetHealthCheckId").primaryKey({
|
||||||
@@ -663,7 +694,9 @@ export const setupTokens = sqliteTable("setupTokens", {
|
|||||||
dateUsed: text("dateUsed")
|
dateUsed: text("dateUsed")
|
||||||
});
|
});
|
||||||
|
|
||||||
export const newts = sqliteTable("newt", {
|
export const newts = sqliteTable(
|
||||||
|
"newt",
|
||||||
|
{
|
||||||
newtId: text("id").primaryKey(),
|
newtId: text("id").primaryKey(),
|
||||||
secretHash: text("secretHash").notNull(),
|
secretHash: text("secretHash").notNull(),
|
||||||
dateCreated: text("dateCreated").notNull(),
|
dateCreated: text("dateCreated").notNull(),
|
||||||
@@ -671,9 +704,15 @@ export const newts = sqliteTable("newt", {
|
|||||||
siteId: integer("siteId").references(() => sites.siteId, {
|
siteId: integer("siteId").references(() => sites.siteId, {
|
||||||
onDelete: "cascade"
|
onDelete: "cascade"
|
||||||
})
|
})
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_newts_siteId").on(table.siteId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const clients = sqliteTable("clients", {
|
export const clients = sqliteTable(
|
||||||
|
"clients",
|
||||||
|
{
|
||||||
clientId: integer("clientId").primaryKey({ autoIncrement: true }),
|
clientId: integer("clientId").primaryKey({ autoIncrement: true }),
|
||||||
orgId: text("orgId")
|
orgId: text("orgId")
|
||||||
.references(() => orgs.orgId, {
|
.references(() => orgs.orgId, {
|
||||||
@@ -706,7 +745,12 @@ export const clients = sqliteTable("clients", {
|
|||||||
approvalState: text("approvalState").$type<
|
approvalState: text("approvalState").$type<
|
||||||
"pending" | "approved" | "denied"
|
"pending" | "approved" | "denied"
|
||||||
>()
|
>()
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_clients_orgId").on(table.orgId),
|
||||||
|
index("idx_clients_userId").on(table.userId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const clientSitesAssociationsCache = sqliteTable(
|
export const clientSitesAssociationsCache = sqliteTable(
|
||||||
"clientSitesAssociationsCache",
|
"clientSitesAssociationsCache",
|
||||||
@@ -734,7 +778,9 @@ export const clientSiteResourcesAssociationsCache = sqliteTable(
|
|||||||
}
|
}
|
||||||
);
|
);
|
||||||
|
|
||||||
export const olms = sqliteTable("olms", {
|
export const olms = sqliteTable(
|
||||||
|
"olms",
|
||||||
|
{
|
||||||
olmId: text("id").primaryKey(),
|
olmId: text("id").primaryKey(),
|
||||||
secretHash: text("secretHash").notNull(),
|
secretHash: text("secretHash").notNull(),
|
||||||
dateCreated: text("dateCreated").notNull(),
|
dateCreated: text("dateCreated").notNull(),
|
||||||
@@ -750,7 +796,11 @@ export const olms = sqliteTable("olms", {
|
|||||||
onDelete: "cascade"
|
onDelete: "cascade"
|
||||||
}),
|
}),
|
||||||
archived: integer("archived", { mode: "boolean" }).notNull().default(false)
|
archived: integer("archived", { mode: "boolean" }).notNull().default(false)
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_olms_userId").on(table.userId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const currentFingerprint = sqliteTable("currentFingerprint", {
|
export const currentFingerprint = sqliteTable("currentFingerprint", {
|
||||||
fingerprintId: integer("id").primaryKey({ autoIncrement: true }),
|
fingerprintId: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
@@ -912,7 +962,9 @@ export const twoFactorBackupCodes = sqliteTable("twoFactorBackupCodes", {
|
|||||||
codeHash: text("codeHash").notNull()
|
codeHash: text("codeHash").notNull()
|
||||||
});
|
});
|
||||||
|
|
||||||
export const sessions = sqliteTable("session", {
|
export const sessions = sqliteTable(
|
||||||
|
"session",
|
||||||
|
{
|
||||||
sessionId: text("id").primaryKey(),
|
sessionId: text("id").primaryKey(),
|
||||||
userId: text("userId")
|
userId: text("userId")
|
||||||
.notNull()
|
.notNull()
|
||||||
@@ -922,7 +974,11 @@ export const sessions = sqliteTable("session", {
|
|||||||
deviceAuthUsed: integer("deviceAuthUsed", { mode: "boolean" })
|
deviceAuthUsed: integer("deviceAuthUsed", { mode: "boolean" })
|
||||||
.notNull()
|
.notNull()
|
||||||
.default(false)
|
.default(false)
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_sessions_userId").on(table.userId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const newtSessions = sqliteTable("newtSession", {
|
export const newtSessions = sqliteTable("newtSession", {
|
||||||
sessionId: text("id").primaryKey(),
|
sessionId: text("id").primaryKey(),
|
||||||
@@ -940,7 +996,9 @@ export const olmSessions = sqliteTable("clientSession", {
|
|||||||
expiresAt: integer("expiresAt").notNull()
|
expiresAt: integer("expiresAt").notNull()
|
||||||
});
|
});
|
||||||
|
|
||||||
export const userOrgs = sqliteTable("userOrgs", {
|
export const userOrgs = sqliteTable(
|
||||||
|
"userOrgs",
|
||||||
|
{
|
||||||
userId: text("userId")
|
userId: text("userId")
|
||||||
.notNull()
|
.notNull()
|
||||||
.references(() => users.userId, { onDelete: "cascade" }),
|
.references(() => users.userId, { onDelete: "cascade" }),
|
||||||
@@ -954,7 +1012,12 @@ export const userOrgs = sqliteTable("userOrgs", {
|
|||||||
mode: "boolean"
|
mode: "boolean"
|
||||||
}).default(false),
|
}).default(false),
|
||||||
pamUsername: text("pamUsername") // cleaned username for ssh and such
|
pamUsername: text("pamUsername") // cleaned username for ssh and such
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_userOrgs_userId").on(table.userId),
|
||||||
|
index("idx_userOrgs_orgId").on(table.orgId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const emailVerificationCodes = sqliteTable("emailVerificationCodes", {
|
export const emailVerificationCodes = sqliteTable("emailVerificationCodes", {
|
||||||
codeId: integer("id").primaryKey({ autoIncrement: true }),
|
codeId: integer("id").primaryKey({ autoIncrement: true }),
|
||||||
@@ -982,7 +1045,9 @@ export const actions = sqliteTable("actions", {
|
|||||||
description: text("description")
|
description: text("description")
|
||||||
});
|
});
|
||||||
|
|
||||||
export const roles = sqliteTable("roles", {
|
export const roles = sqliteTable(
|
||||||
|
"roles",
|
||||||
|
{
|
||||||
roleId: integer("roleId").primaryKey({ autoIncrement: true }),
|
roleId: integer("roleId").primaryKey({ autoIncrement: true }),
|
||||||
orgId: text("orgId")
|
orgId: text("orgId")
|
||||||
.references(() => orgs.orgId, {
|
.references(() => orgs.orgId, {
|
||||||
@@ -1001,7 +1066,11 @@ export const roles = sqliteTable("roles", {
|
|||||||
true
|
true
|
||||||
),
|
),
|
||||||
sshUnixGroups: text("sshUnixGroups").default("[]")
|
sshUnixGroups: text("sshUnixGroups").default("[]")
|
||||||
});
|
},
|
||||||
|
(table) => [
|
||||||
|
index("idx_roles_orgId").on(table.orgId)
|
||||||
|
]
|
||||||
|
);
|
||||||
|
|
||||||
export const userOrgRoles = sqliteTable(
|
export const userOrgRoles = sqliteTable(
|
||||||
"userOrgRoles",
|
"userOrgRoles",
|
||||||
@@ -1980,7 +2049,7 @@ export const aiSessionLog = sqliteTable(
|
|||||||
.notNull()
|
.notNull()
|
||||||
.default(false),
|
.default(false),
|
||||||
statusCode: integer("statusCode"),
|
statusCode: integer("statusCode"),
|
||||||
createdAt: integer("createdAt").notNull() // epoch ms
|
createdAt: integer("createdAt").notNull() // epoch seconds
|
||||||
},
|
},
|
||||||
(t) => [
|
(t) => [
|
||||||
index("idx_ai_session_log_org_created").on(t.orgId, t.createdAt),
|
index("idx_ai_session_log_org_created").on(t.orgId, t.createdAt),
|
||||||
|
|||||||
@@ -580,6 +580,8 @@ export async function recordUsage(input: UsageRecordInput): Promise<void> {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const timestamp = Math.floor(Date.now() / 1000);
|
||||||
|
|
||||||
usageRecordBuffer.push({
|
usageRecordBuffer.push({
|
||||||
orgId: input.orgId,
|
orgId: input.orgId,
|
||||||
providerId: input.providerId,
|
providerId: input.providerId,
|
||||||
@@ -597,7 +599,7 @@ export async function recordUsage(input: UsageRecordInput): Promise<void> {
|
|||||||
totalTokens,
|
totalTokens,
|
||||||
costUsd: input.costUsd,
|
costUsd: input.costUsd,
|
||||||
estimated: usage.estimated,
|
estimated: usage.estimated,
|
||||||
createdAt: input.createdAt ?? Date.now()
|
createdAt: input.createdAt ?? timestamp
|
||||||
});
|
});
|
||||||
|
|
||||||
// Flush immediately if buffer is full, otherwise schedule a flush
|
// Flush immediately if buffer is full, otherwise schedule a flush
|
||||||
|
|||||||
@@ -1,5 +1,6 @@
|
|||||||
import {
|
import {
|
||||||
db,
|
db,
|
||||||
|
primaryDb,
|
||||||
newts,
|
newts,
|
||||||
blueprints,
|
blueprints,
|
||||||
Blueprint,
|
Blueprint,
|
||||||
@@ -80,11 +81,22 @@ export async function applyBlueprint({
|
|||||||
trx,
|
trx,
|
||||||
siteId
|
siteId
|
||||||
);
|
);
|
||||||
|
});
|
||||||
|
|
||||||
|
// Push updates to newts/clients only after the transaction has
|
||||||
|
// committed. Doing this while the transaction is still open can
|
||||||
|
// race with the writes (e.g. newts requesting config before the
|
||||||
|
// new targets/resources are actually visible), leaving them out
|
||||||
|
// of sync until manually toggled.
|
||||||
|
|
||||||
// We need to update the targets on the newts from the successfully updated information
|
// We need to update the targets on the newts from the successfully updated information
|
||||||
for (const result of publicResourcesResults) {
|
for (const result of publicResourcesResults) {
|
||||||
for (const target of result.targetsToUpdate) {
|
for (const target of result.targetsToUpdate) {
|
||||||
const [site] = await trx
|
// read from the primary: this determines whether/how we push
|
||||||
|
// the just-created target to the newt, so a lagging replica
|
||||||
|
// returning stale or missing data here would silently skip
|
||||||
|
// the push
|
||||||
|
const [site] = await primaryDb
|
||||||
.select()
|
.select()
|
||||||
.from(sites)
|
.from(sites)
|
||||||
.innerJoin(newts, eq(sites.siteId, newts.siteId))
|
.innerJoin(newts, eq(sites.siteId, newts.siteId))
|
||||||
@@ -166,7 +178,6 @@ export async function applyBlueprint({
|
|||||||
logger.debug(
|
logger.debug(
|
||||||
`Successfully updated private resources for org ${orgId}: ${JSON.stringify(privateResourcesResults)}`
|
`Successfully updated private resources for org ${orgId}: ${JSON.stringify(privateResourcesResults)}`
|
||||||
);
|
);
|
||||||
});
|
|
||||||
|
|
||||||
blueprintSucceeded = true;
|
blueprintSucceeded = true;
|
||||||
blueprintMessage = "Blueprint applied successfully";
|
blueprintMessage = "Blueprint applied successfully";
|
||||||
|
|||||||
@@ -0,0 +1,38 @@
|
|||||||
|
import { and, asc, eq, or } from "drizzle-orm";
|
||||||
|
import { Transaction, User, userOrgs, users } from "@server/db";
|
||||||
|
|
||||||
|
export async function findOrgUserByIdentifier(
|
||||||
|
trx: Transaction,
|
||||||
|
orgId: string,
|
||||||
|
identifier: string
|
||||||
|
): Promise<User | null> {
|
||||||
|
const [match] = await trx
|
||||||
|
.select()
|
||||||
|
.from(users)
|
||||||
|
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
||||||
|
.where(
|
||||||
|
and(
|
||||||
|
or(eq(users.username, identifier), eq(users.email, identifier)),
|
||||||
|
eq(userOrgs.orgId, orgId)
|
||||||
|
)
|
||||||
|
)
|
||||||
|
.orderBy(asc(users.dateCreated), asc(users.userId))
|
||||||
|
.limit(1);
|
||||||
|
|
||||||
|
return match?.user ?? null;
|
||||||
|
}
|
||||||
|
|
||||||
|
export async function resolveOrgUserIds(
|
||||||
|
trx: Transaction,
|
||||||
|
orgId: string,
|
||||||
|
identifiers: string[]
|
||||||
|
): Promise<string[]> {
|
||||||
|
const userIds = new Set<string>();
|
||||||
|
for (const identifier of identifiers) {
|
||||||
|
const user = await findOrgUserByIdentifier(trx, orgId, identifier);
|
||||||
|
if (user) {
|
||||||
|
userIds.add(user.userId);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return [...userIds];
|
||||||
|
}
|
||||||
@@ -11,15 +11,14 @@ import {
|
|||||||
siteNetworks,
|
siteNetworks,
|
||||||
siteResources,
|
siteResources,
|
||||||
Transaction,
|
Transaction,
|
||||||
userOrgs,
|
|
||||||
users,
|
|
||||||
userSiteResources,
|
userSiteResources,
|
||||||
networks
|
networks
|
||||||
} from "@server/db";
|
} from "@server/db";
|
||||||
import { sites } from "@server/db";
|
import { sites } from "@server/db";
|
||||||
import { eq, and, ne, inArray, or, isNotNull } from "drizzle-orm";
|
import { eq, and, ne, inArray, isNotNull } from "drizzle-orm";
|
||||||
import { Config } from "./types";
|
import { Config } from "./types";
|
||||||
import { getOrCreateLabelIds, syncSiteResourceLabels } from "./labels";
|
import { getOrCreateLabelIds, syncSiteResourceLabels } from "./labels";
|
||||||
|
import { resolveOrgUserIds } from "./findOrgUser";
|
||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { defaultRoleAllowedActions } from "@server/routers/role/createRole";
|
import { defaultRoleAllowedActions } from "@server/routers/role/createRole";
|
||||||
import { getNextAvailableAliasAddress } from "../ip";
|
import { getNextAvailableAliasAddress } from "../ip";
|
||||||
@@ -389,29 +388,23 @@ export async function updatePrivateResources(
|
|||||||
.where(eq(userSiteResources.siteResourceId, siteResourceId));
|
.where(eq(userSiteResources.siteResourceId, siteResourceId));
|
||||||
|
|
||||||
if (resourceData.users.length > 0) {
|
if (resourceData.users.length > 0) {
|
||||||
// get userIds from username
|
const userIds = await resolveOrgUserIds(
|
||||||
const usersToUpdate = await trx
|
trx,
|
||||||
.select()
|
orgId,
|
||||||
.from(users)
|
resourceData.users
|
||||||
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
or(
|
|
||||||
inArray(users.username, resourceData.users),
|
|
||||||
inArray(users.email, resourceData.users)
|
|
||||||
),
|
|
||||||
eq(userOrgs.orgId, orgId)
|
|
||||||
)
|
|
||||||
);
|
);
|
||||||
|
|
||||||
const userIds = usersToUpdate.map((user) => user.user.userId);
|
if (userIds.length > 0) {
|
||||||
|
|
||||||
await trx
|
await trx
|
||||||
.insert(userSiteResources)
|
.insert(userSiteResources)
|
||||||
.values(
|
.values(
|
||||||
userIds.map((userId) => ({ userId, siteResourceId }))
|
userIds.map((userId) => ({
|
||||||
|
userId,
|
||||||
|
siteResourceId
|
||||||
|
}))
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// Get all admin role IDs for this org to exclude from deletion
|
// Get all admin role IDs for this org to exclude from deletion
|
||||||
const adminRoles = await trx
|
const adminRoles = await trx
|
||||||
@@ -721,29 +714,23 @@ export async function updatePrivateResources(
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (resourceData.users.length > 0) {
|
if (resourceData.users.length > 0) {
|
||||||
// get userIds from username
|
const userIds = await resolveOrgUserIds(
|
||||||
const usersToUpdate = await trx
|
trx,
|
||||||
.select()
|
orgId,
|
||||||
.from(users)
|
resourceData.users
|
||||||
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
or(
|
|
||||||
inArray(users.username, resourceData.users),
|
|
||||||
inArray(users.email, resourceData.users)
|
|
||||||
),
|
|
||||||
eq(userOrgs.orgId, orgId)
|
|
||||||
)
|
|
||||||
);
|
);
|
||||||
|
|
||||||
const userIds = usersToUpdate.map((user) => user.user.userId);
|
if (userIds.length > 0) {
|
||||||
|
|
||||||
await trx
|
await trx
|
||||||
.insert(userSiteResources)
|
.insert(userSiteResources)
|
||||||
.values(
|
.values(
|
||||||
userIds.map((userId) => ({ userId, siteResourceId }))
|
userIds.map((userId) => ({
|
||||||
|
userId,
|
||||||
|
siteResourceId
|
||||||
|
}))
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
if (resourceData.machines.length > 0) {
|
if (resourceData.machines.length > 0) {
|
||||||
// get clientIds from niceIds
|
// get clientIds from niceIds
|
||||||
|
|||||||
@@ -46,11 +46,12 @@ import { encrypt } from "@server/lib/crypto";
|
|||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { defaultRoleAllowedActions } from "@server/routers/role/createRole";
|
import { defaultRoleAllowedActions } from "@server/routers/role/createRole";
|
||||||
import { pickPort } from "@server/routers/target/helpers";
|
import { pickPort } from "@server/routers/target/helpers";
|
||||||
import { and, asc, eq, isNotNull, ne, or } from "drizzle-orm";
|
import { and, asc, eq, isNotNull, ne } from "drizzle-orm";
|
||||||
import { tierMatrix } from "../billing/tierMatrix";
|
import { tierMatrix } from "../billing/tierMatrix";
|
||||||
import { isValidCIDR, isValidIP, isValidUrlGlobPattern } from "../validators";
|
import { isValidCIDR, isValidIP, isValidUrlGlobPattern } from "../validators";
|
||||||
import { Config, isTargetsOnlyResource, TargetData } from "./types";
|
import { Config, isTargetsOnlyResource, TargetData } from "./types";
|
||||||
import { getOrCreateLabelIds, syncResourceLabels } from "./labels";
|
import { getOrCreateLabelIds, syncResourceLabels } from "./labels";
|
||||||
|
import { findOrgUserByIdentifier } from "./findOrgUser";
|
||||||
import { LimitId } from "../billing";
|
import { LimitId } from "../billing";
|
||||||
import { usageService } from "../billing/usageService";
|
import { usageService } from "../billing/usageService";
|
||||||
import { syncInferenceAiConfig } from "./aiProviders";
|
import { syncInferenceAiConfig } from "./aiProviders";
|
||||||
@@ -1563,29 +1564,19 @@ async function syncUserResources(
|
|||||||
.where(eq(userResources.resourceId, resourceId));
|
.where(eq(userResources.resourceId, resourceId));
|
||||||
|
|
||||||
for (const username of ssoUsers) {
|
for (const username of ssoUsers) {
|
||||||
const [user] = await trx
|
const user = await findOrgUserByIdentifier(trx, orgId, username);
|
||||||
.select()
|
|
||||||
.from(users)
|
|
||||||
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
or(eq(users.username, username), eq(users.email, username)),
|
|
||||||
eq(userOrgs.orgId, orgId)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
.limit(1);
|
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
throw new Error(`User not found: ${username} in org ${orgId}`);
|
throw new Error(`User not found: ${username} in org ${orgId}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
const existingUserResource = existingUserResources.find(
|
const existingUserResource = existingUserResources.find(
|
||||||
(rr) => rr.userId === user.user.userId
|
(rr) => rr.userId === user.userId
|
||||||
);
|
);
|
||||||
|
|
||||||
if (!existingUserResource) {
|
if (!existingUserResource) {
|
||||||
await trx.insert(userResources).values({
|
await trx.insert(userResources).values({
|
||||||
userId: user.user.userId,
|
userId: user.userId,
|
||||||
resourceId: resourceId
|
resourceId: resourceId
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -1955,29 +1946,19 @@ async function syncUserPolicies(
|
|||||||
.where(eq(userPolicies.resourcePolicyId, policyId));
|
.where(eq(userPolicies.resourcePolicyId, policyId));
|
||||||
|
|
||||||
for (const username of ssoUsers) {
|
for (const username of ssoUsers) {
|
||||||
const [user] = await trx
|
const user = await findOrgUserByIdentifier(trx, orgId, username);
|
||||||
.select()
|
|
||||||
.from(users)
|
|
||||||
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
or(eq(users.username, username), eq(users.email, username)),
|
|
||||||
eq(userOrgs.orgId, orgId)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
.limit(1);
|
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
throw new Error(`User not found: ${username} in org ${orgId}`);
|
throw new Error(`User not found: ${username} in org ${orgId}`);
|
||||||
}
|
}
|
||||||
|
|
||||||
const existingUserPolicy = existingUserPoliciesList.find(
|
const existingUserPolicy = existingUserPoliciesList.find(
|
||||||
(up) => up.userId === user.user.userId
|
(up) => up.userId === user.userId
|
||||||
);
|
);
|
||||||
|
|
||||||
if (!existingUserPolicy) {
|
if (!existingUserPolicy) {
|
||||||
await trx.insert(userPolicies).values({
|
await trx.insert(userPolicies).values({
|
||||||
userId: user.user.userId,
|
userId: user.userId,
|
||||||
resourcePolicyId: policyId
|
resourcePolicyId: policyId
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -13,7 +13,7 @@ import {
|
|||||||
userPolicies,
|
userPolicies,
|
||||||
users
|
users
|
||||||
} from "@server/db";
|
} from "@server/db";
|
||||||
import { eq, and, or } from "drizzle-orm";
|
import { eq, and } from "drizzle-orm";
|
||||||
import { Config, ResourcePolicyData } from "./types";
|
import { Config, ResourcePolicyData } from "./types";
|
||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { getUniqueResourcePolicyName } from "@server/db/names";
|
import { getUniqueResourcePolicyName } from "@server/db/names";
|
||||||
@@ -22,6 +22,7 @@ import { idpExistsForOrg } from "@server/lib/idp/idpExistsForOrg";
|
|||||||
import { isValidCIDR, isValidIP, isValidUrlGlobPattern } from "../validators";
|
import { isValidCIDR, isValidIP, isValidUrlGlobPattern } from "../validators";
|
||||||
import { isLicensedOrSubscribed } from "#dynamic/lib/isLicencedOrSubscribed";
|
import { isLicensedOrSubscribed } from "#dynamic/lib/isLicencedOrSubscribed";
|
||||||
import { tierMatrix } from "../billing/tierMatrix";
|
import { tierMatrix } from "../billing/tierMatrix";
|
||||||
|
import { findOrgUserByIdentifier } from "./findOrgUser";
|
||||||
|
|
||||||
export type ResourcePoliciesResults = {
|
export type ResourcePoliciesResults = {
|
||||||
resourcePolicyId: number;
|
resourcePolicyId: number;
|
||||||
@@ -466,17 +467,7 @@ async function syncUserPolicies(
|
|||||||
.where(eq(userPolicies.resourcePolicyId, policyId));
|
.where(eq(userPolicies.resourcePolicyId, policyId));
|
||||||
|
|
||||||
for (const username of ssoUsers) {
|
for (const username of ssoUsers) {
|
||||||
const [user] = await trx
|
const user = await findOrgUserByIdentifier(trx, orgId, username);
|
||||||
.select()
|
|
||||||
.from(users)
|
|
||||||
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
or(eq(users.username, username), eq(users.email, username)),
|
|
||||||
eq(userOrgs.orgId, orgId)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
.limit(1);
|
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
logger.warn(
|
logger.warn(
|
||||||
@@ -486,12 +477,12 @@ async function syncUserPolicies(
|
|||||||
}
|
}
|
||||||
|
|
||||||
const alreadyExists = existingUserPolicies.some(
|
const alreadyExists = existingUserPolicies.some(
|
||||||
(up) => up.userId === user.user.userId
|
(up) => up.userId === user.userId
|
||||||
);
|
);
|
||||||
|
|
||||||
if (!alreadyExists) {
|
if (!alreadyExists) {
|
||||||
await trx.insert(userPolicies).values({
|
await trx.insert(userPolicies).values({
|
||||||
userId: user.user.userId,
|
userId: user.userId,
|
||||||
resourcePolicyId: policyId
|
resourcePolicyId: policyId
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
@@ -536,17 +527,7 @@ async function addUserPolicies(
|
|||||||
trx: Transaction
|
trx: Transaction
|
||||||
) {
|
) {
|
||||||
for (const username of ssoUsers) {
|
for (const username of ssoUsers) {
|
||||||
const [user] = await trx
|
const user = await findOrgUserByIdentifier(trx, orgId, username);
|
||||||
.select()
|
|
||||||
.from(users)
|
|
||||||
.innerJoin(userOrgs, eq(users.userId, userOrgs.userId))
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
or(eq(users.username, username), eq(users.email, username)),
|
|
||||||
eq(userOrgs.orgId, orgId)
|
|
||||||
)
|
|
||||||
)
|
|
||||||
.limit(1);
|
|
||||||
|
|
||||||
if (!user) {
|
if (!user) {
|
||||||
logger.warn(
|
logger.warn(
|
||||||
@@ -556,7 +537,7 @@ async function addUserPolicies(
|
|||||||
}
|
}
|
||||||
|
|
||||||
await trx.insert(userPolicies).values({
|
await trx.insert(userPolicies).values({
|
||||||
userId: user.user.userId,
|
userId: user.userId,
|
||||||
resourcePolicyId: policyId
|
resourcePolicyId: policyId
|
||||||
});
|
});
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -101,7 +101,7 @@ export const AuthSchema = z.object({
|
|||||||
export const RuleSchema = z
|
export const RuleSchema = z
|
||||||
.object({
|
.object({
|
||||||
action: z.enum(["allow", "deny", "pass"]),
|
action: z.enum(["allow", "deny", "pass"]),
|
||||||
match: z.enum(["cidr", "path", "ip", "country", "asn", "region"]),
|
match: z.enum(["cidr", "path", "ip", "country", "country_is_not", "asn", "region"]),
|
||||||
value: z.coerce.string(),
|
value: z.coerce.string(),
|
||||||
priority: z.int().optional(),
|
priority: z.int().optional(),
|
||||||
enabled: z.boolean().optional().default(true)
|
enabled: z.boolean().optional().default(true)
|
||||||
@@ -136,7 +136,7 @@ export const RuleSchema = z
|
|||||||
)
|
)
|
||||||
.refine(
|
.refine(
|
||||||
(rule) => {
|
(rule) => {
|
||||||
if (rule.match === "country") {
|
if (rule.match === "country" || rule.match === "country_is_not") {
|
||||||
if (!hasMaxmindCountryDb) {
|
if (!hasMaxmindCountryDb) {
|
||||||
return false;
|
return false;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -31,7 +31,6 @@ export async function validateAndConstructDomain(
|
|||||||
subdomain?: string | null
|
subdomain?: string | null
|
||||||
): Promise<DomainValidationResult> {
|
): Promise<DomainValidationResult> {
|
||||||
try {
|
try {
|
||||||
// Query domain with organization access check
|
|
||||||
const [domainRes] = await db
|
const [domainRes] = await db
|
||||||
.select()
|
.select()
|
||||||
.from(domains)
|
.from(domains)
|
||||||
@@ -42,6 +41,10 @@ export async function validateAndConstructDomain(
|
|||||||
eq(orgDomains.orgId, orgId),
|
eq(orgDomains.orgId, orgId),
|
||||||
eq(orgDomains.domainId, domainId)
|
eq(orgDomains.domainId, domainId)
|
||||||
)
|
)
|
||||||
|
)
|
||||||
|
.leftJoin(
|
||||||
|
domainNamespaces,
|
||||||
|
eq(domainNamespaces.domainId, domainId)
|
||||||
);
|
);
|
||||||
|
|
||||||
// Check if domain exists
|
// Check if domain exists
|
||||||
@@ -52,8 +55,7 @@ export async function validateAndConstructDomain(
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
// Check if organization has access to domain
|
if (!domainRes.orgDomains && !domainRes.domainNamespaces) {
|
||||||
if (domainRes.orgDomains && domainRes.orgDomains.orgId !== orgId) {
|
|
||||||
return {
|
return {
|
||||||
success: false,
|
success: false,
|
||||||
error: `Organization does not have access to domain with ID ${domainId}`
|
error: `Organization does not have access to domain with ID ${domainId}`
|
||||||
@@ -84,20 +86,12 @@ export async function validateAndConstructDomain(
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Wildcard subdomains are not allowed on namespace (provided/free) domains
|
// Wildcard subdomains are not allowed on namespace (provided/free) domains
|
||||||
if (isWildcard) {
|
if (isWildcard && domainRes.domainNamespaces) {
|
||||||
const [namespaceDomain] = await db
|
|
||||||
.select()
|
|
||||||
.from(domainNamespaces)
|
|
||||||
.where(eq(domainNamespaces.domainId, domainId))
|
|
||||||
.limit(1);
|
|
||||||
|
|
||||||
if (namespaceDomain) {
|
|
||||||
return {
|
return {
|
||||||
success: false,
|
success: false,
|
||||||
error: "Wildcard subdomains are not supported for provided or free domains. Use a specific subdomain instead."
|
error: "Wildcard subdomains are not supported for provided or free domains. Use a specific subdomain instead."
|
||||||
};
|
};
|
||||||
}
|
}
|
||||||
}
|
|
||||||
|
|
||||||
if (
|
if (
|
||||||
isWildcard &&
|
isWildcard &&
|
||||||
|
|||||||
+50
-1
@@ -3,6 +3,8 @@ import config from "./config";
|
|||||||
import { getHostMeta } from "./hostMeta";
|
import { getHostMeta } from "./hostMeta";
|
||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import {
|
import {
|
||||||
|
aiProviders,
|
||||||
|
aiUsageRecords,
|
||||||
alertRules,
|
alertRules,
|
||||||
apiKeys,
|
apiKeys,
|
||||||
blueprints,
|
blueprints,
|
||||||
@@ -11,7 +13,16 @@ import {
|
|||||||
siteResources
|
siteResources
|
||||||
} from "@server/db";
|
} from "@server/db";
|
||||||
import { sites, users, orgs, resources, clients, idp } from "@server/db";
|
import { sites, users, orgs, resources, clients, idp } from "@server/db";
|
||||||
import { eq, count, notInArray, and, isNotNull, isNull } from "drizzle-orm";
|
import {
|
||||||
|
eq,
|
||||||
|
count,
|
||||||
|
countDistinct,
|
||||||
|
notInArray,
|
||||||
|
and,
|
||||||
|
isNotNull,
|
||||||
|
isNull,
|
||||||
|
gte
|
||||||
|
} from "drizzle-orm";
|
||||||
import { APP_VERSION } from "./consts";
|
import { APP_VERSION } from "./consts";
|
||||||
import crypto from "crypto";
|
import crypto from "crypto";
|
||||||
import { UserType } from "@server/types/UserTypes";
|
import { UserType } from "@server/types/UserTypes";
|
||||||
@@ -172,6 +183,25 @@ class TelemetryClient {
|
|||||||
.select({ count: count() })
|
.select({ count: count() })
|
||||||
.from(blueprints);
|
.from(blueprints);
|
||||||
|
|
||||||
|
const [aiProvidersCount] = await db
|
||||||
|
.select({ count: count() })
|
||||||
|
.from(aiProviders);
|
||||||
|
const [orgsWithAiProviders] = await db
|
||||||
|
.select({ count: countDistinct(aiProviders.orgId) })
|
||||||
|
.from(aiProviders);
|
||||||
|
|
||||||
|
const usageWindowStart =
|
||||||
|
Math.floor(Date.now() / 1000) -
|
||||||
|
this.collectionIntervalDays * 24 * 60 * 60;
|
||||||
|
const [aiUsageRecordsRecent] = await db
|
||||||
|
.select({ count: count() })
|
||||||
|
.from(aiUsageRecords)
|
||||||
|
.where(gte(aiUsageRecords.createdAt, usageWindowStart));
|
||||||
|
const [orgsWithRecentAiUsage] = await db
|
||||||
|
.select({ count: countDistinct(aiUsageRecords.orgId) })
|
||||||
|
.from(aiUsageRecords)
|
||||||
|
.where(gte(aiUsageRecords.createdAt, usageWindowStart));
|
||||||
|
|
||||||
const supporterKey = config.getSupporterData();
|
const supporterKey = config.getSupporterData();
|
||||||
|
|
||||||
const allPrivateResources = await db.select().from(siteResources);
|
const allPrivateResources = await db.select().from(siteResources);
|
||||||
@@ -182,6 +212,7 @@ class TelemetryClient {
|
|||||||
let numPrivResourceCidr = 0;
|
let numPrivResourceCidr = 0;
|
||||||
let numPrivResourceHttp = 0;
|
let numPrivResourceHttp = 0;
|
||||||
let numPrivResourceSsh = 0;
|
let numPrivResourceSsh = 0;
|
||||||
|
let numPrivResourceInference = 0;
|
||||||
for (const res of allPrivateResources) {
|
for (const res of allPrivateResources) {
|
||||||
if (res.mode === "host") {
|
if (res.mode === "host") {
|
||||||
numPrivResourceHosts += 1;
|
numPrivResourceHosts += 1;
|
||||||
@@ -191,6 +222,8 @@ class TelemetryClient {
|
|||||||
numPrivResourceHttp += 1;
|
numPrivResourceHttp += 1;
|
||||||
} else if (res.mode === "ssh") {
|
} else if (res.mode === "ssh") {
|
||||||
numPrivResourceSsh += 1;
|
numPrivResourceSsh += 1;
|
||||||
|
} else if (res.mode === "inference") {
|
||||||
|
numPrivResourceInference += 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (res.alias) {
|
if (res.alias) {
|
||||||
@@ -211,6 +244,11 @@ class TelemetryClient {
|
|||||||
numPrivateResourceCidr: numPrivResourceCidr,
|
numPrivateResourceCidr: numPrivResourceCidr,
|
||||||
numPrivateResourceHttp: numPrivResourceHttp,
|
numPrivateResourceHttp: numPrivResourceHttp,
|
||||||
numPrivateResourceSsh: numPrivResourceSsh,
|
numPrivateResourceSsh: numPrivResourceSsh,
|
||||||
|
numPrivateResourceInference: numPrivResourceInference,
|
||||||
|
numAiProviders: aiProvidersCount.count,
|
||||||
|
numOrgsWithAiProviders: orgsWithAiProviders.count,
|
||||||
|
numAiUsageRecordsRecent: aiUsageRecordsRecent.count,
|
||||||
|
numOrgsWithRecentAiUsage: orgsWithRecentAiUsage.count,
|
||||||
numAlertRules: numAlertRules.count,
|
numAlertRules: numAlertRules.count,
|
||||||
numUserDevices: userDevicesCount.count,
|
numUserDevices: userDevicesCount.count,
|
||||||
numMachineClients: machineClients.count,
|
numMachineClients: machineClients.count,
|
||||||
@@ -323,6 +361,17 @@ class TelemetryClient {
|
|||||||
num_resources_non_http: stats.resources.filter(
|
num_resources_non_http: stats.resources.filter(
|
||||||
(r) => r.mode !== "http"
|
(r) => r.mode !== "http"
|
||||||
).length,
|
).length,
|
||||||
|
num_resources_ai_gateway: stats.resources.filter(
|
||||||
|
(r) => r.mode === "inference"
|
||||||
|
).length,
|
||||||
|
num_private_resources_ai_gateway:
|
||||||
|
stats.numPrivateResourceInference,
|
||||||
|
num_ai_providers: stats.numAiProviders,
|
||||||
|
num_orgs_with_ai_providers: stats.numOrgsWithAiProviders,
|
||||||
|
num_ai_usage_records_recent:
|
||||||
|
stats.numAiUsageRecordsRecent,
|
||||||
|
num_orgs_with_recent_ai_usage:
|
||||||
|
stats.numOrgsWithRecentAiUsage,
|
||||||
num_newt_sites: stats.sites.filter((s) => s.type === "newt")
|
num_newt_sites: stats.sites.filter((s) => s.type === "newt")
|
||||||
.length,
|
.length,
|
||||||
num_local_sites: stats.sites.filter(
|
num_local_sites: stats.sites.filter(
|
||||||
|
|||||||
@@ -0,0 +1,15 @@
|
|||||||
|
import { gzipSync, gunzipSync } from "zlib";
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Gzip a string and return it as base64 so it can be stored in a TEXT column.
|
||||||
|
*/
|
||||||
|
export function compressText(value: string): string {
|
||||||
|
return gzipSync(Buffer.from(value, "utf8")).toString("base64");
|
||||||
|
}
|
||||||
|
|
||||||
|
/**
|
||||||
|
* Reverse of compressText - base64-decode and gunzip back to the original string.
|
||||||
|
*/
|
||||||
|
export function decompressText(value: string): string {
|
||||||
|
return gunzipSync(Buffer.from(value, "base64")).toString("utf8");
|
||||||
|
}
|
||||||
@@ -68,6 +68,11 @@ export async function verifyApiKeyAccessTokenAccess(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if (apiKey.isRoot) {
|
||||||
|
// Root keys can access any access token in any org
|
||||||
|
return next();
|
||||||
|
}
|
||||||
|
|
||||||
if (!resource.orgId) {
|
if (!resource.orgId) {
|
||||||
return next(
|
return next(
|
||||||
createHttpError(
|
createHttpError(
|
||||||
|
|||||||
@@ -25,6 +25,7 @@ import {
|
|||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { and, eq, gt, desc, max, sql } from "drizzle-orm";
|
import { and, eq, gt, desc, max, sql } from "drizzle-orm";
|
||||||
import { decrypt } from "@server/lib/crypto";
|
import { decrypt } from "@server/lib/crypto";
|
||||||
|
import { decompressText } from "@server/lib/textCompression";
|
||||||
import config from "@server/lib/config";
|
import config from "@server/lib/config";
|
||||||
import {
|
import {
|
||||||
LogType,
|
LogType,
|
||||||
@@ -680,8 +681,8 @@ export class LogStreamingManager {
|
|||||||
Record<string, unknown> & { id: number }
|
Record<string, unknown> & { id: number }
|
||||||
>;
|
>;
|
||||||
|
|
||||||
case "aiSession":
|
case "aiSession": {
|
||||||
return (await logsDb
|
const rows = (await logsDb
|
||||||
.select()
|
.select()
|
||||||
.from(aiSessionLog)
|
.from(aiSessionLog)
|
||||||
.where(
|
.where(
|
||||||
@@ -694,6 +695,33 @@ export class LogStreamingManager {
|
|||||||
.limit(limit)) as Array<
|
.limit(limit)) as Array<
|
||||||
Record<string, unknown> & { id: number }
|
Record<string, unknown> & { id: number }
|
||||||
>;
|
>;
|
||||||
|
|
||||||
|
const compressedFields = [
|
||||||
|
"requestBody",
|
||||||
|
"responseBody",
|
||||||
|
"normalizedRequest",
|
||||||
|
"normalizedResponse"
|
||||||
|
] as const;
|
||||||
|
|
||||||
|
for (const row of rows) {
|
||||||
|
for (const field of compressedFields) {
|
||||||
|
const value = row[field];
|
||||||
|
if (typeof value !== "string") {
|
||||||
|
continue;
|
||||||
|
}
|
||||||
|
try {
|
||||||
|
row[field] = decompressText(value);
|
||||||
|
} catch (error) {
|
||||||
|
logger.error(
|
||||||
|
`Failed to decompress AI session log field ${field}`,
|
||||||
|
{ error }
|
||||||
|
);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return rows;
|
||||||
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -149,12 +149,8 @@ LQIDAQAB
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Count used sites and users for license comparison
|
// Count used sites and users for license comparison
|
||||||
const [siteCountRes] = await db
|
const [siteCountRes] = await db.select({ value: count() }).from(sites);
|
||||||
.select({ value: count() })
|
const [userCountRes] = await db.select({ value: count() }).from(users);
|
||||||
.from(sites);
|
|
||||||
const [userCountRes] = await db
|
|
||||||
.select({ value: count() })
|
|
||||||
.from(users);
|
|
||||||
|
|
||||||
const status: LicenseStatus = {
|
const status: LicenseStatus = {
|
||||||
hostId: this.hostMeta.hostMetaId,
|
hostId: this.hostMeta.hostMetaId,
|
||||||
@@ -276,10 +272,13 @@ LQIDAQAB
|
|||||||
logger.error(
|
logger.error(
|
||||||
`Allowing failure. Will retry one more time at next run interval.`
|
`Allowing failure. Will retry one more time at next run interval.`
|
||||||
);
|
);
|
||||||
// return last known good status
|
// Fall back to last known good status if we have
|
||||||
return this.statusCache.get(
|
// one cached; otherwise return the freshly built
|
||||||
|
// status (with defaults) rather than undefined.
|
||||||
|
const lastKnownStatus = this.statusCache.get(
|
||||||
this.statusKey
|
this.statusKey
|
||||||
) as LicenseStatus;
|
) as LicenseStatus | undefined;
|
||||||
|
return lastKnownStatus ?? status;
|
||||||
} else {
|
} else {
|
||||||
// Subsequent failures: fail abruptly
|
// Subsequent failures: fail abruptly
|
||||||
throw e;
|
throw e;
|
||||||
@@ -368,10 +367,7 @@ LQIDAQAB
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Only consider quantity if defined and >= 0 (quantity = users, quantity_2 = sites)
|
// Only consider quantity if defined and >= 0 (quantity = users, quantity_2 = sites)
|
||||||
if (
|
if (cached.quantity_2 !== undefined && cached.quantity_2 >= 0) {
|
||||||
cached.quantity_2 !== undefined &&
|
|
||||||
cached.quantity_2 >= 0
|
|
||||||
) {
|
|
||||||
status.maxSites =
|
status.maxSites =
|
||||||
(status.maxSites ?? 0) + cached.quantity_2;
|
(status.maxSites ?? 0) + cached.quantity_2;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -18,6 +18,7 @@ import { and, eq, lt } from "drizzle-orm";
|
|||||||
import cache from "#private/lib/cache";
|
import cache from "#private/lib/cache";
|
||||||
import { calculateCutoffTimestamp } from "@server/lib/cleanupLogs";
|
import { calculateCutoffTimestamp } from "@server/lib/cleanupLogs";
|
||||||
import { sanitizeString } from "@server/lib/sanitize";
|
import { sanitizeString } from "@server/lib/sanitize";
|
||||||
|
import { compressText } from "@server/lib/textCompression";
|
||||||
import type { AiCapability } from "@server/lib/aiCapabilities";
|
import type { AiCapability } from "@server/lib/aiCapabilities";
|
||||||
import {
|
import {
|
||||||
normalizeAiRequest,
|
normalizeAiRequest,
|
||||||
@@ -151,17 +152,14 @@ async function getRetentionDays(orgId: string): Promise<number> {
|
|||||||
}
|
}
|
||||||
|
|
||||||
export async function cleanUpOldLogs(orgId: string, retentionDays: number) {
|
export async function cleanUpOldLogs(orgId: string, retentionDays: number) {
|
||||||
// calculateCutoffTimestamp returns a seconds-epoch cutoff (built for
|
const cutoffTimestamp = calculateCutoffTimestamp(retentionDays);
|
||||||
// requestAuditLog.timestamp), but aiSessionLog.createdAt is ms-epoch to
|
|
||||||
// match aiUsageRecords - convert before comparing.
|
|
||||||
const cutoffTimestampMs = calculateCutoffTimestamp(retentionDays) * 1000;
|
|
||||||
|
|
||||||
try {
|
try {
|
||||||
await logsDb
|
await logsDb
|
||||||
.delete(aiSessionLog)
|
.delete(aiSessionLog)
|
||||||
.where(
|
.where(
|
||||||
and(
|
and(
|
||||||
lt(aiSessionLog.createdAt, cutoffTimestampMs),
|
lt(aiSessionLog.createdAt, cutoffTimestamp),
|
||||||
eq(aiSessionLog.orgId, orgId)
|
eq(aiSessionLog.orgId, orgId)
|
||||||
)
|
)
|
||||||
);
|
);
|
||||||
@@ -243,6 +241,8 @@ export function logAiSession(data: {
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const timestamp = Math.floor(Date.now() / 1000);
|
||||||
|
|
||||||
sessionLogBuffer.push({
|
sessionLogBuffer.push({
|
||||||
sessionId: data.sessionId,
|
sessionId: data.sessionId,
|
||||||
orgId: sanitizeString(data.orgId),
|
orgId: sanitizeString(data.orgId),
|
||||||
@@ -256,13 +256,19 @@ export function logAiSession(data: {
|
|||||||
),
|
),
|
||||||
requestedModel: sanitizeString(data.requestedModel),
|
requestedModel: sanitizeString(data.requestedModel),
|
||||||
isStream: data.isStream,
|
isStream: data.isStream,
|
||||||
requestBody: sanitizeString(requestBodyText.value),
|
requestBody: compressText(
|
||||||
responseBody: sanitizeString(responseBodyText.value),
|
sanitizeString(requestBodyText.value)
|
||||||
|
),
|
||||||
|
responseBody: compressText(
|
||||||
|
sanitizeString(responseBodyText.value)
|
||||||
|
),
|
||||||
normalizedRequest: normalizedRequestText
|
normalizedRequest: normalizedRequestText
|
||||||
? sanitizeString(normalizedRequestText.value)
|
? compressText(sanitizeString(normalizedRequestText.value))
|
||||||
: undefined,
|
: undefined,
|
||||||
normalizedResponse: normalizedResponseText
|
normalizedResponse: normalizedResponseText
|
||||||
? sanitizeString(normalizedResponseText.value)
|
? compressText(
|
||||||
|
sanitizeString(normalizedResponseText.value)
|
||||||
|
)
|
||||||
: undefined,
|
: undefined,
|
||||||
truncated:
|
truncated:
|
||||||
requestBodyText.truncated ||
|
requestBodyText.truncated ||
|
||||||
@@ -270,7 +276,7 @@ export function logAiSession(data: {
|
|||||||
(normalizedRequestText?.truncated ?? false) ||
|
(normalizedRequestText?.truncated ?? false) ||
|
||||||
(normalizedResponseText?.truncated ?? false),
|
(normalizedResponseText?.truncated ?? false),
|
||||||
statusCode: data.statusCode,
|
statusCode: data.statusCode,
|
||||||
createdAt: Date.now()
|
createdAt: timestamp
|
||||||
});
|
});
|
||||||
|
|
||||||
// Flush immediately if buffer is full, otherwise schedule a flush
|
// Flush immediately if buffer is full, otherwise schedule a flush
|
||||||
|
|||||||
@@ -88,7 +88,27 @@ export const queryAccessAuditLogsQuery = z.object({
|
|||||||
.optional()
|
.optional()
|
||||||
.default("0")
|
.default("0")
|
||||||
.transform(Number)
|
.transform(Number)
|
||||||
.pipe(z.int().nonnegative())
|
.pipe(z.int().nonnegative()),
|
||||||
|
ip: z
|
||||||
|
.preprocess((val) => {
|
||||||
|
if (val === undefined || val === null || val === "") {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
if (Array.isArray(val)) {
|
||||||
|
return val;
|
||||||
|
}
|
||||||
|
// the array is returned as this
|
||||||
|
if (typeof val === "string") {
|
||||||
|
return val.split(",");
|
||||||
|
}
|
||||||
|
return undefined;
|
||||||
|
}, z.array(z.string()))
|
||||||
|
.optional()
|
||||||
|
.catch([])
|
||||||
|
.openapi({
|
||||||
|
type: "array",
|
||||||
|
description: "Filter by IP adresses"
|
||||||
|
})
|
||||||
});
|
});
|
||||||
|
|
||||||
export const queryAccessAuditLogsParams = z.object({
|
export const queryAccessAuditLogsParams = z.object({
|
||||||
@@ -134,6 +154,9 @@ function getWhere(data: Q) {
|
|||||||
data.type ? eq(accessAuditLog.type, data.type) : undefined,
|
data.type ? eq(accessAuditLog.type, data.type) : undefined,
|
||||||
data.action !== undefined
|
data.action !== undefined
|
||||||
? eq(accessAuditLog.action, data.action)
|
? eq(accessAuditLog.action, data.action)
|
||||||
|
: undefined,
|
||||||
|
data.ip && data.ip.length > 0
|
||||||
|
? inArray(accessAuditLog.ip, data.ip)
|
||||||
: undefined
|
: undefined
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -16,12 +16,10 @@ import {
|
|||||||
handleRemoteExitNodePingMessage
|
handleRemoteExitNodePingMessage
|
||||||
} from "#private/routers/remoteExitNode";
|
} from "#private/routers/remoteExitNode";
|
||||||
import { MessageHandler } from "@server/routers/ws";
|
import { MessageHandler } from "@server/routers/ws";
|
||||||
import {
|
import { handleConnectionLogMessage } from "#private/routers/newt";
|
||||||
handleConnectionLogMessage,
|
|
||||||
} from "#private/routers/newt";
|
|
||||||
|
|
||||||
export const messageHandlers: Record<string, MessageHandler> = {
|
export const messageHandlers: Record<string, MessageHandler> = {
|
||||||
"remoteExitNode/register": handleRemoteExitNodeRegisterMessage,
|
"remoteExitNode/register": handleRemoteExitNodeRegisterMessage,
|
||||||
"remoteExitNode/ping": handleRemoteExitNodePingMessage,
|
"remoteExitNode/ping": handleRemoteExitNodePingMessage,
|
||||||
"newt/access-log": handleConnectionLogMessage,
|
"newt/access-log": handleConnectionLogMessage
|
||||||
};
|
};
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ export const aiUsageAnalyticsFiltersQuery = z.object({
|
|||||||
.refine((val) => !isNaN(Date.parse(val)), {
|
.refine((val) => !isNaN(Date.parse(val)), {
|
||||||
error: "timeStart must be a valid ISO date string"
|
error: "timeStart must be a valid ISO date string"
|
||||||
})
|
})
|
||||||
.transform((val) => new Date(val).getTime())
|
.transform((val) => Math.floor(new Date(val).getTime() / 1000))
|
||||||
.prefault(() => getSevenDaysAgo().toISOString())
|
.prefault(() => getSevenDaysAgo().toISOString())
|
||||||
.openapi({
|
.openapi({
|
||||||
type: "string",
|
type: "string",
|
||||||
@@ -31,7 +31,7 @@ export const aiUsageAnalyticsFiltersQuery = z.object({
|
|||||||
.refine((val) => !isNaN(Date.parse(val)), {
|
.refine((val) => !isNaN(Date.parse(val)), {
|
||||||
error: "timeEnd must be a valid ISO date string"
|
error: "timeEnd must be a valid ISO date string"
|
||||||
})
|
})
|
||||||
.transform((val) => new Date(val).getTime())
|
.transform((val) => Math.floor(new Date(val).getTime() / 1000))
|
||||||
.prefault(() => new Date().toISOString())
|
.prefault(() => new Date().toISOString())
|
||||||
.openapi({
|
.openapi({
|
||||||
type: "string",
|
type: "string",
|
||||||
@@ -122,12 +122,12 @@ export function buildAiUsageWhere(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
// Buckets createdAt (epoch ms) down to a per-day string, dialect-aware, same
|
// Buckets createdAt (epoch seconds) down to a per-day string, dialect-aware,
|
||||||
// approach as the DATE_TRUNC/DATE branch in queryRequestAnalytics.ts.
|
// same approach as the DATE_TRUNC/DATE branch in queryRequestAnalytics.ts.
|
||||||
export function dayBucketExpr() {
|
export function dayBucketExpr() {
|
||||||
return driver === "pg"
|
return driver === "pg"
|
||||||
? sql<string>`DATE_TRUNC('day', TO_TIMESTAMP(${aiUsageRecords.createdAt} / 1000.0))`
|
? sql<string>`DATE_TRUNC('day', TO_TIMESTAMP(${aiUsageRecords.createdAt}))`
|
||||||
: sql<string>`DATE(${aiUsageRecords.createdAt} / 1000, 'unixepoch')`;
|
: sql<string>`DATE(${aiUsageRecords.createdAt}, 'unixepoch')`;
|
||||||
}
|
}
|
||||||
|
|
||||||
export type DailyMetricRow<K extends string> = {
|
export type DailyMetricRow<K extends string> = {
|
||||||
|
|||||||
@@ -11,7 +11,8 @@ import {
|
|||||||
queryAiSessionLogsQuery,
|
queryAiSessionLogsQuery,
|
||||||
queryAiSessionLogsParams,
|
queryAiSessionLogsParams,
|
||||||
queryAiSession,
|
queryAiSession,
|
||||||
countAiSessionQuery
|
countAiSessionQuery,
|
||||||
|
decompressAiSessionLogRow
|
||||||
} from "./queryAiSessionLog";
|
} from "./queryAiSessionLog";
|
||||||
import { generateCSV } from "./generateCSV";
|
import { generateCSV } from "./generateCSV";
|
||||||
|
|
||||||
@@ -87,7 +88,9 @@ export async function exportAiSessionLogs(
|
|||||||
|
|
||||||
const baseQuery = queryAiSession(data);
|
const baseQuery = queryAiSession(data);
|
||||||
|
|
||||||
const log = await baseQuery.limit(MAX_EXPORT_LIMIT);
|
const log = (await baseQuery.limit(MAX_EXPORT_LIMIT)).map(
|
||||||
|
decompressAiSessionLogRow
|
||||||
|
);
|
||||||
|
|
||||||
const csvData = generateCSV(log);
|
const csvData = generateCSV(log);
|
||||||
|
|
||||||
|
|||||||
@@ -24,6 +24,7 @@ import { AI_CAPABILITIES } from "@server/lib/aiCapabilities";
|
|||||||
import response from "@server/lib/response";
|
import response from "@server/lib/response";
|
||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
import { getSevenDaysAgo } from "@app/lib/getSevenDaysAgo";
|
import { getSevenDaysAgo } from "@app/lib/getSevenDaysAgo";
|
||||||
|
import { decompressText } from "@server/lib/textCompression";
|
||||||
|
|
||||||
export const queryAiSessionLogsQuery = z.strictObject({
|
export const queryAiSessionLogsQuery = z.strictObject({
|
||||||
// iso string just validate its a parseable date
|
// iso string just validate its a parseable date
|
||||||
@@ -32,7 +33,7 @@ export const queryAiSessionLogsQuery = z.strictObject({
|
|||||||
.refine((val) => !isNaN(Date.parse(val)), {
|
.refine((val) => !isNaN(Date.parse(val)), {
|
||||||
error: "timeStart must be a valid ISO date string"
|
error: "timeStart must be a valid ISO date string"
|
||||||
})
|
})
|
||||||
.transform((val) => new Date(val).getTime())
|
.transform((val) => Math.floor(new Date(val).getTime() / 1000))
|
||||||
.prefault(() => getSevenDaysAgo().toISOString())
|
.prefault(() => getSevenDaysAgo().toISOString())
|
||||||
.openapi({
|
.openapi({
|
||||||
type: "string",
|
type: "string",
|
||||||
@@ -45,7 +46,7 @@ export const queryAiSessionLogsQuery = z.strictObject({
|
|||||||
.refine((val) => !isNaN(Date.parse(val)), {
|
.refine((val) => !isNaN(Date.parse(val)), {
|
||||||
error: "timeEnd must be a valid ISO date string"
|
error: "timeEnd must be a valid ISO date string"
|
||||||
})
|
})
|
||||||
.transform((val) => new Date(val).getTime())
|
.transform((val) => Math.floor(new Date(val).getTime() / 1000))
|
||||||
.optional()
|
.optional()
|
||||||
.prefault(() => new Date().toISOString())
|
.prefault(() => new Date().toISOString())
|
||||||
.openapi({
|
.openapi({
|
||||||
@@ -166,6 +167,35 @@ export function queryAiSession(data: Q) {
|
|||||||
.orderBy(desc(aiSessionLog.createdAt));
|
.orderBy(desc(aiSessionLog.createdAt));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function decompressField(value: string | null): string | null {
|
||||||
|
if (value == null) {
|
||||||
|
return value;
|
||||||
|
}
|
||||||
|
try {
|
||||||
|
return decompressText(value);
|
||||||
|
} catch (error) {
|
||||||
|
logger.error("Failed to decompress AI session log field", { error });
|
||||||
|
return value;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
export function decompressAiSessionLogRow<
|
||||||
|
T extends {
|
||||||
|
requestBody: string | null;
|
||||||
|
responseBody: string | null;
|
||||||
|
normalizedRequest: string | null;
|
||||||
|
normalizedResponse: string | null;
|
||||||
|
}
|
||||||
|
>(row: T): T {
|
||||||
|
return {
|
||||||
|
...row,
|
||||||
|
requestBody: decompressField(row.requestBody),
|
||||||
|
responseBody: decompressField(row.responseBody),
|
||||||
|
normalizedRequest: decompressField(row.normalizedRequest),
|
||||||
|
normalizedResponse: decompressField(row.normalizedResponse)
|
||||||
|
};
|
||||||
|
}
|
||||||
|
|
||||||
async function enrichWithDetails(
|
async function enrichWithDetails(
|
||||||
logs: Awaited<ReturnType<typeof queryAiSession>>
|
logs: Awaited<ReturnType<typeof queryAiSession>>
|
||||||
) {
|
) {
|
||||||
@@ -620,7 +650,9 @@ export async function queryAiSessionLogs(
|
|||||||
|
|
||||||
const baseQuery = queryAiSession(data);
|
const baseQuery = queryAiSession(data);
|
||||||
|
|
||||||
const logsRaw = await baseQuery.limit(data.limit).offset(data.offset);
|
const logsRaw = (
|
||||||
|
await baseQuery.limit(data.limit).offset(data.offset)
|
||||||
|
).map(decompressAiSessionLogRow);
|
||||||
|
|
||||||
const log = await enrichWithDetails(logsRaw);
|
const log = await enrichWithDetails(logsRaw);
|
||||||
|
|
||||||
|
|||||||
@@ -30,14 +30,14 @@ const queryAiUsageFilterOptionsQuery = z.object({
|
|||||||
.refine((val) => !isNaN(Date.parse(val)), {
|
.refine((val) => !isNaN(Date.parse(val)), {
|
||||||
error: "timeStart must be a valid ISO date string"
|
error: "timeStart must be a valid ISO date string"
|
||||||
})
|
})
|
||||||
.transform((val) => new Date(val).getTime())
|
.transform((val) => Math.floor(new Date(val).getTime() / 1000))
|
||||||
.prefault(() => getSevenDaysAgo().toISOString()),
|
.prefault(() => getSevenDaysAgo().toISOString()),
|
||||||
timeEnd: z
|
timeEnd: z
|
||||||
.string()
|
.string()
|
||||||
.refine((val) => !isNaN(Date.parse(val)), {
|
.refine((val) => !isNaN(Date.parse(val)), {
|
||||||
error: "timeEnd must be a valid ISO date string"
|
error: "timeEnd must be a valid ISO date string"
|
||||||
})
|
})
|
||||||
.transform((val) => new Date(val).getTime())
|
.transform((val) => Math.floor(new Date(val).getTime() / 1000))
|
||||||
.prefault(() => new Date().toISOString())
|
.prefault(() => new Date().toISOString())
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|||||||
@@ -81,7 +81,27 @@ export const queryAccessAuditLogsQuery = z.strictObject({
|
|||||||
.optional()
|
.optional()
|
||||||
.default("0")
|
.default("0")
|
||||||
.transform(Number)
|
.transform(Number)
|
||||||
.pipe(z.int().nonnegative())
|
.pipe(z.int().nonnegative()),
|
||||||
|
ip: z
|
||||||
|
.preprocess((val) => {
|
||||||
|
if (val === undefined || val === null || val === "") {
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
|
if (Array.isArray(val)) {
|
||||||
|
return val;
|
||||||
|
}
|
||||||
|
// the array is returned as this
|
||||||
|
if (typeof val === "string") {
|
||||||
|
return val.split(",");
|
||||||
|
}
|
||||||
|
return undefined;
|
||||||
|
}, z.array(z.string()))
|
||||||
|
.optional()
|
||||||
|
.catch([])
|
||||||
|
.openapi({
|
||||||
|
type: "array",
|
||||||
|
description: "Filter by IP adresses"
|
||||||
|
})
|
||||||
});
|
});
|
||||||
|
|
||||||
export const queryRequestAuditLogsParams = z.object({
|
export const queryRequestAuditLogsParams = z.object({
|
||||||
@@ -126,6 +146,9 @@ function getWhere(data: Q) {
|
|||||||
data.path ? eq(requestAuditLog.path, data.path) : undefined,
|
data.path ? eq(requestAuditLog.path, data.path) : undefined,
|
||||||
data.action !== undefined
|
data.action !== undefined
|
||||||
? eq(requestAuditLog.action, data.action)
|
? eq(requestAuditLog.action, data.action)
|
||||||
|
: undefined,
|
||||||
|
data.ip && data.ip.length > 0
|
||||||
|
? inArray(requestAuditLog.ip, data.ip)
|
||||||
: undefined
|
: undefined
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,7 +6,7 @@ import HttpCode from "@server/types/HttpCode";
|
|||||||
import { response } from "@server/lib/response";
|
import { response } from "@server/lib/response";
|
||||||
import { db } from "@server/db";
|
import { db } from "@server/db";
|
||||||
import { passwordResetTokens, users } from "@server/db";
|
import { passwordResetTokens, users } from "@server/db";
|
||||||
import { eq } from "drizzle-orm";
|
import { eq, and } from "drizzle-orm";
|
||||||
import { alphabet, generateRandomString, sha256 } from "oslo/crypto";
|
import { alphabet, generateRandomString, sha256 } from "oslo/crypto";
|
||||||
import { createDate } from "oslo";
|
import { createDate } from "oslo";
|
||||||
import logger from "@server/logger";
|
import logger from "@server/logger";
|
||||||
@@ -49,7 +49,12 @@ export async function requestPasswordReset(
|
|||||||
const existingUser = await db
|
const existingUser = await db
|
||||||
.select()
|
.select()
|
||||||
.from(users)
|
.from(users)
|
||||||
.where(eq(users.email, email));
|
.where(
|
||||||
|
and(
|
||||||
|
eq(users.email, email),
|
||||||
|
eq(users.type, UserType.Internal)
|
||||||
|
)
|
||||||
|
);
|
||||||
|
|
||||||
if (!existingUser || !existingUser.length) {
|
if (!existingUser || !existingUser.length) {
|
||||||
await randomDelay(2000);
|
await randomDelay(2000);
|
||||||
|
|||||||
@@ -533,18 +533,23 @@ export async function startAuthentication(
|
|||||||
|
|
||||||
// If email is provided, get security keys for that specific user
|
// If email is provided, get security keys for that specific user
|
||||||
if (email) {
|
if (email) {
|
||||||
const [user] = await db
|
const matchingUsers = await db
|
||||||
.select()
|
.select()
|
||||||
.from(users)
|
.from(users)
|
||||||
.where(eq(users.email, email))
|
.where(
|
||||||
.limit(1);
|
and(
|
||||||
|
eq(users.email, email.toLowerCase()),
|
||||||
|
eq(users.type, UserType.Internal)
|
||||||
|
)
|
||||||
|
);
|
||||||
|
|
||||||
if (!user || user.type !== UserType.Internal) {
|
if (matchingUsers.length !== 1) {
|
||||||
return next(
|
return next(
|
||||||
createHttpError(HttpCode.BAD_REQUEST, "Invalid credentials")
|
createHttpError(HttpCode.BAD_REQUEST, "Invalid credentials")
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const user = matchingUsers[0];
|
||||||
userId = user.userId;
|
userId = user.userId;
|
||||||
|
|
||||||
const userSecurityKeys = await db
|
const userSecurityKeys = await db
|
||||||
|
|||||||
@@ -42,54 +42,62 @@ export async function setServerAdmin(
|
|||||||
|
|
||||||
const { email, password, setupToken } = parsedBody.data;
|
const { email, password, setupToken } = parsedBody.data;
|
||||||
|
|
||||||
// Validate setup token
|
|
||||||
const [validToken] = await db
|
|
||||||
.select()
|
|
||||||
.from(setupTokens)
|
|
||||||
.where(
|
|
||||||
and(
|
|
||||||
eq(setupTokens.token, setupToken),
|
|
||||||
eq(setupTokens.used, false)
|
|
||||||
)
|
|
||||||
);
|
|
||||||
|
|
||||||
if (!validToken) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Invalid or expired setup token"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const [existing] = await db
|
|
||||||
.select()
|
|
||||||
.from(users)
|
|
||||||
.where(eq(users.serverAdmin, true));
|
|
||||||
|
|
||||||
if (existing) {
|
|
||||||
return next(
|
|
||||||
createHttpError(
|
|
||||||
HttpCode.BAD_REQUEST,
|
|
||||||
"Server admin already exists"
|
|
||||||
)
|
|
||||||
);
|
|
||||||
}
|
|
||||||
|
|
||||||
const passwordHash = await hashPassword(password);
|
const passwordHash = await hashPassword(password);
|
||||||
const userId = generateId(15);
|
const userId = generateId(15);
|
||||||
|
|
||||||
await db.transaction(async (trx) => {
|
await db.transaction(async (trx) => {
|
||||||
// Mark the token as used
|
const consumed = await trx
|
||||||
await trx
|
|
||||||
.update(setupTokens)
|
.update(setupTokens)
|
||||||
.set({
|
.set({
|
||||||
used: true,
|
used: true,
|
||||||
dateUsed: moment().toISOString()
|
dateUsed: moment().toISOString()
|
||||||
})
|
})
|
||||||
.where(eq(setupTokens.tokenId, validToken.tokenId));
|
.where(
|
||||||
|
and(
|
||||||
|
eq(setupTokens.token, setupToken),
|
||||||
|
eq(setupTokens.used, false)
|
||||||
|
)
|
||||||
|
)
|
||||||
|
.returning({ tokenId: setupTokens.tokenId });
|
||||||
|
|
||||||
|
if (!consumed.length) {
|
||||||
|
throw createHttpError(
|
||||||
|
HttpCode.BAD_REQUEST,
|
||||||
|
"Invalid setup token"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const [existingAdmin] = await trx
|
||||||
|
.select({ userId: users.userId })
|
||||||
|
.from(users)
|
||||||
|
.where(eq(users.serverAdmin, true))
|
||||||
|
.limit(1);
|
||||||
|
|
||||||
|
if (existingAdmin) {
|
||||||
|
throw createHttpError(
|
||||||
|
HttpCode.BAD_REQUEST,
|
||||||
|
"Server admin already exists"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
|
const [existingUser] = await trx
|
||||||
|
.select({ userId: users.userId })
|
||||||
|
.from(users)
|
||||||
|
.where(
|
||||||
|
and(
|
||||||
|
eq(users.email, email),
|
||||||
|
eq(users.type, UserType.Internal)
|
||||||
|
)
|
||||||
|
)
|
||||||
|
.limit(1);
|
||||||
|
|
||||||
|
if (existingUser) {
|
||||||
|
throw createHttpError(
|
||||||
|
HttpCode.BAD_REQUEST,
|
||||||
|
"A user with that email address already exists"
|
||||||
|
);
|
||||||
|
}
|
||||||
|
|
||||||
// Create the server admin user
|
|
||||||
await trx.insert(users).values({
|
await trx.insert(users).values({
|
||||||
userId: userId,
|
userId: userId,
|
||||||
email: email,
|
email: email,
|
||||||
@@ -111,6 +119,9 @@ export async function setServerAdmin(
|
|||||||
status: HttpCode.OK
|
status: HttpCode.OK
|
||||||
});
|
});
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
|
if (createHttpError.isHttpError(e)) {
|
||||||
|
return next(e);
|
||||||
|
}
|
||||||
logger.error(e);
|
logger.error(e);
|
||||||
return next(
|
return next(
|
||||||
createHttpError(
|
createHttpError(
|
||||||
|
|||||||
@@ -48,7 +48,7 @@ export async function validateSetupToken(
|
|||||||
return response<ValidateSetupTokenResponse>(res, {
|
return response<ValidateSetupTokenResponse>(res, {
|
||||||
data: {
|
data: {
|
||||||
valid: false,
|
valid: false,
|
||||||
message: "Invalid or expired setup token"
|
message: "Invalid setup token"
|
||||||
},
|
},
|
||||||
success: true,
|
success: true,
|
||||||
error: false,
|
error: false,
|
||||||
|
|||||||
+15
-11
@@ -66,6 +66,10 @@ import * as aiBudget from "@server/routers/aiBudget";
|
|||||||
import * as virtualApiKey from "@server/routers/virtualApiKey";
|
import * as virtualApiKey from "@server/routers/virtualApiKey";
|
||||||
import * as certificates from "@server/routers/certificates";
|
import * as certificates from "@server/routers/certificates";
|
||||||
|
|
||||||
|
function rateLimitIdentityKey(value: unknown): string {
|
||||||
|
return typeof value === "string" ? value.trim().toLowerCase() : "";
|
||||||
|
}
|
||||||
|
|
||||||
// Root routes
|
// Root routes
|
||||||
export const unauthenticated = Router();
|
export const unauthenticated = Router();
|
||||||
|
|
||||||
@@ -1927,7 +1931,7 @@ authRouter.put(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`signup:${ipKeyGenerator(req.ip || "")}:${req.body.email}`,
|
`signup:${ipKeyGenerator(req.ip || "")}:${rateLimitIdentityKey(req.body.email)}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only sign up ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only sign up ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -1942,7 +1946,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`login:${req.body.email || ipKeyGenerator(req.ip || "")}`,
|
`login:${rateLimitIdentityKey(req.body.email) || ipKeyGenerator(req.ip || "")}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only log in ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only log in ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -1959,7 +1963,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`lookupUser:${req.body.identifier || ipKeyGenerator(req.ip || "")}`,
|
`lookupUser:${rateLimitIdentityKey(req.body.identifier) || ipKeyGenerator(req.ip || "")}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only lookup users ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only lookup users ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -2037,7 +2041,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) => {
|
keyGenerator: (req) => {
|
||||||
return `signup:${req.body.email || req.user?.userId || ipKeyGenerator(req.ip || "")}`;
|
return `signup:${rateLimitIdentityKey(req.body.email) || req.user?.userId || ipKeyGenerator(req.ip || "")}`;
|
||||||
},
|
},
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only enable 2FA ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only enable 2FA ${15} times every ${15} minutes. Please try again later.`;
|
||||||
@@ -2053,7 +2057,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) => {
|
keyGenerator: (req) => {
|
||||||
return `signup:${req.body.email || req.user?.userId || ipKeyGenerator(req.ip || "")}`;
|
return `signup:${rateLimitIdentityKey(req.body.email) || req.user?.userId || ipKeyGenerator(req.ip || "")}`;
|
||||||
},
|
},
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only request a 2FA code ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only request a 2FA code ${15} times every ${15} minutes. Please try again later.`;
|
||||||
@@ -2085,7 +2089,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`signup:${req.body.email || ipKeyGenerator(req.ip || "")}`,
|
`signup:${rateLimitIdentityKey(req.body.email) || ipKeyGenerator(req.ip || "")}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only sign up ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only sign up ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -2103,7 +2107,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`requestEmailVerificationCode:${req.user?.email || ipKeyGenerator(req.ip || "")}`,
|
`requestEmailVerificationCode:${rateLimitIdentityKey(req.user?.email) || ipKeyGenerator(req.ip || "")}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only request an email verification code ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only request an email verification code ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -2125,7 +2129,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`requestPasswordReset:${req.body.email || ipKeyGenerator(req.ip || "")}`,
|
`requestPasswordReset:${rateLimitIdentityKey(req.body.email) || ipKeyGenerator(req.ip || "")}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only request a password reset ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only request a password reset ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -2141,7 +2145,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`resetPassword:${req.body.email || ipKeyGenerator(req.ip || "")}`,
|
`resetPassword:${rateLimitIdentityKey(req.body.email) || ipKeyGenerator(req.ip || "")}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only request a password reset ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only request a password reset ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -2188,7 +2192,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000,
|
windowMs: 15 * 60 * 1000,
|
||||||
max: 15,
|
max: 15,
|
||||||
keyGenerator: (req) =>
|
keyGenerator: (req) =>
|
||||||
`authWithWhitelist:${ipKeyGenerator(req.ip || "")}:${req.body.email}:${req.params.resourceId}`,
|
`authWithWhitelist:${ipKeyGenerator(req.ip || "")}:${rateLimitIdentityKey(req.body.email)}:${req.params.resourceId}`,
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only request an email OTP ${15} times every ${15} minutes. Please try again later.`;
|
const message = `You can only request an email OTP ${15} times every ${15} minutes. Please try again later.`;
|
||||||
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
return next(createHttpError(HttpCode.TOO_MANY_REQUESTS, message));
|
||||||
@@ -2240,7 +2244,7 @@ authRouter.post(
|
|||||||
windowMs: 15 * 60 * 1000, // 15 minutes
|
windowMs: 15 * 60 * 1000, // 15 minutes
|
||||||
max: 10, // Allow 10 authentication attempts per 15 minutes per IP
|
max: 10, // Allow 10 authentication attempts per 15 minutes per IP
|
||||||
keyGenerator: (req) => {
|
keyGenerator: (req) => {
|
||||||
return `securityKeyAuth:${req.body.email || ipKeyGenerator(req.ip || "")}`;
|
return `securityKeyAuth:${rateLimitIdentityKey(req.body.email) || ipKeyGenerator(req.ip || "")}`;
|
||||||
},
|
},
|
||||||
handler: (req, res, next) => {
|
handler: (req, res, next) => {
|
||||||
const message = `You can only attempt security key authentication ${10} times every ${15} minutes. Please try again later.`;
|
const message = `You can only attempt security key authentication ${10} times every ${15} minutes. Please try again later.`;
|
||||||
|
|||||||
@@ -16,13 +16,12 @@ const getOrgSchema = z.strictObject({
|
|||||||
});
|
});
|
||||||
|
|
||||||
export type GetOrgResponse = {
|
export type GetOrgResponse = {
|
||||||
org: Org;
|
org: Omit<Org, "sshCaPrivateKey">;
|
||||||
};
|
};
|
||||||
const GetOrgResponseDataSchema = z.object({
|
const GetOrgResponseDataSchema = z.object({
|
||||||
org: z.object({}).passthrough()
|
org: z.object({}).passthrough()
|
||||||
});
|
});
|
||||||
|
|
||||||
|
|
||||||
registry.registerPath({
|
registry.registerPath({
|
||||||
method: "get",
|
method: "get",
|
||||||
path: "/org/{orgId}",
|
path: "/org/{orgId}",
|
||||||
@@ -76,9 +75,12 @@ export async function getOrg(
|
|||||||
);
|
);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
// sshCaPrivateKey is encrypted anyway but just to be safe
|
||||||
|
const { sshCaPrivateKey: _, ...orgWithoutPrivateKey } = org;
|
||||||
|
|
||||||
return response<GetOrgResponse>(res, {
|
return response<GetOrgResponse>(res, {
|
||||||
data: {
|
data: {
|
||||||
org
|
org: orgWithoutPrivateKey
|
||||||
},
|
},
|
||||||
success: true,
|
success: true,
|
||||||
error: false,
|
error: false,
|
||||||
|
|||||||
@@ -18,7 +18,7 @@ const getSiteResourceParamsSchema = z.strictObject({
|
|||||||
.pipe(z.int().positive().optional())
|
.pipe(z.int().positive().optional())
|
||||||
.optional(),
|
.optional(),
|
||||||
niceId: z.string().optional(),
|
niceId: z.string().optional(),
|
||||||
orgId: z.string()
|
orgId: z.string().optional()
|
||||||
});
|
});
|
||||||
|
|
||||||
async function query(siteResourceId?: number, niceId?: string, orgId?: string) {
|
async function query(siteResourceId?: number, niceId?: string, orgId?: string) {
|
||||||
@@ -34,6 +34,13 @@ async function query(siteResourceId?: number, niceId?: string, orgId?: string) {
|
|||||||
)
|
)
|
||||||
.limit(1);
|
.limit(1);
|
||||||
return siteResource;
|
return siteResource;
|
||||||
|
} else if (siteResourceId) {
|
||||||
|
const [siteResource] = await db
|
||||||
|
.select()
|
||||||
|
.from(siteResources)
|
||||||
|
.where(eq(siteResources.siteResourceId, siteResourceId))
|
||||||
|
.limit(1);
|
||||||
|
return siteResource;
|
||||||
} else if (niceId && orgId) {
|
} else if (niceId && orgId) {
|
||||||
const [siteResource] = await db
|
const [siteResource] = await db
|
||||||
.select()
|
.select()
|
||||||
@@ -60,9 +67,7 @@ registry.registerPath({
|
|||||||
tags: [OpenAPITags.PrivateResourceLegacy],
|
tags: [OpenAPITags.PrivateResourceLegacy],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
siteResourceId: z.number(),
|
siteResourceId: z.number()
|
||||||
siteId: z.number(),
|
|
||||||
orgId: z.string()
|
|
||||||
})
|
})
|
||||||
},
|
},
|
||||||
responses: {
|
responses: {
|
||||||
@@ -90,9 +95,7 @@ registry.registerPath({
|
|||||||
tags: [OpenAPITags.PrivateResource],
|
tags: [OpenAPITags.PrivateResource],
|
||||||
request: {
|
request: {
|
||||||
params: z.object({
|
params: z.object({
|
||||||
siteResourceId: z.number(),
|
siteResourceId: z.number()
|
||||||
siteId: z.number(),
|
|
||||||
orgId: z.string()
|
|
||||||
})
|
})
|
||||||
},
|
},
|
||||||
responses: {
|
responses: {
|
||||||
|
|||||||
@@ -223,7 +223,7 @@ export default async function migration() {
|
|||||||
sql`ALTER TABLE "subscriptions" ADD COLUMN "override" boolean DEFAULT false;`
|
sql`ALTER TABLE "subscriptions" ADD COLUMN "override" boolean DEFAULT false;`
|
||||||
);
|
);
|
||||||
await db.execute(
|
await db.execute(
|
||||||
sql`ALTER TABLE "orgs" ADD COLUMN "settingsLogRetentionDaysAISessions" integer DEFAULT 7 NOT NULL;`
|
sql`ALTER TABLE "orgs" ADD COLUMN "settingsLogRetentionDaysAISessions" integer DEFAULT 0 NOT NULL;`
|
||||||
);
|
);
|
||||||
await db.execute(
|
await db.execute(
|
||||||
sql`ALTER TABLE "siteResources" ADD COLUMN "requiresExitNodeConnection" boolean DEFAULT false NOT NULL;`
|
sql`ALTER TABLE "siteResources" ADD COLUMN "requiresExitNodeConnection" boolean DEFAULT false NOT NULL;`
|
||||||
@@ -345,6 +345,9 @@ export default async function migration() {
|
|||||||
await db.execute(
|
await db.execute(
|
||||||
sql`ALTER TABLE "virtualApiKeys" ADD CONSTRAINT "virtualApiKeys_createdByUserId_user_id_fk" FOREIGN KEY ("createdByUserId") REFERENCES "public"."user"("id") ON DELETE set null ON UPDATE no action;`
|
sql`ALTER TABLE "virtualApiKeys" ADD CONSTRAINT "virtualApiKeys_createdByUserId_user_id_fk" FOREIGN KEY ("createdByUserId") REFERENCES "public"."user"("id") ON DELETE set null ON UPDATE no action;`
|
||||||
);
|
);
|
||||||
|
await db.execute(
|
||||||
|
sql`ALTER TABLE "eventStreamingDestinations" ADD "sendAISessionLogs" boolean DEFAULT false NOT NULL;`
|
||||||
|
);
|
||||||
await db.execute(
|
await db.execute(
|
||||||
sql`CREATE INDEX "idx_ai_budget_breach_events_budget_created" ON "aiBudgetBreachEvents" USING btree ("budgetId","createdAt");`
|
sql`CREATE INDEX "idx_ai_budget_breach_events_budget_created" ON "aiBudgetBreachEvents" USING btree ("budgetId","createdAt");`
|
||||||
);
|
);
|
||||||
@@ -451,14 +454,14 @@ export default async function migration() {
|
|||||||
throw new Error(fromZodError(parsedConfig.error).toString());
|
throw new Error(fromZodError(parsedConfig.error).toString());
|
||||||
}
|
}
|
||||||
|
|
||||||
traefikConfig.experimental.plugins.badger.version = "v1.6.1";
|
traefikConfig.experimental.plugins.badger.version = "v1.7.0";
|
||||||
|
|
||||||
const updatedTraefikYaml = yaml.dump(traefikConfig);
|
const updatedTraefikYaml = yaml.dump(traefikConfig);
|
||||||
|
|
||||||
fs.writeFileSync(traefikPath, updatedTraefikYaml, "utf8");
|
fs.writeFileSync(traefikPath, updatedTraefikYaml, "utf8");
|
||||||
|
|
||||||
console.log(
|
console.log(
|
||||||
"Updated the version of Badger in your Traefik configuration to v1.6.1"
|
"Updated the version of Badger in your Traefik configuration to v1.7.0"
|
||||||
);
|
);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
console.log(
|
console.log(
|
||||||
|
|||||||
@@ -397,11 +397,14 @@ export default async function migration() {
|
|||||||
`ALTER TABLE 'clients' ADD 'exitNodeSubnet' text;`
|
`ALTER TABLE 'clients' ADD 'exitNodeSubnet' text;`
|
||||||
).run();
|
).run();
|
||||||
db.prepare(
|
db.prepare(
|
||||||
`ALTER TABLE 'orgs' ADD 'settingsLogRetentionDaysAISessions' integer DEFAULT 7 NOT NULL;`
|
`ALTER TABLE 'orgs' ADD 'settingsLogRetentionDaysAISessions' integer DEFAULT 0 NOT NULL;`
|
||||||
).run();
|
).run();
|
||||||
db.prepare(
|
db.prepare(
|
||||||
`ALTER TABLE 'siteResources' ADD 'requiresExitNodeConnection' integer DEFAULT false NOT NULL;`
|
`ALTER TABLE 'siteResources' ADD 'requiresExitNodeConnection' integer DEFAULT false NOT NULL;`
|
||||||
).run();
|
).run();
|
||||||
|
db.prepare(
|
||||||
|
`ALTER TABLE 'eventStreamingDestinations' ADD 'sendAISessionLogs' integer DEFAULT false NOT NULL;`
|
||||||
|
).run();
|
||||||
|
|
||||||
const insertRoleAction = db.prepare(`
|
const insertRoleAction = db.prepare(`
|
||||||
INSERT INTO 'roleActions' ("roleId", "actionId", "orgId")
|
INSERT INTO 'roleActions' ("roleId", "actionId", "orgId")
|
||||||
@@ -456,14 +459,14 @@ export default async function migration() {
|
|||||||
throw new Error(fromZodError(parsedConfig.error).toString());
|
throw new Error(fromZodError(parsedConfig.error).toString());
|
||||||
}
|
}
|
||||||
|
|
||||||
traefikConfig.experimental.plugins.badger.version = "v1.6.1";
|
traefikConfig.experimental.plugins.badger.version = "v1.7.0";
|
||||||
|
|
||||||
const updatedTraefikYaml = yaml.dump(traefikConfig);
|
const updatedTraefikYaml = yaml.dump(traefikConfig);
|
||||||
|
|
||||||
fs.writeFileSync(traefikPath, updatedTraefikYaml, "utf8");
|
fs.writeFileSync(traefikPath, updatedTraefikYaml, "utf8");
|
||||||
|
|
||||||
console.log(
|
console.log(
|
||||||
"Updated the version of Badger in your Traefik configuration to v1.6.1"
|
"Updated the version of Badger in your Traefik configuration to v1.7.0"
|
||||||
);
|
);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
console.log(
|
console.log(
|
||||||
|
|||||||
@@ -46,6 +46,7 @@ import { AxiosResponse } from "axios";
|
|||||||
import { ListRolesResponse } from "@server/routers/role";
|
import { ListRolesResponse } from "@server/routers/role";
|
||||||
import AutoProvisionConfigWidget from "@app/components/AutoProvisionConfigWidget";
|
import AutoProvisionConfigWidget from "@app/components/AutoProvisionConfigWidget";
|
||||||
import IdpAutoProvisionUsersDescription from "@app/components/IdpAutoProvisionUsersDescription";
|
import IdpAutoProvisionUsersDescription from "@app/components/IdpAutoProvisionUsersDescription";
|
||||||
|
import IdpIdentifierChangeDialog from "@app/components/IdpIdentifierChangeDialog";
|
||||||
import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
||||||
import { tierMatrix } from "@server/lib/billing/tierMatrix";
|
import { tierMatrix } from "@server/lib/billing/tierMatrix";
|
||||||
import {
|
import {
|
||||||
@@ -75,6 +76,12 @@ export default function GeneralPage() {
|
|||||||
>([createMappingBuilderRule()]);
|
>([createMappingBuilderRule()]);
|
||||||
const [rawRoleExpression, setRawRoleExpression] = useState("");
|
const [rawRoleExpression, setRawRoleExpression] = useState("");
|
||||||
const [variant, setVariant] = useState<"oidc" | "google" | "azure">("oidc");
|
const [variant, setVariant] = useState<"oidc" | "google" | "azure">("oidc");
|
||||||
|
const [originalIdentifierPath, setOriginalIdentifierPath] = useState("");
|
||||||
|
const [identifierConfirmOpen, setIdentifierConfirmOpen] = useState(false);
|
||||||
|
const [pendingPayload, setPendingPayload] = useState<Record<
|
||||||
|
string,
|
||||||
|
unknown
|
||||||
|
> | null>(null);
|
||||||
|
|
||||||
const dashboardRedirectUrl = `${env.app.dashboardUrl}/auth/idp/${idpId}/oidc/callback`;
|
const dashboardRedirectUrl = `${env.app.dashboardUrl}/auth/idp/${idpId}/oidc/callback`;
|
||||||
const [redirectUrl, setRedirectUrl] = useState(
|
const [redirectUrl, setRedirectUrl] = useState(
|
||||||
@@ -184,6 +191,9 @@ export default function GeneralPage() {
|
|||||||
const data = res.data.data;
|
const data = res.data.data;
|
||||||
const roleMapping = data.idpOrg.roleMapping;
|
const roleMapping = data.idpOrg.roleMapping;
|
||||||
const idpVariant = data.idpOidcConfig?.variant || "oidc";
|
const idpVariant = data.idpOidcConfig?.variant || "oidc";
|
||||||
|
setOriginalIdentifierPath(
|
||||||
|
data.idpOidcConfig?.identifierPath ?? "sub"
|
||||||
|
);
|
||||||
setRedirectUrl(res.data.data.redirectUrl);
|
setRedirectUrl(res.data.data.redirectUrl);
|
||||||
|
|
||||||
// Set the variant
|
// Set the variant
|
||||||
@@ -378,18 +388,56 @@ export default function GeneralPage() {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
const res = await api.post(
|
const nextIdentifierPath =
|
||||||
`/org/${orgId}/idp/${idpId}/oidc`,
|
variant === "oidc"
|
||||||
payload
|
? (data as OidcFormValues).identifierPath
|
||||||
);
|
: undefined;
|
||||||
|
|
||||||
|
if (
|
||||||
|
typeof nextIdentifierPath === "string" &&
|
||||||
|
nextIdentifierPath !== originalIdentifierPath
|
||||||
|
) {
|
||||||
|
setPendingPayload(payload);
|
||||||
|
setIdentifierConfirmOpen(true);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await persistIdp(payload);
|
||||||
|
} catch (e) {
|
||||||
|
toast({
|
||||||
|
title: t("error"),
|
||||||
|
description: formatAxiosError(e),
|
||||||
|
variant: "destructive"
|
||||||
|
});
|
||||||
|
} finally {
|
||||||
|
setLoading(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function persistIdp(payload: Record<string, unknown>) {
|
||||||
|
const res = await api.post(`/org/${orgId}/idp/${idpId}/oidc`, payload);
|
||||||
|
|
||||||
if (res.status === 200) {
|
if (res.status === 200) {
|
||||||
|
if (typeof payload.identifierPath === "string") {
|
||||||
|
setOriginalIdentifierPath(payload.identifierPath);
|
||||||
|
}
|
||||||
toast({
|
toast({
|
||||||
title: t("success"),
|
title: t("success"),
|
||||||
description: t("idpUpdatedDescription")
|
description: t("idpUpdatedDescription")
|
||||||
});
|
});
|
||||||
router.refresh();
|
router.refresh();
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function confirmIdentifierChange() {
|
||||||
|
if (!pendingPayload) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
setLoading(true);
|
||||||
|
try {
|
||||||
|
await persistIdp(pendingPayload);
|
||||||
|
setPendingPayload(null);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
toast({
|
toast({
|
||||||
title: t("error"),
|
title: t("error"),
|
||||||
@@ -407,6 +455,16 @@ export default function GeneralPage() {
|
|||||||
|
|
||||||
return (
|
return (
|
||||||
<>
|
<>
|
||||||
|
<IdpIdentifierChangeDialog
|
||||||
|
open={identifierConfirmOpen}
|
||||||
|
setOpen={(open) => {
|
||||||
|
setIdentifierConfirmOpen(open);
|
||||||
|
if (!open) {
|
||||||
|
setPendingPayload(null);
|
||||||
|
}
|
||||||
|
}}
|
||||||
|
onConfirm={confirmIdentifierChange}
|
||||||
|
/>
|
||||||
<SettingsContainer>
|
<SettingsContainer>
|
||||||
<SettingsSection>
|
<SettingsSection>
|
||||||
<SettingsSectionHeader>
|
<SettingsSectionHeader>
|
||||||
|
|||||||
@@ -12,6 +12,7 @@ import { DateTimeValue } from "@app/components/DateTimePicker";
|
|||||||
import { ArrowUpRight, Key, User } from "lucide-react";
|
import { ArrowUpRight, Key, User } from "lucide-react";
|
||||||
import Link from "next/link";
|
import Link from "next/link";
|
||||||
import { ColumnFilterButton } from "@app/components/ColumnFilterButton";
|
import { ColumnFilterButton } from "@app/components/ColumnFilterButton";
|
||||||
|
import { ColumnMultiFilterButton } from "@app/components/ColumnMultiFilterButton";
|
||||||
import SettingsSectionTitle from "@app/components/SettingsSectionTitle";
|
import SettingsSectionTitle from "@app/components/SettingsSectionTitle";
|
||||||
import { build } from "@server/build";
|
import { build } from "@server/build";
|
||||||
import { getSevenDaysAgo } from "@app/lib/getSevenDaysAgo";
|
import { getSevenDaysAgo } from "@app/lib/getSevenDaysAgo";
|
||||||
@@ -26,6 +27,7 @@ import { tierMatrix } from "@server/lib/billing/tierMatrix";
|
|||||||
import { logQueries } from "@app/lib/queries";
|
import { logQueries } from "@app/lib/queries";
|
||||||
import { useQuery } from "@tanstack/react-query";
|
import { useQuery } from "@tanstack/react-query";
|
||||||
import type { QueryAccessAuditLogResponse } from "@server/routers/auditLogs/types";
|
import type { QueryAccessAuditLogResponse } from "@server/routers/auditLogs/types";
|
||||||
|
import { countryCodeToFlagEmoji } from "@app/lib/countryCodeToFlagEmoji";
|
||||||
|
|
||||||
export default function GeneralPage() {
|
export default function GeneralPage() {
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
@@ -45,12 +47,14 @@ export default function GeneralPage() {
|
|||||||
resourceId?: string;
|
resourceId?: string;
|
||||||
location?: string;
|
location?: string;
|
||||||
actor?: string;
|
actor?: string;
|
||||||
|
ip?: string[];
|
||||||
}>({
|
}>({
|
||||||
action: searchParams.get("action") || undefined,
|
action: searchParams.get("action") || undefined,
|
||||||
type: searchParams.get("type") || undefined,
|
type: searchParams.get("type") || undefined,
|
||||||
resourceId: searchParams.get("resourceId") || undefined,
|
resourceId: searchParams.get("resourceId") || undefined,
|
||||||
location: searchParams.get("location") || undefined,
|
location: searchParams.get("location") || undefined,
|
||||||
actor: searchParams.get("actor") || undefined
|
actor: searchParams.get("actor") || undefined,
|
||||||
|
ip: searchParams.getAll("ip") || undefined
|
||||||
});
|
});
|
||||||
|
|
||||||
const [currentPage, setCurrentPage] = useState<number>(0);
|
const [currentPage, setCurrentPage] = useState<number>(0);
|
||||||
@@ -176,7 +180,7 @@ export default function GeneralPage() {
|
|||||||
|
|
||||||
const handleFilterChange = (
|
const handleFilterChange = (
|
||||||
filterType: keyof typeof filters,
|
filterType: keyof typeof filters,
|
||||||
value: string | undefined
|
value: string | string[] | undefined
|
||||||
) => {
|
) => {
|
||||||
const newFilters = { ...filters, [filterType]: value };
|
const newFilters = { ...filters, [filterType]: value };
|
||||||
setFilters(newFilters);
|
setFilters(newFilters);
|
||||||
@@ -194,10 +198,13 @@ export default function GeneralPage() {
|
|||||||
) => {
|
) => {
|
||||||
const params = new URLSearchParams(searchParams);
|
const params = new URLSearchParams(searchParams);
|
||||||
Object.entries(newFilters).forEach(([key, value]) => {
|
Object.entries(newFilters).forEach(([key, value]) => {
|
||||||
if (value) {
|
|
||||||
params.set(key, value);
|
|
||||||
} else {
|
|
||||||
params.delete(key);
|
params.delete(key);
|
||||||
|
if (typeof value === "string") {
|
||||||
|
params.set(key, value);
|
||||||
|
} else if (typeof value !== "undefined" && "length" in value) {
|
||||||
|
for (const element of value) {
|
||||||
|
params.append(key, element);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
router.replace(`?${params.toString()}`, { scroll: false });
|
router.replace(`?${params.toString()}`, { scroll: false });
|
||||||
@@ -205,6 +212,7 @@ export default function GeneralPage() {
|
|||||||
|
|
||||||
const exportData = async () => {
|
const exportData = async () => {
|
||||||
try {
|
try {
|
||||||
|
const { ip, ...restFilters } = filters;
|
||||||
const params: any = {
|
const params: any = {
|
||||||
timeStart: dateRange.startDate?.date
|
timeStart: dateRange.startDate?.date
|
||||||
? new Date(dateRange.startDate.date).toISOString()
|
? new Date(dateRange.startDate.date).toISOString()
|
||||||
@@ -212,13 +220,20 @@ export default function GeneralPage() {
|
|||||||
timeEnd: dateRange.endDate?.date
|
timeEnd: dateRange.endDate?.date
|
||||||
? new Date(dateRange.endDate.date).toISOString()
|
? new Date(dateRange.endDate.date).toISOString()
|
||||||
: undefined,
|
: undefined,
|
||||||
...filters
|
...restFilters
|
||||||
};
|
};
|
||||||
|
|
||||||
const response = await api.get(`/org/${orgId}/logs/access/export`, {
|
// axios serializes arrays as `ip[]=…`, which express's query
|
||||||
|
// parser does not read back as `ip`, so pass them in the URL
|
||||||
|
const sp = new URLSearchParams((ip ?? []).map((ip) => ["ip", ip]));
|
||||||
|
|
||||||
|
const response = await api.get(
|
||||||
|
`/org/${orgId}/logs/access/export?${sp.toString()}`,
|
||||||
|
{
|
||||||
responseType: "blob",
|
responseType: "blob",
|
||||||
params
|
params
|
||||||
});
|
}
|
||||||
|
);
|
||||||
|
|
||||||
const url = window.URL.createObjectURL(new Blob([response.data]));
|
const url = window.URL.createObjectURL(new Blob([response.data]));
|
||||||
const link = document.createElement("a");
|
const link = document.createElement("a");
|
||||||
@@ -297,7 +312,24 @@ export default function GeneralPage() {
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
accessorKey: "ip",
|
accessorKey: "ip",
|
||||||
header: () => <span className="px-2">{t("ip")}</span>,
|
header: () => (
|
||||||
|
<span className="px-2">
|
||||||
|
<ColumnMultiFilterButton
|
||||||
|
options={(filters.ip ?? []).map((ip) => ({
|
||||||
|
label: ip,
|
||||||
|
value: ip
|
||||||
|
}))}
|
||||||
|
label={t("ip")}
|
||||||
|
allowArbitraryValues
|
||||||
|
searchPlaceholder={t("ipFilterSearchPlaceholder")}
|
||||||
|
emptyMessage={t("ipFilterEmptyMessage")}
|
||||||
|
selectedValues={filters.ip ?? []}
|
||||||
|
onSelectedValuesChange={(value) =>
|
||||||
|
handleFilterChange("ip", value)
|
||||||
|
}
|
||||||
|
/>
|
||||||
|
</span>
|
||||||
|
),
|
||||||
cell: ({ row }) => {
|
cell: ({ row }) => {
|
||||||
return row.original.ip ? (
|
return row.original.ip ? (
|
||||||
row.original.ip
|
row.original.ip
|
||||||
@@ -315,7 +347,7 @@ export default function GeneralPage() {
|
|||||||
options={filterAttributes.locations.map(
|
options={filterAttributes.locations.map(
|
||||||
(location) => ({
|
(location) => ({
|
||||||
value: location,
|
value: location,
|
||||||
label: location
|
label: `${location} ${countryCodeToFlagEmoji(location)}`
|
||||||
})
|
})
|
||||||
)}
|
)}
|
||||||
label={t("location")}
|
label={t("location")}
|
||||||
@@ -334,7 +366,8 @@ export default function GeneralPage() {
|
|||||||
<span className="flex items-center gap-1">
|
<span className="flex items-center gap-1">
|
||||||
{row.original.location ? (
|
{row.original.location ? (
|
||||||
<span className="text-muted-foreground text-xs">
|
<span className="text-muted-foreground text-xs">
|
||||||
{row.original.location}
|
{row.original.location}{" "}
|
||||||
|
{countryCodeToFlagEmoji(row.original.location)}
|
||||||
</span>
|
</span>
|
||||||
) : (
|
) : (
|
||||||
<span className="text-muted-foreground text-xs">
|
<span className="text-muted-foreground text-xs">
|
||||||
|
|||||||
@@ -276,7 +276,9 @@ export default function AiSessionLogsPage() {
|
|||||||
cell: ({ row }) => {
|
cell: ({ row }) => {
|
||||||
return (
|
return (
|
||||||
<div className="whitespace-nowrap">
|
<div className="whitespace-nowrap">
|
||||||
{new Date(row.original.createdAt).toLocaleString()}
|
{new Date(
|
||||||
|
row.original.createdAt * 1000
|
||||||
|
).toLocaleString()}
|
||||||
</div>
|
</div>
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
@@ -715,8 +717,8 @@ function generateSampleAiSessionLogs(): QueryAiSessionLogResponse["log"] {
|
|||||||
null
|
null
|
||||||
];
|
];
|
||||||
|
|
||||||
const now = Date.now();
|
const now = Math.floor(Date.now() / 1000);
|
||||||
const sevenDaysAgoMs = now - 7 * 24 * 60 * 60 * 1000;
|
const sevenDaysAgoMs = now - 7 * 24 * 60 * 60;
|
||||||
|
|
||||||
return Array.from({ length: 10 }, (_, i) => {
|
return Array.from({ length: 10 }, (_, i) => {
|
||||||
const provider =
|
const provider =
|
||||||
|
|||||||
@@ -23,6 +23,8 @@ import { useMemo, useState, useTransition } from "react";
|
|||||||
import { useStoredPageSize } from "@app/hooks/useStoredPageSize";
|
import { useStoredPageSize } from "@app/hooks/useStoredPageSize";
|
||||||
import type { QueryRequestAuditLogResponse } from "@server/routers/auditLogs/types";
|
import type { QueryRequestAuditLogResponse } from "@server/routers/auditLogs/types";
|
||||||
import { ColumnFilterButton } from "@app/components/ColumnFilterButton";
|
import { ColumnFilterButton } from "@app/components/ColumnFilterButton";
|
||||||
|
import { countryCodeToFlagEmoji } from "@app/lib/countryCodeToFlagEmoji";
|
||||||
|
import { ColumnMultiFilterButton } from "@app/components/ColumnMultiFilterButton";
|
||||||
|
|
||||||
export default function GeneralPage() {
|
export default function GeneralPage() {
|
||||||
const router = useRouter();
|
const router = useRouter();
|
||||||
@@ -47,6 +49,7 @@ export default function GeneralPage() {
|
|||||||
method?: string;
|
method?: string;
|
||||||
reason?: string;
|
reason?: string;
|
||||||
path?: string;
|
path?: string;
|
||||||
|
ip?: string[];
|
||||||
}>({
|
}>({
|
||||||
action: searchParams.get("action") || undefined,
|
action: searchParams.get("action") || undefined,
|
||||||
host: searchParams.get("host") || undefined,
|
host: searchParams.get("host") || undefined,
|
||||||
@@ -55,7 +58,8 @@ export default function GeneralPage() {
|
|||||||
actor: searchParams.get("actor") || undefined,
|
actor: searchParams.get("actor") || undefined,
|
||||||
method: searchParams.get("method") || undefined,
|
method: searchParams.get("method") || undefined,
|
||||||
reason: searchParams.get("reason") || undefined,
|
reason: searchParams.get("reason") || undefined,
|
||||||
path: searchParams.get("path") || undefined
|
path: searchParams.get("path") || undefined,
|
||||||
|
ip: searchParams.getAll("ip") || undefined
|
||||||
});
|
});
|
||||||
|
|
||||||
const getDefaultDateRange = () => {
|
const getDefaultDateRange = () => {
|
||||||
@@ -179,7 +183,7 @@ export default function GeneralPage() {
|
|||||||
|
|
||||||
const handleFilterChange = (
|
const handleFilterChange = (
|
||||||
filterType: keyof typeof filters,
|
filterType: keyof typeof filters,
|
||||||
value: string | undefined
|
value: string | string[] | undefined
|
||||||
) => {
|
) => {
|
||||||
const newFilters = { ...filters, [filterType]: value };
|
const newFilters = { ...filters, [filterType]: value };
|
||||||
setFilters(newFilters);
|
setFilters(newFilters);
|
||||||
@@ -197,10 +201,13 @@ export default function GeneralPage() {
|
|||||||
) => {
|
) => {
|
||||||
const params = new URLSearchParams(searchParams);
|
const params = new URLSearchParams(searchParams);
|
||||||
Object.entries(newFilters).forEach(([key, value]) => {
|
Object.entries(newFilters).forEach(([key, value]) => {
|
||||||
if (value) {
|
|
||||||
params.set(key, value);
|
|
||||||
} else {
|
|
||||||
params.delete(key);
|
params.delete(key);
|
||||||
|
if (typeof value === "string") {
|
||||||
|
params.set(key, value);
|
||||||
|
} else if (typeof value !== "undefined" && "length" in value) {
|
||||||
|
for (const element of value) {
|
||||||
|
params.append(key, element);
|
||||||
|
}
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
router.replace(`?${params.toString()}`, { scroll: false });
|
router.replace(`?${params.toString()}`, { scroll: false });
|
||||||
@@ -209,6 +216,7 @@ export default function GeneralPage() {
|
|||||||
const exportData = async () => {
|
const exportData = async () => {
|
||||||
try {
|
try {
|
||||||
// Prepare query params for export
|
// Prepare query params for export
|
||||||
|
const { ip, ...restFilters } = filters;
|
||||||
const params: any = {
|
const params: any = {
|
||||||
timeStart: dateRange.startDate?.date
|
timeStart: dateRange.startDate?.date
|
||||||
? new Date(dateRange.startDate.date).toISOString()
|
? new Date(dateRange.startDate.date).toISOString()
|
||||||
@@ -216,11 +224,15 @@ export default function GeneralPage() {
|
|||||||
timeEnd: dateRange.endDate?.date
|
timeEnd: dateRange.endDate?.date
|
||||||
? new Date(dateRange.endDate.date).toISOString()
|
? new Date(dateRange.endDate.date).toISOString()
|
||||||
: undefined,
|
: undefined,
|
||||||
...filters
|
...restFilters
|
||||||
};
|
};
|
||||||
|
|
||||||
|
// axios serializes arrays as `ip[]=…`, which express's query
|
||||||
|
// parser does not read back as `ip`, so pass them in the URL
|
||||||
|
const sp = new URLSearchParams((ip ?? []).map((ip) => ["ip", ip]));
|
||||||
|
|
||||||
const response = await api.get(
|
const response = await api.get(
|
||||||
`/org/${orgId}/logs/request/export`,
|
`/org/${orgId}/logs/request/export?${sp.toString()}`,
|
||||||
{
|
{
|
||||||
responseType: "blob",
|
responseType: "blob",
|
||||||
params
|
params
|
||||||
@@ -351,7 +363,24 @@ export default function GeneralPage() {
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
accessorKey: "ip",
|
accessorKey: "ip",
|
||||||
header: ({ column }) => <span className="px-2">{t("ip")}</span>,
|
header: ({ column }) => (
|
||||||
|
<span className="px-2">
|
||||||
|
<ColumnMultiFilterButton
|
||||||
|
options={(filters.ip ?? []).map((ip) => ({
|
||||||
|
label: ip,
|
||||||
|
value: ip
|
||||||
|
}))}
|
||||||
|
label={t("ip")}
|
||||||
|
allowArbitraryValues
|
||||||
|
searchPlaceholder={t("ipFilterSearchPlaceholder")}
|
||||||
|
emptyMessage={t("ipFilterEmptyMessage")}
|
||||||
|
selectedValues={filters.ip ?? []}
|
||||||
|
onSelectedValuesChange={(value) =>
|
||||||
|
handleFilterChange("ip", value)
|
||||||
|
}
|
||||||
|
/>
|
||||||
|
</span>
|
||||||
|
),
|
||||||
cell: ({ row }) => {
|
cell: ({ row }) => {
|
||||||
return row.original.ip ? (
|
return row.original.ip ? (
|
||||||
row.original.ip
|
row.original.ip
|
||||||
@@ -369,7 +398,7 @@ export default function GeneralPage() {
|
|||||||
options={filterAttributes.locations.map(
|
options={filterAttributes.locations.map(
|
||||||
(location) => ({
|
(location) => ({
|
||||||
value: location,
|
value: location,
|
||||||
label: location
|
label: `${location} ${countryCodeToFlagEmoji(location)}`
|
||||||
})
|
})
|
||||||
)}
|
)}
|
||||||
selectedValue={filters.location}
|
selectedValue={filters.location}
|
||||||
@@ -389,7 +418,8 @@ export default function GeneralPage() {
|
|||||||
<span className="flex items-center gap-1">
|
<span className="flex items-center gap-1">
|
||||||
{row.original.location ? (
|
{row.original.location ? (
|
||||||
<span className="text-muted-foreground text-xs">
|
<span className="text-muted-foreground text-xs">
|
||||||
{row.original.location}
|
{row.original.location}{" "}
|
||||||
|
{countryCodeToFlagEmoji(row.original.location)}
|
||||||
</span>
|
</span>
|
||||||
) : (
|
) : (
|
||||||
<span className="text-muted-foreground text-xs">
|
<span className="text-muted-foreground text-xs">
|
||||||
|
|||||||
@@ -50,8 +50,6 @@ import {
|
|||||||
import { useEnvContext } from "@app/hooks/useEnvContext";
|
import { useEnvContext } from "@app/hooks/useEnvContext";
|
||||||
import { usePaidStatus } from "@app/hooks/usePaidStatus";
|
import { usePaidStatus } from "@app/hooks/usePaidStatus";
|
||||||
import { toast } from "@app/hooks/useToast";
|
import { toast } from "@app/hooks/useToast";
|
||||||
import { PaidFeaturesAlert } from "@app/components/PaidFeaturesAlert";
|
|
||||||
import { tierMatrix, TierFeature } from "@server/lib/billing/tierMatrix";
|
|
||||||
import { createApiClient, formatAxiosError } from "@app/lib/api";
|
import { createApiClient, formatAxiosError } from "@app/lib/api";
|
||||||
import {
|
import {
|
||||||
createBrowserGatewayTargetFormSchema,
|
createBrowserGatewayTargetFormSchema,
|
||||||
@@ -59,7 +57,6 @@ import {
|
|||||||
selectedSiteSchema,
|
selectedSiteSchema,
|
||||||
type SshSettingsFormValues
|
type SshSettingsFormValues
|
||||||
} from "@app/lib/browserGatewayTargetFormSchema";
|
} from "@app/lib/browserGatewayTargetFormSchema";
|
||||||
import { DockerManager, DockerState } from "@app/lib/docker";
|
|
||||||
import { orgQueries } from "@app/lib/queries";
|
import { orgQueries } from "@app/lib/queries";
|
||||||
import { finalizeSubdomainSanitize } from "@app/lib/subdomain-utils";
|
import { finalizeSubdomainSanitize } from "@app/lib/subdomain-utils";
|
||||||
import { zodResolver } from "@hookform/resolvers/zod";
|
import { zodResolver } from "@hookform/resolvers/zod";
|
||||||
@@ -328,19 +325,20 @@ export default function Page() {
|
|||||||
const rawResourcesAllowed =
|
const rawResourcesAllowed =
|
||||||
env.flags.allowRawResources &&
|
env.flags.allowRawResources &&
|
||||||
(build !== "saas" || remoteExitNodes.length > 0);
|
(build !== "saas" || remoteExitNodes.length > 0);
|
||||||
const enterpriseModesAllowed =
|
|
||||||
!env.flags.disableEnterpriseFeatures;
|
|
||||||
|
|
||||||
const availableTypes = useMemo((): NewResourceType[] => {
|
const availableTypes = useMemo((): NewResourceType[] => {
|
||||||
const base: NewResourceType[] = ["http", "inference"];
|
const base: NewResourceType[] = [
|
||||||
if (enterpriseModesAllowed) {
|
"http",
|
||||||
base.push("ssh", "rdp", "vnc");
|
"inference",
|
||||||
}
|
"ssh",
|
||||||
|
"rdp",
|
||||||
|
"vnc"
|
||||||
|
];
|
||||||
if (rawResourcesAllowed) {
|
if (rawResourcesAllowed) {
|
||||||
base.push("tcp", "udp");
|
base.push("tcp", "udp");
|
||||||
}
|
}
|
||||||
return base;
|
return base;
|
||||||
}, [enterpriseModesAllowed, rawResourcesAllowed]);
|
}, [rawResourcesAllowed]);
|
||||||
|
|
||||||
useEffect(() => {
|
useEffect(() => {
|
||||||
if (!availableTypes.includes(resourceType)) {
|
if (!availableTypes.includes(resourceType)) {
|
||||||
|
|||||||
@@ -41,6 +41,7 @@ import {
|
|||||||
} from "@app/components/InfoSection";
|
} from "@app/components/InfoSection";
|
||||||
import CopyToClipboard from "@app/components/CopyToClipboard";
|
import CopyToClipboard from "@app/components/CopyToClipboard";
|
||||||
import IdpTypeBadge from "@app/components/IdpTypeBadge";
|
import IdpTypeBadge from "@app/components/IdpTypeBadge";
|
||||||
|
import IdpIdentifierChangeDialog from "@app/components/IdpIdentifierChangeDialog";
|
||||||
import { useTranslations } from "next-intl";
|
import { useTranslations } from "next-intl";
|
||||||
|
|
||||||
export default function GeneralPage() {
|
export default function GeneralPage() {
|
||||||
@@ -51,6 +52,12 @@ export default function GeneralPage() {
|
|||||||
const [loading, setLoading] = useState(false);
|
const [loading, setLoading] = useState(false);
|
||||||
const [initialLoading, setInitialLoading] = useState(true);
|
const [initialLoading, setInitialLoading] = useState(true);
|
||||||
const [variant, setVariant] = useState<"oidc" | "google" | "azure">("oidc");
|
const [variant, setVariant] = useState<"oidc" | "google" | "azure">("oidc");
|
||||||
|
const [originalIdentifierPath, setOriginalIdentifierPath] = useState("");
|
||||||
|
const [identifierConfirmOpen, setIdentifierConfirmOpen] = useState(false);
|
||||||
|
const [pendingPayload, setPendingPayload] = useState<Record<
|
||||||
|
string,
|
||||||
|
unknown
|
||||||
|
> | null>(null);
|
||||||
|
|
||||||
const redirectUrl = `${env.app.dashboardUrl}/auth/idp/${idpId}/oidc/callback`;
|
const redirectUrl = `${env.app.dashboardUrl}/auth/idp/${idpId}/oidc/callback`;
|
||||||
const t = useTranslations();
|
const t = useTranslations();
|
||||||
@@ -141,6 +148,9 @@ export default function GeneralPage() {
|
|||||||
| "google"
|
| "google"
|
||||||
| "azure") || "oidc";
|
| "azure") || "oidc";
|
||||||
setVariant(idpVariant);
|
setVariant(idpVariant);
|
||||||
|
setOriginalIdentifierPath(
|
||||||
|
data.idpOidcConfig?.identifierPath ?? "sub"
|
||||||
|
);
|
||||||
|
|
||||||
let tenantId = "";
|
let tenantId = "";
|
||||||
if (idpVariant === "azure" && data.idpOidcConfig?.authUrl) {
|
if (idpVariant === "azure" && data.idpOidcConfig?.authUrl) {
|
||||||
@@ -258,15 +268,56 @@ export default function GeneralPage() {
|
|||||||
};
|
};
|
||||||
}
|
}
|
||||||
|
|
||||||
|
const nextIdentifierPath =
|
||||||
|
variant === "oidc"
|
||||||
|
? (data as OidcFormValues).identifierPath
|
||||||
|
: undefined;
|
||||||
|
|
||||||
|
if (
|
||||||
|
typeof nextIdentifierPath === "string" &&
|
||||||
|
nextIdentifierPath !== originalIdentifierPath
|
||||||
|
) {
|
||||||
|
setPendingPayload(payload);
|
||||||
|
setIdentifierConfirmOpen(true);
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
await persistIdp(payload);
|
||||||
|
} catch (e) {
|
||||||
|
toast({
|
||||||
|
title: t("error"),
|
||||||
|
description: formatAxiosError(e),
|
||||||
|
variant: "destructive"
|
||||||
|
});
|
||||||
|
} finally {
|
||||||
|
setLoading(false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function persistIdp(payload: Record<string, unknown>) {
|
||||||
const res = await api.post(`/idp/${idpId}/oidc`, payload);
|
const res = await api.post(`/idp/${idpId}/oidc`, payload);
|
||||||
|
|
||||||
if (res.status === 200) {
|
if (res.status === 200) {
|
||||||
|
if (typeof payload.identifierPath === "string") {
|
||||||
|
setOriginalIdentifierPath(payload.identifierPath);
|
||||||
|
}
|
||||||
toast({
|
toast({
|
||||||
title: t("success"),
|
title: t("success"),
|
||||||
description: t("idpUpdatedDescription")
|
description: t("idpUpdatedDescription")
|
||||||
});
|
});
|
||||||
router.refresh();
|
router.refresh();
|
||||||
}
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
async function confirmIdentifierChange() {
|
||||||
|
if (!pendingPayload) {
|
||||||
|
return;
|
||||||
|
}
|
||||||
|
|
||||||
|
setLoading(true);
|
||||||
|
try {
|
||||||
|
await persistIdp(pendingPayload);
|
||||||
|
setPendingPayload(null);
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
toast({
|
toast({
|
||||||
title: t("error"),
|
title: t("error"),
|
||||||
@@ -284,6 +335,16 @@ export default function GeneralPage() {
|
|||||||
|
|
||||||
return (
|
return (
|
||||||
<>
|
<>
|
||||||
|
<IdpIdentifierChangeDialog
|
||||||
|
open={identifierConfirmOpen}
|
||||||
|
setOpen={(open) => {
|
||||||
|
setIdentifierConfirmOpen(open);
|
||||||
|
if (!open) {
|
||||||
|
setPendingPayload(null);
|
||||||
|
}
|
||||||
|
}}
|
||||||
|
onConfirm={confirmIdentifierChange}
|
||||||
|
/>
|
||||||
<SettingsContainer>
|
<SettingsContainer>
|
||||||
<SettingsSection>
|
<SettingsSection>
|
||||||
<SettingsSectionHeader>
|
<SettingsSectionHeader>
|
||||||
|
|||||||
@@ -21,7 +21,7 @@ import { useTranslations } from "next-intl";
|
|||||||
|
|
||||||
interface FilterOption {
|
interface FilterOption {
|
||||||
value: string;
|
value: string;
|
||||||
label: string;
|
label: React.ReactNode;
|
||||||
}
|
}
|
||||||
|
|
||||||
interface ColumnFilterButtonProps {
|
interface ColumnFilterButtonProps {
|
||||||
@@ -32,6 +32,7 @@ interface ColumnFilterButtonProps {
|
|||||||
emptyMessage?: string;
|
emptyMessage?: string;
|
||||||
className?: string;
|
className?: string;
|
||||||
label: string;
|
label: string;
|
||||||
|
allowArbitraryValues?: boolean;
|
||||||
}
|
}
|
||||||
|
|
||||||
export function ColumnFilterButton({
|
export function ColumnFilterButton({
|
||||||
@@ -41,7 +42,8 @@ export function ColumnFilterButton({
|
|||||||
searchPlaceholder = "Search...",
|
searchPlaceholder = "Search...",
|
||||||
emptyMessage = "No options found",
|
emptyMessage = "No options found",
|
||||||
className,
|
className,
|
||||||
label
|
label,
|
||||||
|
allowArbitraryValues
|
||||||
}: ColumnFilterButtonProps) {
|
}: ColumnFilterButtonProps) {
|
||||||
const [open, setOpen] = useState(false);
|
const [open, setOpen] = useState(false);
|
||||||
|
|
||||||
@@ -101,7 +103,7 @@ export function ColumnFilterButton({
|
|||||||
{options.map((option) => (
|
{options.map((option) => (
|
||||||
<CommandItem
|
<CommandItem
|
||||||
key={option.value}
|
key={option.value}
|
||||||
value={option.label}
|
value={option.value}
|
||||||
onSelect={() => {
|
onSelect={() => {
|
||||||
onValueChange(
|
onValueChange(
|
||||||
selectedValue === option.value
|
selectedValue === option.value
|
||||||
|
|||||||
@@ -35,6 +35,7 @@ type ColumnMultiFilterButtonProps = {
|
|||||||
emptyMessage?: string;
|
emptyMessage?: string;
|
||||||
className?: string;
|
className?: string;
|
||||||
label: string;
|
label: string;
|
||||||
|
allowArbitraryValues?: boolean;
|
||||||
};
|
};
|
||||||
|
|
||||||
export function ColumnMultiFilterButton({
|
export function ColumnMultiFilterButton({
|
||||||
@@ -44,11 +45,26 @@ export function ColumnMultiFilterButton({
|
|||||||
searchPlaceholder = "Search...",
|
searchPlaceholder = "Search...",
|
||||||
emptyMessage = "No options found",
|
emptyMessage = "No options found",
|
||||||
className,
|
className,
|
||||||
label
|
label,
|
||||||
|
allowArbitraryValues
|
||||||
}: ColumnMultiFilterButtonProps) {
|
}: ColumnMultiFilterButtonProps) {
|
||||||
const [open, setOpen] = useState(false);
|
const [open, setOpen] = useState(false);
|
||||||
|
const [searchQuery, setSearchQuery] = useState("");
|
||||||
const t = useTranslations();
|
const t = useTranslations();
|
||||||
|
|
||||||
|
const visibleOptions = useMemo<FilterOption[]>(() => {
|
||||||
|
const newOptions = [...options];
|
||||||
|
|
||||||
|
if (allowArbitraryValues && searchQuery.trim().length > 0) {
|
||||||
|
newOptions.push({
|
||||||
|
label: searchQuery,
|
||||||
|
value: searchQuery
|
||||||
|
});
|
||||||
|
}
|
||||||
|
|
||||||
|
return newOptions;
|
||||||
|
}, [options, allowArbitraryValues, searchQuery]);
|
||||||
|
|
||||||
const selectedSet = useMemo(
|
const selectedSet = useMemo(
|
||||||
() => new Set(selectedValues),
|
() => new Set(selectedValues),
|
||||||
[selectedValues]
|
[selectedValues]
|
||||||
@@ -64,7 +80,7 @@ export function ColumnMultiFilterButton({
|
|||||||
selectedValues[0]
|
selectedValues[0]
|
||||||
);
|
);
|
||||||
}
|
}
|
||||||
return t("accessUsersRoleFilterCount", {
|
return t("multiSelectFilterCount", {
|
||||||
count: selectedValues.length
|
count: selectedValues.length
|
||||||
});
|
});
|
||||||
}, [selectedValues, options, t]);
|
}, [selectedValues, options, t]);
|
||||||
@@ -108,7 +124,11 @@ export function ColumnMultiFilterButton({
|
|||||||
align="start"
|
align="start"
|
||||||
>
|
>
|
||||||
<Command>
|
<Command>
|
||||||
<CommandInput placeholder={searchPlaceholder} />
|
<CommandInput
|
||||||
|
placeholder={searchPlaceholder}
|
||||||
|
value={searchQuery}
|
||||||
|
onValueChange={setSearchQuery}
|
||||||
|
/>
|
||||||
<CommandList>
|
<CommandList>
|
||||||
<CommandEmpty>{emptyMessage}</CommandEmpty>
|
<CommandEmpty>{emptyMessage}</CommandEmpty>
|
||||||
<CommandGroup>
|
<CommandGroup>
|
||||||
@@ -123,7 +143,7 @@ export function ColumnMultiFilterButton({
|
|||||||
{t("accessFilterClear")}
|
{t("accessFilterClear")}
|
||||||
</CommandItem>
|
</CommandItem>
|
||||||
)}
|
)}
|
||||||
{options.map((option) => (
|
{visibleOptions.map((option) => (
|
||||||
<CommandItem
|
<CommandItem
|
||||||
key={option.value}
|
key={option.value}
|
||||||
value={option.label}
|
value={option.label}
|
||||||
|
|||||||
@@ -0,0 +1,35 @@
|
|||||||
|
"use client";
|
||||||
|
|
||||||
|
import ConfirmDeleteDialog from "@app/components/ConfirmDeleteDialog";
|
||||||
|
import { useTranslations } from "next-intl";
|
||||||
|
|
||||||
|
type IdpIdentifierChangeDialogProps = {
|
||||||
|
open: boolean;
|
||||||
|
setOpen: (open: boolean) => void;
|
||||||
|
onConfirm: () => Promise<void>;
|
||||||
|
};
|
||||||
|
|
||||||
|
export default function IdpIdentifierChangeDialog({
|
||||||
|
open,
|
||||||
|
setOpen,
|
||||||
|
onConfirm
|
||||||
|
}: IdpIdentifierChangeDialogProps) {
|
||||||
|
const t = useTranslations();
|
||||||
|
|
||||||
|
return (
|
||||||
|
<ConfirmDeleteDialog
|
||||||
|
open={open}
|
||||||
|
setOpen={setOpen}
|
||||||
|
dialog={
|
||||||
|
<div className="space-y-2">
|
||||||
|
<p>{t("idpIdentifierChangeDescription")}</p>
|
||||||
|
</div>
|
||||||
|
}
|
||||||
|
buttonText={t("saveGeneralSettings")}
|
||||||
|
onConfirm={onConfirm}
|
||||||
|
string={t("idpIdentifierChangeConfirmMessage")}
|
||||||
|
title={t("idpIdentifierChangeTitle")}
|
||||||
|
warningText={t("idpIdentifierChangeWarningText")}
|
||||||
|
/>
|
||||||
|
);
|
||||||
|
}
|
||||||
@@ -0,0 +1,74 @@
|
|||||||
|
import { assertEquals } from "@test/assert";
|
||||||
|
import { detectLocale } from "./detectLocale";
|
||||||
|
|
||||||
|
function runTests() {
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("zh-TW,zh;q=0.9,en-US;q=0.8,en;q=0.7,ja;q=0.6"),
|
||||||
|
"zh-TW",
|
||||||
|
"An exact regional match should take precedence over a language fallback"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("ZH-tw"),
|
||||||
|
"zh-TW",
|
||||||
|
"Locale matching should be case-insensitive"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale(" zh-TW ; q=1 , zh-CN;q=0.8 "),
|
||||||
|
"zh-TW",
|
||||||
|
"Whitespace and quality parameters should not prevent an exact match"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("zh-CN,zh-TW;q=0.9"),
|
||||||
|
"zh-CN",
|
||||||
|
"Simplified Chinese should still match exactly"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("zh"),
|
||||||
|
"zh-CN",
|
||||||
|
"A generic Chinese preference should retain the existing fallback"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("en-GB,en;q=0.9"),
|
||||||
|
"en-US",
|
||||||
|
"An unsupported region should fall back to a supported locale for the language"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("ja-JP,zh-TW;q=0.9"),
|
||||||
|
"zh-TW",
|
||||||
|
"The next preference should be used when a language is unsupported"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("zh-CN;q=0.5,zh-TW;q=0.9"),
|
||||||
|
"zh-TW",
|
||||||
|
"Preferences should be evaluated by quality"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("zh-TW;q=0,fr-FR;q=0.8"),
|
||||||
|
"fr-FR",
|
||||||
|
"Locales with zero quality should be excluded"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("*,de-DE;q=0.8"),
|
||||||
|
"de-DE",
|
||||||
|
"A wildcard should not obscure a supported preference"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale("ja-JP"),
|
||||||
|
undefined,
|
||||||
|
"An unsupported language should not match"
|
||||||
|
);
|
||||||
|
assertEquals(
|
||||||
|
detectLocale(""),
|
||||||
|
undefined,
|
||||||
|
"An empty Accept-Language header should not match"
|
||||||
|
);
|
||||||
|
|
||||||
|
console.log("All locale detection tests passed!");
|
||||||
|
}
|
||||||
|
|
||||||
|
try {
|
||||||
|
runTests();
|
||||||
|
} catch (error) {
|
||||||
|
console.error("Locale detection test failed:", error);
|
||||||
|
process.exit(1);
|
||||||
|
}
|
||||||
@@ -0,0 +1,48 @@
|
|||||||
|
import { Locale, locales } from "./config";
|
||||||
|
|
||||||
|
export function detectLocale(acceptLanguage: string): Locale | undefined {
|
||||||
|
const browserLocales = acceptLanguage
|
||||||
|
.split(",")
|
||||||
|
.map((entry, index) => {
|
||||||
|
const [locale, ...parameters] = entry.trim().split(";");
|
||||||
|
const qualityParameter = parameters.find((parameter) =>
|
||||||
|
parameter.trim().toLowerCase().startsWith("q=")
|
||||||
|
);
|
||||||
|
const quality = qualityParameter
|
||||||
|
? Number(qualityParameter.trim().slice(2))
|
||||||
|
: 1;
|
||||||
|
|
||||||
|
return {
|
||||||
|
locale: locale.trim().toLowerCase(),
|
||||||
|
quality,
|
||||||
|
index
|
||||||
|
};
|
||||||
|
})
|
||||||
|
.filter(
|
||||||
|
({ locale, quality }) =>
|
||||||
|
locale && locale !== "*" && quality > 0 && quality <= 1
|
||||||
|
)
|
||||||
|
.sort(
|
||||||
|
(left, right) =>
|
||||||
|
right.quality - left.quality || left.index - right.index
|
||||||
|
);
|
||||||
|
|
||||||
|
for (const { locale: browserLocale } of browserLocales) {
|
||||||
|
const exactMatch = locales.find(
|
||||||
|
(locale) => locale.toLowerCase() === browserLocale
|
||||||
|
);
|
||||||
|
if (exactMatch) {
|
||||||
|
return exactMatch;
|
||||||
|
}
|
||||||
|
|
||||||
|
const browserLanguage = browserLocale.split("-")[0];
|
||||||
|
const languageMatch = locales.find(
|
||||||
|
(locale) => locale.split("-")[0].toLowerCase() === browserLanguage
|
||||||
|
);
|
||||||
|
if (languageMatch) {
|
||||||
|
return languageMatch;
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
return undefined;
|
||||||
|
}
|
||||||
+30
-22
@@ -1,3 +1,8 @@
|
|||||||
|
import {
|
||||||
|
getAiBudgetScopeListPath,
|
||||||
|
type AiBudgetScope
|
||||||
|
} from "@app/lib/aiBudgetScope";
|
||||||
|
import type { AiProviderType } from "@app/lib/aiProviderDefaults";
|
||||||
import type { LauncherQueryFilters } from "@app/lib/launcherSearchParams";
|
import type { LauncherQueryFilters } from "@app/lib/launcherSearchParams";
|
||||||
import { buildLauncherSearchParams } from "@app/lib/launcherSearchParams";
|
import { buildLauncherSearchParams } from "@app/lib/launcherSearchParams";
|
||||||
import { build } from "@server/build";
|
import { build } from "@server/build";
|
||||||
@@ -5,15 +10,21 @@ import {
|
|||||||
StatusHistoryResponse,
|
StatusHistoryResponse,
|
||||||
type BatchedStatusHistoryResponse
|
type BatchedStatusHistoryResponse
|
||||||
} from "@server/lib/statusHistory";
|
} from "@server/lib/statusHistory";
|
||||||
|
import type { ListAiBudgetsByScopeResponse } from "@server/routers/aiBudget/types";
|
||||||
|
import type {
|
||||||
|
ListAiModelsResponse,
|
||||||
|
ListAiProvidersResponse,
|
||||||
|
ListCatalogModelsResponse
|
||||||
|
} from "@server/routers/aiProvider/types";
|
||||||
import type { ListAlertRulesResponse } from "@server/routers/alertRule/types";
|
import type { ListAlertRulesResponse } from "@server/routers/alertRule/types";
|
||||||
import type {
|
import type {
|
||||||
QueryRequestAnalyticsResponse,
|
|
||||||
QueryAiUsageFilterOptionsResponse,
|
QueryAiUsageFilterOptionsResponse,
|
||||||
QueryAiUsageOverviewResponse,
|
QueryAiUsageOverviewResponse,
|
||||||
QueryAiUsageProvidersResponse,
|
QueryAiUsageProvidersResponse,
|
||||||
QueryAiUsageResourcesResponse,
|
QueryAiUsageResourcesResponse,
|
||||||
QueryAiUsageUsersRolesResponse,
|
QueryAiUsageUsersRolesResponse,
|
||||||
QueryAiUsageVirtualApiKeysResponse
|
QueryAiUsageVirtualApiKeysResponse,
|
||||||
|
QueryRequestAnalyticsResponse
|
||||||
} from "@server/routers/auditLogs";
|
} from "@server/routers/auditLogs";
|
||||||
import type {
|
import type {
|
||||||
QueryAccessAuditLogResponse,
|
QueryAccessAuditLogResponse,
|
||||||
@@ -34,6 +45,7 @@ import type {
|
|||||||
import type { GetDomainResponse } from "@server/routers/domain/getDomain";
|
import type { GetDomainResponse } from "@server/routers/domain/getDomain";
|
||||||
import { ListHealthChecksResponse } from "@server/routers/healthChecks/types";
|
import { ListHealthChecksResponse } from "@server/routers/healthChecks/types";
|
||||||
import type { ListOrgLabelsResponse } from "@server/routers/labels/types";
|
import type { ListOrgLabelsResponse } from "@server/routers/labels/types";
|
||||||
|
import type { ListLauncherAiModelsResponse } from "@server/routers/launcher/listLauncherAiModels";
|
||||||
import type {
|
import type {
|
||||||
LauncherResource,
|
LauncherResource,
|
||||||
ListLauncherGroupsResponse,
|
ListLauncherGroupsResponse,
|
||||||
@@ -43,9 +55,8 @@ import type {
|
|||||||
ListLauncherSitesResponse,
|
ListLauncherSitesResponse,
|
||||||
ListLauncherViewsResponse
|
ListLauncherViewsResponse
|
||||||
} from "@server/routers/launcher/types";
|
} from "@server/routers/launcher/types";
|
||||||
import type { ListLauncherAiModelsResponse } from "@server/routers/launcher/listLauncherAiModels";
|
|
||||||
import type { ListMyVirtualApiKeysResponse } from "@server/routers/virtualApiKey/types";
|
|
||||||
import type { GetResourcePolicyResponse } from "@server/routers/policy";
|
import type { GetResourcePolicyResponse } from "@server/routers/policy";
|
||||||
|
import type { ListRemoteExitNodesResponse } from "@server/routers/remoteExitNode/types";
|
||||||
import type {
|
import type {
|
||||||
GetResourcePoliciesResponse,
|
GetResourcePoliciesResponse,
|
||||||
GetResourceWhitelistResponse,
|
GetResourceWhitelistResponse,
|
||||||
@@ -59,7 +70,6 @@ import type {
|
|||||||
import type { GetResourceResponse } from "@server/routers/resource/getResource";
|
import type { GetResourceResponse } from "@server/routers/resource/getResource";
|
||||||
import type { GetResourceAuthInfoResponse } from "@server/routers/resource/getResourceAuthInfo";
|
import type { GetResourceAuthInfoResponse } from "@server/routers/resource/getResourceAuthInfo";
|
||||||
import type { ListResourcePoliciesResponse } from "@server/routers/resource/types";
|
import type { ListResourcePoliciesResponse } from "@server/routers/resource/types";
|
||||||
import type { ListRemoteExitNodesResponse } from "@server/routers/remoteExitNode/types";
|
|
||||||
import type { ListRolesResponse } from "@server/routers/role";
|
import type { ListRolesResponse } from "@server/routers/role";
|
||||||
import type { ListSitesResponse } from "@server/routers/site";
|
import type { ListSitesResponse } from "@server/routers/site";
|
||||||
import type {
|
import type {
|
||||||
@@ -71,18 +81,8 @@ import type {
|
|||||||
} from "@server/routers/siteResource";
|
} from "@server/routers/siteResource";
|
||||||
import type { GetSiteResourceResponse } from "@server/routers/siteResource/getSiteResource";
|
import type { GetSiteResourceResponse } from "@server/routers/siteResource/getSiteResource";
|
||||||
import type { ListTargetsResponse } from "@server/routers/target";
|
import type { ListTargetsResponse } from "@server/routers/target";
|
||||||
import type {
|
|
||||||
ListAiModelsResponse,
|
|
||||||
ListAiProvidersResponse,
|
|
||||||
ListCatalogModelsResponse
|
|
||||||
} from "@server/routers/aiProvider/types";
|
|
||||||
import type { AiProviderType } from "@app/lib/aiProviderDefaults";
|
|
||||||
import type { ListAiBudgetsByScopeResponse } from "@server/routers/aiBudget/types";
|
|
||||||
import {
|
|
||||||
getAiBudgetScopeListPath,
|
|
||||||
type AiBudgetScope
|
|
||||||
} from "@app/lib/aiBudgetScope";
|
|
||||||
import type { ListUsersResponse } from "@server/routers/user";
|
import type { ListUsersResponse } from "@server/routers/user";
|
||||||
|
import type { ListMyVirtualApiKeysResponse } from "@server/routers/virtualApiKey/types";
|
||||||
import type ResponseT from "@server/types/Response";
|
import type ResponseT from "@server/types/Response";
|
||||||
import {
|
import {
|
||||||
infiniteQueryOptions,
|
infiniteQueryOptions,
|
||||||
@@ -1000,7 +1000,8 @@ export const httpLogsFiltersSchema = z.object({
|
|||||||
actor: z.string().optional().catch(undefined),
|
actor: z.string().optional().catch(undefined),
|
||||||
method: z.string().optional().catch(undefined),
|
method: z.string().optional().catch(undefined),
|
||||||
reason: z.string().optional().catch(undefined),
|
reason: z.string().optional().catch(undefined),
|
||||||
path: z.string().optional().catch(undefined)
|
path: z.string().optional().catch(undefined),
|
||||||
|
ip: z.array(z.string()).optional().catch(undefined)
|
||||||
});
|
});
|
||||||
|
|
||||||
export type HttpLogFilters = z.output<typeof httpLogsFiltersSchema>;
|
export type HttpLogFilters = z.output<typeof httpLogsFiltersSchema>;
|
||||||
@@ -1026,7 +1027,8 @@ export const accessLogsFiltersSchema = z.object({
|
|||||||
action: z.string().optional().catch(undefined),
|
action: z.string().optional().catch(undefined),
|
||||||
location: z.string().optional().catch(undefined),
|
location: z.string().optional().catch(undefined),
|
||||||
actor: z.string().optional().catch(undefined),
|
actor: z.string().optional().catch(undefined),
|
||||||
type: z.string().optional().catch(undefined)
|
type: z.string().optional().catch(undefined),
|
||||||
|
ip: z.array(z.string()).optional().catch(undefined)
|
||||||
});
|
});
|
||||||
|
|
||||||
export type AccessLogFilters = z.output<typeof accessLogsFiltersSchema>;
|
export type AccessLogFilters = z.output<typeof accessLogsFiltersSchema>;
|
||||||
@@ -1139,10 +1141,13 @@ export const logQueries = {
|
|||||||
queryOptions({
|
queryOptions({
|
||||||
queryKey: ["REQUEST_LOGS", orgId, "ALL", filters] as const,
|
queryKey: ["REQUEST_LOGS", orgId, "ALL", filters] as const,
|
||||||
queryFn: async ({ signal, meta }) => {
|
queryFn: async ({ signal, meta }) => {
|
||||||
const { page, pageSize, ...rest } = filters;
|
const { page, pageSize, ip, ...rest } = filters;
|
||||||
|
const sp = new URLSearchParams(
|
||||||
|
(ip ?? []).map((ip) => ["ip", ip])
|
||||||
|
);
|
||||||
const res = await meta!.api.get<
|
const res = await meta!.api.get<
|
||||||
AxiosResponse<QueryRequestAuditLogResponse>
|
AxiosResponse<QueryRequestAuditLogResponse>
|
||||||
>(`/org/${orgId}/logs/request`, {
|
>(`/org/${orgId}/logs/request?${sp.toString()}`, {
|
||||||
params: {
|
params: {
|
||||||
...rest,
|
...rest,
|
||||||
limit: pageSize,
|
limit: pageSize,
|
||||||
@@ -1164,10 +1169,13 @@ export const logQueries = {
|
|||||||
queryOptions({
|
queryOptions({
|
||||||
queryKey: ["ACCESS_LOGS", orgId, "ALL", filters] as const,
|
queryKey: ["ACCESS_LOGS", orgId, "ALL", filters] as const,
|
||||||
queryFn: async ({ signal, meta }) => {
|
queryFn: async ({ signal, meta }) => {
|
||||||
const { page, pageSize, ...rest } = filters;
|
const { page, pageSize, ip, ...rest } = filters;
|
||||||
|
const sp = new URLSearchParams(
|
||||||
|
(ip ?? []).map((ip) => ["ip", ip])
|
||||||
|
);
|
||||||
const res = await meta!.api.get<
|
const res = await meta!.api.get<
|
||||||
AxiosResponse<QueryAccessAuditLogResponse>
|
AxiosResponse<QueryAccessAuditLogResponse>
|
||||||
>(`/org/${orgId}/logs/access`, {
|
>(`/org/${orgId}/logs/access?${sp.toString()}`, {
|
||||||
params: {
|
params: {
|
||||||
...rest,
|
...rest,
|
||||||
limit: pageSize,
|
limit: pageSize,
|
||||||
|
|||||||
@@ -2,6 +2,7 @@
|
|||||||
|
|
||||||
import { cookies, headers } from "next/headers";
|
import { cookies, headers } from "next/headers";
|
||||||
import { Locale, defaultLocale, locales } from "@/i18n/config";
|
import { Locale, defaultLocale, locales } from "@/i18n/config";
|
||||||
|
import { detectLocale } from "@/i18n/detectLocale";
|
||||||
import { internal } from "@app/lib/api";
|
import { internal } from "@app/lib/api";
|
||||||
import { authCookieHeader } from "@app/lib/api/cookies";
|
import { authCookieHeader } from "@app/lib/api/cookies";
|
||||||
|
|
||||||
@@ -47,12 +48,7 @@ export async function getUserLocale(): Promise<Locale> {
|
|||||||
const acceptLang = headerList.get("accept-language");
|
const acceptLang = headerList.get("accept-language");
|
||||||
|
|
||||||
if (acceptLang) {
|
if (acceptLang) {
|
||||||
const browserLang = acceptLang.split(",")[0];
|
const matched = detectLocale(acceptLang);
|
||||||
const matched = locales.find((locale) =>
|
|
||||||
browserLang
|
|
||||||
.toLowerCase()
|
|
||||||
.startsWith(locale.split("-")[0].toLowerCase())
|
|
||||||
);
|
|
||||||
if (matched) {
|
if (matched) {
|
||||||
return matched;
|
return matched;
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user