port: apply 7 upstream security/robustness patches

Ports from isolated upstream-port branch (base b3c5a4b), verified in
isolation via baseline-vs-port failure-set diff and re-verified live
(195 pass / 0 fail on affected tests):
- redact Discord bot tokens in outbound (router.ts SECRET_PATTERNS)
- block SSRF to private hosts in MoA base URL (moa.ts)
- refuse public dashboard bind without auth token (web-dashboard-server.ts)
- merge upstream .gitignore rules for python/build/secret noise
- real CPU utilization from /proc/stat instead of load avg (unified-dashboard.ts)
- width-safe placeholder for missing usage window on mobile (unified-dashboard.ts)
- bump direct deps to patch known vulnerabilities (discord.js/yaml/cron-parser)

Risky upstream commits (d5a94af phantom reset-time, patch 6 Codex usage)
intentionally skipped to avoid touching the credential-isolation tree.

Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
Codex
2026-08-24 19:35:59 +09:00
parent b3c5a4b41b
commit c016b9c2fa
11 changed files with 393 additions and 205 deletions

View File

@@ -5,7 +5,10 @@ import path from 'path';
import { afterEach, describe, expect, it } from 'vitest';
import type { NewMessage, PairedTask, RegisteredGroup } from './types.js';
import { createWebDashboardHandler } from './web-dashboard-server.js';
import {
assertDashboardAuthPosture,
createWebDashboardHandler,
} from './web-dashboard-server.js';
const tempDirs: string[] = [];
@@ -45,6 +48,36 @@ afterEach(() => {
}
});
describe('assertDashboardAuthPosture', () => {
it('allows loopback binding without a token', () => {
expect(() => assertDashboardAuthPosture('127.0.0.1', '')).not.toThrow();
expect(() => assertDashboardAuthPosture('localhost', '')).not.toThrow();
});
it('allows any host when a token is set', () => {
expect(() => assertDashboardAuthPosture('0.0.0.0', 'secret')).not.toThrow();
expect(() =>
assertDashboardAuthPosture('203.0.113.5', 'secret'),
).not.toThrow();
});
it('warns but starts on a private / tailnet host without a token', () => {
expect(() =>
assertDashboardAuthPosture('100.101.210.95', ''),
).not.toThrow();
expect(() => assertDashboardAuthPosture('192.168.1.10', '')).not.toThrow();
});
it('refuses a public / all-interface bind without a token', () => {
expect(() => assertDashboardAuthPosture('0.0.0.0', '')).toThrow(
/WEB_DASHBOARD_TOKEN/,
);
expect(() => assertDashboardAuthPosture('203.0.113.5', '')).toThrow(
/WEB_DASHBOARD_TOKEN/,
);
});
});
describe('web dashboard server handler', () => {
it('serves health and overview JSON without requiring Discord', async () => {
const handler = createWebDashboardHandler({