port: apply 7 upstream security/robustness patches
Ports from isolated upstream-port branch (base b3c5a4b), verified in
isolation via baseline-vs-port failure-set diff and re-verified live
(195 pass / 0 fail on affected tests):
- redact Discord bot tokens in outbound (router.ts SECRET_PATTERNS)
- block SSRF to private hosts in MoA base URL (moa.ts)
- refuse public dashboard bind without auth token (web-dashboard-server.ts)
- merge upstream .gitignore rules for python/build/secret noise
- real CPU utilization from /proc/stat instead of load avg (unified-dashboard.ts)
- width-safe placeholder for missing usage window on mobile (unified-dashboard.ts)
- bump direct deps to patch known vulnerabilities (discord.js/yaml/cron-parser)
Risky upstream commits (d5a94af phantom reset-time, patch 6 Codex usage)
intentionally skipped to avoid touching the credential-isolation tree.
Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
This commit is contained in:
@@ -5,7 +5,10 @@ import path from 'path';
|
||||
import { afterEach, describe, expect, it } from 'vitest';
|
||||
|
||||
import type { NewMessage, PairedTask, RegisteredGroup } from './types.js';
|
||||
import { createWebDashboardHandler } from './web-dashboard-server.js';
|
||||
import {
|
||||
assertDashboardAuthPosture,
|
||||
createWebDashboardHandler,
|
||||
} from './web-dashboard-server.js';
|
||||
|
||||
const tempDirs: string[] = [];
|
||||
|
||||
@@ -45,6 +48,36 @@ afterEach(() => {
|
||||
}
|
||||
});
|
||||
|
||||
describe('assertDashboardAuthPosture', () => {
|
||||
it('allows loopback binding without a token', () => {
|
||||
expect(() => assertDashboardAuthPosture('127.0.0.1', '')).not.toThrow();
|
||||
expect(() => assertDashboardAuthPosture('localhost', '')).not.toThrow();
|
||||
});
|
||||
|
||||
it('allows any host when a token is set', () => {
|
||||
expect(() => assertDashboardAuthPosture('0.0.0.0', 'secret')).not.toThrow();
|
||||
expect(() =>
|
||||
assertDashboardAuthPosture('203.0.113.5', 'secret'),
|
||||
).not.toThrow();
|
||||
});
|
||||
|
||||
it('warns but starts on a private / tailnet host without a token', () => {
|
||||
expect(() =>
|
||||
assertDashboardAuthPosture('100.101.210.95', ''),
|
||||
).not.toThrow();
|
||||
expect(() => assertDashboardAuthPosture('192.168.1.10', '')).not.toThrow();
|
||||
});
|
||||
|
||||
it('refuses a public / all-interface bind without a token', () => {
|
||||
expect(() => assertDashboardAuthPosture('0.0.0.0', '')).toThrow(
|
||||
/WEB_DASHBOARD_TOKEN/,
|
||||
);
|
||||
expect(() => assertDashboardAuthPosture('203.0.113.5', '')).toThrow(
|
||||
/WEB_DASHBOARD_TOKEN/,
|
||||
);
|
||||
});
|
||||
});
|
||||
|
||||
describe('web dashboard server handler', () => {
|
||||
it('serves health and overview JSON without requiring Discord', async () => {
|
||||
const handler = createWebDashboardHandler({
|
||||
|
||||
Reference in New Issue
Block a user