mirror of
https://github.com/Termix-SSH/Termix.git
synced 2026-10-09 13:21:47 +00:00
* fix(macos): skip single-instance lock in Mac App Store builds (#1454)
fix(macos): skip single-instance lock in Mac App Store builds
* Fix/backend optional sharp (#1455)
Fix/backend optional sharp
* feat: issue #1218 (#1218)
https://github.com/Termix-SSH/Support/issues/1218
* feat: Add option to use saved global custom theme under Connection Defaults (#1209)
https://github.com/Termix-SSH/Support/issues/1209
* feat: Add Fleet Sharing functionality to the UI (#1228)
https://github.com/Termix-SSH/Support/issues/1228
* feat: Add a list view to the Docker management page (#1237)
https://github.com/Termix-SSH/Support/issues/1237
* feat: issue #1264 (#1264)
https://github.com/Termix-SSH/Support/issues/1264
* feat: 2FA With FortiToken (#1288)
https://github.com/Termix-SSH/Support/issues/1288
* feat: Allow to disable showing paths to folders (#1274)
https://github.com/Termix-SSH/Support/issues/1274
* feat: Sync Network Graph between Desktop and Remote Server (#1245)
https://github.com/Termix-SSH/Support/issues/1245
* feat: Version Number on offline servers (#1291)
https://github.com/Termix-SSH/Support/issues/1291
* feat: Support OrbStack Docker socket path on macOS / Fix "Docker is not installed" on mac... (#1302)
https://github.com/Termix-SSH/Support/issues/1302
* feat: Sidebar host click should focus existing tab instead of opening a new connection (#1289)
https://github.com/Termix-SSH/Support/issues/1289
* fix: Search in side bar shows overlapping hosts when grouped by tags (#1303)
https://github.com/Termix-SSH/Support/issues/1303
* fix: I can't send a file on its own. (#1304)
https://github.com/Termix-SSH/Support/issues/1304
* fix: sudo password not autofilling (#1248)
https://github.com/Termix-SSH/Support/issues/1248
* fix: node-MainThread (#1300)
https://github.com/Termix-SSH/Support/issues/1300
* fix: Tunnel authentication with shared credentials (#1295)
https://github.com/Termix-SSH/Support/issues/1295
* fix: host key updates not syncing, metrics 404 race on first connect
Host key writes never bumped updatedAt so sync never picked them up.
Also retry the first metrics fetch briefly instead of failing right away.
* chore: increment ver
* feat: add category and icon fields to plugin manifest schema
* ci(deps): bump the github-actions group with 2 updates (#1458)
Bumps the github-actions group with 2 updates: [crowdin/github-action](https://github.com/crowdin/github-action) and [actions/github-script](https://github.com/actions/github-script).
Updates `crowdin/github-action` from 2 to 3
- [Release notes](https://github.com/crowdin/github-action/releases)
- [Commits](https://github.com/crowdin/github-action/compare/v2...v3)
Updates `actions/github-script` from 7 to 9
- [Release notes](https://github.com/actions/github-script/releases)
- [Commits](https://github.com/actions/github-script/compare/v7...v9)
---
updated-dependencies:
- dependency-name: crowdin/github-action
dependency-version: '3'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
- dependency-name: actions/github-script
dependency-version: '9'
dependency-type: direct:production
update-type: version-update:semver-major
dependency-group: github-actions
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps-dev): bump the dev-patch-updates group with 13 updates (#1459)
Bumps the dev-patch-updates group with 13 updates:
| Package | From | To |
| --- | --- | --- |
| [@codemirror/commands](https://github.com/codemirror/commands) | `6.11.0` | `6.11.1` |
| [@codemirror/search](https://github.com/codemirror/search) | `6.7.1` | `6.7.2` |
| [@codemirror/view](https://github.com/codemirror/view) | `6.43.9` | `6.43.12` |
| [@testing-library/dom](https://github.com/testing-library/dom-testing-library) | `10.4.1` | `10.4.2` |
| [@testing-library/react](https://github.com/testing-library/react-testing-library) | `16.3.2` | `16.3.3` |
| [@testing-library/user-event](https://github.com/testing-library/user-event) | `14.6.5` | `14.6.7` |
| [@types/ssh2](https://github.com/DefinitelyTyped/DefinitelyTyped/tree/HEAD/types/ssh2) | `1.15.5` | `1.15.6` |
| [@vitejs/plugin-react](https://github.com/vitejs/vite-plugin-react/tree/HEAD/packages/plugin-react) | `6.1.0` | `6.1.1` |
| [cytoscape](https://github.com/cytoscape/cytoscape.js) | `3.34.1` | `3.34.3` |
| [eslint-plugin-react-refresh](https://github.com/ArnaudBarre/eslint-plugin-react-refresh) | `0.5.4` | `0.5.7` |
| [i18next](https://github.com/i18next/i18next) | `26.4.0` | `26.4.2` |
| [prettier](https://github.com/prettier/prettier) | `3.9.6` | `3.9.8` |
| [react-i18next](https://github.com/i18next/react-i18next) | `17.0.12` | `17.0.14` |
Updates `@codemirror/commands` from 6.11.0 to 6.11.1
- [Changelog](https://github.com/codemirror/commands/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/commands/commits)
Updates `@codemirror/search` from 6.7.1 to 6.7.2
- [Changelog](https://github.com/codemirror/search/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/search/commits)
Updates `@codemirror/view` from 6.43.9 to 6.43.12
- [Changelog](https://github.com/codemirror/view/blob/main/CHANGELOG.md)
- [Commits](https://github.com/codemirror/view/commits)
Updates `@testing-library/dom` from 10.4.1 to 10.4.2
- [Release notes](https://github.com/testing-library/dom-testing-library/releases)
- [Changelog](https://github.com/testing-library/dom-testing-library/blob/main/CHANGELOG.md)
- [Commits](https://github.com/testing-library/dom-testing-library/compare/v10.4.1...v10.4.2)
Updates `@testing-library/react` from 16.3.2 to 16.3.3
- [Release notes](https://github.com/testing-library/react-testing-library/releases)
- [Changelog](https://github.com/testing-library/react-testing-library/blob/main/CHANGELOG.md)
- [Commits](https://github.com/testing-library/react-testing-library/compare/v16.3.2...v16.3.3)
Updates `@testing-library/user-event` from 14.6.5 to 14.6.7
- [Release notes](https://github.com/testing-library/user-event/releases)
- [Changelog](https://github.com/testing-library/user-event/blob/main/CHANGELOG.md)
- [Commits](https://github.com/testing-library/user-event/compare/v14.6.5...v14.6.7)
Updates `@types/ssh2` from 1.15.5 to 1.15.6
- [Release notes](https://github.com/DefinitelyTyped/DefinitelyTyped/releases)
- [Commits](https://github.com/DefinitelyTyped/DefinitelyTyped/commits/HEAD/types/ssh2)
Updates `@vitejs/plugin-react` from 6.1.0 to 6.1.1
- [Release notes](https://github.com/vitejs/vite-plugin-react/releases)
- [Changelog](https://github.com/vitejs/vite-plugin-react/blob/main/packages/plugin-react/CHANGELOG.md)
- [Commits](https://github.com/vitejs/vite-plugin-react/commits/plugin-react@6.1.1/packages/plugin-react)
Updates `cytoscape` from 3.34.1 to 3.34.3
- [Release notes](https://github.com/cytoscape/cytoscape.js/releases)
- [Commits](https://github.com/cytoscape/cytoscape.js/compare/v3.34.1...v3.34.3)
Updates `eslint-plugin-react-refresh` from 0.5.4 to 0.5.7
- [Release notes](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/releases)
- [Changelog](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/blob/main/CHANGELOG.md)
- [Commits](https://github.com/ArnaudBarre/eslint-plugin-react-refresh/compare/v0.5.4...v0.5.7)
Updates `i18next` from 26.4.0 to 26.4.2
- [Release notes](https://github.com/i18next/i18next/releases)
- [Changelog](https://github.com/i18next/i18next/blob/master/CHANGELOG.md)
- [Commits](https://github.com/i18next/i18next/compare/v26.4.0...v26.4.2)
Updates `prettier` from 3.9.6 to 3.9.8
- [Release notes](https://github.com/prettier/prettier/releases)
- [Changelog](https://github.com/prettier/prettier/blob/main/CHANGELOG.md)
- [Commits](https://github.com/prettier/prettier/compare/3.9.6...3.9.8)
Updates `react-i18next` from 17.0.12 to 17.0.14
- [Changelog](https://github.com/i18next/react-i18next/blob/master/CHANGELOG.md)
- [Commits](https://github.com/i18next/react-i18next/compare/v17.0.12...v17.0.14)
---
updated-dependencies:
- dependency-name: "@codemirror/commands"
dependency-version: 6.11.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@codemirror/search"
dependency-version: 6.7.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@codemirror/view"
dependency-version: 6.43.12
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@testing-library/dom"
dependency-version: 10.4.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@testing-library/react"
dependency-version: 16.3.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@testing-library/user-event"
dependency-version: 14.6.7
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@types/ssh2"
dependency-version: 1.15.6
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: "@vitejs/plugin-react"
dependency-version: 6.1.1
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: cytoscape
dependency-version: 3.34.3
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: eslint-plugin-react-refresh
dependency-version: 0.5.7
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: i18next
dependency-version: 26.4.2
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: prettier
dependency-version: 3.9.8
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
- dependency-name: react-i18next
dependency-version: 17.0.14
dependency-type: direct:development
update-type: version-update:semver-patch
dependency-group: dev-patch-updates
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* chore(deps): bump the prod-patch-updates group with 6 updates (#1461)
Bumps the prod-patch-updates group with 6 updates:
| Package | From | To |
| --- | --- | --- |
| [@tanstack/react-virtual](https://github.com/TanStack/virtual/tree/HEAD/packages/react-virtual) | `3.14.10` | `3.14.13` |
| [compression](https://github.com/expressjs/compression) | `1.8.1` | `1.8.2` |
| [jose](https://github.com/panva/jose) | `6.2.9` | `6.2.12` |
| [jszip](https://github.com/Stuk/jszip) | `3.10.1` | `3.10.2` |
| [socks](https://github.com/JoshGlazebrook/socks) | `2.8.9` | `2.8.10` |
| [undici](https://github.com/nodejs/undici) | `8.10.0` | `8.10.2` |
Updates `@tanstack/react-virtual` from 3.14.10 to 3.14.13
- [Release notes](https://github.com/TanStack/virtual/releases)
- [Changelog](https://github.com/TanStack/virtual/blob/main/packages/react-virtual/CHANGELOG.md)
- [Commits](https://github.com/TanStack/virtual/commits/@tanstack/react-virtual@3.14.13/packages/react-virtual)
Updates `compression` from 1.8.1 to 1.8.2
- [Release notes](https://github.com/expressjs/compression/releases)
- [Changelog](https://github.com/expressjs/compression/blob/master/HISTORY.md)
- [Commits](https://github.com/expressjs/compression/compare/v1.8.1...v1.8.2)
Updates `jose` from 6.2.9 to 6.2.12
- [Release notes](https://github.com/panva/jose/releases)
- [Changelog](https://github.com/panva/jose/blob/main/CHANGELOG.md)
- [Commits](https://github.com/panva/jose/compare/v6.2.9...v6.2.12)
Updates `jszip` from 3.10.1 to 3.10.2
- [Changelog](https://github.com/Stuk/jszip/blob/main/CHANGES.md)
- [Commits](https://github.com/Stuk/jszip/compare/v3.10.1...v3.10.2)
Updates `socks` from 2.8.9 to 2.8.10
- [Release notes](https://github.com/JoshGlazebrook/socks/releases)
- [Commits](https://github.com/JoshGlazebrook/socks/compare/2.8.9...2.8.10)
Updates `undici` from 8.10.0 to 8.10.2
- [Release notes](https://github.com/nodejs/undici/releases)
- [Commits](https://github.com/nodejs/undici/compare/v8.10.0...v8.10.2)
---
updated-dependencies:
- dependency-name: "@tanstack/react-virtual"
dependency-version: 3.14.13
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: compression
dependency-version: 1.8.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: jose
dependency-version: 6.2.12
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: jszip
dependency-version: 3.10.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: socks
dependency-version: 2.8.10
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
- dependency-name: undici
dependency-version: 8.10.2
dependency-type: direct:production
update-type: version-update:semver-patch
dependency-group: prod-patch-updates
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* feat: add plugin worker protocol, bootstrap and plugin_storage table
Worker-side ctx proxy plus the message envelope it talks over, and the
per-plugin key/value table behind ctx.storage with migrations for all
three dialects. Rows cascade with the plugin so uninstalling leaves
nothing behind.
* feat: add allowlisted host view for plugins
An allowlist rather than a list of fields to strip. A blocklist rots:
the moment a new secret-bearing column lands on SSHHost it starts
leaking silently. With an allowlist a new field stays invisible to
plugins until someone adds it here on purpose.
* feat: add plugin loader with manifest validation and crash restart
Validates an unpacked plugin, spawns a worker_threads worker and manages
activate/deactivate/crash-restart with backoff, disabling after three
tries.
The crash counter clears only after a plugin stays up past a stability
window, not on activation. Clearing it on activation let a plugin that
activates cleanly and then dies restart forever, because every attempt
looked like the first.
loader.ts documents what the worker boundary does and does not buy you.
Node's permission model is process-wide, not per-worker, so it cannot be
enabled for plugin workers alone and is not claimed here.
* feat: route internal events through a shared plugin event bus
Formalises three ad-hoc publish paths that already existed:
automation-events.ts, metrics/automation-bridge.ts and the
hostSessionStatus singleton, now the host.session.status topic.
Both invariants the old code relied on are preserved. Publishing stays
fire-and-forget, so a failing subscriber cannot disturb a metrics poll or
a host delete. The automations engine subscribes to the bus at scheduler
start instead of being imported ad hoc, which keeps the edge
one-directional: automations may import repositories, hosts modules must
not import automations.
* feat: add plugin ctx broker with permission gate and audit
Every ctx call a plugin makes is checked against its granted
capabilities, performed by the main thread, then audited. A capability
must be both declared in the manifest and granted in the database, so
widening a plugin's reach always needs a new manifest the user can see,
never just a database row.
Audit attribution is set by the broker, not the plugin. The plugin
supplies only the details, so it cannot forge the actor.
fix: stop plugin workers seeing plaintext credentials in error messages
A failing ctx.ssh.connect handed the worker the raw error from deep in
the SSH stack, which embeds the connect config. The worker received, in
full:
Authentication failed for root using password <SECRET>
where <SECRET> was the host's real plaintext password. Any plugin with
ssh.exec could read it by catching the error, defeating the whole point
of the handle-based ssh API.
Errors crossing the boundary are now sanitised. Only PluginFacingError
and PluginPermissionError, both authored here, reach a plugin verbatim;
anything else becomes a generic message and the real one goes to the
log. This uses a marker class rather than matching on message text,
because matching would start leaking again the moment an upstream error
happened to contain a familiar phrase.
Covered by credential-isolation.test.ts, which plants a sentinel in
every secret-bearing field and asserts it appears in no message the
worker ever receives.
* feat: dispatch plugin HTTP routes and wire the runtime into startup
ctx.http.route now registers a real router on the /plugin-api/:pluginId
dispatcher, replacing its stub 404. A plugin never touches the Express
req/res: it gets a plain summary and returns a plain object, so sockets
and session cookies stay on this side of the boundary. Authorization and
cookie headers are not forwarded.
Plugins load last in the start-up sequence, after the server is fully
wired, and are terminated before the database on shutdown so none can
outlive it. A plugin that fails to load cannot stop the backend.
fix: correct the nginx plugin-api location regex
The pattern was ^/plugin-api/(/.*)?$, which needs a double slash and so
never matched /plugin-api/<id>/<route>. Every other block in the file
uses ^/prefix(/.*)?$. Left alone, plugin routes would work in dev and
404 only behind Docker.
* fix: update stale SFTP transfer test for single file destination paths
The test still asserted transferToHost was called with the destination
directory "/srv". Commit 7727fa09 (#1304) deliberately changed a single
file transfer to send the full destination path including the filename,
so the correct expectation is "/srv/remote-1.txt". The code was right
and the test was left behind.
* feat: ship the ssh terminal as a first-party in-process plugin
Adds a hardcoded process:transport-owner tier so the terminal can own its
WebSocket server and ssh2 clients, which cannot cross the worker boundary.
* feat: ship docker as a first-party in-process plugin
Moves docker backend and frontend into plugins/docker/, alongside
ssh-terminal. Adds a host editor tab seam, a dashboard card registry,
and a build step to compile plugin backends into dist.
* feat: ship host metrics as a first-party in-process plugin
* fix: harden plugin auth and add per-request identity for ctx calls
Require auth on /plugin-api, gate plugin enable/grant/revoke routes
behind admin.plugins.manage, and thread the calling user through
worker ctx.hosts/ctx.ssh calls instead of always using the install
owner. Also adds the plugin permissions grant/revoke UI.
* feat: ship the AI assistant as a first-party in-process plugin
Moves src/backend/ai and its routes into plugins/ai, mounted through a
small /ai dispatcher instead of its own port. Moves the ai-enabled and
ai-private-endpoints settings routes out of user-settings-routes.ts
into the plugin too, so it has no leftover core dependents.
* fix: remove compiled plugin JS left behind in plugins/ after build
copy-bundled-plugins.cjs compiled and rewrote plugin backend TS in
place, copied it to dist/plugins, but never deleted the .js it had
just emitted next to the .ts sources. Those files shadowed the real
source for vitest/tsx and had import paths rewritten for the dist
layout, so tests failed with "Cannot find module" once a local build
had run. Affects docker, host-metrics and ai, not just this one.
* feat: add a permission-gated backend service registry for plugins
* feat: add a permission-gated UI action registry and action slots for plugins
Moves the terminal toolbar's hardwired AI button into a slot the ssh-terminal
plugin offers and the ai plugin fills, gated on ai.services.use.
* feat: add cross-plugin secret references gated by the provider's RBAC permission
* feat: move proxmox discovery/import/sync into a first-party plugin
* feat: move remote desktop (RDP/VNC/Telnet) into a first-party plugin
Relocates guacamole backend/frontend source and tests into
plugins/remote-desktop, following the ssh-terminal/docker pattern.
* feat: wire remote-desktop plugin into core and rename i18n keys
Repoints core consumers (dispatcher, collab, session-sharing, tab
utils) at the plugin, adds isTabTypeAvailable gating for rdp/vnc/
telnet, widens hostCapability to accept an array, and renames the
guacamole i18n namespace to remoteDesktop.
* feat: move fleets into a first-party plugin
* feat: move automations into a first-party plugin
* feat: remove legacy alert rules, superseded by automations
Alert rules already auto-migrate into automations on boot and the old
engine stands down after. Deletes the rule/firing tables, routes, UI,
and AI tools; keeps notification channels since automations still use
them. Also fixes automations' notify step, which still called the
deleted repository.
* feat: move network topology into a first-party plugin
* feat: move tailscale device discovery and settings into a plugin
Adds plugins/tailscale/ with a devices sidebar tab, admin settings
section, and re-auth dialog. Host Metrics tailscale manager card and
SSH re-auth banner parsing stay in core.
* feat: move workspaces into a first-party plugin
* feat: move web endpoint into a first-party plugin
* feat: collapse plugin runtime to one tier behind a plugin SDK
* feat: make each plugin an npm workspace built by a termix-plugin CLI
* feat: give plugins their own tables, migrations and sync entities
* feat: serve plugin http and websockets from one mount instead of ports
* feat: namespace plugin permissions and keep them valid when a plugin is off
* feat: give plugins their own settings and one settings screen
* feat: load plugin frontends at runtime and remove plugin ids from the shell
* fix: mock the ai status fetch in its activate test
* feat: add auth extension points and one ssh connect pipeline
* feat: rebuild workspaces as the reference plugin
* fix: gate second factors after SSO/LDAP behind an admin setting
* feat: convert network-topology to a full plugin (B1)
* feat: move snippets backend and tables into a plugin (B2)
* feat: point core frontend snippets pickers at the plugin (B2)
* feat: add the snippets plugin (B2)
* feat: wire ai, automations, fleets and ssh-terminal to snippets (B2)
* feat: finish the tailscale plugin, including SSH auth (B3)
* feat: finish the fleets plugin, add ctx.hosts and host-commands SDK (B4)
* chore: update proxmox and host-metrics locale files for B5
* chore: regenerate drizzle migration journals for B5
* feat: add ctx.hosts create/update to the SDK, host-metrics drops proxmox
* feat: move proxmox node stats and collectors into the proxmox plugin
* feat: drop proxmox host columns, use plugin settings instead
* feat: finish the fleets plugin, add ctx.hosts and host-commands SDK (B4)
* feat: convert file manager into a plugin
* feat: convert ssh tunnels into a plugin
* feat: finish the web-endpoint plugin, add ctx.desktop (B8)
* feat: move the terminal fully into the ssh-terminal plugin (B9)
* feat: convert tmux monitoring into a plugin (B10)
* feat: convert serial console into the serial plugin
* feat: move session sharing and collab rooms into a plugin (B12)
* feat: turn session recording into a plugin (B13)
* feat: finish the remote-desktop plugin (B14)
* feat: finish the host-metrics plugin, move host status into core (B16)
* feat: finish the docker plugin (B15)
* feat: finish the automations plugin (B17)
* feat: finish the ai plugin (B18)
* feat: finish the homepage plugin, move service links and canvas out of core (B19)
* feat: convert wake-on-lan into a plugin (B20)
* feat: convert secret-sources into a plugin (B20)
* feat: move totp and passkeys into plugins (C1)
* feat: move sso and ldap logins into plugins (C2)
* feat: move opkssh and warpgate into plugins (C3)
* feat: move step-ca into a plugin (C4)
* feat: move vault ssh signing into a plugin (C5)
* feat: move termix identity into a plugin (C6)
* feat: move acme certificate automation into a plugin (C7)
* fix: finish 2.9.0 plugin moves and get every check green
* chore: lock the plugin boundary and remove 2.9.0 leftovers
* fix: harden the plugin runtime after the 2.9.0 security review
* feat: add plugin packing, signing, pinned trust and tmxplug bundling
* test: prove 2.8 to 2.9.0 upgrade is lossless and fix what it caught
* fix: give bundled plugin backends a real require for CJS deps
* feat: improve UI loading time and jitter
* feat: show credential sharing inline in the sidebar like host sharing
* feat: tailscale add host and copy ip, fix outbound fetch hang and plugin ESM warning
* feat: unify alerts into one plugin, channels, rules and inbox
* feat: rebuild desktop sync as linked server accounts, fix packaged plugin bundles and UI scaling
* fix: set blacksmith builder cache-key to stop broken gha cache fallback
* fix: link plugin-sdk workspace before npm ci in docker deps stage
* fix: link every plugin workspace before npm ci in docker deps stage
* fix(host-metrics): exclude image and firmware filesystems (#1469)
* fix(host-metrics): exclude image and firmware filesystems
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(hosts): normalize imported jump host references (#1470)
* fix(hosts): normalize imported jump host references
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(ci): build plugin SDK and repair MySQL settings migration (#1471)
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(file-manager): keep inline rename consistent (#1476)
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(file-manager): keep inline rename consistent
* fix(dashboard): reuse translated host status labels (#1475)
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(dashboard): reuse translated host status labels
* docs(api): clarify local and remote version fields (#1474)
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* docs(api): clarify local and remote version fields
* fix(file-manager): preserve selected backgrounds on hover (#1473)
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(file-manager): preserve selection feedback on hover
* test(ui): await dialog focus cleanup before teardown
* fix(file-manager): restore Ctrl/Cmd+F file search (#1472)
* fix(ci): build plugin SDK before dependent checks
* fix(mysql): keep plugin settings scope indexes within limits
* test(mysql): refresh reviewed plugin upgrade SQL
* fix(file-manager): focus file search with Ctrl or Cmd F
* fix: keep rounded-full circular in production builds
* fix(file-manager): cancel uploads and stop remote writes (#1477)
* fix(file-manager): cancel uploads and stop remote writes
* test(css): exercise the configured PostCSS plugin chain
* fix(file-manager): apply compact density to directory tree (#1478)
* fix(file-manager): apply compact density to directory tree
* test(css): exercise the configured PostCSS plugin chain
* fix(file-manager): preserve font sizes in compact mode (#1480)
* fix(file-manager): preserve font sizes in compact mode
* test(css): exercise the configured PostCSS plugin chain
* fix(file-manager): prioritize file names in narrow lists (#1483)
* fix(file-manager): prioritize file names in narrow lists
* test(css): exercise the configured PostCSS plugin chain
* test(identity): preserve full Ed25519 public keys in fixtures
* test(remote-desktop): always mutate ciphertext in tamper test
* fix(remote-desktop): probe the saved host guacd endpoint (#1481)
* fix(remote-desktop): probe the saved host guacd endpoint
* test(css): exercise the configured PostCSS plugin chain
* test(identity): preserve full Ed25519 public keys in fixtures
* fix(homepage): check allowlisted private service reachability (#1479)
* fix(homepage): check allowlisted private service reachability
* test(css): exercise the configured PostCSS plugin chain
* fix(remote-desktop): stop unsolicited clipboard read prompts (#1482)
* fix(remote-desktop): read clipboard only on explicit paste
* test(css): exercise the configured PostCSS plugin chain
* test(identity): preserve full Ed25519 public keys in fixtures
* test(remote-desktop): always mutate ciphertext in tamper test
* chore: simplify plugin readmes, changelogs and manifest descriptions
* fix: keep plugins loaded after signing in from the login screen
* fix(file-manager): accept OS file drops over existing rows (#1484)
* fix(file-manager): accept OS file drops over existing rows
* test(file-manager): target the file label in drop tests
* test(css): exercise the configured PostCSS plugin chain
* test(identity): preserve full Ed25519 public keys in fixtures
* test(remote-desktop): always mutate ciphertext in tamper test
* fix(file-manager): pipeline SFTP download reads (#1485)
* feat: add plugin sdk build to beta release
* fix: make link-store secret check immune to random base64 matches
* fix(ldap): preserve the directory-provided bind DN (#1486)
* fix: compute beta changes across dev branches and move the beta tag
* chore: untrack plugin sdk ARCHITECTURE.md
* chore: remove references to plugin sdk ARCHITECTURE.md
* feat: merge host editor terminal tabs into one owned by ssh-terminal
* feat: add descriptions to plugin host enable toggles
* fix(file-manager): show download progress in file viewers (#1487)
* fix(electron): signal backend readiness over IPC (#1488)
* fix(split-screen): allow layout creation without randomUUID (#1490)
* fix(split-screen): allow layout creation without randomUUID
* test(credentials): avoid flaky Ed25519 key generation
* fix(sidebar): remeasure visible rows after density changes (#1489)
* fix(sidebar): remeasure visible rows after density changes
* test(credentials): avoid flaky Ed25519 key generation
* feat(split-screen): redesign split screen with free-form panes and pane picker
* feat(sidebar): add host click behavior setting, default to always opening a new tab
* feat(snippets): redesign panel to match the host list
* fix(session-recording): stop session logs panel from refetching in a loop
* feat(snippets): bring back sharing, target hosts and drag reorder
* feat(ssh-terminal): add toolbar position, start state, display and fade host settings
* feat(ssh-terminal): add host setting to turn off password prompt auto-fill
* fix(ai): stop streams getting cut off and keep tool steps across messages
* feat: improve quick connect system using plugin api
* fix: proxmox guest sync, startup snippet sync, drop dead cloudflare ssh transport
* feat: move terminal settings, look and ssh tools into ssh-terminal plugin
* feat: move snippets, keybinding actions and macros out of core into plugins
* feat: store rdp, vnc and telnet logins in a generic per-protocol table
* feat: type the plugin host record, move plugin strings out of core and add lint checks
* feat: replace core homepage widget registry with generic extension points
* feat: plugins only see their own host settings in the browser
* feat: harden plugin api for separate repos, signed updates and generic external login
* fix: keep plugin css below core utilities and version plugin assets by their css
* fix: load and save plugin host settings in the editor and tighten settings row spacing
* feat: redesign user host defaults system
* fix(remote-desktop): release held keys on focus loss (#1498)
* fix(session-sharing): replace local presentation after takeover (#1500)
* fix(file-manager): refresh disk usage with directory listing (#1503)
* fix(ssh-terminal): preserve input order during local echo reconciliation (#1505)
* feat(remote-desktop): expose display zoom controls for RDP (#1514)
* fix(file-manager): restore text selection and copying in Markdown previews (#1518)
* fix(sidebar): keep compact host addresses visible (#1524)
* fix(hosts): preserve plugin settings when reopening the editor (#1499)
* fix(ssh-terminal): close owner sockets when presentations unmount (#1501)
* fix(session-sharing): synchronize shared SSH terminal dimensions (#1502)
* fix(session-sharing): show participant presence in member terminals (#1504)
* fix(ai): sync provider configuration and keys across linked devices (#1506)
* feat(ssh-terminal): add a duplicate tab action (#1510)
* feat(file-manager): allow disabling move-to-trash confirmation (#1511)
* feat(file-manager): default to the remote login directory (#1512)
* feat(homepage): synchronize canvas layouts across devices (#1515)
* fix(shortcuts): prevent accidental double-Shift palette activation (#1519)
* feat(tmux-monitor): add a unified multi-host view (#1520)
* fix(electron): allow explicit quit with active connections (#1522)
* feat: reconnect all disconnected terminal tabs (#1523)
* fix(hosts): preserve recording and sharing settings in the dev editor (#1509)
* fix(database): preserve RDP domain during startup backfill (#1497)
* feat(sidebar): add keyboard type-ahead search for hosts (#1516)
* feat(automations): add per-host maintenance mode and recurring schedules (#1521)
* feat(tmux): add a per-host mouse toggle and preserve remote configuration (#1513)
* fix(session-sharing): use the linked server for desktop meetings and links (#1507)
* fix(tunnels): support TOTP for client tunnels and jump hosts (#1508)
* fix: type errors and lint failures from merged plugin prs
* feat(installer): make the Windows desktop shortcut optional (#1517)
* fix: ship the plugin sdk and serialport in desktop builds
* fix: prefer ipv4 when resolving ssh host names (#1365)
* fix: readable terminal selection with the light theme (#1319)
* fix: build desktop session share links on the linked server (#1350)
* fix: show meeting guests to members and hide the roster from guests (#1353)
* fix: reliable file manager saves with sudo prompt and no base64 guessing (#1335)
* fix: show disk usage for the mount being browsed (#1347)
* fix: load the linux tray icon reliably and log tray failures (#1332)
* fix: cover the gnome close path in the desktop quit test (#1332)
* fix: prompt for jump host TOTP in terminal, file manager and metrics (#1312)
* feat: optional auto reconnect for dropped ssh sessions (#1321)
* feat: tighter compact host rows with inline tags (#1325)
* feat: bring back the alert feed homepage widget
* feat: pick target terminals for snippets again
* feat: share button on connection tabs again
* feat: recent servers list when linking the desktop app
* feat: list the fixed app shortcuts in keyboard shortcuts
* fix: translate hardcoded toasts and drop em dashes from ui text
* fix: translate leftover hardcoded ui text
* fix: toolbar files button opens at the shell directory again
* fix: show the remote desktop note under connection origin again
* chore: openapi docs for host metrics manager routes
* chore: openapi docs for undocumented routes and fix two broken doc blocks
* fix: declare terminal.listSessions use for snippet targets
* revert: drop the alert feed widget, the notification center replaces it
* feat: restore the alert feed homepage widget
* fix: quick connect fills the host address from plugin auth editors like tailscale
* fix: docker container logs use the base background color
* chore: fix dependabot alerts and apply safe npm upgrades
* fix: proxmox stats tab reads its switch from plugin host settings
* fix: count plugin ssh logins toward host status and stop showing reachable as a warning
* fix: hide the built-in source pill in the host editor
* fix: host status shows online when the port answers and only warns on a failed login
* fix: drop the top border on the split layout menu
* fix: host defaults tabs sit where the host editor puts them and skip plugins with nothing to default
* fix: remote desktop auth method labels and notes for vnc and telnet
* fix: add description to the web endpoint enable switch
* fix: crowdin sync and pretranslate for plugin locales, run plugin tests on release
* feat: move telemetry out of core into a usage statistics plugin
* fix: recent activity card no longer cuts off host names early
* fix: remove duplicate top border on split screen menu
* fix: redesign session log player controls, fix tooltip overlap and drop dot separators
* fix: file manager and sftp text showing raw i18n keys
* fix: onboarding rerunning for existing users after upgrading
* fix: fleet detail buttons overflowing the sidebar
* fix: session log player scrolling off screen horizontally
* fix: network graph lag when adding hosts and on every render
* fix: maintenance index name, shared host read only view and badge polling
* fix: meeting tabs, workspace tab merging, rail panels as tabs and general ui lag
* chore: update release notes
* fix: remote desktop tabs reconnecting on every tab switch
* fix: build plugin sdk before linting in release workflow
* chore: lint, format, and bump version to 2.9.0
* chore: skip crowdin pre-translate in release for now
* chore: sync Crowdin translations for 2.9.0
---------
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: Koi <38512047+datlt4@users.noreply.github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>
1059 lines
33 KiB
JavaScript
1059 lines
33 KiB
JavaScript
// Local filesystem access + streamed local<->remote transfers for the
|
|
// desktop app's dual-pane file manager.
|
|
//
|
|
// The renderer has no Node access (contextIsolation), so browsing the user's
|
|
// own disk and moving bytes between it and the backend has to happen here.
|
|
// Uploads/downloads are streamed through Electron's `net` stack against the
|
|
// same file-manager HTTP routes the renderer already uses, so nothing is ever
|
|
// buffered whole in memory.
|
|
//
|
|
// Trust boundary: the renderer never supplies a URL or headers. It names an
|
|
// origin ("local" | "remote") and a route from a fixed allowlist; the main
|
|
// process resolves the actual Termix backend URL and attaches credentials
|
|
// itself (session cookies for the embedded backend, the linked server's
|
|
// session). Nothing here can be pointed at another host.
|
|
|
|
const fs = require("fs");
|
|
const fsp = require("fs/promises");
|
|
const os = require("os");
|
|
const path = require("path");
|
|
const { URL } = require("url");
|
|
|
|
const IPC = {
|
|
HOME: "local-fs:home",
|
|
LIST: "local-fs:list",
|
|
MKDIR: "local-fs:mkdir",
|
|
CREATE_FILE: "local-fs:create-file",
|
|
RENAME: "local-fs:rename",
|
|
TRASH: "local-fs:trash",
|
|
ENSURE_DIR: "local-fs:ensure-dir",
|
|
EXISTS: "local-fs:exists",
|
|
WALK: "local-fs:walk",
|
|
REVEAL: "local-fs:reveal",
|
|
OPEN: "local-fs:open",
|
|
UPLOAD: "local-transfer:upload",
|
|
DOWNLOAD: "local-transfer:download",
|
|
CANCEL: "local-transfer:cancel",
|
|
PROGRESS: "local-transfer:progress",
|
|
SET_API: "local-transfer:set-api",
|
|
};
|
|
|
|
const READ_CHUNK_BYTES = 1024 * 1024;
|
|
const PROGRESS_INTERVAL_MS = 150;
|
|
|
|
const activeTransfers = new Map();
|
|
|
|
function isAbsoluteLocalPath(candidate) {
|
|
return typeof candidate === "string" && path.isAbsolute(candidate);
|
|
}
|
|
|
|
function normalizeLocalPath(candidate) {
|
|
if (!isAbsoluteLocalPath(candidate)) {
|
|
throw new Error("A local absolute path is required");
|
|
}
|
|
return path.normalize(candidate);
|
|
}
|
|
|
|
function isHiddenEntry(name) {
|
|
return name.startsWith(".");
|
|
}
|
|
|
|
// A single path segment: no separators, not "." / "..", no NULs.
|
|
function requireEntryName(name, what) {
|
|
const safeName = String(name || "").trim();
|
|
if (
|
|
!safeName ||
|
|
safeName === "." ||
|
|
safeName === ".." ||
|
|
/[\/\\\0]/.test(safeName)
|
|
) {
|
|
throw new Error(`Invalid ${what}`);
|
|
}
|
|
return safeName;
|
|
}
|
|
|
|
// Asserts that `candidate` (already absolute) lies strictly inside `root`
|
|
// after normalisation on the *current* platform. `pathImpl` is injectable so
|
|
// the Windows rules can be exercised in tests on any OS. Traversal that
|
|
// survives normalisation ("..\\x" is a plain file name on POSIX but a parent
|
|
// reference on Windows) is caught here, as are absolute / drive-qualified
|
|
// names that path.join or path.resolve would let take over.
|
|
function assertWithinRoot(rootPath, candidate, pathImpl = path) {
|
|
if (typeof rootPath !== "string" || !rootPath.trim()) {
|
|
throw new LocalFileError("EINVAL", "A download folder is required");
|
|
}
|
|
const root = pathImpl.normalize(pathImpl.resolve(rootPath));
|
|
const target = pathImpl.normalize(pathImpl.resolve(candidate));
|
|
const rel = pathImpl.relative(root, target);
|
|
const escapes =
|
|
rel === "" ||
|
|
rel === ".." ||
|
|
rel.startsWith(`..${pathImpl.sep}`) ||
|
|
pathImpl.isAbsolute(rel) ||
|
|
// A different drive on Windows yields an absolute relative path; a UNC
|
|
// or drive-qualified segment must never survive either.
|
|
rel.split(pathImpl.sep).some((seg) => seg === ".." || seg === "");
|
|
if (escapes) {
|
|
throw new LocalFileError(
|
|
"EINVAL",
|
|
`"${pathImpl.basename(candidate)}" would be written outside the selected folder`,
|
|
);
|
|
}
|
|
return target;
|
|
}
|
|
|
|
// Resolve a deliberately selected linked root once, but never follow links
|
|
// supplied as descendants of a downloaded tree.
|
|
async function prepareDownloadPath(rootPath, candidate, directory = false) {
|
|
const target = assertWithinRoot(rootPath, normalizeLocalPath(candidate));
|
|
const selected = path.resolve(rootPath);
|
|
const realRoot = await fsp.realpath(selected);
|
|
if (!(await fsp.stat(realRoot)).isDirectory()) {
|
|
throw new LocalFileError("EINVAL", "The download root is not a directory");
|
|
}
|
|
const parts = path.relative(selected, target).split(path.sep);
|
|
let current = realRoot;
|
|
for (let i = 0; i < parts.length; i++) {
|
|
current = path.join(current, parts[i]);
|
|
const needsDirectory = directory || i < parts.length - 1;
|
|
if (needsDirectory) {
|
|
await fsp.mkdir(current).catch((error) => {
|
|
if (error.code !== "EEXIST") throw error;
|
|
});
|
|
}
|
|
const stat = await fsp.lstat(current).catch((error) => {
|
|
if (error.code === "ENOENT" && !needsDirectory) return null;
|
|
throw error;
|
|
});
|
|
if (stat?.isSymbolicLink()) {
|
|
throw new LocalFileError(
|
|
"EINVAL",
|
|
"Downloads cannot follow links inside the selected folder",
|
|
);
|
|
}
|
|
if (needsDirectory && !stat.isDirectory()) {
|
|
throw new LocalFileError(
|
|
"ENOTDIR",
|
|
"A download parent is not a directory",
|
|
);
|
|
}
|
|
}
|
|
return { root: realRoot, path: current };
|
|
}
|
|
|
|
async function pathExists(target) {
|
|
try {
|
|
await fsp.lstat(target);
|
|
return true;
|
|
} catch {
|
|
return false;
|
|
}
|
|
}
|
|
|
|
async function describeEntry(dirPath, dirent) {
|
|
const entryPath = path.join(dirPath, dirent.name);
|
|
let type = "file";
|
|
let size = 0;
|
|
let modifiedTimestamp;
|
|
let linkTarget;
|
|
|
|
try {
|
|
if (dirent.isSymbolicLink()) {
|
|
type = "link";
|
|
try {
|
|
linkTarget = await fsp.readlink(entryPath);
|
|
} catch {
|
|
// dangling or unreadable link
|
|
}
|
|
// Follow the link so a symlinked directory still navigates like one.
|
|
try {
|
|
const target = await fsp.stat(entryPath);
|
|
if (target.isDirectory()) type = "directory";
|
|
size = target.size;
|
|
modifiedTimestamp = target.mtimeMs;
|
|
} catch {
|
|
const own = await fsp.lstat(entryPath);
|
|
modifiedTimestamp = own.mtimeMs;
|
|
}
|
|
} else if (dirent.isDirectory()) {
|
|
type = "directory";
|
|
const stat = await fsp.stat(entryPath);
|
|
modifiedTimestamp = stat.mtimeMs;
|
|
} else {
|
|
const stat = await fsp.stat(entryPath);
|
|
size = stat.size;
|
|
modifiedTimestamp = stat.mtimeMs;
|
|
}
|
|
} catch {
|
|
// Unreadable entry: still list it so the user sees it exists.
|
|
}
|
|
|
|
return {
|
|
name: dirent.name,
|
|
path: entryPath,
|
|
type,
|
|
size,
|
|
modifiedTimestamp,
|
|
linkTarget,
|
|
hidden: isHiddenEntry(dirent.name),
|
|
};
|
|
}
|
|
|
|
async function listDirectory(dirPath) {
|
|
const resolved = normalizeLocalPath(dirPath);
|
|
const dirents = await fsp.readdir(resolved, { withFileTypes: true });
|
|
const entries = await Promise.all(
|
|
dirents.map((dirent) => describeEntry(resolved, dirent)),
|
|
);
|
|
const parent = path.dirname(resolved);
|
|
return {
|
|
path: resolved,
|
|
parent: parent === resolved ? null : parent,
|
|
entries,
|
|
};
|
|
}
|
|
|
|
// Expands a set of dropped local paths into the flat list of files (with
|
|
// paths relative to the drop root) plus any empty directories, mirroring what
|
|
// the browser's FileSystemEntry walker produces for OS drops.
|
|
async function walkPaths(rootPaths) {
|
|
const files = [];
|
|
const emptyDirs = [];
|
|
let totalBytes = 0;
|
|
|
|
async function walkDir(absDir, relDir) {
|
|
const dirents = await fsp.readdir(absDir, { withFileTypes: true });
|
|
if (dirents.length === 0) {
|
|
emptyDirs.push(relDir);
|
|
return;
|
|
}
|
|
for (const dirent of dirents) {
|
|
const abs = path.join(absDir, dirent.name);
|
|
const rel = `${relDir}/${dirent.name}`;
|
|
if (dirent.isDirectory()) {
|
|
await walkDir(abs, rel);
|
|
} else if (dirent.isFile()) {
|
|
const stat = await fsp.stat(abs);
|
|
files.push({ localPath: abs, relativePath: rel, size: stat.size });
|
|
totalBytes += stat.size;
|
|
} else if (dirent.isSymbolicLink()) {
|
|
// Upload what the link points at, if it is a regular file.
|
|
try {
|
|
const stat = await fsp.stat(abs);
|
|
if (stat.isFile()) {
|
|
files.push({ localPath: abs, relativePath: rel, size: stat.size });
|
|
totalBytes += stat.size;
|
|
}
|
|
} catch {
|
|
// dangling link: skip
|
|
}
|
|
}
|
|
}
|
|
}
|
|
|
|
for (const rootPath of rootPaths) {
|
|
const abs = normalizeLocalPath(rootPath);
|
|
const stat = await fsp.stat(abs);
|
|
const name = path.basename(abs);
|
|
if (stat.isDirectory()) {
|
|
await walkDir(abs, name);
|
|
} else if (stat.isFile()) {
|
|
files.push({ localPath: abs, relativePath: name, size: stat.size });
|
|
totalBytes += stat.size;
|
|
}
|
|
}
|
|
|
|
return { files, emptyDirs, totalBytes };
|
|
}
|
|
|
|
function toHeaderMap(headers) {
|
|
const out = {};
|
|
if (!headers || typeof headers !== "object") return out;
|
|
for (const [key, value] of Object.entries(headers)) {
|
|
if (value === undefined || value === null) continue;
|
|
out[key] = String(value);
|
|
}
|
|
return out;
|
|
}
|
|
|
|
function makeProgressReporter(sender, transferId) {
|
|
let lastSentAt = 0;
|
|
return (transferred, total, force = false) => {
|
|
const now = Date.now();
|
|
if (!force && now - lastSentAt < PROGRESS_INTERVAL_MS) return;
|
|
lastSentAt = now;
|
|
if (sender.isDestroyed()) return;
|
|
sender.send(IPC.PROGRESS, { transferId, transferred, total });
|
|
};
|
|
}
|
|
|
|
function collectBody(response) {
|
|
return new Promise((resolve) => {
|
|
const chunks = [];
|
|
response.on("data", (chunk) => chunks.push(chunk));
|
|
response.on("end", () => resolve(Buffer.concat(chunks).toString("utf8")));
|
|
response.on("error", () => resolve(""));
|
|
});
|
|
}
|
|
|
|
function describeHttpError(statusCode, bodyText) {
|
|
try {
|
|
const parsed = JSON.parse(bodyText);
|
|
if (parsed && typeof parsed.error === "string") return parsed.error;
|
|
if (parsed && typeof parsed.message === "string") return parsed.message;
|
|
} catch {
|
|
// not JSON
|
|
}
|
|
return bodyText?.trim() || `Request failed with status ${statusCode}`;
|
|
}
|
|
|
|
function writeToRequest(request, chunk) {
|
|
return new Promise((resolve, reject) => {
|
|
try {
|
|
request.write(chunk, () => resolve());
|
|
} catch (error) {
|
|
reject(error);
|
|
}
|
|
});
|
|
}
|
|
|
|
const TRANSFER_ROUTES = Object.freeze({
|
|
uploadFileStream: "/uploadFileStream",
|
|
downloadFileStream: "/downloadFileStream",
|
|
});
|
|
|
|
const DEVICE_ID_PATTERN = /^[A-Za-z0-9._:-]{1,128}$/;
|
|
// A compact JWT (base64url segments joined by dots); anything else is refused.
|
|
const AUTH_TOKEN_PATTERN = /^[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+\.[A-Za-z0-9_-]+$/;
|
|
|
|
// The plugin that serves the two streaming routes tells us its /plugin-api/
|
|
// path, so nothing here names it. Only a /plugin-api/<id> path is accepted,
|
|
// which keeps every transfer on the backend's plugin routes.
|
|
const API_PATH_PATTERN = /^\/plugin-api\/[a-z0-9][a-z0-9-]*$/;
|
|
const LOCAL_BACKEND = "http://localhost:30001";
|
|
let registeredApiPath = null;
|
|
|
|
function setTransferApiPath(apiPath) {
|
|
if (typeof apiPath !== "string" || !API_PATH_PATTERN.test(apiPath)) {
|
|
throw new Error("Invalid transfer API path");
|
|
}
|
|
registeredApiPath = apiPath;
|
|
}
|
|
|
|
function normalizeHttpBase(candidate, what) {
|
|
let parsed;
|
|
try {
|
|
parsed = new URL(String(candidate || ""));
|
|
} catch {
|
|
throw new Error(`${what} is not a valid URL`);
|
|
}
|
|
if (parsed.protocol !== "http:" && parsed.protocol !== "https:") {
|
|
throw new Error(`${what} must use http or https`);
|
|
}
|
|
return parsed.toString().replace(/\/$/, "");
|
|
}
|
|
|
|
// Resolves where a transfer may go. Only the two file-manager streaming
|
|
// routes are reachable, and only on the embedded backend or the linked
|
|
// server; credentials come from the main process, not the caller.
|
|
function createTargetResolver({ localBaseUrl, getLinkedServer, apiPath }) {
|
|
const resolveApiPath = () => {
|
|
const resolved = apiPath ?? registeredApiPath;
|
|
if (!resolved)
|
|
throw new Error("Local file transfers are not available yet");
|
|
return resolved;
|
|
};
|
|
return function resolveTransferTarget({
|
|
origin,
|
|
route,
|
|
deviceId,
|
|
authToken,
|
|
} = {}) {
|
|
const routePath = TRANSFER_ROUTES[route];
|
|
if (!routePath) {
|
|
throw new Error(`Unknown transfer route: ${String(route)}`);
|
|
}
|
|
|
|
const headers = { "X-Electron-App": "true" };
|
|
if (deviceId !== undefined && deviceId !== null && deviceId !== "") {
|
|
if (typeof deviceId !== "string" || !DEVICE_ID_PATTERN.test(deviceId)) {
|
|
throw new Error("Invalid device id");
|
|
}
|
|
headers["X-Termix-Device-ID"] = deviceId;
|
|
}
|
|
|
|
if (origin === "local") {
|
|
// The desktop renderer authenticates against the embedded backend with
|
|
// the token it keeps in localStorage (see the Electron branch of the
|
|
// axios request interceptor), and the `jwt` cookie only exists for a
|
|
// while after an interactive login. Send that same token here, so a
|
|
// transfer does not depend on a cookie the rest of the app no longer
|
|
// needs; the session cookie still rides along as a fallback. The
|
|
// renderer already uses this token on every request it makes itself,
|
|
// so forwarding it grants nothing new, and the URL stays ours.
|
|
if (authToken !== undefined && authToken !== null && authToken !== "") {
|
|
if (
|
|
typeof authToken !== "string" ||
|
|
authToken.length > 8192 ||
|
|
!AUTH_TOKEN_PATTERN.test(authToken)
|
|
) {
|
|
throw new Error("Invalid auth token");
|
|
}
|
|
headers.Authorization = `Bearer ${authToken}`;
|
|
}
|
|
return {
|
|
url: `${normalizeHttpBase(
|
|
localBaseUrl ?? `${LOCAL_BACKEND}${resolveApiPath()}`,
|
|
"Local backend URL",
|
|
)}${routePath}`,
|
|
headers,
|
|
};
|
|
}
|
|
|
|
if (origin === "remote") {
|
|
const linked =
|
|
typeof getLinkedServer === "function" ? getLinkedServer() : null;
|
|
if (!linked || !linked.serverUrl) {
|
|
throw new Error("This device is not linked to a server");
|
|
}
|
|
const base = normalizeHttpBase(linked.serverUrl, "Linked server URL");
|
|
if (linked.token) headers.Authorization = `Bearer ${linked.token}`;
|
|
return { url: `${base}${resolveApiPath()}${routePath}`, headers };
|
|
}
|
|
|
|
throw new Error(`Unknown transfer origin: ${String(origin)}`);
|
|
};
|
|
}
|
|
|
|
function createNetRequest(net, event, method, url) {
|
|
return net.request({
|
|
method,
|
|
url,
|
|
session: event.sender.session,
|
|
useSessionCookies: true,
|
|
});
|
|
}
|
|
|
|
// Streams one local file to the backend's multipart `uploadFileStream` route.
|
|
async function uploadLocalFile({ net, resolveTransferTarget }, event, options) {
|
|
const {
|
|
transferId,
|
|
origin,
|
|
deviceId,
|
|
authToken,
|
|
fields,
|
|
localPath,
|
|
fileName,
|
|
} = options || {};
|
|
|
|
if (!transferId || !localPath) {
|
|
throw new Error("Missing upload parameters");
|
|
}
|
|
const { url, headers } = resolveTransferTarget({
|
|
origin,
|
|
route: "uploadFileStream",
|
|
deviceId,
|
|
authToken,
|
|
});
|
|
|
|
const absPath = normalizeLocalPath(localPath);
|
|
const stat = await fsp.stat(absPath);
|
|
if (!stat.isFile()) {
|
|
throw new Error("Only regular files can be uploaded");
|
|
}
|
|
|
|
const boundary = `----TermixLocalUpload${Date.now()}${Math.random()
|
|
.toString(36)
|
|
.slice(2)}`;
|
|
const safeName = String(fileName || path.basename(absPath))
|
|
.replace(/[\r\n]/g, " ")
|
|
.replace(/"/g, "%22");
|
|
|
|
let preamble = "";
|
|
for (const [key, value] of Object.entries(fields || {})) {
|
|
if (value === undefined || value === null) continue;
|
|
preamble +=
|
|
`--${boundary}\r\n` +
|
|
`Content-Disposition: form-data; name="${key}"\r\n\r\n` +
|
|
`${String(value)}\r\n`;
|
|
}
|
|
preamble +=
|
|
`--${boundary}\r\n` +
|
|
`Content-Disposition: form-data; name="file"; filename="${safeName}"\r\n` +
|
|
`Content-Type: application/octet-stream\r\n\r\n`;
|
|
const epilogue = `\r\n--${boundary}--\r\n`;
|
|
|
|
const preambleBuffer = Buffer.from(preamble, "utf8");
|
|
const epilogueBuffer = Buffer.from(epilogue, "utf8");
|
|
|
|
const request = createNetRequest(net, event, "POST", url);
|
|
for (const [key, value] of Object.entries(toHeaderMap(headers))) {
|
|
request.setHeader(key, value);
|
|
}
|
|
request.setHeader(
|
|
"Content-Type",
|
|
`multipart/form-data; boundary=${boundary}`,
|
|
);
|
|
// Without chunked encoding Electron buffers the whole body in the main
|
|
// process before sending; chunked keeps memory flat for multi-GB files.
|
|
// Busboy on the backend parses the multipart stream incrementally either way.
|
|
request.chunkedEncoding = true;
|
|
|
|
const report = makeProgressReporter(event.sender, transferId);
|
|
const readStream = fs.createReadStream(absPath, {
|
|
highWaterMark: READ_CHUNK_BYTES,
|
|
});
|
|
|
|
const state = {
|
|
cancelled: false,
|
|
abort: () => {
|
|
state.cancelled = true;
|
|
readStream.destroy();
|
|
request.abort();
|
|
},
|
|
};
|
|
activeTransfers.set(transferId, state);
|
|
|
|
// The server may answer early (auth failure, missing session) while the
|
|
// body is still streaming; stop pushing bytes as soon as it does.
|
|
let responded = false;
|
|
const responsePromise = new Promise((resolve, reject) => {
|
|
request.on("response", async (response) => {
|
|
responded = true;
|
|
const bodyText = await collectBody(response);
|
|
resolve({ statusCode: response.statusCode, bodyText });
|
|
});
|
|
request.on("error", (error) => reject(error));
|
|
request.on("abort", () => reject(new Error("Transfer cancelled")));
|
|
});
|
|
// Avoid an unhandled rejection if we bail out before awaiting below.
|
|
responsePromise.catch(() => {});
|
|
|
|
// A write callback never fires once the request has errored or been
|
|
// aborted, so every write races against the response promise's rejection.
|
|
const write = (chunk) =>
|
|
Promise.race([writeToRequest(request, chunk), responsePromise]);
|
|
|
|
try {
|
|
await write(preambleBuffer);
|
|
let sent = 0;
|
|
for await (const chunk of readStream) {
|
|
if (state.cancelled) throw new Error("Transfer cancelled");
|
|
if (responded) break;
|
|
await write(chunk);
|
|
sent += chunk.length;
|
|
report(sent, stat.size);
|
|
}
|
|
if (!responded) {
|
|
await write(epilogueBuffer);
|
|
request.end();
|
|
}
|
|
|
|
const { statusCode, bodyText } = await responsePromise;
|
|
if (statusCode < 200 || statusCode >= 300) {
|
|
throw new Error(describeHttpError(statusCode, bodyText));
|
|
}
|
|
report(stat.size, stat.size, true);
|
|
return { success: true, bytes: stat.size };
|
|
} catch (error) {
|
|
readStream.destroy();
|
|
throw error;
|
|
} finally {
|
|
activeTransfers.delete(transferId);
|
|
}
|
|
}
|
|
|
|
class LocalFileError extends Error {
|
|
constructor(code, message) {
|
|
super(message);
|
|
this.name = "LocalFileError";
|
|
this.code = code;
|
|
}
|
|
}
|
|
|
|
// Destinations with a download in flight, so two transfers can never race
|
|
// each other onto the same file.
|
|
const activeDestinations = new Set();
|
|
|
|
function partialPathFor(absDest, transferId) {
|
|
const token = String(transferId)
|
|
.replace(/[^A-Za-z0-9_-]/g, "")
|
|
.slice(0, 48);
|
|
return `${absDest}.${token || "transfer"}.termix-part`;
|
|
}
|
|
|
|
// File operations used to publish a download, injectable so the replace
|
|
// strategy can be tested against Windows-like semantics (where rename() onto
|
|
// an existing name fails) without running on Windows.
|
|
const defaultPublishFs = Object.freeze({
|
|
rename: (from, to) => fsp.rename(from, to),
|
|
link: (from, to) => fsp.link(from, to),
|
|
copyFileExcl: (from, to) =>
|
|
fsp.copyFile(from, to, fs.constants.COPYFILE_EXCL),
|
|
rm: (target) => fsp.rm(target, { force: true }),
|
|
lstat: (target) => fsp.lstat(target),
|
|
});
|
|
|
|
function replacedPathFor(absDest, transferId) {
|
|
const token = String(transferId)
|
|
.replace(/[^A-Za-z0-9_-]/g, "")
|
|
.slice(0, 48);
|
|
return `${absDest}.${token || "transfer"}.termix-replaced`;
|
|
}
|
|
|
|
// Puts `sourcePath` under `absDest` without ever replacing an existing file:
|
|
// link() is atomic and fails with EEXIST if the name is taken; filesystems
|
|
// without hard links fall back to an exclusive copy. The source is removed
|
|
// once the destination exists.
|
|
async function publishExclusive(io, sourcePath, absDest) {
|
|
const exists = () =>
|
|
new LocalFileError("EEXIST", `"${path.basename(absDest)}" already exists`);
|
|
try {
|
|
await io.link(sourcePath, absDest);
|
|
} catch (error) {
|
|
if (error && error.code === "EEXIST") throw exists();
|
|
try {
|
|
await io.copyFileExcl(sourcePath, absDest);
|
|
} catch (copyError) {
|
|
if (copyError && copyError.code === "EEXIST") throw exists();
|
|
throw copyError;
|
|
}
|
|
}
|
|
await io.rm(sourcePath);
|
|
}
|
|
|
|
// Replaces `absDest` with the finished partial. rename() over an existing
|
|
// file is not portable: POSIX replaces it, but on Windows the call commonly
|
|
// fails (EEXIST / EPERM, always when the file is open), so the swap never
|
|
// renames onto an occupied name. Instead:
|
|
// 1. move the current file aside to a transfer-unique sibling
|
|
// (renaming to a fresh name is safe everywhere);
|
|
// 2. publish the partial exclusively under the now-free name;
|
|
// 3. delete the aside copy.
|
|
// If step 1 fails nothing has changed and the caller gets EBUSY. If step 2
|
|
// fails the aside copy is moved back, so the original survives.
|
|
async function replaceExisting(io, partialPath, absDest, transferId) {
|
|
let current;
|
|
try {
|
|
current = await io.lstat(absDest);
|
|
} catch (error) {
|
|
if (error && error.code === "ENOENT") {
|
|
// Nothing to replace after all (the file went away meanwhile).
|
|
await publishExclusive(io, partialPath, absDest);
|
|
return;
|
|
}
|
|
throw error;
|
|
}
|
|
if (current.isDirectory()) {
|
|
throw new LocalFileError(
|
|
"EISDIR",
|
|
`"${path.basename(absDest)}" is a folder and cannot be replaced by a file`,
|
|
);
|
|
}
|
|
|
|
const asidePath = replacedPathFor(absDest, transferId);
|
|
try {
|
|
await io.rename(absDest, asidePath);
|
|
} catch (error) {
|
|
if (
|
|
error &&
|
|
(error.code === "EPERM" ||
|
|
error.code === "EBUSY" ||
|
|
error.code === "EACCES")
|
|
) {
|
|
throw new LocalFileError(
|
|
"EBUSY",
|
|
`"${path.basename(absDest)}" is in use and could not be replaced`,
|
|
);
|
|
}
|
|
throw error;
|
|
}
|
|
|
|
try {
|
|
await publishExclusive(io, partialPath, absDest);
|
|
} catch (error) {
|
|
// Put the original back under its name; the partial is cleaned up by
|
|
// the caller.
|
|
await io.rm(absDest).catch(() => {});
|
|
await io.rename(asidePath, absDest).catch(() => {});
|
|
throw error;
|
|
}
|
|
|
|
// The old contents are no longer reachable under the real name; removing
|
|
// the aside copy can still fail on Windows if another process holds it
|
|
// open, so retry once before giving up and leaving it for the user.
|
|
try {
|
|
await io.rm(asidePath);
|
|
} catch {
|
|
await new Promise((resolve) => setTimeout(resolve, 100));
|
|
await io.rm(asidePath).catch((error) => {
|
|
console.warn(
|
|
`[local-files] replaced "${absDest}" but could not remove the previous copy at "${asidePath}": ${error && error.message}`,
|
|
);
|
|
});
|
|
}
|
|
}
|
|
|
|
// Moves a finished partial file onto its final name. Without `overwrite` the
|
|
// publish is exclusive: an existing file is never replaced, even if it
|
|
// appeared while the download was running. With `overwrite` the existing file
|
|
// is swapped out in a way that also works on Windows.
|
|
async function publishDownload(
|
|
partialPath,
|
|
absDest,
|
|
overwrite,
|
|
transferId,
|
|
io = defaultPublishFs,
|
|
) {
|
|
if (overwrite) {
|
|
await replaceExisting(io, partialPath, absDest, transferId);
|
|
return;
|
|
}
|
|
await publishExclusive(io, partialPath, absDest);
|
|
}
|
|
|
|
// Streams one remote file (via the backend's `downloadFileStream` route) into
|
|
// a local destination. Bytes go to a transfer-unique temp sibling first and
|
|
// are published under the real name only on success, so a failed transfer
|
|
// never leaves a truncated file behind. Existing files are refused unless
|
|
// the caller explicitly asked to overwrite.
|
|
async function downloadToLocal(
|
|
{ net, resolveTransferTarget, publishFs },
|
|
event,
|
|
options,
|
|
) {
|
|
const {
|
|
transferId,
|
|
origin,
|
|
deviceId,
|
|
authToken,
|
|
body,
|
|
destPath,
|
|
rootPath,
|
|
expectedSize,
|
|
} = options || {};
|
|
const overwrite = options?.overwrite === true;
|
|
|
|
if (!transferId || !destPath) {
|
|
throw new Error("Missing download parameters");
|
|
}
|
|
const { url, headers } = resolveTransferTarget({
|
|
origin,
|
|
route: "downloadFileStream",
|
|
deviceId,
|
|
authToken,
|
|
});
|
|
|
|
// The renderer builds destPath from remote names; never trust that it
|
|
// stayed inside the folder the user picked.
|
|
const destination = await prepareDownloadPath(rootPath, destPath);
|
|
const absDest = destination.path;
|
|
if (activeDestinations.has(absDest)) {
|
|
throw new LocalFileError(
|
|
"EBUSY",
|
|
`"${path.basename(absDest)}" is already being downloaded`,
|
|
);
|
|
}
|
|
activeDestinations.add(absDest);
|
|
|
|
const partialPath = partialPathFor(
|
|
path.join(destination.root, path.basename(absDest)),
|
|
transferId,
|
|
);
|
|
const report = makeProgressReporter(event.sender, transferId);
|
|
const state = {
|
|
cancelled: false,
|
|
abort: () => {
|
|
state.cancelled = true;
|
|
request.abort();
|
|
},
|
|
};
|
|
let request = null;
|
|
|
|
try {
|
|
if (!overwrite && (await pathExists(absDest))) {
|
|
throw new LocalFileError(
|
|
"EEXIST",
|
|
`"${path.basename(absDest)}" already exists`,
|
|
);
|
|
}
|
|
|
|
request = createNetRequest(net, event, "POST", url);
|
|
for (const [key, value] of Object.entries(toHeaderMap(headers))) {
|
|
request.setHeader(key, value);
|
|
}
|
|
const payload = Buffer.from(JSON.stringify(body || {}), "utf8");
|
|
request.setHeader("Content-Type", "application/json");
|
|
// No explicit Content-Length: Electron's net module forbids apps from
|
|
// setting it (the request fails with net::ERR_INVALID_ARGUMENT) and
|
|
// computes it itself from the buffered body when chunked encoding is off.
|
|
activeTransfers.set(transferId, state);
|
|
|
|
await new Promise((resolve, reject) => {
|
|
let settled = false;
|
|
const fail = (error) => {
|
|
if (settled) return;
|
|
settled = true;
|
|
reject(error);
|
|
};
|
|
|
|
request.on("error", fail);
|
|
request.on("abort", () => fail(new Error("Transfer cancelled")));
|
|
request.on("response", (response) => {
|
|
const statusCode = response.statusCode;
|
|
if (statusCode < 200 || statusCode >= 300) {
|
|
collectBody(response).then((bodyText) =>
|
|
fail(new Error(describeHttpError(statusCode, bodyText))),
|
|
);
|
|
return;
|
|
}
|
|
|
|
const lengthHeader = response.headers["content-length"];
|
|
const total =
|
|
Number(
|
|
Array.isArray(lengthHeader) ? lengthHeader[0] : lengthHeader,
|
|
) ||
|
|
Number(expectedSize) ||
|
|
undefined;
|
|
|
|
// "wx": the temp name is ours alone; refuse to reuse a stale one.
|
|
const writeStream = fs.createWriteStream(partialPath, { flags: "wx" });
|
|
let received = 0;
|
|
|
|
response.on("data", (chunk) => {
|
|
received += chunk.length;
|
|
const ok = writeStream.write(chunk);
|
|
if (!ok) {
|
|
response.pause();
|
|
writeStream.once("drain", () => response.resume());
|
|
}
|
|
report(received, total);
|
|
});
|
|
response.on("end", () => {
|
|
writeStream.end(() => {
|
|
report(received, total ?? received, true);
|
|
if (settled) return;
|
|
settled = true;
|
|
resolve();
|
|
});
|
|
});
|
|
response.on("error", (error) => {
|
|
writeStream.destroy();
|
|
fail(error);
|
|
});
|
|
writeStream.on("error", (error) => {
|
|
request.abort();
|
|
fail(error);
|
|
});
|
|
});
|
|
|
|
request.end(payload);
|
|
});
|
|
|
|
await prepareDownloadPath(destination.root, absDest);
|
|
await publishDownload(
|
|
partialPath,
|
|
absDest,
|
|
overwrite,
|
|
transferId,
|
|
publishFs || defaultPublishFs,
|
|
);
|
|
return { success: true, path: absDest };
|
|
} catch (error) {
|
|
await fsp.rm(partialPath, { force: true }).catch(() => {});
|
|
throw error;
|
|
} finally {
|
|
activeTransfers.delete(transferId);
|
|
activeDestinations.delete(absDest);
|
|
}
|
|
}
|
|
|
|
function wrap(handler) {
|
|
return async (event, ...args) => {
|
|
try {
|
|
const result = await handler(event, ...args);
|
|
return { success: true, ...(result || {}) };
|
|
} catch (error) {
|
|
return {
|
|
success: false,
|
|
error: error && error.message ? error.message : String(error),
|
|
code: error && error.code ? error.code : undefined,
|
|
};
|
|
}
|
|
};
|
|
}
|
|
|
|
// Builds the IPC handler map from injected dependencies so the whole boundary
|
|
// can be exercised in tests with a Node http shim instead of Electron.
|
|
function createLocalFileHandlers({
|
|
net,
|
|
shell,
|
|
getLinkedServer,
|
|
localBaseUrl,
|
|
publishFs,
|
|
}) {
|
|
if (!net || typeof net.request !== "function") {
|
|
throw new Error("createLocalFileHandlers requires a net implementation");
|
|
}
|
|
const resolveTransferTarget = createTargetResolver({
|
|
localBaseUrl,
|
|
getLinkedServer,
|
|
});
|
|
const deps = {
|
|
net,
|
|
resolveTransferTarget,
|
|
publishFs: publishFs || defaultPublishFs,
|
|
};
|
|
|
|
return {
|
|
[IPC.SET_API]: wrap(async (_event, apiPath) => {
|
|
setTransferApiPath(apiPath);
|
|
return {};
|
|
}),
|
|
|
|
[IPC.HOME]: wrap(async () => ({
|
|
home: os.homedir(),
|
|
separator: path.sep,
|
|
platform: process.platform,
|
|
})),
|
|
|
|
[IPC.LIST]: wrap(async (_event, dirPath) => listDirectory(dirPath)),
|
|
|
|
[IPC.MKDIR]: wrap(async (_event, parentPath, name) => {
|
|
const parent = normalizeLocalPath(parentPath);
|
|
const safeName = requireEntryName(name, "folder name");
|
|
const target = path.join(parent, safeName);
|
|
await fsp.mkdir(target);
|
|
return { path: target };
|
|
}),
|
|
|
|
[IPC.CREATE_FILE]: wrap(async (_event, parentPath, name) => {
|
|
const parent = normalizeLocalPath(parentPath);
|
|
const safeName = requireEntryName(name, "file name");
|
|
const target = path.join(parent, safeName);
|
|
// "wx" fails if the file already exists rather than truncating it.
|
|
await fsp.writeFile(target, "", { flag: "wx" });
|
|
return { path: target };
|
|
}),
|
|
|
|
[IPC.RENAME]: wrap(async (_event, oldPath, newName) => {
|
|
const source = normalizeLocalPath(oldPath);
|
|
const safeName = requireEntryName(newName, "name");
|
|
const target = path.join(path.dirname(source), safeName);
|
|
if (target === source) return { path: source };
|
|
if (await pathExists(target)) {
|
|
throw new LocalFileError("EEXIST", `"${safeName}" already exists`);
|
|
}
|
|
await fsp.rename(source, target);
|
|
return { path: target };
|
|
}),
|
|
|
|
// Moves entries to the OS trash (Finder Trash / Recycle Bin) rather than
|
|
// deleting outright, so a mis-click in the file manager is recoverable.
|
|
[IPC.TRASH]: wrap(async (_event, targetPaths) => {
|
|
if (!Array.isArray(targetPaths) || targetPaths.length === 0) {
|
|
throw new Error("No local paths provided");
|
|
}
|
|
const failed = [];
|
|
for (const candidate of targetPaths) {
|
|
const target = normalizeLocalPath(candidate);
|
|
try {
|
|
await shell.trashItem(target);
|
|
} catch (error) {
|
|
failed.push({
|
|
path: target,
|
|
error: error && error.message ? error.message : String(error),
|
|
});
|
|
}
|
|
}
|
|
return { trashed: targetPaths.length - failed.length, failed };
|
|
}),
|
|
|
|
[IPC.ENSURE_DIR]: wrap(async (_event, dirPath, rootPath) => {
|
|
let target = normalizeLocalPath(dirPath);
|
|
// Transfers pass the folder the user picked; the directory skeleton of
|
|
// a downloaded tree must stay inside it.
|
|
if (rootPath !== undefined) {
|
|
target = (await prepareDownloadPath(rootPath, target, true)).path;
|
|
} else {
|
|
await fsp.mkdir(target, { recursive: true });
|
|
}
|
|
return { path: target };
|
|
}),
|
|
|
|
// Which of the given paths already exist; lets the renderer ask about
|
|
// collisions before a batch download starts.
|
|
[IPC.EXISTS]: wrap(async (_event, targetPaths) => {
|
|
if (!Array.isArray(targetPaths)) {
|
|
throw new Error("Expected a list of paths");
|
|
}
|
|
const existing = [];
|
|
for (const candidate of targetPaths) {
|
|
const target = normalizeLocalPath(candidate);
|
|
if (await pathExists(target)) existing.push(target);
|
|
}
|
|
return { existing };
|
|
}),
|
|
|
|
[IPC.WALK]: wrap(async (_event, rootPaths) => {
|
|
if (!Array.isArray(rootPaths) || rootPaths.length === 0) {
|
|
throw new Error("No local paths provided");
|
|
}
|
|
return walkPaths(rootPaths);
|
|
}),
|
|
|
|
[IPC.REVEAL]: wrap(async (_event, targetPath) => {
|
|
shell.showItemInFolder(normalizeLocalPath(targetPath));
|
|
}),
|
|
|
|
[IPC.OPEN]: wrap(async (_event, targetPath) => {
|
|
const error = await shell.openPath(normalizeLocalPath(targetPath));
|
|
if (error) throw new Error(error);
|
|
}),
|
|
|
|
[IPC.UPLOAD]: wrap((event, options) =>
|
|
uploadLocalFile(deps, event, options),
|
|
),
|
|
|
|
[IPC.DOWNLOAD]: wrap((event, options) =>
|
|
downloadToLocal(deps, event, options),
|
|
),
|
|
|
|
[IPC.CANCEL]: wrap(async (_event, transferId) => {
|
|
const state = activeTransfers.get(transferId);
|
|
if (!state) return { cancelled: false };
|
|
state.abort();
|
|
return { cancelled: true };
|
|
}),
|
|
};
|
|
}
|
|
|
|
function registerLocalFileHandlers({ ipcMain, shell }) {
|
|
// Real Electron wiring; tests build the handlers directly instead.
|
|
const { net } = require("electron");
|
|
const { getLinkedServer } = require("./linked-server.cjs");
|
|
const handlers = createLocalFileHandlers({
|
|
net,
|
|
shell,
|
|
getLinkedServer,
|
|
});
|
|
for (const [channel, handler] of Object.entries(handlers)) {
|
|
ipcMain.handle(channel, handler);
|
|
}
|
|
}
|
|
|
|
module.exports = {
|
|
IPC,
|
|
TRANSFER_ROUTES,
|
|
registerLocalFileHandlers,
|
|
// exported for tests / reuse
|
|
createLocalFileHandlers,
|
|
createTargetResolver,
|
|
setTransferApiPath,
|
|
publishDownload,
|
|
defaultPublishFs,
|
|
assertWithinRoot,
|
|
walkPaths,
|
|
listDirectory,
|
|
};
|