Files
Luke GustafsonandZacharyZcR 6b708106e1 release-2.9.1 (#1557)
* fix(sso): send the PKCE verifier for GitHub login (#1534)

* fix(remote-desktop): clip cursor overflow without disabling zoom (#1535)

* test(remote-desktop): preserve sessions beyond one hour (#1536)

* fix(hosts): expose controls for overflowing editor tabs (#1537)

* fix(hosts): expose controls for overflowing editor tabs

* test(hosts): mock resize observation in admin panel tests

* fix(status): skip TCP probes while host sessions are active (#1538)

* fix(database): batch session activity persistence (#1539)

* docs(api): describe cookie and API key authentication (#1540)

* fix(snippets): repair missing note column on SQLite upgrades (#1541)

* fix(docker): retain stored SSH credential association (#1543)

* fix(file-manager): render transfer toasts without plugin hooks (#1546)

* feat(hosts): keep compact row actions inline (#1547)

* fix(auth): allow retrying unavailable second-factor interfaces (#1549)

* fix(auth): reject unresolved legacy identity provisioning (#1550)

* fix(desktop): ship the plugin SDK inside Mac App Store builds (#1551)

* fix(tmux): pass full session info to the terminal's session picker (#1552)

The tmux.sessions service reduced detected sessions to bare names, but the
picker reads session.name, so every entry rendered blank and selecting one
sent an empty name, which created a new session instead of attaching.

* fix(ssh): read force keyboard-interactive as a boolean when resolving hosts (#1553)

The column holds the text "true"/"false", and the resolver passed it
through as-is. The string "false" is truthy, so the password provider
treated every saved host as forced keyboard-interactive and left the
password out. Jump hops are built straight from the resolved host, so a
password hop whose server doesn't offer keyboard-interactive failed with
"All configured authentication methods failed".

* fix(database): batch database saves for bulk host writes (#1554)

* fix(database): yield to the event loop between database saves

Each SQLite save serializes and encrypts the whole database into new
buffers, which V8 only releases once the event loop turns. Boot
migrations and bulk host import write plugin settings per host and per
key in an awaited loop, so hundreds of full copies piled up and the
container ran out of memory.

* fix(database): save once per bulk host write instead of once per row

On SQLite every repository write force-saves the whole database. Boot
plugin data migrations, host defaults materialization and the bulk
host routes write one row per host per setting, so they serialized and
encrypted the full database hundreds of times in a row.

DatabaseSaveTrigger.batched wraps a function so force saves made while
it runs collapse into a single save when it finishes. Nested scopes fold
into the outer one, and work that outlives its scope saves normally.

* feat(hosts): add instance-wide predefined tag suggestions (#1548)

* feat(hosts): add shared predefined tag suggestions

* style(hosts): format tag catalog routes

* test(database): advance fake timers past the save yield (#1555)

* fix(i18n): complete Simplified Chinese core and plugin translations (#1542)

* fix(i18n): complete Chinese onboarding and navigation labels

* fix(i18n): translate remaining Chinese core and plugin interfaces

* fix(i18n): translate host editor tab overflow controls

* fix(i18n): use consistent Chinese fleet terminology

* fix(i18n): localize hardcoded controls and plugin views

* fix(i18n): translate built-in homepage widget catalog

* test(homepage): follow translated timezone placeholder

* fix(i18n): translate plugin-provided homepage widgets

* fix(i18n): localize feature settings section titles

* fix: 2.8 oidc accounts unable to sign in after upgrading (#1381)

* fix: plugins losing the saved ssh login when copying a host (#1391)

* fix: fleets, proxmox and automations not getting the host sudo password

* fix: host imports running a defaults pass and metrics restart per host (#1384)

* fix: high cpu from status probes and full database saves on every sample (#1300)

* fix: user data export freezing the server (#1393)

* fix: op:// secret references rejected as ssh keys on credentials (#1394)

* fix: slow file deletes from the trash lookups on every delete (#1390)

* fix: add openapi docs and error handling to host tag routes

* test: compare download stream buffers directly so it stops timing out

* chore: drop em dash from host row comment

* chore: update release notes for 2.9.1

* fix: restore space to add host tags and redesign predefined tags editor

* fix: host key silently accepted when the host is missing from the database (#1397)

* fix: clearer host login failed status label and fix its translations (#1396)

* chore: add host key and status label fixes to release notes

* fix: sso and ldap provider dialogs overflowing the screen and using mismatched toggles

* chore: increment ver

* fix(audit): store plugin entries with no acting user as a null user_id (#1556)

Plugin audit entries written outside a request used the literal "system"
as user_id. That column references users.id, so the insert was refused
(Postgres logs it as an FK violation) and the entry was silently dropped.
Write null instead and keep "system" / plugin:<id> in username.

* chore: add sso/ldap dialog and audit log fixes to release notes

* fix: tunnels and host settings missing from shared hosts on desktop

* fix: remote desktop logins missing from shared hosts on desktop

* fix: simplify host status to online/offline and keep it live without a refresh

* chore: sync Crowdin translations for 2.9.1

---------

Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com>
2026-10-04 15:11:41 -05:00

317 lines
10 KiB
TypeScript

import { afterEach, describe, expect, it } from "vitest";
import type {
PluginSshConnectOptions,
PluginSshHost,
} from "@termix/plugin-sdk/backend";
import { startServer, sshHost, type TestServer } from "./server";
import { FakeClient } from "./fake-ssh";
let server: TestServer | null = null;
afterEach(async () => {
await server?.close();
server = null;
});
async function connect(s: TestServer, sessionId = "s1", hostId = 7) {
return s.request("POST", "/ssh/connect", { body: { sessionId, hostId } });
}
/** Swaps ctx.ssh.connect for one that runs `flow` against the prompt channel. */
function promptingConnect(
s: TestServer,
flow: (
ask: NonNullable<PluginSshConnectOptions["prompt"]>["ask"],
) => Promise<void>,
) {
s.mock.ctx.ssh.connect = (async (
host: PluginSshHost,
options?: PluginSshConnectOptions,
) => {
await flow(options!.prompt!.ask);
return {
client: s.client as never,
jumpClient: null,
host,
dispose: () => s.client.end(),
};
}) as never;
}
describe("docker routes", () => {
it("refuses every route without docker.use", async () => {
server = await startServer({ permissions: [] });
const calls: Array<[string, string]> = [
["POST", "/ssh/connect"],
["POST", "/ssh/connect-totp"],
["POST", "/ssh/connect-browser-sign-in"],
["POST", "/ssh/disconnect"],
["POST", "/ssh/keepalive"],
["GET", "/ssh/status?sessionId=s1"],
["GET", "/validate/s1"],
["GET", "/containers/s1"],
["GET", "/containers/s1/abc"],
["POST", "/containers/s1/abc/start"],
["DELETE", "/containers/s1/abc/remove"],
["GET", "/containers/s1/abc/logs"],
["GET", "/containers/s1/abc/stats"],
];
for (const [method, path] of calls) {
const response = await server.request(method, path, {
body: method === "GET" ? undefined : {},
});
expect(response.status, `${method} ${path}`).toBe(403);
}
});
it("refuses a host with Docker switched off", async () => {
server = await startServer({ dockerOn: false });
const response = await connect(server);
expect(response.status).toBe(403);
expect(response.body.code).toBe("DOCKER_DISABLED");
});
it("answers 404 for a host the user cannot reach", async () => {
server = await startServer();
expect((await connect(server, "s1", 99)).status).toBe(404);
});
it("keeps the core-resolved host identity when using stored credentials", async () => {
server = await startServer();
const host = sshHost(7, { authType: "key", password: undefined });
const originalConnect = server.mock.ctx.ssh.connect;
server.mock.ctx.ssh.resolveHost = async () => host;
server.mock.ctx.ssh.connect = (async (target, options) => {
if (target !== host)
throw new Error("Stored credential association lost");
return originalConnect(target, options);
}) as typeof originalConnect;
const response = await connect(server);
expect(response.status).toBe(200);
expect(response.body.success).toBe(true);
});
it("applies explicit authentication overrides without changing the resolved host", async () => {
server = await startServer();
const host = sshHost(7, { authType: "key", password: undefined });
server.mock.ctx.ssh.resolveHost = async () => host;
const response = await server.request("POST", "/ssh/connect", {
body: {
sessionId: "override",
hostId: 7,
userProvidedPassword: "replacement",
},
});
expect(response.status).toBe(200);
expect(server.mock.sshConnections.at(-1)?.host).toMatchObject({
authType: "password",
password: "replacement",
});
expect(host.authType).toBe("key");
expect(host.password).toBeUndefined();
});
it("connects, validates and manages containers on the session", async () => {
server = await startServer();
const connected = await connect(server);
expect(connected.status).toBe(200);
expect(connected.body.success).toBe(true);
expect(server.mock.statusReports).toContainEqual({ hostId: 7, ok: true });
const validation = await server.request("GET", "/validate/s1");
expect(validation.body).toEqual({
available: true,
version: "27.1.1",
runtime: "docker",
});
const list = await server.request("GET", "/containers/s1");
expect(list.body).toEqual([
expect.objectContaining({ id: "abc123", name: "web", state: "running" }),
]);
server.client.reply(/ start abc123$/, { stdout: "abc123" });
const started = await server.request("POST", "/containers/s1/abc123/start");
expect(started.status).toBe(200);
expect(
server.client.commands.some((c) => c.endsWith("docker start abc123")),
).toBe(true);
server.client.reply(/ logs abc123/, { stdout: "line one\nline two\n" });
const logs = await server.request(
"GET",
"/containers/s1/abc123/logs?tail=50&since=2026-01-01T00:00:00Z",
);
expect(logs.body).toEqual({ success: true, logs: "line one\nline two\n" });
expect(server.client.commands.at(-1)).toContain(
"logs abc123 --tail 50 --since 2026-01-01T00:00:00Z 2>&1",
);
server.client.reply(/ stats abc123/, {
stdout:
'{"cpu":"1.5%","memory":"10MiB / 1GiB","memoryPercent":"1%","netIO":"1kB / 2kB","blockIO":"0B / 0B","pids":"3"}',
});
const stats = await server.request("GET", "/containers/s1/abc123/stats");
expect(stats.body).toMatchObject({
cpu: "1.5%",
memoryUsed: "10MiB",
memoryLimit: "1GiB",
netInput: "1kB",
netOutput: "2kB",
});
server.client.reply(/ rm abc123/, {
code: 1,
stderr: "Error: No such container: abc123",
});
const removed = await server.request(
"DELETE",
"/containers/s1/abc123/remove",
);
expect(removed.status).toBe(404);
expect(
(await server.request("POST", "/containers/s1/abc123/explode")).status,
).toBe(404);
expect(
(await server.request("GET", "/containers/s1/bad;id/logs")).status,
).toBe(400);
await server.request("POST", "/ssh/disconnect", {
body: { sessionId: "s1" },
});
const status = await server.request("GET", "/ssh/status?sessionId=s1");
expect(status.body.connected).toBe(false);
});
it("uses Podman when the host says so", async () => {
server = await startServer();
await server.mock.ctx.settings.setHost(7, "containerRuntime", "podman");
await connect(server);
await server.request("GET", "/containers/s1");
expect(server.client.commands.at(-1)).toMatch(/ podman ps -a --format/);
});
it("keeps another user's session to its owner", async () => {
server = await startServer();
await connect(server);
const response = await server.request("GET", "/containers/s1", {
user: "user-2",
});
expect(response.status).toBe(400);
const status = await server.request("GET", "/ssh/status?sessionId=s1", {
user: "user-2",
});
expect(status.body.connected).toBe(false);
});
it("parks a TOTP prompt and re-asks after a wrong code", async () => {
server = await startServer();
promptingConnect(server, async (ask) => {
let code = await ask({ kind: "totp", prompt: "Code:", retry: false });
while (code !== "123456") {
if (code === null) throw new Error("Cancelled");
code = await ask({ kind: "totp", prompt: "Code:", retry: true });
}
});
const first = await connect(server);
expect(first.body).toMatchObject({ requires_totp: true, prompt: "Code:" });
const pending = await server.request("GET", "/containers/s1");
expect(pending.body.code).toBe("AUTH_PENDING");
const wrong = await server.request("POST", "/ssh/connect-totp", {
body: { sessionId: "s1", totpCode: "000000" },
});
expect(wrong.body).toMatchObject({ requires_totp: true, retry: true });
const stranger = await server.request("POST", "/ssh/connect-totp", {
user: "user-2",
body: { sessionId: "s1", totpCode: "123456" },
});
expect(stranger.status).toBe(404);
const right = await server.request("POST", "/ssh/connect-totp", {
body: { sessionId: "s1", totpCode: "123456" },
});
expect(right.body).toMatchObject({ success: true, status: "success" });
expect((await server.request("GET", "/containers/s1")).status).toBe(200);
});
it("continues a browser sign-in and refuses a code for it", async () => {
server = await startServer();
promptingConnect(server, async (ask) => {
await ask({
kind: "browser",
id: "gateway",
label: "Gateway",
url: "https://gateway.example/login",
code: "KEY",
instructions: "",
});
});
const first = await connect(server);
expect(first.body).toMatchObject({
requires_browser_sign_in: true,
label: "Gateway",
url: "https://gateway.example/login",
code: "KEY",
});
const wrongKind = await server.request("POST", "/ssh/connect-totp", {
body: { sessionId: "s1", totpCode: "1" },
});
expect(wrongKind.status).toBe(400);
const done = await server.request("POST", "/ssh/connect-browser-sign-in", {
body: { sessionId: "s1" },
});
expect(done.body.success).toBe(true);
});
it("asks for credentials when a host with no secret gets a password prompt", async () => {
server = await startServer({
mock: {
sshHosts: [
{
id: 7,
userId: "user-1",
ip: "10.0.0.7",
port: 22,
username: "root",
authType: "none",
},
],
},
});
promptingConnect(server, async (ask) => {
const answer = await ask({
kind: "input",
prompt: "Password:",
echo: false,
isPush: false,
});
if (answer === null)
throw new Error("All configured authentication methods failed");
});
const response = await connect(server);
expect(response.body).toEqual({
status: "auth_required",
reason: "no_keyboard",
});
});
it("never reports a failed login to core", async () => {
const client = new FakeClient();
server = await startServer({ client });
server.mock.ctx.ssh.connect = (async () => {
throw new Error("All configured authentication methods failed");
}) as never;
const response = await connect(server);
expect(response.status).toBe(500);
expect(server.mock.statusReports).toEqual([]);
});
});