nodered: its settings are files the mesh writes, and its editor is locked
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED
editor (which runs arbitrary code) was open to anyone who reached it, and
the module's own tools had no token to present to an install that was locked.
- settings.js (fixed, 0600, uid 1000) carries adminAuth: user admin checked
against the admin secret -- a minted password, or the bcrypt hash an
existing install held (accepted), so current logins keep working -- and a
static bearer token (api-token) the sidecar presents. It loads settings.json
beside it, the one mergeable file; endpoints is dropped there, and an
optional timeZone sets process.env.TZ (assignments cannot set env).
- The sidecar's runtime config is no longer merged; it carries the token.
- Directories are placed (state, data), the route binds into state.
- Image pinned to 5.0.7 (a649dd71), what ace runs; the old pin was 5.0.6.
- deployFlows asks for API v2: v1 answers 204 with no body, which the client
tried to parse as JSON.
Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container
started with the generated files: anonymous /flows 401, bearer api-token 200,
bad token 401, password grant 200/403 with a minted password and with a
bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings;
timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy
answers {rev}.
This commit is contained in:
@@ -3,7 +3,8 @@
|
||||
//
|
||||
// Node-RED exposes a runtime admin API under its base URL: GET/POST /flows for the whole flow
|
||||
// configuration, GET /nodes for installed node modules. A default install has no auth; when
|
||||
// adminAuth is on, a bearer token (minted at /auth/token) is required.
|
||||
// adminAuth is on, a bearer token is required — the module's settings accept the mesh-minted
|
||||
// api-token, which the runtime config file carries as `token`.
|
||||
|
||||
import { readFileSync } from "node:fs";
|
||||
|
||||
@@ -88,8 +89,13 @@ export class NodeRedClient {
|
||||
async deployFlows(config: any[], type = "full"): Promise<{ rev?: string; nodeCount: number }> {
|
||||
const body = await this.req("/flows", {
|
||||
method: "POST",
|
||||
headers: this.headers({ "Content-Type": "application/json", "Node-RED-Deployment-Type": type }),
|
||||
body: JSON.stringify(config),
|
||||
// v2 answers { rev }; v1 answers 204 with no body, which req() cannot parse.
|
||||
headers: this.headers({
|
||||
"Content-Type": "application/json",
|
||||
"Node-RED-API-Version": "v2",
|
||||
"Node-RED-Deployment-Type": type,
|
||||
}),
|
||||
body: JSON.stringify({ flows: config }),
|
||||
});
|
||||
return { rev: body?.rev, nodeCount: config.length };
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user