nodered: settings are files the mesh writes; editor locked with adminAuth; pin 5.0.7 #149

Open
mesh-admin wants to merge 2 commits from feat/nodered-for-ace into main
Contributor

The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED
editor (which runs arbitrary code) was open to anyone who reached it, and
the module's own tools had no token to present to an install that was locked.

  • settings.js (fixed, 0600, uid 1000) carries adminAuth: user admin checked
    against the admin secret -- a minted password, or the bcrypt hash an
    existing install held (accepted), so current logins keep working -- and a
    static bearer token (api-token) the sidecar presents. It loads settings.json
    beside it, the one mergeable file; endpoints is dropped there, and an
    optional timeZone sets process.env.TZ (assignments cannot set env).
  • The sidecar's runtime config is no longer merged; it carries the token.
  • Directories are placed (state, data), the route binds into state.
  • Image pinned to 5.0.7 (a649dd71), what ace runs; the old pin was 5.0.6.
  • deployFlows asks for API v2: v1 answers 204 with no body, which the client
    tried to parse as JSON.

Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container
started with the generated files: anonymous /flows 401, bearer api-token 200,
bad token 401, password grant 200/403 with a minted password and with a
bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings;
timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy
answers {rev}.

Migration notes for ace (assignment draft in the migration repo):

  • ACCEPT admin = the bcrypt hash in ace's /data/settings.js adminAuth (so the current password keeps working); MINT api-token.
  • The flow credential key stays in the data dir (.config.runtime.json); credentialSecret deliberately not set.
  • ace's HAL settings.js also set httpNodeAuth/httpStaticAuth; no flow has an http-in node and httpStatic is unset, so nothing depended on them. Not carried; say if they should be.
  • Finding: ace's only mqtt-broker config points at zurag.be:1884, where nothing listens; it has failed every 15 s since at least 2026-09-20, so the MQTT flows are idle today.
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED editor (which runs arbitrary code) was open to anyone who reached it, and the module's own tools had no token to present to an install that was locked. - settings.js (fixed, 0600, uid 1000) carries adminAuth: user admin checked against the admin secret -- a minted password, or the bcrypt hash an existing install held (accepted), so current logins keep working -- and a static bearer token (api-token) the sidecar presents. It loads settings.json beside it, the one mergeable file; endpoints is dropped there, and an optional timeZone sets process.env.TZ (assignments cannot set env). - The sidecar's runtime config is no longer merged; it carries the token. - Directories are placed (state, data), the route binds into state. - Image pinned to 5.0.7 (a649dd71), what ace runs; the old pin was 5.0.6. - deployFlows asks for API v2: v1 answers 204 with no body, which the client tried to parse as JSON. Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container started with the generated files: anonymous /flows 401, bearer api-token 200, bad token 401, password grant 200/403 with a minted password and with a bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings; timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy answers {rev}. Migration notes for ace (assignment draft in the migration repo): - ACCEPT admin = the bcrypt hash in ace's /data/settings.js adminAuth (so the current password keeps working); MINT api-token. - The flow credential key stays in the data dir (.config.runtime.json); credentialSecret deliberately not set. - ace's HAL settings.js also set httpNodeAuth/httpStaticAuth; no flow has an http-in node and httpStatic is unset, so nothing depended on them. Not carried; say if they should be. - Finding: ace's only mqtt-broker config points at zurag.be:1884, where nothing listens; it has failed every 15 s since at least 2026-09-20, so the MQTT flows are idle today.
mesh-admin added 1 commit 2026-09-29 21:41:28 +00:00
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED
editor (which runs arbitrary code) was open to anyone who reached it, and
the module's own tools had no token to present to an install that was locked.

- settings.js (fixed, 0600, uid 1000) carries adminAuth: user admin checked
  against the admin secret -- a minted password, or the bcrypt hash an
  existing install held (accepted), so current logins keep working -- and a
  static bearer token (api-token) the sidecar presents. It loads settings.json
  beside it, the one mergeable file; endpoints is dropped there, and an
  optional timeZone sets process.env.TZ (assignments cannot set env).
- The sidecar's runtime config is no longer merged; it carries the token.
- Directories are placed (state, data), the route binds into state.
- Image pinned to 5.0.7 (a649dd71), what ace runs; the old pin was 5.0.6.
- deployFlows asks for API v2: v1 answers 204 with no body, which the client
  tried to parse as JSON.

Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container
started with the generated files: anonymous /flows 401, bearer api-token 200,
bad token 401, password grant 200/403 with a minted password and with a
bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings;
timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy
answers {rev}.
jschoubben added 1 commit 2026-09-29 21:50:13 +00:00
The sidecar runs on the host network and dialled 127.0.0.1:1880, the
software's port; the mesh publishes nodered on a machine port it assigns,
so the tools reached whatever else holds 1880, or nothing (hq 088).
You are not authorized to merge this pull request.
This pull request can be merged automatically.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin feat/nodered-for-ace:feat/nodered-for-ace
git checkout feat/nodered-for-ace
Sign in to join this conversation.
No Reviewers
No labels
2 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#149