nodered: settings are files the mesh writes; editor locked with adminAuth; pin 5.0.7 #149
Open
mesh-admin
wants to merge 2 commits from
feat/nodered-for-ace into main
pull from: feat/nodered-for-ace
merge into: :main
:main
:feat/oidc-client-provision
:feat/servarr-api-provision
:fix/sidecars-dial-the-port-they-were-given
:feat/nodered-for-ace
:feat/grafana-for-ace
:feat/influxdb-for-ace
:feat/tautulli-for-ace
:feat/jackett-for-ace
:feat/unifi-for-ace
:feat/home-assistant-for-ace
:feat/icecast-for-ace
:feat/ombi-for-ace
:feat/mosquitto-placed
:chore/remove-the-network-checker-module
:feat/a-network-checker-module
:feat/modules-name-their-endpoints
:fix/a-routed-module-listens-from-the-mesh
:fix/the-resolver-declares-both-protocols
:fix/sshd-declares-the-daemon-it-owns
:fix/fail2ban-bans-through-what-every-machine-has
:fix/fail2ban-declares-the-log-its-own-jail-reads
:fix/fail2ban-restarts-on-its-log-target
:fix/fail2ban-declares-where-it-logs
:feat/the-catalogue-hears-what-it-missed
:feat/the-catalogue-prepares-its-own-schema
:fix/the-catalogue-declares-the-event-it-emits
:feat/a-merge-rebuilds-what-it-changed
:fix/a-merge-older-than-the-watching-is-history
:fix/a-merge-announced-is-said
:fix/the-forge-watches-every-repository
:feat/the-forge-announces-every-merge
:feat/nats-serves-the-meshs-certificate
:fix/nats-declares-its-base
:feat/amqp-leaves-the-catalogue
:restore/broker-claim
:revert/broker-seat-claim
:fix/broker-seat-must-stay-held
:fix/go-126-base
:feat/nats-genesis
:feat/ssh-client-module
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED
editor (which runs arbitrary code) was open to anyone who reached it, and
the module's own tools had no token to present to an install that was locked.
against the admin secret -- a minted password, or the bcrypt hash an
existing install held (accepted), so current logins keep working -- and a
static bearer token (api-token) the sidecar presents. It loads settings.json
beside it, the one mergeable file; endpoints is dropped there, and an
optional timeZone sets process.env.TZ (assignments cannot set env).
tried to parse as JSON.
Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container
started with the generated files: anonymous /flows 401, bearer api-token 200,
bad token 401, password grant 200/403 with a minted password and with a
bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings;
timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy
answers {rev}.
Migration notes for ace (assignment draft in the migration repo):
The catalogue ran the image's defaults: no adminAuth, so a routed Node-RED editor (which runs arbitrary code) was open to anyone who reached it, and the module's own tools had no token to present to an install that was locked. - settings.js (fixed, 0600, uid 1000) carries adminAuth: user admin checked against the admin secret -- a minted password, or the bcrypt hash an existing install held (accepted), so current logins keep working -- and a static bearer token (api-token) the sidecar presents. It loads settings.json beside it, the one mergeable file; endpoints is dropped there, and an optional timeZone sets process.env.TZ (assignments cannot set env). - The sidecar's runtime config is no longer merged; it carries the token. - Directories are placed (state, data), the route binds into state. - Image pinned to 5.0.7 (a649dd71), what ace runs; the old pin was 5.0.6. - deployFlows asks for API v2: v1 answers 204 with no body, which the client tried to parse as JSON. Verified: catalogue tests pass against this tree. A throwaway 5.0.7 container started with the generated files: anonymous /flows 401, bearer api-token 200, bad token 401, password grant 200/403 with a minted password and with a bcrypt-hash-accepted one; endpoints and timeZone do not reach /settings; timeZone Europe/Brussels overrides TZ=Etc/UTC; v1 deploy 204, v2 deploy answers {rev}.View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.