control-api: every route now carries a mandatory access level (admin / agent / open) in a route table. All /api/v1/admin/* require the admin token; the write calls of validator-agent and prober (self-check, events, results, complete) require a separate static agent token; register, heartbeat and fetching the assignment stay open. Tokens come from env vars, are compared in constant time and never logged. An empty token leaves that level open with a startup warning (backward compatible). validator-agent / prober: apiclient sends the agent token only to control-api. admin-dashboard: login/password (from env) with a stateless HMAC session cookie, Origin-based CSRF check, per-IP brute-force throttle, HX-Redirect for htmx polls, logout in the sidebar; the dashboard calls control-api with the admin token. Login page layout fixed after review. Also: env plumbing in docker-compose/rxprod-compose/systemd/config examples, e2e script with token assertions, tests, docs (API, SETUP, USAGE, DASHBOARD, README), plan and review under docs/changes/, bin/ rebuilt with new SHA256SUMS. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
73 lines
2.3 KiB
Go
73 lines
2.3 KiB
Go
package dashboard
|
|
|
|
import (
|
|
"net/http"
|
|
"strings"
|
|
)
|
|
|
|
type registryPageData struct {
|
|
PageData
|
|
Items []registryItem
|
|
Query string
|
|
StatusFilter string
|
|
}
|
|
|
|
type registryDetailData struct {
|
|
PageData
|
|
History registryHistoryResponse
|
|
}
|
|
|
|
// handleRegistryPage lists every address ever submitted to the check
|
|
// queue, with a summary of its accumulated check history — the durable
|
|
// record that survives an address being deleted from /ips and later
|
|
// re-added. See internal/db/migrations/0007_ip_registry.sql. Optional
|
|
// ?q=&status= query params narrow the list by address substring and by
|
|
// LastResult — see filterRegistryItems.
|
|
func (s *Server) handleRegistryPage(w http.ResponseWriter, r *http.Request) {
|
|
items, err := s.CA.ListRegistry(r.Context())
|
|
q := strings.TrimSpace(r.URL.Query().Get("q"))
|
|
status := r.URL.Query().Get("status")
|
|
data := registryPageData{
|
|
Items: filterRegistryItems(items, q, status),
|
|
Query: q,
|
|
StatusFilter: status,
|
|
}
|
|
data.ActiveNav = "registry"
|
|
data.Banner = bannerFor(err)
|
|
s.renderPage(w, r, "registry_page", data)
|
|
}
|
|
|
|
// filterRegistryItems narrows items to those whose address contains q
|
|
// (case-insensitive substring) and, if status is set, whose LastResult
|
|
// matches it exactly — the registry list's search-by-IP and
|
|
// filter-by-status, mirroring filterQueueItems in handlers_overview.go.
|
|
func filterRegistryItems(items []registryItem, q, status string) []registryItem {
|
|
if q == "" && status == "" {
|
|
return items
|
|
}
|
|
q = strings.ToLower(q)
|
|
out := make([]registryItem, 0, len(items))
|
|
for _, it := range items {
|
|
if q != "" && !strings.Contains(strings.ToLower(it.IPAddress), q) {
|
|
continue
|
|
}
|
|
if status != "" && it.LastResult != status {
|
|
continue
|
|
}
|
|
out = append(out, it)
|
|
}
|
|
return out
|
|
}
|
|
|
|
// handleRegistryDetail shows one address's full retained check history
|
|
// across every cycle it has ever run, not just the current attempt — see
|
|
// ip_detail_content in ip_detail.html for the attempt-scoped equivalent.
|
|
func (s *Server) handleRegistryDetail(w http.ResponseWriter, r *http.Request) {
|
|
ip := r.PathValue("ip")
|
|
history, err := s.CA.GetRegistryHistory(r.Context(), ip)
|
|
data := registryDetailData{History: history}
|
|
data.ActiveNav = "registry"
|
|
data.Banner = bannerFor(err)
|
|
s.renderPage(w, r, "registry_detail_page", data)
|
|
}
|