boban
|
0f57074e6f
|
chore(audit): full code sweep — fix open-redirect, drop dead code, clean docs
Full-codebase audit + automatic cleanup (no behavioural change for users).
Security
- ServerSwitcher: post-switch redirect is now reduced to a SAME-ORIGIN
relative path. Rejects off-host referers, non-http(s) schemes
(javascript:/data:), different ports (https://host:444/x -> /x), and
protocol-relative tricks (//host, /\host). Closes a Referer open-redirect
(Codex P2).
- EditCredential: a key passphrase is stored only for key auth, never for
password auth.
Removed dead code
- FirewallService::status/allow/deny (+ orphaned clampPort)
- Server::auditEvents(), SshCredential::scopeActive(), unused 'bell' icon
Cleanups / improvements
- Files list + editor use a dedicated 'file' icon (was the audit icon)
- Import RuntimeException/Throwable instead of FQN; fix stale docblocks
(FirewallService, HardeningService) and the Files delete comment
- Quote base64 in the sudo command path (defensive, consistent)
- Null-safe Auth::user()?->email in Settings; single domain() read in hasTls()
Release
- Bump 0.1.0 -> 0.1.1 + CHANGELOG entry
Verified: Pint clean, Codex review clean (no actionable regressions),
R12 browser check — 9 routes HTTP 200, 0 console errors, lazy pages loaded.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
2026-06-13 12:54:26 +02:00 |
boban
|
506fe4044a
|
feat: v1 data models + routes (Server/AuditEvent/SshCredential)
- Server (uuid route key R11; cpu/mem/disk/specs/status/uptime), AuditEvent
(actor/action/target + user/server relations), SshCredential (encrypted vault:
secret/passphrase cast as 'encrypted', hidden). Migrations + FleetSeeder (4 servers, 4 events).
- routes/web.php: full-page Livewire routes for dashboard, servers (index +
{server:uuid} show), services, files, audit.
Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
|
2026-06-12 06:25:47 +02:00 |