mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 00:19:42 +02:00
The opt-in multi-user feature's only enforcement is web-layer scoping (all sessions share one OS account). An adversarial review found 8 critical + 7 high cross-user holes that defeated it, plus mediums; all fixed here. Single-user (flag-off) behavior stays byte-identical apart from documented consistency deltas. Ownership / confinement: - DELETE /api/sessions (bulk) + /:id now owner-scope / findSessionOrFail - quick-start, cron (create+fire), scheduled runs confine workingDir to the owner's space; case link/docker-link/docker-import confine the host path - resolveCasePath no longer resolves linked cases for non-admins; foreign remote/docker cases are skipped (fall through to the caller's own local case) - history, subagents/workflows, mux-sessions, orchestrator, cron run-history, away-digest, and remote/docker host reads are owner- or admin-scoped Permission policy (section 6.3): - non-granted users are downgraded at every spawn site incl. legacy /api/scheduled, PlanOrchestrator one-shots, remote launch, and the cron-fire gemini/codex bypass switches; resolveClaudeModeForUsername now fails closed Auth / store: - verify-first login throttle (a correct password is never locked out), /ws terminal subject to the change-password lockbox, cookie fast-path re-validates identity live, role/grant changes revoke sessions, admin delete runs the last-admin guard before any teardown - users.json: distinguish missing (ENOENT) from corrupt/unreadable so a bad read can't overwrite all accounts; unique per-process temp write path Event streams: - debounced session:updated + batched task:updated, clipboard, and push notifications route by owner (fail closed); getLightState hides machine-wide globalStats from non-admins Tests: two suites updated to assert the fixed (secure) behavior. tsc, eslint, and test:ci all green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
42 lines
1.6 KiB
TypeScript
42 lines
1.6 KiB
TypeScript
/**
|
|
* @fileoverview Infra port — capabilities for infrastructure services.
|
|
* Route modules that interact with mux, push, teams, tunnel, etc. depend on this port.
|
|
*/
|
|
|
|
import type { TerminalMultiplexer } from '../../mux-interface.js';
|
|
import type { RunSummaryTracker } from '../../run-summary.js';
|
|
import type { PlanOrchestrator } from '../../plan-orchestrator.js';
|
|
import type { TeamWatcher } from '../../team-watcher.js';
|
|
import type { TunnelManager } from '../../tunnel-manager.js';
|
|
import type { PushSubscriptionStore } from '../../push-store.js';
|
|
|
|
/** A scheduled autonomous run with session lifecycle management */
|
|
export interface ScheduledRun {
|
|
id: string;
|
|
prompt: string;
|
|
workingDir: string;
|
|
durationMinutes: number;
|
|
startedAt: number;
|
|
endAt: number;
|
|
status: 'running' | 'completed' | 'failed' | 'stopped';
|
|
sessionId: string | null;
|
|
completedTasks: number;
|
|
totalCost: number;
|
|
logs: string[];
|
|
/** Multi-user owner (username) — undefined in single-user mode. Used to scope
|
|
* list/delete and to downgrade the spawned Session's permission mode. */
|
|
owner?: string;
|
|
}
|
|
|
|
export interface InfraPort {
|
|
readonly mux: TerminalMultiplexer;
|
|
readonly runSummaryTrackers: Map<string, RunSummaryTracker>;
|
|
readonly activePlanOrchestrators: Map<string, PlanOrchestrator>;
|
|
readonly scheduledRuns: Map<string, ScheduledRun>;
|
|
readonly teamWatcher: TeamWatcher;
|
|
readonly tunnelManager: TunnelManager;
|
|
readonly pushStore: PushSubscriptionStore;
|
|
startScheduledRun(prompt: string, workingDir: string, durationMinutes: number, owner?: string): Promise<ScheduledRun>;
|
|
stopScheduledRun(id: string): Promise<void>;
|
|
}
|