mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-08 16:39:42 +02:00
The opt-in multi-user feature's only enforcement is web-layer scoping (all sessions share one OS account). An adversarial review found 8 critical + 7 high cross-user holes that defeated it, plus mediums; all fixed here. Single-user (flag-off) behavior stays byte-identical apart from documented consistency deltas. Ownership / confinement: - DELETE /api/sessions (bulk) + /:id now owner-scope / findSessionOrFail - quick-start, cron (create+fire), scheduled runs confine workingDir to the owner's space; case link/docker-link/docker-import confine the host path - resolveCasePath no longer resolves linked cases for non-admins; foreign remote/docker cases are skipped (fall through to the caller's own local case) - history, subagents/workflows, mux-sessions, orchestrator, cron run-history, away-digest, and remote/docker host reads are owner- or admin-scoped Permission policy (section 6.3): - non-granted users are downgraded at every spawn site incl. legacy /api/scheduled, PlanOrchestrator one-shots, remote launch, and the cron-fire gemini/codex bypass switches; resolveClaudeModeForUsername now fails closed Auth / store: - verify-first login throttle (a correct password is never locked out), /ws terminal subject to the change-password lockbox, cookie fast-path re-validates identity live, role/grant changes revoke sessions, admin delete runs the last-admin guard before any teardown - users.json: distinguish missing (ENOENT) from corrupt/unreadable so a bad read can't overwrite all accounts; unique per-process temp write path Event streams: - debounced session:updated + batched task:updated, clipboard, and push notifications route by owner (fail closed); getLightState hides machine-wide globalStats from non-admins Tests: two suites updated to assert the fixed (secure) behavior. tsc, eslint, and test:ci all green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
53 lines
2.1 KiB
TypeScript
53 lines
2.1 KiB
TypeScript
/**
|
|
* @fileoverview Mux (tmux) session management routes.
|
|
* Provides mux session listing, killing, reconciliation, and stats control.
|
|
*/
|
|
|
|
import { FastifyInstance } from 'fastify';
|
|
import type { InfraPort } from '../ports/index.js';
|
|
import { STATS_COLLECTION_INTERVAL_MS } from '../../config/server-timing.js';
|
|
import { requireAdmin } from '../route-helpers.js';
|
|
import { isMultiUserMode } from '../../config/multiuser.js';
|
|
|
|
export function registerMuxRoutes(app: FastifyInstance, ctx: InfraPort): void {
|
|
app.get('/api/mux-sessions', async (req, reply) => {
|
|
// Multi-user: this recovery/debug surface exposes every user's tmux + workdirs → admin-only
|
|
// (requireAdmin is a no-op allow-all in single-user mode, so flag-off is unchanged).
|
|
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
|
|
const sessions = await ctx.mux.getSessionsWithStats();
|
|
return {
|
|
sessions,
|
|
muxAvailable: ctx.mux.isAvailable(),
|
|
};
|
|
});
|
|
|
|
app.delete('/api/mux-sessions/:sessionId', async (req, reply) => {
|
|
// Multi-user: killing any tmux session by name is a cross-user destructive action → admin-only.
|
|
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
|
|
const { sessionId } = req.params as { sessionId: string };
|
|
const success = await ctx.mux.killSession(sessionId);
|
|
return { killed: success };
|
|
});
|
|
|
|
app.post('/api/mux-sessions/reconcile', async (req, reply) => {
|
|
// Multi-user: process-wide reconcile → admin-only.
|
|
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
|
|
const result = await ctx.mux.reconcileSessions();
|
|
return result;
|
|
});
|
|
|
|
app.post('/api/mux-sessions/stats/start', async (req, reply) => {
|
|
// Multi-user: process-wide stats collection toggle → admin-only.
|
|
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
|
|
ctx.mux.startStatsCollection(STATS_COLLECTION_INTERVAL_MS);
|
|
return {};
|
|
});
|
|
|
|
app.post('/api/mux-sessions/stats/stop', async (req, reply) => {
|
|
// Multi-user: process-wide stats collection toggle → admin-only.
|
|
if (isMultiUserMode() && !requireAdmin(req, reply)) return;
|
|
ctx.mux.stopStatsCollection();
|
|
return {};
|
|
});
|
|
}
|