mirror of
https://github.com/Ark0N/Codeman.git
synced 2026-10-04 22:49:41 +02:00
Adds ephemeral single-use QR tokens for passwordless tunnel login. Scanning the QR auto-authenticates; bare tunnel URL requires Basic Auth. Backend: - TunnelManager: 60s token rotation, 90s grace, rejection-sampled 6-char base62 short codes, Map-based O(1) lookup, SVG caching, global rate limit - Auth middleware: /q/ bypass, separate qrAuthFailures counter, enhanced AuthSessionRecord with device context (ip, ua, createdAt, method) - Routes: GET /q/:code (consume + cookie + redirect), POST /api/tunnel/qr/ regenerate, POST /api/auth/revoke, updated GET /api/tunnel/qr with cache - SSE: tunnel:qrRotated, tunnel:qrRegenerated, tunnel:qrAuthUsed events - Audit: qr_auth lifecycle log entries Frontend: - Auto-refresh QR via inline SVG in SSE (fallback fetch if absent) - 60s countdown indicator on QR badge - Regenerate QR button - QRLjacking detection toast with [Revoke All] action button (10s duration) - showToast enhanced with optional duration and action button support Fixes: - /api/logout now invalidates server-side session token (was only clearing browser cookie, leaving token valid for replay) Tests: 20 new tests in test/qr-auth.test.ts covering token lifecycle, bias check, rate limiting, SVG caching, and full server integration. Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
15 lines
623 B
TypeScript
15 lines
623 B
TypeScript
/**
|
|
* @fileoverview Barrel export for all port interfaces.
|
|
*
|
|
* Ports define the capabilities that route modules can depend on.
|
|
* WebServer implements all ports; route modules declare only what they need
|
|
* via TypeScript intersection types (e.g., SessionPort & EventPort).
|
|
*/
|
|
|
|
export type { SessionPort } from './session-port.js';
|
|
export type { EventPort } from './event-port.js';
|
|
export type { RespawnPort } from './respawn-port.js';
|
|
export type { ConfigPort } from './config-port.js';
|
|
export type { InfraPort, ScheduledRun } from './infra-port.js';
|
|
export type { AuthPort, AuthSessionRecord } from './auth-port.js';
|