mirror of
https://github.com/Termix-SSH/Termix.git
synced 2026-08-29 10:21:34 +00:00
fix: allow exec on shared hosts (#1362)
This commit is contained in:
@@ -12,8 +12,8 @@ import {
|
|||||||
resolveSnippetCommand,
|
resolveSnippetCommand,
|
||||||
} from "./snippets-execution.js";
|
} from "./snippets-execution.js";
|
||||||
import { logAudit, getRequestMeta } from "../../utils/audit-logger.js";
|
import { logAudit, getRequestMeta } from "../../utils/audit-logger.js";
|
||||||
|
import { resolveHostById } from "../../hosts/host-resolver.js";
|
||||||
import {
|
import {
|
||||||
createCurrentHostResolutionRepository,
|
|
||||||
createCurrentRbacAccessRepository,
|
createCurrentRbacAccessRepository,
|
||||||
createCurrentRoleRepository,
|
createCurrentRoleRepository,
|
||||||
createCurrentSnippetRepository,
|
createCurrentSnippetRepository,
|
||||||
@@ -587,32 +587,16 @@ router.post(
|
|||||||
}
|
}
|
||||||
|
|
||||||
const { Client } = await import("ssh2");
|
const { Client } = await import("ssh2");
|
||||||
const repository = createCurrentHostResolutionRepository();
|
const host = await resolveHostById(parseInt(hostId), userId);
|
||||||
const host = await repository.findHostById(parseInt(hostId), userId);
|
|
||||||
|
|
||||||
if (!host || host.userId !== userId) {
|
if (!host) {
|
||||||
return res.status(404).json({ error: "Host not found" });
|
return res.status(404).json({ error: "Host not found" });
|
||||||
}
|
}
|
||||||
|
|
||||||
let password = host.password;
|
const password = host.password;
|
||||||
let privateKey = host.key;
|
const privateKey = host.key;
|
||||||
let passphrase = host.keyPassword;
|
const passphrase = host.keyPassword;
|
||||||
let authType = host.authType;
|
const authType = host.authType;
|
||||||
|
|
||||||
if (host.credentialId) {
|
|
||||||
const cred = await repository.findCredentialByIdForUser(
|
|
||||||
host.credentialId as number,
|
|
||||||
userId,
|
|
||||||
);
|
|
||||||
|
|
||||||
if (cred) {
|
|
||||||
authType = (cred.authType || authType) as string;
|
|
||||||
password = (cred.password || undefined) as string | undefined;
|
|
||||||
privateKey = (cred.privateKey || cred.key || undefined) as
|
|
||||||
string | undefined;
|
|
||||||
passphrase = (cred.keyPassword || undefined) as string | undefined;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
const conn = new Client();
|
const conn = new Client();
|
||||||
let output = "";
|
let output = "";
|
||||||
|
|||||||
@@ -0,0 +1,20 @@
|
|||||||
|
import fs from "fs";
|
||||||
|
import path from "path";
|
||||||
|
import { describe, expect, it } from "vitest";
|
||||||
|
|
||||||
|
describe("snippet execution host access", () => {
|
||||||
|
it("uses the shared-host-aware resolver", () => {
|
||||||
|
const source = fs.readFileSync(
|
||||||
|
path.resolve(__dirname, "../../../database/routes/snippets.ts"),
|
||||||
|
"utf8",
|
||||||
|
);
|
||||||
|
const executeRoute = source.slice(
|
||||||
|
source.indexOf('router.post(\n "/execute"'),
|
||||||
|
);
|
||||||
|
|
||||||
|
expect(executeRoute).toContain(
|
||||||
|
"const host = await resolveHostById(parseInt(hostId), userId)",
|
||||||
|
);
|
||||||
|
expect(executeRoute).not.toContain("host.userId !== userId");
|
||||||
|
});
|
||||||
|
});
|
||||||
Reference in New Issue
Block a user