mirror of
https://github.com/Termix-SSH/Termix.git
synced 2026-08-29 10:21:34 +00:00
* Add Helm and GitOps deployment setup * fix: build better-sqlite3 from source in Docker (#1267) * fix: preserve runtime SSL settings (#1268) * fix: support forwarding from the memory SSH agent (#1269) * fix: support forwarding from the memory agent * style: format memory agent test * fix: prompt for encrypted SFTP key passphrases (#1270) * fix: prompt for SFTP key passphrases * style: format SSH key utility test * fix: include host context in automation notifications (#1271) * fix: include host context in automation notifications * style: format automation notification changes * fix: reserve sidebar height for host tags (#1272) * fix: keep host action rows stable at large font sizes (#1273) * fix: honor certificate setting during server probe (#1274) * fix: package standard Linux icon sizes (#1275) * fix: avoid duplicate Docker HTTPS listener (#1276) * Fix host status without metrics collection (#1277) * fix: allow eight-digit secure auth codes (#1263) Allow TOTP prompts to accept secure auth codes longer than six digits without blocking valid authentication attempts. Generated with Codebuff 🤖 Co-authored-by: Chetan <chetan.development@gmail.com> Co-authored-by: Codebuff <noreply@codebuff.com> * Harden Helm deployment defaults * Update Helm workflow action * Exclude Helm templates from Prettier * Fix browser RDP file drops (#1279) * Fix Proxmox guest credential usernames (#1280) * Add WSL local terminal option (#1281) * refactor: split the transfer engine into focused modules (#1282) * refactor: extract SFTP promisify helpers into sftp-promisify module * refactor: extract transfer timing and rate stats into transfer-stats module * refactor: extract transfer error classes and recovery checks into transfer-errors module * refactor: extract host/path utility helpers into transfer-host-utils module * refactor: extract SFTP directory tree helpers into transfer-sftp-dir module * refactor: extract segment copy job builder into transfer-segment-copy module * refactor: extract file scan and sample helpers into transfer-scan module * refactor: move throttled progress helper into transfer-stats module * style: format transfer modules * perf: optimize tmux monitor aggregation (#1283) * fix: reserve credential tag row height (#1284) * feat: edit AI provider model settings (#1285) * fix: clarify click-to-expand host setting (#1286) * fix: allow portable imports on remote databases (#1287) * fix: allow HTTPS to share the configured port (#1288) * fix: resolve synced jump hosts on the server (#1289) * fix: make terminal clipboard shortcuts layout independent (#1290) * fix: use compatible fetch dispatcher for Tailscale (#1291) * fix: add OIDC environment recovery override (#1292) * fix: coalesce rapid mobile terminal input (#1293) * fix: coalesce rapid mobile terminal input * fix: support clean xterm patch installs * fix: resolve synced remote desktop host IDs (#1295) * feat: make the SFTP file manager path bar editable (#1294) Co-authored-by: Maxime Bonillo <257463937+dropafterfree@users.noreply.github.com> Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com> * feat: add passkey sign in to the login screen * fix: remove rounded corners from the host list search bar * fix: stop image storage settings text wrapping to one word per line * fix: prevent malformed websocket messages from crashing the server * chore: increment version * fix: remove gaps between host rows in the sidebar list Keep sub-pixel row measurements and stop wiping the size cache on hover. * fix: Failed to connect through jump hosts (#1180) https://github.com/Termix-SSH/Support/issues/1180 * feat: Progress bar for file downloads in the file manager (#1158) https://github.com/Termix-SSH/Support/issues/1158 * feat: Allow setting Silent OIDC Login via ENV var (#1174) https://github.com/Termix-SSH/Support/issues/1174 * feat: `IdentityFile` to limit the number of attempts by agents (#1165) https://github.com/Termix-SSH/Support/issues/1165 * feat: Credentials clone (#1159) https://github.com/Termix-SSH/Support/issues/1159 * chore: update release notes * docs: move helm setup guide to the docs site * fix: type errors in FilteredAgent agent identity handling * fix: remove stale better-sqlite3 prebuilds so the source build is used * fix: actually build better-sqlite3 from source so arm64 docker images work * fix: credential edit pencil in host editor and add clone action to credential list * fix: clear editingHost so the credential pencil actually opens the editor * chore: run format and lint * fix: folder drag and drop upload failing in the file manager * chore: sync Crowdin translations for 2.7.1 --------- Co-authored-by: alex-ctms <alex-ctms@users.noreply.github.com> Co-authored-by: ZacharyZcR <zacharyzcr1984@gmail.com> Co-authored-by: Chetan Kumar <74929596+ckloop@users.noreply.github.com> Co-authored-by: Chetan <chetan.development@gmail.com> Co-authored-by: Codebuff <noreply@codebuff.com> Co-authored-by: ZacharyZcR <payasonorahc@protonmail.com> Co-authored-by: dropafterfree <maxime.bonillo@gmail.com> Co-authored-by: Maxime Bonillo <257463937+dropafterfree@users.noreply.github.com>
194 lines
5.6 KiB
TypeScript
194 lines
5.6 KiB
TypeScript
import { statsLogger } from "../utils/logger.js";
|
|
import { automationFetch } from "./http.js";
|
|
import type { TemplateContext } from "./template.js";
|
|
|
|
/**
|
|
* Notification delivery for automations.
|
|
*
|
|
* The alert engine special-cased Discord because its dispatcher only knew
|
|
* webhook and ntfy; here every transport goes through one switch, so adding a
|
|
* channel type is a single edit.
|
|
*/
|
|
export interface AutomationChannel {
|
|
id: number;
|
|
type: string;
|
|
config: string;
|
|
}
|
|
|
|
export interface AutomationNotification {
|
|
title: string;
|
|
body: string;
|
|
severity: "info" | "warning" | "critical";
|
|
context?: TemplateContext;
|
|
}
|
|
|
|
const NTFY_PRIORITY: Record<string, number> = {
|
|
info: 2,
|
|
warning: 3,
|
|
critical: 5,
|
|
};
|
|
|
|
const NTFY_TAGS: Record<string, string> = {
|
|
info: "information_source",
|
|
warning: "warning",
|
|
critical: "rotating_light",
|
|
};
|
|
|
|
const DISCORD_COLORS: Record<string, number> = {
|
|
info: 3066993,
|
|
warning: 16753920,
|
|
critical: 15158332,
|
|
};
|
|
|
|
export async function sendAutomationNotification(
|
|
channel: AutomationChannel,
|
|
notification: AutomationNotification,
|
|
): Promise<void> {
|
|
let config: Record<string, unknown>;
|
|
try {
|
|
config = JSON.parse(channel.config) as Record<string, unknown>;
|
|
} catch {
|
|
throw new Error("Channel configuration is not valid JSON");
|
|
}
|
|
|
|
const allowPrivateNetwork = config.allowPrivateNetwork === true;
|
|
|
|
switch (channel.type) {
|
|
case "webhook":
|
|
return sendWebhook(config, notification, allowPrivateNetwork);
|
|
case "ntfy":
|
|
return sendNtfy(config, notification, allowPrivateNetwork);
|
|
case "discord":
|
|
return sendDiscord(config, notification, allowPrivateNetwork);
|
|
default:
|
|
throw new Error(`Unsupported channel type: ${channel.type}`);
|
|
}
|
|
}
|
|
|
|
function requireUrl(config: Record<string, unknown>): string {
|
|
const url = typeof config.url === "string" ? config.url.trim() : "";
|
|
if (!url) throw new Error("Channel is missing a URL");
|
|
return url;
|
|
}
|
|
|
|
async function sendWebhook(
|
|
config: Record<string, unknown>,
|
|
notification: AutomationNotification,
|
|
allowPrivateNetwork: boolean,
|
|
): Promise<void> {
|
|
const url = requireUrl(config);
|
|
const method = config.method === "PUT" ? "PUT" : "POST";
|
|
const headers =
|
|
config.headers && typeof config.headers === "object"
|
|
? (config.headers as Record<string, string>)
|
|
: {};
|
|
|
|
const response = await automationFetch(url, {
|
|
method,
|
|
headers,
|
|
body: JSON.stringify({
|
|
title: notification.title,
|
|
hostName:
|
|
notification.context?.host?.name ??
|
|
notification.context?.trigger?.hostName,
|
|
hostId:
|
|
notification.context?.host?.id ?? notification.context?.trigger?.hostId,
|
|
ruleName: notification.title,
|
|
ruleId: notification.context?.run?.automationId,
|
|
triggerType: notification.context?.trigger?.type,
|
|
value: notification.context?.trigger?.value,
|
|
threshold: notification.context?.trigger?.threshold,
|
|
message: notification.body,
|
|
severity: notification.severity,
|
|
timestamp: new Date().toISOString(),
|
|
}),
|
|
allowPrivateNetwork,
|
|
});
|
|
|
|
if (!response.ok) {
|
|
throw new Error(`HTTP ${response.status} ${response.statusText}`);
|
|
}
|
|
}
|
|
|
|
async function sendNtfy(
|
|
config: Record<string, unknown>,
|
|
notification: AutomationNotification,
|
|
allowPrivateNetwork: boolean,
|
|
): Promise<void> {
|
|
const base = requireUrl(config).replace(/\/$/, "");
|
|
const topic = typeof config.topic === "string" ? config.topic.trim() : "";
|
|
if (!topic) throw new Error("ntfy channel is missing a topic");
|
|
|
|
const headers: Record<string, string> = {
|
|
Title: notification.title || "Termix automation",
|
|
Priority: String(NTFY_PRIORITY[notification.severity] ?? 3),
|
|
Tags: NTFY_TAGS[notification.severity] ?? "information_source",
|
|
};
|
|
if (typeof config.token === "string" && config.token) {
|
|
headers.Authorization = `Bearer ${config.token}`;
|
|
}
|
|
|
|
const response = await automationFetch(`${base}/${topic}`, {
|
|
method: "POST",
|
|
headers,
|
|
body: notification.body || notification.title,
|
|
allowPrivateNetwork,
|
|
});
|
|
|
|
if (!response.ok) {
|
|
throw new Error(`HTTP ${response.status} ${response.statusText}`);
|
|
}
|
|
}
|
|
|
|
async function sendDiscord(
|
|
config: Record<string, unknown>,
|
|
notification: AutomationNotification,
|
|
allowPrivateNetwork: boolean,
|
|
): Promise<void> {
|
|
const url = requireUrl(config);
|
|
const payload: Record<string, unknown> = {
|
|
embeds: [
|
|
{
|
|
title: notification.title || "Termix automation",
|
|
description: notification.body || undefined,
|
|
color: DISCORD_COLORS[notification.severity] ?? 3447003,
|
|
timestamp: new Date().toISOString(),
|
|
},
|
|
],
|
|
};
|
|
if (typeof config.username === "string" && config.username) {
|
|
payload.username = config.username;
|
|
}
|
|
if (typeof config.avatar_url === "string" && config.avatar_url) {
|
|
payload.avatar_url = config.avatar_url;
|
|
}
|
|
|
|
const response = await automationFetch(url, {
|
|
method: "POST",
|
|
body: JSON.stringify(payload),
|
|
allowPrivateNetwork,
|
|
});
|
|
|
|
if (!response.ok) {
|
|
const detail = await response.text().catch(() => "");
|
|
throw new Error(
|
|
`HTTP ${response.status} ${response.statusText}${detail ? `: ${detail}` : ""}`,
|
|
);
|
|
}
|
|
}
|
|
|
|
/** Fire-and-forget wrapper for callers that must not block on delivery. */
|
|
export function sendAutomationNotificationSafely(
|
|
channel: AutomationChannel,
|
|
notification: AutomationNotification,
|
|
): void {
|
|
sendAutomationNotification(channel, notification).catch((error) => {
|
|
statsLogger.warn("Automation notification failed", {
|
|
operation: "automation_notification_error",
|
|
channelId: channel.id,
|
|
type: channel.type,
|
|
error: error instanceof Error ? error.message : String(error),
|
|
});
|
|
});
|
|
}
|