Commit Graph
100 Commits
Author SHA1 Message Date
naiba eba91d2883 chore: update frontend 2026-08-03 20:17:37 +08:00
naiba a9d14a0dfa chore(frontend-templates): add Nezha-Pixel template 2026-08-01 20:21:57 +08:00
naiba f9e7cfa54b chore(frontend): update bundled template versions 2026-08-01 20:21:57 +08:00
naiba 4776dc9ec6 chore(deps): update direct Go dependencies 2026-08-01 20:21:56 +08:00
naiba 6c5317ba93 fix(security): correct stream quota advisory reference 2026-08-01 20:21:56 +08:00
naibaandnaiba/CloudCode 5d7e8b58af chore(frontend): update bundled template versions
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-21 13:11:43 +00:00
naibaandnaiba/CloudCode c893aa5786 fix(service): serialize reports with service lifecycle
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-21 13:11:05 +00:00
naibaandnaiba/CloudCode 77c298fa80 chore(deps): bump libdns-tencentcloud
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-21 02:42:47 +00:00
naibaandnaiba/CloudCode 479fcac11c test(agentcompat): wire FD diagnostics into stress
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 22:11:21 +00:00
naibaandnaiba/CloudCode 11eb339540 test(agentcompat): exercise real FD lifecycle diagnostics
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 22:10:29 +00:00
naibaandnaiba/CloudCode b204e3dda4 test(agentcompat): verify FD diagnostic collection
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 22:09:39 +00:00
naibaandnaiba/CloudCode 970d2ae672 test(agentcompat): model FD diagnostic lifecycles
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 22:08:01 +00:00
naibaandnaiba/CloudCode 1e67f4017a test(agentcompat): preserve default sampler evidence
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 22:07:09 +00:00
naibaandnaiba/CloudCode e78af86164 test(agentcompat): capture FD observations in process samples
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 22:06:19 +00:00
naibaandnaiba/CloudCode 8b352484d8 test(agentcompat): preserve existing CRLF workflow data
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:32:49 +00:00
naibaandnaiba/CloudCode 926f2ca632 chore(agentcompat): document intentional scanner findings
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:07:04 +00:00
naibaandnaiba/CloudCode 0332b1e212 fix(agentcompat): root workflow file reads
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:06:40 +00:00
naibaandnaiba/CloudCode 24c7a898cf test(agentcompat): cover CRLF workflow mutations
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:06:14 +00:00
naibaandnaiba/CloudCode 153dfeb569 fix(agentcompat): retain transfer sentinel handles
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:05:52 +00:00
naibaandnaiba/CloudCode 393f49aa59 fix(agentcompat): retain reconnect sentinel handles
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:05:29 +00:00
naibaandnaiba/CloudCode 20930aaf9f fix(agentcompat): root filesystem guard reads
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:05:10 +00:00
naibaandnaiba/CloudCode 23763c8210 fix(agentcompat): secure legacy file manager boundaries
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:04:52 +00:00
naibaandnaiba/CloudCode 029d458f50 fix(agentcompat): root scenario config reads
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:04:34 +00:00
naibaandnaiba/CloudCode e157304475 fix(agentcompat): root workspace log creation
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:04:16 +00:00
naibaandnaiba/CloudCode 9bc3068d14 fix(agentcompat): resolve trusted Go executable
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:03:55 +00:00
naibaandnaiba/CloudCode e20197fdcc fix(agentcompat): root proc resource reads
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:03:37 +00:00
naibaandnaiba/CloudCode 57f9564ce1 fix(agentcompat): decode inotify events safely
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:03:20 +00:00
naibaandnaiba/CloudCode b92ab9a60f fix(agentcompat): snapshot evidence through rooted handles
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:02:58 +00:00
naibaandnaiba/CloudCode 454c577968 fix(agentcompat): secure credentialed agent workspaces
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:02:37 +00:00
naibaandnaiba/CloudCode c7799854b9 fix(agentcompat): validate supervised executable paths
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 17:02:21 +00:00
naibaandnaiba/CloudCode 8a0382478b test(agentcompat): lock Agent stress preparation
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:16:31 +00:00
naibaandnaiba/CloudCode 396a0fcb21 ci: prepare dashboard inputs for stress
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:16:00 +00:00
naibaandnaiba/CloudCode 620bebbf8e test(agentcompat): find repository root across platforms
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:15:31 +00:00
naibaandnaiba/CloudCode 589b06b63d test(agentcompat): probe credential execution support
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:15:10 +00:00
naibaandnaiba/CloudCode dcab0d2245 fix(agentcompat): classify Windows absolute paths
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:14:37 +00:00
naibaandnaiba/CloudCode 866ddddef1 test(agentcompat): make dedicated fixtures platform-native
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:13:41 +00:00
naibaandnaiba/CloudCode 3bdbfd2593 test(agentcompat): use native validation paths
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:13:41 +00:00
naibaandnaiba/CloudCode ccfee605bf test(agentcompat): use native evidence metadata paths
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:13:08 +00:00
naibaandnaiba/CloudCode a60924b6c7 test(agentcompat): use native contract paths
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:12:38 +00:00
naibaandnaiba/CloudCode 56671d5509 test(agentcompat): define Windows evidence mode semantics
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:11:44 +00:00
naibaandnaiba/CloudCode 1c881ed6d2 test(agentcompat): isolate Unix evidence mode checks
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:11:16 +00:00
naibaandnaiba/CloudCode ffbb8bed09 fix(agentcompat): validate evidence modes by platform
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:10:40 +00:00
naibaandnaiba/CloudCode 381eee0cec fix(agentcompat): constrain command harness to Linux
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 14:09:20 +00:00
naibaandnaiba/CloudCode 5d7fef6408 test(agentcompat): isolate stress resource sampling
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 08:04:17 +00:00
naibaandnaiba/CloudCode a7cf600bd7 test(agentcompat): configure connection count sampling
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 08:02:45 +00:00
naibaandnaiba/CloudCode 02ccdf038c test(agentcompat): expose connection count fixture option
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 08:02:19 +00:00
naibaandnaiba/CloudCode d96b34b0d4 ci: require agentcompat stress validation
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:55:20 +00:00
naibaandnaiba/CloudCode d501f23473 test(agentcompat): add exact stress scenario
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:54:03 +00:00
naibaandnaiba/CloudCode 64daa6e9ae test(agentcompat): add scenario CLI wiring
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:52:28 +00:00
naibaandnaiba/CloudCode 9af3720bf0 test(agentcompat): add integration scenarios
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:51:20 +00:00
naibaandnaiba/CloudCode b3b3d92895 test(agentcompat): add evidence validation
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:50:03 +00:00
naibaandnaiba/CloudCode 1c3e926819 test(agentcompat): add protocol clients
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:48:15 +00:00
naibaandnaiba/CloudCode 8a0e84b214 test(agentcompat): add dashboard runtime harness
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:46:55 +00:00
naibaandnaiba/CloudCode 2a3245c412 test(agentcompat): add agent runtime harness
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:45:05 +00:00
naibaandnaiba/CloudCode 3a9e0c7887 test(agentcompat): add process supervision harness
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:43:28 +00:00
naibaandnaiba/CloudCode 0543995ec3 test(agentcompat): harden deterministic fixtures
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:42:03 +00:00
naibaandnaiba/CloudCode fcf58b0b4b test(agentcompat): define integration contracts
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:39:48 +00:00
naibaandnaiba/CloudCode 391f622c75 test(agentcompat): cover SQLite hold arbitration
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:37:59 +00:00
naibaandnaiba/CloudCode 52c766d27c test(rpc): cover reentrant state observers
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:36:50 +00:00
naibaandnaiba/CloudCode aee586baad feat(agentcompat): add dashboard listener hooks
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:33:38 +00:00
naibaandnaiba/CloudCode 3f6de265a0 fix(mcp): harden dashboard dispatch lifecycle
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:32:16 +00:00
naibaandnaiba/CloudCode 2640b86d3a feat(agentcompat): expose dashboard capability routes
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:30:50 +00:00
naibaandnaiba/CloudCode 0c6eb416a5 feat(agentcompat): add SQLite hold scoped attribution
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:29:21 +00:00
naibaandnaiba/CloudCode 26e92da33b feat(agentcompat): add scoped IO stream capabilities
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:27:33 +00:00
naibaandnaiba/CloudCode c756ef9385 fix(rpc): make IO stream lifecycle race-safe
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:26:19 +00:00
naibaandnaiba/CloudCode 8b47ff141f feat(agentcompat): add shared runtime contracts
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-20 04:25:03 +00:00
naibaandnaiba/CloudCode a416e3bf29 test(compat): complete NAT fixture shutdown
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-14 06:13:57 +00:00
naibaandnaiba/CloudCode be9af6fcb3 test(compat): harden fixture containment cleanup
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-14 06:12:00 +00:00
naibaandnaiba/CloudCode 92a1cc76be test(compat): add deterministic local fixtures
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-14 05:49:15 +00:00
naibaandnaiba/CloudCode b01ff45ef4 chore(frontend-templates): bump user-dist v2.4.1 and aobobo-dist v1.4.6
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-12 06:27:58 +00:00
naibaandnaiba/CloudCode 1477138dad chore(frontend-templates): bump admin-dist v2.2.5, user-dist v2.3.2 and aobobo-dist v1.4.5
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-07-04 11:08:03 +00:00
naibaandnaiba/CloudCode fd31e5f1b0 chore(frontend-templates): add aobobo template
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-06-28 01:09:23 +00:00
naibaandnaiba/CloudCode e1045ffd30 fix(api): redact profile password hash
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-06-28 01:09:23 +00:00
naiba 6aab2e4919 Merge pull request #1213 from nezhahq/dependabot/github_actions/github-actions-02325a8da5
chore(deps): bump the github-actions group with 2 updates
2026-06-27 11:30:04 +08:00
naibaandnaiba/CloudCode d750fa035d chore(frontend-templates): bump user-dist v2.3.1
Co-authored-by: naiba/CloudCode <hi+cloudcode@nai.ba>
2026-06-20 11:01:54 +00:00
naiba d556c3216f chore(frontend-templates): bump user-dist v2.3.0 and nazhua-dist v1.1.0 2026-06-20 00:40:38 +00:00
naiba 8cd2da79b8 chore(frontend-templates): bump admin-dist v2.2.4 2026-06-20 00:39:47 +00:00
naiba 874a47c32c Merge pull request #1211 from hamster1963/fix-service
Filter service stats based on user permissions
2026-06-20 08:25:15 +08:00
naiba 3d74cd9431 fix(alert): retain Duration samples for offline rules so they fire
RetentionWindow() trimmed offline-rule samples to 1, but Check's offline
branch reads points[len-Duration:] and needs Duration samples. The window
never filled, boundCheck always returned "passed", and offline alerts never
fired a notification — while other alert types worked. Offline rules now
retain Duration samples (cycle rules still keep 1, matching their last-sample
lookback).

Fixes the prior over-correction in RetentionWindow; corrects the test that
had pinned the buggy offline=1 value, and adds offline + combined-rule
regression tests driving the real trim loop.
2026-06-08 00:57:14 +00:00
naiba 576e6773c0 fix(release): bump user-dist to v2.1.2 (v2.1.1 never released upstream)
The v2.2.2 Release workflow failed: fetch-frontends.sh fetched user-dist
from hamster1963/nezha-dash-v2 at v2.1.1, but upstream went v2.1.0 -> v2.1.2
and never tagged v2.1.1, so the dist.zip download 404'd and unzip aborted the
build. Point at the existing v2.1.2 asset.
2026-06-07 16:23:24 +00:00
naiba b12b1709d9 test(alert): pin sample-slice memory-boundedness invariant
Add TestCheckStatus_SampleMemoryBounded asserting that, across 100k ticks,
the per-(alert,server) sample slice length and capacity stay bounded by the
rule's retention window and never grow with elapsed time.
2026-06-07 16:14:31 +00:00
naiba e756b4540c fix(alert): keep sample history by rule-defined retention window
Trim alert samples using AlertRule.RetentionWindow() (max rule duration)
instead of Check()'s verdict max, which is 0 while a rule's window is still
filling. The old max<=0 trim wiped history every tick, so Duration>=2 general
rules never accumulated enough samples and never fired a notification.

Add model + end-to-end singleton regression tests covering sample
accumulation, the retention-window contract, and the actual notify path.
2026-06-07 16:11:43 +00:00
naiba 66de244c2e feat(oauth2): add dashboard_host setting for callback URL
Decouple OAuth2 callback host from agent install host. When dashboard_host
is empty, the request Host is passed through; otherwise non-reserved hosts
are pinned to dashboard_host. Added to reserved-host allowlist for NAT.
2026-06-06 05:03:12 +00:00
naiba c595728609 chore(frontend-templates): bump admin-dist v2.2.2 and user-dist v2.1.1 2026-06-06 04:55:31 +00:00
naiba 6e9510d26a chore(frontend-templates): bump admin-dist v2.2.0 2026-06-05 02:42:58 +00:00
naiba 5fd91c44b0 test(rpc): cover both-key-styles present in agent auth metadata
After #1197/#244 a new agent emits both hyphenated and underscore credential
metadata, so a new dashboard receives both at once. Add tests for the everyday
both-present case and pin that the hyphenated key takes precedence over the
underscore alias that Caddy v2.11.4 strips.
2026-06-05 02:42:58 +00:00
naiba 0759f5c801 fix(alert): prevent divide-by-zero panic and unbounded growth on zero-duration rule
A general alert rule with Duration:0 (accepted by the API, no minimum
validation) drove fail*100/total with total==0, panicking with an integer
divide-by-zero inside checkStatus, which has no recover and would take down the
whole alert goroutine — a config-reachable DoS by any user able to create alert
rules. Skip duration<=0 rules in Check via continue (not boundCheck, which would
pollute hasPassedRule and skip sibling valid rules). Also trim the sample slice
when max<=0 in alertsentinel, otherwise it appended every tick without ever
trimming. Adds regression tests for zero-only and mixed rule sets.
2026-06-05 02:42:49 +00:00
naiba 36240f5888 fix(rpc): cap concurrent IO streams per user and per server
GHSA-jg62-j5h6-8mpq: the terminal and file-manager endpoints created unbounded
IO streams; an authenticated member could open thousands, each spawning
goroutines, a 1MiB buffer and an agent-side PTY, exhausting dashboard and agent
resources. CreateStream now enforces a per-user (20) and per-server (40) cap in
the existing ioStreamMutex critical section, using the stream map as the single
source of truth. Dashboard-internal streams (uid==0: NAT, server transfer, MCP
transfer) skip the per-user cap but still count per-server. Adds caps,
exemption, slot-release and no-leak regression tests.
2026-06-05 02:42:38 +00:00
naiba fb5c37e983 fix(oauth2): validate Host header against allowlist for callback URL
GHSA-9rc6-8cjv-rcvx: getRedirectURL derived the OAuth2 callback URL from the
raw Host header, so a forged Host (or a provider with loose redirect-URI
matching) could divert a victim's authorization code to an attacker origin and
bind their identity. Trust the request Host only when it is an operator-declared
dashboard host (IsReservedDashboardHost, same allowlist guarding NAT routing);
otherwise fall back to the configured InstallHost.
2026-06-05 02:42:28 +00:00
naiba 1927b0c6a4 chore(ci): add dependabot version updates for gomod and actions
Repo only had Dependabot security updates (reactive). Add weekly grouped
version updates for Go modules and GitHub Actions to keep dependencies
current and reduce CVE accumulation.
2026-06-05 01:08:00 +00:00
naiba 78f5b014ee fix(csrf): set Secure on csrf cookie only over HTTPS
CodeQL go/cookie-secure-not-set (CWE-614) flagged the nz-csrf cookie as
missing the Secure attribute. Mirror writeOauth2StateCookie and derive
Secure from the request scheme instead of hardcoding it: forcing
Secure=true would make browsers drop the cookie on plain-HTTP intranet
deployments, breaking the double-submit CSRF pair and 403-ing every
unsafe request.
2026-06-05 01:08:00 +00:00
naiba c3c361ad66 fix(service): flip CopyStats public filter to HideForGuest
Completes the EnableShowInService->HideForGuest rename; the public stats
filter was missed in the previous commit, leaving service/singleton
referencing the removed field and breaking the build.
2026-06-02 03:32:10 +00:00
naiba e47b5b99f8 chore(frontend-templates): bump admin-dist v2.1.2 and user-dist v2.1.0 2026-06-02 03:31:36 +00:00
naiba 8285a3d99f docs(mcp): note server.exec reaps the whole process tree
Document in the tool description and protocol comment that the agent
kills the entire process group/JobObject on return or timeout, so
background jobs must fully detach (setsid/screen/tmux/systemd-run).
2026-06-02 03:31:36 +00:00
naiba 836f1db4b7 feat(service): replace EnableShowInService with HideForGuest
Mirror the server HideForGuest flag on services: rename the field
(dropping the gorm default), invert userCanViewService so a service is
visible to guests by default and hidden only when HideForGuest is set,
and flip the public-stats filter in servicesentinel accordingly. Update
the visibility and permission-matrix tests to the new semantics.
2026-06-02 03:31:36 +00:00
naiba bb38a9d4d2 fix(mcp): accept agents reporting version without v prefix and stop masking tool errors
compareSemver fell back to lexical string ordering when the numeric
segments were equal, so an agent reporting "2.1.0" compared as older than
the gate constant "v2.1.0" (0x32 < 0x76). This wrongly flagged every agent
as unsupported_agent, breaking server.exec and fs.* on all online servers.
Drop the fallback: semverParts already strips the v prefix, so equal
numeric segments mean equal versions.

The error was further masked because tool error responses shipped a
structuredContent {error_code,error} that violates the tool outputSchema
(which requires exit_code/stdout/...). Strict MCP clients validated it and
rejected the whole response with -32602, hiding the real isError text.
Omit structuredContent on error; the cause stays in content[].text.
2026-05-31 16:18:57 +00:00
naiba 9b5199ac6c chore(frontend-templates): bump admin-frontend to v2.1.1 2026-05-31 15:14:48 +00:00
naiba 083bc985c5 feat(auth): split inventory scope out of server scope
Carve a new nezha:inventory:{read,delete,*} resource family out of
nezha:server:*. Listing and deleting servers/server-groups (GET /server,
/server-group, /ws/server, batch-delete/server[-group], MCP server.list)
now require nezha:inventory:*, while nezha:server:* covers per-server
runtime operations (get, exec, fs, config, metrics, batch-move,
force-update).

Also declare MCP tool OutputSchema for exec/fs/meta/server/transfer and
wrap server.list output in {servers,count} so strict MCP clients accept
the structured result. Correct the /file all-of scope entry and the stale
server:read documentation.
2026-05-31 15:14:41 +00:00
naiba f7f8264ec0 fix(auth): always serialize User.Role so admin (role 0) is not omitted
The Role field used json:"role,omitempty". Admin is RoleAdmin = 0, so an
admin profile serialized without a `role` key. The admin-frontend gates the
admin menu (user management, settings) on `role === 0`, and its normalizeRole
helper defaults a missing role to non-admin, so admins lost the admin menu.

Drop omitempty so role 0 is always sent. Add a regression test.
2026-05-31 12:05:11 +00:00
naibaandcloudcode 34ab8a31bc chore(frontend-templates): bump admin-frontend to v2.1.0
Embed the admin-frontend v2.1.0 release (PAT UI, CSRF handling, reserved
hosts) so the upcoming backend v2.1.0 ships the matching frontend.

Co-authored-by: cloudcode <cloudcode@users.noreply.github.com>
2026-05-31 10:26:41 +00:00