Files
multi-simadmin/server/core.js
T
chick 2977f75129 fix: apply security and correctness review findings across both stacks
Legacy panel:
- upstream body reads now carry their own deadline and a 10 MB byte budget;
  a stalled modem can no longer hang /api/status fan-out forever nor OOM
  the proxy (request headers alone had the timeout, bodies had none)
- add X-Frame-Options DENY / CSP frame-ancestors none / nosniff; the panel
  (delete-instance and confirmed-write dialogs) is no longer clickjackable
- only send a JSON content-type when the API console request has a body, so
  payload-less dangerous writes stop failing with 400 and burning the
  one-use confirmation token
- register a form-urlencoded parser (the proxy branch was unreachable) and
  drop the multipart parser that buffered up to 60 MB before rejecting;
  bodyLimit drops to 2 MB; framework-level 415 keeps the stable error body
- remove /api/sms/send from readable paths: GET bypassed the write
  confirmation for a send endpoint
- /api/instances/:id/login maps upstream failures to a stable 502 instead
  of leaking raw error text
- guard MULTI_SIMADMIN_TIMEOUT_MS parsing (NaN aborted every request);
  prune dead code (buildClients, cookie expando no-op)

Control plane:
- deleting a notification channel detaches it from rules instead of leaving
  dangling ids that made every referencing rule unreadable and silently
  dropped future notifications; rule reads tolerate unknown ids
- startup sweep resets notification_queue rows stranded in 'sending' by a
  crash (mirrors the sms outbox sweep); terminal outbox rows are pruned on
  the retention timer
- /api/v1/metrics no longer emits operator-assigned node names on the
  session-free scrape; login limiter map is bounded and pruned; Secure
  cookie honors the gateway-declared x-forwarded-proto
- webhook delivery sets redirect: manual (signed payloads are not replayed)
- SMTP envelope sender is validated against CR/LF smuggling
- scheduled reboots with delaySeconds != 3 fail fast at the dispatcher with
  a clear reason instead of burning every retry; contract narrowed to the
  pinned baseline
2026-09-07 01:57:47 +08:00

253 lines
9.5 KiB
JavaScript

export { normalizeBaseUrl, normalizeInstance } from './config/schema.js'
function parsePositiveIntEnv(value, fallback) {
const parsed = Number(value)
return Number.isFinite(parsed) && parsed > 0 ? parsed : fallback
}
export const DEFAULT_TIMEOUT_MS = parsePositiveIntEnv(process.env.MULTI_SIMADMIN_TIMEOUT_MS, 6000)
export const DEFAULT_MAX_BODY_BYTES = parsePositiveIntEnv(process.env.MULTI_SIMADMIN_MAX_BODY_BYTES, 10 * 1024 * 1024)
export function redactInstance(instance) {
return {
id: instance.id,
name: instance.name,
url: instance.url,
description: instance.description,
tags: instance.tags || [],
auth: {
mode: instance.auth?.mode || 'none',
hasPassword: Boolean(instance.auth?.password),
},
capabilities: instance.capabilities || [],
}
}
function apiData(payload) {
return payload?.data ?? payload
}
function pickDevice(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
imei: data.imei || data.IMEI || null,
manufacturer: data.manufacturer || data.vendor || null,
model: data.model || data.device_model || null,
firmware: data.firmware || data.firmware_version || data.version || data.revision || null,
revision: data.revision || null,
powered: data.powered ?? data.power ?? null,
online: data.online ?? data.is_online ?? null,
}
}
function pickSim(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
iccid: data.iccid || data.ICCID || null,
imsi: data.imsi || data.IMSI || null,
phoneNumber: data.phone_number || data.phoneNumber || data.msisdn || (Array.isArray(data.phone_numbers) ? data.phone_numbers[0] : null) || null,
phoneNumbers: data.phone_numbers || data.phoneNumbers || null,
operator: data.operator || data.operator_name || null,
signal: data.signal || data.signal_strength || null,
present: data.present ?? data.inserted ?? null,
smsCenter: data.sms_center || data.smsCenter || null,
}
}
function pickNetwork(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
operator: data.operator || data.operator_name || data.provider || null,
registration: data.registration || data.registration_state || data.registration_status || data.status || null,
accessTechnology: data.access_technology || data.accessTechnology || data.rat || data.mode || data.technology_preference || null,
signal: data.signal || data.signal_strength || data.rssi || null,
mcc: data.mcc || null,
mnc: data.mnc || null,
}
}
function pickSms(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
total: data.total ?? data.total_count ?? data.count ?? null,
unread: data.unread ?? data.unread_count ?? null,
conversations: data.conversations ?? data.conversation_count ?? null,
incoming: data.incoming ?? null,
outgoing: data.outgoing ?? null,
pushed: data.pushed ?? null,
pushAttempted: data.push_attempted ?? data.pushAttempted ?? null,
}
}
function pickDataStatus(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
enabled: data.enabled ?? data.data_enabled ?? null,
connected: data.connected ?? data.is_connected ?? null,
roaming: data.roaming ?? data.roaming_allowed ?? null,
active: data.active ?? null,
}
}
function pickOta(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
currentVersion: data.current_version || data.currentVersion || data.version || null,
latestVersion: data.latest_version || data.latestVersion || null,
updateAvailable: data.update_available ?? data.updateAvailable ?? null,
pendingUpdate: data.pending_update ?? data.pendingUpdate ?? null,
currentCommit: data.current_commit || data.currentCommit || null,
}
}
function pickSystem(data) {
data = apiData(data)
if (!data || typeof data !== 'object') return null
return {
cpuLoad: data.cpu_load ?? data.cpuLoad ?? null,
memory: data.memory || null,
disk: data.disk || null,
networkSpeed: data.network_speed || data.networkSpeed || null,
info: data.system_info || data.systemInfo || null,
temperature: data.temperature || null,
uptime: data.uptime ?? null,
}
}
export function summarizeInstanceSnapshot(raw) {
return {
device: pickDevice(raw.device),
sim: pickSim(raw.sim),
network: pickNetwork(raw.network),
sms: pickSms(raw.smsStats),
data: pickDataStatus(raw.data),
ota: pickOta(raw.ota),
system: pickSystem(raw.stats),
stats: apiData(raw.stats) || null,
calls: apiData(raw.calls) || null,
}
}
function parseSetCookie(value) {
if (!value) return []
if (Array.isArray(value)) return value
return [String(value)]
}
class CookieJar {
constructor() { this.map = new Map() }
setFromHeaders(headers) {
const raw = headers.getSetCookie ? headers.getSetCookie() : parseSetCookie(headers.get('set-cookie'))
for (const line of raw) {
const [pair] = String(line).split(';')
const eq = pair.indexOf('=')
if (eq <= 0) continue
const name = pair.slice(0, eq).trim()
const value = pair.slice(eq + 1).trim()
if (value) this.map.set(name, value)
else this.map.delete(name)
}
}
header() {
return [...this.map.entries()].map(([k, v]) => `${k}=${v}`).join('; ')
}
clear() { this.map.clear() }
}
export function createSimAdminClient(instance, { fetchImpl = fetch, timeoutMs = DEFAULT_TIMEOUT_MS } = {}) {
instance = structuredClone(instance)
const jar = new CookieJar()
async function request(endpoint, options = {}) {
const url = new URL(endpoint, instance.url)
const controller = new AbortController()
const timer = setTimeout(() => controller.abort(), options.timeoutMs || timeoutMs)
const headers = new Headers(options.headers || {})
const cookie = jar.header()
if (cookie && !headers.has('cookie')) headers.set('cookie', cookie)
try {
const response = await fetchImpl(url, { ...options, headers, signal: controller.signal, redirect: options.redirect || 'manual' })
jar.setFromHeaders(response.headers)
return response
} finally {
clearTimeout(timer)
}
}
async function fetchJson(endpoint, options = {}) {
const startedAt = Date.now()
const response = await request(endpoint, { method: 'GET', ...options, headers: { accept: 'application/json,text/plain,*/*', ...(options.headers || {}) } })
const text = (await readResponseBody(response, { bodyTimeoutMs: options.timeoutMs || timeoutMs })).toString('utf8')
let data = null
try { data = text ? JSON.parse(text) : null } catch {}
return { ok: response.ok, status: response.status, latencyMs: Date.now() - startedAt, data, text: data ? undefined : text.slice(0, 1000), headers: response.headers }
}
let ephemeralSecret = ''
async function ensureAuthenticated({ credential } = {}) {
const status = await fetchJson('/api/auth/status')
const auth = apiData(status.data) || {}
const protectionEnabled = auth.settings?.password_protection_enabled ?? auth.settings?.passwordProtectionEnabled
if (auth.authenticated || protectionEnabled === false || auth.configured === false) {
return { configured: auth.configured ?? null, authenticated: Boolean(auth.authenticated || protectionEnabled === false), loginAttempted: false, statusCode: status.status }
}
const password = credential === undefined ? (ephemeralSecret || instance.auth?.password) : String(credential || '')
if (!password) {
if (status.status === 404 && instance.auth?.mode === 'none') return { configured: null, authenticated: null, loginAttempted: false, statusCode: status.status, reason: 'auth_status_unsupported' }
return { configured: auth.configured ?? null, authenticated: false, loginAttempted: false, statusCode: status.status, reason: 'password_required' }
}
if (credential !== undefined) ephemeralSecret = ''
const login = await request('/api/auth/login', {
method: 'POST',
headers: { 'content-type': 'application/json', accept: 'application/json' },
body: JSON.stringify({ password }),
})
if (credential !== undefined && login.ok) ephemeralSecret = password
return { configured: auth.configured ?? null, authenticated: login.ok, loginAttempted: true, statusCode: login.status, reason: login.ok ? null : 'login_failed' }
}
function clearEphemeralSecret() { ephemeralSecret = '' }
return { instance, jar, request, fetchJson, ensureAuthenticated, clearEphemeralSecret }
}
// The header timeout ends once headers arrive; body reads need their own
// deadline and a byte budget so a stalled or hostile upstream can neither hang
// status aggregation nor exhaust memory.
export async function readResponseBody(response, { maxBytes = DEFAULT_MAX_BODY_BYTES, bodyTimeoutMs = DEFAULT_TIMEOUT_MS } = {}) {
const reader = response.body?.getReader()
if (!reader) return Buffer.alloc(0)
const chunks = []
let size = 0
let failure = null
const timer = setTimeout(() => {
failure = new Error('upstream response body timed out')
reader.cancel(failure).catch(() => {})
}, bodyTimeoutMs)
try {
while (true) {
const { done, value } = await reader.read()
if (done) break
size += value.byteLength
if (size > maxBytes) {
failure = new Error('upstream response body exceeded the size limit')
throw failure
}
chunks.push(Buffer.from(value))
}
} finally {
clearTimeout(timer)
}
if (failure) {
await reader.cancel(failure).catch(() => {})
throw failure
}
return Buffer.concat(chunks)
}