mirror of
https://github.com/binaricat/Netcatty.git
synced 2026-09-24 15:49:09 +00:00
904af93a1d
* fix(credentials): stop double-encrypting undecryptable safeStorage blobs When local decrypt failed (e.g. OSCrypt key churn after reboot), encrypt used to wrap the leftover enc:v1 ciphertext again, permanently poisoning the vault. Startup sync could also push those placeholders to cloud and make download restore the same poison. - Keep real enc:v1 blobs unchanged on encrypt (header check, no wrap) - Strip device-bound placeholders when applying portable sync payloads - Guard startup local-wins / merge round-trips before upload - Skip vault init re-encrypt writes when secrets are still undecrypted Fixes #2702 Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(sync): strip enc:v1 secrets from smart-merge uploads Bugbot found that after local apply sanitized placeholders, legacy v1 smart-merge could still decrypt an unstripped remote, merge it, and re-upload the poison. Strip device-bound credentials on remote decrypt and again on the merged payload before upload. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(credentials): address Codex P2 review on #2702 - Always re-encrypt vault init batches so plaintext siblings are not left unprotected when one record is a stale enc:v1 placeholder - Sanitize device-bound secrets before convergent restore prepare so CRDT replica commit matches vault import - Require a complete safeStorage blob (header + min 31 bytes) before treating enc:v1 as ciphertext; encrypt header-only coincidences Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(credentials): address Codex P1 review on #2702 - Decode enc:v1 payloads with atob in the renderer-safe domain helper - Heal poisoned remote secrets from local/base before smart-merge so good credentials are not discarded as remote-only deletions - Keep post-merge strip so leftover enc:v1 never uploads Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(credentials): address Codex P1 CBC min and startup heal - Accept 19-byte v10/v11 CBC OSCrypt blobs (not only 31-byte GCM) - Heal poisoned remote secrets before startup smart-merge - Strip unresolved placeholders on merge round-trip upload Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(sync): sanitize payloads at every apply/commit boundary Codex P1: vault apply stripped enc:v1 while commitRemoteInspection and convergent materialization could keep the poison. Sanitize merged/remote payloads before apply+base commit, strip on CRDT materialization, and sanitize convergent apply inputs. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(sync): heal local and remote secrets before smart-merge Smart-merge could select a locally-changed entity whose only secret delta was enc:v1 poison, then strip and upload empty secrets. Heal both sides from the opposite payload/base before merge on all sync paths. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(sync): keep enc:v1 intact during convergent materialize Stripping device-bound secrets inside materializeSyncPayloadFromConvergentState broke envelope validation for poisoned-but-consistent v2 snapshots, so decrypt could not hydrate the clouds #2702 needs to recover. Portable stripping stays at apply/upload boundaries. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(credentials): detect Windows DPAPI by decoded header bytes Real DPAPI blobs start with 01 00 00 00 d0 8c... and base64-encode as AQAAANCM..., so the previous AQAAAA string prefix rejected them and allowed double-wrapping after key rotation. Match decoded headers in both the main-process bridge and renderer predicate. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * test(credentials): use complete enc:v1 fixtures for stricter detector Short placeholders like enc:v1:djEwAAAA no longer pass the platform header + minimum-size checks. Update auth/SFTP/proxy/sync fixtures to full v10-shaped blobs so npm test matches production validation. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(sync): treat preferred credential deletions as authoritative When healing enc:v1 before merge, an empty/missing secret on a present preferred entity is an intentional clear and must not be revived from base. Only fall back to base when preferred is absent or also poisoned. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(credentials): reject impossible v10/v11 ciphertext lengths Accept only CBC-aligned sizes (19+16n) or GCM-sized blobs (>=31) so coincidental enc:v1 plaintext of intermediate length is encrypted instead of treated as an undecryptable placeholder. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> * fix(credentials): require full DPAPI provider GUID signature Accept Windows safeStorage blobs only when they start with version 01 00 00 00 plus provider GUID df9d8cd0-1501-11d1-8c7a-00c04fc297eb, so coincidental 01 00 00 00 prefixes are not treated as ciphertext. Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com> --------- Co-authored-by: Cursor Agent <cursoragent@cursor.com> Co-authored-by: 陈大猫 <binaricat@users.noreply.github.com>
384 lines
9.2 KiB
TypeScript
384 lines
9.2 KiB
TypeScript
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
import type { Host, Identity, ProxyProfile } from "./models.ts";
|
|
import {
|
|
formatProxyConfigEndpoint,
|
|
formatProxyConfigType,
|
|
findIncompleteProxyIdentityId,
|
|
isCompleteProxyConfig,
|
|
normalizeManualProxyConfig,
|
|
materializeHostProxyProfile,
|
|
findMissingProxyIdentityId,
|
|
removeProxyProfileReferences,
|
|
resolveProxyConfigAuth,
|
|
updateProxyConfigField,
|
|
} from "./proxyProfiles.ts";
|
|
|
|
const profile = (overrides: Partial<ProxyProfile> = {}): ProxyProfile => ({
|
|
id: "proxy-1",
|
|
label: "Office Proxy",
|
|
config: {
|
|
type: "socks5",
|
|
host: "proxy.example.com",
|
|
port: 1080,
|
|
username: "alice",
|
|
password: "secret",
|
|
},
|
|
createdAt: 1,
|
|
updatedAt: 1,
|
|
...overrides,
|
|
});
|
|
|
|
const host = (overrides: Partial<Host> = {}): Host => ({
|
|
id: "host-1",
|
|
label: "Server",
|
|
hostname: "server.example.com",
|
|
username: "root",
|
|
os: "linux",
|
|
tags: [],
|
|
protocol: "ssh",
|
|
...overrides,
|
|
});
|
|
|
|
test("materializeHostProxyProfile resolves a selected proxy profile", () => {
|
|
const resolved = materializeHostProxyProfile(
|
|
host({ proxyProfileId: "proxy-1" }),
|
|
[profile()],
|
|
);
|
|
|
|
assert.deepEqual(resolved.proxyConfig, profile().config);
|
|
});
|
|
|
|
test("materializeHostProxyProfile keeps explicit custom proxy ahead of profile reference", () => {
|
|
const customProxy = {
|
|
type: "http" as const,
|
|
host: "custom.example.com",
|
|
port: 3128,
|
|
};
|
|
|
|
const resolved = materializeHostProxyProfile(
|
|
host({ proxyProfileId: "proxy-1", proxyConfig: customProxy }),
|
|
[profile()],
|
|
);
|
|
|
|
assert.deepEqual(resolved.proxyConfig, customProxy);
|
|
});
|
|
|
|
test("removeProxyProfileReferences clears hosts and group configs that use a deleted profile", () => {
|
|
const result = removeProxyProfileReferences("proxy-1", {
|
|
hosts: [
|
|
host({ id: "host-1", proxyProfileId: "proxy-1" }),
|
|
host({ id: "host-2", proxyProfileId: "proxy-2" }),
|
|
],
|
|
groupConfigs: [
|
|
{ path: "prod", proxyProfileId: "proxy-1" },
|
|
{ path: "dev", proxyProfileId: "proxy-2" },
|
|
],
|
|
});
|
|
|
|
assert.equal(result.hosts[0].proxyProfileId, undefined);
|
|
assert.equal(result.hosts[1].proxyProfileId, "proxy-2");
|
|
assert.equal(result.groupConfigs[0].proxyProfileId, undefined);
|
|
assert.equal(result.groupConfigs[1].proxyProfileId, "proxy-2");
|
|
});
|
|
|
|
test("normalizeManualProxyConfig clears empty proxy drafts", () => {
|
|
assert.equal(
|
|
normalizeManualProxyConfig({ type: "http", host: "", port: 8080 }),
|
|
undefined,
|
|
);
|
|
});
|
|
|
|
test("normalizeManualProxyConfig trims command proxy drafts", () => {
|
|
assert.deepEqual(
|
|
normalizeManualProxyConfig({
|
|
type: "command",
|
|
host: "ignored.example.com",
|
|
port: 8080,
|
|
command: " cloudflared access ssh --hostname %h ",
|
|
username: "ignored",
|
|
password: "ignored",
|
|
}),
|
|
{
|
|
type: "command",
|
|
host: "",
|
|
port: 0,
|
|
command: "cloudflared access ssh --hostname %h",
|
|
},
|
|
);
|
|
});
|
|
|
|
test("normalizeManualProxyConfig strips stale command data from direct proxy configs", () => {
|
|
assert.deepEqual(
|
|
normalizeManualProxyConfig({
|
|
type: "http",
|
|
host: " proxy.example.com ",
|
|
port: "3128" as never,
|
|
command: "cloudflared access ssh --hostname %h --token secret",
|
|
username: " proxy-user ",
|
|
password: "proxy-secret",
|
|
}),
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
username: "proxy-user",
|
|
password: "proxy-secret",
|
|
},
|
|
);
|
|
});
|
|
|
|
test("normalizeManualProxyConfig keeps identity proxy auth without stale manual credentials", () => {
|
|
assert.deepEqual(
|
|
normalizeManualProxyConfig({
|
|
type: "socks5",
|
|
host: "proxy.example.com",
|
|
port: 1080,
|
|
identityId: "identity-1",
|
|
username: "stale-user",
|
|
password: "stale-secret",
|
|
}),
|
|
{
|
|
type: "socks5",
|
|
host: "proxy.example.com",
|
|
port: 1080,
|
|
identityId: "identity-1",
|
|
},
|
|
);
|
|
});
|
|
|
|
test("updateProxyConfigField clears conflicting proxy credential fields", () => {
|
|
assert.deepEqual(
|
|
updateProxyConfigField(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
username: "manual-user",
|
|
password: "manual-secret",
|
|
},
|
|
"identityId",
|
|
"identity-1",
|
|
),
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
identityId: "identity-1",
|
|
},
|
|
);
|
|
|
|
assert.deepEqual(
|
|
updateProxyConfigField(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
identityId: "identity-1",
|
|
},
|
|
"username",
|
|
"manual-user",
|
|
),
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
username: "manual-user",
|
|
},
|
|
);
|
|
});
|
|
|
|
test("updateProxyConfigField clears stale command when switching back to direct proxy types", () => {
|
|
assert.deepEqual(
|
|
updateProxyConfigField(
|
|
{
|
|
type: "command",
|
|
host: "",
|
|
port: 0,
|
|
command: "cloudflared access ssh --hostname %h --token secret",
|
|
},
|
|
"type",
|
|
"http",
|
|
),
|
|
{
|
|
type: "http",
|
|
host: "",
|
|
port: 0,
|
|
},
|
|
);
|
|
});
|
|
|
|
test("isCompleteProxyConfig requires host and a valid port", () => {
|
|
assert.equal(isCompleteProxyConfig({ type: "http", host: "", port: 8080 }), false);
|
|
assert.equal(isCompleteProxyConfig({ type: "http", host: "proxy.example.com", port: 0 }), false);
|
|
assert.equal(isCompleteProxyConfig({ type: "http", host: "proxy.example.com", port: 3128 }), true);
|
|
});
|
|
|
|
test("isCompleteProxyConfig accepts a non-empty command proxy", () => {
|
|
assert.equal(isCompleteProxyConfig({ type: "command", host: "", port: 0, command: "" }), false);
|
|
assert.equal(
|
|
isCompleteProxyConfig({
|
|
type: "command",
|
|
host: "",
|
|
port: 0,
|
|
command: "cloudflared access ssh --hostname %h",
|
|
}),
|
|
true,
|
|
);
|
|
});
|
|
|
|
test("formatProxyConfigEndpoint hides command proxy contents in summaries", () => {
|
|
assert.equal(
|
|
formatProxyConfigEndpoint({
|
|
type: "command",
|
|
host: "",
|
|
port: 0,
|
|
command: "cloudflared access ssh --hostname %h --token secret",
|
|
}),
|
|
"ProxyCommand",
|
|
);
|
|
});
|
|
|
|
test("formatProxyConfigType labels command proxies without uppercasing", () => {
|
|
assert.equal(formatProxyConfigType({ type: "http", host: "proxy.example.com", port: 3128 }), "HTTP");
|
|
assert.equal(
|
|
formatProxyConfigType({
|
|
type: "command",
|
|
host: "",
|
|
port: 0,
|
|
command: "cloudflared access ssh --hostname %h",
|
|
}),
|
|
"ProxyCommand",
|
|
);
|
|
});
|
|
|
|
test("resolveProxyConfigAuth uses a selected identity for proxy credentials", () => {
|
|
const identities: Identity[] = [{
|
|
id: "identity-1",
|
|
label: "Proxy login",
|
|
username: "proxy-user",
|
|
authMethod: "password",
|
|
password: "proxy-secret",
|
|
created: 1,
|
|
}];
|
|
|
|
assert.deepEqual(
|
|
resolveProxyConfigAuth(
|
|
{
|
|
type: "socks5",
|
|
host: "proxy.example.com",
|
|
port: 1080,
|
|
identityId: "identity-1",
|
|
},
|
|
identities,
|
|
),
|
|
{
|
|
type: "socks5",
|
|
host: "proxy.example.com",
|
|
port: 1080,
|
|
username: "proxy-user",
|
|
password: "proxy-secret",
|
|
},
|
|
);
|
|
});
|
|
|
|
test("findMissingProxyIdentityId reports stale proxy identity references", () => {
|
|
assert.equal(
|
|
findMissingProxyIdentityId(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
identityId: "missing-identity",
|
|
},
|
|
[],
|
|
),
|
|
"missing-identity",
|
|
);
|
|
});
|
|
|
|
test("findIncompleteProxyIdentityId reports proxy identities without username or password", () => {
|
|
assert.equal(
|
|
findIncompleteProxyIdentityId(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
identityId: "identity-1",
|
|
},
|
|
[{
|
|
id: "identity-1",
|
|
label: "Proxy login",
|
|
username: "proxy-user",
|
|
authMethod: "password",
|
|
created: 1,
|
|
}],
|
|
),
|
|
"identity-1",
|
|
);
|
|
assert.equal(
|
|
findIncompleteProxyIdentityId(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
identityId: "identity-1",
|
|
},
|
|
[{
|
|
id: "identity-1",
|
|
label: "Proxy login",
|
|
username: "proxy-user",
|
|
authMethod: "password",
|
|
password: "proxy-secret",
|
|
created: 1,
|
|
}],
|
|
),
|
|
undefined,
|
|
);
|
|
});
|
|
|
|
test("findIncompleteProxyIdentityId treats blank usernames as incomplete even with encrypted passwords", () => {
|
|
assert.equal(
|
|
findIncompleteProxyIdentityId(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
identityId: "identity-1",
|
|
},
|
|
[{
|
|
id: "identity-1",
|
|
label: "Proxy login",
|
|
username: " ",
|
|
authMethod: "password",
|
|
password: "enc:v1:djEwdGVzdAAAAAAAAAAAAAAAAA==",
|
|
created: 1,
|
|
}],
|
|
),
|
|
"identity-1",
|
|
);
|
|
});
|
|
|
|
test("resolveProxyConfigAuth keeps manual proxy credentials without an identity", () => {
|
|
assert.deepEqual(
|
|
resolveProxyConfigAuth(
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
username: "manual-user",
|
|
password: "manual-secret",
|
|
},
|
|
[],
|
|
),
|
|
{
|
|
type: "http",
|
|
host: "proxy.example.com",
|
|
port: 3128,
|
|
username: "manual-user",
|
|
password: "manual-secret",
|
|
},
|
|
);
|
|
});
|