Files
Homelab-manager/server/src/routes/agentReport.ts
T
bobbanandClaude Sonnet 5 9712d611a6 Add Servers & Tasks module ported from Schedule Task Manager
Ports cron/systemd task tracking across Debian/Raspbian servers, including
the Linux push agent (install/report/uninstall scripts, rebranded from
"schedule-task-manager-agent" to "homelab-manager-agent") and the
manual-task-entry flow for things an agent can't see (Docker jobs, backups).
The schema (servers/scheduled_tasks tables) was already in place from the
foundation pass, so this is mostly a straight port of the original's
services/routes.

Deliberate change from the original: server/token management (which mints
agent credentials) is now admin-only rather than open to any logged-in user,
and manual task CRUD is gated to operator+ — consistent with how Secrets,
IPAM, and DNS already split "configure credentials" from "everyday edits"
across roles. All mutations are audit-logged.

- server/src/services/tokens.ts, taskSync.ts: ported near-verbatim (agent
  token hashing, the agent-sync-marks-missing-as-stale-not-deleted logic).
- server/src/routes/servers.ts, tasks.ts, agentReport.ts: same contract as
  the original (agent auth is a per-server bearer token, independent of the
  session-based requireAuth used everywhere else).
- web: a single Servers & Tasks page (filter bar, task table grouped by
  server/schedule type, manual task form, and an admin-only server
  management panel with token reveal + copyable install/uninstall commands),
  replacing the original's two separate pages/apps.

Verified: full build passes; a scripted HTTP test against a running server
covers unauthenticated access, role gating at each tier (admin-only server
mgmt, operator+ task mgmt), agent bearer-token auth (valid/invalid/rotated),
manual-vs-agent task edit protection, stale-marking on re-sync, and cascade
delete — 22/22 checks passing. Real agent installation on an actual
Debian/Raspbian host still needs to be tried on the user's network.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-14 23:16:58 +02:00

63 lines
1.8 KiB
TypeScript

import { Router } from "express";
import { z } from "zod";
import { db } from "../db/client.js";
import { hashToken } from "../services/tokens.js";
import { syncServerTasks } from "../services/taskSync.js";
export const agentReportRouter = Router();
const reportSchema = z.object({
hostname: z.string().max(255).optional(),
os_type: z.string().optional(),
reported_at: z.string().optional(),
tasks: z.array(
z.object({
schedule_type: z.enum(["cron", "systemd_timer"]),
name: z.string().min(1),
command: z.string().optional(),
schedule_expression: z.string().optional(),
source: z.string().optional(),
enabled: z.boolean().optional(),
next_run_at: z.string().optional(),
metadata: z.unknown().optional(),
}),
),
});
agentReportRouter.post("/", async (req, res) => {
const authHeader = req.header("authorization") ?? "";
const match = authHeader.match(/^Bearer\s+(.+)$/i);
if (!match) {
return res.status(401).json({ error: "missing_token" });
}
const tokenHash = hashToken(match[1]);
const server = await db.query.servers.findFirst({
where: (s, { eq }) => eq(s.apiTokenHash, tokenHash),
});
if (!server) {
return res.status(401).json({ error: "invalid_token" });
}
const parsed = reportSchema.safeParse(req.body);
if (!parsed.success) {
return res.status(400).json({ error: "invalid_body", details: parsed.error.flatten() });
}
await syncServerTasks(server.id, {
hostname: parsed.data.hostname,
tasks: parsed.data.tasks.map((t) => ({
scheduleType: t.schedule_type,
name: t.name,
command: t.command,
scheduleExpression: t.schedule_expression,
source: t.source,
enabled: t.enabled,
nextRunAt: t.next_run_at,
metadata: t.metadata,
})),
});
res.status(202).json({ ok: true, taskCount: parsed.data.tasks.length });
});