From 431c22a16a64448c3ee70078ab403f7cb046c6e5 Mon Sep 17 00:00:00 2001 From: Tam Nhu Tran Date: Tue, 7 Apr 2026 05:19:44 -0400 Subject: [PATCH 1/4] fix(dashboard): gate remote read-only auth --- src/commands/docker/up-subcommand.ts | 2 +- src/web-server/routes/auth-routes.ts | 24 +++---- .../commands/docker-up-subcommand.test.ts | 3 +- .../auth-check-remote-access.test.ts | 6 +- .../shared/localhost-disclaimer.tsx | 40 ++++++++--- .../components/auth/require-auth.test.tsx | 71 +++++++++++++++++++ .../shared/localhost-disclaimer.test.tsx | 47 ++++++++++++ ui/tests/unit/pages/login-page.test.tsx | 17 +++-- 8 files changed, 176 insertions(+), 34 deletions(-) create mode 100644 ui/tests/unit/components/auth/require-auth.test.tsx create mode 100644 ui/tests/unit/components/shared/localhost-disclaimer.test.tsx diff --git a/src/commands/docker/up-subcommand.ts b/src/commands/docker/up-subcommand.ts index fcbb4242..fa7c7bf3 100644 --- a/src/commands/docker/up-subcommand.ts +++ b/src/commands/docker/up-subcommand.ts @@ -40,7 +40,7 @@ export async function handleUp(args: string[]): Promise { if (parsed.host) { console.log( info( - 'Remote access requires dashboard auth. Run inside the container:\n docker exec -it ccs-cliproxy ccs config auth setup' + 'Full remote management requires dashboard auth. Without it, remote access stays read-only.\nRun inside the container:\n docker exec -it ccs-cliproxy ccs config auth setup' ) ); } diff --git a/src/web-server/routes/auth-routes.ts b/src/web-server/routes/auth-routes.ts index d3bd0bcf..6fcd3e22 100644 --- a/src/web-server/routes/auth-routes.ts +++ b/src/web-server/routes/auth-routes.ts @@ -42,7 +42,17 @@ export function resolveDashboardAccessState( const isLocalAccess = isLoopbackRemoteAddress(remoteAddress); const authConfigured = Boolean(authConfig.username && authConfig.password_hash); - if (authConfig.enabled && authConfigured) { + if (!authConfig.enabled) { + return { + authRequired: false, + authEnabled: false, + authConfigured, + isLocalAccess, + accessMode: 'open', + }; + } + + if (authConfigured) { return { authRequired: true, authEnabled: true, @@ -52,19 +62,9 @@ export function resolveDashboardAccessState( }; } - if (!authConfig.enabled && isLocalAccess) { - return { - authRequired: false, - authEnabled: false, - authConfigured, - isLocalAccess: true, - accessMode: 'open', - }; - } - return { authRequired: true, - authEnabled: authConfig.enabled, + authEnabled: true, authConfigured, isLocalAccess, accessMode: 'setup', diff --git a/tests/unit/commands/docker-up-subcommand.test.ts b/tests/unit/commands/docker-up-subcommand.test.ts index ba290b6c..9aace1f1 100644 --- a/tests/unit/commands/docker-up-subcommand.test.ts +++ b/tests/unit/commands/docker-up-subcommand.test.ts @@ -38,7 +38,8 @@ describe('docker up subcommand', () => { expect(rendered).toContain('Docker stack is running on docker-box.'); expect(rendered).toContain('Dashboard port: 4000'); expect(rendered).toContain('CLIProxy port: 9317'); - expect(rendered).toContain('Remote access requires dashboard auth'); + expect(rendered).toContain('Full remote management requires dashboard auth'); + expect(rendered).toContain('Without it, remote access stays read-only.'); expect(capture.errorLines).toEqual([]); expect(process.exitCode).toBe(0); } finally { diff --git a/tests/unit/web-server/auth-check-remote-access.test.ts b/tests/unit/web-server/auth-check-remote-access.test.ts index 2f1ac17c..fc115673 100644 --- a/tests/unit/web-server/auth-check-remote-access.test.ts +++ b/tests/unit/web-server/auth-check-remote-access.test.ts @@ -54,18 +54,18 @@ describe('resolveDashboardAccessState', () => { }); }); - it('shows setup state for remote access when auth is disabled', () => { + it('keeps remote access open when auth is disabled', () => { expect( resolveDashboardAccessState( { enabled: false, username: '', password_hash: '', session_timeout_hours: 24 }, '192.168.2.100' ) ).toEqual({ - authRequired: true, + authRequired: false, authEnabled: false, authConfigured: false, isLocalAccess: false, - accessMode: 'setup', + accessMode: 'open', }); }); diff --git a/ui/src/components/shared/localhost-disclaimer.tsx b/ui/src/components/shared/localhost-disclaimer.tsx index 78d5c6e1..5890da43 100644 --- a/ui/src/components/shared/localhost-disclaimer.tsx +++ b/ui/src/components/shared/localhost-disclaimer.tsx @@ -1,24 +1,48 @@ import { Shield, X } from 'lucide-react'; import { useState } from 'react'; +import { useAuth } from '@/contexts/auth-context'; export function LocalhostDisclaimer() { const [dismissed, setDismissed] = useState(false); + const { authEnabled, isLocalAccess, loading } = useAuth(); - if (dismissed) return null; + if (dismissed || loading) return null; + + const isRemoteReadonly = !isLocalAccess && !authEnabled; + const wrapperClasses = isRemoteReadonly + ? 'w-full border-t border-amber-200 bg-amber-50 px-4 py-2 text-amber-900 transition-colors duration-200 dark:border-amber-800 dark:bg-amber-900/20 dark:text-amber-200' + : 'w-full border-t border-yellow-200 bg-yellow-50 px-4 py-2 text-yellow-800 transition-colors duration-200 dark:border-yellow-800 dark:bg-yellow-900/20 dark:text-yellow-200'; + const dismissClasses = isRemoteReadonly + ? 'text-amber-600 hover:bg-amber-100 hover:text-amber-800 dark:text-amber-400 dark:hover:bg-amber-800/30' + : 'text-yellow-600 hover:bg-yellow-100 hover:text-yellow-800 dark:text-yellow-400 dark:hover:bg-yellow-800/30'; + const message = isRemoteReadonly ? ( + <> + + Remote dashboard access is read-only until you run ccs config auth setup on the host. + + + Remote dashboard is read-only until host auth is configured. + + + ) : ( + <> + + This dashboard runs locally. All data stays on your machine. + + Local dashboard - data stays on your device. + + ); return ( -
+
-
+
- - This dashboard runs locally. All data stays on your machine. - - Local dashboard - data stays on your device. + {message}
} /> + }> + dashboard page
} /> + + + + ); +} + +describe('RequireAuth', () => { + beforeEach(() => { + useAuthMock.mockReset(); + }); + + it('allows remote readonly sessions through without redirecting to login', () => { + useAuthMock.mockReturnValue({ + authRequired: false, + isAuthenticated: false, + username: null, + loading: false, + authEnabled: false, + authConfigured: false, + isLocalAccess: false, + accessMode: 'open', + login: vi.fn(), + logout: vi.fn(), + }); + + renderGuard(); + + expect(screen.getByText('dashboard page')).toBeVisible(); + expect(screen.queryByText('login page')).toBeNull(); + }); + + it('redirects unauthenticated users when dashboard auth is enabled', () => { + useAuthMock.mockReturnValue({ + authRequired: true, + isAuthenticated: false, + username: null, + loading: false, + authEnabled: true, + authConfigured: true, + isLocalAccess: false, + accessMode: 'login', + login: vi.fn(), + logout: vi.fn(), + }); + + renderGuard(); + + expect(screen.getByText('login page')).toBeVisible(); + expect(screen.queryByText('dashboard page')).toBeNull(); + }); +}); diff --git a/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx b/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx new file mode 100644 index 00000000..5525543e --- /dev/null +++ b/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx @@ -0,0 +1,47 @@ +import { beforeEach, describe, expect, it, vi } from 'vitest'; +import { render, screen } from '@testing-library/react'; +import { LocalhostDisclaimer } from '@/components/shared/localhost-disclaimer'; + +const { useAuthMock } = vi.hoisted(() => ({ + useAuthMock: vi.fn(), +})); + +vi.mock('@/contexts/auth-context', () => ({ + useAuth: useAuthMock, +})); + +describe('LocalhostDisclaimer', () => { + beforeEach(() => { + useAuthMock.mockReset(); + }); + + it('shows the local safety copy for loopback sessions', () => { + useAuthMock.mockReturnValue({ + authEnabled: false, + isLocalAccess: true, + loading: false, + }); + + render(); + + expect( + screen.getByText('This dashboard runs locally. All data stays on your machine.') + ).toBeVisible(); + }); + + it('shows the remote read-only copy when auth is disabled for remote access', () => { + useAuthMock.mockReturnValue({ + authEnabled: false, + isLocalAccess: false, + loading: false, + }); + + render(); + + expect( + screen.getByText( + 'Remote dashboard access is read-only until you run ccs config auth setup on the host.' + ) + ).toBeVisible(); + }); +}); diff --git a/ui/tests/unit/pages/login-page.test.tsx b/ui/tests/unit/pages/login-page.test.tsx index 14dc5cbd..689e5992 100644 --- a/ui/tests/unit/pages/login-page.test.tsx +++ b/ui/tests/unit/pages/login-page.test.tsx @@ -1,7 +1,7 @@ import { beforeEach, describe, expect, it, vi } from 'vitest'; import i18n from '@/lib/i18n'; import { LoginPage } from '@/pages/login'; -import { render, screen, userEvent } from '@tests/setup/test-utils'; +import { render, screen, userEvent, waitFor } from '@tests/setup/test-utils'; const { navigateMock, useAuthMock } = vi.hoisted(() => ({ navigateMock: vi.fn(), @@ -40,13 +40,13 @@ describe('LoginPage', () => { await i18n.changeLanguage('en'); }); - it('renders a setup state for remote access when dashboard auth is unavailable', () => { + it('redirects away when dashboard auth is disabled for remote access', async () => { useAuthMock.mockReturnValue({ - authRequired: true, + authRequired: false, isAuthenticated: false, username: null, loading: false, - accessMode: 'setup', + accessMode: 'open', authEnabled: false, authConfigured: false, isLocalAccess: false, @@ -56,11 +56,10 @@ describe('LoginPage', () => { render(); - expect(screen.getByRole('heading', { name: 'Remote access needs host setup' })).toBeVisible(); - expect(screen.getByText('ccs config auth setup')).toBeVisible(); - expect(screen.getByText('No default credentials ship with CCS.')).toBeVisible(); - expect(screen.queryByLabelText('Username')).not.toBeInTheDocument(); - expect(screen.queryByRole('button', { name: 'Sign In' })).not.toBeInTheDocument(); + await waitFor(() => { + expect(navigateMock).toHaveBeenCalledWith('/settings', { replace: true }); + }); + expect(screen.queryByRole('heading', { name: 'Remote access needs host setup' })).toBeNull(); }); it('renders the incomplete setup copy when auth is enabled without credentials', () => { From 5fbe7313416187b2393fa2bf5e7a7a583aefde5e Mon Sep 17 00:00:00 2001 From: Tam Nhu Tran Date: Tue, 7 Apr 2026 06:10:41 -0400 Subject: [PATCH 2/4] fix(web-server): block remote dashboard writes --- src/web-server/routes/index.ts | 25 ++++ .../api-routes-remote-write-guard.test.ts | 125 ++++++++++++++++++ 2 files changed, 150 insertions(+) create mode 100644 tests/unit/web-server/api-routes-remote-write-guard.test.ts diff --git a/src/web-server/routes/index.ts b/src/web-server/routes/index.ts index 85534e0c..7e84b386 100644 --- a/src/web-server/routes/index.ts +++ b/src/web-server/routes/index.ts @@ -6,6 +6,7 @@ */ import { Router } from 'express'; +import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware'; // Import domain routers import profileRoutes from './profile-routes'; @@ -36,6 +37,30 @@ import claudeExtensionRoutes from './claude-extension-routes'; // Create the main API router export const apiRoutes = Router(); +const REMOTE_WRITE_ACCESS_ERROR = + 'Remote dashboard writes require localhost access when dashboard auth is disabled.'; + +function isMutationMethod(method: string): boolean { + const normalized = method.toUpperCase(); + return ( + normalized === 'POST' || + normalized === 'PUT' || + normalized === 'PATCH' || + normalized === 'DELETE' + ); +} + +apiRoutes.use((req, res, next) => { + if (!isMutationMethod(req.method)) { + next(); + return; + } + + if (requireLocalAccessWhenAuthDisabled(req, res, REMOTE_WRITE_ACCESS_ERROR)) { + next(); + } +}); + // ==================== Profile & Settings ==================== // Profile CRUD, settings management, presets, accounts apiRoutes.use('/profiles', profileRoutes); diff --git a/tests/unit/web-server/api-routes-remote-write-guard.test.ts b/tests/unit/web-server/api-routes-remote-write-guard.test.ts new file mode 100644 index 00000000..de2a2c77 --- /dev/null +++ b/tests/unit/web-server/api-routes-remote-write-guard.test.ts @@ -0,0 +1,125 @@ +import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it } from 'bun:test'; +import express from 'express'; +import type { Server } from 'http'; +import * as fs from 'fs'; +import * as os from 'os'; +import * as path from 'path'; +import { apiRoutes } from '../../../src/web-server/routes'; + +describe('api-routes remote write guard', () => { + let server: Server; + let baseUrl = ''; + let forcedRemoteAddress = '127.0.0.1'; + let tempHome = ''; + let originalDashboardAuthEnabled: string | undefined; + let originalCcsHome: string | undefined; + + beforeAll(async () => { + const app = express(); + app.use(express.json()); + app.use((req, _res, next) => { + Object.defineProperty(req.socket, 'remoteAddress', { + value: forcedRemoteAddress, + configurable: true, + }); + next(); + }); + app.use('/api', apiRoutes); + + await new Promise((resolve, reject) => { + server = app.listen(0, '127.0.0.1'); + server.once('error', reject); + server.once('listening', () => resolve()); + }); + + const address = server.address(); + if (!address || typeof address === 'string') { + throw new Error('Unable to resolve test server port'); + } + baseUrl = `http://127.0.0.1:${address.port}`; + }); + + afterAll(async () => { + await new Promise((resolve) => server.close(() => resolve())); + }); + + beforeEach(() => { + originalDashboardAuthEnabled = process.env.CCS_DASHBOARD_AUTH_ENABLED; + originalCcsHome = process.env.CCS_HOME; + tempHome = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-api-routes-remote-write-guard-')); + process.env.CCS_HOME = tempHome; + process.env.CCS_DASHBOARD_AUTH_ENABLED = 'false'; + forcedRemoteAddress = '10.10.0.24'; + }); + + afterEach(() => { + if (originalDashboardAuthEnabled !== undefined) { + process.env.CCS_DASHBOARD_AUTH_ENABLED = originalDashboardAuthEnabled; + } else { + delete process.env.CCS_DASHBOARD_AUTH_ENABLED; + } + + if (originalCcsHome !== undefined) { + process.env.CCS_HOME = originalCcsHome; + } else { + delete process.env.CCS_HOME; + } + + if (tempHome && fs.existsSync(tempHome)) { + fs.rmSync(tempHome, { recursive: true, force: true }); + tempHome = ''; + } + }); + + it('allows remote read-only GET requests when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/profiles`); + + expect(response.status).toBe(200); + }); + + it('blocks remote profile creation when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/profiles`, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({ + name: 'demo', + baseUrl: 'https://api.example.com', + apiKey: 'token', + }), + }); + + expect(response.status).toBe(403); + expect(await response.json()).toEqual({ + error: 'Remote dashboard writes require localhost access when dashboard auth is disabled.', + }); + }); + + it('blocks remote backup restore when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/persist/restore`, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({}), + }); + + expect(response.status).toBe(403); + expect(await response.json()).toEqual({ + error: 'Remote dashboard writes require localhost access when dashboard auth is disabled.', + }); + }); + + it('allows remote writes again when dashboard auth is enabled', async () => { + process.env.CCS_DASHBOARD_AUTH_ENABLED = 'true'; + + const response = await fetch(`${baseUrl}/api/profiles`, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({ + name: 'demo', + baseUrl: 'https://api.example.com', + apiKey: 'token', + }), + }); + + expect(response.status).not.toBe(403); + }); +}); From 1603f1938802d1dd03b8e6b94310012dfc6ba99c Mon Sep 17 00:00:00 2001 From: Tam Nhu Tran Date: Tue, 7 Apr 2026 07:04:57 -0400 Subject: [PATCH 3/4] fix(usage): block remote refresh without auth --- src/web-server/usage/routes.ts | 15 +++ .../unit/web-server/usage-routes-auth.test.ts | 92 +++++++++++++++++++ 2 files changed, 107 insertions(+) create mode 100644 tests/unit/web-server/usage-routes-auth.test.ts diff --git a/src/web-server/usage/routes.ts b/src/web-server/usage/routes.ts index c4a2dabe..2aeec59f 100644 --- a/src/web-server/usage/routes.ts +++ b/src/web-server/usage/routes.ts @@ -8,6 +8,7 @@ */ import { Router } from 'express'; +import { requireLocalAccessWhenAuthDisabled } from '../middleware/auth-middleware'; import { handleSummary, handleDaily, @@ -24,6 +25,20 @@ export { prewarmUsageCache, clearUsageCache, getLastFetchTimestamp } from './agg export const usageRoutes = Router(); +const USAGE_WRITE_ACCESS_ERROR = + 'Usage refresh requires localhost access when dashboard auth is disabled.'; + +usageRoutes.use((req, res, next) => { + if (req.method.toUpperCase() !== 'POST') { + next(); + return; + } + + if (requireLocalAccessWhenAuthDisabled(req, res, USAGE_WRITE_ACCESS_ERROR)) { + next(); + } +}); + // Summary endpoint usageRoutes.get('/summary', handleSummary); diff --git a/tests/unit/web-server/usage-routes-auth.test.ts b/tests/unit/web-server/usage-routes-auth.test.ts new file mode 100644 index 00000000..424263ff --- /dev/null +++ b/tests/unit/web-server/usage-routes-auth.test.ts @@ -0,0 +1,92 @@ +import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it } from 'bun:test'; +import express from 'express'; +import * as fs from 'fs'; +import * as os from 'os'; +import * as path from 'path'; +import type { Server } from 'http'; +import { usageRoutes } from '../../../src/web-server/usage/routes'; + +describe('usage-routes remote write guard', () => { + let server: Server; + let baseUrl = ''; + let forcedRemoteAddress = '127.0.0.1'; + let tempHome = ''; + let originalDashboardAuthEnabled: string | undefined; + let originalCcsHome: string | undefined; + + beforeAll(async () => { + const app = express(); + app.use(express.json()); + app.use((req, _res, next) => { + Object.defineProperty(req.socket, 'remoteAddress', { + value: forcedRemoteAddress, + configurable: true, + }); + next(); + }); + app.use('/api/usage', usageRoutes); + + await new Promise((resolve, reject) => { + server = app.listen(0, '127.0.0.1'); + server.once('error', reject); + server.once('listening', () => resolve()); + }); + + const address = server.address(); + if (!address || typeof address === 'string') { + throw new Error('Unable to resolve test server port'); + } + baseUrl = `http://127.0.0.1:${address.port}`; + }); + + afterAll(async () => { + await new Promise((resolve) => server.close(() => resolve())); + }); + + beforeEach(() => { + originalDashboardAuthEnabled = process.env.CCS_DASHBOARD_AUTH_ENABLED; + originalCcsHome = process.env.CCS_HOME; + tempHome = fs.mkdtempSync(path.join(os.tmpdir(), 'ccs-usage-routes-auth-')); + process.env.CCS_HOME = tempHome; + process.env.CCS_DASHBOARD_AUTH_ENABLED = 'false'; + forcedRemoteAddress = '10.10.0.24'; + }); + + afterEach(() => { + if (originalDashboardAuthEnabled !== undefined) { + process.env.CCS_DASHBOARD_AUTH_ENABLED = originalDashboardAuthEnabled; + } else { + delete process.env.CCS_DASHBOARD_AUTH_ENABLED; + } + + if (originalCcsHome !== undefined) { + process.env.CCS_HOME = originalCcsHome; + } else { + delete process.env.CCS_HOME; + } + + if (tempHome && fs.existsSync(tempHome)) { + fs.rmSync(tempHome, { recursive: true, force: true }); + tempHome = ''; + } + }); + + it('allows remote read-only usage status requests when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/usage/status`); + + expect(response.status).toBe(200); + }); + + it('blocks remote usage refresh when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/usage/refresh`, { + method: 'POST', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({}), + }); + + expect(response.status).toBe(403); + expect(await response.json()).toEqual({ + error: 'Usage refresh requires localhost access when dashboard auth is disabled.', + }); + }); +}); From 173149ba718503cb3b5b95ebd3fdc879e0fac9eb Mon Sep 17 00:00:00 2001 From: Tam Nhu Tran Date: Tue, 7 Apr 2026 07:08:32 -0400 Subject: [PATCH 4/4] fix(ui): keep remote read-only notice accurate --- .../api-routes-remote-write-guard.test.ts | 99 ++++++++++++++++++- .../shared/localhost-disclaimer.tsx | 49 ++++++--- .../shared/localhost-disclaimer.test.tsx | 21 ++++ 3 files changed, 149 insertions(+), 20 deletions(-) diff --git a/tests/unit/web-server/api-routes-remote-write-guard.test.ts b/tests/unit/web-server/api-routes-remote-write-guard.test.ts index de2a2c77..83575173 100644 --- a/tests/unit/web-server/api-routes-remote-write-guard.test.ts +++ b/tests/unit/web-server/api-routes-remote-write-guard.test.ts @@ -1,10 +1,15 @@ import { afterAll, afterEach, beforeAll, beforeEach, describe, expect, it } from 'bun:test'; +import bcrypt from 'bcrypt'; import express from 'express'; import type { Server } from 'http'; import * as fs from 'fs'; import * as os from 'os'; import * as path from 'path'; import { apiRoutes } from '../../../src/web-server/routes'; +import { + authMiddleware, + createSessionMiddleware, +} from '../../../src/web-server/middleware/auth-middleware'; describe('api-routes remote write guard', () => { let server: Server; @@ -107,12 +112,93 @@ describe('api-routes remote write guard', () => { }); }); - it('allows remote writes again when dashboard auth is enabled', async () => { - process.env.CCS_DASHBOARD_AUTH_ENABLED = 'true'; + it('blocks remote PUT requests when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/cliproxy-server`, { + method: 'PUT', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({}), + }); - const response = await fetch(`${baseUrl}/api/profiles`, { + expect(response.status).toBe(403); + expect(await response.json()).toEqual({ + error: 'Remote dashboard writes require localhost access when dashboard auth is disabled.', + }); + }); + + it('blocks remote PATCH requests when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/codex/config/patch`, { + method: 'PATCH', + headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({}), + }); + + expect(response.status).toBe(403); + expect(await response.json()).toEqual({ + error: 'Remote dashboard writes require localhost access when dashboard auth is disabled.', + }); + }); + + it('blocks remote DELETE requests when dashboard auth is disabled', async () => { + const response = await fetch(`${baseUrl}/api/profiles/demo`, { + method: 'DELETE', + }); + + expect(response.status).toBe(403); + expect(await response.json()).toEqual({ + error: 'Remote dashboard writes require localhost access when dashboard auth is disabled.', + }); + }); + + it('allows remote writes again when dashboard auth is enabled', async () => { + const password = 'testpassword123'; + process.env.CCS_DASHBOARD_AUTH_ENABLED = 'true'; + process.env.CCS_DASHBOARD_USERNAME = 'admin'; + process.env.CCS_DASHBOARD_PASSWORD_HASH = await bcrypt.hash(password, 10); + + const authApp = express(); + authApp.use(express.json()); + authApp.use((req, _res, next) => { + Object.defineProperty(req.socket, 'remoteAddress', { + value: forcedRemoteAddress, + configurable: true, + }); + next(); + }); + authApp.use(createSessionMiddleware()); + authApp.use(authMiddleware); + authApp.use('/api', apiRoutes); + + const authServer = await new Promise((resolve, reject) => { + const instance = authApp.listen(0, '127.0.0.1'); + instance.once('error', reject); + instance.once('listening', () => resolve(instance)); + }); + + const address = authServer.address(); + if (!address || typeof address === 'string') { + throw new Error('Unable to resolve auth-enabled test server port'); + } + const authBaseUrl = `http://127.0.0.1:${address.port}`; + + const loginResponse = await fetch(`${authBaseUrl}/api/auth/login`, { method: 'POST', headers: { 'Content-Type': 'application/json' }, + body: JSON.stringify({ + username: 'admin', + password, + }), + }); + const cookie = loginResponse.headers.get('set-cookie'); + + expect(loginResponse.status).toBe(200); + expect(cookie).toBeTruthy(); + + const response = await fetch(`${authBaseUrl}/api/profiles`, { + method: 'POST', + headers: { + 'Content-Type': 'application/json', + Cookie: cookie as string, + }, body: JSON.stringify({ name: 'demo', baseUrl: 'https://api.example.com', @@ -120,6 +206,11 @@ describe('api-routes remote write guard', () => { }), }); - expect(response.status).not.toBe(403); + expect(response.status).toBe(201); + + await new Promise((resolve) => authServer.close(() => resolve())); + + delete process.env.CCS_DASHBOARD_USERNAME; + delete process.env.CCS_DASHBOARD_PASSWORD_HASH; }); }); diff --git a/ui/src/components/shared/localhost-disclaimer.tsx b/ui/src/components/shared/localhost-disclaimer.tsx index 5890da43..c6efc7b4 100644 --- a/ui/src/components/shared/localhost-disclaimer.tsx +++ b/ui/src/components/shared/localhost-disclaimer.tsx @@ -4,11 +4,12 @@ import { useAuth } from '@/contexts/auth-context'; export function LocalhostDisclaimer() { const [dismissed, setDismissed] = useState(false); - const { authEnabled, isLocalAccess, loading } = useAuth(); - - if (dismissed || loading) return null; + const { authEnabled, authConfigured, isLocalAccess, loading } = useAuth(); const isRemoteReadonly = !isLocalAccess && !authEnabled; + + if ((dismissed && !isRemoteReadonly) || loading) return null; + const wrapperClasses = isRemoteReadonly ? 'w-full border-t border-amber-200 bg-amber-50 px-4 py-2 text-amber-900 transition-colors duration-200 dark:border-amber-800 dark:bg-amber-900/20 dark:text-amber-200' : 'w-full border-t border-yellow-200 bg-yellow-50 px-4 py-2 text-yellow-800 transition-colors duration-200 dark:border-yellow-800 dark:bg-yellow-900/20 dark:text-yellow-200'; @@ -17,12 +18,26 @@ export function LocalhostDisclaimer() { : 'text-yellow-600 hover:bg-yellow-100 hover:text-yellow-800 dark:text-yellow-400 dark:hover:bg-yellow-800/30'; const message = isRemoteReadonly ? ( <> - - Remote dashboard access is read-only until you run ccs config auth setup on the host. - - - Remote dashboard is read-only until host auth is configured. - + {authConfigured ? ( + <> + + Remote dashboard access is read-only because dashboard auth is currently disabled on the + host. Re-enable dashboard auth on the host to unlock remote changes. + + + Remote dashboard is read-only until dashboard auth is re-enabled on the host. + + + ) : ( + <> + + Remote dashboard access is read-only until you run ccs config auth setup on the host. + + + Remote dashboard is read-only until host auth is configured. + + + )} ) : ( <> @@ -40,13 +55,15 @@ export function LocalhostDisclaimer() { {message}
- + {!isRemoteReadonly ? ( + + ) : null}
); diff --git a/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx b/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx index 5525543e..8c27d933 100644 --- a/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx +++ b/ui/tests/unit/components/shared/localhost-disclaimer.test.tsx @@ -18,6 +18,7 @@ describe('LocalhostDisclaimer', () => { it('shows the local safety copy for loopback sessions', () => { useAuthMock.mockReturnValue({ authEnabled: false, + authConfigured: false, isLocalAccess: true, loading: false, }); @@ -32,6 +33,7 @@ describe('LocalhostDisclaimer', () => { it('shows the remote read-only copy when auth is disabled for remote access', () => { useAuthMock.mockReturnValue({ authEnabled: false, + authConfigured: false, isLocalAccess: false, loading: false, }); @@ -43,5 +45,24 @@ describe('LocalhostDisclaimer', () => { 'Remote dashboard access is read-only until you run ccs config auth setup on the host.' ) ).toBeVisible(); + expect(screen.queryByLabelText('Dismiss disclaimer')).toBeNull(); + }); + + it('shows the re-enable message when host credentials already exist', () => { + useAuthMock.mockReturnValue({ + authEnabled: false, + authConfigured: true, + isLocalAccess: false, + loading: false, + }); + + render(); + + expect( + screen.getByText( + 'Remote dashboard access is read-only because dashboard auth is currently disabled on the host. Re-enable dashboard auth on the host to unlock remote changes.' + ) + ).toBeVisible(); + expect(screen.queryByLabelText('Dismiss disclaimer')).toBeNull(); }); });