Commit Graph

213 Commits

Author SHA1 Message Date
68804761bf public id is now shown on the sessions page since authorized keys are
used which is safer.
2024-08-06 22:50:24 +02:00
7af575119d eliminated the username. 2024-08-06 22:38:59 +02:00
e9744a7c2f better messages when the user modifies the .authorized_keys file from
within the session.
2024-08-06 22:28:34 +02:00
Erik Brakkee
3c803d6125 removed password based access
authorized keys can now be modified within the session.
keep last set of keys when no valid keys were found and keys are changed during the session .
2024-08-06 22:03:36 +02:00
95926c5896 getting the bootstrap icons (not checking them in).
Split up instructions for working with agents.
2024-08-05 23:19:41 +02:00
7e60e23df1 A lot of work in getting cut and paste from the UI to
work properly.

Wrote two web components. One for cut and paste in general, and another for code samples.
2024-08-05 22:51:49 +02:00
02914ae40f Simple validation of the id and the authorized keys. 2024-08-04 23:31:12 +02:00
46d4467e94 More clean handling of the contextpath.
Now using long option names for the options of converge to be consistent with the other components.
2024-08-04 22:17:51 +02:00
1b76add15b Alternative contextpath is now supported.
This will simplify hosting in cases where you have no control over DNS but only over one domain.
2024-08-03 23:10:57 +02:00
b875540d6b Preparation for alternative context path.
The contextpath parameter in converge.go is
temporary and should be removed later. What is needed is autodetectio of the context path for the usage page and passing on the context for rendering.
2024-08-03 22:40:26 +02:00
a6bbafe593 fixed issue in usage page where local shell was not used at all. 2024-08-03 21:18:44 +02:00
d3f9c9fd5a Lots of work on making easier interactive documentation, especially to make working with SSH public keys really easy.
Next step is to do more validation in the UI.
Specifically:
* validate authorized keys
* detection of accidental use of a private key

Then, password based access can be disabled.
2024-08-03 21:03:29 +02:00
db44a20d5a large parts of the usage is now dynamic.
Still need to generate instructions for authorized keys. A lot of troubleshooting for the form to cookie persistence.
2024-08-03 18:29:14 +02:00
91e1139881 work in progress:
* usage page now has more dynamic part where user
  can enter id and publis ssh keys and the server will
  generate the appropriate commmands to execute depending on the local and remote shell.
2024-08-03 12:54:32 +02:00
7b9d1cb1b2 relative link to websocket did not work for some reason, reverted back to /.... link 2024-08-03 08:46:16 +02:00
Erik Brakkee
21463a5cad * session will now expire some time after last user
activity and updated documentation.
* downloads will now download again. Because of hx-boost
  the downloads where rendered in the browser. Now
  disabling hx-boost for the downloads section.
* relative link for sessions page
2024-08-02 20:58:46 +02:00
5a91d86b39 fixed typo 2024-08-01 21:23:41 +02:00
7f5768a1e1 dockerfile now also runs templ 2024-08-01 21:21:31 +02:00
b49a4e7613 remark about tcptows 2024-08-01 21:01:27 +02:00
0d60b70ada Updated documentation:
* remote shell usage for linux, cmd, and powershell
* help of wsproxy.
2024-08-01 20:53:52 +02:00
ff97c1ccd2 Now by default wsproxy uses a specific protocol to establish connections to the server. It does this by adding the ?wsproxy query parameter.
The server then sends it the protocol version and the client connection info describing whether an agent was found or not. This improves usability for users.

With the --raw option it bypasses this query parameter and wsproxy then works in the old way as a simple stdio-websocket connector. It then still works with converge server but can also be used for simple websocket troubleshooting.
2024-08-01 20:22:41 +02:00
5c251daa47 Using # instead of id in the sessions page to avoid confusion with the term id used in the docs. 2024-08-01 19:21:39 +02:00
Erik Brakkee
2e12d0a9fd Now displaying agent number instead of id.
Passing timezone to server side for rendering of time stamps
Configuration of preferred shells.
2024-08-01 19:16:00 +02:00
4c52fb0f12 Rendering status as HTML tables. 2024-07-31 21:12:09 +02:00
885b7790d7 doing the same thing as before but now rendering the
status using a template.
2024-07-31 19:52:01 +02:00
Erik Brakkee
f0dd810541 many small changes
* removed the Async utility
* now using Ping message to webclient for keep alive instaed of actual content
* added remote shell to AgentInfo
* retry of connections to the agent
* better logging for SynchronizeStreams
2024-07-31 19:30:38 +02:00
658aaf3880 typo in usage.html 2024-07-30 23:55:09 +02:00
01c9cdd60a usage fix (agent was renamed by intellij to session)
Now using embedded timezone database by go so setting the TZ variable will work.
2024-07-30 23:48:52 +02:00
9a3618f06b Live updates of the sessions.
V1 in ascii-art. To be improved.
2024-07-30 21:51:30 +02:00
f382c02b41 restructuring 2024-07-30 19:59:13 +02:00
367043e0c5 When a duplicate id is requested the server now allocates a new unique id so that the session can be handled anyway. 2024-07-30 19:45:25 +02:00
c1e91f0aba Adding rm/del instruction for agents. 2024-07-30 19:04:46 +02:00
bf5120aa5b refactoring towards being able to send events from Admin to UI (websocket) without exposing connection info but only metadata. 2024-07-30 19:03:21 +02:00
5533b04a5e removed hardcoded host used for testing. 2024-07-30 00:02:52 +02:00
9a10182f76 missing files checked in:
htmx + websocket extension
render.sh script for generating html of the webinterface for quickly
seeing results after modifying templates.
.gitignore file for ignoring generated stuff.
2024-07-29 23:58:48 +02:00
39cf088a41 basic htmx with server sending content to the client over a websocket is now working. This only worked when text message where being sent so the websocket handling had to be made configurable with a 'text' boolean field. 2024-07-29 23:56:44 +02:00
77cffde408 tabbed interface. 2024-07-29 21:05:14 +02:00
68056b0b77 split up in separate pages. 2024-07-29 20:02:08 +02:00
f5135aecdc docs page now working again. 2024-07-29 19:49:47 +02:00
fb8ed0622b extracted basepage. 2024-07-29 19:23:01 +02:00
92504f4130 Split up the main page into different parts. 2024-07-29 19:16:48 +02:00
a4d5060163 Split up the main page into different parts. 2024-07-29 19:02:50 +02:00
f7e94c21f9 Fixed typo: continous continuous. 2024-07-29 18:32:11 +02:00
c8d328dc75 downgrading to alpine 3.19.3 so that we get go 1.21 (same as in dev env). This makes troubleshooting easier. 2024-07-29 18:30:58 +02:00
b1f7304eeb Now rendering the index.html using the Templ library.
This is in preparation for:
1. creating a base page
2. using tabs: Home, Using, Downloads, Status
3. htmx
2024-07-28 21:31:17 +02:00
d17ad9bc3e Added pprof to convergeserver and optionally to
the agent if PPROF_PORT is set.

Fixed issue with converge server not cleaning up goroutines because of blocking channel. Made sure to create channels with > 1 size everywhere it can be done. The blocking behavior of a default channel size is mostly in the way.

Known issue: Killing the SSH client will lead to the server side process not being terminated and some goroutines still running in the agent. This would require additional investigation to solve. The remote processes are still being cleaned up ok (at least on linux) when the agent exits.

This should not be an issue at all since the agent is a short-lived process and when running in a containerized environment with containers running on demand the cleanup will definitely work.
2024-07-28 11:48:31 +02:00
7a51e3ac45 Unique ids for clients generated by converge server and made available to the ssh session through a net.Conn extension that passes the ID to the SSH session through the LocalAddr(). 2024-07-27 22:37:40 +02:00
5a492f3855 initialization of username, password on client (from server) and initialization of agentinfo on server is now done as soon as the agent registered and not through a side channel.
Making use of some simple utilities for GOB to make it easy to send objects over the line.
2024-07-27 20:46:53 +02:00
621bbd8ca6 GOB channel for easily and asynchronously using GOB on a single network connection, also dealing with timeouts and errors in a good way.
Protocol version is now checked when the agent connects to the converge server.

Next up: sending connection metadata and username password from server to agent and sending environment information back to the server. This means then that the side channel will only be used for expiry time messages and session type with the client id passed in so the converge server can than correlate the results back to the correct channel.
2024-07-27 11:21:35 +02:00
f82601d07c Lots of refactoring.
Now hijacking the ssh connection setup in the listener to exchange some information before passing the connection on to the SSH server.

Next step is to do the full exchange of required information and to make it easy some simple Read and Write methods with timeouts are needed that use gob.
2024-07-26 22:40:56 +02:00