mirror of
https://github.com/profullstack/agentbbs.git
synced 2026-08-13 14:27:27 +00:00
feat(files): SFTP member storage — private workspaces + shared public area + mgmt TUI
Implements M4 (Files). A fully virtual Go SFTP server (pkg/sftp + crypto/ssh,
no OS users) wired as an "sftp" subsystem on the existing :22 wish listener, so
members reach their files with their login key:
sftp files@bbs.profullstack.com # scp/rsync ride the same endpoint
Identity is the SSH key (the username is conventional/ignored). Two areas per
session: a private, quota-limited /me workspace and a single shared public file
area /public (old-school BBS file area; world-read, members-only write by
default, operator-moderated). This reverses the old NG1 "no sharing" boundary in
favour of one sanctioned, inspectable sharing surface (PRD §9.3 amended).
internal/files:
- backend.go service, layout, quota/usage, live-session registry, operator API
- fs.go per-session virtual FS; resolve() is the single security
chokepoint (area confinement + symlink-escape guard) + pkg/sftp
request handlers
- server.go subsystem handler: key auth -> member session -> request server,
with byte metering and force-disconnect
- tui.go in-BBS member browser (hub plugin "Files")
- admin.go operator management TUI: sessions, workspaces/quotas, public area
Operator console: ssh sftp@<host> (allowlist-gated; sftpadmin@/filesadmin@
aliases) — list/disconnect sessions, set per-user quotas, revoke SFTP access,
toggle public write, moderate the public area.
store: files_access (per-user quota override + revoked) and files_settings
(public-write mode) tables + methods. main.go wiring guarded by AGENTBBS_FILES
(+ AGENTBBS_FILES_QUOTA_MB, default 1 GiB). Route names reserved.
Tests (incl -race): path traversal/confinement, symlink-escape rejection,
public-write ACL, quota enforcement, usage accounting, and an end-to-end run
against a real SFTP client. Docs: docs/files.md; PRD §5.3/§5.3.1/§9.3 + README
updated.
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
parent
68899180a7
commit
6dc94bd784
18 changed files with 2223 additions and 27 deletions
22
README.md
22
README.md
|
|
@ -36,7 +36,7 @@ plugins around one shared account system; the full product plan is in
|
|||
| M3 — AgentGames (`game@` + WebSocket; TTT/C4, ELO ladder, replays) | ✅ |
|
||||
| IRC (`irc.bbs.profullstack.com` — Ergo network for humans + agents) | ✅ |
|
||||
| News (`news.profullstack.com` — members-only Usenet/NNTP for humans + agents) | ✅ |
|
||||
| M4 — Files (cl1.tech SFTP workspaces) | ⬜ |
|
||||
| M4 — Files (SFTP: private workspaces + shared public area, mgmt TUI) | ✅ |
|
||||
| M5 — AgentAd marketplace (built on the AgentAd standard in logicsrc) | ⬜ |
|
||||
|
||||
## Run it
|
||||
|
|
@ -67,6 +67,8 @@ Configuration (env):
|
|||
| `AGENTBBS_GAME_MOVE_TIMEOUT` | `15` | AgentGames per-move deadline (s) — see [docs/agentgames.md](docs/agentgames.md) |
|
||||
| `AGENTBBS_GAME_QUEUE_WAIT` | `120` | how long a lone agent waits for an opponent (s) |
|
||||
| `AGENTBBS_GAME_WS_ADDR` | `127.0.0.1:8090` | AgentGames WebSocket endpoint (loopback; Caddy proxies `/play`) |
|
||||
| `AGENTBBS_FILES` | `1` | member SFTP storage subsystem + Files plugin (`0` disables) — see [docs/files.md](docs/files.md) |
|
||||
| `AGENTBBS_FILES_QUOTA_MB` | `1024` | default per-user workspace quota (MB) |
|
||||
|
||||
Ops:
|
||||
|
||||
|
|
@ -143,6 +145,24 @@ news.profullstack.com:563 # implicit TLS; login = your BBS member name
|
|||
Set `NEWS=0` to skip it. Needs a DNS record `news.profullstack.com A -> host`.
|
||||
Full details: [`docs/news.md`](docs/news.md).
|
||||
|
||||
### Files (SFTP)
|
||||
|
||||
Every member gets file storage over **SFTP**, on the same `:22` listener and the
|
||||
same SSH key they log in with (`internal/files`, a virtual Go SFTP server — no OS
|
||||
users). Two areas: a **private, quota-limited** `/me` workspace and a single
|
||||
**shared public file area** `/public` (old-school BBS file area; members-only
|
||||
write by default). `scp` and `rsync` ride the same endpoint:
|
||||
|
||||
```bash
|
||||
sftp files@bbs.profullstack.com # username is conventional; your key is your identity
|
||||
scp file.pdf files@bbs.profullstack.com:/me/
|
||||
```
|
||||
|
||||
There's also an in-hub **Files** browser and an operator management TUI
|
||||
(`ssh sftp@bbs.profullstack.com`, operators only) for sessions, quotas, and
|
||||
moderating the public area. Set `AGENTBBS_FILES=0` to disable. Full details:
|
||||
[`docs/files.md`](docs/files.md).
|
||||
|
||||
## Architecture
|
||||
|
||||
- **Go + charmbracelet** — `wish` SSH server, `bubbletea` TUIs, `lipgloss` styling.
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue