mirror of
https://github.com/profullstack/logicsrc.git
synced 2026-10-05 06:05:28 +00:00
`logicsrc vault` (OpenCreds) lived only in ~/.config/logicsrc/opencreds. Lose the machine and the vault went with it, and a second machine had no way to get it. It now syncs to the logged-in account. Server (apps/pwa, /api/opencreds, session or lsk_ bearer): - opencreds_vaults: one per user. meta (key material already wrapped under the master password) + an encrypted folder list, each with a revision. - opencreds_items: one row per item, as the spec asks; envelope NULL is a tombstone so purges propagate; seq for incremental pulls. - Every write names its base revision; a stale one gets 409 with the current row. Writes are conditional and read back (each envelope's random IV identifies our write), so this needs nothing dialect-specific from SQLite or Postgres. - Stores ciphertext only. The server learns item count and type codes, as OpenCreds security.md already accepts. Client (@logicsrc/opencreds sync.ts, key-free except where noted): - Pull before every vault command, push after. Offline, the command still works and the change goes up next time. - Conflicts never lose data: the account's edit keeps the id and this machine's becomes "<name> (conflict copy)" (needs the unlocked key, so it waits otherwise). An edit beats a purge. Byte-identical envelopes are adopted, not split, so a lost sync.json is harmless. - Two different vaults (meta.createdAt differs) are never merged: refused, with `vault sync --use-remote` (backs this machine's up to .bak-NNN) or `--use-local`. - Remote item ids must be plain ids; anything else is ignored and never becomes a path. - Folder names are AES-GCM encrypted under the user key before upload. CLI (0.6.0): `logicsrc vault sync [--status|--use-remote|--use-local]`. Only the default vault syncs, and only when logged in; a --home or OPENCREDS_HOME vault stays local unless LOGICSRC_VAULT_SYNC=on; LOGICSRC_VAULT_SYNC=off disables it. The standalone `opencreds` binary gets no remote and never syncs. `init` on a machine that just downloaded the account's vault says to unlock it instead of suggesting --force. Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
72 lines
3.6 KiB
JavaScript
72 lines
3.6 KiB
JavaScript
// LogicSRC credentials — Express PWA entrypoint (auth + team credential sharing).
|
|
import express from "express";
|
|
import cookieParser from "cookie-parser";
|
|
import path from "node:path";
|
|
import { createRequire } from "node:module";
|
|
import { config } from "./config.mjs";
|
|
import { migrate } from "./migrate.mjs";
|
|
import { sessionMiddleware, csrfGuard } from "./lib/session.mjs";
|
|
import { authRouter } from "./routes/auth.mjs";
|
|
import { passkeyRouter } from "./routes/passkey.mjs";
|
|
import { coinpayRouter } from "./routes/coinpay.mjs";
|
|
import { credshareRouter } from "./routes/credshare.mjs";
|
|
import { opencredsRouter } from "./routes/opencreds.mjs";
|
|
import { cliRouter } from "./routes/cli.mjs";
|
|
import { pagesRouter } from "./routes/pages.mjs";
|
|
|
|
const app = express();
|
|
app.disable("x-powered-by");
|
|
if (config.secure) app.set("trust proxy", 1); // Railway terminates TLS
|
|
|
|
// body parsing — keep the raw body for HMAC signature verification
|
|
// A vault push carries hundreds of encrypted items; parse it under a larger cap
|
|
// first. The global parser below skips a body that is already parsed.
|
|
app.use("/api/opencreds", express.json({ limit: "10mb" }));
|
|
app.use(express.json({ verify: (req, _res, buf) => { req.rawBody = buf.toString("utf8"); } }));
|
|
app.use(express.urlencoded({ extended: false }));
|
|
app.use(cookieParser());
|
|
|
|
// static
|
|
app.use(express.static(path.join(config.root, "public"), { maxAge: "1h" }));
|
|
// the @simplewebauthn/browser UMD bundle, served from node_modules (no CDN)
|
|
app.get("/vendor/simplewebauthn-browser.umd.js", (_req, res) =>
|
|
res.sendFile(path.join(config.root, "node_modules/@simplewebauthn/browser/dist/bundle/index.umd.min.js")));
|
|
// libsodium for in-browser vault decryption (public/vault.js). Same two files
|
|
// the CLI loads; resolved, not path-joined, so a hoisted workspace install works.
|
|
// Load order on the page: libsodium.js (window.libsodium) then the wrappers (window.sodium).
|
|
const requireHere = createRequire(import.meta.url);
|
|
const sodiumWrappers = requireHere.resolve("libsodium-wrappers");
|
|
const sodiumCore = createRequire(sodiumWrappers).resolve("libsodium");
|
|
app.get("/vendor/libsodium.js", (_req, res) => res.sendFile(sodiumCore));
|
|
app.get("/vendor/libsodium-wrappers.js", (_req, res) => res.sendFile(sodiumWrappers));
|
|
|
|
app.get("/healthz", (_req, res) => res.json({ ok: true, env: config.env }));
|
|
|
|
app.use(sessionMiddleware);
|
|
app.use(csrfGuard);
|
|
|
|
// routes
|
|
app.use(authRouter); // GET / (+ /auth/login|register|logout)
|
|
app.use(passkeyRouter);
|
|
app.use(coinpayRouter);
|
|
app.use(credshareRouter); // /api/credshare/* (session or lsk_ Bearer)
|
|
app.use(opencredsRouter); // /api/opencreds/* — personal vault sync (session or lsk_ Bearer)
|
|
app.use(cliRouter); // /cli/authorize, /cli/token, /api/me
|
|
app.use(pagesRouter); // /dashboard, /teams/*, /settings
|
|
|
|
app.use((req, res) => res.status(404).type("html").send(
|
|
`<body style="background:#f6f7f4;color:#101418;font-family:system-ui,sans-serif;padding:14vh 24px;text-align:center"><h1 style="color:#0a7d59">404</h1><p>no such page.</p><a style="color:#0a7d59" href="/">back to your teams →</a></body>`));
|
|
|
|
// eslint-disable-next-line no-unused-vars
|
|
app.use((err, _req, res, _next) => {
|
|
console.error(err);
|
|
res.status(500).type("html").send(`<body style="background:#f6f7f4;color:#c23a3a;font-family:system-ui,sans-serif;padding:14vh 24px;text-align:center"><h1>500</h1><p>something broke.</p></body>`);
|
|
});
|
|
|
|
async function main() {
|
|
await migrate();
|
|
app.listen(config.port, () => console.log(`🔐 logicsrc credentials on :${config.port} (${config.env}) — ${config.origin}`));
|
|
}
|
|
main().catch((e) => { console.error("boot failed:", e); process.exit(1); });
|
|
|
|
export { app };
|