feat: enhance project structure with server and workflow management
- Introduced a new server package with Fastify for handling API requests and workflows. - Implemented user authentication and authorization with JWT and cookie management. - Added endpoints for managing workflows, runs, and user accounts. - Established a dashboard for monitoring workflow status and statistics. - Included a script sandbox for executing user-defined scripts securely. - Updated README with setup instructions and API documentation. - Configured database migrations for user management. - Enhanced logging capabilities for better traceability.
This commit is contained in:
@@ -4,32 +4,38 @@ Content-Type: application/json
|
||||
|
||||
0
|
||||
|
||||
HTTP/1.1 200 - OK
|
||||
content-type: application/json; charset=utf-8
|
||||
content-length: 73
|
||||
date: Fri, 14 Aug 2026 04:34:56 GMT
|
||||
connection: close
|
||||
###
|
||||
POST http://localhost:9000/u/default/time-to-ntfy
|
||||
Content-Type: application/json
|
||||
|
||||
{}
|
||||
|
||||
HTTP/1.1 500 - Internal Server Error
|
||||
content-type: application/json; charset=utf-8
|
||||
content-length: 97
|
||||
date: Fri, 14 Aug 2026 04:11:52 GMT
|
||||
connection: close
|
||||
###
|
||||
GET http://localhost:9000/admin/runs?owner=default&limit=20
|
||||
###
|
||||
POST http://localhost:9000/admin/workflows/reregister
|
||||
### Auth bootstrap
|
||||
GET http://localhost:9000/api/auth/bootstrap
|
||||
|
||||
### Login
|
||||
POST http://localhost:9000/api/auth/login
|
||||
Content-Type: application/json
|
||||
|
||||
{
|
||||
"username": "admin",
|
||||
"password": "changeme1"
|
||||
}
|
||||
|
||||
### Dashboard
|
||||
GET http://localhost:9000/api/dashboard
|
||||
|
||||
### Runs
|
||||
GET http://localhost:9000/api/runs?owner=default&limit=20
|
||||
|
||||
### Reregister
|
||||
POST http://localhost:9000/api/workflows/reregister
|
||||
Content-Type: application/json
|
||||
|
||||
{}
|
||||
|
||||
HTTP/1.1 200 - OK
|
||||
content-type: application/json; charset=utf-8
|
||||
content-length: 33
|
||||
date: Fri, 14 Aug 2026 04:34:22 GMT
|
||||
connection: close
|
||||
### Run workflow manually
|
||||
POST http://localhost:9000/api/workflows/default/manual-trigger.yaml/run
|
||||
Content-Type: application/json
|
||||
|
||||
{}
|
||||
|
||||
@@ -0,0 +1,128 @@
|
||||
import fs from "fs";
|
||||
import path from "path";
|
||||
import yaml from "yaml";
|
||||
import { SCRIPTS_DIR, WORKFLOWS_DIR } from "./paths.js";
|
||||
|
||||
export function assertScriptName(name) {
|
||||
if (typeof name !== "string" || !/^[A-Za-z0-9._-]+\.js$/.test(name)) {
|
||||
const err = new Error("invalid script name");
|
||||
err.statusCode = 400;
|
||||
throw err;
|
||||
}
|
||||
return name;
|
||||
}
|
||||
|
||||
export function assertOwner(name) {
|
||||
if (typeof name !== "string" || !/^[A-Za-z0-9_-]+$/.test(name)) {
|
||||
const err = new Error("invalid owner");
|
||||
err.statusCode = 400;
|
||||
throw err;
|
||||
}
|
||||
return name;
|
||||
}
|
||||
|
||||
export function assertWorkflowFile(name) {
|
||||
if (
|
||||
typeof name !== "string" ||
|
||||
!/^[A-Za-z0-9._-]+\.ya?ml$/.test(name) ||
|
||||
name === "registers.yaml"
|
||||
) {
|
||||
const err = new Error("invalid workflow file");
|
||||
err.statusCode = 400;
|
||||
throw err;
|
||||
}
|
||||
return name;
|
||||
}
|
||||
|
||||
export function listScriptFiles() {
|
||||
if (!fs.existsSync(SCRIPTS_DIR)) return [];
|
||||
return fs
|
||||
.readdirSync(SCRIPTS_DIR)
|
||||
.filter((f) => f.endsWith(".js"))
|
||||
.sort();
|
||||
}
|
||||
|
||||
export function readScript(name) {
|
||||
assertScriptName(name);
|
||||
const filePath = path.join(SCRIPTS_DIR, name);
|
||||
if (!fs.existsSync(filePath)) return null;
|
||||
return fs.readFileSync(filePath, "utf8");
|
||||
}
|
||||
|
||||
export function writeScript(name, content) {
|
||||
assertScriptName(name);
|
||||
fs.mkdirSync(SCRIPTS_DIR, { recursive: true });
|
||||
fs.writeFileSync(path.join(SCRIPTS_DIR, name), content, "utf8");
|
||||
}
|
||||
|
||||
export function deleteScript(name) {
|
||||
assertScriptName(name);
|
||||
const filePath = path.join(SCRIPTS_DIR, name);
|
||||
if (!fs.existsSync(filePath)) return false;
|
||||
fs.unlinkSync(filePath);
|
||||
return true;
|
||||
}
|
||||
|
||||
export function listOwners() {
|
||||
if (!fs.existsSync(WORKFLOWS_DIR)) return [];
|
||||
return fs
|
||||
.readdirSync(WORKFLOWS_DIR, { withFileTypes: true })
|
||||
.filter((d) => d.isDirectory())
|
||||
.map((d) => d.name)
|
||||
.sort();
|
||||
}
|
||||
|
||||
function registersPath(owner) {
|
||||
return path.join(WORKFLOWS_DIR, owner, "registers.yaml");
|
||||
}
|
||||
|
||||
export function readRegisters(owner) {
|
||||
const filePath = registersPath(owner);
|
||||
if (!fs.existsSync(filePath)) return [];
|
||||
const parsed = yaml.parse(fs.readFileSync(filePath, "utf8")) ?? {};
|
||||
return Array.isArray(parsed.scripts) ? parsed.scripts : [];
|
||||
}
|
||||
|
||||
export function writeRegisters(owner, files) {
|
||||
const ownerDir = path.join(WORKFLOWS_DIR, owner);
|
||||
fs.mkdirSync(ownerDir, { recursive: true });
|
||||
fs.writeFileSync(
|
||||
registersPath(owner),
|
||||
yaml.stringify({ scripts: files }),
|
||||
"utf8",
|
||||
);
|
||||
}
|
||||
|
||||
export function readWorkflowYaml(owner, file) {
|
||||
assertOwner(owner);
|
||||
assertWorkflowFile(file);
|
||||
const filePath = path.join(WORKFLOWS_DIR, owner, file);
|
||||
if (!fs.existsSync(filePath)) return null;
|
||||
return fs.readFileSync(filePath, "utf8");
|
||||
}
|
||||
|
||||
export function writeWorkflowYaml(owner, file, content) {
|
||||
assertOwner(owner);
|
||||
assertWorkflowFile(file);
|
||||
const ownerDir = path.join(WORKFLOWS_DIR, owner);
|
||||
fs.mkdirSync(ownerDir, { recursive: true });
|
||||
fs.writeFileSync(path.join(ownerDir, file), content, "utf8");
|
||||
}
|
||||
|
||||
export function deleteWorkflowYaml(owner, file) {
|
||||
assertOwner(owner);
|
||||
assertWorkflowFile(file);
|
||||
const filePath = path.join(WORKFLOWS_DIR, owner, file);
|
||||
if (!fs.existsSync(filePath)) return false;
|
||||
fs.unlinkSync(filePath);
|
||||
return true;
|
||||
}
|
||||
|
||||
export function listOwnerYamlFiles(owner) {
|
||||
const ownerDir = path.join(WORKFLOWS_DIR, owner);
|
||||
if (!fs.existsSync(ownerDir)) return [];
|
||||
return fs
|
||||
.readdirSync(ownerDir)
|
||||
.filter((f) => f.endsWith(".yaml") && f !== "registers.yaml")
|
||||
.sort();
|
||||
}
|
||||
@@ -1,7 +1,8 @@
|
||||
import fs from "fs";
|
||||
import path from "path";
|
||||
import { DATA_DIR, SERVER_ROOT } from "./paths.js";
|
||||
|
||||
const dbPath = process.env.SCRUNNER_DB_PATH ?? path.resolve("data/scrunner.db");
|
||||
const dbPath = process.env.SCRUNNER_DB_PATH ?? path.join(DATA_DIR, "scrunner.db");
|
||||
fs.mkdirSync(path.dirname(dbPath), { recursive: true });
|
||||
|
||||
/** @type {import("knex").Knex.Config} */
|
||||
@@ -12,7 +13,7 @@ const config = {
|
||||
},
|
||||
useNullAsDefault: true,
|
||||
migrations: {
|
||||
directory: "./migrations",
|
||||
directory: path.join(SERVER_ROOT, "migrations"),
|
||||
extension: "js",
|
||||
loadExtensions: [".js"],
|
||||
},
|
||||
|
||||
@@ -2,6 +2,7 @@ import fs from "fs";
|
||||
import path from "path";
|
||||
import pino from "pino";
|
||||
import * as store from "./store.js";
|
||||
import { LOGS_DIR } from "./paths.js";
|
||||
|
||||
const LEVEL_TO_NUM = {
|
||||
trace: 10,
|
||||
@@ -87,12 +88,12 @@ const sqliteStream = {
|
||||
},
|
||||
};
|
||||
|
||||
fs.mkdirSync("logs", { recursive: true });
|
||||
fs.mkdirSync(LOGS_DIR, { recursive: true });
|
||||
|
||||
const rollingFile = pino.transport({
|
||||
target: "pino-roll",
|
||||
options: {
|
||||
file: path.resolve("logs/scrunner.log"),
|
||||
file: path.join(LOGS_DIR, "scrunner.log"),
|
||||
size: "10m",
|
||||
mkdir: true,
|
||||
limit: { count: 5 },
|
||||
|
||||
@@ -0,0 +1,20 @@
|
||||
/**
|
||||
* @param {import("knex").Knex} knex
|
||||
*/
|
||||
export async function up(knex) {
|
||||
await knex.schema.createTable("users", (t) => {
|
||||
t.text("id").primary();
|
||||
t.text("username").notNullable().unique();
|
||||
t.text("password_hash").notNullable();
|
||||
t.text("role").notNullable();
|
||||
t.text("created_at").notNullable();
|
||||
t.text("updated_at").notNullable();
|
||||
});
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {import("knex").Knex} knex
|
||||
*/
|
||||
export async function down(knex) {
|
||||
await knex.schema.dropTableIfExists("users");
|
||||
}
|
||||
@@ -0,0 +1,28 @@
|
||||
{
|
||||
"name": "@scrunner/server",
|
||||
"version": "1.0.0",
|
||||
"private": true,
|
||||
"type": "module",
|
||||
"main": "runner.js",
|
||||
"scripts": {
|
||||
"dev": "node --watch runner.js",
|
||||
"start": "node runner.js",
|
||||
"migrate": "node -e \"import('./db.js').then((m) => m.migrate().then(() => process.exit(0)))\""
|
||||
},
|
||||
"dependencies": {
|
||||
"@fastify/cookie": "^11.0.2",
|
||||
"@fastify/cors": "^11.1.0",
|
||||
"@fastify/jwt": "^9.1.0",
|
||||
"@fastify/static": "^8.2.0",
|
||||
"axios": "^1.19.0",
|
||||
"bcryptjs": "^3.0.2",
|
||||
"better-sqlite3": "^13.0.3",
|
||||
"fastify": "^5.12.0",
|
||||
"jsonata": "^2.2.2",
|
||||
"knex": "^3.3.0",
|
||||
"node-cron": "^4.6.0",
|
||||
"pino": "^10.3.1",
|
||||
"pino-roll": "^4.0.0",
|
||||
"yaml": "^2.9.0"
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,9 @@
|
||||
import path from "path";
|
||||
import { fileURLToPath } from "url";
|
||||
|
||||
export const SERVER_ROOT = path.dirname(fileURLToPath(import.meta.url));
|
||||
export const SCRIPTS_DIR = path.join(SERVER_ROOT, "scripts");
|
||||
export const WORKFLOWS_DIR = path.join(SERVER_ROOT, "workflows");
|
||||
export const DATA_DIR = path.join(SERVER_ROOT, "data");
|
||||
export const LOGS_DIR = path.join(SERVER_ROOT, "logs");
|
||||
export const WEB_DIST = path.resolve(SERVER_ROOT, "../web/dist");
|
||||
@@ -0,0 +1,288 @@
|
||||
import fs from "fs";
|
||||
import path from "path";
|
||||
import yaml from "yaml";
|
||||
import cron from "node-cron";
|
||||
import { WORKFLOWS_DIR } from "./paths.js";
|
||||
import { log } from "./logger.js";
|
||||
import * as store from "./store.js";
|
||||
import { clearScriptCache, runScript } from "./script-sandbox.js";
|
||||
import { namespacedPath, parseScriptStep } from "./workflow-parse.js";
|
||||
import * as fsStore from "./fs-store.js";
|
||||
|
||||
/**
|
||||
* @typedef {{ owner: string, file: string, workflow: any }} WorkflowEntry
|
||||
*/
|
||||
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} server
|
||||
*/
|
||||
export function createRegistry(server) {
|
||||
/** @type {Map<string, WorkflowEntry>} */
|
||||
const workflows = new Map();
|
||||
/** @type {Map<string, string>} */
|
||||
const loadErrors = new Map();
|
||||
/** @type {import("node-cron").ScheduledTask[]} */
|
||||
const cronTasks = [];
|
||||
/** @type {import("node-cron").ScheduledTask | null} */
|
||||
let pruneTask = null;
|
||||
/** @type {Set<string>} */
|
||||
const registeredHttpRoutes = new Set();
|
||||
|
||||
function registerWorkflows() {
|
||||
workflows.clear();
|
||||
loadErrors.clear();
|
||||
clearScriptCache();
|
||||
|
||||
if (!fs.existsSync(WORKFLOWS_DIR)) {
|
||||
log.warn("workflows directory missing");
|
||||
return;
|
||||
}
|
||||
|
||||
const owners = fsStore.listOwners();
|
||||
|
||||
for (const owner of owners) {
|
||||
const registersPath = path.join(WORKFLOWS_DIR, owner, "registers.yaml");
|
||||
if (!fs.existsSync(registersPath)) {
|
||||
log.warn(`Skipping owner "${owner}": no registers.yaml`);
|
||||
continue;
|
||||
}
|
||||
|
||||
let workflowFiles = [];
|
||||
try {
|
||||
workflowFiles = fsStore.readRegisters(owner);
|
||||
} catch (err) {
|
||||
log.error({ err, owner }, "failed to parse registers.yaml");
|
||||
continue;
|
||||
}
|
||||
|
||||
const onDisk = fsStore.listOwnerYamlFiles(owner);
|
||||
for (const file of onDisk) {
|
||||
if (!workflowFiles.includes(file)) {
|
||||
log.warn(`Workflow file not in registers.yaml: ${owner}/${file}`);
|
||||
}
|
||||
}
|
||||
|
||||
for (const file of workflowFiles) {
|
||||
const key = `${owner}/${file}`;
|
||||
const filePath = path.join(WORKFLOWS_DIR, owner, file);
|
||||
try {
|
||||
const workflowData = fs.readFileSync(filePath, "utf8");
|
||||
const workflow = yaml.parse(workflowData);
|
||||
workflows.set(key, { owner, file, workflow });
|
||||
} catch (err) {
|
||||
const message = err instanceof Error ? err.message : String(err);
|
||||
loadErrors.set(key, message);
|
||||
log.error({ err, workflow: key }, "failed to load workflow; skipping");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
log.debug({ count: workflows.size }, "workflows loaded");
|
||||
}
|
||||
|
||||
function registerHttpTriggers() {
|
||||
const seen = new Set();
|
||||
|
||||
for (const [key, { owner, workflow }] of workflows) {
|
||||
if (workflow.enabled === false) {
|
||||
log.debug(`Skipping disabled workflow HTTP triggers (${key})`);
|
||||
continue;
|
||||
}
|
||||
|
||||
for (const trigger of workflow.triggers ?? []) {
|
||||
if (trigger.type !== "HTTP") continue;
|
||||
|
||||
const method = String(trigger.method ?? "POST").toUpperCase();
|
||||
const url = namespacedPath(owner, trigger.path);
|
||||
const routeKey = `${method} ${url}`;
|
||||
|
||||
if (seen.has(routeKey)) {
|
||||
log.warn(`Skipping duplicate HTTP trigger ${routeKey} (${key})`);
|
||||
continue;
|
||||
}
|
||||
seen.add(routeKey);
|
||||
|
||||
if (registeredHttpRoutes.has(routeKey)) {
|
||||
continue;
|
||||
}
|
||||
registeredHttpRoutes.add(routeKey);
|
||||
|
||||
server.route({
|
||||
method,
|
||||
url,
|
||||
handler: async (req, reply) => {
|
||||
const result = await runWorkflow(
|
||||
key,
|
||||
{ data: req.body },
|
||||
{ type: "http", detail: `${method} ${url}` },
|
||||
);
|
||||
if (result.status === "failed") {
|
||||
return reply.code(500).send({
|
||||
runId: result.runId,
|
||||
error: result.error,
|
||||
});
|
||||
}
|
||||
return reply.send({
|
||||
runId: result.runId,
|
||||
result: result.result,
|
||||
});
|
||||
},
|
||||
});
|
||||
log.debug(`Registered HTTP trigger ${routeKey} (${key})`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function registerCronTriggers() {
|
||||
for (const task of cronTasks) {
|
||||
task.destroy();
|
||||
}
|
||||
cronTasks.length = 0;
|
||||
|
||||
for (const [key, { workflow }] of workflows) {
|
||||
if (workflow.enabled === false) {
|
||||
log.debug(`Skipping disabled workflow cron triggers (${key})`);
|
||||
continue;
|
||||
}
|
||||
|
||||
for (const trigger of workflow.triggers ?? []) {
|
||||
if (trigger.type !== "cron") continue;
|
||||
|
||||
const schedule = trigger.schedule;
|
||||
if (!schedule || !cron.validate(schedule)) {
|
||||
log.warn(`Skipping invalid cron schedule "${schedule}" (${key})`);
|
||||
continue;
|
||||
}
|
||||
|
||||
const task = cron.schedule(
|
||||
schedule,
|
||||
() => {
|
||||
log.debug(`cron firing ${key} (${schedule})`);
|
||||
return runWorkflow(
|
||||
key,
|
||||
{ data: workflow.data ?? null },
|
||||
{ type: "cron", detail: schedule },
|
||||
);
|
||||
},
|
||||
{ name: `${key}:${schedule}`, noOverlap: true },
|
||||
);
|
||||
cronTasks.push(task);
|
||||
log.debug(`Registered cron trigger ${schedule} (${key})`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function registerPruneJob() {
|
||||
if (pruneTask) {
|
||||
pruneTask.destroy();
|
||||
pruneTask = null;
|
||||
}
|
||||
const days = Number(process.env.SCRUNNER_RETENTION_DAYS ?? 30);
|
||||
pruneTask = cron.schedule(
|
||||
"0 0 * * *",
|
||||
async () => {
|
||||
try {
|
||||
const deleted = await store.pruneOlderThan(days);
|
||||
log.info({ deleted, days }, "pruned old workflow runs");
|
||||
} catch (err) {
|
||||
log.error({ err }, "failed to prune old workflow runs");
|
||||
}
|
||||
},
|
||||
{ name: "prune-runs" },
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {string} key
|
||||
* @param {{ data?: unknown }} context
|
||||
* @param {{ type: string, detail?: string | null }} trigger
|
||||
*/
|
||||
async function runWorkflow(key, context, trigger) {
|
||||
const entry = workflows.get(key);
|
||||
if (!entry) {
|
||||
log.error({ workflow: key }, "workflow not found");
|
||||
return { runId: null, status: "failed", error: "workflow not found" };
|
||||
}
|
||||
|
||||
const { owner, workflow } = entry;
|
||||
const run = await store.startRun({
|
||||
owner,
|
||||
workflow: key,
|
||||
workflowName: workflow?.name,
|
||||
trigger,
|
||||
input: context.data,
|
||||
});
|
||||
const runLog = log.child({ runId: run.id, owner, workflow: key });
|
||||
runLog.debug("running workflow");
|
||||
|
||||
let ctx = {
|
||||
...context,
|
||||
data: context.data ?? workflow.data ?? null,
|
||||
};
|
||||
|
||||
try {
|
||||
for (const [index, rawStep] of (workflow.scripts ?? []).entries()) {
|
||||
const { script, config } = parseScriptStep(rawStep);
|
||||
const step = await store.startStep({
|
||||
runId: run.id,
|
||||
index,
|
||||
script,
|
||||
config,
|
||||
});
|
||||
const stepLog = runLog.child({ stepId: step.id, script });
|
||||
try {
|
||||
ctx = await runScript(script, { ...ctx, config }, {
|
||||
log: stepLog,
|
||||
workflowName: key,
|
||||
});
|
||||
await store.finishStep(step.id, "success", ctx);
|
||||
} catch (err) {
|
||||
await store.finishStep(step.id, "failed", null, err);
|
||||
throw err;
|
||||
}
|
||||
}
|
||||
await store.finishRun(run.id, "success", ctx);
|
||||
return { runId: run.id, status: "success", result: ctx };
|
||||
} catch (err) {
|
||||
runLog.error({ err }, "workflow failed");
|
||||
await store.finishRun(run.id, "failed", null, err);
|
||||
return {
|
||||
runId: run.id,
|
||||
status: "failed",
|
||||
error: err instanceof Error ? err.message : String(err),
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
function reregister() {
|
||||
registerWorkflows();
|
||||
registerHttpTriggers();
|
||||
registerCronTriggers();
|
||||
}
|
||||
|
||||
function referencedScripts() {
|
||||
const refs = new Set();
|
||||
for (const { workflow } of workflows.values()) {
|
||||
for (const raw of workflow.scripts ?? []) {
|
||||
try {
|
||||
refs.add(parseScriptStep(raw).script);
|
||||
} catch {
|
||||
// skip invalid steps
|
||||
}
|
||||
}
|
||||
}
|
||||
return refs;
|
||||
}
|
||||
|
||||
return {
|
||||
workflows,
|
||||
loadErrors,
|
||||
registerWorkflows,
|
||||
registerHttpTriggers,
|
||||
registerCronTriggers,
|
||||
registerPruneJob,
|
||||
reregister,
|
||||
runWorkflow,
|
||||
referencedScripts,
|
||||
};
|
||||
}
|
||||
+130
-308
@@ -1,328 +1,148 @@
|
||||
import fs from "fs";
|
||||
import path from "path";
|
||||
import yaml from "yaml";
|
||||
import fastify from "fastify";
|
||||
import cron from "node-cron";
|
||||
import cookie from "@fastify/cookie";
|
||||
import cors from "@fastify/cors";
|
||||
import jwt from "@fastify/jwt";
|
||||
import fastifyStatic from "@fastify/static";
|
||||
import { migrate, db } from "./db.js";
|
||||
import { log, enableLogPersistence, flushLogs } from "./logger.js";
|
||||
import * as store from "./store.js";
|
||||
import { clearScriptCache, runScript } from "./script-sandbox.js";
|
||||
import { createRegistry } from "./registry.js";
|
||||
import { COOKIE, OPEN_API_ROUTES } from "./src/api/auth.js";
|
||||
import authPlugin from "./src/api/auth.js";
|
||||
import usersPlugin from "./src/api/users.js";
|
||||
import scriptsPluginFactory from "./src/api/scripts.js";
|
||||
import workflowsPluginFactory from "./src/api/workflows.js";
|
||||
import runsPlugin from "./src/api/runs.js";
|
||||
import dashboardPluginFactory from "./src/api/dashboard.js";
|
||||
import { WEB_DIST } from "./paths.js";
|
||||
|
||||
await migrate();
|
||||
enableLogPersistence();
|
||||
|
||||
/**
|
||||
* @typedef {{ owner: string, file: string, workflow: any }} WorkflowEntry
|
||||
*/
|
||||
const jwtSecret =
|
||||
process.env.SCRUNNER_JWT_SECRET ??
|
||||
(process.env.NODE_ENV === "production" ? "" : "scrunner-dev-secret");
|
||||
|
||||
/**
|
||||
* @type {Map<string, WorkflowEntry>}
|
||||
*/
|
||||
const workflows = new Map();
|
||||
|
||||
/**
|
||||
* @type {import("node-cron").ScheduledTask[]}
|
||||
*/
|
||||
const cronTasks = [];
|
||||
|
||||
/**
|
||||
* @type {import("node-cron").ScheduledTask | null}
|
||||
*/
|
||||
let pruneTask = null;
|
||||
|
||||
/**
|
||||
* @type {Set<string>}
|
||||
*/
|
||||
const registeredHttpRoutes = new Set();
|
||||
|
||||
function parseScriptStep(step) {
|
||||
if (typeof step === "string") return { script: step, config: null };
|
||||
if (step?.script) return { script: step.script, config: step.config ?? null };
|
||||
throw new Error(`Invalid script step: ${JSON.stringify(step)}`);
|
||||
if (!jwtSecret) {
|
||||
log.error("SCRUNNER_JWT_SECRET is required in production");
|
||||
process.exit(1);
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve an HTTP path under the owner namespace: /notify -> /u/alice/notify
|
||||
* @param {string} owner
|
||||
* @param {string} triggerPath
|
||||
*/
|
||||
function namespacedPath(owner, triggerPath) {
|
||||
const cleaned = String(triggerPath).replace(/^\/+/, "");
|
||||
return `/u/${owner}/${cleaned}`;
|
||||
}
|
||||
|
||||
function registerWorkflows() {
|
||||
workflows.clear();
|
||||
clearScriptCache();
|
||||
|
||||
const workflowsRoot = "workflows";
|
||||
if (!fs.existsSync(workflowsRoot)) {
|
||||
log.warn("workflows directory missing");
|
||||
return;
|
||||
}
|
||||
|
||||
const owners = fs
|
||||
.readdirSync(workflowsRoot, { withFileTypes: true })
|
||||
.filter((d) => d.isDirectory())
|
||||
.map((d) => d.name);
|
||||
|
||||
for (const owner of owners) {
|
||||
const registersPath = path.join(workflowsRoot, owner, "registers.yaml");
|
||||
if (!fs.existsSync(registersPath)) {
|
||||
log.warn(`Skipping owner "${owner}": no registers.yaml`);
|
||||
continue;
|
||||
}
|
||||
|
||||
let workflowFiles = [];
|
||||
try {
|
||||
const registerData = fs.readFileSync(registersPath, "utf8");
|
||||
const parsed = yaml.parse(registerData) ?? {};
|
||||
workflowFiles = parsed.scripts ?? [];
|
||||
} catch (err) {
|
||||
log.error({ err, owner }, "failed to parse registers.yaml");
|
||||
continue;
|
||||
}
|
||||
|
||||
const ownerDir = path.join(workflowsRoot, owner);
|
||||
const onDisk = fs
|
||||
.readdirSync(ownerDir)
|
||||
.filter((f) => f.endsWith(".yaml") && f !== "registers.yaml");
|
||||
for (const file of onDisk) {
|
||||
if (!workflowFiles.includes(file)) {
|
||||
log.warn(
|
||||
`Workflow file not in registers.yaml: ${owner}/${file}`,
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
for (const file of workflowFiles) {
|
||||
const key = `${owner}/${file}`;
|
||||
const filePath = path.join(ownerDir, file);
|
||||
try {
|
||||
const workflowData = fs.readFileSync(filePath, "utf8");
|
||||
const workflow = yaml.parse(workflowData);
|
||||
workflows.set(key, { owner, file, workflow });
|
||||
} catch (err) {
|
||||
log.error({ err, workflow: key }, "failed to load workflow; skipping");
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
log.debug({ count: workflows.size }, "workflows loaded");
|
||||
}
|
||||
|
||||
function registerHttpTriggers() {
|
||||
const seen = new Set();
|
||||
|
||||
for (const [key, { owner, workflow }] of workflows) {
|
||||
if (workflow.enabled === false) {
|
||||
log.debug(`Skipping disabled workflow HTTP triggers (${key})`);
|
||||
continue;
|
||||
}
|
||||
|
||||
for (const trigger of workflow.triggers ?? []) {
|
||||
if (trigger.type !== "HTTP") continue;
|
||||
|
||||
const method = String(trigger.method ?? "POST").toUpperCase();
|
||||
const url = namespacedPath(owner, trigger.path);
|
||||
const routeKey = `${method} ${url}`;
|
||||
|
||||
if (seen.has(routeKey)) {
|
||||
log.warn(`Skipping duplicate HTTP trigger ${routeKey} (${key})`);
|
||||
continue;
|
||||
}
|
||||
seen.add(routeKey);
|
||||
|
||||
if (registeredHttpRoutes.has(routeKey)) {
|
||||
continue;
|
||||
}
|
||||
registeredHttpRoutes.add(routeKey);
|
||||
|
||||
server.route({
|
||||
method,
|
||||
url,
|
||||
handler: async (req, reply) => {
|
||||
const result = await runWorkflow(
|
||||
key,
|
||||
{ data: req.body },
|
||||
{ type: "http", detail: `${method} ${url}` },
|
||||
);
|
||||
if (result.status === "failed") {
|
||||
return reply.code(500).send({
|
||||
runId: result.runId,
|
||||
error: result.error,
|
||||
});
|
||||
}
|
||||
return reply.send({
|
||||
runId: result.runId,
|
||||
result: result.result,
|
||||
});
|
||||
},
|
||||
});
|
||||
log.debug(`Registered HTTP trigger ${routeKey} (${key})`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function registerCronTriggers() {
|
||||
for (const task of cronTasks) {
|
||||
task.destroy();
|
||||
}
|
||||
cronTasks.length = 0;
|
||||
|
||||
for (const [key, { workflow }] of workflows) {
|
||||
if (workflow.enabled === false) {
|
||||
log.debug(`Skipping disabled workflow cron triggers (${key})`);
|
||||
continue;
|
||||
}
|
||||
|
||||
for (const trigger of workflow.triggers ?? []) {
|
||||
if (trigger.type !== "cron") continue;
|
||||
|
||||
const schedule = trigger.schedule;
|
||||
if (!schedule || !cron.validate(schedule)) {
|
||||
log.warn(`Skipping invalid cron schedule "${schedule}" (${key})`);
|
||||
continue;
|
||||
}
|
||||
|
||||
const task = cron.schedule(
|
||||
schedule,
|
||||
() => {
|
||||
log.debug(`cron firing ${key} (${schedule})`);
|
||||
return runWorkflow(
|
||||
key,
|
||||
{ data: workflow.data ?? null },
|
||||
{ type: "cron", detail: schedule },
|
||||
);
|
||||
},
|
||||
{ name: `${key}:${schedule}`, noOverlap: true },
|
||||
);
|
||||
cronTasks.push(task);
|
||||
log.debug(`Registered cron trigger ${schedule} (${key})`);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
function registerPruneJob() {
|
||||
if (pruneTask) {
|
||||
pruneTask.destroy();
|
||||
pruneTask = null;
|
||||
}
|
||||
const days = Number(process.env.SCRUNNER_RETENTION_DAYS ?? 30);
|
||||
pruneTask = cron.schedule(
|
||||
"0 0 * * *",
|
||||
async () => {
|
||||
try {
|
||||
const deleted = await store.pruneOlderThan(days);
|
||||
log.info({ deleted, days }, "pruned old workflow runs");
|
||||
} catch (err) {
|
||||
log.error({ err }, "failed to prune old workflow runs");
|
||||
}
|
||||
},
|
||||
{ name: "prune-runs" },
|
||||
);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {string} key
|
||||
* @param {{ data?: unknown }} context
|
||||
* @param {{ type: string, detail?: string | null }} trigger
|
||||
*/
|
||||
async function runWorkflow(key, context, trigger) {
|
||||
const entry = workflows.get(key);
|
||||
if (!entry) {
|
||||
log.error({ workflow: key }, "workflow not found");
|
||||
return { runId: null, status: "failed", error: "workflow not found" };
|
||||
}
|
||||
|
||||
const { owner, workflow } = entry;
|
||||
const run = await store.startRun({
|
||||
owner,
|
||||
workflow: key,
|
||||
workflowName: workflow?.name,
|
||||
trigger,
|
||||
input: context.data,
|
||||
});
|
||||
const runLog = log.child({ runId: run.id, owner, workflow: key });
|
||||
runLog.debug("running workflow");
|
||||
|
||||
let ctx = {
|
||||
...context,
|
||||
data: context.data ?? workflow.data ?? null,
|
||||
};
|
||||
|
||||
try {
|
||||
for (const [index, rawStep] of (workflow.scripts ?? []).entries()) {
|
||||
const { script, config } = parseScriptStep(rawStep);
|
||||
const step = await store.startStep({
|
||||
runId: run.id,
|
||||
index,
|
||||
script,
|
||||
config,
|
||||
});
|
||||
const stepLog = runLog.child({ stepId: step.id, script });
|
||||
try {
|
||||
ctx = await runScript(script, { ...ctx, config }, {
|
||||
log: stepLog,
|
||||
workflowName: key,
|
||||
});
|
||||
await store.finishStep(step.id, "success", ctx);
|
||||
} catch (err) {
|
||||
await store.finishStep(step.id, "failed", null, err);
|
||||
throw err;
|
||||
}
|
||||
}
|
||||
await store.finishRun(run.id, "success", ctx);
|
||||
return { runId: run.id, status: "success", result: ctx };
|
||||
} catch (err) {
|
||||
runLog.error({ err }, "workflow failed");
|
||||
await store.finishRun(run.id, "failed", null, err);
|
||||
return {
|
||||
runId: run.id,
|
||||
status: "failed",
|
||||
error: err instanceof Error ? err.message : String(err),
|
||||
};
|
||||
}
|
||||
}
|
||||
|
||||
registerWorkflows();
|
||||
|
||||
const server = fastify({ loggerInstance: log });
|
||||
|
||||
registerHttpTriggers();
|
||||
registerCronTriggers();
|
||||
registerPruneJob();
|
||||
|
||||
server.post("/admin/workflows/reregister", async (_req, reply) => {
|
||||
registerWorkflows();
|
||||
// Fastify cannot remove routes; new routes are added, cron is rebuilt.
|
||||
registerHttpTriggers();
|
||||
registerCronTriggers();
|
||||
return reply.send({ message: "Workflows refreshed" });
|
||||
await server.register(cookie);
|
||||
await server.register(jwt, {
|
||||
secret: jwtSecret,
|
||||
cookie: {
|
||||
cookieName: COOKIE,
|
||||
signed: false,
|
||||
},
|
||||
});
|
||||
await server.register(cors, {
|
||||
origin: process.env.SCRUNNER_CORS_ORIGIN ?? "http://localhost:5173",
|
||||
credentials: true,
|
||||
});
|
||||
|
||||
server.get("/admin/runs", async (req, reply) => {
|
||||
const q = /** @type {Record<string, string | undefined>} */ (req.query);
|
||||
const limit = q.limit ? Number(q.limit) : undefined;
|
||||
const runs = await store.listRuns({
|
||||
owner: q.owner,
|
||||
workflow: q.workflow,
|
||||
status: q.status,
|
||||
limit: Number.isFinite(limit) ? limit : undefined,
|
||||
before: q.before,
|
||||
});
|
||||
return reply.send({ runs });
|
||||
});
|
||||
|
||||
server.get("/admin/runs/:id", async (req, reply) => {
|
||||
const { id } = /** @type {{ id: string }} */ (req.params);
|
||||
const run = await store.getRun(id);
|
||||
if (!run) {
|
||||
return reply.code(404).send({ error: "run not found" });
|
||||
server.decorate("authenticate", async function authenticate(req, reply) {
|
||||
try {
|
||||
await req.jwtVerify();
|
||||
} catch {
|
||||
return reply.code(401).send({ error: "unauthorized" });
|
||||
}
|
||||
return reply.send(run);
|
||||
});
|
||||
|
||||
server.decorate("requireAdmin", async function requireAdmin(req, reply) {
|
||||
if (req.user?.role !== "admin") {
|
||||
return reply.code(403).send({ error: "forbidden" });
|
||||
}
|
||||
});
|
||||
|
||||
const registry = createRegistry(server);
|
||||
registry.registerWorkflows();
|
||||
registry.registerHttpTriggers();
|
||||
registry.registerCronTriggers();
|
||||
registry.registerPruneJob();
|
||||
|
||||
await server.register(
|
||||
async (api) => {
|
||||
api.addHook("onRequest", async (req, reply) => {
|
||||
const raw = (req.url || "").split("?")[0];
|
||||
const stripped = raw.replace(/^\/api/, "") || "/";
|
||||
const routeUrl = req.routeOptions?.url || stripped;
|
||||
const open =
|
||||
OPEN_API_ROUTES.has(`${req.method} ${routeUrl}`) ||
|
||||
OPEN_API_ROUTES.has(`${req.method} ${stripped}`);
|
||||
if (open) return;
|
||||
await server.authenticate(req, reply);
|
||||
});
|
||||
await api.register(authPlugin);
|
||||
await api.register(usersPlugin);
|
||||
await api.register(scriptsPluginFactory(registry));
|
||||
await api.register(workflowsPluginFactory(registry));
|
||||
await api.register(runsPlugin);
|
||||
await api.register(dashboardPluginFactory(registry));
|
||||
},
|
||||
{ prefix: "/api" },
|
||||
);
|
||||
|
||||
server.post(
|
||||
"/admin/workflows/reregister",
|
||||
{ onRequest: [server.authenticate] },
|
||||
async (_req, reply) => {
|
||||
registry.reregister();
|
||||
return reply.send({ message: "Workflows refreshed" });
|
||||
},
|
||||
);
|
||||
|
||||
server.get(
|
||||
"/admin/runs",
|
||||
{ onRequest: [server.authenticate] },
|
||||
async (req, reply) => {
|
||||
const q = /** @type {Record<string, string | undefined>} */ (req.query);
|
||||
const limit = q.limit ? Number(q.limit) : undefined;
|
||||
const runs = await store.listRuns({
|
||||
owner: q.owner,
|
||||
workflow: q.workflow,
|
||||
status: q.status,
|
||||
limit: Number.isFinite(limit) ? limit : undefined,
|
||||
before: q.before,
|
||||
});
|
||||
return reply.send({ runs });
|
||||
},
|
||||
);
|
||||
|
||||
server.get(
|
||||
"/admin/runs/:id",
|
||||
{ onRequest: [server.authenticate] },
|
||||
async (req, reply) => {
|
||||
const { id } = /** @type {{ id: string }} */ (req.params);
|
||||
const run = await store.getRun(id);
|
||||
if (!run) {
|
||||
return reply.code(404).send({ error: "run not found" });
|
||||
}
|
||||
return reply.send(run);
|
||||
},
|
||||
);
|
||||
|
||||
if (fs.existsSync(WEB_DIST)) {
|
||||
await server.register(fastifyStatic, {
|
||||
root: WEB_DIST,
|
||||
wildcard: false,
|
||||
});
|
||||
server.setNotFoundHandler((req, reply) => {
|
||||
const url = req.raw.url ?? "";
|
||||
if (
|
||||
url.startsWith("/api") ||
|
||||
url.startsWith("/u/") ||
|
||||
url.startsWith("/admin")
|
||||
) {
|
||||
return reply.code(404).send({ error: "not found" });
|
||||
}
|
||||
return reply.sendFile("index.html");
|
||||
});
|
||||
}
|
||||
|
||||
async function shutdown() {
|
||||
try {
|
||||
await flushLogs();
|
||||
@@ -336,13 +156,15 @@ async function shutdown() {
|
||||
process.on("SIGINT", shutdown);
|
||||
process.on("SIGTERM", shutdown);
|
||||
|
||||
const port = Number(process.env.PORT ?? 9000);
|
||||
|
||||
server
|
||||
.listen({
|
||||
host: "0.0.0.0",
|
||||
port: 9000,
|
||||
port,
|
||||
})
|
||||
.then(() => {
|
||||
log.info("Server is running on port 9000");
|
||||
log.info(`Server is running on port ${port}`);
|
||||
})
|
||||
.catch((err) => {
|
||||
log.error({ err }, "failed to start server");
|
||||
|
||||
@@ -1,8 +1,9 @@
|
||||
import fs from "fs";
|
||||
import path from "path";
|
||||
import vm from "node:vm";
|
||||
import { fileURLToPath } from "node:url";
|
||||
import { createRequire } from "node:module";
|
||||
import axios from "axios";
|
||||
import { SCRIPTS_DIR } from "./paths.js";
|
||||
|
||||
const hostRequire = createRequire(import.meta.url);
|
||||
|
||||
@@ -291,7 +292,7 @@ function createScriptSandbox({ log, script, workflowName }) {
|
||||
}
|
||||
|
||||
function loadCompiledScript(script) {
|
||||
const filePath = fileURLToPath(new URL(`./scripts/${script}`, import.meta.url));
|
||||
const filePath = path.join(SCRIPTS_DIR, script);
|
||||
const { mtimeMs } = fs.statSync(filePath);
|
||||
const cached = scriptCache.get(script);
|
||||
if (cached && cached.mtimeMs === mtimeMs) {
|
||||
|
||||
@@ -1,6 +1,10 @@
|
||||
import jsonata from "jsonata";
|
||||
|
||||
export default function jsonataFn(context) {
|
||||
const expression = jsonata(context.config.expression);
|
||||
return expression.evaluate(context.data)
|
||||
export default function jsonataFn(ctx) {
|
||||
log.info({ctx}, "jsonata: context")
|
||||
log.info("jsonata: evaluating expression %s", ctx.config.expression);
|
||||
const expression = jsonata(ctx.config.expression);
|
||||
const result = expression.evaluate(ctx.data);
|
||||
log.info({result}, "jsonata: expression result");
|
||||
return result;
|
||||
}
|
||||
@@ -1,12 +1,19 @@
|
||||
export default async function ntfy(ctx) {
|
||||
log.info({ ctx }, "ntfy");
|
||||
log.info({ ctx }, "ntfy incoming context");
|
||||
const headers = {}
|
||||
|
||||
if(ctx.data?.title) {
|
||||
log.info("ntfy: setting title %s", ctx.data.title);
|
||||
headers.Title = ctx.data.title
|
||||
}
|
||||
|
||||
await $axios.post(ctx.config?.url || "https://ntfy.sh/scrunner", ctx.data?.message || "Hello from scrunner", {
|
||||
const ntfyUrl = ctx.config?.url || "https://ntfy.sh/scrunner";
|
||||
|
||||
log.info("ntfy sending message to %s", ntfyUrl);
|
||||
const truncatedMessage = ctx.data?.message?.substring(0, 100);
|
||||
log.info("ntfy messsage: %s", truncatedMessage);
|
||||
|
||||
await $axios.post(ntfyUrl, ctx.data?.message || "Hello from scrunner", {
|
||||
headers: headers
|
||||
})
|
||||
return {sent: "true"}
|
||||
|
||||
@@ -0,0 +1,103 @@
|
||||
import bcrypt from "bcryptjs";
|
||||
import * as store from "../../store.js";
|
||||
|
||||
export const COOKIE = "scrunner_token";
|
||||
export const OPEN_API_ROUTES = new Set([
|
||||
"GET /auth/bootstrap",
|
||||
"POST /auth/register",
|
||||
"POST /auth/login",
|
||||
]);
|
||||
|
||||
export function cookieOpts() {
|
||||
return {
|
||||
httpOnly: true,
|
||||
path: "/",
|
||||
sameSite: "lax",
|
||||
secure: process.env.NODE_ENV === "production",
|
||||
maxAge: 7 * 24 * 60 * 60,
|
||||
};
|
||||
}
|
||||
|
||||
export function validateCredentials(username, password) {
|
||||
if (!/^[A-Za-z0-9_]{3,32}$/.test(username)) {
|
||||
return "username must be 3-32 letters, numbers, or underscore";
|
||||
}
|
||||
if (password.length < 8) {
|
||||
return "password must be at least 8 characters";
|
||||
}
|
||||
return null;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} fastify
|
||||
*/
|
||||
export default async function authPlugin(fastify) {
|
||||
fastify.get("/auth/bootstrap", async () => {
|
||||
const count = await store.countUsers();
|
||||
return { needsSetup: count === 0 };
|
||||
});
|
||||
|
||||
fastify.post("/auth/register", async (req, reply) => {
|
||||
const count = await store.countUsers();
|
||||
if (count > 0) {
|
||||
return reply.code(403).send({ error: "setup already complete" });
|
||||
}
|
||||
const body = /** @type {{ username?: string, password?: string }} */ (req.body ?? {});
|
||||
const username = String(body.username ?? "").trim();
|
||||
const password = String(body.password ?? "");
|
||||
const err = validateCredentials(username, password);
|
||||
if (err) return reply.code(400).send({ error: err });
|
||||
|
||||
const passwordHash = await bcrypt.hash(password, 10);
|
||||
const user = await store.createUser({
|
||||
username,
|
||||
passwordHash,
|
||||
role: "admin",
|
||||
});
|
||||
const token = await reply.jwtSign({
|
||||
id: user.id,
|
||||
username: user.username,
|
||||
role: user.role,
|
||||
});
|
||||
reply.setCookie(COOKIE, token, cookieOpts());
|
||||
return { user };
|
||||
});
|
||||
|
||||
fastify.post("/auth/login", async (req, reply) => {
|
||||
const body = /** @type {{ username?: string, password?: string }} */ (req.body ?? {});
|
||||
const username = String(body.username ?? "").trim();
|
||||
const password = String(body.password ?? "");
|
||||
const row = await store.getUserAuthByUsername(username);
|
||||
if (!row || !(await bcrypt.compare(password, row.password_hash))) {
|
||||
return reply.code(401).send({ error: "invalid credentials" });
|
||||
}
|
||||
const token = await reply.jwtSign({
|
||||
id: row.id,
|
||||
username: row.username,
|
||||
role: row.role,
|
||||
});
|
||||
reply.setCookie(COOKIE, token, cookieOpts());
|
||||
return {
|
||||
user: {
|
||||
id: row.id,
|
||||
username: row.username,
|
||||
role: row.role,
|
||||
created_at: row.created_at,
|
||||
updated_at: row.updated_at,
|
||||
},
|
||||
};
|
||||
});
|
||||
|
||||
fastify.post("/auth/logout", async (_req, reply) => {
|
||||
reply.clearCookie(COOKIE, { path: "/" });
|
||||
return { ok: true };
|
||||
});
|
||||
|
||||
fastify.get("/auth/me", async (req, reply) => {
|
||||
const user = await store.getUserById(req.user.id);
|
||||
if (!user) {
|
||||
return reply.code(401).send({ error: "unauthorized" });
|
||||
}
|
||||
return { user };
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,86 @@
|
||||
import yaml from "yaml";
|
||||
import * as store from "../../store.js";
|
||||
import * as fsStore from "../../fs-store.js";
|
||||
|
||||
/**
|
||||
* @param {{ workflows: Map<string, any>, loadErrors: Map<string, string> }} registry
|
||||
*/
|
||||
export default function dashboardPluginFactory(registry) {
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} fastify
|
||||
*/
|
||||
return async function dashboardPlugin(fastify) {
|
||||
fastify.get("/dashboard", async () => {
|
||||
const owners = fsStore.listOwners();
|
||||
let workflowCount = 0;
|
||||
let enabledCount = 0;
|
||||
let brokenCount = registry.loadErrors.size;
|
||||
const brokenWorkflows = [];
|
||||
|
||||
for (const [key, message] of registry.loadErrors) {
|
||||
const [owner, ...rest] = key.split("/");
|
||||
brokenWorkflows.push({
|
||||
key,
|
||||
owner,
|
||||
file: rest.join("/"),
|
||||
loadError: message,
|
||||
});
|
||||
}
|
||||
|
||||
for (const owner of owners) {
|
||||
let registered = [];
|
||||
try {
|
||||
registered = fsStore.readRegisters(owner);
|
||||
} catch {
|
||||
registered = [];
|
||||
}
|
||||
const files = [
|
||||
...new Set([...registered, ...fsStore.listOwnerYamlFiles(owner)]),
|
||||
];
|
||||
for (const file of files) {
|
||||
workflowCount += 1;
|
||||
const key = `${owner}/${file}`;
|
||||
const loaded = registry.workflows.get(key);
|
||||
if (loaded?.workflow && loaded.workflow.enabled !== false) {
|
||||
enabledCount += 1;
|
||||
} else if (!loaded && !registry.loadErrors.has(key)) {
|
||||
const raw = fsStore.readWorkflowYaml(owner, file);
|
||||
if (raw) {
|
||||
try {
|
||||
const parsed = yaml.parse(raw);
|
||||
if (parsed?.enabled !== false) enabledCount += 1;
|
||||
} catch (err) {
|
||||
brokenCount += 1;
|
||||
brokenWorkflows.push({
|
||||
key,
|
||||
owner,
|
||||
file,
|
||||
loadError: err instanceof Error ? err.message : String(err),
|
||||
});
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
const [running, failed, recent] = await Promise.all([
|
||||
store.listRuns({ status: "running", limit: 10 }),
|
||||
store.listRuns({ status: "failed", limit: 20 }),
|
||||
store.listRuns({ limit: 10 }),
|
||||
]);
|
||||
|
||||
return {
|
||||
workflowCount,
|
||||
scriptCount: fsStore.listScriptFiles().length,
|
||||
enabledCount,
|
||||
brokenCount,
|
||||
running,
|
||||
needsAttention: {
|
||||
failed,
|
||||
brokenWorkflows,
|
||||
},
|
||||
recent,
|
||||
};
|
||||
});
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,26 @@
|
||||
import * as store from "../../store.js";
|
||||
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} fastify
|
||||
*/
|
||||
export default async function runsPlugin(fastify) {
|
||||
fastify.get("/runs", async (req) => {
|
||||
const q = /** @type {Record<string, string | undefined>} */ (req.query ?? {});
|
||||
const limit = q.limit ? Number(q.limit) : undefined;
|
||||
const runs = await store.listRuns({
|
||||
owner: q.owner,
|
||||
workflow: q.workflow,
|
||||
status: q.status,
|
||||
limit: Number.isFinite(limit) ? limit : undefined,
|
||||
before: q.before,
|
||||
});
|
||||
return { runs };
|
||||
});
|
||||
|
||||
fastify.get("/runs/:id", async (req, reply) => {
|
||||
const { id } = /** @type {{ id: string }} */ (req.params);
|
||||
const run = await store.getRun(id);
|
||||
if (!run) return reply.code(404).send({ error: "run not found" });
|
||||
return run;
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,64 @@
|
||||
import { clearScriptCache } from "../../script-sandbox.js";
|
||||
import * as fsStore from "../../fs-store.js";
|
||||
|
||||
/**
|
||||
* @param {{ referencedScripts: () => Set<string> }} registry
|
||||
*/
|
||||
export default function scriptsPluginFactory(registry) {
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} fastify
|
||||
*/
|
||||
return async function scriptsPlugin(fastify) {
|
||||
fastify.get("/scripts", async () => {
|
||||
return { scripts: fsStore.listScriptFiles() };
|
||||
});
|
||||
|
||||
fastify.get("/scripts/:name", async (req, reply) => {
|
||||
const { name } = /** @type {{ name: string }} */ (req.params);
|
||||
try {
|
||||
fsStore.assertScriptName(name);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
const content = fsStore.readScript(name);
|
||||
if (content == null) return reply.code(404).send({ error: "script not found" });
|
||||
return { name, content };
|
||||
});
|
||||
|
||||
fastify.put("/scripts/:name", async (req, reply) => {
|
||||
const { name } = /** @type {{ name: string }} */ (req.params);
|
||||
try {
|
||||
fsStore.assertScriptName(name);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
const body = /** @type {{ content?: string }} */ (req.body ?? {});
|
||||
if (typeof body.content !== "string") {
|
||||
return reply.code(400).send({ error: "content is required" });
|
||||
}
|
||||
const existed = fsStore.readScript(name) != null;
|
||||
fsStore.writeScript(name, body.content);
|
||||
clearScriptCache();
|
||||
return reply.code(existed ? 200 : 201).send({ name });
|
||||
});
|
||||
|
||||
fastify.delete("/scripts/:name", async (req, reply) => {
|
||||
const { name } = /** @type {{ name: string }} */ (req.params);
|
||||
try {
|
||||
fsStore.assertScriptName(name);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
if (registry.referencedScripts().has(name)) {
|
||||
return reply
|
||||
.code(409)
|
||||
.send({ error: "script is referenced by a workflow" });
|
||||
}
|
||||
if (!fsStore.deleteScript(name)) {
|
||||
return reply.code(404).send({ error: "script not found" });
|
||||
}
|
||||
clearScriptCache();
|
||||
return { ok: true };
|
||||
});
|
||||
};
|
||||
}
|
||||
@@ -0,0 +1,85 @@
|
||||
import bcrypt from "bcryptjs";
|
||||
import * as store from "../../store.js";
|
||||
import { validateCredentials } from "./auth.js";
|
||||
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} fastify
|
||||
*/
|
||||
export default async function usersPlugin(fastify) {
|
||||
fastify.addHook("onRequest", fastify.requireAdmin);
|
||||
|
||||
fastify.get("/users", async () => {
|
||||
const users = await store.listUsers();
|
||||
return { users };
|
||||
});
|
||||
|
||||
fastify.post("/users", async (req, reply) => {
|
||||
const body = /** @type {{ username?: string, password?: string, role?: string }} */ (
|
||||
req.body ?? {}
|
||||
);
|
||||
const username = String(body.username ?? "").trim();
|
||||
const password = String(body.password ?? "");
|
||||
const role = body.role === "admin" ? "admin" : "operator";
|
||||
const err = validateCredentials(username, password);
|
||||
if (err) return reply.code(400).send({ error: err });
|
||||
|
||||
const existing = await store.getUserAuthByUsername(username);
|
||||
if (existing) {
|
||||
return reply.code(409).send({ error: "username taken" });
|
||||
}
|
||||
|
||||
const user = await store.createUser({
|
||||
username,
|
||||
passwordHash: await bcrypt.hash(password, 10),
|
||||
role,
|
||||
});
|
||||
return reply.code(201).send({ user });
|
||||
});
|
||||
|
||||
fastify.patch("/users/:id", async (req, reply) => {
|
||||
const { id } = /** @type {{ id: string }} */ (req.params);
|
||||
const existing = await store.getUserAuthById(id);
|
||||
if (!existing) return reply.code(404).send({ error: "user not found" });
|
||||
|
||||
const body = /** @type {{ password?: string, role?: string }} */ (req.body ?? {});
|
||||
/** @type {{ passwordHash?: string, role?: string }} */
|
||||
const patch = {};
|
||||
|
||||
if (body.role) {
|
||||
if (body.role !== "admin" && body.role !== "operator") {
|
||||
return reply.code(400).send({ error: "invalid role" });
|
||||
}
|
||||
if (existing.role === "admin" && body.role !== "admin") {
|
||||
const admins = await store.countAdmins();
|
||||
if (admins <= 1) {
|
||||
return reply.code(400).send({ error: "cannot demote last admin" });
|
||||
}
|
||||
}
|
||||
patch.role = body.role;
|
||||
}
|
||||
|
||||
if (body.password) {
|
||||
if (body.password.length < 8) {
|
||||
return reply.code(400).send({ error: "password must be at least 8 characters" });
|
||||
}
|
||||
patch.passwordHash = await bcrypt.hash(body.password, 10);
|
||||
}
|
||||
|
||||
const user = await store.updateUser(id, patch);
|
||||
return { user };
|
||||
});
|
||||
|
||||
fastify.delete("/users/:id", async (req, reply) => {
|
||||
const { id } = /** @type {{ id: string }} */ (req.params);
|
||||
const existing = await store.getUserAuthById(id);
|
||||
if (!existing) return reply.code(404).send({ error: "user not found" });
|
||||
if (existing.role === "admin") {
|
||||
const admins = await store.countAdmins();
|
||||
if (admins <= 1) {
|
||||
return reply.code(400).send({ error: "cannot delete last admin" });
|
||||
}
|
||||
}
|
||||
await store.deleteUser(id);
|
||||
return { ok: true };
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,240 @@
|
||||
import yaml from "yaml";
|
||||
import * as store from "../../store.js";
|
||||
import * as fsStore from "../../fs-store.js";
|
||||
import { namespacedPath, parseScriptStep } from "../../workflow-parse.js";
|
||||
|
||||
function triggerSummary(owner, workflow) {
|
||||
if (!workflow || typeof workflow !== "object") return [];
|
||||
return (workflow.triggers ?? []).map((t) => {
|
||||
const type = t?.type ?? "unknown";
|
||||
const isHttp = String(type).toLowerCase() === "http";
|
||||
return {
|
||||
type,
|
||||
method: isHttp ? String(t?.method ?? "POST").toUpperCase() : t?.method ?? null,
|
||||
path: isHttp && t?.path != null ? namespacedPath(owner, t.path) : t?.path ?? null,
|
||||
schedule: t?.schedule ?? null,
|
||||
};
|
||||
});
|
||||
}
|
||||
|
||||
function scriptNames(workflow) {
|
||||
if (!workflow || typeof workflow !== "object") return [];
|
||||
const names = [];
|
||||
for (const raw of workflow.scripts ?? []) {
|
||||
try {
|
||||
names.push(parseScriptStep(raw).script);
|
||||
} catch {
|
||||
names.push(null);
|
||||
}
|
||||
}
|
||||
return names;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {{ workflows: Map<string, any>, loadErrors: Map<string, string>, reregister: () => void }} registry
|
||||
*/
|
||||
export default function workflowsPluginFactory(registry) {
|
||||
/**
|
||||
* @param {import("fastify").FastifyInstance} fastify
|
||||
*/
|
||||
return async function workflowsPlugin(fastify) {
|
||||
fastify.get("/owners", async () => {
|
||||
return { owners: fsStore.listOwners() };
|
||||
});
|
||||
|
||||
fastify.get("/workflows", async (req) => {
|
||||
const q = /** @type {{ owner?: string }} */ (req.query ?? {});
|
||||
const stats = await store.workflowStats();
|
||||
const owners = q.owner
|
||||
? [fsStore.assertOwner(q.owner)]
|
||||
: fsStore.listOwners();
|
||||
|
||||
const items = [];
|
||||
for (const owner of owners) {
|
||||
let registered = [];
|
||||
try {
|
||||
registered = fsStore.readRegisters(owner);
|
||||
} catch {
|
||||
registered = [];
|
||||
}
|
||||
const onDisk = fsStore.listOwnerYamlFiles(owner);
|
||||
const files = [...new Set([...registered, ...onDisk])];
|
||||
|
||||
for (const file of files) {
|
||||
const key = `${owner}/${file}`;
|
||||
const loaded = registry.workflows.get(key);
|
||||
const loadError = registry.loadErrors.get(key) ?? null;
|
||||
let parsed = loaded?.workflow ?? null;
|
||||
if (!parsed) {
|
||||
const raw = fsStore.readWorkflowYaml(owner, file);
|
||||
if (raw != null) {
|
||||
try {
|
||||
parsed = yaml.parse(raw);
|
||||
} catch (err) {
|
||||
// keep loadError
|
||||
if (!loadError) {
|
||||
// file on disk but unparseable and not in registers
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
const st = stats[key] ?? {
|
||||
invocationCount: 0,
|
||||
lastInvokedAt: null,
|
||||
lastStatus: null,
|
||||
};
|
||||
items.push({
|
||||
owner,
|
||||
file,
|
||||
key,
|
||||
name: parsed?.name ?? file,
|
||||
description: parsed?.description ?? null,
|
||||
enabled: parsed ? parsed.enabled !== false : false,
|
||||
registered: registered.includes(file),
|
||||
loadError:
|
||||
loadError ??
|
||||
(parsed ? null : "unreadable"),
|
||||
lastInvokedAt: st.lastInvokedAt,
|
||||
lastStatus: st.lastStatus ?? null,
|
||||
invocationCount: st.invocationCount,
|
||||
triggers: triggerSummary(owner, parsed),
|
||||
scripts: scriptNames(parsed),
|
||||
});
|
||||
}
|
||||
}
|
||||
return { workflows: items };
|
||||
});
|
||||
|
||||
fastify.get("/workflows/:owner/:file", async (req, reply) => {
|
||||
const { owner, file } = /** @type {{ owner: string, file: string }} */ (
|
||||
req.params
|
||||
);
|
||||
try {
|
||||
fsStore.assertOwner(owner);
|
||||
fsStore.assertWorkflowFile(file);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
const content = fsStore.readWorkflowYaml(owner, file);
|
||||
if (content == null) {
|
||||
return reply.code(404).send({ error: "workflow not found" });
|
||||
}
|
||||
const key = `${owner}/${file}`;
|
||||
let parsed = null;
|
||||
let parseError = null;
|
||||
try {
|
||||
parsed = yaml.parse(content);
|
||||
} catch (err) {
|
||||
parseError = err instanceof Error ? err.message : String(err);
|
||||
}
|
||||
const stats = (await store.workflowStats())[key] ?? {
|
||||
invocationCount: 0,
|
||||
lastInvokedAt: null,
|
||||
lastStatus: null,
|
||||
};
|
||||
return {
|
||||
owner,
|
||||
file,
|
||||
key,
|
||||
content,
|
||||
parsed,
|
||||
parseError,
|
||||
loadError: registry.loadErrors.get(key) ?? parseError,
|
||||
lastInvokedAt: stats.lastInvokedAt,
|
||||
lastStatus: stats.lastStatus ?? null,
|
||||
invocationCount: stats.invocationCount,
|
||||
};
|
||||
});
|
||||
|
||||
fastify.put("/workflows/:owner/:file", async (req, reply) => {
|
||||
const { owner, file } = /** @type {{ owner: string, file: string }} */ (
|
||||
req.params
|
||||
);
|
||||
try {
|
||||
fsStore.assertOwner(owner);
|
||||
fsStore.assertWorkflowFile(file);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
const body = /** @type {{ content?: string }} */ (req.body ?? {});
|
||||
if (typeof body.content !== "string") {
|
||||
return reply.code(400).send({ error: "content is required" });
|
||||
}
|
||||
try {
|
||||
yaml.parse(body.content);
|
||||
} catch (err) {
|
||||
return reply.code(400).send({
|
||||
error: `invalid yaml: ${err instanceof Error ? err.message : String(err)}`,
|
||||
});
|
||||
}
|
||||
const existed = fsStore.readWorkflowYaml(owner, file) != null;
|
||||
fsStore.writeWorkflowYaml(owner, file, body.content);
|
||||
const registered = fsStore.readRegisters(owner);
|
||||
if (!registered.includes(file)) {
|
||||
registered.push(file);
|
||||
fsStore.writeRegisters(owner, registered);
|
||||
}
|
||||
registry.reregister();
|
||||
return reply.code(existed ? 200 : 201).send({ owner, file });
|
||||
});
|
||||
|
||||
fastify.delete("/workflows/:owner/:file", async (req, reply) => {
|
||||
const { owner, file } = /** @type {{ owner: string, file: string }} */ (
|
||||
req.params
|
||||
);
|
||||
try {
|
||||
fsStore.assertOwner(owner);
|
||||
fsStore.assertWorkflowFile(file);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
if (!fsStore.deleteWorkflowYaml(owner, file)) {
|
||||
return reply.code(404).send({ error: "workflow not found" });
|
||||
}
|
||||
const registered = fsStore.readRegisters(owner).filter((f) => f !== file);
|
||||
fsStore.writeRegisters(owner, registered);
|
||||
registry.reregister();
|
||||
return { ok: true };
|
||||
});
|
||||
|
||||
fastify.post("/workflows/:owner/:file/run", async (req, reply) => {
|
||||
const { owner, file } = /** @type {{ owner: string, file: string }} */ (
|
||||
req.params
|
||||
);
|
||||
try {
|
||||
fsStore.assertOwner(owner);
|
||||
fsStore.assertWorkflowFile(file);
|
||||
} catch (err) {
|
||||
return reply.code(err.statusCode ?? 400).send({ error: err.message });
|
||||
}
|
||||
const key = `${owner}/${file}`;
|
||||
if (!registry.workflows.has(key)) {
|
||||
return reply.code(404).send({
|
||||
error: registry.loadErrors.get(key) ?? "workflow not loaded",
|
||||
});
|
||||
}
|
||||
const body = /** @type {{ data?: unknown }} */ (req.body ?? {});
|
||||
const result = await registry.runWorkflow(
|
||||
key,
|
||||
{ data: body.data ?? null },
|
||||
{ type: "manual", detail: "ui" },
|
||||
);
|
||||
if (result.status === "failed") {
|
||||
return reply.code(result.runId ? 500 : 404).send({
|
||||
runId: result.runId,
|
||||
error: result.error,
|
||||
});
|
||||
}
|
||||
return {
|
||||
runId: result.runId,
|
||||
status: result.status,
|
||||
result: result.result,
|
||||
};
|
||||
});
|
||||
|
||||
fastify.post("/workflows/reregister", async () => {
|
||||
registry.reregister();
|
||||
return { message: "Workflows refreshed" };
|
||||
});
|
||||
};
|
||||
}
|
||||
@@ -235,3 +235,102 @@ export async function pruneOlderThan(days) {
|
||||
const cutoff = new Date(Date.now() - days * 24 * 60 * 60 * 1000).toISOString();
|
||||
return db("workflow_runs").where("started_at", "<", cutoff).del();
|
||||
}
|
||||
|
||||
/**
|
||||
* @returns {Promise<Record<string, { invocationCount: number, lastInvokedAt: string | null, lastStatus: string | null }>>}
|
||||
*/
|
||||
export async function workflowStats() {
|
||||
const rows = await db("workflow_runs")
|
||||
.select("workflow", "status", "started_at")
|
||||
.orderBy("started_at", "desc");
|
||||
|
||||
/** @type {Record<string, { invocationCount: number, lastInvokedAt: string | null, lastStatus: string | null }>} */
|
||||
const out = {};
|
||||
for (const row of rows) {
|
||||
const existing = out[row.workflow];
|
||||
if (!existing) {
|
||||
out[row.workflow] = {
|
||||
invocationCount: 1,
|
||||
lastInvokedAt: row.started_at ?? null,
|
||||
lastStatus: row.status ?? null,
|
||||
};
|
||||
} else {
|
||||
existing.invocationCount += 1;
|
||||
}
|
||||
}
|
||||
return out;
|
||||
}
|
||||
|
||||
export async function countUsers() {
|
||||
const row = await db("users").count({ n: "*" }).first();
|
||||
return Number(row?.n ?? 0);
|
||||
}
|
||||
|
||||
export async function countAdmins() {
|
||||
const row = await db("users").where({ role: "admin" }).count({ n: "*" }).first();
|
||||
return Number(row?.n ?? 0);
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {{ username: string, passwordHash: string, role: string }} opts
|
||||
*/
|
||||
export async function createUser({ username, passwordHash, role }) {
|
||||
const id = randomUUID();
|
||||
const now = nowIso();
|
||||
await db("users").insert({
|
||||
id,
|
||||
username,
|
||||
password_hash: passwordHash,
|
||||
role,
|
||||
created_at: now,
|
||||
updated_at: now,
|
||||
});
|
||||
return getUserById(id);
|
||||
}
|
||||
|
||||
export async function getUserById(id) {
|
||||
const row = await db("users").where({ id }).first();
|
||||
return row ? publicUser(row) : null;
|
||||
}
|
||||
|
||||
export async function getUserAuthByUsername(username) {
|
||||
return db("users").where({ username }).first();
|
||||
}
|
||||
|
||||
export async function getUserAuthById(id) {
|
||||
return db("users").where({ id }).first();
|
||||
}
|
||||
|
||||
export async function listUsers() {
|
||||
const rows = await db("users")
|
||||
.select("id", "username", "role", "created_at", "updated_at")
|
||||
.orderBy("username", "asc");
|
||||
return rows;
|
||||
}
|
||||
|
||||
/**
|
||||
* @param {string} id
|
||||
* @param {{ passwordHash?: string, role?: string }} patch
|
||||
*/
|
||||
export async function updateUser(id, patch) {
|
||||
const update = { updated_at: nowIso() };
|
||||
if (patch.passwordHash) update.password_hash = patch.passwordHash;
|
||||
if (patch.role) update.role = patch.role;
|
||||
await db("users").where({ id }).update(update);
|
||||
return getUserById(id);
|
||||
}
|
||||
|
||||
export async function deleteUser(id) {
|
||||
return db("users").where({ id }).del();
|
||||
}
|
||||
|
||||
function publicUser(row) {
|
||||
return {
|
||||
id: row.id,
|
||||
username: row.username,
|
||||
role: row.role,
|
||||
created_at: row.created_at,
|
||||
updated_at: row.updated_at,
|
||||
};
|
||||
}
|
||||
|
||||
|
||||
@@ -0,0 +1,15 @@
|
||||
export function parseScriptStep(step) {
|
||||
if (typeof step === "string") return { script: step, config: null };
|
||||
if (step?.script) return { script: step.script, config: step.config ?? null };
|
||||
throw new Error(`Invalid script step: ${JSON.stringify(step)}`);
|
||||
}
|
||||
|
||||
/**
|
||||
* Resolve an HTTP path under the owner namespace: /notify -> /u/alice/notify
|
||||
* @param {string} owner
|
||||
* @param {string} triggerPath
|
||||
*/
|
||||
export function namespacedPath(owner, triggerPath) {
|
||||
const cleaned = String(triggerPath).replace(/^\/+/, "");
|
||||
return `/u/${owner}/${cleaned}`;
|
||||
}
|
||||
@@ -6,4 +6,5 @@ triggers:
|
||||
- type: HTTP
|
||||
method: POST
|
||||
path: /mt
|
||||
- type: manual
|
||||
|
||||
|
||||
@@ -1,4 +1,4 @@
|
||||
name: manual trigger
|
||||
name: jsonata
|
||||
scripts:
|
||||
- get-current-time.js
|
||||
- script: jsonata.js
|
||||
|
||||
Reference in New Issue
Block a user