feat(server): add revealHttpAuthLiterals API and enhance web interface for credential management

- Implemented revealHttpAuthLiterals function to return plaintext credential fields from HTTP auth configurations.
- Added a new endpoint in the HTTP auths API to reveal credentials securely.
- Updated the web interface to fetch and display plaintext literals, improving user experience for managing credentials.
- Enhanced CredentialFields component to support revealing and masking credential values dynamically.
This commit is contained in:
2026-08-15 06:43:16 +07:00
parent d666dc001d
commit 5bfbafeb91
4 changed files with 270 additions and 49 deletions
+18
View File
@@ -233,6 +233,24 @@ export async function getHttpAuthInternal(name) {
};
}
/**
* Return only plaintext literal credential fields (not KV refs or encrypted secrets).
* @param {string} name
* @returns {Promise<{ name: string, type: string, literals: Record<string, string> } | null>}
*/
export async function revealHttpAuthLiterals(name) {
const internal = await getHttpAuthInternal(name);
if (!internal) return null;
/** @type {Record<string, string>} */
const literals = {};
const cfg = internal.config ?? {};
for (const key of ["token", "user", "password", "value"]) {
const v = cfg[key];
if (typeof v === "string") literals[key] = v;
}
return { name: internal.name, type: internal.type, literals };
}
export async function listHttpAuths() {
const rows = await db("http_auths").select("*").orderBy("name", "asc");
return rows.map((r) => publicAuth(r));
+15
View File
@@ -6,6 +6,7 @@ import {
getHttpAuthByName,
upsertHttpAuth,
deleteHttpAuth,
revealHttpAuthLiterals,
} from "../../http-auths-store.js";
import { getHttpPageByName } from "../../http-pages-store.js";
@@ -17,6 +18,20 @@ export default async function httpAuthsPlugin(fastify) {
return { auths: await listHttpAuths() };
});
fastify.get("/http-auths/:name/reveal", async (req, reply) => {
const { name } = /** @type {{ name: string }} */ (req.params);
try {
assertAuthName(name);
} catch (err) {
return reply.code(err.statusCode ?? 400).send({ error: err.message });
}
const revealed = await revealHttpAuthLiterals(name);
if (!revealed) {
return reply.code(404).send({ error: "auth not found" });
}
return revealed;
});
fastify.get("/http-auths/:name", async (req, reply) => {
const { name } = /** @type {{ name: string }} */ (req.params);
try {