feat(http-auth): resolve profiles by UUID and allow multi-auth triggers

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
2026-08-20 22:31:02 +07:00
co-authored by Cursor
parent 69106ab805
commit f68376587e
12 changed files with 1056 additions and 524 deletions
+65 -23
View File
@@ -4,12 +4,27 @@ import { assertHttpStatus } from "./http-pages-store.js";
const MAX_NAME_LENGTH = 128;
const NAME_RE = /^[A-Za-z0-9._-]+$/;
const UUID_RE =
/^[0-9a-f]{8}-[0-9a-f]{4}-[1-8][0-9a-f]{3}-[89ab][0-9a-f]{3}-[0-9a-f]{12}$/i;
const ALLOWED_TYPES = new Set(["bearer", "basic", "header"]);
function nowIso() {
return new Date().toISOString();
}
/**
* @param {unknown} id
* @returns {string}
*/
export function assertAuthId(id) {
if (typeof id !== "string" || !UUID_RE.test(id)) {
const err = new Error("invalid auth id");
err.statusCode = 400;
throw err;
}
return id.toLowerCase();
}
/**
* @param {unknown} name
* @returns {string}
@@ -218,10 +233,11 @@ function publicAuth(row, { includeConfig = true } = {}) {
/**
* Internal: full config including literals (for runtime auth checks).
* @param {string} name
* @param {string} id
*/
export async function getHttpAuthInternal(name) {
const row = await db("http_auths").where({ name: assertAuthName(name) }).first();
export async function getHttpAuthInternal(id) {
const authId = assertAuthId(id);
const row = await db("http_auths").where({ id: authId }).first();
if (!row) return null;
return {
id: row.id,
@@ -235,11 +251,11 @@ export async function getHttpAuthInternal(name) {
/**
* Return only plaintext literal credential fields (not KV refs or encrypted secrets).
* @param {string} name
* @returns {Promise<{ name: string, type: string, literals: Record<string, string> } | null>}
* @param {string} id
* @returns {Promise<{ id: string, name: string, type: string, literals: Record<string, string> } | null>}
*/
export async function revealHttpAuthLiterals(name) {
const internal = await getHttpAuthInternal(name);
export async function revealHttpAuthLiterals(id) {
const internal = await getHttpAuthInternal(id);
if (!internal) return null;
/** @type {Record<string, string>} */
const literals = {};
@@ -248,7 +264,12 @@ export async function revealHttpAuthLiterals(name) {
const v = cfg[key];
if (typeof v === "string") literals[key] = v;
}
return { name: internal.name, type: internal.type, literals };
return {
id: internal.id,
name: internal.name,
type: internal.type,
literals,
};
}
export async function listHttpAuths() {
@@ -256,24 +277,23 @@ export async function listHttpAuths() {
return rows.map((r) => publicAuth(r));
}
/**
* @param {string} name
*/
export async function getHttpAuthByName(name) {
const row = await db("http_auths").where({ name: assertAuthName(name) }).first();
return row ? publicAuth(row) : null;
}
/**
* @param {string} id
*/
export async function getHttpAuthById(id) {
const row = await db("http_auths").where({ id }).first();
let authId;
try {
authId = assertAuthId(id);
} catch {
return null;
}
const row = await db("http_auths").where({ id: authId }).first();
return row ? publicAuth(row) : null;
}
/**
* @param {{
* id?: string | null,
* name: string,
* type: string,
* config?: unknown,
@@ -282,6 +302,7 @@ export async function getHttpAuthById(id) {
* }} opts
*/
export async function upsertHttpAuth({
id,
name,
type,
config,
@@ -290,7 +311,26 @@ export async function upsertHttpAuth({
}) {
const authName = assertAuthName(name);
const authType = assertAuthType(type);
const existing = await db("http_auths").where({ name: authName }).first();
/** @type {Record<string, unknown> | null} */
let existing = null;
if (id != null && String(id).length > 0) {
const authId = assertAuthId(id);
existing = await db("http_auths").where({ id: authId }).first();
if (!existing) {
const err = new Error("auth not found");
err.statusCode = 404;
throw err;
}
}
const nameClash = await db("http_auths").where({ name: authName }).first();
if (nameClash && (!existing || nameClash.id !== existing.id)) {
const err = new Error(`auth name "${authName}" already exists`);
err.statusCode = 409;
throw err;
}
const prevConfig = existing ? parseConfig(existing.config) : {};
const normalized = normalizeAuthConfig(authType, config, {
keepLiteralsFrom: prevConfig,
@@ -315,18 +355,19 @@ export async function upsertHttpAuth({
await db("http_auths")
.where({ id: existing.id })
.update({
name: authName,
type: authType,
config: configJson,
unauthorized_status: unauthStatus,
unauthorized_response: unauthResponse,
updated_at: now,
});
return getHttpAuthById(existing.id);
return getHttpAuthById(/** @type {string} */ (existing.id));
}
const id = randomUUID();
const newId = randomUUID();
await db("http_auths").insert({
id,
id: newId,
name: authName,
type: authType,
config: configJson,
@@ -335,7 +376,7 @@ export async function upsertHttpAuth({
created_at: now,
updated_at: now,
});
return getHttpAuthById(id);
return getHttpAuthById(newId);
}
/**
@@ -343,6 +384,7 @@ export async function upsertHttpAuth({
* @returns {Promise<boolean>}
*/
export async function deleteHttpAuth(id) {
const n = await db("http_auths").where({ id }).del();
const authId = assertAuthId(id);
const n = await db("http_auths").where({ id: authId }).del();
return n > 0;
}
+86 -30
View File
@@ -77,38 +77,47 @@ export async function resolveCredentialValue(field, ctx) {
}
/**
* Normalize trigger.auth into an inline auth mechanism object.
* @param {unknown} authField
* @returns {Promise<{
* @typedef {{
* type: string,
* config: Record<string, unknown>,
* unauthorized_status?: number | null,
* unauthorized_response?: string | null,
* label: string,
* } | null>}
* }} AuthMechanism
*/
export async function resolveAuthMechanism(authField) {
if (authField == null || authField === false) return null;
if (typeof authField === "string") {
const named = await getHttpAuthInternal(authField);
if (!named) {
log.warn({ name: authField }, "http auth: named profile not found");
/**
* Resolve one auth entry (auth profile id UUID, or inline object).
* @param {unknown} entry
* @returns {Promise<AuthMechanism | null>}
*/
export async function resolveAuthMechanism(entry) {
if (entry == null || entry === false) return null;
if (typeof entry === "string") {
try {
const named = await getHttpAuthInternal(entry);
if (!named) {
log.warn({ id: entry }, "http auth: profile id not found");
return null;
}
return {
type: named.type,
config: named.config,
unauthorized_status: named.unauthorized_status,
unauthorized_response: named.unauthorized_response,
label: named.name,
};
} catch (err) {
log.warn({ err, id: entry }, "http auth: invalid profile id");
return null;
}
return {
type: named.type,
config: named.config,
unauthorized_status: named.unauthorized_status,
unauthorized_response: named.unauthorized_response,
label: authField,
};
}
if (typeof authField === "object" && !Array.isArray(authField)) {
const obj = /** @type {Record<string, unknown>} */ (authField);
if (typeof obj.name === "string" && obj.name.length > 0 && !obj.type) {
return resolveAuthMechanism(obj.name);
if (typeof entry === "object" && !Array.isArray(entry)) {
const obj = /** @type {Record<string, unknown>} */ (entry);
if (typeof obj.id === "string" && obj.id.length > 0 && !obj.type) {
return resolveAuthMechanism(obj.id);
}
try {
const type = assertAuthType(obj.type);
@@ -116,6 +125,7 @@ export async function resolveAuthMechanism(authField) {
const config = { ...obj };
delete config.type;
delete config.name;
delete config.id;
return {
type,
config,
@@ -133,18 +143,64 @@ export async function resolveAuthMechanism(authField) {
}
/**
* Label for mermaid / summary (sync, no DB).
* Normalize trigger.auth (array of auth ids / inline objects) into mechanisms.
* Empty / null / false → no auth. Any entry that fails to resolve is skipped;
* if the field was non-empty but nothing resolves, returns [] (caller treats as unauthorized).
* @param {unknown} authField
* @returns {Promise<AuthMechanism[]>}
*/
export function authLabel(authField) {
if (authField == null) return null;
if (typeof authField === "string") return authField;
if (typeof authField === "object" && !Array.isArray(authField)) {
const o = /** @type {Record<string, unknown>} */ (authField);
if (typeof o.name === "string" && o.name) return o.name;
if (typeof o.type === "string" && o.type) return o.type;
export async function resolveAuthMechanisms(authField) {
if (authField == null || authField === false) return [];
if (!Array.isArray(authField) || authField.length === 0) return [];
/** @type {AuthMechanism[]} */
const out = [];
for (const entry of authField) {
const mech = await resolveAuthMechanism(entry);
if (mech) out.push(mech);
}
return "auth";
return out;
}
/**
* True if any mechanism accepts the request (OR).
* @param {import("fastify").FastifyRequest} req
* @param {AuthMechanism[]} mechanisms
* @param {{ owner: string, workflowKey: string }} ctx
*/
export async function checkAnyHttpAuth(req, mechanisms, ctx) {
for (const mechanism of mechanisms) {
if (await checkHttpAuth(req, mechanism, ctx)) return true;
}
return false;
}
/**
* Label for mermaid / summary (sync). Prefer resolved display names when provided.
* @param {unknown} authField
* @param {Map<string, string> | Record<string, string>} [nameById]
*/
export function authLabel(authField, nameById) {
if (authField == null || authField === false) return null;
if (!Array.isArray(authField) || authField.length === 0) return null;
const lookup =
nameById instanceof Map
? (id) => nameById.get(id)
: nameById
? (id) => nameById[id]
: () => undefined;
const parts = authField.map((entry) => {
if (typeof entry === "string") return lookup(entry) ?? entry;
if (entry && typeof entry === "object" && !Array.isArray(entry)) {
const o = /** @type {Record<string, unknown>} */ (entry);
if (typeof o.id === "string" && o.id && !o.type) {
return lookup(o.id) ?? o.id;
}
if (typeof o.type === "string" && o.type) return o.type;
}
return "auth";
});
return parts.join("|");
}
/**
+19 -9
View File
@@ -1,9 +1,9 @@
import {
assertAuthId,
assertAuthName,
assertAuthType,
listHttpAuths,
getHttpAuthById,
getHttpAuthByName,
upsertHttpAuth,
deleteHttpAuth,
revealHttpAuthLiterals,
@@ -18,28 +18,28 @@ export default async function httpAuthsPlugin(fastify) {
return { auths: await listHttpAuths() };
});
fastify.get("/http-auths/:name/reveal", async (req, reply) => {
const { name } = /** @type {{ name: string }} */ (req.params);
fastify.get("/http-auths/:id/reveal", async (req, reply) => {
const { id } = /** @type {{ id: string }} */ (req.params);
try {
assertAuthName(name);
assertAuthId(id);
} catch (err) {
return reply.code(err.statusCode ?? 400).send({ error: err.message });
}
const revealed = await revealHttpAuthLiterals(name);
const revealed = await revealHttpAuthLiterals(id);
if (!revealed) {
return reply.code(404).send({ error: "auth not found" });
}
return revealed;
});
fastify.get("/http-auths/:name", async (req, reply) => {
const { name } = /** @type {{ name: string }} */ (req.params);
fastify.get("/http-auths/:id", async (req, reply) => {
const { id } = /** @type {{ id: string }} */ (req.params);
try {
assertAuthName(name);
assertAuthId(id);
} catch (err) {
return reply.code(err.statusCode ?? 400).send({ error: err.message });
}
const auth = await getHttpAuthByName(name);
const auth = await getHttpAuthById(id);
if (!auth) {
return reply.code(404).send({ error: "auth not found" });
}
@@ -48,6 +48,7 @@ export default async function httpAuthsPlugin(fastify) {
fastify.put("/http-auths", async (req, reply) => {
const body = /** @type {{
id?: string | null,
name?: string,
type?: string,
config?: unknown,
@@ -57,6 +58,9 @@ export default async function httpAuthsPlugin(fastify) {
try {
assertAuthName(String(body.name ?? ""));
assertAuthType(body.type);
if (body.id != null && String(body.id).length > 0) {
assertAuthId(String(body.id));
}
if (
body.unauthorized_response != null &&
String(body.unauthorized_response).length > 0
@@ -69,6 +73,7 @@ export default async function httpAuthsPlugin(fastify) {
);
}
const auth = await upsertHttpAuth({
id: body.id != null && String(body.id).length > 0 ? String(body.id) : null,
name: String(body.name),
type: String(body.type),
config: body.config,
@@ -83,6 +88,11 @@ export default async function httpAuthsPlugin(fastify) {
fastify.delete("/http-auths/:id", async (req, reply) => {
const { id } = /** @type {{ id: string }} */ (req.params);
try {
assertAuthId(id);
} catch (err) {
return reply.code(err.statusCode ?? 400).send({ error: err.message });
}
const existing = await getHttpAuthById(id);
if (!existing) {
return reply.code(404).send({ error: "auth not found" });
@@ -12,9 +12,12 @@ import {
getHttpAuthInternal,
} from "../http-auths-store.js";
import {
authLabel,
checkAnyHttpAuth,
checkHttpAuth,
coerceCredentialString,
resolveAuthMechanism,
resolveAuthMechanisms,
resolveCredentialValue,
resolveUnauthorizedSpec,
sendHttpPageOrJson,
@@ -176,11 +179,11 @@ const secret = await upsertSecret({
config: { token: { secret: "does_not_exist_xyz" } },
},
ctx,
);
);
assert(!missingSec, "missing secret fails closed");
}
// --- named profile ---
// --- named profile (by id) ---
const profile = await upsertHttpAuth({
name: "webhook-smoke",
type: "bearer",
@@ -188,9 +191,10 @@ const profile = await upsertHttpAuth({
unauthorized_status: 403,
unauthorized_response: "deny-smoke",
});
assert(typeof profile.id === "string" && profile.id.length > 0, "profile has id");
{
const mech = await resolveAuthMechanism("webhook-smoke");
assert(mech?.label === "webhook-smoke", "named profile");
const mech = await resolveAuthMechanism(profile.id);
assert(mech?.label === "webhook-smoke", "profile by id");
const ok = await checkHttpAuth(
mockReq({ authorization: "Bearer named-token" }),
mech,
@@ -202,9 +206,68 @@ const profile = await upsertHttpAuth({
assert(pageName === "deny-smoke", "profile unauth page");
}
// --- rename keeps id ---
{
const renamed = await upsertHttpAuth({
id: profile.id,
name: "webhook-renamed",
type: "bearer",
config: { token: { keep: true } },
unauthorized_status: 403,
unauthorized_response: "deny-smoke",
});
assert(renamed.id === profile.id, "rename keeps id");
assert(renamed.name === "webhook-renamed", "rename updates name");
const mech = await resolveAuthMechanism(profile.id);
assert(mech?.label === "webhook-renamed", "resolve uses new name label");
const ok = await checkHttpAuth(
mockReq({ authorization: "Bearer named-token" }),
mech,
ctx,
);
assert(ok, "credentials survive rename");
}
// --- multi-auth OR ---
const basicProfile = await upsertHttpAuth({
name: "basic-smoke",
type: "basic",
config: { user: "bob", password: "p@ss" },
});
{
const mechs = await resolveAuthMechanisms([profile.id, basicProfile.id]);
assert(mechs.length === 2, "resolve two mechanisms");
assert(
authLabel([profile.id, basicProfile.id], {
[profile.id]: "webhook-renamed",
[basicProfile.id]: "basic-smoke",
}) === "webhook-renamed|basic-smoke",
"authLabel",
);
const viaBearer = await checkAnyHttpAuth(
mockReq({ authorization: "Bearer named-token" }),
mechs,
ctx,
);
assert(viaBearer, "OR accepts bearer");
const encoded = Buffer.from("bob:p@ss").toString("base64");
const viaBasic = await checkAnyHttpAuth(
mockReq({ authorization: `Basic ${encoded}` }),
mechs,
ctx,
);
assert(viaBasic, "OR accepts basic");
const neither = await checkAnyHttpAuth(
mockReq({ authorization: "Bearer wrong" }),
mechs,
ctx,
);
assert(!neither, "OR rejects when none match");
}
// trigger-level override
{
const mech = await getHttpAuthInternal("webhook-smoke");
const mech = await getHttpAuthInternal(profile.id);
const { status, pageName } = resolveUnauthorizedSpec(
{ unauthorized: { status: 401, response: "deny-smoke" } },
mech,
@@ -226,7 +289,7 @@ await validateWorkflowHttpTriggers({
type: "HTTP",
method: "POST",
path: "/x",
auth: "webhook-smoke",
auth: [profile.id, basicProfile.id],
response: "deny-smoke",
},
],
@@ -235,12 +298,38 @@ await validateWorkflowHttpTriggers({
let threw = false;
try {
await validateWorkflowHttpTriggers({
triggers: [{ type: "HTTP", path: "/x", auth: "no-such-profile" }],
triggers: [{ type: "HTTP", path: "/x", auth: profile.id }],
});
} catch {
threw = true;
}
assert(threw, "unknown auth fails validation");
assert(threw, "non-array auth fails validation");
threw = false;
try {
await validateWorkflowHttpTriggers({
triggers: [{ type: "HTTP", path: "/x", auth: ["webhook-renamed"] }],
});
} catch {
threw = true;
}
assert(threw, "name string fails validation");
threw = false;
try {
await validateWorkflowHttpTriggers({
triggers: [
{
type: "HTTP",
path: "/x",
auth: ["00000000-0000-4000-8000-000000000000"],
},
],
});
} catch {
threw = true;
}
assert(threw, "unknown auth id fails validation");
threw = false;
try {
@@ -280,6 +369,7 @@ assert(threw, "unknown page fails validation");
// cleanup
await deleteHttpAuth(profile.id);
await deleteHttpAuth(basicProfile.id);
await deleteHttpPage(page.id);
await deleteSecret(secret.id);
const leftover = (await listSecrets({ owner })).find(
+51 -18
View File
@@ -1,7 +1,11 @@
/**
* Validate HTTP trigger auth / response fields on workflow save.
*/
import { assertAuthType, getHttpAuthByName } from "./http-auths-store.js";
import {
assertAuthId,
assertAuthType,
getHttpAuthById,
} from "./http-auths-store.js";
import { getHttpPageByName, assertHttpResponsePage } from "./http-pages-store.js";
import { authLabel } from "./http-trigger-auth.js";
@@ -24,51 +28,80 @@ function assertCredentialFieldShape(field, label) {
}
/**
* @param {unknown} auth
* @param {unknown} entry
* @param {string} path
*/
async function validateAuthField(auth) {
if (auth == null || auth === false) return;
if (typeof auth === "string") {
const named = await getHttpAuthByName(auth);
async function validateAuthEntry(entry, path) {
if (typeof entry === "string") {
try {
assertAuthId(entry);
} catch {
const err = new Error(`${path} must be an auth profile UUID`);
err.statusCode = 400;
throw err;
}
const named = await getHttpAuthById(entry);
if (!named) {
const err = new Error(`unknown auth profile "${auth}"`);
const err = new Error(`unknown auth profile id "${entry}"`);
err.statusCode = 400;
throw err;
}
return;
}
if (typeof auth === "object" && !Array.isArray(auth)) {
const obj = /** @type {Record<string, unknown>} */ (auth);
if (typeof obj.name === "string" && obj.name.length > 0 && !obj.type) {
await validateAuthField(obj.name);
if (entry && typeof entry === "object" && !Array.isArray(entry)) {
const obj = /** @type {Record<string, unknown>} */ (entry);
if (typeof obj.id === "string" && obj.id.length > 0 && !obj.type) {
await validateAuthEntry(obj.id, path);
return;
}
const type = assertAuthType(obj.type);
if (type === "bearer") {
assertCredentialFieldShape(obj.token, "auth.token");
assertCredentialFieldShape(obj.token, `${path}.token`);
} else if (type === "basic") {
assertCredentialFieldShape(obj.user, "auth.user");
assertCredentialFieldShape(obj.user, `${path}.user`);
if (obj.password != null && obj.password !== "") {
assertCredentialFieldShape(obj.password, "auth.password");
assertCredentialFieldShape(obj.password, `${path}.password`);
}
} else if (type === "header") {
if (typeof obj.header !== "string" || obj.header.length === 0) {
const err = new Error("auth.header must be a non-empty string");
const err = new Error(`${path}.header must be a non-empty string`);
err.statusCode = 400;
throw err;
}
assertCredentialFieldShape(obj.value, "auth.value");
assertCredentialFieldShape(obj.value, `${path}.value`);
}
return;
}
const err = new Error("auth must be a profile name or an auth object");
const err = new Error(
`${path} must be an auth profile UUID or an inline auth object`,
);
err.statusCode = 400;
throw err;
}
/**
* auth is an array of auth profile UUIDs and/or inline auth objects (OR).
* null / false / [] = no auth.
* @param {unknown} auth
*/
async function validateAuthField(auth) {
if (auth == null || auth === false) return;
if (!Array.isArray(auth)) {
const err = new Error(
"auth must be an array of auth profile UUIDs and/or inline auth objects",
);
err.statusCode = 400;
throw err;
}
for (let i = 0; i < auth.length; i++) {
await validateAuthEntry(auth[i], `auth[${i}]`);
}
}
/**
* @param {unknown} pageName
* @param {string} label
@@ -13,4 +13,5 @@ triggers:
- type: HTTP
method: POST
path: /dev-zte-sms
auth: basic-auth
auth:
- 0f78d6d7-bd44-45d7-a826-f51c027b767f
@@ -36,4 +36,5 @@ triggers:
- type: HTTP
method: POST
path: /send-gmail
auth: basic-auth
auth:
- 0f78d6d7-bd44-45d7-a826-f51c027b767f
@@ -1,6 +1,7 @@
name: time to ntfy example
description: |
this workflow will send a message to ntfy with the current time
enabled: false
scripts:
- script: plugin/get-current-time
config:
@@ -12,3 +13,5 @@ triggers:
- type: HTTP
method: POST
path: /time-to-ntfy
auth:
- 0f78d6d7-bd44-45d7-a826-f51c027b767f
@@ -0,0 +1,422 @@
import { useEffect, useState } from "react";
import { LuEye, LuEyeOff } from "react-icons/lu";
import { errorMessage } from "../api/client.js";
import {
fetchHttpAuthLiterals,
useHttpPages,
useUpsertHttpAuth,
} from "../api/hooks.js";
function emptyCred(source = "literal") {
return { source, value: "", kv: "", namespace: "", secret: "" };
}
function credFromPublic(field, literalValue) {
if (!field || field.source === "missing") return emptyCred("literal");
if (field.source === "kv") {
return {
source: "kv",
value: "",
kv: field.kv ?? "",
namespace: field.namespace ?? "",
secret: "",
};
}
if (field.source === "secret") {
return {
source: "secret",
value: "",
kv: "",
namespace: "",
secret: field.secret ?? "",
};
}
if (typeof literalValue === "string") {
return {
source: "literal",
value: literalValue,
kv: "",
namespace: "",
secret: "",
keep: true,
};
}
return {
source: "literal",
value: "",
kv: "",
namespace: "",
secret: "",
keep: field.set === true,
};
}
function toApiField(cred, { required = true } = {}) {
if (cred.source === "kv") {
const out = { kv: cred.kv };
if (cred.namespace) out.namespace = cred.namespace;
return out;
}
if (cred.source === "secret") {
return { secret: cred.secret };
}
if (cred.value) return cred.value;
if (cred.keep) return { keep: true };
if (!required) return "";
return null;
}
function emptyForm() {
return {
id: null,
name: "",
type: "bearer",
token: emptyCred(),
user: emptyCred(),
password: emptyCred(),
header: "",
value: emptyCred(),
unauthorized_status: "",
unauthorized_response: "",
};
}
function formFromAuth(auth, literals = {}) {
const cfg = auth.config ?? {};
return {
id: auth.id,
name: auth.name,
type: auth.type,
token: credFromPublic(cfg.token, literals.token),
user: credFromPublic(cfg.user, literals.user),
password: credFromPublic(cfg.password, literals.password),
header: cfg.header ?? "",
value: credFromPublic(cfg.value, literals.value),
unauthorized_status: auth.unauthorized_status ?? "",
unauthorized_response: auth.unauthorized_response ?? "",
};
}
function Field({ label, children, hint }) {
return (
<div className="form-control w-full">
<div className="label py-1">
<span className="label-text text-sm font-medium">{label}</span>
</div>
{children}
{hint ? (
<div className="label py-1">
<span className="label-text-alt opacity-60">{hint}</span>
</div>
) : null}
</div>
);
}
function CredentialFields({ label, cred, onChange, allowEmpty, masked }) {
const [show, setShow] = useState(false);
return (
<div className="space-y-3 rounded-box border border-base-300 p-3">
<p className="text-sm font-medium">{label}</p>
<Field label="Source">
<select
className="select select-bordered w-full"
value={cred.source}
onChange={(e) => onChange({ ...cred, source: e.target.value, keep: false })}
>
<option value="literal">Plain text</option>
<option value="kv">From KV</option>
<option value="secret">From secret</option>
</select>
</Field>
{cred.source === "literal" ? (
<Field
label="Value"
hint={
cred.keep && !cred.value
? "A value is already set. Enter a new one to replace it."
: null
}
>
<div className="flex w-full gap-1">
<input
type={masked && !show ? "password" : "text"}
className="input input-bordered w-full font-mono"
value={cred.value}
onChange={(e) => onChange({ ...cred, value: e.target.value, keep: false })}
placeholder={
cred.keep && !cred.value ? "(unchanged — leave blank to keep)" : ""
}
required={!allowEmpty && !cred.keep && !cred.value}
autoComplete="off"
/>
{masked ? (
<button
type="button"
className="btn btn-ghost btn-square shrink-0"
title={show ? "Hide" : "Reveal"}
aria-label={show ? "Hide value" : "Reveal value"}
onClick={() => setShow((v) => !v)}
>
{show ? <LuEyeOff className="size-4" /> : <LuEye className="size-4" />}
</button>
) : null}
</div>
</Field>
) : null}
{cred.source === "kv" ? (
<>
<Field label="Namespace (optional)">
<input
className="input input-bordered w-full font-mono"
placeholder="namespace"
value={cred.namespace}
onChange={(e) => onChange({ ...cred, namespace: e.target.value })}
/>
</Field>
<Field label="Key">
<input
className="input input-bordered w-full font-mono"
placeholder="key"
value={cred.kv}
onChange={(e) => onChange({ ...cred, kv: e.target.value })}
required
/>
</Field>
</>
) : null}
{cred.source === "secret" ? (
<Field
label="Secret name"
hint="Encrypted secret — value is never shown here. Manage it on the Secrets page."
>
<input
className="input input-bordered w-full font-mono"
placeholder="secret name"
value={cred.secret}
onChange={(e) => onChange({ ...cred, secret: e.target.value })}
required
pattern="[A-Za-z0-9._-]+"
/>
</Field>
) : null}
</div>
);
}
/**
* Add / edit an HTTP trigger auth profile.
* Reusable: mount when open; pass `auth` for edit (literals loaded inside).
*
* @param {"add" | "edit"} mode
* @param {object} [auth] Public auth row when mode is "edit"
* @param {() => void} onClose
* @param {(saved: unknown) => void} [onSaved]
*/
export function AuthEditorModal({ mode, auth, onClose, onSaved }) {
const { data: pages = [] } = useHttpPages();
const upsert = useUpsertHttpAuth();
const [form, setForm] = useState(emptyForm);
const [loading, setLoading] = useState(mode === "edit");
useEffect(() => {
if (mode !== "edit" || !auth?.id) {
setForm(emptyForm());
setLoading(false);
return;
}
let cancelled = false;
setLoading(true);
(async () => {
/** @type {Record<string, string>} */
let literals = {};
try {
const data = await fetchHttpAuthLiterals(auth.id);
literals = data.literals ?? {};
} catch {
// Form still works with keep markers
}
if (cancelled) return;
setForm(formFromAuth(auth, literals));
setLoading(false);
})();
return () => {
cancelled = true;
};
}, [mode, auth]);
function onSubmit(e) {
e.preventDefault();
/** @type {Record<string, unknown>} */
let config = {};
if (form.type === "bearer") {
const token = toApiField(form.token);
if (token == null) return;
config = { token };
} else if (form.type === "basic") {
const user = toApiField(form.user);
if (user == null) return;
const password = toApiField(form.password, { required: false });
config = { user, password: password ?? "" };
} else {
const value = toApiField(form.value);
if (value == null) return;
config = { header: form.header, value };
}
upsert.mutate(
{
id: form.id,
name: form.name,
type: form.type,
config,
unauthorized_status:
form.unauthorized_status === "" ? null : Number(form.unauthorized_status),
unauthorized_response: form.unauthorized_response || null,
},
{
onSuccess: (data) => {
onSaved?.(data?.auth ?? data);
onClose();
},
},
);
}
const title = mode === "add" ? "New auth profile" : `Edit ${form.name || auth?.name || ""}`;
return (
<dialog className="modal modal-open">
<div className="modal-box max-w-xl">
<h3 className="font-bold">{title}</h3>
{loading ? (
<div className="flex justify-center py-10">
<span className="loading loading-spinner" />
</div>
) : (
<form className="mt-3 space-y-4" onSubmit={onSubmit}>
<Field label="Name">
<input
className="input input-bordered w-full font-mono"
value={form.name}
onChange={(e) => setForm({ ...form, name: e.target.value })}
required
pattern="[A-Za-z0-9._-]+"
autoComplete="off"
/>
</Field>
<Field label="Type">
<select
className="select select-bordered w-full"
value={form.type}
onChange={(e) => setForm({ ...form, type: e.target.value })}
>
<option value="bearer">bearer</option>
<option value="basic">basic</option>
<option value="header">header</option>
</select>
</Field>
{form.type === "bearer" ? (
<CredentialFields
label="Token"
cred={form.token}
onChange={(token) => setForm({ ...form, token })}
/>
) : null}
{form.type === "basic" ? (
<>
<CredentialFields
label="User"
cred={form.user}
onChange={(user) => setForm({ ...form, user })}
/>
<CredentialFields
label="Password"
cred={form.password}
onChange={(password) => setForm({ ...form, password })}
allowEmpty
masked
/>
</>
) : null}
{form.type === "header" ? (
<>
<Field label="Header name">
<input
className="input input-bordered w-full font-mono"
value={form.header}
onChange={(e) => setForm({ ...form, header: e.target.value })}
required
placeholder="X-Webhook-Secret"
/>
</Field>
<CredentialFields
label="Header value"
cred={form.value}
onChange={(value) => setForm({ ...form, value })}
/>
</>
) : null}
<Field label="Unauthorized status (optional)">
<input
type="number"
className="input input-bordered w-full"
value={form.unauthorized_status}
onChange={(e) => setForm({ ...form, unauthorized_status: e.target.value })}
min={100}
max={599}
placeholder="401"
/>
</Field>
<Field label="Unauthorized response page (optional)">
<select
className="select select-bordered w-full"
value={form.unauthorized_response}
onChange={(e) => setForm({ ...form, unauthorized_response: e.target.value })}
>
<option value="">(default JSON)</option>
{pages.map((p) => (
<option key={p.id} value={p.name}>
{p.name}
</option>
))}
</select>
</Field>
{upsert.isError ? (
<p className="text-error text-sm">{errorMessage(upsert.error)}</p>
) : null}
<div className="modal-action">
<button type="button" className="btn btn-ghost" onClick={onClose}>
Cancel
</button>
<button type="submit" className="btn btn-primary" disabled={upsert.isPending}>
{upsert.isPending ? (
<span className="loading loading-spinner loading-xs" />
) : null}
Save
</button>
</div>
</form>
)}
{loading ? (
<div className="modal-action">
<button type="button" className="btn btn-ghost" onClick={onClose}>
Cancel
</button>
</div>
) : null}
</div>
<form method="dialog" className="modal-backdrop">
<button type="button" onClick={onClose}>
close
</button>
</form>
</dialog>
);
}
@@ -1,5 +1,5 @@
import { useState } from "react";
import { LuChevronDown, LuCopy, LuGripVertical, LuTrash2 } from "react-icons/lu";
import { useEffect, useMemo, useRef, useState } from "react";
import { LuChevronDown, LuCopy, LuGripVertical, LuTrash2, LuX } from "react-icons/lu";
import { useSortable } from "@dnd-kit/sortable";
import { CSS } from "@dnd-kit/utilities";
import cronstrue from "cronstrue";
@@ -138,15 +138,27 @@ function typeLabel(type) {
return type || "Trigger";
}
function Field({ label, children, hint }) {
return (
<div className="flex w-full flex-col gap-1">
{label ? <span className="text-sm font-medium opacity-80">{label}</span> : null}
{children}
{hint ? <span className="text-xs opacity-60">{hint}</span> : null}
</div>
);
}
function HttpFields({ trigger, owner, disabled, onChange, auths, pages, alertDestinations }) {
const path = trigger.path || "/";
const url = namespacedPath(owner || "owner", path);
const authIsInline = trigger.auth != null && typeof trigger.auth === "object";
const authSelect = authIsInline
? "__inline__"
: typeof trigger.auth === "string" && trigger.auth
? trigger.auth
: "";
const authEntries = Array.isArray(trigger.auth) ? trigger.auth : [];
const selectedIds = authEntries.filter((e) => typeof e === "string" && e).map(String);
const inlineEntries = authEntries.filter((e) => e && typeof e === "object");
function setAuthIds(nextIds) {
const next = [...nextIds, ...inlineEntries];
onChange({ ...trigger, auth: next.length ? next : null });
}
function copyUrl() {
if (typeof navigator?.clipboard?.writeText === "function") {
@@ -155,11 +167,10 @@ function HttpFields({ trigger, owner, disabled, onChange, auths, pages, alertDes
}
return (
<div className="space-y-2">
<label className="form-control">
<span className="label py-0 text-sm">Method</span>
<div className="space-y-3">
<Field label="Method">
<select
className="select select-sm"
className="select select-bordered select-sm w-full"
value={trigger.method || "POST"}
disabled={disabled}
onChange={(e) => onChange({ ...trigger, method: e.target.value })}
@@ -173,51 +184,48 @@ function HttpFields({ trigger, owner, disabled, onChange, auths, pages, alertDes
<option value={trigger.method}>{trigger.method}</option>
)}
</select>
</label>
<label className="form-control">
<span className="label py-0 text-sm">Path</span>
</Field>
<Field label="Path">
<input
className="input input-sm font-mono"
className="input input-bordered input-sm w-full font-mono"
value={trigger.path ?? ""}
disabled={disabled}
onChange={(e) => onChange({ ...trigger, path: e.target.value })}
placeholder="/hook"
/>
</label>
<div className="flex items-center gap-2 text-xs font-mono opacity-80">
<span className="truncate">{url}</span>
<button type="button" className="btn btn-ghost btn-xs btn-square" title="Copy URL" onClick={copyUrl}>
<LuCopy className="size-3.5" />
</button>
</div>
<label className="form-control">
<span className="label py-0 text-sm">Auth</span>
</Field>
<Field label="URL">
<div className="flex w-full items-center gap-1">
<input
className="input input-bordered input-sm w-full font-mono opacity-80"
value={url}
readOnly
tabIndex={-1}
/>
<button
type="button"
className="btn btn-ghost btn-sm btn-square shrink-0"
title="Copy URL"
onClick={copyUrl}
>
<LuCopy className="size-3.5" />
</button>
</div>
</Field>
<AuthPicker
auths={auths}
selectedIds={selectedIds}
inlineCount={inlineEntries.length}
disabled={disabled}
onChange={setAuthIds}
/>
<Field label="Response page">
<select
className="select select-sm"
value={authSelect}
disabled={disabled}
onChange={(e) => {
const v = e.target.value;
if (v === "" || v === "__inline__") {
onChange({ ...trigger, auth: v === "__inline__" ? trigger.auth : null });
} else {
onChange({ ...trigger, auth: v });
}
}}
>
<option value="">None</option>
{auths.map((a) => (
<option key={a.name} value={a.name}>
{a.name}
</option>
))}
{authIsInline ? <option value="__inline__">Inline (edit in YAML)</option> : null}
</select>
</label>
<label className="form-control">
<span className="label py-0 text-sm">Response page</span>
<select
className="select select-sm"
className="select select-bordered select-sm w-full"
value={trigger.response ?? ""}
disabled={disabled}
onChange={(e) => onChange({ ...trigger, response: e.target.value })}
@@ -232,7 +240,8 @@ function HttpFields({ trigger, owner, disabled, onChange, auths, pages, alertDes
<option value={trigger.response}>{trigger.response}</option>
) : null}
</select>
</label>
</Field>
<FailureAlertFields
trigger={trigger}
disabled={disabled}
@@ -243,6 +252,165 @@ function HttpFields({ trigger, owner, disabled, onChange, auths, pages, alertDes
);
}
/**
* Searchable dropdown: pick an auth to add; chips with X to remove.
* YAML stores profile UUIDs; UI shows names.
*/
function AuthPicker({ auths, selectedIds, inlineCount, disabled, onChange }) {
const [open, setOpen] = useState(false);
const [query, setQuery] = useState("");
const rootRef = useRef(null);
const inputRef = useRef(null);
const selectedSet = useMemo(() => new Set(selectedIds), [selectedIds]);
const byId = useMemo(() => new Map(auths.map((a) => [a.id, a])), [auths]);
const available = useMemo(() => {
const q = query.trim().toLowerCase();
return auths
.filter((a) => !selectedSet.has(a.id))
.filter((a) => {
if (!q) return true;
return (
a.name.toLowerCase().includes(q) ||
String(a.type).toLowerCase().includes(q) ||
a.id.toLowerCase().includes(q)
);
});
}, [auths, selectedSet, query]);
useEffect(() => {
if (!open) return;
function onDoc(e) {
if (rootRef.current && !rootRef.current.contains(e.target)) {
setOpen(false);
setQuery("");
}
}
document.addEventListener("mousedown", onDoc);
return () => document.removeEventListener("mousedown", onDoc);
}, [open]);
function addAuth(id) {
if (selectedSet.has(id)) return;
onChange([...selectedIds, id]);
setQuery("");
setOpen(false);
}
function removeAuth(id) {
onChange(selectedIds.filter((x) => x !== id));
}
return (
<div className="flex w-full flex-col gap-1" ref={rootRef}>
<span className="text-sm font-medium opacity-80">Auth (any of)</span>
{selectedIds.length > 0 ? (
<div className="flex flex-wrap gap-1.5">
{selectedIds.map((id) => {
const auth = byId.get(id);
return (
<span
key={id}
className="badge badge-outline gap-1 h-7 px-2 font-normal"
title={id}
>
<span className="max-w-[10rem] truncate">
{auth ? (
<>
{auth.name}
<span className="opacity-60"> · {auth.type}</span>
</>
) : (
<span className="opacity-60">missing</span>
)}
</span>
<button
type="button"
className="btn btn-ghost btn-xs btn-square -mr-1"
title="Remove"
aria-label={`Remove ${auth?.name ?? id}`}
disabled={disabled}
onClick={() => removeAuth(id)}
>
<LuX className="size-3.5" />
</button>
</span>
);
})}
</div>
) : null}
<div className="relative w-full">
<div className="join w-full">
<input
ref={inputRef}
type="search"
className="input input-bordered input-sm join-item w-full min-w-0"
placeholder={auths.length === 0 ? "No auth profiles yet" : "Add auth…"}
value={query}
disabled={disabled || auths.length === 0}
onChange={(e) => {
setQuery(e.target.value);
setOpen(true);
}}
onFocus={() => setOpen(true)}
onKeyDown={(e) => {
if (e.key === "Escape") {
setOpen(false);
setQuery("");
inputRef.current?.blur();
}
if (e.key === "Enter") {
e.preventDefault();
if (available[0]) addAuth(available[0].id);
}
}}
/>
<button
type="button"
className="btn btn-sm join-item btn-square"
disabled={disabled || auths.length === 0}
aria-label="Open auth list"
onClick={() => {
setOpen((v) => !v);
if (!open) inputRef.current?.focus();
}}
>
<LuChevronDown className={`size-4 transition-transform ${open ? "rotate-180" : ""}`} />
</button>
</div>
{open && !disabled && auths.length > 0 ? (
<ul className="menu menu-sm absolute z-50 mt-1 max-h-48 w-full overflow-y-auto rounded-box border border-base-300 bg-base-100 shadow-lg p-1">
{available.length === 0 ? (
<li className="disabled">
<span className="opacity-60">
{query.trim() ? "No matches" : "All profiles selected"}
</span>
</li>
) : (
available.map((a) => (
<li key={a.id}>
<button type="button" onClick={() => addAuth(a.id)}>
<span className="font-mono text-sm">{a.name}</span>
<span className="opacity-60 text-xs">{a.type}</span>
</button>
</li>
))
)}
</ul>
) : null}
</div>
{inlineCount > 0 ? (
<span className="text-xs opacity-60">
+ {inlineCount} inline auth{inlineCount === 1 ? "" : "s"} (edit in YAML)
</span>
) : null}
</div>
);
}
function CronFields({ trigger, disabled, onChange, alertDestinations }) {
const preset = matchCronPreset(trigger.schedule);
let human = "";
@@ -302,12 +470,11 @@ function CronFields({ trigger, disabled, onChange, alertDestinations }) {
function FailureAlertFields({ trigger, disabled, onChange, alertDestinations }) {
return (
<div className="space-y-2 border-t border-base-300 pt-3">
<p className="text-xs font-medium opacity-80">Failure alert</p>
<label className="form-control">
<span className="label py-0 text-sm">Consecutive failures</span>
<div className="space-y-3 border-t border-base-300 pt-3">
<p className="text-sm font-medium opacity-80">Failure alert</p>
<Field label="Consecutive failures">
<input
className="input input-sm"
className="input input-bordered input-sm w-full"
type="number"
min="1"
step="1"
@@ -318,11 +485,19 @@ function FailureAlertFields({ trigger, disabled, onChange, alertDestinations })
}
placeholder="e.g. 3"
/>
</label>
<label className="form-control">
<span className="label py-0 text-sm">On failure, start</span>
</Field>
<Field
label="On failure, start"
hint={
<>
After this many sequential failed runs for this trigger, JerapahFlow starts the
selected workflow (it must declare a <span className="font-mono">workflow</span>{" "}
trigger).
</>
}
>
<select
className="select select-sm"
className="select select-bordered select-sm w-full"
value={trigger.onFailureWorkflow ?? ""}
disabled={disabled}
onChange={(e) => onChange({ ...trigger, onFailureWorkflow: e.target.value })}
@@ -340,12 +515,7 @@ function FailureAlertFields({ trigger, disabled, onChange, alertDestinations })
<option value={trigger.onFailureWorkflow}>{trigger.onFailureWorkflow}</option>
) : null}
</select>
</label>
<p className="text-xs opacity-60">
After this many sequential failed runs for this trigger, JerapahFlow starts the
selected workflow (it must declare a <span className="font-mono">workflow</span>{" "}
trigger).
</p>
</Field>
</div>
);
}
+2 -2
View File
@@ -291,7 +291,7 @@ function normalizeTrigger(raw) {
? ""
: String(raw.onConsecutiveFailures),
onFailureWorkflow: readOnFailureWorkflow(raw),
auth: raw.auth ?? null,
auth: Array.isArray(raw.auth) ? raw.auth : null,
response: typeof raw.response === "string" ? raw.response : "",
unauthorized: raw.unauthorized ?? null,
extra: Object.keys(extra).length ? extra : undefined,
@@ -345,7 +345,7 @@ function dumpTrigger(t) {
method: t.method || "POST",
path: t.path || "/",
};
if (t.auth != null && t.auth !== false && t.auth !== "") out.auth = t.auth;
if (Array.isArray(t.auth) && t.auth.length > 0) out.auth = t.auth;
if (t.response) out.response = t.response;
if (t.unauthorized != null && t.unauthorized !== "") out.unauthorized = t.unauthorized;
dumpFailureTriggerFields(t, out);
+70 -366
View File
@@ -1,163 +1,16 @@
import { useState } from "react";
import { LuEye, LuEyeOff, LuPencil, LuPlus, LuTrash2, LuX } from "react-icons/lu";
import { useEffect, useRef, useState } from "react";
import { useLocation, useNavigate, useParams } from "react-router-dom";
import { LuEye, LuEyeOff, LuPencil, LuPlus, LuTrash2 } from "react-icons/lu";
import { errorMessage } from "../api/client.js";
import {
fetchHttpAuthLiterals,
useDeleteHttpAuth,
useHttpAuths,
useHttpPages,
useUpsertHttpAuth,
} from "../api/hooks.js";
import { AuthEditorModal } from "../components/AuthEditorModal.jsx";
import { formatTime } from "../lib/format.jsx";
function emptyCred(source = "literal") {
return { source, value: "", kv: "", namespace: "", secret: "" };
}
function credFromPublic(field, literalValue) {
if (!field || field.source === "missing") return emptyCred("literal");
if (field.source === "kv") {
return {
source: "kv",
value: "",
kv: field.kv ?? "",
namespace: field.namespace ?? "",
secret: "",
};
}
if (field.source === "secret") {
return {
source: "secret",
value: "",
kv: "",
namespace: "",
secret: field.secret ?? "",
};
}
// literal — prefer revealed value when available
if (typeof literalValue === "string") {
return {
source: "literal",
value: literalValue,
kv: "",
namespace: "",
secret: "",
keep: true,
};
}
return {
source: "literal",
value: "",
kv: "",
namespace: "",
secret: "",
keep: field.set === true,
};
}
function toApiField(cred, { required = true } = {}) {
if (cred.source === "kv") {
const out = { kv: cred.kv };
if (cred.namespace) out.namespace = cred.namespace;
return out;
}
if (cred.source === "secret") {
return { secret: cred.secret };
}
if (cred.value) return cred.value;
if (cred.keep) return { keep: true };
if (!required) return "";
return null;
}
function CredentialFields({ label, cred, onChange, allowEmpty, masked }) {
const [show, setShow] = useState(false);
return (
<div className="space-y-1 border-base-300 border rounded-box p-3">
<label className="label py-0">{label}</label>
<select
className="select select-sm w-full"
value={cred.source}
onChange={(e) => onChange({ ...cred, source: e.target.value, keep: false })}
>
<option value="literal">Plain text</option>
<option value="kv">From KV</option>
<option value="secret">From secret</option>
</select>
{cred.source === "literal" ? (
<>
<div className="flex gap-1 items-center">
<input
type={masked && !show ? "password" : "text"}
className="input input-sm w-full font-mono"
value={cred.value}
onChange={(e) => onChange({ ...cred, value: e.target.value, keep: false })}
placeholder={
cred.keep && !cred.value ? "(unchanged — leave blank to keep)" : ""
}
required={!allowEmpty && !cred.keep && !cred.value}
autoComplete="off"
/>
{masked ? (
<button
type="button"
className="btn btn-ghost btn-sm btn-square"
title={show ? "Hide" : "Reveal"}
aria-label={show ? "Hide value" : "Reveal value"}
onClick={() => setShow((v) => !v)}
>
{show ? <LuEyeOff className="size-4" /> : <LuEye className="size-4" />}
</button>
) : null}
</div>
{cred.keep && !cred.value ? (
<p className="text-xs opacity-60">
A value is already set. Enter a new one to replace it.
</p>
) : null}
</>
) : null}
{cred.source === "kv" ? (
<div className="flex flex-col sm:flex-row gap-2">
<input
className="input input-sm w-full font-mono"
placeholder="namespace (optional)"
value={cred.namespace}
onChange={(e) => onChange({ ...cred, namespace: e.target.value })}
/>
<input
className="input input-sm w-full font-mono"
placeholder="key"
value={cred.kv}
onChange={(e) => onChange({ ...cred, kv: e.target.value })}
required
/>
</div>
) : null}
{cred.source === "secret" ? (
<>
<input
className="input input-sm w-full font-mono"
placeholder="secret name"
value={cred.secret}
onChange={(e) => onChange({ ...cred, secret: e.target.value })}
required
pattern="[A-Za-z0-9._-]+"
/>
<p className="text-xs opacity-60">
Encrypted secret — value is never shown here. Manage it on the Secrets page.
</p>
</>
) : null}
</div>
);
}
/**
* List cell: literals show *** with reveal; secrets never reveal; kv shows ref only.
*/
function CredDisplay({ field, fieldKey, authName, cache, onRevealed }) {
function CredDisplay({ field, fieldKey, authId, cache, onRevealed }) {
const [open, setOpen] = useState(false);
const [loading, setLoading] = useState(false);
const [error, setError] = useState(null);
@@ -181,7 +34,6 @@ function CredDisplay({ field, fieldKey, authName, cache, onRevealed }) {
return <span className="font-mono text-xs">{ref}</span>;
}
// literal
const revealed = cache?.[fieldKey];
const shown = open && typeof revealed === "string";
@@ -197,7 +49,7 @@ function CredDisplay({ field, fieldKey, authName, cache, onRevealed }) {
setLoading(true);
setError(null);
try {
const data = await fetchHttpAuthLiterals(authName);
const data = await fetchHttpAuthLiterals(authId);
onRevealed?.(data.literals ?? {});
setOpen(true);
} catch (err) {
@@ -241,7 +93,7 @@ function CredentialsCell({ auth, cache, onRevealed }) {
<CredDisplay
field={cfg.token}
fieldKey="token"
authName={auth.name}
authId={auth.id}
cache={cache}
onRevealed={onRevealed}
/>
@@ -255,7 +107,7 @@ function CredentialsCell({ auth, cache, onRevealed }) {
<CredDisplay
field={cfg.user}
fieldKey="user"
authName={auth.name}
authId={auth.id}
cache={cache}
onRevealed={onRevealed}
/>
@@ -265,7 +117,7 @@ function CredentialsCell({ auth, cache, onRevealed }) {
<CredDisplay
field={cfg.password}
fieldKey="password"
authName={auth.name}
authId={auth.id}
cache={cache}
onRevealed={onRevealed}
/>
@@ -279,7 +131,7 @@ function CredentialsCell({ auth, cache, onRevealed }) {
<CredDisplay
field={cfg.value}
fieldKey="value"
authName={auth.name}
authId={auth.id}
cache={cache}
onRevealed={onRevealed}
/>
@@ -287,122 +139,70 @@ function CredentialsCell({ auth, cache, onRevealed }) {
);
}
const emptyForm = () => ({
name: "",
type: "bearer",
token: emptyCred(),
user: emptyCred(),
password: emptyCred(),
header: "",
value: emptyCred(),
unauthorized_status: "",
unauthorized_response: "",
});
export function AuthProfilesPage() {
const navigate = useNavigate();
const location = useLocation();
const { name: routeName } = useParams();
const isNewRoute = /\/auth\/new\/?$/.test(location.pathname);
const isEditRoute = Boolean(routeName) && !isNewRoute;
const { data: auths = [], isLoading } = useHttpAuths();
const { data: pages = [] } = useHttpPages();
const upsert = useUpsertHttpAuth();
const del = useDeleteHttpAuth();
const [mode, setMode] = useState(null);
const [form, setForm] = useState(emptyForm);
const [editor, setEditor] = useState(null);
const [confirmDelete, setConfirmDelete] = useState(null);
/** @type {[Record<string, Record<string, string>>, Function]} */
const [revealCache, setRevealCache] = useState({});
const [editLoading, setEditLoading] = useState(false);
const openedRouteKey = useRef(null);
function openAdd() {
setMode("add");
setForm(emptyForm());
}
async function openEdit(a) {
setEditLoading(true);
/** @type {Record<string, string>} */
let literals = {};
try {
const data = await fetchHttpAuthLiterals(a.name);
literals = data.literals ?? {};
setRevealCache((prev) => ({ ...prev, [a.name]: literals }));
} catch {
// keep empty; form still works with keep markers
} finally {
setEditLoading(false);
function closeEditor() {
setEditor(null);
openedRouteKey.current = null;
if (isNewRoute || isEditRoute) {
navigate("/auth", { replace: true });
}
const cfg = a.config ?? {};
setMode("edit");
setForm({
name: a.name,
type: a.type,
token: credFromPublic(cfg.token, literals.token),
user: credFromPublic(cfg.user, literals.user),
password: credFromPublic(cfg.password, literals.password),
header: cfg.header ?? "",
value: credFromPublic(cfg.value, literals.value),
unauthorized_status: a.unauthorized_status ?? "",
unauthorized_response: a.unauthorized_response ?? "",
});
}
function closeForm() {
setMode(null);
setForm(emptyForm());
}
useEffect(() => {
if (!isNewRoute) return;
if (openedRouteKey.current === "new") return;
openedRouteKey.current = "new";
setEditor({ mode: "add" });
}, [isNewRoute]);
function onSubmit(e) {
e.preventDefault();
/** @type {Record<string, unknown>} */
let config = {};
if (form.type === "bearer") {
const token = toApiField(form.token);
if (token == null) return;
config = { token };
} else if (form.type === "basic") {
const user = toApiField(form.user);
if (user == null) return;
const password = toApiField(form.password, { required: false });
config = { user, password: password ?? "" };
} else {
const value = toApiField(form.value);
if (value == null) return;
config = { header: form.header, value };
useEffect(() => {
if (!isEditRoute) {
if (!isNewRoute) openedRouteKey.current = null;
return;
}
upsert.mutate(
{
name: form.name,
type: form.type,
config,
unauthorized_status:
form.unauthorized_status === "" ? null : Number(form.unauthorized_status),
unauthorized_response: form.unauthorized_response || null,
},
{
onSuccess: () => {
setRevealCache((prev) => {
const next = { ...prev };
delete next[form.name];
return next;
});
closeForm();
},
},
);
}
if (isLoading) return;
const key = `edit:${routeName}`;
if (openedRouteKey.current === key) return;
openedRouteKey.current = key;
const auth = auths.find((a) => a.name === routeName);
if (!auth) {
setEditor({ mode: "add" });
return;
}
setEditor({ mode: "edit", auth });
}, [isEditRoute, isNewRoute, routeName, isLoading, auths]);
return (
<div className="space-y-4">
<div className="flex flex-col sm:flex-row sm:items-center justify-between gap-2">
<h1 className="text-xl font-semibold">Auth</h1>
<button type="button" className="btn btn-primary btn-sm" onClick={openAdd}>
<button
type="button"
className="btn btn-primary btn-sm"
onClick={() => navigate("/auth/new")}
>
<LuPlus className="size-4" />
Add
</button>
</div>
<p className="text-sm opacity-70">
Named HTTP trigger auth profiles. Reference in YAML as{" "}
<code className="font-mono text-xs">auth: name</code>. Secrets are managed on the Secrets
page; KV values stay in KV.
HTTP trigger auth profiles. Rename freely — workflows keep working via a stable id.
Add them to a trigger from the workflow editor dropdown. Secrets are managed on the
Secrets page; KV values stay in KV.
</p>
{isLoading ? (
@@ -429,9 +229,9 @@ export function AuthProfilesPage() {
<td>
<CredentialsCell
auth={a}
cache={revealCache[a.name]}
cache={revealCache[a.id]}
onRevealed={(literals) =>
setRevealCache((prev) => ({ ...prev, [a.name]: literals }))
setRevealCache((prev) => ({ ...prev, [a.id]: literals }))
}
/>
</td>
@@ -441,8 +241,7 @@ export function AuthProfilesPage() {
type="button"
className="btn btn-ghost btn-xs"
title="Edit"
disabled={editLoading}
onClick={() => openEdit(a)}
onClick={() => navigate(`/auth/${encodeURIComponent(a.name)}/edit`)}
>
<LuPencil className="size-4" />
</button>
@@ -462,116 +261,21 @@ export function AuthProfilesPage() {
</div>
)}
{mode ? (
<form
onSubmit={onSubmit}
className="fieldset bg-base-100 border-base-300 rounded-box max-w-xl border p-4 space-y-2"
>
<div className="flex items-center justify-between">
<legend className="fieldset-legend">
{mode === "add" ? "New auth profile" : `Edit ${form.name}`}
</legend>
<button
type="button"
className="btn btn-ghost btn-sm btn-square"
onClick={closeForm}
aria-label="Close"
>
<LuX className="size-4" />
</button>
</div>
<label className="label">Name</label>
<input
className="input w-full font-mono"
value={form.name}
onChange={(e) => setForm({ ...form, name: e.target.value })}
required
pattern="[A-Za-z0-9._-]+"
disabled={mode === "edit"}
/>
<label className="label">Type</label>
<select
className="select w-full"
value={form.type}
onChange={(e) => setForm({ ...form, type: e.target.value })}
>
<option value="bearer">bearer</option>
<option value="basic">basic</option>
<option value="header">header</option>
</select>
{form.type === "bearer" ? (
<CredentialFields
label="Token"
cred={form.token}
onChange={(token) => setForm({ ...form, token })}
/>
) : null}
{form.type === "basic" ? (
<>
<CredentialFields
label="User"
cred={form.user}
onChange={(user) => setForm({ ...form, user })}
/>
<CredentialFields
label="Password"
cred={form.password}
onChange={(password) => setForm({ ...form, password })}
allowEmpty
masked
/>
</>
) : null}
{form.type === "header" ? (
<>
<label className="label">Header name</label>
<input
className="input w-full font-mono"
value={form.header}
onChange={(e) => setForm({ ...form, header: e.target.value })}
required
placeholder="X-Webhook-Secret"
/>
<CredentialFields
label="Header value"
cred={form.value}
onChange={(value) => setForm({ ...form, value })}
/>
</>
) : null}
<label className="label">Unauthorized status (optional)</label>
<input
type="number"
className="input w-full"
value={form.unauthorized_status}
onChange={(e) => setForm({ ...form, unauthorized_status: e.target.value })}
min={100}
max={599}
placeholder="401"
/>
<label className="label">Unauthorized response page (optional)</label>
<select
className="select w-full"
value={form.unauthorized_response}
onChange={(e) => setForm({ ...form, unauthorized_response: e.target.value })}
>
<option value="">(default JSON)</option>
{pages.map((p) => (
<option key={p.id} value={p.name}>
{p.name}
</option>
))}
</select>
{upsert.isError ? (
<p className="text-error text-sm">{errorMessage(upsert.error)}</p>
) : null}
<button type="submit" className="btn btn-primary mt-2" disabled={upsert.isPending}>
Save
</button>
</form>
{editor ? (
<AuthEditorModal
mode={editor.mode}
auth={editor.auth}
onClose={closeEditor}
onSaved={(saved) => {
const id = saved?.id || editor.auth?.id;
if (!id) return;
setRevealCache((prev) => {
const next = { ...prev };
delete next[id];
return next;
});
}}
/>
) : null}
{confirmDelete ? (