- Added node-html-parser as a dependency for parsing HTML content.
- Implemented fetch-html script to fetch and parse HTML from a specified URL.
- Updated script sandbox to allow the use of node-html-parser.
- Created a new workflow for fetching data from dev.to, including configuration for URL and selectors.
- Updated package.json to include node-html-parser in server package dependencies.
- Introduced a new server package with Fastify for handling API requests and workflows.
- Implemented user authentication and authorization with JWT and cookie management.
- Added endpoints for managing workflows, runs, and user accounts.
- Established a dashboard for monitoring workflow status and statistics.
- Included a script sandbox for executing user-defined scripts securely.
- Updated README with setup instructions and API documentation.
- Configured database migrations for user management.
- Enhanced logging capabilities for better traceability.
- Added database configuration and migration setup using Knex.
- Implemented a logging system with Pino, including log persistence and flushing.
- Created a server runner with Fastify, integrating authentication and various API routes.
- Introduced a script sandbox for executing user-defined scripts with restricted access.
- Established initial workflows and scripts for manual and cron triggers.
- Included documentation for API endpoints and workflows.
Self-hosted automation targets often run on localhost or loopback
addresses, so keep blocking private/metadata hosts but stop blocking
localhost, 127.x.x.x, and .localhost names.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>
Add $axios to the VM sandbox with a request interceptor that blocks
non-http(s) URLs and common SSRF targets (localhost, private IPs,
link-local, and cloud metadata hosts). require('axios') and import
axios resolve to the same screened instance so scripts cannot bypass
URL screening.
Co-authored-by: Nasyarobby Putra <nasyarobby@gmail.com>