continuous-integration/drone/push Build encountered an error
- Provider-controlled strings (channel names, groups, file names, log lines, in-place mapping edits, client info) are rendered with textContent instead of innerHTML. PopupContent.description() takes an explicit isHTML flag that only the static help texts pass. - Websocket: drop the always-true CheckOrigin so gorilla's same-origin check applies; read the session token from the HttpOnly cookie sent with the handshake (the ?Token= query parameter is still accepted for older clients); the client no longer puts the token in the URL, rewrites the cookie, or console-logs request/response payloads. - Session cookie is HttpOnly, SameSite=Strict, Path=/, session-scoped (expiry stays server side) and is cleared on logout. - Serving the first-run wizard no longer sets Settings.AuthenticationWEB to false; the wizard page simply bypasses login while it is active. - Upgrade failures no longer write a second error response. - Tests: src/websocket_test.go covers cross-origin refusal, same-origin and no-Origin clients, missing/unknown/legacy tokens, and cookie flags.
74 lines
1.3 KiB
TypeScript
74 lines
1.3 KiB
TypeScript
class Log {
|
|
|
|
createLog(entry:string):any {
|
|
|
|
var element = document.createElement("PRE");
|
|
|
|
if (entry.indexOf("WARNING") != -1) {
|
|
element.className = "warningMsg"
|
|
}
|
|
|
|
if (entry.indexOf("ERROR") != -1) {
|
|
element.className = "errorMsg"
|
|
}
|
|
|
|
if (entry.indexOf("DEBUG") != -1) {
|
|
element.className = "debugMsg"
|
|
}
|
|
|
|
element.textContent = entry
|
|
|
|
return element
|
|
}
|
|
|
|
}
|
|
|
|
function showLogs(bottom:boolean) {
|
|
|
|
var log = new Log()
|
|
|
|
var logs = SERVER["log"]["log"]
|
|
var div = document.getElementById("content_log")
|
|
var wrapper = document.getElementById("box-wrapper") as HTMLElement
|
|
var shouldStickToBottom:boolean = bottom
|
|
|
|
div.innerHTML = ""
|
|
|
|
if (wrapper != null && shouldStickToBottom == false) {
|
|
var distanceToBottom:number = wrapper.scrollHeight - wrapper.scrollTop - wrapper.clientHeight
|
|
if (distanceToBottom < 80) {
|
|
shouldStickToBottom = true
|
|
}
|
|
}
|
|
|
|
var keys = getObjKeys(logs)
|
|
|
|
keys.forEach(logID => {
|
|
|
|
var entry = log.createLog(logs[logID])
|
|
|
|
div.append(entry)
|
|
|
|
});
|
|
|
|
setTimeout(function(){
|
|
|
|
if (shouldStickToBottom == true && wrapper != null) {
|
|
|
|
wrapper.scrollTop = wrapper.scrollHeight;
|
|
|
|
}
|
|
|
|
}, 10);
|
|
|
|
}
|
|
|
|
function resetLogs() {
|
|
|
|
var cmd = "resetLogs"
|
|
var data = new Object()
|
|
var server:Server = new Server(cmd)
|
|
server.request(data)
|
|
|
|
}
|