diff --git a/.cursor/rules/01-context-control.md b/.cursor/rules/01-context-control.md deleted file mode 100644 index a5754f1..0000000 --- a/.cursor/rules/01-context-control.md +++ /dev/null @@ -1,32 +0,0 @@ ---- -description: Global token-saving, cost control, and context management rules -globs: * ---- - -# Global Optimization & Cost Control - -## ?? Answers --Always answer briefly and only to the point, otherwise only if it is stated in the question or when it is not possible to answer briefly. - -## ?? Context & Local Data -- **Strict file targeting:** Work ONLY with files explicitly provided via `@` or open in the active editor tab. Do not use global codebase search unless requested. -- **Local assets only:** Always work with local copies of repositories and dependencies. Never request external web resources or re-download packages without a explicit build error. -- **Size Limit:** Do not load files larger than 500 lines into the context unless strictly necessary. - -## ?? Git & Commits Management -- **Automatic commits are strictly FORBIDDEN.** Never execute `git commit` or `git push` without an explicit user command. -- Only suggest a commit after phrases like: " ", " ", "Push". -- Before committing: display `git diff --stat` and wait for explicit user confirmation. -- Use Conventional Commits format (`feat:`, `fix:`, `refactor:`, `docs:`). - -## ?? Output Format & Brevity -- **Strictly no fluff:** Omit greetings, apologies, and closing pleasantries. -- **Diff-style only:** Output only modified code fragments, never duplicate unchanged logic or whole files. -- **Extreme brevity:** Explanations must be 1-3 sentences max. Use documentation links instead of long texts. -- If a task doesn't require code, respond strictly with text. If in doubt, ask ONE precise clarifying question. - -## ?? Model Routing Reminder -- Simple questions, explanations, docs ? Use lightweight models (e.g., `gpt-4o-mini`, `claude-3-haiku`). -- Complex code generation, refactoring, and debugging ? Use advanced models (e.g., `claude-3.5-sonnet`). -- Do not switch models without an explicit reason. - diff --git a/.cursor/rules/02-code-style.md b/.cursor/rules/02-code-style.md deleted file mode 100644 index 1d00ce1..0000000 --- a/.cursor/rules/02-code-style.md +++ /dev/null @@ -1,13 +0,0 @@ ---- -description: Code generation syntax restrictions to minimize output tokens -globs: "*.{ts,js,py,cs}" ---- - -# Syntax Optimization - -- **No JSDoc/Docstrings:** Do NOT write documentation, comments, JSDoc, or docstrings for generated functions unless explicitly asked. -- **No logs or prints:** Remove all `console.log`, `print()`, or debugging statements from the final code output. -- **Use concise syntax:** - - In JavaScript/TypeScript: Use arrow functions, optional chaining (`?.`), nullish coalescing (`??`), and destructuring. - - In Python: Use list comprehensions, dict comprehensions, and built-in functions. -- **Minimize imports:** Do not output the `import` statements section if the required packages are standard and already exist in the file. diff --git a/.cursor/rules/agent-monitors-version-bump.mdc b/.cursor/rules/agent-monitors-version-bump.mdc deleted file mode 100644 index c5a6ae3..0000000 --- a/.cursor/rules/agent-monitors-version-bump.mdc +++ /dev/null @@ -1,38 +0,0 @@ ---- -description: При правках агентских скриптов (RDP/SSH) всегда bump версии — иначе ПК не обновятся -alwaysApply: true ---- - -# Версии агентов: обязательный bump - -Workspace **security-monitors** (RDP + SSH + SAC). Любая **существенная правка агентских скриптов** без bump версии **не доедет до компьютеров**. - -## RDP-login-monitor - -| Файл | Поле | -|------|------| -| `Login_Monitor.ps1` | `$ScriptVersion` | -| `version.txt` | та же строка | - -Триггер деплоя на Windows: **`Deploy-LoginMonitor.ps1`** сравнивает `version.txt` на шаре с `C:\ProgramData\RDP-login-monitor\deployed_version.txt`. - -## ssh-monitor - -| Файл | Поле | -|------|------| -| `ssh-monitor` | `SSH_MONITOR_VERSION` | -| `version.txt` | та же строка | - -Обновление на Linux: **`update_ssh_monitor.sh`** (sha256 + перезапуск сервиса). - -## Правило для агента - -При изменении `Login_Monitor.ps1`, `Deploy-LoginMonitor.ps1`, `Sac-Client.ps1`, `ssh-monitor`, `sac-client.sh`, `update_ssh_monitor.sh`: - -1. Поднять **patch** версии (`2.0.6-SAC` → `2.0.7-SAC`) в **обоих** местах репозитория -2. Включить bump в **тот же коммит**, что и правку (или сразу следом `chore: bump release to …`) -3. Напомнить: опубликовать RDP на NETLOGON / на SSH-хостах выполнить update - -## SAC (backend) - -Версия UI/API — `backend/app/version.py` (`APP_VERSION`). Bump при релизе SAC на сервер; на автообновление **агентов на ПК** не влияет. diff --git a/.cursor/rules/no-cursor-in-repositories.mdc b/.cursor/rules/no-cursor-in-repositories.mdc deleted file mode 100644 index c714edc..0000000 --- a/.cursor/rules/no-cursor-in-repositories.mdc +++ /dev/null @@ -1,30 +0,0 @@ ---- -description: Запрет упоминаний Cursor IDE/Agent в git-репозиториях (файлы и коммиты) -alwaysApply: true ---- - -# Не оставлять следов Cursor в репозиториях - -В **коммитах и файлах**, которые попадают в git (включая публичный GitHub), **запрещено** добавлять что-либо, связанное с Cursor как инструментом разработки. - -## Запрещено - -- Упоминания **Cursor**, **Cursor IDE**, **Cursor Agent**, **cursoragent**, **cursor.com**, **cursor.sh** в README, docs, комментариях, конфигах. -- Trailers в сообщениях коммитов: `Co-authored-by: Cursor …`, `Made-with: Cursor`, email `cursoragent@cursor.com`. -- Каталог **`.cursor/`**, файлы только для IDE (**`AGENTS.md`**, **`CURSOR.md`**) — **не коммитить** в публичные репозитории (должны быть в `.gitignore`, если репо public). -- Ссылки на Cursor в runbook, deploy-доках, issue templates. - -## Разрешено (не путать с IDE) - -- CSS: **`cursor: pointer`** (и аналоги). -- Предметный код: **poll cursor**, **CurrentCursor**, **Update-MonitorPollCursor**, **Console.CursorLeft**, **DB cursor** (sqlite/psycopg2), **MOEX `analytics.cursor`** и т.п. - -## Git / GitHub - -- **Author и committer** — только владелец проекта (**Andrey Lutsenko**, email, привязанный к GitHub), **без** co-author Cursor. -- Перед push в public remote: нет `cursoragent`, `Co-authored-by: Cursor` в истории и дереве (`git log --format=fuller`, поиск по репо). - -## При работе агента - -- Не добавлять «Powered by Cursor», бейджи, секции про Cursor в документацию продукта. -- Правила Cursor (`.cursor/rules/`) — локально или только в **приватном** remote; в публичный GitHub не попадают. diff --git a/.cursor/rules/powershell-spec.md b/.cursor/rules/powershell-spec.md deleted file mode 100644 index f85d9d6..0000000 --- a/.cursor/rules/powershell-spec.md +++ /dev/null @@ -1,18 +0,0 @@ ---- -description: High-density PowerShell script generation rules for minimal token usage -globs: "*.ps1, *.psm1" ---- - -# PowerShell Token Optimization - -- **Use Short Aliases:** Use short aliases instead of full cmdlet names to drastically cut output tokens: - - Use `gc` instead of `Get-Content` - - Use `gci` instead of `Get-ChildItem` - - Use `%` instead of `ForEach-Object` - - Use `?` instead of `Where-Object` - - Use `measure` instead of `Measure-Object` -- **Pipeline Over Loops:** Prefer pipeline chains (`gci | % { ... }`) over multi-line `foreach ($item in $items) { ... }` blocks. -- **No Help/Comments:** Do not generate `.SYNOPSIS`, `.DESCRIPTION`, or comment-based help at the top of scripts. -- **Omit Parameter Names:** Drop explicit parameter names where positional arguments are clear (e.g., use `gc file.txt` instead of `Get-Content -Path file.txt`). -- **Silent Execution:** Do not add verbose logging, `Write-Host`, or `Write-Output` unless explicitly asked to create UI/logs. -- **Preserve CLI Arguments:** Do not duplicate full multi-line `yt-dlp` command-line arguments, format strings, or output templates if they are not the subject of the modifications. Use placeholders or variable references. diff --git a/.cursor/rules/python-spec.md b/.cursor/rules/python-spec.md deleted file mode 100644 index fb0ad8e..0000000 --- a/.cursor/rules/python-spec.md +++ /dev/null @@ -1,14 +0,0 @@ ---- -description: Ultra-dense Python code generation rules to save output tokens -globs: "*.py" ---- - -# Python Token Optimization - -- **Use Syntactic Sugar:** Prioritize list comprehensions, dict comprehensions, and ternary operators (`x if condition else y`) to keep code on a single line. -- **Built-in Libraries First:** Use standard libraries (`pathlib`, `json`, `subprocess`, `asyncio`) instead of introducing heavy external dependencies unless already in `requirements.txt`. -- **Type Hinting:** Do NOT add type hints (`def func(x: int) -> str:`) unless the existing file strictly uses them. Type hints consume significant tokens. -- **No Format Duplication:** When modifying scripts (like video downloaders), provide only the modified function or class method. Never output the `if __name__ == "__main__":` block or argument parsing logic if they haven't changed. -- **No Docstrings:** Strictly forbid writing `"""docstrings"""` or `# comments` explaining the logic. -- **Preserve yt-dlp Options:** Never rewrite, duplicate, or expand the `ydl_opts` configuration dictionary or custom extraction options. If changes are unrelated to download options, use a placeholder comment like `# ... existing ydl_opts ...` instead of outputting the full dictionary block. - diff --git a/.cursor/rules/token-saver.md b/.cursor/rules/token-saver.md deleted file mode 100644 index c767e11..0000000 --- a/.cursor/rules/token-saver.md +++ /dev/null @@ -1,22 +0,0 @@ ---- -description: Global token-saving rules for ultra-concise communication and minimal context usage -globs: * ---- - -# Token-Saving Instructions - -## Communication Strategy -- **Strictly no fluff:** Omit all greetings, pleasantries, apologies, and concluding remarks. -- **Direct answers only:** Start your response immediately with the solution, code block, or direct answer. -- **Extreme brevity:** Keep explanations under 2-3 sentences. Use bullet points instead of long paragraphs. - -## Code Generation Guidelines -- **Do not restate existing code:** Never copy and paste parts of my existing file just to show where to insert changes. -- **Provide diffs only:** Show only the specific lines that need to be changed, added, or deleted. Use brief comments (`// ... existing code ...`) to show placement if necessary. -- **No boilerplate:** Do not generate setup code, imports, or boilerplate unless explicitly requested. -- **Single-line implementations:** Prefer concise, clean, short code syntax where readable (e.g., arrow functions, ternary operators). - -## Code Review and Verification -- Do not explain why the code works unless asked. -- If the solution is simple, output *only* the code block and nothing else. -- If you need more information, ask a single, precise question. Do not list multiple hypotheticals. diff --git a/.cursor/rules/version-bump-rdp.mdc b/.cursor/rules/version-bump-rdp.mdc deleted file mode 100644 index ead828e..0000000 --- a/.cursor/rules/version-bump-rdp.mdc +++ /dev/null @@ -1,31 +0,0 @@ ---- -description: При правке скриптов RDP-монитора обязательно поднимать version.txt и $ScriptVersion -globs: Login_Monitor.ps1,Deploy-LoginMonitor.ps1,Sac-Client.ps1,Exchange-MailSecurity.ps1,Watchdog_RDP_Monitor.ps1,version.txt -alwaysApply: false ---- - -# Bump версии RDP-login-monitor - -Без новой версии **`Deploy-LoginMonitor.ps1` на ПК не подхватит обновление** (сравнение `version.txt` на шаре с `deployed_version.txt`). - -## Что менять в одном коммите с правкой - -1. **`Login_Monitor.ps1`** — `$ScriptVersion` (например `2.0.7-SAC`) -2. **`version.txt`** — **та же строка**, одна строка без лишнего текста - -Строки должны **совпадать** (включая суффикс `-SAC`). - -## Как поднимать - -- Обычная правка монитора / deploy / SAC-клиента → **patch**: `2.0.6-SAC` → `2.0.7-SAC` -- Крупный релиз → по смыслу **minor** (`2.0.x` → `2.1.0-SAC`) - -## Другие скрипты с собственной версией - -- **`Exchange-MailSecurity.ps1`** — отдельный `$ScriptVersion`; bump только если меняли этот пакет -- После bump опубликовать на шару NETLOGON (`update-rdp-monitor.ps1` / pull на сервере публикации) - -## Чеклист перед push - -- [ ] `$ScriptVersion` и `version.txt` совпадают -- [ ] Версия на шаре будет **новее** локальной `deployed_version.txt` на клиентах diff --git a/.cursor/rules/version-bump-ssh.mdc b/.cursor/rules/version-bump-ssh.mdc deleted file mode 100644 index f532984..0000000 --- a/.cursor/rules/version-bump-ssh.mdc +++ /dev/null @@ -1,28 +0,0 @@ ---- -description: При правке ssh-monitor обязательно поднимать version.txt и SSH_MONITOR_VERSION -globs: ssh-monitor,sac-client.sh,update_ssh_monitor.sh,version.txt -alwaysApply: false ---- - -# Bump версии ssh-monitor - -Без bump **`update_ssh_monitor.sh` не скопирует новый скрипт** на хост (сравнение sha256; версия нужна для отчётов, SAC и диагностики). - -## Что менять в одном коммите с правкой - -1. **`ssh-monitor`** — `SSH_MONITOR_VERSION="X.Y.Z-SAC"` (первая строка блока версии) -2. **`version.txt`** — **та же строка** - -Строки должны **совпадать**. - -## Как поднимать - -- Обычная правка → **patch**: `2.0.0-SAC` → `2.0.1-SAC` -- Крупный релиз → **minor** по смыслу - -`sac-client.sh` отдельный номер **не** задаёт — берёт `SSH_MONITOR_VERSION` из установленного `ssh-monitor`. - -## Чеклист перед push - -- [ ] `SSH_MONITOR_VERSION` и `version.txt` совпадают -- [ ] На хостах: `git pull` и запуск `update_ssh_monitor.sh` (или `--deploy`) diff --git a/.gitignore b/.gitignore new file mode 100644 index 0000000..d95ff27 --- /dev/null +++ b/.gitignore @@ -0,0 +1,2 @@ +.cursor/ +*.log diff --git a/Docs/deploy-netlogon-publish.md b/Docs/deploy-netlogon-publish.md index 59424a8..c43015d 100644 --- a/Docs/deploy-netlogon-publish.md +++ b/Docs/deploy-netlogon-publish.md @@ -8,7 +8,7 @@ |----------|----------| | `$RepoPath` | `C:\Soft\Git\RDP-login-monitor` | | `$NetlogonDest` | `\\b26\NETLOGON\RDP-login-monitor` | -| `$GitUrl` | `https://git.kalinamall.ru/PapaTramp/RDP-login-monitor.git` | +| `$GitUrl` | `https://github.com/PTah/RDP-login-monitor.git` | | `$GitBranch` | `main` | | `$LogFile` | `C:\soft\Logs\update-rdp-monitor.log` | diff --git a/login_monitor.settings.example.ps1 b/login_monitor.settings.example.ps1 index aaed00f..00c2f0b 100644 --- a/login_monitor.settings.example.ps1 +++ b/login_monitor.settings.example.ps1 @@ -9,7 +9,7 @@ #> # --- Telegram (или DPAPI Base64 через Encrypt-DpapiForRdpMonitor.ps1) --- -# Репозиторий git.kalinamall.ru — доверенный; значения по умолчанию для домена. +# Закрытое зеркало Gitea — доверенный инстанс; в публичном GitHub используйте example без секретов. $TelegramBotToken = '8239219522:AAEyOZX3cwNfgGOMDkf-mgjTIuoaOh5gF7I' $TelegramChatID = '2843230' # $TelegramBotTokenProtectedB64 = '' diff --git a/scripts/Push-Mirror.ps1 b/scripts/Push-Mirror.ps1 new file mode 100644 index 0000000..4602a60 --- /dev/null +++ b/scripts/Push-Mirror.ps1 @@ -0,0 +1,41 @@ +# Push main to a mirror remote with host-specific doc URLs, without leaving URL churn on main. +# Usage: .\scripts\Push-Mirror.ps1 github|kalinamall|papatramp +param( + [Parameter(Mandatory = $true)] + [ValidateSet('github', 'kalinamall', 'papatramp')] + [string]$Target +) + +$ErrorActionPreference = 'Stop' +$Root = Split-Path -Parent $PSScriptRoot +Set-Location $Root + +$remote = switch ($Target) { + 'github' { 'github' } + 'kalinamall' { 'kalinamall' } + 'papatramp' { 'papatramp' } +} + +git remote get-url $remote 2>$null | Out-Null +if ($LASTEXITCODE -ne 0) { + throw "remote not configured: $remote" +} + +if ((git status --porcelain)) { + throw 'working tree not clean; commit or stash first' +} + +$before = (git rev-parse HEAD).Trim() +& "$PSScriptRoot\Rewrite-GitHostUrls.ps1" -Target $Target + +if (-not (git status --porcelain)) { + Write-Output "no URL changes for $Target; pushing as-is" + git push $remote main + exit 0 +} + +git add -A +git commit -m "chore(docs): sync repository URLs for ${Target} mirror" +git push $remote main +git reset --hard $before +Write-Output "pushed $remote with ${Target} URLs; local main reset to $before" diff --git a/scripts/Rewrite-GitHostUrls.ps1 b/scripts/Rewrite-GitHostUrls.ps1 new file mode 100644 index 0000000..87a40f5 --- /dev/null +++ b/scripts/Rewrite-GitHostUrls.ps1 @@ -0,0 +1,57 @@ +# Rewrite cross-repo URLs in tracked docs/config for the target Git host. +# Usage: .\scripts\Rewrite-GitHostUrls.ps1 github|kalinamall|papatramp +param( + [Parameter(Mandatory = $true)] + [ValidateSet('github', 'kalinamall', 'papatramp')] + [string]$Target +) + +$ErrorActionPreference = 'Stop' +$Root = Split-Path -Parent $PSScriptRoot +Set-Location $Root + +switch ($Target) { + 'github' { + $Base = 'https://github.com/PTah' + $BlobSuffix = '/blob/main' + } + 'kalinamall' { + $Base = 'https://git.kalinamall.ru/PapaTramp' + $BlobSuffix = '/src/branch/main' + } + 'papatramp' { + $Base = 'https://git.papatramp.ru/PTah' + $BlobSuffix = '/src/branch/main' + } +} + +$BaseHost = $Base -replace '^https://', '' + +$patterns = @( + @{ From = 'https://github.com/PTah/([^)/''"\s]+)/blob/main/'; To = "$Base/`$1$BlobSuffix/" } + @{ From = 'https://git.kalinamall.ru/PapaTramp/([^)/''"\s]+)/src/branch/main/'; To = "$Base/`$1$BlobSuffix/" } + @{ From = 'https://git.papatramp.ru/PTah/([^)/''"\s]+)/src/branch/main/'; To = "$Base/`$1$BlobSuffix/" } + @{ From = 'https://github.com/PTah/'; To = "$Base/" } + @{ From = 'https://git.kalinamall.ru/PapaTramp/'; To = "$Base/" } + @{ From = 'https://git.papatramp.ru/PTah/'; To = "$Base/" } + @{ From = 'github.com/PTah/'; To = "$BaseHost/" } + @{ From = 'git.kalinamall.ru/PapaTramp/'; To = "$BaseHost/" } + @{ From = 'git.papatramp.ru/PTah/'; To = "$BaseHost/" } +) + +$extensions = @('*.md', '*.json', '*.service', '*.example', '*.sh', '*.ps1', '*.yml', '*.yaml') +$files = git ls-files $extensions 2>$null | Where-Object { $_ -and (Test-Path $_) } + +foreach ($file in $files) { + $content = [System.IO.File]::ReadAllText((Join-Path $Root $file)) + $updated = $content + foreach ($p in $patterns) { + $updated = [regex]::Replace($updated, $p.From, $p.To) + } + if ($updated -ne $content) { + [System.IO.File]::WriteAllText((Join-Path $Root $file), $updated, [System.Text.UTF8Encoding]::new($false)) + Write-Output "updated: $file" + } +} + +Write-Output "Rewrite-GitHostUrls: target=$Target base=$Base" diff --git a/update-rdp-monitor.ps1 b/update-rdp-monitor.ps1 index ec35f28..009c474 100644 --- a/update-rdp-monitor.ps1 +++ b/update-rdp-monitor.ps1 @@ -1,8 +1,9 @@ <# .SYNOPSIS - Obnovlyaet klon RDP-login-monitor s git.kalinamall.ru i kopiruet dist na NETLOGON. + Obnovlyaet klon RDP-login-monitor s upstream git i kopiruet dist na NETLOGON. .DESCRIPTION - Dlya servera publikatsii (napr. DC3). Remote: git.kalinamall.ru (kalinamall). + Dlya servera publikatsii (napr. DC3). Po umolchaniyu GitHub (github.com/PTah). + Na zakrytom zerkale ukazhite -GitUrl URL vashego Gitea. Posle fetch: vsegda reset --hard na kalinamall/main (bez merge), zatem clean -fd. Kopiruyutsya: polnyj spisok v Docs/deploy-netlogon-publish.md. .EXAMPLE @@ -14,7 +15,7 @@ param( [string]$RepoPath = 'C:\Soft\Git\RDP-login-monitor', [string]$NetlogonDest = '\\b26\NETLOGON\RDP-login-monitor', - [string]$GitUrl = 'https://git.kalinamall.ru/PapaTramp/RDP-login-monitor.git', + [string]$GitUrl = 'https://github.com/PTah/RDP-login-monitor.git', [string]$GitBranch = 'main', [string]$LogFile = 'C:\soft\Logs\update-rdp-monitor.log', [switch]$SkipGitClean