PapaTramp
80320ae698
fix: harden SAC security per audit (0.4.15)
...
Close audit findings: anti-spoof client IP for login rate limit, JWT/CORS
enforce on startup, SSH host-key verification and sudo via stdin, optional
WinRM HTTPS, SSE httpOnly cookie auth, ingest body limit, ILIKE escaping,
and HMAC API key hashing with legacy SHA-256 fallback.
2026-07-07 19:32:12 +10:00
PapaTramp
54c1d96933
fix(backend): non-login SSH and strict loginctl parse, SSH retry (0.20.31)
...
Co-authored-by: Cursor <cursoragent@cursor.com >
2026-06-22 10:54:56 +10:00
PapaTramp
ec5ec62240
fix: enforce SAC git URL when updating ssh-monitor agents (0.20.8)
...
Pass REPO_URL/GIT_BRANCH from agent settings over SSH, preflight git remotes on stale hosts, and stop using GitHub origin on routers.
2026-06-20 19:28:14 +10:00
PapaTramp
c21043d845
feat: bootstrap ssh-monitor updater when missing on host (0.20.2)
...
SAC now clones the ssh-monitor repo and installs update_ssh_monitor.sh before running the update when the remote updater script is absent.
2026-06-20 17:01:06 +10:00
PapaTramp
2eb06acb5b
feat: SSH card UX, agent version sync, persistent ssh_admin_ok (0.11.5)
...
Silent SSH probe on host card open; manual test feedback auto-hides. Persist ssh_admin_ok in DB (migration 019). After agent update read version from host and refresh UI.
2026-06-20 01:01:56 +10:00
PapaTramp
6fea8262fb
fix: skip invalid/unresolvable SSH targets before connect (0.11.2)
...
Do not use human display_name as SSH host; skip short names that do not resolve on SAC (ubabuba -> IPv4 only).
2026-06-20 00:39:29 +10:00
PapaTramp
2e839e0b16
fix: SSH sudo without TTY for non-root Linux admin (0.11.1)
...
Probe commands run without sudo; privileged update uses sudo -S. Add SSH connect and Linux admin API tests.
2026-06-20 00:36:12 +10:00
PapaTramp
cc8f50de89
feat: Linux SSH admin and remote ssh-monitor update (0.11.0)
2026-06-20 00:25:35 +10:00