NPM stays the source of truth for which domains exist; this adds an optional enrichment layer on top of the existing NPM_INCLUDE_PATTERNS filtering, gated behind ADMIN_PASSWORD (disabled entirely if unset). - Force-show/force-hide any NPM-discovered host regardless of what the include pattern would otherwise decide - Per-host display name and check path overrides - Manually add targets that aren't proxied through NPM at all - Every override falls back to the NPM-derived default when unset — a host with no override behaves exactly as before this existed Host overrides and manual targets live in SQLite (better-sqlite3, WAL mode) and are re-read on every 60s check tick, so admin changes take effect within one cycle with no restart. NPM host discovery keeps its original 10-minute cadence — only the local override reads happen every tick. The core merge (NPM hosts + overrides + manual targets -> final check list) is a pure function in targets.ts, kept separate from the checker's I/O for testability. Verified end-to-end against a local mock NPM server (auth, force-show/hide, rename, custom check path, manual targets, reset-to-default all propagate correctly) and against the actual Docker build/runtime (better-sqlite3's native addon builds and loads correctly in the Alpine image). Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
47 lines
1.6 KiB
TypeScript
47 lines
1.6 KiB
TypeScript
export interface ProxyHost {
|
|
domain_names: string[];
|
|
forward_host: string;
|
|
forward_port: number;
|
|
enabled: boolean;
|
|
}
|
|
|
|
const NPM_BASE = process.env.NPM_BASE_URL ?? 'http://localhost:81';
|
|
const NPM_EMAIL = process.env.NPM_EMAIL ?? '';
|
|
const NPM_SECRET = process.env.NPM_SECRET ?? '';
|
|
|
|
const rawPatterns = (process.env.NPM_INCLUDE_PATTERNS ?? '\\.goonk\\.se$,\\.dev\\.xplwd\\.com$')
|
|
.split(',').map(p => new RegExp(p.trim()));
|
|
export const INCLUDE_PATTERNS = rawPatterns;
|
|
|
|
export function matchesIncludePatterns(domain: string): boolean {
|
|
return INCLUDE_PATTERNS.some(p => p.test(domain));
|
|
}
|
|
|
|
let token: string | null = null;
|
|
let tokenExpiry = 0;
|
|
|
|
async function getToken(): Promise<string> {
|
|
if (token && Date.now() < tokenExpiry) return token;
|
|
const res = await fetch(`${NPM_BASE}/api/tokens`, {
|
|
method: 'POST',
|
|
headers: { 'Content-Type': 'application/json' },
|
|
body: JSON.stringify({ identity: NPM_EMAIL, secret: NPM_SECRET }),
|
|
});
|
|
const data = await res.json() as { token: string; expires: string };
|
|
token = data.token;
|
|
tokenExpiry = new Date(data.expires).getTime() - 60_000;
|
|
return token;
|
|
}
|
|
|
|
// Every enabled proxy host, regardless of NPM_INCLUDE_PATTERNS — the admin
|
|
// UI needs the full set to let you force-show something the pattern would
|
|
// otherwise exclude. checker.ts applies the pattern (or an override) itself.
|
|
export async function fetchAllProxyHosts(): Promise<ProxyHost[]> {
|
|
const tok = await getToken();
|
|
const res = await fetch(`${NPM_BASE}/api/nginx/proxy-hosts`, {
|
|
headers: { Authorization: `Bearer ${tok}` },
|
|
});
|
|
const all = await res.json() as ProxyHost[];
|
|
return all.filter(h => h.enabled);
|
|
}
|