Commit Graph

160 Commits

Author SHA1 Message Date
Pouzor 45189e2748 fix: generate test config.yml in conftest for CI
Login route reads config.yml for credentials but it is gitignored.
Session-scoped autouse fixture now writes a minimal config.yml to a
temp path and patches settings.config_path so test_scan.py auth
fixtures work in CI without a real config file.
2026-03-09 09:30:53 +01:00
Pouzor 8da39327ab test: add tests for status WebSocket and scheduler
- test_status.py: 8 tests covering WS auth rejection/acceptance, broadcast_status (dead connection removal, no response_time, no connections), broadcast_scan_update
- test_scheduler.py: 9 tests covering _load_interval variants, _run_status_checks DB update/last_seen/error handling, start/stop lifecycle
- scheduler.py: reinitialize AsyncIOScheduler on each start() to avoid stale event loop across test restarts
2026-03-09 01:32:31 +01:00
Pouzor 20fe4ed9e4 fix: set SECRET_KEY in test conftest before app imports for CI 2026-03-09 00:17:59 +01:00
Pouzor 41e29ac199 fix: suppress mypy false positive on pydantic-settings required field 2026-03-09 00:15:42 +01:00
Pouzor 6ace796c8b security: fix C2, H5 and M1
C2 - JWT token was stored in localStorage (XSS-accessible):
  - Switch Zustand persist storage from localStorage to sessionStorage
  - Token is now scoped to the current tab and cleared on browser close

H5 - docker-compose had unsafe SECRET_KEY fallback:
  - Replace ${SECRET_KEY:-change_me_in_production} with :? syntax
  - Docker Compose now aborts with a clear error if SECRET_KEY is unset

M1 - Login endpoint had timing leak allowing username enumeration:
  - Always call verify_password() regardless of username match
  - Use hmac.compare_digest() for constant-time username comparison
  - Both checks run every time; attacker cannot distinguish wrong
    username from wrong password via response timing
2026-03-09 00:13:01 +01:00
Pouzor dbfc8a2a32 security: fix C3, C1 and H1
C3 - config.yml contains credentials, remove from git tracking:
  - Add backend/config.yml to .gitignore
  - git rm --cached to untrack it
  - Add backend/config.yml.example with instructions

C1 - SECRET_KEY must come from .env, no unsafe default:
  - Remove hardcoded "change_me_in_production" default from config.py
  - App now fails to start if SECRET_KEY is not set (pydantic required field)
  - Generate real random key in backend/.env (gitignored)
  - Add backend/.env.example for new contributors

H1 - WebSocket /ws/status was unauthenticated:
  - Backend: require ?token= query param, validate via decode_token(),
    close with code 1008 (Policy Violation) if missing or invalid
  - Frontend: append ?token=<jwt> to WebSocket URL
2026-03-09 00:05:10 +01:00
Pouzor 5db2c69aee feat: remove minimap from canvas 2026-03-08 22:57:41 +01:00
Pouzor 220d831cf1 feat: add CPL / Powerline node type with PlugZap icon 2026-03-08 20:42:00 +01:00
Pouzor 3312742f4c feat: add printer and computer node types with icons 2026-03-08 17:48:53 +01:00
Pouzor c6fe984511 feat: open edit modal immediately after approving a pending device 2026-03-08 14:00:03 +01:00
Pouzor f156d9dd95 fix: edges appear immediately + sync virtual link with LXC parent_id
- Normalize stub handle IDs (top-t/bottom-t → top/bottom) in canvasStore.onConnect
  so React Flow can locate the handle and render edges without save+reload
- Also normalize on save in App.tsx as a safety net for persisted handle IDs
- Auto-create virtual edge (LXC top → Proxmox bottom) when parent_id is set
  via the node edit modal, and remove it when parent_id is cleared/changed
- Auto-set LXC/VM parent_id when a virtual edge is drawn to/from a Proxmox node
2026-03-08 13:47:30 +01:00
Pouzor d829a4821e fix: use explicit source+hidden-target handles for reliable bidirectional snapping
source handles: visible, can initiate drag from top or bottom
target handles: invisible (opacity:0, 12x12px), overlap the source at same
position — React Flow detects them for snapping and shows visual feedback
without the user seeing a second dot. Ensures bottom→top connections work.
2026-03-08 13:10:25 +01:00
Pouzor be18bcc6d9 fix: add source+target handles at top and bottom so all snatch points work
connectionMode=loose alone does not reliably make source handles act as
drop targets. Each position now has both a source handle (to initiate
drag) and a target handle (to receive drops). They overlap visually as
one dot but support full bidirectional connections.
2026-03-08 12:26:21 +01:00
Pouzor 3e1edd9458 fix: make top handles type=source so connections can be dragged from them
React Flow only allows initiating a drag from type=source handles.
Top handles were type=target so users could never start a connection
from the top of any node. With connectionMode=loose, source-to-source
connections are already allowed, so all handles can now be source.
2026-03-08 12:16:21 +01:00
Pouzor dc96588655 fix: allow parent-to-child connections in React Flow
React Flow blocks connections involving a parentId parent/child pair by
default to prevent hierarchy cycles. Override with isValidConnection
that only rejects self-loops (source === target), allowing explicit
edges between Proxmox container nodes and their nested VMs/LXCs.
2026-03-08 12:12:26 +01:00
Pouzor 409e6fd6b9 fix: show all explicit edges including proxmox-to-child links
The visibleEdges filter was silently dropping any edge between a
container-mode Proxmox and its children, even ones the user explicitly
drew. Since no edges are auto-generated, the filter only blocked
intentional connections. Removed it entirely.
2026-03-08 12:08:10 +01:00
Pouzor 0cd263537f test: cover custom_icon persistence and cctv icon presence 2026-03-08 12:01:46 +01:00
Pouzor 4511763bac fix: persist custom_icon on canvas save + add CCTV icon
- NodeSave schema was missing custom_icon field — icon reset to default on reload
- handleSave was not including custom_icon in the payload
- CameraNode now uses Cctv icon (clearer than Camera)
- Added 'cctv' entry to ICON_REGISTRY for the icon picker
2026-03-08 12:00:11 +01:00
Pouzor 88634aeb1d feat: add Camera node type + flag RTSP/camera ports during scan
- New 'camera' node type with Camera icon (frontend + types)
- Scanner fingerprint: camera ports (554, 8554, 37777, 34567, 2020) now suggest 'camera' instead of 'iot'
- service_signatures.json: all camera/NVR entries updated to suggested_node_type=camera
- 'camera' added to priority list in suggest_node_type (above iot)
2026-03-08 11:55:26 +01:00
Pouzor b334bf69de fix: register cluster in edgeTypes so HomelableEdge renders label after reload 2026-03-08 11:51:25 +01:00
Pouzor 8e711d9016 fix: cluster edge type and label now persisted on connect
- canvasStore.onConnect was hardcoding type=ethernet and ignoring edgeData fields (type, label, color, etc.)
- EdgeModal had no key, so useState was not reset between connections — initial prop ignored
- Added key based on source/target/handles so modal re-mounts for each new connection
2026-03-08 11:48:02 +01:00
Pouzor e306cd7b49 test: add missing tests for cluster edges, handles, colors, and none check method
- backend: cluster edge creation with source/target handles, handle persistence through PATCH
- frontend: cluster color in edgeColors, onConnect preserves sourceHandle/targetHandle
2026-03-08 11:41:09 +01:00
Pouzor 8de4f9b32d fix: pre-select cluster type in EdgeModal when connecting via cluster handles 2026-03-08 11:35:30 +01:00
Pouzor f43a94a403 fix: persist sourceHandle/targetHandle so cluster edges survive reload 2026-03-08 11:32:38 +01:00
Pouzor 0034100286 feat: add cluster edge type — orange dashed, for Proxmox cluster links 2026-03-08 11:26:42 +01:00
Pouzor a63e248427 fix: cluster handles are bidirectional — connectionMode loose, both type source 2026-03-08 11:24:18 +01:00
Pouzor 2fcc9eba80 fix: reduce cluster handles to one per side, normal size 2026-03-08 01:41:36 +01:00
Pouzor f93afd0646 test: add coverage for none check method, re-scan update, icon registry 2026-03-08 01:12:32 +01:00
Pouzor b2a6651db7 fix: show cluster handles in both container and simple mode on Proxmox node 2026-03-08 01:05:13 +01:00
Pouzor 1364b30eb4 feat: add left/right cluster handles on Proxmox group node 2026-03-08 00:44:22 +01:00
Pouzor 627f67336f feat: add 'none' check method — node always appears online 2026-03-08 00:41:17 +01:00
Pouzor 2441d72b41 fix: banner_regex sigs require actual banner match — prevents wrong type inference
Banner-specific signatures (e.g. AdGuard on port 3000) were incorrectly
matching when nmap returned no banner, causing wrong suggested_node_type
(e.g. 'router' for a media server). Now a signature with banner_regex is
only matched when a banner is present AND matches the regex.

Also make _PORT_TYPE_HINTS always contribute to suggest_node_type found set
(not just as elif fallback) so well-known ports like 8006 still resolve to
proxmox even when a generic sig also matched.
2026-03-07 23:31:33 +01:00
Pouzor 6e6041d871 fix: re-scan updates services on existing pending devices instead of skipping 2026-03-07 23:09:54 +01:00
Pouzor d98bfba506 feat: add custom icon picker to node create/edit modal
- Add 65+ icons across 7 categories (Infrastructure, Media, Monitoring,
  Storage, Security, Automation, Dev & Containers, Communications) covering
  popular self-hosted apps: Home Assistant, Jellyfin, Plex, Grafana, Portainer,
  Pi-hole, Vaultwarden, Gitea, Nextcloud, Node-RED, Frigate, etc.
- New nodeIcons.ts utility with ICON_REGISTRY, ICON_MAP and resolveNodeIcon()
- Inline icon picker in NodeModal: collapsible panel with search + grid grouped
  by category; click to select, click again or Reset to revert to type default
- BaseNode uses resolveNodeIcon() so custom icon renders live on canvas
- Add custom_icon field to NodeData type, NodeBase/NodeUpdate schemas, Node ORM
  model, and database.py idempotent ALTER TABLE migration
2026-03-07 23:01:30 +01:00
Pouzor 1a72f9fa20 feat: improve service detection — expanded signatures, port hints, better nmap args
- Expand service_signatures.json from 35 → ~120 entries covering *arr apps,
  smart-home (HA, MQTT, ESPHome), cameras (RTSP, Dahua, Tapo, Reolink),
  network gear (MikroTik, UniFi, Pi-hole), auth (Authelia, Authentik, Vault),
  monitoring (Grafana, InfluxDB, Loki, Uptime Kuma), containers (Portainer),
  and many more home lab services
- Expand nmap port range to cover home lab ports (8989, 7878, 8123, 554, 1883, etc.)
  and increase --host-timeout from 30s to 120s for reliable -sV detection
- Add _PORT_TYPE_HINTS fallback in suggest_node_type for ports without signatures
  (cameras→iot, MQTT→iot, Proxmox→proxmox, MikroTik→router, etc.)
- Show actual port/protocol (e.g. TCP/9999) instead of "unknown_service" so
  all open ports are visible even when not matched
- Update tests to reflect new unknown-port label format
2026-03-07 16:33:03 +01:00
Pouzor bc30250398 feat: pending device detail modal with services and actions
- Click any pending device row to open a detail modal
- Modal shows IP, hostname, MAC, OS, suggested type, discovered_at
- Service list with port/protocol/service_name, colored dot by category
- Approve / Hide / Delete buttons with matching color coding
- List items now show IP, service count, hostname and suggested type at a glance
2026-03-07 16:11:53 +01:00
Pouzor bec699ba93 feat: non-blocking scan with progressive device discovery
Backend:
- asyncio.to_thread(_nmap_scan) — nmap no longer blocks the event loop
- Commit each discovered device immediately (previously one bulk commit at end)
- Update ScanRun.devices_found after each device so history panel shows live count
- broadcast_scan_update() pushes {type: scan_device_found} WS event per device
- Refactor broadcast_status to shared _broadcast() helper, adds type: "status" field

Frontend:
- useStatusPolling handles both WS message types (status / scan_device_found)
- canvasStore: scanEventTs + notifyScanDeviceFound() action
- PendingDevicesPanel auto-refreshes when WS scan event is received
2026-03-07 16:06:44 +01:00
Pouzor 974e782057 fix: resolve all 64 mypy errors across backend
- Add dict[str, Any] / list[Any] type params throughout (fingerprint, models, schemas, scanner, status_checker)
- Add return type annotations to all route functions (nodes, edges, canvas, scan, auth, status, main)
- Fix no-any-return in security.py: cast pwd/jwt results to bool/str explicitly
- Fix canvas.py: use model_validate() for NodeResponse/EdgeResponse, rename db_node/db_edge upsert vars
- Fix scheduler.py: rename 'result' → 'check_result' to avoid type collision
- Fix get_db() return type: AsyncGenerator[AsyncSession, None]
- Add types-PyYAML for yaml import stubs
- Fix scanner.py: remove unnecessary type: ignore comment (nmap has stubs)
- Fix scan.py: wrap scalars().all() with list() for Sequence→list compatibility
2026-03-07 15:48:41 +01:00
Pouzor 1811afa749 fix: upgrade fastapi to 0.135.1, fix starlette CVEs, update auth test assertions
- fastapi 0.115.0 → 0.135.1 pulls starlette 0.52.1 (fixes CVE-2024-47874, CVE-2025-54121)
- pip-audit: ignore CVE-2024-23342 (ecdsa Minerva attack, no fix exists; app uses HS256 only)
- Update auth guard tests: FastAPI 0.135 returns 401 (not 403) when Bearer token is missing
2026-03-07 15:18:28 +01:00
Pouzor e5262b4b71 fix: replace safety scan with pip-audit (no login required)
safety scan requires interactive account login, breaking CI.
pip-audit provides equivalent vulnerability scanning without auth.
2026-03-07 15:11:59 +01:00
Pouzor fccbdad409 fix: patch CVEs — upgrade python-jose 3.3→3.5, python-multipart 0.0.12→0.0.22; use safety scan 2026-03-07 15:08:04 +01:00
Pouzor 4235f10331 chore: add coverage/ to gitignore, clean up config.yml formatting 2026-03-07 15:03:18 +01:00
Pouzor ba91d0f545 test: improve coverage across frontend and backend
Frontend (22 → 37 tests):
- canvasStore: add tests for onNodesChange, onEdgesChange, onConnect,
  addNode with parentId, updateEdge, deleteEdge, setProxmoxContainerMode
  ON/OFF, loadCanvas parent-before-child ordering
- edgeColors: 6 tests for EDGE_DEFAULT_COLORS (all types, hex format, values)

Backend (40 → 80 tests):
- test_canvas (new): load empty canvas, default viewport, save creates/updates/
  deletes nodes+edges, viewport upsert, custom_colors, edge custom_color+path_style,
  auth guard
- test_fingerprint (new): match_port (known, unknown, wrong protocol, banner match,
  banner no-match, no banner), fingerprint_ports (matched, unknown, mixed, empty,
  default protocol), suggest_node_type (proxmox, server, generic, priority)
- test_nodes: update/delete 404, custom_colors CRUD, container_mode CRUD, auth guard
- test_edges: update edge, update/delete 404, custom_color, path_style, auth guard
2026-03-07 15:01:00 +01:00
Pouzor 07d8c4e58b feat: per-link path style toggle (bezier / smooth step) 2026-03-07 14:46:55 +01:00
Pouzor 8437f5ef49 feat: customizable link color per edge
- Add custom_color field to EdgeData type, Edge DB model and all schemas
- HomelableEdge applies custom_color as stroke override (before selected highlight)
- EDGE_DEFAULT_COLORS extracted to utils/edgeColors.ts (react-refresh compliant)
- EdgeModal: color picker row showing effective color (custom or type default)
  with hex value, Reset button when custom color is active
- Auto-migration adds custom_color column to edges table
2026-03-07 14:42:34 +01:00
Pouzor 7dd500feee fix: always show node border color, widen to 2px on selection 2026-03-07 14:37:46 +01:00
Pouzor 37c963cf96 feat: per-node custom color styling (border, background, icon)
- Add resolveNodeColors() utility merging type defaults with per-node overrides
- Default colors per node type (cyan=isp/router/lxc/ap, green=switch/nas,
  purple=server/vm, orange=proxmox, amber=iot, gray=generic)
- Remove glowColor prop from BaseNode — colors now come from node data
- ProxmoxGroupNode uses resolveNodeColors for group border/header/icon
- NodeModal: Appearance section with 3 color swatches (border, background, icon)
  — click swatch to open native color picker; Reset to defaults button
- custom_colors persisted as JSON in DB (backend model + schemas + migration)
- 7 new unit tests for resolveNodeColors covering all node types + partial overrides
2026-03-07 14:31:05 +01:00
Pouzor 0fe3c6390a feat: service badges with clickable port links in detail panel
- Services now show as full-width rows with color-coded category dot
- HTTP/HTTPS services are clickable links (opens ip:port in new tab)
- Supports ports: 80, 443, 8080, 8443, 8000, 3000, 8888, 9000 + name-based detection
- ExternalLink icon shown on clickable services
- Category color coding: web=cyan, db=purple, monitoring=green, storage=amber, security=red
- Service count shown in section header
2026-03-07 14:21:15 +01:00
Pouzor 4fb9a8ee45 feat: edge edit mode + proxmox container mode toggle
- Double-click any link to open Edit Link modal (type, label, VLAN ID, delete)
- Add updateEdge / deleteEdge actions to canvasStore
- Add container_mode field to proxmox nodes (backend model, schemas, migration)
- NodeModal shows container toggle for proxmox type (defaults ON)
- ProxmoxGroupNode renders as regular BaseNode when container_mode is OFF
- setProxmoxContainerMode store action handles structural changes atomically
  (children parentId/extent, node dimensions)
- CanvasContainer filters edges between container proxmox and its children
- Canvas load respects container_mode when assigning parentId/extent
2026-03-07 14:15:08 +01:00
Pouzor 9eba62c5b5 fix: save button now fully persists canvas to DB
Root cause: handleAddNode/handleEdgeConfirm only updated Zustand store,
never creating records in the DB. canvasApi.save() only updated positions
of existing nodes, so nothing survived a page refresh.

Fix: save now sends the full canvas state (all nodes + edges + data) and
the backend does a full sync — upsert incoming, delete anything removed.
This means Save is the single source of truth: no need to call individual
create/update/delete APIs for every drag or edit.
2026-03-07 01:54:59 +01:00