Commit Graph

171 Commits

Author SHA1 Message Date
Pouzor 452f3b0860 feat: add one-liner install script
curl -fsSL https://raw.githubusercontent.com/Pouzor/homelable/main/install.sh | bash

Handles fresh install and updates. Pulls prebuilt images, creates .env from
.env.example on first run. Update README Quick Start accordingly.
2026-03-09 12:03:27 +01:00
Pouzor 6a7113193f feat: add GitHub Actions Docker publish workflow and prebuilt install
- Build and push backend/frontend images to ghcr.io on every push to main and on version tags
- Add docker-compose.prebuilt.yml for pull-based install (no clone needed)
- Update README Quick Start with inline install one-liner using prebuilt images
2026-03-09 12:01:04 +01:00
Pouzor f3a9d95b18 change readme 2026-03-09 11:59:02 +01:00
Pouzor 2de5a5b3aa docs: update README configuration section to reflect .env-based setup
- Replace config.yml references with .env variables
- Document single-quote requirement for AUTH_PASSWORD_HASH
- Fix dev mode setup to copy from root .env.example
2026-03-09 11:57:11 +01:00
Pouzor 5078f4af92 fix: quote AUTH_PASSWORD_HASH in .env.example to prevent Docker dollar-sign interpolation
Bcrypt hashes contain $ chars that Docker Compose interpolates as variables.
Single-quoting the value prevents interpolation in both Docker Compose and python-dotenv.
2026-03-09 11:53:37 +01:00
Pouzor 6f46913b80 fix: use env_file in docker-compose to avoid bcrypt hash dollar-sign misparse
Docker Compose interpolates \$ in environment values as variable refs, breaking
the bcrypt hash (\$2b\$12\$...). Switching to env_file passes values verbatim.
2026-03-09 11:45:35 +01:00
Pouzor 84860b0d99 fix: consolidate .env.example to root, add missing auth defaults
- Add AUTH_USERNAME, AUTH_PASSWORD_HASH (admin/admin) to root .env.example
- Remove duplicate backend/.env.example — root file is the single source of truth
- Fix fresh-install login failure caused by missing password hash
2026-03-09 11:42:00 +01:00
Pouzor dafcd12e40 fix: default admin/admin hash in .env.example, remove required constraint on AUTH_PASSWORD_HASH 2026-03-09 11:32:32 +01:00
Pouzor a56204a5f2 refactor: replace config.yml with .env for all configuration
All settings (auth credentials, scanner ranges, status_checker interval)
now live in a single .env file via pydantic-settings. config.yml and
config.yml.example are deleted.

- Settings: add auth_username, auth_password_hash, scanner_ranges,
  status_checker_interval; add load_overrides()/save_overrides() for
  persisting runtime changes to data/scan_config.json
- auth.py: read credentials directly from settings
- scan.py: read ranges/interval from settings; write-back via save_overrides()
- scheduler.py: read interval directly from settings
- main.py: call settings.load_overrides() at startup
- docker-compose.yml: remove config.yml volume mount, add new env vars
- conftest.py: set settings fields directly instead of writing a temp config.yml
2026-03-09 11:26:49 +01:00
Pouzor acc5bc6a64 fix: cast Service[] to ServiceInfo[] in pending device approve 2026-03-09 11:09:03 +01:00
Pouzor c6733e4dcd fix: resolve TypeScript build errors blocking Docker image
- nodeColors.ts: add missing camera/printer/computer/cpl entries to Record<NodeType, NodeColors>
- CanvasContainer.tsx: use ConnectionMode enum instead of bare string literal
- export.ts: cast style object to Partial<CSSStyleDeclaration> for CSS custom property
- Sidebar.tsx: cast suggested_type to NodeType to satisfy NodeData type
2026-03-09 11:07:22 +01:00
Pouzor 45189e2748 fix: generate test config.yml in conftest for CI
Login route reads config.yml for credentials but it is gitignored.
Session-scoped autouse fixture now writes a minimal config.yml to a
temp path and patches settings.config_path so test_scan.py auth
fixtures work in CI without a real config file.
2026-03-09 09:30:53 +01:00
Pouzor 8da39327ab test: add tests for status WebSocket and scheduler
- test_status.py: 8 tests covering WS auth rejection/acceptance, broadcast_status (dead connection removal, no response_time, no connections), broadcast_scan_update
- test_scheduler.py: 9 tests covering _load_interval variants, _run_status_checks DB update/last_seen/error handling, start/stop lifecycle
- scheduler.py: reinitialize AsyncIOScheduler on each start() to avoid stale event loop across test restarts
2026-03-09 01:32:31 +01:00
Pouzor 20fe4ed9e4 fix: set SECRET_KEY in test conftest before app imports for CI 2026-03-09 00:17:59 +01:00
Pouzor 41e29ac199 fix: suppress mypy false positive on pydantic-settings required field 2026-03-09 00:15:42 +01:00
Pouzor 6ace796c8b security: fix C2, H5 and M1
C2 - JWT token was stored in localStorage (XSS-accessible):
  - Switch Zustand persist storage from localStorage to sessionStorage
  - Token is now scoped to the current tab and cleared on browser close

H5 - docker-compose had unsafe SECRET_KEY fallback:
  - Replace ${SECRET_KEY:-change_me_in_production} with :? syntax
  - Docker Compose now aborts with a clear error if SECRET_KEY is unset

M1 - Login endpoint had timing leak allowing username enumeration:
  - Always call verify_password() regardless of username match
  - Use hmac.compare_digest() for constant-time username comparison
  - Both checks run every time; attacker cannot distinguish wrong
    username from wrong password via response timing
2026-03-09 00:13:01 +01:00
Pouzor dbfc8a2a32 security: fix C3, C1 and H1
C3 - config.yml contains credentials, remove from git tracking:
  - Add backend/config.yml to .gitignore
  - git rm --cached to untrack it
  - Add backend/config.yml.example with instructions

C1 - SECRET_KEY must come from .env, no unsafe default:
  - Remove hardcoded "change_me_in_production" default from config.py
  - App now fails to start if SECRET_KEY is not set (pydantic required field)
  - Generate real random key in backend/.env (gitignored)
  - Add backend/.env.example for new contributors

H1 - WebSocket /ws/status was unauthenticated:
  - Backend: require ?token= query param, validate via decode_token(),
    close with code 1008 (Policy Violation) if missing or invalid
  - Frontend: append ?token=<jwt> to WebSocket URL
2026-03-09 00:05:10 +01:00
Pouzor 5db2c69aee feat: remove minimap from canvas 2026-03-08 22:57:41 +01:00
Pouzor 220d831cf1 feat: add CPL / Powerline node type with PlugZap icon 2026-03-08 20:42:00 +01:00
Pouzor 3312742f4c feat: add printer and computer node types with icons 2026-03-08 17:48:53 +01:00
Pouzor c6fe984511 feat: open edit modal immediately after approving a pending device 2026-03-08 14:00:03 +01:00
Pouzor f156d9dd95 fix: edges appear immediately + sync virtual link with LXC parent_id
- Normalize stub handle IDs (top-t/bottom-t → top/bottom) in canvasStore.onConnect
  so React Flow can locate the handle and render edges without save+reload
- Also normalize on save in App.tsx as a safety net for persisted handle IDs
- Auto-create virtual edge (LXC top → Proxmox bottom) when parent_id is set
  via the node edit modal, and remove it when parent_id is cleared/changed
- Auto-set LXC/VM parent_id when a virtual edge is drawn to/from a Proxmox node
2026-03-08 13:47:30 +01:00
Pouzor d829a4821e fix: use explicit source+hidden-target handles for reliable bidirectional snapping
source handles: visible, can initiate drag from top or bottom
target handles: invisible (opacity:0, 12x12px), overlap the source at same
position — React Flow detects them for snapping and shows visual feedback
without the user seeing a second dot. Ensures bottom→top connections work.
2026-03-08 13:10:25 +01:00
Pouzor be18bcc6d9 fix: add source+target handles at top and bottom so all snatch points work
connectionMode=loose alone does not reliably make source handles act as
drop targets. Each position now has both a source handle (to initiate
drag) and a target handle (to receive drops). They overlap visually as
one dot but support full bidirectional connections.
2026-03-08 12:26:21 +01:00
Pouzor 3e1edd9458 fix: make top handles type=source so connections can be dragged from them
React Flow only allows initiating a drag from type=source handles.
Top handles were type=target so users could never start a connection
from the top of any node. With connectionMode=loose, source-to-source
connections are already allowed, so all handles can now be source.
2026-03-08 12:16:21 +01:00
Pouzor dc96588655 fix: allow parent-to-child connections in React Flow
React Flow blocks connections involving a parentId parent/child pair by
default to prevent hierarchy cycles. Override with isValidConnection
that only rejects self-loops (source === target), allowing explicit
edges between Proxmox container nodes and their nested VMs/LXCs.
2026-03-08 12:12:26 +01:00
Pouzor 409e6fd6b9 fix: show all explicit edges including proxmox-to-child links
The visibleEdges filter was silently dropping any edge between a
container-mode Proxmox and its children, even ones the user explicitly
drew. Since no edges are auto-generated, the filter only blocked
intentional connections. Removed it entirely.
2026-03-08 12:08:10 +01:00
Pouzor 0cd263537f test: cover custom_icon persistence and cctv icon presence 2026-03-08 12:01:46 +01:00
Pouzor 4511763bac fix: persist custom_icon on canvas save + add CCTV icon
- NodeSave schema was missing custom_icon field — icon reset to default on reload
- handleSave was not including custom_icon in the payload
- CameraNode now uses Cctv icon (clearer than Camera)
- Added 'cctv' entry to ICON_REGISTRY for the icon picker
2026-03-08 12:00:11 +01:00
Pouzor 88634aeb1d feat: add Camera node type + flag RTSP/camera ports during scan
- New 'camera' node type with Camera icon (frontend + types)
- Scanner fingerprint: camera ports (554, 8554, 37777, 34567, 2020) now suggest 'camera' instead of 'iot'
- service_signatures.json: all camera/NVR entries updated to suggested_node_type=camera
- 'camera' added to priority list in suggest_node_type (above iot)
2026-03-08 11:55:26 +01:00
Pouzor b334bf69de fix: register cluster in edgeTypes so HomelableEdge renders label after reload 2026-03-08 11:51:25 +01:00
Pouzor 8e711d9016 fix: cluster edge type and label now persisted on connect
- canvasStore.onConnect was hardcoding type=ethernet and ignoring edgeData fields (type, label, color, etc.)
- EdgeModal had no key, so useState was not reset between connections — initial prop ignored
- Added key based on source/target/handles so modal re-mounts for each new connection
2026-03-08 11:48:02 +01:00
Pouzor e306cd7b49 test: add missing tests for cluster edges, handles, colors, and none check method
- backend: cluster edge creation with source/target handles, handle persistence through PATCH
- frontend: cluster color in edgeColors, onConnect preserves sourceHandle/targetHandle
2026-03-08 11:41:09 +01:00
Pouzor 8de4f9b32d fix: pre-select cluster type in EdgeModal when connecting via cluster handles 2026-03-08 11:35:30 +01:00
Pouzor f43a94a403 fix: persist sourceHandle/targetHandle so cluster edges survive reload 2026-03-08 11:32:38 +01:00
Pouzor 0034100286 feat: add cluster edge type — orange dashed, for Proxmox cluster links 2026-03-08 11:26:42 +01:00
Pouzor a63e248427 fix: cluster handles are bidirectional — connectionMode loose, both type source 2026-03-08 11:24:18 +01:00
Pouzor 2fcc9eba80 fix: reduce cluster handles to one per side, normal size 2026-03-08 01:41:36 +01:00
Pouzor f93afd0646 test: add coverage for none check method, re-scan update, icon registry 2026-03-08 01:12:32 +01:00
Pouzor b2a6651db7 fix: show cluster handles in both container and simple mode on Proxmox node 2026-03-08 01:05:13 +01:00
Pouzor 1364b30eb4 feat: add left/right cluster handles on Proxmox group node 2026-03-08 00:44:22 +01:00
Pouzor 627f67336f feat: add 'none' check method — node always appears online 2026-03-08 00:41:17 +01:00
Pouzor 2441d72b41 fix: banner_regex sigs require actual banner match — prevents wrong type inference
Banner-specific signatures (e.g. AdGuard on port 3000) were incorrectly
matching when nmap returned no banner, causing wrong suggested_node_type
(e.g. 'router' for a media server). Now a signature with banner_regex is
only matched when a banner is present AND matches the regex.

Also make _PORT_TYPE_HINTS always contribute to suggest_node_type found set
(not just as elif fallback) so well-known ports like 8006 still resolve to
proxmox even when a generic sig also matched.
2026-03-07 23:31:33 +01:00
Pouzor 6e6041d871 fix: re-scan updates services on existing pending devices instead of skipping 2026-03-07 23:09:54 +01:00
Pouzor d98bfba506 feat: add custom icon picker to node create/edit modal
- Add 65+ icons across 7 categories (Infrastructure, Media, Monitoring,
  Storage, Security, Automation, Dev & Containers, Communications) covering
  popular self-hosted apps: Home Assistant, Jellyfin, Plex, Grafana, Portainer,
  Pi-hole, Vaultwarden, Gitea, Nextcloud, Node-RED, Frigate, etc.
- New nodeIcons.ts utility with ICON_REGISTRY, ICON_MAP and resolveNodeIcon()
- Inline icon picker in NodeModal: collapsible panel with search + grid grouped
  by category; click to select, click again or Reset to revert to type default
- BaseNode uses resolveNodeIcon() so custom icon renders live on canvas
- Add custom_icon field to NodeData type, NodeBase/NodeUpdate schemas, Node ORM
  model, and database.py idempotent ALTER TABLE migration
2026-03-07 23:01:30 +01:00
Pouzor 1a72f9fa20 feat: improve service detection — expanded signatures, port hints, better nmap args
- Expand service_signatures.json from 35 → ~120 entries covering *arr apps,
  smart-home (HA, MQTT, ESPHome), cameras (RTSP, Dahua, Tapo, Reolink),
  network gear (MikroTik, UniFi, Pi-hole), auth (Authelia, Authentik, Vault),
  monitoring (Grafana, InfluxDB, Loki, Uptime Kuma), containers (Portainer),
  and many more home lab services
- Expand nmap port range to cover home lab ports (8989, 7878, 8123, 554, 1883, etc.)
  and increase --host-timeout from 30s to 120s for reliable -sV detection
- Add _PORT_TYPE_HINTS fallback in suggest_node_type for ports without signatures
  (cameras→iot, MQTT→iot, Proxmox→proxmox, MikroTik→router, etc.)
- Show actual port/protocol (e.g. TCP/9999) instead of "unknown_service" so
  all open ports are visible even when not matched
- Update tests to reflect new unknown-port label format
2026-03-07 16:33:03 +01:00
Pouzor bc30250398 feat: pending device detail modal with services and actions
- Click any pending device row to open a detail modal
- Modal shows IP, hostname, MAC, OS, suggested type, discovered_at
- Service list with port/protocol/service_name, colored dot by category
- Approve / Hide / Delete buttons with matching color coding
- List items now show IP, service count, hostname and suggested type at a glance
2026-03-07 16:11:53 +01:00
Pouzor bec699ba93 feat: non-blocking scan with progressive device discovery
Backend:
- asyncio.to_thread(_nmap_scan) — nmap no longer blocks the event loop
- Commit each discovered device immediately (previously one bulk commit at end)
- Update ScanRun.devices_found after each device so history panel shows live count
- broadcast_scan_update() pushes {type: scan_device_found} WS event per device
- Refactor broadcast_status to shared _broadcast() helper, adds type: "status" field

Frontend:
- useStatusPolling handles both WS message types (status / scan_device_found)
- canvasStore: scanEventTs + notifyScanDeviceFound() action
- PendingDevicesPanel auto-refreshes when WS scan event is received
2026-03-07 16:06:44 +01:00
Pouzor 974e782057 fix: resolve all 64 mypy errors across backend
- Add dict[str, Any] / list[Any] type params throughout (fingerprint, models, schemas, scanner, status_checker)
- Add return type annotations to all route functions (nodes, edges, canvas, scan, auth, status, main)
- Fix no-any-return in security.py: cast pwd/jwt results to bool/str explicitly
- Fix canvas.py: use model_validate() for NodeResponse/EdgeResponse, rename db_node/db_edge upsert vars
- Fix scheduler.py: rename 'result' → 'check_result' to avoid type collision
- Fix get_db() return type: AsyncGenerator[AsyncSession, None]
- Add types-PyYAML for yaml import stubs
- Fix scanner.py: remove unnecessary type: ignore comment (nmap has stubs)
- Fix scan.py: wrap scalars().all() with list() for Sequence→list compatibility
2026-03-07 15:48:41 +01:00
Pouzor 1811afa749 fix: upgrade fastapi to 0.135.1, fix starlette CVEs, update auth test assertions
- fastapi 0.115.0 → 0.135.1 pulls starlette 0.52.1 (fixes CVE-2024-47874, CVE-2025-54121)
- pip-audit: ignore CVE-2024-23342 (ecdsa Minerva attack, no fix exists; app uses HS256 only)
- Update auth guard tests: FastAPI 0.135 returns 401 (not 403) when Bearer token is missing
2026-03-07 15:18:28 +01:00