Add internal staff IAM: named users, roles, and management permissions.
Some checks are pending
offline / test (push) Waiting to run

verae-staff-iam (:3028) is the people directory — owner, billing-admin,
cs, sales, accounting, operator, viewer — with scrypt passwords, sessions,
and an audit log. Admin console login uses it when STAFF_IAM_URL is set
and hides tabs the account cannot use. CS/sales/accounting/staff/fleet
check permissions such as cs.credit and fleet.operate. Shared staff key
remains only as a fallback when IAM is unset.
This commit is contained in:
George Lambert 2026-09-11 18:36:12 -04:00
parent 2740d51446
commit d299d245e8
41 changed files with 1337 additions and 52 deletions

View file

@ -0,0 +1,35 @@
export function iamBase() {
return (process.env.STAFF_IAM_URL || '').replace(/\/$/, '');
}
export async function iamCheck(req, permission) {
const base = iamBase();
if (!base) {
if (process.env.STAFF_AUTH === '1') {
const login = (process.env.STAFF_SESSION_URL || 'http://127.0.0.1:3027').replace(/\/$/, '');
const r = await fetch(`${login}/check`, { headers: { cookie: req.headers.cookie || '' } }).catch(() => null);
return { ok: Boolean(r && r.ok) };
}
return { ok: true, skipped: true };
}
const q = permission ? `?permission=${encodeURIComponent(permission)}` : '';
const r = await fetch(`${base}/check${q}`, {
headers: { cookie: req.headers.cookie || '', authorization: req.headers.authorization || '' },
}).catch(() => null);
if (!r) return { ok: false, status: 502 };
const body = await r.json().catch(() => ({}));
return { ok: r.ok, status: r.status, ...body };
}
export async function denyOrRedirect(req, res, json, { permission, html }) {
const out = await iamCheck(req, permission);
if (out.ok) return true;
const login = iamBase() || (process.env.STAFF_SESSION_URL || 'http://127.0.0.1:3028').replace(/\/$/, '');
if (html) {
res.writeHead(302, { location: `${login}/login?next=${encodeURIComponent('http://' + (req.headers.host || '127.0.0.1') + '/')}` });
res.end();
return false;
}
json(out.status === 403 ? 403 : 401, { error: out.reason || 'unauthorized', permission });
return false;
}

View file

@ -9,6 +9,7 @@ import { fileURLToPath } from 'node:url';
import { SUBJECTS, billingRequest } from './nats-billing.js';
import { listCustomers, withCustomerName } from './names.js';
import { staffPageHtml } from './staff-page.js';
import { denyOrRedirect } from './iam-gate.js';
const PUBLIC = path.join(path.dirname(fileURLToPath(import.meta.url)), '..', 'public');
@ -34,16 +35,7 @@ const server = http.createServer(async (req, res) => {
};
try {
if (req.method === 'GET' && (url.pathname === '/' || url.pathname === '/index.html')) {
if (process.env.STAFF_AUTH === '1') {
const login = (process.env.STAFF_SESSION_URL || 'http://127.0.0.1:3027').replace(/\/$/, '');
const chk = await fetch(`${login}/check`, { headers: { cookie: req.headers.cookie || '' } }).catch(() => null);
if (!chk || !chk.ok) {
const next = `http://${req.headers.host || '127.0.0.1'}/`;
res.writeHead(302, { location: `${login}/login?next=${encodeURIComponent(next)}` });
res.end();
return;
}
}
if (!(await denyOrRedirect(req, res, json, { permission: 'cs.review', html: true }))) return;
res.writeHead(200, { 'content-type': 'text/html; charset=utf-8' });
res.end(
await staffPageHtml(
@ -65,12 +57,14 @@ const server = http.createServer(async (req, res) => {
}
const review = url.pathname.match(/^\/review\/([^/]+)$/);
if (req.method === 'GET' && review) {
if (!(await denyOrRedirect(req, res, json, { permission: 'cs.review' }))) return;
const id = decodeURIComponent(review[1]);
const out = await statement(id);
out.body = await withCustomerName(out.body, id, EDGE, KEY);
return json(out.status, out.body);
}
if (req.method === 'POST' && url.pathname === '/credits') {
if (!(await denyOrRedirect(req, res, json, { permission: 'cs.credit' }))) return;
const chunks = [];
for await (const c of req) chunks.push(c);
const payload = JSON.parse(Buffer.concat(chunks).toString('utf8') || '{}');