Files
meshcore-analyzer/public/admin.js
T
efitenandClaude Opus 5.5 abbe6846ff feat: propose and approve hashtag channels (user management part D) (#2139)
Part D of #2128: logged-in users propose a hashtag channel, an admin
approves, rejects or later revokes it, and the ingestor decrypts
approved channels without a restart. It is the first consumer of a
generic proposal table, and answers the request in #2092.

Stacked on #2138 (part C). Review the commits after that branch; GitHub
shows C's commits here until it is merged.

## The situation

- An instance decrypts only the hashtag channels listed in
`hashChannels`. Users who want a city or club channel shown have to ask
the operator, who edits `config.json` and restarts the ingestor.
- #2092 asked for a suggest-and-approve flow; a downstream fork
(dborup/CoreScope#99) runs one with anonymous suggestions and a file
queue.

## What this PR adds

**Name rules (`internal/channel`).** `ValidateHashtagName`, mirrored in
the browser:
- at most 31 UTF-8 bytes including `#` (firmware
`ChannelDetails.name[32]`), case preserved, `Public` refused in any
case;
- control, bidi, separator and format characters refused except ZWJ,
plus invisible fillers (`Other_Default_Ignorable_Code_Point`, U+2800,
non-ASCII spaces).

Go and JS give the same verdict for every code point.

**Store.** Schema v4, one generic `proposals` table (kind, subject,
status pending/approved/rejected/revoked, proposer, reviewer, note). One
row per (kind, subject); limits are checked in the same transaction as
the change.

**Server** (only with `userManagement.channelProposals.enabled`)
- `POST /api/proposals`, `GET /api/account/proposals`, `GET
/api/admin/proposals`, `POST
/api/admin/proposals/{id}/approve|reject|revoke`.
- 400 for an invalid name. 409 for a duplicate, a rejected name, or a
name already in `hashChannels`/`channelKeys` ("this channel is already
decrypted on this instance"). 429 over a limit (`maxPending` 100,
`maxApproved` 128, `perUserPerDay` 5).
- `GET /api/channels` gains `approvedChannels`, so approved channels are
listed before they have traffic. With the feature off the response is
byte-identical.

**Ingestor.** Opens `users.db` with `mode=ro` every 60 seconds,
re-validates the names, and swaps its key map through an
`atomic.Pointer`. Configured channels always win, and a failed read
keeps the last good set. The ingestor never writes `users.db`; AGENTS.md
now says so.

**Frontend.** "Propose for everyone" in the add-channel dialog, an
"approved" marker in the channel list, "My proposals" on the account
page, and an admin "Proposals" tab with a warning on approve. The packet
detail pane now escapes the channel name: until now only the operator
chose those names.

Spec:
[`docs/specs/2026-10-07-channel-proposals-design.md`](https://github.com/efiten/CoreScope/blob/feat/channel-proposals/docs/specs/2026-10-07-channel-proposals-design.md).

## Performance

Every key is tried on each GRP_TXT that no key opens (`decodeGrpTxt`).
Benchmark of that worst case:

| Keys | Time per packet |
|---|---|
| 320 configured | 204 to 216 µs |
| 320 configured + 128 approved | 272 to 320 µs |

That is about +33%, linear in the key count and capped by `maxApproved`.
With the feature off the decoder gets the identical map and no ticker
runs.

## Verification

- `internal/channel`, `internal/users` (with `-race`), `cmd/server` and
`cmd/ingestor` pass locally, 53 new Go tests. The ingestor's
`TestWriteStatsAtomic_SymlinkAtDestIsReplaced` needs symlink rights on
Windows and fails on `master` too.
- `sh test-all.sh` exits 0; the XSS gate in diff mode passes.
- User-management E2E: 21 of 21 steps locally (propose, approve, the
channel appears, revoke removes it).
- On our staging and production instance since 7 October 2026.

## Not in this PR

- Private (PSK) channels: their keys stay in the browser (#725).
- Anonymous proposals.
- Names that need ZWNJ (some Persian and Urdu spellings) and subdivision
flags are refused, because ZWNJ and tag characters are format
characters. Allowing them later only widens the rule, so no approved
name gets stranded.

---------

Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
2026-10-08 21:51:42 +02:00

104 lines
4.5 KiB
JavaScript

/* #/admin: the admin area of optional user management
* (docs/specs/2026-10-07-admin-dashboard-design.md). A tab shell; each tab
* is a module with mount(container) and unmount():
* overview window.CSAdminOverview (admin-overview.js)
* users window.CSAdminUsers (admin-users.js)
* audit window.CSAdminAudit (admin-audit.js)
* proposals window.CSAdminProposals (admin-proposals.js), only with channel proposals on
* Deep link: #/admin?tab=<tab>&<tab filters>. The old #/admin/users?... is
* rewritten to #/admin?tab=users&... with replaceState. Access relies on
* the server's withAdmin check and CSAuth.isAdmin(); the shell adds no
* access mechanism of its own. */
(function () {
'use strict';
var TABS = [
{ id: 'overview', label: 'Overview', mod: 'CSAdminOverview' },
{ id: 'users', label: 'Users', mod: 'CSAdminUsers' },
{ id: 'audit', label: 'Audit', mod: 'CSAdminAudit' },
{ id: 'proposals', label: 'Proposals', mod: 'CSAdminProposals', when: proposalsOn }
];
function proposalsOn() { return !!(window.MC_USER_MGMT && window.MC_USER_MGMT.channelProposals); }
function visibleTabs() { return TABS.filter(function (t) { return !t.when || t.when(); }); }
// The page on screen, whether it was rendered for an admin, and the
// mounted tab, so an auth change can redirect or re-render.
var mounted = { app: null, admin: false, tab: null };
// Bumped by every init and destroy, so an init whose CSAuth.ready()
// resolves after the page was left (or re-rendered) mounts nothing.
var renderSeq = 0;
function readTab(hash) {
var t = new URLSearchParams(String(hash || '').split('?')[1] || '').get('tab');
var tabs = visibleTabs();
for (var i = 0; i < tabs.length; i++) if (tabs[i].id === t) return tabs[i];
return tabs[0];
}
// #/admin/users?x=1 becomes #/admin?tab=users&x=1; any other hash: null.
function legacyRewrite(hash) {
var m = /^#\/admin\/users(?:\?(.*))?$/.exec(String(hash || ''));
if (!m) return null;
return '#/admin?tab=users' + (m[1] ? '&' + m[1] : '');
}
function tabsHtml(active) {
var html = '<nav class="admin-tabs" aria-label="Admin sections">';
visibleTabs().forEach(function (t) {
var on = t.id === active;
html += '<a class="tab-btn' + (on ? ' active' : '') + '" href="#/admin?tab=' + t.id + '"' +
(on ? ' aria-current="page"' : '') + '>' + t.label + '</a>';
});
return html + '</nav>';
}
function page(inner) { return '<div class="um-page admin-page">' + inner + '</div>'; }
function unmountTab() {
if (mounted.tab) window[mounted.tab.mod].unmount();
mounted.tab = null;
}
function init(app, routeParam) {
unmountTab();
var seq = ++renderSeq;
var legacy = routeParam === 'users' ? legacyRewrite(location.hash) : null;
if (legacy) {
history.replaceState(null, '', legacy);
routeParam = null;
}
app.innerHTML = page('<p>Loading…</p>');
var ready = window.CSAuth ? CSAuth.ready() : Promise.resolve();
return ready.then(function () {
if (seq !== renderSeq) return;
if (routeParam || !window.CSAuth || !CSAuth.isEnabled()) {
app.innerHTML = page('<h2>Not found</h2>');
return;
}
mounted.app = app;
mounted.admin = CSAuth.isAdmin();
if (!mounted.admin) {
app.innerHTML = page('<h2>Admin</h2><p>Admins only. <a href="#/account/login">Log in</a></p>');
return;
}
var tab = readTab(location.hash);
app.innerHTML = page('<h2>Admin</h2>' + tabsHtml(tab.id) + '<div id="adminTab"></div>');
mounted.tab = tab;
window[tab.mod].mount(document.getElementById('adminTab'));
}).catch(function () {
if (seq !== renderSeq) return;
app.innerHTML = page('<h2>Admin</h2><p>Network error, reload the page.</p>');
});
}
// Logout (header, account page or a 401) goes to the login view; a login
// or role change that flips admin access re-renders the page.
window.addEventListener('cs-auth-changed', function (e) {
// A logout that already moved elsewhere (the header goes home) wins.
if (!mounted.app || location.hash.split('?')[0] !== '#/admin') return;
if (!e.detail) { location.hash = '#/account/login'; return; }
if (CSAuth.isAdmin() !== mounted.admin) init(mounted.app, null);
});
registerPage('admin', { init: init, destroy: function () { renderSeq++; unmountTab(); mounted.app = null; } });
window.CSAdmin = { _test: { readTab: readTab, legacyRewrite: legacyRewrite, tabsHtml: tabsHtml } };
})();