release r007 security hardening and redesigned UI
This commit is contained in:
+17
-2
@@ -13,7 +13,7 @@ import { createConnection, type Socket } from "net";
|
||||
|
||||
// ── Konstanten ──────────────────────────────────────────────────────────
|
||||
export const MUA_SERVER_NAME = "mua";
|
||||
export const MUA_VERSION = "2026.08.18.r006";
|
||||
export const MUA_VERSION = "2026.08.21.r007";
|
||||
export const MUA_PROTOCOL_VERSION = "2025-03-26";
|
||||
export const PHP_HELPER = "/usr/local/bin/unraid-docker-mcp-helper.php";
|
||||
|
||||
@@ -224,6 +224,17 @@ export function sanitizeLogOutput(text: string, maxChars = 50000): string {
|
||||
let result = text.replace(/\x1b\[[0-9;]*[a-zA-Z]/g, "");
|
||||
// Entferne andere Control-Chars (außer \n, \r, \t)
|
||||
result = result.replace(/[\x00-\x08\x0b\x0c\x0e-\x1f\x7f]/g, "");
|
||||
// Häufige Secret-Formate redigieren. Das ist bewusst nur eine zusätzliche
|
||||
// Schutzschicht; Container-Logs können weiterhin sensible Nutzdaten
|
||||
// enthalten und sollten nur gezielt sowie mit kleinem `tail` gelesen werden.
|
||||
result = result.replace(
|
||||
/((?:api[_-]?key|token|secret|password|passwd|authorization|cookie)\s*[=:]\s*)([^\s,;]+)/gi,
|
||||
"$1[REDACTED]",
|
||||
);
|
||||
result = result.replace(
|
||||
/(\"(?:api[_-]?key|token|secret|password|passwd|authorization|cookie)\"\s*:\s*\")[^\"]*(\")/gi,
|
||||
"$1[REDACTED]$2",
|
||||
);
|
||||
// Begrenze Länge
|
||||
if (result.length > maxChars) {
|
||||
result = "... [truncated] ..." + result.slice(-maxChars);
|
||||
@@ -254,7 +265,11 @@ export async function compactContainerInspect(container: string): Promise<string
|
||||
Image: d.Config?.Image ?? "",
|
||||
NetworkMode: d.HostConfig?.NetworkMode ?? "",
|
||||
Ports: d.NetworkSettings?.Ports ?? [],
|
||||
Env: d.Config?.Env ?? [],
|
||||
// Environment-Werte enthalten sehr häufig API-Keys, Passwörter und
|
||||
// interne URLs. Für Diagnosezwecke reichen die vorhandenen Variablennamen.
|
||||
EnvNames: (d.Config?.Env ?? []).map((entry: unknown) =>
|
||||
typeof entry === "string" ? entry.split("=", 1)[0] : "",
|
||||
).filter((name: string) => name !== ""),
|
||||
Mounts: (d.Mounts ?? []).map((m: any) => ({
|
||||
Type: m.Type ?? "",
|
||||
Source: m.Source ?? "",
|
||||
|
||||
Reference in New Issue
Block a user