diff --git a/README.md b/README.md index 37a3ee2..c054ffe 100644 --- a/README.md +++ b/README.md @@ -72,10 +72,10 @@ Oder manuell: ```bash # .txz von Gitea laden -curl -O http://192.168.1.2:4000/michael/MUA-Mikes-Unraid-Agent/raw/branch/main/dist/mua-2026.08.21.r008-x86_64-1.txz +curl -O http://192.168.1.2:4000/michael/MUA-Mikes-Unraid-Agent/raw/branch/main/dist/mua-2026.08.21.r009-x86_64-1.txz # Installieren -upgradepkg --install-new mua-2026.08.21.r008-x86_64-1.txz +upgradepkg --install-new mua-2026.08.21.r009-x86_64-1.txz ``` ### 2. Service starten @@ -90,7 +90,7 @@ Der Service startet automatisch bei jedem Boot (SysVinit). ```bash curl http://192.168.1.2:3002/health -# → {"status":"ok","version":"2026.08.21.r008","auth":"required"} +# → {"status":"ok","version":"2026.08.21.r009","auth":"required"} ``` --- diff --git a/dist/mua-2026.08.21.r009-x86_64-1.txz b/dist/mua-2026.08.21.r009-x86_64-1.txz new file mode 100644 index 0000000..c25e4f7 Binary files /dev/null and b/dist/mua-2026.08.21.r009-x86_64-1.txz differ diff --git a/package.json b/package.json index 200ca16..1b421bc 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "mua", - "version": "2026.08.21.r008", + "version": "2026.08.21.r009", "description": "Mikes Unraid Agent - MCP over HTTP (Streamable HTTP) for Unraid", "type": "module", "main": "src/index.ts", diff --git a/plugin/mua.plg b/plugin/mua.plg index 3158ac9..7a2d914 100644 --- a/plugin/mua.plg +++ b/plugin/mua.plg @@ -2,13 +2,13 @@ - + - - + + ]> +### 2026.08.21.r009 +- WebGUI-Fix: Alle Formulare senden neben dem internen MUA-CSRF-Wert auch Unraids verpflichtendes csrf_token; Button-Klicks enden nicht mehr auf einer leeren Seite. ### 2026.08.21.r008 - Neue getrennte Nur-Lese-Shell: unraid_system_shell_readonly mit Programm-Allowlist und direkter argv-Ausführung ohne /bin/sh. - Schreibende Unterbefehle und Optionen für ip, find, ss, dmesg, date, mount und hostname werden serverseitig abgelehnt. @@ -96,7 +98,7 @@ Das .txz enthält: install/doinst.sh (läuft nach Installation) =========================================== --> - + &txzURL; &txzSHA256; diff --git a/plugin/plugin.json b/plugin/plugin.json index df68181..5b25f39 100644 --- a/plugin/plugin.json +++ b/plugin/plugin.json @@ -1,7 +1,7 @@ { "name": "mua", "author": "Michael", - "version": "2026.08.18.r005", + "version": "2026.08.21.r009", "minver": "7.0.0", "pluginDirectory": "/usr/local/emhttp/plugins/mua", "configDirectory": "/boot/config/plugins/mua", diff --git a/scripts/mua.page b/scripts/mua.page index 79be802..8286c69 100644 --- a/scripts/mua.page +++ b/scripts/mua.page @@ -12,6 +12,7 @@ $pidfile = '/var/run/mua.pid'; $binary = '/usr/local/bin/mua'; $admin_token_file = '/var/run/mua-admin.token'; $admin_token = is_readable($admin_token_file) ? trim(file_get_contents($admin_token_file)) : ''; +$unraid_csrf = $var['csrf_token'] ?? ''; $host_ip = $_SERVER['SERVER_ADDR'] ?? '127.0.0.1'; $endpoint = 'http://' . $host_ip . ':' . $port . '/mcp'; @@ -157,10 +158,10 @@ $active_count = $all_tools_enabled ? count($all_tools) : count($enabled_tools);

Schnelle Sicherheitsprofile

„Nur Lesen“ ist die empfohlene Dauerstellung. Weitergehende Rechte nur bei konkretem Bedarf freigeben.

-
">
+
">
-

Werkzeuge im Detail

+

Werkzeuge im Detail

$tools): $meta=$risk_labels[$risk]; ?>

@@ -168,7 +169,7 @@ $active_count = $all_tools_enabled ? count($all_tools) : count($enabled_tools);
-

API-Key

Der vollständige Schlüssel wird nicht dauerhaft angezeigt. Beim Erzeugen erscheint er genau einmal; danach ist nur noch die Endung sichtbar.

+

API-Key

Der vollständige Schlüssel wird nicht dauerhaft angezeigt. Beim Erzeugen erscheint er genau einmal; danach ist nur noch die Endung sichtbar.

-

Technische Details

Version
MCP-Port
Verwaltung127.0.0.1: · separater Admin-Token
Konfiguration/boot/config/plugins/mua/mua.conf
Audit-Protokoll/var/log/plugins/mua-audit.log (keine Argumente oder Inhalte)
+

Technische Details

Version
MCP-Port
Verwaltung127.0.0.1: · separater Admin-Token
Konfiguration/boot/config/plugins/mua/mua.conf
Audit-Protokoll/var/log/plugins/mua-audit.log (keine Argumente oder Inhalte)
diff --git a/src/helpers.ts b/src/helpers.ts index 811c777..f951d1c 100644 --- a/src/helpers.ts +++ b/src/helpers.ts @@ -13,7 +13,7 @@ import { createConnection, type Socket } from "net"; // ── Konstanten ────────────────────────────────────────────────────────── export const MUA_SERVER_NAME = "mua"; -export const MUA_VERSION = "2026.08.21.r008"; +export const MUA_VERSION = "2026.08.21.r009"; export const MUA_PROTOCOL_VERSION = "2025-03-26"; export const PHP_HELPER = "/usr/local/bin/unraid-docker-mcp-helper.php";