Merges Renovate's kit 3 (PR #149) and adapter-static 4 (PR #148) bumps, plus the migration they need. The mechanical part is `sv migrate sveltekit-3`, run one task at a time and reviewed: - svelte.config.js is gone. Its options move into sveltekit() in vite.config.ts, exported as kitOptions so vitest.config.ts runs the same kit setup, including the $test-utils alias the tests import. - $lib becomes #lib through package.json "imports". There is no src/lib/index, so only the "#lib/*" entry is kept. - tsconfig extends $app/tsconfig. - Peer floors raised to kit 3's requirements: svelte ^5.57.1, vite ^8.0.12, svelte-check ^4.7.5. By hand, from the codemod's list of non-automated tasks: - goto's replaceState option is now replace; keepFocus becomes reset: false. For the search typeahead, reset: false also stops the scroll-to-top, which is wanted while typing. - The test setup mocks drop pushState/replaceState and $app/paths base/assets, which kit 3 removed, and mock refreshAll in place of invalidateAll. - The other flagged files only read page.url or goto internal routes, so they needed no change. TypeScript goes to ^6, not the ^7 Renovate offers: kit 3 declares typescript ^6 as a peer and svelte-check 4.7 accepts ^5 || ^6. Move to 7 once both accept it. With Tailwind 4 and kit 3 in, `npm audit` on the whole tree reports 0, so the web lane now audits every dependency rather than only what ships to browsers. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
136 lines
5.1 KiB
Svelte
136 lines
5.1 KiB
Svelte
<script lang="ts">
|
|
import { onMount } from 'svelte';
|
|
import { Save, TriangleAlert } from 'lucide-svelte';
|
|
import {
|
|
getNetworkSettings,
|
|
updateNetworkSettings,
|
|
type NetworkSettings
|
|
} from '#lib/api/admin.js';
|
|
import { pushToast } from '#lib/stores/toast.svelte.js';
|
|
|
|
let settings = $state<NetworkSettings | null>(null);
|
|
let hops = $state(1);
|
|
let saving = $state(false);
|
|
let loadError = $state(false);
|
|
|
|
const dirty = $derived(!!settings && hops !== settings.trusted_proxy_hops);
|
|
const chain = $derived(
|
|
(settings?.forwarded_chain ?? '')
|
|
.split(',')
|
|
.map((s) => s.trim())
|
|
.filter(Boolean)
|
|
);
|
|
// The operator can count their proxies from what actually arrived rather
|
|
// than guessing — one XFF entry per proxy in front of us.
|
|
const suggested = $derived(chain.length);
|
|
|
|
async function load() {
|
|
try {
|
|
settings = await getNetworkSettings();
|
|
hops = settings.trusted_proxy_hops;
|
|
loadError = false;
|
|
} catch {
|
|
loadError = true;
|
|
}
|
|
}
|
|
|
|
onMount(load);
|
|
|
|
async function save() {
|
|
saving = true;
|
|
try {
|
|
settings = await updateNetworkSettings(hops);
|
|
hops = settings.trusted_proxy_hops;
|
|
pushToast('Proxy depth saved.');
|
|
} catch {
|
|
pushToast("Couldn't save proxy depth.", 'error');
|
|
} finally {
|
|
saving = false;
|
|
}
|
|
}
|
|
</script>
|
|
|
|
<section class="space-y-4 rounded-xl border border-border bg-surface p-5">
|
|
<div>
|
|
<h3 class="font-display text-lg font-medium text-text-primary">Client IP detection</h3>
|
|
<p class="mt-1 text-sm text-text-secondary">
|
|
How many reverse proxies sit in front of Minstrel. This decides which address is
|
|
recorded for each sign-in on the <span class="whitespace-nowrap">Active sessions</span> card,
|
|
so getting it right is what makes an unfamiliar login visible.
|
|
</p>
|
|
</div>
|
|
|
|
{#if loadError}
|
|
<p class="text-sm text-action-destructive">
|
|
Couldn't load network settings.
|
|
<button type="button" class="underline hover:no-underline" onclick={load}>Try again</button>
|
|
</p>
|
|
{:else if settings === null}
|
|
<p class="text-sm text-text-secondary">Loading…</p>
|
|
{:else}
|
|
<div class="flex flex-wrap items-end gap-3">
|
|
<label class="flex flex-col gap-1">
|
|
<span class="text-sm text-text-secondary">Trusted proxies</span>
|
|
<input
|
|
type="number"
|
|
min="0"
|
|
max={settings.max_hops}
|
|
bind:value={hops}
|
|
class="w-24 rounded border border-border bg-background px-2 py-1
|
|
focus-visible:outline-solid focus-visible:outline-2 focus-visible:outline-accent"
|
|
/>
|
|
</label>
|
|
<button
|
|
type="button"
|
|
class="inline-flex items-center gap-1.5 rounded-md border border-border px-3 py-1.5
|
|
text-sm hover:bg-surface-hover focus-visible:ring-2 focus-visible:ring-accent
|
|
disabled:opacity-50"
|
|
disabled={saving || !dirty}
|
|
onclick={save}
|
|
>
|
|
<Save size={14} aria-hidden="true" />
|
|
{saving ? 'Saving…' : 'Save'}
|
|
</button>
|
|
</div>
|
|
|
|
<!-- Verification, not decoration: the number is abstract, but "the address
|
|
Minstrel currently sees for YOU" is checkable against the machine
|
|
you're sitting at. -->
|
|
<dl class="grid gap-x-4 gap-y-1 text-sm sm:grid-cols-[auto_1fr]">
|
|
<dt class="text-text-secondary">Your address right now</dt>
|
|
<dd class="font-mono">{settings.detected_client_ip || 'unknown'}</dd>
|
|
<dt class="text-text-secondary">Direct connection from</dt>
|
|
<dd class="font-mono">{settings.remote_addr || 'unknown'}</dd>
|
|
<dt class="text-text-secondary">Forwarded chain</dt>
|
|
<dd class="font-mono break-all">{settings.forwarded_chain || '(none)'}</dd>
|
|
</dl>
|
|
|
|
{#if suggested > 0 && settings.trusted_proxy_hops !== suggested}
|
|
<p class="text-sm text-text-secondary">
|
|
This request arrived with {suggested}
|
|
{suggested === 1 ? 'forwarded address' : 'forwarded addresses'}, which usually means
|
|
{suggested}
|
|
{suggested === 1 ? 'proxy' : 'proxies'} in front of Minstrel.
|
|
</p>
|
|
{/if}
|
|
|
|
<div class="space-y-2 rounded border border-border bg-background p-3 text-sm">
|
|
<p class="flex items-start gap-2 text-text-secondary">
|
|
<TriangleAlert size={14} class="mt-0.5 shrink-0 text-action-destructive" aria-hidden="true" />
|
|
<span>
|
|
Count your proxies — don't guess high. This number tells Minstrel how much of the
|
|
<span class="font-mono">X-Forwarded-For</span> header to believe, and that header is
|
|
written by whoever connects. Set it higher than your real chain, or above 0 with no
|
|
proxy at all, and a visitor can choose which address their own session shows — which
|
|
defeats the point of the sessions list.
|
|
</span>
|
|
</p>
|
|
<ul class="ml-6 list-disc space-y-1 text-text-secondary">
|
|
<li><strong>0</strong> — no proxy; Minstrel is reached directly.</li>
|
|
<li><strong>1</strong> — one reverse proxy, e.g. nginx, Caddy or Traefik terminating TLS.</li>
|
|
<li><strong>2</strong> — a CDN in front of your own proxy, e.g. Cloudflare → nginx.</li>
|
|
</ul>
|
|
</div>
|
|
{/if}
|
|
</section>
|