- ops-agent/src/auth.ts: constant-time compare via timingSafeEqual to prevent timing attacks; store secret as Buffer - ops-agent/src/index.ts + ops-agent.service: bind on 127.0.0.1:3099 (was 4242, per plan) - app/api/agent/[...path]/route.ts: Next.js proxy route that verifies ops_session cookie then forwards requests to agent with Authorization: Bearer <secret> - .env.example + deploy/ops-dashboard.env.example: add OPS_AGENT_SECRET and OPS_AGENT_URL - README.md: rotation procedure for the shared secret Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
5 lines
236 B
Text
5 lines
236 B
Text
DATABASE_URL="postgresql://USER:PASSWORD@HOST:5432/ops_dashboard"
|
|
SEED_USER_EMAIL="admin@example.com"
|
|
SEED_USER_PASSWORD="changeme"
|
|
OPS_AGENT_SECRET="replace-with-contents-of-/etc/ops-agent/secret"
|
|
OPS_AGENT_URL="http://127.0.0.1:3099"
|