Adds the connect-by-code side of remote diagnostics and closes two real secret-leak vectors that an end-to-end gateway<->agent test surfaced. Gateway (gateway/, local stdio MCP, Claude connects once): - 14 read-only tools (server_health hub, read_log, list_logs, list_errors, get_queue_state, get_history, get_config_redacted, get_system_info, get_rotation_state, get_app_events + connect/disconnect/list/current). - The HOST is always supplied by the operator, never taken from the code. - TLS fingerprint pinning is enforced in the socket 'open' handler BEFORE the token is sent (wss opt-in); plain ws is loopback-only. - registry.json (holds bearer tokens) is gitignored; only an empty example ships. Security hardening (gates every off-box payload): - redactLogText now scrubs opaque bearer/token-family secrets that are NOT stored config credentials (e.g. a session token a hoster returns inside an error string): bare token/auth_token/refresh_token/session_token + standalone "Bearer <opaque>". Benign "token bucket" prose is left intact. - get_config_redacted deep-redacts every string leaf (JSON-safe, per-leaf, so the cookie/sess line patterns can't gobble across a compact-JSON field) and drops the history subtree (served by get_history with its own per-error redaction). This plugs leaks via globalSettings.pendingQueue[].error etc. Bind-address safety: - _safeDiagBindAddress() forces the diagnostic agent to 127.0.0.1/::1; the 0.0.0.0 UI option is removed. Direct LAN/Internet bind stays disabled until encrypted transport (wss) exists — remote access goes through an SSH/VPN tunnel to loopback. (Never plaintext ws:// on all interfaces.) Tests: end-to-end gateway<->agent gate (connect -> server_health/read_log/ get_config_redacted, asserts zero secret leakage, rejects doodstream log, path traversal and write ops); + redaction regression tests in the main suite. 385 app tests + 9 gateway tests pass; lint 0 errors. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
57 lines
1.9 KiB
Markdown
57 lines
1.9 KiB
Markdown
# mhu-diagnostics-gateway
|
|
|
|
A standalone local **stdio MCP gateway** for remote, **read-only** diagnostics of the
|
|
Multi-Hoster-Uploader app.
|
|
|
|
It is two things at once:
|
|
|
|
- an **MCP server** to Claude Code (stdio transport), exposing read-only diagnostic tools, and
|
|
- a plain **WebSocket client** to a diagnostic agent running inside the Electron app on a
|
|
remote Windows server.
|
|
|
|
The operator enables "Diagnose-Zugriff" on a server, copies the connection **code**, and tells
|
|
Claude `server <name> at <host>, code <CODE>`. Claude calls `connect_server(code, host)` and then
|
|
the read-only diagnostic tools. After the first successful connect the server is remembered under
|
|
its label, so later you can just say `connect_server(label:"prod-3")` with no code.
|
|
|
|
This package is fully self-contained. It does **not** import anything from the parent Electron app
|
|
and is **not** part of the app build.
|
|
|
|
## Install
|
|
|
|
```
|
|
cd gateway
|
|
npm install
|
|
```
|
|
|
|
Requires Node >= 18.
|
|
|
|
## Register with Claude Code (one time)
|
|
|
|
```
|
|
claude mcp add --transport stdio mhu-diag -- node "C:\Users\ploet\Desktop\Claude Projekte\multi-hoster-uploader\gateway\index.js"
|
|
```
|
|
|
|
Adjust the absolute path if you cloned the repo elsewhere.
|
|
|
|
## Usage
|
|
|
|
In Claude Code, tell Claude:
|
|
|
|
```
|
|
server prod-3 at 127.0.0.1, code mhu1_<...>
|
|
```
|
|
|
|
Claude will call `connect_server` and then diagnostic tools such as `server_health`
|
|
(the one-shot "what's wrong" hub), `read_log`, `list_errors`, `get_queue_state`,
|
|
`get_rotation_state`, and so on.
|
|
|
|
## Security
|
|
|
|
- **Read-only.** No screen access, no input injection, no writes. Only reads logs, errors,
|
|
queue/history/config (redacted), rotation and system info.
|
|
- The **code is a secret** — it carries the auth token. Do not paste it anywhere public.
|
|
- The safe default is to reach the agent over `127.0.0.1` via an SSH local port-forward or
|
|
WireGuard. See `docs/remote-diagnostics-setup.md`.
|
|
- `registry.json` stores tokens and is **git-ignored** — never commit it.
|