MrTerm: SSH/SFTP/RDP-Client im Termius-Stil (Electron)
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,266 @@
|
||||
const { app, BrowserWindow, ipcMain, dialog, shell, clipboard, Menu } = require('electron');
|
||||
const path = require('path');
|
||||
const fs = require('fs');
|
||||
const os = require('os');
|
||||
const crypto = require('crypto');
|
||||
const { utils: sshUtils } = require('ssh2');
|
||||
const { Store } = require('./store');
|
||||
const { SshManager } = require('./ssh');
|
||||
const rdp = require('./rdp');
|
||||
|
||||
let win;
|
||||
const store = new Store();
|
||||
const pendingSecrets = new Map();
|
||||
|
||||
function send(channel, ...args) {
|
||||
if (win && !win.isDestroyed()) win.webContents.send(channel, ...args);
|
||||
}
|
||||
|
||||
async function confirmHostKey(target, fingerprint, known) {
|
||||
if (process.env.MRTERM_SMOKE) return true;
|
||||
const changed = !!known;
|
||||
const r = await dialog.showMessageBox(win, {
|
||||
type: changed ? 'warning' : 'question',
|
||||
title: changed ? 'Host-Schlüssel hat sich geändert!' : 'Unbekannter Host',
|
||||
message: changed
|
||||
? `WARNUNG: Der Host-Schlüssel von ${target.host}:${target.port} hat sich geändert. Das kann auf einen Man-in-the-Middle-Angriff hindeuten.`
|
||||
: `Die Echtheit von ${target.host}:${target.port} kann nicht bestätigt werden.`,
|
||||
detail: `Fingerprint:\n${fingerprint}${changed ? `\n\nBisher gespeichert:\n${known.fingerprint}` : ''}`,
|
||||
buttons: [changed ? 'Trotzdem verbinden & ersetzen' : 'Vertrauen & verbinden', 'Abbrechen'],
|
||||
defaultId: changed ? 1 : 0,
|
||||
cancelId: 1,
|
||||
});
|
||||
return r.response === 0;
|
||||
}
|
||||
|
||||
function askSecret(sessionId, req) {
|
||||
return new Promise((resolve) => {
|
||||
const reqId = crypto.randomUUID();
|
||||
pendingSecrets.set(reqId, resolve);
|
||||
send('secret:request', { reqId, sessionId, ...req });
|
||||
});
|
||||
}
|
||||
|
||||
const ssh = new SshManager(store, confirmHostKey, askSecret);
|
||||
|
||||
function createWindow() {
|
||||
win = new BrowserWindow({
|
||||
width: 1360,
|
||||
height: 860,
|
||||
minWidth: 900,
|
||||
minHeight: 560,
|
||||
backgroundColor: '#14161d',
|
||||
frame: false,
|
||||
titleBarStyle: process.platform === 'darwin' ? 'hiddenInset' : 'hidden',
|
||||
webPreferences: {
|
||||
preload: path.join(__dirname, '..', 'preload.js'),
|
||||
contextIsolation: true,
|
||||
nodeIntegration: false,
|
||||
sandbox: true,
|
||||
},
|
||||
});
|
||||
Menu.setApplicationMenu(null);
|
||||
win.loadFile(path.join(__dirname, '..', 'renderer', 'index.html'));
|
||||
win.on('maximize', () => send('win:state', true));
|
||||
win.on('unmaximize', () => send('win:state', false));
|
||||
win.webContents.setWindowOpenHandler(({ url }) => { shell.openExternal(url); return { action: 'deny' }; });
|
||||
}
|
||||
|
||||
function handle(channel, fn) {
|
||||
ipcMain.handle(channel, async (_e, ...args) => {
|
||||
try { return { ok: true, value: await fn(...args) }; }
|
||||
catch (e) { return { ok: false, error: e.message || String(e) }; }
|
||||
});
|
||||
}
|
||||
|
||||
// ---------- Fenster ----------
|
||||
ipcMain.on('win:min', () => win.minimize());
|
||||
ipcMain.on('win:max', () => (win.isMaximized() ? win.unmaximize() : win.maximize()));
|
||||
ipcMain.on('win:close', () => win.close());
|
||||
|
||||
// ---------- Vault ----------
|
||||
handle('vault:get', () => ({ ...store.get(), encrypted: store.encrypted, platform: process.platform }));
|
||||
handle('vault:upsert', (col, item) => store.upsert(col, item));
|
||||
handle('vault:remove', (col, id) => store.remove(col, id));
|
||||
handle('vault:settings', (s) => store.setSettings(s));
|
||||
handle('vault:forgetHost', (id) => { delete store.get().knownHosts[id]; store.save(); });
|
||||
handle('vault:export', async () => {
|
||||
const r = await dialog.showSaveDialog(win, { defaultPath: 'mrterm-backup.json', filters: [{ name: 'JSON', extensions: ['json'] }] });
|
||||
if (r.canceled) return false;
|
||||
fs.writeFileSync(r.filePath, JSON.stringify(store.get(), null, 2), { mode: 0o600 });
|
||||
return r.filePath;
|
||||
});
|
||||
handle('vault:import', async () => {
|
||||
const r = await dialog.showOpenDialog(win, { filters: [{ name: 'JSON', extensions: ['json'] }], properties: ['openFile'] });
|
||||
if (r.canceled) return false;
|
||||
const data = JSON.parse(fs.readFileSync(r.filePaths[0], 'utf8'));
|
||||
for (const col of ['groups', 'hosts', 'keys', 'snippets', 'forwards'])
|
||||
for (const item of data[col] || []) store.upsert(col, item);
|
||||
return true;
|
||||
});
|
||||
|
||||
// Import aus ~/.ssh/config
|
||||
handle('vault:importSshConfig', () => {
|
||||
const file = path.join(os.homedir(), '.ssh', 'config');
|
||||
if (!fs.existsSync(file)) throw new Error('~/.ssh/config nicht gefunden');
|
||||
const entries = [];
|
||||
let cur = null;
|
||||
for (const raw of fs.readFileSync(file, 'utf8').split(/\r?\n/)) {
|
||||
const line = raw.trim();
|
||||
if (!line || line.startsWith('#')) continue;
|
||||
const [k, ...rest] = line.split(/\s+/);
|
||||
const v = rest.join(' ');
|
||||
if (k.toLowerCase() === 'host') {
|
||||
cur = v.includes('*') ? null : { label: v, address: v, port: 22, protocol: 'ssh' };
|
||||
if (cur) entries.push(cur);
|
||||
} else if (cur) {
|
||||
const key = k.toLowerCase();
|
||||
if (key === 'hostname') cur.address = v;
|
||||
else if (key === 'user') cur.username = v;
|
||||
else if (key === 'port') cur.port = Number(v);
|
||||
else if (key === 'identityfile') cur._identity = v.replace(/^~/, os.homedir());
|
||||
}
|
||||
}
|
||||
let n = 0;
|
||||
for (const e of entries) {
|
||||
if (store.get().hosts.some((h) => h.address === e.address && h.username === e.username && Number(h.port) === e.port)) continue;
|
||||
if (e._identity && fs.existsSync(e._identity)) {
|
||||
const pk = fs.readFileSync(e._identity, 'utf8');
|
||||
let key = store.get().keys.find((k) => k.privateKey === pk);
|
||||
if (!key) key = store.upsert('keys', { label: path.basename(e._identity), privateKey: pk, publicKey: readPub(e._identity) });
|
||||
e.keyId = key.id;
|
||||
}
|
||||
delete e._identity;
|
||||
store.upsert('hosts', e);
|
||||
n++;
|
||||
}
|
||||
return n;
|
||||
});
|
||||
|
||||
function readPub(p) {
|
||||
try { return fs.readFileSync(p + '.pub', 'utf8').trim(); } catch { return ''; }
|
||||
}
|
||||
|
||||
// ---------- Schlüssel ----------
|
||||
handle('key:generate', ({ type, bits, comment, passphrase }) => {
|
||||
const opts = { comment: comment || `${os.userInfo().username}@mrterm` };
|
||||
if (type === 'rsa') opts.bits = Number(bits) || 4096;
|
||||
if (passphrase) { opts.passphrase = passphrase; opts.cipher = 'aes256-cbc'; }
|
||||
const k = sshUtils.generateKeyPairSync(type === 'rsa' ? 'rsa' : type === 'ecdsa' ? 'ecdsa' : 'ed25519', opts);
|
||||
return { privateKey: k.private, publicKey: k.public };
|
||||
});
|
||||
handle('key:parse', ({ privateKey, passphrase }) => {
|
||||
const k = sshUtils.parseKey(privateKey, passphrase || undefined);
|
||||
if (k instanceof Error) throw k;
|
||||
const key = Array.isArray(k) ? k[0] : k;
|
||||
return { type: key.type, publicKey: `${key.type} ${key.getPublicSSH().toString('base64')} ${key.comment || ''}`.trim() };
|
||||
});
|
||||
handle('key:pickFile', async () => {
|
||||
const r = await dialog.showOpenDialog(win, { defaultPath: path.join(os.homedir(), '.ssh'), properties: ['openFile', 'showHiddenFiles'] });
|
||||
if (r.canceled) return null;
|
||||
return { name: path.basename(r.filePaths[0]), content: fs.readFileSync(r.filePaths[0], 'utf8'), publicKey: readPub(r.filePaths[0]) };
|
||||
});
|
||||
|
||||
// ---------- SSH-Terminal ----------
|
||||
function hostWithOverrides(hostOrId) {
|
||||
if (typeof hostOrId === 'string') {
|
||||
const h = store.resolveHost(hostOrId);
|
||||
if (!h) throw new Error('Host nicht gefunden');
|
||||
return h;
|
||||
}
|
||||
return hostOrId; // Quick-Connect: temporärer Host
|
||||
}
|
||||
|
||||
handle('ssh:open', async (sessionId, hostRef, size) => {
|
||||
const host = hostWithOverrides(hostRef);
|
||||
if (host.id) store.addHistory({ hostId: host.id, at: Date.now() });
|
||||
await ssh.openShell(sessionId, host, size, (type, payload) => send('ssh:event', sessionId, type, payload));
|
||||
return true;
|
||||
});
|
||||
ipcMain.on('ssh:write', (_e, id, data) => ssh.write(id, data));
|
||||
ipcMain.on('ssh:resize', (_e, id, cols, rows) => ssh.resize(id, cols, rows));
|
||||
ipcMain.on('ssh:close', (_e, id) => ssh.close(id));
|
||||
ipcMain.on('secret:reply', (_e, reqId, value) => {
|
||||
pendingSecrets.get(reqId)?.(value);
|
||||
pendingSecrets.delete(reqId);
|
||||
});
|
||||
|
||||
// ---------- SFTP ----------
|
||||
handle('sftp:open', (sessionId, hostRef) => ssh.openSftp(sessionId, hostWithOverrides(hostRef)));
|
||||
handle('sftp:list', (id, dir) => ssh.sftpList(id, dir));
|
||||
handle('sftp:op', (id, op, a, b) => ssh.sftpOp(id, op, a, b));
|
||||
handle('sftp:transfer', async (id, dir, localPath, remotePath, transferId) => {
|
||||
let last = 0;
|
||||
await ssh.transfer(id, dir, localPath, remotePath, (done, total) => {
|
||||
const now = Date.now();
|
||||
if (now - last > 100 || done === total) { last = now; send('sftp:progress', transferId, done, total, dir === 'download' ? remotePath : localPath); }
|
||||
});
|
||||
return true;
|
||||
});
|
||||
handle('sftp:close', (id) => ssh.close(id));
|
||||
|
||||
// Lokales Dateisystem (für den Dual-Pane-SFTP-Browser)
|
||||
handle('local:home', () => os.homedir());
|
||||
handle('local:list', (dir) => fs.readdirSync(dir, { withFileTypes: true }).map((d) => {
|
||||
let st = {};
|
||||
try { st = fs.statSync(path.join(dir, d.name)); } catch {}
|
||||
return { name: d.name, isDir: d.isDirectory() || (d.isSymbolicLink() && st.isDirectory?.()), size: st.size || 0, mtime: st.mtimeMs || 0 };
|
||||
}));
|
||||
handle('local:join', (...p) => path.join(...p));
|
||||
handle('local:parent', (p) => path.dirname(p));
|
||||
handle('local:roots', () => {
|
||||
if (process.platform !== 'win32') return ['/'];
|
||||
return 'CDEFGHIJKLMNOPQRSTUVWXYZ'.split('').map((l) => `${l}:\\`).filter((d) => fs.existsSync(d));
|
||||
});
|
||||
handle('local:op', (op, a, b) => {
|
||||
if (op === 'mkdir') return fs.mkdirSync(a, { recursive: true });
|
||||
if (op === 'rename') return fs.renameSync(a, b);
|
||||
if (op === 'delete') return shell.trashItem(a);
|
||||
if (op === 'open') return shell.openPath(a);
|
||||
});
|
||||
|
||||
// ---------- Port-Forwarding ----------
|
||||
handle('fw:start', (id) => {
|
||||
const fw = store.get().forwards.find((f) => f.id === id);
|
||||
if (!fw) throw new Error('Regel nicht gefunden');
|
||||
return ssh.startForward(fw, (ev) => send('fw:event', id, ev));
|
||||
});
|
||||
handle('fw:stop', (id) => ssh.stopForward(id));
|
||||
handle('fw:active', () => ssh.activeForwards());
|
||||
|
||||
// ---------- RDP ----------
|
||||
handle('rdp:detect', () => rdp.detect(store.get().settings));
|
||||
handle('rdp:launch', (hostId) => {
|
||||
const host = hostWithOverrides(hostId);
|
||||
if (host.id) store.addHistory({ hostId: host.id, at: Date.now() });
|
||||
const r = rdp.launch(host, store.get().settings);
|
||||
if (r.process) {
|
||||
r.process.on('exit', (code) => { if (code && code !== 0 && code !== 12) send('toast', `RDP beendet (Code ${code}): ${r.getErr().split('\n').filter(Boolean).slice(-1)[0] || ''}`, 'error'); });
|
||||
r.process.on('error', (e) => send('toast', 'RDP-Start fehlgeschlagen: ' + e.message, 'error'));
|
||||
}
|
||||
return r.client;
|
||||
});
|
||||
|
||||
handle('clipboard:write', (t) => clipboard.writeText(t));
|
||||
handle('clipboard:read', () => clipboard.readText());
|
||||
handle('shell:open', (url) => shell.openExternal(url));
|
||||
|
||||
app.whenReady().then(() => {
|
||||
store.load();
|
||||
createWindow();
|
||||
});
|
||||
app.on('window-all-closed', () => { ssh.closeAll(); app.quit(); });
|
||||
|
||||
// Smoke-Test: MRTERM_SMOKE=<pfad.png> startet, loggt Renderer-Meldungen, speichert einen Screenshot und beendet.
|
||||
if (process.env.MRTERM_SMOKE) {
|
||||
app.whenReady().then(() => {
|
||||
win.webContents.on('console-message', (e) => console.log('[renderer]', e.level, e.message));
|
||||
setTimeout(async () => {
|
||||
if (process.env.MRTERM_SMOKE_JS) await win.webContents.executeJavaScript(process.env.MRTERM_SMOKE_JS).catch((e) => console.log('js error', e));
|
||||
setTimeout(async () => {
|
||||
fs.writeFileSync(process.env.MRTERM_SMOKE, (await win.webContents.capturePage()).toPNG());
|
||||
app.quit();
|
||||
}, 1500);
|
||||
}, 2500);
|
||||
});
|
||||
}
|
||||
@@ -0,0 +1,87 @@
|
||||
// RDP: Windows nutzt das eingebaute mstsc.exe, Linux (Arch/CachyOS) FreeRDP (xfreerdp3 / xfreerdp / wlfreerdp).
|
||||
const { spawn, execFile, execFileSync } = require('child_process');
|
||||
const fs = require('fs');
|
||||
const os = require('os');
|
||||
const path = require('path');
|
||||
|
||||
function which(bin) {
|
||||
try {
|
||||
execFileSync(process.platform === 'win32' ? 'where' : 'which', [bin], { stdio: 'ignore' });
|
||||
return true;
|
||||
} catch { return false; }
|
||||
}
|
||||
|
||||
function linuxClient(pref) {
|
||||
const candidates = pref && pref !== 'auto'
|
||||
? [pref]
|
||||
: process.env.WAYLAND_DISPLAY
|
||||
? ['sdl-freerdp3', 'wlfreerdp3', 'xfreerdp3', 'wlfreerdp', 'xfreerdp']
|
||||
: ['xfreerdp3', 'sdl-freerdp3', 'xfreerdp'];
|
||||
return candidates.find(which);
|
||||
}
|
||||
|
||||
function detect(settings) {
|
||||
if (process.platform === 'win32') return { available: true, client: 'mstsc' };
|
||||
const c = linuxClient(settings.rdpClientLinux);
|
||||
return c ? { available: true, client: c } : { available: false, hint: 'sudo pacman -S freerdp' };
|
||||
}
|
||||
|
||||
function launch(host, settings) {
|
||||
const port = Number(host.port) || 3389;
|
||||
const user = host.domain ? `${host.domain}\\${host.username || ''}` : host.username || '';
|
||||
|
||||
if (process.platform === 'win32') {
|
||||
const target = port === 3389 ? host.address : `${host.address}:${port}`;
|
||||
const lines = [
|
||||
`full address:s:${target}`,
|
||||
user && `username:s:${user}`,
|
||||
`screen mode id:i:${host.rdpFullscreen ? 2 : 1}`,
|
||||
host.rdpWidth && `desktopwidth:i:${host.rdpWidth}`,
|
||||
host.rdpHeight && `desktopheight:i:${host.rdpHeight}`,
|
||||
'dynamic resolution:i:1',
|
||||
'smart sizing:i:1',
|
||||
`redirectclipboard:i:${host.rdpClipboard === false ? 0 : 1}`,
|
||||
`redirectdrives:i:${host.rdpDrives ? 1 : 0}`,
|
||||
`audiomode:i:${host.rdpAudio === false ? 2 : 0}`,
|
||||
'prompt for credentials:i:0',
|
||||
'authentication level:i:2',
|
||||
].filter(Boolean);
|
||||
const file = path.join(os.tmpdir(), `mrterm-${host.id}.rdp`);
|
||||
fs.writeFileSync(file, lines.join('\r\n'), 'utf16le');
|
||||
const run = () => {
|
||||
const p = spawn('mstsc.exe', [file], { detached: true, stdio: 'ignore' });
|
||||
p.unref();
|
||||
};
|
||||
if (host.password && user) {
|
||||
// Anmeldedaten temporär im Windows-Anmeldeinformationsspeicher ablegen, danach wieder entfernen.
|
||||
execFile('cmdkey', [`/generic:TERMSRV/${host.address}`, `/user:${user}`, `/pass:${host.password}`], () => {
|
||||
run();
|
||||
setTimeout(() => execFile('cmdkey', [`/delete:TERMSRV/${host.address}`], () => {}), 20000);
|
||||
});
|
||||
} else run();
|
||||
return { client: 'mstsc' };
|
||||
}
|
||||
|
||||
const client = linuxClient(settings.rdpClientLinux);
|
||||
if (!client) throw new Error('Kein FreeRDP gefunden. Installieren mit: sudo pacman -S freerdp');
|
||||
const args = [`/v:${host.address}:${port}`, '/cert:tofu', '+auto-reconnect'];
|
||||
if (host.username) args.push(`/u:${host.username}`);
|
||||
if (host.domain) args.push(`/d:${host.domain}`);
|
||||
if (host.rdpFullscreen) args.push('/f');
|
||||
else if (host.rdpWidth && host.rdpHeight) args.push(`/size:${host.rdpWidth}x${host.rdpHeight}`);
|
||||
else args.push('/dynamic-resolution');
|
||||
if (host.rdpClipboard !== false) args.push('+clipboard');
|
||||
if (host.rdpDrives) args.push(`/drive:home,${os.homedir()}`);
|
||||
if (host.rdpAudio !== false) args.push('/sound');
|
||||
args.push(`/title:${host.label || host.address}`);
|
||||
// Passwort über stdin statt Kommandozeile (nicht in `ps` sichtbar)
|
||||
if (host.password) args.push('/from-stdin');
|
||||
const p = spawn(client, args, { detached: true, stdio: [host.password ? 'pipe' : 'ignore', 'ignore', 'pipe'] });
|
||||
if (host.password) { p.stdin.write(host.password + '\n'); p.stdin.end(); }
|
||||
let err = '';
|
||||
p.stderr.on('data', (d) => { err += d; });
|
||||
p.unref();
|
||||
return { client, process: p, getErr: () => err };
|
||||
}
|
||||
|
||||
module.exports = { detect, launch };
|
||||
+324
@@ -0,0 +1,324 @@
|
||||
// SSH-Verbindungen: Terminal-Shells, SFTP, Port-Forwarding (L/R/D), Jump-Hosts.
|
||||
const { Client } = require('ssh2');
|
||||
const net = require('net');
|
||||
const fs = require('fs');
|
||||
const os = require('os');
|
||||
const path = require('path');
|
||||
const crypto = require('crypto');
|
||||
|
||||
function defaultAgent() {
|
||||
if (process.env.SSH_AUTH_SOCK) return process.env.SSH_AUTH_SOCK;
|
||||
if (process.platform === 'win32') return '\\\\.\\pipe\\openssh-ssh-agent';
|
||||
return undefined;
|
||||
}
|
||||
|
||||
class SshManager {
|
||||
/**
|
||||
* @param {import('./store').Store} store
|
||||
* @param {(host, fingerprint, known) => Promise<boolean>} confirmHostKey
|
||||
* @param {(sessionId, prompt) => Promise<string|null>} askSecret
|
||||
*/
|
||||
constructor(store, confirmHostKey, askSecret) {
|
||||
this.store = store;
|
||||
this.confirmHostKey = confirmHostKey;
|
||||
this.askSecret = askSecret;
|
||||
this.sessions = new Map(); // id -> { conn, stream, sftp, jumps[] }
|
||||
this.forwards = new Map(); // forwardId -> { conn, server, jumps }
|
||||
}
|
||||
|
||||
buildAuth(host, sessionId) {
|
||||
const cfg = {
|
||||
host: host.address,
|
||||
port: Number(host.port) || 22,
|
||||
username: host.username || os.userInfo().username,
|
||||
readyTimeout: 20000,
|
||||
keepaliveInterval: (this.store.get().settings.keepAlive || 0) * 1000,
|
||||
tryKeyboard: true,
|
||||
};
|
||||
if (host.keyId) {
|
||||
const key = this.store.resolveKey(host.keyId);
|
||||
if (key) {
|
||||
cfg.privateKey = key.privateKey;
|
||||
if (key.passphrase) cfg.passphrase = key.passphrase;
|
||||
}
|
||||
}
|
||||
if (host.password) cfg.password = host.password;
|
||||
if (host.useAgent !== false) cfg.agent = defaultAgent();
|
||||
|
||||
cfg.hostVerifier = (keyBuf, verify) => {
|
||||
const fp = 'SHA256:' + crypto.createHash('sha256').update(keyBuf).digest('base64').replace(/=+$/, '');
|
||||
const id = `[${cfg.host}]:${cfg.port}`;
|
||||
const known = this.store.get().knownHosts[id];
|
||||
if (known && known.fingerprint === fp) return verify(true);
|
||||
this.confirmHostKey({ id, host: cfg.host, port: cfg.port }, fp, known).then((ok) => {
|
||||
if (ok) {
|
||||
this.store.get().knownHosts[id] = { fingerprint: fp, addedAt: Date.now() };
|
||||
this.store.save();
|
||||
}
|
||||
verify(ok);
|
||||
});
|
||||
};
|
||||
return cfg;
|
||||
}
|
||||
|
||||
// Baut eine Verbindung auf, optional über eine Kette von Jump-Hosts.
|
||||
async connect(host, sessionId, onStatus = () => {}) {
|
||||
const chain = [];
|
||||
let jumpId = host.jumpHostId;
|
||||
const seen = new Set([host.id]);
|
||||
while (jumpId && !seen.has(jumpId)) {
|
||||
seen.add(jumpId);
|
||||
const j = this.store.resolveHost(jumpId);
|
||||
if (!j) break;
|
||||
chain.unshift(j);
|
||||
jumpId = j.jumpHostId;
|
||||
}
|
||||
const opened = [];
|
||||
let sock;
|
||||
try {
|
||||
for (const hop of [...chain, host]) {
|
||||
onStatus(`Verbinde mit ${hop.label || hop.address} (${hop.address}:${hop.port || 22}) …`);
|
||||
const conn = await this.openClient(hop, sessionId, sock);
|
||||
opened.push(conn);
|
||||
if (hop !== host) {
|
||||
const next = hop === chain[chain.length - 1] ? host : chain[chain.indexOf(hop) + 1];
|
||||
sock = await new Promise((res, rej) =>
|
||||
conn.forwardOut('127.0.0.1', 0, next.address, Number(next.port) || 22, (err, s) => (err ? rej(err) : res(s))));
|
||||
}
|
||||
}
|
||||
} catch (e) {
|
||||
opened.forEach((c) => c.end());
|
||||
throw e;
|
||||
}
|
||||
const conn = opened.pop();
|
||||
return { conn, jumps: opened };
|
||||
}
|
||||
|
||||
openClient(host, sessionId, sock) {
|
||||
return new Promise((resolve, reject) => {
|
||||
const conn = new Client();
|
||||
const cfg = this.buildAuth(host, sessionId);
|
||||
if (sock) { cfg.sock = sock; delete cfg.host; }
|
||||
let askedPassword = false;
|
||||
conn.on('keyboard-interactive', async (name, instr, lang, prompts, finish) => {
|
||||
const answers = [];
|
||||
for (const p of prompts) {
|
||||
if (!p.echo && host.password && !askedPassword) { answers.push(host.password); askedPassword = true; continue; }
|
||||
const a = await this.askSecret(sessionId, { title: name || 'Anmeldung', prompt: p.prompt, echo: p.echo, host: host.label || host.address });
|
||||
if (a == null) return finish([]);
|
||||
answers.push(a);
|
||||
}
|
||||
finish(answers);
|
||||
});
|
||||
conn.once('ready', () => resolve(conn));
|
||||
conn.once('error', async (err) => {
|
||||
// Kein Passwort hinterlegt und alle Methoden schlugen fehl -> nach Passwort fragen und neu versuchen
|
||||
if (err.level === 'client-authentication' && !host.password && !host._retried) {
|
||||
const pw = await this.askSecret(sessionId, { title: 'Passwort', prompt: `Passwort für ${cfg.username}@${host.address}`, echo: false, host: host.label || host.address });
|
||||
if (pw != null) {
|
||||
this.openClient({ ...host, password: pw, _retried: true }, sessionId, sock).then(resolve, reject);
|
||||
return;
|
||||
}
|
||||
}
|
||||
reject(err);
|
||||
});
|
||||
try { conn.connect(cfg); } catch (e) { reject(e); }
|
||||
});
|
||||
}
|
||||
|
||||
// ---------- Terminal ----------
|
||||
async openShell(sessionId, host, { cols, rows }, send) {
|
||||
const { conn, jumps } = await this.connect(host, sessionId, (m) => send('status', m));
|
||||
const sess = { conn, jumps, host };
|
||||
this.sessions.set(sessionId, sess);
|
||||
conn.on('close', () => { send('closed'); this.cleanup(sessionId); });
|
||||
conn.on('error', (e) => send('error', e.message));
|
||||
|
||||
const env = host.env ? Object.fromEntries(host.env.split('\n').filter(Boolean).map((l) => l.split('=').map((s) => s.trim()))) : undefined;
|
||||
await new Promise((res, rej) => {
|
||||
conn.shell({ term: 'xterm-256color', cols, rows }, { env }, (err, stream) => {
|
||||
if (err) return rej(err);
|
||||
sess.stream = stream;
|
||||
stream.on('data', (d) => send('data', d.toString('utf8')));
|
||||
stream.stderr.on('data', (d) => send('data', d.toString('utf8')));
|
||||
stream.on('close', () => conn.end());
|
||||
if (host.startupCommand) stream.write(host.startupCommand + '\n');
|
||||
res();
|
||||
});
|
||||
});
|
||||
}
|
||||
|
||||
write(id, data) { this.sessions.get(id)?.stream?.write(data); }
|
||||
resize(id, cols, rows) { this.sessions.get(id)?.stream?.setWindow(rows, cols, 0, 0); }
|
||||
|
||||
close(id) {
|
||||
const s = this.sessions.get(id);
|
||||
if (!s) return;
|
||||
try { s.stream?.end(); } catch {}
|
||||
try { s.conn.end(); } catch {}
|
||||
this.cleanup(id);
|
||||
}
|
||||
|
||||
cleanup(id) {
|
||||
const s = this.sessions.get(id);
|
||||
if (!s) return;
|
||||
s.jumps?.forEach((c) => { try { c.end(); } catch {} });
|
||||
this.sessions.delete(id);
|
||||
}
|
||||
|
||||
// ---------- SFTP ----------
|
||||
async openSftp(sessionId, host) {
|
||||
const { conn, jumps } = await this.connect(host, sessionId);
|
||||
const sftp = await new Promise((res, rej) => conn.sftp((e, s) => (e ? rej(e) : res(s))));
|
||||
this.sessions.set(sessionId, { conn, jumps, sftp, host });
|
||||
conn.on('close', () => this.cleanup(sessionId));
|
||||
const home = await new Promise((res) => sftp.realpath('.', (e, p) => res(e ? '/' : p)));
|
||||
return { home };
|
||||
}
|
||||
|
||||
sftpOf(id) {
|
||||
const s = this.sessions.get(id);
|
||||
if (!s?.sftp) throw new Error('SFTP-Sitzung nicht gefunden');
|
||||
return s.sftp;
|
||||
}
|
||||
|
||||
sftpList(id, dir) {
|
||||
const sftp = this.sftpOf(id);
|
||||
return new Promise((res, rej) => sftp.readdir(dir, (err, list) => {
|
||||
if (err) return rej(err);
|
||||
res(list.map((f) => ({
|
||||
name: f.filename,
|
||||
size: f.attrs.size,
|
||||
mtime: f.attrs.mtime * 1000,
|
||||
isDir: (f.attrs.mode & 0o170000) === 0o040000,
|
||||
isLink: (f.attrs.mode & 0o170000) === 0o120000,
|
||||
mode: f.attrs.mode,
|
||||
})));
|
||||
}));
|
||||
}
|
||||
|
||||
sftpOp(id, op, a, b) {
|
||||
const sftp = this.sftpOf(id);
|
||||
const cb = (res, rej) => (err, v) => (err ? rej(err) : res(v));
|
||||
return new Promise((res, rej) => {
|
||||
switch (op) {
|
||||
case 'mkdir': return sftp.mkdir(a, cb(res, rej));
|
||||
case 'rename': return sftp.rename(a, b, cb(res, rej));
|
||||
case 'unlink': return sftp.unlink(a, cb(res, rej));
|
||||
case 'rmdir': return this.sftpRmRf(sftp, a).then(res, rej);
|
||||
case 'realpath': return sftp.realpath(a, cb(res, rej));
|
||||
case 'chmod': return sftp.chmod(a, b, cb(res, rej));
|
||||
default: rej(new Error('Unbekannte Operation ' + op));
|
||||
}
|
||||
});
|
||||
}
|
||||
|
||||
async sftpRmRf(sftp, dir) {
|
||||
const list = await new Promise((res, rej) => sftp.readdir(dir, (e, l) => (e ? rej(e) : res(l))));
|
||||
for (const f of list) {
|
||||
const p = path.posix.join(dir, f.filename);
|
||||
if ((f.attrs.mode & 0o170000) === 0o040000) await this.sftpRmRf(sftp, p);
|
||||
else await new Promise((res, rej) => sftp.unlink(p, (e) => (e ? rej(e) : res())));
|
||||
}
|
||||
await new Promise((res, rej) => sftp.rmdir(dir, (e) => (e ? rej(e) : res())));
|
||||
}
|
||||
|
||||
async transfer(id, direction, localPath, remotePath, progress) {
|
||||
const sftp = this.sftpOf(id);
|
||||
const step = (done, _chunk, total) => progress(done, total);
|
||||
if (direction === 'download') {
|
||||
const st = await new Promise((res, rej) => sftp.stat(remotePath, (e, s) => (e ? rej(e) : res(s))));
|
||||
if ((st.mode & 0o170000) === 0o040000) {
|
||||
fs.mkdirSync(localPath, { recursive: true });
|
||||
for (const f of await this.sftpList(id, remotePath))
|
||||
await this.transfer(id, direction, path.join(localPath, f.name), path.posix.join(remotePath, f.name), progress);
|
||||
return;
|
||||
}
|
||||
await new Promise((res, rej) => sftp.fastGet(remotePath, localPath, { step }, (e) => (e ? rej(e) : res())));
|
||||
} else {
|
||||
const st = fs.statSync(localPath);
|
||||
if (st.isDirectory()) {
|
||||
await new Promise((res) => sftp.mkdir(remotePath, () => res()));
|
||||
for (const name of fs.readdirSync(localPath))
|
||||
await this.transfer(id, direction, path.join(localPath, name), path.posix.join(remotePath, name), progress);
|
||||
return;
|
||||
}
|
||||
await new Promise((res, rej) => sftp.fastPut(localPath, remotePath, { step }, (e) => (e ? rej(e) : res())));
|
||||
}
|
||||
}
|
||||
|
||||
// ---------- Port-Forwarding ----------
|
||||
async startForward(fw, onEvent) {
|
||||
const host = this.store.resolveHost(fw.hostId);
|
||||
if (!host) throw new Error('Host nicht gefunden');
|
||||
const { conn, jumps } = await this.connect(host, 'fw-' + fw.id);
|
||||
const entry = { conn, jumps };
|
||||
this.forwards.set(fw.id, entry);
|
||||
conn.on('close', () => { this.stopForward(fw.id); onEvent('stopped'); });
|
||||
const bindHost = fw.bindAddress || '127.0.0.1';
|
||||
|
||||
if (fw.type === 'remote') {
|
||||
await new Promise((res, rej) => conn.forwardIn(bindHost, Number(fw.bindPort), (e) => (e ? rej(e) : res())));
|
||||
conn.on('tcp connection', (info, accept) => {
|
||||
const ch = accept();
|
||||
const sock = net.connect(Number(fw.destPort), fw.destHost || '127.0.0.1');
|
||||
ch.pipe(sock).pipe(ch);
|
||||
sock.on('error', () => ch.close());
|
||||
});
|
||||
return;
|
||||
}
|
||||
|
||||
const server = net.createServer((sock) => {
|
||||
if (fw.type === 'dynamic') return this.socks5(conn, sock);
|
||||
conn.forwardOut(sock.remoteAddress || '127.0.0.1', sock.remotePort || 0, fw.destHost, Number(fw.destPort), (err, ch) => {
|
||||
if (err) return sock.destroy();
|
||||
sock.pipe(ch).pipe(sock);
|
||||
sock.on('error', () => ch.close());
|
||||
});
|
||||
});
|
||||
entry.server = server;
|
||||
await new Promise((res, rej) => { server.once('error', rej); server.listen(Number(fw.bindPort), bindHost, res); });
|
||||
}
|
||||
|
||||
// Minimaler SOCKS5-Server (CONNECT, ohne Auth) für dynamisches Forwarding
|
||||
socks5(conn, sock) {
|
||||
sock.once('data', (hello) => {
|
||||
if (hello[0] !== 5) return sock.destroy();
|
||||
sock.write(Buffer.from([5, 0]));
|
||||
sock.once('data', (req) => {
|
||||
if (req[1] !== 1) { sock.end(Buffer.from([5, 7, 0, 1, 0, 0, 0, 0, 0, 0])); return; }
|
||||
let host, off;
|
||||
if (req[3] === 1) { host = [...req.slice(4, 8)].join('.'); off = 8; }
|
||||
else if (req[3] === 3) { const l = req[4]; host = req.slice(5, 5 + l).toString(); off = 5 + l; }
|
||||
else if (req[3] === 4) { host = req.slice(4, 20).toString('hex').match(/.{4}/g).join(':'); off = 20; }
|
||||
else return sock.destroy();
|
||||
const port = req.readUInt16BE(off);
|
||||
conn.forwardOut('127.0.0.1', 0, host, port, (err, ch) => {
|
||||
if (err) { sock.end(Buffer.from([5, 5, 0, 1, 0, 0, 0, 0, 0, 0])); return; }
|
||||
sock.write(Buffer.from([5, 0, 0, 1, 0, 0, 0, 0, 0, 0]));
|
||||
sock.pipe(ch).pipe(sock);
|
||||
sock.on('error', () => ch.close());
|
||||
});
|
||||
});
|
||||
});
|
||||
sock.on('error', () => {});
|
||||
}
|
||||
|
||||
stopForward(id) {
|
||||
const f = this.forwards.get(id);
|
||||
if (!f) return;
|
||||
this.forwards.delete(id);
|
||||
try { f.server?.close(); } catch {}
|
||||
try { f.conn.end(); } catch {}
|
||||
f.jumps?.forEach((c) => { try { c.end(); } catch {} });
|
||||
}
|
||||
|
||||
activeForwards() { return [...this.forwards.keys()]; }
|
||||
|
||||
closeAll() {
|
||||
for (const id of [...this.sessions.keys()]) this.close(id);
|
||||
for (const id of [...this.forwards.keys()]) this.stopForward(id);
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { SshManager };
|
||||
@@ -0,0 +1,107 @@
|
||||
// Persistenter Vault: Hosts, Keys, Snippets, Forwards, Settings.
|
||||
// Wird mit Electron safeStorage (DPAPI unter Windows, libsecret/kwallet unter Linux) verschlüsselt.
|
||||
const { app, safeStorage } = require('electron');
|
||||
const fs = require('fs');
|
||||
const path = require('path');
|
||||
const crypto = require('crypto');
|
||||
|
||||
const DEFAULTS = {
|
||||
version: 1,
|
||||
groups: [],
|
||||
hosts: [],
|
||||
keys: [],
|
||||
snippets: [],
|
||||
forwards: [],
|
||||
knownHosts: {},
|
||||
history: [],
|
||||
settings: {
|
||||
terminalTheme: 'mrterm',
|
||||
fontFamily: 'Cascadia Code, JetBrains Mono, Fira Code, Consolas, monospace',
|
||||
fontSize: 14,
|
||||
cursorStyle: 'block',
|
||||
cursorBlink: true,
|
||||
scrollback: 10000,
|
||||
copyOnSelect: true,
|
||||
keepAlive: 30,
|
||||
rdpClientLinux: 'auto',
|
||||
},
|
||||
};
|
||||
|
||||
class Store {
|
||||
constructor() {
|
||||
this.dir = app.getPath('userData');
|
||||
this.file = path.join(this.dir, 'vault.dat');
|
||||
this.data = structuredClone(DEFAULTS);
|
||||
this.encrypted = false;
|
||||
}
|
||||
|
||||
canEncrypt() {
|
||||
try {
|
||||
if (!safeStorage.isEncryptionAvailable()) return false;
|
||||
// Unter Linux ohne Keyring fällt Electron auf "basic_text" zurück – das ist keine echte Verschlüsselung.
|
||||
if (process.platform === 'linux' && safeStorage.getSelectedStorageBackend?.() === 'basic_text') return false;
|
||||
return true;
|
||||
} catch { return false; }
|
||||
}
|
||||
|
||||
load() {
|
||||
fs.mkdirSync(this.dir, { recursive: true });
|
||||
if (!fs.existsSync(this.file)) { this.save(); return this.data; }
|
||||
const raw = fs.readFileSync(this.file);
|
||||
let json;
|
||||
if (raw.slice(0, 4).toString() === 'ENC1') {
|
||||
json = safeStorage.decryptString(raw.slice(4));
|
||||
this.encrypted = true;
|
||||
} else {
|
||||
json = raw.toString('utf8');
|
||||
}
|
||||
const parsed = JSON.parse(json);
|
||||
this.data = { ...structuredClone(DEFAULTS), ...parsed, settings: { ...DEFAULTS.settings, ...(parsed.settings || {}) } };
|
||||
return this.data;
|
||||
}
|
||||
|
||||
save() {
|
||||
const json = JSON.stringify(this.data, null, 2);
|
||||
const tmp = this.file + '.tmp';
|
||||
if (this.canEncrypt()) {
|
||||
fs.writeFileSync(tmp, Buffer.concat([Buffer.from('ENC1'), safeStorage.encryptString(json)]));
|
||||
this.encrypted = true;
|
||||
} else {
|
||||
fs.writeFileSync(tmp, json, { mode: 0o600 });
|
||||
this.encrypted = false;
|
||||
}
|
||||
fs.renameSync(tmp, this.file);
|
||||
}
|
||||
|
||||
get() { return this.data; }
|
||||
|
||||
// Generisches Upsert für Collections (hosts, groups, keys, snippets, forwards)
|
||||
upsert(collection, item) {
|
||||
const list = this.data[collection];
|
||||
if (!Array.isArray(list)) throw new Error('Unbekannte Collection: ' + collection);
|
||||
if (!item.id) item.id = crypto.randomUUID();
|
||||
const i = list.findIndex((x) => x.id === item.id);
|
||||
if (i >= 0) list[i] = { ...list[i], ...item, updatedAt: Date.now() };
|
||||
else list.push({ ...item, createdAt: Date.now(), updatedAt: Date.now() });
|
||||
this.save();
|
||||
return item;
|
||||
}
|
||||
|
||||
remove(collection, id) {
|
||||
this.data[collection] = this.data[collection].filter((x) => x.id !== id);
|
||||
if (collection === 'groups') this.data.hosts.forEach((h) => { if (h.groupId === id) h.groupId = null; });
|
||||
this.save();
|
||||
}
|
||||
|
||||
setSettings(s) { this.data.settings = { ...this.data.settings, ...s }; this.save(); }
|
||||
|
||||
addHistory(entry) {
|
||||
this.data.history = [entry, ...this.data.history.filter((h) => h.hostId !== entry.hostId)].slice(0, 30);
|
||||
this.save();
|
||||
}
|
||||
|
||||
resolveHost(id) { return this.data.hosts.find((h) => h.id === id); }
|
||||
resolveKey(id) { return this.data.keys.find((k) => k.id === id); }
|
||||
}
|
||||
|
||||
module.exports = { Store };
|
||||
Reference in New Issue
Block a user