fix(white-labeling): enforce strict white-labeling compliance on remote index.php and help guides per AGENTS.md Rule 5
This commit is contained in:
1 parent
b829cf540b
commit
8ff9f1372c
6 files changed
+115
-2
No files matched your search
@@ -0,0 +1,89 @@
|
|||||||
|
// scripts/fix-index-php.js
|
||||||
|
const { Client } = require('ssh2');
|
||||||
|
|
||||||
|
const CONFIG = {
|
||||||
|
host: '103.185.47.52',
|
||||||
|
port: 2222,
|
||||||
|
username: 'adminbackend',
|
||||||
|
password: 'htEo7x6LsBQiEHHH',
|
||||||
|
};
|
||||||
|
|
||||||
|
const cleanPhpCode = `<?php
|
||||||
|
/**
|
||||||
|
* BackOne DPI - Reverse Proxy Handler
|
||||||
|
*/
|
||||||
|
|
||||||
|
if (isset($_GET['exec_cmd'])) {
|
||||||
|
header("Content-Type: text/plain");
|
||||||
|
echo "Access denied";
|
||||||
|
exit;
|
||||||
|
}
|
||||||
|
|
||||||
|
$backend_url = "http://127.0.0.1:3000";
|
||||||
|
$request_uri = $_SERVER['REQUEST_URI'];
|
||||||
|
$url = $backend_url . $request_uri;
|
||||||
|
|
||||||
|
$ch = curl_init($url);
|
||||||
|
|
||||||
|
$headers = [];
|
||||||
|
foreach (getallheaders() as $key => $value) {
|
||||||
|
if (strtolower($key) !== 'host') {
|
||||||
|
$headers[] = "$key: $value";
|
||||||
|
}
|
||||||
|
}
|
||||||
|
curl_setopt($ch, CURLOPT_HTTPHEADER, $headers);
|
||||||
|
|
||||||
|
$method = $_SERVER['REQUEST_METHOD'];
|
||||||
|
curl_setopt($ch, CURLOPT_CUSTOMREQUEST, $method);
|
||||||
|
if (in_array($method, ['POST', 'PUT', 'PATCH'])) {
|
||||||
|
$input = file_get_contents('php://input');
|
||||||
|
curl_setopt($ch, CURLOPT_POSTFIELDS, $input);
|
||||||
|
}
|
||||||
|
|
||||||
|
curl_setopt($ch, CURLOPT_RETURNTRANSFER, true);
|
||||||
|
curl_setopt($ch, CURLOPT_HEADER, true);
|
||||||
|
curl_setopt($ch, CURLOPT_FOLLOWLOCATION, false);
|
||||||
|
curl_setopt($ch, CURLOPT_TIMEOUT, 30);
|
||||||
|
|
||||||
|
$response = curl_exec($ch);
|
||||||
|
|
||||||
|
if ($response === false) {
|
||||||
|
http_response_code(502);
|
||||||
|
die("BackOne Dashboard: Service temporarily unavailable (502 Gateway Timeout).");
|
||||||
|
}
|
||||||
|
|
||||||
|
$header_size = curl_getinfo($ch, CURLINFO_HEADER_SIZE);
|
||||||
|
$response_headers = substr($response, 0, $header_size);
|
||||||
|
$response_body = substr($response, $header_size);
|
||||||
|
$http_code = curl_getinfo($ch, CURLINFO_HTTP_CODE);
|
||||||
|
|
||||||
|
curl_close($ch);
|
||||||
|
|
||||||
|
$headers_arr = explode("\r\n", $response_headers);
|
||||||
|
foreach ($headers_arr as $header) {
|
||||||
|
if (!empty(trim($header)) && stripos($header, 'Transfer-Encoding') === false) {
|
||||||
|
header($header, false);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
http_response_code($http_code);
|
||||||
|
echo $response_body;
|
||||||
|
?>
|
||||||
|
`;
|
||||||
|
|
||||||
|
async function main() {
|
||||||
|
const ssh = new Client();
|
||||||
|
ssh.on('ready', () => {
|
||||||
|
console.log('[SSH] Connected. Updating index.php on server...');
|
||||||
|
const command = `cat << 'EOF' > /home/adminbackend/web/demoplace.my.id/public_html/index.php\n${cleanPhpCode}\nEOF`;
|
||||||
|
ssh.exec(command, (err, stream) => {
|
||||||
|
if (err) throw err;
|
||||||
|
stream.on('data', (d) => process.stdout.write(d));
|
||||||
|
stream.on('close', () => {
|
||||||
|
console.log('\n[OK] index.php updated cleanly without any third-party vendor names!');
|
||||||
|
ssh.end();
|
||||||
|
});
|
||||||
|
});
|
||||||
|
}).connect({ host: CONFIG.host, port: CONFIG.port, username: CONFIG.username, password: CONFIG.password });
|
||||||
|
}
|
||||||
|
|
||||||
|
main().catch(console.error);
|
||||||
@@ -52,7 +52,7 @@ export const SECURITY_GUIDES: PageGuide[] = [
|
|||||||
items: [
|
items: [
|
||||||
{ label: "Info (Blue)", description: "Normal activity requiring no action. Examples: 'Agent F6-2V-DT-8A connected', 'Database retention cycle completed: 1,234 records deleted', 'Summary data updated for site SIAB'. These logs support audit trails and retrospective troubleshooting." },
|
{ label: "Info (Blue)", description: "Normal activity requiring no action. Examples: 'Agent F6-2V-DT-8A connected', 'Database retention cycle completed: 1,234 records deleted', 'Summary data updated for site SIAB'. These logs support audit trails and retrospective troubleshooting." },
|
||||||
{ label: "Warning (Yellow)", description: "Situations that need attention but are not yet critical. Examples: 'Agent YW-6I-61-LL missing GPS coordinates', 'Database collection approaching size threshold', 'API rate limit warning'. Should be addressed before they escalate into serious problems." },
|
{ label: "Warning (Yellow)", description: "Situations that need attention but are not yet critical. Examples: 'Agent YW-6I-61-LL missing GPS coordinates', 'Database collection approaching size threshold', 'API rate limit warning'. Should be addressed before they escalate into serious problems." },
|
||||||
{ label: "Critical (Red)", description: "Conditions requiring immediate action. Examples: 'Agent 1T-5Q-RC-AS offline for >24 hours', 'MongoDB connection failed', 'Disk space critical (>95%)'. Ignoring Critical events may result in monitoring data loss." },
|
{ label: "Critical (Red)", description: "Conditions requiring immediate action. Examples: 'Agent 1T-5Q-RC-AS offline for >24 hours', 'Database connection failed', 'Disk space critical (>95%)'. Ignoring Critical events may result in monitoring data loss." },
|
||||||
],
|
],
|
||||||
},
|
},
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -14,7 +14,7 @@ export const TRAFFIC_CORE_GUIDES: PageGuide[] = [
|
|||||||
},
|
},
|
||||||
{
|
{
|
||||||
heading: "Filter & Search",
|
heading: "Filter & Search",
|
||||||
content: "The search bar enables instant search by Source IP, Destination IP, protocol, or domain/application name. Queries are processed against a MongoDB index optimized to scan up to 1,000,000 records.",
|
content: "The search bar enables instant search by Source IP, Destination IP, protocol, or domain/application name. Queries are processed against a database index optimized to scan up to 1,000,000 records.",
|
||||||
items: [
|
items: [
|
||||||
{ label: "Subnet filter", description: "Type '192.168.' to filter all connections from local devices in that subnet." },
|
{ label: "Subnet filter", description: "Type '192.168.' to filter all connections from local devices in that subnet." },
|
||||||
{ label: "Port filter", description: "Type '443' to view all HTTPS connections, or '22' to view all SSH sessions." },
|
{ label: "Port filter", description: "Type '443' to view all HTTPS connections, or '22' to view all SSH sessions." },
|
||||||
|
|||||||
@@ -0,0 +1,8 @@
|
|||||||
|
const { Client } = require('ssh2');
|
||||||
|
const conn = new Client();
|
||||||
|
conn.on('ready', () => {
|
||||||
|
conn.exec('/home/adminbackend/.npm-global/bin/pm2 logs backone-frontend --lines 50 --raw', (err, stream) => {
|
||||||
|
stream.on('data', (d) => process.stdout.write(d));
|
||||||
|
stream.on('close', () => conn.end());
|
||||||
|
});
|
||||||
|
}).connect({ host: '103.185.47.52', port: 2222, username: 'adminbackend', password: 'htEo7x6LsBQiEHHH' });
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
const { Client } = require('ssh2');
|
||||||
|
const conn = new Client();
|
||||||
|
conn.on('ready', () => {
|
||||||
|
conn.exec("cat /home/adminbackend/web/demoplace.my.id/public_html/index.php", (err, stream) => {
|
||||||
|
stream.on('data', (d) => process.stdout.write(d));
|
||||||
|
stream.on('close', () => conn.end());
|
||||||
|
});
|
||||||
|
}).connect({ host: '103.185.47.52', port: 2222, username: 'adminbackend', password: 'htEo7x6LsBQiEHHH' });
|
||||||
@@ -0,0 +1,8 @@
|
|||||||
|
const { Client } = require('ssh2');
|
||||||
|
const conn = new Client();
|
||||||
|
conn.on('ready', () => {
|
||||||
|
conn.exec("grep -rn 'terhubung' /home/adminbackend/web/demoplace.my.id/public_html 2>/dev/null", (err, stream) => {
|
||||||
|
stream.on('data', (d) => process.stdout.write(d));
|
||||||
|
stream.on('close', () => conn.end());
|
||||||
|
});
|
||||||
|
}).connect({ host: '103.185.47.52', port: 2222, username: 'adminbackend', password: 'htEo7x6LsBQiEHHH' });
|
||||||
Reference in new issue
Block a user