29 lines
3.0 KiB
Markdown
29 lines
3.0 KiB
Markdown
# Iteration Log - 2026-07-24-1126-adhoc-branding-and-site-isolation
|
|
|
|
## Request
|
|
Address branding leaks (BackOne logos and titles showing up on the Nexus site) and eliminate cross-tenant data leakage (SIAB agents and data appearing on the Nexus site). Ensure that data isolation is strict, so that non-global admins can only query data belonging to their respective sites.
|
|
|
|
## Steps Taken
|
|
|
|
1. **Created Branding Detection System**:
|
|
- Added [branding.ts](file:///c:/Users/demo/Downloads/Deep%20Package%20Inspection/src/lib/branding.ts) to detect whether the user is on the "Nexus", "SIAB", or "BackOne" site based on URL hostname, localStorage, and query arguments.
|
|
2. **Branded Login Page**:
|
|
- Updated [login/page.tsx](file:///c:/Users/demo/Downloads/Deep%20Package%20Inspection/src/app/login/page.tsx) to dynamically choose the correct logo and text headings matching the host domain.
|
|
3. **Reactive Sidebar Branding & Title Replacement**:
|
|
- Refactored [Sidebar.tsx](file:///c:/Users/demo/Downloads/Deep%20Package%20Inspection/src/components/layout/Sidebar.tsx) to auto-lock the selected site state based on the logged-in user's site UUID if they are a `TENANT_ADMIN` or `AGENT_VIEWER`.
|
|
- Intercepted `document.title` on the client side using `Object.defineProperty` to dynamically rewrite tab titles (e.g. replacing "BackOne" with "Nexus" when on the Nexus tenant site).
|
|
4. **Site-Isolated Server Action**:
|
|
- Secured `getAgents` in [agents.ts](file:///c:/Users/demo/Downloads/Deep%20Package%20Inspection/src/lib/actions/agents.ts) by verifying the session cookie inside Next.js Server Actions using a new helper `getAuthUser()`. Restricts the queried site UUID to the tenant admin's site UUID.
|
|
5. **Site-Isolated Backend REST Endpoints**:
|
|
- Updated `/api/dashboard/agents/uptime` and `/api/dashboard/agents/storage` to enforce strict site filtering. In particular, the storage stats endpoint now filters out any agent IDs that do not belong to the active site.
|
|
6. **Automated Site Isolation Testing**:
|
|
- Created [test-site-isolation.js](file:///c:/Users/demo/Downloads/Deep%20Package%20Inspection/test/test-site-isolation.js) to assert that logging in as Nexus Admin only exposes Nexus agents, with zero SIAB data leakages.
|
|
|
|
## Outcome
|
|
- **TDD Integration Verification**: `node test/test-site-isolation.js` passed successfully. Uptime and storage keys returned strictly contain Nexus agents (`2N-ID-VQ-AL`, `1T-5Q-RC-AS`), with 0 leaks from SIAB.
|
|
- **Dynamic Branding**: The login page and dashboard sidebar correctly switch logos and page tab titles dynamically when navigating under the Nexus site.
|
|
- **Production Build and Deployment**: The Next.js production build succeeded locally. The remote deployment was fully uploaded to PM2 server, and reloads completed without errors.
|
|
|
|
## Considerations for Next Time
|
|
- Whenever adding new dashboards or sub-routers in `backend/routes/dashboard/`, always use `getBaseFilter(req)` or verify that JWT/role site overrides are applied correctly so that site-scoped admins are restricted.
|