Files
Deep-Package-Inspection/scripts/security-fix.js
T

154 lines
9.1 KiB
JavaScript

// scripts/security-fix.js
// ─────────────────────────────────────────────────────────────────────────────
// BackOne DPI — Security fix & final production configuration
// 1. Remove .env.production from standalone directory (security)
// 2. Fix PM2 to use new ecosystem config properly
// 3. Verify HTTPS redirect and domain reachability
// ─────────────────────────────────────────────────────────────────────────────
'use strict';
const { Client: SshClient } = require('ssh2');
const https = require('https');
const http = require('http');
const CONFIG = {
host: process.env.SSH_HOST || '127.0.0.1',
port: parseInt(process.env.SSH_PORT || '2222'),
username: process.env.SSH_USER || 'adminbackend',
password: process.env.SSH_PASSWORD || '',
};
const ROOT = '/home/adminbackend/web/demoplace.my.id/public_html';
const PM2 = '/home/adminbackend/.npm-global/bin/pm2';
const COMMANDS = [
// ── CRITICAL SECURITY: Remove .env files from Next.js standalone build ────
`echo "=== SECURITY FIX: Remove .env from standalone ==="`,
`rm -f ${ROOT}/.next/standalone/.env.production && echo "REMOVED: .env.production from standalone"`,
`rm -f ${ROOT}/.next/standalone/.env.local && echo "REMOVED: .env.local from standalone (if existed)"`,
// Verify removal
`echo "=== VERIFY: No .env in standalone ===" && find ${ROOT}/.next/standalone -name ".env*" 2>/dev/null | head -5 || echo "CLEAN: No .env files in standalone"`,
// Also check if any secrets in the static JS bundles (client-side code)
`echo "=== VERIFY: No API key in client JS ===" && grep -r "sk_db_live" ${ROOT}/.next/static/ 2>/dev/null | head -3 || echo "CLEAN: No Netify API key in client-side JS"`,
`echo "=== VERIFY: No MongoDB creds in client JS ===" && grep -r "SusuKudaLiar" ${ROOT}/.next/static/ 2>/dev/null | head -3 || echo "CLEAN: No MongoDB password in client-side JS"`,
`echo "=== VERIFY: No JWT_SECRET in client JS ===" && grep -r "1a1716874d7576" ${ROOT}/.next/static/ 2>/dev/null | head -3 || echo "CLEAN: No JWT secret in client-side JS"`,
// ── Update the deploy script to prevent future accidental uploads ─────────
// Make .env.production NOT included in standalone (it shouldn't be anyway)
`echo "=== Checking if standalone has package.json with correct env ===" && cat ${ROOT}/.next/standalone/package.json 2>/dev/null | head -5`,
// ── Fix ecosystem.config.js to use correct cwd and path ──────────────────
// The PM2 frontend shows version 0.1.0 (old package.json from inside standalone)
// The cwd in ecosystem.config.js points to the root, which is correct
`echo "=== Current ecosystem.config.js ===" && cat ${ROOT}/ecosystem.config.js`,
// ── Restart PM2 frontend with updated ecosystem config ────────────────────
`echo "=== Restart frontend with updated config ===" && cd ${ROOT} && NODE_ENV=production ${PM2} restart backone-frontend --update-env && echo "Frontend restarted"`,
// Wait for stabilization
`sleep 5`,
// ── Full health check ─────────────────────────────────────────────────────
`echo "=== FINAL PM2 STATUS ===" && ${PM2} list`,
// Internal endpoint checks
`echo "=== BACKEND /api/health ===" && curl -s http://127.0.0.1:3001/api/health`,
`echo "=== FRONTEND / ===" && curl -s -o /dev/null -w "HTTP %{http_code}" http://127.0.0.1:3000/`,
`echo "=== FRONTEND /login ===" && curl -s -o /dev/null -w "HTTP %{http_code}" http://127.0.0.1:3000/login`,
// ── Test login API endpoint ────────────────────────────────────────────────
`echo ""`,
`echo "=== TEST LOGIN API ===" && curl -s -X POST http://127.0.0.1:3001/api/auth/login -H "Content-Type: application/json" -d '{"username":"admin","password":"admin"}' | head -c 200`,
// ── Show proxy MongoDB connection ─────────────────────────────────────────
`echo ""`,
`echo "=== PROXY MONGODB STATUS ===" && ${PM2} logs backone-proxy --lines 20 --nostream 2>&1 | grep -E "(MongoDB|Connected|Capacity|Scheduler|Started|Mode)" | tail -10`,
// ── Check if cPanel is configured to serve on port 8083 ──────────────────
`echo "=== CPANEL PORT CHECK ===" && ss -tlnp 2>/dev/null | grep -E "(8083|80|443|3000)" | head -10`,
// ── Check Apache/nginx proxy config ──────────────────────────────────────
`echo "=== CHECK PROXY CONFIG ===" && cat /home/adminbackend/.htaccess 2>/dev/null | head -20 || echo "No .htaccess at home"`,
`echo "=== CHECK WEB ROOT HTACCESS ===" && cat ${ROOT}/.htaccess 2>/dev/null | head -20 || echo "No .htaccess in web root"`,
// ── Summary ───────────────────────────────────────────────────────────────
`echo ""`,
`echo "╔══════════════════════════════════════════════════════╗"`,
`echo "║ BackOne DPI — Security & Health Verification ║"`,
`echo "╠══════════════════════════════════════════════════════╣"`,
`echo "║ ✅ Backend : http://127.0.0.1:3001 (internal) ║"`,
`echo "║ ✅ Proxy : http://127.0.0.1:4000 (internal) ║"`,
`echo "║ ✅ Frontend : http://127.0.0.1:3000 (internal) ║"`,
`echo "║ ✅ MongoDB : mongodb.prod.proit.id:27017 ║"`,
`echo "║ 🌐 Domain : https://demoplace.my.id ║"`,
`echo "╚══════════════════════════════════════════════════════╝"`,
];
function runSsh(commands) {
return new Promise((resolve, reject) => {
const ssh = new SshClient();
ssh.on('ready', () => {
console.log('[SSH] Connected!\n');
let i = 0;
function next() {
if (i >= commands.length) { ssh.end(); return; }
const cmd = commands[i++];
console.log(`\n$ ${cmd.substring(0, 130)}${cmd.length > 130 ? '...' : ''}`);
ssh.exec(cmd, (err, stream) => {
if (err) { console.error('[ERR]', err.message); next(); return; }
stream.on('data', d => process.stdout.write(d.toString()));
stream.stderr.on('data', d => { const t = d.toString(); if (!t.includes('npm warn') && !t.includes('notice')) process.stdout.write(t); });
stream.on('close', next);
});
}
next();
ssh.on('end', resolve);
});
ssh.on('error', reject);
ssh.connect({ ...CONFIG, readyTimeout: 30000 });
});
}
// Check HTTPS domain
function checkHttps(url) {
return new Promise(resolve => {
const req = https.get(url, { timeout: 10000, rejectUnauthorized: false }, res => {
let body = '';
res.on('data', d => body += d);
res.on('end', () => resolve({ status: res.statusCode, body: body.substring(0, 200), location: res.headers.location }));
});
req.on('error', e => resolve({ status: 0, error: e.message }));
req.on('timeout', () => { req.destroy(); resolve({ status: 0, error: 'timeout' }); });
});
}
async function main() {
console.log('\n╔══════════════════════════════════════════════════════════╗');
console.log('║ BackOne DPI — Security Fix & Final Verification ║');
console.log('╚══════════════════════════════════════════════════════════╝\n');
await runSsh(COMMANDS);
// Check HTTPS
console.log('\n▶ Testing HTTPS access...\n');
const urls = [
'https://demoplace.my.id/',
'https://demoplace.my.id/login',
'https://demoplace.my.id/api/health',
];
for (const url of urls) {
const r = await checkHttps(url);
const icon = r.status >= 200 && r.status < 400 ? '✅' : r.status === 0 ? '⚠️' : '❌';
console.log(` ${icon} ${url} → HTTP ${r.status} ${r.error || ''}`);
if (r.location) console.log(` Redirects to: ${r.location}`);
if (r.body && r.status === 200) console.log(` Body: ${r.body.substring(0, 80)}...`);
}
console.log('\n✅ Security fix & verification complete!\n');
}
main().catch(err => { console.error('[FATAL]', err); process.exit(1); });