Commit graph

136 commits

Author SHA1 Message Date
dc805c2086 Add topology maps with LLDP discovery and React Flow canvas.
Includes map CRUD, graph save, neighbor discover, and UI controls for labels, sidebar, and edge flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 23:53:06 +08:00
3b8342acfb fix(webcrt): keep device echo intact and stop dual-WS steal.
Use raw Telnet reads for ANSI backspace, drop local erase so Tab/completion stays in sync, and make WebSocket attach exclusive so StrictMode remounts cannot drop the first echo.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 22:27:15 +08:00
fae26cf9bb fix(webcrt): restore full login transcript on attach
Keep the complete session_log replay including the final prompt, and stop clearing bootstrap on attach so StrictMode remounts do not blank the CRT.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 19:57:02 +08:00
89ff0a7212 Improve WebCRT UX: real login transcript, session tools, and first-input sync.
Capture Netmiko session_log for login replay, open NE terminals in a fresh tab, tidy the device list UI with reconnect/log/clear/copy, and paint a live prompt after attach so the first keystrokes behave normally.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 19:53:41 +08:00
30f2db9708 fix(webcrt): replay login banner/prompt on attach
Drain and nudge the device prompt after Netmiko login, replay bootstrap stdout when the WebSocket attaches, and surface connect errors in the terminal pane.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 18:54:59 +08:00
8e3bed562f fix(webcrt): map backspace and arrows for network device CLIs
Huawei/ZTE/Cisco Telnet often rejects xterm DEL and CSI arrows; rewrite them to BS and emacs Ctrl-B/F/P/N so editing and history work.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 18:44:13 +08:00
1f2e028337 fix(webcrt): install websockets and connect WS to API in Vite dev
Uvicorn had no WebSocket implementation without the websockets package, causing browser websocket_error. Also bypass flaky Vite WS proxy by targeting :8890 in local UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:37:32 +08:00
183cb7eec9 fix(webcrt): keep session across WS remount and fix blank terminal
Allow brief WebSocket re-attach after React StrictMode cleanup, ensure terminal pane has layout height, and show connect status in xterm.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:32:23 +08:00
873f2bfe34 feat(webcrt): add CRT-style browser terminal for managed and UME NEs
Ship an ops WebCRT module with xterm.js UI, WebSocket session bridge reusing hop/bastion login, searchable paged targets, and session audit limits.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:23:45 +08:00
88479245bb feat(ne-exec): make max CLI commands configurable and allow traceroute
Add NETX_NE_EXEC_MAX_COMMANDS (default 5, cap 50) and whitelist traceroute/tracert/trace/trace6 prefixes for lab/ops use.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 10:57:55 +08:00
a6a5abc9ef fix(ne-exec): allow no-more in managed NE CLI pipe whitelist
Support Huawei-style display ... | no-more alongside existing read-only pipe filters.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-14 16:49:44 +08:00
33af0efc98 fix(ne-exec): allow read-only pipe filters in managed NE CLI
Whitelist include/exclude/begin/section/count/match/grep/one-line after show/display pipes while blocking redirect/append/tee/send.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-14 16:24:47 +08:00
c5973eec69 fix(managed-ne): prevent ume-sync route conflicts and prefer host_name
Ensure fixed managed-ne paths are matched before /{ne_id} so deleting UME-synced NEs no longer triggers managed_ne_not_found, and use UME host_name as the synced display name to align managed NE naming with inventory host identity.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 14:24:19 +08:00
3a35b54f0e fix(managed-ne): keep API list behavior for UI while MCP remains restricted
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 11:24:49 +08:00
987b501e53 fix(managed-ne): require filters for listManagedNe and tighten pagination
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 11:07:47 +08:00
572b0cfd9d Add UME-managed NE sync and batch account tools.
Sync UME inventory into managed NE with source-aware dedupe and cleanup, add one-click account updates for selected or tagged NEs, and expose the new managed NE actions in the web UI while keeping bulk bastion flows compatible with optional target passwords.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 10:52:54 +08:00
775989cad4 Improve UME and managed NE list UI layout and styling.
Reorganize the UME page with collapsible CLI, sync status, and AI alert panels; embed CLI connect config in the main view; move task cards under token status; add tags column to managed NE list; and fix hop/proxy form alignment plus consistent section spacing.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 10:22:21 +08:00
39aad258e6 feat(web): poll and display UME CLI connect test results
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 19:56:31 +08:00
e58716c613 fix(web): merge HopProxyFields patches in UME CLI connect panel
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 17:35:10 +08:00
38a1c7f3a9 feat(cli): UME lazy exec via shared profiles and ume_ne_id MCP support
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 17:13:49 +08:00
ba1a40f725 feat(ume): OClaw forwarder runtime task and i18n status codes
Register oclaw_alarm_forwarder in background tasks with pause/resume, emit rt:/ws:/fwd: codes for last_error, and translate them in the UI for English and Chinese.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-24 10:29:10 +08:00
5a00736f23 fix(bastion): subclass netmiko driver class on Python 3.14
ConnectHandler is a factory function in current Netmiko; subclass the CLASS_MAPPER driver (e.g. ZteZxrosSSH) when wrapping a pre-authenticated Paramiko session.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 22:35:37 +08:00
088e920f9d fix(bastion): match OpenSSH username parsing for protocol-proxy hop
OpenSSH treats the last @ as user/host separator, so the SSH username must be hop@target@ip without duplicating hop_host. Legacy templates with {hop_host} are stripped automatically; connect logs now show bastion_ssh_cli for comparison with manual ssh.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:49:43 +08:00
79ae5ff31c fix(bastion): use keyboard-interactive auth for protocol-proxy bastions
ZTE-TSM and similar bastions reject standard SSH password auth and require Vault password via keyboard-interactive; connect over an authenticated Paramiko session instead of re-handshaking with Netmiko.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:31:46 +08:00
e474c0a431 feat(ume): ne_type filter, rule edit, and pager layout
Match key alerts by optional inventory ne_types, add edit dialog to update device types on existing rules, and keep card pager controls on one row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 20:44:33 +08:00
d5d6d4eada fix(ume): keep key-alert monitor toggle on one line
Use inline-flex layout for the enabled checkbox so the label no longer wraps to a second row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 15:02:11 +08:00
17270a26b6 fix(ume): forward stats by rule_key, rule toggle, and list filters
Aggregate push counts per monitor rule, add enabled PATCH and paginated filtered list API/UI so keyword rules show correct stats without deleting.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 14:36:13 +08:00
300fd74565 fix(ume): key-alert DB migration fails on psycopg3 LIKE placeholder
Use starts_with() instead of LIKE kw:% and run each DDL step in its own
transaction so match_type/match_value columns are added reliably.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 19:11:11 +08:00
b54a6e5ad4 fix(ume): global clear-push setting, schema migration, and help hints
Make forward-on-clear a global monitor toggle, run key-alert DDL in an
isolated startup transaction, and fix HelpHint popovers plus API errors
when the server returns non-JSON responses.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 17:26:49 +08:00
34db62c8d2 feat(ume): keyword key-alert rules with label and case-insensitive match
Add description keyword matching alongside notificationId rules, require
per-rule labels, and improve the AI monitor form layout and clear-on-push UX.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 16:48:01 +08:00
99e7b1557f fix(oclaw-bridge): share alarm WSS auth with analyze token
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:22:38 +08:00
1f1b42e8bf feat(ume): key alarm forward to OClaw via WSS and AI monitor UI
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:17:31 +08:00
9a39ddfcc7 feat(ne-exec): allow ping and ping6 on managed NE CLI path
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:14:59 +08:00
06a5615095 feat(managed-ne): tag stats cards and bulk ops by tag
Add tags/remark to import template, stats/ids-by-tag APIs, per-tag overview sub-cards, and bulk proxy/connect-test dialogs filtered by tag.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:13:31 +08:00
d23b5b7cb0 revert(managed-ne): keep bulk import NE-only
Remove hop columns from the import template and stop applying hop settings during import; use Batch add proxy instead.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:16:12 +08:00
81c028949b ui(managed-ne): replace import hint with help popover
Move bulk import and bastion/jump notes into a toolbar help popover to keep the action bar clean.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:00:01 +08:00
7d74e7b3f4 feat(managed-ne): optional password and hop columns in import
Allow creating/importing NEs without target password for bastion-managed workflows, and support optional hop_* columns in bulk import templates.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 11:23:57 +08:00
bac4a609b1 docs(managed-ne): use placeholder IPs in bastion hop examples
Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:59:32 +08:00
a69899d146 chore(web): sync package-lock engines field with package.json
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:49:11 +08:00
d3d7f62a02 feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:47:52 +08:00
e62f4f2c74 fix(ume): block WSS until startup REST alarm sync completes
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:52:39 +08:00
7a729413ab fix(ume): prefer WSS at boot; defer REST grace and avoid parallel sync
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:47:26 +08:00
65e0713e94 fix(startup): defer alarm pull 60s; health probe accepts only HTTP 200
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:32:07 +08:00
f562f50953 fix(startup): defer UME alarm sync so /health is ready quickly
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:28:57 +08:00
d05b64b4c1 fix(scripts): verify netx API after background start and set PYTHONPATH
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 21:25:58 +08:00
0361472ede fix(ne-exec): allow only show/display CLI and harden agent injection
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-04 20:51:06 +08:00
1784d996dd fix(ume): dedupe WSS logs on disconnect and unchanged alarms
Throttle repeated connection-state logs, skip unchanged alarm notifications, and suppress duplicate subscription-lost and parse-ignore messages.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 19:33:15 +08:00
dba8d38f5c fix(scripts): default Node 24 path and add --api-only
Use /usr/local/nodejs/node-v24.16.0-linux-x64 for web dev by default; add --api-only to start API without Node on the host.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 15:53:30 +08:00
f2d686eba8 fix(scripts): set web port 8505 and require Node 20+
Change Linux default web port to 8505, add NODE_CMD/NPM_CMD support with version check, and declare Node 20.19+ in web/package.json engines.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 15:15:00 +08:00
823a5819f7 fix(scripts): use host Python and fix Linux start script
Remove venv requirement, default PYTHON_CMD to /usr/local/python_env_new/bin/python3, and fix web startup without bash -lc. Add .gitattributes to keep shell scripts LF.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 14:44:35 +08:00