Commit graph

87 commits

Author SHA1 Message Date
f5b4a14c0f Harden config sync defaults, crash resume, and network nav collapse.
Disable auto-sync by default, enforce single-flight cycles with crash requeue, delay new scheduled runs after restart, and make the network sidebar collapsible.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 10:43:01 +08:00
0eead0e662 Add industrial config sync separate from collection tasks.
Periodic vendor-aware CLI sync stores zlib snapshots in Postgres with dashboard, retry, and config viewer under Network Management.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 10:25:36 +08:00
2fc47e5135 Add Network Management module with collapsible left nav.
Consolidate devices, topology, alarms, WebCRT, and collection tasks under /network; keep legacy path redirects and workbench entry.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-31 09:48:31 +08:00
hansjone
3bd5d5b7da Simplify WebCRT device list chrome.
Drop the sidebar refresh control and bordered pager buttons; keep page meta with plain chevrons.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
9a72a9a099 fix(topology): keep context menu text readable on hover.
Override .app-main button color so dark menu items stay light on hover/focus.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
2f1c33924e Improve topology canvas UX and vendor NE icons.
Replace the top selection bar with a context menu, tighten map/palette cards and fullscreen controls, and tint the router asset by vendor (ZTE keeps default blue).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
658c19e457 fix(auth): attach bearer token to managed-NE import and template download
These raw fetch/navigation paths skipped Authorization after login was required, same class of bug as topology discover stream.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
325bce0413 fix(topology): send auth token on discover stream requests
The SSE discover endpoint used raw fetch without Authorization, so login sessions got unauthorized after auth was enabled.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
a3bdad5be1 fix(auth): sync logout across browser tabs
Listen for localStorage token changes so other open pages clear session state when one tab signs out.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
b540ea21c1 fix(webcrt): resize hop PTY before nested CLI jump
Nested stelnet/telnet captures hop TTY width at start; Netmiko's default 511 cols made mid-line edit redraws wrap and garble in ~80-col WebCRT.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
6d4cd741ef feat(auth): add local login, audit, API keys, and system admin UI
Gate netx Web/API/WebCRT with JWT and per-user API tokens, bootstrap an admin with forced password change, and expose users/audit/API-key management under a System section. MCP can reuse data/auth/mcp_token without extra env for local labs.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
14f14d34bd fix(webcrt): remove tab close border by dropping button chrome
Global app button styles forced a boxed ×; use an inline span so it reads as part of the device name.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 02:34:25 +00:00
hansjone
2ac8d96409 fix(webcrt): blend session tab close mark into device name
Remove the boxed close control so the x sits inline with the tab label.
2026-07-30 10:34:25 +08:00
ec736b6dc8 Allow topology discovery to scan UME nodes on the map.
Previously only managed NEs were scanned, so UME-only maps reported Scanned 0.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 00:42:34 +08:00
bf82a01a03 Stream topology discovery progress and mark missing links stale.
SSE updates the UI per NE; edges not seen in a successful scan turn red and can be cleared.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 00:35:16 +08:00
bfc10ee8cf Add ZTE LLDP brief parsing and UME NEs to topology palette.
ZXROS uses show lldp neighbor brief; topology library can switch between managed and UME inventory.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-30 00:18:07 +08:00
dc805c2086 Add topology maps with LLDP discovery and React Flow canvas.
Includes map CRUD, graph save, neighbor discover, and UI controls for labels, sidebar, and edge flow.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 23:53:06 +08:00
3b8342acfb fix(webcrt): keep device echo intact and stop dual-WS steal.
Use raw Telnet reads for ANSI backspace, drop local erase so Tab/completion stays in sync, and make WebSocket attach exclusive so StrictMode remounts cannot drop the first echo.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 22:27:15 +08:00
89ff0a7212 Improve WebCRT UX: real login transcript, session tools, and first-input sync.
Capture Netmiko session_log for login replay, open NE terminals in a fresh tab, tidy the device list UI with reconnect/log/clear/copy, and paint a live prompt after attach so the first keystrokes behave normally.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 19:53:41 +08:00
30f2db9708 fix(webcrt): replay login banner/prompt on attach
Drain and nudge the device prompt after Netmiko login, replay bootstrap stdout when the WebSocket attaches, and surface connect errors in the terminal pane.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 18:54:59 +08:00
1f2e028337 fix(webcrt): install websockets and connect WS to API in Vite dev
Uvicorn had no WebSocket implementation without the websockets package, causing browser websocket_error. Also bypass flaky Vite WS proxy by targeting :8890 in local UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:37:32 +08:00
183cb7eec9 fix(webcrt): keep session across WS remount and fix blank terminal
Allow brief WebSocket re-attach after React StrictMode cleanup, ensure terminal pane has layout height, and show connect status in xterm.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:32:23 +08:00
873f2bfe34 feat(webcrt): add CRT-style browser terminal for managed and UME NEs
Ship an ops WebCRT module with xterm.js UI, WebSocket session bridge reusing hop/bastion login, searchable paged targets, and session audit limits.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-29 17:23:45 +08:00
572b0cfd9d Add UME-managed NE sync and batch account tools.
Sync UME inventory into managed NE with source-aware dedupe and cleanup, add one-click account updates for selected or tagged NEs, and expose the new managed NE actions in the web UI while keeping bulk bastion flows compatible with optional target passwords.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 10:52:54 +08:00
775989cad4 Improve UME and managed NE list UI layout and styling.
Reorganize the UME page with collapsible CLI, sync status, and AI alert panels; embed CLI connect config in the main view; move task cards under token status; add tags column to managed NE list; and fix hop/proxy form alignment plus consistent section spacing.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-02 10:22:21 +08:00
39aad258e6 feat(web): poll and display UME CLI connect test results
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 19:56:31 +08:00
e58716c613 fix(web): merge HopProxyFields patches in UME CLI connect panel
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 17:35:10 +08:00
38a1c7f3a9 feat(cli): UME lazy exec via shared profiles and ume_ne_id MCP support
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-26 17:13:49 +08:00
ba1a40f725 feat(ume): OClaw forwarder runtime task and i18n status codes
Register oclaw_alarm_forwarder in background tasks with pause/resume, emit rt:/ws:/fwd: codes for last_error, and translate them in the UI for English and Chinese.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-24 10:29:10 +08:00
088e920f9d fix(bastion): match OpenSSH username parsing for protocol-proxy hop
OpenSSH treats the last @ as user/host separator, so the SSH username must be hop@target@ip without duplicating hop_host. Legacy templates with {hop_host} are stripped automatically; connect logs now show bastion_ssh_cli for comparison with manual ssh.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 21:49:43 +08:00
e474c0a431 feat(ume): ne_type filter, rule edit, and pager layout
Match key alerts by optional inventory ne_types, add edit dialog to update device types on existing rules, and keep card pager controls on one row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 20:44:33 +08:00
d5d6d4eada fix(ume): keep key-alert monitor toggle on one line
Use inline-flex layout for the enabled checkbox so the label no longer wraps to a second row.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 15:02:11 +08:00
17270a26b6 fix(ume): forward stats by rule_key, rule toggle, and list filters
Aggregate push counts per monitor rule, add enabled PATCH and paginated filtered list API/UI so keyword rules show correct stats without deleting.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-23 14:36:13 +08:00
b54a6e5ad4 fix(ume): global clear-push setting, schema migration, and help hints
Make forward-on-clear a global monitor toggle, run key-alert DDL in an
isolated startup transaction, and fix HelpHint popovers plus API errors
when the server returns non-JSON responses.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 17:26:49 +08:00
34db62c8d2 feat(ume): keyword key-alert rules with label and case-insensitive match
Add description keyword matching alongside notificationId rules, require
per-rule labels, and improve the AI monitor form layout and clear-on-push UX.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 16:48:01 +08:00
99e7b1557f fix(oclaw-bridge): share alarm WSS auth with analyze token
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:22:38 +08:00
1f1b42e8bf feat(ume): key alarm forward to OClaw via WSS and AI monitor UI
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-22 11:17:31 +08:00
06a5615095 feat(managed-ne): tag stats cards and bulk ops by tag
Add tags/remark to import template, stats/ids-by-tag APIs, per-tag overview sub-cards, and bulk proxy/connect-test dialogs filtered by tag.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 16:13:31 +08:00
d23b5b7cb0 revert(managed-ne): keep bulk import NE-only
Remove hop columns from the import template and stop applying hop settings during import; use Batch add proxy instead.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:16:12 +08:00
81c028949b ui(managed-ne): replace import hint with help popover
Move bulk import and bastion/jump notes into a toolbar help popover to keep the action bar clean.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 15:00:01 +08:00
7d74e7b3f4 feat(managed-ne): optional password and hop columns in import
Allow creating/importing NEs without target password for bastion-managed workflows, and support optional hop_* columns in bulk import templates.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 11:23:57 +08:00
bac4a609b1 docs(managed-ne): use placeholder IPs in bastion hop examples
Replace real site addresses with 1.1.1.1/2.2.2.2 and generic usernames in i18n hints and tests.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:59:32 +08:00
a69899d146 chore(web): sync package-lock engines field with package.json
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:49:11 +08:00
d3d7f62a02 feat(managed-ne): add bastion SSH protocol proxy hop type
Support composite-username bastion login for automated connect-test and exec, with bastion-managed or manual target credential modes.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-05 10:47:52 +08:00
f2d686eba8 fix(scripts): set web port 8505 and require Node 20+
Change Linux default web port to 8505, add NODE_CMD/NPM_CMD support with version check, and declare Node 20.19+ in web/package.json engines.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-06-01 15:15:00 +08:00
dc17f9d15a feat(ne): connect detail, Huawei/Cisco hop, Cisco hostname probe
Persist full connect test logs (connect_detail) with NE UI detail modal.
Add Huawei/Cisco jump CLI templates and generic CLI hop session path.
Probe Cisco hostname via show configuration | include hostname (60s timeout).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 21:50:41 +08:00
778442dc57 feat(ne): batch delete selected managed network elements
Add POST /v1/managed-ne/batch-delete and toolbar button with confirmation on NE management page.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 19:02:16 +08:00
d3eae3351c feat(ne): add Linux SSH bastion hop type
Support hop_vendor=linux via Paramiko direct-tcpip tunnel; ZTE CLI hop unchanged. UI hop type selector and distinct list badges.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:38:37 +08:00
d395aa7174 feat(ne): batch apply jump proxy on selected NEs
Add POST /v1/managed-ne/batch-hop, shared HopProxyFields form, and toolbar button next to connectivity test.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:28:14 +08:00
4575fef523 feat(ne): ZTE jump host for connect test and collection
Add hop fields and encrypted credentials, unified Netmiko session factory with ZTE ssh/telnet CLI templates and secondary auth, wire connect/collect paths, and NE management UI with auto-suggested jump commands.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-28 17:14:49 +08:00