Compare commits
19
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7ad10b6969 | ||
|
|
1a21656546 | ||
|
|
be58284916 | ||
|
|
7b139e8931 | ||
|
|
19ed16ac12 | ||
|
|
7aebb1120f | ||
|
|
ab38a54d54 | ||
|
|
f30c353b46 | ||
|
|
84f8b9f9ad | ||
|
|
30018e09e2 | ||
|
|
cb2c2c5200 | ||
|
|
fd1c0a2698 | ||
|
|
9c36e61c69 | ||
|
|
556d5ee767 | ||
|
|
eb51eb15b4 | ||
|
|
459d5cb79b | ||
|
|
b3b7041ee9 | ||
|
|
9a1b60fa2b | ||
|
|
a12fac16c8 |
No files matched your search
+23
-1
@@ -4,9 +4,25 @@ HTTP_PORT=8080
|
|||||||
TZ=Europe/Paris
|
TZ=Europe/Paris
|
||||||
# How long logs are kept (e.g. 7d, 30d, 12w, 1y)
|
# How long logs are kept (e.g. 7d, 30d, 12w, 1y)
|
||||||
RETENTION=30d
|
RETENTION=30d
|
||||||
# Web UI authentication (empty = disabled)
|
# Web UI authentication: local (login page with the account below, or none) or oidc (OpenID Connect provider)
|
||||||
|
AUTH_MODE=local
|
||||||
|
# local mode: user and password (empty = no authentication)
|
||||||
AUTH_USER=
|
AUTH_USER=
|
||||||
AUTH_PASS=
|
AUTH_PASS=
|
||||||
|
# local mode: PNG logo shown on the login page, path inside the container (empty = no logo).
|
||||||
|
# Mount the file in docker-compose.yml, e.g. ./logo.png:/config/logo.png:ro, then LOGIN_LOGO=/config/logo.png
|
||||||
|
LOGIN_LOGO=
|
||||||
|
# Session lifetime, both modes (e.g. 8h, 24h)
|
||||||
|
SESSION_TTL=12h
|
||||||
|
# oidc mode: issuer URL exactly as the provider announces it
|
||||||
|
# (Keycloak: https://sso.example.org/realms/<realm>, Authentik: https://auth.example.org/application/o/<slug>/)
|
||||||
|
OIDC_ISSUER=
|
||||||
|
OIDC_CLIENT_ID=
|
||||||
|
OIDC_CLIENT_SECRET=
|
||||||
|
# Callback URL of logstream, to register in the provider (path free, /auth/callback recommended)
|
||||||
|
OIDC_REDIRECT_URL=https://logs.example.org/auth/callback
|
||||||
|
# Requested scopes (openid is always added)
|
||||||
|
OIDC_SCOPES=openid profile email
|
||||||
# Reverse DNS: show host names instead of IP addresses (on/off)
|
# Reverse DNS: show host names instead of IP addresses (on/off)
|
||||||
RDNS=on
|
RDNS=on
|
||||||
# DNS server used for reverse lookups (e.g. your router: 192.168.1.1). Empty = system resolver
|
# DNS server used for reverse lookups (e.g. your router: 192.168.1.1). Empty = system resolver
|
||||||
@@ -19,3 +35,9 @@ EXPORT_MAX=100000
|
|||||||
DOCKER_LOGS=on
|
DOCKER_LOGS=on
|
||||||
# History read from a container seen for the first time (e.g. 30m, 1h, 24h; 0 = only new lines)
|
# History read from a container seen for the first time (e.g. 30m, 1h, 24h; 0 = only new lines)
|
||||||
DOCKER_BACKFILL=1h
|
DOCKER_BACKFILL=1h
|
||||||
|
# Host system logs (enable them in Settings > Sources)
|
||||||
|
# Group allowed to read the host logs: 4 = adm on Debian/Ubuntu; or the systemd-journal group
|
||||||
|
# (getent group systemd-journal | cut -d: -f3)
|
||||||
|
HOST_LOGS_GID=4
|
||||||
|
# History read when the source is turned on (e.g. 30m, 1h, 24h; 0 = only new entries)
|
||||||
|
HOST_LOGS_BACKFILL=1h
|
||||||
+420
@@ -0,0 +1,420 @@
|
|||||||
|
[English](README.md) | Français
|
||||||
|
|
||||||
|
# Logstream
|
||||||
|
|
||||||
|
Un collecteur syslog simple : il reçoit les logs en UDP/TCP sur le port 514, les stocke dans
|
||||||
|
[VictoriaLogs](https://docs.victoriametrics.com/victorialogs/) et sert une interface web
|
||||||
|
soignée (thème clair/sombre, recherche instantanée, direct, tags de couleur, interface en
|
||||||
|
anglais et en français).
|
||||||
|
|
||||||
|
```
|
||||||
|
devices ──514 udp/tcp──▶ logstream (Go) ──HTTP batches──▶ VictoriaLogs
|
||||||
|
▲ └── SSE (live) ──▶ browser
|
||||||
|
└──── API / UI ◀─────────┘
|
||||||
|
```
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
- **Ingestion** : les messages syslog (UDP/TCP) et les logs des conteneurs Docker passent tous
|
||||||
|
par `sink()` (résolution DNS inverse des hôtes donnés par leur IP), puis par la file du
|
||||||
|
`Store`, qui les envoie par lots à VictoriaLogs.
|
||||||
|
- **Direct** : `sink()` publie aussi chaque message dans le `Hub`, qui le diffuse aux
|
||||||
|
navigateurs en SSE.
|
||||||
|
- **Recherche** : l'API HTTP traduit les filtres de l'interface en requêtes LogsQL envoyées à
|
||||||
|
VictoriaLogs.
|
||||||
|
- **Frise** : `/api/histogram` (`histogram.go`) compte les logs par intervalle et par sévérité,
|
||||||
|
alignés sur l'heure locale ; les bornes du zoom (`from`/`to`) s'appliquent aussi à la liste
|
||||||
|
et à l'export.
|
||||||
|
- **État** : les tags et les réglages des sources sont dans `/data` (volume `logstream-data`) ;
|
||||||
|
les logs eux-mêmes dans le volume `vlogs-data`.
|
||||||
|
|
||||||
|
La source modifiable du schéma est
|
||||||
|
[`docs/architecture.excalidraw`](docs/architecture.excalidraw)
|
||||||
|
(à ouvrir sur [excalidraw.com](https://excalidraw.com)).
|
||||||
|
|
||||||
|
## Démarrage
|
||||||
|
|
||||||
|
```bash
|
||||||
|
cp .env.example .env # optional
|
||||||
|
docker compose up -d --build
|
||||||
|
./tools/send-test-logs.sh # sends 100 test messages
|
||||||
|
```
|
||||||
|
|
||||||
|
Ouvrez ensuite <http://localhost:8080>.
|
||||||
|
|
||||||
|
## Envoyer des logs
|
||||||
|
|
||||||
|
- **rsyslog** (Linux) : ajoutez `*.* @SERVER_IP:514` (UDP) ou `*.* @@SERVER_IP:514` (TCP)
|
||||||
|
dans `/etc/rsyslog.d/90-logstream.conf`, puis lancez `systemctl restart rsyslog`.
|
||||||
|
- **Équipements réseau, NAS, pare-feu** : indiquez l'IP du serveur et le port 514 dans leurs
|
||||||
|
réglages « syslog distant » (remote syslog).
|
||||||
|
- **Test manuel** : `logger -n 127.0.0.1 -P 514 -d "hello error"` (util-linux) ou
|
||||||
|
`echo "<14>test ok" | nc -u -w1 127.0.0.1 514`.
|
||||||
|
|
||||||
|
**Paramètres > Sources > Syslog** active ou désactive la réception syslog et choisit les
|
||||||
|
protocoles (UDP, TCP) sans redémarrage ; le choix est enregistré dans `/data/syslog.json`. Cet
|
||||||
|
onglet affiche aussi l'état d'écoute (et l'erreur si le port est déjà utilisé). Le port
|
||||||
|
lui-même est publié par docker-compose : modifiez `SYSLOG_PORT` dans `.env`, puis lancez
|
||||||
|
`docker compose up -d`.
|
||||||
|
|
||||||
|
Formats pris en charge : RFC 3164 (BSD) et RFC 5424. En TCP, les deux découpages sont acceptés :
|
||||||
|
« un message par ligne » et « octet counting » (RFC 6587).
|
||||||
|
|
||||||
|
## Recherche
|
||||||
|
|
||||||
|
**Mode simple** (par défaut) : chaque mot est cherché comme sous-chaîne, sans tenir compte de
|
||||||
|
la casse, dans le message, l'hôte et l'application. Les mots sont combinés avec ET.
|
||||||
|
|
||||||
|
| Saisie | Signification |
|
||||||
|
|---|---|
|
||||||
|
| `error disk` | contient « error » **et** « disk » |
|
||||||
|
| `"disk full"` | contient la phrase exacte |
|
||||||
|
| `error -timeout` | contient « error » mais pas « timeout » |
|
||||||
|
|
||||||
|
**Mode LogsQL** (bouton `Simple` / `LogsQL`) : le langage de requête complet de VictoriaLogs,
|
||||||
|
par exemple `error AND host:web-01`, `app:~"ssh|nginx"` ou `* | stats by (host) count()`.
|
||||||
|
Le direct est désactivé dans ce mode.
|
||||||
|
|
||||||
|
Chaque ligne affiche, de gauche à droite : l'**heure de réception** (horloge du serveur),
|
||||||
|
l'horodatage trouvé dans le message lui-même (`msg_time`), la sévérité, l'hôte, l'application
|
||||||
|
et le message. Un clic sur un hôte ou une application filtre dessus.
|
||||||
|
|
||||||
|
Les logs sont indexés, recherchés et triés par **heure de réception** : les équipements dont
|
||||||
|
l'horloge est fausse (par exemple des points d'accès dont le NTP échoue) apparaissent quand même
|
||||||
|
dans la bonne plage de temps. Les logs stockés par les versions antérieures à ce changement sont
|
||||||
|
indexés par l'horodatage de leur message ; purgez-les depuis les Paramètres pour repartir sur
|
||||||
|
une base propre.
|
||||||
|
|
||||||
|
Les badges de sévérité `err`/`crit` et `warning` reprennent les couleurs des tags `error` et
|
||||||
|
`warning`.
|
||||||
|
|
||||||
|
Raccourcis : `/` place le curseur dans la recherche, `Esc` la vide. Un clic sur une ligne
|
||||||
|
affiche tous ses champs.
|
||||||
|
|
||||||
|
Les en-têtes de colonnes restent visibles pendant le défilement. Faites glisser le bord d'un
|
||||||
|
en-tête (réception, heure message, sévérité, hôte, app) pour redimensionner la colonne, et
|
||||||
|
double-cliquez dessus pour revenir à la largeur automatique ; le message occupe l'espace
|
||||||
|
restant. Les largeurs sont mémorisées par le navigateur (**Paramètres > Interface >
|
||||||
|
Réinitialiser les colonnes** les rétablit toutes). Sur téléphone, la liste garde sa
|
||||||
|
présentation sur deux lignes, sans colonnes.
|
||||||
|
|
||||||
|
## Frise
|
||||||
|
|
||||||
|
La frise au-dessus de la liste montre le volume de logs par intervalle, compté selon l'**heure
|
||||||
|
de réception** sur l'horloge du serveur (elle correspond donc aux heures affichées dans les
|
||||||
|
lignes).
|
||||||
|
|
||||||
|
- Au survol d'un intervalle : ses bornes, son total et le détail par sévérité.
|
||||||
|
- Un clic sur une barre zoome sur cet intervalle ; un glisser sur plusieurs barres zoome sur la
|
||||||
|
sélection. La plage de temps affiche alors la période zoomée (« × Annuler le zoom » ou le
|
||||||
|
choix d'une autre plage en sort) ; la liste, les compteurs et l'export CSV suivent le zoom,
|
||||||
|
et le direct se met en pause.
|
||||||
|
- En direct, le dernier intervalle grandit à l'arrivée des messages, et la frise se recharge à
|
||||||
|
chaque nouvel intervalle. Rien n'est rafraîchi tant que l'onglet du navigateur est masqué ;
|
||||||
|
la frise se met à jour dès qu'il redevient visible.
|
||||||
|
|
||||||
|
**Paramètres > Interface > Frise** (mémorisé par navigateur) : échelle (linéaire, √ par défaut,
|
||||||
|
log), hauteur (S/M/L : 40/80/120 px), couleur (empilement par sévérité, intensité comparée à
|
||||||
|
la médiane de la fenêtre : calme, rafale au-delà de 3×, anomalie au-delà de 10×, ou aucune),
|
||||||
|
barres ou aire, division (automatique, environ 100 intervalles, ou fixe : 1 s, 10 s, 1 min,
|
||||||
|
5 min, 1 h, 1 jour) et rafraîchissement (désactivé, 5 s, 15 s, 30 s, 1 min, ou à chaque nouvel
|
||||||
|
intervalle). Une division fixe qui dépasserait 300 intervalles sur la plage est élargie
|
||||||
|
(signalé par « élargi »). Les intervalles sont alignés sur l'heure locale du fuseau horaire
|
||||||
|
choisi dans les Paramètres (les jours commencent à minuit, heure locale).
|
||||||
|
|
||||||
|
API : `curl 'localhost:8080/api/histogram?range=24h&step=auto&tz=Europe/Paris'` renvoie
|
||||||
|
`step` (ms), `start` (ms), `count`, `now` (horloge du serveur) et les `buckets` non vides
|
||||||
|
(`i` = numéro d'intervalle, `n` = total, `sev` = nombre par sévérité). Toutes les routes de
|
||||||
|
logs acceptent aussi `from` / `to` (millisecondes Unix) à la place de `range`.
|
||||||
|
|
||||||
|
## Logs des conteneurs Docker
|
||||||
|
|
||||||
|
Logstream collecte aussi les logs des conteneurs Docker qui tournent sur la machine où il est
|
||||||
|
installé (`DOCKER_LOGS=on`, le défaut dans `docker-compose.yml`). Ils sont recherchés, filtrés,
|
||||||
|
colorés et exportés comme les messages syslog :
|
||||||
|
|
||||||
|
- **host** est le nom de l'hôte Docker, **app** le service compose (ou le nom du conteneur), et
|
||||||
|
chaque log porte aussi `container`, `container_id`, `image`, `compose_project`,
|
||||||
|
`compose_service` et `stream` (stdout/stderr), visibles dans le détail de la ligne.
|
||||||
|
- Le filtre **Source** n'affiche que les logs syslog ou que les logs Docker ; les lignes Docker
|
||||||
|
ont un petit cube devant le nom de l'application, de la couleur de son projet compose.
|
||||||
|
- La sévérité vient de la ligne elle-même quand l'application l'écrit : JSON
|
||||||
|
(`"level":"error"`), logfmt (`level=warn`), `[ERROR]`, ou un niveau en majuscules au début de
|
||||||
|
la ligne (`ERROR`, `WARN`…). Sinon, elle vaut `info`. Les codes de couleur du terminal sont
|
||||||
|
supprimés.
|
||||||
|
- **Paramètres > Sources** affiche une étiquette par conteneur (`project/service`) dans un seul
|
||||||
|
champ : les conteneurs suivis en couleur, puis les non suivis en gris ; un clic bascule une
|
||||||
|
étiquette. La couleur identifie le projet compose, et les noms d'applications Docker de la
|
||||||
|
liste utilisent la même couleur. Les conteneurs arrêtés sont masqués par défaut (« Afficher
|
||||||
|
les conteneurs arrêtés » les montre, en pointillés, et ils restent modifiables). Une zone de
|
||||||
|
filtre et « Tout activer » / « Tout désactiver » (appliqués aux étiquettes affichées) aident
|
||||||
|
quand les conteneurs sont nombreux. Les nouveaux conteneurs sont suivis automatiquement, sauf
|
||||||
|
si cette option est désactivée. Les choix sont enregistrés par service compose (ou nom de
|
||||||
|
conteneur) dans `/data/docker.json` : ils survivent aux recréations.
|
||||||
|
- Logstream mémorise la position lue dans chaque conteneur (`/data/docker-state.json`) : après
|
||||||
|
un redémarrage, il reprend sans perdre ni dupliquer de lignes. Un conteneur vu pour la
|
||||||
|
première fois est lu à partir de `DOCKER_BACKFILL` en arrière (1 heure par défaut).
|
||||||
|
- Logstream lui-même et le proxy ci-dessous ne sont jamais collectés ; ajoutez l'étiquette
|
||||||
|
`logstream.exclude=true` à tout autre conteneur pour l'exclure définitivement.
|
||||||
|
|
||||||
|
**Sécurité** : l'accès au socket Docker équivaut à un accès root sur la machine. Logstream passe
|
||||||
|
donc par [docker-socket-proxy](https://github.com/Tecnativa/docker-socket-proxy), qui ne laisse
|
||||||
|
passer que la liste des conteneurs, la lecture des logs, les événements et les informations du
|
||||||
|
moteur (`GET` uniquement).
|
||||||
|
|
||||||
|
## Logs système de l'hôte
|
||||||
|
|
||||||
|
Logstream peut aussi collecter les logs système de la machine qui héberge la stack, sans rien
|
||||||
|
configurer sur l'hôte. La source est **désactivée par défaut** : activez-la dans
|
||||||
|
**Paramètres > Sources > Logs système de l'hôte** (enregistré dans `/data/hostlogs.json`).
|
||||||
|
|
||||||
|
- `docker-compose.yml` monte `/var/log` et `/run/log/journal` en lecture seule sous `/host`.
|
||||||
|
- Si l'hôte utilise systemd, Logstream lit directement les fichiers du **journal systemd**
|
||||||
|
(pas besoin de `journalctl` dans l'image) : **host** est le nom de la machine, **app** le
|
||||||
|
programme (`SYSLOG_IDENTIFIER`), la sévérité et la facility viennent du journal, et l'unité
|
||||||
|
systemd est conservée dans `unit`. Sinon, il suit les fichiers texte de `/var/log` (`syslog`,
|
||||||
|
`messages`, `*.log`), analysés comme des lignes syslog, avec le nom du fichier dans `log_file`.
|
||||||
|
- Ces logs ont la source `host` : le filtre **Source** permet de les afficher seuls.
|
||||||
|
- À l'activation, la dernière heure est lue d'abord (`HOST_LOGS_BACKFILL`) ; la position
|
||||||
|
atteinte est enregistrée dans `/data/hostlogs-state.json`, un redémarrage ne perd donc ni ne
|
||||||
|
duplique d'entrées.
|
||||||
|
- **Droits** : le conteneur tourne avec un utilisateur sans privilège et reçoit le groupe `adm`
|
||||||
|
(gid 4), qui peut lire le journal et `/var/log` sur Debian et Ubuntu. Sur d'autres systèmes,
|
||||||
|
réglez `HOST_LOGS_GID` dans `.env` sur le gid de `systemd-journal`
|
||||||
|
(`getent group systemd-journal | cut -d: -f3`). Paramètres > Sources affiche un message clair
|
||||||
|
si l'accès est refusé.
|
||||||
|
- Limites : les champs du journal compressés par journald (messages de plus de 512 octets,
|
||||||
|
compressés en zstd/lz4/xz) ne peuvent pas être décodés sans bibliothèque supplémentaire ; ils
|
||||||
|
sont comptés dans les Paramètres et affichés comme « (compressed journal entry) ». Les fichiers
|
||||||
|
texte tournés ou compressés (`*.1`, `*.gz`) ne sont pas lus.
|
||||||
|
|
||||||
|
## Export CSV
|
||||||
|
|
||||||
|
Le bouton **Exporter** (à côté du nombre de logs) télécharge tous les logs stockés qui
|
||||||
|
correspondent aux filtres en cours (recherche, plage de temps, sévérité, hôte, application),
|
||||||
|
du plus récent au plus ancien, jusqu'à `EXPORT_MAX` lignes (100 000 par défaut), et pas
|
||||||
|
seulement les lignes à l'écran. Deux variantes :
|
||||||
|
|
||||||
|
- **CSV** : séparateur virgule, UTF-8.
|
||||||
|
- **CSV pour Excel** : séparateur point-virgule avec un BOM UTF-8, pour qu'Excel en français
|
||||||
|
l'ouvre directement avec les accents. Les cellules qui commencent par `=`, `+`, `-` ou `@`
|
||||||
|
sont préfixées par `'` pour qu'un message de log forgé ne puisse pas s'exécuter comme une
|
||||||
|
formule.
|
||||||
|
|
||||||
|
Colonnes : `received`, `message_time` (toutes deux au format `YYYY-MM-DD HH:MM:SS.mmm` dans le
|
||||||
|
fuseau horaire choisi dans les Paramètres), `severity`, `facility`, `host`, `host_ip`, `app`,
|
||||||
|
`pid`, `source_ip`, `proto`, `message`. En mode LogsQL, seule la partie filtre est prise en
|
||||||
|
charge (pas de `| pipes`).
|
||||||
|
|
||||||
|
En ligne de commande : `curl -o logs.csv 'localhost:8080/api/export.csv?q=error&range=24h&tz=Europe/Paris'`.
|
||||||
|
|
||||||
|
## Paramètres
|
||||||
|
|
||||||
|
L'icône en forme d'engrenage ouvre les paramètres, organisés en onglets. Tout, sauf les tags de
|
||||||
|
couleur, est mémorisé par navigateur.
|
||||||
|
|
||||||
|
- **Localisation**
|
||||||
|
- *Langue* : anglais ou français.
|
||||||
|
- *Date et heure* : fuseau horaire (celui du navigateur, UTC ou environ 80 fuseaux courants)
|
||||||
|
et format d'affichage de l'heure de réception : `DD/MM/YYYY HH:MM:SS` (par défaut,
|
||||||
|
l'affichage français habituel), avec millisecondes, `YYYY-MM-DD`, horloge sur 12 heures,
|
||||||
|
ISO 8601 ou epoch Unix. Le fuseau horaire s'applique à toutes les dates affichées.
|
||||||
|
- **Filtres** : tags de couleur. Chaque tag a un mot-clé, une couleur de fond (le texte passe
|
||||||
|
automatiquement en noir ou en blanc pour rester lisible) et des options : mot entier, respect
|
||||||
|
de la casse, expression régulière, actif. Les tags sont stockés sur le serveur dans
|
||||||
|
`/data/tags.json` (volume `logstream-data`) : ils sont donc partagés par tous les navigateurs.
|
||||||
|
Tags par défaut (pastel) : `warning` (orange), `error` (rouge), `ok` (vert). Les tags par
|
||||||
|
défaut qui utilisent encore les couleurs des versions précédentes passent automatiquement aux
|
||||||
|
couleurs pastel.
|
||||||
|
Le menu *+ Préréglage…* ajoute des tags tout faits pour les logs d'accès HTTP/HTTPS (nginx et
|
||||||
|
Apache common/combined, Traefik CLF et JSON, Caddy JSON, HAProxy httplog) : codes de statut
|
||||||
|
(2xx vert, 3xx bleu, 4xx orange, 5xx rouge), méthodes, sondes et attaques (`wp-login.php`,
|
||||||
|
`/.env`, `../`…), robots et scripts, erreurs TLS et proxy. Les tags déjà présents ne sont pas
|
||||||
|
ajoutés en double, et les tags ajoutés se modifient comme les autres. Dans une expression
|
||||||
|
régulière, un groupe nommé `hl` (`(?<hl>…)`) ne colore que cette partie de la correspondance :
|
||||||
|
les préréglages s'en servent pour colorer le code de statut ou la méthode, pas le texte autour.
|
||||||
|
- **Interface**
|
||||||
|
- *Thème* : Système (suit la préférence de l'ordinateur ou du téléphone), Clair ou Sombre. Le
|
||||||
|
bouton soleil/lune de l'en-tête bascule entre clair et sombre.
|
||||||
|
- *Affichage des logs* : taille du texte (très petite, petite, moyenne, grande), densité
|
||||||
|
(normale, ou compacte pour afficher environ 50 % de lignes en plus à l'écran) et police :
|
||||||
|
la police monospace du système, [Iosevka](https://github.com/be5invis/Iosevka) (étroite,
|
||||||
|
donc plus de texte par ligne ; servie par LogStream lui-même, fonctionne hors ligne), ou
|
||||||
|
l'une des 12 polices libres conçues pour le texte dense (JetBrains Mono, Fira Code, Source
|
||||||
|
Code Pro, IBM Plex Mono, Cascadia Code, Roboto Mono, Ubuntu Mono, Inconsolata, Red Hat Mono,
|
||||||
|
Noto Sans Mono, Victor Mono, DM Mono). Ces 12 polices sont chargées par le navigateur depuis
|
||||||
|
[Bunny Fonts](https://fonts.bunny.net), un service européen de polices respectueux de la vie
|
||||||
|
privée ; sans accès à internet, la police du système est utilisée. Les ligatures sont
|
||||||
|
désactivées pour que `->` ou `!=` s'affichent tels quels. Le réglage le plus dense est Très
|
||||||
|
petite + Compacte + Iosevka.
|
||||||
|
- **Données** : « Supprimer tous les logs » efface définitivement tous les logs stockés (il faut
|
||||||
|
taper `PURGE` pour confirmer). Les tags et les paramètres sont conservés. VictoriaLogs doit
|
||||||
|
être lancé avec `-delete.enable` (déjà présent dans `docker-compose.yml`) ; mettez
|
||||||
|
`ALLOW_PURGE=false` pour désactiver la fonction. Toute personne qui peut ouvrir l'interface
|
||||||
|
peut purger : activez l'[authentification](#authentification) si l'interface est accessible
|
||||||
|
à d'autres.
|
||||||
|
|
||||||
|
## Authentification
|
||||||
|
|
||||||
|
`AUTH_MODE` choisit comment l'interface et l'API sont protégées (`/healthz` reste toujours ouvert) :
|
||||||
|
|
||||||
|
- **`local`** (par défaut) : une page de connexion avec le compte `AUTH_USER` / `AUTH_PASS` ; laissez-les
|
||||||
|
vides pour n'avoir aucune authentification (par exemple derrière un reverse proxy qui contrôle déjà).
|
||||||
|
- **`oidc`** : connexion par un fournisseur OpenID Connect (Keycloak, Authentik, Authelia, Zitadel…),
|
||||||
|
flux « authorization code » avec PKCE.
|
||||||
|
|
||||||
|
En mode `local`, la page de connexion suit le thème et la langue de l'interface. La session dure
|
||||||
|
`SESSION_TTL` (12 h par défaut), survit aux redémarrages (sa clé de signature est dans
|
||||||
|
`/data/session.key`) et se termine quand `AUTH_USER` ou `AUTH_PASS` change ; le bouton de
|
||||||
|
déconnexion (en haut à droite) y met fin. Les échecs de connexion sont écrits dans les logs avec
|
||||||
|
l'adresse du client (`auth: failed login for "bob" from 192.0.2.7`). Les scripts peuvent toujours
|
||||||
|
appeler l'API avec des identifiants HTTP Basic (`curl -u utilisateur:motdepasse`).
|
||||||
|
|
||||||
|
Pour afficher votre logo sur la page de connexion, montez un PNG dans le conteneur et indiquez
|
||||||
|
son chemin dans `LOGIN_LOGO` :
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# docker-compose.yml, service logstream
|
||||||
|
volumes:
|
||||||
|
- ./logo.png:/config/logo.png:ro
|
||||||
|
```
|
||||||
|
```bash
|
||||||
|
# .env
|
||||||
|
LOGIN_LOGO=/config/logo.png
|
||||||
|
```
|
||||||
|
|
||||||
|
Pour utiliser OIDC :
|
||||||
|
|
||||||
|
1. Dans le fournisseur, créez un client **confidentiel** (avec secret) pour logstream et déclarez
|
||||||
|
l'URL de retour `https://logs.example.org/auth/callback` (votre adresse).
|
||||||
|
2. Dans `.env` :
|
||||||
|
```bash
|
||||||
|
AUTH_MODE=oidc
|
||||||
|
OIDC_ISSUER=https://sso.example.org/realms/maison # exactement l'« issuer » du fournisseur
|
||||||
|
OIDC_CLIENT_ID=logstream
|
||||||
|
OIDC_CLIENT_SECRET=...
|
||||||
|
OIDC_REDIRECT_URL=https://logs.example.org/auth/callback
|
||||||
|
```
|
||||||
|
3. `docker compose up -d`. Les logs affichent `oidc authentication enabled`, ou la raison pour
|
||||||
|
laquelle le fournisseur n'a pas pu être lu (issuer incorrect, injoignable…).
|
||||||
|
|
||||||
|
Ouvrir l'interface renvoie vers la page de connexion du fournisseur, puis revient sur logstream.
|
||||||
|
La session dure `SESSION_TTL` (12 h par défaut) et survit aux redémarrages (sa clé de
|
||||||
|
signature est dans `/data/session.key`) ; à son expiration, la page repasse par la connexion. Le
|
||||||
|
bouton de déconnexion (en haut à droite) termine la session logstream, puis ouvre la page de
|
||||||
|
déconnexion du fournisseur s'il en a une.
|
||||||
|
|
||||||
|
Tout utilisateur accepté par le fournisseur pour ce client peut se connecter : restreignez l'accès
|
||||||
|
dans le fournisseur (Keycloak : rôles du client ou realm dédié ; Authentik : liaisons de
|
||||||
|
l'application). Les connexions sont écrites dans les logs de logstream (`oidc: alice logged in`).
|
||||||
|
Avec une URL de retour en `https`, les cookies ne sont envoyés qu'en HTTPS : logstream doit être
|
||||||
|
joint à travers un reverse proxy TLS.
|
||||||
|
|
||||||
|
## Noms d'hôtes (DNS inverse)
|
||||||
|
|
||||||
|
Quand un équipement envoie son adresse IP comme nom d'hôte (ou pas de nom d'hôte du tout),
|
||||||
|
Logstream cherche son nom DNS (enregistrement PTR) et stocke le nom dans `host` et l'IP dans
|
||||||
|
`host_ip`. Les résultats sont mis en cache (1 heure, 10 minutes quand il n'y a pas de nom). Les
|
||||||
|
logs stockés auparavant avec une IP sont résolus à l'affichage, et le filtre d'hôte affiche
|
||||||
|
`name (IP)`.
|
||||||
|
|
||||||
|
Le conteneur utilise le DNS de Docker, qui relaie vers les résolveurs de l'hôte. Si vos noms
|
||||||
|
locaux ne sont connus que de votre routeur ou d'un DNS local (Pi-hole, AdGuard, Unbound…),
|
||||||
|
définissez `DNS_SERVER=192.168.1.1` (son adresse). Mettez `RDNS=off` pour désactiver les
|
||||||
|
résolutions.
|
||||||
|
|
||||||
|
## Configuration
|
||||||
|
|
||||||
|
| Variable | Défaut | Rôle |
|
||||||
|
|---|---|---|
|
||||||
|
| `SYSLOG_PORT` | `514` | port syslog publié sur l'hôte |
|
||||||
|
| `HTTP_PORT` | `8080` | port de l'interface web |
|
||||||
|
| `RETENTION` | `30d` | durée de conservation des logs dans VictoriaLogs |
|
||||||
|
| `AUTH_MODE` | `local` | `local` (page de connexion) ou `oidc`, voir [Authentification](#authentification) |
|
||||||
|
| `AUTH_USER` / `AUTH_PASS` | vide | compte de la page de connexion (mode `local`) ; vide = pas d'authentification |
|
||||||
|
| `LOGIN_LOGO` | vide | PNG affiché sur la page de connexion, chemin dans le conteneur (mode `local`) |
|
||||||
|
| `SESSION_TTL` | `12h` | durée de la session (les deux modes ; `OIDC_SESSION_TTL` fonctionne toujours) |
|
||||||
|
| `OIDC_ISSUER` | vide | URL de l'issuer du fournisseur OpenID Connect (mode `oidc`) |
|
||||||
|
| `OIDC_CLIENT_ID` / `OIDC_CLIENT_SECRET` | vide | client déclaré dans le fournisseur |
|
||||||
|
| `OIDC_REDIRECT_URL` | vide | URL de retour de logstream, ex. `https://logs.example.org/auth/callback` |
|
||||||
|
| `OIDC_SCOPES` | `openid profile email` | scopes demandés |
|
||||||
|
| `RDNS` | `on` | résoudre les hôtes donnés par leur IP en noms DNS |
|
||||||
|
| `DNS_SERVER` | vide | serveur DNS pour les résolutions inverses (`ip` ou `ip:port`) |
|
||||||
|
| `ALLOW_PURGE` | `true` | autoriser « Supprimer tous les logs » dans les Paramètres |
|
||||||
|
| `EXPORT_MAX` | `100000` | nombre maximal de lignes dans un export CSV |
|
||||||
|
| `DOCKER_LOGS` | `on` dans compose | collecter les logs des conteneurs Docker locaux |
|
||||||
|
| `DOCKER_HOST` | `tcp://docker-proxy:2375` dans compose | adresse de l'API Docker (`unix:///var/run/docker.sock` hors compose) |
|
||||||
|
| `DOCKER_BACKFILL` | `1h` | historique lu pour un conteneur vu pour la première fois |
|
||||||
|
| `HOST_LOGS_GID` | `4` (adm) dans compose | groupe donné au conteneur pour lire les logs de l'hôte |
|
||||||
|
| `HOST_LOGS_BACKFILL` | `1h` | historique lu à l'activation de la source « logs système de l'hôte » |
|
||||||
|
| `HOST_LOGS_ROOT` | `/host` | emplacement de montage des répertoires de l'hôte |
|
||||||
|
| `TZ` | `Europe/Paris` | fuseau horaire des horodatages RFC 3164 (qui n'en portent pas) |
|
||||||
|
| `BATCH_SIZE`, `FLUSH_MS`, `QUEUE_SIZE` | `1000`, `1000`, `100000` | réglage de l'ingestion |
|
||||||
|
|
||||||
|
## Débogage
|
||||||
|
|
||||||
|
- `docker compose logs -f logstream` : erreurs de réception et erreurs d'envoi vers
|
||||||
|
VictoriaLogs.
|
||||||
|
- La barre du bas affiche les compteurs reçus / stockés / perdus et la dernière erreur de
|
||||||
|
stockage.
|
||||||
|
- <http://localhost:9428/select/vmui> : l'interface de VictoriaLogs, pour essayer des requêtes
|
||||||
|
LogsQL.
|
||||||
|
- API :
|
||||||
|
```bash
|
||||||
|
curl 'localhost:8080/api/logs?q=error&range=1h&limit=5' # the response includes the generated LogsQL query
|
||||||
|
curl localhost:8080/api/stats
|
||||||
|
curl localhost:8080/api/tags
|
||||||
|
```
|
||||||
|
- Lancement hors Docker (Go 1.22+) : `VLOGS_URL=http://localhost:9428 DATA_DIR=./data SYSLOG_ADDR=:5514 go run .`
|
||||||
|
|
||||||
|
## Mise à jour
|
||||||
|
|
||||||
|
Toutes les versions d'images sont épinglées : un `docker compose pull` ou une reconstruction ne
|
||||||
|
change jamais un composant à votre insu.
|
||||||
|
|
||||||
|
| Emplacement | Image | Version |
|
||||||
|
|---|---|---|
|
||||||
|
| `docker-compose.yml` | `victoriametrics/victoria-logs` | `v1.52.0` |
|
||||||
|
| `docker-compose.yml` | `tecnativa/docker-socket-proxy` | `v0.5.0` |
|
||||||
|
| `Dockerfile` (build) | `golang` | `1.27.1-alpine3.24` |
|
||||||
|
| `Dockerfile` (exécution) | `alpine` | `3.24.2` |
|
||||||
|
|
||||||
|
Pour mettre à jour l'une d'elles :
|
||||||
|
|
||||||
|
1. Lisez les notes de version : [VictoriaLogs](https://docs.victoriametrics.com/victorialogs/changelog/),
|
||||||
|
[docker-socket-proxy](https://github.com/Tecnativa/docker-socket-proxy/releases),
|
||||||
|
[Go](https://go.dev/doc/devel/release), [Alpine](https://alpinelinux.org/releases/).
|
||||||
|
VictoriaLogs conserve son format de stockage entre versions mineures ; lisez le changelog
|
||||||
|
avant un changement de version majeure.
|
||||||
|
2. Modifiez la version dans le fichier indiqué ci-dessus, puis lancez `docker compose up -d --build`.
|
||||||
|
3. Vérifiez la barre du bas (reçus / stockés / perdus) et **Paramètres > Sources**. Pour revenir
|
||||||
|
en arrière, remettez la version précédente et lancez la même commande.
|
||||||
|
|
||||||
|
## Organisation du code
|
||||||
|
|
||||||
|
| Fichier | Contenu |
|
||||||
|
|---|---|
|
||||||
|
| `main.go` | configuration, démarrage |
|
||||||
|
| `auth.go` | authentification : OpenID Connect (découverte, PKCE, contrôle de l'ID token) et cookie de session signé |
|
||||||
|
| `auth_local.go` | mode `local` : page de connexion (`web/login.html`), cookie de session, `LOGIN_LOGO` |
|
||||||
|
| `syslog.go` | écoute UDP/TCP et analyse RFC 3164 / 5424 |
|
||||||
|
| `store.go` | insertions par lots dans VictoriaLogs et requêtes LogsQL |
|
||||||
|
| `query.go` | traduit les filtres de l'interface en LogsQL ; filtre du direct |
|
||||||
|
| `histogram.go` | frise : division, alignement des intervalles, `/api/histogram` |
|
||||||
|
| `hub.go` | envoie les nouveaux messages aux navigateurs (SSE) |
|
||||||
|
| `rdns.go` | résolutions DNS inverses avec cache |
|
||||||
|
| `export.go` | export CSV en flux |
|
||||||
|
| `docker.go` | logs des conteneurs Docker (API, lecteurs, positions, détection du niveau) |
|
||||||
|
| `syslogserver.go` | écoutes syslog ouvertes et fermées depuis Paramètres > Sources |
|
||||||
|
| `hostlogs.go`, `journal.go` | logs système de l'hôte : lecteur du journal systemd (sans `journalctl`) et suivi de `/var/log` |
|
||||||
|
| `tags.go` | stockage des tags de couleur |
|
||||||
|
| `api.go` | routes HTTP `/api/*` |
|
||||||
|
| `web/` | interface (HTML, CSS, JavaScript simple, sans étape de build), embarquée dans le binaire ; les traductions sont dans `web/app.js` (`I18N`), et dans `web/login.html` pour la page de connexion |
|
||||||
|
|
||||||
|
## Remarque
|
||||||
|
|
||||||
|
Avec Docker Desktop (macOS/Windows), l'IP source vue par le conteneur pour les paquets UDP est
|
||||||
|
la passerelle Docker. Le champ `host` vient toujours de l'en-tête syslog, qui porte normalement
|
||||||
|
le vrai nom de l'émetteur.
|
||||||
@@ -1,3 +1,5 @@
|
|||||||
|
English | [Français](README.fr.md)
|
||||||
|
|
||||||
# Logstream
|
# Logstream
|
||||||
|
|
||||||
A simple syslog sink: receives logs over UDP/TCP on port 514, stores them in
|
A simple syslog sink: receives logs over UDP/TCP on port 514, stores them in
|
||||||
@@ -10,6 +12,24 @@ devices ──514 udp/tcp──▶ logstream (Go) ──HTTP batches──▶ Vi
|
|||||||
└──── API / UI ◀─────────┘
|
└──── API / UI ◀─────────┘
|
||||||
```
|
```
|
||||||
|
|
||||||
|
## Architecture
|
||||||
|
|
||||||
|

|
||||||
|
|
||||||
|
- **Ingestion**: syslog (UDP/TCP) and Docker container logs both go through `sink()` (reverse DNS
|
||||||
|
on IP hosts), then the `Store` queue, which sends them in batches to VictoriaLogs.
|
||||||
|
- **Live view**: `sink()` also publishes each message to the `Hub`, which streams it to the
|
||||||
|
browsers over SSE.
|
||||||
|
- **Search**: the HTTP API turns the UI filters into LogsQL queries sent to VictoriaLogs.
|
||||||
|
- **Timeline**: `/api/histogram` (`histogram.go`) counts the logs per interval and severity,
|
||||||
|
aligned on the local time; the zoom bounds (`from`/`to`) also apply to the list and the export.
|
||||||
|
- **State**: tags and source settings live in `/data` (`logstream-data` volume); the logs
|
||||||
|
themselves in the `vlogs-data` volume.
|
||||||
|
|
||||||
|
The editable source of the diagram is
|
||||||
|
[`docs/architecture.excalidraw`](docs/architecture.excalidraw)
|
||||||
|
(open it on [excalidraw.com](https://excalidraw.com)).
|
||||||
|
|
||||||
## Getting started
|
## Getting started
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
@@ -64,6 +84,12 @@ Severity badges `err`/`crit` and `warning` use the colors of the `error` and `wa
|
|||||||
|
|
||||||
Shortcuts: `/` focuses the search box, `Esc` clears it. Clicking a row shows all its fields.
|
Shortcuts: `/` focuses the search box, `Esc` clears it. Clicking a row shows all its fields.
|
||||||
|
|
||||||
|
The column headers stay visible while scrolling. Drag the edge of a header (received, message
|
||||||
|
time, severity, host, app) to resize the column, double-click it to go back to the automatic
|
||||||
|
width; the message takes the remaining space. Widths are remembered by the browser
|
||||||
|
(**Settings > Interface > Reset column widths** restores them all). On phones the list keeps its
|
||||||
|
two-line layout without columns.
|
||||||
|
|
||||||
## Timeline
|
## Timeline
|
||||||
|
|
||||||
The timeline above the list shows the volume of logs per interval, counted by **reception
|
The timeline above the list shows the volume of logs per interval, counted by **reception
|
||||||
@@ -121,6 +147,32 @@ colored and exported like syslog messages:
|
|||||||
therefore goes through [docker-socket-proxy](https://github.com/Tecnativa/docker-socket-proxy),
|
therefore goes through [docker-socket-proxy](https://github.com/Tecnativa/docker-socket-proxy),
|
||||||
which only lets through listing containers, reading logs, events and engine info (`GET` only).
|
which only lets through listing containers, reading logs, events and engine info (`GET` only).
|
||||||
|
|
||||||
|
## Host system logs
|
||||||
|
|
||||||
|
Logstream can also collect the system logs of the machine hosting the stack, without
|
||||||
|
configuring anything on the host. The source is **off by default**: turn it on in
|
||||||
|
**Settings > Sources > Host system logs** (saved in `/data/hostlogs.json`).
|
||||||
|
|
||||||
|
- `docker-compose.yml` mounts `/var/log` and `/run/log/journal` read-only under `/host`.
|
||||||
|
- When the host runs systemd, Logstream reads the **systemd journal** files directly (no
|
||||||
|
`journalctl` needed in the image): **host** is the machine name, **app** the program
|
||||||
|
(`SYSLOG_IDENTIFIER`), severity and facility come from the journal, and the systemd unit is
|
||||||
|
kept in `unit`. Otherwise it follows the text files of `/var/log` (`syslog`, `messages`,
|
||||||
|
`*.log`), parsed like syslog lines, with the file name in `log_file`.
|
||||||
|
- These logs have the `host` source: the **Source** filter shows them alone.
|
||||||
|
- When the source is turned on, the last hour is read first (`HOST_LOGS_BACKFILL`); the
|
||||||
|
position reached is saved in `/data/hostlogs-state.json`, so a restart neither loses nor
|
||||||
|
duplicates entries.
|
||||||
|
- **Permissions**: the container runs as an unprivileged user and gets the `adm` group
|
||||||
|
(gid 4), which can read the journal and `/var/log` on Debian and Ubuntu. On other systems,
|
||||||
|
set `HOST_LOGS_GID` in `.env` to the gid of `systemd-journal`
|
||||||
|
(`getent group systemd-journal | cut -d: -f3`). Settings > Sources shows a clear message when
|
||||||
|
access is denied.
|
||||||
|
- Limits: journal fields compressed by journald (messages longer than 512 bytes, compressed
|
||||||
|
with zstd/lz4/xz) cannot be decoded without extra libraries; they are counted in Settings and
|
||||||
|
shown as "(compressed journal entry)". Rotated or compressed text files (`*.1`, `*.gz`) are
|
||||||
|
not read.
|
||||||
|
|
||||||
## CSV export
|
## CSV export
|
||||||
|
|
||||||
The **Export** button (next to the log count) downloads every stored log matching the
|
The **Export** button (next to the log count) downloads every stored log matching the
|
||||||
@@ -155,20 +207,82 @@ remembered per browser.
|
|||||||
(`logstream-data` volume), so they are shared by every browser. Default tags (pastel):
|
(`logstream-data` volume), so they are shared by every browser. Default tags (pastel):
|
||||||
`warning` (orange), `error` (red), `ok` (green). Default tags still using the colors of
|
`warning` (orange), `error` (red), `ok` (green). Default tags still using the colors of
|
||||||
earlier versions are switched to the pastel ones automatically.
|
earlier versions are switched to the pastel ones automatically.
|
||||||
|
The *+ Preset…* menu adds ready-made tags for HTTP/HTTPS access logs (nginx and Apache
|
||||||
|
common/combined, Traefik CLF and JSON, Caddy JSON, HAProxy httplog): status codes (2xx green,
|
||||||
|
3xx blue, 4xx orange, 5xx red), methods, probes and attacks (`wp-login.php`, `/.env`,
|
||||||
|
`../`…), bots and scripts, TLS and proxy errors. Tags already in the list are skipped, and the
|
||||||
|
added tags can be edited like any other. In a regular expression, a group named `hl`
|
||||||
|
(`(?<hl>…)`) colors only that part of the match: the presets use it to color the status code
|
||||||
|
or the method, not the text around it.
|
||||||
- **Interface**
|
- **Interface**
|
||||||
- *Theme*: System (follows the computer/phone preference), Light or Dark. The sun/moon
|
- *Theme*: System (follows the computer/phone preference), Light or Dark. The sun/moon
|
||||||
button in the header switches between light and dark.
|
button in the header switches between light and dark.
|
||||||
- *Log display*: font size (tiny, small, medium, large) and font: the system monospace
|
- *Log display*: font size (tiny, small, medium, large), density (normal, or compact to
|
||||||
font, or one of 12 free fonts made for dense text (JetBrains Mono, Fira Code, Source
|
fit about 50% more lines on screen) and font: the system monospace font,
|
||||||
Code Pro, IBM Plex Mono, Cascadia Code, Roboto Mono, Ubuntu Mono, Inconsolata, Red Hat
|
[Iosevka](https://github.com/be5invis/Iosevka) (narrow, so more text fits on each line;
|
||||||
Mono, Noto Sans Mono, Victor Mono, DM Mono). They are loaded by the browser from
|
served by LogStream itself, works offline), or one of 12 free fonts made for dense text
|
||||||
[Bunny Fonts](https://fonts.bunny.net), a privacy-friendly European font service; without
|
(JetBrains Mono, Fira Code, Source Code Pro, IBM Plex Mono, Cascadia Code, Roboto Mono,
|
||||||
internet access, the system font is used. Ligatures are disabled so `->` or `!=` show as typed.
|
Ubuntu Mono, Inconsolata, Red Hat Mono, Noto Sans Mono, Victor Mono, DM Mono). These 12 are
|
||||||
|
loaded by the browser from [Bunny Fonts](https://fonts.bunny.net), a privacy-friendly
|
||||||
|
European font service; without internet access, the system font is used. Ligatures are
|
||||||
|
disabled so `->` or `!=` show as typed. The densest setting is Tiny + Compact + Iosevka.
|
||||||
- **Data**: "Delete all logs" permanently erases every stored log (you must type
|
- **Data**: "Delete all logs" permanently erases every stored log (you must type
|
||||||
`PURGE` to confirm). Tags and settings are kept. VictoriaLogs needs `-delete.enable`
|
`PURGE` to confirm). Tags and settings are kept. VictoriaLogs needs `-delete.enable`
|
||||||
(already set in `docker-compose.yml`); set `ALLOW_PURGE=false` to disable the feature.
|
(already set in `docker-compose.yml`); set `ALLOW_PURGE=false` to disable the feature.
|
||||||
Anyone who can open the UI can purge: set `AUTH_USER` / `AUTH_PASS` if the UI is reachable
|
Anyone who can open the UI can purge: turn on [authentication](#authentication) if the UI
|
||||||
by others.
|
is reachable by others.
|
||||||
|
|
||||||
|
## Authentication
|
||||||
|
|
||||||
|
`AUTH_MODE` picks how the UI and the API are protected (`/healthz` always stays open):
|
||||||
|
|
||||||
|
- **`local`** (default): a login page with the account `AUTH_USER` / `AUTH_PASS`; leave them
|
||||||
|
empty to have no authentication (for instance behind a reverse proxy that already checks).
|
||||||
|
- **`oidc`**: login through an OpenID Connect provider (Keycloak, Authentik, Authelia, Zitadel…),
|
||||||
|
authorization code flow with PKCE.
|
||||||
|
|
||||||
|
In `local` mode the login page follows the theme and language of the UI. The session lasts
|
||||||
|
`SESSION_TTL` (12 h by default), survives restarts (its signing key is in `/data/session.key`) and
|
||||||
|
ends when `AUTH_USER` or `AUTH_PASS` changes; the log out button (top right) ends it. Failed logins
|
||||||
|
are written in the logs with the client address (`auth: failed login for "bob" from 192.0.2.7`).
|
||||||
|
Scripts can still call the API with HTTP Basic credentials (`curl -u user:pass`).
|
||||||
|
|
||||||
|
To show your logo on the login page, mount a PNG in the container and point `LOGIN_LOGO` to it:
|
||||||
|
|
||||||
|
```yaml
|
||||||
|
# docker-compose.yml, logstream service
|
||||||
|
volumes:
|
||||||
|
- ./logo.png:/config/logo.png:ro
|
||||||
|
```
|
||||||
|
```bash
|
||||||
|
# .env
|
||||||
|
LOGIN_LOGO=/config/logo.png
|
||||||
|
```
|
||||||
|
|
||||||
|
To use OIDC:
|
||||||
|
|
||||||
|
1. In the provider, create a **confidential** client (with a secret) for logstream and register
|
||||||
|
the redirect URL `https://logs.example.org/auth/callback` (your address).
|
||||||
|
2. In `.env`:
|
||||||
|
```bash
|
||||||
|
AUTH_MODE=oidc
|
||||||
|
OIDC_ISSUER=https://sso.example.org/realms/home # exactly the "issuer" of the provider
|
||||||
|
OIDC_CLIENT_ID=logstream
|
||||||
|
OIDC_CLIENT_SECRET=...
|
||||||
|
OIDC_REDIRECT_URL=https://logs.example.org/auth/callback
|
||||||
|
```
|
||||||
|
3. `docker compose up -d`. The logs show `oidc authentication enabled`, or the reason the
|
||||||
|
provider could not be read (wrong issuer, unreachable…).
|
||||||
|
|
||||||
|
Opening the UI sends you to the provider's login page, then back to logstream. The session
|
||||||
|
lasts `SESSION_TTL` (12 h by default) and survives restarts (its signing key is in
|
||||||
|
`/data/session.key`); when it ends, the page goes through the login again. The log out button
|
||||||
|
(top right) ends the logstream session, then opens the provider's log out page if it has one.
|
||||||
|
|
||||||
|
Every user the provider accepts for this client can log in: restrict access in the provider
|
||||||
|
(Keycloak: client roles or a dedicated realm; Authentik: application bindings). Logins are written
|
||||||
|
in the logstream logs (`oidc: alice logged in`). With an `https` redirect URL, the cookies are
|
||||||
|
only sent over HTTPS: logstream must be reached through a TLS reverse proxy.
|
||||||
|
|
||||||
## Host names (reverse DNS)
|
## Host names (reverse DNS)
|
||||||
|
|
||||||
@@ -180,11 +294,6 @@ on display, and the host filter shows `name (IP)`.
|
|||||||
The container uses Docker's DNS, which forwards to the host's resolvers. If your local names
|
The container uses Docker's DNS, which forwards to the host's resolvers. If your local names
|
||||||
are only known by your router or a local DNS (Pi-hole, AdGuard, Unbound…), set
|
are only known by your router or a local DNS (Pi-hole, AdGuard, Unbound…), set
|
||||||
`DNS_SERVER=192.168.1.1` (its address). Set `RDNS=off` to disable lookups.
|
`DNS_SERVER=192.168.1.1` (its address). Set `RDNS=off` to disable lookups.
|
||||||
- **Color tags**: each tag has a keyword, a background color (the text automatically
|
|
||||||
switches to black or white to stay readable) and options: whole word, match case,
|
|
||||||
regular expression, active. Tags are stored in `/data/tags.json` (`logstream-data` volume).
|
|
||||||
Default tags (pastel): `warning` (orange), `error` (red), `ok` (green). Default tags
|
|
||||||
still using the colors of earlier versions are switched to the pastel ones automatically.
|
|
||||||
|
|
||||||
## Configuration
|
## Configuration
|
||||||
|
|
||||||
@@ -193,7 +302,14 @@ are only known by your router or a local DNS (Pi-hole, AdGuard, Unbound…), set
|
|||||||
| `SYSLOG_PORT` | `514` | syslog port published on the host |
|
| `SYSLOG_PORT` | `514` | syslog port published on the host |
|
||||||
| `HTTP_PORT` | `8080` | web UI port |
|
| `HTTP_PORT` | `8080` | web UI port |
|
||||||
| `RETENTION` | `30d` | how long VictoriaLogs keeps logs |
|
| `RETENTION` | `30d` | how long VictoriaLogs keeps logs |
|
||||||
| `AUTH_USER` / `AUTH_PASS` | empty | HTTP Basic authentication for the UI |
|
| `AUTH_MODE` | `local` | `local` (login page) or `oidc`, see [Authentication](#authentication) |
|
||||||
|
| `AUTH_USER` / `AUTH_PASS` | empty | account of the login page (`local` mode); empty = no authentication |
|
||||||
|
| `LOGIN_LOGO` | empty | PNG shown on the login page, path inside the container (`local` mode) |
|
||||||
|
| `SESSION_TTL` | `12h` | session lifetime (both modes; `OIDC_SESSION_TTL` still works) |
|
||||||
|
| `OIDC_ISSUER` | empty | issuer URL of the OpenID Connect provider (`oidc` mode) |
|
||||||
|
| `OIDC_CLIENT_ID` / `OIDC_CLIENT_SECRET` | empty | client registered in the provider |
|
||||||
|
| `OIDC_REDIRECT_URL` | empty | callback URL of logstream, e.g. `https://logs.example.org/auth/callback` |
|
||||||
|
| `OIDC_SCOPES` | `openid profile email` | requested scopes |
|
||||||
| `RDNS` | `on` | resolve IP hosts to DNS names |
|
| `RDNS` | `on` | resolve IP hosts to DNS names |
|
||||||
| `DNS_SERVER` | empty | DNS server for reverse lookups (`ip` or `ip:port`) |
|
| `DNS_SERVER` | empty | DNS server for reverse lookups (`ip` or `ip:port`) |
|
||||||
| `ALLOW_PURGE` | `true` | allow "Delete all logs" in Settings |
|
| `ALLOW_PURGE` | `true` | allow "Delete all logs" in Settings |
|
||||||
@@ -201,6 +317,9 @@ are only known by your router or a local DNS (Pi-hole, AdGuard, Unbound…), set
|
|||||||
| `DOCKER_LOGS` | `on` in compose | collect the logs of the local Docker containers |
|
| `DOCKER_LOGS` | `on` in compose | collect the logs of the local Docker containers |
|
||||||
| `DOCKER_HOST` | `tcp://docker-proxy:2375` in compose | Docker API address (`unix:///var/run/docker.sock` outside compose) |
|
| `DOCKER_HOST` | `tcp://docker-proxy:2375` in compose | Docker API address (`unix:///var/run/docker.sock` outside compose) |
|
||||||
| `DOCKER_BACKFILL` | `1h` | history read from a container seen for the first time |
|
| `DOCKER_BACKFILL` | `1h` | history read from a container seen for the first time |
|
||||||
|
| `HOST_LOGS_GID` | `4` (adm) in compose | group given to the container to read the host logs |
|
||||||
|
| `HOST_LOGS_BACKFILL` | `1h` | history read when the host system logs source is turned on |
|
||||||
|
| `HOST_LOGS_ROOT` | `/host` | where the host directories are mounted |
|
||||||
| `TZ` | `Europe/Paris` | time zone for RFC 3164 timestamps (which carry none) |
|
| `TZ` | `Europe/Paris` | time zone for RFC 3164 timestamps (which carry none) |
|
||||||
| `BATCH_SIZE`, `FLUSH_MS`, `QUEUE_SIZE` | `1000`, `1000`, `100000` | ingestion tuning |
|
| `BATCH_SIZE`, `FLUSH_MS`, `QUEUE_SIZE` | `1000`, `1000`, `100000` | ingestion tuning |
|
||||||
|
|
||||||
@@ -244,7 +363,9 @@ To update one of them:
|
|||||||
|
|
||||||
| File | Contents |
|
| File | Contents |
|
||||||
|---|---|
|
|---|---|
|
||||||
| `main.go` | configuration, startup, authentication |
|
| `main.go` | configuration, startup |
|
||||||
|
| `auth.go` | authentication: OpenID Connect (discovery, PKCE, ID token checks) and the signed session cookie |
|
||||||
|
| `auth_local.go` | `local` mode: login page (`web/login.html`), session cookie, `LOGIN_LOGO` |
|
||||||
| `syslog.go` | UDP/TCP listeners and RFC 3164 / 5424 parsing |
|
| `syslog.go` | UDP/TCP listeners and RFC 3164 / 5424 parsing |
|
||||||
| `store.go` | batched inserts into VictoriaLogs and LogsQL queries |
|
| `store.go` | batched inserts into VictoriaLogs and LogsQL queries |
|
||||||
| `query.go` | turns UI filters into LogsQL; live-view filter |
|
| `query.go` | turns UI filters into LogsQL; live-view filter |
|
||||||
@@ -254,9 +375,10 @@ To update one of them:
|
|||||||
| `export.go` | streamed CSV export |
|
| `export.go` | streamed CSV export |
|
||||||
| `docker.go` | Docker container logs (API, followers, positions, level detection) |
|
| `docker.go` | Docker container logs (API, followers, positions, level detection) |
|
||||||
| `syslogserver.go` | syslog listeners opened and closed from Settings > Sources |
|
| `syslogserver.go` | syslog listeners opened and closed from Settings > Sources |
|
||||||
|
| `hostlogs.go`, `journal.go` | host system logs: systemd journal reader (no `journalctl`) and `/var/log` follower |
|
||||||
| `tags.go` | color tag storage |
|
| `tags.go` | color tag storage |
|
||||||
| `api.go` | `/api/*` HTTP routes |
|
| `api.go` | `/api/*` HTTP routes |
|
||||||
| `web/` | UI (HTML, CSS, plain JavaScript, no build step), embedded in the binary; translations live in `web/app.js` (`I18N`) |
|
| `web/` | UI (HTML, CSS, plain JavaScript, no build step), embedded in the binary; translations live in `web/app.js` (`I18N`), and in `web/login.html` for the login page |
|
||||||
|
|
||||||
## Note
|
## Note
|
||||||
|
|
||||||
|
|||||||
@@ -21,6 +21,7 @@ type API struct {
|
|||||||
exportMax int
|
exportMax int
|
||||||
docker *DockerManager // nil when DOCKER_LOGS is off
|
docker *DockerManager // nil when DOCKER_LOGS is off
|
||||||
syslog *SyslogServer
|
syslog *SyslogServer
|
||||||
|
host *HostLogs
|
||||||
}
|
}
|
||||||
|
|
||||||
func (a *API) Routes(mux *http.ServeMux) {
|
func (a *API) Routes(mux *http.ServeMux) {
|
||||||
@@ -42,6 +43,28 @@ func (a *API) Routes(mux *http.ServeMux) {
|
|||||||
mux.HandleFunc("PUT /api/syslog", a.syslogConfigure)
|
mux.HandleFunc("PUT /api/syslog", a.syslogConfigure)
|
||||||
mux.HandleFunc("GET /api/docker", a.dockerStatus)
|
mux.HandleFunc("GET /api/docker", a.dockerStatus)
|
||||||
mux.HandleFunc("PUT /api/docker", a.dockerConfigure)
|
mux.HandleFunc("PUT /api/docker", a.dockerConfigure)
|
||||||
|
mux.HandleFunc("GET /api/hostlogs", a.hostLogsStatus)
|
||||||
|
mux.HandleFunc("PUT /api/hostlogs", a.hostLogsConfigure)
|
||||||
|
}
|
||||||
|
|
||||||
|
// GET /api/hostlogs: state of the host system logs source (Settings > Sources).
|
||||||
|
func (a *API) hostLogsStatus(w http.ResponseWriter, r *http.Request) {
|
||||||
|
writeJSON(w, http.StatusOK, a.host.Status())
|
||||||
|
}
|
||||||
|
|
||||||
|
// PUT /api/hostlogs {"enabled": bool}
|
||||||
|
func (a *API) hostLogsConfigure(w http.ResponseWriter, r *http.Request) {
|
||||||
|
var cfg hostLogsConfig
|
||||||
|
if err := json.NewDecoder(http.MaxBytesReader(w, r.Body, 4096)).Decode(&cfg); err != nil {
|
||||||
|
writeErr(w, http.StatusBadRequest, err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if err := a.host.Configure(cfg); err != nil {
|
||||||
|
writeErr(w, http.StatusInternalServerError, err)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
log.Printf("host system logs changed from %s: %+v", r.RemoteAddr, cfg)
|
||||||
|
writeJSON(w, http.StatusOK, a.host.Status())
|
||||||
}
|
}
|
||||||
|
|
||||||
// GET /api/syslog: syslog reception state (Settings > Sources).
|
// GET /api/syslog: syslog reception state (Settings > Sources).
|
||||||
|
|||||||
@@ -0,0 +1,622 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"crypto"
|
||||||
|
"crypto/ecdsa"
|
||||||
|
"crypto/elliptic"
|
||||||
|
"crypto/hmac"
|
||||||
|
"crypto/rand"
|
||||||
|
"crypto/rsa"
|
||||||
|
"crypto/sha256"
|
||||||
|
_ "crypto/sha512" // SHA-384/512 for RS384, ES384, RS512…
|
||||||
|
"crypto/subtle"
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"fmt"
|
||||||
|
"io"
|
||||||
|
"log"
|
||||||
|
"math/big"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"sync"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Web UI authentication. AUTH_MODE=local (default) shows a login page when AUTH_USER /
|
||||||
|
// AUTH_PASS are set (auth_local.go); AUTH_MODE=oidc delegates the login to an
|
||||||
|
// OpenID Connect provider (Keycloak, Authentik, Authelia…) with the authorization code
|
||||||
|
// flow and PKCE. Only the standard library is used.
|
||||||
|
|
||||||
|
const (
|
||||||
|
sessionCookie = "logstream_session"
|
||||||
|
loginCookie = "logstream_login_" // + state: one cookie per login in progress
|
||||||
|
loginTTL = 10 * time.Minute
|
||||||
|
clockSkew = time.Minute
|
||||||
|
)
|
||||||
|
|
||||||
|
type authConfig struct {
|
||||||
|
mode string
|
||||||
|
user, pass string // local mode
|
||||||
|
issuer string
|
||||||
|
clientID string
|
||||||
|
clientSecret string
|
||||||
|
redirectURL string
|
||||||
|
scopes string
|
||||||
|
sessionTTL time.Duration
|
||||||
|
dataDir string
|
||||||
|
loginLogo string // local mode: PNG shown on the login page
|
||||||
|
|
||||||
|
}
|
||||||
|
|
||||||
|
// newAuth returns the middleware that protects the UI and the API (except /healthz).
|
||||||
|
func newAuth(c authConfig, next http.Handler) (http.Handler, error) {
|
||||||
|
if c.sessionTTL <= 0 {
|
||||||
|
c.sessionTTL = 12 * time.Hour
|
||||||
|
}
|
||||||
|
switch strings.ToLower(c.mode) {
|
||||||
|
case "", "local":
|
||||||
|
if c.user == "" {
|
||||||
|
return next, nil
|
||||||
|
}
|
||||||
|
l := newLocal(c)
|
||||||
|
l.next = next
|
||||||
|
return l, nil
|
||||||
|
case "oidc":
|
||||||
|
o, err := newOIDC(c)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
o.next = next
|
||||||
|
log.Printf("oidc authentication enabled (issuer %s)", c.issuer)
|
||||||
|
return o, nil
|
||||||
|
}
|
||||||
|
return nil, fmt.Errorf("AUTH_MODE=%q: expected local or oidc", c.mode)
|
||||||
|
}
|
||||||
|
|
||||||
|
type oidcMeta struct {
|
||||||
|
Issuer string `json:"issuer"`
|
||||||
|
AuthEndpoint string `json:"authorization_endpoint"`
|
||||||
|
TokenEndpoint string `json:"token_endpoint"`
|
||||||
|
JWKSURI string `json:"jwks_uri"`
|
||||||
|
EndSession string `json:"end_session_endpoint"`
|
||||||
|
TokenAuthMethods []string `json:"token_endpoint_auth_methods_supported"`
|
||||||
|
}
|
||||||
|
|
||||||
|
type OIDC struct {
|
||||||
|
cfg authConfig
|
||||||
|
callback string // path of OIDC_REDIRECT_URL
|
||||||
|
secure bool // cookies only sent over HTTPS
|
||||||
|
key []byte // signs the session and login cookies
|
||||||
|
client *http.Client
|
||||||
|
next http.Handler
|
||||||
|
|
||||||
|
mu sync.Mutex
|
||||||
|
meta *oidcMeta
|
||||||
|
keys map[string]crypto.PublicKey
|
||||||
|
keysAt time.Time
|
||||||
|
}
|
||||||
|
|
||||||
|
func newOIDC(c authConfig) (*OIDC, error) {
|
||||||
|
var missing []string
|
||||||
|
for _, v := range [][2]string{
|
||||||
|
{"OIDC_ISSUER", c.issuer}, {"OIDC_CLIENT_ID", c.clientID},
|
||||||
|
{"OIDC_CLIENT_SECRET", c.clientSecret}, {"OIDC_REDIRECT_URL", c.redirectURL},
|
||||||
|
} {
|
||||||
|
if v[1] == "" {
|
||||||
|
missing = append(missing, v[0])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(missing) > 0 {
|
||||||
|
return nil, fmt.Errorf("AUTH_MODE=oidc: missing %s", strings.Join(missing, ", "))
|
||||||
|
}
|
||||||
|
ru, err := url.Parse(c.redirectURL)
|
||||||
|
if err != nil || ru.Host == "" || ru.Path == "" || ru.Path == "/" {
|
||||||
|
return nil, fmt.Errorf("OIDC_REDIRECT_URL=%q: expected a full URL such as https://logs.example.org/auth/callback", c.redirectURL)
|
||||||
|
}
|
||||||
|
if c.scopes == "" {
|
||||||
|
c.scopes = "openid profile email"
|
||||||
|
}
|
||||||
|
if !strings.Contains(" "+c.scopes+" ", " openid ") {
|
||||||
|
c.scopes = "openid " + c.scopes
|
||||||
|
}
|
||||||
|
return &OIDC{
|
||||||
|
cfg: c,
|
||||||
|
callback: ru.Path,
|
||||||
|
secure: ru.Scheme == "https",
|
||||||
|
key: sessionKey(c.dataDir),
|
||||||
|
client: &http.Client{Timeout: 10 * time.Second},
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// checkProvider reads the provider configuration at startup so a mistake shows in the logs.
|
||||||
|
func (o *OIDC) checkProvider() {
|
||||||
|
if _, err := o.discover(); err != nil {
|
||||||
|
log.Printf("oidc: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// sessionKey is kept in DATA_DIR so sessions survive a restart.
|
||||||
|
func sessionKey(dir string) []byte {
|
||||||
|
path := filepath.Join(dir, "session.key")
|
||||||
|
if k, err := os.ReadFile(path); err == nil && len(k) >= 32 {
|
||||||
|
return k
|
||||||
|
}
|
||||||
|
k := make([]byte, 32)
|
||||||
|
if _, err := rand.Read(k); err != nil {
|
||||||
|
log.Fatalf("session key: %v", err)
|
||||||
|
}
|
||||||
|
if err := os.WriteFile(path, k, 0o600); err != nil {
|
||||||
|
log.Printf("auth: cannot save %s (%v): sessions end when logstream restarts", path, err)
|
||||||
|
}
|
||||||
|
return k
|
||||||
|
}
|
||||||
|
|
||||||
|
type session struct {
|
||||||
|
User string `json:"u"`
|
||||||
|
Exp int64 `json:"e"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// writeAuthRequired answers API calls without a session; the UI turns it into a reload
|
||||||
|
// (and so into a new login).
|
||||||
|
func writeAuthRequired(w http.ResponseWriter) {
|
||||||
|
w.Header().Set("Content-Type", "application/json")
|
||||||
|
w.WriteHeader(http.StatusUnauthorized)
|
||||||
|
_, _ = w.Write([]byte(`{"error":"authentication required","code":"auth"}` + "\n"))
|
||||||
|
}
|
||||||
|
|
||||||
|
type loginState struct {
|
||||||
|
Nonce string `json:"n"`
|
||||||
|
Verifier string `json:"v"`
|
||||||
|
Return string `json:"r"`
|
||||||
|
Exp int64 `json:"e"`
|
||||||
|
}
|
||||||
|
|
||||||
|
func (o *OIDC) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/healthz":
|
||||||
|
o.next.ServeHTTP(w, r)
|
||||||
|
return
|
||||||
|
case o.callback:
|
||||||
|
o.handleCallback(w, r)
|
||||||
|
return
|
||||||
|
case "/auth/logout":
|
||||||
|
o.handleLogout(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
var s session
|
||||||
|
if c, err := r.Cookie(sessionCookie); err == nil && verifyCookie(o.key, c.Value, &s) && time.Now().Unix() < s.Exp {
|
||||||
|
if r.URL.Path == "/auth/me" {
|
||||||
|
writeJSON(w, http.StatusOK, map[string]string{"mode": "oidc", "user": s.User})
|
||||||
|
return
|
||||||
|
}
|
||||||
|
o.next.ServeHTTP(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
// Not logged in: pages go to the provider, API calls get a 401 that the UI turns
|
||||||
|
// into a reload (and so into a new login).
|
||||||
|
if r.Method == http.MethodGet && !strings.HasPrefix(r.URL.Path, "/api/") && r.URL.Path != "/auth/me" {
|
||||||
|
o.startLogin(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
writeAuthRequired(w)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (o *OIDC) startLogin(w http.ResponseWriter, r *http.Request) {
|
||||||
|
meta, err := o.discover()
|
||||||
|
if err != nil {
|
||||||
|
log.Printf("oidc: %v", err)
|
||||||
|
http.Error(w, "identity provider unreachable, try again later", http.StatusBadGateway)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
state, nonce, verifier := randomString(), randomString(), randomString()+randomString()
|
||||||
|
ret := r.URL.RequestURI()
|
||||||
|
if !strings.HasPrefix(ret, "/") || strings.HasPrefix(ret, "//") {
|
||||||
|
ret = "/"
|
||||||
|
}
|
||||||
|
http.SetCookie(w, &http.Cookie{
|
||||||
|
Name: loginCookie + state,
|
||||||
|
Value: signCookie(o.key, loginState{Nonce: nonce, Verifier: verifier, Return: ret, Exp: time.Now().Add(loginTTL).Unix()}),
|
||||||
|
Path: "/",
|
||||||
|
MaxAge: int(loginTTL.Seconds()),
|
||||||
|
HttpOnly: true,
|
||||||
|
Secure: o.secure,
|
||||||
|
SameSite: http.SameSiteLaxMode, // sent back on the redirect from the provider
|
||||||
|
})
|
||||||
|
challenge := sha256.Sum256([]byte(verifier))
|
||||||
|
q := url.Values{
|
||||||
|
"response_type": {"code"},
|
||||||
|
"client_id": {o.cfg.clientID},
|
||||||
|
"redirect_uri": {o.cfg.redirectURL},
|
||||||
|
"scope": {o.cfg.scopes},
|
||||||
|
"state": {state},
|
||||||
|
"nonce": {nonce},
|
||||||
|
"code_challenge": {base64.RawURLEncoding.EncodeToString(challenge[:])},
|
||||||
|
"code_challenge_method": {"S256"},
|
||||||
|
}
|
||||||
|
http.Redirect(w, r, addQuery(meta.AuthEndpoint, q), http.StatusFound)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (o *OIDC) handleCallback(w http.ResponseWriter, r *http.Request) {
|
||||||
|
q := r.URL.Query()
|
||||||
|
if e := q.Get("error"); e != "" {
|
||||||
|
log.Printf("oidc: login refused by the provider: %s %s", e, q.Get("error_description"))
|
||||||
|
http.Error(w, "login refused by the identity provider: "+e, http.StatusForbidden)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
state := q.Get("state")
|
||||||
|
var ls loginState
|
||||||
|
c, err := r.Cookie(loginCookie + state)
|
||||||
|
if state == "" || err != nil || !verifyCookie(o.key, c.Value, &ls) || time.Now().Unix() > ls.Exp {
|
||||||
|
http.Error(w, "login expired or started in another browser: open LogStream again", http.StatusBadRequest)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
http.SetCookie(w, &http.Cookie{Name: loginCookie + state, Path: "/", MaxAge: -1, HttpOnly: true, Secure: o.secure})
|
||||||
|
|
||||||
|
user, err := o.exchange(r, q.Get("code"), ls)
|
||||||
|
if err != nil {
|
||||||
|
log.Printf("oidc: login failed: %v", err)
|
||||||
|
http.Error(w, "login failed, see the LogStream logs", http.StatusForbidden)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
log.Printf("oidc: %s logged in", user)
|
||||||
|
http.SetCookie(w, &http.Cookie{
|
||||||
|
Name: sessionCookie,
|
||||||
|
Value: signCookie(o.key, session{User: user, Exp: time.Now().Add(o.cfg.sessionTTL).Unix()}),
|
||||||
|
Path: "/",
|
||||||
|
MaxAge: int(o.cfg.sessionTTL.Seconds()),
|
||||||
|
HttpOnly: true,
|
||||||
|
Secure: o.secure,
|
||||||
|
SameSite: http.SameSiteLaxMode,
|
||||||
|
})
|
||||||
|
http.Redirect(w, r, ls.Return, http.StatusFound)
|
||||||
|
}
|
||||||
|
|
||||||
|
// The session ends here; the provider's own session ends on its logout page if it has one.
|
||||||
|
func (o *OIDC) handleLogout(w http.ResponseWriter, r *http.Request) {
|
||||||
|
http.SetCookie(w, &http.Cookie{Name: sessionCookie, Path: "/", MaxAge: -1, HttpOnly: true, Secure: o.secure})
|
||||||
|
if meta, err := o.discover(); err == nil && meta.EndSession != "" {
|
||||||
|
http.Redirect(w, r, addQuery(meta.EndSession, url.Values{"client_id": {o.cfg.clientID}}), http.StatusFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
http.Redirect(w, r, "/", http.StatusFound)
|
||||||
|
}
|
||||||
|
|
||||||
|
// exchange trades the code for tokens and returns the user name from the verified ID token.
|
||||||
|
func (o *OIDC) exchange(r *http.Request, code string, ls loginState) (string, error) {
|
||||||
|
if code == "" {
|
||||||
|
return "", errors.New("no code in the callback")
|
||||||
|
}
|
||||||
|
meta, err := o.discover()
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
form := url.Values{
|
||||||
|
"grant_type": {"authorization_code"},
|
||||||
|
"code": {code},
|
||||||
|
"redirect_uri": {o.cfg.redirectURL},
|
||||||
|
"code_verifier": {ls.Verifier},
|
||||||
|
}
|
||||||
|
// client_secret_basic is the default; some providers only accept client_secret_post.
|
||||||
|
post := len(meta.TokenAuthMethods) > 0 && !contains(meta.TokenAuthMethods, "client_secret_basic") && contains(meta.TokenAuthMethods, "client_secret_post")
|
||||||
|
if post {
|
||||||
|
form.Set("client_id", o.cfg.clientID)
|
||||||
|
form.Set("client_secret", o.cfg.clientSecret)
|
||||||
|
}
|
||||||
|
req, err := http.NewRequestWithContext(r.Context(), http.MethodPost, meta.TokenEndpoint, strings.NewReader(form.Encode()))
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
||||||
|
req.Header.Set("Accept", "application/json")
|
||||||
|
if !post {
|
||||||
|
req.SetBasicAuth(url.QueryEscape(o.cfg.clientID), url.QueryEscape(o.cfg.clientSecret))
|
||||||
|
}
|
||||||
|
res, err := o.client.Do(req)
|
||||||
|
if err != nil {
|
||||||
|
return "", fmt.Errorf("token endpoint: %w", err)
|
||||||
|
}
|
||||||
|
defer res.Body.Close()
|
||||||
|
body, _ := io.ReadAll(io.LimitReader(res.Body, 1<<20))
|
||||||
|
if res.StatusCode != http.StatusOK {
|
||||||
|
return "", fmt.Errorf("token endpoint: %s: %s", res.Status, bytes.TrimSpace(body))
|
||||||
|
}
|
||||||
|
var tok struct {
|
||||||
|
IDToken string `json:"id_token"`
|
||||||
|
}
|
||||||
|
if err := json.Unmarshal(body, &tok); err != nil || tok.IDToken == "" {
|
||||||
|
return "", errors.New("token endpoint: no id_token in the response")
|
||||||
|
}
|
||||||
|
claims, err := o.verifyIDToken(tok.IDToken, ls.Nonce)
|
||||||
|
if err != nil {
|
||||||
|
return "", err
|
||||||
|
}
|
||||||
|
for _, k := range []string{"preferred_username", "email", "name", "sub"} {
|
||||||
|
if v, _ := claims[k].(string); v != "" {
|
||||||
|
return v, nil
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return "", errors.New("id_token: no sub")
|
||||||
|
}
|
||||||
|
|
||||||
|
// verifyIDToken checks the signature (keys from jwks_uri) and the claims of an ID token.
|
||||||
|
func (o *OIDC) verifyIDToken(raw, nonce string) (map[string]any, error) {
|
||||||
|
parts := strings.Split(raw, ".")
|
||||||
|
if len(parts) != 3 {
|
||||||
|
return nil, errors.New("id_token: not a JWT")
|
||||||
|
}
|
||||||
|
var hdr struct {
|
||||||
|
Alg string `json:"alg"`
|
||||||
|
Kid string `json:"kid"`
|
||||||
|
}
|
||||||
|
if err := decodeSegment(parts[0], &hdr); err != nil {
|
||||||
|
return nil, fmt.Errorf("id_token header: %w", err)
|
||||||
|
}
|
||||||
|
sig, err := base64.RawURLEncoding.DecodeString(parts[2])
|
||||||
|
if err != nil {
|
||||||
|
return nil, errors.New("id_token: bad signature encoding")
|
||||||
|
}
|
||||||
|
key, err := o.keyFor(hdr.Kid)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
if err := verifySignature(hdr.Alg, key, []byte(parts[0]+"."+parts[1]), sig); err != nil {
|
||||||
|
return nil, fmt.Errorf("id_token: %w", err)
|
||||||
|
}
|
||||||
|
var claims map[string]any
|
||||||
|
if err := decodeSegment(parts[1], &claims); err != nil {
|
||||||
|
return nil, fmt.Errorf("id_token claims: %w", err)
|
||||||
|
}
|
||||||
|
if iss, _ := claims["iss"].(string); iss != o.cfg.issuer {
|
||||||
|
return nil, fmt.Errorf("id_token: issuer %q, expected %q", iss, o.cfg.issuer)
|
||||||
|
}
|
||||||
|
var aud []string
|
||||||
|
switch v := claims["aud"].(type) {
|
||||||
|
case string:
|
||||||
|
aud = []string{v}
|
||||||
|
case []any:
|
||||||
|
for _, a := range v {
|
||||||
|
if s, ok := a.(string); ok {
|
||||||
|
aud = append(aud, s)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if !contains(aud, o.cfg.clientID) {
|
||||||
|
return nil, fmt.Errorf("id_token: audience %v does not include %q", aud, o.cfg.clientID)
|
||||||
|
}
|
||||||
|
if azp, ok := claims["azp"].(string); ok && len(aud) > 1 && azp != o.cfg.clientID {
|
||||||
|
return nil, fmt.Errorf("id_token: azp %q", azp)
|
||||||
|
}
|
||||||
|
now := time.Now()
|
||||||
|
exp, _ := claims["exp"].(float64)
|
||||||
|
if exp == 0 || now.After(time.Unix(int64(exp), 0).Add(clockSkew)) {
|
||||||
|
return nil, errors.New("id_token: expired (check the clocks)")
|
||||||
|
}
|
||||||
|
if iat, ok := claims["iat"].(float64); ok && time.Unix(int64(iat), 0).After(now.Add(clockSkew)) {
|
||||||
|
return nil, errors.New("id_token: issued in the future (check the clocks)")
|
||||||
|
}
|
||||||
|
if n, _ := claims["nonce"].(string); subtle.ConstantTimeCompare([]byte(n), []byte(nonce)) != 1 {
|
||||||
|
return nil, errors.New("id_token: wrong nonce")
|
||||||
|
}
|
||||||
|
return claims, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func verifySignature(alg string, key crypto.PublicKey, signed, sig []byte) error {
|
||||||
|
if len(alg) != 5 {
|
||||||
|
return fmt.Errorf("unsupported algorithm %q", alg)
|
||||||
|
}
|
||||||
|
var h crypto.Hash
|
||||||
|
switch alg[2:] {
|
||||||
|
case "256":
|
||||||
|
h = crypto.SHA256
|
||||||
|
case "384":
|
||||||
|
h = crypto.SHA384
|
||||||
|
case "512":
|
||||||
|
h = crypto.SHA512
|
||||||
|
}
|
||||||
|
if h == 0 {
|
||||||
|
return fmt.Errorf("unsupported algorithm %q", alg)
|
||||||
|
}
|
||||||
|
hh := h.New()
|
||||||
|
hh.Write(signed)
|
||||||
|
digest := hh.Sum(nil)
|
||||||
|
switch k := key.(type) {
|
||||||
|
case *rsa.PublicKey:
|
||||||
|
switch alg[:2] {
|
||||||
|
case "RS":
|
||||||
|
return rsa.VerifyPKCS1v15(k, h, digest, sig)
|
||||||
|
case "PS":
|
||||||
|
return rsa.VerifyPSS(k, h, digest, sig, &rsa.PSSOptions{SaltLength: rsa.PSSSaltLengthEqualsHash})
|
||||||
|
}
|
||||||
|
case *ecdsa.PublicKey:
|
||||||
|
size := (k.Curve.Params().BitSize + 7) / 8
|
||||||
|
if alg[:2] != "ES" || len(sig) != 2*size {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
r, s := new(big.Int).SetBytes(sig[:size]), new(big.Int).SetBytes(sig[size:])
|
||||||
|
if ecdsa.Verify(k, digest, r, s) {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return errors.New("bad signature")
|
||||||
|
}
|
||||||
|
return fmt.Errorf("algorithm %q does not match the key", alg)
|
||||||
|
}
|
||||||
|
|
||||||
|
// discover reads the provider configuration once (and again after a failure).
|
||||||
|
func (o *OIDC) discover() (*oidcMeta, error) {
|
||||||
|
o.mu.Lock()
|
||||||
|
defer o.mu.Unlock()
|
||||||
|
if o.meta != nil {
|
||||||
|
return o.meta, nil
|
||||||
|
}
|
||||||
|
u := strings.TrimSuffix(o.cfg.issuer, "/") + "/.well-known/openid-configuration"
|
||||||
|
var m oidcMeta
|
||||||
|
if err := o.getJSON(u, &m); err != nil {
|
||||||
|
return nil, fmt.Errorf("discovery: %w", err)
|
||||||
|
}
|
||||||
|
if m.Issuer != o.cfg.issuer {
|
||||||
|
return nil, fmt.Errorf("discovery: the provider says its issuer is %q, set OIDC_ISSUER to that exact value", m.Issuer)
|
||||||
|
}
|
||||||
|
if m.AuthEndpoint == "" || m.TokenEndpoint == "" || m.JWKSURI == "" {
|
||||||
|
return nil, errors.New("discovery: incomplete provider configuration")
|
||||||
|
}
|
||||||
|
o.meta = &m
|
||||||
|
return o.meta, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// keyFor returns the signing key kid; the key set is reloaded when the provider rotates its keys.
|
||||||
|
func (o *OIDC) keyFor(kid string) (crypto.PublicKey, error) {
|
||||||
|
meta, err := o.discover()
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
o.mu.Lock()
|
||||||
|
defer o.mu.Unlock()
|
||||||
|
pick := func() crypto.PublicKey {
|
||||||
|
if k, ok := o.keys[kid]; ok {
|
||||||
|
return k
|
||||||
|
}
|
||||||
|
if kid == "" && len(o.keys) == 1 {
|
||||||
|
for _, k := range o.keys {
|
||||||
|
return k
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
if k := pick(); k != nil {
|
||||||
|
return k, nil
|
||||||
|
}
|
||||||
|
if time.Since(o.keysAt) < 10*time.Second {
|
||||||
|
return nil, fmt.Errorf("id_token: unknown key %q", kid)
|
||||||
|
}
|
||||||
|
var set struct {
|
||||||
|
Keys []struct {
|
||||||
|
Kty string `json:"kty"`
|
||||||
|
Kid string `json:"kid"`
|
||||||
|
Use string `json:"use"`
|
||||||
|
N string `json:"n"`
|
||||||
|
E string `json:"e"`
|
||||||
|
Crv string `json:"crv"`
|
||||||
|
X string `json:"x"`
|
||||||
|
Y string `json:"y"`
|
||||||
|
} `json:"keys"`
|
||||||
|
}
|
||||||
|
if err := o.getJSON(meta.JWKSURI, &set); err != nil {
|
||||||
|
return nil, fmt.Errorf("jwks: %w", err)
|
||||||
|
}
|
||||||
|
keys := map[string]crypto.PublicKey{}
|
||||||
|
for _, k := range set.Keys {
|
||||||
|
if k.Use != "" && k.Use != "sig" {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
switch k.Kty {
|
||||||
|
case "RSA":
|
||||||
|
n, e := decodeBig(k.N), decodeBig(k.E)
|
||||||
|
if n != nil && e != nil && e.IsInt64() {
|
||||||
|
keys[k.Kid] = &rsa.PublicKey{N: n, E: int(e.Int64())}
|
||||||
|
}
|
||||||
|
case "EC":
|
||||||
|
var c elliptic.Curve
|
||||||
|
switch k.Crv {
|
||||||
|
case "P-256":
|
||||||
|
c = elliptic.P256()
|
||||||
|
case "P-384":
|
||||||
|
c = elliptic.P384()
|
||||||
|
case "P-521":
|
||||||
|
c = elliptic.P521()
|
||||||
|
}
|
||||||
|
x, y := decodeBig(k.X), decodeBig(k.Y)
|
||||||
|
if c != nil && x != nil && y != nil && c.IsOnCurve(x, y) {
|
||||||
|
keys[k.Kid] = &ecdsa.PublicKey{Curve: c, X: x, Y: y}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
o.keys, o.keysAt = keys, time.Now()
|
||||||
|
if k := pick(); k != nil {
|
||||||
|
return k, nil
|
||||||
|
}
|
||||||
|
return nil, fmt.Errorf("id_token: unknown key %q", kid)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (o *OIDC) getJSON(u string, v any) error {
|
||||||
|
res, err := o.client.Get(u)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
defer res.Body.Close()
|
||||||
|
if res.StatusCode != http.StatusOK {
|
||||||
|
return fmt.Errorf("%s: %s", u, res.Status)
|
||||||
|
}
|
||||||
|
return json.NewDecoder(io.LimitReader(res.Body, 1<<20)).Decode(v)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Cookies are base64url(JSON) + "." + base64url(HMAC-SHA256).
|
||||||
|
func signCookie(key []byte, v any) string {
|
||||||
|
b, _ := json.Marshal(v)
|
||||||
|
p := base64.RawURLEncoding.EncodeToString(b)
|
||||||
|
m := hmac.New(sha256.New, key)
|
||||||
|
m.Write([]byte(p))
|
||||||
|
return p + "." + base64.RawURLEncoding.EncodeToString(m.Sum(nil))
|
||||||
|
}
|
||||||
|
|
||||||
|
func verifyCookie(key []byte, s string, v any) bool {
|
||||||
|
p, sig, ok := strings.Cut(s, ".")
|
||||||
|
if !ok {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
got, err := base64.RawURLEncoding.DecodeString(sig)
|
||||||
|
if err != nil {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
m := hmac.New(sha256.New, key)
|
||||||
|
m.Write([]byte(p))
|
||||||
|
if !hmac.Equal(got, m.Sum(nil)) {
|
||||||
|
return false
|
||||||
|
}
|
||||||
|
return decodeSegment(p, v) == nil
|
||||||
|
}
|
||||||
|
|
||||||
|
func decodeSegment(s string, v any) error {
|
||||||
|
b, err := base64.RawURLEncoding.DecodeString(s)
|
||||||
|
if err != nil {
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
return json.Unmarshal(b, v)
|
||||||
|
}
|
||||||
|
|
||||||
|
func decodeBig(s string) *big.Int {
|
||||||
|
b, err := base64.RawURLEncoding.DecodeString(s)
|
||||||
|
if err != nil || len(b) == 0 {
|
||||||
|
return nil
|
||||||
|
}
|
||||||
|
return new(big.Int).SetBytes(b)
|
||||||
|
}
|
||||||
|
|
||||||
|
func randomString() string {
|
||||||
|
b := make([]byte, 16)
|
||||||
|
if _, err := rand.Read(b); err != nil {
|
||||||
|
panic(err)
|
||||||
|
}
|
||||||
|
return base64.RawURLEncoding.EncodeToString(b)
|
||||||
|
}
|
||||||
|
|
||||||
|
func addQuery(endpoint string, q url.Values) string {
|
||||||
|
sep := "?"
|
||||||
|
if strings.Contains(endpoint, "?") {
|
||||||
|
sep = "&"
|
||||||
|
}
|
||||||
|
return endpoint + sep + q.Encode()
|
||||||
|
}
|
||||||
|
|
||||||
|
func contains(list []string, s string) bool {
|
||||||
|
for _, v := range list {
|
||||||
|
if v == s {
|
||||||
|
return true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return false
|
||||||
|
}
|
||||||
+167
@@ -0,0 +1,167 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto/hmac"
|
||||||
|
"crypto/sha256"
|
||||||
|
"crypto/subtle"
|
||||||
|
"log"
|
||||||
|
"net"
|
||||||
|
"net/http"
|
||||||
|
"net/url"
|
||||||
|
"os"
|
||||||
|
"strings"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Local mode with AUTH_USER set: a login page (web/login.html) in the colors of the UI and a
|
||||||
|
// session kept in a signed cookie, like the OIDC mode. HTTP Basic credentials are still
|
||||||
|
// accepted so scripts calling the API keep working, but the browser popup is gone.
|
||||||
|
|
||||||
|
const loginPage = "/login.html"
|
||||||
|
|
||||||
|
var loginFailDelay = time.Second // slows down password guessing
|
||||||
|
|
||||||
|
type Local struct {
|
||||||
|
user, pass string
|
||||||
|
ttl time.Duration
|
||||||
|
logo string // LOGIN_LOGO, served at /auth/logo
|
||||||
|
key []byte
|
||||||
|
next http.Handler
|
||||||
|
}
|
||||||
|
|
||||||
|
func newLocal(c authConfig) *Local {
|
||||||
|
// The key depends on the credentials: changing AUTH_USER or AUTH_PASS ends every session.
|
||||||
|
m := hmac.New(sha256.New, sessionKey(c.dataDir))
|
||||||
|
m.Write([]byte("local\x00" + c.user + "\x00" + c.pass))
|
||||||
|
if c.loginLogo != "" {
|
||||||
|
if _, err := os.Stat(c.loginLogo); err != nil {
|
||||||
|
log.Printf("auth: LOGIN_LOGO: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
log.Printf("local authentication enabled (user %s)", c.user)
|
||||||
|
return &Local{user: c.user, pass: c.pass, ttl: c.sessionTTL, logo: c.loginLogo, key: m.Sum(nil)}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (l *Local) ServeHTTP(w http.ResponseWriter, r *http.Request) {
|
||||||
|
switch r.URL.Path {
|
||||||
|
case "/healthz", "/style.css":
|
||||||
|
l.next.ServeHTTP(w, r)
|
||||||
|
return
|
||||||
|
case "/auth/logo":
|
||||||
|
l.serveLogo(w, r)
|
||||||
|
return
|
||||||
|
case "/auth/login":
|
||||||
|
l.handleLogin(w, r)
|
||||||
|
return
|
||||||
|
case "/auth/logout":
|
||||||
|
http.SetCookie(w, &http.Cookie{Name: sessionCookie, Path: "/", MaxAge: -1, HttpOnly: true, Secure: isHTTPS(r)})
|
||||||
|
http.Redirect(w, r, loginPage, http.StatusFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
user, ok := l.sessionUser(r)
|
||||||
|
if !ok {
|
||||||
|
if u, p, basic := r.BasicAuth(); basic && l.check(u, p) {
|
||||||
|
user, ok = u, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
switch {
|
||||||
|
case r.URL.Path == loginPage:
|
||||||
|
if ok {
|
||||||
|
http.Redirect(w, r, safeReturn(r.URL.Query().Get("r")), http.StatusFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Cache-Control", "no-store")
|
||||||
|
l.next.ServeHTTP(w, r)
|
||||||
|
case ok && r.URL.Path == "/auth/me":
|
||||||
|
writeJSON(w, http.StatusOK, map[string]string{"mode": "local", "user": user})
|
||||||
|
case ok:
|
||||||
|
l.next.ServeHTTP(w, r)
|
||||||
|
case r.Method == http.MethodGet && !strings.HasPrefix(r.URL.Path, "/api/") && r.URL.Path != "/auth/me":
|
||||||
|
target := loginPage
|
||||||
|
if ret := r.URL.RequestURI(); ret != "/" {
|
||||||
|
target += "?" + url.Values{"r": {ret}}.Encode()
|
||||||
|
}
|
||||||
|
http.Redirect(w, r, target, http.StatusFound)
|
||||||
|
default:
|
||||||
|
writeAuthRequired(w)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (l *Local) handleLogin(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if r.Method != http.MethodPost {
|
||||||
|
http.Redirect(w, r, loginPage, http.StatusFound)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
user, pass := r.PostFormValue("user"), r.PostFormValue("pass")
|
||||||
|
ret := safeReturn(r.PostFormValue("r"))
|
||||||
|
if !l.check(user, pass) {
|
||||||
|
log.Printf("auth: failed login for %q from %s", user, clientIP(r))
|
||||||
|
time.Sleep(loginFailDelay)
|
||||||
|
q := url.Values{"e": {"1"}}
|
||||||
|
if ret != "/" {
|
||||||
|
q.Set("r", ret)
|
||||||
|
}
|
||||||
|
http.Redirect(w, r, loginPage+"?"+q.Encode(), http.StatusSeeOther)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
log.Printf("auth: %s logged in from %s", user, clientIP(r))
|
||||||
|
http.SetCookie(w, &http.Cookie{
|
||||||
|
Name: sessionCookie,
|
||||||
|
Value: signCookie(l.key, session{User: user, Exp: time.Now().Add(l.ttl).Unix()}),
|
||||||
|
Path: "/",
|
||||||
|
MaxAge: int(l.ttl.Seconds()),
|
||||||
|
HttpOnly: true,
|
||||||
|
Secure: isHTTPS(r),
|
||||||
|
SameSite: http.SameSiteLaxMode,
|
||||||
|
})
|
||||||
|
http.Redirect(w, r, ret, http.StatusSeeOther)
|
||||||
|
}
|
||||||
|
|
||||||
|
func (l *Local) sessionUser(r *http.Request) (string, bool) {
|
||||||
|
var s session
|
||||||
|
c, err := r.Cookie(sessionCookie)
|
||||||
|
if err != nil || !verifyCookie(l.key, c.Value, &s) || time.Now().Unix() >= s.Exp {
|
||||||
|
return "", false
|
||||||
|
}
|
||||||
|
return s.User, true
|
||||||
|
}
|
||||||
|
|
||||||
|
func (l *Local) check(user, pass string) bool {
|
||||||
|
u := subtle.ConstantTimeCompare([]byte(user), []byte(l.user))
|
||||||
|
p := subtle.ConstantTimeCompare([]byte(pass), []byte(l.pass))
|
||||||
|
return u&p == 1
|
||||||
|
}
|
||||||
|
|
||||||
|
// serveLogo sends LOGIN_LOGO; without it the login page hides the image.
|
||||||
|
func (l *Local) serveLogo(w http.ResponseWriter, r *http.Request) {
|
||||||
|
if l.logo == "" {
|
||||||
|
http.NotFound(w, r)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
w.Header().Set("Cache-Control", "no-cache")
|
||||||
|
http.ServeFile(w, r, l.logo)
|
||||||
|
}
|
||||||
|
|
||||||
|
// safeReturn keeps the page to open after login inside logstream.
|
||||||
|
func safeReturn(ret string) string {
|
||||||
|
if !strings.HasPrefix(ret, "/") || strings.HasPrefix(ret, "//") || strings.HasPrefix(ret, "/\\") || ret == loginPage {
|
||||||
|
return "/"
|
||||||
|
}
|
||||||
|
return ret
|
||||||
|
}
|
||||||
|
|
||||||
|
// isHTTPS is true when the browser talks HTTPS, directly or through a reverse proxy.
|
||||||
|
func isHTTPS(r *http.Request) bool {
|
||||||
|
return r.TLS != nil || strings.EqualFold(r.Header.Get("X-Forwarded-Proto"), "https")
|
||||||
|
}
|
||||||
|
|
||||||
|
func clientIP(r *http.Request) string {
|
||||||
|
if f := r.Header.Get("X-Forwarded-For"); f != "" {
|
||||||
|
return strings.TrimSpace(strings.Split(f, ",")[0])
|
||||||
|
}
|
||||||
|
host, _, err := net.SplitHostPort(r.RemoteAddr)
|
||||||
|
if err != nil {
|
||||||
|
return r.RemoteAddr
|
||||||
|
}
|
||||||
|
return host
|
||||||
|
}
|
||||||
@@ -0,0 +1,142 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"net/http"
|
||||||
|
"net/http/cookiejar"
|
||||||
|
"net/url"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
)
|
||||||
|
|
||||||
|
// newLocalApp puts the local login in front of a handler that echoes "app" and returns a
|
||||||
|
// browser (client with cookies) that does not follow redirects.
|
||||||
|
func newLocalApp(t *testing.T, c authConfig) (string, *http.Client) {
|
||||||
|
t.Helper()
|
||||||
|
loginFailDelay = 0
|
||||||
|
c.mode, c.dataDir = "local", t.TempDir()
|
||||||
|
h, err := newAuth(c, http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { _, _ = w.Write([]byte("app " + r.URL.Path)) }))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
jar, _ := cookiejar.New(nil)
|
||||||
|
return "http://app.test", &http.Client{
|
||||||
|
Jar: jar,
|
||||||
|
Transport: hosts{"app.test": h},
|
||||||
|
CheckRedirect: func(*http.Request, []*http.Request) error { return http.ErrUseLastResponse },
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func login(t *testing.T, c *http.Client, app, user, pass, ret string) *http.Response {
|
||||||
|
t.Helper()
|
||||||
|
res, err := c.PostForm(app+"/auth/login", url.Values{"user": {user}, "pass": {pass}, "r": {ret}})
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
res.Body.Close()
|
||||||
|
return res
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLocalLoginFlow(t *testing.T) {
|
||||||
|
app, c := newLocalApp(t, authConfig{user: "admin", pass: "pw"})
|
||||||
|
|
||||||
|
res, _ := c.Get(app + "/api/logs?q=x")
|
||||||
|
if res.StatusCode != http.StatusUnauthorized || res.Header.Get("WWW-Authenticate") != "" {
|
||||||
|
t.Fatalf("API without session: %d %q", res.StatusCode, res.Header.Get("WWW-Authenticate"))
|
||||||
|
}
|
||||||
|
res, _ = c.Get(app + "/?q=disk")
|
||||||
|
if loc := res.Header.Get("Location"); res.StatusCode != http.StatusFound || loc != "/login.html?r=%2F%3Fq%3Ddisk" {
|
||||||
|
t.Fatalf("page without session: %d %q", res.StatusCode, loc)
|
||||||
|
}
|
||||||
|
for _, p := range []string{"/login.html", "/style.css", "/healthz"} {
|
||||||
|
if code, body := get(t, c, app+p); code != http.StatusOK || body != "app "+p {
|
||||||
|
t.Errorf("%s without session: %d %q", p, code, body)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
res = login(t, c, app, "admin", "wrong", "/?q=disk")
|
||||||
|
if loc := res.Header.Get("Location"); res.StatusCode != http.StatusSeeOther || !strings.Contains(loc, "e=1") {
|
||||||
|
t.Fatalf("wrong password: %d %q", res.StatusCode, loc)
|
||||||
|
}
|
||||||
|
if code, _ := get(t, c, app+"/api/logs"); code != http.StatusUnauthorized {
|
||||||
|
t.Fatal("session created by a wrong password")
|
||||||
|
}
|
||||||
|
|
||||||
|
res = login(t, c, app, "admin", "pw", "//evil.example/")
|
||||||
|
if loc := res.Header.Get("Location"); loc != "/" {
|
||||||
|
t.Fatalf("open redirect: %q", loc)
|
||||||
|
}
|
||||||
|
res = login(t, c, app, "admin", "pw", "/?q=disk")
|
||||||
|
if loc := res.Header.Get("Location"); res.StatusCode != http.StatusSeeOther || loc != "/?q=disk" {
|
||||||
|
t.Fatalf("login: %d %q", res.StatusCode, loc)
|
||||||
|
}
|
||||||
|
if code, body := get(t, c, app+"/api/logs"); code != http.StatusOK || body != "app /api/logs" {
|
||||||
|
t.Fatalf("API with session: %d %q", code, body)
|
||||||
|
}
|
||||||
|
if code, body := get(t, c, app+"/auth/me"); code != http.StatusOK || !strings.Contains(body, `"user":"admin"`) || !strings.Contains(body, `"mode":"local"`) {
|
||||||
|
t.Fatalf("/auth/me: %d %s", code, body)
|
||||||
|
}
|
||||||
|
if res, _ := c.Get(app + "/login.html"); res.StatusCode != http.StatusFound {
|
||||||
|
t.Errorf("login page while logged in: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
|
||||||
|
if res, _ := c.Get(app + "/auth/logout"); res.Header.Get("Location") != "/login.html" {
|
||||||
|
t.Fatalf("logout: %q", res.Header.Get("Location"))
|
||||||
|
}
|
||||||
|
if code, _ := get(t, c, app+"/api/logs"); code != http.StatusUnauthorized {
|
||||||
|
t.Fatal("session still valid after logout")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLocalBasicAuthForScripts(t *testing.T) {
|
||||||
|
app, c := newLocalApp(t, authConfig{user: "admin", pass: "pw"})
|
||||||
|
req, _ := http.NewRequest(http.MethodGet, app+"/api/logs", nil)
|
||||||
|
req.SetBasicAuth("admin", "pw")
|
||||||
|
if res, _ := c.Do(req); res.StatusCode != http.StatusOK {
|
||||||
|
t.Fatalf("basic auth: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
req.SetBasicAuth("admin", "nope")
|
||||||
|
if res, _ := c.Do(req); res.StatusCode != http.StatusUnauthorized {
|
||||||
|
t.Fatalf("wrong basic auth: %d", res.StatusCode)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLocalPasswordChangeEndsSessions(t *testing.T) {
|
||||||
|
dir := t.TempDir()
|
||||||
|
loginFailDelay = 0
|
||||||
|
echo := http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {})
|
||||||
|
h1, _ := newAuth(authConfig{mode: "local", user: "admin", pass: "old", dataDir: dir}, echo)
|
||||||
|
h2, _ := newAuth(authConfig{mode: "local", user: "admin", pass: "new", dataDir: dir}, echo)
|
||||||
|
cookie := signCookie(h1.(*Local).key, session{User: "admin", Exp: 9999999999})
|
||||||
|
r, _ := http.NewRequest(http.MethodGet, "/", nil)
|
||||||
|
r.AddCookie(&http.Cookie{Name: sessionCookie, Value: cookie})
|
||||||
|
if _, ok := h1.(*Local).sessionUser(r); !ok {
|
||||||
|
t.Fatal("session refused with the same password")
|
||||||
|
}
|
||||||
|
if _, ok := h2.(*Local).sessionUser(r); ok {
|
||||||
|
t.Fatal("session kept after a password change")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLocalLogo(t *testing.T) {
|
||||||
|
app, c := newLocalApp(t, authConfig{user: "admin", pass: "pw"})
|
||||||
|
if code, _ := get(t, c, app+"/auth/logo"); code != http.StatusNotFound {
|
||||||
|
t.Errorf("no LOGIN_LOGO: %d", code)
|
||||||
|
}
|
||||||
|
png := filepath.Join(t.TempDir(), "logo.png")
|
||||||
|
_ = os.WriteFile(png, []byte("\x89PNG\r\n\x1a\nfake"), 0o644)
|
||||||
|
app, c = newLocalApp(t, authConfig{user: "admin", pass: "pw", loginLogo: png})
|
||||||
|
res, _ := c.Get(app + "/auth/logo")
|
||||||
|
if res.StatusCode != http.StatusOK || res.Header.Get("Content-Type") != "image/png" {
|
||||||
|
t.Errorf("LOGIN_LOGO: %d %q", res.StatusCode, res.Header.Get("Content-Type"))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestLocalWithoutUserIsOpen(t *testing.T) {
|
||||||
|
if h, _ := newAuth(authConfig{mode: "local"}, http.NotFoundHandler()); h == nil || isLocal(h) {
|
||||||
|
t.Error("local mode without AUTH_USER should not protect anything")
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func isLocal(h http.Handler) bool { _, ok := h.(*Local); return ok }
|
||||||
+230
@@ -0,0 +1,230 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"crypto"
|
||||||
|
"crypto/ecdsa"
|
||||||
|
"crypto/elliptic"
|
||||||
|
"crypto/rand"
|
||||||
|
"crypto/rsa"
|
||||||
|
"crypto/sha256"
|
||||||
|
"encoding/base64"
|
||||||
|
"encoding/json"
|
||||||
|
"math/big"
|
||||||
|
"net/http"
|
||||||
|
"net/http/cookiejar"
|
||||||
|
"net/http/httptest"
|
||||||
|
"net/url"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// hosts routes requests to in-memory handlers (no listening socket needed).
|
||||||
|
type hosts map[string]http.Handler
|
||||||
|
|
||||||
|
func (h hosts) RoundTrip(r *http.Request) (*http.Response, error) {
|
||||||
|
rec := httptest.NewRecorder()
|
||||||
|
h[r.URL.Host].ServeHTTP(rec, r)
|
||||||
|
res := rec.Result()
|
||||||
|
res.Request = r
|
||||||
|
return res, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// fakeIdP is a minimal OpenID provider: it logs in "alice" without asking.
|
||||||
|
type fakeIdP struct {
|
||||||
|
mux *http.ServeMux
|
||||||
|
rsaKey *rsa.PrivateKey
|
||||||
|
ecKey *ecdsa.PrivateKey
|
||||||
|
useEC bool
|
||||||
|
codes map[string]url.Values // code -> authorize request
|
||||||
|
claims func(map[string]any) // last-minute changes to the ID token
|
||||||
|
tokenErr bool
|
||||||
|
}
|
||||||
|
|
||||||
|
func newFakeIdP(t *testing.T) *fakeIdP {
|
||||||
|
rk, _ := rsa.GenerateKey(rand.Reader, 2048)
|
||||||
|
ek, _ := ecdsa.GenerateKey(elliptic.P256(), rand.Reader)
|
||||||
|
p := &fakeIdP{rsaKey: rk, ecKey: ek, codes: map[string]url.Values{}}
|
||||||
|
mux := http.NewServeMux()
|
||||||
|
p.mux = mux
|
||||||
|
iss := "http://idp.test/realm"
|
||||||
|
mux.HandleFunc("/realm/.well-known/openid-configuration", func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
_ = json.NewEncoder(w).Encode(map[string]any{
|
||||||
|
"issuer": iss, "authorization_endpoint": iss + "/auth", "token_endpoint": iss + "/token",
|
||||||
|
"jwks_uri": iss + "/jwks", "end_session_endpoint": iss + "/logout",
|
||||||
|
})
|
||||||
|
})
|
||||||
|
mux.HandleFunc("/realm/jwks", func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
b := func(i *big.Int) string { return base64.RawURLEncoding.EncodeToString(i.Bytes()) }
|
||||||
|
_ = json.NewEncoder(w).Encode(map[string]any{"keys": []any{
|
||||||
|
map[string]string{"kty": "RSA", "kid": "r1", "use": "sig", "n": b(rk.N), "e": "AQAB"},
|
||||||
|
map[string]string{"kty": "EC", "kid": "e1", "crv": "P-256", "x": b(ek.X), "y": b(ek.Y)},
|
||||||
|
}})
|
||||||
|
})
|
||||||
|
mux.HandleFunc("/realm/auth", func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
q := r.URL.Query()
|
||||||
|
code := randomString()
|
||||||
|
p.codes[code] = q
|
||||||
|
http.Redirect(w, r, q.Get("redirect_uri")+"?code="+code+"&state="+q.Get("state"), http.StatusFound)
|
||||||
|
})
|
||||||
|
mux.HandleFunc("/realm/token", func(w http.ResponseWriter, r *http.Request) {
|
||||||
|
_ = r.ParseForm()
|
||||||
|
id, secret, _ := r.BasicAuth()
|
||||||
|
authz, ok := p.codes[r.Form.Get("code")]
|
||||||
|
sum := sha256.Sum256([]byte(r.Form.Get("code_verifier")))
|
||||||
|
if p.tokenErr || !ok || id != "logstream" || secret != "s3cret" ||
|
||||||
|
base64.RawURLEncoding.EncodeToString(sum[:]) != authz.Get("code_challenge") ||
|
||||||
|
r.Form.Get("redirect_uri") != authz.Get("redirect_uri") {
|
||||||
|
http.Error(w, `{"error":"invalid_grant"}`, http.StatusBadRequest)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
delete(p.codes, r.Form.Get("code"))
|
||||||
|
c := map[string]any{
|
||||||
|
"iss": iss, "aud": "logstream", "sub": "123", "preferred_username": "alice",
|
||||||
|
"exp": time.Now().Add(5 * time.Minute).Unix(), "iat": time.Now().Unix(), "nonce": authz.Get("nonce"),
|
||||||
|
}
|
||||||
|
if p.claims != nil {
|
||||||
|
p.claims(c)
|
||||||
|
}
|
||||||
|
_ = json.NewEncoder(w).Encode(map[string]string{"access_token": "x", "id_token": p.sign(c)})
|
||||||
|
})
|
||||||
|
return p
|
||||||
|
}
|
||||||
|
|
||||||
|
func (p *fakeIdP) sign(claims map[string]any) string {
|
||||||
|
alg, kid := "RS256", "r1"
|
||||||
|
if p.useEC {
|
||||||
|
alg, kid = "ES256", "e1"
|
||||||
|
}
|
||||||
|
h, _ := json.Marshal(map[string]string{"alg": alg, "kid": kid, "typ": "JWT"})
|
||||||
|
c, _ := json.Marshal(claims)
|
||||||
|
in := base64.RawURLEncoding.EncodeToString(h) + "." + base64.RawURLEncoding.EncodeToString(c)
|
||||||
|
d := sha256.Sum256([]byte(in))
|
||||||
|
var sig []byte
|
||||||
|
if p.useEC {
|
||||||
|
r, s, _ := ecdsa.Sign(rand.Reader, p.ecKey, d[:])
|
||||||
|
sig = make([]byte, 64)
|
||||||
|
r.FillBytes(sig[:32])
|
||||||
|
s.FillBytes(sig[32:])
|
||||||
|
} else {
|
||||||
|
sig, _ = rsa.SignPKCS1v15(rand.Reader, p.rsaKey, crypto.SHA256, d[:])
|
||||||
|
}
|
||||||
|
return in + "." + base64.RawURLEncoding.EncodeToString(sig)
|
||||||
|
}
|
||||||
|
|
||||||
|
// newOIDCApp puts logstream's auth in front of a handler that echoes "app" and returns
|
||||||
|
// a browser (client with cookies) that reaches both the app and the provider.
|
||||||
|
func newOIDCApp(t *testing.T, idp *fakeIdP) (string, *http.Client) {
|
||||||
|
h, err := newAuth(authConfig{
|
||||||
|
mode: "oidc", issuer: "http://idp.test/realm", clientID: "logstream", clientSecret: "s3cret",
|
||||||
|
redirectURL: "http://app.test/auth/callback", dataDir: t.TempDir(),
|
||||||
|
}, http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) { _, _ = w.Write([]byte("app " + r.URL.Path)) }))
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
net := hosts{"app.test": h, "idp.test": idp.mux}
|
||||||
|
h.(*OIDC).client.Transport = net
|
||||||
|
jar, _ := cookiejar.New(nil)
|
||||||
|
return "http://app.test", &http.Client{Jar: jar, Transport: net}
|
||||||
|
}
|
||||||
|
|
||||||
|
func get(t *testing.T, c *http.Client, u string) (int, string) {
|
||||||
|
t.Helper()
|
||||||
|
res, err := c.Get(u)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
defer res.Body.Close()
|
||||||
|
var b strings.Builder
|
||||||
|
buf := make([]byte, 4096)
|
||||||
|
for {
|
||||||
|
n, err := res.Body.Read(buf)
|
||||||
|
b.Write(buf[:n])
|
||||||
|
if err != nil {
|
||||||
|
break
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return res.StatusCode, b.String()
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestOIDCLoginFlow(t *testing.T) {
|
||||||
|
for _, ec := range []bool{false, true} {
|
||||||
|
idp := newFakeIdP(t)
|
||||||
|
idp.useEC = ec
|
||||||
|
app, c := newOIDCApp(t, idp)
|
||||||
|
|
||||||
|
if code, _ := get(t, c, app+"/api/logs"); code != http.StatusUnauthorized {
|
||||||
|
t.Fatalf("api without session: %d", code)
|
||||||
|
}
|
||||||
|
if code, body := get(t, c, app+"/healthz"); code != 200 || body != "app /healthz" {
|
||||||
|
t.Fatalf("healthz: %d %q", code, body)
|
||||||
|
}
|
||||||
|
// A page goes through the provider and comes back to the page asked for.
|
||||||
|
if code, body := get(t, c, app+"/index.html?x=1"); code != 200 || body != "app /index.html" {
|
||||||
|
t.Fatalf("login (ec=%v): %d %q", ec, code, body)
|
||||||
|
}
|
||||||
|
if code, body := get(t, c, app+"/api/logs"); code != 200 || body != "app /api/logs" {
|
||||||
|
t.Fatalf("api with session: %d %q", code, body)
|
||||||
|
}
|
||||||
|
if code, body := get(t, c, app+"/auth/me"); code != 200 || !strings.Contains(body, `"user":"alice"`) {
|
||||||
|
t.Fatalf("me: %d %q", code, body)
|
||||||
|
}
|
||||||
|
// Logout drops the session (the fake provider has no logout page: 404).
|
||||||
|
get(t, c, app+"/auth/logout")
|
||||||
|
if code, _ := get(t, c, app+"/api/logs"); code != http.StatusUnauthorized {
|
||||||
|
t.Fatalf("api after logout: %d", code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestOIDCRejectsBadTokens(t *testing.T) {
|
||||||
|
cases := map[string]func(map[string]any){
|
||||||
|
"wrong nonce": func(c map[string]any) { c["nonce"] = "x" },
|
||||||
|
"wrong audience": func(c map[string]any) { c["aud"] = "other" },
|
||||||
|
"wrong issuer": func(c map[string]any) { c["iss"] = "https://evil" },
|
||||||
|
"expired": func(c map[string]any) { c["exp"] = time.Now().Add(-time.Hour).Unix() },
|
||||||
|
}
|
||||||
|
for name, change := range cases {
|
||||||
|
idp := newFakeIdP(t)
|
||||||
|
idp.claims = change
|
||||||
|
app, c := newOIDCApp(t, idp)
|
||||||
|
if code, _ := get(t, c, app+"/"); code != http.StatusForbidden {
|
||||||
|
t.Errorf("%s: login gave %d, expected 403", name, code)
|
||||||
|
}
|
||||||
|
if code, _ := get(t, c, app+"/api/logs"); code != http.StatusUnauthorized {
|
||||||
|
t.Errorf("%s: session created", name)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestOIDCCallbackNeedsLoginCookie(t *testing.T) {
|
||||||
|
idp := newFakeIdP(t)
|
||||||
|
app, c := newOIDCApp(t, idp)
|
||||||
|
if code, _ := get(t, c, app+"/auth/callback?code=abc&state=forged"); code != http.StatusBadRequest {
|
||||||
|
t.Fatalf("forged callback: %d", code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestOIDCForgedSessionCookie(t *testing.T) {
|
||||||
|
idp := newFakeIdP(t)
|
||||||
|
app, c := newOIDCApp(t, idp)
|
||||||
|
u, _ := url.Parse(app)
|
||||||
|
payload := base64.RawURLEncoding.EncodeToString([]byte(`{"u":"mallory","e":9999999999}`))
|
||||||
|
c.Jar.SetCookies(u, []*http.Cookie{{Name: sessionCookie, Value: payload + ".AAAA"}})
|
||||||
|
if code, _ := get(t, c, app+"/api/logs"); code != http.StatusUnauthorized {
|
||||||
|
t.Fatalf("forged session accepted: %d", code)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestAuthModeConfig(t *testing.T) {
|
||||||
|
next := http.NotFoundHandler()
|
||||||
|
if _, err := newAuth(authConfig{mode: "oidc"}, next); err == nil || !strings.Contains(err.Error(), "OIDC_CLIENT_ID") {
|
||||||
|
t.Errorf("missing variables not reported: %v", err)
|
||||||
|
}
|
||||||
|
if _, err := newAuth(authConfig{mode: "ldap"}, next); err == nil {
|
||||||
|
t.Error("unknown mode accepted")
|
||||||
|
}
|
||||||
|
if h, err := newAuth(authConfig{mode: "local"}, next); err != nil || h == nil {
|
||||||
|
t.Errorf("local mode: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
+28
-15
@@ -12,24 +12,39 @@ services:
|
|||||||
- "${HTTP_PORT:-8080}:8080"
|
- "${HTTP_PORT:-8080}:8080"
|
||||||
environment:
|
environment:
|
||||||
VLOGS_URL: http://victorialogs:9428
|
VLOGS_URL: http://victorialogs:9428
|
||||||
SYSLOG_PUBLIC_PORT: ${SYSLOG_PORT:-514} # shown in Settings > Sources (the mapping is set above)
|
SYSLOG_PUBLIC_PORT: ${SYSLOG_PORT:-514} # le port d'ecoute syslog par defaut (attention aux ports <1024)
|
||||||
TZ: ${TZ:-Europe/Paris}
|
TZ: ${TZ:-Europe/Paris}
|
||||||
AUTH_USER: ${AUTH_USER:-} # leave empty to disable authentication
|
AUTH_MODE: ${AUTH_MODE:-local} # local (page de connexion, compte ci-dessous) ou oidc
|
||||||
|
AUTH_USER: ${AUTH_USER:-} # vide = pas d'authentification, on delegue ca au reverse proxy traefik
|
||||||
AUTH_PASS: ${AUTH_PASS:-}
|
AUTH_PASS: ${AUTH_PASS:-}
|
||||||
RDNS: ${RDNS:-on} # replace IP hosts with their DNS name (PTR)
|
LOGIN_LOGO: ${LOGIN_LOGO:-} # PNG affiche sur la page de connexion (chemin dans le conteneur, voir volumes)
|
||||||
DNS_SERVER: ${DNS_SERVER:-} # e.g. 192.168.1.1 to query your LAN DNS; empty = system resolver
|
OIDC_ISSUER: ${OIDC_ISSUER:-}
|
||||||
|
OIDC_CLIENT_ID: ${OIDC_CLIENT_ID:-}
|
||||||
|
OIDC_CLIENT_SECRET: ${OIDC_CLIENT_SECRET:-}
|
||||||
|
OIDC_REDIRECT_URL: ${OIDC_REDIRECT_URL:-}
|
||||||
|
OIDC_SCOPES: ${OIDC_SCOPES:-openid profile email}
|
||||||
|
SESSION_TTL: ${SESSION_TTL:-${OIDC_SESSION_TTL:-12h}} # duree de la session (local et oidc)
|
||||||
|
RDNS: ${RDNS:-on} # resol dns
|
||||||
|
DNS_SERVER: ${DNS_SERVER:-} # si resolv directe
|
||||||
ALLOW_PURGE: ${ALLOW_PURGE:-true}
|
ALLOW_PURGE: ${ALLOW_PURGE:-true}
|
||||||
EXPORT_MAX: ${EXPORT_MAX:-100000}
|
EXPORT_MAX: ${EXPORT_MAX:-100000}
|
||||||
DOCKER_LOGS: ${DOCKER_LOGS:-on} # collect the logs of this machine's containers
|
DOCKER_LOGS: ${DOCKER_LOGS:-on} # collecte des logs des conteneurs Docker
|
||||||
DOCKER_HOST: tcp://docker-proxy:2375 # read-only Docker API gateway (below)
|
DOCKER_HOST: tcp://docker-proxy:2375 # lecture seul de l'API Docker
|
||||||
DOCKER_BACKFILL: ${DOCKER_BACKFILL:-1h} # history read from a container seen for the first time
|
DOCKER_BACKFILL: ${DOCKER_BACKFILL:-1h}
|
||||||
|
HOST_LOGS_BACKFILL: ${HOST_LOGS_BACKFILL:-1h} # historique lu a l'activation des logs systeme de l'hote
|
||||||
|
group_add:
|
||||||
|
- "${HOST_LOGS_GID:-4}" # groupe autorise a lire les logs de l'hote (4 = adm sur Debian/Ubuntu)
|
||||||
volumes:
|
volumes:
|
||||||
- logstream-data:/data # tags.json, docker.json (container choices)
|
- logstream-data:/data # tags.json, docker.json (les choix des conteneurs)
|
||||||
|
# logs systeme de l'hote, en lecture seule (source a activer dans Reglages > Sources)
|
||||||
|
- /var/log:/host/var/log:ro # journal systemd persistant et fichiers texte
|
||||||
|
- /run/log/journal:/host/run/log/journal:ro # journal systemd volatile
|
||||||
|
# logo de la page de connexion, avec LOGIN_LOGO=/config/logo.png dans .env
|
||||||
|
# - ./logo.png:/config/logo.png:ro
|
||||||
labels:
|
labels:
|
||||||
logstream.exclude: "true" # never collect Logstream's own logs
|
logstream.exclude: "true" # pas de collect des logs logstream
|
||||||
|
|
||||||
victorialogs:
|
victorialogs:
|
||||||
# Pinned version: see "Updating" in the README before changing it
|
|
||||||
image: victoriametrics/victoria-logs:v1.52.0
|
image: victoriametrics/victoria-logs:v1.52.0
|
||||||
container_name: logstream-victorialogs
|
container_name: logstream-victorialogs
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
@@ -37,7 +52,7 @@ services:
|
|||||||
- -storageDataPath=/vlogs
|
- -storageDataPath=/vlogs
|
||||||
- -retentionPeriod=${RETENTION:-30d}
|
- -retentionPeriod=${RETENTION:-30d}
|
||||||
- -httpListenAddr=:9428
|
- -httpListenAddr=:9428
|
||||||
- -delete.enable # required by "Delete all logs" in Settings
|
- -delete.enable # obliger pour autoriser la purge de la base via l'interface
|
||||||
volumes:
|
volumes:
|
||||||
- vlogs-data:/vlogs
|
- vlogs-data:/vlogs
|
||||||
ports:
|
ports:
|
||||||
@@ -45,9 +60,7 @@ services:
|
|||||||
- "127.0.0.1:9428:9428"
|
- "127.0.0.1:9428:9428"
|
||||||
|
|
||||||
docker-proxy:
|
docker-proxy:
|
||||||
# Read-only gateway to the Docker API: Logstream can only list containers,
|
# Docker proxy pour eviter de solliciter directement l'API docker
|
||||||
# read their logs, receive events and engine info. Anything else (start,
|
|
||||||
# stop, exec, images, volumes…) is refused.
|
|
||||||
image: tecnativa/docker-socket-proxy:v0.5.0
|
image: tecnativa/docker-socket-proxy:v0.5.0
|
||||||
container_name: logstream-docker-proxy
|
container_name: logstream-docker-proxy
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
@@ -59,7 +72,7 @@ services:
|
|||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
labels:
|
labels:
|
||||||
logstream.exclude: "true" # its access log would only echo Logstream's own requests
|
logstream.exclude: "true" # pour exclure les logs propres de logstream
|
||||||
|
|
||||||
volumes:
|
volumes:
|
||||||
logstream-data:
|
logstream-data:
|
||||||
|
|||||||
File diff suppressed because it is too large.
Load diff
Binary file not shown.
|
After Width: | Height: | Size: 884 KiB |
+452
@@ -0,0 +1,452 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"context"
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"io"
|
||||||
|
"io/fs"
|
||||||
|
"log"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"sort"
|
||||||
|
"strconv"
|
||||||
|
"strings"
|
||||||
|
"sync"
|
||||||
|
"syscall"
|
||||||
|
"time"
|
||||||
|
"unicode/utf8"
|
||||||
|
)
|
||||||
|
|
||||||
|
// hostLogsConfig is saved in /data/hostlogs.json and edited in Settings > Sources.
|
||||||
|
type hostLogsConfig struct {
|
||||||
|
Enabled bool `json:"enabled"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// hostPos is where reading resumes in a journal file (by file ID) or a text
|
||||||
|
// file (by name, with its inode to detect rotations). Off -1: archived file
|
||||||
|
// read to the end.
|
||||||
|
type hostPos struct {
|
||||||
|
Off int64 `json:"off"`
|
||||||
|
Ino uint64 `json:"ino,omitempty"`
|
||||||
|
}
|
||||||
|
|
||||||
|
// HostLogs collects the system logs of the machine hosting the stack: the
|
||||||
|
// systemd journal when there is one, else the text files of /var/log. The
|
||||||
|
// host directories are mounted read-only under root (/host by default).
|
||||||
|
type HostLogs struct {
|
||||||
|
root string
|
||||||
|
sink func(*Entry)
|
||||||
|
backfill time.Duration
|
||||||
|
cfgPath string
|
||||||
|
statePath string
|
||||||
|
wake chan struct{}
|
||||||
|
|
||||||
|
// Owned by the Run goroutine.
|
||||||
|
pos map[string]hostPos
|
||||||
|
dirty bool
|
||||||
|
started bool // a first scan was done since enabling: new files are read from their start
|
||||||
|
|
||||||
|
mu sync.Mutex
|
||||||
|
cfg hostLogsConfig
|
||||||
|
reset bool
|
||||||
|
mode string // "journal", "files" or "" (nothing found)
|
||||||
|
files int
|
||||||
|
read uint64
|
||||||
|
compressed uint64
|
||||||
|
errCode string
|
||||||
|
errDetail string
|
||||||
|
}
|
||||||
|
|
||||||
|
func NewHostLogs(root, dataDir string, backfill time.Duration, sink func(*Entry)) *HostLogs {
|
||||||
|
h := &HostLogs{
|
||||||
|
root: root,
|
||||||
|
sink: sink,
|
||||||
|
backfill: backfill,
|
||||||
|
cfgPath: filepath.Join(dataDir, "hostlogs.json"),
|
||||||
|
statePath: filepath.Join(dataDir, "hostlogs-state.json"),
|
||||||
|
wake: make(chan struct{}, 1),
|
||||||
|
pos: map[string]hostPos{},
|
||||||
|
}
|
||||||
|
if b, err := os.ReadFile(h.cfgPath); err == nil {
|
||||||
|
_ = json.Unmarshal(b, &h.cfg)
|
||||||
|
}
|
||||||
|
if b, err := os.ReadFile(h.statePath); err == nil {
|
||||||
|
_ = json.Unmarshal(b, &h.pos)
|
||||||
|
h.started = len(h.pos) > 0
|
||||||
|
}
|
||||||
|
return h
|
||||||
|
}
|
||||||
|
|
||||||
|
// Run polls the host logs every second while the source is enabled.
|
||||||
|
func (h *HostLogs) Run(ctx context.Context) {
|
||||||
|
tick := time.NewTicker(time.Second)
|
||||||
|
defer tick.Stop()
|
||||||
|
n := 0
|
||||||
|
for {
|
||||||
|
select {
|
||||||
|
case <-ctx.Done():
|
||||||
|
h.saveState()
|
||||||
|
return
|
||||||
|
case <-tick.C:
|
||||||
|
case <-h.wake:
|
||||||
|
}
|
||||||
|
h.mu.Lock()
|
||||||
|
enabled, reset := h.cfg.Enabled, h.reset
|
||||||
|
h.reset = false
|
||||||
|
h.mu.Unlock()
|
||||||
|
if reset {
|
||||||
|
// Disabled then enabled again: start over from HOST_LOGS_BACKFILL ago
|
||||||
|
// rather than reading everything written in between.
|
||||||
|
h.pos, h.started, h.dirty = map[string]hostPos{}, false, true
|
||||||
|
}
|
||||||
|
if enabled {
|
||||||
|
h.scan(time.Now())
|
||||||
|
}
|
||||||
|
if n++; n%5 == 0 || reset {
|
||||||
|
h.saveState()
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HostLogs) saveState() {
|
||||||
|
if !h.dirty {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.dirty = false
|
||||||
|
if err := writeJSONFile(h.statePath, h.pos); err != nil {
|
||||||
|
log.Printf("host logs: saving positions: %v", err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HostLogs) setStatus(mode string, files int, code, detail string) {
|
||||||
|
h.mu.Lock()
|
||||||
|
h.mode, h.files, h.errCode, h.errDetail = mode, files, code, detail
|
||||||
|
h.mu.Unlock()
|
||||||
|
}
|
||||||
|
|
||||||
|
// scan reads what was added since the previous poll.
|
||||||
|
func (h *HostLogs) scan(now time.Time) {
|
||||||
|
notBefore := time.Time{}
|
||||||
|
if !h.started {
|
||||||
|
notBefore = now.Add(-h.backfill)
|
||||||
|
}
|
||||||
|
defer func() { h.started = true }()
|
||||||
|
|
||||||
|
var journals []string
|
||||||
|
for _, dir := range []string{"var/log/journal", "run/log/journal"} {
|
||||||
|
base := filepath.Join(h.root, dir)
|
||||||
|
for _, pat := range []string{"*.journal", "*/*.journal"} {
|
||||||
|
m, _ := filepath.Glob(filepath.Join(base, pat))
|
||||||
|
journals = append(journals, m...)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
if len(journals) > 0 {
|
||||||
|
h.scanJournals(journals, notBefore)
|
||||||
|
return
|
||||||
|
}
|
||||||
|
h.scanFiles(notBefore.IsZero())
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HostLogs) scanJournals(paths []string, notBefore time.Time) {
|
||||||
|
seen := map[string]bool{}
|
||||||
|
var firstErr error
|
||||||
|
for _, p := range paths {
|
||||||
|
f, err := os.Open(p)
|
||||||
|
if err != nil {
|
||||||
|
firstErr = keepFirst(firstErr, err)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
hdr, err := readJournalHeader(f)
|
||||||
|
f.Close()
|
||||||
|
if err != nil {
|
||||||
|
continue // file being created, or not a journal
|
||||||
|
}
|
||||||
|
key := "j:" + hdr.fileID
|
||||||
|
seen[key] = true
|
||||||
|
pos, known := h.pos[key]
|
||||||
|
if known && pos.Off < 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
from, nb := pos.Off, time.Time{}
|
||||||
|
if !known {
|
||||||
|
if hdr.archived && !notBefore.IsZero() && time.UnixMicro(int64(hdr.tailRealtimeUS)).Before(notBefore) {
|
||||||
|
h.pos[key], h.dirty = hostPos{Off: -1}, true // archived before the backfill window
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
nb = notBefore
|
||||||
|
}
|
||||||
|
next, hdr, err := readJournal(p, from, nb, h.emitJournal)
|
||||||
|
if err != nil {
|
||||||
|
firstErr = keepFirst(firstErr, err)
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if hdr.archived {
|
||||||
|
next = -1
|
||||||
|
}
|
||||||
|
if !known || next != pos.Off {
|
||||||
|
h.pos[key], h.dirty = hostPos{Off: next}, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
h.prune("j:", seen)
|
||||||
|
code, detail := "", ""
|
||||||
|
if firstErr != nil && len(seen) == 0 {
|
||||||
|
code, detail = errCode(firstErr), firstErr.Error()
|
||||||
|
}
|
||||||
|
h.setStatus("journal", len(seen), code, detail)
|
||||||
|
}
|
||||||
|
|
||||||
|
func keepFirst(first, err error) error {
|
||||||
|
if first != nil {
|
||||||
|
return first
|
||||||
|
}
|
||||||
|
return err
|
||||||
|
}
|
||||||
|
|
||||||
|
func errCode(err error) string {
|
||||||
|
if errors.Is(err, fs.ErrPermission) {
|
||||||
|
return "permission"
|
||||||
|
}
|
||||||
|
return "read"
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HostLogs) prune(prefix string, seen map[string]bool) {
|
||||||
|
for k := range h.pos {
|
||||||
|
if strings.HasPrefix(k, prefix) && !seen[k] {
|
||||||
|
delete(h.pos, k)
|
||||||
|
h.dirty = true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
// hostLogFile reports the classic text logs of /var/log (rotated and
|
||||||
|
// compressed copies are left out).
|
||||||
|
func hostLogFile(name string) bool {
|
||||||
|
return name == "syslog" || name == "messages" || strings.HasSuffix(name, ".log")
|
||||||
|
}
|
||||||
|
|
||||||
|
const maxHostRead = 4 << 20 // per file and per poll
|
||||||
|
|
||||||
|
// scanFiles follows the text files of /var/log, for hosts without journald.
|
||||||
|
// Files present at the first scan are read from their end (only new lines).
|
||||||
|
func (h *HostLogs) scanFiles(fromStart bool) {
|
||||||
|
dir := filepath.Join(h.root, "var/log")
|
||||||
|
ents, err := os.ReadDir(dir)
|
||||||
|
if err != nil {
|
||||||
|
code := errCode(err)
|
||||||
|
if errors.Is(err, fs.ErrNotExist) {
|
||||||
|
code = "not_mounted"
|
||||||
|
}
|
||||||
|
h.setStatus("", 0, code, err.Error())
|
||||||
|
return
|
||||||
|
}
|
||||||
|
seen := map[string]bool{}
|
||||||
|
var firstErr error
|
||||||
|
for _, de := range ents {
|
||||||
|
if !de.Type().IsRegular() || !hostLogFile(de.Name()) {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
name := de.Name()
|
||||||
|
key := "f:" + name
|
||||||
|
fi, err := de.Info()
|
||||||
|
if err != nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
var ino uint64
|
||||||
|
if st, ok := fi.Sys().(*syscall.Stat_t); ok {
|
||||||
|
ino = uint64(st.Ino)
|
||||||
|
}
|
||||||
|
pos, known := h.pos[key]
|
||||||
|
switch {
|
||||||
|
case !known && !fromStart:
|
||||||
|
pos = hostPos{Off: fi.Size(), Ino: ino}
|
||||||
|
case !known || pos.Ino != ino || fi.Size() < pos.Off:
|
||||||
|
pos = hostPos{Off: 0, Ino: ino} // new, rotated or truncated file
|
||||||
|
}
|
||||||
|
if fi.Size() > pos.Off {
|
||||||
|
off, err := h.readFile(filepath.Join(dir, name), name, pos.Off)
|
||||||
|
if err != nil {
|
||||||
|
firstErr = keepFirst(firstErr, err)
|
||||||
|
continue // not readable: not counted as followed
|
||||||
|
}
|
||||||
|
pos.Off = off
|
||||||
|
}
|
||||||
|
seen[key] = true
|
||||||
|
if old, ok := h.pos[key]; !ok || old != pos {
|
||||||
|
h.pos[key], h.dirty = pos, true
|
||||||
|
}
|
||||||
|
}
|
||||||
|
h.prune("f:", seen)
|
||||||
|
code, detail := "", ""
|
||||||
|
if firstErr != nil && len(seen) == 0 {
|
||||||
|
code, detail = errCode(firstErr), firstErr.Error()
|
||||||
|
}
|
||||||
|
mode := "files"
|
||||||
|
if len(seen) == 0 && code == "" {
|
||||||
|
mode, code = "", "empty"
|
||||||
|
}
|
||||||
|
h.setStatus(mode, len(seen), code, detail)
|
||||||
|
}
|
||||||
|
|
||||||
|
// readFile sends the complete lines written after off and returns the new offset.
|
||||||
|
func (h *HostLogs) readFile(path, name string, off int64) (int64, error) {
|
||||||
|
f, err := os.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
return off, err
|
||||||
|
}
|
||||||
|
defer f.Close()
|
||||||
|
buf, err := io.ReadAll(io.NewSectionReader(f, off, maxHostRead))
|
||||||
|
if err != nil {
|
||||||
|
return off, err
|
||||||
|
}
|
||||||
|
end := bytes.LastIndexByte(buf, '\n')
|
||||||
|
if end < 0 {
|
||||||
|
if len(buf) < maxHostRead {
|
||||||
|
return off, nil // partial line: wait for its end
|
||||||
|
}
|
||||||
|
end = len(buf) - 1 // line longer than the read window: cut it
|
||||||
|
}
|
||||||
|
now := time.Now()
|
||||||
|
fac := fileFacility(name)
|
||||||
|
for _, line := range bytes.Split(buf[:end+1], []byte{'\n'}) {
|
||||||
|
if len(bytes.TrimSpace(line)) == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
e := ParseSyslog(line, "", "file", now)
|
||||||
|
if e.Host == "" {
|
||||||
|
e.Host = "localhost"
|
||||||
|
}
|
||||||
|
if n, ok := detectLevel(e.Message); ok {
|
||||||
|
e.SevNum, e.Severity = n, severityNames[n]
|
||||||
|
} else {
|
||||||
|
e.SevNum, e.Severity = 6, "info"
|
||||||
|
}
|
||||||
|
if fac >= 0 {
|
||||||
|
e.Facility = facilityNames[fac]
|
||||||
|
}
|
||||||
|
e.SourceType = "host"
|
||||||
|
e.Extra = map[string]string{"log_file": "/var/log/" + name}
|
||||||
|
h.sink(e)
|
||||||
|
h.count(1, 0)
|
||||||
|
}
|
||||||
|
return off + int64(end) + 1, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// fileFacility guesses the facility from the usual Debian/RHEL file names.
|
||||||
|
func fileFacility(name string) int {
|
||||||
|
switch strings.TrimSuffix(name, ".log") {
|
||||||
|
case "kern":
|
||||||
|
return 0
|
||||||
|
case "mail", "maillog":
|
||||||
|
return 2
|
||||||
|
case "daemon":
|
||||||
|
return 3
|
||||||
|
case "auth", "secure":
|
||||||
|
return 4
|
||||||
|
case "cron":
|
||||||
|
return 9
|
||||||
|
}
|
||||||
|
return -1
|
||||||
|
}
|
||||||
|
|
||||||
|
func (h *HostLogs) count(read, compressed uint64) {
|
||||||
|
h.mu.Lock()
|
||||||
|
h.read += read
|
||||||
|
h.compressed += compressed
|
||||||
|
h.mu.Unlock()
|
||||||
|
}
|
||||||
|
|
||||||
|
// emitJournal turns a journal entry into an Entry.
|
||||||
|
func (h *HostLogs) emitJournal(je *journalEntry) {
|
||||||
|
f := je.Fields
|
||||||
|
msg := f["MESSAGE"]
|
||||||
|
if msg == "" && je.Compressed > 0 {
|
||||||
|
msg = "(compressed journal entry: read it with journalctl)"
|
||||||
|
}
|
||||||
|
h.count(1, uint64(je.Compressed))
|
||||||
|
if strings.TrimSpace(msg) == "" {
|
||||||
|
return
|
||||||
|
}
|
||||||
|
if !utf8.ValidString(msg) {
|
||||||
|
msg = strings.ToValidUTF8(msg, "�")
|
||||||
|
}
|
||||||
|
sev := 6
|
||||||
|
if n, err := strconv.Atoi(f["PRIORITY"]); err == nil && n >= 0 && n <= 7 {
|
||||||
|
sev = n
|
||||||
|
}
|
||||||
|
fac := 1 // user
|
||||||
|
switch {
|
||||||
|
case f["_TRANSPORT"] == "kernel":
|
||||||
|
fac = 0
|
||||||
|
case f["_SYSTEMD_UNIT"] != "":
|
||||||
|
fac = 3 // daemon
|
||||||
|
}
|
||||||
|
if n, err := strconv.Atoi(f["SYSLOG_FACILITY"]); err == nil && n >= 0 && n < len(facilityNames) {
|
||||||
|
fac = n
|
||||||
|
}
|
||||||
|
app := firstNonEmpty(f["SYSLOG_IDENTIFIER"], f["_COMM"], strings.TrimSuffix(f["_SYSTEMD_UNIT"], ".service"))
|
||||||
|
host := firstNonEmpty(f["_HOSTNAME"], "localhost")
|
||||||
|
h.sink(&Entry{
|
||||||
|
Time: je.Realtime,
|
||||||
|
Received: time.Now(),
|
||||||
|
Host: host,
|
||||||
|
App: app,
|
||||||
|
ProcID: firstNonEmpty(f["SYSLOG_PID"], f["_PID"]),
|
||||||
|
Facility: facilityNames[fac],
|
||||||
|
Severity: severityNames[sev],
|
||||||
|
SevNum: sev,
|
||||||
|
Message: strings.TrimRight(msg, "\n"),
|
||||||
|
Proto: "journal",
|
||||||
|
SourceType: "host",
|
||||||
|
Extra: map[string]string{"unit": f["_SYSTEMD_UNIT"]},
|
||||||
|
})
|
||||||
|
}
|
||||||
|
|
||||||
|
func firstNonEmpty(vals ...string) string {
|
||||||
|
for _, v := range vals {
|
||||||
|
if v != "" {
|
||||||
|
return v
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return ""
|
||||||
|
}
|
||||||
|
|
||||||
|
// Configure saves and applies the configuration.
|
||||||
|
func (h *HostLogs) Configure(cfg hostLogsConfig) error {
|
||||||
|
h.mu.Lock()
|
||||||
|
if h.cfg.Enabled && !cfg.Enabled {
|
||||||
|
h.reset = true
|
||||||
|
h.mode, h.files, h.errCode, h.errDetail = "", 0, "", ""
|
||||||
|
}
|
||||||
|
h.cfg = cfg
|
||||||
|
h.mu.Unlock()
|
||||||
|
select {
|
||||||
|
case h.wake <- struct{}{}:
|
||||||
|
default:
|
||||||
|
}
|
||||||
|
return writeJSONFile(h.cfgPath, cfg)
|
||||||
|
}
|
||||||
|
|
||||||
|
// Status is the state shown in Settings > Sources.
|
||||||
|
func (h *HostLogs) Status() map[string]any {
|
||||||
|
h.mu.Lock()
|
||||||
|
defer h.mu.Unlock()
|
||||||
|
dirs := []string{}
|
||||||
|
for _, d := range []string{"var/log/journal", "run/log/journal", "var/log"} {
|
||||||
|
if _, err := os.Stat(filepath.Join(h.root, d)); err == nil {
|
||||||
|
dirs = append(dirs, "/"+d)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
sort.Strings(dirs)
|
||||||
|
return map[string]any{
|
||||||
|
"enabled": h.cfg.Enabled,
|
||||||
|
"mode": h.mode,
|
||||||
|
"files": h.files,
|
||||||
|
"read": h.read,
|
||||||
|
"compressed": h.compressed,
|
||||||
|
"code": h.errCode,
|
||||||
|
"error": h.errDetail,
|
||||||
|
"mounted": dirs,
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -0,0 +1,206 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/binary"
|
||||||
|
"os"
|
||||||
|
"path/filepath"
|
||||||
|
"strings"
|
||||||
|
"testing"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// fakeJournal builds a minimal journal file: header, data objects, entries.
|
||||||
|
type fakeJournal struct {
|
||||||
|
compact bool
|
||||||
|
buf []byte
|
||||||
|
seq uint64
|
||||||
|
tail uint64
|
||||||
|
}
|
||||||
|
|
||||||
|
func newFakeJournal(compact bool) *fakeJournal {
|
||||||
|
j := &fakeJournal{compact: compact, buf: make([]byte, 272)}
|
||||||
|
copy(j.buf, jSignature)
|
||||||
|
if compact {
|
||||||
|
binary.LittleEndian.PutUint32(j.buf[12:], jIncompatCompact)
|
||||||
|
}
|
||||||
|
j.buf[16] = 1 // online
|
||||||
|
copy(j.buf[24:40], "0123456789abcdef")
|
||||||
|
binary.LittleEndian.PutUint64(j.buf[88:], 272)
|
||||||
|
return j
|
||||||
|
}
|
||||||
|
|
||||||
|
func (j *fakeJournal) object(typ, flags byte, body []byte) uint64 {
|
||||||
|
for len(j.buf)%8 != 0 {
|
||||||
|
j.buf = append(j.buf, 0)
|
||||||
|
}
|
||||||
|
off := uint64(len(j.buf))
|
||||||
|
h := make([]byte, jObjHeaderSize)
|
||||||
|
h[0], h[1] = typ, flags
|
||||||
|
binary.LittleEndian.PutUint64(h[8:], uint64(jObjHeaderSize+len(body)))
|
||||||
|
j.buf = append(append(j.buf, h...), body...)
|
||||||
|
j.tail = off
|
||||||
|
binary.LittleEndian.PutUint64(j.buf[136:], off)
|
||||||
|
return off
|
||||||
|
}
|
||||||
|
|
||||||
|
func (j *fakeJournal) data(field string, flags byte) uint64 {
|
||||||
|
n := 48
|
||||||
|
if j.compact {
|
||||||
|
n = 56
|
||||||
|
}
|
||||||
|
return j.object(jObjData, flags, append(make([]byte, n), field...))
|
||||||
|
}
|
||||||
|
|
||||||
|
// entry appends an entry; linked=false leaves it unfinished (tail seqnum not updated).
|
||||||
|
func (j *fakeJournal) entry(t time.Time, linked bool, fields ...string) {
|
||||||
|
var items []byte
|
||||||
|
for _, f := range fields {
|
||||||
|
flags := byte(0)
|
||||||
|
if strings.HasPrefix(f, "!") { // compressed data object
|
||||||
|
f, flags = f[1:], 4
|
||||||
|
}
|
||||||
|
off := j.data(f, flags)
|
||||||
|
if j.compact {
|
||||||
|
items = binary.LittleEndian.AppendUint32(items, uint32(off))
|
||||||
|
} else {
|
||||||
|
items = binary.LittleEndian.AppendUint64(items, off)
|
||||||
|
items = binary.LittleEndian.AppendUint64(items, 0)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
j.seq++
|
||||||
|
body := make([]byte, 48)
|
||||||
|
binary.LittleEndian.PutUint64(body[0:], j.seq)
|
||||||
|
binary.LittleEndian.PutUint64(body[8:], uint64(t.UnixMicro()))
|
||||||
|
j.object(jObjEntry, 0, append(body, items...))
|
||||||
|
if linked {
|
||||||
|
binary.LittleEndian.PutUint64(j.buf[160:], j.seq)
|
||||||
|
binary.LittleEndian.PutUint64(j.buf[192:], uint64(t.UnixMicro()))
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func (j *fakeJournal) write(t *testing.T, path string) {
|
||||||
|
t.Helper()
|
||||||
|
if err := os.WriteFile(path, j.buf, 0o644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestReadJournal(t *testing.T) {
|
||||||
|
for _, compact := range []bool{false, true} {
|
||||||
|
path := filepath.Join(t.TempDir(), "system.journal")
|
||||||
|
now := time.Now()
|
||||||
|
j := newFakeJournal(compact)
|
||||||
|
j.entry(now.Add(-2*time.Hour), true, "MESSAGE=too old", "PRIORITY=6")
|
||||||
|
j.entry(now.Add(-time.Minute), true, "MESSAGE=Started cron.", "PRIORITY=5", "SYSLOG_IDENTIFIER=systemd", "_HOSTNAME=srv1", "_PID=1")
|
||||||
|
j.write(t, path)
|
||||||
|
|
||||||
|
var got []*journalEntry
|
||||||
|
emit := func(e *journalEntry) { got = append(got, e) }
|
||||||
|
next, _, err := readJournal(path, 0, now.Add(-time.Hour), emit)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(got) != 1 || got[0].Fields["MESSAGE"] != "Started cron." || got[0].Fields["_HOSTNAME"] != "srv1" {
|
||||||
|
t.Fatalf("compact=%v: got %+v", compact, got)
|
||||||
|
}
|
||||||
|
|
||||||
|
// A new complete entry and one still being written.
|
||||||
|
j.entry(now, true, "MESSAGE=second", "!MESSAGE=big")
|
||||||
|
j.entry(now, false, "MESSAGE=unfinished")
|
||||||
|
j.write(t, path)
|
||||||
|
got = nil
|
||||||
|
next2, _, err := readJournal(path, next, time.Time{}, emit)
|
||||||
|
if err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(got) != 1 || got[0].Fields["MESSAGE"] != "second" || got[0].Compressed != 1 {
|
||||||
|
t.Fatalf("compact=%v: resumed read got %d entries", compact, len(got))
|
||||||
|
}
|
||||||
|
|
||||||
|
// Once linked, the unfinished entry is read from where reading stopped.
|
||||||
|
binary.LittleEndian.PutUint64(j.buf[160:], j.seq)
|
||||||
|
j.write(t, path)
|
||||||
|
got = nil
|
||||||
|
if _, _, err := readJournal(path, next2, time.Time{}, emit); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
if len(got) != 1 || got[0].Fields["MESSAGE"] != "unfinished" {
|
||||||
|
t.Fatalf("compact=%v: unfinished entry got %+v", compact, got)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHostLogsJournal(t *testing.T) {
|
||||||
|
root := t.TempDir()
|
||||||
|
dir := filepath.Join(root, "var/log/journal/machine")
|
||||||
|
if err := os.MkdirAll(dir, 0o755); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
j := newFakeJournal(true)
|
||||||
|
j.entry(time.Now(), true, "MESSAGE=Accepted publickey", "PRIORITY=6", "SYSLOG_FACILITY=10", "SYSLOG_IDENTIFIER=sshd", "_PID=42", "_HOSTNAME=srv1", "_SYSTEMD_UNIT=ssh.service")
|
||||||
|
j.entry(time.Now(), true, "MESSAGE=oops", "PRIORITY=3", "_TRANSPORT=kernel", "_HOSTNAME=srv1")
|
||||||
|
j.write(t, filepath.Join(dir, "system.journal"))
|
||||||
|
|
||||||
|
var got []*Entry
|
||||||
|
h := NewHostLogs(root, t.TempDir(), time.Hour, func(e *Entry) { got = append(got, e) })
|
||||||
|
h.scan(time.Now())
|
||||||
|
if len(got) != 2 {
|
||||||
|
t.Fatalf("got %d entries", len(got))
|
||||||
|
}
|
||||||
|
e := got[0]
|
||||||
|
if e.App != "sshd" || e.ProcID != "42" || e.Facility != "authpriv" || e.Severity != "info" || e.Host != "srv1" || e.SourceType != "host" || e.Extra["unit"] != "ssh.service" {
|
||||||
|
t.Fatalf("entry %+v", e)
|
||||||
|
}
|
||||||
|
if got[1].Facility != "kern" || got[1].Severity != "err" {
|
||||||
|
t.Fatalf("kernel entry %+v", got[1])
|
||||||
|
}
|
||||||
|
h.scan(time.Now()) // nothing new
|
||||||
|
if len(got) != 2 {
|
||||||
|
t.Fatalf("re-read: %d entries", len(got))
|
||||||
|
}
|
||||||
|
if st := h.Status(); st["mode"] != "journal" || st["files"] != 1 {
|
||||||
|
t.Fatalf("status %+v", st)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHostLogsFiles(t *testing.T) {
|
||||||
|
root := t.TempDir()
|
||||||
|
dir := filepath.Join(root, "var/log")
|
||||||
|
if err := os.MkdirAll(dir, 0o755); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
auth := filepath.Join(dir, "auth.log")
|
||||||
|
if err := os.WriteFile(auth, []byte("Oct 3 07:00:00 srv1 sshd[1]: old line\n"), 0o644); err != nil {
|
||||||
|
t.Fatal(err)
|
||||||
|
}
|
||||||
|
_ = os.WriteFile(filepath.Join(dir, "auth.log.1"), []byte("rotated\n"), 0o644)
|
||||||
|
|
||||||
|
var got []*Entry
|
||||||
|
h := NewHostLogs(root, t.TempDir(), time.Hour, func(e *Entry) { got = append(got, e) })
|
||||||
|
h.scan(time.Now()) // existing content is skipped
|
||||||
|
if len(got) != 0 {
|
||||||
|
t.Fatalf("first scan read %d lines", len(got))
|
||||||
|
}
|
||||||
|
f, _ := os.OpenFile(auth, os.O_APPEND|os.O_WRONLY, 0)
|
||||||
|
_, _ = f.WriteString("Oct 3 08:00:00 srv1 sshd[7]: Failed password for root\nOct 3 08:00:01 srv1 sshd[7]: partial")
|
||||||
|
f.Close()
|
||||||
|
h.scan(time.Now())
|
||||||
|
if len(got) != 1 {
|
||||||
|
t.Fatalf("got %d lines", len(got))
|
||||||
|
}
|
||||||
|
e := got[0]
|
||||||
|
if e.Host != "srv1" || e.App != "sshd" || e.ProcID != "7" || e.Facility != "auth" || e.Extra["log_file"] != "/var/log/auth.log" || e.Proto != "file" {
|
||||||
|
t.Fatalf("entry %+v", e)
|
||||||
|
}
|
||||||
|
if st := h.Status(); st["mode"] != "files" || st["files"] != 1 {
|
||||||
|
t.Fatalf("status %+v", st)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestHostLogsNotMounted(t *testing.T) {
|
||||||
|
h := NewHostLogs(filepath.Join(t.TempDir(), "none"), t.TempDir(), time.Hour, func(*Entry) {})
|
||||||
|
h.scan(time.Now())
|
||||||
|
if st := h.Status(); st["code"] != "not_mounted" {
|
||||||
|
t.Fatalf("status %+v", st)
|
||||||
|
}
|
||||||
|
}
|
||||||
+174
@@ -0,0 +1,174 @@
|
|||||||
|
package main
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bufio"
|
||||||
|
"bytes"
|
||||||
|
"encoding/binary"
|
||||||
|
"encoding/hex"
|
||||||
|
"errors"
|
||||||
|
"io"
|
||||||
|
"os"
|
||||||
|
"time"
|
||||||
|
)
|
||||||
|
|
||||||
|
// Minimal reader of systemd journal files (*.journal), enough to follow them
|
||||||
|
// without journalctl: objects are walked in file order, which is the order
|
||||||
|
// entries were written. Format: https://systemd.io/JOURNAL_FILE_FORMAT/
|
||||||
|
|
||||||
|
const (
|
||||||
|
jHeaderMin = 208 // header fields used below end at offset 208
|
||||||
|
jObjHeaderSize = 16
|
||||||
|
|
||||||
|
jObjData = 1
|
||||||
|
jObjEntry = 3
|
||||||
|
|
||||||
|
jIncompatCompact = 1 << 4
|
||||||
|
jStateArchived = 2
|
||||||
|
jObjCompressed = 1<<0 | 1<<1 | 1<<2 // XZ, LZ4, ZSTD: not decoded (no stdlib codec)
|
||||||
|
)
|
||||||
|
|
||||||
|
var jSignature = []byte("LPKSHHRH")
|
||||||
|
|
||||||
|
// jHeader holds the header fields the reader needs.
|
||||||
|
type jHeader struct {
|
||||||
|
compact bool
|
||||||
|
archived bool
|
||||||
|
fileID string
|
||||||
|
headerSize uint64
|
||||||
|
tailObject uint64 // offset of the last object
|
||||||
|
tailSeqnum uint64 // seqnum of the last complete entry
|
||||||
|
tailRealtimeUS uint64 // realtime of the last entry (µs since the epoch)
|
||||||
|
}
|
||||||
|
|
||||||
|
func readJournalHeader(f io.ReaderAt) (jHeader, error) {
|
||||||
|
b := make([]byte, jHeaderMin)
|
||||||
|
if _, err := f.ReadAt(b, 0); err != nil {
|
||||||
|
return jHeader{}, err
|
||||||
|
}
|
||||||
|
if !bytes.Equal(b[:8], jSignature) {
|
||||||
|
return jHeader{}, errors.New("not a journal file")
|
||||||
|
}
|
||||||
|
le := binary.LittleEndian
|
||||||
|
h := jHeader{
|
||||||
|
compact: le.Uint32(b[12:])&jIncompatCompact != 0,
|
||||||
|
archived: b[16] == jStateArchived,
|
||||||
|
fileID: hex.EncodeToString(b[24:40]),
|
||||||
|
headerSize: le.Uint64(b[88:]),
|
||||||
|
tailObject: le.Uint64(b[136:]),
|
||||||
|
tailSeqnum: le.Uint64(b[160:]),
|
||||||
|
tailRealtimeUS: le.Uint64(b[192:]),
|
||||||
|
}
|
||||||
|
if h.headerSize < jHeaderMin {
|
||||||
|
return h, errors.New("journal header too small")
|
||||||
|
}
|
||||||
|
return h, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// journalEntry is one entry: its time and its "FIELD=value" pairs.
|
||||||
|
type journalEntry struct {
|
||||||
|
Realtime time.Time
|
||||||
|
Fields map[string]string
|
||||||
|
Compressed int // fields that could not be read (compressed data)
|
||||||
|
}
|
||||||
|
|
||||||
|
// readJournal reads the entries complete after offset `from` (0 = start of
|
||||||
|
// the file) and returns the offset to resume from. Entries older than
|
||||||
|
// `notBefore` are skipped without decoding their fields.
|
||||||
|
func readJournal(path string, from int64, notBefore time.Time, emit func(*journalEntry)) (next int64, h jHeader, err error) {
|
||||||
|
f, err := os.Open(path)
|
||||||
|
if err != nil {
|
||||||
|
return from, h, err
|
||||||
|
}
|
||||||
|
defer f.Close()
|
||||||
|
if h, err = readJournalHeader(f); err != nil {
|
||||||
|
return from, h, err
|
||||||
|
}
|
||||||
|
if from < int64(h.headerSize) {
|
||||||
|
from = int64(h.headerSize)
|
||||||
|
}
|
||||||
|
end := int64(h.tailObject)
|
||||||
|
r := bufio.NewReaderSize(io.NewSectionReader(f, from, 1<<62), 64*1024)
|
||||||
|
le := binary.LittleEndian
|
||||||
|
hdr := make([]byte, jObjHeaderSize)
|
||||||
|
off := from
|
||||||
|
for off <= end {
|
||||||
|
if _, err := io.ReadFull(r, hdr); err != nil {
|
||||||
|
return off, h, nil // object still being written
|
||||||
|
}
|
||||||
|
typ, size := hdr[0], int64(le.Uint64(hdr[8:]))
|
||||||
|
if size < jObjHeaderSize {
|
||||||
|
return off, h, nil
|
||||||
|
}
|
||||||
|
body := size - jObjHeaderSize
|
||||||
|
if typ == jObjEntry && body >= 48 && body < 1<<20 {
|
||||||
|
obj := make([]byte, body)
|
||||||
|
if _, err := io.ReadFull(r, obj); err != nil {
|
||||||
|
return off, h, nil
|
||||||
|
}
|
||||||
|
seq := le.Uint64(obj[0:])
|
||||||
|
if seq == 0 || seq > h.tailSeqnum {
|
||||||
|
return off, h, nil // not linked yet: retry at the next poll
|
||||||
|
}
|
||||||
|
rt := time.UnixMicro(int64(le.Uint64(obj[8:])))
|
||||||
|
if !rt.Before(notBefore) {
|
||||||
|
emit(readEntryFields(f, h.compact, rt, obj[48:]))
|
||||||
|
}
|
||||||
|
} else if _, err := r.Discard(int(body)); err != nil {
|
||||||
|
return off, h, nil
|
||||||
|
}
|
||||||
|
next := (off + size + 7) &^ 7 // objects are 8-byte aligned
|
||||||
|
if pad := next - off - size; pad > 0 {
|
||||||
|
if _, err := r.Discard(int(pad)); err != nil {
|
||||||
|
return next, h, nil // the object is complete: resume after it
|
||||||
|
}
|
||||||
|
}
|
||||||
|
off = next
|
||||||
|
}
|
||||||
|
return off, h, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// readEntryFields resolves the data objects referenced by an entry.
|
||||||
|
func readEntryFields(f io.ReaderAt, compact bool, rt time.Time, items []byte) *journalEntry {
|
||||||
|
le := binary.LittleEndian
|
||||||
|
e := &journalEntry{Realtime: rt, Fields: make(map[string]string, 16)}
|
||||||
|
step := 16
|
||||||
|
if compact {
|
||||||
|
step = 4
|
||||||
|
}
|
||||||
|
payloadAt := int64(64)
|
||||||
|
if compact {
|
||||||
|
payloadAt = 72
|
||||||
|
}
|
||||||
|
hdr := make([]byte, jObjHeaderSize)
|
||||||
|
for i := 0; i+step <= len(items); i += step {
|
||||||
|
var off int64
|
||||||
|
if compact {
|
||||||
|
off = int64(le.Uint32(items[i:]))
|
||||||
|
} else {
|
||||||
|
off = int64(le.Uint64(items[i:]))
|
||||||
|
}
|
||||||
|
if off == 0 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if _, err := f.ReadAt(hdr, off); err != nil || hdr[0] != jObjData {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if hdr[1]&jObjCompressed != 0 {
|
||||||
|
e.Compressed++
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
size := int64(le.Uint64(hdr[8:]))
|
||||||
|
n := size - payloadAt
|
||||||
|
if n <= 0 || n > 1<<20 {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
p := make([]byte, n)
|
||||||
|
if _, err := f.ReadAt(p, off+payloadAt); err != nil {
|
||||||
|
continue
|
||||||
|
}
|
||||||
|
if k := bytes.IndexByte(p, '='); k > 0 {
|
||||||
|
e.Fields[string(p[:k])] = string(p[k+1:])
|
||||||
|
}
|
||||||
|
}
|
||||||
|
return e
|
||||||
|
}
|
||||||
@@ -1,10 +1,9 @@
|
|||||||
// Logstream: a syslog (UDP/TCP) sink stored in VictoriaLogs,
|
// Logstream: a syslog (UDP/TCP), Docker and host system logs sink stored in VictoriaLogs,
|
||||||
// with a web interface to browse and search the logs.
|
// with a web interface to browse and search the logs.
|
||||||
package main
|
package main
|
||||||
|
|
||||||
import (
|
import (
|
||||||
"context"
|
"context"
|
||||||
"crypto/subtle"
|
|
||||||
"embed"
|
"embed"
|
||||||
"errors"
|
"errors"
|
||||||
"io/fs"
|
"io/fs"
|
||||||
@@ -29,8 +28,7 @@ type config struct {
|
|||||||
httpAddr string
|
httpAddr string
|
||||||
vlogsURL string
|
vlogsURL string
|
||||||
dataDir string
|
dataDir string
|
||||||
authUser string
|
auth authConfig
|
||||||
authPass string
|
|
||||||
rdns bool
|
rdns bool
|
||||||
dnsServer string
|
dnsServer string
|
||||||
allowPurge bool
|
allowPurge bool
|
||||||
@@ -38,6 +36,8 @@ type config struct {
|
|||||||
dockerLogs bool
|
dockerLogs bool
|
||||||
dockerHost string
|
dockerHost string
|
||||||
backfill time.Duration
|
backfill time.Duration
|
||||||
|
hostRoot string
|
||||||
|
hostFill time.Duration
|
||||||
batchSize int
|
batchSize int
|
||||||
queueSize int
|
queueSize int
|
||||||
flushEvery time.Duration
|
flushEvery time.Duration
|
||||||
@@ -80,8 +80,19 @@ func main() {
|
|||||||
httpAddr: getenv("HTTP_ADDR", ":8080"),
|
httpAddr: getenv("HTTP_ADDR", ":8080"),
|
||||||
vlogsURL: getenv("VLOGS_URL", "http://victorialogs:9428"),
|
vlogsURL: getenv("VLOGS_URL", "http://victorialogs:9428"),
|
||||||
dataDir: getenv("DATA_DIR", "/data"),
|
dataDir: getenv("DATA_DIR", "/data"),
|
||||||
authUser: os.Getenv("AUTH_USER"),
|
auth: authConfig{
|
||||||
authPass: os.Getenv("AUTH_PASS"),
|
mode: getenv("AUTH_MODE", "local"),
|
||||||
|
user: os.Getenv("AUTH_USER"),
|
||||||
|
pass: os.Getenv("AUTH_PASS"),
|
||||||
|
issuer: os.Getenv("OIDC_ISSUER"),
|
||||||
|
clientID: os.Getenv("OIDC_CLIENT_ID"),
|
||||||
|
clientSecret: os.Getenv("OIDC_CLIENT_SECRET"),
|
||||||
|
redirectURL: os.Getenv("OIDC_REDIRECT_URL"),
|
||||||
|
scopes: os.Getenv("OIDC_SCOPES"),
|
||||||
|
// SESSION_TTL applies to both modes; OIDC_SESSION_TTL is its former name.
|
||||||
|
sessionTTL: getenvDuration("SESSION_TTL", getenvDuration("OIDC_SESSION_TTL", 12*time.Hour)),
|
||||||
|
loginLogo: os.Getenv("LOGIN_LOGO"),
|
||||||
|
},
|
||||||
rdns: getenvBool("RDNS", true),
|
rdns: getenvBool("RDNS", true),
|
||||||
dnsServer: os.Getenv("DNS_SERVER"),
|
dnsServer: os.Getenv("DNS_SERVER"),
|
||||||
allowPurge: getenvBool("ALLOW_PURGE", true),
|
allowPurge: getenvBool("ALLOW_PURGE", true),
|
||||||
@@ -89,11 +100,15 @@ func main() {
|
|||||||
dockerLogs: getenvBool("DOCKER_LOGS", false),
|
dockerLogs: getenvBool("DOCKER_LOGS", false),
|
||||||
dockerHost: getenv("DOCKER_HOST", "unix:///var/run/docker.sock"),
|
dockerHost: getenv("DOCKER_HOST", "unix:///var/run/docker.sock"),
|
||||||
backfill: getenvDuration("DOCKER_BACKFILL", time.Hour),
|
backfill: getenvDuration("DOCKER_BACKFILL", time.Hour),
|
||||||
|
hostRoot: getenv("HOST_LOGS_ROOT", "/host"),
|
||||||
|
hostFill: getenvDuration("HOST_LOGS_BACKFILL", time.Hour),
|
||||||
batchSize: getenvInt("BATCH_SIZE", 1000),
|
batchSize: getenvInt("BATCH_SIZE", 1000),
|
||||||
queueSize: getenvInt("QUEUE_SIZE", 100000),
|
queueSize: getenvInt("QUEUE_SIZE", 100000),
|
||||||
flushEvery: time.Duration(getenvInt("FLUSH_MS", 1000)) * time.Millisecond,
|
flushEvery: time.Duration(getenvInt("FLUSH_MS", 1000)) * time.Millisecond,
|
||||||
}
|
}
|
||||||
|
|
||||||
|
cfg.auth.dataDir = cfg.dataDir
|
||||||
|
|
||||||
ctx, stop := signal.NotifyContext(context.Background(), os.Interrupt, syscall.SIGTERM)
|
ctx, stop := signal.NotifyContext(context.Background(), os.Interrupt, syscall.SIGTERM)
|
||||||
defer stop()
|
defer stop()
|
||||||
|
|
||||||
@@ -139,12 +154,22 @@ func main() {
|
|||||||
log.Printf("docker logs enabled through %s", cfg.dockerHost)
|
log.Printf("docker logs enabled through %s", cfg.dockerHost)
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
// System logs of the host (journal or /var/log), off until enabled in Settings > Sources.
|
||||||
|
api.host = NewHostLogs(cfg.hostRoot, cfg.dataDir, cfg.hostFill, sink)
|
||||||
|
go api.host.Run(ctx)
|
||||||
api.Routes(mux)
|
api.Routes(mux)
|
||||||
mux.Handle("GET /", http.FileServer(http.FS(static)))
|
mux.Handle("GET /", http.FileServer(http.FS(static)))
|
||||||
|
|
||||||
|
handler, err := newAuth(cfg.auth, mux)
|
||||||
|
if err != nil {
|
||||||
|
log.Fatalf("auth: %v", err)
|
||||||
|
}
|
||||||
|
if o, ok := handler.(*OIDC); ok {
|
||||||
|
go o.checkProvider()
|
||||||
|
}
|
||||||
srv := &http.Server{
|
srv := &http.Server{
|
||||||
Addr: cfg.httpAddr,
|
Addr: cfg.httpAddr,
|
||||||
Handler: basicAuth(cfg.authUser, cfg.authPass, mux),
|
Handler: handler,
|
||||||
ReadHeaderTimeout: 10 * time.Second,
|
ReadHeaderTimeout: 10 * time.Second,
|
||||||
// Requests inherit the global context so SSE streams end on shutdown.
|
// Requests inherit the global context so SSE streams end on shutdown.
|
||||||
BaseContext: func(net.Listener) context.Context { return ctx },
|
BaseContext: func(net.Listener) context.Context { return ctx },
|
||||||
@@ -163,25 +188,3 @@ func main() {
|
|||||||
<-storeDone
|
<-storeDone
|
||||||
log.Println("shutdown complete")
|
log.Println("shutdown complete")
|
||||||
}
|
}
|
||||||
|
|
||||||
// basicAuth protects the UI when AUTH_USER is set (except /healthz).
|
|
||||||
func basicAuth(user, pass string, next http.Handler) http.Handler {
|
|
||||||
if user == "" {
|
|
||||||
return next
|
|
||||||
}
|
|
||||||
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
|
|
||||||
if r.URL.Path == "/healthz" {
|
|
||||||
next.ServeHTTP(w, r)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
u, p, ok := r.BasicAuth()
|
|
||||||
if !ok ||
|
|
||||||
subtle.ConstantTimeCompare([]byte(u), []byte(user)) != 1 ||
|
|
||||||
subtle.ConstantTimeCompare([]byte(p), []byte(pass)) != 1 {
|
|
||||||
w.Header().Set("WWW-Authenticate", `Basic realm="logstream"`)
|
|
||||||
http.Error(w, "authentication required", http.StatusUnauthorized)
|
|
||||||
return
|
|
||||||
}
|
|
||||||
next.ServeHTTP(w, r)
|
|
||||||
})
|
|
||||||
}
|
|
||||||
@@ -17,7 +17,7 @@ type Filter struct {
|
|||||||
Host string
|
Host string
|
||||||
App string
|
App string
|
||||||
Severity int // highest severity number included (0 = emerg … 7 = debug), -1 = all
|
Severity int // highest severity number included (0 = emerg … 7 = debug), -1 = all
|
||||||
Source string // "syslog", "docker" or "" for all
|
Source string // "syslog", "docker", "host" or "" for all
|
||||||
}
|
}
|
||||||
|
|
||||||
var rangeDurations = map[string]time.Duration{
|
var rangeDurations = map[string]time.Duration{
|
||||||
@@ -119,10 +119,10 @@ func (f Filter) filterExpr() string {
|
|||||||
parts = append(parts, "app:="+strconv.Quote(f.App))
|
parts = append(parts, "app:="+strconv.Quote(f.App))
|
||||||
}
|
}
|
||||||
switch f.Source {
|
switch f.Source {
|
||||||
case "docker":
|
case "docker", "host":
|
||||||
parts = append(parts, `source_type:="docker"`)
|
parts = append(parts, `source_type:=`+strconv.Quote(f.Source))
|
||||||
case "syslog": // also matches logs stored before source_type existed
|
case "syslog": // also matches logs stored before source_type existed
|
||||||
parts = append(parts, `!(source_type:="docker")`)
|
parts = append(parts, `!(source_type:in("docker","host"))`)
|
||||||
}
|
}
|
||||||
if f.Severity >= 0 && f.Severity < 7 {
|
if f.Severity >= 0 && f.Severity < 7 {
|
||||||
names := make([]string, 0, 8)
|
names := make([]string, 0, 8)
|
||||||
@@ -209,7 +209,7 @@ func (m *Matcher) Match(e *Entry) bool {
|
|||||||
if m.f.App != "" && e.App != m.f.App {
|
if m.f.App != "" && e.App != m.f.App {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
if (m.f.Source == "docker") != (e.SourceType == "docker") && m.f.Source != "" {
|
if m.f.Source != "" && m.f.Source != e.SourceType {
|
||||||
return false
|
return false
|
||||||
}
|
}
|
||||||
if m.f.Severity >= 0 && e.SevNum > m.f.Severity {
|
if m.f.Severity >= 0 && e.SevNum > m.f.Severity {
|
||||||
|
|||||||
@@ -17,6 +17,7 @@ import (
|
|||||||
type Tag struct {
|
type Tag struct {
|
||||||
ID string `json:"id"`
|
ID string `json:"id"`
|
||||||
Pattern string `json:"pattern"`
|
Pattern string `json:"pattern"`
|
||||||
|
Label string `json:"label,omitempty"` // shown instead of the pattern (presets)
|
||||||
Color string `json:"color"`
|
Color string `json:"color"`
|
||||||
WholeWord bool `json:"wholeWord"`
|
WholeWord bool `json:"wholeWord"`
|
||||||
CaseSensitive bool `json:"caseSensitive"`
|
CaseSensitive bool `json:"caseSensitive"`
|
||||||
@@ -72,6 +73,7 @@ var (
|
|||||||
|
|
||||||
func (t *Tag) validate() error {
|
func (t *Tag) validate() error {
|
||||||
t.Pattern = strings.TrimSpace(t.Pattern)
|
t.Pattern = strings.TrimSpace(t.Pattern)
|
||||||
|
t.Label = strings.TrimSpace(t.Label)
|
||||||
if t.Pattern == "" {
|
if t.Pattern == "" {
|
||||||
return &codedError{code: "pattern_required", msg: "the keyword is required"}
|
return &codedError{code: "pattern_required", msg: "the keyword is required"}
|
||||||
}
|
}
|
||||||
|
|||||||
+270
-18
@@ -14,6 +14,7 @@ const I18N = {
|
|||||||
liveUnavailable: 'Live view is not available in LogsQL mode',
|
liveUnavailable: 'Live view is not available in LogsQL mode',
|
||||||
settings: 'Settings',
|
settings: 'Settings',
|
||||||
theme: 'Light / dark theme',
|
theme: 'Light / dark theme',
|
||||||
|
logout: 'Log out',
|
||||||
close: 'Close',
|
close: 'Close',
|
||||||
rangeAria: 'Time range', severityAria: 'Severity', hostAria: 'Host', appAria: 'Application',
|
rangeAria: 'Time range', severityAria: 'Severity', hostAria: 'Host', appAria: 'Application',
|
||||||
histoAria: 'Log volume over time',
|
histoAria: 'Log volume over time',
|
||||||
@@ -47,6 +48,12 @@ const I18N = {
|
|||||||
newTag: 'new',
|
newTag: 'new',
|
||||||
confirmDelete: (p) => `Delete tag "${p}"?`,
|
confirmDelete: (p) => `Delete tag "${p}"?`,
|
||||||
confirmReset: 'Replace all tags with the defaults (warning, error, ok)?',
|
confirmReset: 'Replace all tags with the defaults (warning, error, ok)?',
|
||||||
|
presetAria: 'Add a preset', presetPick: '+ Preset…',
|
||||||
|
preset_http_status: 'HTTP status codes', preset_http_methods: 'HTTP methods',
|
||||||
|
preset_http_probes: 'Probes and attacks', preset_http_bots: 'Bots and scripts',
|
||||||
|
preset_http_errors: 'TLS/HTTPS and proxy errors',
|
||||||
|
pl_probes: 'probes / attacks', pl_bots: 'bots / scripts', pl_tls: 'TLS errors', pl_proxy: 'proxy errors',
|
||||||
|
presetAdded: (n) => (n ? `${n} tag(s) added` : 'These tags are already in the list'),
|
||||||
tagsLoadErr: 'Tags: ',
|
tagsLoadErr: 'Tags: ',
|
||||||
err_pattern_required: 'The keyword is required',
|
err_pattern_required: 'The keyword is required',
|
||||||
err_invalid_color: 'Invalid color (expected #rrggbb)',
|
err_invalid_color: 'Invalid color (expected #rrggbb)',
|
||||||
@@ -67,6 +74,19 @@ const I18N = {
|
|||||||
fHostName: 'host name (DNS)', fHostIp: 'host IP',
|
fHostName: 'host name (DNS)', fHostIp: 'host IP',
|
||||||
clickHost: 'Click to filter on this host', clickApp: 'Click to filter on this app',
|
clickHost: 'Click to filter on this host', clickApp: 'Click to filter on this app',
|
||||||
sourceAria: 'Source', srcAll: 'All sources', tabSources: 'Sources',
|
sourceAria: 'Source', srcAll: 'All sources', tabSources: 'Sources',
|
||||||
|
srcHost: 'Host system',
|
||||||
|
hostTitle: 'Host system logs',
|
||||||
|
hostEnabled: 'Collect the system logs of this machine',
|
||||||
|
hostOff: 'Off: the system logs of the machine hosting LogStream are not collected.',
|
||||||
|
hostWaiting: 'Starting…',
|
||||||
|
hostJournal: ({ n, r }) => `Reading the systemd journal (${n} files): ${r} entries since startup.`,
|
||||||
|
hostFiles: ({ n, r }) => `Following ${n} files of /var/log: ${r} lines since startup.`,
|
||||||
|
hostCompressed: (n) => ` ${n} compressed fields skipped (long messages, readable with journalctl).`,
|
||||||
|
host_not_mounted: 'No host log directory found: mount /var/log and /run/log/journal under /host (see docker-compose.yml).',
|
||||||
|
host_permission: 'Permission denied: give the container a group allowed to read the logs (HOST_LOGS_GID in .env, see the README). ',
|
||||||
|
host_empty: 'No systemd journal and no log file found in /var/log.',
|
||||||
|
host_read: 'Cannot read the host logs: ',
|
||||||
|
hostHelp: 'Reads the systemd journal of the host (/var/log/journal, /run/log/journal), or the text files of /var/log (syslog, messages, *.log) when there is no journal. Directories are mounted read-only. When turned on, the last hour is read first (HOST_LOGS_BACKFILL).',
|
||||||
syslogEnabled: 'Receive syslog messages', syslogProtocols: 'Protocols', syslogPort: 'Port',
|
syslogEnabled: 'Receive syslog messages', syslogProtocols: 'Protocols', syslogPort: 'Port',
|
||||||
syslogListening: ({ port, protos }) => `Listening on port ${port} (${protos}).`,
|
syslogListening: ({ port, protos }) => `Listening on port ${port} (${protos}).`,
|
||||||
syslogOff: 'Syslog reception is off: syslog messages are ignored (Docker logs are still collected).',
|
syslogOff: 'Syslog reception is off: syslog messages are ignored (Docker logs are still collected).',
|
||||||
@@ -84,10 +104,11 @@ const I18N = {
|
|||||||
dockerLegend: 'Colored: followed · grey: not followed · dashed: stopped · the color identifies the compose project. Click a label to switch it.',
|
dockerLegend: 'Colored: followed · grey: not followed · dashed: stopped · the color identifies the compose project. Click a label to switch it.',
|
||||||
dockerNoMatch: 'No container',
|
dockerNoMatch: 'No container',
|
||||||
stFollowing: 'followed', stSelected: 'followed when running', stIgnored: 'not followed', stStopped: 'stopped',
|
stFollowing: 'followed', stSelected: 'followed when running', stIgnored: 'not followed', stStopped: 'stopped',
|
||||||
stLocked: 'excluded', stLockedTitle: 'Logstream itself, or label logstream.exclude=true',
|
stLocked: 'excluded', stLockedTitle: 'LogStream itself, or label logstream.exclude=true',
|
||||||
dockerHelp: 'Logs are read through docker-socket-proxy, a read-only gateway: Logstream can list containers and read their logs, nothing else. Choices apply per compose service (or container name), so they survive container re-creations.',
|
dockerHelp: 'Logs are read through docker-socket-proxy, a read-only gateway: LogStream can list containers and read their logs, nothing else. Choices apply per compose service (or container name), so they survive container re-creations.',
|
||||||
fContainer: 'container', fContainerId: 'container ID', fImage: 'image', fProject: 'compose project',
|
fContainer: 'container', fContainerId: 'container ID', fImage: 'image', fProject: 'compose project',
|
||||||
fService: 'compose service', fStream: 'stream', fSourceType: 'source',
|
fService: 'compose service', fStream: 'stream', fSourceType: 'source',
|
||||||
|
fUnit: 'systemd unit', fLogFile: 'log file',
|
||||||
export: 'Export', exportCsvHint: 'Comma separated, UTF-8',
|
export: 'Export', exportCsvHint: 'Comma separated, UTF-8',
|
||||||
exportExcel: 'CSV for Excel', exportExcelHint: 'Semicolon separated, for Excel in French',
|
exportExcel: 'CSV for Excel', exportExcelHint: 'Semicolon separated, for Excel in French',
|
||||||
exportNote: (n) => `Up to ${n} logs matching the current filters, newest first. Dates use the time zone chosen in Settings.`,
|
exportNote: (n) => `Up to ${n} logs matching the current filters, newest first. Dates use the time zone chosen in Settings.`,
|
||||||
@@ -98,8 +119,9 @@ const I18N = {
|
|||||||
themeHelp: 'System follows the light/dark preference of your computer or phone.',
|
themeHelp: 'System follows the light/dark preference of your computer or phone.',
|
||||||
logDisplay: 'Log display', fontSize: 'Font size',
|
logDisplay: 'Log display', fontSize: 'Font size',
|
||||||
sizeTiny: 'Tiny', sizeSmall: 'Small', sizeMedium: 'Medium', sizeLarge: 'Large',
|
sizeTiny: 'Tiny', sizeSmall: 'Small', sizeMedium: 'Medium', sizeLarge: 'Large',
|
||||||
fontLabel: 'Font', fontSystem: 'System monospace (no download)',
|
density: 'Density', densityNormal: 'Normal', densityCompact: 'Compact',
|
||||||
fontHelp: 'Free fonts (SIL Open Font License) loaded by your browser from Bunny Fonts, a privacy-friendly European font service. Without internet access, the system font is used.',
|
fontLabel: 'Font', fontSystem: 'System monospace (no download)', fontBuiltin: 'built in, narrow',
|
||||||
|
fontHelp: 'Free fonts (SIL Open Font License). Iosevka is served by LogStream itself and works offline; it is narrow, so more text fits on each line. The others are loaded by your browser from Bunny Fonts, a privacy-friendly European font service; without internet access, the system font is used.',
|
||||||
previewMsgs: ['error: link down on eth1, carrier lost', 'warning: disk /dev/sda temperature 58°C', 'backup finished: ok (12.4 GB in 00:14:32)'],
|
previewMsgs: ['error: link down on eth1, carrier lost', 'warning: disk /dev/sda temperature 58°C', 'backup finished: ok (12.4 GB in 00:14:32)'],
|
||||||
dangerZone: 'Danger zone',
|
dangerZone: 'Danger zone',
|
||||||
purgeHelp: 'Permanently delete every stored log to start from scratch. Color tags and settings are kept.',
|
purgeHelp: 'Permanently delete every stored log to start from scratch. Color tags and settings are kept.',
|
||||||
@@ -126,6 +148,11 @@ const I18N = {
|
|||||||
hDivision: (s) => `interval ${s}`, hCapped: 'enlarged',
|
hDivision: (s) => `interval ${s}`, hCapped: 'enlarged',
|
||||||
hCappedTitle: 'The chosen division would exceed 300 intervals over this range: it has been enlarged.',
|
hCappedTitle: 'The chosen division would exceed 300 intervals over this range: it has been enlarged.',
|
||||||
hUnzoom: '× Reset zoom', unitDay: 'd',
|
hUnzoom: '× Reset zoom', unitDay: 'd',
|
||||||
|
toTop: 'Back to top',
|
||||||
|
colRcv: 'Received', colMt: 'Message time', colSev: 'Severity', colHost: 'Host', colApp: 'App', colMsg: 'Message',
|
||||||
|
colGrip: 'Drag to resize, double-click for the automatic width',
|
||||||
|
resetCols: 'Reset column widths', colsReset: 'Column widths reset',
|
||||||
|
colsHelp: 'Drag the edge of a column header in the log list to resize it (remembered by this browser).',
|
||||||
},
|
},
|
||||||
fr: {
|
fr: {
|
||||||
locale: 'fr-FR',
|
locale: 'fr-FR',
|
||||||
@@ -138,6 +165,7 @@ const I18N = {
|
|||||||
liveUnavailable: 'Le direct n\'est pas disponible en mode LogsQL',
|
liveUnavailable: 'Le direct n\'est pas disponible en mode LogsQL',
|
||||||
settings: 'Paramètres',
|
settings: 'Paramètres',
|
||||||
theme: 'Thème clair / sombre',
|
theme: 'Thème clair / sombre',
|
||||||
|
logout: 'Se déconnecter',
|
||||||
close: 'Fermer',
|
close: 'Fermer',
|
||||||
rangeAria: 'Période', severityAria: 'Sévérité', hostAria: 'Hôte', appAria: 'Application',
|
rangeAria: 'Période', severityAria: 'Sévérité', hostAria: 'Hôte', appAria: 'Application',
|
||||||
histoAria: 'Volume de logs dans le temps',
|
histoAria: 'Volume de logs dans le temps',
|
||||||
@@ -171,6 +199,12 @@ const I18N = {
|
|||||||
newTag: 'nouveau',
|
newTag: 'nouveau',
|
||||||
confirmDelete: (p) => `Supprimer le tag « ${p} » ?`,
|
confirmDelete: (p) => `Supprimer le tag « ${p} » ?`,
|
||||||
confirmReset: 'Remplacer tous les tags par les tags par défaut (warning, error, ok) ?',
|
confirmReset: 'Remplacer tous les tags par les tags par défaut (warning, error, ok) ?',
|
||||||
|
presetAria: 'Ajouter un préréglage', presetPick: '+ Préréglage…',
|
||||||
|
preset_http_status: 'Codes HTTP', preset_http_methods: 'Méthodes HTTP',
|
||||||
|
preset_http_probes: 'Sondes et attaques', preset_http_bots: 'Robots et scripts',
|
||||||
|
preset_http_errors: 'Erreurs TLS/HTTPS et proxy',
|
||||||
|
pl_probes: 'sondes / attaques', pl_bots: 'robots / scripts', pl_tls: 'erreurs TLS', pl_proxy: 'erreurs proxy',
|
||||||
|
presetAdded: (n) => (n ? `${n} tag(s) ajouté(s)` : 'Ces tags sont déjà dans la liste'),
|
||||||
tagsLoadErr: 'Tags : ',
|
tagsLoadErr: 'Tags : ',
|
||||||
err_pattern_required: 'Le mot-clé est obligatoire',
|
err_pattern_required: 'Le mot-clé est obligatoire',
|
||||||
err_invalid_color: 'Couleur invalide (format #rrggbb attendu)',
|
err_invalid_color: 'Couleur invalide (format #rrggbb attendu)',
|
||||||
@@ -191,6 +225,19 @@ const I18N = {
|
|||||||
fHostName: 'nom d\'hôte (DNS)', fHostIp: 'IP de l\'hôte',
|
fHostName: 'nom d\'hôte (DNS)', fHostIp: 'IP de l\'hôte',
|
||||||
clickHost: 'Cliquer pour filtrer sur cet hôte', clickApp: 'Cliquer pour filtrer sur cette appli',
|
clickHost: 'Cliquer pour filtrer sur cet hôte', clickApp: 'Cliquer pour filtrer sur cette appli',
|
||||||
sourceAria: 'Source', srcAll: 'Toutes les sources', tabSources: 'Sources',
|
sourceAria: 'Source', srcAll: 'Toutes les sources', tabSources: 'Sources',
|
||||||
|
srcHost: 'Système hôte',
|
||||||
|
hostTitle: 'Logs système de l\'hôte',
|
||||||
|
hostEnabled: 'Collecter les logs système de cette machine',
|
||||||
|
hostOff: 'Désactivé : les logs système de la machine qui héberge LogStream ne sont pas collectés.',
|
||||||
|
hostWaiting: 'Démarrage…',
|
||||||
|
hostJournal: ({ n, r }) => `Lecture du journal systemd (${n} fichiers) : ${r} entrées depuis le démarrage.`,
|
||||||
|
hostFiles: ({ n, r }) => `Suivi de ${n} fichiers de /var/log : ${r} lignes depuis le démarrage.`,
|
||||||
|
hostCompressed: (n) => ` ${n} champs compressés ignorés (messages longs, lisibles avec journalctl).`,
|
||||||
|
host_not_mounted: 'Aucun répertoire de logs de l\'hôte trouvé : montez /var/log et /run/log/journal sous /host (voir docker-compose.yml).',
|
||||||
|
host_permission: 'Accès refusé : donnez au conteneur un groupe autorisé à lire les logs (HOST_LOGS_GID dans .env, voir le README). ',
|
||||||
|
host_empty: 'Ni journal systemd ni fichier de log trouvé dans /var/log.',
|
||||||
|
host_read: 'Lecture des logs de l\'hôte impossible : ',
|
||||||
|
hostHelp: 'Lit le journal systemd de l\'hôte (/var/log/journal, /run/log/journal), ou les fichiers texte de /var/log (syslog, messages, *.log) s\'il n\'y a pas de journal. Les répertoires sont montés en lecture seule. À l\'activation, la dernière heure est lue d\'abord (HOST_LOGS_BACKFILL).',
|
||||||
syslogEnabled: 'Recevoir les messages syslog', syslogProtocols: 'Protocoles', syslogPort: 'Port',
|
syslogEnabled: 'Recevoir les messages syslog', syslogProtocols: 'Protocoles', syslogPort: 'Port',
|
||||||
syslogListening: ({ port, protos }) => `Écoute sur le port ${port} (${protos}).`,
|
syslogListening: ({ port, protos }) => `Écoute sur le port ${port} (${protos}).`,
|
||||||
syslogOff: 'Réception syslog désactivée : les messages syslog sont ignorés (les logs Docker sont toujours collectés).',
|
syslogOff: 'Réception syslog désactivée : les messages syslog sont ignorés (les logs Docker sont toujours collectés).',
|
||||||
@@ -208,10 +255,11 @@ const I18N = {
|
|||||||
dockerLegend: 'En couleur : suivis · en gris : non suivis · pointillés : arrêtés · la couleur identifie le projet compose. Cliquez sur une étiquette pour la basculer.',
|
dockerLegend: 'En couleur : suivis · en gris : non suivis · pointillés : arrêtés · la couleur identifie le projet compose. Cliquez sur une étiquette pour la basculer.',
|
||||||
dockerNoMatch: 'Aucun conteneur',
|
dockerNoMatch: 'Aucun conteneur',
|
||||||
stFollowing: 'suivi', stSelected: 'suivi dès qu\'il tourne', stIgnored: 'non suivi', stStopped: 'arrêté',
|
stFollowing: 'suivi', stSelected: 'suivi dès qu\'il tourne', stIgnored: 'non suivi', stStopped: 'arrêté',
|
||||||
stLocked: 'exclu', stLockedTitle: 'Logstream lui-même, ou étiquette logstream.exclude=true',
|
stLocked: 'exclu', stLockedTitle: 'LogStream lui-même, ou étiquette logstream.exclude=true',
|
||||||
dockerHelp: 'Les logs sont lus via docker-socket-proxy, une passerelle en lecture seule : Logstream peut lister les conteneurs et lire leurs logs, rien d\'autre. Les choix s\'appliquent par service compose (ou nom de conteneur), ils survivent donc à la recréation des conteneurs.',
|
dockerHelp: 'Les logs sont lus via docker-socket-proxy, une passerelle en lecture seule : LogStream peut lister les conteneurs et lire leurs logs, rien d\'autre. Les choix s\'appliquent par service compose (ou nom de conteneur), ils survivent donc à la recréation des conteneurs.',
|
||||||
fContainer: 'conteneur', fContainerId: 'ID du conteneur', fImage: 'image', fProject: 'projet compose',
|
fContainer: 'conteneur', fContainerId: 'ID du conteneur', fImage: 'image', fProject: 'projet compose',
|
||||||
fService: 'service compose', fStream: 'flux', fSourceType: 'source',
|
fService: 'service compose', fStream: 'flux', fSourceType: 'source',
|
||||||
|
fUnit: 'unité systemd', fLogFile: 'fichier de log',
|
||||||
export: 'Exporter', exportCsvHint: 'Séparateur virgule, UTF-8',
|
export: 'Exporter', exportCsvHint: 'Séparateur virgule, UTF-8',
|
||||||
exportExcel: 'CSV pour Excel', exportExcelHint: 'Séparateur point-virgule, pour Excel en français',
|
exportExcel: 'CSV pour Excel', exportExcelHint: 'Séparateur point-virgule, pour Excel en français',
|
||||||
exportNote: (n) => `Jusqu'à ${n} logs correspondant aux filtres, du plus récent au plus ancien. Dates dans le fuseau choisi dans Paramètres.`,
|
exportNote: (n) => `Jusqu'à ${n} logs correspondant aux filtres, du plus récent au plus ancien. Dates dans le fuseau choisi dans Paramètres.`,
|
||||||
@@ -222,8 +270,9 @@ const I18N = {
|
|||||||
themeHelp: 'Système suit la préférence clair/sombre de votre ordinateur ou de votre téléphone.',
|
themeHelp: 'Système suit la préférence clair/sombre de votre ordinateur ou de votre téléphone.',
|
||||||
logDisplay: 'Affichage des logs', fontSize: 'Taille du texte',
|
logDisplay: 'Affichage des logs', fontSize: 'Taille du texte',
|
||||||
sizeTiny: 'Très petite', sizeSmall: 'Petite', sizeMedium: 'Moyenne', sizeLarge: 'Grande',
|
sizeTiny: 'Très petite', sizeSmall: 'Petite', sizeMedium: 'Moyenne', sizeLarge: 'Grande',
|
||||||
fontLabel: 'Police', fontSystem: 'Monospace du système (aucun téléchargement)',
|
density: 'Densité', densityNormal: 'Normale', densityCompact: 'Compacte',
|
||||||
fontHelp: 'Polices libres (licence SIL Open Font) chargées par votre navigateur depuis Bunny Fonts, un service européen respectueux de la vie privée. Sans accès à internet, la police du système est utilisée.',
|
fontLabel: 'Police', fontSystem: 'Monospace du système (aucun téléchargement)', fontBuiltin: 'intégrée, étroite',
|
||||||
|
fontHelp: 'Polices libres (licence SIL Open Font). Iosevka est servie par LogStream lui-même et fonctionne hors ligne ; elle est étroite, donc chaque ligne affiche plus de texte. Les autres sont chargées par votre navigateur depuis Bunny Fonts, un service européen respectueux de la vie privée ; sans accès à internet, la police du système est utilisée.',
|
||||||
previewMsgs: ['error: link down on eth1, carrier lost', 'warning: disk /dev/sda temperature 58°C', 'backup finished: ok (12.4 GB in 00:14:32)'],
|
previewMsgs: ['error: link down on eth1, carrier lost', 'warning: disk /dev/sda temperature 58°C', 'backup finished: ok (12.4 GB in 00:14:32)'],
|
||||||
dangerZone: 'Zone de danger',
|
dangerZone: 'Zone de danger',
|
||||||
purgeHelp: 'Supprime définitivement tous les logs stockés pour repartir de zéro. Les tags de couleur et les réglages sont conservés.',
|
purgeHelp: 'Supprime définitivement tous les logs stockés pour repartir de zéro. Les tags de couleur et les réglages sont conservés.',
|
||||||
@@ -250,6 +299,11 @@ const I18N = {
|
|||||||
hDivision: (s) => `intervalle ${s}`, hCapped: 'élargi',
|
hDivision: (s) => `intervalle ${s}`, hCapped: 'élargi',
|
||||||
hCappedTitle: 'La division choisie dépasserait 300 intervalles sur cette plage : elle a été élargie.',
|
hCappedTitle: 'La division choisie dépasserait 300 intervalles sur cette plage : elle a été élargie.',
|
||||||
hUnzoom: '× Annuler le zoom', unitDay: 'j',
|
hUnzoom: '× Annuler le zoom', unitDay: 'j',
|
||||||
|
toTop: 'Revenir en haut',
|
||||||
|
colRcv: 'Réception', colMt: 'Heure message', colSev: 'Sévérité', colHost: 'Hôte', colApp: 'App', colMsg: 'Message',
|
||||||
|
colGrip: 'Glisser pour redimensionner, double-clic pour la largeur automatique',
|
||||||
|
resetCols: 'Réinitialiser les colonnes', colsReset: 'Largeurs de colonnes réinitialisées',
|
||||||
|
colsHelp: 'Glissez le bord d\'un en-tête de colonne de la liste pour la redimensionner (mémorisé par ce navigateur).',
|
||||||
},
|
},
|
||||||
};
|
};
|
||||||
|
|
||||||
@@ -371,6 +425,8 @@ async function api(url, opts = {}) {
|
|||||||
|
|
||||||
// Known error codes are translated; otherwise the server message is shown.
|
// Known error codes are translated; otherwise the server message is shown.
|
||||||
function apiError(res, text, data) {
|
function apiError(res, text, data) {
|
||||||
|
// OIDC session expired: reloading the page goes through the login again.
|
||||||
|
if (res.status === 401 && data && data.code === 'auth') location.reload();
|
||||||
let msg = (data && data.error) || text || res.statusText;
|
let msg = (data && data.error) || text || res.statusText;
|
||||||
if (data && data.code && I18N[lang]['err_' + data.code]) {
|
if (data && data.code && I18N[lang]['err_' + data.code]) {
|
||||||
msg = t('err_' + data.code) + (data.detail ? (lang === 'fr' ? ' : ' : ': ') + data.detail : '');
|
msg = t('err_' + data.code) + (data.detail ? (lang === 'fr' ? ' : ' : ': ') + data.detail : '');
|
||||||
@@ -414,7 +470,7 @@ const list = $('#list');
|
|||||||
function applyLang() {
|
function applyLang() {
|
||||||
document.documentElement.lang = lang;
|
document.documentElement.lang = lang;
|
||||||
for (const el of document.querySelectorAll('[data-i18n]')) el.textContent = t(el.dataset.i18n);
|
for (const el of document.querySelectorAll('[data-i18n]')) el.textContent = t(el.dataset.i18n);
|
||||||
for (const el of document.querySelectorAll('[data-i18n-title]')) el.title = t(el.dataset.i18nTitle);
|
for (const el of document.querySelectorAll('[data-i18n-title]')) el.title = t(el.dataset.i18nTitle) + (el.dataset.user ? ` (${el.dataset.user})` : '');
|
||||||
for (const el of document.querySelectorAll('[data-i18n-aria]')) el.setAttribute('aria-label', t(el.dataset.i18nAria));
|
for (const el of document.querySelectorAll('[data-i18n-aria]')) el.setAttribute('aria-label', t(el.dataset.i18nAria));
|
||||||
for (const el of document.querySelectorAll('[data-i18n-ph]')) el.placeholder = t(el.dataset.i18nPh);
|
for (const el of document.querySelectorAll('[data-i18n-ph]')) el.placeholder = t(el.dataset.i18nPh);
|
||||||
for (const b of document.querySelectorAll('#langSwitch [data-lang]')) b.setAttribute('aria-checked', String(b.dataset.lang === lang));
|
for (const b of document.querySelectorAll('#langSwitch [data-lang]')) b.setAttribute('aria-checked', String(b.dataset.lang === lang));
|
||||||
@@ -437,6 +493,7 @@ function setLang(next) {
|
|||||||
renderPurge();
|
renderPurge();
|
||||||
renderInterface();
|
renderInterface();
|
||||||
renderSyslog();
|
renderSyslog();
|
||||||
|
renderHost();
|
||||||
renderDocker();
|
renderDocker();
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -476,9 +533,11 @@ $('#themeSwitch').addEventListener('click', (ev) => {
|
|||||||
|
|
||||||
/* ================= Log font and size ================= */
|
/* ================= Log font and size ================= */
|
||||||
|
|
||||||
// Free monospace fonts, served by Bunny Fonts (https://fonts.bunny.net).
|
// Free monospace fonts, served by Bunny Fonts (https://fonts.bunny.net), except the
|
||||||
|
// built-in ones (web/fonts, declared in style.css), which also work offline.
|
||||||
const LOG_FONTS = [
|
const LOG_FONTS = [
|
||||||
{ id: 'system' },
|
{ id: 'system' },
|
||||||
|
{ id: 'iosevka', family: 'Iosevka', builtin: true },
|
||||||
{ id: 'jetbrains-mono', family: 'JetBrains Mono' },
|
{ id: 'jetbrains-mono', family: 'JetBrains Mono' },
|
||||||
{ id: 'fira-code', family: 'Fira Code' },
|
{ id: 'fira-code', family: 'Fira Code' },
|
||||||
{ id: 'source-code-pro', family: 'Source Code Pro' },
|
{ id: 'source-code-pro', family: 'Source Code Pro' },
|
||||||
@@ -493,7 +552,8 @@ const LOG_FONTS = [
|
|||||||
{ id: 'dm-mono', family: 'DM Mono', weights: '400,500' },
|
{ id: 'dm-mono', family: 'DM Mono', weights: '400,500' },
|
||||||
];
|
];
|
||||||
const LOG_SIZES = { tiny: '10.5px', small: '11.5px', medium: '12.5px', large: '14px' };
|
const LOG_SIZES = { tiny: '10.5px', small: '11.5px', medium: '12.5px', large: '14px' };
|
||||||
const ui = { font: 'system', size: 'medium' };
|
const LOG_DENSITIES = ['normal', 'compact'];
|
||||||
|
const ui = { font: 'system', size: 'medium', density: 'normal' };
|
||||||
|
|
||||||
function applyLogFont(id) {
|
function applyLogFont(id) {
|
||||||
const f = LOG_FONTS.find((x) => x.id === id) || LOG_FONTS[0];
|
const f = LOG_FONTS.find((x) => x.id === id) || LOG_FONTS[0];
|
||||||
@@ -503,6 +563,10 @@ function applyLogFont(id) {
|
|||||||
root.removeProperty('--log-font');
|
root.removeProperty('--log-font');
|
||||||
return;
|
return;
|
||||||
}
|
}
|
||||||
|
if (f.builtin) {
|
||||||
|
root.setProperty('--log-font', `'${f.family}', var(--mono)`);
|
||||||
|
return;
|
||||||
|
}
|
||||||
const href = `https://fonts.bunny.net/css?family=${f.id}:${f.weights || '400,700'}&display=swap`;
|
const href = `https://fonts.bunny.net/css?family=${f.id}:${f.weights || '400,700'}&display=swap`;
|
||||||
let link = document.getElementById('logFontCss');
|
let link = document.getElementById('logFontCss');
|
||||||
if (!link) {
|
if (!link) {
|
||||||
@@ -518,13 +582,22 @@ function applyLogSize(id) {
|
|||||||
document.documentElement.style.setProperty('--log-size', LOG_SIZES[ui.size]);
|
document.documentElement.style.setProperty('--log-size', LOG_SIZES[ui.size]);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
function applyLogDensity(id) {
|
||||||
|
ui.density = LOG_DENSITIES.includes(id) ? id : 'normal';
|
||||||
|
document.documentElement.dataset.density = ui.density;
|
||||||
|
}
|
||||||
|
|
||||||
function renderInterface() {
|
function renderInterface() {
|
||||||
renderThemeSwitch();
|
renderThemeSwitch();
|
||||||
for (const b of document.querySelectorAll('#sizeSwitch [data-size]')) {
|
for (const b of document.querySelectorAll('#sizeSwitch [data-size]')) {
|
||||||
b.setAttribute('aria-checked', String(b.dataset.size === ui.size));
|
b.setAttribute('aria-checked', String(b.dataset.size === ui.size));
|
||||||
}
|
}
|
||||||
|
for (const b of document.querySelectorAll('#densitySwitch [data-density]')) {
|
||||||
|
b.setAttribute('aria-checked', String(b.dataset.density === ui.density));
|
||||||
|
}
|
||||||
const sel = $('#fontSelect');
|
const sel = $('#fontSelect');
|
||||||
sel.innerHTML = LOG_FONTS.map((f) => `<option value="${f.id}">${esc(f.family || t('fontSystem'))}</option>`).join('');
|
const fontName = (f) => (!f.family ? t('fontSystem') : f.builtin ? `${f.family} (${t('fontBuiltin')})` : f.family);
|
||||||
|
sel.innerHTML = LOG_FONTS.map((f) => `<option value="${f.id}">${esc(fontName(f))}</option>`).join('');
|
||||||
sel.value = ui.font;
|
sel.value = ui.font;
|
||||||
renderFontPreview();
|
renderFontPreview();
|
||||||
renderHistoSettings();
|
renderHistoSettings();
|
||||||
@@ -548,6 +621,13 @@ $('#sizeSwitch').addEventListener('click', (ev) => {
|
|||||||
store.set('logSize', ui.size);
|
store.set('logSize', ui.size);
|
||||||
renderInterface();
|
renderInterface();
|
||||||
});
|
});
|
||||||
|
$('#densitySwitch').addEventListener('click', (ev) => {
|
||||||
|
const b = ev.target.closest('[data-density]');
|
||||||
|
if (!b) return;
|
||||||
|
applyLogDensity(b.dataset.density);
|
||||||
|
store.set('logDensity', ui.density);
|
||||||
|
renderInterface();
|
||||||
|
});
|
||||||
$('#fontSelect').addEventListener('change', (ev) => {
|
$('#fontSelect').addEventListener('change', (ev) => {
|
||||||
applyLogFont(ev.target.value);
|
applyLogFont(ev.target.value);
|
||||||
store.set('logFont', ui.font);
|
store.set('logFont', ui.font);
|
||||||
@@ -638,7 +718,10 @@ function compileMatchers() {
|
|||||||
let src = tag.regex ? tag.pattern : escapeRe(tag.pattern);
|
let src = tag.regex ? tag.pattern : escapeRe(tag.pattern);
|
||||||
if (tag.wholeWord) src = `(?<![\\p{L}\\p{N}_])(?:${src})(?![\\p{L}\\p{N}_])`;
|
if (tag.wholeWord) src = `(?<![\\p{L}\\p{N}_])(?:${src})(?![\\p{L}\\p{N}_])`;
|
||||||
try {
|
try {
|
||||||
out.push({ re: new RegExp(src, 'gu' + (tag.caseSensitive ? '' : 'i')), html: `<mark class="tag" style="${tagStyle(tag.color)}">` });
|
// A regex may name a group "hl" to color only that part of the match.
|
||||||
|
const hl = tag.regex && /\(\?P?<hl>/.test(tag.pattern);
|
||||||
|
if (hl) src = src.replace(/\(\?P<hl>/g, '(?<hl>');
|
||||||
|
out.push({ re: new RegExp(src, 'gu' + (hl ? 'd' : '') + (tag.caseSensitive ? '' : 'i')), html: `<mark class="tag" style="${tagStyle(tag.color)}">` });
|
||||||
} catch (e) {
|
} catch (e) {
|
||||||
console.warn('Tag skipped (invalid pattern):', tag.pattern, e.message);
|
console.warn('Tag skipped (invalid pattern):', tag.pattern, e.message);
|
||||||
}
|
}
|
||||||
@@ -663,6 +746,8 @@ function highlight(text) {
|
|||||||
let x;
|
let x;
|
||||||
while ((x = m.re.exec(text)) !== null) {
|
while ((x = m.re.exec(text)) !== null) {
|
||||||
if (x[0] === '') { m.re.lastIndex++; continue; }
|
if (x[0] === '') { m.re.lastIndex++; continue; }
|
||||||
|
const g = x.indices?.groups?.hl;
|
||||||
|
if (g) { if (g[1] > g[0]) spans.push({ s: g[0], e: g[1], prio, html: m.html }); continue; }
|
||||||
spans.push({ s: x.index, e: x.index + x[0].length, prio, html: m.html });
|
spans.push({ s: x.index, e: x.index + x[0].length, prio, html: m.html });
|
||||||
}
|
}
|
||||||
});
|
});
|
||||||
@@ -762,6 +847,7 @@ function renderList() {
|
|||||||
addFacetValues(state.rows);
|
addFacetValues(state.rows);
|
||||||
list.innerHTML = state.rows.map((r) => rowHTML(r, false)).join('');
|
list.innerHTML = state.rows.map((r) => rowHTML(r, false)).join('');
|
||||||
bindRows(list.firstElementChild, state.rows);
|
bindRows(list.firstElementChild, state.rows);
|
||||||
|
$('#table').hidden = !state.rows.length;
|
||||||
$('#empty').hidden = state.rows.length > 0 || !$('#error').hidden;
|
$('#empty').hidden = state.rows.length > 0 || !$('#error').hidden;
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -778,6 +864,7 @@ function prependRows(rows) {
|
|||||||
list.insertAdjacentHTML('afterbegin', rows.map((r) => rowHTML(r, true)).join(''));
|
list.insertAdjacentHTML('afterbegin', rows.map((r) => rowHTML(r, true)).join(''));
|
||||||
bindRows(list.firstElementChild, rows);
|
bindRows(list.firstElementChild, rows);
|
||||||
state.rows = rows.concat(state.rows);
|
state.rows = rows.concat(state.rows);
|
||||||
|
$('#table').hidden = false;
|
||||||
while (state.rows.length > MAX_ROWS) {
|
while (state.rows.length > MAX_ROWS) {
|
||||||
state.rows.pop();
|
state.rows.pop();
|
||||||
list.lastElementChild?.remove();
|
list.lastElementChild?.remove();
|
||||||
@@ -793,14 +880,14 @@ function updateCount(tookMs) {
|
|||||||
}
|
}
|
||||||
|
|
||||||
function detailsHTML(r) {
|
function detailsHTML(r) {
|
||||||
const order = ['received', 'msg_time', '_time', 'host', 'host_name', 'host_ip', 'source_type', 'container', 'image', 'compose_project', 'compose_service', 'stream', 'app', 'procid', 'severity', 'facility', 'source', 'proto', 'sd', '_msg'];
|
const order = ['received', 'msg_time', '_time', 'host', 'host_name', 'host_ip', 'source_type', 'container', 'image', 'compose_project', 'compose_service', 'stream', 'unit', 'log_file', 'app', 'procid', 'severity', 'facility', 'source', 'proto', 'sd', '_msg'];
|
||||||
const hidden = new Set(['_stream_id', '_stream', 'sevnum']);
|
const hidden = new Set(['_stream_id', '_stream', 'sevnum']);
|
||||||
if (r.msg_time) hidden.add('_time'); // same as the reception time
|
if (r.msg_time) hidden.add('_time'); // same as the reception time
|
||||||
const keys = order.filter((k) => r[k] != null && r[k] !== '' && !hidden.has(k))
|
const keys = order.filter((k) => r[k] != null && r[k] !== '' && !hidden.has(k))
|
||||||
.concat(Object.keys(r).filter((k) => !order.includes(k) && !hidden.has(k)).sort());
|
.concat(Object.keys(r).filter((k) => !order.includes(k) && !hidden.has(k)).sort());
|
||||||
const label = {
|
const label = {
|
||||||
container: t('fContainer'), container_id: t('fContainerId'), image: t('fImage'), compose_project: t('fProject'),
|
container: t('fContainer'), container_id: t('fContainerId'), image: t('fImage'), compose_project: t('fProject'),
|
||||||
compose_service: t('fService'), stream: t('fStream'), source_type: t('fSourceType'),
|
compose_service: t('fService'), stream: t('fStream'), source_type: t('fSourceType'), unit: t('fUnit'), log_file: t('fLogFile'),
|
||||||
msg_time: t('fTime'), host_name: t('fHostName'), host_ip: t('fHostIp'), received: t('fReceived'), _time: t('fTime'), _msg: t('fMsg'), procid: t('fPid'), sd: t('fSd') };
|
msg_time: t('fTime'), host_name: t('fHostName'), host_ip: t('fHostIp'), received: t('fReceived'), _time: t('fTime'), _msg: t('fMsg'), procid: t('fPid'), sd: t('fSd') };
|
||||||
const val = (k) => (k === '_time' || k === 'received' || k === 'msg_time'
|
const val = (k) => (k === '_time' || k === 'received' || k === 'msg_time'
|
||||||
? `${esc(fmtFull(r[k]))} <span class="muted">(${esc(r[k])})</span>`
|
? `${esc(fmtFull(r[k]))} <span class="muted">(${esc(r[k])})</span>`
|
||||||
@@ -858,6 +945,66 @@ list.addEventListener('keydown', (ev) => {
|
|||||||
if (ev.key === 'Enter' && ev.target.classList.contains('row')) ev.target.click();
|
if (ev.key === 'Enter' && ev.target.classList.contains('row')) ev.target.click();
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/* ================= Column widths ================= */
|
||||||
|
|
||||||
|
// Resizable columns of the log list: width in px per column, remembered per
|
||||||
|
// browser (logstream.cols.<name>); no stored width = automatic default (CSS).
|
||||||
|
const COLS = { rcv: [60, 420], mt: [60, 420], sev: [36, 200], host: [50, 600], app: [40, 600] }; // [min, max]
|
||||||
|
const clampCol = (k, w) => Math.min(COLS[k][1], Math.max(COLS[k][0], Math.round(w)));
|
||||||
|
|
||||||
|
function applyColWidths() {
|
||||||
|
const table = $('#table');
|
||||||
|
for (const k of Object.keys(COLS)) {
|
||||||
|
const w = parseInt(store.get('cols.' + k, ''), 10);
|
||||||
|
if (w > 0) table.style.setProperty('--col-' + k, clampCol(k, w) + 'px');
|
||||||
|
else table.style.removeProperty('--col-' + k);
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
$('#listHead').addEventListener('pointerdown', (ev) => {
|
||||||
|
const grip = ev.target.closest('.grip');
|
||||||
|
if (!grip || ev.button !== 0) return;
|
||||||
|
ev.preventDefault();
|
||||||
|
const k = grip.parentElement.dataset.col;
|
||||||
|
const x0 = ev.clientX;
|
||||||
|
const w0 = grip.parentElement.getBoundingClientRect().width;
|
||||||
|
const table = $('#table');
|
||||||
|
grip.setPointerCapture(ev.pointerId);
|
||||||
|
grip.classList.add('active');
|
||||||
|
document.body.classList.add('col-resizing');
|
||||||
|
const move = (e) => table.style.setProperty('--col-' + k, clampCol(k, w0 + e.clientX - x0) + 'px');
|
||||||
|
const end = () => {
|
||||||
|
grip.removeEventListener('pointermove', move);
|
||||||
|
grip.removeEventListener('pointerup', end);
|
||||||
|
grip.removeEventListener('pointercancel', end);
|
||||||
|
grip.classList.remove('active');
|
||||||
|
document.body.classList.remove('col-resizing');
|
||||||
|
const w = parseInt(table.style.getPropertyValue('--col-' + k), 10);
|
||||||
|
if (w > 0 && w !== Math.round(w0)) store.set('cols.' + k, String(w));
|
||||||
|
};
|
||||||
|
grip.addEventListener('pointermove', move);
|
||||||
|
grip.addEventListener('pointerup', end);
|
||||||
|
grip.addEventListener('pointercancel', end);
|
||||||
|
});
|
||||||
|
// Double-click on a handle: back to the automatic width.
|
||||||
|
$('#listHead').addEventListener('dblclick', (ev) => {
|
||||||
|
const grip = ev.target.closest('.grip');
|
||||||
|
if (!grip) return;
|
||||||
|
store.set('cols.' + grip.parentElement.dataset.col, '');
|
||||||
|
applyColWidths();
|
||||||
|
});
|
||||||
|
$('#resetCols').addEventListener('click', () => {
|
||||||
|
for (const k of Object.keys(COLS)) store.set('cols.' + k, '');
|
||||||
|
applyColWidths();
|
||||||
|
toast(t('colsReset'));
|
||||||
|
});
|
||||||
|
|
||||||
|
// The header sticks right under the top bar, whose height changes with the layout.
|
||||||
|
new ResizeObserver(([e]) => {
|
||||||
|
document.documentElement.style.setProperty('--topbar-h', Math.ceil(e.target.getBoundingClientRect().height) + 'px');
|
||||||
|
}).observe($('.topbar'));
|
||||||
|
applyColWidths();
|
||||||
|
|
||||||
/* ================= Timeline (histogram) ================= */
|
/* ================= Timeline (histogram) ================= */
|
||||||
|
|
||||||
// Settings > Interface > Timeline, remembered per browser; the first value is the default.
|
// Settings > Interface > Timeline, remembered per browser; the first value is the default.
|
||||||
@@ -1447,6 +1594,15 @@ $('#newPill').addEventListener('click', () => {
|
|||||||
});
|
});
|
||||||
window.addEventListener('scroll', debounce(() => { if (window.scrollY <= 80) flushPending(); }, 150), { passive: true });
|
window.addEventListener('scroll', debounce(() => { if (window.scrollY <= 80) flushPending(); }, 150), { passive: true });
|
||||||
|
|
||||||
|
// "Back to top" button, shown once the page has scrolled a little.
|
||||||
|
const syncToTop = () => { $('#toTop').hidden = window.scrollY < 400; };
|
||||||
|
window.addEventListener('scroll', syncToTop, { passive: true });
|
||||||
|
$('#toTop').addEventListener('click', () => {
|
||||||
|
const smooth = !matchMedia('(prefers-reduced-motion: reduce)').matches;
|
||||||
|
window.scrollTo({ top: 0, behavior: smooth ? 'smooth' : 'auto' });
|
||||||
|
});
|
||||||
|
syncToTop();
|
||||||
|
|
||||||
$('#live').addEventListener('click', () => {
|
$('#live').addEventListener('click', () => {
|
||||||
state.live = !state.live;
|
state.live = !state.live;
|
||||||
store.set('live', state.live ? '1' : '0');
|
store.set('live', state.live ? '1' : '0');
|
||||||
@@ -1645,6 +1801,48 @@ $('#syslogProtos').addEventListener('click', (ev) => {
|
|||||||
configureSyslog({ [b.dataset.proto]: !syslogState[b.dataset.proto] });
|
configureSyslog({ [b.dataset.proto]: !syslogState[b.dataset.proto] });
|
||||||
});
|
});
|
||||||
|
|
||||||
|
/* ================= Host system logs ================= */
|
||||||
|
|
||||||
|
let hostState = null;
|
||||||
|
|
||||||
|
async function loadHost() {
|
||||||
|
try { hostState = await api('/api/hostlogs'); } catch { hostState = null; }
|
||||||
|
renderHost();
|
||||||
|
}
|
||||||
|
|
||||||
|
function renderHost() {
|
||||||
|
const s = hostState;
|
||||||
|
const status = $('#hostStatus');
|
||||||
|
if (!s) { status.textContent = ''; return; }
|
||||||
|
$('#hostEnabled').checked = s.enabled;
|
||||||
|
let text = t('hostWaiting');
|
||||||
|
let cls = 'muted';
|
||||||
|
if (!s.enabled) {
|
||||||
|
text = t('hostOff');
|
||||||
|
} else if (s.code) {
|
||||||
|
text = t('host_' + s.code) + (s.code === 'read' || s.code === 'permission' ? s.error || '' : '');
|
||||||
|
cls = 'bad';
|
||||||
|
} else if (s.mode === 'journal') {
|
||||||
|
text = t('hostJournal', { n: s.files, r: fmtNum(s.read) }) + (s.compressed ? t('hostCompressed', fmtNum(s.compressed)) : '');
|
||||||
|
cls = 'good';
|
||||||
|
} else if (s.mode === 'files') {
|
||||||
|
text = t('hostFiles', { n: s.files, r: fmtNum(s.read) });
|
||||||
|
cls = 'good';
|
||||||
|
}
|
||||||
|
status.textContent = text;
|
||||||
|
status.className = 'docker-status ' + cls;
|
||||||
|
}
|
||||||
|
|
||||||
|
async function configureHost(enabled) {
|
||||||
|
hostState = { ...(hostState || {}), enabled };
|
||||||
|
renderHost();
|
||||||
|
try { hostState = await api('/api/hostlogs', { method: 'PUT', body: { enabled } }); } catch (e) { toast(e.message); }
|
||||||
|
renderHost();
|
||||||
|
setTimeout(loadHost, 1500); // the first scan runs in the background
|
||||||
|
}
|
||||||
|
|
||||||
|
$('#hostEnabled').addEventListener('change', (ev) => configureHost(ev.target.checked));
|
||||||
|
|
||||||
/* ================= Docker source ================= */
|
/* ================= Docker source ================= */
|
||||||
|
|
||||||
let dockerState = null;
|
let dockerState = null;
|
||||||
@@ -1758,7 +1956,10 @@ for (const [id, on] of [['#dockerAll', true], ['#dockerNone', false]]) {
|
|||||||
}
|
}
|
||||||
// Keep the list fresh while the Sources tab is open.
|
// Keep the list fresh while the Sources tab is open.
|
||||||
setInterval(() => {
|
setInterval(() => {
|
||||||
if ($('#settingsDlg').open && !document.querySelector('[data-panel="sources"]').hidden) loadDocker();
|
if ($('#settingsDlg').open && !document.querySelector('[data-panel="sources"]').hidden) {
|
||||||
|
loadDocker();
|
||||||
|
loadHost();
|
||||||
|
}
|
||||||
}, 4000);
|
}, 4000);
|
||||||
|
|
||||||
/* ================= Purge ================= */
|
/* ================= Purge ================= */
|
||||||
@@ -1819,6 +2020,28 @@ $('#purgeBtn').addEventListener('click', async () => {
|
|||||||
|
|
||||||
const PALETTE = ['#6366f1', '#0ea5e9', '#14b8a6', '#a855f7', '#ec4899', '#eab308', '#64748b', '#f97316'];
|
const PALETTE = ['#6366f1', '#0ea5e9', '#14b8a6', '#a855f7', '#ec4899', '#eab308', '#64748b', '#f97316'];
|
||||||
|
|
||||||
|
// Ready-made tags for HTTP/HTTPS access logs. The patterns are valid in both
|
||||||
|
// JavaScript and Go (RE2) and cover nginx/Apache (common, combined), Traefik
|
||||||
|
// (CLF, JSON), Caddy (JSON) and HAProxy (httplog). For status codes and
|
||||||
|
// methods only the "hl" group is colored, not the context around it.
|
||||||
|
const HTTP_STATUS_CTX = '(?:" |"(?:status|DownstreamStatus|OriginStatus|status_code)": ?|(?:-1|\\d+)/(?:-1|\\d+)/(?:-1|\\d+)/(?:-1|\\d+)/\\+?\\d+ )';
|
||||||
|
const httpStatus = (d, color) => ({ label: `HTTP ${d}xx`, pattern: `${HTTP_STATUS_CTX}(?<hl>${d}\\d\\d)\\b`, color });
|
||||||
|
const httpMethod = (m, color) => ({ label: m.replace(/\|/g, '/'), pattern: `"(?<hl>${m})[ "]`, color, caseSensitive: true });
|
||||||
|
const PRESETS = {
|
||||||
|
http_status: () => [httpStatus(2, '#86efac'), httpStatus(3, '#93c5fd'), httpStatus(4, '#fdba74'), httpStatus(5, '#f87171')],
|
||||||
|
http_methods: () => [httpMethod('GET|HEAD|OPTIONS', '#cbd5e1'), httpMethod('POST|PUT|PATCH', '#c4b5fd'), httpMethod('DELETE', '#f9a8d4')],
|
||||||
|
http_probes: () => [{ label: t('pl_probes'), color: '#fda4af',
|
||||||
|
pattern: '(?:wp-login\\.php|xmlrpc\\.php|wp-admin|phpmyadmin|/\\.env|/\\.git|/\\.aws|/cgi-bin/|\\.\\./|%2e%2e|/etc/passwd|<script|union(?:\\s|%20|\\+)+select)' }],
|
||||||
|
http_bots: () => [{ label: t('pl_bots'), color: '#fde68a',
|
||||||
|
pattern: '\\b(?:[a-z]*bot|crawler|spider|curl|wget|python-requests|Go-http-client|zgrab|masscan|nmap|sqlmap|nikto)\\b' }],
|
||||||
|
http_errors: () => [
|
||||||
|
{ label: t('pl_tls'), color: '#f0abfc',
|
||||||
|
pattern: '(?:TLS handshake error|SSL_do_handshake\\(\\) failed|SSL handshake|SSL routines|certificate (?:has )?expired|certificate verify failed|bad certificate|unknown certificate|x509:)' },
|
||||||
|
{ label: t('pl_proxy'), color: '#fdba74',
|
||||||
|
pattern: '(?:upstream timed out|upstream prematurely closed|no live upstreams|connect\\(\\) failed|connection refused|bad gateway|gateway time-?out|service unavailable)' },
|
||||||
|
],
|
||||||
|
};
|
||||||
|
|
||||||
async function loadTags() {
|
async function loadTags() {
|
||||||
try { state.tags = await api('/api/tags'); } catch (e) { toast(t('tagsLoadErr') + e.message); }
|
try { state.tags = await api('/api/tags'); } catch (e) { toast(t('tagsLoadErr') + e.message); }
|
||||||
compileMatchers();
|
compileMatchers();
|
||||||
@@ -1830,7 +2053,7 @@ function tagRowHTML(tag) {
|
|||||||
return `<div class="tag-row${tag.enabled ? '' : ' off'}" data-id="${esc(tag.id)}">
|
return `<div class="tag-row${tag.enabled ? '' : ' off'}" data-id="${esc(tag.id)}">
|
||||||
<input type="color" value="${esc(tag.color)}" data-f="color" aria-label="${esc(t('colorAria'))}">
|
<input type="color" value="${esc(tag.color)}" data-f="color" aria-label="${esc(t('colorAria'))}">
|
||||||
<input type="text" value="${esc(tag.pattern)}" data-f="pattern" placeholder="${esc(t('keyword'))}" spellcheck="false" aria-label="${esc(t('keyword'))}">
|
<input type="text" value="${esc(tag.pattern)}" data-f="pattern" placeholder="${esc(t('keyword'))}" spellcheck="false" aria-label="${esc(t('keyword'))}">
|
||||||
<span class="preview"><mark class="tag" style="${tagStyle(tag.color)}">${esc(tag.pattern || t('preview'))}</mark></span>
|
<span class="preview" title="${esc(tag.pattern)}"><mark class="tag" style="${tagStyle(tag.color)}">${esc(tag.label || tag.pattern || t('preview'))}</mark></span>
|
||||||
<div class="opts">
|
<div class="opts">
|
||||||
${opt('wholeWord', t('optWhole'), t('optWholeTitle'))}
|
${opt('wholeWord', t('optWhole'), t('optWholeTitle'))}
|
||||||
${opt('caseSensitive', 'Aa', t('optCaseTitle'))}
|
${opt('caseSensitive', 'Aa', t('optCaseTitle'))}
|
||||||
@@ -1873,7 +2096,7 @@ $('#tagList').addEventListener('input', (ev) => {
|
|||||||
tag[field] = ev.target.type === 'checkbox' ? ev.target.checked : ev.target.value;
|
tag[field] = ev.target.type === 'checkbox' ? ev.target.checked : ev.target.value;
|
||||||
rowEl.classList.toggle('off', !tag.enabled);
|
rowEl.classList.toggle('off', !tag.enabled);
|
||||||
const mark = rowEl.querySelector('.preview mark');
|
const mark = rowEl.querySelector('.preview mark');
|
||||||
mark.textContent = tag.pattern || t('preview');
|
mark.textContent = tag.label || tag.pattern || t('preview');
|
||||||
mark.setAttribute('style', tagStyle(tag.color));
|
mark.setAttribute('style', tagStyle(tag.color));
|
||||||
scheduleSave(tag, rowEl);
|
scheduleSave(tag, rowEl);
|
||||||
applyTags();
|
applyTags();
|
||||||
@@ -1906,6 +2129,24 @@ $('#addTag').addEventListener('click', async () => {
|
|||||||
} catch (e) { toast(e.message); }
|
} catch (e) { toast(e.message); }
|
||||||
});
|
});
|
||||||
|
|
||||||
|
// Adds a preset group, skipping tags whose pattern is already in the list.
|
||||||
|
$('#presetTags').addEventListener('change', async (ev) => {
|
||||||
|
const make = PRESETS[ev.target.value];
|
||||||
|
ev.target.value = '';
|
||||||
|
if (!make) return;
|
||||||
|
let added = 0;
|
||||||
|
try {
|
||||||
|
for (const p of make()) {
|
||||||
|
if (state.tags.some((x) => x.pattern === p.pattern)) continue;
|
||||||
|
state.tags.push(await api('/api/tags', { method: 'POST', body: { regex: true, enabled: true, ...p } }));
|
||||||
|
added++;
|
||||||
|
}
|
||||||
|
} catch (e) { toast(e.message); }
|
||||||
|
renderTagList();
|
||||||
|
applyTags();
|
||||||
|
toast(t('presetAdded', added));
|
||||||
|
});
|
||||||
|
|
||||||
$('#resetTags').addEventListener('click', async () => {
|
$('#resetTags').addEventListener('click', async () => {
|
||||||
if (!confirm(t('confirmReset'))) return;
|
if (!confirm(t('confirmReset'))) return;
|
||||||
try {
|
try {
|
||||||
@@ -1921,6 +2162,7 @@ $('#settingsBtn').addEventListener('click', () => {
|
|||||||
renderInterface();
|
renderInterface();
|
||||||
loadPurgeStatus();
|
loadPurgeStatus();
|
||||||
loadSyslog();
|
loadSyslog();
|
||||||
|
loadHost();
|
||||||
loadDocker();
|
loadDocker();
|
||||||
showSettingsTab(store.get('settingsTab', 'locale'));
|
showSettingsTab(store.get('settingsTab', 'locale'));
|
||||||
$('#settingsDlg').showModal();
|
$('#settingsDlg').showModal();
|
||||||
@@ -1938,11 +2180,21 @@ $('#settingsDlg').addEventListener('click', (ev) => { if (ev.target === ev.curre
|
|||||||
}
|
}
|
||||||
applyLogFont(store.get('logFont', 'system'));
|
applyLogFont(store.get('logFont', 'system'));
|
||||||
applyLogSize(store.get('logSize', 'medium'));
|
applyLogSize(store.get('logSize', 'medium'));
|
||||||
|
applyLogDensity(store.get('logDensity', 'normal'));
|
||||||
applyLang();
|
applyLang();
|
||||||
$('#range').value = store.get('range', '1h');
|
$('#range').value = store.get('range', '1h');
|
||||||
if (!$('#range').value) $('#range').value = '1h';
|
if (!$('#range').value) $('#range').value = '1h';
|
||||||
$('#severity').value = store.get('severity', '');
|
$('#severity').value = store.get('severity', '');
|
||||||
|
|
||||||
|
// With a login (local or OIDC), show who is logged in and the log out button.
|
||||||
|
fetch('/auth/me').then((res) => (res.ok ? res.json() : null)).then((me) => {
|
||||||
|
if (!me || !me.user) return;
|
||||||
|
const btn = $('#logoutBtn');
|
||||||
|
btn.hidden = false;
|
||||||
|
btn.dataset.user = me.user;
|
||||||
|
btn.title = `${t('logout')} (${me.user})`;
|
||||||
|
}).catch(() => {});
|
||||||
|
|
||||||
(async () => {
|
(async () => {
|
||||||
await loadTags();
|
await loadTags();
|
||||||
loadFacets();
|
loadFacets();
|
||||||
|
|||||||
@@ -0,0 +1,110 @@
|
|||||||
|
Copyright (c) 2015-2023, Renzhi Li (aka. Belleve Invis, belleve@typeof.net)
|
||||||
|
|
||||||
|
This Font Software is licensed under the SIL Open Font License, Version 1.1.
|
||||||
|
|
||||||
|
This license is copied below, and is also available with a FAQ at:
|
||||||
|
http://scripts.sil.org/OFL
|
||||||
|
|
||||||
|
--------------------------
|
||||||
|
|
||||||
|
|
||||||
|
SIL Open Font License v1.1
|
||||||
|
====================================================
|
||||||
|
|
||||||
|
|
||||||
|
Preamble
|
||||||
|
----------
|
||||||
|
|
||||||
|
The goals of the Open Font License (OFL) are to stimulate worldwide
|
||||||
|
development of collaborative font projects, to support the font creation
|
||||||
|
efforts of academic and linguistic communities, and to provide a free and
|
||||||
|
open framework in which fonts may be shared and improved in partnership
|
||||||
|
with others.
|
||||||
|
|
||||||
|
The OFL allows the licensed fonts to be used, studied, modified and
|
||||||
|
redistributed freely as long as they are not sold by themselves. The
|
||||||
|
fonts, including any derivative works, can be bundled, embedded,
|
||||||
|
redistributed and/or sold with any software provided that any reserved
|
||||||
|
names are not used by derivative works. The fonts and derivatives,
|
||||||
|
however, cannot be released under any other type of license. The
|
||||||
|
requirement for fonts to remain under this license does not apply
|
||||||
|
to any document created using the fonts or their derivatives.
|
||||||
|
|
||||||
|
|
||||||
|
Definitions
|
||||||
|
-------------
|
||||||
|
|
||||||
|
`"Font Software"` refers to the set of files released by the Copyright
|
||||||
|
Holder(s) under this license and clearly marked as such. This may
|
||||||
|
include source files, build scripts and documentation.
|
||||||
|
|
||||||
|
`"Reserved Font Name"` refers to any names specified as such after the
|
||||||
|
copyright statement(s).
|
||||||
|
|
||||||
|
`"Original Version"` refers to the collection of Font Software components as
|
||||||
|
distributed by the Copyright Holder(s).
|
||||||
|
|
||||||
|
`"Modified Version"` refers to any derivative made by adding to, deleting,
|
||||||
|
or substituting -- in part or in whole -- any of the components of the
|
||||||
|
Original Version, by changing formats or by porting the Font Software to a
|
||||||
|
new environment.
|
||||||
|
|
||||||
|
`"Author"` refers to any designer, engineer, programmer, technical
|
||||||
|
writer or other person who contributed to the Font Software.
|
||||||
|
|
||||||
|
|
||||||
|
Permission & Conditions
|
||||||
|
------------------------
|
||||||
|
|
||||||
|
Permission is hereby granted, free of charge, to any person obtaining
|
||||||
|
a copy of the Font Software, to use, study, copy, merge, embed, modify,
|
||||||
|
redistribute, and sell modified and unmodified copies of the Font
|
||||||
|
Software, subject to the following conditions:
|
||||||
|
|
||||||
|
1. Neither the Font Software nor any of its individual components,
|
||||||
|
in Original or Modified Versions, may be sold by itself.
|
||||||
|
|
||||||
|
2. Original or Modified Versions of the Font Software may be bundled,
|
||||||
|
redistributed and/or sold with any software, provided that each copy
|
||||||
|
contains the above copyright notice and this license. These can be
|
||||||
|
included either as stand-alone text files, human-readable headers or
|
||||||
|
in the appropriate machine-readable metadata fields within text or
|
||||||
|
binary files as long as those fields can be easily viewed by the user.
|
||||||
|
|
||||||
|
3. No Modified Version of the Font Software may use the Reserved Font
|
||||||
|
Name(s) unless explicit written permission is granted by the corresponding
|
||||||
|
Copyright Holder. This restriction only applies to the primary font name as
|
||||||
|
presented to the users.
|
||||||
|
|
||||||
|
4. The name(s) of the Copyright Holder(s) or the Author(s) of the Font
|
||||||
|
Software shall not be used to promote, endorse or advertise any
|
||||||
|
Modified Version, except to acknowledge the contribution(s) of the
|
||||||
|
Copyright Holder(s) and the Author(s) or with their explicit written
|
||||||
|
permission.
|
||||||
|
|
||||||
|
5. The Font Software, modified or unmodified, in part or in whole,
|
||||||
|
must be distributed entirely under this license, and must not be
|
||||||
|
distributed under any other license. The requirement for fonts to
|
||||||
|
remain under this license does not apply to any document created
|
||||||
|
using the Font Software.
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
|
Termination
|
||||||
|
-----------
|
||||||
|
|
||||||
|
This license becomes null and void if any of the above conditions are
|
||||||
|
not met.
|
||||||
|
|
||||||
|
|
||||||
|
DISCLAIMER
|
||||||
|
|
||||||
|
THE FONT SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND,
|
||||||
|
EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO ANY WARRANTIES OF
|
||||||
|
MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT
|
||||||
|
OF COPYRIGHT, PATENT, TRADEMARK, OR OTHER RIGHT. IN NO EVENT SHALL THE
|
||||||
|
COPYRIGHT HOLDER BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY,
|
||||||
|
INCLUDING ANY GENERAL, SPECIAL, INDIRECT, INCIDENTAL, OR CONSEQUENTIAL
|
||||||
|
DAMAGES, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING
|
||||||
|
FROM, OUT OF THE USE OR INABILITY TO USE THE FONT SOFTWARE OR FROM
|
||||||
|
OTHER DEALINGS IN THE FONT SOFTWARE.
|
||||||
Binary file not shown.
Binary file not shown.
+51
-4
@@ -3,7 +3,7 @@
|
|||||||
<head>
|
<head>
|
||||||
<meta charset="utf-8">
|
<meta charset="utf-8">
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1">
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||||
<title>Logstream</title>
|
<title>LogStream</title>
|
||||||
<link rel="icon" href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32'%3E%3Crect width='32' height='32' rx='8' fill='%236366f1'/%3E%3Cpath d='M8 10h16M8 16h11M8 22h14' stroke='white' stroke-width='3' stroke-linecap='round'/%3E%3C/svg%3E">
|
<link rel="icon" href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32'%3E%3Crect width='32' height='32' rx='8' fill='%236366f1'/%3E%3Cpath d='M8 10h16M8 16h11M8 22h14' stroke='white' stroke-width='3' stroke-linecap='round'/%3E%3C/svg%3E">
|
||||||
<link rel="stylesheet" href="style.css">
|
<link rel="stylesheet" href="style.css">
|
||||||
<script>
|
<script>
|
||||||
@@ -20,7 +20,7 @@
|
|||||||
<header class="topbar">
|
<header class="topbar">
|
||||||
<div class="brand">
|
<div class="brand">
|
||||||
<svg viewBox="0 0 32 32" aria-hidden="true"><rect width="32" height="32" rx="8"/><path d="M8 10h16M8 16h11M8 22h14"/></svg>
|
<svg viewBox="0 0 32 32" aria-hidden="true"><rect width="32" height="32" rx="8"/><path d="M8 10h16M8 16h11M8 22h14"/></svg>
|
||||||
<span>Logstream</span>
|
<span>LogStream</span>
|
||||||
</div>
|
</div>
|
||||||
|
|
||||||
<div class="search">
|
<div class="search">
|
||||||
@@ -41,6 +41,10 @@
|
|||||||
<svg class="sun" viewBox="0 0 24 24"><circle cx="12" cy="12" r="4"/><path d="M12 2v2M12 20v2M4.9 4.9l1.4 1.4M17.7 17.7l1.4 1.4M2 12h2M20 12h2M4.9 19.1l1.4-1.4M17.7 6.3l1.4-1.4"/></svg>
|
<svg class="sun" viewBox="0 0 24 24"><circle cx="12" cy="12" r="4"/><path d="M12 2v2M12 20v2M4.9 4.9l1.4 1.4M17.7 17.7l1.4 1.4M2 12h2M20 12h2M4.9 19.1l1.4-1.4M17.7 6.3l1.4-1.4"/></svg>
|
||||||
<svg class="moon" viewBox="0 0 24 24"><path d="M21 12.8A9 9 0 1 1 11.2 3a7 7 0 0 0 9.8 9.8z"/></svg>
|
<svg class="moon" viewBox="0 0 24 24"><path d="M21 12.8A9 9 0 1 1 11.2 3a7 7 0 0 0 9.8 9.8z"/></svg>
|
||||||
</button>
|
</button>
|
||||||
|
<a id="logoutBtn" class="icon-btn" href="/auth/logout" hidden data-i18n-title="logout" data-i18n-aria="logout">
|
||||||
|
<!-- Log out icon (Lucide "log-out", ISC license) -->
|
||||||
|
<svg viewBox="0 0 24 24"><path d="M9 21H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h4"/><path d="m16 17 5-5-5-5"/><path d="M21 12H9"/></svg>
|
||||||
|
</a>
|
||||||
</div>
|
</div>
|
||||||
<div class="progress" aria-hidden="true"></div>
|
<div class="progress" aria-hidden="true"></div>
|
||||||
</header>
|
</header>
|
||||||
@@ -70,6 +74,7 @@
|
|||||||
<option value="" data-i18n="srcAll">All sources</option>
|
<option value="" data-i18n="srcAll">All sources</option>
|
||||||
<option value="syslog">Syslog</option>
|
<option value="syslog">Syslog</option>
|
||||||
<option value="docker">Docker</option>
|
<option value="docker">Docker</option>
|
||||||
|
<option value="host" data-i18n="srcHost">Host system</option>
|
||||||
</select>
|
</select>
|
||||||
<span class="spacer"></span>
|
<span class="spacer"></span>
|
||||||
<span id="count" class="muted"></span>
|
<span id="count" class="muted"></span>
|
||||||
@@ -95,7 +100,17 @@
|
|||||||
<div id="error" class="error-banner" hidden></div>
|
<div id="error" class="error-banner" hidden></div>
|
||||||
<button id="newPill" class="pill" type="button" hidden></button>
|
<button id="newPill" class="pill" type="button" hidden></button>
|
||||||
|
|
||||||
<main id="list" class="list"></main>
|
<div id="table" class="table" hidden>
|
||||||
|
<div id="listHead" class="list-head" role="presentation">
|
||||||
|
<span data-col="rcv"><span class="lbl" data-i18n="colRcv">Received</span><i class="grip" data-i18n-title="colGrip"></i></span>
|
||||||
|
<span data-col="mt"><span class="lbl" data-i18n="colMt">Message time</span><i class="grip" data-i18n-title="colGrip"></i></span>
|
||||||
|
<span data-col="sev"><span class="lbl" data-i18n="colSev">Severity</span><i class="grip" data-i18n-title="colGrip"></i></span>
|
||||||
|
<span data-col="host"><span class="lbl" data-i18n="colHost">Host</span><i class="grip" data-i18n-title="colGrip"></i></span>
|
||||||
|
<span data-col="app"><span class="lbl" data-i18n="colApp">App</span><i class="grip" data-i18n-title="colGrip"></i></span>
|
||||||
|
<span data-col="msg"><span class="lbl" data-i18n="colMsg">Message</span></span>
|
||||||
|
</div>
|
||||||
|
<main id="list" class="list"></main>
|
||||||
|
</div>
|
||||||
<div id="empty" class="empty" hidden>
|
<div id="empty" class="empty" hidden>
|
||||||
<svg viewBox="0 0 24 24" aria-hidden="true"><path d="M4 6h16M4 12h10M4 18h7"/></svg>
|
<svg viewBox="0 0 24 24" aria-hidden="true"><path d="M4 6h16M4 12h10M4 18h7"/></svg>
|
||||||
<p><strong data-i18n="emptyTitle">No matching logs.</strong></p>
|
<p><strong data-i18n="emptyTitle">No matching logs.</strong></p>
|
||||||
@@ -105,6 +120,9 @@
|
|||||||
<footer class="status">
|
<footer class="status">
|
||||||
<span id="conn" class="conn"></span>
|
<span id="conn" class="conn"></span>
|
||||||
<span id="stats" class="muted"></span>
|
<span id="stats" class="muted"></span>
|
||||||
|
<button id="toTop" class="icon-btn to-top" type="button" data-i18n-title="toTop" data-i18n-aria="toTop" hidden>
|
||||||
|
<svg viewBox="0 0 24 24" aria-hidden="true"><path d="M12 19V5M5 12l7-7 7 7"/></svg>
|
||||||
|
</button>
|
||||||
</footer>
|
</footer>
|
||||||
|
|
||||||
<dialog id="settingsDlg" class="settings" aria-labelledby="settingsTitle">
|
<dialog id="settingsDlg" class="settings" aria-labelledby="settingsTitle">
|
||||||
@@ -170,7 +188,17 @@
|
|||||||
<p class="muted small" data-i18n="tagsHelp"></p>
|
<p class="muted small" data-i18n="tagsHelp"></p>
|
||||||
<div id="tagList" class="tag-list"></div>
|
<div id="tagList" class="tag-list"></div>
|
||||||
<footer>
|
<footer>
|
||||||
<button id="addTag" class="btn primary" type="button" data-i18n="addTag">+ Add tag</button>
|
<span class="tag-add">
|
||||||
|
<button id="addTag" class="btn primary" type="button" data-i18n="addTag">+ Add tag</button>
|
||||||
|
<select id="presetTags" class="field" aria-label="Presets" data-i18n-aria="presetAria">
|
||||||
|
<option value="" data-i18n="presetPick">+ Preset…</option>
|
||||||
|
<option value="http_status" data-i18n="preset_http_status">HTTP status codes</option>
|
||||||
|
<option value="http_methods" data-i18n="preset_http_methods">HTTP methods</option>
|
||||||
|
<option value="http_probes" data-i18n="preset_http_probes">Probes and attacks</option>
|
||||||
|
<option value="http_bots" data-i18n="preset_http_bots">Bots and scripts</option>
|
||||||
|
<option value="http_errors" data-i18n="preset_http_errors">TLS/HTTPS and proxy errors</option>
|
||||||
|
</select>
|
||||||
|
</span>
|
||||||
<button id="resetTags" class="btn ghost" type="button" data-i18n="resetTags">Restore default tags</button>
|
<button id="resetTags" class="btn ghost" type="button" data-i18n="resetTags">Restore default tags</button>
|
||||||
</footer>
|
</footer>
|
||||||
</section>
|
</section>
|
||||||
@@ -196,6 +224,16 @@
|
|||||||
</div>
|
</div>
|
||||||
</section>
|
</section>
|
||||||
|
|
||||||
|
<section class="set-section">
|
||||||
|
<h3 data-i18n="hostTitle">Host system logs</h3>
|
||||||
|
<p id="hostStatus" class="docker-status"></p>
|
||||||
|
<label class="switch-row">
|
||||||
|
<input id="hostEnabled" type="checkbox" class="switch">
|
||||||
|
<span data-i18n="hostEnabled">Collect the system logs of this machine</span>
|
||||||
|
</label>
|
||||||
|
<p class="muted small" data-i18n="hostHelp"></p>
|
||||||
|
</section>
|
||||||
|
|
||||||
<section class="set-section">
|
<section class="set-section">
|
||||||
<h3 data-i18n="dockerTitle">Docker containers</h3>
|
<h3 data-i18n="dockerTitle">Docker containers</h3>
|
||||||
<p id="dockerStatus" class="docker-status"></p>
|
<p id="dockerStatus" class="docker-status"></p>
|
||||||
@@ -243,11 +281,20 @@
|
|||||||
<button type="button" role="radio" data-size="medium" data-i18n="sizeMedium">Medium</button>
|
<button type="button" role="radio" data-size="medium" data-i18n="sizeMedium">Medium</button>
|
||||||
<button type="button" role="radio" data-size="large" data-i18n="sizeLarge">Large</button>
|
<button type="button" role="radio" data-size="large" data-i18n="sizeLarge">Large</button>
|
||||||
</div>
|
</div>
|
||||||
|
<span class="lbl" data-i18n="density">Density</span>
|
||||||
|
<div id="densitySwitch" class="seg" role="radiogroup" data-i18n-aria="density">
|
||||||
|
<button type="button" role="radio" data-density="normal" data-i18n="densityNormal">Normal</button>
|
||||||
|
<button type="button" role="radio" data-density="compact" data-i18n="densityCompact">Compact</button>
|
||||||
|
</div>
|
||||||
<label for="fontSelect" data-i18n="fontLabel">Font</label>
|
<label for="fontSelect" data-i18n="fontLabel">Font</label>
|
||||||
<select id="fontSelect" class="field"></select>
|
<select id="fontSelect" class="field"></select>
|
||||||
</div>
|
</div>
|
||||||
<div id="fontPreview" class="list preview-list" aria-hidden="true"></div>
|
<div id="fontPreview" class="list preview-list" aria-hidden="true"></div>
|
||||||
<p class="muted small" data-i18n="fontHelp"></p>
|
<p class="muted small" data-i18n="fontHelp"></p>
|
||||||
|
<div class="cols-row">
|
||||||
|
<button id="resetCols" class="btn ghost" type="button" data-i18n="resetCols">Reset column widths</button>
|
||||||
|
<span class="muted small" data-i18n="colsHelp"></span>
|
||||||
|
</div>
|
||||||
</section>
|
</section>
|
||||||
<section class="set-section">
|
<section class="set-section">
|
||||||
<h3 data-i18n="histoTitle">Timeline</h3>
|
<h3 data-i18n="histoTitle">Timeline</h3>
|
||||||
|
|||||||
@@ -0,0 +1,95 @@
|
|||||||
|
<!doctype html>
|
||||||
|
<html lang="en">
|
||||||
|
<head>
|
||||||
|
<meta charset="utf-8">
|
||||||
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
||||||
|
<title>LogStream</title>
|
||||||
|
<link rel="icon" href="data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 32 32'%3E%3Crect width='32' height='32' rx='8' fill='%236366f1'/%3E%3Cpath d='M8 10h16M8 16h11M8 22h14' stroke='white' stroke-width='3' stroke-linecap='round'/%3E%3C/svg%3E">
|
||||||
|
<link rel="stylesheet" href="style.css">
|
||||||
|
<script>
|
||||||
|
// Same saved theme and language as the UI, applied before first paint.
|
||||||
|
try {
|
||||||
|
var t = localStorage.getItem('logstream.theme');
|
||||||
|
if (t === 'light' || t === 'dark') document.documentElement.dataset.theme = t;
|
||||||
|
var l = localStorage.getItem('logstream.lang');
|
||||||
|
if (l) document.documentElement.lang = l;
|
||||||
|
} catch (e) {}
|
||||||
|
</script>
|
||||||
|
</head>
|
||||||
|
<body class="login-page">
|
||||||
|
<div class="login-tools">
|
||||||
|
<div class="seg" role="radiogroup" id="langSwitch">
|
||||||
|
<button type="button" role="radio" data-lang="fr">FR</button>
|
||||||
|
<button type="button" role="radio" data-lang="en">EN</button>
|
||||||
|
</div>
|
||||||
|
<button id="themeBtn" class="icon-btn" type="button" data-i18n-title="theme" data-i18n-aria="theme">
|
||||||
|
<svg class="sun" viewBox="0 0 24 24"><circle cx="12" cy="12" r="4"/><path d="M12 2v2M12 20v2M4.9 4.9l1.4 1.4M17.7 17.7l1.4 1.4M2 12h2M20 12h2M4.9 19.1l1.4-1.4M17.7 6.3l1.4-1.4"/></svg>
|
||||||
|
<svg class="moon" viewBox="0 0 24 24"><path d="M21 12.8A9 9 0 1 1 11.2 3a7 7 0 0 0 9.8 9.8z"/></svg>
|
||||||
|
</button>
|
||||||
|
</div>
|
||||||
|
|
||||||
|
<main class="login-card">
|
||||||
|
<img id="logo" class="login-logo" src="auth/logo" alt="" hidden>
|
||||||
|
<div class="brand">
|
||||||
|
<svg viewBox="0 0 32 32" aria-hidden="true"><rect width="32" height="32" rx="8"/><path d="M8 10h16M8 16h11M8 22h14"/></svg>
|
||||||
|
<span>LogStream</span>
|
||||||
|
</div>
|
||||||
|
<p class="muted" data-i18n="intro">Sign in to view the logs.</p>
|
||||||
|
|
||||||
|
<form method="post" action="auth/login">
|
||||||
|
<input type="hidden" name="r" id="ret">
|
||||||
|
<label for="user" data-i18n="user">User</label>
|
||||||
|
<input id="user" name="user" type="text" autocomplete="username" autocapitalize="none" spellcheck="false" required autofocus>
|
||||||
|
<label for="pass" data-i18n="pass">Password</label>
|
||||||
|
<input id="pass" name="pass" type="password" autocomplete="current-password" required>
|
||||||
|
<p id="err" class="login-err" role="alert" data-i18n="error" hidden>Wrong user or password.</p>
|
||||||
|
<button class="btn primary" type="submit" data-i18n="submit">Sign in</button>
|
||||||
|
</form>
|
||||||
|
</main>
|
||||||
|
|
||||||
|
<script>
|
||||||
|
(function () {
|
||||||
|
var I18N = {
|
||||||
|
en: { intro: 'Sign in to view the logs.', user: 'User', pass: 'Password', submit: 'Sign in',
|
||||||
|
error: 'Wrong user or password.', theme: 'Light / dark theme' },
|
||||||
|
fr: { intro: 'Connectez-vous pour consulter les logs.', user: 'Utilisateur', pass: 'Mot de passe',
|
||||||
|
submit: 'Se connecter', error: 'Utilisateur ou mot de passe incorrect.', theme: 'Thème clair / sombre' },
|
||||||
|
};
|
||||||
|
function get(k) { try { return localStorage.getItem('logstream.' + k); } catch (e) { return null; } }
|
||||||
|
function set(k, v) { try { localStorage.setItem('logstream.' + k, v); } catch (e) {} }
|
||||||
|
var lang = get('lang');
|
||||||
|
if (!I18N[lang]) lang = /^fr\b/i.test(navigator.language || '') ? 'fr' : 'en';
|
||||||
|
|
||||||
|
function applyLang() {
|
||||||
|
var d = I18N[lang];
|
||||||
|
document.documentElement.lang = lang;
|
||||||
|
document.querySelectorAll('[data-i18n]').forEach(function (el) { el.textContent = d[el.dataset.i18n]; });
|
||||||
|
document.querySelectorAll('[data-i18n-title]').forEach(function (el) { el.title = d[el.dataset.i18nTitle]; });
|
||||||
|
document.querySelectorAll('[data-i18n-aria]').forEach(function (el) { el.setAttribute('aria-label', d[el.dataset.i18nAria]); });
|
||||||
|
document.querySelectorAll('#langSwitch [data-lang]').forEach(function (b) { b.setAttribute('aria-checked', String(b.dataset.lang === lang)); });
|
||||||
|
}
|
||||||
|
document.querySelectorAll('#langSwitch [data-lang]').forEach(function (b) {
|
||||||
|
b.addEventListener('click', function () { lang = b.dataset.lang; set('lang', lang); applyLang(); });
|
||||||
|
});
|
||||||
|
|
||||||
|
document.getElementById('themeBtn').addEventListener('click', function () {
|
||||||
|
var root = document.documentElement;
|
||||||
|
var dark = root.dataset.theme ? root.dataset.theme === 'dark' : matchMedia('(prefers-color-scheme: dark)').matches;
|
||||||
|
root.dataset.theme = dark ? 'light' : 'dark';
|
||||||
|
set('theme', root.dataset.theme);
|
||||||
|
});
|
||||||
|
|
||||||
|
var q = new URLSearchParams(location.search);
|
||||||
|
document.getElementById('ret').value = q.get('r') || '/';
|
||||||
|
document.getElementById('err').hidden = q.get('e') !== '1';
|
||||||
|
|
||||||
|
// LOGIN_LOGO: shown only when the server has one.
|
||||||
|
var logo = document.getElementById('logo');
|
||||||
|
logo.addEventListener('load', function () { logo.hidden = false; });
|
||||||
|
if (logo.complete && logo.naturalWidth) logo.hidden = false;
|
||||||
|
|
||||||
|
applyLang();
|
||||||
|
})();
|
||||||
|
</script>
|
||||||
|
</body>
|
||||||
|
</html>
|
||||||
+85
-6
@@ -1,3 +1,8 @@
|
|||||||
|
/* Iosevka (SIL OFL, web/fonts/OFL-Iosevka.txt): a narrow monospace font served by LogStream
|
||||||
|
itself, so it also works offline. Latin subset only; other scripts fall back to --mono. */
|
||||||
|
@font-face { font-family: "Iosevka"; src: url("fonts/iosevka-400.woff2") format("woff2"); font-weight: 400 500; font-display: swap; }
|
||||||
|
@font-face { font-family: "Iosevka"; src: url("fonts/iosevka-700.woff2") format("woff2"); font-weight: 600 800; font-display: swap; }
|
||||||
|
|
||||||
/* ---------- Theme: everything goes through these variables ---------- */
|
/* ---------- Theme: everything goes through these variables ---------- */
|
||||||
:root {
|
:root {
|
||||||
--bg: #f6f7f9;
|
--bg: #f6f7f9;
|
||||||
@@ -296,6 +301,39 @@ body.busy .progress::after {
|
|||||||
.list { margin: 6px 20px 0; background: var(--panel); border: 1px solid var(--border); border-radius: var(--radius); overflow: hidden; }
|
.list { margin: 6px 20px 0; background: var(--panel); border: 1px solid var(--border); border-radius: var(--radius); overflow: hidden; }
|
||||||
.list:empty { display: none; }
|
.list:empty { display: none; }
|
||||||
|
|
||||||
|
/* Columns: received, message time, severity, host, app, message. Widths come from
|
||||||
|
--col-* (set on #table when a column has been resized, see app.js), shared by
|
||||||
|
the header and every row through subgrid so that the columns line up. */
|
||||||
|
.table {
|
||||||
|
display: grid;
|
||||||
|
grid-template-columns: var(--col-rcv, max-content) var(--col-mt, max-content) var(--col-sev, 4.6rem)
|
||||||
|
var(--col-host, minmax(5rem, 9rem)) var(--col-app, minmax(4rem, 8rem)) minmax(0, 1fr);
|
||||||
|
column-gap: 12px;
|
||||||
|
margin: 6px 20px 0; background: var(--panel); border: 1px solid var(--border); border-radius: var(--radius);
|
||||||
|
overflow: clip; /* rounded corners without breaking the sticky header (hidden would) */
|
||||||
|
}
|
||||||
|
.table[hidden] { display: none; }
|
||||||
|
.table .list {
|
||||||
|
display: grid; grid-template-columns: subgrid; grid-column: 1 / -1;
|
||||||
|
margin: 0; border: 0; border-radius: 0; background: none; overflow: visible;
|
||||||
|
}
|
||||||
|
.table .row { grid-template-columns: subgrid; grid-column: 1 / -1; }
|
||||||
|
.list-head {
|
||||||
|
display: grid; grid-template-columns: subgrid; grid-column: 1 / -1;
|
||||||
|
position: sticky; top: var(--topbar-h, 0px); z-index: 5;
|
||||||
|
padding: 0 14px 0 11px; border-left: 3px solid transparent;
|
||||||
|
background: var(--panel-2); border-bottom: 1px solid var(--border);
|
||||||
|
font-size: 10.5px; font-weight: 650; letter-spacing: .04em; text-transform: uppercase; color: var(--muted);
|
||||||
|
}
|
||||||
|
.list-head > span { position: relative; min-width: 0; padding: 4px 0; }
|
||||||
|
/* Labels never widen a column (contain: inline-size), they are cut instead */
|
||||||
|
.list-head .lbl { display: block; contain: inline-size; overflow: hidden; text-overflow: ellipsis; white-space: nowrap; font: inherit; }
|
||||||
|
.list-head .grip { position: absolute; top: 0; bottom: 0; right: -9px; width: 6px; z-index: 1; cursor: col-resize; touch-action: none; }
|
||||||
|
.list-head .grip::after { content: ""; position: absolute; left: 2px; top: 25%; bottom: 25%; border-left: 1px solid var(--border); }
|
||||||
|
.list-head .grip:hover::after, .list-head .grip.active::after { top: 0; bottom: 0; border-left: 2px solid var(--accent); left: 2px; }
|
||||||
|
body.col-resizing, body.col-resizing * { cursor: col-resize !important; user-select: none; -webkit-user-select: none; }
|
||||||
|
.cols-row { display: flex; flex-wrap: wrap; align-items: center; gap: 6px 12px; margin-top: 12px; }
|
||||||
|
|
||||||
.row {
|
.row {
|
||||||
display: grid;
|
display: grid;
|
||||||
grid-template-columns: max-content max-content 4.6rem minmax(5rem, 9rem) minmax(4rem, 8rem) 1fr;
|
grid-template-columns: max-content max-content 4.6rem minmax(5rem, 9rem) minmax(4rem, 8rem) 1fr;
|
||||||
@@ -308,12 +346,16 @@ body.busy .progress::after {
|
|||||||
cursor: pointer;
|
cursor: pointer;
|
||||||
}
|
}
|
||||||
.row:last-child { border-bottom: 0; }
|
.row:last-child { border-bottom: 0; }
|
||||||
|
/* Settings > Interface > Density: compact fits about 50% more lines on screen */
|
||||||
|
:root[data-density="compact"] .row { padding-top: 1px; padding-bottom: 1px; line-height: 1.25; }
|
||||||
|
:root[data-density="compact"] .row .sev { padding-top: 0; padding-bottom: 0; line-height: 1.3; }
|
||||||
.row:hover { background: var(--row-hover); }
|
.row:hover { background: var(--row-hover); }
|
||||||
.row:focus-visible { outline: 2px solid var(--accent); outline-offset: -2px; }
|
.row:focus-visible { outline: 2px solid var(--accent); outline-offset: -2px; }
|
||||||
.row.new { animation: flash 1.2s ease-out; }
|
.row.new { animation: flash 1.2s ease-out; }
|
||||||
@keyframes flash { from { background: var(--accent-soft); } to { background: transparent; } }
|
@keyframes flash { from { background: var(--accent-soft); } to { background: transparent; } }
|
||||||
|
|
||||||
.row time { color: var(--muted); white-space: nowrap; font-variant-numeric: tabular-nums; }
|
.row > * { min-width: 0; }
|
||||||
|
.row time { color: var(--muted); white-space: nowrap; font-variant-numeric: tabular-nums; overflow: hidden; text-overflow: ellipsis; }
|
||||||
.row time.rcv { color: var(--text); }
|
.row time.rcv { color: var(--text); }
|
||||||
.row time .ms { opacity: .6; }
|
.row time .ms { opacity: .6; }
|
||||||
.row .host, .row .app { overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
|
.row .host, .row .app { overflow: hidden; text-overflow: ellipsis; white-space: nowrap; }
|
||||||
@@ -322,7 +364,7 @@ body.busy .progress::after {
|
|||||||
.row .msg { white-space: pre-wrap; word-break: break-word; min-width: 0; }
|
.row .msg { white-space: pre-wrap; word-break: break-word; min-width: 0; }
|
||||||
|
|
||||||
.sev {
|
.sev {
|
||||||
justify-self: start;
|
justify-self: start; max-width: 100%; overflow: hidden; text-overflow: ellipsis;
|
||||||
font-size: 10.5px; font-weight: 700; text-transform: uppercase; letter-spacing: .03em;
|
font-size: 10.5px; font-weight: 700; text-transform: uppercase; letter-spacing: .03em;
|
||||||
padding: 1px 6px; border-radius: 5px;
|
padding: 1px 6px; border-radius: 5px;
|
||||||
color: var(--sev); background: color-mix(in srgb, var(--sev) 14%, transparent);
|
color: var(--sev); background: color-mix(in srgb, var(--sev) 14%, transparent);
|
||||||
@@ -391,6 +433,10 @@ mark.hit { background: var(--hit); color: inherit; border-radius: 3px; padding:
|
|||||||
.conn.ok::before { color: var(--sev-info); }
|
.conn.ok::before { color: var(--sev-info); }
|
||||||
.conn.ko::before { color: var(--sev-err); }
|
.conn.ko::before { color: var(--sev-err); }
|
||||||
#stats .bad { color: var(--sev-err); }
|
#stats .bad { color: var(--sev-err); }
|
||||||
|
/* "Back to top", at the right end of the status bar: never over a log row */
|
||||||
|
.to-top { width: 24px; height: 24px; margin: -5px -6px -5px auto; flex: none; } /* no taller bar */
|
||||||
|
.to-top svg { width: 16px; height: 16px; }
|
||||||
|
.to-top[hidden] { display: none; }
|
||||||
|
|
||||||
.toast {
|
.toast {
|
||||||
position: fixed; bottom: 48px; left: 50%; transform: translateX(-50%); z-index: 50;
|
position: fixed; bottom: 48px; left: 50%; transform: translateX(-50%); z-index: 50;
|
||||||
@@ -540,6 +586,8 @@ input.switch:disabled { cursor: not-allowed; }
|
|||||||
input.switch:focus-visible { outline: 2px solid var(--accent); outline-offset: 2px; }
|
input.switch:focus-visible { outline: 2px solid var(--accent); outline-offset: 2px; }
|
||||||
|
|
||||||
.set-section footer { display: flex; flex-wrap: wrap; gap: 8px; justify-content: space-between; margin-top: 14px; }
|
.set-section footer { display: flex; flex-wrap: wrap; gap: 8px; justify-content: space-between; margin-top: 14px; }
|
||||||
|
.tag-add { display: flex; flex-wrap: wrap; gap: 8px; }
|
||||||
|
.tag-add select.field { width: auto; }
|
||||||
|
|
||||||
.seg { display: inline-flex; padding: 3px; gap: 3px; background: var(--panel-2); border: 1px solid var(--border); border-radius: 10px; }
|
.seg { display: inline-flex; padding: 3px; gap: 3px; background: var(--panel-2); border: 1px solid var(--border); border-radius: 10px; }
|
||||||
.seg button {
|
.seg button {
|
||||||
@@ -593,8 +641,12 @@ input.switch:focus-visible { outline: 2px solid var(--accent); outline-offset: 2
|
|||||||
#count { flex: 1 1 50%; min-width: 0; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; }
|
#count { flex: 1 1 50%; min-width: 0; white-space: nowrap; overflow: hidden; text-overflow: ellipsis; }
|
||||||
.histo { padding: 0 16px 6px; }
|
.histo { padding: 0 16px 6px; }
|
||||||
.h-leg { display: none; }
|
.h-leg { display: none; }
|
||||||
.list, .error-banner { margin-left: 16px; margin-right: 16px; }
|
.list, .error-banner, .table { margin-left: 16px; margin-right: 16px; }
|
||||||
.row {
|
/* Phones: no columns, two lines per log (layout below); the widths do not apply */
|
||||||
|
.table { display: block; }
|
||||||
|
.table .list { display: block; margin: 0; }
|
||||||
|
.list-head { display: none; }
|
||||||
|
.row, .table .row {
|
||||||
grid-template-columns: auto auto 1fr;
|
grid-template-columns: auto auto 1fr;
|
||||||
grid-template-areas: "rcv sev host" "msg msg msg";
|
grid-template-areas: "rcv sev host" "msg msg msg";
|
||||||
gap: 3px 8px; padding: 8px 12px 8px 10px;
|
gap: 3px 8px; padding: 8px 12px 8px 10px;
|
||||||
@@ -621,8 +673,9 @@ input.switch:focus-visible { outline: 2px solid var(--accent); outline-offset: 2
|
|||||||
}
|
}
|
||||||
.set-nav button span { max-width: 100%; overflow: hidden; text-overflow: ellipsis; }
|
.set-nav button span { max-width: 100%; overflow: hidden; text-overflow: ellipsis; }
|
||||||
.set-panels { padding: 0 16px 18px; }
|
.set-panels { padding: 0 16px 18px; }
|
||||||
#sizeSwitch { display: flex; }
|
#sizeSwitch, #densitySwitch { display: flex; }
|
||||||
#sizeSwitch button { flex: 1; padding: 0 4px; white-space: nowrap; font-size: 12px; }
|
#sizeSwitch button, #densitySwitch button { flex: 1; padding: 0 4px; white-space: nowrap; font-size: 12px; }
|
||||||
|
:root[data-density="compact"] .row { padding-top: 3px; padding-bottom: 3px; }
|
||||||
.field-grid select { margin-bottom: 6px; }
|
.field-grid select { margin-bottom: 6px; }
|
||||||
.status { padding: 6px 16px; }
|
.status { padding: 6px 16px; }
|
||||||
.tag-row { grid-template-columns: 38px 1fr 36px; }
|
.tag-row { grid-template-columns: 38px 1fr 36px; }
|
||||||
@@ -630,3 +683,29 @@ input.switch:focus-visible { outline: 2px solid var(--accent); outline-offset: 2
|
|||||||
.tag-row .opts { grid-column: 1 / -1; grid-row: 2; flex-wrap: wrap; }
|
.tag-row .opts { grid-column: 1 / -1; grid-row: 2; flex-wrap: wrap; }
|
||||||
.tag-row [data-del] { grid-column: 3; grid-row: 1; }
|
.tag-row [data-del] { grid-column: 3; grid-row: 1; }
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* ---------- Login page (AUTH_MODE=local) ---------- */
|
||||||
|
body.login-page {
|
||||||
|
min-height: 100vh; padding: 16px;
|
||||||
|
display: grid; place-items: center;
|
||||||
|
}
|
||||||
|
.login-tools { position: fixed; top: 12px; right: 16px; display: flex; align-items: center; gap: 8px; }
|
||||||
|
.login-card {
|
||||||
|
width: 100%; max-width: 360px;
|
||||||
|
display: flex; flex-direction: column; align-items: center; gap: 10px;
|
||||||
|
padding: 32px 28px 28px;
|
||||||
|
background: var(--panel); border: 1px solid var(--border); border-radius: 14px; box-shadow: var(--shadow);
|
||||||
|
}
|
||||||
|
.login-logo { max-width: 200px; max-height: 96px; object-fit: contain; margin-bottom: 6px; }
|
||||||
|
.login-card .brand { font-size: 20px; }
|
||||||
|
.login-card .brand svg { width: 32px; height: 32px; }
|
||||||
|
.login-card > p { margin: 0 0 8px; text-align: center; }
|
||||||
|
.login-card form { width: 100%; display: flex; flex-direction: column; gap: 6px; }
|
||||||
|
.login-card label { font-size: 13px; font-weight: 550; }
|
||||||
|
.login-card input {
|
||||||
|
height: 38px; padding: 0 11px; margin-bottom: 6px;
|
||||||
|
border: 1px solid var(--border); border-radius: 9px; background: var(--bg);
|
||||||
|
}
|
||||||
|
.login-card input:focus { outline: 0; border-color: var(--accent); box-shadow: 0 0 0 3px var(--accent-soft); }
|
||||||
|
.login-card .btn.primary { height: 38px; justify-content: center; margin-top: 6px; font-size: 14px; }
|
||||||
|
.login-err { margin: 0; color: var(--sev-err); font-size: 13px; }
|
||||||
Reference in new issue
Block a user