Commit Graph
17 Commits
Author SHA1 Message Date
Keli GrubbandMadison Grubb cfac12b699 chore(deps): update dependencies and fix security vulnerabilities (#44)
Push / release (push) Successful in 12s
Push / publish (push) Successful in 37s
## Summary

Updates all out-of-date dependencies and applies `npm audit fix` to resolve 14 security vulnerabilities (3 critical, 8 high).

### Dependency Updates

| Package | Current → Latest |
|---|---|
| `nuxt` | 4.4.8 → 4.5.2 |
| `mediasoup` | 3.20.9 → 3.24.2 |
| `mediasoup-client` | 3.21.0 → 3.22.0 |
| `hls.js` | 1.6.16 → 1.7.0 |
| `vue` | 3.5.38 → 3.5.41 |
| `vue-router` | 5.1.0 → 5.2.0 |
| `@nuxt/icon` | 2.2.3 → 2.5.0 |
| `eslint` | 10.5.0 → 10.8.1 |
| `vitest` / `@vitest/coverage-v8` | 4.1.9 → 4.1.10 |
| `ws` | 8.21.0 → 8.21.3 |
| `openid-client` | 6.8.4 → 6.8.5 |
| `fast-xml-parser` | 5.9.3 → 5.10.1 |
| `happy-dom` | 20.10.6 → 20.11.2 |
| `@playwright/test` | 1.61.1 → 1.62.1 |
| `@nuxt/eslint` | 1.16.0 → 1.17.0 |
| `@nuxt/test-utils` | 4.0.3 → 4.1.0 |
| `@iconify-json/tabler` | 1.2.35 → 1.2.38 |

### Security Audit Fixes (`npm audit fix`)

- **`@nuxt/devtools`** (critical): Unauthenticated DevTools RPC allows arbitrary command execution on the developer's host
- **`tar`** (critical): Multiple process-crash/DoS vulnerabilities via crafted tar archives
- **`esbuild`** (high): Arbitrary file read when running dev server on Windows
- **`brace-expansion`** (high): Multiple DoS vectors (memory exhaustion, process hang)
- **`flatted`** (high): Prototype pollution via `parse()`
- **`svgo`** (high): `removeScripts` plugin leaves executable scripts intact

### Verification

- All 406 tests pass (3 skipped)
- Lint clean (`eslint . --max-warnings 0`)
- `npm audit` reports 0 vulnerabilities

---------

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #44
2026-08-14 22:27:36 +00:00
Keli GrubbandMadison Grubb bb01e9a06c Add ADS-B, AIS, and ALPR map layers with live CoT streaming (#36)
Push / release (push) Successful in 13s
Push / publish (push) Successful in 1m4s
## Summary

- **ADS-B & AIS:** OpenSky and AISStream OSINT feeds upsert into the CoT store; tactical tracks still arrive via adsbcot/aiscot on `:8089`. Map clients subscribe via `GET /api/cot/stream` (SSE) with viewport bbox filtering and Air / Surface / Team layer toggles.
- **ALPR (Flock/OSM):** Toggleable license-plate reader layer sourced from OpenStreetMap, with SQLite cache, Overpass fallback, tiled viewport fetching, and clustered markers with direction cones.
- **Map performance:** Ring-based tile selection (fixes zoom-out crash), immutable tile cache, incremental marker sync, split cluster load/query, and padded SSE bbox to reduce reconnect churn.

## Docs

- `docs/tracking.md` — ADS-B/AIS accuracy tiers, freshness, self-hosted receivers, optional OSINT API keys
- `docs/map-and-cameras.md` — ALPR layer and map behavior updates

---------

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #36
2026-06-24 20:54:50 +00:00
Keli Grubb fded3a04d4 ci: split push release/publish and harden workflows (#27)
Push / release (push) Successful in 47s
Push / publish (push) Successful in 1m0s
### Added
* Separate release from Docker/Helm publish
* enrich releases with PRbodies when available
* tighten release.sh validation and idempotency
* trim PR docker-build metadata for act-runner stability

Reviewed-on: #27
Co-authored-by: keligrubb <keligrubb324@gmail.com>
Co-committed-by: keligrubb <keligrubb324@gmail.com>
2026-04-15 03:03:04 +00:00
Keli Grubb 78f3ad8fcc Remove npm overrides for tar (#26)
Push / release-docker-helm (push) Successful in 4m21s
Drop the package.json overrides entry so transitive tar versions follow
what dependencies resolve. Refresh package-lock.json after npm install.

Reviewed-on: #26
Co-authored-by: keligrubb <keligrubb324@gmail.com>
Co-committed-by: keligrubb <keligrubb324@gmail.com>
2026-04-15 02:32:49 +00:00
Keli Grubb 0ecad475ef patch: fix release file (#22)
Push / release-docker-helm (push) Successful in 4m16s
Reviewed-on: #22
2026-03-12 19:39:15 +00:00
Keli Grubb d5789b79a6 patch: swap to stdlib sqlite3 (#21)
Push / release-docker-helm (push) Failing after 2m39s
Reviewed-on: #21
2026-03-12 19:17:26 +00:00
Keli GrubbandMadison Grubb 1da69ac272 patch: fix docker login during push stage (#18)
Push / release-docker-helm (push) Successful in 4m24s
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #18
2026-03-05 15:34:32 +00:00
Keli GrubbandMadison Grubb afb6fb8ac7 patch: fix deploy pipeline stages for token registry uploads (#17)
Push / release-docker-helm (push) Failing after 2m56s
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #17
2026-03-05 14:52:10 +00:00
Keli GrubbandMadison Grubb 10035221fb patch: fix deploy pipeline (#15)
Push / release-docker-helm (push) Failing after 2m15s
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #15
2026-03-04 20:01:50 +00:00
Keli GrubbandMadison Grubb 52a6f4368c patch: migrate to gitea actions (#14)
Push / release-docker-helm (push) Failing after 2s
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #14
2026-03-04 19:49:16 +00:00
Keli Grubb 68082fd893 patch: fix ci parallelism (#8)
Reviewed-on: #8
Co-authored-by: keligrubb <keligrubb324@gmail.com>
Co-committed-by: keligrubb <keligrubb324@gmail.com>
2026-02-22 03:11:23 +00:00
Keli GrubbandMadison Grubb e61e6bc7e3 major: kestrel is now a tak server (#6)
ci/woodpecker/push/push Pipeline was successful
## Added

- CoT (Cursor on Target) server on port 8089 enabling ATAK/iTAK device connectivity
- Support for TAK stream protocol and traditional XML CoT messages
- TLS/SSL support with automatic fallback to plain TCP
- Username/password authentication for CoT connections
- Real-time device position tracking with TTL-based expiration (90s default)
- API endpoints: `/api/cot/config`, `/api/cot/server-package`, `/api/cot/truststore`, `/api/me/cot-password`
- TAK Server section in Settings with QR code for iTAK setup
- ATAK password management in Account page for OIDC users
- CoT device markers on map showing real-time positions
- Comprehensive documentation in `docs/` directory
- Environment variables: `COT_PORT`, `COT_TTL_MS`, `COT_REQUIRE_AUTH`, `COT_SSL_CERT`, `COT_SSL_KEY`, `COT_DEBUG`
- Dependencies: `fast-xml-parser`, `jszip`, `qrcode`

## Changed

- Authentication system supports CoT password management for OIDC users
- Database schema includes `cot_password_hash` field
- Test suite refactored to follow functional design principles

## Removed

- Consolidated utility modules: `authConfig.js`, `authSkipPaths.js`, `bootstrap.js`, `poiConstants.js`, `session.js`

## Security

- XML entity expansion protection in CoT parser
- Enhanced input validation and SQL injection prevention
- Authentication timeout to prevent hanging connections

## Breaking Changes

- Port 8089 must be exposed for CoT server. Update firewall rules and Docker/Kubernetes configurations.

## Migration Notes

- OIDC users must set ATAK password via Account settings before connecting
- Docker: expose port 8089 (`-p 8089:8089`)
- Kubernetes: update Helm values to expose port 8089

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #6
2026-02-17 16:41:41 +00:00
Keli GrubbandMadison Grubb 0aab29ea72 minor: new nav system (#5)
ci/woodpecker/push/push Pipeline was successful
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #5
2026-02-15 04:04:54 +00:00
Keli GrubbandMadison Grubb 17f28401ba minor: heavily simplify server and app content. unify styling (#4)
ci/woodpecker/push/push Pipeline was successful
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #4
2026-02-14 04:52:18 +00:00
Keli GrubbandMadison Grubb a302a4a1a0 minor: add a new release system (#3)
ci/woodpecker/push/push Pipeline was successful
# Changes

* package and release helm charts for the project
* configure a new release system based of semver
* add changelog entries via keep-a-changelog formatting
* add gitea releases

Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #3
2026-02-12 22:07:53 +00:00
Keli GrubbandMadison Grubb 547b94bac8 fix malformed path in docker publish (#2)
ci/woodpecker/push/push Pipeline was successful
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #2
2026-02-12 20:27:03 +00:00
Keli GrubbandMadison Grubb 28ac43e47b add ci (#1)
ci/woodpecker/push/ci Pipeline failed
Co-authored-by: Madison Grubb <madison@elastiflow.com>
Reviewed-on: #1
2026-02-12 19:50:44 +00:00