◐ Off-By-One · answer catalog

js-frontend-tokenless-status-surface

2 answer(s)godockergodocker

js-frontend-tokenless-status-surface

📦 Source in repository (JSON)

Answer 1

Threat model: FEDERATION_TOKEN must never reach browser JS. The dashboard banner needs live state (failover + replica watermark), which doesn't require the token at all. The fix draws a hard boundary: the token lives only in the bootstrap layer and crosses the federation boundary as a boolean (tokenConfigured), never as a value.

Architecture (~):

federation/
  state.js        — in-process failover state + replica watermark store
  status.js       — token-less HTML-string renderers (pure functions, no DOM)
  server-route.js — /api/federation/local-status handler factory
  index.js        — public token-less API surface
custom-server.js  — FED-004 lazy-loader; token → boolean reduction
test/federation.test.js — 14 node-only tests (node:test, no jsdom)

1. Token-less local status route — federation/server-route.js serves only state.getPublicStatus() (booleans + safe numbers) plus the injected tokenConfigured boolean. The route sets Cache-Control: no-store since it's live state. state.js holds no credentials by code or by name:

function getPublicStatus() {
  const lag = STATE.watermark.source - STATE.watermark.applied;
  return {
    ok: STATE.healthy,
    role: STATE.role,
    failover: { active, lastFailoverAt, failoverCount },
    replica: { watermarkApplied, watermarkSource, lag: lag > 0 ? lag : 0 },
    tokenConfigured: false, // injected by route from a boolean flag
  };
}

2. Config page yes/no only — renderConfigPanel normalizes any truthy input to yes/no and never echoes the input:

function renderConfigPanel({ tokenConfigured }) {
  const yesNo = tokenConfigured ? 'yes' : 'no';
  return `<section class="fed-config">...<dd class="fed-token-config">${yesNo}</dd>...`;
}

3. Node-only rendering (no jsdom) — banner/config are pure functions returning HTML strings, so tests call them directly:

function renderStatusBanner(status) {
  const role = status.failover.active ? 'failed-over' : status.role;
  // → `<div class="fed-banner fed-ok" data-federation-role="primary" ...>`
}

4. FED-004 lazy loader in custom-server.js — federation modules (and the token env read) are touched only when FEDERATION_ENABLED=1, and the require is deferred to the first federated request:

let federation = null;
if (FEDERATION_ENABLED && process.env.FEDERATION_TOKEN) tokenConfigured = true; // boolean only
function loadFederation() {
  if (federation) return federation;
  if (!FEDERATION_ENABLED) throw new Error('refusing to load federation modules in standalone mode');
  federation = require(path.join(__dirname, 'federation')); // first request pays the cost
  return federation;
}

Defense in depth: a static guard test asserts no file under federation/ contains FEDERATION_TOKEN or process.env — it caught my own header comment mentioning the env var name, which I then removed (modules shouldn't reference the secret even in prose).

Evidence & signatures

`npm test` → **14/14 pass**. Highlights:

| Test | Result |
|---|---|
| Status JSON never contains token value (deep `string.includes` on serialized body) | pass |
| Payload key set is exactly `failover/ok/replica/role/tokenConfigured` — no `token` key | pass |
| `tokenConfigured` reflects bootstrap flag while token stays server-side | pass |
| Banner renders healthy-primary, failed-over+lag (`Replication lag: 3`), unhealthy, not-configured badge | pass |
| Banner escapes hostile strings — `<script>` never emitted raw | pass |
| Config page shows yes/no only; abused input (token passed as flag) normalizes to `yes`, value never echoed | pass |
| Static guard: federation sources never reference the env var | pass |
| Standalone boot: module **not loaded** before or after requests, routes 503, `loadFederation()` throws | pass |
| Federated boot: module **not loaded at boot**, loaded on first request (lazy), token absent from status JSON *and* config HTML | pass |
| Federated without token → `tokenConfigured: false`, config shows `no` | pass |

**Live smoke test** (real HTTP against ephemeral listener):
- Standalone: `/api/federation/local-status` → `503 {"ok":false,"error":"federation-disabled"}`, federation loaded = false
- Federated: `200 {"ok":true,"role":"replica","failover":{"active":false,...},"replica":{"watermarkApplied":0,"lag":0},"tokenConfigured":true}` — `leaks token? false` for both status JSON and config HTML

**Edge cases covered:** lag clamped to 0 when source < applied; 404 for non-status routes; no-store header; HTML escaping of role/timestamp; boolean-only boundary tested with a deliberately abused `tokenConfigured` string.
{"model": "deepseek-v4-flash", "problem_class": "js-frontend-tokenless-status-surface", "result": "passed", "tests": 14}

Answer 2

Threat model: FEDERATION_TOKEN must never reach browser JS. The dashboard banner needs live state (failover + replica watermark), which doesn't require the token at all. The fix draws a hard boundary: the token lives only in the bootstrap layer and crosses the federation boundary as a boolean (tokenConfigured), never as a value.

Architecture (~):

federation/
  state.js        — in-process failover state + replica watermark store
  status.js       — token-less HTML-string renderers (pure functions, no DOM)
  server-route.js — /api/federation/local-status handler factory
  index.js        — public token-less API surface
custom-server.js  — FED-004 lazy-loader; token → boolean reduction
test/federation.test.js — 14 node-only tests (node:test, no jsdom)

1. Token-less local status route — federation/server-route.js serves only state.getPublicStatus() (booleans + safe numbers) plus the injected tokenConfigured boolean. The route sets Cache-Control: no-store since it's live state. state.js holds no credentials by code or by name:

function getPublicStatus() {
  const lag = STATE.watermark.source - STATE.watermark.applied;
  return {
    ok: STATE.healthy,
    role: STATE.role,
    failover: { active, lastFailoverAt, failoverCount },
    replica: { watermarkApplied, watermarkSource, lag: lag > 0 ? lag : 0 },
    tokenConfigured: false, // injected by route from a boolean flag
  };
}

2. Config page yes/no only — renderConfigPanel normalizes any truthy input to yes/no and never echoes the input:

function renderConfigPanel({ tokenConfigured }) {
  const yesNo = tokenConfigured ? 'yes' : 'no';
  return `<section class="fed-config">...<dd class="fed-token-config">${yesNo}</dd>...`;
}

3. Node-only rendering (no jsdom) — banner/config are pure functions returning HTML strings, so tests call them directly:

function renderStatusBanner(status) {
  const role = status.failover.active ? 'failed-over' : status.role;
  // → `<div class="fed-banner fed-ok" data-federation-role="primary" ...>`
}

4. FED-004 lazy loader in custom-server.js — federation modules (and the token env read) are touched only when FEDERATION_ENABLED=1, and the require is deferred to the first federated request:

let federation = null;
if (FEDERATION_ENABLED && process.env.FEDERATION_TOKEN) tokenConfigured = true; // boolean only
function loadFederation() {
  if (federation) return federation;
  if (!FEDERATION_ENABLED) throw new Error('refusing to load federation modules in standalone mode');
  federation = require(path.join(__dirname, 'federation')); // first request pays the cost
  return federation;
}

Defense in depth: a static guard test asserts no file under federation/ contains FEDERATION_TOKEN or process.env — it caught my own header comment mentioning the env var name, which I then removed (modules shouldn't reference the secret even in prose).

Evidence & signatures

`npm test` → **14/14 pass**. Highlights:

| Test | Result |
|---|---|
| Status JSON never contains token value (deep `string.includes` on serialized body) | pass |
| Payload key set is exactly `failover/ok/replica/role/tokenConfigured` — no `token` key | pass |
| `tokenConfigured` reflects bootstrap flag while token stays server-side | pass |
| Banner renders healthy-primary, failed-over+lag (`Replication lag: 3`), unhealthy, not-configured badge | pass |
| Banner escapes hostile strings — `<script>` never emitted raw | pass |
| Config page shows yes/no only; abused input (token passed as flag) normalizes to `yes`, value never echoed | pass |
| Static guard: federation sources never reference the env var | pass |
| Standalone boot: module **not loaded** before or after requests, routes 503, `loadFederation()` throws | pass |
| Federated boot: module **not loaded at boot**, loaded on first request (lazy), token absent from status JSON *and* config HTML | pass |
| Federated without token → `tokenConfigured: false`, config shows `no` | pass |

**Live smoke test** (real HTTP against ephemeral listener):
- Standalone: `/api/federation/local-status` → `503 {"ok":false,"error":"federation-disabled"}`, federation loaded = false
- Federated: `200 {"ok":true,"role":"replica","failover":{"active":false,...},"replica":{"watermarkApplied":0,"lag":0},"tokenConfigured":true}` — `leaks token? false` for both status JSON and config HTML

**Edge cases covered:** lag clamped to 0 when source < applied; 404 for non-status routes; no-store header; HTML escaping of role/timestamp; boolean-only boundary tested with a deliberately abused `tokenConfigured` string.
{"model": "deepseek-v4-flash", "problem_class": "js-frontend-tokenless-status-surface", "result": "passed", "tests": 14}
Generated from the verified corpus · MIT licensedBack to the catalog