js-frontend-tokenless-status-surface
Threat model: FEDERATION_TOKEN must never reach browser JS. The dashboard banner needs live state (failover + replica watermark), which doesn't require the token at all. The fix draws a hard boundary: the token lives only in the bootstrap layer and crosses the federation boundary as a boolean (tokenConfigured), never as a value.
Architecture (~):
federation/
state.js — in-process failover state + replica watermark store
status.js — token-less HTML-string renderers (pure functions, no DOM)
server-route.js — /api/federation/local-status handler factory
index.js — public token-less API surface
custom-server.js — FED-004 lazy-loader; token → boolean reduction
test/federation.test.js — 14 node-only tests (node:test, no jsdom)
1. Token-less local status route — federation/server-route.js serves only state.getPublicStatus() (booleans + safe numbers) plus the injected tokenConfigured boolean. The route sets Cache-Control: no-store since it's live state. state.js holds no credentials by code or by name:
function getPublicStatus() {
const lag = STATE.watermark.source - STATE.watermark.applied;
return {
ok: STATE.healthy,
role: STATE.role,
failover: { active, lastFailoverAt, failoverCount },
replica: { watermarkApplied, watermarkSource, lag: lag > 0 ? lag : 0 },
tokenConfigured: false, // injected by route from a boolean flag
};
}
2. Config page yes/no only — renderConfigPanel normalizes any truthy input to yes/no and never echoes the input:
function renderConfigPanel({ tokenConfigured }) {
const yesNo = tokenConfigured ? 'yes' : 'no';
return `<section class="fed-config">...<dd class="fed-token-config">${yesNo}</dd>...`;
}
3. Node-only rendering (no jsdom) — banner/config are pure functions returning HTML strings, so tests call them directly:
function renderStatusBanner(status) {
const role = status.failover.active ? 'failed-over' : status.role;
// → `<div class="fed-banner fed-ok" data-federation-role="primary" ...>`
}
4. FED-004 lazy loader in custom-server.js — federation modules (and the token env read) are touched only when FEDERATION_ENABLED=1, and the require is deferred to the first federated request:
let federation = null;
if (FEDERATION_ENABLED && process.env.FEDERATION_TOKEN) tokenConfigured = true; // boolean only
function loadFederation() {
if (federation) return federation;
if (!FEDERATION_ENABLED) throw new Error('refusing to load federation modules in standalone mode');
federation = require(path.join(__dirname, 'federation')); // first request pays the cost
return federation;
}
Defense in depth: a static guard test asserts no file under federation/ contains FEDERATION_TOKEN or process.env — it caught my own header comment mentioning the env var name, which I then removed (modules shouldn't reference the secret even in prose).
`npm test` → **14/14 pass**. Highlights:
| Test | Result |
|---|---|
| Status JSON never contains token value (deep `string.includes` on serialized body) | pass |
| Payload key set is exactly `failover/ok/replica/role/tokenConfigured` — no `token` key | pass |
| `tokenConfigured` reflects bootstrap flag while token stays server-side | pass |
| Banner renders healthy-primary, failed-over+lag (`Replication lag: 3`), unhealthy, not-configured badge | pass |
| Banner escapes hostile strings — `<script>` never emitted raw | pass |
| Config page shows yes/no only; abused input (token passed as flag) normalizes to `yes`, value never echoed | pass |
| Static guard: federation sources never reference the env var | pass |
| Standalone boot: module **not loaded** before or after requests, routes 503, `loadFederation()` throws | pass |
| Federated boot: module **not loaded at boot**, loaded on first request (lazy), token absent from status JSON *and* config HTML | pass |
| Federated without token → `tokenConfigured: false`, config shows `no` | pass |
**Live smoke test** (real HTTP against ephemeral listener):
- Standalone: `/api/federation/local-status` → `503 {"ok":false,"error":"federation-disabled"}`, federation loaded = false
- Federated: `200 {"ok":true,"role":"replica","failover":{"active":false,...},"replica":{"watermarkApplied":0,"lag":0},"tokenConfigured":true}` — `leaks token? false` for both status JSON and config HTML
**Edge cases covered:** lag clamped to 0 when source < applied; 404 for non-status routes; no-store header; HTML escaping of role/timestamp; boolean-only boundary tested with a deliberately abused `tokenConfigured` string.{"model": "deepseek-v4-flash", "problem_class": "js-frontend-tokenless-status-surface", "result": "passed", "tests": 14}Threat model: FEDERATION_TOKEN must never reach browser JS. The dashboard banner needs live state (failover + replica watermark), which doesn't require the token at all. The fix draws a hard boundary: the token lives only in the bootstrap layer and crosses the federation boundary as a boolean (tokenConfigured), never as a value.
Architecture (~):
federation/
state.js — in-process failover state + replica watermark store
status.js — token-less HTML-string renderers (pure functions, no DOM)
server-route.js — /api/federation/local-status handler factory
index.js — public token-less API surface
custom-server.js — FED-004 lazy-loader; token → boolean reduction
test/federation.test.js — 14 node-only tests (node:test, no jsdom)
1. Token-less local status route — federation/server-route.js serves only state.getPublicStatus() (booleans + safe numbers) plus the injected tokenConfigured boolean. The route sets Cache-Control: no-store since it's live state. state.js holds no credentials by code or by name:
function getPublicStatus() {
const lag = STATE.watermark.source - STATE.watermark.applied;
return {
ok: STATE.healthy,
role: STATE.role,
failover: { active, lastFailoverAt, failoverCount },
replica: { watermarkApplied, watermarkSource, lag: lag > 0 ? lag : 0 },
tokenConfigured: false, // injected by route from a boolean flag
};
}
2. Config page yes/no only — renderConfigPanel normalizes any truthy input to yes/no and never echoes the input:
function renderConfigPanel({ tokenConfigured }) {
const yesNo = tokenConfigured ? 'yes' : 'no';
return `<section class="fed-config">...<dd class="fed-token-config">${yesNo}</dd>...`;
}
3. Node-only rendering (no jsdom) — banner/config are pure functions returning HTML strings, so tests call them directly:
function renderStatusBanner(status) {
const role = status.failover.active ? 'failed-over' : status.role;
// → `<div class="fed-banner fed-ok" data-federation-role="primary" ...>`
}
4. FED-004 lazy loader in custom-server.js — federation modules (and the token env read) are touched only when FEDERATION_ENABLED=1, and the require is deferred to the first federated request:
let federation = null;
if (FEDERATION_ENABLED && process.env.FEDERATION_TOKEN) tokenConfigured = true; // boolean only
function loadFederation() {
if (federation) return federation;
if (!FEDERATION_ENABLED) throw new Error('refusing to load federation modules in standalone mode');
federation = require(path.join(__dirname, 'federation')); // first request pays the cost
return federation;
}
Defense in depth: a static guard test asserts no file under federation/ contains FEDERATION_TOKEN or process.env — it caught my own header comment mentioning the env var name, which I then removed (modules shouldn't reference the secret even in prose).
`npm test` → **14/14 pass**. Highlights:
| Test | Result |
|---|---|
| Status JSON never contains token value (deep `string.includes` on serialized body) | pass |
| Payload key set is exactly `failover/ok/replica/role/tokenConfigured` — no `token` key | pass |
| `tokenConfigured` reflects bootstrap flag while token stays server-side | pass |
| Banner renders healthy-primary, failed-over+lag (`Replication lag: 3`), unhealthy, not-configured badge | pass |
| Banner escapes hostile strings — `<script>` never emitted raw | pass |
| Config page shows yes/no only; abused input (token passed as flag) normalizes to `yes`, value never echoed | pass |
| Static guard: federation sources never reference the env var | pass |
| Standalone boot: module **not loaded** before or after requests, routes 503, `loadFederation()` throws | pass |
| Federated boot: module **not loaded at boot**, loaded on first request (lazy), token absent from status JSON *and* config HTML | pass |
| Federated without token → `tokenConfigured: false`, config shows `no` | pass |
**Live smoke test** (real HTTP against ephemeral listener):
- Standalone: `/api/federation/local-status` → `503 {"ok":false,"error":"federation-disabled"}`, federation loaded = false
- Federated: `200 {"ok":true,"role":"replica","failover":{"active":false,...},"replica":{"watermarkApplied":0,"lag":0},"tokenConfigured":true}` — `leaks token? false` for both status JSON and config HTML
**Edge cases covered:** lag clamped to 0 when source < applied; 404 for non-status routes; no-store header; HTML escaping of role/timestamp; boolean-only boundary tested with a deliberately abused `tokenConfigured` string.{"model": "deepseek-v4-flash", "problem_class": "js-frontend-tokenless-status-surface", "result": "passed", "tests": 14}