feat: add combined docker+API service widgets for gitea/coolify/immich/n8n/umami/headscale
One new `service` widget type (nested discriminated union on `service`) rather than six, so a single config entry shows both docker container health and a service-specific stat (repo count, project list, photo count, workflow count, active users, users/nodes) - avoiding the overhead of configuring a docker widget and a separate service widget per container. All six collectors hit the service's container name + internal port directly on falcon_network, the same container-to- container pattern just proven out for Traefik's own API, avoiding vpn-only/hairpin-NAT entirely. Also adds the public/private config split that was scoped in the original project plan but never built: lib/config/public.ts strips apiToken/apiKey/password fields before the config reaches the browser via SSR or the WS config topic - required before any widget could carry a real secret. Verified via a throwaway secret field that it's absent from both the SSR HTML and the WS config:update frame. Endpoint shapes verified live against the running gitea/coolify/immich/ n8n/umami/headscale containers before committing (unauthenticated requests correctly 401/200 on every target route; gitea's X-Total-Count header confirmed present).
This commit is contained in:
@@ -0,0 +1,48 @@
|
||||
import type { UmamiServiceWidget } from "@/lib/config/schema";
|
||||
import type { ServiceStat } from "@/lib/types/service-result";
|
||||
import { serviceBaseUrl } from "./base-url";
|
||||
|
||||
// Self-hosted Umami has no static API-key header (that's Cloud-only) - it needs
|
||||
// a username/password login exchanged for a Bearer token. Cache the token per
|
||||
// container and only re-login when a request comes back 401, since the docs
|
||||
// don't document a fixed token lifetime to pre-emptively refresh against.
|
||||
const tokenCache = new Map<string, string>();
|
||||
|
||||
async function login(widget: UmamiServiceWidget, base: string): Promise<string> {
|
||||
const response = await fetch(`${base}/api/auth/login`, {
|
||||
method: "POST",
|
||||
headers: { "Content-Type": "application/json" },
|
||||
body: JSON.stringify({ username: widget.username, password: widget.password }),
|
||||
signal: AbortSignal.timeout(5_000),
|
||||
});
|
||||
if (!response.ok) {
|
||||
throw new Error(`Umami login returned ${response.status}`);
|
||||
}
|
||||
const body = (await response.json()) as { token: string };
|
||||
tokenCache.set(widget.containerName, body.token);
|
||||
return body.token;
|
||||
}
|
||||
|
||||
export async function collectUmami(widget: UmamiServiceWidget): Promise<{ stats: ServiceStat[] }> {
|
||||
const base = serviceBaseUrl(widget);
|
||||
let token = tokenCache.get(widget.containerName) ?? (await login(widget, base));
|
||||
|
||||
let response = await fetch(`${base}/api/websites/${widget.websiteId}/active`, {
|
||||
headers: { Authorization: `Bearer ${token}` },
|
||||
signal: AbortSignal.timeout(5_000),
|
||||
});
|
||||
|
||||
if (response.status === 401) {
|
||||
token = await login(widget, base);
|
||||
response = await fetch(`${base}/api/websites/${widget.websiteId}/active`, {
|
||||
headers: { Authorization: `Bearer ${token}` },
|
||||
signal: AbortSignal.timeout(5_000),
|
||||
});
|
||||
}
|
||||
|
||||
if (!response.ok) {
|
||||
throw new Error(`Umami API returned ${response.status}`);
|
||||
}
|
||||
const body = (await response.json()) as { visitors: number };
|
||||
return { stats: [{ label: "Active", value: String(body.visitors) }] };
|
||||
}
|
||||
Reference in New Issue
Block a user