One new `service` widget type (nested discriminated union on `service`) rather than six, so a single config entry shows both docker container health and a service-specific stat (repo count, project list, photo count, workflow count, active users, users/nodes) - avoiding the overhead of configuring a docker widget and a separate service widget per container. All six collectors hit the service's container name + internal port directly on falcon_network, the same container-to- container pattern just proven out for Traefik's own API, avoiding vpn-only/hairpin-NAT entirely. Also adds the public/private config split that was scoped in the original project plan but never built: lib/config/public.ts strips apiToken/apiKey/password fields before the config reaches the browser via SSR or the WS config topic - required before any widget could carry a real secret. Verified via a throwaway secret field that it's absent from both the SSR HTML and the WS config:update frame. Endpoint shapes verified live against the running gitea/coolify/immich/ n8n/umami/headscale containers before committing (unauthenticated requests correctly 401/200 on every target route; gitea's X-Total-Count header confirmed present).
20 lines
525 B
TypeScript
20 lines
525 B
TypeScript
import type { Config, Widget } from "./schema";
|
|
|
|
const SECRET_WIDGET_FIELDS = ["apiToken", "apiKey", "password"] as const;
|
|
|
|
export function toPublicConfig(config: Config): Config {
|
|
return {
|
|
...config,
|
|
groups: config.groups.map((group) => ({
|
|
...group,
|
|
widgets: group.widgets.map(redactWidget),
|
|
})),
|
|
};
|
|
}
|
|
|
|
function redactWidget(widget: Widget): Widget {
|
|
const clone: Record<string, unknown> = { ...widget };
|
|
for (const key of SECRET_WIDGET_FIELDS) delete clone[key];
|
|
return clone as Widget;
|
|
}
|