Files
OmniRoute/src/mitm/sudoGate.ts
Burak Keskin 4914954866 fix(mitm): keep Windows DNS elevation off the POSIX sudo path (#11430) (#11542)
Merged via /merge-batch (lote 2026-08-26, v3.8.51). Boarded no worktree combinado junto com outras ~30 PRs; validação única: typecheck/complexity/cognitive-complexity/changelog-integrity verdes, file-size rebaseado onde necessário (crescimento legítimo), lint com os mesmos 228 achados pré-existentes confirmados via sonda contra o tip puro (não introduzidos por este lote), e ~370 testes focados (unit + vitest) passando. Obrigado pela contribuição.
2026-08-26 08:11:26 -03:00

37 lines
1.4 KiB
TypeScript

import os from "os";
import { isSudoPasswordRequired } from "./dns/dnsConfig.ts";
import { isRoot } from "./systemCommands.ts";
/** Trim and treat whitespace-only sudo passwords as missing (#7865 review). */
export function normalizeMitmSudoPasswordInput(value?: string | null): string {
return value?.trim() ?? "";
}
/** Resolve the sudo password from the request body and in-process cache. */
export function resolveMitmSudoPassword(
bodyPassword?: string,
cachedPassword?: string | null
): string {
const body = normalizeMitmSudoPasswordInput(bodyPassword);
if (body) return body;
return normalizeMitmSudoPasswordInput(cachedPassword);
}
/**
* Whether a privileged MITM operation must reject because no sudo password is
* available. Mirrors the gate in `/api/cli-tools/antigravity-mitm` (#822) and
* `/api/settings/mitm` — skip on Windows, root, NOPASSWD sudoers, and hosts
* without sudo on PATH.
*/
export function isMitmSudoPasswordRequired(sudoPassword: string): boolean {
if (os.platform() === "win32") return false;
if (isRoot()) return false;
if (normalizeMitmSudoPasswordInput(sudoPassword)) return false;
return isSudoPasswordRequired();
}
/** Whether cert trust / DNS provisioning may run (inverse of the hard gate). */
export function canRunPrivilegedMitmSteps(sudoPassword: string): boolean {
return !isMitmSudoPasswordRequired(sudoPassword);
}