Open /api/system/health to all signed-in users so the Dashboard hero works for non-admins
This commit is contained in:
+5
-3
@@ -578,9 +578,11 @@ async function boot() {
|
||||
if (!state.updateCheckTimer) state.updateCheckTimer = setInterval(() => { if (!$("#dashboard").classList.contains("hidden")) checkForUpdate().catch(() => {}); }, 60000);
|
||||
// Dashboard hero panel: one immediate load so it isn't sitting on dashes until the first
|
||||
// 7-second tick, then the same lightweight poll-while-visible pattern as the System tab's
|
||||
// hero uses, gated on the Dashboard actually being the visible view.
|
||||
if (state.view === "overview" && canAdmin()) refreshDashboardHero().catch(() => {});
|
||||
if (!state.dashboardHeroTimer) state.dashboardHeroTimer = setInterval(() => { if (state.view === "overview" && canAdmin() && !$("#dashboard").classList.contains("hidden")) refreshDashboardHero().catch(() => {}); }, 7000);
|
||||
// hero uses, gated on the Dashboard actually being the visible view. Available to every
|
||||
// signed-in user, not just administrators -- /api/system/health is read-only and shows
|
||||
// nothing a standard user couldn't already infer from the Dashboard running slow or fast.
|
||||
if (state.view === "overview") refreshDashboardHero().catch(() => {});
|
||||
if (!state.dashboardHeroTimer) state.dashboardHeroTimer = setInterval(() => { if (state.view === "overview" && !$("#dashboard").classList.contains("hidden")) refreshDashboardHero().catch(() => {}); }, 7000);
|
||||
}
|
||||
|
||||
async function checkForUpdate() {
|
||||
|
||||
@@ -8,7 +8,7 @@
|
||||
<title>Site Gateway</title>
|
||||
<meta name="description" content="Host sites, proxy services, and manage HTTPS from one simple dashboard.">
|
||||
<link rel="icon" type="image/png" href="/site-gateway-icon-approved.png">
|
||||
<link rel="stylesheet" href="/styles.css?v=0.16.35">
|
||||
<link rel="stylesheet" href="/styles.css?v=0.16.36">
|
||||
</head>
|
||||
|
||||
<!-- ================================================================
|
||||
@@ -432,6 +432,6 @@
|
||||
<div id="toast" class="toast" role="status"></div>
|
||||
<div id="update-banner" class="update-banner hidden" role="status"><span>A new version of Site Gateway is available.</span><div class="update-banner-actions"><button id="update-banner-refresh" class="button primary">Refresh</button><button id="update-banner-dismiss" class="text-button">Dismiss</button></div></div>
|
||||
<!-- App scripts: core (app.js) then extended views/admin (features.js) -->
|
||||
<script src="/app.js?v=0.16.35" defer></script><script src="/features.js?v=0.16.35" defer></script><script src="/select-enhance.js?v=0.16.35" defer></script>
|
||||
<script src="/app.js?v=0.16.36" defer></script><script src="/features.js?v=0.16.36" defer></script><script src="/select-enhance.js?v=0.16.36" defer></script>
|
||||
</body>
|
||||
</html>
|
||||
|
||||
+5
-1
@@ -1713,8 +1713,12 @@ app.post("/api/account/mfa/recovery-codes", async (req, res, next) => {
|
||||
app.get("/api/config", (req, res) => res.json({ version: appVersion, minPort, maxPort, adminPort, storage: { engine: "sqlite", databasePath: storage.databasePath, instanceId: LOCAL_INSTANCE_ID, backupsPath: backupsDir, certificatesPath: certificatesRoot }, gateway: { enabled: true, error: gatewayError }, backup: { encryptionAvailable: Boolean(scheduledBackupPassword) }, docker: { socketMounted: dockerSocketMounted, enabled: dockerSocketMounted && settings.dockerIntegration?.enabled === true } }));
|
||||
|
||||
// --- System tab: storage usage, restart-policy check, and self-restart -----------------------------------
|
||||
// Read-only, non-destructive live resource stats (CPU/memory/swap/disk/network/throughput) --
|
||||
// shown on the Dashboard for every signed-in user, same as the rest of the Dashboard's health
|
||||
// panel, and additionally on the Administration > System tab's hero for administrators. Unlike
|
||||
// most /api/system/* routes this intentionally isn't administrator-gated, since there's nothing
|
||||
// here a standard user couldn't already infer from the Dashboard being slow or fast.
|
||||
app.get("/api/system/health", async (req, res, next) => {
|
||||
if (req.user.role !== "administrator") return res.status(403).json({ error: "Administrator access is required." });
|
||||
try { res.json(await systemHealthSnapshot()); } catch (error) { next(error); }
|
||||
});
|
||||
app.get("/api/system/storage", async (req, res, next) => {
|
||||
|
||||
Reference in New Issue
Block a user