Multi-tenant reverse-tunnel service ("ngrok for Claude Code" with E2E): a
host-agent dials OUT to an operator-run relay; external devices reach the host
THROUGH the relay, routed by per-tenant subdomain, forwarding ciphertext only
(the relay never sees plaintext). Lets a customer reach their own self-hosted
web-terminal from anywhere with zero networking setup.
Packages — all tsc-strict + vitest green (656 tests), cross-package integration verified:
- relay-contracts: frozen shared contracts (mux frame codec, data model,
capability token, E2E envelope, pairing) — the src/types.ts analog
- term-relay: native WS mux + stateless data plane (subdomain routing, ciphertext forward)
- agent: host-agent (pairing, per-host Ed25519 + mTLS dial-out, forwards to 127.0.0.1:3000)
- control-plane: accounts/hosts registry, pairing-code flow, routing table, provisioning
- relay-e2e: browser<->agent E2E (X25519 ECDH through relay, AEAD, anti-replay, recoverable replay key)
- relay-auth: Passkey/WebAuthn, capability tokens, per-host certs, deny-by-default tenant isolation
- relay-web: browser login + Web Crypto E2E + client-side preview rendering
Security invariants INV1-15 enforced; cross-tenant isolation CI tripwire live
(.github/workflows/relay-tripwire.yml). Design + implementation-level plans in
docs/PLAN_RELAY_*.md and docs/EXPLORE_RELAY_SERVICE.md.
NOTE: generated autonomously per the reviewed plans. The security-critical
packages (relay-e2e, relay-auth) REQUIRE expert security audit before any real
deployment — passing tests prove self-consistency, not resistance to attackers.
Base app (src/, public/) unchanged; concurrent desktop work left uncommitted.
64 lines
1.9 KiB
TypeScript
64 lines
1.9 KiB
TypeScript
import type { WsLike, TimerLike } from '../../src/transport/seams.js'
|
|
|
|
/** In-memory WsLike double: records sent frames, lets tests emit inbound events. */
|
|
export class FakeWs implements WsLike {
|
|
readonly sent: Uint8Array[] = []
|
|
closed = false
|
|
private readonly listeners = new Map<string, Array<(...a: unknown[]) => void>>()
|
|
|
|
send(d: Uint8Array): void {
|
|
this.sent.push(d)
|
|
}
|
|
on(ev: 'message' | 'close' | 'error', cb: (...a: unknown[]) => void): void {
|
|
const arr = this.listeners.get(ev) ?? []
|
|
arr.push(cb)
|
|
this.listeners.set(ev, arr)
|
|
}
|
|
close(): void {
|
|
this.closed = true
|
|
this.emit('close')
|
|
}
|
|
emit(ev: string, ...args: unknown[]): void {
|
|
for (const cb of this.listeners.get(ev) ?? []) cb(...args)
|
|
}
|
|
emitMessage(bytes: Uint8Array): void {
|
|
this.emit('message', bytes)
|
|
}
|
|
}
|
|
|
|
/** Deterministic controllable timer for heartbeat/rotation tests. */
|
|
export class FakeTimer implements TimerLike {
|
|
private seq = 0
|
|
private readonly timeouts = new Map<number, { cb: () => void; ms: number }>()
|
|
private readonly intervals = new Map<number, { cb: () => void; ms: number }>()
|
|
|
|
setTimeout(cb: () => void, ms: number): unknown {
|
|
const id = this.seq++
|
|
this.timeouts.set(id, { cb, ms })
|
|
return id
|
|
}
|
|
clearTimeout(handle: unknown): void {
|
|
this.timeouts.delete(handle as number)
|
|
}
|
|
setInterval(cb: () => void, ms: number): unknown {
|
|
const id = this.seq++
|
|
this.intervals.set(id, { cb, ms })
|
|
return id
|
|
}
|
|
clearInterval(handle: unknown): void {
|
|
this.intervals.delete(handle as number)
|
|
}
|
|
/** Fire every armed timeout whose delay is ≤ ms (single shot) and every interval once. */
|
|
advance(ms: number): void {
|
|
for (const [id, t] of [...this.timeouts]) {
|
|
if (t.ms <= ms) {
|
|
this.timeouts.delete(id)
|
|
t.cb()
|
|
}
|
|
}
|
|
for (const t of [...this.intervals.values()]) {
|
|
if (t.ms <= ms) t.cb()
|
|
}
|
|
}
|
|
}
|