Repository navigation
feat(security): wire port-scan queue + SSE realtime feedback - #82
Merged
Merged
Conversation
Scans were stuck in 'queued' because nothing bridged the port_scans table to the prober. This adds the Railway producer side and realtime UI feedback: - lib/prober-queue.ts: enqueue queued rows to the 'prober' BullMQ queue, then reconcile finished jobs back to the DB (status done/failed + port_findings). Parses REDIS_URL into bullmq connection opts (no direct ioredis import). - worker/index.ts: portScanSweep on a 5s interval (+ startup), no-ops without REDIS_URL. - SSE route /projects/[id]/security/stream: pushes status changes (queued → running → done/failed) + findings to the browser via EventSource. - request-scan-button.tsx: opens the stream on Run and resumes an in-flight scan on load; live status pill; router.refresh() on completion. - requestPortScan returns scanId; add bullmq/ioredis deps. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
vu1nz Security Review0 finding(s) in PR #? No security issues found. |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes scans stuck in
queuedwith no feedback. The UI wrote aport_scansrow but nothing bridged it to the prober, and the page never updated.The missing middle (now built)
Changes
lib/prober-queue.ts— enqueuesqueuedrows to theproberBullMQ queue (jobId = scan id, idempotent), then reconciles finished jobs: reads the job's return value and writesport_scans→done(+open_ports) and upsertsport_findings(severity by port; DB/cache/admin ports = high). Times out stuck scans. ParsesREDIS_URLinto bullmq connection options (no direct ioredis import → avoids the bundled-ioredis type clash).worker/index.ts—portScanSweepon a 5s interval + startup; no-ops whenREDIS_URLis unset.app/(app)/projects/[id]/security/stream/route.ts— auth'dtext/event-stream; polls the DB server-side and pushesstatus/doneevents; 5-min cap; closes on client abort.request-scan-button.tsx— opens the stream on Run, resumes an in-flight scan on page load, shows a live status pill,router.refresh()on completion.requestPortScanreturnsscanId; addedbullmq/ioredisdeps.Realtime path uses SSE (server push) per request; the web tier needs no Redis connection (the worker owns Redis).
Root + worker
tsc --noEmitboth pass. Depends on the prober droplet running (deploy-prober is green) andREDIS_URLset on the crawlproof.com service (done).🤖 Generated with Claude Code