diff --git a/js/defaults.js b/js/defaults.js index b0fa680ccb..8fbb365856 100644 --- a/js/defaults.js +++ b/js/defaults.js @@ -24,7 +24,6 @@ const defaults = { customCss: "config/custom.css", foreignModulesDir: "modules", defaultModulesDir: "defaultmodules", - hideConfigSecrets: false, // httpHeaders used by helmet, see https://helmetjs.github.io/. You can add other/more object values by overriding this in config.js, // e.g. you need to add `frameguard: false` for embedding MagicMirror in another website, see https://github.com/MagicMirrorOrg/MagicMirror/issues/2847 httpHeaders: { contentSecurityPolicy: false, crossOriginOpenerPolicy: false, crossOriginEmbedderPolicy: false, crossOriginResourcePolicy: false, originAgentCluster: false }, diff --git a/js/node_helper.js b/js/node_helper.js index 90e8ffa8e1..c34b090af2 100644 --- a/js/node_helper.js +++ b/js/node_helper.js @@ -118,7 +118,7 @@ class NodeHelper { io.of(this.name).on("connection", (socket) => { // register catch all. socket.onAny((notification, payload) => { - if (global.config?.hideConfigSecrets && payload && typeof payload === "object") { + if (payload && typeof payload === "object") { try { // Calculate exactly which secrets this module is allowed to receive const allowedSecrets = getAllowedSecrets(this.name); diff --git a/js/server.js b/js/server.js index 0c48511555..60728203f7 100644 --- a/js/server.js +++ b/js/server.js @@ -108,17 +108,12 @@ class Server { app.use(helmet(config.httpHeaders)); app.use("/js", express.static(__dirname)); - if (config.hideConfigSecrets) { - const getErrorText = (filename) => { - return `\n\n\n\nError\n\n\n
Cannot GET /config/${filename}
\n\n`; - }; - app.get("/config/config.env", (req, res) => { - res.status(404).send(getErrorText("config.env")); - }); - app.get("/config/config.js", (req, res) => { - res.status(404).send(getErrorText("config.js")); - }); - } + const getConfigFileError = (filename) => (req, res) => { + const errorText = `\n\n\n\nError\n\n\n
Cannot GET /config/${filename}
\n\n`; + res.status(404).send(errorText); + }; + app.get("/config/config.env", getConfigFileError("config.env")); + app.get("/config/config.js", getConfigFileError("config.js")); const directories = ["/config", "/css", "/favicon.svg", "/defaultmodules", "/modules", "/node_modules/animate.css", "/node_modules/@fontsource", "/node_modules/@fortawesome", "/node_modules/suncalc", "/translations", "/tests/configs", "/tests/mocks"]; for (const value of Object.values(vendor)) { @@ -135,7 +130,7 @@ class Server { const getStartup = (req, res) => res.send(startUp); const getConfig = (req, res) => { - const obj = config.hideConfigSecrets ? configObj.redactedConf : configObj.fullConf; + const obj = configObj.redactedConf; // Functions can't survive JSON.stringify, so we wrap them in a // tagged object { __mmFunction: "" }. The client-side // JSON reviver in main.js recognises this tag and reconstructs diff --git a/js/server_functions.js b/js/server_functions.js index cf7b0627b1..d79ced0fbc 100644 --- a/js/server_functions.js +++ b/js/server_functions.js @@ -70,11 +70,7 @@ const cors = async (req, res) => { return res.status(400).send(url); } else { url = match[1]; - if (typeof global.config !== "undefined") { - if (global.config.hideConfigSecrets) { - url = replaceSecretPlaceholder(url); - } - } + if (typeof global.config !== "undefined") url = replaceSecretPlaceholder(url); // Validate protocol before attempting connection (non-http/https are never allowed) let parsed; diff --git a/js/utils.js b/js/utils.js index 2ac76c5f8a..e209526173 100644 --- a/js/utils.js +++ b/js/utils.js @@ -141,21 +141,17 @@ const loadConfig = () => { // Load config.js and catch errors if not accessible try { const configContent = fs.readFileSync(configFilename, "utf-8"); - const hideConfigSecrets = configContent.match(/^\s*hideConfigSecrets: true.*$/m); let configContentFull = configContent; - let configContentRedacted = hideConfigSecrets ? configContent : undefined; + let configContentRedacted = configContent; Object.keys(process.env).forEach((env) => { configContentFull = configContentFull.replaceAll(`\${${env}}`, process.env[env]); - if (hideConfigSecrets) { - if (env.startsWith("SECRET_")) { - configContentRedacted = configContentRedacted.replaceAll(`"\${${env}}"`, `"**${env}**"`); - configContentRedacted = configContentRedacted.replaceAll(`\${${env}}`, `**${env}**`); - } else { - configContentRedacted = configContentRedacted.replaceAll(`\${${env}}`, process.env[env]); - } + if (env.startsWith("SECRET_")) { + configContentRedacted = configContentRedacted.replaceAll(`"\${${env}}"`, `"**${env}**"`); + configContentRedacted = configContentRedacted.replaceAll(`\${${env}}`, `**${env}**`); + } else { + configContentRedacted = configContentRedacted.replaceAll(`\${${env}}`, process.env[env]); } }); - configContentRedacted = configContentRedacted ? configContentRedacted : configContentFull; const configObj = { configFilename: configFilename, configContentFull: configContentFull, diff --git a/tests/configs/config_variables.js b/tests/configs/config_variables.js index db8cb2ad88..aea032b864 100644 --- a/tests/configs/config_variables.js +++ b/tests/configs/config_variables.js @@ -2,7 +2,6 @@ const config = require(`${process.cwd()}/tests/configs/default.js`).configFactor language: "${MM_LANGUAGE}", logLevel: ["${MM_LOG_ERROR}", "LOG", "WARN", "${MM_LOG_INFO}"], timeFormat: ${MM_TIME_FORMAT}, - hideConfigSecrets: true, ipWhitelist: ["${SECRET_IP2}", "::${SECRET_IP3}", "${SECRET_IP1}", "192.168.0.0/16", "172.16.0.0/12"], address: "0.0.0.0",