GPU decrypt worker live on nightmare (systemd, token-authed queue pulls); decrypt endpoints accept agent token; README android+worker

This commit is contained in:
Hermes
2026-10-01 19:42:46 +00:00
parent d3501f862a
commit 212d04f87d
2 changed files with 12 additions and 2 deletions

View File

@@ -40,7 +40,7 @@ function agentAuthOk(req) {
}
function authMiddleware(req, res, next) {
if (!AUTH_TOKEN) return next();
if (req.path.startsWith('/api/agent/')) {
if (req.path.startsWith('/api/agent/') || req.path.startsWith('/api/decrypt/')) {
if (agentAuthOk(req)) return next();
return res.status(401).json({ error: 'agent token required' });
}
@@ -1179,13 +1179,18 @@ try { fs.mkdirSync(DECRYPT_QUEUE_DIR, { recursive: true }); } catch (e) {}
// credential decryption queue (for GPU/hashing workers, e.g. hashcat on nightmare)
app.post('/api/decrypt/queue', (req, res) => {
if (AUTH_TOKEN && !workerAuthOk(req) && req.headers.authorization !== 'Bearer ' + AUTH_TOKEN) return res.status(401).json({ error: 'unauthorized' });
const { nodeId, kind, blob_b64, meta } = req.body || {};
if (!nodeId || !blob_b64) return res.status(400).json({ error: 'nodeId and blob_b64 required' });
const f = path.join(DECRYPT_QUEUE_DIR, `${Date.now()}-${nodeId}-${kind || 'blob'}.b64`);
fs.writeFileSync(f, JSON.stringify({ nodeId, kind, meta: meta || {}, blob_b64, at: Date.now() }));
res.json({ success: true, file: path.basename(f) });
});
function workerAuthOk(req) {
return AGENT_TOKEN && (req.headers['x-agent-token'] === AGENT_TOKEN);
}
app.get('/api/decrypt/queue', (req, res) => {
if (AUTH_TOKEN && !workerAuthOk(req) && req.headers.authorization !== 'Bearer ' + AUTH_TOKEN) return res.status(401).json({ error: 'unauthorized' });
try {
res.json({ jobs: fs.readdirSync(DECRYPT_QUEUE_DIR).map(f => {
try { return JSON.parse(fs.readFileSync(path.join(DECRYPT_QUEUE_DIR, f), 'utf8')); } catch (e) { return null; }