function parsePeers(peerMap) { if (!peerMap) { return []; } return Object.keys(peerMap).map(function (key) { var p = peerMap[key]; return { hostname: p.HostName || key, ip: (p.TailscaleIPs && p.TailscaleIPs.length) ? p.TailscaleIPs[0] : "", online: p.Online || false, exitNode: p.ExitNodeOption || false }; }); } function makeExitNodeCommand(hostname) { if (!isValidExitNodeHostname(hostname)) { return null; } if (hostname === "") { return ["tailscale", "set", "--exit-node="]; } return ["tailscale", "set", "--exit-node=" + hostname]; } function findActiveExitNode(peerMap) { if (!peerMap) { return ""; } for (const key of Object.keys(peerMap)) { const p = peerMap[key]; if (p.ExitNode) { return p.HostName || key; } } return ""; } const clipboardTools = [ { argv: ["dms", "cl", "copy"] }, { argv: ["wl-copy"] } ]; function getClipboardCommands(text) { return clipboardTools.map(function (tool) { return tool.argv.concat([text]); }); } function getStrings() { return { header: "Tailscale", connected: "Connected", disconnected: "Disconnected", exitNodePrefix: "Exit node: ", none: "None", copied: "Copied %1 to clipboard", invalidExitNodeHostname: "Invalid exit node hostname", notConnectedHint: "Not connected" }; } // Security: validate hostnames coming from tailscale status JSON. // Fail closed on obviously malicious input. Allow multi-label MagicDNS names // up to DNS FQDN length (253). function isValidExitNodeHostname(hostname) { if (typeof hostname !== "string") { return false; } if (hostname === "") { return true; } if (hostname.length > 253) { return false; } // Each label: alnum start/end, alnum/hyphen/underscore inside; dots separate labels. return /^(?=.{1,253}$)([a-zA-Z0-9]([a-zA-Z0-9_-]{0,61}[a-zA-Z0-9])?)(\.([a-zA-Z0-9]([a-zA-Z0-9_-]{0,61}[a-zA-Z0-9])?))*$/.test(hostname); } function parseStatusResult(jsonText) { try { const data = JSON.parse(jsonText); const isConnected = data.BackendState === "Running"; if (!isConnected) { // #55: when not Running, do not surface stale peer list / exit node / IP. return { isConnected: false, tailscaleIP: "", currentExitNode: "", peers: [] }; } return { isConnected: true, tailscaleIP: (data.Self && data.Self.TailscaleIPs && data.Self.TailscaleIPs[0]) || "", currentExitNode: findActiveExitNode(data.Peer || {}), peers: parsePeers(data.Peer || {}) }; } catch (e) { return { isConnected: false, tailscaleIP: "", currentExitNode: "", peers: [] }; } } function buildToggleCommand(isConnected) { return isConnected ? ["tailscale", "down"] : ["tailscale", "up"]; } // Single source of truth for the status command used for on-demand and post-action verification. function getStatusCommand() { return ["tailscale", "status", "--json"]; } function errorMessage(cmd) { var messages = { "up": "Failed to connect to Tailscale", "connect": "Failed to connect to Tailscale", "down": "Failed to disconnect from Tailscale", "disconnect": "Failed to disconnect from Tailscale", "set": "Failed to set exit node", "status": "Failed to read Tailscale status", "clipboard": "Error copying to clipboard" }; return messages[cmd] || "Tailscale command failed"; } // Central error formatting for the widget. detail is optional truncated stderr or extra context. function formatError(action, detail) { var base = errorMessage(action); if (detail && detail.length > 0) { var truncated = detail.length > 120 ? detail.slice(0, 120) : detail; return base + " — " + truncated; } return base; } const PendingAction = Object.freeze({ TOGGLE: "toggle" }); // statusOk must be true (successful status poll) before acting on pending toggle. // Never invent up/down from a failed poll (would force "up" after clearing isConnected). function commandForPendingAction(pending, freshIsConnected, statusOk) { if (!statusOk) { return null; } if (pending === PendingAction.TOGGLE) { return buildToggleCommand(freshIsConnected); } return null; } if (typeof module !== "undefined" && module.exports) { module.exports = { parsePeers, makeExitNodeCommand, findActiveExitNode, errorMessage, formatError, getStatusCommand, isValidExitNodeHostname, getClipboardCommands, buildToggleCommand, parseStatusResult, getStrings, PendingAction, commandForPendingAction }; }