Skip to content

Mbweb console

Teuk edited this page Oct 6, 2026 · 2 revisions

mbweb console

mbweb is the optional Node.js/Express console in contrib/mbweb. It uses existing Mediabot accounts and exposes profiles, visible channels, commands, quotes, radio status and privileged operational views.

Install Mediabot and apply every database migration first. Production sessions require MBWEB_SESSION.

Recommended layout

Item Recommended value
Source /home/mediabot/mediabot_v3/contrib/mbweb
Runtime /opt/mbweb/app
Bind 127.0.0.1:4002
Example base path /mediabotv3dev/
Service account mediabot

The application base URL and reverse-proxy path must match.

Prerequisites

sudo apt update
sudo apt install nodejs npm mariadb-client curl jq rsync apache2
sudo a2enmod proxy proxy_http headers
sudo systemctl reload apache2.service

Transactional deployment

cd /home/mediabot/mediabot_v3
sudo install/mbweb_deploy.sh deploy \
  --source /home/mediabot/mediabot_v3/contrib/mbweb \
  --unit /home/mediabot/mediabot_v3/install/systemd/mbweb.service \
  --health-url http://127.0.0.1:4002/mediabotv3dev/health

Keep the printed MBWEB_BACKUP path. Read-only verification:

sudo install/mbweb_deploy.sh verify \
  --source /home/mediabot/mediabot_v3/contrib/mbweb \
  --unit /home/mediabot/mediabot_v3/install/systemd/mbweb.service \
  --health-url http://127.0.0.1:4002/mediabotv3dev/health

Private configuration

Create /opt/mbweb/app/.env from .env.sample, owned by mediabot:mediabot, mode 0600. Generate a session secret of at least 32 characters:

openssl rand -hex 48
sudo chown mediabot:mediabot /opt/mbweb/app/.env
sudo chmod 0600 /opt/mbweb/app/.env

Use production mode, a loopback bind, the chosen port/base path, the MySQL session store and Mediabot database coordinates. Never commit .env.

Use a dedicated database identity: read-only access to displayed data, plus SELECT, INSERT, UPDATE, DELETE on MBWEB_SESSION. It needs no schema-changing or server-administration privileges.

Reverse proxy and verification

Terminate TLS at Apache (or another trusted proxy) and proxy the exact base path to loopback. Do not bind Node publicly.

sudo systemctl status mbweb.service --no-pager
curl --fail --silent http://127.0.0.1:4002/mediabotv3dev/health

Verify login, channel visibility with ordinary and privileged accounts, logout/session expiry, and CSRF protection. contrib/mbweb/README.md in the matching checkout contains the full Apache and rollback examples.

Current authorization boundaries

The reviewed development console revalidates the account and role before protected access. Deleted/malformed/downgraded identities lose access; a database outage returns a service failure rather than silently granting or fabricating data. Owner and Master keep global quote browsing. Other permitted users see only quote rows, counts and channel choices allowed by their current memberships; literal search escapes SQL wildcard characters. Regular dashboard responses omit database identity and global counts.

This update adds no general write API. Session persistence remains the narrow database write requirement. Validate both HTML and JSON views with ordinary and privileged accounts after deployment; keep source and /opt/mbweb/app aligned through the transactional deploy/verify commands above.

Clone this wiki locally