feat(api): add Redfish API to the v1.45.0 baseline - #1292
Merged
Merged
Conversation
…978) Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.1 to 2.19.2. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@a5ad31d...9ca718d) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.2 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…980) Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.2 to 2.19.3. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@9ca718d...ab7a940) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.4 to 4.35.5. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@68bde55...9e0d7b8) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.35.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* Extract shouldAutoLaunchBrowser() — browser now launches only when GIN_MODE=debug Related to device-management-toolkit/deployment#573
* Return x509.ParseCertificate(certBytes) instead of &template * Persist web server cert files to disk when loading from Vault * Propagate saveCertAndKeyToFiles errors Related to device-management-toolkit/deployment#573
os.Executable() can return a symlink path; using filepath.Dir on it anchors config beside the symlink rather than the real binary. On macOS this surfaces when /usr/local/bin/dmt-console symlinks into /usr/local/device-management-toolkit/console: the app tries to mkdir /usr/local/bin/config and fails with EACCES.
A second invocation now detects the running instance via a per-user flock (Unix) or named mutex (Windows), opens the existing tray's URL in the browser, and exits cleanly rather than racing on port 8181. The lock FD is inherited across the background re-exec so it survives parent exit. Default HTTP_HOST changes from "localhost" to wildcard so the tray is reachable from other devices on the LAN. The tray menu and startup log enumerate every routable IPv4, filtering virtual bridges (docker, veth, br-, tun/tap, virbr, vmnet, vboxnet, wg, zt, awdl, llw) and deduping. When bound to a wildcard, the UI's injected ##CONSOLE_SERVER_API## resolves to a relative URL so same-origin fetches match the user's actual host/SNI. Refs: Package Console as an installer #870
Bumps [codecov/codecov-action](https://github.com/codecov/codecov-action) from 6.0.0 to 6.0.1. - [Release notes](https://github.com/codecov/codecov-action/releases) - [Changelog](https://github.com/codecov/codecov-action/blob/main/CHANGELOG.md) - [Commits](codecov/codecov-action@57e3a13...e79a696) --- updated-dependencies: - dependency-name: codecov/codecov-action dependency-version: 6.0.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
The previous reference @device-management-toolkit/owner-open-amt-cloud-toolkit has no direct access to this repository, which causes GitHub to silently treat the CODEOWNERS rule as having no valid owners. As a result, `require_code_owner_reviews` on the main branch is vacuously satisfied by any approval from a user with write access, defeating the gate. owner-console has admin access on this repo, so referencing it makes the required-review enforcement actually work.
* fix(ui): browser always launched to localhost ignoring configured host launchBrowser hardcoded the URL without reading cfg.Host, so the browser always opened http://localhost:<port> regardless of what HTTP_HOST was set to. When HTTP_HOST was unset, an empty cfg.Host produced a malformed URL like http://:8181. Read cfg.Host when building the URL and default to "localhost" only when the configured value is empty. Update README lint commands to use --pull always so Docker always fetches the current latest image instead of reusing a stale cache. * refactor: extract shared host-normalisation helpers to hostnorm.go Add untagged hostnorm.go with unbracketHost, isWildcardListenHost, and navigableHost so browser.go and tray.go share one implementation.
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.35.5 to 4.36.0. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@9e0d7b8...7211b7c) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MadhaviLosetty <madhavi.losetty@gmail.com>
….0 (#1026) Bumps [github.com/getkin/kin-openapi](https://github.com/getkin/kin-openapi) from 0.138.0 to 0.139.0. - [Release notes](https://github.com/getkin/kin-openapi/releases) - [Commits](getkin/kin-openapi@v0.138.0...v0.139.0) --- updated-dependencies: - dependency-name: github.com/getkin/kin-openapi dependency-version: 0.139.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Ganesh Raikhelkar <ganesh.raikhelkar@intel.com>
…1024) Bumps [step-security/harden-runner](https://github.com/step-security/harden-runner) from 2.19.3 to 2.19.4. - [Release notes](https://github.com/step-security/harden-runner/releases) - [Commits](step-security/harden-runner@ab7a940...9af89fc) --- updated-dependencies: - dependency-name: step-security/harden-runner dependency-version: 2.19.4 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [docker/login-action](https://github.com/docker/login-action) from 4.1.0 to 4.2.0. - [Release notes](https://github.com/docker/login-action/releases) - [Commits](docker/login-action@4907a6d...650006c) --- updated-dependencies: - dependency-name: docker/login-action dependency-version: 4.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.50.1 to 1.51.0. - [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md) - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.50.1...v1.51.0) --- updated-dependencies: - dependency-name: modernc.org/sqlite dependency-version: 1.51.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* feat: store lmsInstalled in deviceInfo JSON column * Wire deviceInfo serialization/deserialization in dtoToEntity/entityToDTO * Merge isLMSAvailable from activation into deviceInfo.lmsInstalled * Add LMSInstalled field to DeviceInfo DTO struct Related to device-management-toolkit/rpc-go#1246 * refactor: reuse existing mock --------- Co-authored-by: Mike Johanson <michael.johanson@intel.com>
Bumps [JulienKode/pull-request-name-linter-action](https://github.com/julienkode/pull-request-name-linter-action) from 20.1.0 to 20.5.0. - [Release notes](https://github.com/julienkode/pull-request-name-linter-action/releases) - [Commits](JulienKode/pull-request-name-linter-action@4fb4c27...8dab22a) --- updated-dependencies: - dependency-name: JulienKode/pull-request-name-linter-action dependency-version: 20.5.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.36.0 to 4.36.1. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@7211b7c...87557b9) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.36.1 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Ganesh Raikhelkar <ganesh.raikhelkar@intel.com>
Bumps [github.com/go-playground/validator/v10](https://github.com/go-playground/validator) from 10.30.2 to 10.30.3. - [Release notes](https://github.com/go-playground/validator/releases) - [Commits](go-playground/validator@v10.30.2...v10.30.3) --- updated-dependencies: - dependency-name: github.com/go-playground/validator/v10 dependency-version: 10.30.3 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Ganesh Raikhelkar <ganesh.raikhelkar@intel.com>
Bump both build stages to golang:1.26-alpine (sha256:f23e8b22), which ships patched alpine 3.23 packages and clears the stale base-image CVEs Trivy was reporting.
…1043) Bumps [github.com/quic-go/quic-go](https://github.com/quic-go/quic-go) from 0.59.0 to 0.59.1. - [Release notes](https://github.com/quic-go/quic-go/releases) - [Commits](quic-go/quic-go@v0.59.0...v0.59.1) --- updated-dependencies: - dependency-name: github.com/quic-go/quic-go dependency-version: 0.59.1 dependency-type: indirect ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite) from 1.51.0 to 1.52.0. - [Changelog](https://gitlab.com/cznic/sqlite/blob/master/CHANGELOG.md) - [Commits](https://gitlab.com/cznic/sqlite/compare/v1.51.0...v1.52.0) --- updated-dependencies: - dependency-name: modernc.org/sqlite dependency-version: 1.52.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
* refactor(api): add rpc-go release discovery and archive handling Groundwork for Download RPC; nothing calls it yet. - List v3+ rpc-go releases from GitHub (newest five) or from a local <dir>/<version>/ cache, sorted newest first - Match rpc-go's published builds, rpc_linux_<arch>.tar.gz and rpc_windows_<arch>.exe - Take the binary from the bare .exe or the tarball's single entry, capped at 200 MiB - Assemble the download zip holding the binaries and config.yaml - Add the package request/release DTOs and the asset download URL * refactor(api): add rpc-go packaging service Builds the Download RPC zip; not yet exposed over HTTP. - Resolve the requested build from GitHub, falling back to package.local_dir - package.disable_fetch serves builds from local_dir only; with fetching on, GitHub releases list first, then local-only versions - Render rpc-go's config.yaml for activate or deactivate with token, userpass, or no embedded credentials, scoped to the caller's tenant - Mint the auth token with a requested lifetime capped by package.max_token_ttl; no token is minted when auth is disabled - Point rpc-go at the request's serverUrl or the listener address, and skip cert checks when the listener serves a generated certificate - Package the Windows and Linux builds together for os "both" * feat(api): add download-rpc package endpoints - GET /api/package/rpc-versions lists the rpc-go releases available to package - POST /api/package returns a zip with the rpc-go binary and a config.yaml pointing at this Console - Map missing assets to 404 and unsafe versions and out-of-range token lifetimes to 400 - Declare both routes in OpenAPI and add Postman requests
Bumps [astral-sh/setup-uv](https://github.com/astral-sh/setup-uv) from 10.1.0 to 10.2.0. - [Release notes](https://github.com/astral-sh/setup-uv/releases) - [Commits](astral-sh/setup-uv@bec219d...c18668a) --- updated-dependencies: - dependency-name: astral-sh/setup-uv dependency-version: 10.2.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…1288) Bumps [github.com/gin-contrib/pprof](https://github.com/gin-contrib/pprof) from 1.5.5 to 1.5.6. - [Release notes](https://github.com/gin-contrib/pprof/releases) - [Commits](gin-contrib/pprof@v1.5.5...v1.5.6) --- updated-dependencies: - dependency-name: github.com/gin-contrib/pprof dependency-version: 1.5.6 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Madhavi Losetty <madhavi.losetty@intel.com>
Bumps [github.com/go-playground/validator/v10](https://github.com/go-playground/validator) from 10.30.4 to 10.30.5. - [Release notes](https://github.com/go-playground/validator/releases) - [Commits](go-playground/validator@v10.30.4...v10.30.5) --- updated-dependencies: - dependency-name: github.com/go-playground/validator/v10 dependency-version: 10.30.5 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com> Co-authored-by: Madhavi Losetty <madhavi.losetty@intel.com>
) Bumps [github.com/gin-contrib/cors](https://github.com/gin-contrib/cors) from 1.7.8 to 1.7.9. - [Release notes](https://github.com/gin-contrib/cors/releases) - [Commits](gin-contrib/cors@v1.7.8...v1.7.9) --- updated-dependencies: - dependency-name: github.com/gin-contrib/cors dependency-version: 1.7.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
#1236) fix(cors): reject cross-origin relay handshakes and drop wildcard default The KVM/SOL/IDER relay accepted websocket connections from any origin, enabling Cross-Site WebSocket Hijacking, and allowed_origins defaulted to "*", so the API answered every request with Access-Control-Allow-Origin: *. - Validate the relay's Origin header against the configured allowlist. - Do not honor "*" for the relay: a wildcard or empty allowlist degrades to same-origin only, which closes the hijack on installs that still carry "*" on disk. Same-origin is always accepted, so the embedded UI is unaffected. Opaque origins ("null", data:, file:) are rejected. - Compare hosts case-insensitively, matching the CORS middleware. A mixed-case entry previously passed CORS but failed the relay. - Replace the "*" allowed_headers with an explicit list, and reject an empty allowed_origins at startup instead of panicking in the CORS library. - Remove the wildcard from the shipped config.yml and .env.example, and warn at startup if it is still configured. Deployments serving the UI from a separate origin while relying on "*" must now list that origin explicitly. Same-origin deployments are unaffected.
* feat: denormalize currentMode/discovered into device columns Addresses: #1210 - Mirror the deviceinfo currentMode and discovered JSON fields into dedicated queryable device columns, synced on every insert/update from the deviceinfo blob (source of truth). - Adds nullable columns via migration and wires the write path across sqldb (Postgres/SQLite) and mongo backends. No API or behaviour change: the columns are written but not yet read. Signed-off-by: ShradhaGupta31 <shradha.gupta@intel.com>
* feat: expose activated/discovered stats and device filters Addresses: #1210 - Add activatedCount and discoveredCount to the device stats response, and - Add support ?activated=true / ?discovered=true filtering on the devices list endpoint - Support stats and filtering across Postgres, SQLite, and MongoDB - Update OpenAPI/Fuego declarations and Postman collection entries. Signed-off-by: ShradhaGupta31 <shradha.gupta@intel.com>
# Conflicts: # .env.example # .github/workflows/api-test.yml # .github/workflows/ci.yml # .github/workflows/codeql-analysis.yml # .github/workflows/docker-build.yml # .github/workflows/projectsSync.yaml # .github/workflows/release.yml # .github/workflows/scorecards.yml # .github/workflows/semantic.yml # .github/workflows/trivy-scan.yml # Dockerfile # cmd/app/browser.go # cmd/app/browser_test.go # cmd/app/main.go # cmd/app/main_test.go # cmd/app/tray_windows.go # config/config.go # config/config.yml # go.mod # go.sum # integration-test/collections/console_mps_apis.postman_collection.json # internal/controller/httpapi/router.go # internal/controller/httpapi/v1/devicemanagement.go # internal/controller/httpapi/v1/devices_test.go # internal/controller/httpapi/v1/login_test.go # internal/controller/httpapi/v1/profiles_test.go # internal/controller/httpapi/v1/wifiprofile.go # internal/controller/httpapi/v1/wifiprofile_test.go # internal/controller/httpapi/v1/wifistate.go # internal/controller/openapi/devicemanagement.go # internal/controller/ws/v1/interface.go # internal/entity/dto/v1/device.go # internal/mocks/devicemanagement_mocks.go # internal/mocks/wsman_mocks.go # internal/mocks/wsv1_mocks.go # internal/usecase/devices/boot.go # internal/usecase/devices/boot_test.go # internal/usecase/devices/interfaces.go # internal/usecase/devices/repo.go # internal/usecase/devices/usecase.go # internal/usecase/devices/usecase_private_test.go # internal/usecase/devices/wifiprofile.go # internal/usecase/devices/wifiprofile_test.go # internal/usecase/devices/wifistate.go # internal/usecase/devices/wsman/interfaces.go # internal/usecase/profiles/usecase.go # internal/usecase/profiles/usecase_test.go # pkg/httpserver/server.go
sudhir-intc
force-pushed
the
redfish-baseline-v1-45
branch
from
September 30, 2026 05:49
740e11e to
69bfc32
Compare
Codecov Report❌ Patch coverage is Additional details and impacted files@@ Coverage Diff @@
## redfish #1292 +/- ##
============================================
+ Coverage 46.81% 62.70% +15.88%
============================================
Files 157 176 +19
Lines 16041 15783 -258
============================================
+ Hits 7509 9896 +2387
+ Misses 7891 5887 -2004
+ Partials 641 0 -641 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
sudhir-intc
force-pushed
the
redfish-baseline-v1-45
branch
2 times, most recently
from
September 30, 2026 08:22
7c1cc73 to
0ba6b09
Compare
DevipriyaS17
approved these changes
Sep 30, 2026
sudhir-intc
force-pushed
the
redfish-baseline-v1-45
branch
from
September 30, 2026 09:11
0ba6b09 to
14df618
Compare
amarnath-ac
approved these changes
Sep 30, 2026
sudhir-intc
force-pushed
the
redfish-baseline-v1-45
branch
from
September 30, 2026 14:58
e20f38f to
0f455e0
Compare
Add the Redfish API as a tech-preview feature on the v1.45.0 baseline, including service routes, handlers, OpenAPI definitions, Postman coverage, WSMAN-backed system operations, boot actions, and related test support. Bind Redfish redirection tokens to the lowercased device ID so KVM, SOL, and IDE-R relay sessions can validate the requested host. Add Vite dev UI origins to the default configuration and prevent unmatched Redfish paths from falling through to the embedded UI shell. Align the release workflow with .releaserc.json so redfish-preview versions are embedded in generated binaries. Keep Docker latest tags exclusive to main releases, while publishing versioned prerelease images for redfish. Document Redfish availability as a tech preview and identify its prerelease release channel in the README.
sudhir-intc
force-pushed
the
redfish-baseline-v1-45
branch
from
October 1, 2026 08:58
d86228e to
f37d821
Compare
|
🎉 This PR is included in version 1.46.0-redfish-preview.1 🎉 The release is available on:
Your semantic-release bot 📦🚀 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Redfish support in console is a tech-preview for evaluation
Key features:
Testing: