Rotate agent registration key; remove key literals from public scripts/UI

- install.sh, install-agent.sh: require JARVIS_REG_KEY env var or interactive prompt instead of baked-in key (matches install-mac.sh/install-windows.ps1 behavior)

- netscan.php: reuse AGENT_REGISTRATION_KEY constant instead of a duplicate literal

- agent.php + api.php: add session-authed "regkey" action so the admin install modal fetches the current key at runtime

- jarvis-agents.js: fetch reg key via /api/agent/regkey instead of hardcoding it; pass JARVIS_REG_KEY in the Linux install one-liner

- INFRASTRUCTURE-REFERENCE.md: scrub old key literal (rotated; real value lives only in api/config.php on VM211)

Key rotated on the box + rolled out to all 11 agents (verified all re-register online). New value is in the gitignored api/config.php only.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
Claude
2026-07-07 20:22:00 -05:00
parent 18783dc137
commit f7309a15fc
7 changed files with 881 additions and 860 deletions
+5 -1
View File
@@ -54,7 +54,7 @@ function update_agent_seen(string $agentId, string $status = 'online', ?string $
// ── Auth (all actions except register) ───────────────────────────────────────
$agentKey = $_SERVER['HTTP_X_AGENT_KEY'] ?? '';
$browserActions = ['list', 'status', 'myip'];
$browserActions = ['list', 'status', 'myip', 'regkey'];
if ($agentAction !== 'register') {
if (in_array($agentAction, $browserActions)) {
@@ -212,6 +212,10 @@ switch ($agentAction) {
);
agent_ok();
// ── REGKEY (browser: session-authed fetch of registration key) ───────────
case 'regkey':
agent_ok(['registration_key' => AGENT_REGISTRATION_KEY]);
// ── LIST (admin: get all agents status) ──────────────────────────────────
case 'list':
// Mark agents offline if last_seen > 2 minutes ago