/*
* SysDeck - Hardware Auth Panel
* Author: Jeremy Anderson (https://dcos.net)
*
* Lists smartcard reader slots via pkcs11-tool. Falls back to a hint
* card when opensc / pcsc-lite is absent.
*
* v0.1.4 SECURITY + FIX: reader descriptions are USB string
* descriptors — attacker-controllable via a malicious device — and
* are now escaped before landing in innerHTML (0.3.0 audit). The
* Quick Actions used to call bridge.spawn(), which bridge.js never
* exported (the buttons always threw); they now use the auth bridge's
* certs/readers subcommands and render output via textContent.
*/
function escapeHtml(s) {
return String(s == null ? '' : s)
.replace(/&/g, '&')
.replace(//g, '>')
.replace(/"/g, '"')
.replace(/'/g, ''');
}
export async function mount(panel, { bridge, EventBus }) {
panel.innerHTML = renderSkeleton();
const slots = await bridge.auth.smartcards();
panel.innerHTML = `
PKCS#11 / pcsc-lite — ${slots.length} slotsHardware Auth
No smartcard readers detected. Install opensc and pcsc-lite, then start pcscd.service.