Files
NeuroSploit/web
CyberSecurityUPandClaude Opus 5 4f277838c6 fix(web): responsive pass — real device sizes, scroll in the right containers
Audited at 390×844, 844×390 (phone landscape), 768×1024, 1024×768, 1440×900
and ≥1600px. What was actually broken:

- **The run header collapsed.** `justify-content: space-between` let the two
  action buttons take the whole row, so at 390px the title wrapped one
  character per line ("Test AspNe / t") and the facts line wrapped one word per
  line. It now stacks below 680px, with the title block sized to its content
  instead of stretching (the desktop `flex: 1` was what left a 180px void above
  the buttons in the stacked layout).
- **The terminal header overflowed** its dock at 390px (557px of content in a
  390px box) — it wraps now, and the status text drops out on narrow screens
  where the coloured dot already carries it.
- **`100vh` is wrong on mobile.** It measures the viewport without the
  collapsing address bar, so the wizard footer and its CTA sit underneath it.
  Switched to `dvh` with the `vh` line kept as the fallback.
- **The dock took 82% of a phone in landscape** at its fixed 320px. It now
  tracks the viewport (`clamp(180px, 42dvh, 340px)`, tighter still under
  500px of height).
- **The off-canvas drawer had no way out but the button that opened it.**
  Added a scrim that closes it, Esc, and auto-close when a run is picked —
  and it closes itself if the window grows past the breakpoint, which
  otherwise left a scrim over a sidebar that was no longer a drawer.
- **The stepper scrolls horizontally on a phone**, so advancing to an
  off-screen step looked like nothing happened; the active step is scrolled
  into view.

Device-type rules rather than width alone: `pointer: coarse` gets 38-44px hit
targets and 16px inputs (under 16px, iOS zooms the page on focus and breaks the
layout the user is typing into); `prefers-reduced-motion` drops the drawer
slide and the progress animation, which are decoration.

Scrolling stays where it belongs — one scroller per pane (`.wizard-body`,
`.run-body`, `.dash-body`, `.sb-groups`, `.modal-body`, `.term-host`), wide
tables scroll inside `.table-wrap`, and the page itself never scrolls
horizontally at any tested size.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-09-13 15:16:24 -03:00
..

NeuroSploit v4.0.0 — web console

A browser UI for the neurosploit CLI harness: a 5-step engagement wizard (Asset → Scope & Auth → Leads → Model & Run → Review), a live structured findings view with a generative attack-path graph, run history, an Auth & Keys menu, and a real terminal — all driven by spawning the actual CLI binary, never a reimplementation of harness logic.

  • Asset — pick black/white/grey-box, host/infra, or AI/LLM, set the target or repo.
  • Scope & Auth — objective, focus, out-of-scope, and a link into the Auth & Keys menu.
  • Leads — the categorized agent picker (435 agents auto-classified) + custom leads.
  • Model & Run — pick a provider/model from the live catalog, API-key vs. subscription auth mode, votes/chain-depth/recon intensity.
  • Review — confirm the plan, then Start Exploitation spawns the real CLI.
  • Auth & Keys (one menu, 🔑 in the sidebar) — target auth header + named roles for IDOR/BOLA/BFLA testing, per-provider API keys (kept in server memory only, never on disk), and an explicit creds.yaml path override.
  • Generative Attack Path Chaining — findings are grouped into kill-chain columns (recon → initial-access → execution → privesc → lateral → exfil → impact) with chained findings linked back to their parent, built live as findings stream in.
  • Terminal dock (xterm.js) — ❭_ in the sidebar, the topbar button, or Ctrl+\`` opens a docked terminal running a real neurosploitREPL session. Its stdout is streamed **unstripped**, so the harness's own colour and box-drawn panels render as they do in a local shell. Line editing (echo, ←/→, history,Tabslash-command completion,Ctrl+C/L/U/A/E`) is local because the child is spawned over a pipe, not a PTY, and therefore never echoes. The target picker in its header switches between a standalone session and the running engagement, so mid-run instructions go to the same process that is doing the testing.
  • Real REPL underneath run/whitebox/greybox — the wizard scripts an actual interactive neurosploit session instead of a one-shot CLI call, so it keeps reading stdin while the engagement streams. The Activity log tab grows a ❭ prompt box to send /status, /stop, /continue, or a plain-language instruction mid-run. host/aitest/skills stay one-shot (their onboarding scope picker can't be scripted over piped stdin).
cd neurosploit-rs && cargo build --release   # build the CLI once
node web/server.js                            # → http://localhost:4173

Zero npm dependencies (Node ≥18, built-ins only: http, child_process, events, fs).

API reference: API.md.

Layout

web/
├── server.js         backend: static server + agents_md/runs reader + CLI process manager
├── public/
│   ├── index.html     SPA shell
│   ├── style.css       lead-board / live-run / terminal-dock styling
│   ├── app.js          client logic (fetch + EventSource + terminal, no framework)
│   └── vendor/         xterm.js + fit addon (vendored; nothing is fetched at runtime)
├── API.md
└── package.json