Profiler: validate server/PKI settings before they reach OpenVPN config

- Schema validators on the update models (ports, subnet/mask, routes,
  DNS, public host, loopback-only management address, MTU/MSS, script
  paths, PKI DN fields, key size and lifetimes).
- Script paths must be root-owned, non-writable files directly inside
  /etc/openvpn/scripts (services/validation.py).
- Generators refuse values with newlines, quotes, backslashes or control
  characters; router maps validation errors to HTTP 400.
- Add change record and links.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
This commit is contained in:
iclaoudezinandClaude Sonnet 5.5 committed 2026-09-30 12:25:38 +00:00
1 parent 5de0501cbc
commit 05f44b9928
7 files changed
+279 -6

No files matched your search

+1
View File
@@ -13,6 +13,7 @@ Welcome to the documentation for the OpenVPN Monitor suite.
## 🛠 Changes and results
- [Security hardening (2026-09-30)](../Changes/2026-09-30_Security_Hardening.md)
- [Admin username change (2026-09-30)](../Changes/2026-09-30_Admin_Username_Change.md)
- [Settings validation (2026-09-30)](../Changes/2026-09-30_Settings_Validation.md)
- [Egress via Hysteria2 (2026-09-30)](../Changes/2026-09-30_Egress_via_Hysteria2.md)
## 🔍 Core Monitoring (`APP_CORE`)