38 Commits
Author SHA1 Message Date
iclaoudezinandClaude Sonnet 5.5 3836049230 Docs: add operations records (SUMMARY, Hysteria chain manifest, reboot test, plans)
- DOCS/Operations: current-state SUMMARY of the ENTRY deployment (access,
  install, egress via Hysteria2, security findings and fixes, risk
  assessment, commits/backups, open items), the Hysteria chain manifest
  with an OpenVPN Monitor section, reboot test results, and the plan and
  rollout records for settings validation and privilege separation.
- Link them from README and DOCS/General/Index.md.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:59:55 +00:00
iclaoudezinandClaude Sonnet 5.5 e1146ed4fe Docs: README security defaults and links to the privilege-separation files
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:43:45 +00:00
iclaoudezinandClaude Sonnet 5.5 9ffdbfa259 Publish CRL for the unprivileged OpenVPN user so crl_verify works
- ovpmon-helper: new publish-crl command (validated copy of pki/crl.pem to
  /etc/openvpn/crl.pem, root:root 644); crl-verify allowlisted only for
  that path; CRL is refreshed on service start/restart.
- Profiler: publish after gen-crl (init/revoke) and on server/configure;
  generator renders the published path when running unprivileged.
- doas rule for publish-crl; docs and helper copy updated.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:38:30 +00:00
iclaoudezinandClaude Sonnet 5.5 6f9e800779 Run API services unprivileged; add root helper for OpenVPN config and service control
- Profiler: when not root, render server.conf to the staging dir and let
  the root helper validate (directive allowlist) and install it; control
  the openvpn service through the helper (doas, fixed commands).
- Add ovpmon-helper and doas rules under DOCS/General/privilege-separation.
- Document the design, rollout, results and limitations.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:33:15 +00:00
iclaoudezinandClaude Sonnet 5.5 05f44b9928 Profiler: validate server/PKI settings before they reach OpenVPN config
- Schema validators on the update models (ports, subnet/mask, routes,
  DNS, public host, loopback-only management address, MTU/MSS, script
  paths, PKI DN fields, key size and lifetimes).
- Script paths must be root-owned, non-writable files directly inside
  /etc/openvpn/scripts (services/validation.py).
- Generators refuse values with newlines, quotes, backslashes or control
  characters; router maps validation errors to HTTP 400.
- Add change record and links.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:25:38 +00:00
iclaoudezinandClaude Sonnet 5.5 5de0501cbc Compose: require JWT secret, seed admin via env, stop publishing internal ports
- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
  APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
  host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:14:22 +00:00
iclaoudezinandClaude Sonnet 5.5 9b2882d5f4 Docs: concise README, split deployment guides, add change records
- README: short overview, quick start, config table and links.
- DOCS/General: Deployment_Docker.md and Deployment_Native.md (system
  services, HTTPS, host hardening); refresh Index.md.
- DOCS/Changes: security hardening, admin username change and egress
  via Hysteria2 with results and verification.
- Drop mentions of the built-in admin/password account.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:12:09 +00:00
iclaoudezinandClaude Sonnet 5.5 11c1b6379b Harden auth and API: username change, 2FA fixes, input validation
- Add POST /api/auth/change-username (password + OTP when 2FA is on,
  format/reserved-name checks, uniqueness) and a Change Username modal
  in Account.vue; use the real username for the 2FA provisioning URI.
- Stop creating the built-in admin/password user; the initial admin is
  seeded only from OVPMON_INITIAL_ADMIN_USER/PASSWORD.
- Reject 2FA-pending temporary tokens on all protected routes (Flask
  token_required, Profiler verify_token); only /api/auth/verify-2fa
  accepts them.
- Stop logging the OTP and TOTP secret in enable_2fa.
- Profiler: validate profile username (pattern + realpath checks in
  schema, router, pki and generator) to prevent path traversal.
- Restrict CORS to the panel origin in Profiler and Flask APIs.
- UI: header username no longer sticks to the hardcoded Admin fallback;
  it is synced from /user/me and updated after a rename.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:03:36 +00:00
Антон 14ffd64801 fix revocation list in server template 2026-02-08 19:43:58 +03:00
Антон e5c0e154b5 fix apply config event 2026-02-08 19:10:35 +03:00
Антон 0ccdfcf7bf fix process restart event 2026-02-08 17:53:14 +03:00
Антон 68c57c174e fix client config dir 2026-02-07 22:40:40 +03:00
Антон f7fe266571 minor fix for mangle tables in entrypoint.sh 2026-02-07 22:10:27 +03:00
Антон 8fd44fc658 minor fix for mangle tables in entrypoint.sh 2026-02-07 22:02:22 +03:00
Антон f6a81b3d7c update main README.md 2026-02-07 15:23:23 +03:00
Антон f177a89f0b analytics page fix 2026-02-07 15:11:33 +03:00
Антон 961de020fb container detection implemented 2026-02-07 14:51:15 +03:00
Антон 195d40daa2 fix entrypoint.sh stage-2 2026-02-07 14:37:57 +03:00
Антон 0961daedce fix entrypoint.sh 2026-02-07 14:30:45 +03:00
Антон 9d10bb97c7 fix missing pki path inside container 2026-02-07 14:16:49 +03:00
Антон 6131bcaba9 fix dev tun and sysctl ip_forward error 2026-02-07 14:07:47 +03:00
Антон f9df3f8d05 fix missing path to db 2026-02-07 14:01:20 +03:00
Антон 4bd4127bb5 profiler module moved from static config to environment dpendent config 2026-02-07 13:51:52 +03:00
Антон 5260e45bd8 nginx template fix 2026-02-06 21:14:52 +03:00
Антон bb1a3c9400 docker environment control improvement 2026-02-06 09:02:59 +03:00
Антон 0d0761cb31 docker support 2026-02-05 07:36:25 +03:00
Антон 97ec607a4b minor css fix 2026-01-29 22:48:57 +03:00
Антон fcb8f6bac7 new awesome build 2026-01-28 22:37:47 +03:00
Антон 848646003c update README to support new API endpoint for sessions 2026-01-12 11:47:20 +03:00
Антон 6df0f5e180 new calculation approach with unique sessions, new API endpoint to get list of active sessions, fix for UNDEF user, UI and Back to support certificate management still under development 2026-01-12 11:44:50 +03:00
Антон 839dd4994f new calculation approach with unique sessions, new API endpoint to get list of active sessions, fix for UNDEF user, UI and Back to support certificate management still under development 2026-01-12 11:43:22 +03:00
Антон 520dd04789 move legacy UI in .php to artifacts 2026-01-09 21:07:45 +03:00
Антон de09326c38 minor UI fix, minot data processing improvements 2026-01-09 21:05:02 +03:00
Антон facde3b80e minor UI fix 2026-01-09 18:00:53 +03:00
Антон f64f49a7a6 performance improvements, charts improvements, minor UI improvements 2026-01-09 17:50:45 +03:00
Антон 53a3a99309 minor readme improvements 2026-01-09 11:04:37 +03:00
Антон 9b501a8585 move from PHP to VUE, improved Certificate listning 2026-01-09 10:30:49 +03:00
Антон c9af0a5bb1 init commit 2026-01-09 01:05:50 +03:00