20 Commits
Author SHA1 Message Date
iclaoudezinandClaude Sonnet 5.5 9ffdbfa259 Publish CRL for the unprivileged OpenVPN user so crl_verify works
- ovpmon-helper: new publish-crl command (validated copy of pki/crl.pem to
  /etc/openvpn/crl.pem, root:root 644); crl-verify allowlisted only for
  that path; CRL is refreshed on service start/restart.
- Profiler: publish after gen-crl (init/revoke) and on server/configure;
  generator renders the published path when running unprivileged.
- doas rule for publish-crl; docs and helper copy updated.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:38:30 +00:00
iclaoudezinandClaude Sonnet 5.5 6f9e800779 Run API services unprivileged; add root helper for OpenVPN config and service control
- Profiler: when not root, render server.conf to the staging dir and let
  the root helper validate (directive allowlist) and install it; control
  the openvpn service through the helper (doas, fixed commands).
- Add ovpmon-helper and doas rules under DOCS/General/privilege-separation.
- Document the design, rollout, results and limitations.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:33:15 +00:00
iclaoudezinandClaude Sonnet 5.5 05f44b9928 Profiler: validate server/PKI settings before they reach OpenVPN config
- Schema validators on the update models (ports, subnet/mask, routes,
  DNS, public host, loopback-only management address, MTU/MSS, script
  paths, PKI DN fields, key size and lifetimes).
- Script paths must be root-owned, non-writable files directly inside
  /etc/openvpn/scripts (services/validation.py).
- Generators refuse values with newlines, quotes, backslashes or control
  characters; router maps validation errors to HTTP 400.
- Add change record and links.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:25:38 +00:00
iclaoudezinandClaude Sonnet 5.5 5de0501cbc Compose: require JWT secret, seed admin via env, stop publishing internal ports
- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
  APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
  host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:14:22 +00:00
iclaoudezinandClaude Sonnet 5.5 11c1b6379b Harden auth and API: username change, 2FA fixes, input validation
- Add POST /api/auth/change-username (password + OTP when 2FA is on,
  format/reserved-name checks, uniqueness) and a Change Username modal
  in Account.vue; use the real username for the 2FA provisioning URI.
- Stop creating the built-in admin/password user; the initial admin is
  seeded only from OVPMON_INITIAL_ADMIN_USER/PASSWORD.
- Reject 2FA-pending temporary tokens on all protected routes (Flask
  token_required, Profiler verify_token); only /api/auth/verify-2fa
  accepts them.
- Stop logging the OTP and TOTP secret in enable_2fa.
- Profiler: validate profile username (pattern + realpath checks in
  schema, router, pki and generator) to prevent path traversal.
- Restrict CORS to the panel origin in Profiler and Flask APIs.
- UI: header username no longer sticks to the hardcoded Admin fallback;
  it is synced from /user/me and updated after a rename.

Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
2026-09-30 12:03:36 +00:00
Антон 14ffd64801 fix revocation list in server template 2026-02-08 19:43:58 +03:00
Антон e5c0e154b5 fix apply config event 2026-02-08 19:10:35 +03:00
Антон 0ccdfcf7bf fix process restart event 2026-02-08 17:53:14 +03:00
Антон f7fe266571 minor fix for mangle tables in entrypoint.sh 2026-02-07 22:10:27 +03:00
Антон 8fd44fc658 minor fix for mangle tables in entrypoint.sh 2026-02-07 22:02:22 +03:00
Антон 961de020fb container detection implemented 2026-02-07 14:51:15 +03:00
Антон 195d40daa2 fix entrypoint.sh stage-2 2026-02-07 14:37:57 +03:00
Антон 0961daedce fix entrypoint.sh 2026-02-07 14:30:45 +03:00
Антон 9d10bb97c7 fix missing pki path inside container 2026-02-07 14:16:49 +03:00
Антон 6131bcaba9 fix dev tun and sysctl ip_forward error 2026-02-07 14:07:47 +03:00
Антон f9df3f8d05 fix missing path to db 2026-02-07 14:01:20 +03:00
Антон 4bd4127bb5 profiler module moved from static config to environment dpendent config 2026-02-07 13:51:52 +03:00
Антон 5260e45bd8 nginx template fix 2026-02-06 21:14:52 +03:00
Антон 0d0761cb31 docker support 2026-02-05 07:36:25 +03:00
Антон fcb8f6bac7 new awesome build 2026-01-28 22:37:47 +03:00