- ovpmon-helper: new publish-crl command (validated copy of pki/crl.pem to
/etc/openvpn/crl.pem, root:root 644); crl-verify allowlisted only for
that path; CRL is refreshed on service start/restart.
- Profiler: publish after gen-crl (init/revoke) and on server/configure;
generator renders the published path when running unprivileged.
- doas rule for publish-crl; docs and helper copy updated.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- Profiler: when not root, render server.conf to the staging dir and let
the root helper validate (directive allowlist) and install it; control
the openvpn service through the helper (doas, fixed commands).
- Add ovpmon-helper and doas rules under DOCS/General/privilege-separation.
- Document the design, rollout, results and limitations.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- JWT_SECRET is mandatory (no more "supersecret" fallback).
- Pass OVPMON_INITIAL_ADMIN_USER/PASSWORD and OVPMON_CORS_ORIGINS to the
APIs; add restart policy and drop the obsolete compose "version".
- Publish only 80/tcp and 1194/udp; expose 5001 and 8000 on ovp-net.
- CORS origins now come from OVPMON_CORS_ORIGINS instead of a hardcoded
host (default: same-origin only).
- Update Docker/native deployment docs and README accordingly.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- README: short overview, quick start, config table and links.
- DOCS/General: Deployment_Docker.md and Deployment_Native.md (system
services, HTTPS, host hardening); refresh Index.md.
- DOCS/Changes: security hardening, admin username change and egress
via Hysteria2 with results and verification.
- Drop mentions of the built-in admin/password account.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
- Add POST /api/auth/change-username (password + OTP when 2FA is on,
format/reserved-name checks, uniqueness) and a Change Username modal
in Account.vue; use the real username for the 2FA provisioning URI.
- Stop creating the built-in admin/password user; the initial admin is
seeded only from OVPMON_INITIAL_ADMIN_USER/PASSWORD.
- Reject 2FA-pending temporary tokens on all protected routes (Flask
token_required, Profiler verify_token); only /api/auth/verify-2fa
accepts them.
- Stop logging the OTP and TOTP secret in enable_2fa.
- Profiler: validate profile username (pattern + realpath checks in
schema, router, pki and generator) to prevent path traversal.
- Restrict CORS to the panel origin in Profiler and Flask APIs.
- UI: header username no longer sticks to the hardcoded Admin fallback;
it is synced from /user/me and updated after a rename.
Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>