- Add POST /api/auth/change-username (password + OTP when 2FA is on, format/reserved-name checks, uniqueness) and a Change Username modal in Account.vue; use the real username for the 2FA provisioning URI. - Stop creating the built-in admin/password user; the initial admin is seeded only from OVPMON_INITIAL_ADMIN_USER/PASSWORD. - Reject 2FA-pending temporary tokens on all protected routes (Flask token_required, Profiler verify_token); only /api/auth/verify-2fa accepts them. - Stop logging the OTP and TOTP secret in enable_2fa. - Profiler: validate profile username (pattern + realpath checks in schema, router, pki and generator) to prevent path traversal. - Restrict CORS to the panel origin in Profiler and Flask APIs. - UI: header username no longer sticks to the hardcoded Admin fallback; it is synced from /user/me and updated after a rename. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
OpenVPN Dashboard UI (APP_UI)
A Single Page Application (SPA) built with Vue 3 and Vite. It serves as the unified dashboard for monitoring and management.
Project Structure
src/views/: Page components (Dashboard, Login, Profiles, etc.).src/components/: Reusable widgets (Charts, Sidebar).src/stores/: Pinia state management (Auth, Client Data).
Configuration
Runtime configuration is loaded from /config.json (in public/) to allow environment-independent builds.
Development
npm install
npm run dev
# Access at http://localhost:5173
Documentation
See DOCS/UI/Architecture.md for detailed architecture notes.