- Add POST /api/auth/change-username (password + OTP when 2FA is on, format/reserved-name checks, uniqueness) and a Change Username modal in Account.vue; use the real username for the 2FA provisioning URI. - Stop creating the built-in admin/password user; the initial admin is seeded only from OVPMON_INITIAL_ADMIN_USER/PASSWORD. - Reject 2FA-pending temporary tokens on all protected routes (Flask token_required, Profiler verify_token); only /api/auth/verify-2fa accepts them. - Stop logging the OTP and TOTP secret in enable_2fa. - Profiler: validate profile username (pattern + realpath checks in schema, router, pki and generator) to prevent path traversal. - Restrict CORS to the panel origin in Profiler and Flask APIs. - UI: header username no longer sticks to the hardcoded Admin fallback; it is synced from /user/me and updated after a rename. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
Core Monitoring Module (APP_CORE)
The Core Monitoring module provides the backend logic for collecting, extracting, and serving OpenVPN usage statistics.
Components
-
Mining API (
openvpn_api_v3.py):- A Flask-based REST API running on port
5001. - Serves real-time data, authentication (JWT), and historical statistics.
- Connects to the SQLite database
ovpmon.db.
- A Flask-based REST API running on port
-
Data Gatherer (
openvpn_gatherer_v3.py):- A background service/daemon.
- Parses OpenVPN server logs (
status.log). - Aggregates bandwidth usage into time-series tables (
usage_history,stats_hourly, etc.).
Configuration
Configuration is handled via config.ini (typically located in the project root or /etc/openvpn/monitor/).
Development
# Setup Environment
python3 -m venv venv
source venv/bin/activate
pip install -r requirements.txt
# Run API
python3 openvpn_api_v3.py
# Run Gatherer (in separate terminal)
python3 openvpn_gatherer_v3.py
API Documentation
Full API documentation is available in DOCS/Core_Monitoring/API_Reference.md.