- Add POST /api/auth/change-username (password + OTP when 2FA is on, format/reserved-name checks, uniqueness) and a Change Username modal in Account.vue; use the real username for the 2FA provisioning URI. - Stop creating the built-in admin/password user; the initial admin is seeded only from OVPMON_INITIAL_ADMIN_USER/PASSWORD. - Reject 2FA-pending temporary tokens on all protected routes (Flask token_required, Profiler verify_token); only /api/auth/verify-2fa accepts them. - Stop logging the OTP and TOTP secret in enable_2fa. - Profiler: validate profile username (pattern + realpath checks in schema, router, pki and generator) to prevent path traversal. - Restrict CORS to the panel origin in Profiler and Flask APIs. - UI: header username no longer sticks to the hardcoded Admin fallback; it is synced from /user/me and updated after a rename. Co-Authored-By: Claude Sonnet 5.5 <noreply@anthropic.com>
46 lines
1.3 KiB
Python
46 lines
1.3 KiB
Python
import uvicorn
|
|
from fastapi import FastAPI
|
|
import sys
|
|
import os
|
|
|
|
# Add project root to sys.path explicitly to ensure absolute imports work
|
|
import os
|
|
sys.path.append(os.path.dirname(os.path.abspath(__file__)))
|
|
|
|
from database import engine, Base
|
|
from routers import system, server, profiles, server_process
|
|
from utils.logging import setup_logging
|
|
from fastapi.middleware.cors import CORSMiddleware
|
|
|
|
# Create Database Tables
|
|
Base.metadata.create_all(bind=engine)
|
|
|
|
setup_logging()
|
|
|
|
app = FastAPI(
|
|
title="OpenVPN Profiler API",
|
|
description="REST API for managing OpenVPN profiles and configuration",
|
|
version="1.0.0"
|
|
)
|
|
|
|
# Enable CORS
|
|
app.add_middleware(
|
|
CORSMiddleware,
|
|
allow_origins=["https://213.226.125.13:8088"],
|
|
allow_credentials=True,
|
|
allow_methods=["GET", "POST", "PUT", "DELETE"],
|
|
allow_headers=["Authorization", "Content-Type"],
|
|
)
|
|
|
|
app.include_router(system.router, prefix="/api", tags=["System"])
|
|
app.include_router(server.router, prefix="/api", tags=["Server"])
|
|
app.include_router(profiles.router, prefix="/api", tags=["Profiles"])
|
|
app.include_router(server_process.router, prefix="/api", tags=["Process Control"])
|
|
|
|
@app.get("/")
|
|
def read_root():
|
|
return {"message": "Welcome to OpenVPN Profiler API"}
|
|
|
|
if __name__ == "__main__":
|
|
uvicorn.run("main:app", host="0.0.0.0", port=8000, reload=True)
|