Add central host-wide firewall allow/block lists
New model.IPListEntry + jsondb CRUD, independent of any single WireGuard server. firewall.GenerateGlobalRuleset builds an nftables table (wireguard_ui_global) with allow/block sets evaluated at priority -10 - before every per-server table - so it applies to all traffic on the host, not just WireGuard. Allow entries always win over block entries. firewall.ApplyGlobal loads it live via `nft -f`, scoped to that one table. New "Global Firewall Lists" page (nav entry under Settings): add/delete entries, ruleset preview, "Apply now (live)" with an explicit confirm() warning since this affects the whole host's firewall, not just one server. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
bdcf1ec60c
commit
eb1913d400
+19
-9
@@ -8,18 +8,17 @@ import (
|
||||
"time"
|
||||
)
|
||||
|
||||
// Apply writes ruleset to a temp file and loads it with `nft -f`, after
|
||||
// first deleting the server's own table (ignoring the error - the table
|
||||
// may not exist yet on first apply). Only ever touches the single table
|
||||
// named by TableName(serverID), never any other nftables state.
|
||||
// Returns combined nft output for display, and an error if the load failed.
|
||||
func Apply(serverID, ruleset string) (string, error) {
|
||||
// applyTable writes ruleset to a temp file and loads it with `nft -f`,
|
||||
// after first deleting the given table (ignoring the error - the table may
|
||||
// not exist yet on first apply). Only ever touches that single table,
|
||||
// never any other nftables state.
|
||||
func applyTable(tableName, ruleset string) (string, error) {
|
||||
ctx, cancel := context.WithTimeout(context.Background(), 10*time.Second)
|
||||
defer cancel()
|
||||
|
||||
// best-effort: drop any previous version of this server's table so
|
||||
// reapplying is idempotent. Error ignored - table may not exist yet.
|
||||
_ = exec.CommandContext(ctx, "nft", "delete", "table", "inet", TableName(serverID)).Run()
|
||||
// best-effort: drop the previous version of this table so reapplying
|
||||
// is idempotent. Error ignored - table may not exist yet.
|
||||
_ = exec.CommandContext(ctx, "nft", "delete", "table", "inet", tableName).Run()
|
||||
|
||||
tmpFile, err := os.CreateTemp("", "wg-ui-multi-fw-*.nft")
|
||||
if err != nil {
|
||||
@@ -42,3 +41,14 @@ func Apply(serverID, ruleset string) (string, error) {
|
||||
}
|
||||
return string(out), nil
|
||||
}
|
||||
|
||||
// Apply loads a single server's ruleset live, scoped to TableName(serverID).
|
||||
func Apply(serverID, ruleset string) (string, error) {
|
||||
return applyTable(TableName(serverID), ruleset)
|
||||
}
|
||||
|
||||
// ApplyGlobal loads the host-wide allow/block list ruleset live, scoped to
|
||||
// GlobalTableName.
|
||||
func ApplyGlobal(ruleset string) (string, error) {
|
||||
return applyTable(GlobalTableName, ruleset)
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user