Commit Graph
13 Commits
Author SHA1 Message Date
sysopsandClaude Sonnet 5 3e57de1b44 Make Start/Stop enable/disable the wg-quick unit, not just start/stop it
A server brought up via the UI stayed active but not enabled, so a reboot
silently dropped it (and its PostUp cross-tunnel routes) with no error to
point at. Start now runs enable --now, Stop runs disable --now, so
"running now" and "survives a reboot" are the same action.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ATVUwTa4Pqwq26orW5BcDW
2026-07-29 13:37:44 +02:00
sysopsandClaude Sonnet 5 83b1da291f Add per-server NAT egress, ip_forward auto-enable, OPNsense import review checklist
- ServerSetting gains WanInterface/EgressSNATIP for optional per-server
  masquerade/SNAT of client traffic, isolated in each server's own
  nftables table
- wireguard.Start/Restart now ensure net.ipv4.ip_forward and
  net.ipv6.conf.all.forwarding are enabled before bringing an interface up
- OPNsense config.xml import now parses staticroutes/filter/nat rules and
  surfaces them as a manual-review checklist in the preview UI (never
  auto-applied)

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01ATVUwTa4Pqwq26orW5BcDW
2026-07-29 13:08:52 +02:00
sysopsandClaude Sonnet 5 34bc8f76f9 Add per-user TOTP 2FA, client-level user assignment, self-service portal
- TOTP (RFC 6238, stdlib-only) enrollment in profile, login step-up,
  admin emergency reset.
- Admins can grant a user visibility into individual clients
  (User.ClientIDs) in addition to whole-server access (User.ServerIDs).
- New "My Access" page: non-admin users see only their assigned clients
  (view/QR/download only, no management), reachable from the main nav.
- GetUser/GetUsers now redact TOTPSecret before returning JSON.

No Go toolchain was available while writing this - not yet build-verified.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PvrfUytqd74H6WcQkRzFM4
2026-07-25 00:42:05 +02:00
sysopsandClaude Sonnet 5 c29edfdcc3 Add wg-quick/systemctl service control and bulk-delete list views
Per-server Start/Stop/Restart via systemd wg-quick@<iface>.service units
plus live status badge, and a table/list-view toggle with checkbox
bulk-delete for both the server list and per-server client list.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01PvrfUytqd74H6WcQkRzFM4
2026-07-25 00:19:13 +02:00
sysopsandClaude Sonnet 5 067d0af323 Fix "no such file" error creating clients on non-default servers
SuggestIPAllocation always looked up the legacy "wg0" server regardless
of which server the request was for, so any setup without a migrated
wg0 (i.e. every fresh multi-server install) failed with
"open db/servers/wg0.json: no such file or directory" when adding a
new client.

Now accepts an optional server_id query param (falling back to wg0 for
the legacy bare routes), and the per-server clients page passes its
own server ID.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 23:39:26 +02:00
sysopsandClaude Sonnet 5 8a92958a84 Update DEVLOG session log
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 23:27:13 +02:00
sysopsandClaude Sonnet 5 fc0d192e59 Port upstream security fixes and features from ngoduykhanh/wireguard-ui
- Escape HTML in client list and wake-on-LAN names to prevent XSS
- Log successful/failed login attempts with remote address
- Fix leading-comma bug in AllowedIPs template when only extra allowed IPs are set
- Add PreUp script support for server interfaces (alongside existing PostUp/PreDown/PostDown)
- Fix endpoint parsing to support IPv6 addresses (upstream PR #223)

Cherry-picked from upstream PRs #656, #653, #680, #673, #223.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 23:26:30 +02:00
sysopsandClaude Sonnet 5 58db6839c3 Remove legacy default-server page, unify on multi-server registry
Deletes /wg-server (route, handlers, template) entirely and adds generic
/servers/:id/interface and /servers/:id/keypair endpoints + UI in the
All Servers page, so every server (including the default one) is managed
through the same per-server registry. Drops the write-through dual-write
hacks that kept the old single-server collection in sync - the registry
is now the single source of truth. One-time legacy-install migration path
is untouched.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 16:27:17 +02:00
sysopsandClaude Sonnet 5 2212141ba3 Clarify server nav labels (Default Server Interface vs All Servers)
No route/logic changes - pure label cleanup so the legacy default-server
editor and the multi-server management page are no longer confusable.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-12 12:54:29 +02:00
sysops 31f504e61b Document current product capabilities (multi-server CRUD, per-server access control, confirmed gaps) 2026-07-11 23:53:43 +02:00
sysopsandClaude Sonnet 5 867dc7740a Replace from-scratch rewrite with real ngoduykhanh/wireguard-ui fork
The from-scratch Go rewrite had unresolved bugs (missing go.sum, UI
404s, path issues) from being built without a working local Go
toolchain to verify against. Switching strategy: use the actual
upstream wireguard-ui codebase (proven, battle-tested single-server
manager) as the base, and extend it for multi-server support instead
of re-deriving everything from zero.

Kept our own installers (bootstrap.sh, update.sh, scripts/install.sh,
scripts/proxmox-install.sh) - these still apply, just need updating
to build/install the upstream module layout instead of the old
cmd/wireguard-ui-multi structure.

Module path intentionally left as upstream's own
(github.com/ngoduykhanh/wireguard-ui) for now to avoid touching every
internal import; revisit if this needs to be fully rebranded.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-10 18:34:44 +02:00
sysopsandClaude Sonnet 5 9a1d8112e7 Add one-shot bootstrap installer script
Clones repo, installs deps (Go, wireguard-tools, nftables), builds
binary, and runs the native installer end-to-end via curl-pipe-bash.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-10 17:31:11 +02:00
sysopsandClaude Sonnet 5 3b3ffd8ebf Add wireguard-ui-multi core: multi-server DB, WireGuard manager, REST API, UI, installers
Implements the from-scratch multi-server WireGuard management fork per
CLAUDE.md spec: sqlite schema (servers/peers/audit_log/users), Curve25519
key generation, per-interface config rendering + wg-quick/systemd control,
nftables hook scaffolding, session+CSRF-protected REST API with QR code
and config download endpoints, a minimal vanilla-JS web UI, legacy
wg0.conf migration, and both a native installer and a Proxmox LXC
provisioning script (with auto-detected latest Debian template).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-07-10 02:53:14 +02:00