Real per-server data isolation, the core ask behind the access-control
work: clients, config generation, and the client-management UI are now
scoped by server ID instead of implicitly operating on one global
"the server".
- util.DefaultServerID ("wg0") is the server every legacy bare route
now resolves to, so old and new routes share one consistent identity
instead of drifting apart.
- New /servers/:id/... routes (new-client, update-client, remove-client,
set-status, download, api/clients, api/client/:cid, api/apply-wg-config)
reuse the same handlers as the legacy routes via resolveServerID(c),
gated by RequireServerAccess middleware. Cross-server edits/deletes on
scoped routes are rejected (403) if a client belongs to a different
server.
- Fixes a real data leak: ApplyServerConfig previously wrote ALL clients
from ALL servers into whichever single wg.conf it targeted. It now
filters clients by server ID before generating a config, and resolves
each server's own ConfigFilePath/EndpointAddress via the new
ServerSetting record instead of the app-wide GlobalSetting.
- WireGuardServerInterfaces/WireGuardServerKeyPair/GlobalSettingSubmit
(the legacy /wg-server and /global-settings edit routes) now write
through to the new per-server registry record for "wg0" in addition
to the legacy collection, so the two stay in sync until the legacy
routes are eventually retired.
- New templates/server_clients.html: per-server clone of clients.html
wired to the scoped endpoints, with a server name/id heading.
- base.html's shared "New Client" and "Apply Config" actions (used by
every page's nav buttons) now target the scoped route when a
serverID is present on the page, instead of always hitting the
legacy default-server endpoint regardless of which server's client
page is open.
Legacy bare routes (/, /new-client, /wg-server, ...) are untouched and
still fully functional against the default "wg0" server - nothing was
removed yet, per the incremental-delivery approach for this project.
41 lines
1.7 KiB
Go
41 lines
1.7 KiB
Go
package store
|
|
|
|
import (
|
|
"github.com/ngoduykhanh/wireguard-ui/model"
|
|
)
|
|
|
|
type IStore interface {
|
|
Init() error
|
|
GetUsers() ([]model.User, error)
|
|
GetUserByName(username string) (model.User, error)
|
|
SaveUser(user model.User) error
|
|
DeleteUser(username string) error
|
|
GetGlobalSettings() (model.GlobalSetting, error)
|
|
GetServer() (model.Server, error)
|
|
GetClients(hasQRCode bool) ([]model.ClientData, error)
|
|
GetClientByID(clientID string, qrCode model.QRCodeSettings) (model.ClientData, error)
|
|
SaveClient(client model.Client) error
|
|
DeleteClient(clientID string) error
|
|
SaveServerInterface(serverInterface model.ServerInterface) error
|
|
SaveServerKeyPair(serverKeyPair model.ServerKeypair) error
|
|
SaveGlobalSettings(globalSettings model.GlobalSetting) error
|
|
GetWakeOnLanHosts() ([]model.WakeOnLanHost, error)
|
|
GetWakeOnLanHost(macAddress string) (*model.WakeOnLanHost, error)
|
|
DeleteWakeOnHostLanHost(macAddress string) error
|
|
SaveWakeOnLanHost(host model.WakeOnLanHost) error
|
|
DeleteWakeOnHost(host model.WakeOnLanHost) error
|
|
GetPath() string
|
|
SaveHashes(hashes model.ClientServerHashes) error
|
|
GetHashes() (model.ClientServerHashes, error)
|
|
GetServers() ([]model.Server, error)
|
|
GetServerByID(serverID string) (model.Server, error)
|
|
CreateServer(server model.Server) error
|
|
DeleteServer(serverID string) error
|
|
GetServerSettings(serverID string) (model.ServerSetting, error)
|
|
SaveServerSettings(serverID string, settings model.ServerSetting) error
|
|
GetServerHashes(serverID string) (model.ClientServerHashes, error)
|
|
SaveServerHashes(serverID string, hashes model.ClientServerHashes) error
|
|
UpdateServerInterface(serverID string, serverInterface model.ServerInterface) error
|
|
UpdateServerKeyPair(serverID string, serverKeyPair model.ServerKeypair) error
|
|
}
|