Add one-time setup links as an alternative to the QR code

A config can now be handed over as a one-time link, valid for 1 h, 24 h or
7 days and protected by a PIN by default. Keys are made only when the link
is opened; the link works once and is revoked after 5 wrong PINs. Issuing a
new config offers the same choice, and the current config keeps working
until the link is used.

Remove the option to paste a client's public key, in the web UI, the API
and the iOS app.
This commit is contained in:
Daniel Redetzke
2026-10-03 23:10:28 +03:00
parent 55aaaa3a78
commit ef1988e4d0
17 changed files with 885 additions and 119 deletions
+15 -2
View File
@@ -8,14 +8,14 @@ import (
// The web UI and its icons are built into the binary. The UI talks only to
// /api/v1, the same API the iOS app uses.
//
//go:embed index.html app.js app.css favicon.svg apple-touch-icon.png
//go:embed index.html setup.html app.js setup.js app.css favicon.svg apple-touch-icon.png
var webFiles embed.FS
func webHandler() http.Handler {
files := http.FileServerFS(webFiles)
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
switch r.URL.Path {
case "/", "/app.js", "/app.css", "/favicon.svg", "/apple-touch-icon.png":
case "/", "/app.js", "/setup.js", "/app.css", "/favicon.svg", "/apple-touch-icon.png":
w.Header().Set("Cache-Control", "no-cache")
files.ServeHTTP(w, r)
case "/favicon.ico":
@@ -26,3 +26,16 @@ func webHandler() http.Handler {
}
})
}
// setupPage serves the page a setup link opens. The token stays in the URL;
// setup.js reads it from there and talks to /api/v1/setup.
func setupPage(w http.ResponseWriter, r *http.Request) {
b, err := webFiles.ReadFile("setup.html")
if err != nil {
http.Error(w, err.Error(), http.StatusInternalServerError)
return
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
w.Header().Set("Cache-Control", "no-store")
_, _ = w.Write(b)
}