Add native iOS app with App Store preparation
iOS app (ios/, SwiftUI, iOS 17+) in the web UI's styling with the Kamon logo. It covers everything the web interface does except password, API tokens and backups: dashboard, peers with search and filter, peer detail with traffic charts, add/edit peers, one-time config with QR code and share sheet, server settings with apply bar, app settings, data retention and log viewer. - Pairing by QR code or pasted pairing code; token kept in the keychain; self-signed certificates are pinned by SHA-256 fingerprint. - Colour providers and logo drawing are nonisolated: SwiftUI's background renderer calls them, and main-actor closures crashed there when the camera scanner was open. - App Store: version 1.0, export compliance, privacy manifest, app icon, release.sh (archive and upload), listing text, review notes and 6.9" screenshots in ios/AppStore. Server: - Full-access API tokens may use settings, logs and restart; password, tokens, backup/restore and the admin username stay admin-only. - Web pairing dialog gains "Copy pairing code". - The development simulator reports health checks in Linux wording. Claude-Session: https://claude.ai/code/session_01RAnLbyQZ5ZTA7KqwXP98nw
This commit is contained in:
@@ -117,8 +117,9 @@ After editing `config.json` by hand, run `sudo systemctl reload ghostwire`.
|
||||
|
||||
Base path `/api/v1`. The web interface signs in with a session cookie. Apps and
|
||||
scripts use `Authorization: Bearer <token>`; create the token under Settings →
|
||||
Pair iOS app. A read-only token may only use GET. Tokens cannot use the admin
|
||||
endpoints.
|
||||
Pair iOS app. A read-only token may only use GET. Full-access tokens can do
|
||||
everything the web interface does except the admin-only endpoints: password,
|
||||
API tokens, backup and restore, and changing the admin username.
|
||||
|
||||
```
|
||||
POST /auth/login · /auth/logout GET /auth/me POST /auth/password (admin)
|
||||
@@ -128,8 +129,9 @@ GET /peers POST /peers (returns the config and QR once)
|
||||
GET /peers/{id} PATCH /peers/{id} DELETE /peers/{id}
|
||||
POST /peers/{id}/enable | /disable | /issue-config
|
||||
GET /peers/{id}/stats?range=…
|
||||
admin: GET|PATCH /settings · POST /restart · GET|POST /tokens · DELETE /tokens/{id}
|
||||
GET /logs?level=&limit=&audit=1 · GET /logs/download · GET /backup · POST /restore
|
||||
GET /settings PATCH /settings POST /restart
|
||||
GET /logs?level=&limit=&audit=1 GET /logs/download
|
||||
admin: GET|POST /tokens · DELETE /tokens/{id} · GET /backup · POST /restore
|
||||
```
|
||||
|
||||
Traffic is reported from the peer's point of view: `down` is what the peer
|
||||
@@ -141,6 +143,20 @@ GHOSTWIRE's rules sit in their own nftables table. An accept there cannot
|
||||
override a drop in another table, so if ufw or firewalld is active, allow UDP
|
||||
51820 (and TCP 443/80) in that firewall too.
|
||||
|
||||
## iOS app
|
||||
|
||||
`ios/` holds the native iPhone app (SwiftUI, iOS 17+). It does everything the
|
||||
web interface does except password, API tokens and backups. Pair it in the web
|
||||
interface under Settings → Pair iOS app: scan the QR code, or tap "Copy pairing
|
||||
code" and paste it into the app's "Enter manually". Self-signed certificates are
|
||||
pinned during pairing.
|
||||
|
||||
- Open `ios/GHOSTWIRE.xcodeproj` in Xcode to build and run.
|
||||
- `TEAM_ID=<your team> ios/release.sh` archives and uploads a build to App Store
|
||||
Connect.
|
||||
- `ios/AppStore/` has the store listing text, privacy details, review notes and
|
||||
6.9-inch screenshots.
|
||||
|
||||
## Development
|
||||
|
||||
On macOS (or any non-Linux system), `make dev` starts the app on
|
||||
|
||||
Reference in New Issue
Block a user