Commit Graph

61 Commits

Author SHA1 Message Date
Daniel Redetzke 2b7b41859d Live page: curved lines and speeds with one decimal
The chart draws download and upload as smooth curves that never dip
below zero or overshoot a peak, and speeds always show one decimal
from kbit/s up so the figures keep their shape as they change.
2026-10-05 20:28:56 +03:00
Daniel Redetzke ccf7b50c59 Live page: figures update without counting 2026-10-05 14:48:30 +03:00
Daniel Redetzke a82314ee94 Live page: 10-second averages for the figures and the table
The big figures, the per-peer speeds and the busiest-first order
average the last 5 steps instead of swinging with every burst, and the
figures sit in fixed-width columns so they no longer push each other
around. The charts still show every step.
2026-10-05 14:44:18 +03:00
Daniel Redetzke d83582eea1 Live page: streamed updates and a sliding chart
The server pushes each new step over server-sent events
(GET /api/v1/live/stream) the moment it is sampled, so updates no
longer arrive in uneven pairs. The chart slides left steadily between
steps instead of jumping, and the big numbers count to their new
value. Both stay still with reduced motion.
2026-10-05 14:39:35 +03:00
Daniel Redetzke 5f321f2979 Live page: online peers only 2026-10-05 14:34:08 +03:00
Daniel Redetzke 6661424daf Live page: the speed of every peer right now
A new Live page shows current download and upload per peer, updated
every 2 seconds, with the last 2 minutes as a chart and a small chart
per peer. The server reads the WireGuard counters every 2 seconds and
keeps 2 minutes in memory; GET /api/v1/live serves them, with since=
for only the newer steps. The dev simulator now adds traffic in
proportion to the time between samples.
2026-10-05 14:28:29 +03:00
Daniel Redetzke 456ae6a41e Dashboard: a range switch redraws only the traffic chart
The range buttons light up at once and fetch only the chart's stats,
like on the peer page, instead of reloading the whole dashboard.
2026-10-05 14:18:18 +03:00
Daniel Redetzke c7b4ca692e Dashboard: 24 h, 7 day and 30 day range on the traffic chart 2026-10-05 14:12:44 +03:00
Daniel Redetzke 6733bf2f3a Peer page: traffic chart opens on 24 hours 2026-10-05 14:06:05 +03:00
Daniel Redetzke e9bd3090a8 Charts: clock times and dates along the bottom
Traffic and latency charts label the x-axis with clock times every
3 hours (6 on phones, the date at midnight), or dates for the 7- and
30-day ranges. The hover readout for hourly bars shows the clock
time range instead of "3 h ago".
2026-10-05 14:01:10 +03:00
Daniel Redetzke 50467535a8 Remove old config copies from updates
Settings -> Upkeep -> Backup & restore lists the config.json.bak-* files
that update leaves behind and removes one or all of them; they hold the
same secrets as a backup. Removing needs a signed-in user and is logged.
After a successful update only the newest 3 copies are kept, and a copy
that would overwrite an older one (version unknown, or the same version
twice) gets the time appended. The backup card now also names preshared
keys and authenticator app secrets.

The update notice uses the existing compareVersions instead of its own.
v0.6.0
2026-10-05 12:34:22 +03:00
Daniel Redetzke 39dde98af5 Settings in groups; the log on its own page
Settings is grouped into Access (users, sign-in, iOS app and API tokens),
Web interface (address and HTTPS), Logs & history and Upkeep
(updates, backup). Session length moved to Sign-in and no longer asks for
a restart. Log level, log size and traffic history share one card; the
country lookup is its own switch. Each card says how it saves.

The log viewer moved to a new Log page in the sidebar, with a filter for
changes only, and the Dashboard's Log link opens it.
2026-10-05 12:11:32 +03:00
Daniel Redetzke 59c4fb5ff1 Update notice: a newer release shows in the web interface
Once a day the server asks Gitea or GitHub, as picked under Settings ->
Updates, for the latest release. A newer one shows as a pill in the
sidebar, a banner on the Dashboard and in the Updates card with its
release notes and the commands to update this server. Drafts and
pre-releases are ignored, nothing about the server is sent, and the check
can be switched off. POST /updates/check checks now.
v0.5.0
2026-10-05 11:59:27 +03:00
Daniel Redetzke 15d921019a Health card: addresses beside a list of checks
The public addresses stack on the left and the other checks are rows in
one list on the right, each with its raw setting right after the status.
Below 1000px the addresses move above the list.
2026-10-05 10:10:51 +03:00
Daniel Redetzke 2bc6465ea7 README: the iOS app is in beta testing; invites by email 2026-10-05 09:35:34 +03:00
Daniel Redetzke ef636e8a58 Health card: public addresses up top, checks as tiles
The public IPv4 and IPv6 addresses, with their uplink, lead the card.
Every other check is a tile with a plain-word status, the raw setting
and, when it fails, what is wrong. The header counts passing or failing
checks.
v0.4.0
2026-10-05 09:09:44 +03:00
Daniel Redetzke caa8774c02 Revert "Send adminUsername in /settings again"
This reverts commit c846345a1c.
2026-10-05 08:54:04 +03:00
Daniel Redetzke 1d3bce3da3 Send adminUsername in /settings again
iOS app builds before Companion 2c9cc1c cannot decode /settings without
it, and App Review still tests such builds. A test keeps it in place.
2026-10-05 08:51:19 +03:00
Daniel Redetzke ae89692ba9 API tokens no longer manage users, passwords or tokens
A full-access token could create a user or reset a password, sign in as
that user and so reach backups and two-step sign-in settings. Users,
passwords, API tokens and the sign-in rules in PATCH /settings now need
a signed-in user again. /auth/me no longer returns tokenId, and
/settings no longer returns adminUsername.
2026-10-05 08:41:18 +03:00
Daniel Redetzke dc002b7440 Show peer names in plain ink instead of underlined links 2026-10-05 01:57:00 +03:00
Daniel Redetzke cf1e1f7f63 Show dialogs again when an extension moves them
Bitwarden moves elements around in <body>. A moved dialog stayed open but
fell out of the top layer to the bottom of the page, so a confirmation
seemed to vanish and its checkbox stayed ticked unsaved.
2026-10-05 01:45:32 +03:00
Daniel Redetzke 592b738f10 Cap concurrent password checks and count attempts before checking
Every argon2 run takes 64 MiB and nothing limited how many ran at once,
so parallel sign-in attempts could run the server out of memory (8 at
once used about 600 MB). At most two now run at once; at most 16
sign-ins wait for one, more get HTTP 429. 30 parallel sign-ins peaked
at 275 MB.

A sign-in attempt now counts toward the lockout before its password is
checked, so parallel attempts cannot get past it; a right password
takes its own attempt back. IPv6 addresses are locked out by /64.
2026-10-05 00:23:05 +03:00
Daniel Redetzke e4a40ff0c3 Keep IPv6 router announcements working with forwarding on
With net.ipv6.conf.all.forwarding=1, Linux ignores router announcements
unless accept_ra is 2, so a server that gets its IPv6 route by SLAAC
(e.g. a Raspberry Pi at home) lost IPv6 once the route expired.

The sysctl file now also sets accept_ra=2 for the default and for every
network card and the IPv6 default-route interface, except where
accept_ra is 0. "update" rewrites the file, which fixes existing
installs. A new health check warns while the uplink still has
accept_ra=1.
v0.3.2
2026-10-05 00:10:13 +03:00
Daniel Redetzke fbca13e528 README: dashboard screenshot from v0.3.1 2026-10-04 23:01:17 +03:00
Daniel Redetzke 3069a3006e README: bring iOS app, tokens, config.json and lockout up to date 2026-10-04 22:54:48 +03:00
Daniel Redetzke f5052642c6 README: keep only the dashboard screenshot 2026-10-04 22:50:13 +03:00
Daniel Redetzke 00429ae484 Delete stored security keys v0.3.1 2026-10-04 22:35:19 +03:00
Daniel Redetzke 1de98f785b Passkeys only: drop adding security keys 2026-10-04 22:13:31 +03:00
Daniel Redetzke 0bafc3d7bc Japanese hover label on the passkey button 2026-10-04 22:03:12 +03:00
Daniel Redetzke 9d54d2d5ad Two-step sign-in: authenticator app, security keys and passkeys v0.3.0 2026-10-04 21:55:53 +03:00
Daniel Redetzke 420f1688ac Drop the tagline from the sign-in page 2026-10-04 21:02:37 +03:00
Daniel Redetzke d5a36572fb Fingerprint app.js, setup.js and app.css 2026-10-04 20:56:35 +03:00
Daniel Redetzke 7d875450c8 Sortable peers table, shorter connection history 2026-10-04 20:53:56 +03:00
Daniel Redetzke ce4f2bc36d More web interface pages 2026-10-04 20:47:12 +03:00
Daniel Redetzke bbf54680c3 Full-access tokens manage users, passwords and tokens v0.2.0 2026-10-04 20:37:46 +03:00
Daniel Redetzke 464788d944 Sign out from an icon in the account row 2026-10-04 20:21:00 +03:00
Daniel Redetzke 9394c9bc7a Web interface setting 2026-10-04 20:16:57 +03:00
Daniel Redetzke ab5fb131a3 Keep the sidebar in view on long pages
Beside the page, the sidebar now stays in place while the page scrolls,
so the account link and Sign out are always visible; it scrolls by
itself in very short windows. On a phone it still stacks above the page.
Also show the version with one 'v': release builds already start with it.
v0.1.1
2026-10-04 16:36:30 +03:00
Daniel Redetzke 500b7ef4b5 README: screenshots of the web interface
Seven pages captured from a demo instance with sample data from the
simulator: dashboard (under the introduction), peers, peer, server,
settings, my account and sign-in. Images live in screenshots/.
2026-10-04 16:31:01 +03:00
Daniel Redetzke 796618625c README: show the Hannya logo at the top 2026-10-04 16:14:54 +03:00
Daniel Redetzke 0444a0b2be My account page
The signed-in user's profile, password and own app tokens move from the
Settings card to their own page at #/account, ready for more user
functions. The sidebar footer links to it with the user's name. Users
can now set their own note; the page header shows when and from where
the session started, which the server now records. Settings keeps the
Users table, where your own row links to My account.
v0.1.0
2026-10-04 16:07:21 +03:00
Daniel Redetzke 15b1983a0b Multiple users, all admins
The single admin account becomes a list of users; config.json moves to
version 2 and the old admin is migrated on first start. Every user is an
admin. Sessions are tied to a user and their password, so deleting a user
or resetting a password signs them out at once. API tokens belong to the
user who made them and go away with that user.

Admins add users with a temporary password and choose whether it must be
changed at first sign-in; until then the API refuses everything but the
password change. Settings gets My account and Users cards, and the token
table shows each token's owner. 'GHOSTWIRE passwd [username]' resets any
user's password. A failed update now also restores config.json, since the
new version may have upgraded it.
2026-10-04 15:51:14 +03:00
Daniel Redetzke 34fb329e46 Hannya mark and Shippori Mincho B1 wordmark
Replace the Kamon ghost with the horned Hannya mask in favicon.svg,
apple-touch-icon.png, the web UI and the setup page. The wordmark and
katakana use Shippori Mincho B1 ExtraBold, bundled as a subset (ASCII
and katakana, 21 KB) under the SIL OFL and served from the binary.
2026-10-04 15:06:18 +03:00
Daniel Redetzke 4866d92216 Peers: optional latency check with per-peer setting
The server pings a peer's tunnel address every 30 s and shows the median
of the last 5 minutes in the peer list (with a 1-hour sparkline) and a
24-hour chart on the peer page. Off by default; "active" pings only
while the device sends traffic, "always" keeps the tunnel up.
2026-10-04 14:28:44 +03:00
Daniel Redetzke b2a91bb811 Move the iOS app to its own GHOSTWIRE-Companion repo 2026-10-04 12:10:45 +03:00
Daniel Redetzke ce9353a17d Show the Sign in button's label in katakana on hover 2026-10-04 02:36:17 +03:00
Daniel Redetzke 2fb49bb05b Keep the login button's text dark on hover 2026-10-04 02:34:29 +03:00
Daniel Redetzke 85cd0eebbd Sidebar logo links to the start page 2026-10-04 02:31:36 +03:00
Daniel Redetzke 5dbccfbdc6 Health: show IPv6 uplink and public IPv4/IPv6 addresses
The uplink check only reported the IPv4 default route. Split it into
IPv4 and IPv6 uplink rows, and add a public address row for each, read
from the uplink interface (private addresses are shown as behind NAT).
2026-10-04 00:39:13 +03:00
Daniel Redetzke ef66cd53d8 Interactive install, with flags kept for unattended installs
In a terminal, install now asks for the domain, Let's Encrypt email,
endpoint, WireGuard port and admin password, shows a summary and changes
nothing until confirmed. Re-runs offer the current settings and say how
many devices need a new config when the endpoint or port changes.

Flags still work and skip their question; -y or no terminal skips all
questions. New -port flag sets the WireGuard UDP port. Every value is
checked before the system is touched.
2026-10-03 23:46:04 +03:00