mirror of
https://github.com/freedombox/FreedomBox.git
synced 2026-08-26 12:46:08 +00:00
calibre: Add protection to local service using firewall
Tests: - When app is freshly installed, nft rules are inserted. - When app is upgraded from older version, nft rules are inserted. - When app is enabled/disabled, nft rules are added/removed. - When app is uninstalled, rules are removed - Inserted rules are after the basic setup rules inserted firewall app. - Trying to connect to local daemon from fbx user fails. Trying to access as root user or apache succeeds. Test connecting with 'nc localhost <port>'. - Functional tests pass. Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org> Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
This commit is contained in:
parent
4bf347dbe3
commit
05e5ec4011
@ -10,7 +10,8 @@ from plinth import cfg, frontpage, menu
|
|||||||
from plinth.daemon import Daemon
|
from plinth.daemon import Daemon
|
||||||
from plinth.modules.apache.components import Webserver
|
from plinth.modules.apache.components import Webserver
|
||||||
from plinth.modules.backups.components import BackupRestore
|
from plinth.modules.backups.components import BackupRestore
|
||||||
from plinth.modules.firewall.components import Firewall
|
from plinth.modules.firewall.components import (Firewall,
|
||||||
|
FirewallLocalProtection)
|
||||||
from plinth.modules.users.components import UsersAndGroups
|
from plinth.modules.users.components import UsersAndGroups
|
||||||
from plinth.package import Packages
|
from plinth.package import Packages
|
||||||
from plinth.utils import format_lazy
|
from plinth.utils import format_lazy
|
||||||
@ -40,7 +41,7 @@ class CalibreApp(app_module.App):
|
|||||||
|
|
||||||
app_id = 'calibre'
|
app_id = 'calibre'
|
||||||
|
|
||||||
_version = 1
|
_version = 2
|
||||||
|
|
||||||
DAEMON = 'calibre-server-freedombox'
|
DAEMON = 'calibre-server-freedombox'
|
||||||
|
|
||||||
@ -78,6 +79,10 @@ class CalibreApp(app_module.App):
|
|||||||
ports=['http', 'https'], is_external=True)
|
ports=['http', 'https'], is_external=True)
|
||||||
self.add(firewall)
|
self.add(firewall)
|
||||||
|
|
||||||
|
firewall_local_protection = FirewallLocalProtection(
|
||||||
|
'firewall-local-protection-calibre', ['8844'])
|
||||||
|
self.add(firewall_local_protection)
|
||||||
|
|
||||||
webserver = Webserver('webserver-calibre', 'calibre-freedombox',
|
webserver = Webserver('webserver-calibre', 'calibre-freedombox',
|
||||||
urls=['https://{host}/calibre'])
|
urls=['https://{host}/calibre'])
|
||||||
self.add(webserver)
|
self.add(webserver)
|
||||||
@ -98,7 +103,8 @@ class CalibreApp(app_module.App):
|
|||||||
def setup(self, old_version):
|
def setup(self, old_version):
|
||||||
"""Install and configure the app."""
|
"""Install and configure the app."""
|
||||||
super().setup(old_version)
|
super().setup(old_version)
|
||||||
self.enable()
|
if not old_version:
|
||||||
|
self.enable()
|
||||||
|
|
||||||
|
|
||||||
def validate_library_name(library_name):
|
def validate_library_name(library_name):
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user