mirror of
https://github.com/freedombox/FreedomBox.git
synced 2026-08-26 12:46:08 +00:00
i2p: Add protection to local service using firewall
Tests: - When app is freshly installed, nft rules are inserted. - Trying to connect to local daemon from fbx user fails. - Functional tests pass. Signed-off-by: Sunil Mohan Adapa <sunil@medhas.org> Reviewed-by: James Valleroy <jvalleroy@mailbox.org>
This commit is contained in:
parent
489c536805
commit
c4241abfe8
@ -8,7 +8,8 @@ from plinth import frontpage, menu
|
|||||||
from plinth.daemon import Daemon
|
from plinth.daemon import Daemon
|
||||||
from plinth.modules.apache.components import Webserver
|
from plinth.modules.apache.components import Webserver
|
||||||
from plinth.modules.backups.components import BackupRestore
|
from plinth.modules.backups.components import BackupRestore
|
||||||
from plinth.modules.firewall.components import Firewall
|
from plinth.modules.firewall.components import (Firewall,
|
||||||
|
FirewallLocalProtection)
|
||||||
from plinth.modules.i2p.resources import FAVORITES
|
from plinth.modules.i2p.resources import FAVORITES
|
||||||
from plinth.modules.users.components import UsersAndGroups
|
from plinth.modules.users.components import UsersAndGroups
|
||||||
from plinth.package import Packages
|
from plinth.package import Packages
|
||||||
@ -38,7 +39,7 @@ class I2PApp(app_module.App):
|
|||||||
|
|
||||||
app_id = 'i2p'
|
app_id = 'i2p'
|
||||||
|
|
||||||
_version = 1
|
_version = 2
|
||||||
|
|
||||||
def __init__(self):
|
def __init__(self):
|
||||||
"""Create components for the app."""
|
"""Create components for the app."""
|
||||||
@ -78,6 +79,10 @@ class I2PApp(app_module.App):
|
|||||||
is_external=False)
|
is_external=False)
|
||||||
self.add(firewall)
|
self.add(firewall)
|
||||||
|
|
||||||
|
firewall_local_protection = FirewallLocalProtection(
|
||||||
|
'firewall-local-protection-i2p', ['7657'])
|
||||||
|
self.add(firewall_local_protection)
|
||||||
|
|
||||||
webserver = Webserver('webserver-i2p', 'i2p-freedombox',
|
webserver = Webserver('webserver-i2p', 'i2p-freedombox',
|
||||||
urls=['https://{host}/i2p/'])
|
urls=['https://{host}/i2p/'])
|
||||||
self.add(webserver)
|
self.add(webserver)
|
||||||
@ -96,14 +101,16 @@ class I2PApp(app_module.App):
|
|||||||
"""Install and configure the app."""
|
"""Install and configure the app."""
|
||||||
super().setup(old_version)
|
super().setup(old_version)
|
||||||
|
|
||||||
self.disable()
|
if not old_version:
|
||||||
# Add favorites to the configuration
|
self.disable()
|
||||||
for fav in FAVORITES:
|
# Add favorites to the configuration
|
||||||
privileged.add_favorite(fav['name'], fav['url'],
|
for fav in FAVORITES:
|
||||||
fav.get('description'), fav.get('icon'))
|
privileged.add_favorite(fav['name'], fav['url'],
|
||||||
|
fav.get('description'),
|
||||||
|
fav.get('icon'))
|
||||||
|
|
||||||
# Tunnels to all interfaces
|
# Tunnels to all interfaces
|
||||||
for tunnel in tunnels_to_manage:
|
for tunnel in tunnels_to_manage:
|
||||||
privileged.set_tunnel_property(tunnel, 'interface', '0.0.0.0')
|
privileged.set_tunnel_property(tunnel, 'interface', '0.0.0.0')
|
||||||
|
|
||||||
self.enable()
|
self.enable()
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user