Skip to content

Feature: Merge Insiders-exclusive features - #2152

Merged
billz merged 20 commits into
masterfrom
feat/insiders-merge
Sep 29, 2026
Merged

billz merged 20 commits into
masterfrom
feat/insiders-merge

Conversation

@billz

@billz billz commented Sep 16, 2026

Copy link
Copy Markdown
Member

No description provided.

Ports three Insiders  plugin packages into plugins-available/.
The plugin discovery, install, and management pipeline (PluginManager,
PluginInstaller, PluginInterface) is already public infrastructure, so
these are additive: a captive portal via nodogsplash, a Tailscale VPN
exit-node plugin, and Wireshark packet capture support.
Reworks the Authentication page into a tabbed layout (login/general/
avatar) and adds two related Insiders features that share this UI.

- Custom user avatars: upload/reset a per-admin avatar image, shown
  in the top navbar via a new getUserAvatar() helper.
- Limited privilege user role: a second, non-admin credential set
  that can be enabled from Auth settings. Logging out to this role
  flips the existing RASPI_MONITOR_ENABLED read-only flag app-wide,
  so the limited user gets view access without further per-page
  gating logic.

HTTPAuth::login()/isValidCredentials() gain an optional $role param
to select between admin and limited credential validation, and
HTTPAuth::isNonPrivileged() reports the current mode.
Adds a toggle in Hotspot > Advanced settings that writes hostapd's
ap_isolate option, blocking wireless clients on the same AP from
seeing or reaching each other (useful for guest networks).
…ection

Adds four related Insiders features that live on the Networking and
System pages and share backend plumbing:

- Network devices: a Devices tab listing attached network interfaces
  (name, MAC, USB vid/pid, type) with per-device MAC address cloning
  and udev-rule-based type assignment, backed by NetDeviceHandler,
  NetDeviceService and the UdevRuleManager/UdevRulePrototypes udev
  rule catalog.
- MAC address cloning: the editable MAC field on the Devices tab,
  applied via `ip link set  address`.
- WLAN routing: a WLAN Routing tab that NATs traffic from a wireless
  client (STA) interface to another interface via iptables, with
  optional DHCP/dnsmasq config for the output interface.
- Mobile broadband: a Mobile Data tab (SIM PIN/APN) backed by
  MobileDataHandler, plus Huawei HiLink modem auto-connect via a
  udev-triggered systemd service, and USB tethering auto-routing via
  a udev rule that reuses the WLAN routing script.
- Inspect network adapters: an "Inspect adapters" tool on the System
  page (udev/ethtool details, supported modes, adapter up/down/cycle,
  and a health check) backed by get_adapter/test_adapter/
  set_adapter_state endpoints.

Fixed several bugs at the same time:
- NetDeviceHandler compared $mac to the undefined $newmac (wrong
  case) instead of $newMac, so MAC cloning never actually triggered.
- HostapdValidator's return array never included ap_isolate is a
  separate fix (previous commit); here, the Devices/Mobile Data save
  button had no working click handler (saveNetworkSettings/
  saveNetDeviceSettings were never defined), and several of its
  inputs were missing `name` attributes so no data would have been
  submitted anyway.
- includes/networking.php's WLAN routing "remove config" path called
  removeDHCPConfig/removeDnsmasqConfig, which didn't exist anywhere
  in the source, so saving with the static-IP checkbox unchecked
  would have fatally errored. Implemented them as the natural inverse
  of the existing save functions.
- Shell commands in NetDeviceService and UdevRuleManager interpolated
  device MAC/VID/PID into exec()/sed patterns without escaping;
  added escapeshellarg() and character-class sanitization.
- Excluded HuaweiModemService (unused, unwired, self-described as
  work-in-progress) and a get_hostapd_config.php endpoint that only
  served the excluded dual-AP feature.
Adds a Configurations tab to the WireGuard page for managing several
uploaded .conf files: activate one (symlinks it to wg0.conf and
restarts wg-quick@wg0) or delete one, each behind a confirmation
modal.

Hardened the new endpoints and the existing upload path: cfg_id and
uploaded filenames are now restricted to a safe character set before
being used to build paths passed to sudo rm/mv/ln, shell arguments
are wrapped with escapeshellarg() instead of interpolated raw, and
deleting/activating the reserved "wg0" id is rejected. Also fixed
get_wgkey.php's escapeshellcmd() downgrade from escapeshellarg() by
leaving the stronger existing quoting in place.
Adds a log level dropdown to Hotspot > Logging, backed by hostapd's
logger_syslog_level option. HostapdManager::getLogLevels() supplies
the options, and the level persists to hostapd.ini via the existing
LogEnable mode-state in deriveModeStates()/persistHostapdIni().
@billz
billz requested a review from ruralmeltdown September 16, 2026 18:59
@billz
billz merged commit e7e1edb into master Sep 29, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant