* Add umedbazarov/ruh-vpn: VPN/proxy manager for sing-box New community plugin: bar widget, panel, service and control-center shortcut for managing SSH, VLESS, VMess, Shadowsocks and SOCKS5 connections through sing-box, with routing presets, custom rules, system-proxy/TUN modes and a kill switch. The bundled Python backend serves a loopback control API protected by a per-launch bearer token. * Address review: sanitize kill-switch ruleset, scope TUN capability, fix mux error path, disclose DNS - kill switch: only pre-resolved, canonicalized literal IPs enter the nft ruleset; domains are resolved first and anything unparseable is dropped, so subscription-supplied addresses can no longer inject nft syntax - TUN: CAP_NET_ADMIN is granted to a plugin-private copy of sing-box in a 0700 directory instead of the shared system binary; the copy is refreshed (clearing the cap) when the system binary changes, and the legacy grant on the shared binary is removed in the same polkit prompt - fix NameError in the mux startup failure path (undefined mux_name) that hid the log tail and skipped teardown - README: disclose plain-UDP DNS endpoints (8.8.8.8 via tunnel, 223.5.5.5 direct in rules mode) alongside the TUN DoH endpoint --------- Co-authored-by: Umedjon Bazarov <170195993+UmedjonBA@users.noreply.github.com>
40 lines
1.1 KiB
Python
40 lines
1.1 KiB
Python
from backend.models.server import (
|
|
SENSITIVE_FIELDS,
|
|
parse_server,
|
|
server_to_dict,
|
|
server_to_public_dict,
|
|
)
|
|
|
|
|
|
def test_public_dict_strips_secrets():
|
|
server = parse_server({
|
|
"id": "s1", "name": "n", "protocol": "vless",
|
|
"address": "example.com", "port": 443,
|
|
"uuid": "11111111-2222-3333-4444-555555555555",
|
|
})
|
|
full = server_to_dict(server)
|
|
public = server_to_public_dict(server)
|
|
assert full["uuid"]
|
|
for key in SENSITIVE_FIELDS:
|
|
assert key not in public
|
|
assert public["address"] == "example.com"
|
|
assert public["port"] == 443
|
|
|
|
|
|
def test_public_dict_ssh_password():
|
|
server = parse_server({
|
|
"id": "s2", "name": "n", "protocol": "ssh",
|
|
"host": "example.com", "port": 22, "user": "root", "password": "pw",
|
|
})
|
|
public = server_to_public_dict(server)
|
|
assert "password" not in public
|
|
assert public["user"] == "root"
|
|
|
|
|
|
def test_socks_alias():
|
|
server = parse_server({
|
|
"id": "s3", "name": "n", "protocol": "socks",
|
|
"host": "example.com", "port": 1080,
|
|
})
|
|
assert server.protocol == "socks5"
|