fix: send WS JWT as bare subprotocol name; CSSOM inline styles; open mgmt services on public zone
- websocket.js passes the raw JWT as the Sec-WebSocket-Protocol subprotocol (no 'Bearer ' prefix): subprotocol names must be valid RFC 6455 tokens, and the space in 'Bearer <token>' made the browser reject the constructor with a SyntaxError. - daemon accepts a JWT-shaped subprotocol plus the legacy 'Bearer <token>' form via _extract_ws_token; unit tests in tests/test_ws_auth.py. - vdom.js applies inline styles through el.style (CSSOM) instead of setAttribute, which the management-domain CSP (no 'unsafe-inline') blocks. - install.sh opens http/https/ssh on the public zone alongside WAN setup. - docs (hoover.md, security.md) updated to match.
This commit is contained in:
@@ -416,6 +416,11 @@ else
|
||||
"$(jq -n --arg zone "public" --arg iface "$WAN_IFACE" \
|
||||
'{zone: $zone, interfaces: [$iface]}')" \
|
||||
"WAN interface assigned to public zone"
|
||||
|
||||
# Open management services (HTTP, HTTPS, SSH) on the public/WAN zone
|
||||
_daemon_post "/firewall/zones/services" \
|
||||
"$(jq -n '{zone: "public", services: ["http", "https", "ssh"]}')" \
|
||||
"Management services opened on public zone (http, https, ssh)"
|
||||
fi
|
||||
|
||||
if [[ -n "$LAN_IFACES" ]]; then
|
||||
|
||||
Reference in New Issue
Block a user