obfuscation layer: shim v2 on :28443 (token-gated, de-Ollama'd paths, nginx fingerprint), tailnet-only dashboard :47077 (token gate), secrets staged
This commit is contained in:
26
app.py
26
app.py
@@ -357,5 +357,31 @@ def api_stop():
|
||||
cfg = load_config(); cfg["stopped"] = True; save_config(cfg)
|
||||
return jsonify(ok=True)
|
||||
|
||||
# --- obfuscated remote access: token-gated listener on the tailnet IP only ---
|
||||
TAILNET_IP = "100.120.108.13"
|
||||
REMOTE_PORT = 47077
|
||||
try:
|
||||
OPERATOR_TOKEN = open(os.path.join(APP_DIR, "operator_token.txt")).read().strip()
|
||||
except Exception:
|
||||
OPERATOR_TOKEN = ""
|
||||
|
||||
@app.before_request
|
||||
def _gate_remote():
|
||||
"""Requests arriving on the tailnet listener must carry the token; localhost is free."""
|
||||
if request.host.startswith(f"{TAILNET_IP}:{REMOTE_PORT}") and OPERATOR_TOKEN:
|
||||
auth = request.headers.get("X-Auth-Token", "")
|
||||
# also accept ?t= for browser links
|
||||
if not auth:
|
||||
auth = request.args.get("t", "")
|
||||
from hmac import compare_digest
|
||||
if not compare_digest(auth, OPERATOR_TOKEN):
|
||||
return ("not found", 404)
|
||||
return None
|
||||
|
||||
def _run_remote():
|
||||
app.run(host=TAILNET_IP, port=REMOTE_PORT, threaded=True, use_reloader=False)
|
||||
|
||||
if __name__ == "__main__":
|
||||
import threading
|
||||
threading.Thread(target=_run_remote, daemon=True).start()
|
||||
app.run(host="127.0.0.1", port=8899, threaded=True)
|
||||
|
||||
Reference in New Issue
Block a user