obfuscation layer: shim v2 on :28443 (token-gated, de-Ollama'd paths, nginx fingerprint), tailnet-only dashboard :47077 (token gate), secrets staged

This commit is contained in:
Hermes
2026-10-02 02:21:27 -07:00
parent b3c3cec909
commit 1e3aaf3193
5 changed files with 115 additions and 5 deletions

26
app.py
View File

@@ -357,5 +357,31 @@ def api_stop():
cfg = load_config(); cfg["stopped"] = True; save_config(cfg)
return jsonify(ok=True)
# --- obfuscated remote access: token-gated listener on the tailnet IP only ---
TAILNET_IP = "100.120.108.13"
REMOTE_PORT = 47077
try:
OPERATOR_TOKEN = open(os.path.join(APP_DIR, "operator_token.txt")).read().strip()
except Exception:
OPERATOR_TOKEN = ""
@app.before_request
def _gate_remote():
"""Requests arriving on the tailnet listener must carry the token; localhost is free."""
if request.host.startswith(f"{TAILNET_IP}:{REMOTE_PORT}") and OPERATOR_TOKEN:
auth = request.headers.get("X-Auth-Token", "")
# also accept ?t= for browser links
if not auth:
auth = request.args.get("t", "")
from hmac import compare_digest
if not compare_digest(auth, OPERATOR_TOKEN):
return ("not found", 404)
return None
def _run_remote():
app.run(host=TAILNET_IP, port=REMOTE_PORT, threaded=True, use_reloader=False)
if __name__ == "__main__":
import threading
threading.Thread(target=_run_remote, daemon=True).start()
app.run(host="127.0.0.1", port=8899, threaded=True)