Compare commits

...
12 Commits
Author SHA1 Message Date
MrBlake 430c18b84e Version 0.10.3 2026-09-25 23:32:05 +02:00
MrBlakeandClaude Opus 5.5 98c7763c47 README: add screenshots of hosts, terminal, host settings, Docker, firewall, network, VPN and settings
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:32:05 +02:00
MrBlake e4396db3c8 Version 0.10.2 2026-09-25 23:22:21 +02:00
MrBlakeandClaude Opus 5.5 98d8cfa993 Network: confirm a change only after it has been fully applied, keep the session when the old connection times out, and retry reloading so changes show up without reopening the tab
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:22:16 +02:00
MrBlake 1517764cca Version 0.10.1 2026-09-25 23:15:49 +02:00
MrBlakeandClaude Opus 5.5 eba3e38620 Sync: warn CachyOS/UFW/firewalld users to open the sync ports with copyable commands; ask before sharing newly created SSH keys, passwords and VPN configurations
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:15:49 +02:00
MrBlake 6a63e0e80d Version 0.10.0 2026-09-25 23:05:39 +02:00
MrBlakeandClaude Opus 5.5 41717b2d07 Add encrypted LAN sync between MrTerm devices: UDP discovery, X25519 pairing with short authentication code, mutually authenticated AES-256-GCM sessions, last-writer-wins merge with deletions, and per-item opt-in for SSH keys, passwords and VPN configurations
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 23:05:39 +02:00
MrBlake ae5309f693 Version 0.9.1 2026-09-25 22:51:33 +02:00
MrBlakeandClaude Opus 5.5 487ed069fc Fix main-process crash on SSH connection errors: handle repeated ssh2 error events, use the Windows OpenSSH agent only when it is running, show uncaught errors as a toast
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 22:51:33 +02:00
MrBlake 7a9b70e645 Version 0.9.0 2026-09-25 22:40:58 +02:00
MrBlakeandClaude Opus 5.5 352a887a67 Add network management over SSH for Ubuntu (netplan) and Debian/Proxmox (ifupdown): interfaces, IPs, DHCP, gateway, DNS, bonds with LACP, bridges, VLANs, hostname and config files, applied with automatic rollback; UFW shows a hint when disabled
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
2026-09-25 22:40:58 +02:00
21 changed files with 1927 additions and 25 deletions
+59
View File
@@ -4,6 +4,8 @@ A modern SSH, SFTP and RDP client for Windows and Arch Linux / CachyOS. All your
MrTerm is available in **English** and **German**. It follows your system language by default, and you can change it under **Settings → Language**.
![MrTerm host overview with groups](docs/screenshots/hosts.png)
## Download & installation
Get the latest version from the [releases page](https://git.mrblake.cc/MrBlake/MrTerm/releases).
@@ -34,6 +36,7 @@ sudo pacman -S freerdp gnome-keyring # use kwallet instead of gnome-keyring on
- **Keychain**: generate Ed25519/ECDSA/RSA keys, import existing ones and copy the public key
- **Docker & Podman**: list a host's containers, open a shell inside a container, follow logs, and start, stop, restart or remove containers, all over SSH
- **Firewall**: view and edit UFW and iptables/ip6tables rules on your servers
- **Network**: configure interfaces, IP addresses, DHCP, gateway, DNS, bonds (LACP), bridges, VLANs and the hostname on Ubuntu and Debian/Proxmox servers, with automatic rollback
- **Port forwarding**: local (-L), remote (-R) and dynamic/SOCKS5 (-D)
- **VPN**: add WireGuard or OpenVPN configurations and assign them to hosts. MrTerm connects the VPN automatically when you open such a host
- **Snippets**: save frequently used commands and send them to a terminal with one click
@@ -41,11 +44,25 @@ sudo pacman -S freerdp gnome-keyring # use kwallet instead of gnome-keyring on
- **History** of recent connections
- **Import** from `~/.ssh/config` and from **Devolutions Remote Desktop Manager** (`.rdm`/XML, JSON or CSV)
- **Backup** export and import
- **LAN sync**: keep several MrTerm devices in sync over your local network, end-to-end encrypted and without a server
- **7 app themes** (Midnight, Navy, Nord, Dracula, Catppuccin, Forest, Light) plus a custom accent color
- **Encrypted vault** using your operating system's keyring (Windows DPAPI, Linux libsecret/KWallet)
- **App lock** with a password and/or a FIDO2 security key such as a YubiKey. The vault is then additionally encrypted, and it can lock automatically when you're inactive
- **Automatic updates**: MrTerm checks for new versions on startup and can install them for you
## Screenshots
| | |
|---|---|
| ![SSH terminal](docs/screenshots/terminal.png) | ![Editing a host](docs/screenshots/edit-host.png) |
| **SSH terminal** with tabs and quick access to SFTP, Docker, Firewall and Network | **Host settings**: authentication, keys, jump hosts and VPN |
| ![Docker containers](docs/screenshots/docker.png) | ![UFW firewall rules](docs/screenshots/firewall.png) |
| **Docker & Podman** containers with CPU and memory usage | **Firewall** rules for UFW and iptables |
| ![Network configuration](docs/screenshots/network.png) | ![VPN configurations](docs/screenshots/vpn.png) |
| **Network**: interfaces, bonds (LACP), bridges, gateway and DNS | **VPN**: WireGuard and OpenVPN, connected automatically per host |
| ![Settings](docs/screenshots/settings.png) | |
| **Settings**: language, app lock, LAN sync and themes | |
## Getting started
1. Click **New host**, enter the address, username and password or key, and click **Save**.
@@ -69,6 +86,28 @@ For a quick one-off connection, press `Ctrl+Shift+K` and type `user@host` (or `r
`Ctrl+W`, `Ctrl+K` and `Ctrl+T` still reach the terminal, so editors like nano work as usual.
## Synchronization between devices
Under **Settings → Synchronization**, you can keep several MrTerm installations in sync, for example your desktop and laptop. Devices talk to each other directly in your local network. There is no server or cloud involved.
1. Turn on **LAN synchronization** on both devices.
2. Click **Pair new device** on both devices and select the other one.
3. Both devices show a 6-digit code. If the codes match, click **Codes match** on both devices.
4. Choose which **SSH keys, host passwords and VPN configurations** this device may share. Nothing secret is shared unless you select it, and you can change the selection at any time. When you add a new key, password or VPN later, MrTerm asks whether to share it.
From then on, hosts, groups, snippets, port forwards, VPNs and known hosts are synchronized automatically whenever both devices are running on the same network. Deletions are synchronized too. If a change was made on both devices, the newest one wins. Device-specific settings such as theme, language and app lock stay local.
**Security:** pairing uses an X25519 key exchange confirmed by the matching code, so another device on the network can't intercept it. Every sync connection is mutually authenticated and encrypted with AES-256-GCM, using a new key for each session.
**Firewall:** devices find each other on UDP port 47811 and sync on TCP port 47812. **CachyOS enables the UFW firewall by default**, so run this once on CachyOS (and on any other Linux with UFW enabled):
```sh
sudo ufw allow 47811/udp
sudo ufw allow 47812/tcp
```
MrTerm shows these commands automatically when it detects CachyOS, UFW or firewalld. Windows asks for permission the first time. If devices can't find each other, you can also add one by its IP address.
## Docker
Right-click an SSH host and choose **Docker containers**, or click **Docker** in the toolbar of an open terminal. MrTerm connects over SSH and shows all containers on that host, with status, ports, CPU and memory.
@@ -87,8 +126,28 @@ Right-click an SSH host and choose **Firewall**, or click **Firewall** in the to
- **iptables**: all chains with their rules, the policy of INPUT, FORWARD and OUTPUT, and adding or deleting rules. iptables changes are lost on reboot unless you click **Save permanently** (uses `netfilter-persistent` on Debian/Ubuntu or `/etc/iptables/*.rules` on Arch).
- **Lockout protection**: if you enable UFW without a rule that allows SSH, MrTerm warns you and offers to allow SSH first. Switching a default policy to blocking asks for confirmation.
UFW rules can only be viewed and added while UFW is enabled.
This needs root privileges. Either log in as root, or save the password of a user with sudo rights on the host.
## Network
Right-click an SSH host and choose **Network**, or click **Network** in the terminal toolbar. MrTerm shows every interface with its state, MAC address, MTU and IP addresses. Bonds also show their mode, LACP rate and the status of each member. The default gateway, DNS servers and hostname appear at the top.
On **Ubuntu (netplan)** and **Debian/Proxmox (ifupdown)** you can also edit the configuration:
- **Per interface**: DHCP or static IPv4 addresses, gateway, DNS servers and search domains, IPv6 (SLAAC, DHCPv6, static or disabled) and MTU
- **Bonds** with any mode, including **802.3ad (LACP)** with LACP rate, hash policy and MII monitoring
- **Bridges** (e.g. Proxmox `vmbr`) and **VLANs**, which you can also create and delete
- **Hostname** and, if not managed by systemd-resolved, `/etc/resolv.conf`
- **Config files**: edit the netplan files, `/etc/network/interfaces` or `/etc/hosts` directly
**Automatic rollback:** before applying a change, MrTerm backs up the configuration and checks the new one. After applying it, MrTerm opens a new SSH connection to confirm the server is still reachable. If that doesn't work within 90 seconds, the server restores the previous configuration by itself, so a wrong IP address won't lock you out. If your change affects the address MrTerm connects to, enter the new address in the confirmation dialog.
On Ubuntu, MrTerm writes the complete netplan configuration to `/etc/netplan/90-mrterm.yaml` and renames the previous files to `*.yaml.mrterm-off`. On Debian/Proxmox, only the changed interfaces are rewritten, and all other lines (such as `post-up` or `bridge-fd`) are kept.
Root privileges are required, the same as for the firewall.
## VPN
Under **VPN** in the sidebar you can add WireGuard (`.conf`) and OpenVPN (`.ovpn`) configurations. Paste them or load them from a file, then assign hosts, either in the VPN itself or through the *VPN* field of a host.
Binary file not shown.

After

Width:  |  Height:  |  Size: 75 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 96 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 71 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 65 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 74 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 92 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 90 KiB

Binary file not shown.

After

Width:  |  Height:  |  Size: 64 KiB

+2 -2
View File
@@ -1,12 +1,12 @@
{
"name": "mrterm",
"version": "0.8.0",
"version": "0.10.3",
"lockfileVersion": 3,
"requires": true,
"packages": {
"": {
"name": "mrterm",
"version": "0.8.0",
"version": "0.10.3",
"license": "MIT",
"dependencies": {
"@xterm/addon-fit": "^0.11.0",
+1 -1
View File
@@ -1,7 +1,7 @@
{
"name": "mrterm",
"productName": "MrTerm",
"version": "0.8.0",
"version": "0.10.3",
"description": "Moderner SSH-, SFTP- und RDP-Client",
"main": "src/main/main.js",
"author": "MrBlake",
+129
View File
@@ -468,6 +468,135 @@
'A port needs the protocol TCP or UDP.': 'Für einen Port ist das Protokoll TCP oder UDP nötig.',
'No known way to save iptables rules on this host (e.g. install iptables-persistent).': 'Keine bekannte Möglichkeit, iptables-Regeln auf diesem Host zu speichern (z. B. iptables-persistent installieren).',
'UFW is disabled': 'UFW ist deaktiviert',
'Enable UFW to view or add rules.': 'Aktiviere UFW, um Regeln einzusehen oder anzulegen.',
// Netzwerk
'Network': 'Netzwerk',
'Show virtual interfaces': 'Virtuelle Schnittstellen anzeigen',
'Config files': 'Konfigurationsdateien',
'New interface': 'Neue Schnittstelle',
'New bond': 'Neuer Bond',
'New bridge': 'Neue Bridge',
'New VLAN': 'Neues VLAN',
'The last network change was rolled back automatically ({time}) because MrTerm could not reconnect.': 'Die letzte Netzwerkänderung wurde automatisch zurückgenommen ({time}), weil MrTerm sich nicht erneut verbinden konnte.',
'Editing is supported for Ubuntu (netplan) and Debian/Proxmox (ifupdown). This host uses {backend}, so interfaces are shown read-only. Config files can still be edited.': 'Bearbeiten wird für Ubuntu (netplan) und Debian/Proxmox (ifupdown) unterstützt. Dieser Host nutzt {backend}, daher werden die Schnittstellen nur angezeigt. Konfigurationsdateien lassen sich trotzdem bearbeiten.',
'none': 'keins',
'Hostname': 'Hostname',
'Default gateway': 'Standard-Gateway',
'DNS servers': 'DNS-Server',
'Search': 'Suche',
'systemd-resolved is used: set DNS servers per interface.': 'systemd-resolved ist aktiv: DNS-Server pro Schnittstelle festlegen.',
'Not configured': 'Nicht konfiguriert',
'Static': 'Statisch',
'No IPv4': 'Kein IPv4',
'Mode': 'Modus',
'Configured, but not present': 'Konfiguriert, aber nicht vorhanden',
'No address': 'Keine Adresse',
'Configured': 'Konfiguriert',
'MrTerm reconnects to confirm the change. Without confirmation the server restores the previous configuration after 90 seconds.': 'MrTerm verbindet sich neu, um die Änderung zu bestätigen. Ohne Bestätigung stellt der Server nach 90 Sekunden die vorherige Konfiguration wieder her.',
'Saved': 'Gespeichert',
'Network change applied and confirmed': 'Netzwerkänderung angewendet und bestätigt',
'MrTerm could not reconnect after the change. The server restores the previous configuration automatically within 90 seconds.': 'MrTerm konnte sich nach der Änderung nicht erneut verbinden. Der Server stellt die vorherige Konfiguration innerhalb von 90 Sekunden automatisch wieder her.',
'Apply network change?': 'Netzwerkänderung anwenden?',
'The change is applied immediately. If MrTerm cannot reconnect within 90 seconds, the server restores the previous configuration automatically.': 'Die Änderung wird sofort angewendet. Kann MrTerm sich nicht innerhalb von 90 Sekunden erneut verbinden, stellt der Server die vorherige Konfiguration automatisch wieder her.',
'Reconnect via': 'Neu verbinden über',
'Change this if the change affects the address MrTerm uses to connect.': 'Ändern, wenn die Änderung die Adresse betrifft, über die MrTerm sich verbindet.',
'Apply': 'Anwenden',
'No suitable interfaces found.': 'Keine passenden Schnittstellen gefunden.',
'Usually <parent>.<VLAN ID>, e.g. eno1.100': 'Üblich: <Eltern>.<VLAN-ID>, z. B. eno1.100',
'Bond': 'Bond',
'Members': 'Mitglieder',
'LACP rate': 'LACP-Rate',
'Hash policy': 'Hash-Richtlinie',
'MII monitoring (ms)': 'MII-Überwachung (ms)',
'Bridge': 'Bridge',
'Spanning Tree (STP)': 'Spanning Tree (STP)',
'VLAN ID': 'VLAN-ID',
'Parent interface': 'Übergeordnete Schnittstelle',
'IPv4 addresses (one per line, CIDR)': 'IPv4-Adressen (eine pro Zeile, CIDR)',
'Gateway': 'Gateway',
'IPv6 addresses (one per line, CIDR)': 'IPv6-Adressen (eine pro Zeile, CIDR)',
'IPv6 gateway': 'IPv6-Gateway',
'Method': 'Methode',
'No IPv4 address': 'Keine IPv4-Adresse',
'Search domains': 'Suchdomänen',
'Automatic (SLAAC)': 'Automatisch (SLAAC)',
'Disabled': 'Deaktiviert',
'New {kind}': 'Neue(r) {kind}',
'Select at least one member.': 'Wähle mindestens ein Mitglied aus.',
'Select the parent interface.': 'Wähle die übergeordnete Schnittstelle aus.',
'An interface with this name already exists.': 'Eine Schnittstelle mit diesem Namen gibt es bereits.',
'Applying network configuration …': 'Netzwerkkonfiguration wird angewendet …',
'Delete {kind} {name}?': '{kind} {name} löschen?',
'The interface is removed from the configuration. Members keep their current settings.': 'Die Schnittstelle wird aus der Konfiguration entfernt. Mitglieder behalten ihre aktuellen Einstellungen.',
'Change hostname': 'Hostname ändern',
'Hostname changed': 'Hostname geändert',
'Written to /etc/resolv.conf.': 'Wird in /etc/resolv.conf geschrieben.',
'Content': 'Inhalt',
'Saving applies the file with automatic rollback.': 'Beim Speichern wird die Datei mit automatischem Rollback angewendet.',
'Saving …': 'Speichere …',
'Network session not found': 'Netzwerk-Sitzung nicht gefunden',
'netplan configuration could not be read ({err}).': 'netplan-Konfiguration konnte nicht gelesen werden ({err}).',
'Editing is not supported for this network configuration ({backend}).': 'Bearbeiten wird für diese Netzwerkkonfiguration ({backend}) nicht unterstützt.',
'The new configuration is invalid and was not applied: {err}': 'Die neue Konfiguration ist ungültig und wurde nicht angewendet: {err}',
'A static configuration needs at least one IPv4 address (e.g. 192.168.1.10/24).': 'Eine statische Konfiguration braucht mindestens eine IPv4-Adresse (z. B. 192.168.1.10/24).',
'A static IPv6 configuration needs at least one IPv6 address.': 'Eine statische IPv6-Konfiguration braucht mindestens eine IPv6-Adresse.',
'Authentication failed for {user}. Check the username, password or key.': 'Anmeldung für {user} fehlgeschlagen. Prüfe Benutzername, Passwort oder Schlüssel.',
// Synchronisation
'Synchronization': 'Synchronisation',
'Synchronize hosts, groups, snippets, port forwards, VPNs and known hosts directly between MrTerm devices in your local network. The connection is end-to-end encrypted; no server or cloud is involved.': 'Hosts, Gruppen, Snippets, Port-Weiterleitungen, VPNs und Known Hosts direkt zwischen MrTerm-Geräten im lokalen Netz abgleichen. Die Verbindung ist Ende-zu-Ende verschlüsselt, ohne Server oder Cloud.',
'Enable LAN synchronization': 'LAN-Synchronisation aktivieren',
'Device name': 'Gerätename',
'No paired devices yet.': 'Noch keine gekoppelten Geräte.',
'online': 'online',
'offline': 'offline',
'last sync {time}': 'zuletzt {time}',
'Unpair': 'Entkoppeln',
'Unpair device?': 'Gerät entkoppeln?',
'“{name}” will no longer synchronize with this device.': '„{name}“ synchronisiert dann nicht mehr mit diesem Gerät.',
'Shared secrets: {keys} SSH keys, {pw} host passwords, {vpn} VPN configurations': 'Geteilte Geheimnisse: {keys} SSH-Schlüssel, {pw} Host-Passwörter, {vpn} VPN-Konfigurationen',
'Pair new device': 'Neues Gerät koppeln',
'Sync now': 'Jetzt synchronisieren',
'Synchronized with {n} device(s)': 'Mit {n} Gerät(en) synchronisiert',
'Choose shared secrets': 'Geteilte Geheimnisse auswählen',
'Devices find each other via UDP port 47811 and synchronize via TCP port 47812. If a firewall is active, allow these ports in your local network (with UFW: sudo ufw allow 47811/udp and sudo ufw allow 47812/tcp).': 'Geräte finden sich über UDP-Port 47811 und synchronisieren über TCP-Port 47812. Ist eine Firewall aktiv, erlaube diese Ports im lokalen Netz (mit UFW: sudo ufw allow 47811/udp und sudo ufw allow 47812/tcp).',
'Open “Pair new device” on the other device too, then select it here. Both devices show a code that you confirm on both sides.': 'Öffne „Neues Gerät koppeln“ auch auf dem anderen Gerät und wähle es dann hier aus. Beide Geräte zeigen einen Code, den du auf beiden Seiten bestätigst.',
'Or enter an IP address, e.g. 192.168.0.25': 'Oder IP-Adresse eingeben, z. B. 192.168.0.25',
'Searching for devices …': 'Suche nach Geräten …',
'not ready for pairing': 'nicht bereit zum Koppeln',
'Pair': 'Koppeln',
'Pairing …': 'Kopple …',
'Device found': 'Gerät gefunden',
'Choose which secrets this device may send to paired devices. Everything else (hosts, groups, snippets …) is synchronized without passwords and private keys.': 'Wähle, welche Geheimnisse dieses Gerät an gekoppelte Geräte senden darf. Alles andere (Hosts, Gruppen, Snippets …) wird ohne Passwörter und private Schlüssel synchronisiert.',
'SSH keys': 'SSH-Schlüssel',
'Host passwords': 'Host-Passwörter',
'VPN configurations': 'VPN-Konfigurationen',
'There are no secrets on this device yet.': 'Auf diesem Gerät gibt es noch keine Geheimnisse.',
'Share nothing': 'Nichts teilen',
'Select all': 'Alle auswählen',
'Paired with {name}': 'Mit {name} gekoppelt',
'Confirm pairing': 'Kopplung bestätigen',
'Pairing with “{name}”. Does the other device show the same code?': 'Kopplung mit „{name}“. Zeigt das andere Gerät denselben Code?',
'Codes differ': 'Codes unterschiedlich',
'Codes match': 'Codes stimmen überein',
'Pairing was rejected on this device.': 'Die Kopplung wurde auf diesem Gerät abgelehnt.',
'Pairing was rejected on the other device.': 'Die Kopplung wurde auf dem anderen Gerät abgelehnt.',
'Pairing verification failed.': 'Die Überprüfung der Kopplung ist fehlgeschlagen.',
'Device is not ready for pairing': 'Das Gerät ist nicht zum Koppeln bereit',
'CachyOS: allow the sync ports in the firewall': 'CachyOS: Sync-Ports in der Firewall freigeben',
'Firewall active: allow the sync ports': 'Firewall aktiv: Sync-Ports freigeben',
'Otherwise other devices cannot find or reach this device. Run these commands once in a terminal:': 'Sonst können andere Geräte dieses Gerät weder finden noch erreichen. Führe diese Befehle einmal in einem Terminal aus:',
'Copy commands': 'Befehle kopieren',
'Already done, hide': 'Erledigt, ausblenden',
'CachyOS enables the UFW firewall by default. It blocks the ports MrTerm needs to find and reach other devices (UDP 47811, TCP 47812). Run these commands once in a terminal:': 'CachyOS aktiviert standardmäßig die Firewall UFW. Sie blockiert die Ports, über die MrTerm andere Geräte findet und erreicht (UDP 47811, TCP 47812). Führe diese Befehle einmal in einem Terminal aus:',
'No devices found? The firewall on this device may block them:': 'Keine Geräte gefunden? Die Firewall dieses Geräts blockiert sie eventuell:',
'Host password': 'Host-Passwort',
'Share with paired devices?': 'Mit gekoppelten Geräten teilen?',
'Should this secret be synchronized to your paired devices ({names})? You can change this later under Settings → Synchronization.': 'Soll dieses Geheimnis mit deinen gekoppelten Geräten ({names}) synchronisiert werden? Du kannst das später unter Einstellungen → Synchronisation ändern.',
'Don\'t share': 'Nicht teilen',
'Share': 'Teilen',
// Main-Prozess
'Host key has changed!': 'Host-Schlüssel hat sich geändert!',
'Unknown host': 'Unbekannter Host',
+57 -7
View File
@@ -14,6 +14,8 @@ const fido = require('./fido');
const { VpnManager } = require('./vpn');
const { DockerManager } = require('./docker');
const { FirewallManager } = require('./firewall');
const { NetworkConfigManager } = require('./network');
const { SyncService } = require('./sync');
const applyLanguage = () => i18n.setLanguage(store.get().settings.language, app.getLocale());
let win;
@@ -31,6 +33,13 @@ if (process.platform === 'linux' && readLaunch().x11 !== false && !process.argv.
}
const pendingSecrets = new Map();
// Sicherheitsnetz: unerwartete Fehler (z. B. aus Netzwerkbibliotheken) als Meldung anzeigen statt den Hauptprozess abstürzen zu lassen
process.on('uncaughtException', (e) => {
console.error('Uncaught exception:', e);
send('toast', e?.message || String(e), 'error');
});
process.on('unhandledRejection', (e) => console.error('Unhandled rejection:', e));
function send(channel, ...args) {
if (win && !win.isDestroyed()) win.webContents.send(channel, ...args);
}
@@ -65,6 +74,18 @@ const updater = new Updater(store, send);
const vpn = new VpnManager(store, app.getPath('userData'));
const docker = new DockerManager(ssh);
const firewall = new FirewallManager(ssh);
const network = new NetworkConfigManager(ssh);
// LAN-Synchronisation; Vergleichscode beim Koppeln bestätigt der Nutzer in der Oberfläche
const pairReplies = new Map();
const sync = new SyncService(store, send, (req) => new Promise((resolve) => {
const reqId = crypto.randomUUID();
pairReplies.set(reqId, resolve);
send('sync:pairPrompt', { reqId, ...req });
setTimeout(() => { if (pairReplies.delete(reqId)) resolve(false); }, 115000);
}));
ipcMain.on('sync:pairReply', (_e, reqId, ok) => { const r = pairReplies.get(reqId); pairReplies.delete(reqId); r?.(!!ok); });
store.onChange = () => sync.schedule();
function createWindow() {
win = new BrowserWindow({
@@ -125,7 +146,7 @@ function lockStatus() {
}
function requireUnlocked() { if (store.locked) throw new Error(i18n.t('MrTerm is locked.')); }
const ensureLock = () => (store.lock = store.lock || { password: null, fido: [] });
function afterUnlock() { applyLanguage(); scheduleUpdateCheck(); }
function afterUnlock() { applyLanguage(); scheduleUpdateCheck(); sync.start().catch(() => {}); }
handle('lock:status', lockStatus);
handle('lock:lock', () => { if (store.lockEnabled) store.locked = true; return lockStatus(); });
@@ -181,7 +202,9 @@ handle('lock:removeFido', (id) => {
});
// ---------- Vault ----------
handle('vault:get', () => ({ ...store.get(), encrypted: store.encrypted, platform: process.platform }));
// Kopplungsschlüssel und Löschvermerke bleiben im Hauptprozess
const publicData = () => { const { sync: _s, tombstones: _t, ...rest } = store.get(); return rest; };
handle('vault:get', () => ({ ...publicData(), encrypted: store.encrypted, platform: process.platform }));
handle('vault:upsert', async (col, item) => {
// Geänderte VPN-Konfiguration: alte Systemverbindung entfernen, beim nächsten Verbinden neu importieren
if (col === 'vpns' && item.id) {
@@ -193,7 +216,7 @@ handle('vault:upsert', async (col, item) => {
handle('vault:remove', async (col, id) => {
if (col === 'vpns') {
await vpn.forget(store.get().vpns.find((v) => v.id === id));
store.get().hosts.forEach((h) => { if (h.vpnId === id) h.vpnId = null; });
store.get().hosts.forEach((h) => { if (h.vpnId === id) { h.vpnId = null; h.updatedAt = Date.now(); } });
}
return store.remove(col, id);
});
@@ -221,6 +244,32 @@ handle('firewall:ufw', (id, op, args) => firewall.ufw(id, op, args));
handle('firewall:ipt', (id, op, args) => firewall.ipt(id, op, args));
handle('firewall:close', (id) => firewall.close(id));
// ---------- Netzwerk ----------
handle('network:open', async (id, hostRef) => {
const host = hostWithOverrides(hostRef);
if (await vpn.ensureForHost(host)) send('vpn:changed');
return network.open(id, host, () => send('network:closed', id));
});
handle('network:read', (id) => network.read(id));
handle('network:save', (id, model, verify) => network.saveInterface(id, model, verify));
handle('network:remove', (id, model) => network.removeInterface(id, model));
handle('network:hostname', (id, name) => network.setHostname(id, name));
handle('network:resolv', (id, servers, search) => network.setResolv(id, servers, search));
handle('network:readFile', (id, path) => network.readFile(id, path));
handle('network:writeFile', (id, path, content, verify) => network.writeFile(id, path, content, verify));
handle('network:close', (id) => network.close(id));
// ---------- Synchronisation ----------
handle('sync:status', () => sync.status());
handle('sync:enable', (on, name) => sync.setEnabled(on, name));
handle('sync:pairable', (on) => { sync.setPairable(on); return sync.status(); });
handle('sync:pair', (id) => sync.pair(id));
handle('sync:unpair', (id) => sync.unpair(id));
handle('sync:now', () => sync.syncAll());
handle('sync:share', (sel) => sync.setShare(sel));
handle('sync:shareItem', (c, id, yes) => sync.shareItem(c, id, yes));
handle('sync:probe', (address) => sync.probe(address));
// ---------- VPN ----------
handle('vpn:status', () => vpn.status());
handle('vpn:up', (id) => vpn.up(id));
@@ -230,18 +279,18 @@ handle('vault:settings', (s) => {
if ('language' in s) applyLanguage();
if ('rdpEmbed' in s) fs.writeFileSync(launchFile, JSON.stringify({ ...readLaunch(), x11: s.rdpEmbed !== false }));
});
handle('vault:forgetHost', (id) => { delete store.get().knownHosts[id]; store.save(); });
handle('vault:forgetHost', (id) => store.forgetKnownHost(id));
handle('vault:export', async () => {
const r = await dialog.showSaveDialog(win, { defaultPath: 'mrterm-backup.json', filters: [{ name: 'JSON', extensions: ['json'] }] });
if (r.canceled) return false;
fs.writeFileSync(r.filePath, JSON.stringify(store.get(), null, 2), { mode: 0o600 });
fs.writeFileSync(r.filePath, JSON.stringify(publicData(), null, 2), { mode: 0o600 });
return r.filePath;
});
handle('vault:import', async () => {
const r = await dialog.showOpenDialog(win, { filters: [{ name: 'JSON', extensions: ['json'] }], properties: ['openFile'] });
if (r.canceled) return false;
const data = JSON.parse(fs.readFileSync(r.filePaths[0], 'utf8'));
for (const col of ['groups', 'hosts', 'keys', 'snippets', 'forwards'])
for (const col of ['groups', 'hosts', 'keys', 'snippets', 'forwards', 'vpns'])
for (const item of data[col] || []) store.upsert(col, item);
return true;
});
@@ -501,6 +550,7 @@ app.whenReady().then(() => {
store.load();
applyLanguage();
createWindow();
sync.start().catch(() => {});
scheduleUpdateCheck();
});
@@ -511,7 +561,7 @@ function scheduleUpdateCheck() {
updateScheduled = true;
setTimeout(() => updater.check().then((r) => { if (r.available) send('update:available', r); }).catch(() => {}), 6000);
}
app.on('window-all-closed', async () => { ssh.closeAll(); await vpn.downOnQuit(); app.quit(); });
app.on('window-all-closed', async () => { ssh.closeAll(); sync.stop(); await vpn.downOnQuit(); app.quit(); });
// Smoke-Test: MRTERM_SMOKE=<pfad.png> startet, loggt Renderer-Meldungen, speichert einen Screenshot und beendet.
if (process.env.MRTERM_SMOKE) {
+346
View File
@@ -0,0 +1,346 @@
// Netzwerk-Konfiguration als einheitliches Modell – Lesen/Schreiben für
// Ubuntu: netplan (YAML, hier als JSON verarbeitet; JSON ist gültiges YAML)
// Debian/Proxmox: ifupdown / ifupdown2 (/etc/network/interfaces + interfaces.d)
// Modell pro Schnittstelle:
// { name, kind: ethernet|bond|bridge|vlan, method4: dhcp|static|none, addresses[], gateway, dns[], search[], mtu,
// method6: auto|dhcp|static|none, addresses6[], gateway6,
// bond: { members[], mode, lacpRate, hashPolicy, miimon }, bridge: { members[], stp }, vlan: { id, link }, file }
// Reine Funktionen ohne Seiteneffekte (lokal testbar).
const RX = {
name: /^[a-zA-Z0-9_.:-]{1,15}$/,
cidr4: /^(\d{1,3})(\.\d{1,3}){3}\/\d{1,2}$/,
cidr6: /^[0-9a-fA-F:]+(%\w+)?\/\d{1,3}$/,
ip4: /^\d{1,3}(\.\d{1,3}){3}$/,
ip6: /^[0-9a-fA-F:]+$/,
domain: /^[a-zA-Z0-9.-]{1,253}$/,
};
const BOND_MODES = ['balance-rr', 'active-backup', 'balance-xor', 'broadcast', '802.3ad', 'balance-tlb', 'balance-alb'];
const HASH = ['layer2', 'layer2+3', 'layer3+4', 'encap2+3', 'encap3+4'];
function fail(msg) { const e = new Error(msg); e.validation = true; throw e; }
// Eingaben prüfen, bevor daraus Konfigurationsdateien entstehen
function validate(m, t = (s, v) => (v ? s.replace(/\{(\w+)\}/g, (x, k) => v[k]) : s)) {
const chk = (ok, field, value) => { if (!ok) fail(t('Invalid value for {field}: {value}', { field, value })); };
chk(RX.name.test(m.name || ''), 'name', m.name);
chk(['ethernet', 'bond', 'bridge', 'vlan'].includes(m.kind), 'kind', m.kind);
chk(['dhcp', 'static', 'none'].includes(m.method4), 'IPv4', m.method4);
chk(['auto', 'dhcp', 'static', 'none'].includes(m.method6), 'IPv6', m.method6);
for (const a of m.addresses || []) chk(RX.cidr4.test(a), 'IPv4 address', a);
for (const a of m.addresses6 || []) chk(RX.cidr6.test(a), 'IPv6 address', a);
if (m.method4 === 'static' && !(m.addresses || []).length) fail(t('A static configuration needs at least one IPv4 address (e.g. 192.168.1.10/24).'));
if (m.method6 === 'static' && !(m.addresses6 || []).length) fail(t('A static IPv6 configuration needs at least one IPv6 address.'));
if (m.gateway) chk(RX.ip4.test(m.gateway), 'gateway', m.gateway);
if (m.gateway6) chk(RX.ip6.test(m.gateway6), 'IPv6 gateway', m.gateway6);
for (const d of m.dns || []) chk(RX.ip4.test(d) || RX.ip6.test(d), 'DNS', d);
for (const d of m.search || []) chk(RX.domain.test(d), 'search domain', d);
if (m.mtu !== '' && m.mtu != null) chk(Number(m.mtu) >= 68 && Number(m.mtu) <= 65535, 'MTU', m.mtu);
if (m.kind === 'bond') {
chk(BOND_MODES.includes(m.bond?.mode), 'bond mode', m.bond?.mode);
for (const x of m.bond.members || []) chk(RX.name.test(x), 'member', x);
if (m.bond.lacpRate) chk(['slow', 'fast'].includes(m.bond.lacpRate), 'LACP rate', m.bond.lacpRate);
if (m.bond.hashPolicy) chk(HASH.includes(m.bond.hashPolicy), 'hash policy', m.bond.hashPolicy);
if (m.bond.miimon !== '' && m.bond.miimon != null) chk(/^\d{1,5}$/.test(String(m.bond.miimon)), 'miimon', m.bond.miimon);
}
if (m.kind === 'bridge') for (const x of m.bridge?.members || []) chk(RX.name.test(x), 'port', x);
if (m.kind === 'vlan') {
chk(Number(m.vlan?.id) >= 1 && Number(m.vlan?.id) <= 4094, 'VLAN ID', m.vlan?.id);
chk(RX.name.test(m.vlan?.link || ''), 'VLAN parent', m.vlan?.link);
}
return m;
}
const blank = (name, kind = 'ethernet') => ({
name, kind, method4: 'none', addresses: [], gateway: '', dns: [], search: [], mtu: '',
method6: 'auto', addresses6: [], gateway6: '',
bond: kind === 'bond' ? { members: [], mode: '802.3ad', lacpRate: 'fast', hashPolicy: 'layer3+4', miimon: 100 } : undefined,
bridge: kind === 'bridge' ? { members: [], stp: false } : undefined,
vlan: kind === 'vlan' ? { id: '', link: '' } : undefined,
});
// ======================================================================= netplan
const NP_SECT = { ethernet: 'ethernets', bond: 'bonds', bridge: 'bridges', vlan: 'vlans' };
const DEFAULT_ROUTE = (r) => ['default', '0.0.0.0/0', '::/0'].includes(r?.to);
const addrOf = (a) => (typeof a === 'string' ? a : Object.keys(a || {})[0] || '');
function fromNetplan(cfg) {
const net = cfg?.network || {};
const out = [];
for (const [kind, sect] of Object.entries(NP_SECT)) {
for (const [name, c] of Object.entries(net[sect] || {})) {
const m = blank(name, kind);
const addrs = (c.addresses || []).map(addrOf);
m.addresses = addrs.filter((a) => !a.includes(':'));
m.addresses6 = addrs.filter((a) => a.includes(':'));
const routes = c.routes || [];
m.gateway = c.gateway4 || routes.find((r) => DEFAULT_ROUTE(r) && !String(r.via).includes(':'))?.via || '';
m.gateway6 = c.gateway6 || routes.find((r) => DEFAULT_ROUTE(r) && String(r.via).includes(':'))?.via || '';
m.method4 = c.dhcp4 === true || c.dhcp4 === 'yes' || c.dhcp4 === 'true' ? 'dhcp' : m.addresses.length ? 'static' : 'none';
m.method6 = c.dhcp6 === true || c.dhcp6 === 'yes' ? 'dhcp' : m.addresses6.length ? 'static' : c['accept-ra'] === false ? 'none' : 'auto';
m.dns = c.nameservers?.addresses || [];
m.search = c.nameservers?.search || [];
m.mtu = c.mtu ?? '';
const p = c.parameters || {};
if (kind === 'bond') m.bond = { members: c.interfaces || [], mode: p.mode || 'balance-rr', lacpRate: p['lacp-rate'] || '', hashPolicy: p['transmit-hash-policy'] || '', miimon: p['mii-monitor-interval'] ?? '' };
if (kind === 'bridge') m.bridge = { members: c.interfaces || [], stp: p.stp === true };
if (kind === 'vlan') m.vlan = { id: c.id ?? '', link: c.link || '' };
out.push(m);
}
}
return out;
}
// Mitglieder aus allen Bonds/Bridges außer "keep" entfernen
function npDetach(net, members, keepSect, keepName) {
for (const sect of ['bonds', 'bridges']) {
for (const [n, c] of Object.entries(net[sect] || {})) {
if (sect === keepSect && n === keepName) continue;
if (Array.isArray(c.interfaces)) c.interfaces = c.interfaces.filter((x) => !members.includes(x));
}
}
}
// Modell m in die netplan-Konfiguration übernehmen (liefert neue Konfiguration)
function applyNetplan(cfg, m, { remove = false } = {}) {
const out = structuredClone(cfg || {});
const net = (out.network ||= { version: 2 });
net.version ||= 2;
const sect = NP_SECT[m.kind];
if (remove) {
if (net[sect]) delete net[sect][m.name];
npDetach(net, [m.name]);
return out;
}
const c = ((net[sect] ||= {})[m.name] ||= {});
delete c.gateway4; delete c.gateway6;
c.dhcp4 = m.method4 === 'dhcp';
if (m.method6 === 'dhcp') c.dhcp6 = true; else delete c.dhcp6;
if (m.method6 === 'none') { c['accept-ra'] = false; c['link-local'] = ['ipv4']; }
else { if (c['accept-ra'] === false) delete c['accept-ra']; if (Array.isArray(c['link-local']) && !c['link-local'].includes('ipv6')) delete c['link-local']; }
const addrs = [...(m.method4 === 'static' ? m.addresses : []), ...(m.method6 === 'static' ? m.addresses6 : [])];
if (addrs.length) c.addresses = addrs; else delete c.addresses;
const routes = (c.routes || []).filter((r) => !DEFAULT_ROUTE(r));
if (m.method4 === 'static' && m.gateway) routes.push({ to: 'default', via: m.gateway });
if (m.method6 === 'static' && m.gateway6) routes.push({ to: '::/0', via: m.gateway6 });
if (routes.length) c.routes = routes; else delete c.routes;
if ((m.dns || []).length || (m.search || []).length) c.nameservers = { ...((m.dns || []).length ? { addresses: m.dns } : {}), ...((m.search || []).length ? { search: m.search } : {}) };
else delete c.nameservers;
if (m.mtu !== '' && m.mtu != null) c.mtu = Number(m.mtu); else delete c.mtu;
const members = m.kind === 'bond' ? m.bond.members : m.kind === 'bridge' ? m.bridge.members : [];
if (m.kind === 'bond' || m.kind === 'bridge') {
c.interfaces = [...members];
npDetach(net, members, sect, m.name);
// Mitglieder dürfen selbst keine IP-Konfiguration haben
for (const x of members) {
const sub = Object.values(NP_SECT).map((s) => net[s]?.[x]).find(Boolean) || ((net.ethernets ||= {})[x] = {});
for (const k of ['addresses', 'routes', 'nameservers', 'gateway4', 'gateway6', 'dhcp6']) delete sub[k];
sub.dhcp4 = false;
}
}
if (m.kind === 'bond') {
const p = { ...(c.parameters || {}), mode: m.bond.mode };
if (m.bond.mode === '802.3ad' && m.bond.lacpRate) p['lacp-rate'] = m.bond.lacpRate; else delete p['lacp-rate'];
if (m.bond.hashPolicy && ['802.3ad', 'balance-xor', 'balance-tlb', 'balance-alb'].includes(m.bond.mode)) p['transmit-hash-policy'] = m.bond.hashPolicy; else delete p['transmit-hash-policy'];
if (m.bond.miimon !== '' && m.bond.miimon != null) p['mii-monitor-interval'] = Number(m.bond.miimon); else delete p['mii-monitor-interval'];
c.parameters = p;
}
if (m.kind === 'bridge') c.parameters = { ...(c.parameters || {}), stp: !!m.bridge.stp };
if (m.kind === 'vlan') { c.id = Number(m.vlan.id); c.link = m.vlan.link; }
return out;
}
// ======================================================================= ifupdown
const KEYWORDS = /^(iface|auto|allow-[\w-]+|mapping|source|source-directory|rename|no-auto-down|no-scripts)\b/;
// Optionen, die MrTerm selbst schreibt; alle anderen bleiben unverändert erhalten
const MANAGED = new Set(['address', 'netmask', 'gateway', 'dns-nameservers', 'dns-search', 'mtu',
'bond-slaves', 'bond_slaves', 'slaves', 'bond-mode', 'bond_mode', 'bond-miimon', 'bond_miimon', 'bond-lacp-rate', 'bond_lacp_rate',
'bond-xmit-hash-policy', 'bond_xmit_hash_policy', 'bridge-ports', 'bridge_ports', 'bridge-stp', 'bridge_stp', 'vlan-raw-device', 'vlan-id', 'bond-master']);
// IP-Optionen, die ein Bond-/Bridge-Mitglied nicht haben darf
const IPKEYS = new Set(['address', 'netmask', 'gateway', 'dns-nameservers', 'dns-search']);
function parseInterfaces(text, file) {
const blocks = [];
let cur = null;
for (const line of String(text).split('\n')) {
const t = line.trim();
if (KEYWORDS.test(t)) {
const [kw, ...rest] = t.split(/\s+/);
if (kw === 'iface') {
cur = { type: 'iface', name: rest[0], family: rest[1] || 'inet', method: rest[2] || 'manual', options: [], file };
blocks.push(cur);
continue;
}
cur = null;
if (kw === 'auto' || kw.startsWith('allow-')) { blocks.push({ type: 'auto', kw, names: rest, file }); continue; }
blocks.push({ type: 'raw', line, file });
continue;
}
if (cur && t && !t.startsWith('#')) {
const [key, ...v] = t.split(/\s+/);
cur.options.push({ key, value: v.join(' ') });
continue;
}
if (cur && t.startsWith('#')) { cur.options.push({ comment: line }); continue; }
if (!t) cur = null;
blocks.push({ type: 'raw', line, file });
}
return blocks;
}
const maskToPrefix = (mask) => String(mask).split('.').reduce((n, o) => n + (Number(o) >>> 0).toString(2).split('').filter((b) => b === '1').length, 0);
function fromIfupdown(blocks) {
const byName = new Map();
const opt = (b, ...keys) => b?.options.filter((o) => keys.includes(o.key)).map((o) => o.value) || [];
for (const b of blocks.filter((x) => x.type === 'iface')) {
if (b.method === 'loopback' || b.name === 'lo') continue;
const e = byName.get(b.name) || { inet: null, inet6: null };
e[b.family === 'inet6' ? 'inet6' : 'inet'] = b;
byName.set(b.name, e);
}
// Mitglieder, die per bond-master auf einen Bond zeigen
const bondMasters = {};
for (const [name, e] of byName) { const bm = opt(e.inet, 'bond-master')[0]; if (bm) (bondMasters[bm] ||= []).push(name); }
const out = [];
for (const [name, { inet, inet6 }] of byName) {
const b = inet || inet6;
const slaves = opt(inet, 'bond-slaves', 'bond_slaves', 'slaves')[0];
const bridgePorts = opt(inet, 'bridge-ports', 'bridge_ports')[0];
const vlanDev = opt(inet, 'vlan-raw-device')[0] || opt(inet6, 'vlan-raw-device')[0];
const vm = name.match(/^(.+)\.(\d+)$/);
const kind = slaves !== undefined || opt(inet, 'bond-mode', 'bond_mode').length ? 'bond' : bridgePorts !== undefined ? 'bridge' : vlanDev || vm || /^vlan\d+$/.test(name) ? 'vlan' : 'ethernet';
const m = blank(name, kind);
m.file = b.file;
if (inet) {
m.method4 = inet.method === 'dhcp' ? 'dhcp' : inet.method === 'static' ? 'static' : 'none';
const mask = opt(inet, 'netmask')[0];
m.addresses = opt(inet, 'address').map((a) => (a.includes('/') ? a : `${a}/${mask ? maskToPrefix(mask) : 24}`));
m.gateway = opt(inet, 'gateway')[0] || '';
m.dns = (opt(inet, 'dns-nameservers')[0] || '').split(/\s+/).filter(Boolean);
m.search = (opt(inet, 'dns-search')[0] || '').split(/\s+/).filter(Boolean);
m.mtu = opt(inet, 'mtu')[0] || '';
}
if (inet6) {
m.method6 = inet6.method === 'dhcp' ? 'dhcp' : inet6.method === 'static' ? 'static' : inet6.method === 'auto' ? 'auto' : 'none';
m.addresses6 = opt(inet6, 'address').map((a) => (a.includes('/') ? a : `${a}/${opt(inet6, 'netmask')[0] || 64}`));
m.gateway6 = opt(inet6, 'gateway')[0] || '';
} else m.method6 = 'auto';
if (kind === 'bond') {
const members = slaves && slaves !== 'none' ? slaves.split(/\s+/) : bondMasters[name] || [];
m.bond = { members, mode: opt(inet, 'bond-mode', 'bond_mode')[0] || 'balance-rr', lacpRate: opt(inet, 'bond-lacp-rate', 'bond_lacp_rate')[0] || '',
hashPolicy: opt(inet, 'bond-xmit-hash-policy', 'bond_xmit_hash_policy')[0] || '', miimon: opt(inet, 'bond-miimon', 'bond_miimon')[0] || '' };
if (m.bond.lacpRate === '1') m.bond.lacpRate = 'fast';
if (m.bond.lacpRate === '0') m.bond.lacpRate = 'slow';
if (m.bond.mode === '4') m.bond.mode = '802.3ad';
}
if (kind === 'bridge') m.bridge = { members: bridgePorts && bridgePorts !== 'none' ? bridgePorts.split(/\s+/) : [], stp: /^(on|yes)$/.test(opt(inet, 'bridge-stp', 'bridge_stp')[0] || '') };
if (kind === 'vlan') m.vlan = { id: opt(inet, 'vlan-id')[0] || vm?.[2] || (name.match(/^vlan(\d+)$/) || [])[1] || '', link: vlanDev || vm?.[1] || '' };
out.push(m);
}
return out;
}
function ifaceLines(m, keep4 = [], keep6 = [], had6 = false) {
const L = [];
const o = (k, v) => L.push(` ${k} ${v}`);
L.push(`iface ${m.name} inet ${m.method4 === 'dhcp' ? 'dhcp' : m.method4 === 'static' ? 'static' : 'manual'}`);
if (m.method4 === 'static') { m.addresses.forEach((a) => o('address', a)); if (m.gateway) o('gateway', m.gateway); }
if ((m.dns || []).length) o('dns-nameservers', m.dns.join(' '));
if ((m.search || []).length) o('dns-search', m.search.join(' '));
if (m.mtu !== '' && m.mtu != null) o('mtu', m.mtu);
if (m.kind === 'bond') {
o('bond-slaves', m.bond.members.length ? m.bond.members.join(' ') : 'none');
o('bond-mode', m.bond.mode);
if (m.bond.miimon !== '' && m.bond.miimon != null) o('bond-miimon', m.bond.miimon);
if (m.bond.mode === '802.3ad' && m.bond.lacpRate) o('bond-lacp-rate', m.bond.lacpRate);
if (m.bond.hashPolicy && ['802.3ad', 'balance-xor', 'balance-tlb', 'balance-alb'].includes(m.bond.mode)) o('bond-xmit-hash-policy', m.bond.hashPolicy);
}
if (m.kind === 'bridge') { o('bridge-ports', m.bridge.members.length ? m.bridge.members.join(' ') : 'none'); o('bridge-stp', m.bridge.stp ? 'on' : 'off'); }
if (m.kind === 'vlan' && !/^.+\.\d+$/.test(m.name)) { o('vlan-raw-device', m.vlan.link); o('vlan-id', m.vlan.id); }
keep4.forEach((x) => L.push(x.comment ?? ` ${x.key} ${x.value}`));
// inet6: dhcp/static immer; "auto" nur, wenn der Block vorher schon existierte (sonst Kernel-Standard SLAAC)
if (m.method6 === 'dhcp' || m.method6 === 'static' || (m.method6 === 'auto' && had6)) {
L.push('');
L.push(`iface ${m.name} inet6 ${m.method6}`);
if (m.method6 === 'static') { m.addresses6.forEach((a) => o('address', a)); if (m.gateway6) o('gateway', m.gateway6); }
keep6.forEach((x) => L.push(x.comment ?? ` ${x.key} ${x.value}`));
}
return L;
}
// Modell in die Blöcke übernehmen; liefert { files: { pfad: inhalt } } für alle geänderten Dateien
function applyIfupdown(blocks, m, { remove = false, mainFile = '/etc/network/interfaces' } = {}) {
let bl = blocks.map((b) => ({ ...b, options: b.options ? [...b.options] : undefined, names: b.names ? [...b.names] : undefined }));
const changed = new Set();
const file = bl.find((b) => b.type === 'iface' && b.name === m.name)?.file || m.file || mainFile;
const members = m.kind === 'bond' ? m.bond.members : m.kind === 'bridge' ? m.bridge.members : [];
// bestehende Blöcke der Schnittstelle entfernen (Position merken)
const old = bl.filter((b) => b.type === 'iface' && b.name === m.name);
old.forEach((b) => changed.add(b.file));
const keep4 = (old.find((b) => b.family !== 'inet6')?.options || []).filter((x) => x.comment || !MANAGED.has(x.key));
const keep6 = (old.find((b) => b.family === 'inet6')?.options || []).filter((x) => x.comment || !MANAGED.has(x.key));
let pos = bl.findIndex((b) => b.type === 'iface' && b.name === m.name);
bl = bl.filter((b) => !(b.type === 'iface' && b.name === m.name));
if (remove) {
bl.forEach((b) => { if (b.type === 'auto' && b.names.includes(m.name)) { b.names = b.names.filter((n) => n !== m.name); changed.add(b.file); } });
bl = bl.filter((b) => !(b.type === 'auto' && !b.names.length));
} else {
changed.add(file);
if (pos < 0) { bl.push({ type: 'raw', line: '', file }); pos = bl.length; }
const hasAuto = bl.some((b) => b.type === 'auto' && b.names.includes(m.name));
const nb = [];
if (!hasAuto) nb.push({ type: 'auto', kw: 'auto', names: [m.name], file });
nb.push({ type: 'text', lines: ifaceLines(m, keep4, keep6, old.some((b) => b.family === 'inet6')), file });
bl.splice(pos, 0, ...nb);
}
// Mitglieder: aus anderen Bonds/Bridges lösen, selbst "inet manual" ohne IP
if (!remove && members.length) {
for (const b of bl) {
if (b.type !== 'iface' || b.name === m.name || b.family === 'inet6') continue;
for (const o of b.options) {
if (['bond-slaves', 'bond_slaves', 'slaves', 'bridge-ports', 'bridge_ports'].includes(o.key)) {
const v = o.value.split(/\s+/).filter((x) => x !== 'none' && !members.includes(x));
if (v.join(' ') !== o.value) { o.value = v.length ? v.join(' ') : 'none'; changed.add(b.file); }
}
}
}
for (const x of members) {
const idx = bl.findIndex((b) => b.type === 'iface' && b.name === x && b.family !== 'inet6');
const cur = bl[idx];
// Bereits "manual" ohne IP (z. B. Bond als Bridge-Port): unverändert lassen
if (cur && cur.method === 'manual' && !cur.options.some((o) => IPKEYS.has(o.key))) continue;
const others = (cur?.options || []).filter((o) => o.comment || !IPKEYS.has(o.key));
bl = bl.filter((b) => !(b.type === 'iface' && b.name === x));
const f = cur?.file || file;
changed.add(f);
const lines = [`iface ${x} inet manual`, ...others.map((o) => o.comment ?? ` ${o.key} ${o.value}`)];
if (cur) { bl.splice(Math.min(idx, bl.length), 0, { type: 'text', lines, file: f }); continue; }
// Neues Mitglied vor dem Block der Schnittstelle (inkl. deren auto-Zeile) einfügen
let at = bl.findIndex((b) => b.type === 'text' && b.lines[0].startsWith(`iface ${m.name} `));
if (at > 0 && bl[at - 1].type === 'auto' && bl[at - 1].names.includes(m.name)) at--;
bl.splice(at < 0 ? bl.length : at, 0, { type: 'auto', kw: 'auto', names: [x], file: f }, { type: 'text', lines, file: f }, { type: 'raw', line: '', file: f });
}
}
const files = {};
for (const f of changed) {
const lines = [];
for (const b of bl.filter((x) => x.file === f)) {
if (b.type === 'raw') lines.push(b.line);
else if (b.type === 'auto') lines.push(`${b.kw} ${b.names.join(' ')}`);
else if (b.type === 'text') lines.push(...b.lines);
else if (b.type === 'iface') {
lines.push(`iface ${b.name} ${b.family} ${b.method}`);
b.options.forEach((o) => lines.push(o.comment ?? ` ${o.key} ${o.value}`));
}
}
files[f] = lines.join('\n').replace(/\n{3,}/g, '\n\n').replace(/^\n+/, '').replace(/\n*$/, '\n');
}
return { files };
}
module.exports = { validate, blank, fromNetplan, applyNetplan, parseInterfaces, fromIfupdown, applyIfupdown, BOND_MODES, HASH };
+326
View File
@@ -0,0 +1,326 @@
// Netzwerk-Tab: Schnittstellen, IPs, Bonds (LACP), Bridges, VLANs, Gateway, DNS und Hostname entfernter Hosts.
// Bearbeiten für Ubuntu (netplan) und Debian/Proxmox (ifupdown/ifupdown2); sonst Übersicht + Datei-Editor.
// Änderungen werden mit automatischem Rollback angewendet: Der Server stellt die vorherige Konfiguration
// nach 90 s selbst wieder her, falls MrTerm sich nicht erneut verbinden und die Änderung bestätigen kann.
const i18n = require('../i18n');
const { execOn } = require('./docker');
const nc = require('./netconf');
const STATE = '/var/lib/mrterm-net';
const ROLLBACK_SECONDS = 90;
const lastLine = (s) => String(s || '').split('\n').map((l) => l.trim()).filter(Boolean).slice(-1)[0] || '';
const b64 = (s) => Buffer.from(String(s)).toString('base64');
const HOSTNAME = /^[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?(\.[a-zA-Z0-9]([a-zA-Z0-9-]{0,61}[a-zA-Z0-9])?)*$/;
const EDITABLE_PATH = /^(\/etc\/netplan\/[\w.-]+\.yaml|\/etc\/network\/interfaces(\.d\/[\w.-]+)?|\/etc\/systemd\/network\/[\w.-]+|\/etc\/resolv\.conf|\/etc\/hosts)$/;
const BACKENDS = {
netplan: {
paths: ['etc/netplan'],
restore: `rm -rf /etc/netplan && mkdir -p /etc/netplan && tar xzf ${STATE}/backup.tgz -C /`,
validate: 'netplan generate',
apply: 'netplan apply',
},
ifupdown: {
paths: ['etc/network/interfaces', 'etc/network/interfaces.d'],
restore: `tar xzf ${STATE}/backup.tgz -C /`,
validate: 'if command -v ifreload >/dev/null 2>&1; then ifquery -a >/dev/null; else ifup --no-act -a >/dev/null; fi',
apply: 'if command -v ifreload >/dev/null 2>&1; then ifreload -a; else systemctl restart networking; fi',
},
networkd: {
paths: ['etc/systemd/network'],
restore: `rm -rf /etc/systemd/network && mkdir -p /etc/systemd/network && tar xzf ${STATE}/backup.tgz -C /`,
validate: 'true',
apply: 'networkctl reload 2>/dev/null || systemctl restart systemd-networkd',
},
};
// Merged netplan-Konfiguration (alle /etc/netplan/*.yaml) als JSON – netplan bringt python3-yaml mit
const NETPLAN_PY = `import sys,json,glob,os
try:
import yaml
except Exception:
print(json.dumps({"error":"python3-yaml missing"})); sys.exit(0)
def merge(a,b):
for k,v in (b or {}).items():
if isinstance(v,dict) and isinstance(a.get(k),dict): merge(a[k],v)
else: a[k]=v
return a
files=sorted(glob.glob("/etc/netplan/*.yaml"), key=os.path.basename)
out={}
for f in files:
merge(out, yaml.safe_load(open(f)) or {})
print(json.dumps({"files":files,"config":out}))`;
const GATHER = `export PATH=$PATH:/usr/sbin:/sbin
echo "@@HOSTNAME"; hostname
echo "@@OS"; (. /etc/os-release 2>/dev/null; echo "$PRETTY_NAME")
echo "@@BACKEND"
if ls /etc/netplan/*.yaml >/dev/null 2>&1 && command -v netplan >/dev/null 2>&1; then echo netplan
elif [ -f /etc/network/interfaces ] && { command -v ifreload >/dev/null 2>&1 || command -v ifup >/dev/null 2>&1; }; then echo ifupdown
elif systemctl is-active -q NetworkManager 2>/dev/null; then echo networkmanager
elif systemctl is-active -q systemd-networkd 2>/dev/null; then echo networkd
else echo unknown; fi
echo "@@LINK"; ip -j -d link show
echo "@@ADDR"; ip -j addr show
echo "@@ROUTE"; ip -j route show default
echo "@@ROUTE6"; ip -j -6 route show default
echo "@@RESOLVTYPE"; if [ -L /etc/resolv.conf ]; then echo symlink; else echo file; fi
echo "@@RESOLV"; cat /etc/resolv.conf 2>/dev/null
echo "@@RESOLVECTL"; resolvectl dns 2>/dev/null
echo "@@BONDING"; for f in /proc/net/bonding/*; do [ -f "$f" ] && { echo "== \${f##*/}"; cat "$f"; }; done
echo "@@NETPLAN"; if command -v netplan >/dev/null 2>&1; then python3 -c '${NETPLAN_PY}' 2>&1; fi
echo "@@IFUPDOWN"; for f in /etc/network/interfaces /etc/network/interfaces.d/*; do [ -f "$f" ] && { echo "==FILE $f"; cat "$f"; echo; }; done
echo "@@FILES"; ls -1d /etc/netplan/*.yaml /etc/network/interfaces /etc/network/interfaces.d/* /etc/systemd/network/* 2>/dev/null
echo "@@PENDING"; [ -f ${STATE}/pending ] && echo pending; [ -f ${STATE}/rolled-back ] && cat ${STATE}/rolled-back
echo "@@END"`;
function sections(out) {
const res = {};
let cur = null;
for (const line of out.split('\n')) {
const m = line.match(/^@@(\w+)$/);
if (m) { cur = m[1]; res[cur] = []; continue; }
if (cur) res[cur].push(line);
}
return Object.fromEntries(Object.entries(res).map(([k, v]) => [k, v.join('\n').trim()]));
}
const json = (s, def) => { try { return JSON.parse(s); } catch { return def; } };
function parseBonding(text) {
const out = {};
for (const part of text.split(/^== /m).filter(Boolean)) {
const [name, ...lines] = part.split('\n');
const b = { slaves: [] };
let slave = null;
for (const l of lines) {
const [k, ...v] = l.split(':');
const val = v.join(':').trim();
if (k === 'Bonding Mode') b.mode = val;
else if (k === 'Transmit Hash Policy') b.hashPolicy = val.replace(/\s*\(\d+\)$/, '');
else if (k === 'LACP rate') b.lacpRate = val;
else if (k === 'MII Polling Interval (ms)') b.miimon = val;
else if (k === 'Slave Interface') { slave = { name: val }; b.slaves.push(slave); }
else if (slave && k === 'MII Status') slave.mii = val;
else if (slave && k === 'Speed') slave.speed = val;
else if (slave && k === 'Aggregator ID') slave.aggregator = val;
else if (!slave && k === 'MII Status') b.mii = val;
else if (k.trim() === 'Partner Mac Address' && !b.partnerMac) b.partnerMac = val;
}
out[name.trim()] = b;
}
return out;
}
class NetworkConfigManager {
constructor(ssh) {
this.ssh = ssh;
this.sessions = new Map(); // id -> { conn, jumps, host, sudo, backend, blocks, netplan }
}
get(id) {
const s = this.sessions.get(id);
if (!s) throw new Error(i18n.t('Network session not found'));
return s;
}
// Shell-Skript als root ausführen (Skript base64-kodiert, damit kein Quoting-Problem entsteht)
root(s, script, conn = s.conn) {
const cmd = `sh -c "$(printf %s ${b64(script)} | base64 -d)"`;
if (!s.sudo) return execOn(conn, cmd);
return execOn(conn, `sudo -S -p '' ${cmd}`, `${s.host.password || ''}\n`);
}
async rootOk(s, script) {
const r = await this.root(s, script);
if (r.code) throw new Error(lastLine(r.err) || lastLine(r.out) || i18n.t('Command failed with code {code}', { code: r.code }));
return r.out;
}
async open(id, host, onClose) {
const { conn, jumps } = await this.ssh.connect(host, id);
const s = { conn, jumps, host, sudo: false, onClose };
this.sessions.set(id, s);
this.watch(id, s);
if ((await execOn(conn, 'id -u')).out.trim() !== '0') {
s.sudo = true;
const r = await execOn(conn, "sudo -S -p '' -v", `${host.password || ''}\n`);
if (r.code) throw new Error(i18n.t('Root privileges are required. Log in as root or save the password of a user with sudo rights on the host.'));
}
return this.read(id);
}
watch(id, s) {
const conn = s.conn;
// Nur die aktuelle Verbindung darf die Sitzung beenden (nach apply wird sie ersetzt)
conn.on('close', () => { if (this.sessions.get(id) === s && s.conn === conn) { this.close(id); s.onClose(); } });
conn.on('error', () => {});
}
async read(id) {
const s = this.get(id);
const sec = sections(await this.rootOk(s, GATHER));
s.backend = sec.BACKEND || 'unknown';
const links = json(sec.LINK, []);
const addrs = json(sec.ADDR, []);
const bonding = parseBonding(sec.BONDING || '');
let config = [];
let note = '';
if (s.backend === 'netplan') {
const np = json(sec.NETPLAN, {});
if (np.error || !np.config) { note = i18n.t('netplan configuration could not be read ({err}).', { err: np.error || lastLine(sec.NETPLAN) }); s.netplan = null; }
else { s.netplan = np; config = nc.fromNetplan(np.config); }
} else if (s.backend === 'ifupdown') {
s.blocks = [];
for (const part of (sec.IFUPDOWN || '').split(/^==FILE /m).filter(Boolean)) {
const nl = part.indexOf('\n');
s.blocks.push(...nc.parseInterfaces(part.slice(nl + 1), part.slice(0, nl).trim()));
}
config = nc.fromIfupdown(s.blocks);
}
const interfaces = links.filter((l) => l.ifname !== 'lo').map((l) => {
const a = addrs.find((x) => x.ifname === l.ifname) || {};
return {
name: l.ifname, mac: l.address, mtu: l.mtu, state: l.operstate, master: l.master || '',
kind: l.linkinfo?.info_kind || (l.link_type === 'ether' ? 'ethernet' : l.link_type), slaveKind: l.linkinfo?.info_slave_kind || '',
vlanId: l.linkinfo?.info_data?.id, link: l.link || '',
addrs: (a.addr_info || []).filter((x) => x.scope !== 'link').map((x) => ({ addr: `${x.local}/${x.prefixlen}`, family: x.family, dynamic: !!x.dynamic })),
bonding: bonding[l.ifname] || null,
};
});
const resolv = sec.RESOLV || '';
return {
hostname: sec.HOSTNAME, os: sec.OS, backend: s.backend, editable: ['netplan', 'ifupdown'].includes(s.backend) && !note, note,
interfaces, config,
routes: [...json(sec.ROUTE, []), ...json(sec.ROUTE6, [])].map((r) => ({ via: r.gateway, dev: r.dev, metric: r.metric })),
dns: { servers: (resolv.match(/^nameserver\s+(\S+)/gm) || []).map((l) => l.split(/\s+/)[1]), search: ((resolv.match(/^search\s+(.+)$/m) || [])[1] || '').split(/\s+/).filter(Boolean), resolved: sec.RESOLVECTL || '', editable: sec.RESOLVTYPE === 'file' },
files: (sec.FILES || '').split('\n').filter(Boolean),
rolledBack: /\d/.test(sec.PENDING || '') ? sec.PENDING.split('\n').filter((x) => /\d/.test(x)).pop() : '',
};
}
// Schreibbefehle für eine Modelländerung erzeugen
plan(s, model, remove) {
const m = nc.validate(model, i18n.t);
if (s.backend === 'netplan') {
const cfg = nc.applyNetplan(s.netplan.config, m, { remove });
// Gesamte Konfiguration in eine Datei; bisherige Dateien werden deaktiviert (im Backup enthalten)
const others = s.netplan.files.filter((f) => f !== '/etc/netplan/90-mrterm.yaml');
return [
...others.map((f) => `mv '${f}' '${f}.mrterm-off'`),
`printf %s ${b64(`# Managed by MrTerm – previous files were renamed to *.yaml.mrterm-off\n${JSON.stringify(cfg, null, 2)}\n`)} | base64 -d > /etc/netplan/90-mrterm.yaml`,
'chmod 600 /etc/netplan/90-mrterm.yaml',
// cloud-init soll die Netzwerkkonfiguration beim nächsten Start nicht neu erzeugen
...(others.some((f) => /cloud-init/.test(f)) ? ["[ -d /etc/cloud/cloud.cfg.d ] && echo 'network: {config: disabled}' > /etc/cloud/cloud.cfg.d/99-disable-network-config.cfg || true"] : []),
];
}
if (s.backend === 'ifupdown') {
const { files } = nc.applyIfupdown(s.blocks, m, { remove });
return Object.entries(files).map(([f, content]) => {
if (!/^\/etc\/network\/interfaces(\.d\/[\w.-]+)?$/.test(f)) throw new Error('Invalid file');
return `printf %s ${b64(content)} | base64 -d > '${f}'`;
});
}
throw new Error(i18n.t('Editing is not supported for this network configuration ({backend}).', { backend: s.backend }));
}
// Änderung anwenden: Backup, schreiben, prüfen, im Hintergrund anwenden, Rollback-Wächter starten, neu verbinden und bestätigen
async apply(id, writes, verifyAddress, backendName) {
const s = this.get(id);
const be = BACKENDS[backendName || s.backend];
if (!be) throw new Error(i18n.t('Editing is not supported for this network configuration ({backend}).', { backend: s.backend }));
const script = `export PATH=$PATH:/usr/sbin:/sbin
mkdir -p ${STATE} || exit 1; rm -f ${STATE}/pending ${STATE}/applied ${STATE}/rolled-back
cd / && tar czf ${STATE}/backup.tgz $(for p in ${be.paths.join(' ')}; do [ -e "$p" ] && echo "$p"; done) || exit 1
# Schreiben in einer Subshell: bei einem Fehler sofort den alten Stand wiederherstellen
if ! ( set -e
${writes.join('\n')}
) >${STATE}/write.log 2>&1; then ${be.restore}; cat ${STATE}/write.log >&2; exit 5; fi
if ! (${be.validate}) >${STATE}/validate.log 2>&1; then ${be.restore}; cat ${STATE}/validate.log >&2; exit 4; fi
touch ${STATE}/pending
nohup setsid sh -c 'export PATH=$PATH:/usr/sbin:/sbin; sleep 2; (${be.apply}) >${STATE}/apply.log 2>&1; touch ${STATE}/applied; sleep ${ROLLBACK_SECONDS}; if [ -f ${STATE}/pending ]; then ${be.restore}; (${be.apply}) >>${STATE}/apply.log 2>&1; rm -f ${STATE}/pending; date "+%Y-%m-%d %H:%M:%S" > ${STATE}/rolled-back; fi' >/dev/null 2>&1 &
echo started`;
const r = await this.root(s, script);
if (r.code === 4) throw new Error(i18n.t('The new configuration is invalid and was not applied: {err}', { err: lastLine(r.err) }));
if (r.code) throw new Error(lastLine(r.err) || i18n.t('Command failed with code {code}', { code: r.code }));
const deadline = Date.now() + (ROLLBACK_SECONDS - 12) * 1000;
await new Promise((res) => setTimeout(res, 6000));
const target = { ...s.host, address: verifyAddress || s.host.address };
while (Date.now() < deadline) {
try {
const { conn, jumps } = await this.ssh.connect(target, id);
// Erst bestätigen, wenn das Anwenden fertig ist: sonst reißt z. B. ein Bond-Neustart die neue Verbindung wieder ab
const c = await this.root(s, `[ -f ${STATE}/applied ] || exit 7; rm -f ${STATE}/pending`, conn);
if (c.code) { conn.on('error', () => {}); conn.end(); jumps?.forEach((x) => { try { x.end(); } catch {} }); throw new Error(lastLine(c.err) || 'not applied yet'); }
// Neue Verbindung übernimmt die Sitzung
const old = { conn: s.conn, jumps: s.jumps };
Object.assign(s, { conn, jumps });
// Alte Verbindung ist nach dem IP-Wechsel meist tot: Fehler (z. B. Keepalive-Timeout) still verwerfen
for (const c of [old.conn, ...(old.jumps || [])]) { c.on('error', () => {}); try { c.end(); } catch {} }
if (verifyAddress) s.host = target;
this.watch(id, s);
return { confirmed: true };
} catch {
await new Promise((res) => setTimeout(res, 4000));
}
}
return { confirmed: false, rollbackSeconds: ROLLBACK_SECONDS };
}
saveInterface(id, model, verifyAddress) {
const s = this.get(id);
return this.apply(id, this.plan(s, model, false), verifyAddress);
}
removeInterface(id, model) {
const s = this.get(id);
return this.apply(id, this.plan(s, model, true));
}
async setHostname(id, name) {
const s = this.get(id);
if (!HOSTNAME.test(name)) throw new Error(i18n.t('Invalid value for {field}: {value}', { field: 'hostname', value: name }));
const old = (await this.rootOk(s, 'hostname')).trim();
const esc = (x) => x.replace(/\./g, '\\.');
const short = name.split('.')[0];
await this.rootOk(s, `export PATH=$PATH:/usr/sbin:/sbin
hostnamectl set-hostname '${name}' 2>/dev/null || { echo '${name}' > /etc/hostname; hostname '${name}'; }
${HOSTNAME.test(old) ? `sed -i -E 's/(^|[[:space:]])${esc(old)}([[:space:]]|$)/\\1${name}\\2/g; s/(^|[[:space:]])${esc(old.split('.')[0])}([[:space:]]|$)/\\1${short}\\2/g' /etc/hosts` : ''}
grep -qE '[[:space:]]${esc(short)}([[:space:]]|$)' /etc/hosts || echo '127.0.1.1 ${name}${name !== short ? ` ${short}` : ''}' >> /etc/hosts`);
return true;
}
async setResolv(id, servers, search) {
const s = this.get(id);
const ip = /^(\d{1,3}(\.\d{1,3}){3}|[0-9a-fA-F:]+)$/;
servers.forEach((x) => { if (!ip.test(x)) throw new Error(i18n.t('Invalid value for {field}: {value}', { field: 'DNS', value: x })); });
search.forEach((x) => { if (!/^[a-zA-Z0-9.-]+$/.test(x)) throw new Error(i18n.t('Invalid value for {field}: {value}', { field: 'search', value: x })); });
const content = `# Written by MrTerm\n${search.length ? `search ${search.join(' ')}\n` : ''}${servers.map((x) => `nameserver ${x}`).join('\n')}\n`;
await this.rootOk(s, `[ -L /etc/resolv.conf ] && exit 5; printf %s ${b64(content)} | base64 -d > /etc/resolv.conf`);
return true;
}
async readFile(id, path) {
const s = this.get(id);
if (!EDITABLE_PATH.test(path)) throw new Error('Invalid file');
return this.rootOk(s, `cat '${path}'`);
}
// Datei direkt bearbeiten; Netzwerkdateien mit Rollback, /etc/hosts und resolv.conf direkt
async writeFile(id, path, content, verifyAddress) {
const s = this.get(id);
if (!EDITABLE_PATH.test(path)) throw new Error('Invalid file');
const write = `printf %s ${b64(content)} | base64 -d > '${path}'`;
if (/^\/etc\/(hosts|resolv\.conf)$/.test(path)) { await this.rootOk(s, write); return { confirmed: true, direct: true }; }
const backend = path.startsWith('/etc/netplan/') ? 'netplan' : path.startsWith('/etc/network/') ? 'ifupdown' : 'networkd';
return this.apply(id, [write], verifyAddress, backend);
}
close(id) {
const s = this.sessions.get(id);
if (!s) return;
this.sessions.delete(id);
try { s.conn.end(); } catch {}
s.jumps?.forEach((c) => { try { c.end(); } catch {} });
}
}
module.exports = { NetworkConfigManager, parseBonding, sections };
+17 -5
View File
@@ -9,7 +9,11 @@ const i18n = require('../i18n');
function defaultAgent() {
if (process.env.SSH_AUTH_SOCK) return process.env.SSH_AUTH_SOCK;
if (process.platform === 'win32') return '\\\\.\\pipe\\openssh-ssh-agent';
if (process.platform === 'win32') {
// Nur verwenden, wenn der Windows-OpenSSH-Agent läuft (sonst schlägt die Agent-Anmeldung unnötig fehl)
const pipe = '\\\\.\\pipe\\openssh-ssh-agent';
try { return fs.existsSync(pipe) ? pipe : undefined; } catch { return undefined; }
}
return undefined;
}
@@ -111,8 +115,16 @@ class SshManager {
}
finish(answers);
});
conn.once('ready', () => resolve(conn));
conn.once('error', async (err) => {
// ssh2 kann mehrere 'error'-Ereignisse senden (z. B. Anmeldefehler und danach Handshake-Timeout).
// Ein dauerhafter Listener verhindert, dass ein späterer Fehler den Hauptprozess abstürzen lässt;
// Fehler nach dem Verbindungsaufbau melden die Sitzungen selbst (close/error).
let settled = false;
conn.on('error', () => {});
conn.once('ready', () => { settled = true; resolve(conn); });
conn.on('error', async (err) => {
if (settled) return;
settled = true;
try { conn.end(); } catch {}
// Kein Passwort hinterlegt und alle Methoden schlugen fehl -> nach Passwort fragen und neu versuchen
if (err.level === 'client-authentication' && !host.password && !host._retried) {
const pw = await this.askSecret(sessionId, { title: i18n.t('Password'), prompt: i18n.t('Password for {user}', { user: `${cfg.username}@${host.address}` }), echo: false, host: host.label || host.address });
@@ -121,9 +133,9 @@ class SshManager {
return;
}
}
reject(err);
reject(err.level === 'client-authentication' ? new Error(i18n.t('Authentication failed for {user}. Check the username, password or key.', { user: `${cfg.username}@${host.address}` })) : err);
});
try { conn.connect(cfg); } catch (e) { reject(e); }
try { conn.connect(cfg); } catch (e) { settled = true; reject(e); }
});
}
+19 -1
View File
@@ -15,6 +15,10 @@ const DEFAULTS = {
vpns: [],
knownHosts: {},
history: [],
// Löschvermerke für die Synchronisation: { c: Collection, id, at }
tombstones: [],
// LAN-Synchronisation (gerätebezogen, wird selbst nicht synchronisiert)
sync: { enabled: false, deviceId: '', deviceName: '', peers: [], share: { keys: [], hosts: [], vpns: [] }, asked: false },
settings: {
terminalTheme: 'mrterm',
fontFamily: 'Cascadia Code, JetBrains Mono, Fira Code, Consolas, monospace',
@@ -124,6 +128,7 @@ class Store {
save() {
if (this.sealed) return; // Inhalt noch nicht entschlüsselt – nichts überschreiben
if (!this.muted) this.onChange?.();
let json = JSON.stringify(this.data, null, 2);
if (this.lockEnabled && this.dek) {
const { language, appTheme, accent } = this.data.settings;
@@ -156,7 +161,20 @@ class Store {
remove(collection, id) {
this.data[collection] = this.data[collection].filter((x) => x.id !== id);
if (collection === 'groups') this.data.hosts.forEach((h) => { if (h.groupId === id) h.groupId = null; });
if (collection === 'groups') this.data.hosts.forEach((h) => { if (h.groupId === id) { h.groupId = null; h.updatedAt = Date.now(); } });
this.tombstone(collection, id);
this.save();
}
// Löschung für andere Geräte vermerken (180 Tage aufbewahren)
tombstone(c, id) {
const now = Date.now();
this.data.tombstones = [...(this.data.tombstones || []).filter((t) => !(t.c === c && t.id === id) && now - t.at < 180 * 864e5), { c, id, at: now }];
}
forgetKnownHost(id) {
delete this.data.knownHosts[id];
this.tombstone('knownHosts', id);
this.save();
}
+502
View File
@@ -0,0 +1,502 @@
// LAN-Synchronisation zwischen MrTerm-Clients (Peer-to-Peer, Ende-zu-Ende verschlüsselt).
//
// Finden: UDP-Broadcast auf Port 47811 ("Beacon" mit Geräte-ID, Name, TCP-Port, koppelbar ja/nein).
// Koppeln: X25519-Schlüsselaustausch mit Commitment (der Initiator legt sich per Hash auf seinen Schlüssel fest,
// bevor er den des anderen kennt). Beide Geräte zeigen denselben 6-stelligen Vergleichscode (SAS);
// der Nutzer bestätigt auf beiden Geräten. Ergebnis: dauerhafter Kopplungsschlüssel (32 Byte).
// Sitzung: Gegenseitige Authentisierung per HMAC mit dem Kopplungsschlüssel, frische X25519-Schlüssel je Sitzung
// (Forward Secrecy), danach alle Nachrichten AES-256-GCM-verschlüsselt.
// Abgleich: Beide Seiten senden einen Schnappschuss; pro Eintrag gewinnt die neueste Änderung (updatedAt),
// Löschvermerke (tombstones) entfernen Einträge. Geheimnisse (SSH-Schlüssel, Passwörter, VPN-Konfigurationen)
// werden nur übertragen, wenn der Nutzer sie freigegeben hat.
const dgram = require('dgram');
const net = require('net');
const os = require('os');
const crypto = require('crypto');
const i18n = require('../i18n');
const fs = require('fs');
const { execFileSync } = require('child_process');
// Lokale Firewall erkennen, die Broadcasts/eingehende Verbindungen blockieren könnte (Linux).
// Ob die Ports bereits freigegeben sind, lässt sich ohne root nicht prüfen (UFW-Regeln sind nur für root lesbar).
function localFirewall() {
if (process.platform !== 'linux') return null;
const read = (f) => { try { return fs.readFileSync(f, 'utf8'); } catch { return ''; } };
const active = (unit) => { try { return execFileSync('systemctl', ['is-active', unit], { timeout: 3000 }).toString().trim() === 'active'; } catch { return false; } };
const os = (read('/etc/os-release').match(/^ID=(.*)$/m) || [])[1]?.replace(/"/g, '') || '';
const ufw = /^ENABLED=yes/m.test(read('/etc/ufw/ufw.conf')) || active('ufw');
const firewalld = active('firewalld');
if (!ufw && !firewalld && os !== 'cachyos') return null;
return { os, ufw, firewalld };
}
const UDP_PORT = 47811;
const TCP_PORT = 47812;
const PROTO = 1;
const COLLECTIONS = ['groups', 'hosts', 'keys', 'snippets', 'forwards', 'vpns'];
const SECRETS = { keys: ['privateKey', 'passphrase'], hosts: ['password'], vpns: ['config', 'password'] };
const SPKI_X25519 = Buffer.from('302a300506032b656e032100', 'hex');
const MAX_FRAME = 32 * 1024 * 1024;
const sha = (...parts) => crypto.createHash('sha256').update(Buffer.concat(parts.map((p) => Buffer.from(p)))).digest();
const hmac = (key, ...parts) => crypto.createHmac('sha256', key).update(Buffer.concat(parts.map((p) => Buffer.from(p)))).digest();
const hkdf = (ikm, salt, info) => Buffer.from(crypto.hkdfSync('sha256', ikm, salt, info, 32));
const ts = (x) => x?.updatedAt || x?.createdAt || 0;
function x25519() {
const { publicKey, privateKey } = crypto.generateKeyPairSync('x25519');
return { privateKey, pub: publicKey.export({ type: 'spki', format: 'der' }).subarray(-32) };
}
function dh(privateKey, peerPub) {
const pk = crypto.createPublicKey({ key: Buffer.concat([SPKI_X25519, Buffer.from(peerPub)]), format: 'der', type: 'spki' });
return crypto.diffieHellman({ privateKey, publicKey: pk });
}
// ---------------------------------------------------------------- Framing (4 Byte Länge + Nutzlast)
class Channel {
constructor(sock) {
this.sock = sock;
this.buf = Buffer.alloc(0);
this.queue = [];
this.waiters = [];
this.keys = null; // { send, recv } nach dem Handshake
sock.on('data', (d) => this.onData(d));
const fail = (e) => { this.closed = e || new Error('closed'); this.waiters.splice(0).forEach((w) => w.reject(this.closed)); };
sock.on('close', () => fail());
sock.on('error', (e) => fail(e));
sock.setTimeout(180000, () => sock.destroy(new Error('timeout')));
}
onData(d) {
this.buf = Buffer.concat([this.buf, d]);
while (this.buf.length >= 4) {
const len = this.buf.readUInt32BE(0);
if (len > MAX_FRAME) { this.sock.destroy(new Error('frame too large')); return; }
if (this.buf.length < 4 + len) break;
const frame = this.buf.subarray(4, 4 + len);
this.buf = this.buf.subarray(4 + len);
let msg;
try { msg = this.decode(frame); } catch (e) { this.sock.destroy(e); return; }
const w = this.waiters.shift();
if (w) w.resolve(msg); else this.queue.push(msg);
}
}
encode(obj) {
const plain = Buffer.from(JSON.stringify(obj));
if (!this.keys) return plain;
const iv = crypto.randomBytes(12);
const c = crypto.createCipheriv('aes-256-gcm', this.keys.send, iv);
return Buffer.concat([iv, c.update(plain), c.final(), c.getAuthTag()]);
}
decode(frame) {
if (!this.keys) return JSON.parse(frame.toString('utf8'));
const d = crypto.createDecipheriv('aes-256-gcm', this.keys.recv, frame.subarray(0, 12));
d.setAuthTag(frame.subarray(frame.length - 16));
return JSON.parse(Buffer.concat([d.update(frame.subarray(12, frame.length - 16)), d.final()]).toString('utf8'));
}
send(obj) {
const p = this.encode(obj);
const h = Buffer.alloc(4); h.writeUInt32BE(p.length);
this.sock.write(Buffer.concat([h, p]));
}
recv(type, timeout = 30000) {
const msg = this.queue.length ? Promise.resolve(this.queue.shift()) : this.closed ? Promise.reject(this.closed) : new Promise((resolve, reject) => this.waiters.push({ resolve, reject }));
let t;
const to = new Promise((_, rej) => { t = setTimeout(() => rej(new Error('timeout')), timeout); });
return Promise.race([msg, to]).finally(() => clearTimeout(t)).then((m) => {
if (m?.t === 'error') throw new Error(m.msg || 'remote error');
if (type && m?.t !== type) throw new Error(`unexpected message ${m?.t}`);
return m;
});
}
close() { try { this.sock.end(); } catch {} }
}
// ---------------------------------------------------------------- Zusammenführen
// Schnappschuss für ein Gerät; nicht freigegebene Geheimnisse werden entfernt
function snapshot(data) {
const share = data.sync?.share || {};
const out = { tombstones: data.tombstones || [], knownHosts: data.knownHosts || {} };
for (const c of COLLECTIONS) {
out[c] = (data[c] || []).map((x) => {
const fields = SECRETS[c];
if (!fields || (share[c] || []).includes(x.id)) return x;
const y = { ...x, _noSecret: true };
fields.forEach((f) => delete y[f]);
return y;
});
}
return out;
}
// Eingehenden Schnappschuss übernehmen; liefert true, wenn sich etwas geändert hat
function merge(data, incoming) {
let changed = false;
const tombs = new Map((data.tombstones || []).map((t) => [`${t.c}|${t.id}`, t]));
for (const t of incoming.tombstones || []) {
const k = `${t.c}|${t.id}`;
if (!tombs.has(k) || tombs.get(k).at < t.at) { tombs.set(k, t); changed = true; }
}
data.tombstones = [...tombs.values()];
for (const c of COLLECTIONS) {
const list = data[c] || (data[c] = []);
for (const inc of incoming[c] || []) {
if (!inc?.id) continue;
const tomb = tombs.get(`${c}|${inc.id}`);
if (tomb && tomb.at >= ts(inc)) continue;
const i = list.findIndex((x) => x.id === inc.id);
const local = list[i];
if (local && ts(local) >= ts(inc)) continue;
const { _noSecret, ...item } = inc;
// Nicht freigegebene Geheimnisse: lokale Werte behalten
if (_noSecret && local) (SECRETS[c] || []).forEach((f) => { if (local[f] !== undefined) item[f] = local[f]; });
if (i >= 0) list[i] = item; else list.push(item);
changed = true;
}
// Löschvermerke anwenden
const before = list.length;
data[c] = list.filter((x) => { const t = tombs.get(`${c}|${x.id}`); return !t || t.at < ts(x); });
if (data[c].length !== before) changed = true;
}
for (const [id, kh] of Object.entries(incoming.knownHosts || {})) {
const t = tombs.get(`knownHosts|${id}`);
if (t && t.at >= (kh.addedAt || 0)) continue;
const local = data.knownHosts[id];
if (!local || (kh.addedAt || 0) > (local.addedAt || 0)) { data.knownHosts[id] = kh; changed = true; }
}
for (const t of tombs.values()) {
if (t.c === 'knownHosts' && data.knownHosts[t.id] && (data.knownHosts[t.id].addedAt || 0) <= t.at) { delete data.knownHosts[t.id]; changed = true; }
}
return changed;
}
// ---------------------------------------------------------------- Dienst
class SyncService {
/**
* @param {import('./store').Store} store
* @param {(event: string, payload?: any) => void} emit Ereignisse an die Oberfläche
* @param {(req: { code, name, id }) => Promise<boolean>} confirmPair Vergleichscode anzeigen und Bestätigung abwarten
*/
constructor(store, emit, confirmPair) {
this.store = store;
this.emit = emit;
this.confirmPair = confirmPair;
this.seen = new Map(); // id -> { id, name, address, port, pairable, at }
this.pairable = false;
this.running = false;
this.lastError = '';
this.syncing = new Set();
this.firewall = localFirewall();
}
get cfg() {
const d = this.store.get();
d.sync ||= { enabled: false, peers: [], share: { keys: [], hosts: [], vpns: [] } };
const s = d.sync;
if (!s.deviceId) s.deviceId = crypto.randomUUID();
if (!s.deviceName) s.deviceName = os.hostname();
s.peers ||= []; s.share ||= { keys: [], hosts: [], vpns: [] };
return s;
}
// ------------------------------------------------ Start/Stop
async start() {
if (this.running || this.store.sealed || !this.cfg.enabled) return;
this.running = true;
this.server = net.createServer((sock) => this.accept(sock).catch(() => sock.destroy()));
this.server.on('error', () => {});
await new Promise((res) => {
this.server.once('error', () => this.server.listen(0, res));
this.server.listen(TCP_PORT, res);
});
this.port = this.server.address().port;
this.udp = dgram.createSocket({ type: 'udp4', reuseAddr: true });
this.udp.on('error', () => {});
this.udp.on('message', (msg, rinfo) => this.onBeacon(msg, rinfo));
await new Promise((res) => this.udp.bind(UDP_PORT, () => { try { this.udp.setBroadcast(true); } catch {} res(); }));
this.beaconTimer = setInterval(() => this.beacon(), 5000);
this.syncTimer = setInterval(() => this.syncAll(), 120000);
this.beacon();
this.emitState();
}
stop() {
if (!this.running) return;
this.running = false;
clearInterval(this.beaconTimer); clearInterval(this.syncTimer); clearTimeout(this.debounce);
try { this.server.close(); } catch {}
try { this.udp.close(); } catch {}
this.seen.clear();
this.emitState();
}
setEnabled(on, name) {
const c = this.cfg;
c.enabled = !!on;
if (name) c.deviceName = String(name).slice(0, 60);
this.store.save();
if (on) this.start(); else this.stop();
return this.status();
}
// ------------------------------------------------ Finden
broadcastAddrs() {
const out = new Set(['255.255.255.255']);
for (const list of Object.values(os.networkInterfaces())) {
for (const a of list || []) {
if (a.family !== 'IPv4' || a.internal) continue;
const ip = a.address.split('.').map(Number), mask = a.netmask.split('.').map(Number);
out.add(ip.map((o, i) => (o & mask[i]) | (~mask[i] & 255)).join('.'));
}
}
return [...out];
}
beacon() {
if (!this.running) return;
const c = this.cfg;
const msg = Buffer.from(JSON.stringify({ mrterm: PROTO, id: c.deviceId, name: c.deviceName, port: this.port, pairable: this.pairable }));
for (const addr of this.broadcastAddrs()) this.udp.send(msg, UDP_PORT, addr, () => {});
// Einträge älter als 20 s gelten als offline
for (const [id, p] of this.seen) if (Date.now() - p.at > 20000) { this.seen.delete(id); this.emitState(); }
}
onBeacon(buf, rinfo) {
let b;
try { b = JSON.parse(buf.toString('utf8')); } catch { return; }
if (b?.mrterm !== PROTO || !b.id || b.id === this.cfg.deviceId || !Number.isInteger(b.port)) return;
const known = this.seen.get(b.id);
this.seen.set(b.id, { id: b.id, name: String(b.name || '').slice(0, 60), address: rinfo.address, port: b.port, pairable: !!b.pairable, at: Date.now() });
const peer = this.cfg.peers.find((p) => p.id === b.id);
if (peer && peer.address !== rinfo.address) { peer.address = rinfo.address; peer.port = b.port; }
if (!known) { this.emitState(); if (peer) this.syncWith(peer).catch(() => {}); }
else if (known.pairable !== !!b.pairable) this.emitState();
}
setPairable(on) {
this.pairable = !!on;
clearTimeout(this.pairTimer);
if (on) this.pairTimer = setTimeout(() => this.setPairable(false), 180000);
this.beacon();
this.emitState();
}
// ------------------------------------------------ Status für die Oberfläche
status() {
const c = this.cfg;
return {
enabled: c.enabled, running: this.running, deviceId: c.deviceId, deviceName: c.deviceName, pairable: this.pairable, port: this.port,
peers: c.peers.map((p) => ({ id: p.id, name: p.name, lastSync: p.lastSync || 0, online: this.seen.has(p.id), address: p.address, error: p.error || '' })),
nearby: [...this.seen.values()].filter((p) => !c.peers.some((x) => x.id === p.id)).map(({ id, name, address, pairable }) => ({ id, name, address, pairable })),
share: c.share, asked: !!c.asked, sealed: !!this.store.sealed, firewall: this.firewall,
};
}
emitState() { this.emit('sync:state', this.status()); }
// ------------------------------------------------ Verbindungen
connect(address, port) {
return new Promise((resolve, reject) => {
const sock = net.connect({ host: address, port, timeout: 8000 });
sock.once('connect', () => { sock.setTimeout(0); resolve(new Channel(sock)); });
sock.once('timeout', () => { sock.destroy(); reject(new Error('timeout')); });
sock.once('error', reject);
});
}
// Eingehende Verbindung: Kopplung oder Synchronisation
async accept(sock) {
const ch = new Channel(sock);
try {
const first = await ch.recv(null, 10000);
if (first.t === 'pair') await this.pairResponder(ch, first);
else if (first.t === 'hello') await this.sessionResponder(ch, first);
} catch (e) {
try { ch.send({ t: 'error', msg: e.message }); } catch {}
} finally { ch.close(); }
}
// ------------------------------------------------ Kopplung
// Initiator (Gerät, auf dem der Nutzer ein anderes Gerät ausgewählt hat)
async pair(id) {
const target = this.seen.get(id);
if (!target) throw new Error('Device not found');
const ch = await this.connect(target.address, target.port);
try {
const me = x25519();
const nonce = crypto.randomBytes(16);
const c = this.cfg;
ch.send({ t: 'pair', v: PROTO, id: c.deviceId, name: c.deviceName, commit: sha(me.pub, nonce).toString('base64') });
const r = await ch.recv('pair-pub');
ch.send({ t: 'pair-reveal', pub: me.pub.toString('base64'), nonce: nonce.toString('base64') });
const peerPub = Buffer.from(r.pub, 'base64');
const { code, key } = this.derivePair(dh(me.privateKey, peerPub), peerPub, me.pub, r.id, c.deviceId);
return await this.finishPair(ch, { id: r.id, name: r.name, address: target.address, port: target.port }, code, key, 'initiator');
} finally { ch.close(); }
}
// Gegenseite: nur solange "koppelbar" aktiv ist
async pairResponder(ch, msg) {
if (!this.pairable) throw new Error(i18n.t('Device is not ready for pairing'));
const me = x25519();
const c = this.cfg;
ch.send({ t: 'pair-pub', id: c.deviceId, name: c.deviceName, pub: me.pub.toString('base64') });
const rev = await ch.recv('pair-reveal');
const peerPub = Buffer.from(rev.pub, 'base64');
if (!sha(peerPub, Buffer.from(rev.nonce, 'base64')).equals(Buffer.from(msg.commit, 'base64'))) throw new Error('Commitment mismatch');
const { code, key } = this.derivePair(dh(me.privateKey, peerPub), me.pub, peerPub, c.deviceId, msg.id);
const addr = ch.sock.remoteAddress?.replace(/^::ffff:/, '');
await this.finishPair(ch, { id: msg.id, name: String(msg.name || '').slice(0, 60), address: addr, port: this.seen.get(msg.id)?.port || TCP_PORT }, code, key, 'responder');
}
// Vergleichscode und Kopplungsschlüssel aus dem Schlüsselaustausch (Reihenfolge: Responder, Initiator)
derivePair(shared, pubR, pubI, idR, idI) {
const transcript = Buffer.concat([pubR, pubI, Buffer.from(`${idR}|${idI}`)]);
const code = String(sha('mrterm-sas', transcript).readUInt32BE(0) % 1000000).padStart(6, '0');
const key = hkdf(shared, transcript, 'mrterm-pair-key');
return { code, key };
}
async finishPair(ch, peer, code, key, role) {
const ok = await this.confirmPair({ code, name: peer.name, id: peer.id, role });
ch.send({ t: 'pair-confirm', ok, mac: ok ? hmac(key, 'confirm', role).toString('base64') : '' });
const r = await ch.recv('pair-confirm', 120000);
const other = role === 'initiator' ? 'responder' : 'initiator';
if (!ok) throw new Error(i18n.t('Pairing was rejected on this device.'));
if (!r.ok) throw new Error(i18n.t('Pairing was rejected on the other device.'));
if (!crypto.timingSafeEqual(Buffer.from(r.mac, 'base64'), hmac(key, 'confirm', other))) throw new Error(i18n.t('Pairing verification failed.'));
const c = this.cfg;
c.peers = [...c.peers.filter((p) => p.id !== peer.id), { ...peer, key: key.toString('base64'), pairedAt: Date.now() }];
this.store.save();
this.setPairable(false);
this.emit('sync:paired', { id: peer.id, name: peer.name });
this.emitState();
if (role === 'initiator') setTimeout(() => this.syncWith(c.peers.find((p) => p.id === peer.id)).catch(() => {}), 1500);
return true;
}
unpair(id) {
const c = this.cfg;
c.peers = c.peers.filter((p) => p.id !== id);
this.store.save();
this.emitState();
return this.status();
}
// ------------------------------------------------ Sitzung (authentisiert + verschlüsselt)
sessionKeys(pairKey, shared, transcript, initiator) {
const k1 = hkdf(Buffer.concat([pairKey, shared]), transcript, 'mrterm-i2r');
const k2 = hkdf(Buffer.concat([pairKey, shared]), transcript, 'mrterm-r2i');
return initiator ? { send: k1, recv: k2 } : { send: k2, recv: k1 };
}
async syncWith(peer) {
if (!peer || !this.running || this.store.sealed || this.syncing.has(peer.id)) return;
const live = this.seen.get(peer.id);
const address = live?.address || peer.address;
const port = live?.port || peer.port || TCP_PORT;
if (!address) return;
this.syncing.add(peer.id);
let ch;
try {
ch = await this.connect(address, port);
const key = Buffer.from(peer.key, 'base64');
const me = x25519();
const nI = crypto.randomBytes(16);
const c = this.cfg;
ch.send({ t: 'hello', v: PROTO, id: c.deviceId, eph: me.pub.toString('base64'), nonce: nI.toString('base64') });
const r = await ch.recv('hello');
if (r.id !== peer.id) throw new Error('Unexpected device');
const transcript = Buffer.concat([Buffer.from(c.deviceId), Buffer.from(peer.id), me.pub, Buffer.from(r.eph, 'base64'), nI, Buffer.from(r.nonce, 'base64')]);
if (!crypto.timingSafeEqual(Buffer.from(r.mac, 'base64'), hmac(key, 'responder', transcript))) throw new Error('Authentication failed');
ch.send({ t: 'auth', mac: hmac(key, 'initiator', transcript).toString('base64') });
ch.keys = this.sessionKeys(key, dh(me.privateKey, Buffer.from(r.eph, 'base64')), transcript, true);
ch.send({ t: 'state', data: snapshot(this.store.get()) });
const theirs = await ch.recv('state');
this.applyRemote(theirs.data);
Object.assign(peer, { lastSync: Date.now(), error: '', address, port });
this.store.muted = true; this.store.save(); this.store.muted = false;
} catch (e) {
peer.error = e.message;
throw e;
} finally {
this.syncing.delete(peer.id);
ch?.close();
this.emitState();
}
}
async sessionResponder(ch, msg) {
const c = this.cfg;
const peer = c.peers.find((p) => p.id === msg.id);
if (!peer || this.store.sealed) throw new Error('Unknown device');
const key = Buffer.from(peer.key, 'base64');
const me = x25519();
const nR = crypto.randomBytes(16);
const transcript = Buffer.concat([Buffer.from(msg.id), Buffer.from(c.deviceId), Buffer.from(msg.eph, 'base64'), me.pub, Buffer.from(msg.nonce, 'base64'), nR]);
ch.send({ t: 'hello', id: c.deviceId, eph: me.pub.toString('base64'), nonce: nR.toString('base64'), mac: hmac(key, 'responder', transcript).toString('base64') });
const a = await ch.recv('auth');
if (!crypto.timingSafeEqual(Buffer.from(a.mac, 'base64'), hmac(key, 'initiator', transcript))) throw new Error('Authentication failed');
ch.keys = this.sessionKeys(key, dh(me.privateKey, Buffer.from(msg.eph, 'base64')), transcript, false);
const theirs = await ch.recv('state');
ch.send({ t: 'state', data: snapshot(this.store.get()) });
this.applyRemote(theirs.data);
Object.assign(peer, { lastSync: Date.now(), error: '', address: ch.sock.remoteAddress?.replace(/^::ffff:/, '') || peer.address });
this.store.muted = true; this.store.save(); this.store.muted = false;
this.emitState();
}
applyRemote(data) {
if (merge(this.store.get(), data || {})) {
this.store.muted = true; this.store.save(); this.store.muted = false;
this.emit('sync:changed');
// Änderungen an weitere gekoppelte Geräte weitergeben
this.schedule(3000);
}
}
// Nach lokalen Änderungen (entprellt) mit allen erreichbaren Geräten abgleichen
schedule(delay = 2000) {
if (!this.running) return;
clearTimeout(this.debounce);
this.debounce = setTimeout(() => this.syncAll(), delay);
}
async syncAll() {
const results = await Promise.allSettled(this.cfg.peers.filter((p) => this.seen.has(p.id) || p.address).map((p) => this.syncWith(p)));
return results.filter((r) => r.status === 'fulfilled').length;
}
setShare(share) {
const clean = (a) => (Array.isArray(a) ? a.filter((x) => typeof x === 'string') : []);
const c = this.cfg;
c.share = { keys: clean(share?.keys), hosts: clean(share?.hosts), vpns: clean(share?.vpns), declined: { keys: [], hosts: [], vpns: [] } };
c.asked = true;
this.store.save();
return this.status();
}
// Einzelnes neues Geheimnis teilen oder ablehnen (Ablehnung wird gemerkt, damit nicht erneut gefragt wird)
shareItem(c, id, yes) {
if (!SECRETS[c] || typeof id !== 'string') throw new Error('Invalid');
const sh = this.cfg.share;
sh.declined ||= { keys: [], hosts: [], vpns: [] };
sh[c] = (sh[c] || []).filter((x) => x !== id);
sh.declined[c] = (sh.declined[c] || []).filter((x) => x !== id);
(yes ? sh[c] : sh.declined[c]).push(id);
this.store.save();
if (yes) this.schedule(500);
return this.status();
}
// Gerät per IP hinzufügen (wenn Broadcasts im Netz blockiert sind)
async probe(address, port = TCP_PORT) {
if (!/^[\w.:-]+$/.test(address)) throw new Error('Invalid address');
// Kurzer Test, ob dort ein MrTerm lauscht; das Gerät erscheint danach unter "In der Nähe"
const ch = await this.connect(address, Number(port) || TCP_PORT);
ch.close();
this.seen.set(`manual:${address}`, { id: `manual:${address}`, name: address, address, port: Number(port) || TCP_PORT, pairable: true, at: Date.now() + 600000 });
this.emitState();
return true;
}
}
module.exports = { SyncService, snapshot, merge, Channel };
+1
View File
@@ -34,4 +34,5 @@ contextBridge.exposeInMainWorld('api', {
close: (id) => ipcRenderer.send('rdp:close', id),
},
replySecret: (reqId, v) => ipcRenderer.send('secret:reply', reqId, v),
pairReply: (reqId, ok) => ipcRenderer.send('sync:pairReply', reqId, ok),
});
+427 -9
View File
@@ -42,6 +42,7 @@ const ICONS = {
upload: '<svg viewBox="0 0 24 24"><path d="M12 20V8M6 14l6-6 6 6M4 4h16"/></svg>',
docker: '<svg viewBox="0 0 24 24"><path d="M2 12h19c-.6 4.5-4 8-10 8-5 0-8-3-9-8z"/><path d="M5 12V9h3v3M8 12V9h3v3M11 12V9h3v3M8 9V6h3v3M21 12c.5-1.5 0-3-1-3.5"/></svg>',
wall: '<svg viewBox="0 0 24 24"><rect x="3" y="4" width="18" height="16" rx="1"/><path d="M3 9.3h18M3 14.7h18M9 4v5.3M15 4v5.3M6 9.3v5.4M12 9.3v5.4M18 9.3v5.4M9 14.7V20M15 14.7V20"/></svg>',
network: '<svg viewBox="0 0 24 24"><rect x="9" y="3" width="6" height="5" rx="1"/><rect x="3" y="16" width="6" height="5" rx="1"/><rect x="15" y="16" width="6" height="5" rx="1"/><path d="M12 8v4M6 16v-4h12v4"/></svg>',
logs: '<svg viewBox="0 0 24 24"><path d="M5 4h14v16H5zM8 8h8M8 12h8M8 16h5"/></svg>',
};
const COLORS = ['#6e7bff', '#3ecf8e', '#ff5f6d', '#ffb454', '#c792ea', '#56d6d6', '#ff79c6', '#8b91a5', '#4f9dff', '#e0a100'];
@@ -82,7 +83,7 @@ async function call(ch, ...a) {
}
// ---------- Modals
function modal({ title, text = '', body = '', buttons = [] }) {
function modal({ title, text = '', body = '', buttons = [], noEnter = false }) {
return new Promise((resolve) => {
const bg = h(`<div class="modal-bg"><div class="modal"><div class="mbody"><h3>${esc(title)}</h3>${text ? `<p>${esc(text)}</p>` : ''}${body}</div><div class="mfoot"></div></div></div>`);
const foot = $('.mfoot', bg);
@@ -95,7 +96,7 @@ function modal({ title, text = '', body = '', buttons = [] }) {
bg.addEventListener('mousedown', (e) => { if (e.target === bg) done(null); });
bg.addEventListener('keydown', (e) => {
if (e.key === 'Escape') done(null);
if (e.key === 'Enter' && e.target.tagName !== 'TEXTAREA') { e.preventDefault(); foot.lastElementChild.click(); }
if (e.key === 'Enter' && !noEnter && e.target.tagName !== 'TEXTAREA') { e.preventDefault(); foot.lastElementChild.click(); }
});
$('#modalRoot').append(bg);
($('input,select,textarea', bg) || foot.lastElementChild).focus();
@@ -390,7 +391,7 @@ function hostMenu(hst) {
return [
{ label: hst.protocol === 'rdp' ? T('Connect in tab') : T('Connect'), icon: 'play', run: () => connectHost(hst) },
...(hst.protocol === 'rdp' ? [{ label: T('Open in separate window'), icon: 'screen', run: () => launchRdp(hst) }] : []),
...(hst.protocol !== 'rdp' ? [{ label: T('Open SFTP'), icon: 'folder', run: () => openSftp(hst) }, { label: T('Docker containers'), icon: 'docker', run: () => openDocker(hst) }, { label: T('Firewall'), icon: 'wall', run: () => openFirewall(hst) }] : []),
...(hst.protocol !== 'rdp' ? [{ label: T('Open SFTP'), icon: 'folder', run: () => openSftp(hst) }, { label: T('Docker containers'), icon: 'docker', run: () => openDocker(hst) }, { label: T('Firewall'), icon: 'wall', run: () => openFirewall(hst) }, { label: T('Network'), icon: 'network', run: () => openNetwork(hst) }] : []),
'-',
{ label: T('Edit'), icon: 'edit', run: () => editHost(hst) },
{ label: T('Duplicate'), icon: 'dup', run: async () => { const { id, createdAt, updatedAt, ...rest } = hst; await call('vault:upsert', 'hosts', { ...rest, label: (hst.label || hst.address) + T(' (copy)') }); reload(); } },
@@ -555,7 +556,8 @@ function editHost(hst = {}) {
tags: v.tags.split(',').map((t) => t.trim()).filter(Boolean),
groupId: v.groupId || null, keyId: v.keyId || null, jumpHostId: v.jumpHostId || null, vpnId: v.vpnId || null,
};
await call('vault:upsert', 'hosts', item);
const savedHost = await call('vault:upsert', 'hosts', item);
if (item.password) askShareSecret('hosts', savedHost, item.label || item.address);
reload();
}, isNew ? null : (() => { const b = h(`<button class="btn danger">${ICONS.trash}</button>`); b.title = T('Delete'); b.onclick = async () => { if (await confirmBox(T('Delete host?'), T('“{name}” will be permanently removed.', { name: hst.label || hst.address }))) { await call('vault:remove', 'hosts', hst.id); closeDrawer(); reload(); } }; return b; })());
setProto(proto);
@@ -616,7 +618,8 @@ async function generateKey() {
});
if (!r) return;
const k = await call('key:generate', { type: r.type, passphrase: r.passphrase, comment: r.label });
await call('vault:upsert', 'keys', { label: r.label, privateKey: k.privateKey, publicKey: k.publicKey, passphrase: r.passphrase || undefined });
const newKey = await call('vault:upsert', 'keys', { label: r.label, privateKey: k.privateKey, publicKey: k.publicKey, passphrase: r.passphrase || undefined });
askShareSecret('keys', newKey, r.label);
await call('clipboard:write', k.publicKey);
toast(T('Key generated – public key copied to clipboard'), 'ok');
reload();
@@ -632,7 +635,8 @@ function editKey(k = {}, pick = false) {
const v = formValues(form);
if (!v.privateKey.trim()) throw new Error(T('Private key is missing.'));
const parsed = await call('key:parse', { privateKey: v.privateKey, passphrase: v.passphrase });
await call('vault:upsert', 'keys', { ...k, ...v, label: v.label || parsed.type, publicKey: v.publicKey.trim() || parsed.publicKey });
const savedKey = await call('vault:upsert', 'keys', { ...k, ...v, label: v.label || parsed.type, publicKey: v.publicKey.trim() || parsed.publicKey });
askShareSecret('keys', savedKey, savedKey.label);
reload();
}, (() => { const b = h(`<button class="btn">${ICONS.folder}${T('File…')}</button>`); b.onclick = loadFile; return b; })());
async function loadFile() {
@@ -810,6 +814,7 @@ function editVpn(v = {}, pick = false) {
const item = { ...v, type, label: f.label.trim() || VPN_TYPES[type], config: f.config, disconnectOnQuit: f.disconnectOnQuit,
username: type === 'openvpn' ? f.username : '', password: type === 'openvpn' ? f.password : '' };
const saved = await call('vault:upsert', 'vpns', item);
askShareSecret('vpns', saved, saved.label);
for (const cb of $$('[data-host]', hostBox)) {
const hst = S.vault.hosts.find((x) => x.id === cb.dataset.host);
const want = cb.checked ? saved.id : (hst.vpnId === saved.id ? null : hst.vpnId || null);
@@ -944,6 +949,10 @@ async function viewSettings(page) {
const secCard = h(`<div class="settings-card"><h3>${T('App lock')}</h3><p style="color:var(--muted);margin-top:0">${T('Lock MrTerm with a password and/or a FIDO2 security key (e.g. YubiKey). The vault is then additionally encrypted and can only be opened with one of these methods.')}</p><div class="lock-rows"></div></div>`);
renderLockSettings($('.lock-rows', secCard));
// ---- LAN-Synchronisation
const syncCard = h('<div class="settings-card sync-card"></div>');
renderSyncCard(syncCard);
// ---- Updates
const updCard = h(`<div class="settings-card"><h3>Updates</h3><p class="upd-info" style="color:var(--muted);margin-top:0">${T('Installed version: {v}', { v: '…' })}</p></div>`);
api.call('app:version').then((v) => { $('.upd-info', updCard).textContent = T('Installed version: {v}', { v }); });
@@ -976,7 +985,7 @@ async function viewSettings(page) {
<span>${C}+<kbd>Shift</kbd>+<kbd>F</kbd></span><span>${T('Search in terminal')}</span>
<span>${C}+<kbd>+/−/0</kbd></span><span>${T('Font size')}</span>
<span>${C}+<kbd>Shift</kbd>+<kbd>L</kbd></span><span>${T('Lock now')}</span></div></div>`);
c.append(langCard, secCard, designCard, themeCard, termCard, rdpCard, importCard, dataCard, updCard, keysCard);
c.append(langCard, secCard, syncCard, designCard, themeCard, termCard, rdpCard, importCard, dataCard, updCard, keysCard);
}
// ============================================================ App-Sperre
@@ -1091,6 +1100,146 @@ function renderLockSettings(box) {
}
}
// ============================================================ LAN-Synchronisation
S.syncStatus = null;
async function renderSyncCard(card) {
if (!S.syncStatus) { try { S.syncStatus = await api.call('sync:status'); } catch { return; } }
const st = S.syncStatus;
card.innerHTML = `<h3>${T('Synchronization')}</h3><p style="color:var(--muted);margin-top:0">${T('Synchronize hosts, groups, snippets, port forwards, VPNs and known hosts directly between MrTerm devices in your local network. The connection is end-to-end encrypted; no server or cloud is involved.')}</p>`;
const en = check(T('Enable LAN synchronization'), 'syncOn', st.enabled);
$('input', en).onchange = async (e) => {
S.syncStatus = await call('sync:enable', e.target.checked);
renderSyncCard(card);
if (e.target.checked && S.syncStatus.firewall) showFirewallHint();
};
card.append(en);
if (!st.enabled) return;
if (st.firewall && !syncFwDismissed()) card.append(firewallHintBox(() => renderSyncCard(card)));
const name = field(T('Device name'), 'devName', st.deviceName);
$('input', name).onchange = async (e) => { S.syncStatus = await call('sync:enable', true, e.target.value.trim()); };
card.append(name);
const list = h('<div class="sync-peers"></div>');
if (!st.peers.length) list.append(h(`<div class="hint" style="color:var(--faint);padding:6px 0">${T('No paired devices yet.')}</div>`));
for (const p of st.peers) {
const row = h(`<div class="lock-row"><span class="dot ${p.online ? 'on' : ''}"></span><div class="grow"><b>${esc(p.name)}</b><div class="sub">${p.online ? T('online') : T('offline')}${p.lastSync ? ` · ${T('last sync {time}', { time: relTime(p.lastSync) })}` : ''}${p.error ? ` · <span style="color:var(--red)">${esc(p.error)}</span>` : ''}</div></div></div>`);
const rm = h(`<button class="btn ghost" title="${esc(T('Unpair'))}">${ICONS.trash}</button>`);
rm.onclick = async () => { if (await confirmBox(T('Unpair device?'), T('“{name}” will no longer synchronize with this device.', { name: p.name }), T('Unpair'))) { S.syncStatus = await call('sync:unpair', p.id); renderSyncCard(card); } };
row.append(rm);
list.append(row);
}
card.append(list);
const shared = (c, arr, pred = () => true) => `${(st.share[c] || []).filter((id) => arr.some((x) => x.id === id)).length}/${arr.filter(pred).length}`;
card.append(h(`<div class="hint" style="color:var(--muted);font-size:12px;margin-top:10px">${T('Shared secrets: {keys} SSH keys, {pw} host passwords, {vpn} VPN configurations', { keys: shared('keys', S.vault.keys), pw: shared('hosts', S.vault.hosts, (x) => x.password), vpn: shared('vpns', S.vault.vpns) })}</div>`));
const acts = h('<div class="row" style="flex-wrap:wrap;margin-top:12px"></div>');
const pair = h(`<button class="btn primary">${ICONS.plus}${T('Pair new device')}</button>`); pair.onclick = openPairing;
const now = h(`<button class="btn">${ICONS.refresh}${T('Sync now')}</button>`);
now.onclick = async () => { now.disabled = true; try { const n = await call('sync:now'); toast(T('Synchronized with {n} device(s)', { n }), 'ok'); } catch {} now.disabled = false; };
const sec = h(`<button class="btn">${ICONS.key}${T('Choose shared secrets')}</button>`); sec.onclick = chooseSharedSecrets;
acts.append(pair, now, sec);
card.append(acts);
if (!st.firewall || syncFwDismissed()) card.append(h(`<div class="hint" style="color:var(--faint);font-size:11px;margin-top:10px">${T('Devices find each other via UDP port 47811 and synchronize via TCP port 47812. If a firewall is active, allow these ports in your local network (with UFW: sudo ufw allow 47811/udp and sudo ufw allow 47812/tcp).')}</div>`));
}
// Neues Geheimnis bei aktiver Synchronisation: fragen, ob es geteilt werden soll (Antwort wird gemerkt)
async function askShareSecret(c, item, label) {
try {
const st = S.syncStatus || (S.syncStatus = await api.call('sync:status'));
if (!st.enabled || !st.peers.length || !item?.id) return;
if ((st.share[c] || []).includes(item.id) || (st.share.declined?.[c] || []).includes(item.id)) return;
const what = { keys: T('SSH key'), hosts: T('Host password'), vpns: T('VPN configuration') }[c];
const r = await modal({ title: T('Share with paired devices?'), text: `${what}: ${label || ''}`,
body: `<p style="margin-top:0">${T('Should this secret be synchronized to your paired devices ({names})? You can change this later under Settings → Synchronization.', { names: st.peers.map((p) => p.name).join(', ') })}</p>`,
buttons: [{ label: T("Don't share"), value: 'no', cls: 'ghost' }, { label: T('Share'), value: 'yes', cls: 'primary' }], noEnter: true });
if (!r) return; // Dialog geschlossen: beim nächsten Speichern erneut fragen
S.syncStatus = await api.call('sync:shareItem', c, item.id, r === 'yes');
} catch {}
}
// Firewall-Hinweis (CachyOS / aktive UFW bzw. firewalld): Ports für die Synchronisation freigeben
const FW_CMDS = { ufw: 'sudo ufw allow 47811/udp\nsudo ufw allow 47812/tcp', firewalld: 'sudo firewall-cmd --permanent --add-port=47811/udp --add-port=47812/tcp\nsudo firewall-cmd --reload' };
const fwCmds = (f) => (f.firewalld && !f.ufw ? FW_CMDS.firewalld : FW_CMDS.ufw);
const syncFwDismissed = () => { try { return localStorage.getItem('mrterm.sync.fwHint') === '1'; } catch { return false; } };
function firewallHintBox(onDismiss) {
const f = S.syncStatus.firewall;
const box = h(`<div class="net-banner warn fw-hint"><div>${ICONS.wall}</div><div class="grow"><b>${f.os === 'cachyos' ? T('CachyOS: allow the sync ports in the firewall') : T('Firewall active: allow the sync ports')}</b>
<p>${T('Otherwise other devices cannot find or reach this device. Run these commands once in a terminal:')}</p><pre class="mono">${esc(fwCmds(f))}</pre>
<div class="row"><button class="btn sm" data-f="copy">${ICONS.copy}${T('Copy commands')}</button><button class="btn sm ghost" data-f="hide">${T('Already done, hide')}</button></div></div></div>`);
box.onclick = (e) => {
const a = e.target.closest('[data-f]')?.dataset.f;
if (a === 'copy') { api.call('clipboard:write', fwCmds(f)); toast(T('Copied'), 'ok'); }
if (a === 'hide') { try { localStorage.setItem('mrterm.sync.fwHint', '1'); } catch {} onDismiss?.(); }
};
return box;
}
async function showFirewallHint() {
const f = S.syncStatus.firewall;
const r = await modal({ title: f.os === 'cachyos' ? T('CachyOS: allow the sync ports in the firewall') : T('Firewall active: allow the sync ports'),
body: `<p style="margin-top:0">${T('CachyOS enables the UFW firewall by default. It blocks the ports MrTerm needs to find and reach other devices (UDP 47811, TCP 47812). Run these commands once in a terminal:')}</p><pre class="mono fw-pre">${esc(fwCmds(f))}</pre>`,
buttons: [{ label: T('Close'), value: null, cls: 'ghost' }, { label: T('Copy commands'), value: 'copy', cls: 'primary' }] });
if (r === 'copy') { await api.call('clipboard:write', fwCmds(f)); toast(T('Copied'), 'ok'); }
}
// Kopplungsdialog: dieses Gerät ist sichtbar, gefundene Geräte können gekoppelt werden
async function openPairing() {
S.syncStatus = await call('sync:pairable', true);
const body = `<p style="margin-top:0">${T('Open “Pair new device” on the other device too, then select it here. Both devices show a code that you confirm on both sides.')}</p><div class="pair-list list"></div>
<div class="row" style="margin-top:12px"><div class="field" style="flex:1;margin:0"><input name="ip" placeholder="${esc(T('Or enter an IP address, e.g. 192.168.0.25'))}"/></div><button class="btn" data-probe type="button">${T('Search')}</button></div>`;
let timer;
const draw = () => {
const box = $('.pair-list');
if (!box) return clearInterval(timer);
const near = S.syncStatus?.nearby || [];
box.innerHTML = near.length ? '' : `<div class="hint" style="color:var(--muted);display:flex;gap:10px;align-items:center"><span class="spinner sm"></span>${T('Searching for devices …')}</div>${S.syncStatus?.firewall ? `<div class="hint" style="color:var(--orange);margin-top:10px;font-size:12px">${T('No devices found? The firewall on this device may block them:')}<pre class="mono fw-pre">${esc(fwCmds(S.syncStatus.firewall))}</pre></div>` : ''}`;
for (const d of near) {
const row = h(`<div class="card" style="padding:10px 12px;cursor:default"><div class="avatar" style="background:var(--icon-bg);color:var(--accent)">${ICONS.screen}</div><div class="meta"><div class="title">${esc(d.name)}</div><div class="sub">${esc(d.address)}${d.pairable ? '' : ` · ${T('not ready for pairing')}`}</div></div></div>`);
const b = h(`<button class="btn sm primary" ${d.pairable ? '' : 'disabled'}>${T('Pair')}</button>`);
b.onclick = async () => {
b.disabled = true; b.innerHTML = `<span class="spinner sm"></span>${T('Pairing …')}`;
try { await call('sync:pair', d.id); $('.pair-list')?.closest('.modal-bg')?.remove(); } catch {}
b.disabled = false; b.textContent = T('Pair');
};
row.append(b);
box.append(row);
}
};
setTimeout(() => {
draw();
timer = setInterval(draw, 1500);
const probe = $('[data-probe]');
if (probe) probe.onclick = async () => { const ip = $('[name=ip]', probe.closest('.modal')).value.trim(); if (ip) { try { await call('sync:probe', ip); toast(T('Device found'), 'ok'); } catch {} } };
}, 0);
await modal({ title: T('Pair new device'), body, buttons: [{ label: T('Close'), value: null, cls: 'ghost' }] });
clearInterval(timer);
S.syncStatus = await call('sync:pairable', false).catch(() => S.syncStatus);
}
// Auswahl, welche Geheimnisse dieses Gerät an gekoppelte Geräte weitergibt
async function chooseSharedSecrets() {
const sh = S.syncStatus?.share || { keys: [], hosts: [], vpns: [] };
const sect = (title, c, items, label) => items.length ? `<h4>${title}</h4>${items.map((x) => `<label class="check"><input type="checkbox" name="${c}|${esc(x.id)}" ${(sh[c] || []).includes(x.id) ? 'checked' : ''}/>${esc(label(x))}</label>`).join('')}` : '';
const hostsPw = S.vault.hosts.filter((x) => x.password);
const body = `<p style="margin-top:0">${T('Choose which secrets this device may send to paired devices. Everything else (hosts, groups, snippets …) is synchronized without passwords and private keys.')}</p>
<div class="share-list">${sect(T('SSH keys'), 'keys', S.vault.keys, (x) => x.label)}${sect(T('Host passwords'), 'hosts', hostsPw, (x) => `${x.label || x.address} (${x.username || '?'}@${x.address})`)}${sect(T('VPN configurations'), 'vpns', S.vault.vpns, (x) => x.label)}
${!S.vault.keys.length && !hostsPw.length && !S.vault.vpns.length ? `<div class="hint">${T('There are no secrets on this device yet.')}</div>` : ''}</div>`;
const r = await modal({ title: T('Choose shared secrets'), body, buttons: [{ label: T('Share nothing'), value: 'none', cls: 'ghost' }, { label: T('Select all'), value: 'all', cls: '' }, { label: T('Save'), value: 'form', cls: 'primary' }] });
if (!r) return;
const picked = { keys: [], hosts: [], vpns: [] };
if (typeof r === 'object') for (const [k, on] of Object.entries(r)) { const [c, id] = k.split('|'); if (on && picked[c]) picked[c].push(id); }
const sel = r === 'none' ? { keys: [], hosts: [], vpns: [] } : r === 'all' ? { keys: S.vault.keys.map((x) => x.id), hosts: hostsPw.map((x) => x.id), vpns: S.vault.vpns.map((x) => x.id) } : picked;
S.syncStatus = await call('sync:share', sel);
toast(T('Saved'), 'ok');
const card = $('.sync-card'); if (card) renderSyncCard(card);
}
api.on('sync:state', (st) => { S.syncStatus = st; const card = $('.sync-card'); if (card && !card.contains(document.activeElement)) renderSyncCard(card); });
api.on('sync:changed', () => { if (!S.lock?.locked && !$('.lock-screen')) reload(); });
api.on('sync:paired', async (p) => { toast(T('Paired with {name}', { name: p.name }), 'ok'); chooseSharedSecrets(); });
api.on('sync:pairPrompt', async (req) => {
const r = await modal({ title: T('Confirm pairing'), body: `<p style="margin-top:0">${esc(T('Pairing with “{name}”. Does the other device show the same code?', { name: req.name }))}</p><div class="pair-code">${req.code.slice(0, 3)} ${req.code.slice(3)}</div>`,
buttons: [{ label: T('Codes differ'), value: false, cls: 'danger' }, { label: T('Codes match'), value: true, cls: 'primary' }], noEnter: true });
api.pairReply(req.reqId, r === true);
});
// ============================================================ Design
function termTheme() {
const id = settings().terminalTheme;
@@ -1161,7 +1310,7 @@ function addTab(session) {
tab.onclick = (e) => { if (e.target.closest('.x')) return closeTab(session.id); activateTab(session.id); };
tab.onauxclick = (e) => { if (e.button === 1) closeTab(session.id); };
tab.oncontextmenu = (e) => ctxMenu(e.clientX, e.clientY, [
...(session.host ? [{ label: T('Duplicate'), icon: 'dup', run: () => ({ sftp: openSftp, docker: openDocker, firewall: openFirewall }[session.kind] || openTerminal)(session.host) }] : []),
...(session.host ? [{ label: T('Duplicate'), icon: 'dup', run: () => ({ sftp: openSftp, docker: openDocker, firewall: openFirewall, network: openNetwork }[session.kind] || openTerminal)(session.host) }] : []),
...(session.kind === 'ssh' ? [{ label: T('Reconnect'), icon: 'refresh', run: () => session.reconnect() }] : []),
{ label: T('Rename'), icon: 'edit', run: async () => { const n = await promptBox(T('Rename tab'), T('Title'), session.title); if (n) { session.title = n; $('span:nth-child(2)', tab).textContent = n; } } },
'-', { label: T('Close'), icon: 'close', run: () => closeTab(session.id) },
@@ -1208,7 +1357,7 @@ class TerminalSession {
this.el = h(`<div class="session">
<div class="sbar"><div class="info">${avatar(host, 22).replace('<span class="proto">SSH</span>', '')}<span>${esc(hostSub(host))}</span></div>
<button class="btn ghost sm" data-a="sftp" title="${T('SFTP for this host')}">${ICONS.folder}SFTP</button>
${host.execCommand ? '' : `<button class="btn ghost sm" data-a="docker" title="${T('Docker containers')}">${ICONS.docker}Docker</button><button class="btn ghost sm" data-a="firewall" title="${T('Firewall')}">${ICONS.wall}${T('Firewall')}</button>`}
${host.execCommand ? '' : `<button class="btn ghost sm" data-a="docker" title="${T('Docker containers')}">${ICONS.docker}Docker</button><button class="btn ghost sm" data-a="firewall" title="${T('Firewall')}">${ICONS.wall}${T('Firewall')}</button><button class="btn ghost sm" data-a="network" title="${T('Network')}">${ICONS.network}${T('Network')}</button>`}
<button class="btn ghost sm" data-a="snip" title="Snippets">${ICONS.code}Snippets</button>
<button class="btn ghost sm" data-a="find" title="${T('Search (Ctrl+Shift+F)')}">${ICONS.search}</button>
</div>
@@ -1268,6 +1417,7 @@ class TerminalSession {
if (a === 'sftp') openSftp(this.host);
if (a === 'docker') openDocker(this.host);
if (a === 'firewall') openFirewall(this.host);
if (a === 'network') openNetwork(this.host);
if (a === 'snip') { $('.snip-panel', this.el).classList.toggle('open'); this.renderSnips(); this.doFit(); }
if (a === 'snipnew') editSnippet();
if (a === 'find') this.toggleFind();
@@ -1842,6 +1992,7 @@ class FirewallSession {
this.backend = b;
$$('.backends button', this.el).forEach((x) => x.classList.toggle('active', x.dataset.b === b));
$('[data-a=save]', this.el).style.display = b === 'ufw' ? 'none' : '';
$('[data-a=add]', this.el).disabled = false;
await this.refresh();
}
@@ -1894,6 +2045,11 @@ class FirewallSession {
}
}
this.body.append(head);
$('[data-a=add]', this.el).disabled = !on;
if (!on) {
this.body.append(h(`<div class="pane-empty" style="height:auto;padding:48px 20px"><div class="fw-off">${ICONS.wall}<b>${T('UFW is disabled')}</b><span>${T('Enable UFW to view or add rules.')}</span></div></div>`));
return;
}
if (!d.rules.length) { this.body.append(h(`<div class="pane-empty" style="height:auto;padding:40px"><div style="color:var(--muted)">${T('No rules yet.')}</div></div>`)); return; }
const t = h(`<table class="docker-table fw-table"><thead><tr><th>#</th><th>${T('To')}</th><th>${T('Action')}</th><th>${T('From')}</th><th>${T('Comment')}</th><th></th></tr></thead><tbody></tbody></table>`);
for (const r of d.rules) {
@@ -1971,6 +2127,267 @@ class FirewallSession {
}
function openFirewall(host) { return new FirewallSession(host); }
// ============================================================ Netzwerk (Ubuntu netplan / Debian ifupdown über SSH)
const NET_KINDS = { ethernet: 'Ethernet', bond: 'Bond', bridge: 'Bridge', vlan: 'VLAN' };
const BOND_MODES = [['802.3ad', '802.3ad (LACP)'], ['active-backup', 'active-backup'], ['balance-rr', 'balance-rr'], ['balance-xor', 'balance-xor'], ['balance-tlb', 'balance-tlb'], ['balance-alb', 'balance-alb'], ['broadcast', 'broadcast']];
const VIRTUAL_IF = /^(veth|docker\d|br-[0-9a-f]{12}|tap\d|fwbr|fwpr|fwln|vnet|virbr|cali|flannel|cni|kube|tun|wg|tailscale|zt)/;
const splitList = (v) => String(v || '').split(/[\s,;]+/).map((x) => x.trim()).filter(Boolean);
class NetworkSession {
constructor(host) {
this.kind = 'network'; this.id = uid(); this.host = host;
this.title = `${T('Network')} · ${host.label || host.address}`;
this.data = null; this.showVirtual = false;
this.el = h(`<div class="session network">
<div class="sbar"><div class="info">${avatar(host, 22)}<span>${esc(hostSub(host))}</span><span class="rt"></span></div>
<label class="check" style="margin:0 6px"><input type="checkbox" data-a="virtual"/>${T('Show virtual interfaces')}</label>
<button class="btn ghost sm" data-a="files">${ICONS.file}${T('Config files')}</button>
<button class="btn ghost sm" data-a="refresh" title="${T('Refresh')}">${ICONS.refresh}</button>
<button class="btn primary sm" data-a="new" disabled>${ICONS.plus}${T('New interface')}</button>
</div>
<div class="docker-body net-body"><div class="pane-empty"><div class="spinner" style="width:30px;height:30px;border:3px solid var(--border);border-top-color:var(--accent);border-radius:50%;animation:spin .9s linear infinite"></div><div>${esc(T('Connecting to {host} …', { host: host.address }))}</div></div></div></div>`);
this.body = $('.net-body', this.el);
this.el.addEventListener('click', (e) => {
const a = e.target.closest('[data-a]')?.dataset.a;
if (a === 'refresh') this.refresh();
if (a === 'files') this.files();
if (a === 'new') ctxMenu(e.clientX, e.clientY, [
{ label: T('New bond'), icon: 'plus', run: () => this.edit(null, 'bond') },
{ label: T('New bridge'), icon: 'plus', run: () => this.edit(null, 'bridge') },
{ label: T('New VLAN'), icon: 'plus', run: () => this.edit(null, 'vlan') },
]);
});
$('[data-a=virtual]', this.el).onchange = (e) => { this.showVirtual = e.target.checked; this.draw(); };
this.unsub = api.on('network:closed', (sid) => { if (sid === this.id && !this.applying) { setTabState(this, 'err'); this.error(T('Connection closed.')); } });
addTab(this);
this.open();
}
async open() {
try {
this.apply(await api.call('network:open', this.id, hostRef(this.host)));
setTabState(this, 'on');
} catch (e) { setTabState(this, 'err'); this.error(e.message); }
}
error(msg) {
this.body.innerHTML = `<div class="pane-empty"><div style="color:var(--red);max-width:560px;text-align:center">${esc(msg)}</div></div>`;
const b = h(`<button class="btn primary">${ICONS.refresh}${T('Try again')}</button>`);
b.onclick = () => { closeTab(this.id); openNetwork(this.host); };
$('.pane-empty', this.body).append(b);
}
apply(d) {
this.data = d;
const be = { netplan: 'netplan', ifupdown: 'ifupdown', networkmanager: 'NetworkManager', networkd: 'systemd-networkd' }[d.backend] || d.backend;
$('.rt', this.el).textContent = ` · ${d.os || ''} · ${be}`;
$('[data-a=new]', this.el).disabled = !d.editable;
this.draw();
}
async refresh(tries = 1) {
for (let i = 1; ; i++) {
try { return this.apply(await api.call('network:read', this.id)); } catch (e) {
if (i >= tries) return toast(e.message, 'error');
await new Promise((r) => setTimeout(r, 3000));
}
}
}
cfg(name) { return this.data.config.find((c) => c.name === name); }
draw() {
const d = this.data;
const scroll = this.body.scrollTop;
this.body.innerHTML = '';
const wrap = h('<div class="net-wrap"></div>');
if (d.rolledBack) wrap.append(h(`<div class="net-banner warn">${ICONS.refresh}<span>${esc(T('The last network change was rolled back automatically ({time}) because MrTerm could not reconnect.', { time: d.rolledBack }))}</span></div>`));
if (!d.editable) wrap.append(h(`<div class="net-banner">${ICONS.network}<span>${esc(d.note || T('Editing is supported for Ubuntu (netplan) and Debian/Proxmox (ifupdown). This host uses {backend}, so interfaces are shown read-only. Config files can still be edited.', { backend: d.backend }))}</span></div>`));
// System: Hostname, Gateway, DNS
const gw = d.routes.map((r) => `${esc(r.via || '—')} <span class="muted">(${esc(r.dev)})</span>`).join('<br>') || `<span class="muted">${T('none')}</span>`;
const sys = h(`<div class="net-sys">
<div><label>${T('Hostname')}</label><div class="v"><b>${esc(d.hostname)}</b><button class="btn ghost sm" data-s="host">${ICONS.edit}</button></div></div>
<div><label>${T('Default gateway')}</label><div class="v">${gw}</div></div>
<div><label>${T('DNS servers')}</label><div class="v">${esc(d.dns.servers.join(', ') || '—')}${d.dns.search.length ? `<br><span class="muted">${T('Search')}: ${esc(d.dns.search.join(' '))}</span>` : ''}${d.dns.editable && !d.dns.servers.includes('127.0.0.53') ? `<button class="btn ghost sm" data-s="dns">${ICONS.edit}</button>` : ''}</div>
${d.dns.servers.includes('127.0.0.53') ? `<div class="hint">${T('systemd-resolved is used: set DNS servers per interface.')}</div>` : ''}</div></div>`);
sys.onclick = (e) => { const a = e.target.closest('[data-s]')?.dataset.s; if (a === 'host') this.hostname(); if (a === 'dns') this.resolv(); };
wrap.append(sys);
// Schnittstellen: live + nur konfigurierte
const live = d.interfaces.filter((i) => this.showVirtual || !VIRTUAL_IF.test(i.name));
const names = new Set(live.map((i) => i.name));
const cfgOnly = d.config.filter((c) => !d.interfaces.some((i) => i.name === c.name)).map((c) => ({ name: c.name, kind: c.kind, state: 'ABSENT', addrs: [], master: '' }));
const order = { bond: 1, bridge: 2, vlan: 3, ethernet: 0 };
const list = [...live, ...cfgOnly.filter((c) => !names.has(c.name))].sort((a, b) => ((order[this.kindOf(a)] ?? 4) - (order[this.kindOf(b)] ?? 4)) || a.name.localeCompare(b.name, undefined, { numeric: true }));
const grid = h('<div class="net-grid"></div>');
for (const i of list) grid.append(this.card(i));
wrap.append(grid);
this.body.append(wrap);
this.body.scrollTop = scroll;
}
kindOf(i) { return this.cfg(i.name)?.kind || (['bond', 'bridge', 'vlan'].includes(i.kind) ? i.kind : 'ethernet'); }
card(i) {
const c = this.cfg(i.name);
const kind = this.kindOf(i);
const up = i.state === 'UP' || i.state === 'UNKNOWN';
const summary = !c ? `<span class="muted">${T('Not configured')}</span>`
: c.method4 === 'dhcp' ? 'DHCP' : c.method4 === 'static' ? `${T('Static')} ${esc(c.addresses.join(', '))}${c.gateway ? ` → ${esc(c.gateway)}` : ''}` : `<span class="muted">${T('No IPv4')}</span>`;
const b = i.bonding;
const bondInfo = b ? `<div class="net-bond"><div><span class="muted">${T('Mode')}:</span> ${esc(b.mode || '')}${b.lacpRate ? ` · LACP ${esc(b.lacpRate)}` : ''}${b.hashPolicy ? ` · ${esc(b.hashPolicy)}` : ''}</div>
${b.slaves.map((s) => `<div class="slave"><span class="dot ${s.mii === 'up' ? 'on' : 'err'}"></span>${esc(s.name)} <span class="muted">${esc(s.speed || '')}${s.aggregator ? ` · Agg ${esc(s.aggregator)}` : ''}</span></div>`).join('')}</div>` : '';
const el = h(`<div class="net-card ${i.state === 'ABSENT' ? 'absent' : ''}">
<div class="nh"><span class="dot ${i.state === 'ABSENT' ? '' : up ? 'on' : 'err'}"></span><b>${esc(i.name)}</b><span class="kind">${NET_KINDS[kind] || esc(i.kind || '')}</span>
${i.master ? `<span class="muted">→ ${esc(i.master)}</span>` : ''}<span class="grow"></span>
${this.data.editable ? `<button class="btn ghost sm" data-n="edit" title="${T('Edit')}">${ICONS.edit}</button>` : ''}
${this.data.editable && c && kind !== 'ethernet' ? `<button class="btn ghost sm" data-n="del" title="${T('Delete')}">${ICONS.trash}</button>` : ''}</div>
<div class="nm muted">${i.mac ? esc(i.mac) : ''}${i.mtu ? ` · MTU ${i.mtu}` : ''}${i.state === 'ABSENT' ? T('Configured, but not present') : ''}</div>
<div class="na">${i.addrs.map((a) => `<div>${esc(a.addr)}${a.dynamic ? ' <span class="tag">DHCP</span>' : ''}</div>`).join('') || `<div class="muted">${T('No address')}</div>`}</div>
${bondInfo}
<div class="ncfg"><span class="muted">${T('Configured')}:</span> ${summary}</div></div>`);
el.onclick = (e) => {
const a = e.target.closest('[data-n]')?.dataset.n;
if (a === 'edit') this.edit(i.name, kind);
if (a === 'del') this.remove(c);
};
return el;
}
// Anwenden mit Rollback-Anzeige
async run(label, fn) {
this.applying = true;
const ov = h(`<div class="overlay"><div class="spinner"></div><div class="msg">${esc(label)}</div><div class="msg" style="font-size:12px;color:var(--faint)">${T('MrTerm reconnects to confirm the change. Without confirmation the server restores the previous configuration after 90 seconds.')}</div></div>`);
this.el.append(ov);
try {
const r = await fn();
ov.remove();
if (r?.confirmed) { toast(r.direct ? T('Saved') : T('Network change applied and confirmed'), 'ok'); await this.refresh(4); }
else {
setTabState(this, 'err');
this.body.innerHTML = `<div class="pane-empty"><div style="color:var(--orange);max-width:560px;text-align:center">${T('MrTerm could not reconnect after the change. The server restores the previous configuration automatically within 90 seconds.')}</div></div>`;
const b = h(`<button class="btn primary">${ICONS.refresh}${T('Reconnect')}</button>`);
b.onclick = () => { closeTab(this.id); openNetwork(this.host); };
$('.pane-empty', this.body).append(b);
}
} catch (e) { ov.remove(); toast(e.message, 'error'); }
this.applying = false;
}
async confirmApply(what) {
const r = await modal({ title: T('Apply network change?'), text: what,
body: `<p style="margin-top:0">${T('The change is applied immediately. If MrTerm cannot reconnect within 90 seconds, the server restores the previous configuration automatically.')}</p>
<div class="field"><label>${T('Reconnect via')}</label><input name="verify" value="${esc(this.host.address)}"/><div class="hint">${T('Change this if the change affects the address MrTerm uses to connect.')}</div></div>`,
buttons: [{ label: T('Cancel'), value: null, cls: 'ghost' }, { label: T('Apply'), value: 'form', cls: 'primary' }] });
return r ? (r.verify.trim() === this.host.address ? '' : r.verify.trim()) : null;
}
edit(name, kind) {
const d = this.data;
const isNew = !name;
const m = structuredClone(this.cfg(name) || { name: name || '', kind, method4: 'none', addresses: [], gateway: '', dns: [], search: [], mtu: '', method6: 'auto', addresses6: [], gateway6: '',
bond: kind === 'bond' ? { members: [], mode: '802.3ad', lacpRate: 'fast', hashPolicy: 'layer3+4', miimon: 100 } : undefined,
bridge: kind === 'bridge' ? { members: [], stp: false } : undefined, vlan: kind === 'vlan' ? { id: '', link: '' } : undefined });
if (!this.cfg(name) && name) { const live = d.interfaces.find((i) => i.name === name); if (live?.addrs.some((a) => a.dynamic)) m.method4 = 'dhcp'; }
const phys = [...new Set([...d.interfaces.filter((i) => !VIRTUAL_IF.test(i.name) && (i.kind === 'ethernet' || i.kind === 'bond' || i.kind === 'vlan')).map((i) => i.name), ...d.config.filter((c) => c.kind !== 'bridge').map((c) => c.name)])].filter((x) => x !== m.name).sort();
const memberBox = (sel, filter) => {
const box = h('<div class="vpn-hosts"></div>');
phys.filter(filter).forEach((x) => box.append(h(`<label class="check"><input type="checkbox" data-m="${esc(x)}" ${sel.includes(x) ? 'checked' : ''}/>${esc(x)}<span class="muted" style="margin-left:6px;font-size:11px">${esc(d.interfaces.find((i) => i.name === x)?.mac || '')}</span></label>`)));
if (!box.children.length) box.append(h(`<div class="hint">${T('No suitable interfaces found.')}</div>`));
return box;
};
const fields = [];
if (isNew) fields.push(field(T('Name'), 'name', kind === 'bond' ? 'bond0' : kind === 'bridge' ? (d.backend === 'ifupdown' ? 'vmbr1' : 'br0') : '', { placeholder: kind === 'vlan' ? 'eno1.100' : '', hint: kind === 'vlan' ? T('Usually <parent>.<VLAN ID>, e.g. eno1.100') : '' }));
let members = null;
if (m.kind === 'bond') {
members = memberBox(m.bond.members, (x) => this.kindOf({ name: x, kind: d.interfaces.find((i) => i.name === x)?.kind }) === 'ethernet');
fields.push(heading(T('Bond')), h(`<label class="flabel">${T('Members')}</label>`), members,
field(T('Mode'), 'bmode', m.bond.mode, { type: 'select', options: BOND_MODES }),
row(field(T('LACP rate'), 'lacp', m.bond.lacpRate || 'slow', { type: 'select', options: [['fast', 'fast (1 s)'], ['slow', 'slow (30 s)']] }),
field(T('Hash policy'), 'hash', m.bond.hashPolicy || 'layer2', { type: 'select', options: ['layer2', 'layer2+3', 'layer3+4', 'encap2+3', 'encap3+4'].map((x) => [x, x]) })),
field(T('MII monitoring (ms)'), 'miimon', m.bond.miimon ?? 100, { type: 'number' }));
}
if (m.kind === 'bridge') {
members = memberBox(m.bridge.members, () => true);
fields.push(heading(T('Bridge')), h(`<label class="flabel">${T('Ports')}</label>`), members, check(T('Spanning Tree (STP)'), 'stp', m.bridge.stp));
}
if (m.kind === 'vlan') fields.push(heading('VLAN'), row(field(T('VLAN ID'), 'vid', m.vlan.id, { type: 'number', placeholder: '100' }), field(T('Parent interface'), 'vlink', m.vlan.link, { type: 'select', options: [['', '—'], ...phys.map((x) => [x, x])] })));
const v4 = h('<div></div>');
v4.append(field(T('IPv4 addresses (one per line, CIDR)'), 'addresses', m.addresses.join('\n'), { type: 'textarea', placeholder: '192.168.1.10/24' }), field(T('Gateway'), 'gateway', m.gateway, { placeholder: '192.168.1.1' }));
const v6 = h('<div></div>');
v6.append(field(T('IPv6 addresses (one per line, CIDR)'), 'addresses6', m.addresses6.join('\n'), { type: 'textarea', placeholder: '2001:db8::10/64' }), field(T('IPv6 gateway'), 'gateway6', m.gateway6));
fields.push(heading('IPv4'), field(T('Method'), 'method4', m.method4, { type: 'select', options: [['dhcp', 'DHCP'], ['static', T('Static')], ['none', T('No IPv4 address')]] }), v4,
heading('DNS'), row(field(T('DNS servers'), 'dns', m.dns.join(', '), { placeholder: '1.1.1.1, 9.9.9.9' }), field(T('Search domains'), 'search', m.search.join(' '), { placeholder: 'example.lan' })),
heading('IPv6'), field(T('Method'), 'method6', m.method6, { type: 'select', options: [['auto', T('Automatic (SLAAC)')], ['dhcp', 'DHCPv6'], ['static', T('Static')], ['none', T('Disabled')]] }), v6,
heading(T('Advanced')), field('MTU', 'mtu', m.mtu, { type: 'number', placeholder: '1500' }));
const form = openDrawer(isNew ? T('New {kind}', { kind: NET_KINDS[kind] }) : `${NET_KINDS[m.kind]} ${m.name}`, fields, async () => {
const f = formValues(form);
const out = { ...m, name: isNew ? f.name.trim() : m.name, method4: f.method4, addresses: f.method4 === 'static' ? splitList(f.addresses) : [], gateway: f.method4 === 'static' ? f.gateway.trim() : '',
dns: splitList(f.dns), search: splitList(f.search), mtu: f.mtu, method6: f.method6, addresses6: f.method6 === 'static' ? splitList(f.addresses6) : [], gateway6: f.method6 === 'static' ? f.gateway6.trim() : '' };
const sel = members ? $$('[data-m]', members).filter((x) => x.checked).map((x) => x.dataset.m) : [];
if (m.kind === 'bond') { if (!sel.length) throw new Error(T('Select at least one member.')); out.bond = { members: sel, mode: f.bmode, lacpRate: f.bmode === '802.3ad' ? f.lacp : '', hashPolicy: f.hash, miimon: f.miimon }; }
if (m.kind === 'bridge') out.bridge = { members: sel, stp: f.stp };
if (m.kind === 'vlan') { out.vlan = { id: f.vid, link: f.vlink }; if (!f.vlink) throw new Error(T('Select the parent interface.')); }
if (isNew && d.config.some((c) => c.name === out.name)) throw new Error(T('An interface with this name already exists.'));
const verify = await this.confirmApply(`${NET_KINDS[out.kind]} ${out.name}`);
if (verify === null) return false;
closeDrawer();
this.run(T('Applying network configuration …'), () => api.call('network:save', this.id, out, verify));
return false;
});
const sync = () => {
v4.style.display = $('[name=method4]', form).value === 'static' ? '' : 'none';
v6.style.display = $('[name=method6]', form).value === 'static' ? '' : 'none';
const bm = $('[name=bmode]', form);
if (bm) $('[name=lacp]', form).closest('.field').style.display = bm.value === '802.3ad' ? '' : 'none';
};
form.addEventListener('change', sync);
sync();
}
async remove(c) {
if (!(await confirmBox(T('Delete {kind} {name}?', { kind: NET_KINDS[c.kind], name: c.name }), T('The interface is removed from the configuration. Members keep their current settings.')))) return;
const verify = await this.confirmApply(`${T('Delete')} ${c.name}`);
if (verify === null) return;
this.run(T('Applying network configuration …'), () => api.call('network:remove', this.id, c, verify));
}
async hostname() {
const n = await promptBox(T('Change hostname'), T('Hostname'), this.data.hostname);
if (!n || n === this.data.hostname) return;
try { await call('network:hostname', this.id, n.trim()); toast(T('Hostname changed'), 'ok'); this.refresh(); } catch {}
}
async resolv() {
const r = await modal({ title: T('DNS servers'), body: `<div class="field"><label>${T('DNS servers')}</label><input name="s" value="${esc(this.data.dns.servers.join(', '))}"/></div><div class="field"><label>${T('Search domains')}</label><input name="d" value="${esc(this.data.dns.search.join(' '))}"/></div><div class="hint">${T('Written to /etc/resolv.conf.')}</div>`,
buttons: [{ label: T('Cancel'), value: null, cls: 'ghost' }, { label: T('Save'), value: 'form', cls: 'primary' }] });
if (!r) return;
try { await call('network:resolv', this.id, splitList(r.s), splitList(r.d)); toast(T('Saved'), 'ok'); this.refresh(); } catch {}
}
async files() {
const list = [...new Set([...this.data.files, '/etc/hosts', ...(this.data.dns.editable ? ['/etc/resolv.conf'] : [])])];
const f = await new Promise((res) => ctxMenu(innerWidth - 320, 90, list.map((p) => ({ label: p, icon: 'file', run: () => res(p) }))));
let content;
try { content = await call('network:readFile', this.id, f); } catch { return; }
const net = !/^\/etc\/(hosts|resolv\.conf)$/.test(f);
const form = openDrawer(f, [field(T('Content'), 'content', content, { type: 'textarea', hint: net ? T('Saving applies the file with automatic rollback.') : '' })], async () => {
const v = formValues(form).content;
if (!net) { this.run(T('Saving …'), () => api.call('network:writeFile', this.id, f, v, '')); return; }
const verify = await this.confirmApply(f);
if (verify === null) return false;
closeDrawer();
this.run(T('Applying network configuration …'), () => api.call('network:writeFile', this.id, f, v, verify));
return false;
});
const ta = $('textarea', form); ta.classList.add('mono'); ta.style.minHeight = '60vh';
}
dispose() { this.unsub(); api.call('network:close', this.id).catch(() => {}); }
}
function openNetwork(host) { return new NetworkSession(host); }
// ============================================================ Command Palette / Quick Connect
function openPalette() {
if ($('.palette')) return;
@@ -1991,6 +2408,7 @@ function openPalette() {
if (x.protocol !== 'rdp' && q) items.push({ grp: 'Hosts', icon: `<div class="avatar" style="background:var(--icon-bg);color:var(--folder)">${ICONS.folder}</div>`, label: `SFTP: ${x.label || x.address}`, run: () => openSftp(x) });
if (x.protocol !== 'rdp' && q) items.push({ grp: 'Hosts', icon: `<div class="avatar" style="background:var(--icon-bg);color:var(--accent-2)">${ICONS.docker}</div>`, label: `Docker: ${x.label || x.address}`, run: () => openDocker(x) });
if (x.protocol !== 'rdp' && q) items.push({ grp: 'Hosts', icon: `<div class="avatar" style="background:var(--icon-bg);color:var(--orange)">${ICONS.wall}</div>`, label: `${T('Firewall')}: ${x.label || x.address}`, run: () => openFirewall(x) });
if (x.protocol !== 'rdp' && q) items.push({ grp: 'Hosts', icon: `<div class="avatar" style="background:var(--icon-bg);color:var(--accent)">${ICONS.network}</div>`, label: `${T('Network')}: ${x.label || x.address}`, run: () => openNetwork(x) });
});
S.vault.snippets.filter((s) => q && s.label.toLowerCase().includes(q)).slice(0, 5).forEach((s) => items.push({ grp: 'Snippets', icon: `<div class="avatar" style="background:var(--icon-bg);color:var(--green)">${ICONS.code}</div>`, label: s.label, sub: s.command, run: () => runSnippet(s) }));
[[T('New host'), () => { activateTab('home'); editHost({}); }], [T('Generate key'), generateKey], [T('Settings'), () => $('[data-view=settings]').click()]]
+41
View File
@@ -402,3 +402,44 @@ kbd { background: var(--card); border: 1px solid var(--border); border-bottom-wi
.fw-act.deny, .fw-act.reject { background: color-mix(in srgb, var(--red) 14%, transparent); color: var(--red); }
.fw-act.limit { background: color-mix(in srgb, var(--orange) 14%, transparent); color: var(--orange); }
.fw-table th:first-child, .fw-table td:first-child { width: 44px; text-align: left; padding-left: 16px; }
.fw-off { display: flex; flex-direction: column; align-items: center; gap: 6px; color: var(--muted); text-align: center; }
.fw-off svg { width: 40px; height: 40px; color: var(--faint); margin-bottom: 6px; }
.fw-off b { color: var(--text); font-size: 15px; }
/* Netzwerk */
.net-wrap { padding: 16px; display: flex; flex-direction: column; gap: 14px; }
.net-banner { display: flex; gap: 10px; align-items: center; padding: 10px 14px; border-radius: 10px; background: var(--panel); border: 1px solid var(--border); color: var(--muted); font-size: 13px; }
.net-banner.warn { border-color: color-mix(in srgb, var(--orange) 50%, transparent); color: var(--orange); }
.net-sys { display: grid; grid-template-columns: repeat(auto-fit, minmax(220px, 1fr)); gap: 12px; background: var(--card); border-radius: 12px; padding: 14px 16px; }
.net-sys label { font-size: 11px; text-transform: uppercase; letter-spacing: .4px; color: var(--faint); font-weight: 600; }
.net-sys .v { margin-top: 4px; display: flex; align-items: center; gap: 6px; flex-wrap: wrap; }
.net-sys .hint { font-size: 11px; color: var(--faint); margin-top: 4px; }
.net-grid { display: grid; grid-template-columns: repeat(auto-fill, minmax(320px, 1fr)); gap: 12px; align-items: start; }
.net-card { background: var(--card); border-radius: 12px; padding: 12px 14px; display: flex; flex-direction: column; gap: 6px; }
.net-card.absent { opacity: .7; border: 1px dashed var(--border); }
.net-card .nh { display: flex; align-items: center; gap: 8px; }
.net-card .nh .grow { flex: 1; }
.net-card .kind { font-size: 10px; font-weight: 700; text-transform: uppercase; letter-spacing: .4px; padding: 2px 6px; border-radius: 6px; background: rgb(var(--tint) / 0.063); color: var(--muted); }
.net-card .nm, .net-card .ncfg { font-size: 12px; }
.net-card .na { font-family: var(--mono, monospace); font-size: 12.5px; display: flex; flex-direction: column; gap: 2px; }
.net-card .net-bond { font-size: 12px; border-top: 1px solid var(--row-line); padding-top: 6px; display: flex; flex-direction: column; gap: 3px; }
.net-card .slave { display: flex; align-items: center; gap: 6px; }
.net-card .muted, .net-sys .muted { color: var(--faint); }
.network .dot, .net-card .dot { display: inline-block; width: 8px; height: 8px; border-radius: 50%; background: var(--faint); flex: none; }
.net-card .dot.on { background: var(--green); }
.net-card .dot.err { background: var(--red); }
.flabel { display: block; font-size: 11px; text-transform: uppercase; letter-spacing: .4px; color: var(--muted); font-weight: 600; margin: 4px 0 6px; }
/* Synchronisation */
.sync-peers .dot { display: inline-block; width: 8px; height: 8px; border-radius: 50%; background: var(--faint); flex: none; }
.sync-peers .dot.on { background: var(--green); }
.pair-code { font-size: 34px; font-weight: 700; letter-spacing: 6px; text-align: center; padding: 14px 0 6px; font-variant-numeric: tabular-nums; color: var(--accent); }
.pair-list { max-height: 260px; overflow: auto; }
.share-list { max-height: 380px; overflow: auto; }
.share-list h4 { margin: 12px 0 6px; }
.fw-hint { align-items: flex-start; margin: 4px 0 14px; }
.fw-hint svg { width: 22px; height: 22px; }
.fw-hint .grow { flex: 1; min-width: 0; }
.fw-hint b { color: var(--text); }
.fw-hint p { margin: 4px 0 8px; color: var(--muted); }
.fw-hint pre, .fw-pre { background: var(--bg); border: 1px solid var(--border); border-radius: 8px; padding: 8px 10px; margin: 0 0 10px; color: var(--text); white-space: pre-wrap; user-select: text; }