Match standard firewall header and gate private device reads

This commit is contained in:
archipelago
2026-10-08 07:06:31 -04:00
parent 8a70232f18
commit 83632c2439
6 changed files with 115 additions and 37 deletions
+38 -4
View File
@@ -11,8 +11,11 @@ actual device tunnels, mesh connections, router settings and merely saved port
entries. A running mesh no longer produces a false Protected firewall label.
The new device section uses existing WireGuard APIs for add, reveal/copy and remove.
Mutation controls require the new backend's explicit peer_management_verified flag;
older or unavailable backends cannot enable them. Private configuration is fetched
All saved-device reads and changes require known status and the new backend's
explicit peer_management_verified flag. Older or unavailable backends receive no
list/config RPCs: legacy list replies contain private configurations, and legacy
reveal can also write an endpoint. Capability loss clears device/private state and
rejects late replies; batched prop changes cannot briefly enable a private read. Private configuration is fetched
only by an explicit reveal action, QR SVG is sanitized, and cached navigation clears
private details and rejects late replies. Failed creation/removal requires a fresh
list before retrying. Pending/revoking operations get recovery guidance.
@@ -27,8 +30,8 @@ local JSON. They are not exposed as controls that claim to open or close real po
The existing OpenWrt management screen remains linked. Actual node firewall rule
inspection/editing and the complete app exposure workflow are still separate work.
Validation: current focused tests pass 25/25 (22 component cases plus three
background resolver cases), and the full app typecheck passes. Typecheck exposed
Prior checkpoint at b2fee5c5: focused tests passed 25/25 (22 component cases plus three
background resolver cases), and the full app typecheck passed. Typecheck exposed
an unsupported replaceAll call and a test-wrapper assertion; both were corrected
and the changed device test file was rerun successfully (16/16).
@@ -53,3 +56,34 @@ changes are isolated separately; actual ephemeral-kernel helper qualification
passed, but Rust compilation/tests and paired helper deployment remain required
before the new mutation controls can be enabled on a node. Task 18 remains open
for broader host firewall management, persistence and rollback.
## Header/back and legacy privacy follow-up
The header now matches the OpenWrt Gateway sibling: shared BackButton with
`desktop-margin="mb-0"`, an inline `items-center gap-3 mb-6` row and `text-lg`
semibold title. The shared component provides the standard floating mobile back
control; navigation always returns to the named Network/server route.
Current affected checks passed: seven firewall/header cases and seventeen device
cases. The initial capability regression found that a synchronous watcher could
briefly read mixed old/new props while status became unknown; the batched watcher
and response/render guards fixed this, and the full device file passed on rerun.
The unchanged three background cases retain their earlier pass.
The updated browser fixture passed at all four widths (320/390/768/1440), checking
header font/spacing, desktop alignment, floating mobile BackButton, return to
Network, unchanged background, full width, status alignment, QR containment and
zero legacy private RPCs while unverified. These are source-component fixtures
with synthetic RPCs, not live acceptance or a full production Dashboard test.
The app-wide typecheck has not been repeated after this final focused follow-up;
it and production build remain part of integration qualification.
Final follow-up receipts:
- `/tmp/archy-firewall-header-privacy-tests-20261008.log` — seven header/firewall
passes and the initial privacy transition failure (retained).
- `/tmp/archy-firewall-privacy-batched-tests-20261008.log` — all 17 device cases
passed after the transition correction.
- `/tmp/archy-firewall-header-privacy-browser-20261008.log` — four viewport passes.
All fixture browser/server processes stopped after verification. No node, helper,
firewall, wallet or saved-device configuration was changed by these UI checks.
+2
View File
@@ -522,6 +522,8 @@ Operator refinements on 8 October, retained as acceptance requirements:
present the mesh service as proof that the node firewall is protected.
- Fill the main content width and inherit the Network tab background; opening
Firewalls & tunnels must not switch to a different page background.
- Match the established header and shared back button, including desktop title
alignment and mobile back placement. Use the OpenWrt Gateway sibling pattern.
- Use the standard black primary button at the bottom of the Local Network
container, matching other container actions.
- Use plain language throughout and provide real, supported configuration