RD WebDesign
e43a67464c
Design changes on the API page
...
- apply the same color to every button and add hover effect;
- change header and fotter background;
- use display:flex on header and footer to better fit items;
- separate theme buttons from style buttons (on the footer);
- keeping visible outline to help navigation for visual impaired users;
2023-10-16 01:39:45 -03:00
DL6ER
7e1d55ee71
Make HTTPS scheme the default case and fix paths to allow loading of the favicon
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-15 12:52:28 +02:00
DL6ER
64baa94395
Add new config option webserver.api.searchAPIauth defaulting to false
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-13 18:51:49 +02:00
DL6ER
231f8f876e
Fix endpoint security requirements for /info/login, /auth/totp, /info/client
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-10 19:21:14 +02:00
DL6ER
b60e8bdc2f
Add /api/info/login and remove some parts from /api/auth
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-08 22:55:24 +02:00
DL6ER
970695b65f
Adjust tests to include the new https_port property
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-08 19:57:35 +02:00
DL6ER
ac056f07eb
Merge branch 'development-v6' into tweak/api_auth_https
2023-10-08 09:11:32 +02:00
DL6ER
c4237f1846
Include HTTPS port (if any) in /api/auth response
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-08 09:11:32 +02:00
DL6ER
678d014a26
Merge branch 'development-v6' into tweak/search_abp
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-08 09:11:32 +02:00
DL6ER
db1fa3a106
Searchterm should simply be called domain
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-07 21:52:42 +02:00
DL6ER
88e7b1e5dc
Add ABP-support for /api/search and add new optional debug parameter
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-07 21:52:39 +02:00
DL6ER
2141db3d64
Add rate-limiting on password login attempts
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-10-07 19:59:32 +02:00
DL6ER
f8b8e63044
Add antigravity (subscribed allowlists with wildcard support)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-09-15 21:39:04 +02:00
DL6ER
392db953b3
Merge pull request #1607 from pi-hole/tweak/query_details
...
Provide regex ID for API
2023-09-15 17:25:17 +02:00
DL6ER
9704455591
Always set regex_id when available
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-09-13 16:44:40 +02:00
DL6ER
2788fa0137
Add files.pcap to expose integrated packet (PCAP) dumping to a file
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-09-02 18:25:34 +02:00
Christian König
22954823b5
Hard limit for searching the adlists is 10,000
...
Signed-off-by: Christian König <ckoenig@posteo.de >
2023-08-09 22:13:34 +02:00
Christian König
da544dcbb2
Change default webport to 80
...
Signed-off-by: Christian König <ckoenig@posteo.de >
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-08-01 15:54:20 +02:00
DL6ER
a9d47713e4
Provide regex ID for API
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-30 21:49:23 +02:00
DL6ER
e085728e3e
Merge pull request #1601 from pi-hole/fix/redirect_slash
...
Slash the slash
2023-07-28 23:07:30 +02:00
DL6ER
55785f1b0c
Simplify code and handle case of missing trailing slashes for index pages properly
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-28 22:36:41 +02:00
DL6ER
723db23703
Use explicitly sized integers (u/int64_t) to ensure consistent operation on both 32 and 64 bit architectures
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-27 04:10:23 +02:00
DL6ER
e772442ea7
Use header SID authentication instead of the implicit cookie authentication to circumvent CORS issues
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-18 22:01:58 +02:00
DL6ER
756a688f05
Fix OpenAPI documentation login
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-18 22:00:06 +02:00
DL6ER
de3e9bf0a5
Fix logo path to use the embedded SVG icon
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-13 20:03:31 +02:00
DL6ER
ea40474635
Add OpenAPI Authentication and Authorization details for the API. Every endpoint except GET,POST /api/auth needs authentication
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-07-13 20:00:11 +02:00
DL6ER
73f9ad02a0
Allow defining lines to inject into the generated dnsmasq configuration (misc.dnsmasq_lines)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-06-15 17:53:21 +02:00
DL6ER
07f1f7df44
Save number of ABP-style entries in adlist table's new column abp_entries
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-06-15 09:38:37 +02:00
DL6ER
a7f47a5e1f
The number of entries on a list should be the sum of domains and ABP-style entries
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-06-12 21:44:24 +02:00
DL6ER
813509841b
Accept cookie authentication only when CSRF header is provided (and correct)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-06-04 19:29:54 +02:00
DL6ER
6975a17c7c
Allow fractional delay for blocking mode changes and fix a few smaller memory leaks
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-06-03 13:26:58 +02:00
DL6ER
7ad68b785b
Fix favicon for API documentation (in the same way we did for the web interface a few minutes ago)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-06-03 12:50:15 +02:00
Christian König
62cfc25b95
Fix spelling in v6
...
Signed-off-by: Christian König <ckoenig@posteo.de >
2023-05-30 22:42:13 +02:00
DL6ER
19c72d354e
!!! BREAKING CHANGE !!! Switch to the proven memory-hard password-hashing alogorithm BALLOON. The stored password hash will be upgraded on the first successdful login. To wave the necessity to implement BALLOON with every client trying to access the API, we remove the existing challenge-response authentication in favor of allowing login straight with the password. This has been avoided in the past, however, seems now acceptable that FTL (even by default) offers secure end-to-end encryption over HTTPS.
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-30 21:22:45 +02:00
DL6ER
d42d4be97b
Add webserver.tls.rev_server boolean useful to tell FTL that unencrypted connections are still secure (in the context of Pi-hole solely being reachable through a reverse proxy)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-28 14:45:03 +02:00
DL6ER
d86a2f1c95
Add pihole.webhome() and add settings + group pages deep URI rewrite
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-26 21:50:26 +02:00
DL6ER
54cf9ad1f9
Add new debug.tls option logging any mbedTLS debug output to webserver.log
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-25 18:28:34 +02:00
DL6ER
0aecb57375
Add to /api/info/ftl if FTL is allowed to perform destructive operations (such as poweroff or reboot)
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 20:59:23 +02:00
DL6ER
c672120123
Add a setting to block possibly harmful actions
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 20:49:27 +02:00
DL6ER
b5a6ae44aa
Add /api/action/flush/arp flushing both the network and network_addresses tables in pihole-FTL.db
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 20:47:51 +02:00
DL6ER
3b404ff9a0
Add /api/actions/flush/logs
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 20:39:18 +02:00
DL6ER
7b72c762ce
Add dns boolean to /api/auth signalling if the DNS server is up and running
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 20:25:02 +02:00
DL6ER
1083128828
Fix OpenAPI definition of /api/dns/blocking
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 18:48:55 +02:00
DL6ER
f48683a11e
Continue to run webserver even when dnsmasq fails to still serve the web interface. Change the type of api/dns/blocking from bool to enum-string to support the new "failure" state
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-24 17:19:12 +02:00
DL6ER
f5cd3b00d2
Add strict_tls property to list of sessions showing if really every connection of this session happened over TLS/SSL
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-22 20:30:56 +02:00
DL6ER
391d1c9d0c
Extend /info/metrics to show details also about stale cache records
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-11 14:18:21 +02:00
DL6ER
f06b2e5397
Add tls boolean to list of sessions to indicate whether this session was established over a secure (end-to-end encrypted) connection
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-09 10:01:05 +02:00
DL6ER
d4f30e4f3d
Send more gravity-specific quantities in /search/{domain}
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-07 13:10:24 +02:00
DL6ER
c12625f0c1
Add global object "took" to all API endpoints
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-07 12:20:07 +02:00
DL6ER
c3468b7403
Include regex results in domains array when using /search/{domain}
...
Signed-off-by: DL6ER <dl6er@dl6er.de >
2023-05-07 11:19:02 +02:00