Commit Graph

178 Commits

Author SHA1 Message Date
RD WebDesign e43a67464c Design changes on the API page
- apply the same color to every button and add hover effect;
- change header and fotter background;
- use display:flex on header and footer to better fit items;
- separate theme buttons from style buttons (on the footer);
- keeping visible outline to help navigation for visual impaired users;
2023-10-16 01:39:45 -03:00
DL6ER 7e1d55ee71 Make HTTPS scheme the default case and fix paths to allow loading of the favicon
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-15 12:52:28 +02:00
DL6ER 64baa94395 Add new config option webserver.api.searchAPIauth defaulting to false
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-13 18:51:49 +02:00
DL6ER 231f8f876e Fix endpoint security requirements for /info/login, /auth/totp, /info/client
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-10 19:21:14 +02:00
DL6ER b60e8bdc2f Add /api/info/login and remove some parts from /api/auth
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-08 22:55:24 +02:00
DL6ER 970695b65f Adjust tests to include the new https_port property
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-08 19:57:35 +02:00
DL6ER ac056f07eb Merge branch 'development-v6' into tweak/api_auth_https 2023-10-08 09:11:32 +02:00
DL6ER c4237f1846 Include HTTPS port (if any) in /api/auth response
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-08 09:11:32 +02:00
DL6ER 678d014a26 Merge branch 'development-v6' into tweak/search_abp
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-08 09:11:32 +02:00
DL6ER db1fa3a106 Searchterm should simply be called domain
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-07 21:52:42 +02:00
DL6ER 88e7b1e5dc Add ABP-support for /api/search and add new optional debug parameter
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-07 21:52:39 +02:00
DL6ER 2141db3d64 Add rate-limiting on password login attempts
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-10-07 19:59:32 +02:00
DL6ER f8b8e63044 Add antigravity (subscribed allowlists with wildcard support)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-09-15 21:39:04 +02:00
DL6ER 392db953b3 Merge pull request #1607 from pi-hole/tweak/query_details
Provide regex ID for API
2023-09-15 17:25:17 +02:00
DL6ER 9704455591 Always set regex_id when available
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-09-13 16:44:40 +02:00
DL6ER 2788fa0137 Add files.pcap to expose integrated packet (PCAP) dumping to a file
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-09-02 18:25:34 +02:00
Christian König 22954823b5 Hard limit for searching the adlists is 10,000
Signed-off-by: Christian König <ckoenig@posteo.de>
2023-08-09 22:13:34 +02:00
Christian König da544dcbb2 Change default webport to 80
Signed-off-by: Christian König <ckoenig@posteo.de>
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-08-01 15:54:20 +02:00
DL6ER a9d47713e4 Provide regex ID for API
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-30 21:49:23 +02:00
DL6ER e085728e3e Merge pull request #1601 from pi-hole/fix/redirect_slash
Slash the slash
2023-07-28 23:07:30 +02:00
DL6ER 55785f1b0c Simplify code and handle case of missing trailing slashes for index pages properly
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-28 22:36:41 +02:00
DL6ER 723db23703 Use explicitly sized integers (u/int64_t) to ensure consistent operation on both 32 and 64 bit architectures
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-27 04:10:23 +02:00
DL6ER e772442ea7 Use header SID authentication instead of the implicit cookie authentication to circumvent CORS issues
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-18 22:01:58 +02:00
DL6ER 756a688f05 Fix OpenAPI documentation login
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-18 22:00:06 +02:00
DL6ER de3e9bf0a5 Fix logo path to use the embedded SVG icon
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-13 20:03:31 +02:00
DL6ER ea40474635 Add OpenAPI Authentication and Authorization details for the API. Every endpoint except GET,POST /api/auth needs authentication
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-07-13 20:00:11 +02:00
DL6ER 73f9ad02a0 Allow defining lines to inject into the generated dnsmasq configuration (misc.dnsmasq_lines)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-06-15 17:53:21 +02:00
DL6ER 07f1f7df44 Save number of ABP-style entries in adlist table's new column abp_entries
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-06-15 09:38:37 +02:00
DL6ER a7f47a5e1f The number of entries on a list should be the sum of domains and ABP-style entries
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-06-12 21:44:24 +02:00
DL6ER 813509841b Accept cookie authentication only when CSRF header is provided (and correct)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-06-04 19:29:54 +02:00
DL6ER 6975a17c7c Allow fractional delay for blocking mode changes and fix a few smaller memory leaks
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-06-03 13:26:58 +02:00
DL6ER 7ad68b785b Fix favicon for API documentation (in the same way we did for the web interface a few minutes ago)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-06-03 12:50:15 +02:00
Christian König 62cfc25b95 Fix spelling in v6
Signed-off-by: Christian König <ckoenig@posteo.de>
2023-05-30 22:42:13 +02:00
DL6ER 19c72d354e !!! BREAKING CHANGE !!! Switch to the proven memory-hard password-hashing alogorithm BALLOON. The stored password hash will be upgraded on the first successdful login. To wave the necessity to implement BALLOON with every client trying to access the API, we remove the existing challenge-response authentication in favor of allowing login straight with the password. This has been avoided in the past, however, seems now acceptable that FTL (even by default) offers secure end-to-end encryption over HTTPS.
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-30 21:22:45 +02:00
DL6ER d42d4be97b Add webserver.tls.rev_server boolean useful to tell FTL that unencrypted connections are still secure (in the context of Pi-hole solely being reachable through a reverse proxy)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-28 14:45:03 +02:00
DL6ER d86a2f1c95 Add pihole.webhome() and add settings + group pages deep URI rewrite
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-26 21:50:26 +02:00
DL6ER 54cf9ad1f9 Add new debug.tls option logging any mbedTLS debug output to webserver.log
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-25 18:28:34 +02:00
DL6ER 0aecb57375 Add to /api/info/ftl if FTL is allowed to perform destructive operations (such as poweroff or reboot)
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 20:59:23 +02:00
DL6ER c672120123 Add a setting to block possibly harmful actions
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 20:49:27 +02:00
DL6ER b5a6ae44aa Add /api/action/flush/arp flushing both the network and network_addresses tables in pihole-FTL.db
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 20:47:51 +02:00
DL6ER 3b404ff9a0 Add /api/actions/flush/logs
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 20:39:18 +02:00
DL6ER 7b72c762ce Add dns boolean to /api/auth signalling if the DNS server is up and running
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 20:25:02 +02:00
DL6ER 1083128828 Fix OpenAPI definition of /api/dns/blocking
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 18:48:55 +02:00
DL6ER f48683a11e Continue to run webserver even when dnsmasq fails to still serve the web interface. Change the type of api/dns/blocking from bool to enum-string to support the new "failure" state
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-24 17:19:12 +02:00
DL6ER f5cd3b00d2 Add strict_tls property to list of sessions showing if really every connection of this session happened over TLS/SSL
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-22 20:30:56 +02:00
DL6ER 391d1c9d0c Extend /info/metrics to show details also about stale cache records
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-11 14:18:21 +02:00
DL6ER f06b2e5397 Add tls boolean to list of sessions to indicate whether this session was established over a secure (end-to-end encrypted) connection
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-09 10:01:05 +02:00
DL6ER d4f30e4f3d Send more gravity-specific quantities in /search/{domain}
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-07 13:10:24 +02:00
DL6ER c12625f0c1 Add global object "took" to all API endpoints
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-07 12:20:07 +02:00
DL6ER c3468b7403 Include regex results in domains array when using /search/{domain}
Signed-off-by: DL6ER <dl6er@dl6er.de>
2023-05-07 11:19:02 +02:00