release: NX9-WG v1.0.0
This commit is contained in:
1 parent
c8a9b7cde6
commit
4dfe42fe68
42 files changed
+4689
-336
No files matched your search
@@ -79,18 +79,31 @@ impl ClientConfigBuilder {
|
||||
lines.push(format!("PresharedKey = {}", psk.as_str()));
|
||||
}
|
||||
|
||||
let host_trimmed = server_host_or_ip.trim();
|
||||
if host_trimmed.is_empty() {
|
||||
return Err(WireGuardError::Config(
|
||||
"No reachable WireGuard server endpoint is configured. Configure 'server_endpoint' in settings or provide --endpoint.".to_string(),
|
||||
));
|
||||
}
|
||||
|
||||
// Endpoint
|
||||
let endpoint = if server_host_or_ip.contains(':') && !server_host_or_ip.starts_with('[') {
|
||||
let endpoint = if host_trimmed.contains(':') && !host_trimmed.starts_with('[') {
|
||||
// Check if already contains port
|
||||
server_host_or_ip.to_string()
|
||||
host_trimmed.to_string()
|
||||
} else {
|
||||
format!("{}:{}", server_host_or_ip, interface.listen_port)
|
||||
format!("{}:{}", host_trimmed, interface.listen_port)
|
||||
};
|
||||
lines.push(format!("Endpoint = {endpoint}"));
|
||||
|
||||
// AllowedIPs based on Peer Profile
|
||||
let allowed_ips = match peer.profile {
|
||||
PeerProfile::FullTunnel => "0.0.0.0/0, ::/0".to_string(),
|
||||
PeerProfile::FullTunnel => {
|
||||
if interface.address_v6.is_some() || peer.address_v6.is_some() {
|
||||
"0.0.0.0/0, ::/0".to_string()
|
||||
} else {
|
||||
"0.0.0.0/0".to_string()
|
||||
}
|
||||
}
|
||||
PeerProfile::SplitTunnel => {
|
||||
let mut subnets = Vec::new();
|
||||
subnets.push(interface.address_v4.to_string());
|
||||
@@ -101,7 +114,11 @@ impl ClientConfigBuilder {
|
||||
}
|
||||
PeerProfile::Custom => {
|
||||
if peer.allowed_ips.trim().is_empty() {
|
||||
"0.0.0.0/0, ::/0".to_string()
|
||||
if interface.address_v6.is_some() || peer.address_v6.is_some() {
|
||||
"0.0.0.0/0, ::/0".to_string()
|
||||
} else {
|
||||
"0.0.0.0/0".to_string()
|
||||
}
|
||||
} else {
|
||||
peer.allowed_ips.clone()
|
||||
}
|
||||
@@ -181,7 +198,7 @@ mod tests {
|
||||
updated_at: now,
|
||||
};
|
||||
|
||||
// Full Tunnel
|
||||
// Full Tunnel (IPv4-only interface -> 0.0.0.0/0 to prevent silent IPv6 blackhole)
|
||||
let full_conf = ClientConfigBuilder::build(&peer, &iface, "vpn.example.com").unwrap();
|
||||
assert!(full_conf.contains(&format!("PrivateKey = {}", peer_priv.as_str())));
|
||||
assert!(full_conf.contains("Address = 10.0.0.2/32"));
|
||||
@@ -190,9 +207,15 @@ mod tests {
|
||||
assert!(full_conf.contains(&format!("PublicKey = {}", srv_pub.as_str())));
|
||||
assert!(full_conf.contains(&format!("PresharedKey = {}", psk.as_str())));
|
||||
assert!(full_conf.contains("Endpoint = vpn.example.com:51820"));
|
||||
assert!(full_conf.contains("AllowedIPs = 0.0.0.0/0, ::/0"));
|
||||
assert!(full_conf.contains("AllowedIPs = 0.0.0.0/0"));
|
||||
assert!(full_conf.contains("PersistentKeepalive = 25"));
|
||||
|
||||
// Full Tunnel (Dual-stack interface -> 0.0.0.0/0, ::/0)
|
||||
let mut dual_iface = iface.clone();
|
||||
dual_iface.address_v6 = Some(IpNet::from_str("fd00::1/64").unwrap());
|
||||
let dual_conf = ClientConfigBuilder::build(&peer, &dual_iface, "vpn.example.com").unwrap();
|
||||
assert!(dual_conf.contains("AllowedIPs = 0.0.0.0/0, ::/0"));
|
||||
|
||||
// Split Tunnel
|
||||
peer.profile = PeerProfile::SplitTunnel;
|
||||
let split_conf = ClientConfigBuilder::build(&peer, &iface, "vpn.example.com").unwrap();
|
||||
@@ -274,6 +297,6 @@ mod tests {
|
||||
assert!(conf.contains("PersistentKeepalive = 20"));
|
||||
assert!(conf.contains("DNS = 9.9.9.9"));
|
||||
assert!(conf.contains("Address = 10.0.0.5/32"));
|
||||
assert!(conf.contains("AllowedIPs = 0.0.0.0/0, ::/0"));
|
||||
assert!(conf.contains("AllowedIPs = 0.0.0.0/0"));
|
||||
}
|
||||
}
|
||||
Reference in new issue
Block a user