mirror of
https://github.com/amnezia-vpn/amnezia-client.git
synced 2026-05-08 14:33:23 +00:00
* refactor: move business logic from servers model * refactor: move containersModel initialization * refactor: added protocol ui controller and removed settings class from protocols model * refactor: moved cli management to separate controller * refactor: moved app split to separate controller * refactor: moved site split to separate controller * refactor: moved allowed dns to separate controller * refactor: moved language logic to separate ui controller * refactor: removed Settings from devices model * refactor: moved configs and services api logit to separate core controller * refactor: added a layer with a repository between the storage and controllers * refactor: use child parent system instead of smart pointers for controllers and models initialization * refactor: moved install functions from server controller to install controller * refactor: install controller refactoring * chore: renamed exportController to exportUiController * refactor: separate export controller * refactor: removed VpnConfigurationsController * chore: renamed ServerController to SshSession * refactor: replaced ServerController to SshSession * chore: moved qml controllers to separate folder * chore: include fixes * chore: moved utils from core root to core/utils * chore: include fixes * chore: rename core/utils files to camelCase foramt * chore: include fixes * chore: moved some utils to api and selfhosted folders * chore: include fixes * chore: remove unused file * chore: moved serialization folder to core/utils * chore: include fixes * chore: moved some files from client root to core/utils * chore: include fixes * chore: moved ui utils to ui/utils folder * chore: include fixes * chore: move utils from root to ui/utils * chore: include fixes * chore: moved configurators to core/configurators * chore: include fixes * refactor: moved iap logic from ui controller to core * refactor: moved remaining core logic from ApiConfigsController to SubscriptionController * chore: rename apiNewsController to apiNewsUiController * refactor: moved core logic from news ui controller to core * chore: renamed apiConfigsController to subscriptionUiController * chore: include fixes * refactor: merge ApiSettingsController with SubscriptionUiController * chore: moved ui selfhosted controllers to separate folder * chore: include fixes * chore: rename connectionController to connectiomUiController * refactor: moved core logic from connectionUiController * chore: rename settingsController to settingsUiController * refactor: move core logic from settingsUiController * refactor: moved core controller signal/slot connections to separate class * fix: newsController fixes after refactoring * chore: rename model to camelCase * chore: include fixes * chore: remove unused code * chore: move selfhosted core to separate folder * chore: include fixes * chore: rename importController to importUiController * refactor: move core logic from importUiController * chore: minor fixes * chore: remove prem v1 migration * refactor: remove openvpn over cloak and openvpn over shadowsocks * refactor: removed protocolsForContainer function * refactor: add core models * refactor: replace json with c++ structs for server config * refactor: move getDnsPair to ServerConfigUtils * feat: add admin selfhosted config export test * feat: add multi import test * refactor: use coreController for tests * feat: add few simple tests * chore: qrepos in all core controllers * feat: add test for settings * refactor: remove repo dependency from configurators * chore: moved protocols to core folder * chore: include fixes * refactor: moved containersDefs, defs, apiDefs, protocolsDefs to different places * chore: include fixes * chore: build fixes * chore: build fixes * refactor: remove q repo and interface repo * feat: add test for ui servers model and controller * chore: renamed to camelCase * chore: include fixes * refactor: moved core logic from sites ui controller * fix: fixed api config processing * fix: fixed processed server index processing * refactor: protocol models now use c++ structs instead of json configs * refactor: servers model now use c++ struct instead of json config * fix: fixed default server index processing * fix: fix logs init * fix: fix secure settings load keys * chore: build fixes * fix: fixed clear settings * fix: fixed restore backup * fix: sshSession usage * fix: fixed export functions signatures * fix: return missing part from buildContainerWorker * fix: fixed server description on page home * refactor: add container config helpers functions * refactor: c++ structs instead of json * chore: add dns protocol config struct * refactor: move config utils functions to config structs * feat: add test for selfhosted server setup * refactor: separate resources.qrc * fix: fixed server rename * chore: return nameOverriddenByUser * fix: build fixes * fix: fixed models init * refactor: cleanup models usage * fix: fixed models init * chore: cleanup connections and functions signatures * chore: cleanup updateModel calls * feat: added cache to servers repo * chore: cleanup unused functions * chore: ssxray processing * chore: remove transportProtoWithDefault and portWithDefault functions * chore: removed proto types any and l2tp * refactor: moved some constants * fix: fixed native configs export * refactor: remove json from processConfigWith functions * fix: fixed processed server index usage * fix: qml warning fixes * chore: merge fixes * chore: update tests * fix: fixed xray config processing * fix: fixed split tunneling processing * chore: rename sites controllers and model * chore: rename fixes * chore: minor fixes * chore: remove ability to load backup from "file with connection settings" button * fix: fixed api device revoke * fix: remove full model update when renaming a user * fix: fixed premium/free server rename * fix: fixed selfhosted new server install * fix: fixed updateContainer function * fix: fixed revoke for external premium configs * feat: add native configs qr processing * chore: codestyle fixes * fix: fixed admin config create * chore: again remove ability to load backup from "file with connection settings" button * chore: minor fixes * fix: fixed variables initialization * fix: fixed qml imports * fix: minor fixes * fix: fix vpnConnection function calls * feat: add buckup error handling * fix: fixed admin config revok * fix: fixed selfhosted awg installation * fix: ad visability * feat: add empty check for primary dns * chore: minor fixes
144 lines
5.5 KiB
C++
144 lines
5.5 KiB
C++
#include "ikev2Configurator.h"
|
|
|
|
#include <QDebug>
|
|
#include <QJsonDocument>
|
|
#include <QProcess>
|
|
#include <QString>
|
|
#include <QTemporaryDir>
|
|
#include <QTemporaryFile>
|
|
#include <QUuid>
|
|
|
|
#include "core/utils/containerEnum.h"
|
|
#include "core/utils/containers/containerUtils.h"
|
|
#include "core/utils/protocolEnum.h"
|
|
#include "core/utils/selfhosted/sshSession.h"
|
|
#include "core/utils/selfhosted/scriptsRegistry.h"
|
|
#include "core/utils/utilities.h"
|
|
#include "core/models/protocols/ikev2ProtocolConfig.h"
|
|
|
|
Ikev2Configurator::Ikev2Configurator(SshSession* sshSession, QObject *parent)
|
|
: ConfiguratorBase(sshSession, parent)
|
|
{
|
|
}
|
|
|
|
Ikev2Configurator::ConnectionData Ikev2Configurator::prepareIkev2Config(const ServerCredentials &credentials, DockerContainer container,
|
|
ErrorCode &errorCode)
|
|
{
|
|
Ikev2Configurator::ConnectionData connData;
|
|
connData.host = credentials.hostName;
|
|
connData.clientId = Utils::getRandomString(16);
|
|
connData.password = "";
|
|
|
|
QString certFileName = "/opt/amnezia/ikev2/clients/" + connData.clientId + ".p12";
|
|
|
|
QString scriptCreateCert = QString("certutil -z <(head -c 1024 /dev/urandom) "
|
|
"-S -c \"IKEv2 VPN CA\" -n \"%1\" "
|
|
"-s \"O=IKEv2 VPN,CN=%1\" "
|
|
"-k rsa -g 3072 -v 120 "
|
|
"-d sql:/etc/ipsec.d -t \",,\" "
|
|
"--keyUsage digitalSignature,keyEncipherment "
|
|
"--extKeyUsage serverAuth,clientAuth -8 \"%1\"")
|
|
.arg(connData.clientId);
|
|
|
|
errorCode = m_sshSession->runContainerScript(credentials, container, scriptCreateCert);
|
|
|
|
QString scriptExportCert =
|
|
QString("pk12util -W \"%1\" -d sql:/etc/ipsec.d -n \"%2\" -o \"%3\"").arg(connData.password).arg(connData.clientId).arg(certFileName);
|
|
errorCode = m_sshSession->runContainerScript(credentials, container, scriptExportCert);
|
|
|
|
connData.clientCert = m_sshSession->getTextFileFromContainer(container, credentials, certFileName, errorCode);
|
|
connData.caCert = m_sshSession->getTextFileFromContainer(container, credentials, "/etc/ipsec.d/ca_cert_base64.p12", errorCode);
|
|
|
|
qDebug() << "Ikev2Configurator::ConnectionData client cert size:" << connData.clientCert.size();
|
|
qDebug() << "Ikev2Configurator::ConnectionData ca cert size:" << connData.caCert.size();
|
|
|
|
return connData;
|
|
}
|
|
|
|
ProtocolConfig Ikev2Configurator::createConfig(const ServerCredentials &credentials, DockerContainer container, const ContainerConfig &containerConfig,
|
|
const DnsSettings &dnsSettings,
|
|
ErrorCode &errorCode)
|
|
{
|
|
const Ikev2ServerConfig* serverConfig = nullptr;
|
|
if (auto* ikev2Config = containerConfig.protocolConfig.as<Ikev2ProtocolConfig>()) {
|
|
serverConfig = &ikev2Config->serverConfig;
|
|
}
|
|
|
|
ConnectionData connData = prepareIkev2Config(credentials, container, errorCode);
|
|
if (errorCode != ErrorCode::NoError) {
|
|
return Ikev2ProtocolConfig{};
|
|
}
|
|
|
|
QString configJson = genIkev2Config(connData);
|
|
QJsonDocument doc = QJsonDocument::fromJson(configJson.toUtf8());
|
|
QJsonObject configObj = doc.object();
|
|
|
|
Ikev2ProtocolConfig protocolConfig;
|
|
if (serverConfig) {
|
|
protocolConfig.serverConfig = *serverConfig;
|
|
} else {
|
|
protocolConfig.serverConfig.hostName = connData.host;
|
|
}
|
|
|
|
Ikev2ClientConfig clientConfig;
|
|
clientConfig.nativeConfig = configJson;
|
|
clientConfig.hostName = connData.host;
|
|
clientConfig.userName = connData.clientId;
|
|
clientConfig.cert = QString(connData.clientCert.toBase64());
|
|
clientConfig.password = connData.password;
|
|
clientConfig.clientId = connData.clientId;
|
|
|
|
protocolConfig.setClientConfig(clientConfig);
|
|
|
|
return protocolConfig;
|
|
}
|
|
|
|
QString Ikev2Configurator::genIkev2Config(const ConnectionData &connData)
|
|
{
|
|
QJsonObject config;
|
|
config[configKey::hostName] = connData.host;
|
|
config[configKey::userName] = connData.clientId;
|
|
config[configKey::cert] = QString(connData.clientCert.toBase64());
|
|
config[configKey::password] = connData.password;
|
|
|
|
return QJsonDocument(config).toJson();
|
|
}
|
|
|
|
QString Ikev2Configurator::genMobileConfig(const ConnectionData &connData)
|
|
{
|
|
QFile file(":/server_scripts/ipsec/mobileconfig.plist");
|
|
file.open(QIODevice::ReadOnly);
|
|
QString config = QString(file.readAll());
|
|
|
|
config.replace("$CLIENT_NAME", connData.clientId);
|
|
config.replace("$UUID1", QUuid::createUuid().toString());
|
|
config.replace("$SERVER_ADDR", connData.host);
|
|
|
|
QString subStr("$(UUID_GEN)");
|
|
while (config.indexOf(subStr) > 0) {
|
|
config.replace(config.indexOf(subStr), subStr.size(), QUuid::createUuid().toString());
|
|
}
|
|
|
|
config.replace("$P12_BASE64", connData.clientCert.toBase64());
|
|
config.replace("$CA_BASE64", connData.caCert.toBase64());
|
|
|
|
return config;
|
|
}
|
|
|
|
QString Ikev2Configurator::genStrongSwanConfig(const ConnectionData &connData)
|
|
{
|
|
QFile file(":/server_scripts/ipsec/strongswan.profile");
|
|
file.open(QIODevice::ReadOnly);
|
|
QString config = QString(file.readAll());
|
|
|
|
config.replace("$CLIENT_NAME", connData.clientId);
|
|
config.replace("$UUID", QUuid::createUuid().toString());
|
|
config.replace("$SERVER_ADDR", connData.host);
|
|
|
|
QByteArray cert = connData.clientCert.toBase64();
|
|
cert.replace("\r", "").replace("\n", "");
|
|
config.replace("$P12_BASE64", cert);
|
|
|
|
return config;
|
|
}
|