aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorpacien2024-01-20 00:20:12 +0100
committerpacien2024-01-20 00:20:12 +0100
commit94f3a07b20019a7d412bb1b5caa4f5ce153732a9 (patch)
treed27823422dad159b9a57c064b28ca64d1af1cf78
parentb5fe5e49e0d3cc2b7c53af23b7a4e7d3c4491be1 (diff)
downloadtincapp-94f3a07b20019a7d412bb1b5caa4f5ce153732a9.tar.gz
config: make all generated files accessible to the user
Permissions mode 0600 was preventing even the user from accessing the configuration files. This makes the permissions more open. The private key files should nevertheless be protected from other apps by the permissions on the parent directory. Password protection for the private key is also recommended in general. GitHub: fixes #122
-rw-r--r--app/src/main/java/org/pacien/tincapp/activities/configure/tools/GenerateConfigToolDialogFragment.kt7
-rw-r--r--app/src/main/java/org/pacien/tincapp/activities/configure/tools/JoinNetworkToolDialogFragment.kt5
-rw-r--r--app/src/main/java/org/pacien/tincapp/utils/Files.kt47
-rw-r--r--app/src/main/java/org/pacien/tincapp/utils/TincKeyring.kt8
-rw-r--r--changelog.md3
5 files changed, 60 insertions, 10 deletions
diff --git a/app/src/main/java/org/pacien/tincapp/activities/configure/tools/GenerateConfigToolDialogFragment.kt b/app/src/main/java/org/pacien/tincapp/activities/configure/tools/GenerateConfigToolDialogFragment.kt
index 96e39ba..c152d54 100644
--- a/app/src/main/java/org/pacien/tincapp/activities/configure/tools/GenerateConfigToolDialogFragment.kt
+++ b/app/src/main/java/org/pacien/tincapp/activities/configure/tools/GenerateConfigToolDialogFragment.kt
@@ -1,6 +1,6 @@
1/* 1/*
2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon 2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon
3 * Copyright (C) 2017-2018 Pacien TRAN-GIRARD 3 * Copyright (C) 2017-2024 Pacien TRAN-GIRARD
4 * 4 *
5 * This program is free software: you can redistribute it and/or modify 5 * This program is free software: you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by 6 * it under the terms of the GNU General Public License as published by
@@ -23,6 +23,8 @@ import kotlinx.android.synthetic.main.configure_tools_dialog_network_generate.vi
23import org.pacien.tincapp.R 23import org.pacien.tincapp.R
24import org.pacien.tincapp.commands.Tinc 24import org.pacien.tincapp.commands.Tinc
25import org.pacien.tincapp.commands.TincApp 25import org.pacien.tincapp.commands.TincApp
26import org.pacien.tincapp.context.AppPaths
27import org.pacien.tincapp.utils.makePublic
26 28
27/** 29/**
28 * @author pacien 30 * @author pacien
@@ -47,5 +49,6 @@ class GenerateConfigToolDialogFragment : ConfigurationToolDialogFragment() {
47 .thenCompose { Tinc.init(netName, nodeName) } 49 .thenCompose { Tinc.init(netName, nodeName) }
48 .thenCompose { TincApp.removeScripts(netName) } 50 .thenCompose { TincApp.removeScripts(netName) }
49 .thenCompose { TincApp.generateIfaceCfgTemplate(netName) } 51 .thenCompose { TincApp.generateIfaceCfgTemplate(netName) }
50 .thenCompose { TincApp.setPassphrase(netName, newPassphrase = passphrase) }) 52 .thenCompose { TincApp.setPassphrase(netName, newPassphrase = passphrase) }
53 .thenApply { AppPaths.confDir(netName).makePublic() })
51} 54}
diff --git a/app/src/main/java/org/pacien/tincapp/activities/configure/tools/JoinNetworkToolDialogFragment.kt b/app/src/main/java/org/pacien/tincapp/activities/configure/tools/JoinNetworkToolDialogFragment.kt
index 25bdb15..f00b961 100644
--- a/app/src/main/java/org/pacien/tincapp/activities/configure/tools/JoinNetworkToolDialogFragment.kt
+++ b/app/src/main/java/org/pacien/tincapp/activities/configure/tools/JoinNetworkToolDialogFragment.kt
@@ -1,6 +1,6 @@
1/* 1/*
2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon 2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon
3 * Copyright (C) 2017-2018 Pacien TRAN-GIRARD 3 * Copyright (C) 2017-2024 Pacien TRAN-GIRARD
4 * 4 *
5 * This program is free software: you can redistribute it and/or modify 5 * This program is free software: you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by 6 * it under the terms of the GNU General Public License as published by
@@ -27,7 +27,9 @@ import kotlinx.android.synthetic.main.configure_tools_dialog_network_join.view.*
27import org.pacien.tincapp.R 27import org.pacien.tincapp.R
28import org.pacien.tincapp.commands.Tinc 28import org.pacien.tincapp.commands.Tinc
29import org.pacien.tincapp.commands.TincApp 29import org.pacien.tincapp.commands.TincApp
30import org.pacien.tincapp.context.AppPaths
30import org.pacien.tincapp.databinding.ConfigureToolsDialogNetworkJoinBinding 31import org.pacien.tincapp.databinding.ConfigureToolsDialogNetworkJoinBinding
32import org.pacien.tincapp.utils.makePublic
31 33
32/** 34/**
33 * @author pacien 35 * @author pacien
@@ -78,5 +80,6 @@ class JoinNetworkToolDialogFragment : ConfigurationToolDialogFragment() {
78 .thenCompose { TincApp.removeScripts(netName) } 80 .thenCompose { TincApp.removeScripts(netName) }
79 .thenCompose { TincApp.generateIfaceCfg(netName) } 81 .thenCompose { TincApp.generateIfaceCfg(netName) }
80 .thenCompose { TincApp.setPassphrase(netName, newPassphrase = passphrase) } 82 .thenCompose { TincApp.setPassphrase(netName, newPassphrase = passphrase) }
83 .thenApply { AppPaths.confDir(netName).makePublic() }
81 ) 84 )
82} 85}
diff --git a/app/src/main/java/org/pacien/tincapp/utils/Files.kt b/app/src/main/java/org/pacien/tincapp/utils/Files.kt
new file mode 100644
index 0000000..95653b3
--- /dev/null
+++ b/app/src/main/java/org/pacien/tincapp/utils/Files.kt
@@ -0,0 +1,47 @@
1/*
2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon
3 * Copyright (C) 2017-2024 Pacien TRAN-GIRARD
4 *
5 * This program is free software: you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by
7 * the Free Software Foundation, either version 3 of the License, or
8 * (at your option) any later version.
9 *
10 * This program is distributed in the hope that it will be useful,
11 * but WITHOUT ANY WARRANTY; without even the implied warranty of
12 * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 * GNU General Public License for more details.
14 *
15 * You should have received a copy of the GNU General Public License
16 * along with this program. If not, see <https://www.gnu.org/licenses/>.
17 */
18
19package org.pacien.tincapp.utils
20
21import android.annotation.SuppressLint
22import java.io.File
23
24/**
25 * @author pacien
26 */
27
28fun File.makePrivate() {
29 this.setExecutable(this.isDirectory, false)
30 this.setReadable(true, true)
31 this.setWritable(true, true)
32
33 if (this.isDirectory)
34 for (file in this.listFiles()!!)
35 file.makePrivate()
36}
37
38@SuppressLint("SetWorldReadable", "SetWorldWritable")
39fun File.makePublic() {
40 this.setExecutable(this.isDirectory, false)
41 this.setReadable(true, false)
42 this.setWritable(true, false)
43
44 if (this.isDirectory)
45 for (file in this.listFiles()!!)
46 file.makePublic()
47} \ No newline at end of file
diff --git a/app/src/main/java/org/pacien/tincapp/utils/TincKeyring.kt b/app/src/main/java/org/pacien/tincapp/utils/TincKeyring.kt
index 7d534e6..e8d9ad6 100644
--- a/app/src/main/java/org/pacien/tincapp/utils/TincKeyring.kt
+++ b/app/src/main/java/org/pacien/tincapp/utils/TincKeyring.kt
@@ -1,6 +1,6 @@
1/* 1/*
2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon 2 * Tinc App, an Android binding and user interface for the tinc mesh VPN daemon
3 * Copyright (C) 2017-2020 Pacien TRAN-GIRARD 3 * Copyright (C) 2017-2024 Pacien TRAN-GIRARD
4 * 4 *
5 * This program is free software: you can redistribute it and/or modify 5 * This program is free software: you can redistribute it and/or modify
6 * it under the terms of the GNU General Public License as published by 6 * it under the terms of the GNU General Public License as published by
@@ -49,10 +49,4 @@ object TincKeyring {
49 file.makePrivate() 49 file.makePrivate()
50 return file 50 return file
51 } 51 }
52
53 private fun File.makePrivate() {
54 this.setExecutable(false, false)
55 this.setReadable(true, true)
56 this.setWritable(true, true)
57 }
58} 52}
diff --git a/changelog.md b/changelog.md
index dfc455b..8b17f91 100644
--- a/changelog.md
+++ b/changelog.md
@@ -3,6 +3,9 @@
3This file lists notable changes that have been made to the application on each release. 3This file lists notable changes that have been made to the application on each release.
4Releases are tracked and referred to using git tags. 4Releases are tracked and referred to using git tags.
5 5
6## v0.39 -- (next release)
7- fix permissions for newly created or joined network host and key files
8
6## v0.38 -- 2023-07-30 9## v0.38 -- 2023-07-30
7- make configuration files and logs accessible in the user-accessible storage 10- make configuration files and logs accessible in the user-accessible storage
8 (in USB storage mode). The embedded FTP server has been removed 11 (in USB storage mode). The embedded FTP server has been removed