Bug #1681
closed
OpenVPN tun IPs fail HTTP REFERER checks
Added by Chris Buechler over 13 years ago.
Updated about 10 years ago.
Description
tun IPs on OpenVPN connections fail the local IP check used for the HTTP_REFERER web interface protection, so the default GUI can't be accessed on tun IPs.
- Target version deleted (
2.1)
- Target version set to 2.1
This gets annoying when trying to help customers fix up broken OpenVPN routing, we should fix this sooner rather than later...
- Status changed from New to Feedback
- % Done changed from 0 to 100
- Status changed from Feedback to Resolved
This bug has not been correctly resolved, as tested with pfSense 2.1-RELEASE.
The changeset listed earlier does remove the red warning box when accessing the OpenVPN server IP address. However, it does not remove the warning box correctly when accessing an OpenVPN client address.
It also does not resolve the issue with the unbypassable HTTP_REFERER warning.
Two further changes need to happen for this to be correctly resolved:
1. The warning box needs to not be shown when accessing an OpenVPN client IP.
2. The HTTP_REFERER check needs to also take into account OpenVPN server and client IP addresses.
- Status changed from Resolved to New
- Target version changed from 2.1 to 2.2
I'm going to see if I can't just make a fix for this myself.
- Assignee set to Jim Pingle
pull request received 3 months ago. assigned to Pingle.
please ensure that a CLA is on-file before reviewing the patch.
- Status changed from New to Confirmed
still no CLA.
Per - could you please go through that process as Jim noted so we can accept this?
- Status changed from Confirmed to Feedback
The pull request seems to add only the CP users which should anyhow be allowed to go through openvpn to the gui.
The openvpn client is already covered before if assigned.
If not assigned i am unsure this is a safe thing to do.
- Status changed from Feedback to Resolved
this seems to be fine, works where it's reasonable to work, can be assigned if desired in other circumstances.
Also available in: Atom
PDF