WGX shares its name with several other WireGuard tools, so the project becomes ihasvpn, alongside ihasmail. - Module github.com/Coffey-Labs/ihasvpn, command cmd/ihasvpn, image ghcr.io/coffey-labs/ihasvpn. - Environment variables move from WGX_* to IHASVPN_*. The default database is ihasvpn.db, the nftables table is `ihasvpn`, metrics are ihasvpn_*, and the session cookie and theme key are renamed, so existing sessions end. - The mark is the ihasmail cat peeking over the edge of a shield, drawn as a vector. docs/brand/generate.py builds the mark, mono mark, wordmarks, social card, favicons and app icons from that one drawing. - The console takes ihasmail's palette: the ihasmail.org teal-navy for dark, its contrast-checked light tiers with the site's light accent, received traffic in the cat's orange and sent in teal. The wordmark weight and font stack follow ihasmail.org. - Detail values wrap at spaces before breaking inside an address, so an IPv6 tunnel address no longer splits mid-number. - The README history note about the earlier WGX installer is gone with the name it explained. Screenshots retaken.
2.0 KiB
2.0 KiB
Security Policy
Supported versions
Security fixes go to main and the next release. Older releases are not
patched.
Reporting a vulnerability
Please do not open a public issue for a security problem. Email johnellisATlinuxDOTcom with what you found, how to reproduce it and what you think the impact is. You will get an acknowledgement within a few days and a fix or a plan before anything is made public.
What ihasvpn does to protect itself
- The admin UI requires a password (argon2id, 64 MiB, 3 passes) and offers
time-based one-time codes with recovery codes. Sessions are random 256-bit
tokens stored hashed,
HttpOnly,SameSite=Strict, with idle and absolute expiry. - Every state-changing request must come from the same origin
(
Sec-Fetch-Site/Originare checked in addition to the cookie policy) and carry a JSON body; the first-run setup endpoint stops working the moment a user exists. - Login is rate-limited per address and per username, and a failed login for an unknown user takes as long as one for a known user.
- Responses carry a strict Content-Security-Policy,
X-Frame-Options: DENY,Referrer-Policy: no-referrerand, under TLS, HSTS. - Peer private keys never appear in list or detail responses; they are only returned through the configuration and QR endpoints, and each view is written to the audit log. The server's own private key never leaves the process.
- The database file is created mode 0600 and the container image contains no shell tooling beyond what nftables and WireGuard need.
What you must do
- Do not expose port 51821 to the internet without TLS. Either set
IHASVPN_TLS_SELF_SIGNED=true(orIHASVPN_TLS_CERT/IHASVPN_TLS_KEY) or put a TLS-terminating reverse proxy in front and list it inIHASVPN_TRUSTED_PROXIESso client addresses in the audit log are right. - Turn on two-factor authentication for every administrator.
- Keep the
/datavolume private: it holds every peer's private key.