Add encrypted configuration backup and planned restore
This commit is contained in:
@@ -198,6 +198,26 @@ class Agent:
|
||||
record = validate_record(data.get('credentials'))
|
||||
save(DATA/'auth.json', record)
|
||||
return {'saved':True}
|
||||
if action == 'backup-export':
|
||||
config = json.loads((DATA/'config.json').read_text()) if (DATA/'config.json').exists() else None
|
||||
return {'config': config, 'enabled': self.address is not None, 'mode': self.policy.mode}
|
||||
if action == 'backup-restore':
|
||||
if self.address or self.policy.mode != 'lan' or self.policy.pending:
|
||||
raise ValueError('Netzwerk-Restore nur im bestätigten LAN-Modus bei deaktiviertem Deck-Tunnel.')
|
||||
value = data.get('backup')
|
||||
if not isinstance(value, dict) or set(value) != {'config','enabled','mode'} or value['mode'] not in ('lan','both','tunnel') or type(value['enabled']) is not bool:
|
||||
raise ValueError('Ungültiger Netzwerk-Backupstand.')
|
||||
if value['config'] is not None:
|
||||
parse_config(value['config']);save(DATA/'config.json', value['config'])
|
||||
if value['enabled']:
|
||||
self.connect();save(DATA/'enabled.json', True)
|
||||
until=time.monotonic()+20
|
||||
while not self.connected()[0] and time.monotonic()<until:time.sleep(.5)
|
||||
if not self.connected()[0]:
|
||||
self.disconnect();save(DATA/'enabled.json',False)
|
||||
raise ValueError('WireGuard-Handshake fehlt; LAN-Zugang bleibt erhalten.')
|
||||
if value['mode'] != 'lan':self.policy.propose(value['mode'], True)
|
||||
return self.status(ingress)
|
||||
if action == 'status':
|
||||
return self.status(ingress)
|
||||
if action == 'import':
|
||||
|
||||
Reference in New Issue
Block a user