Skip to content

WEB UI - #24

Closed
GIC-de wants to merge 16 commits into
mainfrom
webui
Closed

GIC-de wants to merge 16 commits into
mainfrom
webui

Conversation

@GIC-de

@GIC-de GIC-de commented Sep 16, 2026

Copy link
Copy Markdown
Member

Summary

Adds an experimental, embedded single-page web UI (pkg/server/webui/) for
creating and observing BNG Blaster test instances without calling the REST
API directly, plus the supporting API surface it needs:

  • New read endpoints: /_overview, /_streams, /_sessions, /_logs,
    /_files (+ per-file download), and /api/v1/interfaces (host network
    interfaces, used to populate the "New Instance" form)
  • Embedded OpenAPI/Swagger docs served under /docs
  • Response caching for the summary endpoints (pkg/server/cache.go) to
    avoid hammering the bngblaster control socket on repeated UI polling

The web UI, the interfaces endpoint, and the upload endpoint are new attack
surface with no authentication yet, so all three ship disabled by
default
behind -ui, -interfaces-api, and -upload flags (see the new
"Experimental Web UI" section in the README for how to turn them on).

Also includes some incidental fixes picked up along the way: corrected the
default bngblaster executable path, and config/logging tweaks for the
systemd packaging.

Test plan

  • go build ./...
  • go test ./...
  • Manual smoke test of the UI in a browser (create/start/stop an
    instance, check overview/streams/sessions/logs/files views, upload a
    file) — recommended before merging since this is a large new surface
    with no automated UI tests

🤖 Generated with Claude Code

@GIC-de GIC-de self-assigned this Sep 16, 2026
GIC-de and others added 12 commits September 26, 2026 12:07
- reject uploads of run files and pids <= 1 (kill as root)
- graceful HTTP shutdown; no write deadline for file transfers
- deb: keep service state on upgrade, add postrm, recommend bngblaster
- golangci-lint v2 + CI lint job, testify bump, swagger _overview

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- reject cross-origin state-changing requests (Sec-Fetch-Site/Origin)
- add -allowed-hosts Host header allowlist against DNS rebinding
- security headers and CSP on every response
- bound request bodies, reject uploads larger than free disk space
- restrict stream_config to files inside the instance folder
- audit log client address for requests and lifecycle changes
- systemd unit sandboxing; document in README, swagger and CLAUDE.md

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- interface stats: loss count plus ratio (0.001%), red when > 0
- progress bars: 3 decimals rounded down, so 9999/10000 no longer shows 100%
- serve instance files with Cache-Control: no-cache and fetch config.json
  with no-store, so the editor no longer reopens the previous version
- interface stats: loss count plus ratio (0.001%), red when > 0
- progress bars: 3 decimals rounded down, so 9999/10000 no longer shows 100%

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
- stream_config: absolute paths are used as-is again, so stream files
  kept in home directories work; relative paths must still stay inside
  the instance folder
- systemd: keep home directories readable (ProtectHome=read-only) for
  stream, BGP and MRT files
- uploads and downloads remain confined to the instance folder
- update README, swagger and web UI hint

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Deduplicate the stream and session pagination handlers into a generic
summary endpoint (summary.go), split Start's startup wait and the overview
fetch into their own functions, and fix the remaining style findings:
FlowID/SessionID naming, min/max and any, test file permissions, request
contexts and unused parameters. Allow generic returns in ireturn, as the
summary cache necessarily returns its type parameter.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Build golangci-lint v2.14.0 from source in CI, as its prebuilt binaries
are built with go 1.26 and refuse to load a module targeting go 1.27.
Bump checkout and setup-go to v7, golangci-lint-action to v9 and
goreleaser-action to v7.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Run a goreleaser snapshot after build and test and upload the .deb,
tarball and checksums as the bngblasterctrl-dev workflow artifact.
Snapshot versions are now <next patch>~dev.<commit time>.<commit>, which
dpkg sorts below the upcoming release so it upgrades over a dev build.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
dpkg runs the old package's prerm on upgrade, and the one shipped up to
0.1.3 unconditionally stopped and disabled the service, so try-restart
left it stopped and disabled. Those versions always enabled the service
on install, so restore that when upgrading from them.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
@GIC-de GIC-de closed this Oct 3, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant