## Problem - https://jira.suse.com/browse/AGM-153 - For security reasons it should be possible to disable remote access to the Agama web server. A server which is not reachable cannot be hacked. 😃 ## Solution - Add a new `inst.listen_on` boot option, the possible values: - `inst.listen_on=all` - listen on all network interfaces (allow local and remote access). This is the default behavior used even without the `inst.listen_on` option, added just for completeness. - `inst.listen_on=localhost` - listen only on loop back (localhost) device. This disables remote access, Agama can be accessed only locally. - `inst.listen_on=<ip>` - listen on the specified IP address. Both IPv4 and IPv6 addresses are supported. It is possible to use multiple IP addresses separated by comma. Addresses not found in the system are ignored. - `inst.listen_on=<interface>` - listen on the specified network interface. Multiple interfaces can be separated by comma. Not found interfaces are ignored. Agama always listens on the local loop back interface even when specifying a specific network interface or IP address for listening. The reason is to avoid reporting connection errors by the Firefox started in the Live ISO. ## Details - The `--address2` CLI option has been removed, instead it is possible to specify `--address` option multiple times. - The PR includes the @mvidner's patch https://github.com/agama-project/agama/pull/3111 - fallback to an IPv4 address when listening to IPv6 address fails (when IPv6 is disabled with the `ipv6.disable=1` boot option) - Added the `agama-web-server.sh` wrapper script started from the systemd service. It evaluates the boot parameters and builds the address parameters for the Agama server. ## Notes - The other network services like SSH can be disabled using the standard `systemd.mask` boot option. For example to disable the SSH service use this boot option: `systemd.mask=sshd.service`. (I'll document this as well...) ## Testing - Tested manually in all scenarios: with disabled remote access, listening on the specified IPv6 (including link local address) or IPv4 address, listening on specified interface, listening on multiple interfaces - Tested Martin's patch with the `ipv6.disable=1` boot option, Agama properly listens on the IPv4 addresses in that case. --------- Co-authored-by: Martin Vidner <mvidner@suse.com>
99 lines
3.8 KiB
Markdown
99 lines
3.8 KiB
Markdown
# Agama Web UI
|
|
|
|
The Agama web user interface is a React-based application that offers a user
|
|
interface to the [Agama service](file:../service).
|
|
|
|
## Development
|
|
|
|
The easiest way to work on the Agama Web UI is to use the development server.
|
|
The advantage is that you can use the [Hot Module Replacement] (https://
|
|
webpack.js.org/concepts/hot-module-replacement/) feature for automatically
|
|
updating the code and stylesheet in the browser without reloading the page.
|
|
|
|
### Using a development server
|
|
|
|
To start the [webpack-dev-server](https://github.com/webpack/webpack-dev-server)
|
|
use this command:
|
|
|
|
```
|
|
npm run server -- --open
|
|
```
|
|
|
|
The extra `--open` option automatically opens the server page in your default
|
|
web browser. In this case the server will use the `http://localhost:8080` URL
|
|
and expects a running `agama-web-server` at `http://localhost`.
|
|
|
|
This can work also remotely, with a Agama instance running in a different
|
|
machine (a virtual machine as well). In that case run
|
|
|
|
```
|
|
AGAMA_SERVER=https://<IP>:<port> npm run server -- --open
|
|
```
|
|
|
|
Where `AGAMA_SERVER` is the IP address, the hostname or the full URL of the
|
|
running Agama server instance. This is especially useful if you use the Live ISO
|
|
which does not contain any development tools, you can develop the web frontend
|
|
easily from your workstation.
|
|
|
|
Example of running from different machine:
|
|
|
|
```
|
|
# backend machine
|
|
# using ip of machine instead of localhost is important to be network accessible
|
|
# second address is needed for SSL which is mandatory for remote access
|
|
agama-web-server serve --address :::80 --address :::443
|
|
|
|
# frontend machine
|
|
# ESLINT=0 is useful to ignore linter problems during development
|
|
ESLINT=0 AGAMA_SERVER=https://10.100.1.1 npm run server
|
|
```
|
|
|
|
If you are using the Live ISO then you can use the predefined `agama` host name
|
|
configured via mDNS:
|
|
|
|
```
|
|
AGAMA_SERVER=https://agama.local npm run server
|
|
```
|
|
|
|
### Debugging Hints
|
|
|
|
There are several places to look when something does not work and requires debugging.
|
|
The first place is the browser's console which can give
|
|
some hints. The second location to check for errors or warnings is output of `npm run server`
|
|
where you can find issues when communicating with the backend. And last but on least is
|
|
journal on backend machine where is logged backend activity `journalctl -b`.
|
|
If the journal does not contain the required info, you can inspect the D-Bus communication
|
|
which can give hint about data flow. Command is `busctl monitor --address unix:path=/run/agama/bus`
|
|
|
|
### Special Environment Variables
|
|
|
|
`AGAMA_SERVER` - When running the development server set up a proxy to
|
|
the specified Agama web server. See the [using a development server]
|
|
(#using-a-development-server) section above.
|
|
|
|
`LOCAL_CONNECTION` - Force behaving as in a local connection, useful for
|
|
development or testing some Agama features. For example the keyboard layout
|
|
switcher is displayed only in local installation because it cannot work in
|
|
remote connection. This option will force displaying it even in a remote
|
|
connection.
|
|
|
|
## Type-Checking Support
|
|
|
|
This module started as a JavaScript-only project. We have decided to add type-checking support, but
|
|
instead of converting the code to TypeScript, we prefer to use [TypeScript support for JSDoc
|
|
annotations](https://www.typescriptlang.org/docs/handbook/intro-to-js-ts.html).
|
|
|
|
Run the following command to check the types:
|
|
|
|
```
|
|
npm run check-types
|
|
```
|
|
|
|
Not our JavaScript code is properly documented yet, so type-checking is an opt-in feature by now. If
|
|
you want a JavaScript file to be type-checked, please add a `// @ts-check` comment before any code.
|
|
|
|
### Links
|
|
|
|
- [Webpack documentation](https://webpack.js.org/configuration/)
|
|
- [PatternFly documentation](https://www.patternfly.org)
|
|
- [Material Symbols (aka icons)](https://fonts.google.com/icons)
|