Skip to content
This repository was archived by the owner on Jan 3, 2023. It is now read-only.
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
258 commits
Select commit Hold shift + click to select a range
c207baa
Update install.sh
arvage Apr 27, 2020
115a352
Update install.sh
arvage Apr 27, 2020
ddff862
Update README.md
arvage Apr 27, 2020
c35d9a6
Update README.md
arvage Apr 27, 2020
fac2d7d
Delete icon.png
arvage Apr 27, 2020
c1b119b
Add files via upload
arvage Apr 27, 2020
868bf13
Update install.sh
arvage Apr 27, 2020
10e244a
Update README.md
arvage Apr 27, 2020
6954c98
Update install.sh
arvage Apr 28, 2020
b85b6c6
Update install.sh
arvage Apr 28, 2020
c4552dd
Update index.php
arvage Apr 28, 2020
074b868
Update configuration.php
arvage Apr 28, 2020
d6514ab
Update index.php
arvage Apr 28, 2020
d821641
Update index.php
arvage Apr 28, 2020
c3bad15
Update install.sh
arvage May 1, 2020
47e526a
Update install.sh
arvage May 1, 2020
6e5ba47
Create .htaccess
arvage May 1, 2020
8056284
Update install.sh
arvage May 1, 2020
27dfb33
Update install.sh
arvage May 1, 2020
00a8f9f
Update install.sh
arvage May 1, 2020
145f047
Fixed client conf download
arvage May 1, 2020
d3ee3a7
Update README.md
arvage May 1, 2020
00e29a7
Visual touchups
arvage May 1, 2020
702d47c
Merge branch 'master' of https://github.com/arvage/OpenVPN-Admin
arvage May 1, 2020
b025f20
visual touchups
arvage May 1, 2020
5e88c7b
added git as prerequisite
arvage May 1, 2020
acf5dcc
fixed configuration file name on save
arvage May 1, 2020
d386543
Update install.sh
arvage May 1, 2020
e15d057
Update install.sh
arvage May 1, 2020
0cbe2be
Update install.sh
arvage May 1, 2020
3620a03
fixed error when no sql user provided
arvage May 1, 2020
fb0c554
Update README.md
arvage May 1, 2020
5d719ea
Update install.sh
arvage May 1, 2020
4fc47e4
Update README.md
arvage May 1, 2020
4d7dca5
Update install.sh
arvage May 1, 2020
b3b6968
added instruction button
arvage May 1, 2020
2ed02ff
manual
arvage May 1, 2020
4d38c24
download instructions
arvage May 1, 2020
2e91230
download instructions
arvage May 1, 2020
67ee746
get instructions
arvage May 1, 2020
8841a5e
instruction ger
arvage May 2, 2020
c76c04b
Fully automated install
arvage May 2, 2020
23e0763
removed unnecessary package install
arvage May 2, 2020
831198e
fix easy-rsa
arvage May 2, 2020
f6064e8
Update README.md
arvage May 2, 2020
2db974b
online install created
arvage May 2, 2020
975c65d
online install
arvage May 2, 2020
66de7fb
automated install
arvage May 2, 2020
04608ce
Updating client-conf folder web security
arvage May 3, 2020
7a121d0
Providing auto-generated information when finished
arvage May 3, 2020
3e730fe
fixed hostname
arvage May 3, 2020
65b36ec
fixed error on auto install
arvage May 3, 2020
005350f
fixed final messages
arvage May 3, 2020
d431307
rearranged the script
arvage May 3, 2020
6f06ac0
Update README.md
arvage May 3, 2020
e36329e
added auto admin install
arvage May 3, 2020
9560e01
Update README.md
arvage May 3, 2020
3744d9e
fixed an error
arvage May 3, 2020
74bc507
fixed mariadb error
arvage May 3, 2020
6e374f7
fixed prerequisite checkups
arvage May 3, 2020
0e87d08
error fix
arvage May 3, 2020
6f41b85
script touchups
arvage May 3, 2020
4f43760
add user auto start date to date
arvage May 4, 2020
7a69e86
static timezone added
arvage May 4, 2020
526fd0e
static timezone added
arvage May 4, 2020
92c64af
fixed sql user or pass error
arvage May 4, 2020
c5e17da
added download conf to admin page
arvage May 4, 2020
b2302d9
added configurations table
arvage May 4, 2020
3423248
update
arvage May 4, 2020
e340dad
update
arvage May 4, 2020
10110ef
Update README.md
arvage May 4, 2020
dcbf6d2
Update README.md
arvage May 4, 2020
6c0a59c
Update README.md
arvage May 4, 2020
c51fdbd
added config download button to admin page
arvage May 4, 2020
ccd09cc
updated unistall
arvage May 4, 2020
dc93d3c
update
arvage May 4, 2020
d33ba61
auto first time admin install
arvage May 4, 2020
5eb6b86
updated public ip and hotname
arvage May 4, 2020
b75916f
update install
arvage May 4, 2020
e0b36ea
updated install
arvage May 5, 2020
80c75a9
updated install script
arvage May 5, 2020
946a6e9
updated install script
arvage May 5, 2020
a1bf476
Update install.sh
arvage May 5, 2020
7a53df2
updated install script
arvage May 5, 2020
9a8b442
timeout for hostname input for automated install
arvage May 5, 2020
6c330d2
updated install script
arvage May 5, 2020
f03b705
update
arvage May 5, 2020
3860451
update
arvage May 5, 2020
a32f9fc
update
arvage May 5, 2020
3911af0
added mysql timezone to install script
arvage May 5, 2020
94e51f4
fixed MySQL timezone.
arvage May 5, 2020
463776c
fix
arvage May 5, 2020
bab6166
fix
arvage May 5, 2020
8891733
update
arvage May 5, 2020
9fb12ed
fix
arvage May 5, 2020
7b1d023
fix
arvage May 5, 2020
9e2af72
fix
arvage May 5, 2020
9f42e08
added npm update line
arvage May 5, 2020
fdf0368
update
arvage May 5, 2020
a0fcbe0
added ip_forward for ubuntu
arvage May 6, 2020
c6ae7be
welcome ubuntu full install
arvage May 6, 2020
474cff9
grammar typo fixed. fixed KB and MB
arvage May 6, 2020
07e34b3
removed 2 columns from logs table
arvage May 6, 2020
0d282d1
removed decimals from bytes send and received
arvage May 6, 2020
0b814e6
added coloring to logs based on MB KB
arvage May 6, 2020
17a04be
coloring logs
arvage May 6, 2020
11f09e7
logs coloring
arvage May 6, 2020
4ebbede
logs coloring
arvage May 6, 2020
5941e18
logs coloring
arvage May 7, 2020
ea68f67
log table text align
arvage May 7, 2020
0104ea3
update
arvage May 7, 2020
3147dc7
added download filename selection to install script
arvage May 7, 2020
8d42a4e
added config file manual setup in install script
arvage May 7, 2020
00a1b07
fixed error
arvage May 7, 2020
276200d
download filename selection on install script
arvage May 7, 2020
d72952e
fixed error on changing file name
arvage May 7, 2020
7b870aa
updated install script user outputs
arvage May 7, 2020
067966f
updated user outputs
arvage May 7, 2020
ec5440c
fixed file save name
arvage May 7, 2020
e81debe
updated user comments
arvage May 7, 2020
5527166
fixed download file extension
arvage May 7, 2020
6825b7e
quick fix
arvage May 7, 2020
599de1b
force iptables save rules on Ubuntu
arvage Jul 15, 2020
0003e30
Added MAC instructions
arvage Oct 21, 2020
2911675
MAC instructions
arvage Oct 21, 2020
d44698c
Update index.php
arvage Oct 21, 2020
6d6a0b9
Update configuration.php
arvage Oct 21, 2020
986827d
Update configuration.php
arvage Oct 21, 2020
7756f73
Fixed filename
arvage Apr 12, 2021
db6d63b
Delete Download and install the OpenVPN GUI.pdf
arvage Apr 12, 2021
81170ee
Added Debian Support
arvage Jul 17, 2021
0ad1185
Update install.sh
arvage Jul 17, 2021
8071548
Update install.sh
arvage Jul 21, 2021
0a03546
Update install.sh
arvage Jul 21, 2021
b48f4e5
minor touch
arvage Aug 30, 2021
a2bebbd
Added filename tab and configurations
arvage Sep 2, 2021
ee7e4a3
now saving ovpn file based on filename in configs
arvage Sep 2, 2021
2885994
Create filename
arvage Sep 2, 2021
4bbbe09
Update grids.php
arvage Sep 2, 2021
0e0b86c
Update install.sh
arvage Sep 2, 2021
7722f71
touchups :)
arvage Sep 2, 2021
38fa71d
Update online-install.sh
arvage Sep 2, 2021
a0a025b
fixed a missing quotation
arvage Sep 15, 2021
5bad8e4
Fixed IP forward issue after reboots
arvage Oct 8, 2021
d279b0c
Update install.sh
arvage Oct 14, 2021
4a8d153
fixed .ovpn file save
arvage Oct 14, 2021
5bb52b3
Update online-install.sh
arvage Oct 14, 2021
fa77b96
Update online-install.sh
arvage Oct 14, 2021
28ac14b
Update online-install.sh
arvage Oct 14, 2021
9ace200
Update online-install.sh
arvage Oct 14, 2021
b6f8403
Update README.md
arvage Oct 14, 2021
06dfa13
Update online-install.sh
arvage Oct 14, 2021
ca21625
Update online-install.sh
arvage Oct 14, 2021
219d718
Update filename
arvage Oct 14, 2021
603713f
fixed MySQL root password reset
arvage Oct 14, 2021
bad7a71
Update online-install.sh
arvage Oct 14, 2021
e96d433
Update install.sh
arvage Oct 14, 2021
6ed245a
Update install.sh
arvage Oct 14, 2021
22ff51a
Update README.md
arvage Oct 14, 2021
cdba39a
Update README.md
arvage Oct 14, 2021
342a1b5
Update install.sh
arvage Oct 14, 2021
241b82f
Update install.sh
arvage Oct 14, 2021
6c56b8b
Update install.sh
arvage Oct 14, 2021
7779a3d
Update README.md
arvage Oct 14, 2021
59e714b
Update install.sh
arvage Oct 14, 2021
4b5f133
Update install.sh
arvage Oct 14, 2021
4660d63
Update install.sh
arvage Oct 14, 2021
fdbe29f
Update install.sh
arvage Oct 15, 2021
869c109
Update install.sh
arvage Oct 15, 2021
9aab409
Update online-install.sh
arvage Oct 15, 2021
42e3162
Update install.sh
arvage Oct 15, 2021
45aee9a
Update install.sh
arvage Oct 15, 2021
1c716ef
Update online-install.sh
arvage Oct 15, 2021
b19d788
Update install.sh
arvage Oct 15, 2021
5ea1682
Update install.sh
arvage Oct 15, 2021
d6606ab
Update README.md
arvage Nov 24, 2021
c0a2212
Update README.md
arvage Nov 24, 2021
7a130e1
getting ready for ubuntu 22
Aug 24, 2022
2dfacd0
getting ready for ubuntu 22
Aug 24, 2022
78cfed6
adding php7.4 to ubuntu 22
Aug 24, 2022
dcb0327
SSL CERT expiration is 100 years now
Aug 24, 2022
c1a4eca
fixed a tiny error
Aug 24, 2022
db686a0
fixed an error
Aug 24, 2022
6b034d1
tiny fix
Aug 24, 2022
5d9fad7
debugging
Aug 24, 2022
c31d5a4
tiny fix
Aug 24, 2022
76dbee3
tiny fix again!
Aug 24, 2022
614c996
fix!
Aug 24, 2022
2c827c2
fix2.0
Aug 24, 2022
57d7d49
unattended install
Aug 24, 2022
f3be3ac
unattended install fix
Aug 24, 2022
796e03b
last fix!
Aug 24, 2022
470ce78
last fix?
Aug 24, 2022
10e25a7
corrected typo
Aug 24, 2022
794db2b
corrected typo
Aug 24, 2022
4c474f7
fixed SQL query
Aug 24, 2022
4cbe55f
added some art :)
Aug 24, 2022
06347be
Amiga!?
Aug 24, 2022
0036a49
new OpenSSL compatibility
arvage Nov 15, 2022
8b582f6
Update install.sh
arvage Nov 18, 2022
8d7f356
updated version
arvage Mar 22, 2023
b683575
FD0 removal!
arvage Mar 27, 2023
810ad4e
Added RDP on Mac
arvage Mar 27, 2023
748476f
removed FD0
arvage Mar 27, 2023
01729ab
feat: add dark sidebar (A), dashboard stats panel (B), and improved u…
claude Feb 20, 2026
d84c08d
feat: add Debian 11/12 support to install, uninstall, and online-inst…
claude Feb 20, 2026
189412f
fix: use ID field from /etc/os-release for reliable OS detection
claude Feb 20, 2026
1b193b7
fix: point clone URLs to fork (ringmor) instead of upstream (arvage)
claude Feb 21, 2026
dea45fb
feat: URL-based admin pages, unified login, and admin user management
Feb 22, 2026
7bba70b
Update README.md
sandmanstorm Mar 4, 2026
b733b51
Merge pull request #1 from sandmanstorm/claude/explain-codebase-mlvb1…
arvage Mar 4, 2026
8652b41
Update repository links in installation instructions
arvage Mar 4, 2026
16dba7d
Fixed online install script
arvage Mar 5, 2026
aabf736
fixed require error
arvage Mar 6, 2026
e9ff143
Update tested Ubuntu version in README
arvage Mar 6, 2026
621c010
Upgrade to Bootstrap 5, add role-based access, certificates, SMTP, li…
arvage Jun 3, 2026
d0ddbdf
Fix install.sh compatibility with Ubuntu 22/24, Debian 11/12, Raspber…
arvage Jun 4, 2026
daeab33
Fix online-install.sh for modern Ubuntu/Debian/Raspberry Pi OS
arvage Jun 4, 2026
2bf3f9c
Fix uninstall.sh: colors, socket auth, NIC detection, complete cleanup
arvage Jun 4, 2026
13e0051
Fix update.sh: colors, backup, stat, sudoers, log dir, server.conf pa…
arvage Jun 4, 2026
080558a
Update README and CHANGELOG for v1.0.0
arvage Jun 4, 2026
933ed22
Fix PHP 7.2 compatibility: replace match(), str_contains(), arrow fun…
arvage Jun 4, 2026
25cc38c
Fix online-install.sh: add sudo to needrestart sed command
arvage Jun 4, 2026
1c67535
Fix needrestart suppression: use env var instead of sed on config file
arvage Jun 4, 2026
9b31ec3
Fix Apache PHP module mismatch in install.sh and update.sh
arvage Jun 4, 2026
e6f8849
Add author credit to sidebar footer and login page
arvage Jun 4, 2026
3db633e
Fix SQL migration: remove ADD COLUMN IF NOT EXISTS, add per-statement…
arvage Jun 4, 2026
4f8f59b
Fix isInstalled(): check for admin users, not just the admin table
arvage Jun 4, 2026
964493f
Fix duplicate redirect-gateway warning in client configs
arvage Jun 4, 2026
ae92ca0
Fix LZO decompression header error causing connection drops
arvage Jun 4, 2026
abac3a4
Fix LZO header mismatch: align compression to lz4-v2 everywhere
arvage Jun 4, 2026
d49fd90
add live dashboard auto-refresh, user notifications, and admin profil…
arvage Jun 24, 2026
8fbf3c4
fix 7 security vulnerabilities identified in security review
arvage Jun 24, 2026
fe7be7b
add fail2ban integration with dashboard page
arvage Jun 24, 2026
3070c13
add fail2ban install/config to install.sh; fix interactive prompts
arvage Jun 24, 2026
76b1db1
add fail2ban install/config to update.sh
arvage Jun 24, 2026
9fd7584
docs: update README, CHANGELOG, and issue template for v1.1.0
arvage Jun 24, 2026
af54e80
update.sh: pull latest code from git automatically before applying up…
arvage Jun 24, 2026
727ad78
fix notifications not appearing after user CRUD; improve bell UX
arvage Jun 24, 2026
9632e7b
add per-type toggles for admin in-app notifications in Settings → Not…
arvage Jun 24, 2026
539cc3c
add edit email button to admins grid
arvage Jun 24, 2026
1919cca
docs: update README and CHANGELOG for v1.1.1
arvage Jun 24, 2026
470b04d
add ban/unban notifications to the admin notification system
arvage Jun 24, 2026
0ae4db2
docs: update README and CHANGELOG for v1.1.2 (ban/unban notifications)
arvage Jun 24, 2026
2889a91
fix CSP blocking inline script; move window vars to js/config.php
Jun 24, 2026
2f99b7e
docs: update README and CHANGELOG for v1.1.3 (CSP fix)
Jun 24, 2026
b79df5d
fix public IP not applied to client .ovpn files; fix Fail2Ban sudo bl…
arvage Jul 20, 2026
f6fe244
docs: update README and CHANGELOG for v1.1.4 (public IP fix, Fail2Ban…
arvage Jul 20, 2026
6ad3d06
changed compress
arvage Aug 14, 2026
c20c016
fixed compress
arvage Aug 14, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
44 changes: 38 additions & 6 deletions .github/ISSUE_TEMPLATE.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,38 @@
* **PHP version:**
* **MySQL version:**
* **Webserver (Nginx, Apache...):**
* **What is the expected behaviour?**
* **What do you see instead?**
* **PHP logs on pastebin:**
**OS and version** (e.g. Ubuntu 24.04):

**PHP version** (`php -v`):

**MySQL / MariaDB version** (`mysql --version`):

**fail2ban version** (`fail2ban-client --version`):

**OpenVPN version** (`openvpn --version`):

**Admin panel version** (shown in CHANGELOG or git tag):

**What did you expect to happen?**

**What happened instead?**

**Steps to reproduce:**

1.
2.
3.

**Relevant logs** (redact sensitive info):

Apache error log (`/var/log/apache2/error.log`):
```

```

PHP errors (if any):
```

```

fail2ban log if relevant (`/var/log/fail2ban.log`):
```

```
3 changes: 3 additions & 0 deletions .vs/ProjectSettings.json
Original file line number Diff line number Diff line change
@@ -0,0 +1,3 @@
{
"CurrentProjectSetting": null
}
Binary file added .vs/slnx.sqlite
Binary file not shown.
105 changes: 105 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,110 @@
# OpenVPN-Admin Version History

## 1.1.4

### Fixes
- **Public IP never applied to client `.ovpn` files** — `install.sh` patched the placeholder `remote xxx.xxx.xxx.xxx 1194/443`, but the shipped templates actually use `remote 10.10.100.27 1194`. The `sed` pattern never matched, so every fresh install (including the one-liner installer) shipped `.ovpn` files still pointing at the example IP instead of the detected/entered public IP. The installer now matches the real placeholder.
- **Fail2Ban page always shows the "grant sudo access" warning, even after following it** — on Ubuntu 26.04+, `apache2.service` ships with `InaccessiblePaths=-/etc/sudoers` and `-/etc/sudoers.d`, which hides sudo's config from Apache and everything it spawns (PHP included) as a defense against a compromised web app escalating to root. This silently broke the web UI's `sudo fail2ban-client` / `sudo easyrsa` calls regardless of what was in `/etc/sudoers.d` — adding the suggested sudoers entry had no effect. `install.sh` now drops a systemd override (`apache2.service.d/openvpn-admin-sudo.conf`) that re-declares `InaccessiblePaths` without those two entries, when the packaged unit has them.

### Changes
- **Client Configuration Editor simplified** — the GNU/Linux and macOS/Viscosity tabs are removed from the admin Configs page; only the shared `.ovpn` template remains, under a single "Editor" tab.

---

## 1.1.3

### Fixes
- **All admin buttons missing / Fail2Ban page stuck on spinner** — the `Content-Security-Policy` header (`script-src 'self'`) silently blocked the inline `<script>` block that set `window.ADMIN_ROLE`, `window.CURRENT_PAGE`, and `window.CSRF_TOKEN`. As a result `isSuperAdmin` was always `false` (hiding every edit/delete/reset button on the Users, Admins, and Certificates pages) and `currentPage` defaulted to `'dashboard'` (so `loadFail2Ban()` was never called, leaving the Fail2Ban page frozen on the loading spinner). Fixed by moving the three variables into `js/config.php`, a PHP-served external script that satisfies the `'self'` CSP directive.
- **Sudoers file missing after `update.sh`** — when running an older copy of `update.sh` the script git-pulls itself mid-run, but the already-loaded (old) process does not re-read the new version; the sudoers block introduced in v1.1.0 was therefore never written. `update.sh` now always writes `/etc/sudoers.d/openvpn-admin`.

### Improvements
- **Asset cache busting** — `grids.js` and `index.css` are now loaded with a `?v=<filemtime>` query string so future updates take effect immediately without requiring a hard refresh.

---

## 1.1.2

- **Ban/unban notifications** — banning or unbanning an IP via the Fail2Ban page now creates an in-app notification for super-admins; the bell refreshes immediately after the action
- Two new toggles in Settings → Notifications (Admin Notifications section): **IP Banned** (default on) and **IP Unbanned** (default on); backed by `notify_admin_ban` / `notify_admin_unban` columns (schema-13)
- Bell dropdown shows a red shield (🛡✕) for bans and a green shield (🛡✓) for unbans

---

## 1.1.1

### New Features
- **Admin email editing from the Admins grid** — each row in the Web Admins table now has a pencil button that opens a modal pre-filled with the admin's current email; super-admins can update any other admin's email without needing that admin to log in and use their own Profile button
- **Per-type admin notification toggles** — Settings → Notifications now has a second section ("Admin Notifications") with three toggle switches controlling which user events create in-app bell notifications for super-admins: User Added (default on), User Edited (default off), User Deleted (default on); backed by new `smtp_settings` columns (schema-12)

### Fixes
- **Notifications not appearing after user actions** — `refreshNotifications()` was never called after add/edit/delete user, so the bell badge only updated on the 30-second background poll; now refreshes immediately after each action
- **Bell stuck on "Loading…" when notification table missing** — `?select=notifications` catch block returned `is_super:false` on DB error, causing JS to bail silently; now returns `is_super:true` with a `setup_needed` flag so the dropdown shows an actionable message instead
- **Bell dropdown always fresh on open** — clicking the bell now fetches notifications immediately regardless of when the 30-second poll last ran

### Updater
- **`update.sh` now pulls from git automatically** — running `sudo ./update.sh /var/www` is the only command needed to go from any state to fully up-to-date; a separate `git pull` is no longer required

---

## 1.1.0

### New Features
- **Fail2Ban integration** — new Fail2Ban page in the admin sidebar (super-admin only):
- Live jail status cards with currently banned count, currently failing count, and lifetime total
- Per-jail banned IP list with one-click unban (confirm dialog)
- Manual Ban IP modal: enter any IPv4/IPv6 address and select the target jail
- Auto-refreshes every 10 seconds; manual refresh button
- `install.sh` and `update.sh` now install fail2ban, write `/etc/fail2ban/filter.d/openvpn.conf` and `/etc/fail2ban/jail.d/openvpn-admin.conf` (SSH + OpenVPN jails, 5 attempts → 1-hour ban), and extend `/etc/sudoers.d/openvpn-admin` to grant the web server passwordless access to `fail2ban-client`
- **In-app notifications** — bell icon in the topbar for super-admins:
- Unread badge count; dropdown shows last 50 events with timestamps
- Notification fired on every user add, edit, and delete (records which admin performed the action)
- Click bell or "Mark all read" to clear unread state per-admin
- Polls every 30 seconds; backed by new `notification` database table (schema-11)
- **Admin profile editing** — Profile button in the topbar lets any logged-in admin update their own email address; email pre-fills from the database when the modal opens
- **Dashboard auto-refresh** — user table now also refreshes every 10 seconds while the Users page is open (was manual-only)

### Security Fixes (7 vulnerabilities)
- **Path traversal → RCE** — `update_config` handler now validates `config_file` against an explicit allowlist of 4 permitted paths; arbitrary file writes via `..` sequences are no longer possible
- **Password hashes in API responses** — `user_pass` and `admin_pass` are no longer returned by `?select=user` or `?select=admin`; hashes never leave the server
- **Authorization bypass on certificate download** — `cert_download` handler now calls `requireSuperAdmin()` (was the only sensitive endpoint missing it); read-only admins can no longer download private key material
- **CSRF** — `generateCsrfToken()` / `verifyCsrfToken()` added; token exposed as `window.CSRF_TOKEN`; jQuery `$.ajaxPrefilter` attaches it to every POST; `grids.php` validates it before any state-changing operation
- **Stored XSS — certificate CN** — `listCertificates()` now `htmlspecialchars()` the CN field; JS `loadCertificates()` uses `$('<td>').text()` and `.attr()` instead of string concatenation
- **Stored XSS — user email/phone in HTML attributes** — `userActionsFormatter`, `adminActionsFormatter`, `passFormatter`, and `adminPassFormatter` rebuilt with jQuery DOM construction (`.attr()`, `.append()`); no user data is concatenated into raw HTML strings
- **Privilege escalation — fail-open role** — `getCurrentAdminRole()` now returns `'read-only'` (not `'super-admin'`) when the role field is empty or on any database exception; system fails closed
- **Session cookie hardening** — `session_set_cookie_params()` with `httponly=true`, `samesite=Strict`, and `secure` (auto-detected from HTTPS) added before every `session_start()`

### Installer / Updater
- `install.sh`: fixed `read -t 120` prompt bug — timeout persisted even after user pressed Enter; replaced with plain `read -p` which returns immediately
- `install.sh` / `update.sh`: fail2ban installed, configured, and enabled as part of the standard install/update flow
- `update.sh`: sudoers block now always writes both `easyrsa` and `fail2ban-client` entries unconditionally (was "create only if missing"), so existing installs pick up `fail2ban-client` permission on next update

---

## 1.0.0
- Upgrade UI from Bootstrap 3 to Bootstrap 5 with Bootstrap Icons (CDN-based; removes Bower/npm dependency entirely)
- Replace x-editable inline editing with Bootstrap 5 modal-based row editing
- Add live connection dashboard (polls OpenVPN status log every 10 seconds)
- Add per-user certificate management: generate, revoke, download `.ovpn`, email config
- Add role-based admin access: `super-admin` (full control) and `read-only`
- Add SMTP configuration page with send-test functionality
- Add email notification toggles: on-connect, on-disconnect, account-expiry
- Add `include/mailer.php`: lightweight zero-dependency PHP SMTP client
- Add `include/notify.php`: CLI script called by OpenVPN connect/disconnect hooks
- Add `sql/schema-10.sql`: admin role column, `smtp_settings` table, fix missing admin columns
- Fix `install.sh`: remove PHP 7.4 forcing; use system PHP; fix OpenVPN 2.5+ genkey syntax;
fix `iptables-save`; fix IP forwarding persistence via `sysctl.d`; fix hardcoded `eth0`;
detect MySQL vs MariaDB; add sudoers entry for EasyRSA; add 64-bit Raspberry Pi OS detection;
remove Bower/nodejs/npm; fix `apt-get upgrade` removal; add `systemctl enable`
- Fix `online-install.sh`: remove non-ASCII chars from ASCII art; fix RPi 64-bit detection;
guard `needrestart` edit; remove `apt-get upgrade`; handle existing clone directory; add `set -e`
- Fix `uninstall.sh`: add colors; fix MySQL socket auth; fix hardcoded `eth0`; fix `iptables-save`;
fix sysctl cleanup; stop/disable OpenVPN service before file removal; clean up all new artifacts
(sudoers, log dir, iptables persistence file, Apache conf); fix PHP timezone revert
- Fix `update.sh`: add colors; add pre-update backup; fix `stat` for user/group detection;
add sudoers and log dir creation for existing installs; patch `server.conf` for OpenVPN 2.5+;
add Apache reload; add OpenVPN restart when server.conf changes
- Connect and disconnect scripts now call `notify.php` for email alerts

## 0.3.2
- Fix with MySQL NO_ZERO_DATE mode

Expand Down
Loading