mirror of
https://github.com/gesellix/Bose-SoundTouch.git
synced 2026-08-19 00:56:16 +00:00
feat(tls): persist TLSExtraHosts + Settings UI + speaker_marge_url QuickFix
Operators who deploy AfterTouch on an IP-only host (no DNS hostname) and who get a speaker_marge_url health warning previously had to SSH in, edit their systemd unit or docker-compose, add --tls-extra-host, and restart. The fix is now reachable from the UI: - datastore.Settings gains TLSExtraHosts []string. At startup applyPersistedSettings merges CLI/env values (still authoritative) with persisted ones, deduplicating while preserving order. - /setup/settings (GET) exposes tls_extra_hosts (editable list) and tls_san_hosts (the full effective SAN list, read-only). - /setup/settings (POST) accepts tls_extra_hosts (*[]string so callers can distinguish "field omitted" from "explicitly empty"). - Settings tab grows a "TLS extra hosts" textarea + an info panel explaining the restart-required dance. - speaker_marge_url emits a QuickFix labelled "Add <host> to TLS hosts" alongside the existing CLI manual command. The fix re-probes the device's /info, extracts the margeURL host, and appends it to the persisted list — race-safe against stale findings. - HTTPS-SETUP.md documents both paths. Tests cover: merge dedup + ordering + whitespace, the new QuickFix emission shape, and the margeURL host extraction across HTTPS/HTTP/bare input forms. Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 4.6
parent
377fa9ceda
commit
3a0b30bc33
@@ -88,6 +88,15 @@ The `:443` indicator is only displayed when **AfterTouch's DNS interception is e
|
||||
|
||||
When AfterTouch's configured `--server-url` is `http://…`, the pre-flight short-circuits to an `ℹ️ :443 reachability check not applicable` info line. Speakers that were migrated to that HTTP URL never connect to `:443`, so the iptables / setcap / reverse-proxy work is only needed if you also expect unmigrated speakers to fall back to `streaming.bose.com:443` via DNS hijack. If that's not your situation, the iptables rules above are optional.
|
||||
|
||||
#### Adding extra hosts to the TLS certificate
|
||||
|
||||
If speakers reach AfterTouch via a hostname or IP that isn't already covered by the served certificate, the speaker rejects the TLS handshake (typical syslog: `CURLE_SSL_CACERT (60)`). Two paths to fix this:
|
||||
|
||||
* **One-click QuickFix on the Health tab.** The `speaker_marge_url` check detects the mismatch and offers an `Add <host> to TLS hosts` button. Clicking it appends the missing host to `settings.json` (`tls_extra_hosts`). A subsequent service restart regenerates the certificate.
|
||||
* **Settings tab → "TLS extra hosts" textarea.** Add one host per line and click Save. Same persistence path; restart required to apply. The textarea is pre-filled with the persisted list; the read-only "Currently covered by TLS cert" line below it shows the full effective SAN list (including the values from `--server-url`, `--https-server-url`, the system hostname, and any `--tls-extra-host` / `TLS_EXTRA_HOST` CLI/env entries).
|
||||
|
||||
CLI/env values still win over persisted ones, so an operator who pinned a host via systemd unit doesn't have to migrate it into `settings.json` — the merge in `applyPersistedSettings` deduplicates while preserving order.
|
||||
|
||||
If you intercept Bose hostnames **outside** AfterTouch (Pi-hole, router DNS rule, `/etc/hosts` on a gateway), the UI gate above will hide the indicator. The data is still in the `GET /setup/settings` JSON response (`https_443_localhost_reachable`, `https_443_lan_reachable`, `https_443_lan_host`, `https_443_not_applicable`, `https_443_reason`) if you want to inspect it directly, or you can briefly enable AfterTouch's DNS server to see the indicator render.
|
||||
|
||||
---
|
||||
|
||||
Reference in New Issue
Block a user