diff --git a/app.py b/app.py index c43dec1..37b94c6 100644 --- a/app.py +++ b/app.py @@ -1231,7 +1231,7 @@ try: for address in item.get("addr_info", []): result["addresses"].append(address["local"] + "/" + str(address["prefixlen"])) result["routes"] = json.loads(run(["ip", "-j", "route", "show", "dev", "wg0"])) - rows = run(["wg", "show", "wg0", "dump"]).splitlines() + rows = run(["sudo", "-n", "wg", "show", "wg0", "dump"]).splitlines() if rows: interface = rows[0].split("\\t") result["listen_port"] = int(interface[2]) @@ -1244,7 +1244,7 @@ try: "latest_handshake": int(fields[4]), "rx_bytes": int(fields[5]), "tx_bytes": int(fields[6]), - "persistent_keepalive": int(fields[7]), + "persistent_keepalive": 0 if fields[7] == "off" else int(fields[7]), }) except Exception as exc: result["error"] = str(exc)[:300] diff --git a/tests/test_app.py b/tests/test_app.py index eb3be0d..c49a918 100644 --- a/tests/test_app.py +++ b/tests/test_app.py @@ -92,6 +92,18 @@ def test_wireguard_status_rejects_unknown_host_without_ssh(monkeypatch): assert response.status_code == 404 +def test_wireguard_status_command_uses_sudo_and_accepts_off_keepalive(): + import base64 + import re + + command = app._wireguard_status_command() + encoded = re.search(r"b64decode\('([^']+)'\)", command).group(1) + script = base64.b64decode(encoded).decode() + + assert '["sudo", "-n", "wg", "show", "wg0", "dump"]' in script + assert '0 if fields[7] == "off" else int(fields[7])' in script + + def test_tts_generate_returns_cloned_wav(monkeypatch): captured = {}