Commit Graph

1778 Commits

Author SHA1 Message Date
CyberMind
270f655d3a
Merge pull request #579 from CyberMind-FR/feature/574-webext-popup-protection-stats-quick-filt
Some checks are pending
License Headers / check (push) Waiting to run
webext popup: protection stats + live filter toggles (#574)
2026-06-14 12:10:41 +02:00
b366946855 feat(webext): popup protection stats + live filter toggles (closes #574)
New Protection panel in the popup: ghost savings (blocked/Mo/pages cleaned
via /admin/ghost) + live toggles for ad_ghost / ad_ghost_block / banner /
protective(off|alert|spoof) via /admin/filters. api.js: ghost/getAdminFilters/
setAdminFilters helpers. Top-tracker list stays top-5. webext 0.1.4,
tag-pin -> webext-v0.1.4, secubox-toolbox 2.6.27.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 12:10:20 +02:00
CyberMind
433c5ca190
Merge pull request #573 from CyberMind-FR/feature/572-banner-colorful-emoji-chip-guirlande-fla
Some checks are pending
License Headers / check (push) Waiting to run
Banner: colourful emoji-chip guirlande (#572)
2026-06-14 11:02:14 +02:00
1a23c1f78a feat(toolbox): colourful emoji-chip guirlande banner (closes #572)
inject_banner right-side stats now render as vibrant rounded pills cycling
an 8-colour festive palette with neon box-shadow glow. Pure-ASCII inline
styling, works in CSP-strict + JS variants. secubox-toolbox 2.6.26.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 11:01:37 +02:00
CyberMind
ff0503ea70
Merge pull request #571 from CyberMind-FR/feature/570-toolbox-mitm-dpi-media-type-statistifier
DPI media/content-type statistifier + donut (#570)
2026-06-14 10:58:08 +02:00
675f6ae458 feat(toolbox): DPI media/content-type statistifier + donut (closes #570)
mitmproxy_addons/media_stats.py buckets responses by content-type category
(emoji-iconified) + provider (eTLD+1), summing Content-Length (header only,
no body read). Rolling -> /run/secubox/media.json. api: /admin/media +
/admin/media/ui (SVG donut + emoji legend + top-5 providers w/ favicons).
Wired into the mitm-wg launcher. secubox-toolbox 2.6.25.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 10:57:48 +02:00
CyberMind
b689c235f6
Merge pull request #569 from CyberMind-FR/feature/568-webext-popup-cap-top-tracker-list-to-5-e
Some checks are pending
License Headers / check (push) Waiting to run
webext: cap popup top-tracker list to 5 (#568)
2026-06-14 10:26:55 +02:00
d26992d905 feat(webext): cap popup top-tracker list to 5 (closes #568)
popup top-tracker list 12 -> 5. webext 0.1.3; /wg/toolbox.xpi tag-pin
-> webext-v0.1.3. secubox-toolbox 2.6.24.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 10:26:34 +02:00
CyberMind
295f77601d
Merge pull request #567 from CyberMind-FR/feature/566-r3-r4-silent-ad-banner-ghoster-economisa
Some checks are pending
License Headers / check (push) Waiting to run
Modular mitm filters + R3+/R4 silent ad/banner ghoster (#566)
2026-06-14 09:29:15 +02:00
f176fa3173 feat(toolbox): modular mitm filters + R3+/R4 silent ad/banner ghoster (closes #566)
- filters.py: live filter config (/etc/secubox/toolbox/filters.json), toolbox
  WebUI toggles (banner / protective off|alert|spoof / ad_ghost / block /
  per-category cosmetics), 5s cache, no restart.
- ad_ghost.py: R3+/R4 (10.99.1.0/24) only — 204 known ad/tracker hosts
  (bandwidth save) + inject ad-hiding CSS (ads/consent-nag/newsletter/social);
  tallies blocked + bytes_saved_est + pages_cleaned → /run/secubox/ghost.json.
- inject_banner: filter-gated; shows ghost quick-stats; status inspected→
  protected on R3+/R4. protective_mode reads filter (env fallback).
- api: /admin/filters (GET/POST), /admin/ghost, /admin/filters/ui panel.
- launcher loads ad_ghost; postinst seeds filters.json. Unit-tested.
secubox-toolbox 2.6.23.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-14 09:28:54 +02:00
CyberMind
18f727b7d7
Merge pull request #565 from CyberMind-FR/feature/564-detect-antibot-split-deployment-vs-chall
Some checks are pending
License Headers / check (push) Waiting to run
detect_antibot: deployment vs challenge, response-level signals (#564, ref #516)
2026-06-13 18:27:01 +02:00
9bd5a958f2 fix(toolbox): detect_antibot deployment vs challenge (response-level) — ref #516 (closes #564)
detect_antibot(flow) -> (vendor, is_challenge). vendor = WAF/anti-bot
DEPLOYED (URL/cookie/header presence) -> deployment map, always recorded.
is_challenge = a challenge actually ISSUED on this response (response-level
only): Cloudflare cf-mitigated, or non-200 (403/429/503) text/html small
body with __cf_chl / challenges.cloudflare.com / cdn-cgi/challenge-platform
/ vendor block markers. Presence on a 200 is no longer counted as a
challenge (kills false positives from bm_sz/_abck, _px*, datadome cookie,
embedded reCAPTCHA). Only is_challenge feeds the per-client alert/severity.
Unit-tested 8 cases. secubox-toolbox 2.6.22.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 18:26:39 +02:00
CyberMind
bbcfe7ad1a
Merge pull request #563 from CyberMind-FR/feature/562-ca-fingerprint-surface-the-r3-ca-on-the
fix(ca): /ca/fingerprint surfaces the R3 CA on the tunnel (#562)
2026-06-13 18:14:47 +02:00
dbe255c31e fix(toolbox): /ca/fingerprint surfaces the R3 CA on the tunnel (closes #562)
It always read the R1/R2 captive CA, so R3 users verifying their installed
cert saw the wrong fingerprint. Now ?ca=wg|default|auto; auto returns the
R3 CA (/etc/secubox/toolbox/ca-wg/mitmproxy-ca-cert.pem) when the request
arrives over the R3 tunnel (X-R3-Peer / 10.99.1.x), else R1/R2; response
gains a 'ca' field. Landing cert-probe fetches ?ca=wg. secubox-toolbox 2.6.21.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 18:14:22 +02:00
CyberMind
52e51b2766
Merge pull request #561 from CyberMind-FR/feature/560-toolbox-protective-mode-tracker-alerting
Some checks are pending
License Headers / check (push) Waiting to run
Toolbox protective mode — tracker alerting + active spoofer (default OFF) (#560)
2026-06-13 16:03:44 +02:00
87614c7143 feat(toolbox): protective mode — tracker alerting + active spoofer, default OFF (closes #560)
New mitmproxy_addons/protective_mode.py. SECUBOX_PROTECTIVE_MODE =
off (default) | alert | spoof. Spoof neutralises classified 3rd-party
tracker hosts ONLY (1st-party untouched): strips operator-grade/tracking
headers (MSISDN, x-acr, x-up-*, x-wap-*, forwarded IPs), drops the Cookie
header + referer to the tracker, asserts DNT:1 + Sec-GPC:1. Alerting +
spoof actions → /var/log/secubox/audit.log; counts → /run/secubox/protective.json.
Wired into the mitm-wg launcher + mitm.service addon list (inert until
opted in). GET /admin/protective exposes mode + counters.

Doctrine: opt-in, default off, logged, reversible — not enabled on any
board by this package. secubox-toolbox 2.6.20.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 16:03:33 +02:00
CyberMind
93cf0ebafa
Merge pull request #556 from CyberMind-FR/feature/555-favicons-of-major-sites-in-the-xpi-popup
Favicons of major sites in cartographie + XPI popup (drop IPs) (#555)
2026-06-13 16:02:52 +02:00
CyberMind
94f40c9162
Merge pull request #559 from CyberMind-FR/feature/558-apk-make-zero-tap-auto-run-robust-real-f
Some checks are pending
License Headers / check (push) Waiting to run
Android: real zero-tap full-auto onboarding (launch + boot) (#558)
2026-06-13 15:44:58 +02:00
c1fa245a6a feat(android): real zero-tap full-auto onboarding — launch + boot, no gate (closes #558)
Strengthen the zero-tap root onboarding (keeps it, doesn't kill it):
- launch auto-run: drop the per-host 'onboarded' gate (runs every launch,
  idempotent) + retry reachability ~9s so a WiFi/tunnel race no longer
  aborts the auto-run.
- boot auto-run: BootReceiver (BOOT_COMPLETED) → OnboardService foreground
  service runs the silent sequence WITHOUT opening the app (retries
  reachability ~30s), then stops. Rooted device self-onboards after a reboot.
-  button kept as a manual re-trigger.
Unavoidable (Android-mandated, not bugs): sideload install confirm + first
su grant. versionName 0.3.0 / versionCode 3.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 15:33:00 +02:00
6e83a4a065 feat(toolbox+webext): favicons of major sites in cartographie + popup, never IPs (closes #555)
- social.js eye-view: site + tracker nodes render the site favicon via the
  same-origin /social/favicon/{domain} proxy (7d cached, transparent 1×1
  fallback so the tier circle shows through), clipped to the bubble.
- webext popup top-tracker list gains a 16px favicon per row (api.faviconUrl
  helper). clients/webext-toolbox 0.1.2 ; /wg/toolbox.xpi tag-pin → webext-v0.1.2.
No IP/ASN displayed anywhere. secubox-toolbox 2.6.19.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 15:27:57 +02:00
CyberMind
92b203cbbc
Merge pull request #554 from CyberMind-FR/feature/553-cartographie-graph-impact-sized-icon-bub
Some checks are pending
License Headers / check (push) Waiting to run
Cartographie donut-bubble view + geography rollups (#553)
2026-06-13 15:18:15 +02:00
7bd265fe1a feat(toolbox): cartographie donut-bubble view + geography rollups (closes #553)
User vision: 'bubble of donuts graph' — impact-sized bubbles, each a donut
by tier, agglomerated by country with continent bubbles; IP/ASN dropped.

Backend (social.py fetch_graph, additive, tested):
- nodes gain country_iso / country_flag / continent / tier
- by_country (flag + per-tier breakdown), by_continent, by_tier
- stats: total_countries / total_continents ; helpers _flag_emoji /
  _continent_of / _tracker_tier (no GeoIP/publicsuffix dep)

Frontend (social.js):
- '🍩 Donuts' view (default) ⇄ '👁️ Œil' toggle. d3.pack: continent
  backdrop bubbles → country donuts sized by impact, ring split by
  severity tier, flag in the hole, tier legend, click→country summary.
- Eye force-graph kept as fallback; detail panel now shows country flag.
secubox-toolbox 2.6.18.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 15:15:32 +02:00
CyberMind
dc6505a2f2
Merge pull request #552 from CyberMind-FR/feature/551-android-apk-zero-tap-auto-run-silent-onb
Some checks are pending
License Headers / check (push) Waiting to run
Android: zero-tap auto-run silent onboarding on root (#551)
2026-06-13 13:16:59 +02:00
CyberMind
51ed62f10a
Merge pull request #548 from CyberMind-FR/feature/547-linux-firefox-installer-script-for-the-t
Linux Firefox fast installer/launcher for the ToolBoX extension (#547)
2026-06-13 13:16:53 +02:00
CyberMind
dfa7e34ad0
Merge pull request #550 from CyberMind-FR/feature/549-social-tracker-domain-rollup-history-tim
Social: tracker domain-rollup + history + target↔tracker correlation (#549)
2026-06-13 13:16:17 +02:00
2a51348b9d feat(toolbox): tracker domain-rollup + history + target↔tracker correlation (closes #549)
fetch_graph() gains three additive, read-time keys (no schema change,
d3 /social/graph contract untouched):
- by_domain: trackers rolled up under their registrable parent (eTLD+1,
  all *.doubleclick.net → doubleclick.net) with tracker_count/hits/sites/vendors
- targets: inverse map — per 1st-party site, the trackers + parent domains
  watching it
- history: per-UTC-day timeline (hits/trackers/sites) from social_edges
stats gains total_domains; local _registrable_domain helper (no publicsuffix
dep). Integration-tested (rollup, inversion, history). secubox-toolbox 2.6.17.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 13:16:06 +02:00
CyberMind
4cb8fb87fa
Merge pull request #546 from CyberMind-FR/feature/545-injected-banner-neon-tube-redesign-for-r
Neon-tube injected banner for R3 (+ R4-ready theme) (#545)
2026-06-13 13:15:19 +02:00
8d48d86bcd feat(toolbox): neon-tube injected banner for R3 (+R4-ready theme) (closes #545)
_LEVEL_THEME map drives the banner look per opt-in level: R3 (and the
planned R4) get a neon-tube treatment — dark glass bar, glowing tube
border (layered box-shadow) and neon text-shadow on the title — while R2
keeps the original amber flat bar. _banner_html_dynamic() now takes the
level and themes both the CSP-strict (JS-less) and JS (dismissible)
variants; all inline CSS, no injected <style>/@keyframes, ASCII/NCR-clean.
R4 theme is defined but inert until _client_level() returns 'r4'.
secubox-toolbox 2.6.16.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 13:14:56 +02:00
CyberMind
7a651f360d
Merge pull request #544 from CyberMind-FR/feature/543-kbin-landing-radical-simplify-livelier-f
kbin landing: radical-simplify redesign (#543)
2026-06-13 13:14:08 +02:00
81da97e53e feat(android): zero-tap auto-run silent onboarding on root (closes #551)
On a rooted device the app now runs the full silent onboarding on launch
with no taps: a LaunchedEffect auto-starts the root sequence once when
root is detected and this host hasn't been onboarded yet. The root-auto
logic is extracted into a reusable runRootAuto lambda (shared by the
auto-launch and the  button, which remains for re-runs). An onboarded
flag is persisted per host in SharedPreferences so reopening doesn't redo
it. versionName 0.2.0 / versionCode 2.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 13:13:02 +02:00
2647cfffa1 feat(webext): Linux Firefox fast installer/launcher script (closes #547)
install-firefox-linux.sh: one call grabs the ToolBoX .xpi (from a cabine
host, --release, or --local) and launches Firefox with it loaded via
'web-ext run' (temporary, works unsigned — fastest), opening /social/me.
Falls back to opening the .xpi for the install prompt when web-ext/npx
is absent, with the unsigned-install note. Detects firefox/-esr/-bin/flatpak.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 13:04:01 +02:00
e4d59569eb feat(toolbox): kbin landing radical-simplify redesign (closes #543)
Animated hero (gazing eye + floating tracker dots) + one big 'Protège-moi
(R3)' CTA + the auto-detected install panel up front. KPIs, cert-probe,
pitch, R0-R3 levels, charts, architecture, open-source and contact are
folded behind an 'En savoir plus' <details>. Quick-nav trimmed: dropped
the CA iPhone / CA Android / QR profil cards (now inside the per-platform
install panel); kept R3 Install / Mon rapport / Ma carto / Wiki / Cabine.
Count-up animation on the live KPIs. All Jinja vars + live-stats and
cert-probe scripts preserved. secubox-toolbox 2.6.15.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 12:52:34 +02:00
CyberMind
d2cb735f09
Merge pull request #542 from CyberMind-FR/feature/532-plan-browser-xpi-webextension-emancipate
Some checks are pending
License Headers / check (push) Waiting to run
docs: webext .xpi published + tag-pinned release note (#532)
2026-06-13 12:48:03 +02:00
9b7c6f67f1 fix(webext): 'redeclaration of const ext' SyntaxError + PNG icons, v0.1.1 (ref #532)
Real cause of the broken extension: api.js and background.js BOTH did
`const ext = …`. In a Firefox event page the background.scripts array
loads them into one shared scope (same via importScripts in a Chromium
SW), and popup.js's `const ext` collided with api.js's in the popup
page realm too — 'redeclaration of const ext' aborts the script. web-ext
lint misses it because it never concatenates/executes the scripts.
Now only api.js declares `const ext`; background.js and popup.js use
`api.ext`.

Also (defensive + Chromium-correct): replace the SVG action/extension
icon with rasterised PNGs (48/128) and keep the SVG out of the package,
so Firefox never renders SVG in chrome UI. Bump to v0.1.1; the
/wg/toolbox.xpi endpoint + fetch helper + docs point at webext-v0.1.1.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 12:32:17 +02:00
4289f8ff3c docs: webext .xpi published/downloadable + tag-pinned release note (ref #532)
README + wiki Browser-Extension: add the direct release download URL,
document make_latest:false / tag-pinned design. TODO/WIP: mark the
webext-v0.1.0 release published (downloadable, verified) and note the
remaining board deploy of secubox-toolbox 2.6.14.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 11:29:06 +02:00
CyberMind
008da01444
Merge pull request #541 from CyberMind-FR/feature/532-plan-browser-xpi-webextension-emancipate
Some checks are pending
License Headers / check (push) Waiting to run
Tag-pinned .xpi release URL — don't steal "latest" from the APK (#532)
2026-06-13 10:57:16 +02:00
68e2723747 fix(webext): tag-pinned .xpi release URL + make_latest:false (ref #532)
Publishing webext-v* with the default make_latest would steal the
"latest" release pointer from the Android APK release, breaking the
APK endpoint's /releases/latest/download/secubox-toolbox-android.apk
fallback. Publish the webext release with make_latest:false and point
the /wg/toolbox.xpi endpoint + fetch helper at the tag-pinned download
URL instead.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 10:45:40 +02:00
CyberMind
b8da257b83
Merge pull request #540 from CyberMind-FR/feature/532-plan-browser-xpi-webextension-emancipate
Some checks are pending
License Headers / check (push) Waiting to run
Browser extension: emancipate R3 toolbox cartographie live (#532)
2026-06-13 10:33:01 +02:00
b2ee2a97ef fix(webext): clean web-ext lint — drop unused optional_host_permissions, ignore build.sh/README (ref #532)
web-ext lint: 0 errors, 2 benign warnings (AMO data-collection
declaration is submission-time, tied to the signing follow-up;
service_worker-ignored is the intentional cross-browser pattern).
optional_host_permissions needed FF128 and was unused at MVP.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 10:21:45 +02:00
c77e6250a9 feat(webext): browser extension — emancipate R3 cartographie live (ref #532)
New client clients/webext-toolbox/ (WebExtension MV3, Firefox .xpi +
Chromium): surfaces the toolbox live tracker analysis in the browser.

- manifest.json MV3, cross-browser background (service_worker + scripts
  for Firefox 115+ event page); host_permissions *.secubox.in only
- api.js: shared client over /wg/r3-check, /social/me (pair → HMAC token),
  /social/graph/{token}, /social/wipe/{token}
- background.js: toolbar badge = live tracker count, silent re-pair on
  token expiry, colour escalates gold → anti-bot → operator-grade
- popup: 4 stat tiles + dependency-free mini Round-Eye SVG graph + top
  trackers tagged CDN/anti-bot/operator-grade + cartographie/PDF/RGPD-wipe
- options: host / analysis window / manual token
- build.sh + build-webext.yml (web-ext lint + build, release on webext-v*)

Serve from the toolbox (2.6.14):
- GET /wg/toolbox.xpi (local file, else 302 → latest release asset)
- '🧩 Extension navigateur' button on both onboard panels
- sbin/secubox-toolbox-fetch-xpi + postinst serve dir + rules install

No server-side CORS needed (MV3 host_permissions). MVP polls /social/graph
and computes the delta client-side; SSE /social/live is a follow-up.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 10:08:06 +02:00
CyberMind
e7a84f0380
Merge pull request #491 from CyberMind-FR/feature/490-phase-2c-toolbox-receiving-modules-actua
Some checks are pending
License Headers / check (push) Waiting to run
feat(phase-2c): receiving modules enrichment (nDPI-style classify, JA4 fingerprint, providers, avatar)
2026-06-13 08:19:50 +02:00
e67baf4cd7 feat(secubox-core+5modules+toolbox): Phase 2c receiving modules enrichment (ref #490)
Phase 2b (#488/#489) wired mitm addons to 5 receiving modules but events
were persisted raw. This phase implements actual enrichment in each module
via the enrich_hook param, plus aggregator merge so reports show meaningful
data (YouTube/Signal/iPhone/Safari/JA4 fingerprints) instead of raw bytes.

  - host_app.py  : 60+ host patterns -> app + category + emoji
  - cookie.py    : 40+ cookie tracker patterns -> provider + category + emoji
  - avatar.py    : UA + Client Hints -> device + browser + OS + emoji
  - ja4.py       : NEW. Deterministic JA4-style fingerprint hash from
                   cipher_suites + alpn + extensions. Lookup table for
                   known JA4 fingerprints (empty for now, Phase 3 will
                   populate). 12-char hex (SHA256 truncated).

The host_app/cookie/avatar are copies of the secubox-toolbox classifiers
moved to secubox-core so all 5 receiving modules can import them. The
secubox-toolbox-local ones stay as-is to avoid breaking changes — Phase 3
will consolidate.

  - secubox-dpi             : host/SNI -> {app, category, emoji}
  - secubox-cookies         : cookie names -> {providers{}, categories{}}
  - secubox-avatar          : UA + CH -> {device, browser, os_label}
  - secubox-threat-analyst  : ClientHello -> {ja4_fingerprint, known_client}
  - secubox-soc             : indicators -> {total_weight, band, kinds}

Each is ~25 lines, called by mount_ingest_routes BEFORE persistence.
Enriched output joins the raw event under the 'enriched' key.

_pull_mitm_module_events() now also calls _summarize_enriched(kind, events)
to consolidate per-module enrichment :

  - dpi             : top_apps[] aggregated from enriched.app counts
  - cookies         : top_providers[] from enriched.providers + tracker_total
  - avatar          : devices{} + browsers{} from enriched.{device,browser}
  - threat-analyst  : top_fingerprints[] grouped by JA4 hash
  - soc             : total_weight + max_band + indicator_kinds

These appear under mitm_modules.<kind>.enriched_summary in the /report JSON.

POST realistic payloads to all 5 sockets :
  - YouTube host -> dpi/enriched.app = 'YouTube' (streaming)
  - GA + FB Pixel cookies -> cookies/providers : GA x3, FB x1, total 4
  - iPhone Safari UA -> avatar/device='iPhone' (📱 iOS 17.4) + Safari (🧭)
  - facebook.com ClientHello -> threat-analyst/ja4 = '7175ee3a68f0'
  - 2 indicators (weight 15+25) -> soc/band='medium', total=40, kinds=[dga, suspicious]

  - secubox-dpi : call live nDPI/netifyd socket (currently pattern-match only)
  - secubox-threat-analyst : implement full FoxIO JA4 string format (currently
    deterministic SHA256 trunc which is JA4-like but not the canonical format)
  - secubox-soc : threat-intel feed lookup (currently just sums static weights)
  - secubox-avatar : screen/timing fingerprinting via WebGL hash (currently UA only)
  - Reports (PDF + HTML) : surface mitm_modules.enriched_summary in the report UI
2026-06-13 08:00:18 +02:00
CyberMind
110133bee9
Merge pull request #539 from CyberMind-FR/feature/538-android-app-root-mode-fully-automated-si
Some checks are pending
License Headers / check (push) Waiting to run
Android root-mode fully-automated silent R3 onboarding (#538)
2026-06-13 07:47:00 +02:00
ac14e65353 docs: wiki/README/WIP/TODO/HISTORY for Android ToolBox app + root-mode (ref #538)
- new wiki page Android-ToolBox.md (install via /wg/toolbox.apk, manual +
  root onboarding flows, CI build, endpoints) + sidebar link
- README: document the root-mode silent path + revised constraints
- WIP/TODO/HISTORY: Android client section (#531/#536/#538)

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 07:46:50 +02:00
1351054927 feat(android): root-mode fully-automated silent R3 onboarding (ref #538)
Add an optional one-tap, zero-interaction onboarding path for rooted
devices. When root is detected the app can:

- install the village3b CA into the SYSTEM trust store (bind-mount over
  /system/etc/security/cacerts + conscrypt APEX, SELinux ctx restored),
  so every app trusts the cabine CA — not just user-CA opt-in apps;
- bring the WireGuard tunnel up natively via the kernel module
  (ip link add … type wireguard + wg set), no WireGuard app needed;
- verify R3 reachability automatically.

Falls back to the existing manual handoff (KeyChain CA prompt + WG app)
when the kernel lacks WireGuard. All root actions are gated behind an
explicit ' Installation automatique (root)' tap — nothing runs as root
without the operator choosing it on their own device.

New: RootShell (su wrapper), RootOnboard (silent sequence + subject_hash_old
in pure Kotlin). MainActivity gains a RootAuto step with a streaming log.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
2026-06-13 07:40:58 +02:00
CyberMind
46dfd781d3
Merge pull request #537 from CyberMind-FR/feature/536-serve-the-android-toolbox-apk-from-the-t
Some checks are pending
License Headers / check (push) Waiting to run
feat(toolbox): serve Android APK from /wg/toolbox.apk + onboard button (#536)
2026-06-12 23:46:50 +02:00
cf3aef48c8 feat(toolbox): serve Android APK from /wg/toolbox.apk + onboard button (#536)
Follow-up to #531 — one-tap APK install from the cabine.
  - api.py GET /wg/toolbox.apk: serve local APK (android content-type),
    302 → latest GitHub release asset if absent (never dead-ends).
  - /wg/onboard Android panels (inline + _install_panels): 📱 Installer
    l'app ToolBoX (1-tap) button.
  - sbin/secubox-toolbox-fetch-apk: pull latest release asset into the
    serve path (best-effort + APK magic check); postinst creates the dir
    + first fetch.
  - build-android-apk.yml: publish APK as release asset
    secubox-toolbox-android.apk on android-v* tags (contents:write).
  - changelog 2.6.13.

Live on gk2: /wg/toolbox.apk 302 → release (fallback, no release yet),
serve dir created, onboard button rendered.
2026-06-12 23:46:29 +02:00
CyberMind
198fecea11
Merge pull request #535 from CyberMind-FR/feature/531-plan-android-apk-one-tap-toolbox-r3-clie
Some checks are pending
License Headers / check (push) Waiting to run
feat(android): one-tap toolbox R3 installer scaffold + CI (#531)
2026-06-12 23:27:34 +02:00
ab67c981dd feat(android): scaffold one-tap toolbox R3 installer + CI (ref #531)
Kotlin/Jetpack-Compose app under clients/android-toolbox/ replacing the
manual Android onboarding tutorial. 5-step flow:
  discover -> install CA (KeyChain intent) -> import WG profile (handed
  to the WireGuard app via FileProvider) -> verify (/wg/r3-check) ->
  live cartographie sociale (/social/me).

  - ToolboxApi: plain HttpURLConnection client for /wg/ca.crt,
    /wg/profile/new, /wg/r3-check, /social/me (no Retrofit/OkHttp —
    minimal deps + CI).
  - MainActivity: Compose stepper UI, palette-matched (cosmos/gold/cyan),
    FR copy. Intents for CA install + WireGuard handoff + Play fallback.
  - Gradle (AGP 8.5.2 / Kotlin 1.9.24 / Compose BOM 2024.06), minSdk 26,
    targetSdk 34, package in.secubox.toolbox. No wrapper jar committed.
  - res: adaptive launcher icon (vector eye glyph), theme, file_paths,
    strings — all text/XML, no binaries.
  - .github/workflows/build-android-apk.yml: setup-android + setup-gradle
    8.9 build assembleDebug -> APK artifact (sideloadable).
  - README documents the flow, build, and the Android user-CA-trust
    constraint (MVP guides manual confirm; release signing is follow-up).

Closes the scaffold half of #531; CI produces the debug APK.
2026-06-12 18:15:46 +02:00
CyberMind
92dee2d2d0
Merge pull request #534 from CyberMind-FR/feature/529-admin-wireguard-tunnel-wg-admin-for-secu
Some checks are pending
License Headers / check (push) Waiting to run
feat: admin WireGuard tunnel (wg-admin) + SSH hardening (#529)
2026-06-12 17:45:16 +02:00