91 lines
3.2 KiB
Bash
Executable File
91 lines
3.2 KiB
Bash
Executable File
#!/usr/bin/env bash
|
|
# Install patched backone + webhub and verify secure-chat prerequisites.
|
|
# Run: sudo ./scripts/install-secure-chat-deps.sh
|
|
set -euo pipefail
|
|
|
|
ROOT="$(cd "$(dirname "$0")/.." && pwd)"
|
|
BACKONE_REPO="${BACKONE_REPO:-$ROOT/../BackOne}"
|
|
|
|
if [[ "${EUID}" -ne 0 ]]; then
|
|
echo "Run with sudo: sudo $0" >&2
|
|
exit 1
|
|
fi
|
|
|
|
if [[ ! -x "${BACKONE_REPO}/backone" ]]; then
|
|
echo "Building BackOne in ${BACKONE_REPO}..." >&2
|
|
make -C "${BACKONE_REPO}" -j"$(nproc)" one
|
|
fi
|
|
|
|
echo "Installing backone $("${BACKONE_REPO}/backone" -v)..."
|
|
systemctl stop backone
|
|
install -m 755 "${BACKONE_REPO}/backone" /usr/sbin/backone
|
|
systemctl start backone
|
|
|
|
echo "Installing backone-webhub..."
|
|
install -m 755 "${BACKONE_REPO}/addons/webhub/backone-webhub" /usr/lib/backone/addons/webhub/backone-webhub
|
|
systemctl restart backone-webhub
|
|
|
|
sleep 2
|
|
TOKEN="$(cat /var/lib/backone/authtoken.secret)"
|
|
PORT="$(cat /var/lib/backone/backone.port 2>/dev/null || echo 9993)"
|
|
|
|
echo ""
|
|
echo "Verifying installed binaries match git build..."
|
|
if cmp -s "${BACKONE_REPO}/backone" /usr/sbin/backone; then
|
|
echo " backone: OK"
|
|
else
|
|
echo " backone: MISMATCH" >&2
|
|
fi
|
|
if cmp -s "${BACKONE_REPO}/addons/webhub/backone-webhub" /usr/lib/backone/addons/webhub/backone-webhub; then
|
|
echo " webhub: OK"
|
|
else
|
|
echo " webhub: MISMATCH" >&2
|
|
fi
|
|
|
|
echo ""
|
|
echo "Verifying comms API..."
|
|
for path in "/app/api/webrtc-config" "/controller/comms/ping?host=127.0.0.1"; do
|
|
code="$(curl -s -o /dev/null -w '%{http_code}' -H "X-ZT1-Auth: ${TOKEN}" "http://127.0.0.1:${PORT}${path}")"
|
|
echo " ${path} -> HTTP ${code}"
|
|
done
|
|
|
|
echo ""
|
|
echo "Verifying relay accepts private-IP POST without auth..."
|
|
code="$(curl -s -o /dev/null -w '%{http_code}' -X POST -H 'Content-Type: application/json' \
|
|
-d '{"networkId":"0000000000000000","senderId":"0000000000","senderName":"t","targetId":"0000000000","body":"t","at":1}' \
|
|
"http://127.0.0.1:${PORT}/controller/comms/chat/relay")"
|
|
echo " POST /controller/comms/chat/relay (no auth) -> HTTP ${code}"
|
|
if [[ "$code" != "200" ]]; then
|
|
echo " WARN: relay no-auth check failed — cross-peer delivery may not work" >&2
|
|
fi
|
|
|
|
echo ""
|
|
echo "Secure Chat cross-host settings (add to /var/lib/backone/local.conf on EACH peer):"
|
|
echo ' "settings": {'
|
|
echo ' "webhubBind": "overlay",'
|
|
echo ' "webhubAllowOverlayChat": true'
|
|
echo ' }'
|
|
echo "Then: systemctl restart backone-webhub"
|
|
echo ""
|
|
|
|
WEBHUB_PORT="$(python3 -c "
|
|
import json, os
|
|
p = '/var/lib/backone/local.conf'
|
|
try:
|
|
s = json.load(open(p)).get('settings') or {}
|
|
print(int(s.get('webhubPort', 9994)))
|
|
except Exception:
|
|
print(9994)
|
|
" 2>/dev/null || echo 9994)"
|
|
echo "Verifying webhub listen address (port ${WEBHUB_PORT})..."
|
|
if command -v ss >/dev/null 2>&1; then
|
|
ss -tlnp 2>/dev/null | grep ":${WEBHUB_PORT} " || echo " WARN: webhub not listening on port ${WEBHUB_PORT}" >&2
|
|
elif command -v netstat >/dev/null 2>&1; then
|
|
netstat -tlnp 2>/dev/null | grep ":${WEBHUB_PORT} " || echo " WARN: webhub not listening on port ${WEBHUB_PORT}" >&2
|
|
fi
|
|
|
|
systemctl --no-pager status backone backone-webhub | sed -n '1,12p'
|
|
echo ""
|
|
echo "Done. Run the SAME script on every peer machine (e.g. c52b90363c)."
|
|
echo "Then restart BackOneUI and open Secure Chat on the recipient."
|