Commit graph

591 commits

Author SHA1 Message Date
Franco Fichtner
38e6614831 www/nginx: new version 2026-01-20 12:59:16 +01:00
Franco Fichtner
81f3e21a1a www/squid: remove old link reference; closes #9537 2025-12-18 10:31:39 +01:00
Franco Fichtner
b943ea34a7 www/nginx: bump model version 2025-12-17 12:08:50 +01:00
Jan Chlouba
dcaf201b0c
nginx: add optional HTTP/3 support with dynamic Alt-Svc (#5071) 2025-12-17 10:30:41 +01:00
Franco Fichtner
e591bd7e5a www/web-proxy-sso: style 2025-12-09 15:28:09 +01:00
Franco Fichtner
c8a35ea27b www/squid: style 2025-12-09 15:27:43 +01:00
Franco Fichtner
c93a745e72 www/c-icap: style 2025-12-09 15:27:17 +01:00
Franco Fichtner
e71840b1ff www/web-proxy-sso: switch to ummaintained instead of obsolete for now
PR: https://github.com/opnsense/plugins/commit/6450cbcaca3
2025-12-09 14:51:31 +01:00
Monviech
ec2181d8a3
www/caddy: Fix race condition that moved domain filter selectpicker into invisible tab, fix css (#5076) 2025-12-08 17:09:31 +01:00
Franco Fichtner
94a21efccc www/OPNProxy: same here 2025-12-04 09:26:01 +01:00
Franco Fichtner
e3bf36a2ec plugins: remove a few of my historic maintainerships
These plugins have had maintainership attached due to the fact
that they became plugins at one point in time.  Since we can now
annotate this better, do it.
2025-12-04 09:19:37 +01:00
Franco Fichtner
6450cbcaca www/web-proxy-sso: very old and likely unused nowadays 2025-12-04 09:16:24 +01:00
Ad Schellevis
fafe14b7bd www/squid - remove references to firewall_nat.php as this will go away shortly and we don't plan to re-add a similar template for this.
ref: https://github.com/opnsense/core/issues/8401
2025-11-30 11:13:35 +01:00
Franco Fichtner
a92fe03b6a www/nginx: one more refactor revision bump 2025-11-20 09:46:06 -05:00
Monviech
840714060e
www/caddy: Add changelog for sudo fix (#5036) 2025-11-18 21:28:19 +01:00
Franco Fichtner
2e56601903 www/OPNProxy: switch to mwexecf() use 2025-11-17 21:47:57 -05:00
Franco Fichtner
9f23ada61d www/caddy: revision bump after trust store vs. sudo fix 2025-11-17 21:43:17 -05:00
Franco Fichtner
b50c0c3daa www/nginx: another change here 2025-11-17 21:42:47 -05:00
Monviech
0152180865
www/caddy: Prevent sudo on startup via skip_install_trust (#5015)
This can happen when an internal domain has been added, e.g. example.internal. Caddy will then generate a self signed certificate via smallstep CA, and on startup it tries to install a root certificate for it into the FreeBSD trust store.

If running as www user, this causes sudo to appear at boot, because that is baked into smallstep CA.

https://github.com/smallstep/truststore/blob/master/truststore_freebsd.go

Via skip_install_trust, we prevent caddy from trying this.
2025-11-10 17:01:03 +01:00
Franco Fichtner
7ceccc441b www/nginx: use mwexecf
PR: https://github.com/opnsense/core/issues/9325
2025-10-28 15:26:04 +01:00
Franco Fichtner
04a0f55879 www/squid: use short version as discussed 2025-10-21 08:36:32 +02:00
Franco Fichtner
68c34f4f0b www/squid: annotate fix contribution 2025-10-20 16:15:34 +02:00
Michael
d9dea7f9cc
www/squid: add email_err_data off as static (#4987) 2025-10-20 15:08:50 +02:00
Monviech
e19e3c94f6
www/caddy: fix setup.sh script not setting correct ownership in www user mode (#4976)
* www/caddy: Streamline setup.sh, since chown is skipped automatically when ownership matches

* add changelog
2025-10-11 14:02:48 +02:00
Monviech
a9c5f61850
www/caddy: Bump version to 2.0.4_1 (#4975) 2025-10-10 16:11:20 +02:00
Monviech
bcd2deb43e
www/caddy: Fix HTTP access log excluding the process logs accidentally (#4974)
When using "include" in the default global logger, all other logs get excluded, except those that get included.

Using a "log default" instead, sends the HTTP access logs to the default logger.

This allows process and HTTP access logs to coexist in the same logger.
2025-10-10 16:05:31 +02:00
Franco Fichtner
613df67b2f www/nginx: why not 2025-10-08 09:13:33 +02:00
kulikov-a
3f9299b3aa
naxsi rules install fix (#4968)
regex adapted
removed redundant validation (validated on serialization)
skip validation on serialization
2025-10-06 09:20:49 +02:00
Monviech
97603fc29b
www/caddy: Bump plugin version to 2.0.4 (#4954) 2025-09-24 17:59:44 +02:00
sdsys-ch
b2401a695c
www/caddy: Add DNS-01 challenge delegation via CNAME (#4950)
* caddy: Add DNS-01 override domain feature

Adds support for DNS-01 CNAME delegation through the dns_challenge_override_domain directive. This enables least-privilege DNS setups where the certificate domain delegates ACME challenges to a target domain managed by the configured DNS provider.

* Review feedback: Remove default defs and align validation string with existing one

---------

Co-authored-by: Christophe Neuerburg <c.neuerburg@sdsys.ch>
2025-09-24 08:45:05 +02:00
Franco Fichtner
45b48a6aeb www/nginx: cleanup 2025-09-16 14:57:09 +02:00
kulikov-a
99dfc67984
www/nginx: 1.35_1 hotfix. change ban_ttl default (#4937) 2025-09-16 14:56:04 +02:00
Franco Fichtner
3f298fc57f www/caddy: fix for #4930
Best practice vs. reality, flagged in code audit but reality had other plans.
2025-09-09 19:33:00 +02:00
Franco Fichtner
439e6f9b26 www/nginx: style sweep 2025-09-09 08:02:22 +02:00
Franco Fichtner
6c66db83c7 www/nginx: clean up model
Some elaborate defaults were not used. They look kind of useful, but
also suggest maintenance nightmares (default cipher list), so let's
get rid of them.
2025-09-06 18:52:31 +02:00
kulikov-a
d9e74df9eb
nginx_1.35 (#4600) 2025-09-06 18:32:23 +02:00
Monviech
2c4e372109
www/caddy: Fix subdomain http access log (#4919)
* www/caddy: Emit subdomain http access logs in the same log collector as their wildcard parent

* add changelog
2025-09-02 09:52:37 +02:00
Monviech
a691165cee
www/caddy: Fix setup.sh script interaction with files and directories in caddy storage (#4911)
* www/caddy: Fix setup.sh script interaction with files and directories in caddy storage

This fixes multiple things:
- When running as www:www user, the interaction with the admin socket could fail, now we do not touch /var/run/caddy and let it be handled by the permissions set in the rc.d script
- When restarting/reloading caddy, permissions and ownerships would be changed every time, possibly breaking the storage if caddy writes at the same time
- The custom certificates are now stored outside the scope of the caddy storage, ensuring caddy has atomic write guarantee on /var/db/caddy/data...

* Fix some review comments

* add changelog
2025-09-02 09:26:22 +02:00
Franco Fichtner
034e337747 www/squid: new version 2025-08-29 08:41:19 +02:00
Monviech
e0897e1430
www/caddy: Implement tabulator groupBy, fix tabulator 'Data Load Response Blocked' warning, remove unnecessary HTML (#4909)
* www/caddy: Implement tabulator groupBy into subdomain and handlers tabs, modernize style and html

* www/caddy: Fix search endpoints being fired multiple times on initial page load, and when using the command buttons. This fixes some tabulator warnings and improves performance.

* www/caddy: Bump version to 2.0.3 and add changelog
2025-08-23 15:34:23 +02:00
Franco Fichtner
bc94cb0298 www/squid: small lint pass 2025-08-21 08:25:32 +02:00
Franco Fichtner
9f69e909c2 www/squid: make this plugin a community user of contrib dir support 2025-08-20 17:16:22 +02:00
Franco Fichtner
95162ce51d plugins: fix changelog styling
No GitHub handles, looks like broken mail addresses.  ;)
2025-08-13 09:57:14 +02:00
KS
2244a20843
nginx: fix PHP 8.2+ deprecation warnings (#4872)
* fix PHP 8.2+ deprecation warnings

* revision bump
2025-08-05 17:05:23 +02:00
Franco Fichtner
6c13dfb82e www/caddy: try new lint inclusion and address complaints 2025-07-29 10:28:27 +02:00
Franco Fichtner
fc15874002 www/c-icap: update version 2025-07-28 09:42:38 +02:00
Andy Binder
8439492503
www/c-icap: Define localserver acl once. (#4836)
* www/c-icap: Define localserver acl once.

* www/c-icap: Change maintainer.
2025-07-25 19:18:06 +02:00
Franco Fichtner
6da8598a6b www/nginx: document this change 2025-07-17 08:26:31 +02:00
Monviech
b7959fddb5 www/squid: Fix camelCase API endpoint notation for https://github.com/opnsense/plugins/commit/ef2e005e8 2025-07-15 11:05:12 +02:00
Monviech
9b31fedd44
www/caddy: Remove obsolete model_relation_domain formatter (#4813)
* www/caddy: Remove obsolete model_relation_domain formatter

* www/caddy: Bump revision and changelog
2025-07-15 09:58:13 +02:00