Repository navigation
feat: local mobile access over a trusted home network (LAN mode) - #52
Merged
Merged
Conversation
FLIPPER_WEB_SECURITY_MODE=lan reuses the single-user boundary (owner password hash, signed sessions, same-origin checks, throttling, headers) and adds two rules: the TCP peer must be on a loopback/private/link-local network, and the Host may be any private IP literal so the phone URL survives DHCP changes without admitting DNS-rebinding names. The mode refuses to start without both FLIPPER_PASSWORD_HASH and FLIPPER_SESSION_SECRET and rejects FLIPPER_PUBLIC_ORIGIN. Local and hosted behavior is unchanged.
LAN exposure is an explicit command; `uvicorn web.app:app` and the container are unchanged. The command requires FLIPPER_PASSWORD_HASH, generates an in-memory session secret when none is configured (never printed or written), refuses hosted configuration, resolves storage exactly as the web app does, checks the port before serving, and runs one Uvicorn process on 0.0.0.0:8000 (or --port/--bind) without trusting forwarded headers. The startup summary shows the local and phone URLs (default-route private address, else a short fallback list or ipconfig guidance), the database path, and the private-network-only warnings; it never shows secrets. Discovery sends no packets and changes no firewall, router, or interface settings.
The login and app pages link a same-origin manifest (name, standalone display, existing Flipper logo as icon) and an apple-touch-icon. The manifest is a public login asset because browsers fetch it without cookies; it contains no data. CSP gains only manifest-src 'self'. No service worker is registered, so no authenticated or accounting page is cached on the phone.
Deals cards and the deal-detail hero sit in single-column grid tracks on phones, where overflow-wrap:break-word does not reduce min-content width, so a long unbroken token (serial number, model string) widened the page to ~500px at a 375px viewport. Add both headings to the existing overflow-wrap:anywhere list. Found while validating LAN phone access.
New docs/guides/phone-access.md covers setup, the startup summary, finding the private IP, home-screen use, the LAN security model, storage resolution, eBay behavior, troubleshooting, future Tailscale compatibility, and the pre-implementation network audit. Web security, configuration, CLI, deployment, troubleshooting, architecture, README, getting started, and .env.example now describe the lan mode and link the guide.
|
| GitGuardian id | GitGuardian status | Secret | Commit | Filename | |
|---|---|---|---|---|---|
| 37670708 | Triggered | Generic High Entropy Secret | 6889ffd | tests/test_web_lan.py | View secret |
🛠 Guidelines to remediate hardcoded secrets
- Understand the implications of revoking this secret by investigating where it is used in your code.
- Replace and store your secret safely. Learn here the best practices.
- Revoke and rotate this secret.
- If possible, rewrite git history. Rewriting git history is not a trivial act. You might completely break other contributing developers' workflow and you risk accidentally deleting legitimate data.
To avoid such incidents in the future consider
- following these best practices for managing and storing secrets including API keys and other credentials
- install secret detection on pre-commit to catch secret before it leaves your machine and ease remediation.
🦉 GitGuardian detects secrets in your source code to help developers and security teams secure the modern development process. You are seeing this because you or someone else with access to this repository has authorized GitGuardian to scan your pull request.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Use Flipper from a phone on the same trusted Wi-Fi while it keeps running on your own computer with its existing SQLite database and attachments. Nothing is deployed and nothing is exposed to the Internet.
python main.py web lan # 0.0.0.0:8000, sign-in required python main.py web lan --port 8123 --bind 192.168.1.23Audit findings (before implementation)
webCLI command.uvicorn web.app:app --reloadbinds127.0.0.1:8000. Only the container binds0.0.0.0, and it forceshostedmode.FLIPPER_ALLOWED_HOSTS, but it accepted any peer address, including public ones. It also needed manual uvicorn flags and broke when DHCP changed the IP.default-src 'none'would block a manifest.Changes
lansecurity mode (web/security.py):FLIPPER_PUBLIC_ORIGIN.100.64/10.web/lan.py+main.py web lan:FLIPPER_PASSWORD_HASH.--database).SO_EXCLUSIVEADDRUSE, so it also detects a loopback-only listener.proxy_headers=Falseand noServerheader.ipconfigguidance) plus the DB path and safety warnings.manifest.webmanifest(public, since browsers fetch it without cookies),apple-touch-icon, and CSPmanifest-src 'self'. No service worker; pages stayno-store./dealsand deal detail to ~496px at 375px. This was pre-existing and found during validation.docs/guides/phone-access.md, cross-linked from README, web security, deployment, CLI, configuration, troubleshooting, architecture and getting started.No schema change (v14). No eBay behavior change.
Validation
pytest: 891 passed, 4 skipped (baseline onmain: 802 passed, 4 skipped). Newtests/test_web_lan.pyhas 89 tests.ruff check .andruff format --check .clean.mkdocs build --strictclean.git diff --checkclean.