Go backend that drives kernel WireGuard over netlink (wireguard-go as the fallback), nftables NAT with MSS clamping, forwarding and buffer sysctls, SQLite for peers, users, sessions, traffic history and the audit log. React console: dashboard with live rates and usage history, peer management with QR codes and .conf downloads, disconnect, session reset, key rotation, expiry, client-supplied keys, settings, users with admin and viewer roles, two-factor authentication with recovery codes, audit log. Docker image on Alpine with compose files for bridged and host networking, CI and GHCR publish workflows, performance notes.
1.9 KiB
1.9 KiB
Security Policy
Supported versions
Security fixes go to main and the next release. Older releases are not
patched.
Reporting a vulnerability
Please do not open a public issue for a security problem. Email johnellisATlinuxDOTcom with what you found, how to reproduce it and what you think the impact is. You will get an acknowledgement within a few days and a fix or a plan before anything is made public.
What WGX does to protect itself
- The admin UI requires a password (argon2id, 64 MiB, 3 passes) and offers
time-based one-time codes with recovery codes. Sessions are random 256-bit
tokens stored hashed,
HttpOnly,SameSite=Strict, with idle and absolute expiry. - Every state-changing request must come from the same origin
(
Sec-Fetch-Site/Originare checked in addition to the cookie policy) and carry a JSON body; the first-run setup endpoint stops working the moment a user exists. - Login is rate-limited per address and per username, and a failed login for an unknown user takes as long as one for a known user.
- Responses carry a strict Content-Security-Policy,
X-Frame-Options: DENY,Referrer-Policy: no-referrerand, under TLS, HSTS. - Peer private keys never appear in list or detail responses; they are only returned through the configuration and QR endpoints, and each view is written to the audit log. The server's own private key never leaves the process.
- The database file is created mode 0600 and the container image contains no shell tooling beyond what nftables and WireGuard need.
What you must do
- Do not expose port 51821 to the internet without TLS. Either set
WGX_TLS_SELF_SIGNED=true(orWGX_TLS_CERT/WGX_TLS_KEY) or put a TLS-terminating reverse proxy in front and list it inWGX_TRUSTED_PROXIESso client addresses in the audit log are right. - Turn on two-factor authentication for every administrator.
- Keep the
/datavolume private: it holds every peer's private key.