Repository navigation
fix: splash stub clientmac passthrough + NDS session timeout config - #363
Conversation
E2E Test Evidence (physical router, OpenWrt 24.10.4 GL-MT3000)Deployed both fixes from this PR to a physical test router and verified live. 1. Splash stub clientmac passthrough ✅Router file location.replace("http://" + location.hostname + ":2051/splash.html" + location.search);
2. NDS session timeout ✅Go backend now controls session lifetime — users who buy 1h no longer get kicked at 20min by NDS defaults. Playwright E2E (video)End-to-end flow through the redirect chain recorded: Portal + balance page screenshots: Unit tests
Test files: evidence/2026-08-27-portal-fixes/ |
|
Correction: earlier evidence was captured in degraded mode — replaced with full-mode proof (upstream online, mints reachable). The previous evidence run (comment) was taken while the test router had no upstream internet, so the deployed backend returned Backend mint probe recovery (from the router):
Router online proof ( E2E rerun in full mode — 2/2 PASS (backend gate baked into the test:
New evidence (full mode): Video — Test 2, Cashu tab UX: https://raw.githubusercontent.com/felixfelix-bot/physical-router-test-automation/evidence/portal-fixes-20260827/evidence/2026-08-27-portal-fixes/test2-cashu-tab-ux.mp4 Video — Test 1, Get Access → Cashu tab with live mint list served by the backend: Lightning tab with live pricing: The old evidence files at the same URLs have been overwritten with these full-mode captures; full set + test source: evidence/2026-08-27-portal-fixes (branch |
Rebase of OpenTollGate#363 onto rewritten main — carries only the two captive-portal session fixes: 1. Splash stub redirect appends location.search so the NDS-provided ?clientmac= survives the redirect to the SPA on :2051. 2. setup_nodogsplash() sets sessiontimeout=86400 / authidletimeout=3600 so NDS defaults (1200 s) no longer deauth users mid-session; the Go backend becomes the sole authority on session lifetime. Dropped: deploy-backup-20260730/ (leaked secrets, incident #364), DEPENDS packaging change, pre-commit config, local-build script, token-recovery binary, unrelated go.mod churn. Original-PR: OpenTollGate#363
28163ee to
1ba1646
Compare
|
Thanks for these two fixes — both are real problems we've hit in the lab (our own router backups show NDS Your branch was based on pre-incident history and carried New head
Shell syntax verified; |
|
E2E results (follow-up to review): deployed head
Both fixes validated on-router:
Approving — thanks for the fix. (Lab note: SHC cloud was unavailable for nested-virt reasons, so this ran on the local QEMU virtual lab; the deployed ipk is the CI-built artifact.) |
Amperstrand
left a comment
There was a problem hiding this comment.
Both fixes verified end-to-end on a deployed OpenWrt VM (details in the E2E comment). The SETUP_VERSION-bump note is the only suggestion — merge at your discretion.
Rebase of OpenTollGate#363 onto rewritten main — carries only the two captive-portal session fixes: 1. Splash stub redirect appends location.search so the NDS-provided ?clientmac= survives the redirect to the SPA on :2051. 2. setup_nodogsplash() sets sessiontimeout=86400 / authidletimeout=3600 so NDS defaults (1200 s) no longer deauth users mid-session; the Go backend becomes the sole authority on session lifetime. Dropped: deploy-backup-20260730/ (leaked secrets, incident #364), DEPENDS packaging change, pre-commit config, local-build script, token-recovery binary, unrelated go.mod churn. Original-PR: OpenTollGate#363
aaf7382 to
781ea1d
Compare
…penTollGate#363) Rebase of OpenTollGate#363 onto rewritten main — carries only the two captive-portal session fixes: 1. Splash stub redirect appends location.search so the NDS-provided ?clientmac= survives the redirect to the SPA on :2051. 2. setup_nodogsplash() sets sessiontimeout=86400 / authidletimeout=3600 so NDS defaults (1200 s) no longer deauth users mid-session; the Go backend becomes the sole authority on session lifetime. Dropped: deploy-backup-20260730/ (leaked secrets, incident #364), DEPENDS packaging change, pre-commit config, local-build script, token-recovery binary, unrelated go.mod churn. Original-PR: OpenTollGate#363 Co-authored-by: Amperstrand <amperstrand@users.noreply.github.com>



Summary
Two fixes for captive-portal session handling:
1. Splash stub drops
?clientmac=query paramFile:
packaging/files/etc/uci-defaults/90-tollgate-captive-portal-symlinkThe JavaScript redirect stub did:
NDS appends
?clientmac=XX:XX:…to the splash URL, but the stub dropped it. The SPA on port 2051 then had no MAC to work with, breaking the backend's MAC-based session logic.Fix: Append
location.search:2. NDS
sessiontimeoutdefaults to 1200s (20 min)File:
packaging/files/etc/uci-defaults/99-tollgate-setupsetup_nodogsplash()did not setsessiontimeoutorauthidletimeout. NDS defaults to 1200 seconds (20 min), which deauths users mid-session regardless of the Go backend's purchased duration.Fix: Set large ceilings so the Go backend is the sole authority on session lifetime:
Testing
gofmt -l .— clean (no output)go vet ./...— cleango build ./...— cleango test -race -count=1 -tags testenv ./...— all passNotes
[Unreleased] → Fixed.