Skip to content

Commit 1f9a299

Browse files
committed
Keep router credentials out of WebUI config
1 parent daabb6c commit 1f9a299

2 files changed

Lines changed: 364 additions & 50 deletions

File tree

‎MerlinAU.asp‎

Lines changed: 40 additions & 26 deletions
Original file line numberDiff line numberDiff line change
@@ -1521,10 +1521,23 @@ const loginPassword =
15211521
};
15221522
15231523
/**----------------------------------------**/
1524-
/** Modified by Martinski W. [2025-Jun-01] **/
1524+
/** Modified by maghuro [2026-Sep-24] **/
15251525
/**----------------------------------------**/
15261526
function ValidatePasswordString (formField, eventID)
15271527
{
1528+
if (formField.value.length === 0 &&
1529+
custom_settings &&
1530+
custom_settings.credentialsStored === 'ENABLED')
1531+
{
1532+
loginPassword.pswdStr = '';
1533+
loginPassword.pswdLen = 0;
1534+
loginPassword.pswdFocus = false;
1535+
loginPassword.pswdInvalid = false;
1536+
$(formField).removeClass('Invalid');
1537+
$(formField).off('mouseover');
1538+
return true;
1539+
}
1540+
15281541
if (loginPassword.ValidateString(formField, eventID))
15291542
{
15301543
$(formField).removeClass('Invalid');
@@ -2053,9 +2066,9 @@ function BlockChangelog()
20532066
document.form.submit();
20542067
}
20552068
2056-
/**------------------------------------------**/
2057-
/** Modified by ExtremeFiretop [2025-May-18] **/
2058-
/**------------------------------------------**/
2069+
/**----------------------------------------**/
2070+
/** Modified by maghuro [2026-Sep-24] **/
2071+
/**----------------------------------------**/
20592072
function InitializeFields()
20602073
{
20612074
console.log("Initializing fields...");
@@ -2101,10 +2114,11 @@ function InitializeFields()
21012114
{
21022115
if (routerPassword)
21032116
{
2104-
if (custom_settings.routerPassword === 'TBD')
2105-
{ routerPassword.value = ''; }
2117+
routerPassword.value = '';
2118+
if (custom_settings.credentialsStored === 'ENABLED')
2119+
{ routerPassword.placeholder = 'Stored password - leave blank to keep'; }
21062120
else
2107-
{ routerPassword.value = custom_settings.routerPassword; }
2121+
{ routerPassword.placeholder = 'Enter password'; }
21082122
}
21092123
loginUsername = usernameElem ? usernameElem.value.trim() : 'admin';
21102124
loginPswdHint = loginPswdStatHintMsg.replace (/LoginUSER/, loginUsername);
@@ -2381,7 +2395,7 @@ function GetConfigSettings()
23812395
}
23822396
23832397
/**----------------------------------------**/
2384-
/** Modified by Martinski W. [2025-Feb-23] **/
2398+
/** Modified by maghuro [2026-Sep-24] **/
23852399
/**----------------------------------------**/
23862400
// Helper function to assign settings based on key //
23872401
function AssignAjaxSetting (keyName, keyValue)
@@ -2453,17 +2467,12 @@ function AssignAjaxSetting (keyName, keyValue)
24532467
break;
24542468
24552469
case keyUpper === 'CREDENTIALS_BASE64':
2456-
try
2457-
{
2458-
var decoded = atob(keyValue);
2459-
var separatorIndex = decoded.indexOf(':');
2460-
var password = (separatorIndex >= 0) ? decoded.slice(separatorIndex + 1) : '';
2461-
ajax_custom_settings.routerPassword = password;
2462-
}
2463-
catch (e)
2464-
{
2465-
console.error("Error decoding credentials_base64:", e);
2466-
}
2470+
// The real credential is kept in protected server-side storage. //
2471+
ajax_custom_settings.routerPassword = '';
2472+
break;
2473+
2474+
case keyUpper === 'CREDENTIALS_STORED':
2475+
ajax_custom_settings.credentialsStored = convertToStatus(keyValue);
24672476
break;
24682477
24692478
case keyUpper === 'ROGBUILD':
@@ -2613,7 +2622,7 @@ function initial()
26132622
}
26142623
26152624
/**----------------------------------------**/
2616-
/** Modified by Martinski W. [2025-Mar-07] **/
2625+
/** Modified by maghuro [2026-Sep-24] **/
26172626
/**----------------------------------------**/
26182627
function SaveCombinedConfig()
26192628
{
@@ -2682,20 +2691,22 @@ function SaveCombinedConfig()
26822691
let fwUpdateRawCronSchedule = custom_settings.FW_New_Update_Cron_Job_Schedule;
26832692
fwUpdateRawCronSchedule = FWConvertWebUISettingsToCronSchedule(fwUpdateRawCronSchedule);
26842693
2685-
// Encode credentials in Base64 //
2686-
var credentials = usernameStr + ':' + passwordElem.value;
2687-
var encodedCredentials = btoa(credentials);
2688-
26892694
// Build the Actions settings object //
26902695
var action_settings =
26912696
{
2692-
credentials_base64: encodedCredentials,
26932697
FW_New_Update_Cron_Job_Schedule: fwUpdateRawCronSchedule,
26942698
FW_New_Update_Postponement_Days: document.getElementById('fwUpdatePostponement')?.value || '0',
26952699
CheckChangeLog: document.getElementById('changelogCheckEnabled').checked ? 'ENABLED' : 'DISABLED',
26962700
FW_Update_Check: document.getElementById('FW_AutoUpdate_Check').checked ? 'ENABLED' : 'DISABLED'
26972701
};
26982702
2703+
// Only send credentials when the user actually entered a replacement password. //
2704+
if (passwordElem.value.length > 0)
2705+
{
2706+
var credentials = usernameStr + ':' + passwordElem.value;
2707+
action_settings.credentials_base64 = btoa(credentials);
2708+
}
2709+
26992710
// Prefix Actions settings //
27002711
var prefixedActionSettings = PrefixCustomSettings(action_settings, 'MerlinAU_');
27012712
@@ -2796,7 +2807,10 @@ function SaveCombinedConfig()
27962807
/**==============================**/
27972808
// Merge shared settings with prefixed Action and Advanced settings //
27982809
var updatedSettings = Object.assign({}, shared_custom_settings, prefixedActionSettings, prefixedAdvancedSettings);
2799-
ConsoleLogDEBUG("Combined Config Form submitted with settings:", updatedSettings);
2810+
var debugSettings = Object.assign({}, updatedSettings);
2811+
if (debugSettings.MerlinAU_credentials_base64)
2812+
{ debugSettings.MerlinAU_credentials_base64 = '[REDACTED]'; }
2813+
ConsoleLogDEBUG("Combined Config Form submitted with settings:", debugSettings);
28002814
28012815
// Save merged settings to the hidden input field //
28022816
document.getElementById('amng_custom').value = JSON.stringify(updatedSettings);

0 commit comments

Comments
 (0)