summaryrefslogtreecommitdiffstats
path: root/themes/luci-theme-footstrap/root/etc/uci-defaults/30_luci-theme-footstrap
blob: 8e4925733e1dfdbca247cc82e63289be85aad8e5 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
#!/bin/sh

# Registration, plus the two symlinks that expose what the admin uploads (a third, the pattern, is
# deliberately NOT one — see below). Nothing here migrates a router off an older footstrap: OpenWrt
# expects a sysupgrade rather than a package upgrade — the one exception is the stale pattern
# symlink itself, removed below because leaving it would keep a reported security hole open.

changed=0

set_opt() {
	uci -q get "luci.$1" >/dev/null 2>&1 && return
	uci set "luci.$1=$2"
	changed=1
}

set_opt themes.Footstrap /luci-static/footstrap

# A fresh install may pick the theme; an upgrade must never move a router off the theme it is on.
# `changed` is what tells the two apart — on an upgrade the entry is already there — and it has to
# carry the decision alone, because apk exports no PKG_UPGRADE.
if [ "${PKG_UPGRADE:-}" != 1 ] && [ "$changed" = 1 ]; then
	set_opt main.mediaurlbase /luci-static/footstrap
fi

[ "$changed" = 1 ] && uci commit luci

# uhttpd serves /www only, so the admin's uploads live in /etc — where a sysupgrade keeps them
# (lib/upgrade/keep.d) — and are reached through symlinks, EXCEPT the pattern (below).
#
# The pattern is deliberately NOT symlinked into /www: an SVG is a document, and served as one
# through a plain same-origin URL it runs as a script with the admin's session (OpenWrt forum
# thread 251930). It is instead read by cgi-bin/luci-theme-footstrap-pattern, which answers with
# CSP 'none' + sandbox and nosniff — headers uhttpd cannot attach to a static file. It needs its
# .svg name to paint at all, so octet-stream is not open to it.
#
# The login background stays a plain symlink, and NOT because of what the browser did to the
# bytes: the ACL authorises the cgi-upload POST whatever wrote it, so fs-assets.js's canvas
# re-encode is compression and EXIF removal, not a boundary (it says so itself). What keeps a
# direct open inert is the extension-less name — uhttpd types the response by extension and
# answers application/octet-stream, which a browser downloads instead of running as a document.
mkdir -p /etc/footstrap
if [ -d /www/luci-static/footstrap ]; then
	ln -sf /etc/footstrap/login-bg /www/luci-static/footstrap/bg
	ln -sfn /etc/footstrap/fonts /www/luci-static/footstrap/fonts
fi
# Clean up a pre-0.14.13 install's stale pattern symlink — see the header comment above for why this
# is the one migration this script makes. `-L` only: never remove a real file some other install
# step could have left at that path.
[ -L /www/luci-static/footstrap/pattern.svg ] && rm -f /www/luci-static/footstrap/pattern.svg

exit 0