Repository navigation
Configuration Guide
This document provides comprehensive guidance on configuring the Secure Browser project, including installation, setup, and customization options.
- Overview
- Installation
- Configuration File
- Browser-Specific Configuration
- Security Configuration
- Network Configuration
- UI Customization
- Environment Variables
- Advanced Configuration
Secure Browser provides multiple configuration options to customize the browsing experience. Configuration can be done through:
- Command-line arguments
- Configuration files (JSON)
- In-browser settings panels
- Environment variables
- Python 3.7 or higher
- pip (Python package manager)
- Virtual environment (recommended)
git clone <repository-url>
cd secure_browser# Linux/macOS
python3 -m venv .venv
source .venv/bin/activate
# Windows
python -m venv .venv
.venv\Scripts\activatepip install -r requirements.txtpython main.py --helpExpected output:
usage: main.py [-h] [--browser {pyqt5,tkinter,webview,search}]
Secure Browser - A secure web browser implementation
optional arguments:
-h, --help show this help message and exit
--browser {pyqt5,tkinter,webview,search}
Select browser implementation (default: pyqt5)
pip install -r requirements.txt# PyQt5 Browser only
pip install PyQt5>=5.15.0 PyQtWebEngine>=5.15.0
# Tkinter Browser only
pip install tkinterweb>=3.0
# WebView Browser only
pip install pywebview>=4.0# Install system dependencies (Ubuntu/Debian)
sudo apt-get update
sudo apt-get install python3 python3-pip python3-venv
# Install Qt dependencies for PyQt5
sudo apt-get install python3-pyqt5 python3-pyqt5-dev python3-pyqt5.qtwebengine
# Install Tkinter
sudo apt-get install python3-tk# Install Homebrew if not already installed
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/Homebrew/install/HEAD/install.sh)"
# Install Python
brew install python3
# Install Qt dependencies
brew install pyqt5 pyqt5-webengine# Install Python from python.org
# During installation, check "Add Python to PATH"
# Install Qt dependencies
pip install PyQt5 PyQtWebEngineConfiguration is stored in config/user_settings.json.
{
"home_url": "https://search.brave.com/",
"security": {
"https_enforcement": true,
"javascript_enabled": true,
"whitelist": [],
"blacklist": [],
"security_headers": {
"X-Content-Type-Options": "nosniff",
"X-Frame-Options": "DENY",
"Content-Security-Policy": "default-src 'self'; script-src 'self'; object-src 'none';"
},
"user_agent": "default"
},
"proxy": {
"http": "",
"https": ""
},
"vpn_enabled": false,
"bookmarks": []
}- Type: String
- Default: "https://search.brave.com/"
- Description: Default homepage URL
- Example: "https://duckduckgo.com/"
- Type: Boolean
- Default: true
- Description: Automatically add HTTPS prefix to URLs
- Example: true
- Type: Boolean
- Default: true
- Description: Enable JavaScript execution
- Example: false
- Type: Array of strings
- Default: []
- Description: Allowed website URLs (prefix matching)
- Example: ["https://example.com", "https://trusted.org"]
- Type: Array of strings
- Default: []
- Description: Blocked website URLs (prefix matching)
- Example: ["http://malicious.com", "http://phishing.net"]
- Type: Object
- Default: See default configuration
- Description: HTTP security headers
- Example: See Security Headers section
- Type: String
- Default: "default"
- Description: Custom user-agent string
- Example: "Mozilla/5.0 (Windows NT 10.0; Win64; x64)"
- Type: String
- Default: ""
- Description: HTTP proxy URL
- Example: "http://proxy.example.com:8080"
- Type: String
- Default: ""
- Description: HTTPS proxy URL
- Example: "https://proxy.example.com:8080"
- Type: Boolean
- Default: false
- Description: Enable VPN (placeholder for future implementation)
- Example: true
- Type: Array of strings
- Default: []
- Description: Saved bookmark URLs
- Example: ["https://example.com", "https://docs.python.org"]
The PyQt5 browser provides a settings panel accessible via the "Settings" button.
Accessing Settings:
- Click the "Settings" button in the navigation bar
- Modify settings in the dialog
- Click "Save" to apply changes
Available Settings:
- VPN Toggle: Enable/disable VPN (placeholder)
- JavaScript Checkbox: Enable/disable JavaScript
- Proxy Input: Configure proxy server
from src.browsers.hope import Browser
from PyQt5.QtWidgets import QApplication
import sys
app = QApplication(sys.argv)
browser = Browser()
# Set configuration programmatically
browser.use_vpn = False
browser.enable_javascript = True
browser.proxy = "http://proxy.example.com:8080"
browser.show()
sys.exit(app.exec_())The Tkinter browser provides a comprehensive settings window.
Accessing Settings:
- Click the "⚙ Settings" button
- Navigate to configuration sections
- Apply settings using buttons
Configuration Sections:
User-Agent Settings:
- Enter custom user-agent string
- Click "Set User-Agent" to apply
- Enter "default" to reset
Proxy Settings:
- Enter HTTP proxy URL
- Enter HTTPS proxy URL
- Click "Save Proxy" to apply
Security Settings:
- Toggle JavaScript enable/disable
- Enter whitelist sites (comma-separated)
- Enter blacklist sites (comma-separated)
- Click "Save Security Settings" to apply
Bookmarks:
- View saved bookmarks
- Double-click to open bookmark
import tkinter as tk
from src.browsers.secure_browser import SimpleBrowser
root = tk.Tk()
browser = SimpleBrowser(root)
# Set configuration programmatically
browser.whitelist = ["https://example.com"]
browser.blacklist = ["http://malicious.com"]
browser.javascript_var.set(False)
browser.toggle_javascript()
root.mainloop()The WebView browser provides a basic settings window.
Accessing Settings:
- Click the "⚙ Settings" button
- Configure user-agent and proxy
- Apply settings
Available Settings:
- User-Agent: Custom user-agent (limited support)
- HTTP Proxy: HTTP proxy configuration
- HTTPS Proxy: HTTPS proxy configuration
import tkinter as tk
from src.browsers.modern_browser import SimpleBrowser
root = tk.Tk()
browser = SimpleBrowser(root)
# Set proxy via environment variables
import os
os.environ["http_proxy"] = "http://proxy.example.com:8080"
os.environ["https_proxy"] = "https://proxy.example.com:8080"
root.mainloop()Purpose: Ensure all connections use HTTPS for encryption.
Configuration Methods:
- Configuration File:
{
"security": {
"https_enforcement": true
}
}- Programmatic:
# Implemented automatically in load_url methods
if not url.startswith(("http://", "https://")):
url = "https://" + urlTesting:
- Try loading "example.com" (should become "https://example.com")
- Try loading "http://example.com" (should remain HTTP)
Purpose: Enable or disable JavaScript execution for security.
Configuration Methods:
- Tkinter Browser Settings:
- Open settings window
- Toggle "Enable JavaScript" checkbox
- Click "Save Security Settings"
- Configuration File:
{
"security": {
"javascript_enabled": false
}
}- Programmatic:
browser.javascript_var.set(False)
browser.toggle_javascript()Testing:
- Disable JavaScript
- Visit JavaScript-heavy site (e.g., modern web app)
- Verify scripts don't execute
Purpose: Control which websites can be accessed.
Whitelist Configuration:
- Tkinter Browser Settings:
- Open settings window
- Enter whitelist sites (comma-separated)
- Click "Save Security Settings"
- Configuration File:
{
"security": {
"whitelist": [
"https://example.com",
"https://trusted.org"
]
}
}Blacklist Configuration:
- Tkinter Browser Settings:
- Open settings window
- Enter blacklist sites (comma-separated)
- Click "Save Security Settings"
- Configuration File:
{
"security": {
"blacklist": [
"http://malicious.com",
"http://phishing.net"
]
}
}Testing:
- Add site to whitelist, try accessing non-whitelisted site (should be blocked)
- Add site to blacklist, try accessing it (should be blocked)
Purpose: Apply HTTP security headers to prevent common web vulnerabilities.
Configuration:
{
"security": {
"security_headers": {
"X-Content-Type-Options": "nosniff",
"X-Frame-Options": "DENY",
"Content-Security-Policy": "default-src 'self'; script-src 'self'; object-src 'none';"
}
}
}Available Headers:
X-Content-Type-Options:
-
nosniff: Prevent MIME type sniffing
X-Frame-Options:
-
DENY: Prevent framing -
SAMEORIGIN: Allow framing from same origin
Content-Security-Policy:
-
default-src 'self': Only load from same origin -
script-src 'self': Only scripts from same origin -
object-src 'none': No plugins
Purpose: Customize user-agent for privacy or compatibility.
Configuration Methods:
- Tkinter Browser Settings:
- Open settings window
- Enter custom user-agent
- Click "Set User-Agent"
- Configuration File:
{
"security": {
"user_agent": "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
}
}Common User-Agents:
Chrome on Windows:
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.124 Safari/537.36
Firefox on Linux:
Mozilla/5.0 (X11; Linux x86_64; rv:89.0) Gecko/20100101 Firefox/89.0
Safari on macOS:
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Safari/605.1.15
Purpose: Route traffic through proxy servers for security, privacy, or access control.
Configuration Methods:
- Browser Settings:
- Open settings window
- Enter HTTP proxy URL
- Enter HTTPS proxy URL
- Click "Save Proxy"
- Configuration File:
{
"proxy": {
"http": "http://proxy.example.com:8080",
"https": "https://proxy.example.com:8080"
}
}- Environment Variables:
export http_proxy="http://proxy.example.com:8080"
export https_proxy="https://proxy.example.com:8080"- Programmatic:
import os
os.environ["http_proxy"] = "http://proxy.example.com:8080"
os.environ["https_proxy"] = "https://proxy.example.com:8080"Proxy URL Format:
http://username:password@proxy.example.com:8080
https://username:password@proxy.example.com:8080
Testing:
- Configure proxy
- Try loading a website
- Check proxy logs for connection
Purpose: Route all traffic through VPN for privacy and security.
Current Status: Placeholder feature (not fully implemented)
Configuration:
{
"vpn_enabled": true
}Note: This is a placeholder for future VPN integration. Currently, VPN must be configured at the system level.
The PyQt5 browser uses Qt Style Sheets (QSS) for theming.
Modifying Colors:
Edit src/browsers/hope.py in the __init__ method:
self.setStyleSheet("""
QMainWindow {
background-color: #2b2b2b; /* Change background color */
color: #ffffff; /* Change text color */
}
QPushButton {
background-color: #5865f2; /* Change button color */
color: #ffffff;
}
# ... additional styling
""")Color Schemes:
Light Theme:
self.setStyleSheet("""
QMainWindow {
background-color: #ffffff;
color: #000000;
}
QPushButton {
background-color: #007bff;
color: #ffffff;
}
""")Custom Theme:
self.setStyleSheet("""
QMainWindow {
background-color: #1a1a2e;
color: #e94560;
}
QPushButton {
background-color: #16213e;
color: #0f3460;
}
""")PyQt5 Browser:
# In src/browsers/hope.py
self.setGeometry(100, 100, 1280, 720) # x, y, width, heightTkinter Browser:
# In src/browsers/secure_browser.py
root.geometry("1280x720") # width x heightWebView Browser:
# In src/browsers/modern_browser.py
root.geometry("900x650") # width x heightPyQt5 Browser:
self.setStyleSheet("""
QLineEdit {
font: 12px 'Segoe UI';
}
""")Tkinter Browser:
self.url_entry = tk.Entry(nav_frame, font=("Arial", 14))- Purpose: HTTP proxy configuration
-
Format:
http://proxy.example.com:8080 -
Example:
export HTTP_PROXY="http://proxy.example.com:8080"
- Purpose: HTTPS proxy configuration
-
Format:
https://proxy.example.com:8080 -
Example:
export HTTPS_PROXY="https://proxy.example.com:8080"
- Purpose: Exclude URLs from proxy
- Format: Comma-separated list
-
Example:
export NO_PROXY="localhost,127.0.0.1,.local"
# Temporary (current session)
export HTTP_PROXY="http://proxy.example.com:8080"
export HTTPS_PROXY="https://proxy.example.com:8080"
# Permanent (add to ~/.bashrc or ~/.zshrc)
echo 'export HTTP_PROXY="http://proxy.example.com:8080"' >> ~/.bashrc
echo 'export HTTPS_PROXY="https://proxy.example.com:8080"' >> ~/.bashrc# Temporary (current session)
set HTTP_PROXY=http://proxy.example.com:8080
set HTTPS_PROXY=https://proxy.example.com:8080
# Permanent (system environment variables)
# Use System Properties > Environment VariablesCreate multiple configuration files for different use cases:
Work Profile (config/work_profile.json):
{
"home_url": "https://work-portal.example.com",
"security": {
"javascript_enabled": true,
"whitelist": [
"https://work-portal.example.com",
"https://company-intranet.example.com"
]
},
"proxy": {
"http": "http://corporate-proxy.example.com:8080",
"https": "https://corporate-proxy.example.com:8080"
}
}Personal Profile (config/personal_profile.json):
{
"home_url": "https://search.brave.com/",
"security": {
"javascript_enabled": false,
"blacklist": [
"http://malicious.com"
]
},
"proxy": {
"http": "",
"https": ""
}
}Kiosk Profile (config/kiosk_profile.json):
{
"home_url": "https://kiosk-content.example.com",
"security": {
"javascript_enabled": false,
"whitelist": [
"https://kiosk-content.example.com"
],
"user_agent": "Kiosk-Browser/1.0"
},
"proxy": {
"http": "http://kiosk-proxy.example.com:8080",
"https": "https://kiosk-proxy.example.com:8080"
}
}Modify main.py to support profile selection:
import argparse
import json
def load_profile(profile_name):
with open(f"config/{profile_name}.json", "r") as f:
return json.load(f)
def main():
parser = argparse.ArgumentParser()
parser.add_argument("--browser", choices=["pyqt5", "tkinter", "webview", "search"], default="pyqt5")
parser.add_argument("--profile", default="user_settings")
args = parser.parse_args()
config = load_profile(args.profile)
# Apply configuration...Create a configuration validator:
import json
import jsonschema
schema = {
"type": "object",
"properties": {
"home_url": {"type": "string", "format": "uri"},
"security": {
"type": "object",
"properties": {
"https_enforcement": {"type": "boolean"},
"javascript_enabled": {"type": "boolean"},
"whitelist": {"type": "array", "items": {"type": "string"}},
"blacklist": {"type": "array", "items": {"type": "string"}}
}
}
},
"required": ["home_url"]
}
def validate_config(config_file):
with open(config_file, "r") as f:
config = json.load(f)
jsonschema.validate(config, schema)
return TrueAutomatically backup configuration before changes:
import shutil
from datetime import datetime
import os
def backup_config():
config_file = "config/user_settings.json"
if os.path.exists(config_file):
timestamp = datetime.now().strftime("%Y%m%d_%H%M%S")
backup_file = f"config/user_settings_backup_{timestamp}.json"
shutil.copy2(config_file, backup_file)
print(f"Configuration backed up to {backup_file}")Migrate configuration between versions:
def migrate_config(old_config):
new_config = old_config.copy()
# Add new fields with defaults
if "security" not in new_config:
new_config["security"] = {
"https_enforcement": True,
"javascript_enabled": True,
"whitelist": [],
"blacklist": []
}
# Remove deprecated fields
if "deprecated_field" in new_config:
del new_config["deprecated_field"]
return new_configSymptoms: Settings not applied, default values used
Solutions:
- Verify JSON syntax:
python -m json.tool config/user_settings.json - Check file permissions:
ls -la config/user_settings.json - Verify file path: Ensure file exists in
config/directory
Symptoms: Traffic not routing through proxy
Solutions:
- Verify proxy URL format
- Test proxy with curl:
curl -x http://proxy.example.com:8080 https://example.com - Check proxy server logs
- Verify environment variables:
echo $HTTP_PROXY
Symptoms: Blacklisted/whitelisted sites still accessible
Solutions:
- Verify URL format (include http:// or https://)
- Check for typos in URLs
- Verify prefix matching logic
- Test with exact URL match
Symptoms: JavaScript runs despite being disabled
Solutions:
- Verify setting was saved
- Reload page after changing setting
- Check browser-specific implementation
- Clear cache and reload
- Backup Configuration: Always backup before making changes
- Validate JSON: Use JSON validator to ensure syntax is correct
- Test Changes: Apply changes incrementally and test
- Document Changes: Keep track of configuration modifications
- Version Control: Store configuration files in version control
- Use Profiles: Create different profiles for different use cases
- Regular Updates: Keep configuration updated with security best practices
- Monitor Logs: Check logs for configuration-related errors
- Security Review: Regularly review security settings
- User Training: Train users on configuration options