-
Notifications
You must be signed in to change notification settings - Fork 154
EN security root_panel_ip_allowlist
MagnusBilling can restrict web-panel login for any user to IP
addresses authorized from an SSH session. The allowlist is stored outside the
web document root and outside MariaDB, under
/etc/magnusbilling/panel-ip-access.
Connect by SSH from the same public IP used by the browser and run:
addmyip root
The command obtains the client address from the SSH connection itself. It does not accept an IP supplied on the command line. The first successful execution creates a user-specific allowlist and activates the restriction for that user. Existing users remain unrestricted until this command is run for their exact username.
The command also removes the SSH client IP from pkg_firewall and pkg_log
and then inserts it into pkg_firewall with action 5 (IgnoreIP).
These database operations run in one transaction; if they fail, the external
panel allowlist is not changed.
Any panel username can be used, for example:
addmyip administrator
addmyip "support manager"
Each username has an independent allowlist. Usernames are represented by a SHA-256 identifier in the storage directory so special characters cannot be interpreted as filesystem paths.
From the SSH session whose address should be removed, run:
delmyip root
The restriction remains active even when the last address is removed. In that
case no web-panel IP can log in as that user until addmyip USERNAME is run
from SSH or all restrictions are released.
Run:
releaseAll
This removes all panel allowlist files and makes every user unrestricted again.
All three commands require root privileges.
The web login compares Apache's trusted client address (REMOTE_ADDR) with
the SSH client address. If a reverse proxy, CDN, NAT gateway, or VPN makes the
two addresses different, configure Apache mod_remoteip with only the
trusted proxy ranges or connect to SSH through the same egress path. Do not
trust arbitrary X-Forwarded-For headers.
Documentation source · Report an issue · English documentation generated from the MagnusBilling 8 RST sources.