diff --git a/portal.go b/portal.go index 1e32a3c..0a21663 100644 --- a/portal.go +++ b/portal.go @@ -182,6 +182,10 @@ func (p *proxyHandler) handlePortal(w http.ResponseWriter, r *http.Request) { p.handleMobilePAC(w, r) return } + if r.URL.Path == "/qr.png" { + p.handleQR(w, r) + return + } if r.URL.Path == "/" || r.URL.Path == "/setup" { p.handleSetup(w, r) return @@ -199,6 +203,18 @@ func (p *proxyHandler) handlePAC(w http.ResponseWriter, r *http.Request) { pacTmpl.Execute(w, struct{ ProxyHost string }{parsed.Host}) } +func (p *proxyHandler) handleQR(w http.ResponseWriter, r *http.Request) { + png, err := qrcode.Encode(p.httpOrigin, qrcode.Medium, 256) + if err != nil { + http.Error(w, "failed to generate QR code", http.StatusInternalServerError) + return + } + w.Header().Set("Content-Type", "image/png") + w.Header().Set("Cache-Control", "public, max-age=3600") + w.WriteHeader(http.StatusOK) + w.Write(png) +} + func (p *proxyHandler) handleMobilePAC(w http.ResponseWriter, r *http.Request) { parsed, err := url.Parse(p.httpOrigin) if err != nil { diff --git a/portal_https.go b/portal_https.go index 3c38b4f..baee8e8 100644 --- a/portal_https.go +++ b/portal_https.go @@ -40,6 +40,10 @@ func (h *portalHandler) ServeHTTP(w http.ResponseWriter, r *http.Request) { h.proxy.handleMobilePAC(w, r) return } + if r.URL.Path == "/qr.png" { + h.proxy.handleQR(w, r) + return + } if r.URL.Path == "/setup" { h.proxy.handleSetup(w, r) return diff --git a/static/setup.html b/static/setup.html index 5c14e23..44e5881 100644 --- a/static/setup.html +++ b/static/setup.html @@ -32,7 +32,6 @@ border-radius: 3px; font-size: 0.9em; } - .section { border-top: 1px solid #eee; padding-top: 1rem; margin-top: 1rem; } .card { background: #f8fafc; border: 1px solid #e2e8f0; @@ -78,6 +77,24 @@ color: #666; margin-top: 0.5rem; } + details { + border-top: 1px solid #eee; + padding-top: 1rem; + margin-top: 1rem; + } + details:first-of-type { + border-top: none; + padding-top: 0; + margin-top: 0.5rem; + } + summary { + font-size: 1.1rem; + font-weight: 600; + cursor: pointer; + padding: 0.25rem 0; + } + summary:hover { color: #2563eb; } + details[open] summary { margin-bottom: 0.5rem; } @@ -100,8 +117,8 @@

2. Install and Trust the Certificate

Follow the instructions for your platform:

-
-

macOS

+
+ macOS
  1. Download ca.crt and open it — Keychain Access will launch
  2. Add the certificate to the System keychain
  3. @@ -109,10 +126,10 @@
  4. Expand Trust and set When using this certificate to Always Trust
  5. Restart your browser for the change to take effect
-
+ -
-

iOS / iPadOS

+
+ iOS / iPadOS
  1. Open this page on your device (scan the QR code above)
  2. Tap Download CA Certificate — a prompt appears to download the profile
  3. @@ -121,10 +138,10 @@
  4. Go to Settings → General → About → Certificate Trust Settings
  5. Enable full trust for ublproxy CA
-
+ -
-

Android

+
+ Android
  1. Open this page on your device (scan the QR code above)
  2. Tap Download CA Certificate
  3. @@ -132,19 +149,19 @@
  4. Select the downloaded ublproxy-ca.crt file and confirm

Menu paths vary by manufacturer (Samsung, Pixel, etc.).

-
+ -
-

Linux

+
+ Linux
  1. Copy the certificate: sudo cp ublproxy-ca.crt /usr/local/share/ca-certificates/
  2. Update the trust store: sudo update-ca-certificates
  3. Restart your browser for the change to take effect
-
+ -
-

Windows

+
+ Windows
  1. Download ca.crt and double-click it
  2. Click Install Certificate
  3. @@ -152,17 +169,17 @@
  4. Choose Trusted Root Certification Authorities and finish the wizard
  5. Restart your browser for the change to take effect
-
+ -
-

Firefox

+
+ Firefox
  1. Open Settings → Privacy & Security → Certificates → View Certificates
  2. Click Import and select the downloaded ca.crt
  3. Check Trust this CA to identify websites and confirm
  4. Restart Firefox for the change to take effect
-
+
@@ -173,49 +190,47 @@

PAC URL:

-
-

Firefox

+
+ Firefox
  1. Open Settings → General → Network Settings → Settings…
  2. Select Automatic proxy configuration URL
  3. Enter the PAC URL shown above
  4. Click OK
-
+ -
-

macOS (system-wide)

+
+ macOS (system-wide)
  1. Open System Settings → Network → Wi-Fi → Details → Proxies
  2. Enable Automatic Proxy Configuration
  3. Enter the PAC URL shown above
-
+ -
-

Chromium / Chrome

+
+ Chromium / Chrome

Chromium-based browsers use the system proxy settings. Configure the PAC URL at the OS level, or launch with:

-
+ -
-

Mobile

-

Mobile devices (iOS/Android) use a separate PAC URL because they don't support HTTPS proxy connections:

- -
+

Mobile

+

Mobile devices (iOS/Android) use a separate PAC URL because they don't support HTTPS proxy connections:

+ -
-

iOS / iPadOS

+
+ iOS / iPadOS
  1. Go to Settings → Wi-Fi
  2. Tap the info button (i) on your connected network
  3. Scroll to Configure Proxy and select Automatic
  4. Enter the mobile PAC URL shown above
-
+ -
-

Android

+
+ Android
  1. Go to Settings → Wi-Fi
  2. Tap the gear icon on your connected network
  3. @@ -223,7 +238,7 @@
  4. Enter the mobile PAC URL shown above

Some manufacturers label this setting differently. Look for proxy settings within your Wi-Fi network configuration.

-
+

The desktop PAC file routes traffic through the encrypted HTTPS proxy.