proxy.cgi: Remove option to show Squid's version entirely

Message ID b4f59ffb-9a04-938f-7c0e-5a39ded292e8@ipfire.org
State Accepted
Commit 13aeb192178b57bc1b14abc514a022ca89cc87bd
Headers
Series proxy.cgi: Remove option to show Squid's version entirely |

Commit Message

Peter Müller Oct. 10, 2021, 7:43 p.m. UTC
  There is no sense to display this to anybody, and we do not reveal
version information anywhere else on purpose. The IT staff knows which
version of IPFire they are running (hopefully the latest), and it's
none of the rest of the world's business.

Fixes: #12665 (in some way)

Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
---
 html/cgi-bin/proxy.cgi | 18 +++---------------
 1 file changed, 3 insertions(+), 15 deletions(-)
  

Comments

Michael Tremer Oct. 11, 2021, 11:20 a.m. UTC | #1
Hello,

> On 10 Oct 2021, at 20:43, Peter Müller <peter.mueller@ipfire.org> wrote:
> 
> There is no sense to display this to anybody, and we do not reveal
> version information anywhere else on purpose. The IT staff knows which
> version of IPFire they are running (hopefully the latest), and it's
> none of the rest of the world's business.

LOL. Harsh, but true :)

-Michael

Acked-by: Michael Tremer <michael.tremer@ipfire.org>

> 
> Fixes: #12665 (in some way)
> 
> Signed-off-by: Peter Müller <peter.mueller@ipfire.org>
> ---
> html/cgi-bin/proxy.cgi | 18 +++---------------
> 1 file changed, 3 insertions(+), 15 deletions(-)
> 
> diff --git a/html/cgi-bin/proxy.cgi b/html/cgi-bin/proxy.cgi
> index 966593e4d..28321fa7f 100644
> --- a/html/cgi-bin/proxy.cgi
> +++ b/html/cgi-bin/proxy.cgi
> @@ -192,7 +192,6 @@ $proxysettings{'ADMIN_MAIL_ADDRESS'} = '';
> $proxysettings{'ADMIN_PASSWORD'} = '';
> $proxysettings{'ERR_LANGUAGE'} = 'en';
> $proxysettings{'ERR_DESIGN'} = 'ipfire';
> -$proxysettings{'SUPPRESS_VERSION'} = 'on';
> $proxysettings{'FORWARD_VIA'} = 'off';
> $proxysettings{'FORWARD_IPADDRESS'} = 'off';
> $proxysettings{'FORWARD_USERNAME'} = 'off';
> @@ -706,10 +705,6 @@ $checked{'TRANSPARENT_BLUE'}{'off'} = '';
> $checked{'TRANSPARENT_BLUE'}{'on'} = '';
> $checked{'TRANSPARENT_BLUE'}{$proxysettings{'TRANSPARENT_BLUE'}} = "checked='checked'";
> 
> -$checked{'SUPPRESS_VERSION'}{'off'} = '';
> -$checked{'SUPPRESS_VERSION'}{'on'} = '';
> -$checked{'SUPPRESS_VERSION'}{$proxysettings{'SUPPRESS_VERSION'}} = "checked='checked'";
> -
> $checked{'FORWARD_IPADDRESS'}{'off'} = '';
> $checked{'FORWARD_IPADDRESS'}{'on'} = '';
> $checked{'FORWARD_IPADDRESS'}{$proxysettings{'FORWARD_IPADDRESS'}} = "checked='checked'";
> @@ -962,20 +957,14 @@ print <<END
> 	</td>
> </tr>
> <tr>
> -	<td class='base'>$Lang::tr{'advproxy suppress version'}:</td>
> -	<td><input type='checkbox' name='SUPPRESS_VERSION' $checked{'SUPPRESS_VERSION'}{'on'} /></td>
> +	<td>&nbsp;</td>
> +	<td>&nbsp;</td>
> 	<td class='base'>$Lang::tr{'advproxy error design'}:</td>
> 	<td class='base'><select name='ERR_DESIGN'>
> 		<option value='ipfire' $selected{'ERR_DESIGN'}{'ipfire'}>IPFire</option>
> 		<option value='squid' $selected{'ERR_DESIGN'}{'squid'}>$Lang::tr{'advproxy standard'}</option>
> 	</select></td>
> </tr>
> -<tr>
> -	<td class='base'>$Lang::tr{'advproxy squid version'}:</td>
> -	<td class='base'>&nbsp;[<font color='$Header::colourred'> $squidversion[0] </font>]</td>
> -	<td>&nbsp;</td>
> -	<td>&nbsp;</td>
> -</tr>
> </table>
> <hr size='1'>
> <table width='100%'>
> @@ -3070,6 +3059,7 @@ sub writeconfig
> 
> shutdown_lifetime 5 seconds
> icp_port 0
> +httpd_suppress_version_string on
> 
> END
> 	;
> @@ -3868,8 +3858,6 @@ END
> 
> 	}
> 
> -	if ($proxysettings{'SUPPRESS_VERSION'} eq 'on') { print FILE "httpd_suppress_version_string on\n\n" }
> -
> 	if ((!-z $mimetypes) && ($proxysettings{'ENABLE_MIME_FILTER'} eq 'on')) {
> 		if (!-z $acl_src_unrestricted_ip)  { print FILE "http_reply_access allow IPFire_unrestricted_ips\n"; }
> 		if (!-z $acl_src_unrestricted_mac) { print FILE "http_reply_access allow IPFire_unrestricted_mac\n"; }
> -- 
> 2.26.2
  

Patch

diff --git a/html/cgi-bin/proxy.cgi b/html/cgi-bin/proxy.cgi
index 966593e4d..28321fa7f 100644
--- a/html/cgi-bin/proxy.cgi
+++ b/html/cgi-bin/proxy.cgi
@@ -192,7 +192,6 @@  $proxysettings{'ADMIN_MAIL_ADDRESS'} = '';
 $proxysettings{'ADMIN_PASSWORD'} = '';
 $proxysettings{'ERR_LANGUAGE'} = 'en';
 $proxysettings{'ERR_DESIGN'} = 'ipfire';
-$proxysettings{'SUPPRESS_VERSION'} = 'on';
 $proxysettings{'FORWARD_VIA'} = 'off';
 $proxysettings{'FORWARD_IPADDRESS'} = 'off';
 $proxysettings{'FORWARD_USERNAME'} = 'off';
@@ -706,10 +705,6 @@  $checked{'TRANSPARENT_BLUE'}{'off'} = '';
 $checked{'TRANSPARENT_BLUE'}{'on'} = '';
 $checked{'TRANSPARENT_BLUE'}{$proxysettings{'TRANSPARENT_BLUE'}} = "checked='checked'";
 
-$checked{'SUPPRESS_VERSION'}{'off'} = '';
-$checked{'SUPPRESS_VERSION'}{'on'} = '';
-$checked{'SUPPRESS_VERSION'}{$proxysettings{'SUPPRESS_VERSION'}} = "checked='checked'";
-
 $checked{'FORWARD_IPADDRESS'}{'off'} = '';
 $checked{'FORWARD_IPADDRESS'}{'on'} = '';
 $checked{'FORWARD_IPADDRESS'}{$proxysettings{'FORWARD_IPADDRESS'}} = "checked='checked'";
@@ -962,20 +957,14 @@  print <<END
 	</td>
 </tr>
 <tr>
-	<td class='base'>$Lang::tr{'advproxy suppress version'}:</td>
-	<td><input type='checkbox' name='SUPPRESS_VERSION' $checked{'SUPPRESS_VERSION'}{'on'} /></td>
+	<td>&nbsp;</td>
+	<td>&nbsp;</td>
 	<td class='base'>$Lang::tr{'advproxy error design'}:</td>
 	<td class='base'><select name='ERR_DESIGN'>
 		<option value='ipfire' $selected{'ERR_DESIGN'}{'ipfire'}>IPFire</option>
 		<option value='squid' $selected{'ERR_DESIGN'}{'squid'}>$Lang::tr{'advproxy standard'}</option>
 	</select></td>
 </tr>
-<tr>
-	<td class='base'>$Lang::tr{'advproxy squid version'}:</td>
-	<td class='base'>&nbsp;[<font color='$Header::colourred'> $squidversion[0] </font>]</td>
-	<td>&nbsp;</td>
-	<td>&nbsp;</td>
-</tr>
 </table>
 <hr size='1'>
 <table width='100%'>
@@ -3070,6 +3059,7 @@  sub writeconfig
 
 shutdown_lifetime 5 seconds
 icp_port 0
+httpd_suppress_version_string on
 
 END
 	;
@@ -3868,8 +3858,6 @@  END
 
 	}
 
-	if ($proxysettings{'SUPPRESS_VERSION'} eq 'on') { print FILE "httpd_suppress_version_string on\n\n" }
-
 	if ((!-z $mimetypes) && ($proxysettings{'ENABLE_MIME_FILTER'} eq 'on')) {
 		if (!-z $acl_src_unrestricted_ip)  { print FILE "http_reply_access allow IPFire_unrestricted_ips\n"; }
 		if (!-z $acl_src_unrestricted_mac) { print FILE "http_reply_access allow IPFire_unrestricted_mac\n"; }