secured the plugin a bit for 0.1.1

This commit is contained in:
2026-08-05 05:38:01 +02:00
parent c8f5baedde
commit b59fbd1fa8
5 changed files with 47 additions and 12 deletions

View File

@@ -7,7 +7,7 @@ class ProxmoxPowerButtonConfig(PluginConfig):
name = "proxmox_power_button"
verbose_name = "Proxmox Power Button"
description = "Start/stop/reboot Proxmox VMs from the NetBox VM detail page"
version = "0.1.0"
version = "0.1.1"
author = "Bryan Pedini"
base_url = "proxmox-power-button"
# The data migration pins extras.0134_owner / virtualization.0052_gfk_indexes,
@@ -16,11 +16,13 @@ class ProxmoxPowerButtonConfig(PluginConfig):
min_version = "4.5.0"
# Optional behaviour, overridable via PLUGINS_CONFIG["proxmox_power_button"]:
# verify_ssl : verify the Proxmox TLS cert (default False)
# verify_ssl : verify the Proxmox TLS cert (default True — set False
# only for self-signed lab certs; the API token crosses
# this connection, so disabling verification invites MitM)
# stop_mode : "shutdown" (graceful ACPI, default) or "stop" (hard kill)
# reboot_mode : "reboot" (graceful, default) or "reset" (hard)
default_settings = {
"verify_ssl": False,
"verify_ssl": True,
"stop_mode": "shutdown",
"reboot_mode": "reboot",
}

View File

@@ -1,4 +1,5 @@
{# SPDX-License-Identifier: GPL-2.0-or-later — Copyright (C) 2026 Bryan Joshua Pedini #}
{% if perms.virtualization.change_virtualmachine %}
{% if object.status == 'active' %}
{# Powered on: reboot (left) + stop. #}
<form class="d-inline" method="post" action="{% url 'plugins:proxmox_power_button:power' pk=object.pk action='reboot' %}">
@@ -22,3 +23,4 @@
</button>
</form>
{% endif %}
{% endif %}

View File

@@ -61,7 +61,12 @@ class VMPowerActionView(PermissionRequiredMixin, View):
return redirect("virtualization:virtualmachine", pk=pk)
def post(self, request, pk, action):
vm = get_object_or_404(VirtualMachine, pk=pk)
# Scope the lookup through NetBox's object-permission system: a user
# whose change_virtualmachine permission is constraint-scoped gets a
# 404 on VMs outside their scope, exactly like core NetBox views.
vm = get_object_or_404(
VirtualMachine.objects.restrict(request.user, "change"), pk=pk
)
if action not in VALID_ACTIONS:
logger.error("user=%s vm=%s: unknown power action '%s'", request.user, vm.name, action)
@@ -72,7 +77,13 @@ class VMPowerActionView(PermissionRequiredMixin, View):
result = power_action(vm, action)
except ProxmoxError as exc:
logger.error("user=%s vm=%s: %s failed: %s", request.user, vm.name, action, exc)
messages.error(request, f"Proxmox action failed: {exc}")
# Don't echo raw Proxmox/network errors to the browser — they can
# leak internal hostnames, URLs, and response bodies. Full detail
# is in the log line above.
messages.error(
request,
f"Proxmox {action} failed for {vm.name} — see the NetBox log for details.",
)
return redirect("virtualization:virtualmachine", pk=vm.pk)
if action == "start":