change: provider base configs move into the provider classes (#143) #184

Merged
mysticalsoap merged 1 commit from template-paths into trunk 2026-08-27 22:03:40 -04:00
Owner

Problem

Second half of #143, taken to its end state. The provider templates were code-shaped knowledge in data clothing: per-type OpenVPN options restating filenames the provider classes already stage (proton_ca.crt), embedding per-install per-type paths (auth-user-pass /usr/share/aqomui/ProtonVPN/ProtonVPN-auth.txt) that go wrong once an entry's name can differ from its type, and drifting from conventions update.py owns — Windscribe's template pointed at windscribe_userpass.txt while copy_certs writes {entry}-auth.txt. Every historical bug in this area was a two-homes bug.

Fix

Templates stop existing — as files or as text blobs. The four shipped templates shared an identical 10-line OpenVPN client boilerplate (now update.OVPN_BASE); what actually differs per type is three facts, and each provider class now states exactly those:

  • ovpn_options — the type's directives beyond the boilerplate
  • ovpn_auth — whether the tunnel logs in with the entry's auth file
  • ovpn_files — option → staged filename, for exactly the files that class's own fetch() stages

copy_certs builds {entry}/openvpn.conf from them: filenames anchored to the entry's own directory quoted with ovpn_quote (entry names may hold spaces), auth-user-pass pointed at copy_certs's own {entry}-auth.txt convention (retiring the Windscribe drift). No text rewriting, no shlex re-parsing, no missing-file failure mode — a provider registered without its ovpn_files is caught by a test, not by a user's first import. The seeded proto /remote placeholders keep the trailing space write_config matches with startswith("proto "); OVPN_BASE is that quirk's one home, commented.

The stunnel template becomes a format string in tunnel.py filled per connection (replacing the readlines/rewrite loop), with the Airvpn CAfile path now derived from config.ROOTDIR. ovpn_quote moves up to providers/__init__.py for both import paths to share. resources/templates/ retires along with its setup.py/PKGBUILD entries.

Existing installs are untouched: seeding still only happens when openvpn.conf is absent. A freshly seeded config lists the same directives as before in different order (OpenVPN options are position-independent) with file paths now quoted.

Verification

  • ruff check --select E9,F63,F7,F82 . clean; 439 tests pass (4 new)
  • TestTemplateSeeding runs copy_certs for an entry named My Proton (type ProtonVPN) — asserts ca/tls-crypt/auth paths all land in My Proton/, the proto /remote placeholders come out in write_config's expected form, and an existing openvpn.conf is never reseeded; registry-wide tests pin that every provider names its staged files (bare names, known file options) and embeds no paths
  • Repo-wide sweep: no remaining references to resources/templates/
  • Live check before merge (ProtonVPN is the one currently-supported path): build/install the branch, delete the ProtonVPN provider, re-import, connect — exercises build → auth/ca/tls-crypt resolution end to end

🤖 Generated with Claude Code

## Problem Second half of #143, taken to its end state. The provider templates were code-shaped knowledge in data clothing: per-type OpenVPN options restating filenames the provider classes already stage (`proton_ca.crt`), embedding per-install per-type paths (`auth-user-pass /usr/share/aqomui/ProtonVPN/ProtonVPN-auth.txt`) that go wrong once an entry's name can differ from its type, and drifting from conventions update.py owns — Windscribe's template pointed at `windscribe_userpass.txt` while copy_certs writes `{entry}-auth.txt`. Every historical bug in this area was a two-homes bug. ## Fix Templates stop existing — as files *or* as text blobs. The four shipped templates shared an identical 10-line OpenVPN client boilerplate (now `update.OVPN_BASE`); what actually differs per type is three facts, and each provider class now states exactly those: - `ovpn_options` — the type's directives beyond the boilerplate - `ovpn_auth` — whether the tunnel logs in with the entry's auth file - `ovpn_files` — option → staged filename, for exactly the files that class's own `fetch()` stages `copy_certs` builds `{entry}/openvpn.conf` from them: filenames anchored to the entry's own directory quoted with `ovpn_quote` (entry names may hold spaces), `auth-user-pass` pointed at copy_certs's own `{entry}-auth.txt` convention (retiring the Windscribe drift). No text rewriting, no shlex re-parsing, no missing-file failure mode — a provider registered without its `ovpn_files` is caught by a test, not by a user's first import. The seeded `proto `/`remote ` placeholders keep the trailing space `write_config` matches with `startswith("proto ")`; OVPN_BASE is that quirk's one home, commented. The stunnel template becomes a format string in tunnel.py filled per connection (replacing the readlines/rewrite loop), with the Airvpn CAfile path now derived from `config.ROOTDIR`. `ovpn_quote` moves up to `providers/__init__.py` for both import paths to share. `resources/templates/` retires along with its setup.py/PKGBUILD entries. Existing installs are untouched: seeding still only happens when `openvpn.conf` is absent. A freshly seeded config lists the same directives as before in different order (OpenVPN options are position-independent) with file paths now quoted. ## Verification - `ruff check --select E9,F63,F7,F82 .` clean; 439 tests pass (4 new) - `TestTemplateSeeding` runs `copy_certs` for an entry named `My Proton` (type ProtonVPN) — asserts ca/tls-crypt/auth paths all land in `My Proton/`, the `proto `/`remote ` placeholders come out in write_config's expected form, and an existing openvpn.conf is never reseeded; registry-wide tests pin that every provider names its staged files (bare names, known file options) and embeds no paths - Repo-wide sweep: no remaining references to `resources/templates/` - Live check before merge (ProtonVPN is the one currently-supported path): build/install the branch, delete the ProtonVPN provider, re-import, connect — exercises build → auth/ca/tls-crypt resolution end to end 🤖 Generated with [Claude Code](https://claude.com/claude-code)
change: inject entry paths at seed time, strip them from templates
All checks were successful
ci / test (pull_request) Successful in 28s
d37156f4a5
The shipped templates hardcoded per-install, per-type paths
(auth-user-pass /usr/share/aqomui/ProtonVPN/ProtonVPN-auth.txt), which
goes wrong once an entry's name can differ from its type: the certs
land in the entry's directory while the seeded config points at the
type's. Templates now carry only the filenames their type needs;
copy_certs makes them absolute for the entry when it seeds
openvpn.conf, the way the custom import already rewrites
auth-user-pass. The auth filename comes from copy_certs's own
{entry}-auth.txt convention, which also retires the stale
windscribe_userpass.txt reference the Windscribe template carried.

ovpn_quote and the file-option tuple move up to providers/__init__:
generic OpenVPN config knowledge both import paths now share.

Closes #143

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
mysticalsoap force-pushed template-paths from d37156f4a5
All checks were successful
ci / test (pull_request) Successful in 28s
to 0d446c9c99
All checks were successful
ci / test (pull_request) Successful in 29s
2026-08-27 20:20:27 -04:00
Compare
mysticalsoap changed title from change: inject entry paths at seed time, strip them from templates (#143) to change: provider base configs move into the provider classes (#143) 2026-08-27 20:20:52 -04:00
mysticalsoap force-pushed template-paths from 0d446c9c99
All checks were successful
ci / test (pull_request) Successful in 29s
to 4fe456ab52
All checks were successful
ci / test (pull_request) Successful in 23s
2026-08-27 20:27:08 -04:00
Compare
mysticalsoap force-pushed template-paths from 4fe456ab52
All checks were successful
ci / test (pull_request) Successful in 23s
to b873ec8627
All checks were successful
ci / test (pull_request) Successful in 25s
ci / test (push) Successful in 44s
2026-08-27 20:36:13 -04:00
Compare
mysticalsoap deleted branch template-paths 2026-08-27 22:03:40 -04:00
Sign in to join this conversation.
No description provided.