add: WireGuard entries in the ProtonVPN import #204

Merged
mysticalsoap merged 1 commit from feat/proton-wireguard-196 into trunk 2026-08-29 13:01:49 -04:00
Owner

Problem: The ProtonVPN import only produces OpenVPN entries, although the API already hands over everything WireGuard needs (#196).

Fix: The import registers an Ed25519 key at POST /vpn/v1/certificate (Mode: persistent, 365 days - a dashboard-visible device named "aqomui"; Proton takes no raw WireGuard public key the way Mullvad does) and stages protonvpn_wg.conf holding the key's X25519 form plus the fixed interface half (10.2.0.2/32, DNS 10.2.0.1). Every logical whose physical server carries an X25519PublicKey gets a WireGuard sibling entry (<name>-WireGuard, port 51820) next to its OpenVPN one. A re-import keeps the registered key; an update replaces it - same contract as Mullvad's gen_wg_key.

The two Mullvad-only branches on the connect path generalize: tunnel.wireguard() completes the staged template of any entry carrying public_key (found by the entry's type, so a renamed provider keeps working - the Mullvad hardcode already broke that case), and catalog.connect_dict stops projecting the provider's selected OpenVPN protocol onto any WireGuard entry.

Verification: 11 new tests - registration payload and staged conf, key-reuse on plain re-import, wg-tool-missing and no-X25519 degradation, renamed-provider template lookup, protocol-projection bypass, and an independent check of the Ed25519→X25519 conversion against the curve's birational map. Full suite 510 passed. Live import/connect still needs a run against a real Proton account.

Closes #196

🤖 Generated with Claude Code

**Problem**: The ProtonVPN import only produces OpenVPN entries, although the API already hands over everything WireGuard needs (#196). **Fix**: The import registers an Ed25519 key at `POST /vpn/v1/certificate` (`Mode: persistent`, 365 days - a dashboard-visible device named "aqomui"; Proton takes no raw WireGuard public key the way Mullvad does) and stages `protonvpn_wg.conf` holding the key's X25519 form plus the fixed interface half (`10.2.0.2/32`, DNS `10.2.0.1`). Every logical whose physical server carries an `X25519PublicKey` gets a WireGuard sibling entry (`<name>-WireGuard`, port 51820) next to its OpenVPN one. A re-import keeps the registered key; an update replaces it - same contract as Mullvad's `gen_wg_key`. The two Mullvad-only branches on the connect path generalize: `tunnel.wireguard()` completes the staged template of any entry carrying `public_key` (found by the entry's *type*, so a renamed provider keeps working - the Mullvad hardcode already broke that case), and `catalog.connect_dict` stops projecting the provider's selected OpenVPN protocol onto any WireGuard entry. **Verification**: 11 new tests - registration payload and staged conf, key-reuse on plain re-import, wg-tool-missing and no-X25519 degradation, renamed-provider template lookup, protocol-projection bypass, and an independent check of the Ed25519→X25519 conversion against the curve's birational map. Full suite 510 passed. Live import/connect still needs a run against a real Proton account. Closes #196 🤖 Generated with [Claude Code](https://claude.com/claude-code)
add: WireGuard entries in the ProtonVPN import
All checks were successful
ci / test (pull_request) Successful in 24s
ci / test (push) Successful in 1m0s
30fbc1504b
The import registers an Ed25519 key at the certificate endpoint (a
persistent, dashboard-visible device - Proton takes no raw WireGuard
public key the way Mullvad does) and stages the interface half of the
config with the key's X25519 form; each logical's X25519PublicKey
becomes a WireGuard sibling entry next to the OpenVPN one.

The two Mullvad-only branches on the connect path open up: any entry
carrying public_key completes its provider's staged template, found by
the entry's type so renamed providers keep working, and any WireGuard
entry escapes the provider's selected OpenVPN protocol projection.

Closes #196

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
mysticalsoap deleted branch feat/proton-wireguard-196 2026-08-29 13:01:49 -04:00
Sign in to join this conversation.
No description provided.