modules/admin-full: add option to override the WPA cipher (#303)
[project/luci.git] / modules / admin-full / luasrc / model / cbi / admin_network / wifi.lua
1 --[[
2 LuCI - Lua Configuration Interface
3
4 Copyright 2008 Steven Barth <steven@midlink.org>
5
6 Licensed under the Apache License, Version 2.0 (the "License");
7 you may not use this file except in compliance with the License.
8 You may obtain a copy of the License at
9
10 http://www.apache.org/licenses/LICENSE-2.0
11
12 $Id$
13 ]]--
14
15 local wa = require "luci.tools.webadmin"
16 local nw = require "luci.model.network"
17 local fs = require "nixio.fs"
18
19 arg[1] = arg[1] or ""
20
21 m = Map("wireless", "",
22 translate("The <em>Device Configuration</em> section covers physical settings of the radio " ..
23 "hardware such as channel, transmit power or antenna selection which is shared among all " ..
24 "defined wireless networks (if the radio hardware is multi-SSID capable). Per network settings " ..
25 "like encryption or operation mode are grouped in the <em>Interface Configuration</em>."))
26
27 m:chain("network")
28 m:chain("firewall")
29
30 local ifsection
31
32 function m.on_commit(map)
33 local wnet = nw:get_wifinet(arg[1])
34 if ifsection and wnet then
35 ifsection.section = wnet.sid
36 m.title = luci.util.pcdata(wnet:get_i18n())
37 end
38 end
39
40 nw.init(m.uci)
41
42 local wnet = nw:get_wifinet(arg[1])
43 local wdev = wnet and wnet:get_device()
44
45 -- redirect to overview page if network does not exist anymore (e.g. after a revert)
46 if not wnet or not wdev then
47 luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless"))
48 return
49 end
50
51 -- wireless toggle was requested, commit and reload page
52 function m.parse(map)
53 if m:formvalue("cbid.wireless.%s.__toggle" % wdev:name()) then
54 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
55 wnet:set("disabled", nil)
56 else
57 wnet:set("disabled", "1")
58 end
59 wdev:set("disabled", nil)
60
61 nw:commit("wireless")
62 luci.sys.call("(env -i /sbin/wifi down; env -i /sbin/wifi up) >/dev/null 2>/dev/null")
63
64 luci.http.redirect(luci.dispatcher.build_url("admin/network/wireless", arg[1]))
65 return
66 end
67 Map.parse(map)
68 end
69
70 m.title = luci.util.pcdata(wnet:get_i18n())
71
72
73 local iw = luci.sys.wifi.getiwinfo(arg[1])
74 local hw_modes = iw.hwmodelist or { }
75 local tx_powers = iw.txpwrlist or { }
76 local tx_power = tostring(
77 (iw.txpower and iw.txpower > 0 and iw.txpower) or
78 (#tx_powers > 0 and tx_powers[#tx_powers].dbm)
79 )
80
81 s = m:section(NamedSection, wdev:name(), "wifi-device", translate("Device Configuration"))
82 s.addremove = false
83
84 s:tab("general", translate("General Setup"))
85 s:tab("macfilter", translate("MAC-Filter"))
86 s:tab("advanced", translate("Advanced Settings"))
87
88 --[[
89 back = s:option(DummyValue, "_overview", translate("Overview"))
90 back.value = ""
91 back.titleref = luci.dispatcher.build_url("admin", "network", "wireless")
92 ]]
93
94 st = s:taboption("general", DummyValue, "__status", translate("Status"))
95 st.template = "admin_network/wifi_status"
96 st.ifname = arg[1]
97
98 en = s:taboption("general", Button, "__toggle")
99
100 if wdev:get("disabled") == "1" or wnet:get("disabled") == "1" then
101 en.title = translate("Wireless network is disabled")
102 en.inputtitle = translate("Enable")
103 en.inputstyle = "apply"
104 else
105 en.title = translate("Wireless network is enabled")
106 en.inputtitle = translate("Disable")
107 en.inputstyle = "reset"
108 end
109
110
111 local hwtype = wdev:get("type")
112 local htcaps = wdev:get("ht_capab") and true or false
113
114 -- NanoFoo
115 local nsantenna = wdev:get("antenna")
116
117 -- Check whether there is a client interface on the same radio,
118 -- if yes, lock the channel choice as the station will dicatate the freq
119 local has_sta = nil
120 local _, net
121 for _, net in ipairs(wdev:get_wifinets()) do
122 if net:mode() == "sta" and net:id() ~= wnet:id() then
123 has_sta = net
124 break
125 end
126 end
127
128 if has_sta then
129 ch = s:taboption("general", DummyValue, "choice", translate("Channel"))
130 ch.value = translatef("Locked to channel %d used by %s",
131 has_sta:channel(), has_sta:shortname())
132 else
133 ch = s:taboption("general", Value, "channel", translate("Channel"))
134 ch:value("auto", translate("auto"))
135 for _, f in ipairs(iw and iw.freqlist or luci.sys.wifi.channels()) do
136 if not f.restricted then
137 ch:value(f.channel, "%i (%.3f GHz)" %{ f.channel, f.mhz / 1000 })
138 end
139 end
140 end
141
142 ------------------- MAC80211 Device ------------------
143
144 if hwtype == "mac80211" then
145 tp = s:taboption("general",
146 (tx_powers and #tx_powers > 0) and ListValue or Value,
147 "txpower", translate("Transmit Power"), "dBm")
148
149 tp.rmempty = true
150 tp.default = tx_power
151 for _, p in ipairs(tx_powers or {}) do
152 tp:value(p.dbm, "%i dBm (%i mW)" %{ p.dbm, p.mw })
153 end
154
155 mode = s:taboption("advanced", ListValue, "hwmode", translate("Mode"))
156 mode:value("", translate("auto"))
157 if hw_modes.b then mode:value("11b", "802.11b") end
158 if hw_modes.g then mode:value("11g", "802.11g") end
159 if hw_modes.a then mode:value("11a", "802.11a") end
160
161 if htcaps then
162 if hw_modes.g and hw_modes.n then mode:value("11ng", "802.11g+n") end
163 if hw_modes.a and hw_modes.n then mode:value("11na", "802.11a+n") end
164
165 htmode = s:taboption("advanced", ListValue, "htmode", translate("HT mode"))
166 htmode:depends("hwmode", "11na")
167 htmode:depends("hwmode", "11ng")
168 htmode:value("HT20", "20MHz")
169 htmode:value("HT40-", translate("40MHz 2nd channel below"))
170 htmode:value("HT40+", translate("40MHz 2nd channel above"))
171
172 --htcapab = s:taboption("advanced", DynamicList, "ht_capab", translate("HT capabilities"))
173 --htcapab:depends("hwmode", "11na")
174 --htcapab:depends("hwmode", "11ng")
175 end
176
177 local cl = iw and iw.countrylist
178 if cl and #cl > 0 then
179 cc = s:taboption("advanced", ListValue, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
180 cc.default = tostring(iw and iw.country or "00")
181 for _, c in ipairs(cl) do
182 cc:value(c.alpha2, "%s - %s" %{ c.alpha2, c.name })
183 end
184 else
185 s:taboption("advanced", Value, "country", translate("Country Code"), translate("Use ISO/IEC 3166 alpha2 country codes."))
186 end
187
188 s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
189 translate("Distance to farthest network member in meters."))
190
191 s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
192 s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
193 end
194
195
196 ------------------- Madwifi Device ------------------
197
198 if hwtype == "atheros" then
199 tp = s:taboption("general",
200 (#tx_powers > 0) and ListValue or Value,
201 "txpower", translate("Transmit Power"), "dBm")
202
203 tp.rmempty = true
204 tp.default = tx_power
205 for _, p in ipairs(tx_powers or {}) do
206 tp:value(p.dbm, "%i dBm (%i mW)" %{ p.dbm, p.mw })
207 end
208
209 mode = s:taboption("advanced", ListValue, "hwmode", translate("Mode"))
210 mode:value("", translate("auto"))
211 if hw_modes.b then mode:value("11b", "802.11b") end
212 if hw_modes.g then mode:value("11g", "802.11g") end
213 if hw_modes.a then mode:value("11a", "802.11a") end
214 if hw_modes.g then mode:value("11bg", "802.11b+g") end
215 if hw_modes.g then mode:value("11gst", "802.11g + Turbo") end
216 if hw_modes.a then mode:value("11ast", "802.11a + Turbo") end
217 mode:value("fh", translate("Frequency Hopping"))
218
219 s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
220
221 if not nsantenna then
222 ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
223 ant1.widget = "radio"
224 ant1.orientation = "horizontal"
225 ant1:depends("diversity", "")
226 ant1:value("0", translate("auto"))
227 ant1:value("1", translate("Antenna 1"))
228 ant1:value("2", translate("Antenna 2"))
229
230 ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
231 ant2.widget = "radio"
232 ant2.orientation = "horizontal"
233 ant2:depends("diversity", "")
234 ant2:value("0", translate("auto"))
235 ant2:value("1", translate("Antenna 1"))
236 ant2:value("2", translate("Antenna 2"))
237
238 else -- NanoFoo
239 local ant = s:taboption("advanced", ListValue, "antenna", translate("Transmitter Antenna"))
240 ant:value("auto")
241 ant:value("vertical")
242 ant:value("horizontal")
243 ant:value("external")
244 end
245
246 s:taboption("advanced", Value, "distance", translate("Distance Optimization"),
247 translate("Distance to farthest network member in meters."))
248 s:taboption("advanced", Value, "regdomain", translate("Regulatory Domain"))
249 s:taboption("advanced", Value, "country", translate("Country Code"))
250 s:taboption("advanced", Flag, "outdoor", translate("Outdoor Channels"))
251
252 --s:option(Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
253 end
254
255
256
257 ------------------- Broadcom Device ------------------
258
259 if hwtype == "broadcom" then
260 tp = s:taboption("general",
261 (#tx_powers > 0) and ListValue or Value,
262 "txpower", translate("Transmit Power"), "dBm")
263
264 tp.rmempty = true
265 tp.default = tx_power
266 for _, p in ipairs(tx_powers or {}) do
267 tp:value(p.dbm, "%i dBm (%i mW)" %{ p.dbm, p.mw })
268 end
269
270 mode = s:taboption("advanced", ListValue, "hwmode", translate("Mode"))
271 mode:value("11bg", "802.11b+g")
272 mode:value("11b", "802.11b")
273 mode:value("11g", "802.11g")
274 mode:value("11gst", "802.11g + Turbo")
275
276 ant1 = s:taboption("advanced", ListValue, "txantenna", translate("Transmitter Antenna"))
277 ant1.widget = "radio"
278 ant1:depends("diversity", "")
279 ant1:value("3", translate("auto"))
280 ant1:value("0", translate("Antenna 1"))
281 ant1:value("1", translate("Antenna 2"))
282
283 ant2 = s:taboption("advanced", ListValue, "rxantenna", translate("Receiver Antenna"))
284 ant2.widget = "radio"
285 ant2:depends("diversity", "")
286 ant2:value("3", translate("auto"))
287 ant2:value("0", translate("Antenna 1"))
288 ant2:value("1", translate("Antenna 2"))
289
290 s:taboption("advanced", Flag, "frameburst", translate("Frame Bursting"))
291
292 s:taboption("advanced", Value, "distance", translate("Distance Optimization"))
293 --s:option(Value, "slottime", translate("Slot time"))
294
295 s:taboption("advanced", Value, "country", translate("Country Code"))
296 s:taboption("advanced", Value, "maxassoc", translate("Connection Limit"))
297 end
298
299
300 --------------------- HostAP Device ---------------------
301
302 if hwtype == "prism2" then
303 s:taboption("advanced", Value, "txpower", translate("Transmit Power"), "att units").rmempty = true
304
305 s:taboption("advanced", Flag, "diversity", translate("Diversity")).rmempty = false
306
307 s:taboption("advanced", Value, "txantenna", translate("Transmitter Antenna"))
308 s:taboption("advanced", Value, "rxantenna", translate("Receiver Antenna"))
309 end
310
311
312 ----------------------- Interface -----------------------
313
314 s = m:section(NamedSection, wnet.sid, "wifi-iface", translate("Interface Configuration"))
315 ifsection = s
316 s.addremove = false
317 s.anonymous = true
318 s.defaults.device = wdev:name()
319
320 s:tab("general", translate("General Setup"))
321 s:tab("encryption", translate("Wireless Security"))
322 s:tab("macfilter", translate("MAC-Filter"))
323 s:tab("advanced", translate("Advanced Settings"))
324
325 s:taboption("general", Value, "ssid", translate("<abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
326
327 mode = s:taboption("general", ListValue, "mode", translate("Mode"))
328 mode.override_values = true
329 mode:value("ap", translate("Access Point"))
330 mode:value("sta", translate("Client"))
331 mode:value("adhoc", translate("Ad-Hoc"))
332
333 bssid = s:taboption("general", Value, "bssid", translate("<abbr title=\"Basic Service Set Identifier\">BSSID</abbr>"))
334
335 network = s:taboption("general", Value, "network", translate("Network"),
336 translate("Choose the network you want to attach to this wireless interface. " ..
337 "Select <em>unspecified</em> to not attach any network or fill out the " ..
338 "<em>create</em> field to define a new network."))
339
340 network.rmempty = true
341 network.template = "cbi/network_netlist"
342 network.widget = "radio"
343
344 function network.write(self, section, value)
345 local i = nw:get_interface(section)
346 if i then
347 if value == '-' then
348 value = m:formvalue(self:cbid(section) .. ".newnet")
349 if value and #value > 0 then
350 local n = nw:add_network(value, {proto="none"})
351 if n then n:add_interface(i) end
352 else
353 local n = i:get_network()
354 if n then n:del_interface(i) end
355 end
356 else
357 local n = nw:get_network(value)
358 if n then
359 n:set("type", "bridge")
360 n:add_interface(i)
361 end
362 end
363 end
364 end
365
366 -------------------- MAC80211 Interface ----------------------
367
368 if hwtype == "mac80211" then
369 if fs.access("/usr/sbin/iw") then
370 mode:value("mesh", "802.11s")
371 end
372
373 mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
374 mode:value("monitor", translate("Monitor"))
375 bssid:depends({mode="adhoc"})
376
377 mp = s:taboption("macfilter", ListValue, "macfilter", translate("MAC-Address Filter"))
378 mp:depends({mode="ap"})
379 mp:depends({mode="ap-wds"})
380 mp:value("", translate("disable"))
381 mp:value("allow", translate("Allow listed only"))
382 mp:value("deny", translate("Allow all except listed"))
383
384 ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
385 ml.datatype = "macaddr"
386 ml:depends({macfilter="allow"})
387 ml:depends({macfilter="deny"})
388
389 mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
390 mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
391
392 function mode.write(self, section, value)
393 if value == "ap-wds" then
394 ListValue.write(self, section, "ap")
395 m.uci:set("wireless", section, "wds", 1)
396 elseif value == "sta-wds" then
397 ListValue.write(self, section, "sta")
398 m.uci:set("wireless", section, "wds", 1)
399 else
400 ListValue.write(self, section, value)
401 m.uci:delete("wireless", section, "wds")
402 end
403 end
404
405 function mode.cfgvalue(self, section)
406 local mode = ListValue.cfgvalue(self, section)
407 local wds = m.uci:get("wireless", section, "wds") == "1"
408
409 if mode == "ap" and wds then
410 return "ap-wds"
411 elseif mode == "sta" and wds then
412 return "sta-wds"
413 else
414 return mode
415 end
416 end
417
418 hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
419 hidden:depends({mode="ap"})
420 hidden:depends({mode="ap-wds"})
421 end
422
423
424
425 -------------------- Madwifi Interface ----------------------
426
427 if hwtype == "atheros" then
428 mode:value("ahdemo", translate("Pseudo Ad-Hoc (ahdemo)"))
429 mode:value("monitor", translate("Monitor"))
430 mode:value("ap-wds", "%s (%s)" % {translate("Access Point"), translate("WDS")})
431 mode:value("sta-wds", "%s (%s)" % {translate("Client"), translate("WDS")})
432 mode:value("wds", translate("Static WDS"))
433
434 function mode.write(self, section, value)
435 if value == "ap-wds" then
436 ListValue.write(self, section, "ap")
437 m.uci:set("wireless", section, "wds", 1)
438 elseif value == "sta-wds" then
439 ListValue.write(self, section, "sta")
440 m.uci:set("wireless", section, "wds", 1)
441 else
442 ListValue.write(self, section, value)
443 m.uci:delete("wireless", section, "wds")
444 end
445 end
446
447 function mode.cfgvalue(self, section)
448 local mode = ListValue.cfgvalue(self, section)
449 local wds = m.uci:get("wireless", section, "wds") == "1"
450
451 if mode == "ap" and wds then
452 return "ap-wds"
453 elseif mode == "sta" and wds then
454 return "sta-wds"
455 else
456 return mode
457 end
458 end
459
460 bssid:depends({mode="adhoc"})
461 bssid:depends({mode="ahdemo"})
462 bssid:depends({mode="wds"})
463
464 wdssep = s:taboption("advanced", Flag, "wdssep", translate("Separate WDS"))
465 wdssep:depends({mode="ap-wds"})
466
467 s:taboption("advanced", Flag, "doth", "802.11h")
468 hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
469 hidden:depends({mode="ap"})
470 hidden:depends({mode="adhoc"})
471 hidden:depends({mode="ap-wds"})
472 hidden:depends({mode="sta-wds"})
473 isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
474 translate("Prevents client-to-client communication"))
475 isolate:depends({mode="ap"})
476 s:taboption("advanced", Flag, "bgscan", translate("Background Scan"))
477
478 mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
479 mp:value("", translate("disable"))
480 mp:value("allow", translate("Allow listed only"))
481 mp:value("deny", translate("Allow all except listed"))
482
483 ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
484 ml.datatype = "macaddr"
485 ml:depends({macpolicy="allow"})
486 ml:depends({macpolicy="deny"})
487
488 s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
489 s:taboption("advanced", Value, "mcast_rate", translate("Multicast Rate"))
490 s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
491 s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
492 s:taboption("advanced", Value, "minrate", translate("Minimum Rate"))
493 s:taboption("advanced", Value, "maxrate", translate("Maximum Rate"))
494 s:taboption("advanced", Flag, "compression", translate("Compression"))
495
496 s:taboption("advanced", Flag, "bursting", translate("Frame Bursting"))
497 s:taboption("advanced", Flag, "turbo", translate("Turbo Mode"))
498 s:taboption("advanced", Flag, "ff", translate("Fast Frames"))
499
500 s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
501 s:taboption("advanced", Flag, "xr", translate("XR Support"))
502 s:taboption("advanced", Flag, "ar", translate("AR Support"))
503
504 local swm = s:taboption("advanced", Flag, "sw_merge", translate("Disable HW-Beacon timer"))
505 swm:depends({mode="adhoc"})
506
507 local nos = s:taboption("advanced", Flag, "nosbeacon", translate("Disable HW-Beacon timer"))
508 nos:depends({mode="sta"})
509 nos:depends({mode="sta-wds"})
510
511 local probereq = s:taboption("advanced", Flag, "probereq", translate("Do not send probe responses"))
512 probereq.enabled = "0"
513 probereq.disabled = "1"
514 end
515
516
517 -------------------- Broadcom Interface ----------------------
518
519 if hwtype == "broadcom" then
520 mode:value("wds", translate("WDS"))
521 mode:value("monitor", translate("Monitor"))
522
523 hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
524 hidden:depends({mode="ap"})
525 hidden:depends({mode="adhoc"})
526 hidden:depends({mode="wds"})
527
528 isolate = s:taboption("advanced", Flag, "isolate", translate("Separate Clients"),
529 translate("Prevents client-to-client communication"))
530 isolate:depends({mode="ap"})
531
532 s:taboption("advanced", Flag, "doth", "802.11h")
533 s:taboption("advanced", Flag, "wmm", translate("WMM Mode"))
534
535 bssid:depends({mode="wds"})
536 bssid:depends({mode="adhoc"})
537 end
538
539
540 ----------------------- HostAP Interface ---------------------
541
542 if hwtype == "prism2" then
543 mode:value("wds", translate("WDS"))
544 mode:value("monitor", translate("Monitor"))
545
546 hidden = s:taboption("general", Flag, "hidden", translate("Hide <abbr title=\"Extended Service Set Identifier\">ESSID</abbr>"))
547 hidden:depends({mode="ap"})
548 hidden:depends({mode="adhoc"})
549 hidden:depends({mode="wds"})
550
551 bssid:depends({mode="sta"})
552
553 mp = s:taboption("macfilter", ListValue, "macpolicy", translate("MAC-Address Filter"))
554 mp:value("", translate("disable"))
555 mp:value("allow", translate("Allow listed only"))
556 mp:value("deny", translate("Allow all except listed"))
557 ml = s:taboption("macfilter", DynamicList, "maclist", translate("MAC-List"))
558 ml:depends({macpolicy="allow"})
559 ml:depends({macpolicy="deny"})
560
561 s:taboption("advanced", Value, "rate", translate("Transmission Rate"))
562 s:taboption("advanced", Value, "frag", translate("Fragmentation Threshold"))
563 s:taboption("advanced", Value, "rts", translate("RTS/CTS Threshold"))
564 end
565
566
567 ------------------- WiFI-Encryption -------------------
568
569 encr = s:taboption("encryption", ListValue, "encryption", translate("Encryption"))
570 encr.override_values = true
571 encr.override_depends = true
572 encr:depends({mode="ap"})
573 encr:depends({mode="sta"})
574 encr:depends({mode="adhoc"})
575 encr:depends({mode="ahdemo"})
576 encr:depends({mode="ap-wds"})
577 encr:depends({mode="sta-wds"})
578 encr:depends({mode="mesh"})
579
580 cipher = s:taboption("encryption", ListValue, "cipher", translate("Cipher"))
581 cipher.rmempty = false
582 cipher:depends({encryption="wpa"})
583 cipher:depends({encryption="wpa2"})
584 cipher:depends({encryption="psk"})
585 cipher:depends({encryption="psk2"})
586 cipher:depends({encryption="wpa-mixed"})
587 cipher:depends({encryption="psk-mixed"})
588 cipher:value("auto", translate("auto"))
589 cipher:value("ccmp", translate("Force CCMP (AES)"))
590 cipher:value("tkip", translate("Force TKIP"))
591 cipher:value("tkip+ccmp", translate("Force TKIP and CCMP (AES)"))
592
593 function encr.cfgvalue(self, section)
594 local v = tostring(ListValue.cfgvalue(self, section))
595 if v == "wep" then
596 return "wep-open"
597 elseif v and v:match("%+") then
598 return (v:gsub("%+.+$", ""))
599 end
600 return v
601 end
602
603 function encr.write(self, section, value)
604 local e = tostring(encr:formvalue(section))
605 local c = tostring(cipher:formvalue(section))
606 if value == "wpa" or value == "wpa2" then
607 self.map.uci:delete("wireless", section, "key")
608 end
609 if e and (c == "tkip" or c == "ccmp" or c == "tkip+ccmp") then
610 e = e .. "+" .. c
611 end
612 self.map:set(section, "encryption", e)
613 end
614
615 function cipher.cfgvalue(self, section)
616 local v = tostring(ListValue.cfgvalue(encr, section))
617 if v and v:match("%+") then
618 v = v:gsub("^[^%+]+%+", "")
619 if v == "aes" then v = "ccmp"
620 elseif v == "tkip+aes" then v = "tkip+ccmp"
621 elseif v == "aes+tkip" then v = "tkip+ccmp"
622 elseif v == "ccmp+tkip" then v = "tkip+ccmp"
623 end
624 end
625 return v
626 end
627
628 function cipher.write(self, section)
629 return encr:write(section)
630 end
631
632
633 encr:value("none", "No Encryption")
634 encr:value("wep-open", translate("WEP Open System"), {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
635 encr:value("wep-shared", translate("WEP Shared Key"), {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
636
637 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
638 local supplicant = fs.access("/usr/sbin/wpa_supplicant")
639 local hostapd = fs.access("/usr/sbin/hostapd")
640
641 if hostapd and supplicant then
642 encr:value("psk", "WPA-PSK")
643 encr:value("psk2", "WPA2-PSK")
644 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode")
645 encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
646 encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="sta"}, {mode="ap-wds"}, {mode="sta-wds"})
647 elseif hostapd and not supplicant then
648 encr:value("psk", "WPA-PSK", {mode="ap"}, {mode="ap-wds"}, {mode="adhoc"}, {mode="ahdemo"})
649 encr:value("psk2", "WPA2-PSK", {mode="ap"}, {mode="ap-wds"}, {mode="adhoc"}, {mode="ahdemo"})
650 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="ap"}, {mode="ap-wds"}, {mode="adhoc"}, {mode="ahdemo"})
651 encr:value("wpa", "WPA-EAP", {mode="ap"}, {mode="ap-wds"})
652 encr:value("wpa2", "WPA2-EAP", {mode="ap"}, {mode="ap-wds"})
653 encr.description = translate(
654 "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
655 "and ad-hoc mode) to be installed."
656 )
657 elseif not hostapd and supplicant then
658 encr:value("psk", "WPA-PSK", {mode="sta"}, {mode="sta-wds"})
659 encr:value("psk2", "WPA2-PSK", {mode="sta"}, {mode="sta-wds"})
660 encr:value("psk-mixed", "WPA-PSK/WPA2-PSK Mixed Mode", {mode="sta"}, {mode="sta-wds"})
661 encr:value("wpa", "WPA-EAP", {mode="sta"}, {mode="sta-wds"})
662 encr:value("wpa2", "WPA2-EAP", {mode="sta"}, {mode="sta-wds"})
663 encr.description = translate(
664 "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
665 "and ad-hoc mode) to be installed."
666 )
667 else
668 encr.description = translate(
669 "WPA-Encryption requires wpa_supplicant (for client mode) or hostapd (for AP " ..
670 "and ad-hoc mode) to be installed."
671 )
672 end
673 elseif hwtype == "broadcom" then
674 encr:value("psk", "WPA-PSK")
675 encr:value("psk2", "WPA2-PSK")
676 encr:value("psk+psk2", "WPA-PSK/WPA2-PSK Mixed Mode")
677 end
678
679 auth_server = s:taboption("encryption", Value, "auth_server", translate("Radius-Authentication-Server"))
680 auth_server:depends({mode="ap", encryption="wpa"})
681 auth_server:depends({mode="ap", encryption="wpa2"})
682 auth_server:depends({mode="ap-wds", encryption="wpa"})
683 auth_server:depends({mode="ap-wds", encryption="wpa2"})
684 auth_server.rmempty = true
685 auth_server.datatype = "host"
686
687 auth_port = s:taboption("encryption", Value, "auth_port", translate("Radius-Authentication-Port"), translatef("Default %d", 1812))
688 auth_port:depends({mode="ap", encryption="wpa"})
689 auth_port:depends({mode="ap", encryption="wpa2"})
690 auth_port:depends({mode="ap-wds", encryption="wpa"})
691 auth_port:depends({mode="ap-wds", encryption="wpa2"})
692 auth_port.rmempty = true
693 auth_port.datatype = "port"
694
695 auth_secret = s:taboption("encryption", Value, "auth_secret", translate("Radius-Authentication-Secret"))
696 auth_secret:depends({mode="ap", encryption="wpa"})
697 auth_secret:depends({mode="ap", encryption="wpa2"})
698 auth_secret:depends({mode="ap-wds", encryption="wpa"})
699 auth_secret:depends({mode="ap-wds", encryption="wpa2"})
700 auth_secret.rmempty = true
701 auth_secret.password = true
702
703 acct_server = s:taboption("encryption", Value, "acct_server", translate("Radius-Accounting-Server"))
704 acct_server:depends({mode="ap", encryption="wpa"})
705 acct_server:depends({mode="ap", encryption="wpa2"})
706 acct_server:depends({mode="ap-wds", encryption="wpa"})
707 acct_server:depends({mode="ap-wds", encryption="wpa2"})
708 acct_server.rmempty = true
709 acct_server.datatype = "host"
710
711 acct_port = s:taboption("encryption", Value, "acct_port", translate("Radius-Accounting-Port"), translatef("Default %d", 1813))
712 acct_port:depends({mode="ap", encryption="wpa"})
713 acct_port:depends({mode="ap", encryption="wpa2"})
714 acct_port:depends({mode="ap-wds", encryption="wpa"})
715 acct_port:depends({mode="ap-wds", encryption="wpa2"})
716 acct_port.rmempty = true
717 acct_port.datatype = "port"
718
719 acct_secret = s:taboption("encryption", Value, "acct_secret", translate("Radius-Accounting-Secret"))
720 acct_secret:depends({mode="ap", encryption="wpa"})
721 acct_secret:depends({mode="ap", encryption="wpa2"})
722 acct_secret:depends({mode="ap-wds", encryption="wpa"})
723 acct_secret:depends({mode="ap-wds", encryption="wpa2"})
724 acct_secret.rmempty = true
725 acct_secret.password = true
726
727 wpakey = s:taboption("encryption", Value, "_wpa_key", translate("Key"))
728 wpakey:depends("encryption", "psk")
729 wpakey:depends("encryption", "psk2")
730 wpakey:depends("encryption", "psk+psk2")
731 wpakey:depends("encryption", "psk-mixed")
732 wpakey.datatype = "wpakey"
733 wpakey.rmempty = true
734 wpakey.password = true
735
736 wpakey.cfgvalue = function(self, section, value)
737 local key = m.uci:get("wireless", section, "key")
738 if key == "1" or key == "2" or key == "3" or key == "4" then
739 return nil
740 end
741 return key
742 end
743
744 wpakey.write = function(self, section, value)
745 self.map.uci:set("wireless", section, "key", value)
746 self.map.uci:delete("wireless", section, "key1")
747 end
748
749
750 wepslot = s:taboption("encryption", ListValue, "_wep_key", translate("Used Key Slot"))
751 wepslot:depends("encryption", "wep-open")
752 wepslot:depends("encryption", "wep-shared")
753 wepslot:value("1", translatef("Key #%d", 1))
754 wepslot:value("2", translatef("Key #%d", 2))
755 wepslot:value("3", translatef("Key #%d", 3))
756 wepslot:value("4", translatef("Key #%d", 4))
757
758 wepslot.cfgvalue = function(self, section)
759 local slot = tonumber(m.uci:get("wireless", section, "key"))
760 if not slot or slot < 1 or slot > 4 then
761 return 1
762 end
763 return slot
764 end
765
766 wepslot.write = function(self, section, value)
767 self.map.uci:set("wireless", section, "key", value)
768 end
769
770 local slot
771 for slot=1,4 do
772 wepkey = s:taboption("encryption", Value, "key" .. slot, translatef("Key #%d", slot))
773 wepkey:depends("encryption", "wep-open")
774 wepkey:depends("encryption", "wep-shared")
775 wepkey.datatype = "wepkey"
776 wepkey.rmempty = true
777 wepkey.password = true
778
779 function wepkey.write(self, section, value)
780 if value and (#value == 5 or #value == 13) then
781 value = "s:" .. value
782 end
783 return Value.write(self, section, value)
784 end
785 end
786
787
788 if hwtype == "atheros" or hwtype == "mac80211" or hwtype == "prism2" then
789 nasid = s:taboption("encryption", Value, "nasid", translate("NAS ID"))
790 nasid:depends({mode="ap", encryption="wpa"})
791 nasid:depends({mode="ap", encryption="wpa2"})
792 nasid:depends({mode="ap-wds", encryption="wpa"})
793 nasid:depends({mode="ap-wds", encryption="wpa2"})
794 nasid.rmempty = true
795
796 eaptype = s:taboption("encryption", ListValue, "eap_type", translate("EAP-Method"))
797 eaptype:value("tls", "TLS")
798 eaptype:value("ttls", "TTLS")
799 eaptype:value("peap", "PEAP")
800 eaptype:depends({mode="sta", encryption="wpa"})
801 eaptype:depends({mode="sta", encryption="wpa2"})
802 eaptype:depends({mode="sta-wds", encryption="wpa"})
803 eaptype:depends({mode="sta-wds", encryption="wpa2"})
804
805 cacert = s:taboption("encryption", FileUpload, "ca_cert", translate("Path to CA-Certificate"))
806 cacert:depends({mode="sta", encryption="wpa"})
807 cacert:depends({mode="sta", encryption="wpa2"})
808 cacert:depends({mode="sta-wds", encryption="wpa"})
809 cacert:depends({mode="sta-wds", encryption="wpa2"})
810
811 privkey = s:taboption("encryption", FileUpload, "priv_key", translate("Path to Private Key"))
812 privkey:depends({mode="sta", eap_type="tls", encryption="wpa2"})
813 privkey:depends({mode="sta", eap_type="tls", encryption="wpa"})
814 privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
815 privkey:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
816
817 privkeypwd = s:taboption("encryption", Value, "priv_key_pwd", translate("Password of Private Key"))
818 privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa2"})
819 privkeypwd:depends({mode="sta", eap_type="tls", encryption="wpa"})
820 privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa2"})
821 privkeypwd:depends({mode="sta-wds", eap_type="tls", encryption="wpa"})
822
823
824 auth = s:taboption("encryption", Value, "auth", translate("Authentication"))
825 auth:value("PAP")
826 auth:value("CHAP")
827 auth:value("MSCHAP")
828 auth:value("MSCHAPV2")
829 auth:depends({mode="sta", eap_type="peap", encryption="wpa2"})
830 auth:depends({mode="sta", eap_type="peap", encryption="wpa"})
831 auth:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
832 auth:depends({mode="sta", eap_type="ttls", encryption="wpa"})
833 auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
834 auth:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
835 auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
836 auth:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
837
838
839 identity = s:taboption("encryption", Value, "identity", translate("Identity"))
840 identity:depends({mode="sta", eap_type="peap", encryption="wpa2"})
841 identity:depends({mode="sta", eap_type="peap", encryption="wpa"})
842 identity:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
843 identity:depends({mode="sta", eap_type="ttls", encryption="wpa"})
844 identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
845 identity:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
846 identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
847 identity:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
848
849 password = s:taboption("encryption", Value, "password", translate("Password"))
850 password:depends({mode="sta", eap_type="peap", encryption="wpa2"})
851 password:depends({mode="sta", eap_type="peap", encryption="wpa"})
852 password:depends({mode="sta", eap_type="ttls", encryption="wpa2"})
853 password:depends({mode="sta", eap_type="ttls", encryption="wpa"})
854 password:depends({mode="sta-wds", eap_type="peap", encryption="wpa2"})
855 password:depends({mode="sta-wds", eap_type="peap", encryption="wpa"})
856 password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa2"})
857 password:depends({mode="sta-wds", eap_type="ttls", encryption="wpa"})
858 end
859
860 return m