wg_iface.removePeer() previously just did `wg set ... remove` -- the
kernel routes setPeer() adds for a peer's AllowedIPs (since wg itself
only configures crypto-routing, not kernel routes -- see setPeer's own
comment) were never cleaned up, a real TODO flagged in code but never
exercised because nothing removed a mesh peer at all.
- removePeer() now queries the peer's current AllowedIPs (`wg show
<iface> allowed-ips`) BEFORE removing it -- once gone, wg no longer
knows what to clean up -- and issues `ip route del` for each.
- New DELETE /api/mesh/gateways/:id (models/mesh_gateway.js gained
remove()) actually calls removePeer(), so the fix has a real caller;
previously there was no removal path anywhere in the mesh feature at
all. Refuses to remove the local "(self)" entry. Does not reach out
to the remote gateway to remove the reciprocal peer -- that side
needs the same action taken independently.
- Mesh UI: remove button per non-self peer row, using app.messages.confirm
(not native confirm() -- caught by this repo's own no-native-dialogs
test, which failed on first pass and is now green).
Verified for real with a live WireGuard interface in a container: routes
for a peer's AllowedIPs present after setPeer, confirmed gone after
removePeer, while the interface's own local route correctly survives.
The mesh API (routes/mesh.js) had zero UI -- minting a join token,
joining a remote gateway, or seeing what's meshed all required calling
the API directly. New Mesh page (nav: Dashboard/Sessions/WireGuard/
Mesh/Audit):
- This Gateway card: interface name, kernel-vs-userspace WireGuard mode
(wireguard-go fallback), meshed-gateway count.
- Mint a Join Token: calls POST /api/mesh/join-tokens, shows the
single-use token once.
- Join a Remote Gateway's Mesh: calls POST /api/mesh/join with a remote
endpoint + token.
- Meshed Gateways table: site, mesh index, mesh subnet, endpoint, public
key, last seen -- including this gateway's own self-entry.
EJS compile verified; jump-host's existing test suite (34 tests) still
passes. Not yet visually driven in a browser the way sso-manager-node's
modal was (jump-host's OIDC-based admin auth is a heavier lift to stand
up for a one-off check) -- route registration, EJS compilation, and the
API layer underneath are verified; the actual click-through is not.