evilsocket / evilsocket/opensnitch

[Feature Request] Add ability to select a single file for rules, ontop of a directory.

Open
#1,015 0 comments 1 reaction 0 assignees View on GitHub
feature
Dominant language
Python
Stars
14.1k
Forks
665
PR merge metrics
No merged PRs in 30d

Description

### Summary:
According to https://github.com/evilsocket/opensnitch/wiki/block-lists#limiting-to-what-domains-an-application-can-connect-to we have to select a directory in which any filename can be placed to list rules.

The current functionality is nice for downloaded rules, with unknown filenames, but it is absurd for admin-created rule files, because an admin creates files them self and place them alongside other files that might contain rules to allow/reject/deny.

**_So to be backward-compatible, i suggest to add functionality to check if the selection is a directory or a single file._**
- Directory = Old behavior.
- Single file= Only use that specific file for the rule.

#### Example use-case:
1. We have a single app that we want to control.
1. We want to create explicit rules to **allow** some destinations using `reExp`.
1. We want to create explicit rules to **reject** some destinations using `reExp`.
1. We want to create a catch-all to **deny** unknown destinations.

- Current way:
Create **multiple directories** containing single files. __(**This is VERY ugly for an admin !**)__
- Enhancement:
We want multiple files to be kept inside a **single directory**, that can be selected in separate rules.
Example file paths:
- `appX/allow-re.txt`
- `appX/reject-re.txt`
- `admin-rules/appX-allow-re.txt`
- `admin-rules/appX-reject-re.txt`
- `admin-rules/appY-allow-re.txt`
- `admin-rules/appY-reject-re.txt`

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.