Page MenuHomeVyOS Platform

webproxy: several url-filtering options are accepted by the CLI but never used
Open, Requires assessmentPublicBUG

Description

Several service webproxy url-filtering squidguard nodes are accepted by the CLI but never read by squidGuard.conf.j2 or service_webproxy.py. They have no effect and
nothing warns the user. Checked on a 2026.09.30-1921-rolling image (generated squidGuard.conf, squidGuard run against test URLs).

Not used at all:

  • source-group <name> domain, user, ldap-ip-search, ldap-user-search (only address is rendered)
  • every time-period <name> ... node and rule <n> time-period

Rule level ignored, only the global value counts:

  • rule <n> allow-ipaddr-url, enable-safe-search, redirect-url, log

Also: log <category> only checks "is defined", one entry enables logging for all categories.

set service webproxy url-filtering squidguard source-group sg1 address 192.0.2.0/24
set service webproxy url-filtering squidguard source-group sg1 domain example.local
set service webproxy url-filtering squidguard time-period work days Mon time 08:00-17:00
set service webproxy url-filtering squidguard rule 10 source-group sg1
set service webproxy url-filtering squidguard rule 10 time-period work
commit

The generated config has "src sg1" with the ip lines only, no domain or time match.

Expected: implement the options or remove them from service_webproxy.xml.in. At least warn in verify().

Details

Version
1.5.1
Is it a breaking change?
Unspecified (possibly destroys the router)
Issue type
Bug (incorrect behavior)