Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
16 changes: 16 additions & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,22 @@

Use it as a local utility or run it on a remote VM to expose WoL via an HTTP API.

## ✨ What's New

### Latest: v1.0.10 (October 2026)

- **Dev-tooling dependency bumps ([#35](https://github.com/CLDMV/wol-proxy/pull/35), [#38](https://github.com/CLDMV/wol-proxy/pull/38), [#40](https://github.com/CLDMV/wol-proxy/pull/40))** — `@cldmv/fix-headers` moves to 2.2.0, `@cldmv/configs` to 1.2.4 and `@cldmv/vitest-runner` to 1.5.3. No file headers changed and no runtime code changed: the Express server and `postinstall.js` are as in the previous version, so it's a drop-in replacement.
- [View full v1.0.10 Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.10.md)

### Recent Releases

- **v1.0.9** (October 2026) — CI only: the in-repo PR mirror job now always runs and reports under a non-required name instead of being skipped ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.9.md))
- **v1.0.8** (October 2026) — CI only: a skipped PR-run mirror job no longer satisfies the `✅ Required PR Check` ruleset gate ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.8.md))
- **v1.0.7** (October 2026) — workflows synced to the CLDMV/.github v4.29.2 templates, shared fix-headers config (comment-only headers in `index.js` and `postinstall.js`), vitest 5.0.2; no runtime change ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.7.md))
- **v1.0.6** (September 2026) — vitest 5 test toolchain and a CI Node matrix of 22.12.0–26; Express's transitive `qs` moves to 6.16.0 in the lockfile ([Changelog](https://github.com/CLDMV/wol-proxy/blob/master/docs/changelog/v1/v1.0.6.md))

📚 **For complete version history and detailed release notes, see the [docs/changelog/](https://github.com/CLDMV/wol-proxy/tree/master/docs/changelog/) folder.**

---

## 📦 Installation
Expand Down
52 changes: 52 additions & 0 deletions docs/changelog/v1/v1.0.0.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,52 @@
# wol-proxy v1.0.0 Changelog

**Release Date**: June 2025
**Release Type**: Initial release

---

## Overview

First release of `@cldmv/wol-proxy`, published to npm on 2025-06-29. wol-proxy is a small cross-platform CLI tool and HTTP server that sends Wake-on-LAN (WoL) magic packets, so a device on your network can be powered on by sending an HTTP request. Run it locally as a utility, or on an always-on machine or VM to expose WoL over HTTP.

The whole implementation is a single file, `index.js`, built on `express` (^5.1.0) and `wake_on_lan` (^1.0.0).

---

## ✨ Features

### `wol-proxy` command and HTTP server

- Installs a `wol-proxy` executable (`bin` → `index.js`) that starts an Express server bound to `0.0.0.0`.
- Listens on port **3000** by default; override with the `PORT` environment variable.

### `POST /wake`

Accepts a JSON body and broadcasts a magic packet through `wake_on_lan`:

| Field | Required | Default | Description |
| ------ | -------- | ----------------- | ---------------------------- |
| `mac` | yes | none | Target device MAC address |
| `ip` | no | `255.255.255.255` | Broadcast address to send to |
| `port` | no | `9` | UDP port |

- Success returns `{ "success": true }` and logs `Sent WoL to <mac> via <ip>:<port>`.
- A missing `mac` returns HTTP 400 with `{ "error": "MAC required" }`.
- A failure from the WoL library returns HTTP 500 with `{ "error": "<message>" }`.

### Documentation

- The README covers usage, a `curl` example, the request options table, a quick test, development setup and the GPL-3.0 license.
- It notes that the server is unauthenticated and recommends a reverse proxy with IP allow-listing or auth, a firewall, or a VPN.
- The README's install command at this release is `npm install -g wol-proxy` (unscoped), while the published package name is `@cldmv/wol-proxy`.

### Repository

- A comprehensive `.gitignore` was added and the license is declared as GPL-3.0.

---

## Upgrade notes

- First release; nothing to upgrade from.
- The server has no authentication. Do not expose it to untrusted networks without a reverse proxy, firewall or VPN in front of it.
55 changes: 55 additions & 0 deletions docs/changelog/v1/v1.0.1.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,55 @@
# wol-proxy v1.0.1 Changelog

**Release Date**: June 2025
**Release Type**: Patch

---

## Overview

Adds systemd service support, shipped as a patch release and published to npm on 2025-06-29, about twenty minutes after v1.0.0. A bundled `wol-proxy.service` unit file and a `postinstall.js` script let the tool be set up as a background service on Linux. The HTTP server itself (`index.js`) is unchanged from [v1.0.0](./v1.0.0.md).

Although it carries a patch version, this is a feature addition, and it changes what `npm install` does: a `postinstall` script now runs on install and, on systemd systems, calls `sudo` to copy a file into `/etc/systemd/system`. It does not change the runtime API and is not a breaking change, but it is behavior you should know about before installing.

---

## ✨ Features

### Systemd service file

- New `wol-proxy.service` unit: `ExecStart=/usr/bin/env wol-proxy`, `Restart=on-failure` with `RestartSec=3`, `Environment=PORT=3000`, output to the journal, `WantedBy=multi-user.target`.
- The unit has no `User=` setting, so systemd runs the service as root unless you edit it.

### `postinstall.js`

Wired up as the package's `postinstall` script, so it runs on every install of the package (global installs included). What it does:

- Looks for `/etc/systemd/system`, and failing that `/bin/systemctl`, to decide whether this is a systemd Linux system. Otherwise it prints "Skipping systemd setup" and does nothing.
- On a systemd system it runs `sudo cp wol-proxy.service /etc/systemd/system/wol-proxy.service` followed by `sudo systemctl daemon-reload`, with output attached to the terminal (so `sudo` may prompt for a password).
- It does **not** enable or start the service; it prints the `sudo systemctl enable wol-proxy` and `sudo systemctl start wol-proxy` commands for you to run.
- If the copy fails, it prints a warning to install manually with sudo, and the npm install still succeeds.
- If only `/bin/systemctl` is found (no `/etc/systemd/system` directory), the script builds its destination path under `/bin/systemctl/`, which fails and falls into the warning above.

### Package contents

- A `files` whitelist now limits the published package to `index.js`, `postinstall.js`, `wol-proxy.service`, `README.md` and `LICENSE`.
- `publishConfig.access` is set to `public`.

---

## 📚 Documentation

- The README gains a "Running as a System Service" section: the automatic install attempt, manual setup (copying the bundled unit file from the global npm root), enabling and starting the service, checking status with `systemctl status`, and viewing logs with `journalctl -u wol-proxy -f`.

---

## 🐛 Packaging note

- `package.json` in this release contains two `"scripts"` keys: the original one with the placeholder `test` script and a second one with only `postinstall`. When parsed, the later key wins, so the effective scripts object is just `{ "postinstall": "node postinstall.js" }` and the placeholder `test` script is dropped. This is cleaned up in [v1.0.2](./v1.0.2.md).

---

## Upgrade notes

- No breaking changes to the HTTP API or CLI; drop-in for v1.0.0.
- Installing now runs `postinstall.js`, which on systemd Linux uses `sudo` to place a unit file in `/etc/systemd/system` and reload systemd. Nothing is enabled or started automatically.
34 changes: 34 additions & 0 deletions docs/changelog/v1/v1.0.10.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# wol-proxy v1.0.10 Changelog

**Release Date**: October 2026
**Release Type**: Patch
**Branch**: `next` → `master`

---

## Overview

A dev-tooling dependency release. Three development dependencies move forward: `@cldmv/fix-headers`, which maintains the comment headers at the top of the repository's source, test, config and workflow files (2.1.1 to 2.2.0), `@cldmv/configs`, the shared lint, format and header configuration (1.2.0 to 1.2.4), and `@cldmv/vitest-runner`, the test runner (1.2.0 to 1.5.3).

No runtime code changed: `index.js`, `postinstall.js` and `wol-proxy.service` are exactly as in v1.0.9, and the runtime dependency ranges (`express` `^5.1.0`, `wake_on_lan` `^1.0.0`) and their lockfile entries are unchanged. The only other lockfile movement is `chalk` 5.6.2 to 6.0.1, a dev-only dependency of the test runner. No file headers were restamped by either fix-headers step, so the files touched are `package.json`, `package-lock.json` and the documentation.

---

## 🔧 Dependencies

All dev-only; nothing that ships depends on them.

- **`@cldmv/fix-headers` `^2.1.1` → `^2.2.0`** (locked 2.1.1 to 2.2.0), in two steps: 2.1.4 ([#35](https://github.com/CLDMV/wol-proxy/pull/35)) and 2.2.0 ([#40](https://github.com/CLDMV/wol-proxy/pull/40)). The 2.1.x line no longer stamps a header into files that have no usable comment syntax (strict JSON such as `package.json`, and Markdown unless explicitly forced), never walks into `node_modules` or other dependency folders, and processes every repeated `--input` value instead of only the last. From 2.2.0 the `@Last modified by` tag follows content edits only, so a header-only rewrite keeps the recorded editor. It only runs through the `fix:headers` script. Neither step changed any header in this repository.
- **`@cldmv/configs` `^1.2.0` → `^1.2.4`** (locked 1.2.0 to 1.2.4) ([#40](https://github.com/CLDMV/wol-proxy/pull/40)). Version 1.2.4 sets `forceAuthorUpdate` and `forceLastModifiedAuthorUpdate` to `false`, so `@Author` is never rewritten and `@Last modified by` changes only on real content edits. Re-running `fix:headers` under the new config restamped no files.
- **`@cldmv/vitest-runner` `^1.2.0` → `^1.5.3`** (locked 1.2.0 to 1.5.3) ([#38](https://github.com/CLDMV/wol-proxy/pull/38)). This restores the bump from [#30](https://github.com/CLDMV/wol-proxy/pull/30), which merged into `next` just after the previous release and was dropped by the post-release reset of `next` ([CLDMV/.github#360](https://github.com/CLDMV/.github/issues/360)); it is reinstalled at the latest version instead of the original 1.5.1. The runner's own `chalk` dependency moves from `^5.4.1` to `^6.0.1` (locked 5.6.2 to 6.0.1), which requires Node 22 or newer; the CI matrix already starts at 22.12.0.

## 📚 Documentation

- **NEW:** [docs/changelog/v1/v1.0.10.md](./v1.0.10.md) — this changelog.
- Changelogs for earlier releases that shipped without one were added in the same pass (see the [docs/changelog/](https://github.com/CLDMV/wol-proxy/tree/master/docs/changelog/) folder).

---

## Upgrade notes

- No breaking changes, and no runtime code changed. It's a drop-in replacement for v1.0.9.
63 changes: 63 additions & 0 deletions docs/changelog/v1/v1.0.2.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,63 @@
# wol-proxy v1.0.2 Changelog

**Release Date**: August 2026
**Release Type**: Patch

---

## Overview

First release through the CLDMV v4 staging-branch workflow. The headline change is repository tooling: a full set of `CLDMV/.github` v4 workflows, a Vitest-based test suite for the previously untested server, and refreshed transitive dependencies. The release PR was [#7](https://github.com/CLDMV/wol-proxy/pull/7).

No runtime source changed: `index.js`, `postinstall.js`, `wol-proxy.service` and the README are identical to [v1.0.1](./v1.0.1.md). The only change a consumer can observe is newer resolved versions of Express's transitive dependencies in the repo's lockfile.

---

## 🔧 CI & tooling

### Adopt CLDMV v4 workflows and Vitest tests ([#4](https://github.com/CLDMV/wol-proxy/pull/4))

- Adds the v4 workflow set under `.github/workflows/` (CI, publish, feature-PR opener, next/hotfixes release, next-reset, hotfix-redirector, labeler, PR-title normalizer, master-commit audit, release notify, tag health, major-tag updater, v4 bootstrap, CLA, CodeQL, Scorecard, dependency review, Dependabot auto-merge, stale, welcome, branch retention), all thin callers of `CLDMV/.github` reusable workflows pinned `@v4`, plus `.github/dependabot.yml`. Releases now go through a `next` to `master` release PR.
- Adds a `@cldmv/vitest-runner` test setup: `.configs/vitest.config.mjs` (coverage measured on `index.js`), `tests/run-vitest.mjs`, and two test files that characterize `index.js`: `wake-endpoint.test.vitest.mjs` (the `POST /wake` route with a stubbed `wake_on_lan`) and `port-fallback.test.vitest.mjs` (the `PORT` / default-3000 selection).
- New scripts: `test`, `test:watch`, `coverage`, `ci:coverage`, and placeholder `build` / `build:ci` scripts that only echo (the CI coverage job runs `npm run build`).
- New dev dependencies: `@cldmv/vitest-runner` ^1.2.0, `@vitest/coverage-v8` ^4.1.10, `vitest` ^4.1.10.

### Test file naming ([#6](https://github.com/CLDMV/wol-proxy/pull/6))

- Test files use the `*.test.vitest.mjs` suffix, and the Vitest config's include glob matches it.

### `package.json` cleanup

- The duplicated `"scripts"` key from v1.0.1 is merged into a single object. Because the later key used to win when parsed, the effective scripts before this release were only `postinstall`; the merged object keeps `postinstall` and adds the new scripts above.
- Runtime dependency ranges (`express` ^5.1.0, `wake_on_lan` ^1.0.0) are unchanged.

---

## 🔧 Dependencies

### Transitive security bumps ([#5](https://github.com/CLDMV/wol-proxy/pull/5))

Lockfile-only refresh of runtime transitive dependencies; the `package.json` ranges did not change. Consumers installing from the registry resolve their own versions; the lockfile applies to the repo's own CI and local installs. Notable changes:

- `express` 5.1.0 to 5.2.1
- `body-parser` 2.2.0 to 2.3.0
- `qs` 6.14.0 to 6.15.3
- `path-to-regexp` 8.2.0 to 8.4.2
- `send` 1.2.0 to 1.2.1 and `serve-static` 2.2.0 to 2.2.1
- `iconv-lite` 0.6.3 to 0.7.3, `raw-body` 3.0.0 to 3.0.2, `type-is` 2.0.1 to 2.1.0, `debug` 4.4.1 to 4.4.3, `http-errors` 2.0.0 to 2.0.1, `mime-types` 3.0.1 to 3.0.2
- Smaller bumps to `content-disposition`, `finalhandler`, `range-parser`, `side-channel` and related packages, and removal of the now-unneeded `safe-buffer`.

The lockfile also now records the package under its scoped name `@cldmv/wol-proxy` at the current version, with `license` GPL-3.0 and `hasInstallScript`, and includes the new dev dependencies.

---

## 📚 Documentation

- **NEW:** [docs/changelog/v1/v1.0.2.md](./v1.0.2.md) — this changelog (added retroactively).

---

## Upgrade notes

- No breaking changes — drop-in for v1.0.1.
- No runtime code changed; the new files are CI configuration and tests, and the `build` scripts are placeholders.
35 changes: 35 additions & 0 deletions docs/changelog/v1/v1.0.3.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,35 @@
# wol-proxy v1.0.3 Changelog

**Release Date**: August 2026
**Release Type**: Patch

---

## Overview

CI-only release: the `ci.yml` concurrency rules are changed so runs that matter for releasing are never cancelled by newer pushes. The release PR was [#9](https://github.com/CLDMV/wol-proxy/pull/9) and carries [#8](https://github.com/CLDMV/wol-proxy/pull/8).

No runtime code changed, and the lockfile differs from [v1.0.2](./v1.0.2.md) only in the package version. The diff touches `.github/workflows/ci.yml` and the version in `package.json`.

---

## 🔧 CI & tooling

### Never supersede release-relevant CI runs ([#8](https://github.com/CLDMV/wol-proxy/pull/8))

- Pushes to the release base branch (taken from the `CLDMV_RELEASE_BASE` variable, else the repository's default branch), pushes to `next` and `hotfixes`, and the `next` / `hotfixes` release PRs each get a unique concurrency group per run (the run id is appended).
- Feature branches and feature PRs still cancel superseded runs.
- Previously a burst of pushes during a release could cancel a pending run, leaving a red "cancelled" check on the release PR even though nothing had failed.

---

## 📚 Documentation

- **NEW:** [docs/changelog/v1/v1.0.3.md](./v1.0.3.md) — this changelog (added retroactively).

---

## Upgrade notes

- No breaking changes — drop-in for v1.0.2.
- No runtime code changed.
44 changes: 44 additions & 0 deletions docs/changelog/v1/v1.0.4.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,44 @@
# wol-proxy v1.0.4 Changelog

**Release Date**: August 2026
**Release Type**: Patch

---

## Overview

Maintenance release: bot-identity wiring in three release workflows and a patch-level bump of the Vitest toolchain. The release PR was [#12](https://github.com/CLDMV/wol-proxy/pull/12), which carries [#10](https://github.com/CLDMV/wol-proxy/pull/10) and [#11](https://github.com/CLDMV/wol-proxy/pull/11).

No runtime code changed, and the runtime part of the lockfile is identical to [v1.0.3](./v1.0.3.md). Only dev dependencies moved, so only the repo's test and CI toolchain is affected.

---

## 🔧 CI & tooling

### Recognize the bot identity ([#10](https://github.com/CLDMV/wol-proxy/pull/10))

- `feature-pr.yml`, `next-release.yml` and `hotfixes-release.yml` now pass `BOT_NAME` and `BOT_EMAIL` (from the `CLDMV_BOT_NAME` and `CLDMV_BOT_EMAIL` secrets), so bot-authored commits and PRs use the real bot identity. The PR re-triggered the feature-PR opener against the fixed `@v4` workflows.

---

## 🔧 Dependencies

### Patch group bump ([#11](https://github.com/CLDMV/wol-proxy/pull/11))

Dev dependencies only; `package.json` ranges are unchanged and the lockfile moved:

- `vitest` and `@vitest/coverage-v8` 4.1.10 to 4.1.11, along with the rest of the `@vitest/*` family.
- `vite` 8.2.0 to 8.2.2 and `rolldown` 1.2.1 to 1.2.5, plus smaller transitive bumps (`postcss`, `nanoid`, `@oxc-project/types`) and removal of some unused WASM fallback packages.

---

## 📚 Documentation

- **NEW:** [docs/changelog/v1/v1.0.4.md](./v1.0.4.md) — this changelog (added retroactively).

---

## Upgrade notes

- No breaking changes — drop-in for v1.0.3.
- No runtime code changed; dev dependencies only.
34 changes: 34 additions & 0 deletions docs/changelog/v1/v1.0.5.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,34 @@
# wol-proxy v1.0.5 Changelog

**Release Date**: September 2026
**Release Type**: Patch

---

## Overview

CI-only release: the `hotfix-redirector` workflow now has the signing secrets it needs so redirected security PRs are signed. The release PR was [#14](https://github.com/CLDMV/wol-proxy/pull/14), carrying [#13](https://github.com/CLDMV/wol-proxy/pull/13).

No runtime code changed and the lockfile differs from [v1.0.4](./v1.0.4.md) only in the package version. The diff is four added lines in `.github/workflows/hotfix-redirector.yml` plus the version bump.

---

## 🔒 Security & supply chain

### Sign redirected security PRs ([#13](https://github.com/CLDMV/wol-proxy/pull/13))

- `hotfix-redirector.yml` now maps `BOT_NAME`, `BOT_EMAIL`, `BOT_GPG_PRIVATE_KEY` and `BOT_GPG_PASSPHRASE` from the `CLDMV_BOT_*` secrets.
- When a Dependabot security PR is redirected away from `master`, the cherry-picked commit is now signed. Unsigned redirected commits were blocked by the repository's signature rule.

---

## 📚 Documentation

- **NEW:** [docs/changelog/v1/v1.0.5.md](./v1.0.5.md) — this changelog (added retroactively).

---

## Upgrade notes

- No breaking changes — drop-in for v1.0.4.
- No runtime code changed.
Loading
Loading