Skip to content

Commit c5a8f5c

Browse files
fengyilyclaude
andcommitted
Fix --visable flag to support no-argument usage and correct README concepts
- Set NoOptDefVal on --visable flag so it works without a value (defaults to "visable") - Fix README: invisible mode is the default, visible mode requires --visable - Fix README: visibility is about authorization (Site URL access), not console display - Remove API Tunnel line from example output - Fix stray dot syntax error in root.go Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
1 parent a21417e commit c5a8f5c

3 files changed

Lines changed: 100 additions & 53 deletions

File tree

‎README.md‎

Lines changed: 61 additions & 42 deletions
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,7 @@ Traditional remote access requires installing dedicated clients (RDP client, VNC
3838

3939
- **Browser-Based Access** — RDP, VNC, SSH all rendered in the browser via HTML5, no plugins or client software needed
4040
- **Zero Config** — Just specify protocol and target, everything else is automatic
41-
- **Visible & Invisible Modes** — Choose whether the tunnel is listed in the management console or hidden
41+
- **Visible & Invisible Modes** — Control whether unauthorized users can access the service via the Site URL alone
4242
- **Cross-Platform** — Linux, macOS, Windows native support
4343
- **Encrypted Tunnels** — Built on [chisel](https://github.com/jpillora/chisel) with WebSocket transport
4444
- **Auto Credentials** — Machine fingerprint-based identity, encrypted local storage
@@ -65,43 +65,53 @@ Once the tunnel is established, open the **Access URL** in any browser — that'
6565

6666
## Visibility Modes
6767

68-
Shield CLI supports two visibility modes controlled by the `--visible` flag:
68+
Shield CLI supports two access modes controlled by the `--visable` flag.
6969

70-
### Visible Mode (default)
70+
When a tunnel is established, two URLs are generated:
7171

72-
The tunnel and its associated application are listed in the management console. Ideal for shared services that team members need to discover and access.
72+
- **Site URL** — The application address (e.g., `https://xxxx.hk01.apps.yishield.com`). This URL alone is **not accessible** without authorization.
73+
- **Access URL** — Contains an embedded authorization key. Anyone with this URL can access the service directly.
74+
75+
### Visible Mode
76+
77+
The service is **open to unauthorized users** — anyone who knows the Site URL can access it without an authorization key. Suitable for services that are intended to be publicly reachable.
7378

7479
```bash
75-
# Visible: appears in the console, team members can find and access it
76-
shield -t rdp -s 10.0.0.5:3389
80+
# Visible: the Site URL is accessible without authorization
81+
shield --visable -t rdp -s 10.0.0.5:3389
82+
83+
# Filter a specific AC node by name
84+
shield --visable=HK -t ssh -s 10.0.0.2:22
7785
```
7886

7987
**Use cases:**
80-
- Shared development servers that the whole team needs
88+
89+
- Public demo environments
90+
- Shared development servers for the whole team
8191
- Staging environments for QA testing
82-
- Internal tools and dashboards
8392

84-
### Invisible Mode
93+
### Invisible Mode (default)
8594

86-
The tunnel works identically but is **hidden from the management console**. Only users with the direct Access URL can connect. Ideal for temporary, sensitive, or personal access.
95+
The service **requires authorization** — the Site URL alone will not grant access. Users must use the Access URL (which contains the authorization key) to connect. This is the secure default for all services.
8796

8897
```bash
89-
# Invisible: works the same, but hidden from the console
90-
shield --visible=false -t rdp -s 10.0.0.5:3389
98+
# Invisible (default): only the Access URL (with key) grants access
99+
shield -t rdp -s 10.0.0.5:3389
91100

92-
# Invisible SSH tunnel for a quick debugging session
93-
shield --visible=false -t ssh -s 10.0.0.2:22
101+
# Secure SSH tunnel — share the Access URL with specific people
102+
shield -t ssh -s 10.0.0.2:22
94103

95-
# Invisible VNC access to a lab machine
96-
shield --visible=false -t vnc -s 192.168.1.50:5900
104+
# Secure VNC access to a lab machine
105+
shield -t vnc -s 192.168.1.50:5900
97106
```
98107

99108
**Use cases:**
100-
- Temporary access during incident response — share the URL, close when done
101-
- Personal development machines that don't need to be discoverable
102-
- Sensitive servers where access should be strictly URL-based
103109

104-
> In both modes, the Access URL is printed to the terminal. The only difference is whether the tunnel appears in the management console.
110+
- Production servers that must not be publicly accessible
111+
- Temporary access during incident response — share the Access URL, revoke when done
112+
- Sensitive machines where access is restricted to authorized users only
113+
114+
> Both modes print the Site URL and Access URL to the terminal. The difference is whether the Site URL alone is sufficient to access the service, or whether the authorization key in the Access URL is required.
105115
106116
## Installation
107117

@@ -127,7 +137,7 @@ Flags:
127137
-s, --source string Target address in ip:port format [required]
128138
-H, --server string API server URL (default: https://console.yishield.com/raas)
129139
-p, --tunnel-port int Chisel tunnel server port (default: 62888)
130-
--visible Show tunnel in console (default: true)
140+
--visable [filter] Enable visible mode (optional: AC node name filter)
131141
-v, --verbose Enable verbose log output
132142
-h, --help Help for shield
133143
```
@@ -143,7 +153,6 @@ Flags:
143153
Shield CLI - Secure Tunnel Connector
144154
145155
⚡ Tunnel Mapping
146-
API Tunnel: remote:63203 ←→ local:4000
147156
App Tunnel: remote:58845 ←→ 172.16.3.137:22
148157
Server: 121.43.154.105:62888
149158
@@ -212,7 +221,7 @@ Shield CLI 是一个安全内网穿透工具,支持通过浏览器直接访问
212221

213222
- **浏览器直接访问** — RDP、VNC、SSH 均通过 HTML5 在浏览器中渲染,无需安装客户端
214223
- **零配置** — 只需指定协议和目标地址,其余自动完成
215-
- **可见/隐身模式** — 选择隧道是否在管理控制台中显示
224+
- **可见/隐身模式** — 控制未授权用户是否可以通过 Site URL 直接访问服务
216225
- **跨平台** — 原生支持 Linux、macOS、Windows
217226
- **加密隧道** — 基于 [chisel](https://github.com/jpillora/chisel) 的 WebSocket 传输
218227
- **自动凭证** — 基于机器指纹的身份标识,本地加密存储
@@ -239,43 +248,53 @@ shield -t http -s 192.168.1.100:8080
239248

240249
### 可见与隐身模式
241250

242-
通过 `--visible` 参数控制隧道在管理控制台中的可见性:
251+
隧道建立后会生成两个 URL:
243252

244-
#### 可见模式(默认)
253+
- **Site URL** — 应用地址(如 `https://xxxx.hk01.apps.yishield.com`)。单独使用此 URL **无法访问**,需要授权。
254+
- **Access URL** — 包含内嵌授权密钥的链接。拥有此 URL 的人可以直接访问服务。
245255

246-
隧道及关联应用在管理控制台中可见,适合团队共享的服务。
256+
通过 `--visable` 参数控制服务的访问权限:
257+
258+
#### 可见模式
259+
260+
服务**对未授权用户开放** — 任何知道 Site URL 的人都可以直接访问,无需授权密钥。适合需要公开访问的服务。
247261

248262
```bash
249-
# 可见模式:出现在控制台,团队成员可以发现并访问
250-
shield -t rdp -s 10.0.0.5:3389
263+
# 可见模式:Site URL 无需授权即可访问
264+
shield --visable -t rdp -s 10.0.0.5:3389
265+
266+
# 指定特定 AC 节点
267+
shield --visable=HK -t ssh -s 10.0.0.2:22
251268
```
252269

253270
**适用场景:**
271+
272+
- 公开演示环境
254273
- 团队共享的开发服务器
255274
- QA 测试的预发布环境
256-
- 内部工具和仪表盘
257275

258-
#### 隐身模式
276+
#### 隐身模式(默认)
259277

260-
隧道功能完全相同,但在管理控制台中**不可见**。只有知道 Access URL 的用户才能连接。适合临时、敏感或个人使用的场景。
278+
服务**需要授权** — 仅凭 Site URL 无法访问。用户必须使用 Access URL(包含授权密钥)才能连接。这是所有服务的安全默认值。
261279

262280
```bash
263-
# 隐身模式:功能不变,但在控制台中隐藏
264-
shield --visible=false -t rdp -s 10.0.0.5:3389
281+
# 隐身模式(默认):只有 Access URL(带密钥)才能访问
282+
shield -t rdp -s 10.0.0.5:3389
265283

266-
# 隐身 SSH 隧道,用于临时调试
267-
shield --visible=false -t ssh -s 10.0.0.2:22
284+
# 安全的 SSH 隧道 — 将 Access URL 分享给指定人员
285+
shield -t ssh -s 10.0.0.2:22
268286

269-
# 隐身 VNC 访问实验室机器
270-
shield --visible=false -t vnc -s 192.168.1.50:5900
287+
# 安全的 VNC 访问实验室机器
288+
shield -t vnc -s 192.168.1.50:5900
271289
```
272290

273291
**适用场景:**
274-
- 故障处理期间的临时访问 — 分享 URL,用完即关
275-
- 不需要被发现的个人开发机器
276-
- 敏感服务器,访问严格限定在知道 URL 的人
277292

278-
> 两种模式下 Access URL 都会打印在终端中,唯一区别是隧道是否出现在管理控制台。
293+
- 不能公开访问的生产服务器
294+
- 故障处理期间的临时访问 — 分享 Access URL,处理完毕即撤销
295+
- 敏感机器,访问仅限授权用户
296+
297+
> 两种模式下终端都会打印 Site URL 和 Access URL。区别在于:可见模式下 Site URL 即可访问;隐身模式下必须使用包含授权密钥的 Access URL。
279298
280299
### 安装
281300

@@ -301,7 +320,7 @@ shield [flags]
301320
-s, --source string 目标地址,格式 ip:port [必填]
302321
-H, --server string API 服务器地址 (默认: https://console.yishield.com/raas)
303322
-p, --tunnel-port int 隧道服务器端口 (默认: 62888)
304-
--visible 在控制台中显示隧道 (默认: true)
323+
--visable [过滤词] 启用可见模式 (可选: AC 节点名称过滤)
305324
-v, --verbose 启用详细日志输出
306325
-h, --help 显示帮助信息
307326
```

‎cmd/root.go‎

Lines changed: 23 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -8,13 +8,20 @@ import (
88
)
99

1010
var (
11-
protocol string
12-
server string
13-
target string
14-
apiServer string
15-
verbose bool
16-
tunnelPort int
17-
visible string
11+
protocol string
12+
server string
13+
target string
14+
apiServer string
15+
verbose bool
16+
tunnelPort int
17+
visable string
18+
displayName string
19+
siteName string
20+
authUser string
21+
authPass string
22+
privateKey string
23+
passphrase string
24+
enableSftp bool
1825
)
1926

2027
var rootCmd = &cobra.Command{
@@ -30,7 +37,15 @@ func init() {
3037
rootCmd.Flags().StringVarP(&apiServer, "server", "H", "https://console.yishield.com/raas", "API server URL")
3138
rootCmd.Flags().BoolVarP(&verbose, "verbose", "v", false, "Enable verbose log output")
3239
rootCmd.Flags().IntVarP(&tunnelPort, "tunnel-port", "p", 62888, "Chisel tunnel server port")
33-
rootCmd.Flags().StringVar(&visible, "visible", "true", "Make the tunnel visible in the console (true/false)")
40+
rootCmd.Flags().StringVar(&visable, "visable", "", "AC node filter for visibility mode (use without value for visible mode)")
41+
rootCmd.Flags().Lookup("visable").NoOptDefVal = "visable"
42+
rootCmd.Flags().StringVar(&displayName, "display-name", "", "Connector display name")
43+
rootCmd.Flags().StringVar(&siteName, "site-name", "", "Application site name")
44+
rootCmd.Flags().StringVar(&authUser, "username", "", "Target service username (SSH/RDP/VNC)")
45+
rootCmd.Flags().StringVar(&authPass, "auth-pass", "", "Target service password (SSH/RDP/VNC)")
46+
rootCmd.Flags().StringVar(&privateKey, "private-key", "", "SSH private key")
47+
rootCmd.Flags().StringVar(&passphrase, "passphrase", "", "SSH private key passphrase")
48+
rootCmd.Flags().BoolVar(&enableSftp, "enable-sftp", false, "Enable SFTP (SSH only)")
3449

3550
rootCmd.MarkFlagRequired("type")
3651
rootCmd.MarkFlagRequired("source")

‎cmd/run.go‎

Lines changed: 16 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -69,7 +69,14 @@ type QuickSetupRequest struct {
6969
Port int `json:"port"`
7070
ConnectorName string `json:"connector_name"`
7171
Password string `json:"password"`
72-
Visible string `json:"visible"`
72+
DisplayName string `json:"display_name,omitempty"`
73+
SiteName string `json:"site_name,omitempty"`
74+
Visable string `json:"visable,omitempty"`
75+
Username string `json:"username,omitempty"`
76+
AuthPass string `json:"auth_pass,omitempty"`
77+
PrivateKey string `json:"private_key,omitempty"`
78+
Passphrase string `json:"passphrase,omitempty"`
79+
EnableSftp bool `json:"enable_sftp,omitempty"`
7380
}
7481

7582
type QuickSetupResponse struct {
@@ -182,7 +189,6 @@ func runShield(cmd *cobra.Command, args []string) error {
182189
// === Phase 2: Print tunnel mapping & connection info ===
183190
fmt.Println()
184191
fmt.Printf(" \033[1;33m⚡ Tunnel Mapping\033[0m\n")
185-
fmt.Printf(" \033[36mAPI Tunnel:\033[0m remote:%d ←→ local:%d\n", resp.Data.Connector.APIPort, localPort)
186192
fmt.Printf(" \033[36mApp Tunnel:\033[0m remote:%d ←→ %s:%d\n", resource.Port, ip, port)
187193
fmt.Printf(" \033[36mServer:\033[0m %s:%d\n", resp.Data.Connector.ExternalIP, tunnelPort)
188194
fmt.Println()
@@ -230,7 +236,14 @@ func callQuickSetup(ip string, port int, creds *config.Credentials) (*QuickSetup
230236
Port: port,
231237
ConnectorName: creds.ConnectorName,
232238
Password: creds.Password,
233-
Visible: visible,
239+
DisplayName: displayName,
240+
SiteName: siteName,
241+
Visable: visable,
242+
Username: authUser,
243+
AuthPass: authPass,
244+
PrivateKey: privateKey,
245+
Passphrase: passphrase,
246+
EnableSftp: enableSftp,
234247
}
235248

236249
jsonData, err := json.Marshal(reqBody)

0 commit comments

Comments
 (0)