diff --git a/README.md b/README.md index 307197b..adb7200 100644 --- a/README.md +++ b/README.md @@ -56,11 +56,11 @@ ### HTTPS / TLS -- `muxplex setup-tls` — set up TLS certificates for HTTPS (auto-detects best method) -- **Tailscale** *(Phase 2)* — automatic HTTPS via Tailscale funnel -- **mkcert** *(Phase 2)* — locally-trusted development certificates via mkcert -- **Self-signed fallback** — generates a self-signed cert when no other method is available -- **Clipboard API** — HTTPS is required for clipboard access in most browsers +- `muxplex setup-tls` — auto-detect and set up TLS certificates +- **Tailscale** — real Let's Encrypt certs via `tailscale cert` (recommended) +- **mkcert** — locally-trusted certs, zero browser warnings +- **Self-signed** — fallback for immediate HTTPS (browser shows warning) +- Required for browser clipboard API on non-localhost --- @@ -148,7 +148,8 @@ muxplex upgrade [--force] Smart update with version check muxplex doctor Check dependencies + config muxplex show-password Show current auth password muxplex reset-secret Regenerate signing secret -muxplex setup-tls [--method auto] Set up TLS certs for HTTPS +muxplex setup-tls [--method auto] Set up TLS certs (Tailscale/mkcert/self-signed) +muxplex setup-tls --status Show current TLS configuration ``` ### Service management @@ -189,16 +190,25 @@ muxplex serve --host 0.0.0.0 # Auto-detect the best TLS method and set up certificates muxplex setup-tls -# Use self-signed certificates explicitly +# Use a specific TLS method +muxplex setup-tls --method tailscale +muxplex setup-tls --method mkcert muxplex setup-tls --method selfsigned +# Show current TLS status and configuration +muxplex setup-tls --status + # Override TLS cert/key for a single run (without saving to config) -muxplex serve --tls-cert /path/to/cert.pem --tls-key /path/to/key.pem +muxplex serve --tls-cert /path/cert.pem --tls-key /path/key.pem # Check TLS configuration and dependencies muxplex doctor ``` +Auto-detection priority: **Tailscale** (if `tailscale` is installed and a cert is available) → **mkcert** (if `mkcert` is installed) → **self-signed** (always available as a fallback). Use `--method` to override. + +> **Note:** Tailscale certs have a 90-day expiry. Run `muxplex setup-tls --method tailscale` to renew when needed. + --- ## Configuration diff --git a/muxplex/tests/test_readme.py b/muxplex/tests/test_readme.py index 096d5b4..6b0821a 100644 --- a/muxplex/tests/test_readme.py +++ b/muxplex/tests/test_readme.py @@ -167,16 +167,89 @@ def test_readme_examples_show_tls_commands(): ) -def test_readme_phase_2_items_noted(): - """README must note Phase 2 items (Tailscale, mkcert) as upcoming.""" +def test_readme_no_phase_2_placeholders(): + """README must NOT contain any '(Phase 2)' placeholder text.""" + assert "(Phase 2)" not in README, ( + "README must not contain '(Phase 2)' placeholder text — Phase 2 is complete" + ) + + +def test_readme_tls_tailscale_lets_encrypt(): + """README must document Tailscale as providing real Let's Encrypt certs via tailscale cert.""" + assert "tailscale cert" in README, ( + "README must mention 'tailscale cert' command for Let's Encrypt certs" + ) assert "Tailscale" in README, ( - "README must mention Tailscale as a Phase 2 TLS method" + "README must mention Tailscale as a TLS method" ) - assert "mkcert" in README, ( - "README must mention mkcert as a Phase 2 TLS method" + + +def test_readme_tls_mkcert_zero_browser_warnings(): + """README must document mkcert as providing locally-trusted certs with zero browser warnings.""" + assert "mkcert" in README, "README must mention mkcert as a TLS method" + assert "zero browser warnings" in README or "browser warnings" in README, ( + "README must mention that mkcert provides zero browser warnings" ) - assert "Phase 2" in README, ( - "README must note Phase 2 items as upcoming" + + +def test_readme_tls_selfsigned_browser_warning(): + """README must document self-signed as fallback with browser warning note.""" + readme_lower = README.lower() + assert "browser shows warning" in readme_lower or "browser warning" in readme_lower, ( + "README must note that self-signed certs show browser warnings" + ) + + +def test_readme_tls_setup_status_command(): + """README must document the 'muxplex setup-tls --status' command.""" + assert "muxplex setup-tls --status" in README, ( + "README must document 'muxplex setup-tls --status' command" + ) + + +def test_readme_tls_setup_method_tailscale(): + """README must document 'muxplex setup-tls --method tailscale' in examples.""" + assert "muxplex setup-tls --method tailscale" in README, ( + "README must show 'muxplex setup-tls --method tailscale' in examples" + ) + + +def test_readme_tls_setup_method_mkcert(): + """README must document 'muxplex setup-tls --method mkcert' in examples.""" + assert "muxplex setup-tls --method mkcert" in README, ( + "README must show 'muxplex setup-tls --method mkcert' in examples" + ) + + +def test_readme_tls_detection_priority_explanation(): + """README must explain detection priority for TLS method auto-detection.""" + readme_lower = README.lower() + assert "detection" in readme_lower or "priority" in readme_lower or "auto-detect" in readme_lower, ( + "README must explain detection priority for auto-detect TLS method selection" + ) + + +def test_readme_tls_tailscale_cert_renewal_note(): + """README must include a note about Tailscale cert renewal (90-day expiry).""" + assert "90-day" in README or "90 day" in README or "90 days" in README, ( + "README must include a note about 90-day Tailscale cert renewal/expiry" + ) + + +def test_readme_cli_reference_setup_tls_updated(): + """README CLI Reference must describe setup-tls with Tailscale/mkcert/self-signed.""" + assert "Tailscale/mkcert/self-signed" in README or "Tailscale/mkcert" in README, ( + "README CLI Reference must describe setup-tls with Tailscale/mkcert/self-signed methods" + ) + + +def test_readme_cli_reference_has_setup_tls_status(): + """README CLI Reference must include setup-tls --status command with description.""" + assert "setup-tls --status" in README, ( + "README CLI Reference must include 'setup-tls --status' with description" + ) + assert "Show current TLS" in README or "current TLS configuration" in README, ( + "README CLI Reference must describe what setup-tls --status does" )