LOCAL NETWORK / TAILSCALE / OAUTH

TAKE CONTROL.
SECURE THE BRIDGE.

Run the website and Rust CLI bridge on your own Kali Linux host, then access it from a trusted browser on the same network or in your Tailscale tailnet.

NODE 22+RUST CLIPORT 8787AUTHENTICATED
00 / ARCHITECTURE

One Kali host. Browser-controlled jobs.

The all-in-one Node web server serves the UI, manages authenticated sessions, accepts challenge artifacts and starts the installed WROSECODE native CLI as a child process. Events are streamed over Server-Sent Events (SSE). This package does not modify the WROSECODE Rust repository.

01 / INSTALL

Start on Kali Linux.

Transfer the ZIP archive to Kali, extract it, open the resulting WROSECODE-Web-Console folder and confirm that WROSECODE is installed and working. Requires Node.js 22.13 or newer.

TERMINAL / KALI
node --version
wrosecode --version
wrosecode providers list
cp .env.example .env
# Edit .env to set:
# BRIDGE_MODE=cli
# WROSECODE_BIN=/absolute/path/to/wrosecode
node --env-file=.env server/server.mjs

Default local access URL: http://127.0.0.1:8787. The backend is disabled until you explicitly set BRIDGE_MODE=cli. BRIDGE_MODE=mock is for demos only.

02 / OWNER

Create the first account.

Run this in the extracted folder before launching the server. Choose a unique password of 12 or more characters.

TERMINAL / KALI
read -rp "Admin email: " ADMIN_EMAIL
read -rsp "Admin password (12+ chars): " ADMIN_PASSWORD; echo
export ADMIN_EMAIL ADMIN_PASSWORD
node --env-file=.env scripts/create-admin.mjs
unset ADMIN_EMAIL ADMIN_PASSWORD

Then open /login.html. Passwords use salted scrypt hashes in a local SQLite database. Session tokens are HttpOnly cookies, and tasks are owner-only by default.

03 / LOCAL NETWORK

Choose a LAN IP and port.

Find Kali's LAN address (example only: 192.168.1.50). To serve devices on the same network, set HOST=0.0.0.0, PORT=8787 and PUBLIC_BASE_URL=http://192.168.1.50:8787 in .env. Restart the server.

TERMINAL / KALI
hostname -I
# Sample .env values (replace with the REAL Kali LAN IP):
HOST=0.0.0.0
PORT=8787
PUBLIC_BASE_URL=http://192.168.1.50:8787
BRIDGE_MODE=cli
04 / PRIVATE REMOTE ACCESS

Connect through Tailscale.

On Kali, install and log in to Tailscale. Use a loopback-only backend; let Tailscale Serve provide encrypted HTTPS for devices authorized on the same tailnet. You do not need a public port-forward.

TERMINAL / KALI
sudo tailscale up
# .env on Kali:
HOST=127.0.0.1
PORT=8787
# Set PUBLIC_BASE_URL to the exact HTTPS URL shown by Tailscale Serve
node --env-file=.env server/server.mjs
# In another terminal:
tailscale serve --bg 8787
tailscale serve status

Copy the actual https://your-kali.your-tailnet.ts.net URL from the status output into PUBLIC_BASE_URL and restart the Node server. Users must be allowed into your tailnet. Tailscale Funnel is different: it exposes a service publicly and is not recommended for a CLI execution server.

05 / SOCIAL LOGIN

Enable Google and GitHub.

Create your own OAuth apps and configure the credentials in Kali's private .env. The login page shows the buttons, but they only activate when both client ID and secret are configured. For an existing email/password account, sign in first and use the AI providers page to explicitly link your Google/GitHub identity. Email/password registration does not verify inbox ownership and requires careful owner review. Register these exact redirect URIs with the providers:

CALLBACK URLS
https://your-kali.your-tailnet.ts.net/api/oauth/google/callback
https://your-kali.your-tailnet.ts.net/api/oauth/github/callback
PRIVATE .env
GOOGLE_CLIENT_ID=your_google_client_id
GOOGLE_CLIENT_SECRET=your_google_client_secret
GITHUB_CLIENT_ID=your_github_client_id
GITHUB_CLIENT_SECRET=your_github_client_secret

Google may impose domain verification, test-user and OAuth consent restrictions. A private tailnet URL is not guaranteed to be accepted as an authorized Google redirect domain; a managed public HTTPS domain may be required. Keep all client secrets on the server.

06 / APPROVALS

Decide who can execute.

Set SIGNUP_MODE=open only if you want visitors to register. Accounts are initially pending. The owner can approve or revoke them from Access control in the console. Approval by itself does not allow them to execute the host CLI: that is deliberately restricted to the owner.

07 / PUBLIC LANDING PAGE

Separate marketing from execution.

You can host the static homepage, screenshots and CLI documentation on Cloudflare Pages. The authenticated console API and native Rust subprocesses require a live Kali/server runtime, and the console pages must connect to that API on a compatible HTTPS origin. Simply uploading the ZIP to Pages does not create a functioning backend.

08 / BOUNDARIES

Read before deployment.

Challenge files are untrusted. Avoid running untrusted binaries or macros without a proper sandbox. The bridge limits upload size and job count, records task events, checks authentication and login origin, and never exposes stored provider credentials intentionally. It is not a hardened multi-tenant platform. CTF patterns are unverified candidates until an authorized challenge authority validates them.

Live CLI compatibility and provider functionality must be checked against your installed WROSECODE version using wrosecode --help, wrosecode ctf --help and wrosecode providers list.