Reduce force-off to only 4: audio, camera, tunnel, privacy-mode

User clarified: only these 4 should default-off. The other 5 I had
forced off (keyboard, clipboard, file-transfer, terminal, remote-restart)
should be on by default (RustDesk's normal behavior).

What I force off now (OVERWRITE_SETTINGS = N, user cannot override):
  - enable-audio
  - enable-camera
  - enable-tunnel
  - enable-privacy-mode

What stays at RustDesk's default (on, user-configurable):
  - enable-keyboard
  - enable-clipboard
  - enable-file-transfer
  - enable-terminal
  - enable-remote-restart
  - enable-record-session

Old config had no leftover enable-* values, so this is a clean transition.
This commit is contained in:
xuwenwei
2026-06-09 11:15:30 +08:00
parent a92b7c22bc
commit f5a6b033ff
+16 -32
View File
@@ -2102,43 +2102,27 @@ pub fn load_custom_client() {
read_custom_client(&data.trim());
}
// Custom fork: hardcode bandwidth-heavy / sensitive defaults to off.
// Reason: RustDesk's official custom.txt path requires ed25519-signed base64 (see
// read_custom_client at line 2191 — decode64 + sign::verify with key
// "5Qbwsde3unUcJBtrx9ZkvUmwFNoExHzpryHuPUdqlWM="), which we can't produce without the
// official signing key. So we bypass custom.txt and inject directly.
// Custom fork: force off ONLY the 4 options the user explicitly asked to default-off.
// Everything else stays at RustDesk's normal default (typically on, user-configurable).
//
// We use TWO mechanisms:
// 1. OVERWRITE_SETTINGS for options we want to FORCE off — user cannot flip
// them on, even if they have old config entries. Get_or logic returns the
// overwrite value before checking user config. This is what the user wants
// for security/billing reasons — they explicitly asked for "默认开启是不对的"
// and got bitten by old config values surviving.
// 2. DEFAULT_SETTINGS for options we want as fallbacks only — user can
// override in their own RustDesk2.toml if they want.
// enable-audio — not needed; 4-user remote support doesn't use it
// enable-camera — 500 kbps; not needed for support scenarios
// enable-tunnel — TCP tunneling; opens server as jump host, risky
// enable-privacy-mode — user said "本来就不勾"
//
// Why each one is off (user has 4 users on 5 Mbps server):
// enable-audio — not needed for 4-user remote support
// enable-file-transfer — THE KILLER: 1 GB upload = 2 GB server bandwidth
// enable-clipboard — 50 kbps + privacy; user complained "默认开启不对"
// enable-keyboard — user complained "默认开启不对"
// enable-tunnel — TCP tunneling = server as jump host
// enable-record-session — only when explicitly recording
// enable-camera — 500 kbps; rarely used for support
// Things we DO NOT force off (RustDesk defaults them ON, user can override):
// enable-keyboard, enable-clipboard, enable-file-transfer, enable-terminal,
// enable-remote-restart, enable-record-session
//
// Mechanism note: OVERWRITE_SETTINGS is the highest priority. User cannot
// flip these to on from the UI. is_option_can_save() at config.rs:2766 will
// also refuse to write them to the user config file (RustDesk2.toml).
{
// Force-off: user CANNOT override (use this for the ones the user
// explicitly complained about being on by default)
let mut overwrites = config::OVERWRITE_SETTINGS.write().unwrap();
overwrites.entry("enable-keyboard".to_string()).or_insert("N".to_string());
overwrites.entry("enable-clipboard".to_string()).or_insert("N".to_string());
overwrites.entry("enable-file-transfer".to_string()).or_insert("N".to_string());
overwrites.entry("enable-tunnel".to_string()).or_insert("N".to_string());
overwrites.entry("enable-record-session".to_string()).or_insert("N".to_string());
overwrites.entry("enable-camera".to_string()).or_insert("N".to_string());
overwrites.entry("enable-audio".to_string()).or_insert("N".to_string());
// These two were missing from previous commit — user had them enabled.
overwrites.entry("enable-terminal".to_string()).or_insert("N".to_string());
overwrites.entry("enable-remote-restart".to_string()).or_insert("N".to_string());
overwrites.entry("enable-camera".to_string()).or_insert("N".to_string());
overwrites.entry("enable-tunnel".to_string()).or_insert("N".to_string());
overwrites.entry("enable-privacy-mode".to_string()).or_insert("N".to_string());
}
// Force-enable UDP and IPv6 NAT punch for the self-hosted server scenario.