Add WebAuthn passkey enrollment and login for issue #536, with trusted origin configuration, user verification, single-use challenges, and documented deployment and recovery behavior.
## Summary
- Format traffic amounts adaptively through PB across the user,
dashboard, forwarding, node, monitoring, and panel sharing views. Closes
#548.
- Let administrators choose MB, GB, TB, or PB when setting user, tunnel
permission, and panel sharing traffic limits. Closes#549.
- Persist exact MiB limits for users and tunnel permissions while
retaining the legacy GB field and existing data. Apply the precise limit
in forwarding policy checks and preserve it in backups.
## Verification
- `go test ./...` in `go-backend` (724 passed)
- `pnpm run build` in `vite-frontend`
- ESLint on changed frontend files
- `git diff --check`
## Summary
- Add separate light and dark wallpapers with fallback to the existing
background setting, resolving #554.
- Make both wallpaper settings available to unauthenticated pages and
update the background when the theme changes.
- Include the pre-existing installer regression changes in this commit,
as requested.
## Verification
- `go test ./...` in `go-backend` (723 passed)
- `pnpm run build` in `vite-frontend`
- ESLint on changed frontend files
- `bash test-install-scripts-proxy.sh`
- `git diff --check`
Fix panel update deployment discovery and rollback safety, add nftables compatibility and atomic replacement, and restore reproducible frontend CI installs.
Reset only the selected forwarding rule's displayed upload/download usage without affecting user totals, tunnel quotas, historical statistics, nftables baselines, or running services.
Closes#523
## Summary
- Skip agent protocol SetProtocol commands when updating nftables nodes.
- Preserve existing nftables SSH credentials when edit forms omit secret
fields.
- Add regression coverage for nftables updates and SSH config
persistence across repository reopen.
## Test Plan
- rtk go test ./...
## Summary
- Reconcile nftables nodes when background jobs start so rules are
restored after server reboot.
- Collect nftables traffic immediately at startup and every 30 seconds
by default.
- Return nftables rule binding status in forward diagnostics and cover
it with regression tests.
## Test Plan
- `cd go-backend && go test ./...`
- `cd go-backend && make build`
Adds nftables forwarding support for nodes, including frontend mode
selection, backend rule rendering, SSH-based rule reconciliation, and
online-state handling for nftables nodes.\n\nVerification:\n-
go-backend: go test ./...\n- vite-frontend: pnpm run build