Skip to main content

NetCurfew

A production-grade local screen-time and internet control system for parents.

NetCurfew runs a privileged background daemon that manipulates OS firewall rules. Access is granted by the parent via CLI or a local web dashboard — from any device on the same network, including a smartphone.


Architecture

 CLI (netcurfew)          Web UI (browser)
       |                        |
       +----------+-------------+
                  | HTTP REST  (localhost:5000)
                  v
        NetCurfew Daemon  (FastAPI / runs as admin)
                  |
                  v  OS firewall commands
        Windows netsh / Linux iptables / macOS pfctl

Default state: internet BLOCKED. Access must be explicitly granted.


Installation

# Requires Python 3.11+
pip install -e .

Optional: set a parent PIN

netcurfew set-pin MySecretPin

Running the Daemon

The daemon must run with elevated privileges.

Windows (Run as Administrator)

netcurfew serve

To install as a Windows Service (using NSSM or sc.exe):

sc create NetCurfew binPath= "C:\Python311\Scripts\netcurfew.exe serve" start= auto
sc start NetCurfew

Linux (systemd)

Create /etc/systemd/system/netcurfew.service:

[Unit]
Description=NetCurfew Internet Control Daemon
After=network.target

[Service]
ExecStart=/usr/local/bin/netcurfew serve
Restart=always
RestartSec=5

[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable --now netcurfew

macOS (launchd)

sudo netcurfew serve

CLI Usage

# View current state
netcurfew status

# Grant 30 minutes of internet
netcurfew start 30m

# Grant 1 hour
netcurfew start 1h

# Immediately block
netcurfew stop

# Add 15 more minutes to an active session
netcurfew extend 15m

# Use with PIN
netcurfew start 30m --pin MySecretPin
netcurfew stop --pin MySecretPin

Web Dashboard

Open http://<machine-ip>:5000 in any browser on the local network.

Features:

  • Live status badge (green / red) with MM:SS countdown
  • Quick action buttons: +15m, +30m, +1h, +2h, Extend, Stop
  • PIN modal if a parent PIN is configured
  • Mobile-responsive

Configuration (config.json)

Copy config.json.example to config.json and edit:

Key Default Description
parent_pin_hash null Scrypt-hashed PIN (set via netcurfew set-pin)
default_port 5000 Daemon listen port
allowed_durations [15,30,60,120] Allowed session lengths (minutes)
lan_only true Bind only to localhost/LAN

Security Notes

  • All firewall changes require the daemon to run as Administrator / root.
  • The daemon binds to 127.0.0.1 by default; LAN access requires binding to a local network interface (handled when lan_only: true).
  • Session timing uses time.monotonic() — immune to OS clock manipulation.
  • Fail-safe: the daemon blocks internet on startup, shutdown, and crash recovery.

Metadata

Release files for netcurfew 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for netcurfew 0.1.2
File Size Uploaded
netcurfew-0.1.2.tar.gz 17.7 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for netcurfew 0.1.2
File Interpreter ABI Platform
netcurfew-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 33.5 kB

Release files / netcurfew-0.1.2.tar.gz

Download URL netcurfew-0.1.2.tar.gz
Size 17.7 kB
Tags Source
SHA-256 checksum
How to use checksums
feea77934a811ab75a3fcba59de8b51705a1d4d010241f2ee9a790c0a8e1adf1
BLAKE2b-256 checksum
How to use checksums
0441c980b61f7b4e4a652a78be3eeb22656e3e9c75df71597bac1f16d1bf21a8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 9, 2026.

Transparency log

Release files / netcurfew-0.1.2-py3-none-any.whl

Download URL netcurfew-0.1.2-py3-none-any.whl
Size 15.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
cb1eb32f8240fe605d31b9b9248773a373c43a8f3c8130a1ae65d0407b2880c1
BLAKE2b-256 checksum
How to use checksums
c2de4ee08c797f5c971119e65d7109b2bc3b6cb73e94e1b50c655ec11c7d4222
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 9, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.9

2 release files

0.1.8

2 release files

0.1.7

2 release files

0.1.6

2 release files

0.1.5

2 release files

0.1.4

2 release files

0.1.3

2 release files

This release

0.1.2 This release

2 release files

0.1.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page