NetCurfew
A production-grade local screen-time and internet control system for parents.
NetCurfew runs a privileged background daemon that manipulates OS firewall rules. Access is granted by the parent via CLI or a local web dashboard — from any device on the same network, including a smartphone.
Architecture
CLI (netcurfew) Web UI (browser)
| |
+----------+-------------+
| HTTP REST (localhost:5000)
v
NetCurfew Daemon (FastAPI / runs as admin)
|
v OS firewall commands
Windows netsh / Linux iptables / macOS pfctl
Default state: internet BLOCKED. Access must be explicitly granted.
Installation
# Requires Python 3.11+
pip install -e .
Optional: set a parent PIN
netcurfew set-pin MySecretPin
Running the Daemon
The daemon must run with elevated privileges.
Windows (Run as Administrator)
netcurfew serve
To install as a Windows Service (using NSSM or sc.exe):
sc create NetCurfew binPath= "C:\Python311\Scripts\netcurfew.exe serve" start= auto
sc start NetCurfew
Linux (systemd)
Create /etc/systemd/system/netcurfew.service:
[Unit]
Description=NetCurfew Internet Control Daemon
After=network.target
[Service]
ExecStart=/usr/local/bin/netcurfew serve
Restart=always
RestartSec=5
[Install]
WantedBy=multi-user.target
sudo systemctl daemon-reload
sudo systemctl enable --now netcurfew
macOS (launchd)
sudo netcurfew serve
CLI Usage
# View current state
netcurfew status
# Grant internet access — duration defaults to the first allowed_durations entry (15m)
netcurfew start
# Grant a specific duration
netcurfew start 30m
netcurfew start 1h
# Immediately block internet
netcurfew stop
# Add time to the active session
netcurfew extend 15m
# Supply PIN via flag (skips interactive prompt)
netcurfew start 30m --pin 123456
netcurfew stop --pin 123456
# Skip PIN prompt entirely (useful when no PIN is configured, or in scripts)
netcurfew start -i
netcurfew stop -i
netcurfew extend 30m -i
If no parent PIN is configured, the PIN prompt is skipped automatically.
Use --immediately / -i on start, stop, and extend to bypass the prompt
when a PIN is set but you want to proceed without one (the daemon still enforces
its own PIN check server-side).
Web Dashboard
Open http://<machine-ip>:5000 in any browser on the local network.
Features:
- Live status badge (green / red) with MM:SS countdown
- Quick action buttons: +15m, +30m, +1h, +2h, Extend, Stop
- PIN modal if a parent PIN is configured
- Mobile-responsive
Configuration (config.json)
Copy config.json.example to config.json and edit:
| Key | Default | Description |
|---|---|---|
parent_pin_hash |
null |
Scrypt-hashed PIN (set via netcurfew set-pin) |
default_port |
5000 |
Daemon listen port |
allowed_durations |
[15,30,60,120] |
Allowed session lengths (minutes) |
lan_only |
true |
Bind only to localhost/LAN |
Security Notes
- All firewall changes require the daemon to run as Administrator / root.
- The daemon binds to
127.0.0.1by default; LAN access requires binding to a local network interface (handled whenlan_only: true). - Session timing uses
time.monotonic()— immune to OS clock manipulation. - Fail-safe: the daemon blocks internet on startup, shutdown, and crash recovery.
Metadata
Release files for netcurfew 0.1.4
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| netcurfew-0.1.4.tar.gz | 19.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| netcurfew-0.1.4-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 36.6 kB
Release files / netcurfew-0.1.4.tar.gz
| Download URL | netcurfew-0.1.4.tar.gz |
|---|---|
| Size | 19.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
534e14c1d08f1fd27f0c7c0728cfad3e9458f02fd772808b0e25f2e4fbd79152
|
|
BLAKE2b-256 checksum How to use checksums |
35ef02d187d37a761ac69b926a1b423c6ec00403ae8d63ddd2fb10e108f9b050
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency logRelease files / netcurfew-0.1.4-py3-none-any.whl
| Download URL | netcurfew-0.1.4-py3-none-any.whl |
|---|---|
| Size | 17.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c98f34a51f1c437b22324b3cef10c2dfa7ec815aba01dc13e81b19c4dfac76c3
|
|
BLAKE2b-256 checksum How to use checksums |
fd8e5d910e79d8dc8ad7e3c49d8bbe9b8b9bcb7eff384b6c2e4072990fcdd1b5
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Aug 10, 2026.
Transparency log