1
0

node.go 9.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351
  1. package controller
  2. import (
  3. "context"
  4. "errors"
  5. "fmt"
  6. "slices"
  7. "strconv"
  8. "time"
  9. "github.com/mhsanaei/3x-ui/v3/internal/database/model"
  10. "github.com/mhsanaei/3x-ui/v3/internal/logger"
  11. "github.com/mhsanaei/3x-ui/v3/internal/web/middleware"
  12. "github.com/mhsanaei/3x-ui/v3/internal/web/service"
  13. "github.com/gin-gonic/gin"
  14. )
  15. type NodeController struct {
  16. nodeService service.NodeService
  17. xrayService service.XrayService
  18. }
  19. func NewNodeController(g *gin.RouterGroup) *NodeController {
  20. a := &NodeController{}
  21. a.initRouter(g)
  22. return a
  23. }
  24. func (a *NodeController) initRouter(g *gin.RouterGroup) {
  25. g.GET("/list", a.list)
  26. g.GET("/get/:id", a.get)
  27. g.GET("/webCert/:id", a.webCert)
  28. g.POST("/add", a.add)
  29. g.POST("/update/:id", a.update)
  30. g.POST("/del/:id", a.del)
  31. g.POST("/setEnable/:id", a.setEnable)
  32. g.POST("/test", a.test)
  33. g.POST("/certFingerprint", a.certFingerprint)
  34. g.POST("/inbounds", a.inbounds)
  35. g.POST("/probe/:id", a.probe)
  36. g.POST("/updatePanel", a.updatePanel)
  37. g.GET("/history/:id/:metric/:bucket", a.history)
  38. g.POST("/mtls/ca", a.mtlsCa)
  39. g.POST("/mtls/trustCA", a.setMtlsTrustCA)
  40. }
  41. // mtlsCa returns this panel's node-auth CA certificate (public) to paste into a
  42. // node's mTLS trust setting. It lazily mints the CA + master client cert on
  43. // first call.
  44. func (a *NodeController) mtlsCa(c *gin.Context) {
  45. caCert, err := a.nodeService.NodeMtlsCaCert()
  46. if err != nil {
  47. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  48. return
  49. }
  50. jsonObj(c, gin.H{"caCert": caCert}, nil)
  51. }
  52. // setMtlsTrustCA stores the CA this panel trusts for incoming node-API client
  53. // certificates (this panel acting as a node). An empty value disables it.
  54. // Applied on the next panel restart.
  55. func (a *NodeController) setMtlsTrustCA(c *gin.Context) {
  56. var req struct {
  57. CaCert string `json:"caCert" form:"caCert"`
  58. }
  59. if err := c.ShouldBind(&req); err != nil {
  60. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.saveMtls"), err)
  61. return
  62. }
  63. if err := a.nodeService.SetNodeMtlsTrustCA(req.CaCert); err != nil {
  64. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.saveMtls"), err)
  65. return
  66. }
  67. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.saveMtls"), nil)
  68. }
  69. func (a *NodeController) list(c *gin.Context) {
  70. nodes, err := a.nodeService.GetNodeTree()
  71. if err != nil {
  72. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.list"), err)
  73. return
  74. }
  75. jsonObj(c, nodes, nil)
  76. }
  77. func (a *NodeController) get(c *gin.Context) {
  78. id, err := strconv.Atoi(c.Param("id"))
  79. if err != nil {
  80. jsonMsg(c, I18nWeb(c, "get"), err)
  81. return
  82. }
  83. n, err := a.nodeService.GetById(id)
  84. if err != nil {
  85. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  86. return
  87. }
  88. jsonObj(c, n, nil)
  89. }
  90. // webCert returns the node's own web TLS certificate/key file paths so the
  91. // inbound form's "Set Cert from Panel" can fill paths that exist on the node.
  92. func (a *NodeController) webCert(c *gin.Context) {
  93. id, err := strconv.Atoi(c.Param("id"))
  94. if err != nil {
  95. jsonMsg(c, I18nWeb(c, "get"), err)
  96. return
  97. }
  98. files, err := a.nodeService.GetWebCertFiles(id)
  99. if err != nil {
  100. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  101. return
  102. }
  103. jsonObj(c, files, nil)
  104. }
  105. func (a *NodeController) ensureReachable(c *gin.Context, n *model.Node) error {
  106. ctx, cancel := context.WithTimeout(c.Request.Context(), 6*time.Second)
  107. defer cancel()
  108. if _, err := a.nodeService.Probe(ctx, n); err != nil {
  109. return errors.New(service.FriendlyProbeError(err.Error()))
  110. }
  111. return nil
  112. }
  113. func (a *NodeController) add(c *gin.Context) {
  114. n, ok := middleware.BindAndValidate[model.Node](c)
  115. if !ok {
  116. return
  117. }
  118. if n.OutboundTag == "" {
  119. if err := a.ensureReachable(c, n); err != nil {
  120. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.add"), err)
  121. return
  122. }
  123. }
  124. if err := a.nodeService.Create(n); err != nil {
  125. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.add"), err)
  126. return
  127. }
  128. if n.OutboundTag != "" {
  129. if err := a.xrayService.RestartXray(false); err != nil {
  130. logger.Warning("apply node outbound bridge failed:", err)
  131. }
  132. if err := a.ensureReachable(c, n); err != nil {
  133. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.add"), err)
  134. return
  135. }
  136. }
  137. jsonMsgObj(c, I18nWeb(c, "pages.nodes.toasts.add"), n, nil)
  138. }
  139. func (a *NodeController) update(c *gin.Context) {
  140. id, err := strconv.Atoi(c.Param("id"))
  141. if err != nil {
  142. jsonMsg(c, I18nWeb(c, "get"), err)
  143. return
  144. }
  145. n, ok := middleware.BindAndValidate[model.Node](c)
  146. if !ok {
  147. return
  148. }
  149. old, err := a.nodeService.GetById(id)
  150. if err != nil {
  151. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  152. return
  153. }
  154. if n.OutboundTag == "" && old.OutboundTag == "" {
  155. if err := a.ensureReachable(c, n); err != nil {
  156. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), err)
  157. return
  158. }
  159. }
  160. if err := a.nodeService.Update(id, n); err != nil {
  161. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), err)
  162. return
  163. }
  164. if n.OutboundTag != old.OutboundTag {
  165. if err := a.xrayService.RestartXray(false); err != nil {
  166. logger.Warning("apply node outbound bridge change failed:", err)
  167. }
  168. if err := a.ensureReachable(c, n); err != nil {
  169. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), err)
  170. return
  171. }
  172. }
  173. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), nil)
  174. }
  175. func (a *NodeController) del(c *gin.Context) {
  176. id, err := strconv.Atoi(c.Param("id"))
  177. if err != nil {
  178. jsonMsg(c, I18nWeb(c, "get"), err)
  179. return
  180. }
  181. if err := a.nodeService.Delete(id); err != nil {
  182. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.delete"), err)
  183. return
  184. }
  185. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.delete"), nil)
  186. }
  187. func (a *NodeController) setEnable(c *gin.Context) {
  188. id, err := strconv.Atoi(c.Param("id"))
  189. if err != nil {
  190. jsonMsg(c, I18nWeb(c, "get"), err)
  191. return
  192. }
  193. body := struct {
  194. Enable bool `json:"enable" form:"enable"`
  195. }{}
  196. if err := c.ShouldBind(&body); err != nil {
  197. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), err)
  198. return
  199. }
  200. n, err := a.nodeService.GetById(id)
  201. if err != nil {
  202. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  203. return
  204. }
  205. if err := a.nodeService.SetEnable(id, body.Enable); err != nil {
  206. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), err)
  207. return
  208. }
  209. if n.OutboundTag != "" {
  210. if err := a.xrayService.RestartXray(false); err != nil {
  211. logger.Warning("apply node enable change failed:", err)
  212. }
  213. }
  214. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.update"), nil)
  215. }
  216. func (a *NodeController) inbounds(c *gin.Context) {
  217. n := &model.Node{}
  218. if err := c.ShouldBind(n); err != nil {
  219. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  220. return
  221. }
  222. ctx, cancel := context.WithTimeout(c.Request.Context(), 10*time.Second)
  223. defer cancel()
  224. options, err := a.nodeService.GetRemoteInboundOptions(ctx, n)
  225. jsonObj(c, options, err)
  226. }
  227. func (a *NodeController) test(c *gin.Context) {
  228. n := &model.Node{}
  229. if err := c.ShouldBind(n); err != nil {
  230. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.test"), err)
  231. return
  232. }
  233. if n.Scheme == "" {
  234. n.Scheme = "https"
  235. }
  236. if n.BasePath == "" {
  237. n.BasePath = "/"
  238. }
  239. ctx, cancel := context.WithTimeout(c.Request.Context(), 6*time.Second)
  240. defer cancel()
  241. var patch service.HeartbeatPatch
  242. var err error
  243. if n.OutboundTag != "" {
  244. patch, err = a.nodeService.ProbeWithOutbound(ctx, n, n.OutboundTag)
  245. } else {
  246. patch, err = a.nodeService.Probe(ctx, n)
  247. }
  248. jsonObj(c, patch.ToUI(err == nil), nil)
  249. }
  250. func (a *NodeController) certFingerprint(c *gin.Context) {
  251. n := &model.Node{}
  252. if err := c.ShouldBind(n); err != nil {
  253. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.test"), err)
  254. return
  255. }
  256. if n.Scheme == "" {
  257. n.Scheme = "https"
  258. }
  259. if n.BasePath == "" {
  260. n.BasePath = "/"
  261. }
  262. ctx, cancel := context.WithTimeout(c.Request.Context(), 6*time.Second)
  263. defer cancel()
  264. fp, err := a.nodeService.FetchCertFingerprint(ctx, n)
  265. if err != nil {
  266. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.test"), err)
  267. return
  268. }
  269. jsonObj(c, fp, nil)
  270. }
  271. func (a *NodeController) probe(c *gin.Context) {
  272. id, err := strconv.Atoi(c.Param("id"))
  273. if err != nil {
  274. jsonMsg(c, I18nWeb(c, "get"), err)
  275. return
  276. }
  277. n, err := a.nodeService.GetById(id)
  278. if err != nil {
  279. jsonMsg(c, I18nWeb(c, "pages.nodes.toasts.obtain"), err)
  280. return
  281. }
  282. ctx, cancel := context.WithTimeout(c.Request.Context(), 6*time.Second)
  283. defer cancel()
  284. patch, probeErr := a.nodeService.Probe(ctx, n)
  285. if probeErr != nil {
  286. patch.Status = "offline"
  287. } else {
  288. patch.Status = "online"
  289. }
  290. _ = a.nodeService.UpdateHeartbeat(id, patch)
  291. jsonObj(c, patch.ToUI(probeErr == nil), nil)
  292. }
  293. func (a *NodeController) updatePanel(c *gin.Context) {
  294. var req struct {
  295. Ids []int `json:"ids"`
  296. }
  297. if err := c.ShouldBindJSON(&req); err != nil {
  298. jsonMsg(c, I18nWeb(c, "somethingWentWrong"), err)
  299. return
  300. }
  301. if len(req.Ids) == 0 {
  302. jsonMsg(c, I18nWeb(c, "somethingWentWrong"), fmt.Errorf("no nodes selected"))
  303. return
  304. }
  305. results, err := a.nodeService.UpdatePanels(req.Ids)
  306. jsonMsgObj(c, I18nWeb(c, "pages.nodes.toasts.updateStarted"), results, err)
  307. }
  308. func (a *NodeController) history(c *gin.Context) {
  309. id, err := strconv.Atoi(c.Param("id"))
  310. if err != nil {
  311. jsonMsg(c, I18nWeb(c, "get"), err)
  312. return
  313. }
  314. metric := c.Param("metric")
  315. if !slices.Contains(service.NodeMetricKeys, metric) {
  316. jsonMsg(c, "invalid metric", fmt.Errorf("unknown metric"))
  317. return
  318. }
  319. bucket, err := strconv.Atoi(c.Param("bucket"))
  320. if err != nil || bucket <= 0 || !service.IsAllowedHistoryBucket(bucket) {
  321. jsonMsg(c, "invalid bucket", fmt.Errorf("unsupported bucket"))
  322. return
  323. }
  324. jsonObj(c, a.nodeService.AggregateNodeMetric(id, metric, bucket, 60), nil)
  325. }