| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894 |
- package sub
- import (
- "encoding/base64"
- "fmt"
- "maps"
- "net"
- "net/url"
- "slices"
- "strings"
- "time"
- "github.com/gin-gonic/gin"
- "github.com/goccy/go-json"
- "github.com/mhsanaei/3x-ui/v3/database"
- "github.com/mhsanaei/3x-ui/v3/database/model"
- "github.com/mhsanaei/3x-ui/v3/logger"
- "github.com/mhsanaei/3x-ui/v3/util/common"
- "github.com/mhsanaei/3x-ui/v3/util/random"
- "github.com/mhsanaei/3x-ui/v3/web/service"
- "github.com/mhsanaei/3x-ui/v3/xray"
- )
- // SubService provides business logic for generating subscription links and managing subscription data.
- type SubService struct {
- address string
- showInfo bool
- remarkModel string
- datepicker string
- emailInRemark bool
- inboundService service.InboundService
- settingService service.SettingService
- // nodesByID is populated per request from the Node table so
- // resolveInboundAddress can return the node's address for any
- // inbound whose NodeID is set. Keeps the per-link host derivation
- // O(1) instead of O(N) DB hits.
- nodesByID map[int]*model.Node
- }
- // NewSubService creates a new subscription service with the given configuration.
- func NewSubService(showInfo bool, remarkModel string) *SubService {
- return &SubService{
- showInfo: showInfo,
- remarkModel: remarkModel,
- }
- }
- // PrepareForRequest sets per-request state (host + nodes map) on the
- // shared SubService. Called by every entry point — GetSubs, GetJson,
- // GetClash — so resolveInboundAddress sees the right host and the
- // freshly-loaded node map regardless of which sub flavour the client
- // hit.
- func (s *SubService) PrepareForRequest(host string) {
- s.address = host
- s.loadNodes()
- }
- // GetSubs retrieves subscription links for a given subscription ID and host.
- func (s *SubService) GetSubs(subId string, host string) ([]string, []string, int64, xray.ClientTraffic, error) {
- s.PrepareForRequest(host)
- var result []string
- var emails []string
- var traffic xray.ClientTraffic
- var hasEnabledClient bool
- inbounds, err := s.getInboundsBySubId(subId)
- if err != nil {
- return nil, nil, 0, traffic, err
- }
- if len(inbounds) == 0 {
- return nil, nil, 0, traffic, nil
- }
- s.datepicker, err = s.settingService.GetDatepicker()
- if err != nil {
- s.datepicker = "gregorian"
- }
- s.emailInRemark, err = s.settingService.GetSubEmailInRemark()
- if err != nil {
- s.emailInRemark = true
- }
- seenEmails := make(map[string]struct{})
- for _, inbound := range inbounds {
- clients, err := s.inboundService.GetClients(inbound)
- if err != nil {
- logger.Error("SubService - GetClients: Unable to get clients from inbound")
- }
- if clients == nil {
- continue
- }
- s.projectThroughFallbackMaster(inbound)
- for _, client := range clients {
- if client.SubID == subId {
- if client.Enable {
- hasEnabledClient = true
- }
- result = append(result, s.GetLink(inbound, client.Email))
- emails = append(emails, client.Email)
- seenEmails[client.Email] = struct{}{}
- }
- }
- }
- uniqueEmails := make([]string, 0, len(seenEmails))
- for e := range seenEmails {
- uniqueEmails = append(uniqueEmails, e)
- }
- traffic, lastOnline := s.AggregateTrafficByEmails(uniqueEmails)
- traffic.Enable = hasEnabledClient
- return result, emails, lastOnline, traffic, nil
- }
- // AggregateTrafficByEmails resolves traffic for every email in one
- // query and folds the rows into a single ClientTraffic + lastOnline.
- // xray.ClientTraffic.Email is globally unique, so a multi-inbound
- // client's single row is attached to exactly one inbound — iterating
- // per-inbound ClientStats would miss it on the others. Used by GetSubs,
- // SubClashService.GetClash, and SubJsonService.GetJson to keep the
- // sub-info header consistent across all three formats.
- func (s *SubService) AggregateTrafficByEmails(emails []string) (xray.ClientTraffic, int64) {
- var agg xray.ClientTraffic
- var lastOnline int64
- if len(emails) == 0 {
- return agg, 0
- }
- var rows []xray.ClientTraffic
- if err := database.GetDB().
- Model(&xray.ClientTraffic{}).
- Where("email IN ?", emails).
- Find(&rows).Error; err != nil {
- logger.Warning("SubService - AggregateTrafficByEmails: load by email:", err)
- return agg, 0
- }
- now := time.Now().UnixMilli()
- for i, ct := range rows {
- if ct.LastOnline > lastOnline {
- lastOnline = ct.LastOnline
- }
- if i == 0 {
- agg.Up = ct.Up
- agg.Down = ct.Down
- agg.Total = ct.Total
- agg.ExpiryTime = subscriptionExpiryFromClient(now, ct.ExpiryTime)
- continue
- }
- agg.Up += ct.Up
- agg.Down += ct.Down
- if agg.Total == 0 || ct.Total == 0 {
- agg.Total = 0
- } else {
- agg.Total += ct.Total
- }
- normalized := subscriptionExpiryFromClient(now, ct.ExpiryTime)
- if normalized != agg.ExpiryTime {
- agg.ExpiryTime = 0
- }
- }
- return agg, lastOnline
- }
- func subscriptionExpiryFromClient(nowMs, expiryTime int64) int64 {
- if expiryTime > 0 {
- return expiryTime
- }
- if expiryTime < 0 {
- return nowMs + (-expiryTime)
- }
- return 0
- }
- func (s *SubService) getInboundsBySubId(subId string) ([]*model.Inbound, error) {
- db := database.GetDB()
- var inbounds []*model.Inbound
- err := db.Model(model.Inbound{}).Preload("ClientStats").Where(`id in (
- SELECT DISTINCT inbounds.id
- FROM inbounds
- JOIN client_inbounds ON client_inbounds.inbound_id = inbounds.id
- JOIN clients ON clients.id = client_inbounds.client_id
- WHERE
- inbounds.protocol in ('vmess','vless','trojan','shadowsocks','hysteria')
- AND clients.sub_id = ? AND inbounds.enable = ?
- )`, subId, true).Find(&inbounds).Error
- if err != nil {
- return nil, err
- }
- return inbounds, nil
- }
- // projectThroughFallbackMaster mutates the inbound in place so its
- // Listen/Port/StreamSettings reflect the externally reachable master
- // when applicable. Covers both fallback mechanisms:
- // - panel-tracked: an inbound_fallbacks row where child_id = inbound.Id
- // - legacy unix-socket: inbound.Listen begins with "@" and some VLESS/
- // Trojan inbound's settings.fallbacks references that listen address
- //
- // Returns true when a projection happened; sub services call this before
- // generating links so a child VLESS-WS bound to 127.0.0.1 emits the
- // master's :443 + TLS state instead of its own loopback endpoint.
- func (s *SubService) projectThroughFallbackMaster(inbound *model.Inbound) bool {
- if inbound == nil {
- return false
- }
- db := database.GetDB()
- var master *model.Inbound
- var rule model.InboundFallback
- if err := db.Where("child_id = ?", inbound.Id).
- Order("sort_order ASC, id ASC").
- First(&rule).Error; err == nil {
- var m model.Inbound
- if err := db.Where("id = ?", rule.MasterId).First(&m).Error; err == nil {
- master = &m
- }
- }
- if master == nil && len(inbound.Listen) > 0 && inbound.Listen[0] == '@' {
- var m model.Inbound
- if err := db.Model(model.Inbound{}).
- Where("JSON_TYPE(settings, '$.fallbacks') = 'array'").
- Where("EXISTS (SELECT * FROM json_each(settings, '$.fallbacks') WHERE json_extract(value, '$.dest') = ?)", inbound.Listen).
- First(&m).Error; err == nil {
- master = &m
- }
- }
- if master == nil {
- return false
- }
- inbound.StreamSettings = mergeStreamFromMaster(inbound.StreamSettings, master.StreamSettings)
- inbound.Listen = master.Listen
- inbound.Port = master.Port
- return true
- }
- // mergeStreamFromMaster copies the master's security + tlsSettings +
- // realitySettings + externalProxy onto the child's stream so the child's
- // link advertises the master's TLS / Reality state. Transport (network
- // + ws/grpc/etc. settings) stays the child's.
- func mergeStreamFromMaster(childStream, masterStream string) string {
- var stream map[string]any
- json.Unmarshal([]byte(childStream), &stream)
- if stream == nil {
- stream = map[string]any{}
- }
- var mst map[string]any
- json.Unmarshal([]byte(masterStream), &mst)
- if mst == nil {
- return childStream
- }
- stream["security"] = mst["security"]
- if v, ok := mst["tlsSettings"]; ok {
- stream["tlsSettings"] = v
- } else {
- delete(stream, "tlsSettings")
- }
- if v, ok := mst["realitySettings"]; ok {
- stream["realitySettings"] = v
- } else {
- delete(stream, "realitySettings")
- }
- if v, ok := mst["externalProxy"]; ok {
- stream["externalProxy"] = v
- }
- out, err := json.MarshalIndent(stream, "", " ")
- if err != nil {
- return childStream
- }
- return string(out)
- }
- // GetLink dispatches to the protocol-specific generator for one (inbound, client)
- // pair. Returns "" when the inbound's protocol doesn't produce a subscription URL
- // (socks, http, mixed, wireguard, dokodemo, tunnel). The returned string may
- // contain multiple `\n`-separated URLs when the inbound has externalProxy set.
- func (s *SubService) GetLink(inbound *model.Inbound, email string) string {
- switch inbound.Protocol {
- case "vmess":
- return s.genVmessLink(inbound, email)
- case "vless":
- return s.genVlessLink(inbound, email)
- case "trojan":
- return s.genTrojanLink(inbound, email)
- case "shadowsocks":
- return s.genShadowsocksLink(inbound, email)
- case "hysteria":
- return s.genHysteriaLink(inbound, email)
- }
- return ""
- }
- // Protocol link generators are intentionally ordered as:
- // vmess -> vless -> trojan -> shadowsocks -> hysteria.
- func (s *SubService) genVmessLink(inbound *model.Inbound, email string) string {
- if inbound.Protocol != model.VMESS {
- return ""
- }
- address := s.resolveInboundAddress(inbound)
- obj := map[string]any{
- "v": "2",
- "add": address,
- "port": inbound.Port,
- "type": "none",
- }
- stream := unmarshalStreamSettings(inbound.StreamSettings)
- network, _ := stream["network"].(string)
- applyVmessNetworkParams(stream, network, obj)
- if finalmask, ok := stream["finalmask"].(map[string]any); ok {
- applyFinalMaskObj(finalmask, obj)
- }
- security, _ := stream["security"].(string)
- obj["tls"] = security
- if security == "tls" {
- applyVmessTLSParams(stream, obj)
- }
- clients, _ := s.inboundService.GetClients(inbound)
- clientIndex := findClientIndex(clients, email)
- obj["id"] = clients[clientIndex].ID
- obj["scy"] = clients[clientIndex].Security
- externalProxies, _ := stream["externalProxy"].([]any)
- if len(externalProxies) > 0 {
- return s.buildVmessExternalProxyLinks(externalProxies, obj, inbound, email)
- }
- obj["ps"] = s.genRemark(inbound, email, "")
- return buildVmessLink(obj)
- }
- func (s *SubService) genVlessLink(inbound *model.Inbound, email string) string {
- if inbound.Protocol != model.VLESS {
- return ""
- }
- address := s.resolveInboundAddress(inbound)
- stream := unmarshalStreamSettings(inbound.StreamSettings)
- clients, _ := s.inboundService.GetClients(inbound)
- clientIndex := findClientIndex(clients, email)
- uuid := clients[clientIndex].ID
- port := inbound.Port
- streamNetwork := stream["network"].(string)
- params := make(map[string]string)
- params["type"] = streamNetwork
- // Add encryption parameter for VLESS from inbound settings
- var settings map[string]any
- json.Unmarshal([]byte(inbound.Settings), &settings)
- if encryption, ok := settings["encryption"].(string); ok {
- params["encryption"] = encryption
- }
- applyShareNetworkParams(stream, streamNetwork, params)
- if finalmask, ok := stream["finalmask"].(map[string]any); ok {
- applyFinalMaskParams(finalmask, params)
- }
- security, _ := stream["security"].(string)
- switch security {
- case "tls":
- applyShareTLSParams(stream, params)
- if streamNetwork == "tcp" && len(clients[clientIndex].Flow) > 0 {
- params["flow"] = clients[clientIndex].Flow
- }
- case "reality":
- applyShareRealityParams(stream, params)
- if streamNetwork == "tcp" && len(clients[clientIndex].Flow) > 0 {
- params["flow"] = clients[clientIndex].Flow
- }
- default:
- params["security"] = "none"
- }
- externalProxies, _ := stream["externalProxy"].([]any)
- if len(externalProxies) > 0 {
- return s.buildExternalProxyURLLinks(
- externalProxies,
- params,
- security,
- func(dest string, port int) string {
- return fmt.Sprintf("vless://%s@%s:%d", uuid, dest, port)
- },
- func(ep map[string]any) string {
- return s.genRemark(inbound, email, ep["remark"].(string))
- },
- )
- }
- link := fmt.Sprintf("vless://%s@%s:%d", uuid, address, port)
- return buildLinkWithParams(link, params, s.genRemark(inbound, email, ""))
- }
- func (s *SubService) genTrojanLink(inbound *model.Inbound, email string) string {
- if inbound.Protocol != model.Trojan {
- return ""
- }
- address := s.resolveInboundAddress(inbound)
- stream := unmarshalStreamSettings(inbound.StreamSettings)
- clients, _ := s.inboundService.GetClients(inbound)
- clientIndex := findClientIndex(clients, email)
- password := encodeUserinfo(clients[clientIndex].Password)
- port := inbound.Port
- streamNetwork := stream["network"].(string)
- params := make(map[string]string)
- params["type"] = streamNetwork
- applyShareNetworkParams(stream, streamNetwork, params)
- if finalmask, ok := stream["finalmask"].(map[string]any); ok {
- applyFinalMaskParams(finalmask, params)
- }
- security, _ := stream["security"].(string)
- switch security {
- case "tls":
- applyShareTLSParams(stream, params)
- case "reality":
- applyShareRealityParams(stream, params)
- if streamNetwork == "tcp" && len(clients[clientIndex].Flow) > 0 {
- params["flow"] = clients[clientIndex].Flow
- }
- default:
- params["security"] = "none"
- }
- externalProxies, _ := stream["externalProxy"].([]any)
- if len(externalProxies) > 0 {
- return s.buildExternalProxyURLLinks(
- externalProxies,
- params,
- security,
- func(dest string, port int) string {
- return fmt.Sprintf("trojan://%s@%s:%d", password, dest, port)
- },
- func(ep map[string]any) string {
- return s.genRemark(inbound, email, ep["remark"].(string))
- },
- )
- }
- link := fmt.Sprintf("trojan://%s@%s:%d", password, address, port)
- return buildLinkWithParams(link, params, s.genRemark(inbound, email, ""))
- }
- // encodeUserinfo percent-encodes a userinfo (password/auth) value so it
- // can be safely embedded in a `scheme://<value>@host:port` URL. RFC 3986
- // allows `=` in userinfo as a sub-delim, but several Trojan and Hysteria
- // clients reject share-links where the password contains literal `/`
- // or `=` (notably the common base64-with-padding shape produced by the
- // panel). Encode them too — this matches encodeURIComponent() on the
- // frontend and round-trips cleanly through net/url's parser.
- func encodeUserinfo(s string) string {
- return strings.ReplaceAll(url.QueryEscape(s), "+", "%20")
- }
- func (s *SubService) genShadowsocksLink(inbound *model.Inbound, email string) string {
- if inbound.Protocol != model.Shadowsocks {
- return ""
- }
- address := s.resolveInboundAddress(inbound)
- stream := unmarshalStreamSettings(inbound.StreamSettings)
- clients, _ := s.inboundService.GetClients(inbound)
- var settings map[string]any
- json.Unmarshal([]byte(inbound.Settings), &settings)
- inboundPassword := settings["password"].(string)
- method := settings["method"].(string)
- clientIndex := findClientIndex(clients, email)
- streamNetwork := stream["network"].(string)
- params := make(map[string]string)
- params["type"] = streamNetwork
- applyShareNetworkParams(stream, streamNetwork, params)
- if finalmask, ok := stream["finalmask"].(map[string]any); ok {
- applyFinalMaskParams(finalmask, params)
- }
- security, _ := stream["security"].(string)
- if security == "tls" {
- applyShareTLSParams(stream, params)
- }
- encPart := fmt.Sprintf("%s:%s", method, clients[clientIndex].Password)
- if method[0] == '2' {
- encPart = fmt.Sprintf("%s:%s:%s", method, inboundPassword, clients[clientIndex].Password)
- }
- externalProxies, _ := stream["externalProxy"].([]any)
- if len(externalProxies) > 0 {
- proxyParams := cloneStringMap(params)
- proxyParams["security"] = security
- return s.buildExternalProxyURLLinks(
- externalProxies,
- proxyParams,
- security,
- func(dest string, port int) string {
- return fmt.Sprintf("ss://%s@%s:%d", base64.StdEncoding.EncodeToString([]byte(encPart)), dest, port)
- },
- func(ep map[string]any) string {
- return s.genRemark(inbound, email, ep["remark"].(string))
- },
- )
- }
- link := fmt.Sprintf("ss://%s@%s:%d", base64.StdEncoding.EncodeToString([]byte(encPart)), address, inbound.Port)
- return buildLinkWithParams(link, params, s.genRemark(inbound, email, ""))
- }
- func (s *SubService) genHysteriaLink(inbound *model.Inbound, email string) string {
- if inbound.Protocol != model.Hysteria {
- return ""
- }
- var stream map[string]any
- json.Unmarshal([]byte(inbound.StreamSettings), &stream)
- clients, _ := s.inboundService.GetClients(inbound)
- clientIndex := -1
- for i, client := range clients {
- if client.Email == email {
- clientIndex = i
- break
- }
- }
- auth := encodeUserinfo(clients[clientIndex].Auth)
- params := make(map[string]string)
- params["security"] = "tls"
- tlsSetting, _ := stream["tlsSettings"].(map[string]any)
- alpns, _ := tlsSetting["alpn"].([]any)
- var alpn []string
- for _, a := range alpns {
- alpn = append(alpn, a.(string))
- }
- if len(alpn) > 0 {
- params["alpn"] = strings.Join(alpn, ",")
- }
- if sniValue, ok := searchKey(tlsSetting, "serverName"); ok {
- params["sni"], _ = sniValue.(string)
- }
- tlsSettings, _ := searchKey(tlsSetting, "settings")
- if tlsSetting != nil {
- if fpValue, ok := searchKey(tlsSettings, "fingerprint"); ok {
- params["fp"], _ = fpValue.(string)
- }
- if insecure, ok := searchKey(tlsSettings, "allowInsecure"); ok {
- if insecure.(bool) {
- params["insecure"] = "1"
- }
- }
- }
- // salamander obfs (Hysteria2). The panel-side link generator already
- // emits these; keep the subscription output in sync so a client has
- // the obfs password to match the server.
- if finalmask, ok := stream["finalmask"].(map[string]any); ok {
- applyFinalMaskParams(finalmask, params)
- if udpMasks, ok := finalmask["udp"].([]any); ok {
- for _, m := range udpMasks {
- mask, _ := m.(map[string]any)
- if mask == nil || mask["type"] != "salamander" {
- continue
- }
- settings, _ := mask["settings"].(map[string]any)
- if pw, ok := settings["password"].(string); ok && pw != "" {
- params["obfs"] = "salamander"
- params["obfs-password"] = pw
- break
- }
- }
- }
- }
- var settings map[string]any
- json.Unmarshal([]byte(inbound.Settings), &settings)
- version, _ := settings["version"].(float64)
- protocol := "hysteria2"
- if int(version) == 1 {
- protocol = "hysteria"
- }
- // Fan out one link per External Proxy entry if any. Previously this
- // generator ignored `externalProxy` entirely, so the link kept the
- // server's own IP/port even when the admin configured an alternate
- // endpoint (e.g. a CDN hostname + port that forwards to the node).
- // Matches the behaviour of genVlessLink / genTrojanLink / ….
- externalProxies, _ := stream["externalProxy"].([]any)
- if len(externalProxies) > 0 {
- links := make([]string, 0, len(externalProxies))
- for _, externalProxy := range externalProxies {
- ep, ok := externalProxy.(map[string]any)
- if !ok {
- continue
- }
- dest, _ := ep["dest"].(string)
- portF, okPort := ep["port"].(float64)
- if dest == "" || !okPort {
- continue
- }
- epRemark, _ := ep["remark"].(string)
- link := fmt.Sprintf("%s://%s@%s:%d", protocol, auth, dest, int(portF))
- u, _ := url.Parse(link)
- q := u.Query()
- for k, v := range params {
- q.Add(k, v)
- }
- u.RawQuery = q.Encode()
- u.Fragment = s.genRemark(inbound, email, epRemark)
- links = append(links, u.String())
- }
- return strings.Join(links, "\n")
- }
- // No external proxy configured — use the inbound's resolved address so
- // node-managed inbounds get the node's host instead of the central panel's.
- link := fmt.Sprintf("%s://%s@%s:%d", protocol, auth, s.resolveInboundAddress(inbound), inbound.Port)
- url, _ := url.Parse(link)
- q := url.Query()
- for k, v := range params {
- q.Add(k, v)
- }
- url.RawQuery = q.Encode()
- url.Fragment = s.genRemark(inbound, email, "")
- return url.String()
- }
- // loadNodes refreshes nodesByID from the DB. Called once per request so
- // the per-inbound resolveInboundAddress lookups are pure map reads.
- // We filter to address != ” so a half-configured node row doesn't
- // accidentally produce a useless host like "https://:2053".
- func (s *SubService) loadNodes() {
- db := database.GetDB()
- var nodes []*model.Node
- if err := db.Model(&model.Node{}).Where("address != ''").Find(&nodes).Error; err != nil {
- logger.Warning("subscription: load nodes failed:", err)
- s.nodesByID = nil
- return
- }
- m := make(map[int]*model.Node, len(nodes))
- for _, n := range nodes {
- m[n.Id] = n
- }
- s.nodesByID = m
- }
- // resolveInboundAddress picks the host an external client should
- // connect to. Order:
- // 1. If the inbound is node-managed and the node has an address, use
- // the node's address — central panel's hostname doesn't speak xray
- // for that inbound.
- // 2. If the inbound binds to a non-wildcard listen address, use it.
- // 3. Otherwise fall back to the request's host (whatever the client
- // subscribed against).
- func (s *SubService) resolveInboundAddress(inbound *model.Inbound) string {
- if inbound.NodeID != nil && s.nodesByID != nil {
- if n, ok := s.nodesByID[*inbound.NodeID]; ok && n.Address != "" {
- return n.Address
- }
- }
- if inbound.Listen == "" || inbound.Listen == "0.0.0.0" || inbound.Listen == "::" || inbound.Listen == "::0" {
- return s.address
- }
- return inbound.Listen
- }
- func findClientIndex(clients []model.Client, email string) int {
- for i, client := range clients {
- if client.Email == email {
- return i
- }
- }
- return -1
- }
- func unmarshalStreamSettings(streamSettings string) map[string]any {
- var stream map[string]any
- json.Unmarshal([]byte(streamSettings), &stream)
- return stream
- }
- func applyPathAndHostParams(settings map[string]any, params map[string]string) {
- params["path"] = settings["path"].(string)
- if host, ok := settings["host"].(string); ok && len(host) > 0 {
- params["host"] = host
- } else {
- headers, _ := settings["headers"].(map[string]any)
- params["host"] = searchHost(headers)
- }
- }
- func applyPathAndHostObj(settings map[string]any, obj map[string]any) {
- obj["path"] = settings["path"].(string)
- if host, ok := settings["host"].(string); ok && len(host) > 0 {
- obj["host"] = host
- } else {
- headers, _ := settings["headers"].(map[string]any)
- obj["host"] = searchHost(headers)
- }
- }
- func applyShareNetworkParams(stream map[string]any, streamNetwork string, params map[string]string) {
- switch streamNetwork {
- case "tcp":
- tcp, _ := stream["tcpSettings"].(map[string]any)
- header, _ := tcp["header"].(map[string]any)
- typeStr, _ := header["type"].(string)
- if typeStr == "http" {
- request := header["request"].(map[string]any)
- requestPath, _ := request["path"].([]any)
- params["path"] = requestPath[0].(string)
- headers, _ := request["headers"].(map[string]any)
- params["host"] = searchHost(headers)
- params["headerType"] = "http"
- }
- case "kcp":
- applyKcpShareParams(stream, params)
- case "ws":
- ws, _ := stream["wsSettings"].(map[string]any)
- applyPathAndHostParams(ws, params)
- case "grpc":
- grpc, _ := stream["grpcSettings"].(map[string]any)
- params["serviceName"] = grpc["serviceName"].(string)
- params["authority"], _ = grpc["authority"].(string)
- if grpc["multiMode"].(bool) {
- params["mode"] = "multi"
- }
- case "httpupgrade":
- httpupgrade, _ := stream["httpupgradeSettings"].(map[string]any)
- applyPathAndHostParams(httpupgrade, params)
- case "xhttp":
- xhttp, _ := stream["xhttpSettings"].(map[string]any)
- applyXhttpExtraParams(xhttp, params)
- }
- }
- // applyXhttpExtraObj copies the bidirectional xhttp settings into the
- // VMess base64 JSON link object. VMess supports arbitrary keys, so we
- // flatten the SplitHTTPConfig "extra" fields directly onto obj.
- func applyXhttpExtraObj(xhttp map[string]any, obj map[string]any) {
- if xpb, ok := xhttp["xPaddingBytes"].(string); ok && len(xpb) > 0 {
- obj["x_padding_bytes"] = xpb
- }
- maps.Copy(obj, buildXhttpExtra(xhttp))
- }
- func applyVmessNetworkParams(stream map[string]any, network string, obj map[string]any) {
- obj["net"] = network
- switch network {
- case "tcp":
- tcp, _ := stream["tcpSettings"].(map[string]any)
- header, _ := tcp["header"].(map[string]any)
- typeStr, _ := header["type"].(string)
- obj["type"] = typeStr
- if typeStr == "http" {
- request := header["request"].(map[string]any)
- requestPath, _ := request["path"].([]any)
- obj["path"] = requestPath[0].(string)
- headers, _ := request["headers"].(map[string]any)
- obj["host"] = searchHost(headers)
- }
- case "kcp":
- applyKcpShareObj(stream, obj)
- case "ws":
- ws, _ := stream["wsSettings"].(map[string]any)
- applyPathAndHostObj(ws, obj)
- case "grpc":
- grpc, _ := stream["grpcSettings"].(map[string]any)
- obj["path"] = grpc["serviceName"].(string)
- obj["authority"] = grpc["authority"].(string)
- if grpc["multiMode"].(bool) {
- obj["type"] = "multi"
- }
- case "httpupgrade":
- httpupgrade, _ := stream["httpupgradeSettings"].(map[string]any)
- applyPathAndHostObj(httpupgrade, obj)
- case "xhttp":
- xhttp, _ := stream["xhttpSettings"].(map[string]any)
- applyPathAndHostObj(xhttp, obj)
- if mode, ok := xhttp["mode"].(string); ok {
- obj["mode"] = mode
- }
- applyXhttpExtraObj(xhttp, obj)
- }
- }
- func applyShareTLSParams(stream map[string]any, params map[string]string) {
- params["security"] = "tls"
- tlsSetting, _ := stream["tlsSettings"].(map[string]any)
- alpns, _ := tlsSetting["alpn"].([]any)
- var alpn []string
- for _, a := range alpns {
- alpn = append(alpn, a.(string))
- }
- if len(alpn) > 0 {
- params["alpn"] = strings.Join(alpn, ",")
- }
- if sniValue, ok := searchKey(tlsSetting, "serverName"); ok {
- params["sni"], _ = sniValue.(string)
- }
- tlsSettings, _ := searchKey(tlsSetting, "settings")
- if tlsSetting != nil {
- if fpValue, ok := searchKey(tlsSettings, "fingerprint"); ok {
- params["fp"], _ = fpValue.(string)
- }
- }
- }
- func applyVmessTLSParams(stream map[string]any, obj map[string]any) {
- tlsSetting, _ := stream["tlsSettings"].(map[string]any)
- alpns, _ := tlsSetting["alpn"].([]any)
- if len(alpns) > 0 {
- var alpn []string
- for _, a := range alpns {
- alpn = append(alpn, a.(string))
- }
- obj["alpn"] = strings.Join(alpn, ",")
- }
- if sniValue, ok := searchKey(tlsSetting, "serverName"); ok {
- obj["sni"], _ = sniValue.(string)
- }
- tlsSettings, _ := searchKey(tlsSetting, "settings")
- if tlsSetting != nil {
- if fpValue, ok := searchKey(tlsSettings, "fingerprint"); ok {
- obj["fp"], _ = fpValue.(string)
- }
- }
- }
- func applyShareRealityParams(stream map[string]any, params map[string]string) {
- params["security"] = "reality"
- realitySetting, _ := stream["realitySettings"].(map[string]any)
- realitySettings, _ := searchKey(realitySetting, "settings")
- if realitySetting != nil {
- if sniValue, ok := searchKey(realitySetting, "serverNames"); ok {
- sNames, _ := sniValue.([]any)
- params["sni"] = sNames[random.Num(len(sNames))].(string)
- }
- if pbkValue, ok := searchKey(realitySettings, "publicKey"); ok {
- params["pbk"], _ = pbkValue.(string)
- }
- if sidValue, ok := searchKey(realitySetting, "shortIds"); ok {
- shortIds, _ := sidValue.([]any)
- params["sid"] = shortIds[random.Num(len(shortIds))].(string)
- }
- if fpValue, ok := searchKey(realitySettings, "fingerprint"); ok {
- if fp, ok := fpValue.(string); ok && len(fp) > 0 {
- params["fp"] = fp
- }
- }
- if pqvValue, ok := searchKey(realitySettings, "mldsa65Verify"); ok {
- if pqv, ok := pqvValue.(string); ok && len(pqv) > 0 {
- params["pqv"] = pqv
- }
- }
- params["spx"] = "/" + random.Seq(15)
- }
- }
- func buildVmessLink(obj map[string]any) string {
- jsonStr, _ := json.MarshalIndent(obj, "", " ")
- return "vmess://" + base64.StdEncoding.EncodeToString(jsonStr)
- }
- func cloneVmessShareObj(baseObj map[string]any, newSecurity string) map[string]any {
- newObj := map[string]any{}
- for key, value := range baseObj {
- if !(newSecurity == "none" && (key == "alpn" || key == "sni" || key == "fp")) {
- newObj[key] = value
- }
- }
- return newObj
- }
- func applyExternalProxyTLSObj(ep map[string]any, obj map[string]any, security string) {
- if security != "tls" {
- return
- }
- if sni, ok := externalProxySNI(ep); ok {
- obj["sni"] = sni
- }
- if fp, ok := ep["fingerprint"].(string); ok && fp != "" {
- obj["fp"] = fp
- }
- if alpn, ok := externalProxyALPN(ep["alpn"]); ok {
- obj["alpn"] = alpn
- }
- }
- func applyExternalProxyTLSParams(ep map[string]any, params map[string]string, security string) {
- if security != "tls" {
- return
- }
- if sni, ok := externalProxySNI(ep); ok {
- params["sni"] = sni
- }
- if fp, ok := ep["fingerprint"].(string); ok && fp != "" {
- params["fp"] = fp
- }
- if alpn, ok := externalProxyALPN(ep["alpn"]); ok {
- params["alpn"] = alpn
- }
- }
- // cloneStreamForExternalProxy returns a shallow clone of stream with
- // tlsSettings (and its nested settings map) deep-copied. The external
- // proxy loop mutates tlsSettings per iteration, so without isolating
- // those maps each proxy's SNI/fingerprint/ALPN would leak into the next.
- func cloneStreamForExternalProxy(stream map[string]any) map[string]any {
- out := cloneMap(stream)
- ts, ok := out["tlsSettings"].(map[string]any)
- if !ok || ts == nil {
- return out
- }
- clonedTs := cloneMap(ts)
- if inner, ok := clonedTs["settings"].(map[string]any); ok && inner != nil {
- clonedTs["settings"] = cloneMap(inner)
- }
- out["tlsSettings"] = clonedTs
- return out
- }
- func applyExternalProxyTLSToStream(ep map[string]any, stream map[string]any, security string) {
- if security != "tls" {
- return
- }
- tlsSettings, _ := stream["tlsSettings"].(map[string]any)
- if tlsSettings == nil {
- tlsSettings = map[string]any{}
- stream["tlsSettings"] = tlsSettings
- }
- if sni, ok := externalProxySNI(ep); ok {
- tlsSettings["serverName"] = sni
- }
- if fp, ok := ep["fingerprint"].(string); ok && fp != "" {
- tlsSettings["fingerprint"] = fp
- settings, _ := tlsSettings["settings"].(map[string]any)
- if settings == nil {
- settings = map[string]any{}
- tlsSettings["settings"] = settings
- }
- settings["fingerprint"] = fp
- }
- if alpn, ok := externalProxyALPNList(ep["alpn"]); ok {
- tlsSettings["alpn"] = alpn
- }
- }
- func externalProxySNI(ep map[string]any) (string, bool) {
- if sni, ok := ep["sni"].(string); ok && sni != "" {
- return sni, true
- }
- if dest, ok := ep["dest"].(string); ok && dest != "" {
- return dest, true
- }
- return "", false
- }
- func externalProxyALPN(value any) (string, bool) {
- switch v := value.(type) {
- case string:
- return v, v != ""
- case []string:
- if len(v) == 0 {
- return "", false
- }
- return strings.Join(v, ","), true
- case []any:
- alpn := make([]string, 0, len(v))
- for _, item := range v {
- if s, ok := item.(string); ok && s != "" {
- alpn = append(alpn, s)
- }
- }
- if len(alpn) == 0 {
- return "", false
- }
- return strings.Join(alpn, ","), true
- default:
- return "", false
- }
- }
- func externalProxyALPNList(value any) ([]any, bool) {
- switch v := value.(type) {
- case string:
- if v == "" {
- return nil, false
- }
- parts := strings.Split(v, ",")
- out := make([]any, 0, len(parts))
- for _, part := range parts {
- if part = strings.TrimSpace(part); part != "" {
- out = append(out, part)
- }
- }
- return out, len(out) > 0
- case []string:
- out := make([]any, 0, len(v))
- for _, item := range v {
- if item != "" {
- out = append(out, item)
- }
- }
- return out, len(out) > 0
- case []any:
- out := make([]any, 0, len(v))
- for _, item := range v {
- if s, ok := item.(string); ok && s != "" {
- out = append(out, s)
- }
- }
- return out, len(out) > 0
- default:
- return nil, false
- }
- }
- func (s *SubService) buildVmessExternalProxyLinks(externalProxies []any, baseObj map[string]any, inbound *model.Inbound, email string) string {
- var links strings.Builder
- for index, externalProxy := range externalProxies {
- ep, _ := externalProxy.(map[string]any)
- newSecurity, _ := ep["forceTls"].(string)
- securityToApply := baseObj["tls"].(string)
- if newSecurity != "same" {
- securityToApply = newSecurity
- }
- newObj := cloneVmessShareObj(baseObj, newSecurity)
- newObj["ps"] = s.genRemark(inbound, email, ep["remark"].(string))
- newObj["add"] = ep["dest"].(string)
- newObj["port"] = int(ep["port"].(float64))
- if newSecurity != "same" {
- newObj["tls"] = newSecurity
- }
- applyExternalProxyTLSObj(ep, newObj, securityToApply)
- if index > 0 {
- links.WriteString("\n")
- }
- links.WriteString(buildVmessLink(newObj))
- }
- return links.String()
- }
- func buildLinkWithParams(link string, params map[string]string, fragment string) string {
- parsedURL, _ := url.Parse(link)
- q := parsedURL.Query()
- for k, v := range params {
- q.Add(k, v)
- }
- parsedURL.RawQuery = q.Encode()
- parsedURL.Fragment = fragment
- return parsedURL.String()
- }
- func buildLinkWithParamsAndSecurity(link string, params map[string]string, fragment, security string, omitTLSFields bool) string {
- parsedURL, _ := url.Parse(link)
- q := parsedURL.Query()
- for k, v := range params {
- if k == "security" {
- v = security
- }
- if omitTLSFields && (k == "alpn" || k == "sni" || k == "fp") {
- continue
- }
- q.Add(k, v)
- }
- parsedURL.RawQuery = q.Encode()
- parsedURL.Fragment = fragment
- return parsedURL.String()
- }
- func (s *SubService) buildExternalProxyURLLinks(
- externalProxies []any,
- params map[string]string,
- baseSecurity string,
- makeLink func(dest string, port int) string,
- makeRemark func(ep map[string]any) string,
- ) string {
- links := make([]string, 0, len(externalProxies))
- for _, externalProxy := range externalProxies {
- ep, _ := externalProxy.(map[string]any)
- newSecurity, _ := ep["forceTls"].(string)
- dest, _ := ep["dest"].(string)
- port := int(ep["port"].(float64))
- securityToApply := baseSecurity
- if newSecurity != "same" {
- securityToApply = newSecurity
- }
- nextParams := cloneStringMap(params)
- applyExternalProxyTLSParams(ep, nextParams, securityToApply)
- links = append(
- links,
- buildLinkWithParamsAndSecurity(
- makeLink(dest, port),
- nextParams,
- makeRemark(ep),
- securityToApply,
- newSecurity == "none",
- ),
- )
- }
- return strings.Join(links, "\n")
- }
- func cloneStringMap(source map[string]string) map[string]string {
- cloned := make(map[string]string, len(source))
- maps.Copy(cloned, source)
- return cloned
- }
- func (s *SubService) genRemark(inbound *model.Inbound, email string, extra string) string {
- separationChar := string(s.remarkModel[0])
- orderChars := s.remarkModel[1:]
- orders := map[byte]string{
- 'i': "",
- 'e': "",
- 'o': "",
- }
- if len(email) > 0 && s.emailInRemark {
- orders['e'] = email
- }
- if len(inbound.Remark) > 0 {
- orders['i'] = inbound.Remark
- }
- if len(extra) > 0 {
- orders['o'] = extra
- }
- var remark []string
- for i := 0; i < len(orderChars); i++ {
- char := orderChars[i]
- order, exists := orders[char]
- if exists && order != "" {
- remark = append(remark, order)
- }
- }
- if s.showInfo {
- statsExist := false
- var stats xray.ClientTraffic
- for _, clientStat := range inbound.ClientStats {
- if clientStat.Email == email {
- stats = clientStat
- statsExist = true
- break
- }
- }
- // Get remained days
- if statsExist {
- if !stats.Enable {
- return fmt.Sprintf("⛔️N/A%s%s", separationChar, strings.Join(remark, separationChar))
- }
- if vol := stats.Total - (stats.Up + stats.Down); vol > 0 {
- remark = append(remark, fmt.Sprintf("%s%s", common.FormatTraffic(vol), "📊"))
- }
- now := time.Now().Unix()
- switch exp := stats.ExpiryTime / 1000; {
- case exp > 0:
- remainingSeconds := exp - now
- days := remainingSeconds / 86400
- hours := (remainingSeconds % 86400) / 3600
- minutes := (remainingSeconds % 3600) / 60
- if days > 0 {
- if hours > 0 {
- remark = append(remark, fmt.Sprintf("%dD,%dH⏳", days, hours))
- } else {
- remark = append(remark, fmt.Sprintf("%dD⏳", days))
- }
- } else if hours > 0 {
- remark = append(remark, fmt.Sprintf("%dH⏳", hours))
- } else {
- remark = append(remark, fmt.Sprintf("%dM⏳", minutes))
- }
- case exp < 0:
- days := exp / -86400
- hours := (exp % -86400) / 3600
- minutes := (exp % -3600) / 60
- if days > 0 {
- if hours > 0 {
- remark = append(remark, fmt.Sprintf("%dD,%dH⏳", days, hours))
- } else {
- remark = append(remark, fmt.Sprintf("%dD⏳", days))
- }
- } else if hours > 0 {
- remark = append(remark, fmt.Sprintf("%dH⏳", hours))
- } else {
- remark = append(remark, fmt.Sprintf("%dM⏳", minutes))
- }
- }
- }
- }
- return strings.Join(remark, separationChar)
- }
- func searchKey(data any, key string) (any, bool) {
- switch val := data.(type) {
- case map[string]any:
- for k, v := range val {
- if k == key {
- return v, true
- }
- if result, ok := searchKey(v, key); ok {
- return result, true
- }
- }
- case []any:
- for _, v := range val {
- if result, ok := searchKey(v, key); ok {
- return result, true
- }
- }
- }
- return nil, false
- }
- // buildXhttpExtra walks an xhttpSettings map and returns the JSON blob
- // that goes into the URL's `extra` param (or, for VMess, the link
- // object). Carries ONLY the bidirectional fields from xray-core's
- // SplitHTTPConfig — i.e. the ones the server enforces and the client
- // must match. Strictly one-sided fields are excluded:
- //
- // - server-only (noSSEHeader, scMaxBufferedPosts, scStreamUpServerSecs,
- // serverMaxHeaderBytes) — client wouldn't read them, so emitting
- // them just bloats the URL.
- // - client-only values are included only when present in the inbound
- // JSON. Some deployments/imported configs carry them there, and the
- // subscription link is the only place clients can receive them.
- //
- // Truthy-only guards keep default inbounds emitting the same compact URL
- // they did before this helper grew.
- func buildXhttpExtra(xhttp map[string]any) map[string]any {
- if xhttp == nil {
- return nil
- }
- extra := map[string]any{}
- if xpb, ok := xhttp["xPaddingBytes"].(string); ok && len(xpb) > 0 {
- extra["xPaddingBytes"] = xpb
- }
- if obfs, ok := xhttp["xPaddingObfsMode"].(bool); ok && obfs {
- extra["xPaddingObfsMode"] = true
- for _, field := range []string{"xPaddingKey", "xPaddingHeader", "xPaddingPlacement", "xPaddingMethod"} {
- if v, ok := xhttp[field].(string); ok && len(v) > 0 {
- extra[field] = v
- }
- }
- }
- stringFields := []string{
- "uplinkHTTPMethod",
- "sessionPlacement", "sessionKey",
- "seqPlacement", "seqKey",
- "uplinkDataPlacement", "uplinkDataKey",
- "scMaxEachPostBytes", "scMinPostsIntervalMs",
- }
- for _, field := range stringFields {
- if v, ok := xhttp[field].(string); ok && len(v) > 0 {
- extra[field] = v
- }
- }
- for _, field := range []string{"uplinkChunkSize"} {
- if v, ok := nonZeroShareValue(xhttp[field]); ok {
- extra[field] = v
- }
- }
- for _, field := range []string{"noGRPCHeader"} {
- if v, ok := xhttp[field].(bool); ok && v {
- extra[field] = v
- }
- }
- for _, field := range []string{"xmux", "downloadSettings"} {
- if v, ok := nonEmptyShareObject(xhttp[field]); ok {
- extra[field] = v
- }
- }
- // Headers — emitted as the {name: value} map upstream's struct
- // expects. The server runtime ignores this field, but the client
- // (consuming the share link) honors it. Drop any "host" entry —
- // host already wins as a top-level URL param.
- if rawHeaders, ok := xhttp["headers"].(map[string]any); ok && len(rawHeaders) > 0 {
- out := map[string]any{}
- for k, v := range rawHeaders {
- if strings.EqualFold(k, "host") {
- continue
- }
- out[k] = v
- }
- if len(out) > 0 {
- extra["headers"] = out
- }
- }
- if len(extra) == 0 {
- return nil
- }
- return extra
- }
- func nonZeroShareValue(v any) (any, bool) {
- switch value := v.(type) {
- case string:
- return value, value != ""
- case int:
- return value, value != 0
- case int32:
- return value, value != 0
- case int64:
- return value, value != 0
- case float32:
- return value, value != 0
- case float64:
- return value, value != 0
- default:
- return nil, false
- }
- }
- func nonEmptyShareObject(v any) (any, bool) {
- switch value := v.(type) {
- case map[string]any:
- return value, len(value) > 0
- case map[string]string:
- return value, len(value) > 0
- case []any:
- return value, len(value) > 0
- default:
- return nil, false
- }
- }
- // applyXhttpExtraParams emits the full xhttp config into the URL query
- // params of a vless:// / trojan:// / ss:// link. Sets path/host/mode at
- // top level (xray's Build() always lets these win over `extra`) and packs
- // everything else into a JSON `extra` param. Also writes the flat
- // `x_padding_bytes` param sing-box-family clients understand.
- //
- // Without this, the admin's custom xPaddingBytes / sessionKey / etc. never
- // reach the client and handshakes are silently rejected with
- // `invalid padding (...) length: 0` — the client-visible symptom is
- // "xhttp doesn't connect" on OpenWRT / sing-box.
- //
- // Two encodings are written so every popular client can read at least one:
- //
- // - x_padding_bytes=<range> — flat param, understood by sing-box and its
- // derivatives (Podkop, OpenWRT sing-box, Karing, NekoBox, …).
- // - extra=<url-encoded-json> — full xhttp settings blob, which is how
- // xray-core clients (v2rayNG, Happ, Furious, Exclave, …) pick up the
- // bidirectional fields beyond path/host/mode.
- func applyXhttpExtraParams(xhttp map[string]any, params map[string]string) {
- if xhttp == nil {
- return
- }
- applyPathAndHostParams(xhttp, params)
- if mode, ok := xhttp["mode"].(string); ok {
- params["mode"] = mode
- }
- if xpb, ok := xhttp["xPaddingBytes"].(string); ok && len(xpb) > 0 {
- params["x_padding_bytes"] = xpb
- }
- extra := buildXhttpExtra(xhttp)
- if extra != nil {
- if b, err := json.Marshal(extra); err == nil {
- params["extra"] = string(b)
- }
- }
- }
- var kcpMaskToHeaderType = map[string]string{
- "header-dns": "dns",
- "header-dtls": "dtls",
- "header-srtp": "srtp",
- "header-utp": "utp",
- "header-wechat": "wechat-video",
- "header-wireguard": "wireguard",
- }
- var validFinalMaskUDPTypes = map[string]struct{}{
- "salamander": {},
- "mkcp-aes128gcm": {},
- "header-dns": {},
- "header-dtls": {},
- "header-srtp": {},
- "header-utp": {},
- "header-wechat": {},
- "header-wireguard": {},
- "mkcp-original": {},
- "xdns": {},
- "xicmp": {},
- "noise": {},
- "header-custom": {},
- }
- var validFinalMaskTCPTypes = map[string]struct{}{
- "header-custom": {},
- "fragment": {},
- "sudoku": {},
- }
- // applyKcpShareParams reconstructs legacy KCP share-link fields from either
- // the historical kcpSettings.header/seed shape or the current finalmask model.
- // This keeps subscription output compatible while avoiding panics when older
- // keys are absent from modern inbounds.
- func applyKcpShareParams(stream map[string]any, params map[string]string) {
- extractKcpShareFields(stream).applyToParams(params)
- }
- func applyKcpShareObj(stream map[string]any, obj map[string]any) {
- extractKcpShareFields(stream).applyToObj(obj)
- }
- type kcpShareFields struct {
- headerType string
- seed string
- mtu int
- tti int
- }
- func (f kcpShareFields) applyToParams(params map[string]string) {
- if f.headerType != "" && f.headerType != "none" {
- params["headerType"] = f.headerType
- }
- setStringParam(params, "seed", f.seed)
- setIntParam(params, "mtu", f.mtu)
- setIntParam(params, "tti", f.tti)
- }
- func (f kcpShareFields) applyToObj(obj map[string]any) {
- if f.headerType != "" && f.headerType != "none" {
- obj["type"] = f.headerType
- }
- setStringField(obj, "path", f.seed)
- setIntField(obj, "mtu", f.mtu)
- setIntField(obj, "tti", f.tti)
- }
- func extractKcpShareFields(stream map[string]any) kcpShareFields {
- fields := kcpShareFields{headerType: "none"}
- if kcp, ok := stream["kcpSettings"].(map[string]any); ok {
- if header, ok := kcp["header"].(map[string]any); ok {
- if value, ok := header["type"].(string); ok && value != "" {
- fields.headerType = value
- }
- }
- if value, ok := kcp["seed"].(string); ok && value != "" {
- fields.seed = value
- }
- if value, ok := readPositiveInt(kcp["mtu"]); ok {
- fields.mtu = value
- }
- if value, ok := readPositiveInt(kcp["tti"]); ok {
- fields.tti = value
- }
- }
- for _, rawMask := range normalizedFinalMaskUDPMasks(stream["finalmask"]) {
- mask, _ := rawMask.(map[string]any)
- if mask == nil {
- continue
- }
- maskType, _ := mask["type"].(string)
- if mapped, ok := kcpMaskToHeaderType[maskType]; ok {
- fields.headerType = mapped
- continue
- }
- switch maskType {
- case "mkcp-original":
- fields.seed = ""
- case "mkcp-aes128gcm":
- fields.seed = ""
- settings, _ := mask["settings"].(map[string]any)
- if value, ok := settings["password"].(string); ok && value != "" {
- fields.seed = value
- }
- }
- }
- return fields
- }
- func readPositiveInt(value any) (int, bool) {
- switch number := value.(type) {
- case int:
- return number, number > 0
- case int32:
- return int(number), number > 0
- case int64:
- return int(number), number > 0
- case float32:
- parsed := int(number)
- return parsed, parsed > 0
- case float64:
- parsed := int(number)
- return parsed, parsed > 0
- default:
- return 0, false
- }
- }
- func setStringParam(params map[string]string, key, value string) {
- if value == "" {
- delete(params, key)
- return
- }
- params[key] = value
- }
- func setIntParam(params map[string]string, key string, value int) {
- if value <= 0 {
- delete(params, key)
- return
- }
- params[key] = fmt.Sprintf("%d", value)
- }
- func setStringField(obj map[string]any, key, value string) {
- if value == "" {
- delete(obj, key)
- return
- }
- obj[key] = value
- }
- func setIntField(obj map[string]any, key string, value int) {
- if value <= 0 {
- delete(obj, key)
- return
- }
- obj[key] = value
- }
- // applyFinalMaskParams exports the finalmask payload as the compact
- // `fm=<json>` share-link field used by v2rayN-compatible clients.
- func applyFinalMaskParams(finalmask map[string]any, params map[string]string) {
- if fm, ok := marshalFinalMask(finalmask); ok {
- params["fm"] = fm
- }
- }
- func applyFinalMaskObj(finalmask map[string]any, obj map[string]any) {
- if fm, ok := marshalFinalMask(finalmask); ok {
- obj["fm"] = fm
- }
- }
- func marshalFinalMask(finalmask map[string]any) (string, bool) {
- normalized := normalizeFinalMask(finalmask)
- if !hasFinalMaskContent(normalized) {
- return "", false
- }
- b, err := json.Marshal(normalized)
- if err != nil || len(b) == 0 || string(b) == "null" {
- return "", false
- }
- return string(b), true
- }
- func normalizeFinalMask(finalmask map[string]any) map[string]any {
- tcpMasks := normalizedFinalMaskTCPMasks(finalmask)
- udpMasks := normalizedFinalMaskUDPMasks(finalmask)
- quicParams, hasQuicParams := finalmask["quicParams"].(map[string]any)
- if len(tcpMasks) == 0 && len(udpMasks) == 0 && !hasQuicParams {
- return nil
- }
- result := map[string]any{}
- if len(tcpMasks) > 0 {
- result["tcp"] = tcpMasks
- }
- if len(udpMasks) > 0 {
- result["udp"] = udpMasks
- }
- if hasQuicParams && len(quicParams) > 0 {
- result["quicParams"] = quicParams
- }
- return result
- }
- func normalizedFinalMaskTCPMasks(value any) []any {
- finalmask, _ := value.(map[string]any)
- if finalmask == nil {
- return nil
- }
- rawMasks, _ := finalmask["tcp"].([]any)
- if len(rawMasks) == 0 {
- return nil
- }
- normalized := make([]any, 0, len(rawMasks))
- for _, rawMask := range rawMasks {
- mask, _ := rawMask.(map[string]any)
- if mask == nil {
- continue
- }
- maskType, _ := mask["type"].(string)
- if _, ok := validFinalMaskTCPTypes[maskType]; !ok || maskType == "" {
- continue
- }
- normalizedMask := map[string]any{"type": maskType}
- if settings, ok := mask["settings"].(map[string]any); ok && len(settings) > 0 {
- normalizedMask["settings"] = settings
- }
- normalized = append(normalized, normalizedMask)
- }
- if len(normalized) == 0 {
- return nil
- }
- return normalized
- }
- func normalizedFinalMaskUDPMasks(value any) []any {
- finalmask, _ := value.(map[string]any)
- if finalmask == nil {
- return nil
- }
- rawMasks, _ := finalmask["udp"].([]any)
- if len(rawMasks) == 0 {
- return nil
- }
- normalized := make([]any, 0, len(rawMasks))
- for _, rawMask := range rawMasks {
- mask, _ := rawMask.(map[string]any)
- if mask == nil {
- continue
- }
- maskType, _ := mask["type"].(string)
- if _, ok := validFinalMaskUDPTypes[maskType]; !ok || maskType == "" {
- continue
- }
- normalizedMask := map[string]any{"type": maskType}
- if settings, ok := mask["settings"].(map[string]any); ok && len(settings) > 0 {
- normalizedMask["settings"] = settings
- }
- normalized = append(normalized, normalizedMask)
- }
- if len(normalized) == 0 {
- return nil
- }
- return normalized
- }
- func hasFinalMaskContent(value any) bool {
- switch v := value.(type) {
- case nil:
- return false
- case string:
- return len(v) > 0
- case map[string]any:
- for _, item := range v {
- if hasFinalMaskContent(item) {
- return true
- }
- }
- return false
- case []any:
- return slices.ContainsFunc(v, hasFinalMaskContent)
- default:
- return true
- }
- }
- func searchHost(headers any) string {
- data, _ := headers.(map[string]any)
- for k, v := range data {
- if strings.EqualFold(k, "host") {
- switch v.(type) {
- case []any:
- hosts, _ := v.([]any)
- if len(hosts) > 0 {
- return hosts[0].(string)
- } else {
- return ""
- }
- case any:
- return v.(string)
- }
- }
- }
- return ""
- }
- // PageData is a view model for subpage.html
- // PageData contains data for rendering the subscription information page.
- type PageData struct {
- Host string
- BasePath string
- SId string
- Enabled bool
- Download string
- Upload string
- Total string
- Used string
- Remained string
- Expire int64
- LastOnline int64
- Datepicker string
- DownloadByte int64
- UploadByte int64
- TotalByte int64
- SubUrl string
- SubJsonUrl string
- SubClashUrl string
- SubTitle string
- SubSupportUrl string
- Result []string
- Emails []string
- }
- // ResolveRequest extracts scheme and host info from request/headers consistently.
- // ResolveRequest extracts scheme, host, and header information from an HTTP request.
- func (s *SubService) ResolveRequest(c *gin.Context) (scheme string, host string, hostWithPort string, hostHeader string) {
- // scheme
- scheme = "http"
- if c.Request.TLS != nil || strings.EqualFold(c.GetHeader("X-Forwarded-Proto"), "https") {
- scheme = "https"
- }
- // base host (no port)
- if h, err := getHostFromXFH(c.GetHeader("X-Forwarded-Host")); err == nil && h != "" {
- host = h
- }
- if host == "" {
- host = c.GetHeader("X-Real-IP")
- }
- if host == "" {
- var err error
- host, _, err = net.SplitHostPort(c.Request.Host)
- if err != nil {
- host = c.Request.Host
- }
- }
- // host:port for URLs
- hostWithPort = c.GetHeader("X-Forwarded-Host")
- if hostWithPort == "" {
- hostWithPort = c.Request.Host
- }
- if hostWithPort == "" {
- hostWithPort = host
- }
- // header display host
- hostHeader = c.GetHeader("X-Forwarded-Host")
- if hostHeader == "" {
- hostHeader = c.GetHeader("X-Real-IP")
- }
- if hostHeader == "" {
- hostHeader = host
- }
- return
- }
- // BuildURLs constructs absolute subscription and JSON subscription URLs for a given subscription ID.
- // It prioritizes configured URIs, then individual settings, and finally falls back to request-derived components.
- func (s *SubService) BuildURLs(scheme, hostWithPort, subPath, subJsonPath, subClashPath, subId string) (subURL, subJsonURL, subClashURL string) {
- if subId == "" {
- return "", "", ""
- }
- configuredSubURI, _ := s.settingService.GetSubURI()
- configuredSubJsonURI, _ := s.settingService.GetSubJsonURI()
- configuredSubClashURI, _ := s.settingService.GetSubClashURI()
- var baseScheme, baseHostWithPort string
- if configuredSubURI == "" || configuredSubJsonURI == "" || configuredSubClashURI == "" {
- baseScheme, baseHostWithPort = s.getBaseSchemeAndHost(scheme, hostWithPort)
- }
- subURL = s.buildSingleURL(configuredSubURI, baseScheme, baseHostWithPort, subPath, subId)
- subJsonURL = s.buildSingleURL(configuredSubJsonURI, baseScheme, baseHostWithPort, subJsonPath, subId)
- subClashURL = s.buildSingleURL(configuredSubClashURI, baseScheme, baseHostWithPort, subClashPath, subId)
- return subURL, subJsonURL, subClashURL
- }
- // getBaseSchemeAndHost determines the base scheme and host from settings or falls back to request values
- func (s *SubService) getBaseSchemeAndHost(requestScheme, requestHostWithPort string) (string, string) {
- subDomain, err := s.settingService.GetSubDomain()
- if err != nil || subDomain == "" {
- return requestScheme, requestHostWithPort
- }
- // Get port and TLS settings
- subPort, _ := s.settingService.GetSubPort()
- subKeyFile, _ := s.settingService.GetSubKeyFile()
- subCertFile, _ := s.settingService.GetSubCertFile()
- // Determine scheme from TLS configuration
- scheme := "http"
- if subKeyFile != "" && subCertFile != "" {
- scheme = "https"
- }
- // Build host:port, always include port for clarity
- hostWithPort := fmt.Sprintf("%s:%d", subDomain, subPort)
- return scheme, hostWithPort
- }
- // buildSingleURL constructs a single URL using configured URI or base components
- func (s *SubService) buildSingleURL(configuredURI, baseScheme, baseHostWithPort, basePath, subId string) string {
- if configuredURI != "" {
- return s.joinPathWithID(configuredURI, subId)
- }
- baseURL := fmt.Sprintf("%s://%s", baseScheme, baseHostWithPort)
- return s.joinPathWithID(baseURL+basePath, subId)
- }
- // joinPathWithID safely joins a base path with a subscription ID
- func (s *SubService) joinPathWithID(basePath, subId string) string {
- if strings.HasSuffix(basePath, "/") {
- return basePath + subId
- }
- return basePath + "/" + subId
- }
- // BuildPageData parses header and prepares the template view model.
- // BuildPageData constructs page data for rendering the subscription information page.
- func (s *SubService) BuildPageData(subId string, hostHeader string, traffic xray.ClientTraffic, lastOnline int64, subs []string, emails []string, subURL, subJsonURL, subClashURL string, basePath string, subTitle string, subSupportUrl string) PageData {
- download := common.FormatTraffic(traffic.Down)
- upload := common.FormatTraffic(traffic.Up)
- total := "∞"
- used := common.FormatTraffic(traffic.Up + traffic.Down)
- remained := ""
- if traffic.Total > 0 {
- total = common.FormatTraffic(traffic.Total)
- left := max(traffic.Total-(traffic.Up+traffic.Down), 0)
- remained = common.FormatTraffic(left)
- }
- datepicker := s.datepicker
- if datepicker == "" {
- datepicker = "gregorian"
- }
- return PageData{
- Host: hostHeader,
- BasePath: basePath,
- SId: subId,
- Enabled: traffic.Enable,
- Download: download,
- Upload: upload,
- Total: total,
- Used: used,
- Remained: remained,
- Expire: traffic.ExpiryTime / 1000,
- LastOnline: lastOnline,
- Datepicker: datepicker,
- DownloadByte: traffic.Down,
- UploadByte: traffic.Up,
- TotalByte: traffic.Total,
- SubUrl: subURL,
- SubJsonUrl: subJsonURL,
- SubClashUrl: subClashURL,
- SubTitle: subTitle,
- SubSupportUrl: subSupportUrl,
- Result: subs,
- Emails: emails,
- }
- }
- func getHostFromXFH(s string) (string, error) {
- if strings.Contains(s, ":") {
- realHost, _, err := net.SplitHostPort(s)
- if err != nil {
- return "", err
- }
- return realHost, nil
- }
- return s, nil
- }
|