setting.go 26 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004
  1. package service
  2. import (
  3. "crypto/subtle"
  4. _ "embed"
  5. "encoding/json"
  6. "errors"
  7. "fmt"
  8. "net"
  9. "reflect"
  10. "strconv"
  11. "strings"
  12. "time"
  13. "github.com/mhsanaei/3x-ui/v3/database"
  14. "github.com/mhsanaei/3x-ui/v3/database/model"
  15. "github.com/mhsanaei/3x-ui/v3/logger"
  16. "github.com/mhsanaei/3x-ui/v3/util/common"
  17. "github.com/mhsanaei/3x-ui/v3/util/random"
  18. "github.com/mhsanaei/3x-ui/v3/util/reflect_util"
  19. "github.com/mhsanaei/3x-ui/v3/web/entity"
  20. "github.com/mhsanaei/3x-ui/v3/xray"
  21. )
  22. //go:embed config.json
  23. var xrayTemplateConfig string
  24. var defaultValueMap = map[string]string{
  25. "xrayTemplateConfig": xrayTemplateConfig,
  26. "webListen": "",
  27. "webDomain": "",
  28. "webPort": "2053",
  29. "webCertFile": "",
  30. "webKeyFile": "",
  31. "secret": random.Seq(32),
  32. "apiToken": "",
  33. "webBasePath": "/",
  34. "sessionMaxAge": "360",
  35. "trustedProxyCIDRs": "127.0.0.1/32,::1/128",
  36. "pageSize": "25",
  37. "expireDiff": "0",
  38. "trafficDiff": "0",
  39. "remarkModel": "-ieo",
  40. "timeLocation": "Local",
  41. "tgBotEnable": "false",
  42. "tgBotToken": "",
  43. "tgBotProxy": "",
  44. "tgBotAPIServer": "",
  45. "tgBotChatId": "",
  46. "tgRunTime": "@daily",
  47. "tgBotBackup": "false",
  48. "tgBotLoginNotify": "true",
  49. "tgCpu": "80",
  50. "tgLang": "en-US",
  51. "twoFactorEnable": "false",
  52. "twoFactorToken": "",
  53. "subEnable": "true",
  54. "subJsonEnable": "false",
  55. "subTitle": "",
  56. "subSupportUrl": "",
  57. "subProfileUrl": "",
  58. "subAnnounce": "",
  59. "subEnableRouting": "true",
  60. "subRoutingRules": "",
  61. "subListen": "",
  62. "subPort": "2096",
  63. "subPath": "/sub/",
  64. "subDomain": "",
  65. "subCertFile": "",
  66. "subKeyFile": "",
  67. "subUpdates": "12",
  68. "subEncrypt": "true",
  69. "subShowInfo": "true",
  70. "subURI": "",
  71. "subJsonPath": "/json/",
  72. "subJsonURI": "",
  73. "subClashEnable": "true",
  74. "subClashPath": "/clash/",
  75. "subClashURI": "",
  76. "subJsonFragment": "",
  77. "subJsonNoises": "",
  78. "subJsonMux": "",
  79. "subJsonRules": "",
  80. "datepicker": "gregorian",
  81. "warp": "",
  82. "nord": "",
  83. "externalTrafficInformEnable": "false",
  84. "externalTrafficInformURI": "",
  85. "restartXrayOnClientDisable": "true",
  86. "xrayOutboundTestUrl": "https://www.google.com/generate_204",
  87. // LDAP defaults
  88. "ldapEnable": "false",
  89. "ldapHost": "",
  90. "ldapPort": "389",
  91. "ldapUseTLS": "false",
  92. "ldapBindDN": "",
  93. "ldapPassword": "",
  94. "ldapBaseDN": "",
  95. "ldapUserFilter": "(objectClass=person)",
  96. "ldapUserAttr": "mail",
  97. "ldapVlessField": "vless_enabled",
  98. "ldapSyncCron": "@every 1m",
  99. "ldapFlagField": "",
  100. "ldapTruthyValues": "true,1,yes,on",
  101. "ldapInvertFlag": "false",
  102. "ldapInboundTags": "",
  103. "ldapAutoCreate": "false",
  104. "ldapAutoDelete": "false",
  105. "ldapDefaultTotalGB": "0",
  106. "ldapDefaultExpiryDays": "0",
  107. "ldapDefaultLimitIP": "0",
  108. }
  109. // SettingService provides business logic for application settings management.
  110. // It handles configuration storage, retrieval, and validation for all system settings.
  111. type SettingService struct{}
  112. func (s *SettingService) GetDefaultJSONConfig() (any, error) {
  113. var jsonData any
  114. err := json.Unmarshal([]byte(xrayTemplateConfig), &jsonData)
  115. if err != nil {
  116. return nil, err
  117. }
  118. return jsonData, nil
  119. }
  120. func (s *SettingService) GetAllSetting() (*entity.AllSetting, error) {
  121. db := database.GetDB()
  122. settings := make([]*model.Setting, 0)
  123. err := db.Model(model.Setting{}).Not("key = ?", "xrayTemplateConfig").Find(&settings).Error
  124. if err != nil {
  125. return nil, err
  126. }
  127. allSetting := &entity.AllSetting{}
  128. t := reflect.TypeFor[entity.AllSetting]()
  129. v := reflect.ValueOf(allSetting).Elem()
  130. fields := reflect_util.GetFields(t)
  131. setSetting := func(key, value string) (err error) {
  132. defer func() {
  133. panicErr := recover()
  134. if panicErr != nil {
  135. err = errors.New(fmt.Sprint(panicErr))
  136. }
  137. }()
  138. var found bool
  139. var field reflect.StructField
  140. for _, f := range fields {
  141. if f.Tag.Get("json") == key {
  142. field = f
  143. found = true
  144. break
  145. }
  146. }
  147. if !found {
  148. // Some settings are automatically generated, no need to return to the front end to modify the user
  149. return nil
  150. }
  151. fieldV := v.FieldByName(field.Name)
  152. switch t := fieldV.Interface().(type) {
  153. case int:
  154. n, err := strconv.ParseInt(value, 10, 64)
  155. if err != nil {
  156. return err
  157. }
  158. fieldV.SetInt(n)
  159. case string:
  160. fieldV.SetString(value)
  161. case bool:
  162. fieldV.SetBool(value == "true")
  163. default:
  164. return common.NewErrorf("unknown field %v type %v", key, t)
  165. }
  166. return
  167. }
  168. keyMap := map[string]bool{}
  169. for _, setting := range settings {
  170. err := setSetting(setting.Key, setting.Value)
  171. if err != nil {
  172. return nil, err
  173. }
  174. keyMap[setting.Key] = true
  175. }
  176. for key, value := range defaultValueMap {
  177. if keyMap[key] {
  178. continue
  179. }
  180. err := setSetting(key, value)
  181. if err != nil {
  182. return nil, err
  183. }
  184. }
  185. return allSetting, nil
  186. }
  187. func (s *SettingService) GetAllSettingView() (*entity.AllSettingView, error) {
  188. allSetting, err := s.GetAllSetting()
  189. if err != nil {
  190. return nil, err
  191. }
  192. view := &entity.AllSettingView{AllSetting: *allSetting}
  193. view.HasTgBotToken = secretConfigured(allSetting.TgBotToken)
  194. view.HasTwoFactorToken = secretConfigured(allSetting.TwoFactorToken)
  195. view.HasLdapPassword = secretConfigured(allSetting.LdapPassword)
  196. view.HasWarpSecret = secretConfigured(mustString(s.GetWarp()))
  197. view.HasNordSecret = secretConfigured(mustString(s.GetNord()))
  198. view.HasApiToken = secretConfigured(mustString(s.getString("apiToken")))
  199. view.TgBotToken = ""
  200. view.TwoFactorToken = ""
  201. view.LdapPassword = ""
  202. return view, nil
  203. }
  204. func secretConfigured(value string) bool {
  205. return strings.TrimSpace(value) != ""
  206. }
  207. func mustString(value string, _ error) string {
  208. return value
  209. }
  210. func (s *SettingService) ResetSettings() error {
  211. db := database.GetDB()
  212. err := db.Where("1 = 1").Delete(model.Setting{}).Error
  213. if err != nil {
  214. return err
  215. }
  216. return db.Model(model.User{}).
  217. Where("1 = 1").Error
  218. }
  219. func (s *SettingService) getSetting(key string) (*model.Setting, error) {
  220. db := database.GetDB()
  221. setting := &model.Setting{}
  222. err := db.Model(model.Setting{}).Where("key = ?", key).First(setting).Error
  223. if err != nil {
  224. return nil, err
  225. }
  226. return setting, nil
  227. }
  228. func (s *SettingService) saveSetting(key string, value string) error {
  229. setting, err := s.getSetting(key)
  230. db := database.GetDB()
  231. if database.IsNotFound(err) {
  232. return db.Create(&model.Setting{
  233. Key: key,
  234. Value: value,
  235. }).Error
  236. } else if err != nil {
  237. return err
  238. }
  239. setting.Key = key
  240. setting.Value = value
  241. return db.Save(setting).Error
  242. }
  243. func (s *SettingService) getString(key string) (string, error) {
  244. setting, err := s.getSetting(key)
  245. if database.IsNotFound(err) {
  246. value, ok := defaultValueMap[key]
  247. if !ok {
  248. return "", common.NewErrorf("key <%v> not in defaultValueMap", key)
  249. }
  250. return value, nil
  251. } else if err != nil {
  252. return "", err
  253. }
  254. return setting.Value, nil
  255. }
  256. func (s *SettingService) setString(key string, value string) error {
  257. return s.saveSetting(key, value)
  258. }
  259. func (s *SettingService) getBool(key string) (bool, error) {
  260. str, err := s.getString(key)
  261. if err != nil {
  262. return false, err
  263. }
  264. return strconv.ParseBool(str)
  265. }
  266. func (s *SettingService) setBool(key string, value bool) error {
  267. return s.setString(key, strconv.FormatBool(value))
  268. }
  269. func (s *SettingService) getInt(key string) (int, error) {
  270. str, err := s.getString(key)
  271. if err != nil {
  272. return 0, err
  273. }
  274. return strconv.Atoi(str)
  275. }
  276. func (s *SettingService) setInt(key string, value int) error {
  277. return s.setString(key, strconv.Itoa(value))
  278. }
  279. func (s *SettingService) GetXrayConfigTemplate() (string, error) {
  280. return s.getString("xrayTemplateConfig")
  281. }
  282. func (s *SettingService) GetXrayOutboundTestUrl() (string, error) {
  283. return s.getString("xrayOutboundTestUrl")
  284. }
  285. func (s *SettingService) SetXrayOutboundTestUrl(url string) error {
  286. clean, err := SanitizeHTTPURL(url)
  287. if err != nil {
  288. return err
  289. }
  290. return s.setString("xrayOutboundTestUrl", clean)
  291. }
  292. func (s *SettingService) GetListen() (string, error) {
  293. return s.getString("webListen")
  294. }
  295. func (s *SettingService) SetListen(ip string) error {
  296. return s.setString("webListen", ip)
  297. }
  298. func (s *SettingService) GetWebDomain() (string, error) {
  299. return s.getString("webDomain")
  300. }
  301. func (s *SettingService) GetTgBotToken() (string, error) {
  302. return s.getString("tgBotToken")
  303. }
  304. func (s *SettingService) SetTgBotToken(token string) error {
  305. return s.setString("tgBotToken", token)
  306. }
  307. func (s *SettingService) GetTgBotProxy() (string, error) {
  308. return s.getString("tgBotProxy")
  309. }
  310. func (s *SettingService) SetTgBotProxy(token string) error {
  311. return s.setString("tgBotProxy", token)
  312. }
  313. func (s *SettingService) GetTgBotAPIServer() (string, error) {
  314. return s.getString("tgBotAPIServer")
  315. }
  316. func (s *SettingService) SetTgBotAPIServer(token string) error {
  317. return s.setString("tgBotAPIServer", token)
  318. }
  319. func (s *SettingService) GetTgBotChatId() (string, error) {
  320. return s.getString("tgBotChatId")
  321. }
  322. func (s *SettingService) SetTgBotChatId(chatIds string) error {
  323. return s.setString("tgBotChatId", chatIds)
  324. }
  325. func (s *SettingService) GetTgbotEnabled() (bool, error) {
  326. return s.getBool("tgBotEnable")
  327. }
  328. func (s *SettingService) SetTgbotEnabled(value bool) error {
  329. return s.setBool("tgBotEnable", value)
  330. }
  331. func (s *SettingService) GetTgbotRuntime() (string, error) {
  332. return s.getString("tgRunTime")
  333. }
  334. func (s *SettingService) SetTgbotRuntime(time string) error {
  335. return s.setString("tgRunTime", time)
  336. }
  337. func (s *SettingService) GetTgBotBackup() (bool, error) {
  338. return s.getBool("tgBotBackup")
  339. }
  340. func (s *SettingService) GetTgBotLoginNotify() (bool, error) {
  341. return s.getBool("tgBotLoginNotify")
  342. }
  343. func (s *SettingService) GetTgCpu() (int, error) {
  344. return s.getInt("tgCpu")
  345. }
  346. func (s *SettingService) GetTgLang() (string, error) {
  347. return s.getString("tgLang")
  348. }
  349. func (s *SettingService) GetTwoFactorEnable() (bool, error) {
  350. return s.getBool("twoFactorEnable")
  351. }
  352. func (s *SettingService) SetTwoFactorEnable(value bool) error {
  353. return s.setBool("twoFactorEnable", value)
  354. }
  355. func (s *SettingService) GetTwoFactorToken() (string, error) {
  356. return s.getString("twoFactorToken")
  357. }
  358. func (s *SettingService) SetTwoFactorToken(value string) error {
  359. return s.setString("twoFactorToken", value)
  360. }
  361. func (s *SettingService) GetPort() (int, error) {
  362. return s.getInt("webPort")
  363. }
  364. func (s *SettingService) SetPort(port int) error {
  365. return s.setInt("webPort", port)
  366. }
  367. func (s *SettingService) SetCertFile(webCertFile string) error {
  368. return s.setString("webCertFile", webCertFile)
  369. }
  370. func (s *SettingService) GetCertFile() (string, error) {
  371. return s.getString("webCertFile")
  372. }
  373. func (s *SettingService) SetKeyFile(webKeyFile string) error {
  374. return s.setString("webKeyFile", webKeyFile)
  375. }
  376. func (s *SettingService) GetKeyFile() (string, error) {
  377. return s.getString("webKeyFile")
  378. }
  379. func (s *SettingService) GetExpireDiff() (int, error) {
  380. return s.getInt("expireDiff")
  381. }
  382. func (s *SettingService) GetTrafficDiff() (int, error) {
  383. return s.getInt("trafficDiff")
  384. }
  385. func (s *SettingService) GetSessionMaxAge() (int, error) {
  386. return s.getInt("sessionMaxAge")
  387. }
  388. func (s *SettingService) GetTrustedProxyCIDRs() (string, error) {
  389. return s.getString("trustedProxyCIDRs")
  390. }
  391. func (s *SettingService) GetRemarkModel() (string, error) {
  392. return s.getString("remarkModel")
  393. }
  394. func (s *SettingService) GetSecret() ([]byte, error) {
  395. secret, err := s.getString("secret")
  396. if secret == defaultValueMap["secret"] {
  397. err := s.saveSetting("secret", secret)
  398. if err != nil {
  399. logger.Warning("save secret failed:", err)
  400. }
  401. }
  402. return []byte(secret), err
  403. }
  404. // GetApiToken returns the panel's API token, lazily generating one on
  405. // first read so existing installs upgrade transparently. The token is
  406. // stored plaintext to match how the existing tg/ldap secrets are kept.
  407. func (s *SettingService) GetApiToken() (string, error) {
  408. tok, err := s.getString("apiToken")
  409. if err != nil {
  410. return "", err
  411. }
  412. if tok == "" {
  413. tok = random.Seq(48)
  414. if saveErr := s.saveSetting("apiToken", tok); saveErr != nil {
  415. logger.Warning("save apiToken failed:", saveErr)
  416. return "", saveErr
  417. }
  418. }
  419. return tok, nil
  420. }
  421. // RegenerateApiToken rotates the API token, invalidating any central
  422. // panel that has the old value cached.
  423. func (s *SettingService) RegenerateApiToken() (string, error) {
  424. tok := random.Seq(48)
  425. if err := s.saveSetting("apiToken", tok); err != nil {
  426. return "", err
  427. }
  428. return tok, nil
  429. }
  430. // MatchApiToken returns true when the supplied bearer token matches the
  431. // stored API token. Uses constant-time compare so a remote attacker
  432. // can't time-attack the token byte-by-byte.
  433. func (s *SettingService) MatchApiToken(presented string) bool {
  434. if presented == "" {
  435. return false
  436. }
  437. stored, err := s.getString("apiToken")
  438. if err != nil || stored == "" {
  439. return false
  440. }
  441. return subtle.ConstantTimeCompare([]byte(stored), []byte(presented)) == 1
  442. }
  443. func (s *SettingService) SetBasePath(basePath string) error {
  444. if !strings.HasPrefix(basePath, "/") {
  445. basePath = "/" + basePath
  446. }
  447. if !strings.HasSuffix(basePath, "/") {
  448. basePath += "/"
  449. }
  450. return s.setString("webBasePath", basePath)
  451. }
  452. func (s *SettingService) GetBasePath() (string, error) {
  453. basePath, err := s.getString("webBasePath")
  454. if err != nil {
  455. return "", err
  456. }
  457. if !strings.HasPrefix(basePath, "/") {
  458. basePath = "/" + basePath
  459. }
  460. if !strings.HasSuffix(basePath, "/") {
  461. basePath += "/"
  462. }
  463. return basePath, nil
  464. }
  465. func (s *SettingService) GetTimeLocation() (*time.Location, error) {
  466. l, err := s.getString("timeLocation")
  467. if err != nil {
  468. return nil, err
  469. }
  470. location, err := time.LoadLocation(l)
  471. if err != nil {
  472. defaultLocation := defaultValueMap["timeLocation"]
  473. logger.Errorf("location <%v> not exist, using default location: %v", l, defaultLocation)
  474. location, err = time.LoadLocation(defaultLocation)
  475. if err != nil {
  476. logger.Errorf("failed to load default location, using UTC: %v", err)
  477. return time.UTC, nil
  478. }
  479. return location, nil
  480. }
  481. return location, nil
  482. }
  483. func (s *SettingService) GetSubEnable() (bool, error) {
  484. return s.getBool("subEnable")
  485. }
  486. func (s *SettingService) GetSubJsonEnable() (bool, error) {
  487. return s.getBool("subJsonEnable")
  488. }
  489. func (s *SettingService) GetSubTitle() (string, error) {
  490. return s.getString("subTitle")
  491. }
  492. func (s *SettingService) GetSubSupportUrl() (string, error) {
  493. return s.getString("subSupportUrl")
  494. }
  495. func (s *SettingService) GetSubProfileUrl() (string, error) {
  496. return s.getString("subProfileUrl")
  497. }
  498. func (s *SettingService) GetSubAnnounce() (string, error) {
  499. return s.getString("subAnnounce")
  500. }
  501. func (s *SettingService) GetSubEnableRouting() (bool, error) {
  502. return s.getBool("subEnableRouting")
  503. }
  504. func (s *SettingService) GetSubRoutingRules() (string, error) {
  505. return s.getString("subRoutingRules")
  506. }
  507. func (s *SettingService) GetSubListen() (string, error) {
  508. return s.getString("subListen")
  509. }
  510. func (s *SettingService) GetSubPort() (int, error) {
  511. return s.getInt("subPort")
  512. }
  513. func (s *SettingService) GetSubPath() (string, error) {
  514. return s.getString("subPath")
  515. }
  516. func (s *SettingService) GetSubJsonPath() (string, error) {
  517. return s.getString("subJsonPath")
  518. }
  519. func (s *SettingService) GetSubDomain() (string, error) {
  520. return s.getString("subDomain")
  521. }
  522. func (s *SettingService) SetSubCertFile(subCertFile string) error {
  523. return s.setString("subCertFile", subCertFile)
  524. }
  525. func (s *SettingService) GetSubCertFile() (string, error) {
  526. return s.getString("subCertFile")
  527. }
  528. func (s *SettingService) SetSubKeyFile(subKeyFile string) error {
  529. return s.setString("subKeyFile", subKeyFile)
  530. }
  531. func (s *SettingService) GetSubKeyFile() (string, error) {
  532. return s.getString("subKeyFile")
  533. }
  534. func (s *SettingService) GetSubUpdates() (string, error) {
  535. return s.getString("subUpdates")
  536. }
  537. func (s *SettingService) GetSubEncrypt() (bool, error) {
  538. return s.getBool("subEncrypt")
  539. }
  540. func (s *SettingService) GetSubShowInfo() (bool, error) {
  541. return s.getBool("subShowInfo")
  542. }
  543. func (s *SettingService) GetPageSize() (int, error) {
  544. return s.getInt("pageSize")
  545. }
  546. func (s *SettingService) GetSubURI() (string, error) {
  547. return s.getString("subURI")
  548. }
  549. func (s *SettingService) GetSubJsonURI() (string, error) {
  550. return s.getString("subJsonURI")
  551. }
  552. func (s *SettingService) GetSubClashEnable() (bool, error) {
  553. return s.getBool("subClashEnable")
  554. }
  555. func (s *SettingService) GetSubClashPath() (string, error) {
  556. return s.getString("subClashPath")
  557. }
  558. func (s *SettingService) GetSubClashURI() (string, error) {
  559. return s.getString("subClashURI")
  560. }
  561. func (s *SettingService) GetSubJsonFragment() (string, error) {
  562. return s.getString("subJsonFragment")
  563. }
  564. func (s *SettingService) GetSubJsonNoises() (string, error) {
  565. return s.getString("subJsonNoises")
  566. }
  567. func (s *SettingService) GetSubJsonMux() (string, error) {
  568. return s.getString("subJsonMux")
  569. }
  570. func (s *SettingService) GetSubJsonRules() (string, error) {
  571. return s.getString("subJsonRules")
  572. }
  573. func (s *SettingService) GetDatepicker() (string, error) {
  574. return s.getString("datepicker")
  575. }
  576. func (s *SettingService) GetWarp() (string, error) {
  577. return s.getString("warp")
  578. }
  579. func (s *SettingService) SetWarp(data string) error {
  580. return s.setString("warp", data)
  581. }
  582. func (s *SettingService) GetNord() (string, error) {
  583. return s.getString("nord")
  584. }
  585. func (s *SettingService) SetNord(data string) error {
  586. return s.setString("nord", data)
  587. }
  588. func (s *SettingService) GetExternalTrafficInformEnable() (bool, error) {
  589. return s.getBool("externalTrafficInformEnable")
  590. }
  591. func (s *SettingService) SetExternalTrafficInformEnable(value bool) error {
  592. return s.setBool("externalTrafficInformEnable", value)
  593. }
  594. func (s *SettingService) GetExternalTrafficInformURI() (string, error) {
  595. return s.getString("externalTrafficInformURI")
  596. }
  597. func (s *SettingService) SetExternalTrafficInformURI(InformURI string) error {
  598. return s.setString("externalTrafficInformURI", InformURI)
  599. }
  600. func (s *SettingService) GetRestartXrayOnClientDisable() (bool, error) {
  601. return s.getBool("restartXrayOnClientDisable")
  602. }
  603. func (s *SettingService) SetRestartXrayOnClientDisable(value bool) error {
  604. return s.setBool("restartXrayOnClientDisable", value)
  605. }
  606. func (s *SettingService) GetIpLimitEnable() (bool, error) {
  607. accessLogPath, err := xray.GetAccessLogPath()
  608. if err != nil {
  609. return false, err
  610. }
  611. return (accessLogPath != "none" && accessLogPath != ""), nil
  612. }
  613. // GetLdapEnable returns whether LDAP is enabled.
  614. func (s *SettingService) GetLdapEnable() (bool, error) {
  615. return s.getBool("ldapEnable")
  616. }
  617. func (s *SettingService) GetLdapHost() (string, error) {
  618. return s.getString("ldapHost")
  619. }
  620. func (s *SettingService) GetLdapPort() (int, error) {
  621. return s.getInt("ldapPort")
  622. }
  623. func (s *SettingService) GetLdapUseTLS() (bool, error) {
  624. return s.getBool("ldapUseTLS")
  625. }
  626. func (s *SettingService) GetLdapBindDN() (string, error) {
  627. return s.getString("ldapBindDN")
  628. }
  629. func (s *SettingService) GetLdapPassword() (string, error) {
  630. return s.getString("ldapPassword")
  631. }
  632. func (s *SettingService) GetLdapBaseDN() (string, error) {
  633. return s.getString("ldapBaseDN")
  634. }
  635. func (s *SettingService) GetLdapUserFilter() (string, error) {
  636. return s.getString("ldapUserFilter")
  637. }
  638. func (s *SettingService) GetLdapUserAttr() (string, error) {
  639. return s.getString("ldapUserAttr")
  640. }
  641. func (s *SettingService) GetLdapVlessField() (string, error) {
  642. return s.getString("ldapVlessField")
  643. }
  644. func (s *SettingService) GetLdapSyncCron() (string, error) {
  645. return s.getString("ldapSyncCron")
  646. }
  647. func (s *SettingService) GetLdapFlagField() (string, error) {
  648. return s.getString("ldapFlagField")
  649. }
  650. func (s *SettingService) GetLdapTruthyValues() (string, error) {
  651. return s.getString("ldapTruthyValues")
  652. }
  653. func (s *SettingService) GetLdapInvertFlag() (bool, error) {
  654. return s.getBool("ldapInvertFlag")
  655. }
  656. func (s *SettingService) GetLdapInboundTags() (string, error) {
  657. return s.getString("ldapInboundTags")
  658. }
  659. func (s *SettingService) GetLdapAutoCreate() (bool, error) {
  660. return s.getBool("ldapAutoCreate")
  661. }
  662. func (s *SettingService) GetLdapAutoDelete() (bool, error) {
  663. return s.getBool("ldapAutoDelete")
  664. }
  665. func (s *SettingService) GetLdapDefaultTotalGB() (int, error) {
  666. return s.getInt("ldapDefaultTotalGB")
  667. }
  668. func (s *SettingService) GetLdapDefaultExpiryDays() (int, error) {
  669. return s.getInt("ldapDefaultExpiryDays")
  670. }
  671. func (s *SettingService) GetLdapDefaultLimitIP() (int, error) {
  672. return s.getInt("ldapDefaultLimitIP")
  673. }
  674. func (s *SettingService) UpdateAllSetting(allSetting *entity.AllSetting) error {
  675. if err := s.preserveRedactedSecrets(allSetting); err != nil {
  676. return err
  677. }
  678. if err := validateSettingsURLs(allSetting); err != nil {
  679. return err
  680. }
  681. if err := allSetting.CheckValid(); err != nil {
  682. return err
  683. }
  684. v := reflect.ValueOf(allSetting).Elem()
  685. t := reflect.TypeFor[entity.AllSetting]()
  686. fields := reflect_util.GetFields(t)
  687. errs := make([]error, 0)
  688. for _, field := range fields {
  689. key := field.Tag.Get("json")
  690. fieldV := v.FieldByName(field.Name)
  691. value := fmt.Sprint(fieldV.Interface())
  692. err := s.saveSetting(key, value)
  693. if err != nil {
  694. errs = append(errs, err)
  695. }
  696. }
  697. return common.Combine(errs...)
  698. }
  699. func (s *SettingService) preserveRedactedSecrets(allSetting *entity.AllSetting) error {
  700. if strings.TrimSpace(allSetting.TgBotToken) == "" {
  701. value, err := s.GetTgBotToken()
  702. if err != nil {
  703. return err
  704. }
  705. allSetting.TgBotToken = value
  706. }
  707. if strings.TrimSpace(allSetting.LdapPassword) == "" {
  708. value, err := s.GetLdapPassword()
  709. if err != nil {
  710. return err
  711. }
  712. allSetting.LdapPassword = value
  713. }
  714. if allSetting.TwoFactorEnable && strings.TrimSpace(allSetting.TwoFactorToken) == "" {
  715. value, err := s.GetTwoFactorToken()
  716. if err != nil {
  717. return err
  718. }
  719. allSetting.TwoFactorToken = value
  720. }
  721. return nil
  722. }
  723. func validateSettingsURLs(allSetting *entity.AllSetting) error {
  724. if allSetting.ExternalTrafficInformURI != "" {
  725. u, err := SanitizeHTTPURL(allSetting.ExternalTrafficInformURI)
  726. if err != nil {
  727. return common.NewError("external traffic inform URI is invalid:", err)
  728. }
  729. allSetting.ExternalTrafficInformURI = u
  730. }
  731. if allSetting.TgBotAPIServer != "" {
  732. u, err := SanitizeHTTPURL(allSetting.TgBotAPIServer)
  733. if err != nil {
  734. return common.NewError("telegram API server URL is invalid:", err)
  735. }
  736. allSetting.TgBotAPIServer = u
  737. }
  738. return nil
  739. }
  740. func (s *SettingService) UpdateSecret(key string, value string) error {
  741. switch key {
  742. case "tgBotToken", "ldapPassword", "twoFactorToken", "apiToken":
  743. return s.saveSetting(key, strings.TrimSpace(value))
  744. default:
  745. return common.NewError("secret key is not replaceable:", key)
  746. }
  747. }
  748. func (s *SettingService) GetDefaultXrayConfig() (any, error) {
  749. var jsonData any
  750. err := json.Unmarshal([]byte(xrayTemplateConfig), &jsonData)
  751. if err != nil {
  752. return nil, err
  753. }
  754. return jsonData, nil
  755. }
  756. func extractHostname(host string) string {
  757. h, _, err := net.SplitHostPort(host)
  758. // Err is not nil means host does not contain port
  759. if err != nil {
  760. h = host
  761. }
  762. ip := net.ParseIP(h)
  763. // If it's not an IP, return as is
  764. if ip == nil {
  765. return h
  766. }
  767. // If it's an IPv4, return as is
  768. if ip.To4() != nil {
  769. return h
  770. }
  771. // IPv6 needs bracketing
  772. return "[" + h + "]"
  773. }
  774. func (s *SettingService) GetDefaultSettings(host string) (any, error) {
  775. type settingFunc func() (any, error)
  776. settings := map[string]settingFunc{
  777. "expireDiff": func() (any, error) { return s.GetExpireDiff() },
  778. "trafficDiff": func() (any, error) { return s.GetTrafficDiff() },
  779. "pageSize": func() (any, error) { return s.GetPageSize() },
  780. "defaultCert": func() (any, error) { return s.GetCertFile() },
  781. "defaultKey": func() (any, error) { return s.GetKeyFile() },
  782. "tgBotEnable": func() (any, error) { return s.GetTgbotEnabled() },
  783. "subEnable": func() (any, error) { return s.GetSubEnable() },
  784. "subJsonEnable": func() (any, error) { return s.GetSubJsonEnable() },
  785. "subClashEnable": func() (any, error) { return s.GetSubClashEnable() },
  786. "subTitle": func() (any, error) { return s.GetSubTitle() },
  787. "subURI": func() (any, error) { return s.GetSubURI() },
  788. "subJsonURI": func() (any, error) { return s.GetSubJsonURI() },
  789. "subClashURI": func() (any, error) { return s.GetSubClashURI() },
  790. "remarkModel": func() (any, error) { return s.GetRemarkModel() },
  791. "datepicker": func() (any, error) { return s.GetDatepicker() },
  792. "ipLimitEnable": func() (any, error) { return s.GetIpLimitEnable() },
  793. }
  794. result := make(map[string]any)
  795. for key, fn := range settings {
  796. value, err := fn()
  797. if err != nil {
  798. return "", err
  799. }
  800. result[key] = value
  801. }
  802. subEnable := result["subEnable"].(bool)
  803. subJsonEnable := false
  804. if v, ok := result["subJsonEnable"]; ok {
  805. if b, ok2 := v.(bool); ok2 {
  806. subJsonEnable = b
  807. }
  808. }
  809. subClashEnable := false
  810. if v, ok := result["subClashEnable"]; ok {
  811. if b, ok2 := v.(bool); ok2 {
  812. subClashEnable = b
  813. }
  814. }
  815. if (subEnable && result["subURI"].(string) == "") || (subJsonEnable && result["subJsonURI"].(string) == "") || (subClashEnable && result["subClashURI"].(string) == "") {
  816. subURI := ""
  817. subTitle, _ := s.GetSubTitle()
  818. subPort, _ := s.GetSubPort()
  819. subPath, _ := s.GetSubPath()
  820. subJsonPath, _ := s.GetSubJsonPath()
  821. subClashPath, _ := s.GetSubClashPath()
  822. subDomain, _ := s.GetSubDomain()
  823. subKeyFile, _ := s.GetSubKeyFile()
  824. subCertFile, _ := s.GetSubCertFile()
  825. subTLS := false
  826. if subKeyFile != "" && subCertFile != "" {
  827. subTLS = true
  828. }
  829. if subDomain == "" {
  830. subDomain = extractHostname(host)
  831. }
  832. if subTLS {
  833. subURI = "https://"
  834. } else {
  835. subURI = "http://"
  836. }
  837. if (subPort == 443 && subTLS) || (subPort == 80 && !subTLS) {
  838. subURI += subDomain
  839. } else {
  840. subURI += fmt.Sprintf("%s:%d", subDomain, subPort)
  841. }
  842. if subEnable && result["subURI"].(string) == "" {
  843. result["subURI"] = subURI + subPath
  844. }
  845. if result["subTitle"].(string) == "" {
  846. result["subTitle"] = subTitle
  847. }
  848. if subJsonEnable && result["subJsonURI"].(string) == "" {
  849. result["subJsonURI"] = subURI + subJsonPath
  850. }
  851. if subClashEnable && result["subClashURI"].(string) == "" {
  852. result["subClashURI"] = subURI + subClashPath
  853. }
  854. }
  855. return result, nil
  856. }