client.go 49 KB

1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963
  1. package service
  2. import (
  3. "context"
  4. "encoding/base64"
  5. "encoding/json"
  6. "errors"
  7. "fmt"
  8. "math"
  9. "strings"
  10. "sync"
  11. "time"
  12. "github.com/google/uuid"
  13. "github.com/mhsanaei/3x-ui/v3/database"
  14. "github.com/mhsanaei/3x-ui/v3/database/model"
  15. "github.com/mhsanaei/3x-ui/v3/logger"
  16. "github.com/mhsanaei/3x-ui/v3/util/common"
  17. "github.com/mhsanaei/3x-ui/v3/util/random"
  18. "github.com/mhsanaei/3x-ui/v3/xray"
  19. "gorm.io/gorm"
  20. )
  21. type ClientWithAttachments struct {
  22. model.ClientRecord
  23. InboundIds []int `json:"inboundIds"`
  24. Traffic *xray.ClientTraffic `json:"traffic,omitempty"`
  25. }
  26. // MarshalJSON is required because model.ClientRecord defines its own
  27. // MarshalJSON. Go promotes the embedded method to the outer struct, so without
  28. // this the encoder would call ClientRecord.MarshalJSON for the whole value and
  29. // silently drop InboundIds and Traffic from the API response.
  30. func (c ClientWithAttachments) MarshalJSON() ([]byte, error) {
  31. rec, err := json.Marshal(c.ClientRecord)
  32. if err != nil {
  33. return nil, err
  34. }
  35. extras := struct {
  36. InboundIds []int `json:"inboundIds"`
  37. Traffic *xray.ClientTraffic `json:"traffic,omitempty"`
  38. }{InboundIds: c.InboundIds, Traffic: c.Traffic}
  39. extra, err := json.Marshal(extras)
  40. if err != nil {
  41. return nil, err
  42. }
  43. if len(rec) < 2 || rec[len(rec)-1] != '}' || len(extra) <= 2 {
  44. return rec, nil
  45. }
  46. if len(extra) > math.MaxInt-len(rec) {
  47. return rec, nil
  48. }
  49. out := make([]byte, 0, len(rec)+len(extra))
  50. out = append(out, rec[:len(rec)-1]...)
  51. if len(rec) > 2 {
  52. out = append(out, ',')
  53. }
  54. out = append(out, extra[1:]...)
  55. return out, nil
  56. }
  57. func clientKeyForProtocol(p model.Protocol, rec *model.ClientRecord) string {
  58. if rec == nil {
  59. return ""
  60. }
  61. switch p {
  62. case model.Trojan:
  63. return rec.Password
  64. case model.Shadowsocks:
  65. return rec.Email
  66. case model.Hysteria, model.Hysteria2:
  67. return rec.Auth
  68. default:
  69. return rec.UUID
  70. }
  71. }
  72. type ClientService struct{}
  73. // Short-lived tombstone of just-deleted client emails so that a node snapshot
  74. // arriving between delete and node-side processing doesn't resurrect them.
  75. var (
  76. recentlyDeletedMu sync.Mutex
  77. recentlyDeleted = map[string]time.Time{}
  78. )
  79. const deleteTombstoneTTL = 90 * time.Second
  80. var (
  81. inboundMutationLocksMu sync.Mutex
  82. inboundMutationLocks = map[int]*sync.Mutex{}
  83. )
  84. func lockInbound(inboundId int) *sync.Mutex {
  85. inboundMutationLocksMu.Lock()
  86. defer inboundMutationLocksMu.Unlock()
  87. m, ok := inboundMutationLocks[inboundId]
  88. if !ok {
  89. m = &sync.Mutex{}
  90. inboundMutationLocks[inboundId] = m
  91. }
  92. m.Lock()
  93. return m
  94. }
  95. func compactOrphans(db *gorm.DB, clients []any) []any {
  96. if len(clients) == 0 {
  97. return clients
  98. }
  99. emails := make([]string, 0, len(clients))
  100. for _, c := range clients {
  101. cm, ok := c.(map[string]any)
  102. if !ok {
  103. continue
  104. }
  105. if e, _ := cm["email"].(string); e != "" {
  106. emails = append(emails, e)
  107. }
  108. }
  109. if len(emails) == 0 {
  110. return clients
  111. }
  112. var existingEmails []string
  113. if err := db.Model(&model.ClientRecord{}).Where("email IN ?", emails).Pluck("email", &existingEmails).Error; err != nil {
  114. logger.Warning("compactOrphans pluck:", err)
  115. return clients
  116. }
  117. if len(existingEmails) == len(emails) {
  118. return clients
  119. }
  120. existing := make(map[string]struct{}, len(existingEmails))
  121. for _, e := range existingEmails {
  122. existing[e] = struct{}{}
  123. }
  124. out := make([]any, 0, len(existingEmails))
  125. for _, c := range clients {
  126. cm, ok := c.(map[string]any)
  127. if !ok {
  128. out = append(out, c)
  129. continue
  130. }
  131. e, _ := cm["email"].(string)
  132. if e == "" {
  133. out = append(out, c)
  134. continue
  135. }
  136. if _, ok := existing[e]; ok {
  137. out = append(out, c)
  138. }
  139. }
  140. return out
  141. }
  142. func tombstoneClientEmail(email string) {
  143. if email == "" {
  144. return
  145. }
  146. recentlyDeletedMu.Lock()
  147. defer recentlyDeletedMu.Unlock()
  148. recentlyDeleted[email] = time.Now()
  149. cutoff := time.Now().Add(-deleteTombstoneTTL)
  150. for e, ts := range recentlyDeleted {
  151. if ts.Before(cutoff) {
  152. delete(recentlyDeleted, e)
  153. }
  154. }
  155. }
  156. func isClientEmailTombstoned(email string) bool {
  157. if email == "" {
  158. return false
  159. }
  160. recentlyDeletedMu.Lock()
  161. defer recentlyDeletedMu.Unlock()
  162. ts, ok := recentlyDeleted[email]
  163. if !ok {
  164. return false
  165. }
  166. if time.Since(ts) > deleteTombstoneTTL {
  167. delete(recentlyDeleted, email)
  168. return false
  169. }
  170. return true
  171. }
  172. func (s *ClientService) SyncInbound(tx *gorm.DB, inboundId int, clients []model.Client) error {
  173. if tx == nil {
  174. tx = database.GetDB()
  175. }
  176. if err := tx.Where("inbound_id = ?", inboundId).Delete(&model.ClientInbound{}).Error; err != nil {
  177. return err
  178. }
  179. for i := range clients {
  180. c := clients[i]
  181. email := strings.TrimSpace(c.Email)
  182. if email == "" {
  183. continue
  184. }
  185. incoming := c.ToRecord()
  186. row := &model.ClientRecord{}
  187. err := tx.Where("email = ?", email).First(row).Error
  188. if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
  189. return err
  190. }
  191. if errors.Is(err, gorm.ErrRecordNotFound) {
  192. if isClientEmailTombstoned(email) {
  193. continue
  194. }
  195. if err := tx.Create(incoming).Error; err != nil {
  196. return err
  197. }
  198. row = incoming
  199. } else {
  200. row.UUID = incoming.UUID
  201. row.Password = incoming.Password
  202. row.Auth = incoming.Auth
  203. row.Flow = incoming.Flow
  204. row.Security = incoming.Security
  205. row.Reverse = incoming.Reverse
  206. row.SubID = incoming.SubID
  207. row.LimitIP = incoming.LimitIP
  208. row.TotalGB = incoming.TotalGB
  209. row.ExpiryTime = incoming.ExpiryTime
  210. row.Enable = incoming.Enable
  211. row.TgID = incoming.TgID
  212. row.Comment = incoming.Comment
  213. row.Reset = incoming.Reset
  214. if incoming.CreatedAt > 0 && (row.CreatedAt == 0 || incoming.CreatedAt < row.CreatedAt) {
  215. row.CreatedAt = incoming.CreatedAt
  216. }
  217. if incoming.UpdatedAt > row.UpdatedAt {
  218. row.UpdatedAt = incoming.UpdatedAt
  219. }
  220. if err := tx.Save(row).Error; err != nil {
  221. return err
  222. }
  223. }
  224. link := model.ClientInbound{
  225. ClientId: row.Id,
  226. InboundId: inboundId,
  227. FlowOverride: c.Flow,
  228. }
  229. if err := tx.Create(&link).Error; err != nil {
  230. return err
  231. }
  232. }
  233. return nil
  234. }
  235. func (s *ClientService) DetachInbound(tx *gorm.DB, inboundId int) error {
  236. if tx == nil {
  237. tx = database.GetDB()
  238. }
  239. return tx.Where("inbound_id = ?", inboundId).Delete(&model.ClientInbound{}).Error
  240. }
  241. func (s *ClientService) ListForInbound(tx *gorm.DB, inboundId int) ([]model.Client, error) {
  242. if tx == nil {
  243. tx = database.GetDB()
  244. }
  245. type joinedRow struct {
  246. model.ClientRecord
  247. FlowOverride string
  248. }
  249. var rows []joinedRow
  250. err := tx.Table("clients").
  251. Select("clients.*, client_inbounds.flow_override AS flow_override").
  252. Joins("JOIN client_inbounds ON client_inbounds.client_id = clients.id").
  253. Where("client_inbounds.inbound_id = ?", inboundId).
  254. Order("clients.id ASC").
  255. Find(&rows).Error
  256. if err != nil {
  257. return nil, err
  258. }
  259. out := make([]model.Client, 0, len(rows))
  260. for i := range rows {
  261. c := rows[i].ToClient()
  262. if rows[i].FlowOverride != "" {
  263. c.Flow = rows[i].FlowOverride
  264. }
  265. out = append(out, *c)
  266. }
  267. return out, nil
  268. }
  269. func (s *ClientService) GetRecordByEmail(tx *gorm.DB, email string) (*model.ClientRecord, error) {
  270. if tx == nil {
  271. tx = database.GetDB()
  272. }
  273. row := &model.ClientRecord{}
  274. err := tx.Where("email = ?", email).First(row).Error
  275. if err != nil {
  276. return nil, err
  277. }
  278. return row, nil
  279. }
  280. func (s *ClientService) GetInboundIdsForEmail(tx *gorm.DB, email string) ([]int, error) {
  281. if tx == nil {
  282. tx = database.GetDB()
  283. }
  284. var ids []int
  285. err := tx.Table("client_inbounds").
  286. Select("client_inbounds.inbound_id").
  287. Joins("JOIN clients ON clients.id = client_inbounds.client_id").
  288. Where("clients.email = ?", email).
  289. Scan(&ids).Error
  290. if err != nil {
  291. return nil, err
  292. }
  293. return ids, nil
  294. }
  295. func (s *ClientService) GetByID(id int) (*model.ClientRecord, error) {
  296. row := &model.ClientRecord{}
  297. if err := database.GetDB().Where("id = ?", id).First(row).Error; err != nil {
  298. return nil, err
  299. }
  300. return row, nil
  301. }
  302. func (s *ClientService) GetInboundIdsForRecord(id int) ([]int, error) {
  303. var ids []int
  304. err := database.GetDB().Table("client_inbounds").
  305. Where("client_id = ?", id).
  306. Order("inbound_id ASC").
  307. Pluck("inbound_id", &ids).Error
  308. if err != nil {
  309. return nil, err
  310. }
  311. return ids, nil
  312. }
  313. func (s *ClientService) List() ([]ClientWithAttachments, error) {
  314. db := database.GetDB()
  315. var rows []model.ClientRecord
  316. if err := db.Order("id ASC").Find(&rows).Error; err != nil {
  317. return nil, err
  318. }
  319. if len(rows) == 0 {
  320. return []ClientWithAttachments{}, nil
  321. }
  322. clientIds := make([]int, 0, len(rows))
  323. emails := make([]string, 0, len(rows))
  324. for i := range rows {
  325. clientIds = append(clientIds, rows[i].Id)
  326. if rows[i].Email != "" {
  327. emails = append(emails, rows[i].Email)
  328. }
  329. }
  330. var links []model.ClientInbound
  331. if err := db.Where("client_id IN ?", clientIds).Find(&links).Error; err != nil {
  332. return nil, err
  333. }
  334. attachments := make(map[int][]int, len(rows))
  335. for _, l := range links {
  336. attachments[l.ClientId] = append(attachments[l.ClientId], l.InboundId)
  337. }
  338. trafficByEmail := make(map[string]*xray.ClientTraffic, len(emails))
  339. if len(emails) > 0 {
  340. var stats []xray.ClientTraffic
  341. if err := db.Where("email IN ?", emails).Find(&stats).Error; err != nil {
  342. return nil, err
  343. }
  344. for i := range stats {
  345. trafficByEmail[stats[i].Email] = &stats[i]
  346. }
  347. }
  348. out := make([]ClientWithAttachments, 0, len(rows))
  349. for i := range rows {
  350. out = append(out, ClientWithAttachments{
  351. ClientRecord: rows[i],
  352. InboundIds: attachments[rows[i].Id],
  353. Traffic: trafficByEmail[rows[i].Email],
  354. })
  355. }
  356. return out, nil
  357. }
  358. type ClientCreatePayload struct {
  359. Client model.Client `json:"client"`
  360. InboundIds []int `json:"inboundIds"`
  361. }
  362. func (s *ClientService) Create(inboundSvc *InboundService, payload *ClientCreatePayload) (bool, error) {
  363. if payload == nil {
  364. return false, common.NewError("empty payload")
  365. }
  366. client := payload.Client
  367. if strings.TrimSpace(client.Email) == "" {
  368. return false, common.NewError("client email is required")
  369. }
  370. if len(payload.InboundIds) == 0 {
  371. return false, common.NewError("at least one inbound is required")
  372. }
  373. if client.SubID == "" {
  374. client.SubID = uuid.NewString()
  375. }
  376. if !client.Enable {
  377. client.Enable = true
  378. }
  379. now := time.Now().UnixMilli()
  380. if client.CreatedAt == 0 {
  381. client.CreatedAt = now
  382. }
  383. client.UpdatedAt = now
  384. existing := &model.ClientRecord{}
  385. err := database.GetDB().Where("email = ?", client.Email).First(existing).Error
  386. if err != nil && !errors.Is(err, gorm.ErrRecordNotFound) {
  387. return false, err
  388. }
  389. emailTaken := !errors.Is(err, gorm.ErrRecordNotFound)
  390. if emailTaken {
  391. if existing.SubID == "" || existing.SubID != client.SubID {
  392. return false, common.NewError("email already in use:", client.Email)
  393. }
  394. }
  395. needRestart := false
  396. for _, ibId := range payload.InboundIds {
  397. inbound, getErr := inboundSvc.GetInbound(ibId)
  398. if getErr != nil {
  399. return needRestart, getErr
  400. }
  401. if err := s.fillProtocolDefaults(&client, inbound); err != nil {
  402. return needRestart, err
  403. }
  404. settingsPayload, mErr := json.Marshal(map[string][]model.Client{"clients": {client}})
  405. if mErr != nil {
  406. return needRestart, mErr
  407. }
  408. nr, addErr := s.AddInboundClient(inboundSvc, &model.Inbound{
  409. Id: ibId,
  410. Settings: string(settingsPayload),
  411. })
  412. if addErr != nil {
  413. return needRestart, addErr
  414. }
  415. if nr {
  416. needRestart = true
  417. }
  418. }
  419. return needRestart, nil
  420. }
  421. func (s *ClientService) fillProtocolDefaults(c *model.Client, ib *model.Inbound) error {
  422. switch ib.Protocol {
  423. case model.VMESS, model.VLESS:
  424. if c.ID == "" {
  425. c.ID = uuid.NewString()
  426. }
  427. case model.Trojan:
  428. if c.Password == "" {
  429. c.Password = strings.ReplaceAll(uuid.NewString(), "-", "")
  430. }
  431. case model.Shadowsocks:
  432. method := shadowsocksMethodFromSettings(ib.Settings)
  433. if c.Password == "" || !validShadowsocksClientKey(method, c.Password) {
  434. c.Password = randomShadowsocksClientKey(method)
  435. }
  436. case model.Hysteria, model.Hysteria2:
  437. if c.Auth == "" {
  438. c.Auth = strings.ReplaceAll(uuid.NewString(), "-", "")
  439. }
  440. }
  441. return nil
  442. }
  443. // shadowsocksMethodFromSettings pulls the "method" field out of the inbound's
  444. // settings JSON. Returns "" when the field is missing or settings is invalid.
  445. func shadowsocksMethodFromSettings(settings string) string {
  446. if settings == "" {
  447. return ""
  448. }
  449. var m map[string]any
  450. if err := json.Unmarshal([]byte(settings), &m); err != nil {
  451. return ""
  452. }
  453. method, _ := m["method"].(string)
  454. return method
  455. }
  456. // randomShadowsocksClientKey returns a per-client key sized to the cipher.
  457. // The 2022-blake3 ciphers require a base64-encoded key of an exact byte
  458. // length (16 bytes for aes-128-gcm, 32 bytes for aes-256-gcm and
  459. // chacha20-poly1305) — anything else fails with "bad key" on xray start.
  460. // Older ciphers accept arbitrary passwords, so we keep the uuid-style.
  461. func randomShadowsocksClientKey(method string) string {
  462. if n := shadowsocksKeyBytes(method); n > 0 {
  463. return random.Base64Bytes(n)
  464. }
  465. return strings.ReplaceAll(uuid.NewString(), "-", "")
  466. }
  467. // validShadowsocksClientKey reports whether key is acceptable for the cipher.
  468. // For 2022-blake3 it must decode to the exact byte length the cipher needs;
  469. // any other method accepts any non-empty string.
  470. func validShadowsocksClientKey(method, key string) bool {
  471. n := shadowsocksKeyBytes(method)
  472. if n == 0 {
  473. return key != ""
  474. }
  475. decoded, err := base64.StdEncoding.DecodeString(key)
  476. if err != nil {
  477. return false
  478. }
  479. return len(decoded) == n
  480. }
  481. func shadowsocksKeyBytes(method string) int {
  482. switch method {
  483. case "2022-blake3-aes-128-gcm":
  484. return 16
  485. case "2022-blake3-aes-256-gcm", "2022-blake3-chacha20-poly1305":
  486. return 32
  487. }
  488. return 0
  489. }
  490. // applyShadowsocksClientMethod ensures each client entry carries a "method"
  491. // field for legacy shadowsocks ciphers. xray's multi-user shadowsocks code
  492. // requires a per-client method; an empty/missing field fails with
  493. // "unsupported cipher method:". 2022-blake3 ciphers use the top-level
  494. // method only, so the per-client field must stay absent.
  495. func applyShadowsocksClientMethod(clients []any, settings map[string]any) {
  496. method, _ := settings["method"].(string)
  497. if method == "" || strings.HasPrefix(method, "2022-blake3-") {
  498. return
  499. }
  500. for i := range clients {
  501. cm, ok := clients[i].(map[string]any)
  502. if !ok {
  503. continue
  504. }
  505. if existing, _ := cm["method"].(string); existing != "" {
  506. continue
  507. }
  508. cm["method"] = method
  509. clients[i] = cm
  510. }
  511. }
  512. func (s *ClientService) Update(inboundSvc *InboundService, id int, updated model.Client) (bool, error) {
  513. existing, err := s.GetByID(id)
  514. if err != nil {
  515. return false, err
  516. }
  517. inboundIds, err := s.GetInboundIdsForRecord(id)
  518. if err != nil {
  519. return false, err
  520. }
  521. if strings.TrimSpace(updated.Email) == "" {
  522. return false, common.NewError("client email is required")
  523. }
  524. if updated.SubID == "" {
  525. updated.SubID = existing.SubID
  526. }
  527. if updated.SubID == "" {
  528. updated.SubID = uuid.NewString()
  529. }
  530. updated.UpdatedAt = time.Now().UnixMilli()
  531. if updated.CreatedAt == 0 {
  532. updated.CreatedAt = existing.CreatedAt
  533. }
  534. needRestart := false
  535. for _, ibId := range inboundIds {
  536. inbound, getErr := inboundSvc.GetInbound(ibId)
  537. if getErr != nil {
  538. return needRestart, getErr
  539. }
  540. oldKey := clientKeyForProtocol(inbound.Protocol, existing)
  541. if oldKey == "" {
  542. continue
  543. }
  544. if err := s.fillProtocolDefaults(&updated, inbound); err != nil {
  545. return needRestart, err
  546. }
  547. settingsPayload, mErr := json.Marshal(map[string][]model.Client{"clients": {updated}})
  548. if mErr != nil {
  549. return needRestart, mErr
  550. }
  551. nr, upErr := s.UpdateInboundClient(inboundSvc, &model.Inbound{
  552. Id: ibId,
  553. Settings: string(settingsPayload),
  554. }, oldKey)
  555. if upErr != nil {
  556. return needRestart, upErr
  557. }
  558. if nr {
  559. needRestart = true
  560. }
  561. }
  562. return needRestart, nil
  563. }
  564. func (s *ClientService) Delete(inboundSvc *InboundService, id int, keepTraffic bool) (bool, error) {
  565. existing, err := s.GetByID(id)
  566. if err != nil {
  567. return false, err
  568. }
  569. tombstoneClientEmail(existing.Email)
  570. inboundIds, err := s.GetInboundIdsForRecord(id)
  571. if err != nil {
  572. return false, err
  573. }
  574. needRestart := false
  575. for _, ibId := range inboundIds {
  576. inbound, getErr := inboundSvc.GetInbound(ibId)
  577. if getErr != nil {
  578. return needRestart, getErr
  579. }
  580. key := clientKeyForProtocol(inbound.Protocol, existing)
  581. if key == "" {
  582. continue
  583. }
  584. nr, delErr := s.DelInboundClient(inboundSvc, ibId, key)
  585. if delErr != nil {
  586. return needRestart, delErr
  587. }
  588. if nr {
  589. needRestart = true
  590. }
  591. }
  592. db := database.GetDB()
  593. if err := db.Where("client_id = ?", id).Delete(&model.ClientInbound{}).Error; err != nil {
  594. return needRestart, err
  595. }
  596. if !keepTraffic && existing.Email != "" {
  597. if err := db.Where("email = ?", existing.Email).Delete(&xray.ClientTraffic{}).Error; err != nil {
  598. return needRestart, err
  599. }
  600. if err := db.Where("client_email = ?", existing.Email).Delete(&model.InboundClientIps{}).Error; err != nil {
  601. return needRestart, err
  602. }
  603. }
  604. if err := db.Delete(&model.ClientRecord{}, id).Error; err != nil {
  605. return needRestart, err
  606. }
  607. return needRestart, nil
  608. }
  609. func (s *ClientService) Attach(inboundSvc *InboundService, id int, inboundIds []int) (bool, error) {
  610. existing, err := s.GetByID(id)
  611. if err != nil {
  612. return false, err
  613. }
  614. currentIds, err := s.GetInboundIdsForRecord(id)
  615. if err != nil {
  616. return false, err
  617. }
  618. have := make(map[int]struct{}, len(currentIds))
  619. for _, x := range currentIds {
  620. have[x] = struct{}{}
  621. }
  622. clientWire := existing.ToClient()
  623. clientWire.UpdatedAt = time.Now().UnixMilli()
  624. needRestart := false
  625. for _, ibId := range inboundIds {
  626. if _, attached := have[ibId]; attached {
  627. continue
  628. }
  629. inbound, getErr := inboundSvc.GetInbound(ibId)
  630. if getErr != nil {
  631. return needRestart, getErr
  632. }
  633. copyClient := *clientWire
  634. if err := s.fillProtocolDefaults(&copyClient, inbound); err != nil {
  635. return needRestart, err
  636. }
  637. settingsPayload, mErr := json.Marshal(map[string][]model.Client{"clients": {copyClient}})
  638. if mErr != nil {
  639. return needRestart, mErr
  640. }
  641. nr, addErr := s.AddInboundClient(inboundSvc, &model.Inbound{
  642. Id: ibId,
  643. Settings: string(settingsPayload),
  644. })
  645. if addErr != nil {
  646. return needRestart, addErr
  647. }
  648. if nr {
  649. needRestart = true
  650. }
  651. }
  652. return needRestart, nil
  653. }
  654. func (s *ClientService) CreateOne(inboundSvc *InboundService, inboundId int, client model.Client) (bool, error) {
  655. return s.Create(inboundSvc, &ClientCreatePayload{
  656. Client: client,
  657. InboundIds: []int{inboundId},
  658. })
  659. }
  660. func (s *ClientService) DetachByEmail(inboundSvc *InboundService, inboundId int, email string) (bool, error) {
  661. if email == "" {
  662. return false, common.NewError("client email is required")
  663. }
  664. rec, err := s.GetRecordByEmail(nil, email)
  665. if err != nil {
  666. return false, err
  667. }
  668. return s.Detach(inboundSvc, rec.Id, []int{inboundId})
  669. }
  670. func (s *ClientService) AttachByEmail(inboundSvc *InboundService, email string, inboundIds []int) (bool, error) {
  671. if email == "" {
  672. return false, common.NewError("client email is required")
  673. }
  674. rec, err := s.GetRecordByEmail(nil, email)
  675. if err != nil {
  676. return false, err
  677. }
  678. return s.Attach(inboundSvc, rec.Id, inboundIds)
  679. }
  680. func (s *ClientService) DetachByEmailMany(inboundSvc *InboundService, email string, inboundIds []int) (bool, error) {
  681. if email == "" {
  682. return false, common.NewError("client email is required")
  683. }
  684. rec, err := s.GetRecordByEmail(nil, email)
  685. if err != nil {
  686. return false, err
  687. }
  688. return s.Detach(inboundSvc, rec.Id, inboundIds)
  689. }
  690. func (s *ClientService) DeleteByEmail(inboundSvc *InboundService, email string, keepTraffic bool) (bool, error) {
  691. if email == "" {
  692. return false, common.NewError("client email is required")
  693. }
  694. rec, err := s.GetRecordByEmail(nil, email)
  695. if err != nil {
  696. return false, err
  697. }
  698. return s.Delete(inboundSvc, rec.Id, keepTraffic)
  699. }
  700. func (s *ClientService) UpdateByEmail(inboundSvc *InboundService, email string, updated model.Client) (bool, error) {
  701. if email == "" {
  702. return false, common.NewError("client email is required")
  703. }
  704. rec, err := s.GetRecordByEmail(nil, email)
  705. if err != nil {
  706. return false, err
  707. }
  708. return s.Update(inboundSvc, rec.Id, updated)
  709. }
  710. func (s *ClientService) ResetTrafficByEmail(inboundSvc *InboundService, email string) (bool, error) {
  711. if email == "" {
  712. return false, common.NewError("client email is required")
  713. }
  714. rec, err := s.GetRecordByEmail(nil, email)
  715. if err != nil {
  716. return false, err
  717. }
  718. inboundIds, err := s.GetInboundIdsForRecord(rec.Id)
  719. if err != nil {
  720. return false, err
  721. }
  722. if len(inboundIds) == 0 {
  723. if rErr := inboundSvc.ResetClientTrafficByEmail(email); rErr != nil {
  724. return false, rErr
  725. }
  726. return false, nil
  727. }
  728. needRestart := false
  729. for _, ibId := range inboundIds {
  730. nr, rErr := inboundSvc.ResetClientTraffic(ibId, email)
  731. if rErr != nil {
  732. return needRestart, rErr
  733. }
  734. if nr {
  735. needRestart = true
  736. }
  737. }
  738. return needRestart, nil
  739. }
  740. func (s *ClientService) DelDepleted(inboundSvc *InboundService) (int, bool, error) {
  741. db := database.GetDB()
  742. now := time.Now().UnixMilli()
  743. depletedClause := "reset = 0 and ((total > 0 and up + down >= total) or (expiry_time > 0 and expiry_time <= ?))"
  744. var rows []xray.ClientTraffic
  745. if err := db.Where(depletedClause, now).Find(&rows).Error; err != nil {
  746. return 0, false, err
  747. }
  748. if len(rows) == 0 {
  749. return 0, false, nil
  750. }
  751. emails := make(map[string]struct{}, len(rows))
  752. for _, r := range rows {
  753. if r.Email != "" {
  754. emails[r.Email] = struct{}{}
  755. }
  756. }
  757. needRestart := false
  758. deleted := 0
  759. for email := range emails {
  760. var rec model.ClientRecord
  761. if err := db.Where("email = ?", email).First(&rec).Error; err != nil {
  762. if errors.Is(err, gorm.ErrRecordNotFound) {
  763. continue
  764. }
  765. return deleted, needRestart, err
  766. }
  767. nr, err := s.Delete(inboundSvc, rec.Id, false)
  768. if err != nil {
  769. return deleted, needRestart, err
  770. }
  771. if nr {
  772. needRestart = true
  773. }
  774. deleted++
  775. }
  776. return deleted, needRestart, nil
  777. }
  778. func (s *ClientService) ResetAllClientTraffics(inboundSvc *InboundService, id int) error {
  779. return submitTrafficWrite(func() error {
  780. return s.resetAllClientTrafficsLocked(id)
  781. })
  782. }
  783. func (s *ClientService) resetAllClientTrafficsLocked(id int) error {
  784. db := database.GetDB()
  785. now := time.Now().Unix() * 1000
  786. if err := db.Transaction(func(tx *gorm.DB) error {
  787. whereText := "inbound_id "
  788. if id == -1 {
  789. whereText += " > ?"
  790. } else {
  791. whereText += " = ?"
  792. }
  793. result := tx.Model(xray.ClientTraffic{}).
  794. Where(whereText, id).
  795. Updates(map[string]any{"enable": true, "up": 0, "down": 0})
  796. if result.Error != nil {
  797. return result.Error
  798. }
  799. inboundWhereText := "id "
  800. if id == -1 {
  801. inboundWhereText += " > ?"
  802. } else {
  803. inboundWhereText += " = ?"
  804. }
  805. result = tx.Model(model.Inbound{}).
  806. Where(inboundWhereText, id).
  807. Update("last_traffic_reset_time", now)
  808. return result.Error
  809. }); err != nil {
  810. return err
  811. }
  812. return nil
  813. }
  814. func (s *ClientService) ResetAllTraffics() (bool, error) {
  815. res := database.GetDB().Model(&xray.ClientTraffic{}).
  816. Where("1 = 1").
  817. Updates(map[string]any{"up": 0, "down": 0})
  818. if res.Error != nil {
  819. return false, res.Error
  820. }
  821. return res.RowsAffected > 0, nil
  822. }
  823. func (s *ClientService) Detach(inboundSvc *InboundService, id int, inboundIds []int) (bool, error) {
  824. existing, err := s.GetByID(id)
  825. if err != nil {
  826. return false, err
  827. }
  828. currentIds, err := s.GetInboundIdsForRecord(id)
  829. if err != nil {
  830. return false, err
  831. }
  832. have := make(map[int]struct{}, len(currentIds))
  833. for _, x := range currentIds {
  834. have[x] = struct{}{}
  835. }
  836. needRestart := false
  837. for _, ibId := range inboundIds {
  838. if _, attached := have[ibId]; !attached {
  839. continue
  840. }
  841. inbound, getErr := inboundSvc.GetInbound(ibId)
  842. if getErr != nil {
  843. return needRestart, getErr
  844. }
  845. key := clientKeyForProtocol(inbound.Protocol, existing)
  846. if key == "" {
  847. continue
  848. }
  849. nr, delErr := s.DelInboundClient(inboundSvc, ibId, key)
  850. if delErr != nil {
  851. return needRestart, delErr
  852. }
  853. if nr {
  854. needRestart = true
  855. }
  856. }
  857. return needRestart, nil
  858. }
  859. func (s *ClientService) checkEmailsExistForClients(inboundSvc *InboundService, clients []model.Client) (string, error) {
  860. emailSubIDs, err := inboundSvc.getAllEmailSubIDs()
  861. if err != nil {
  862. return "", err
  863. }
  864. seen := make(map[string]string, len(clients))
  865. for _, client := range clients {
  866. if client.Email == "" {
  867. continue
  868. }
  869. key := strings.ToLower(client.Email)
  870. if prev, ok := seen[key]; ok {
  871. if prev != client.SubID || client.SubID == "" {
  872. return client.Email, nil
  873. }
  874. continue
  875. }
  876. seen[key] = client.SubID
  877. if existingSub, ok := emailSubIDs[key]; ok {
  878. if client.SubID == "" || existingSub == "" || existingSub != client.SubID {
  879. return client.Email, nil
  880. }
  881. }
  882. }
  883. return "", nil
  884. }
  885. func (s *ClientService) AddInboundClient(inboundSvc *InboundService, data *model.Inbound) (bool, error) {
  886. defer lockInbound(data.Id).Unlock()
  887. clients, err := inboundSvc.GetClients(data)
  888. if err != nil {
  889. return false, err
  890. }
  891. var settings map[string]any
  892. err = json.Unmarshal([]byte(data.Settings), &settings)
  893. if err != nil {
  894. return false, err
  895. }
  896. interfaceClients := settings["clients"].([]any)
  897. nowTs := time.Now().Unix() * 1000
  898. for i := range interfaceClients {
  899. if cm, ok := interfaceClients[i].(map[string]any); ok {
  900. if _, ok2 := cm["created_at"]; !ok2 {
  901. cm["created_at"] = nowTs
  902. }
  903. cm["updated_at"] = nowTs
  904. interfaceClients[i] = cm
  905. }
  906. }
  907. existEmail, err := s.checkEmailsExistForClients(inboundSvc, clients)
  908. if err != nil {
  909. return false, err
  910. }
  911. if existEmail != "" {
  912. return false, common.NewError("Duplicate email:", existEmail)
  913. }
  914. oldInbound, err := inboundSvc.GetInbound(data.Id)
  915. if err != nil {
  916. return false, err
  917. }
  918. for _, client := range clients {
  919. if strings.TrimSpace(client.Email) == "" {
  920. return false, common.NewError("client email is required")
  921. }
  922. switch oldInbound.Protocol {
  923. case "trojan":
  924. if client.Password == "" {
  925. return false, common.NewError("empty client ID")
  926. }
  927. case "shadowsocks":
  928. if client.Email == "" {
  929. return false, common.NewError("empty client ID")
  930. }
  931. case "hysteria", "hysteria2":
  932. if client.Auth == "" {
  933. return false, common.NewError("empty client ID")
  934. }
  935. default:
  936. if client.ID == "" {
  937. return false, common.NewError("empty client ID")
  938. }
  939. }
  940. }
  941. var oldSettings map[string]any
  942. err = json.Unmarshal([]byte(oldInbound.Settings), &oldSettings)
  943. if err != nil {
  944. return false, err
  945. }
  946. if oldInbound.Protocol == model.Shadowsocks {
  947. applyShadowsocksClientMethod(interfaceClients, oldSettings)
  948. }
  949. oldClients := oldSettings["clients"].([]any)
  950. oldClients = compactOrphans(database.GetDB(), oldClients)
  951. oldClients = append(oldClients, interfaceClients...)
  952. oldSettings["clients"] = oldClients
  953. newSettings, err := json.MarshalIndent(oldSettings, "", " ")
  954. if err != nil {
  955. return false, err
  956. }
  957. oldInbound.Settings = string(newSettings)
  958. db := database.GetDB()
  959. tx := db.Begin()
  960. defer func() {
  961. if err != nil {
  962. tx.Rollback()
  963. } else {
  964. tx.Commit()
  965. }
  966. }()
  967. needRestart := false
  968. rt, rterr := inboundSvc.runtimeFor(oldInbound)
  969. if rterr != nil {
  970. if oldInbound.NodeID != nil {
  971. err = rterr
  972. return false, err
  973. }
  974. needRestart = true
  975. } else if oldInbound.NodeID == nil {
  976. for _, client := range clients {
  977. if len(client.Email) == 0 {
  978. needRestart = true
  979. continue
  980. }
  981. inboundSvc.AddClientStat(tx, data.Id, &client)
  982. if !client.Enable {
  983. continue
  984. }
  985. cipher := ""
  986. if oldInbound.Protocol == "shadowsocks" {
  987. cipher = oldSettings["method"].(string)
  988. }
  989. err1 := rt.AddUser(context.Background(), oldInbound, map[string]any{
  990. "email": client.Email,
  991. "id": client.ID,
  992. "auth": client.Auth,
  993. "security": client.Security,
  994. "flow": client.Flow,
  995. "password": client.Password,
  996. "cipher": cipher,
  997. })
  998. if err1 == nil {
  999. logger.Debug("Client added on", rt.Name(), ":", client.Email)
  1000. } else {
  1001. logger.Debug("Error in adding client on", rt.Name(), ":", err1)
  1002. needRestart = true
  1003. }
  1004. }
  1005. } else {
  1006. for _, client := range clients {
  1007. if len(client.Email) > 0 {
  1008. inboundSvc.AddClientStat(tx, data.Id, &client)
  1009. }
  1010. if err1 := rt.AddClient(context.Background(), oldInbound, client); err1 != nil {
  1011. err = err1
  1012. return false, err
  1013. }
  1014. }
  1015. }
  1016. if err = tx.Save(oldInbound).Error; err != nil {
  1017. return false, err
  1018. }
  1019. finalClients, gcErr := inboundSvc.GetClients(oldInbound)
  1020. if gcErr != nil {
  1021. err = gcErr
  1022. return false, err
  1023. }
  1024. if err = s.SyncInbound(tx, oldInbound.Id, finalClients); err != nil {
  1025. return false, err
  1026. }
  1027. return needRestart, nil
  1028. }
  1029. func (s *ClientService) UpdateInboundClient(inboundSvc *InboundService, data *model.Inbound, clientId string) (bool, error) {
  1030. defer lockInbound(data.Id).Unlock()
  1031. clients, err := inboundSvc.GetClients(data)
  1032. if err != nil {
  1033. return false, err
  1034. }
  1035. var settings map[string]any
  1036. err = json.Unmarshal([]byte(data.Settings), &settings)
  1037. if err != nil {
  1038. return false, err
  1039. }
  1040. interfaceClients := settings["clients"].([]any)
  1041. oldInbound, err := inboundSvc.GetInbound(data.Id)
  1042. if err != nil {
  1043. return false, err
  1044. }
  1045. oldClients, err := inboundSvc.GetClients(oldInbound)
  1046. if err != nil {
  1047. return false, err
  1048. }
  1049. oldEmail := ""
  1050. newClientId := ""
  1051. clientIndex := -1
  1052. for index, oldClient := range oldClients {
  1053. oldClientId := ""
  1054. switch oldInbound.Protocol {
  1055. case "trojan":
  1056. oldClientId = oldClient.Password
  1057. newClientId = clients[0].Password
  1058. case "shadowsocks":
  1059. oldClientId = oldClient.Email
  1060. newClientId = clients[0].Email
  1061. case "hysteria", "hysteria2":
  1062. oldClientId = oldClient.Auth
  1063. newClientId = clients[0].Auth
  1064. default:
  1065. oldClientId = oldClient.ID
  1066. newClientId = clients[0].ID
  1067. }
  1068. if clientId == oldClientId {
  1069. oldEmail = oldClient.Email
  1070. clientIndex = index
  1071. break
  1072. }
  1073. }
  1074. if newClientId == "" || clientIndex == -1 {
  1075. return false, common.NewError("empty client ID")
  1076. }
  1077. if strings.TrimSpace(clients[0].Email) == "" {
  1078. return false, common.NewError("client email is required")
  1079. }
  1080. if clients[0].Email != oldEmail {
  1081. existEmail, err := s.checkEmailsExistForClients(inboundSvc, clients)
  1082. if err != nil {
  1083. return false, err
  1084. }
  1085. if existEmail != "" {
  1086. return false, common.NewError("Duplicate email:", existEmail)
  1087. }
  1088. }
  1089. var oldSettings map[string]any
  1090. err = json.Unmarshal([]byte(oldInbound.Settings), &oldSettings)
  1091. if err != nil {
  1092. return false, err
  1093. }
  1094. settingsClients := oldSettings["clients"].([]any)
  1095. var preservedCreated any
  1096. if clientIndex >= 0 && clientIndex < len(settingsClients) {
  1097. if oldMap, ok := settingsClients[clientIndex].(map[string]any); ok {
  1098. if v, ok2 := oldMap["created_at"]; ok2 {
  1099. preservedCreated = v
  1100. }
  1101. }
  1102. }
  1103. if len(interfaceClients) > 0 {
  1104. if newMap, ok := interfaceClients[0].(map[string]any); ok {
  1105. if preservedCreated == nil {
  1106. preservedCreated = time.Now().Unix() * 1000
  1107. }
  1108. newMap["created_at"] = preservedCreated
  1109. newMap["updated_at"] = time.Now().Unix() * 1000
  1110. interfaceClients[0] = newMap
  1111. }
  1112. }
  1113. if oldInbound.Protocol == model.Shadowsocks {
  1114. applyShadowsocksClientMethod(interfaceClients, oldSettings)
  1115. }
  1116. settingsClients[clientIndex] = interfaceClients[0]
  1117. oldSettings["clients"] = settingsClients
  1118. if oldInbound.Protocol == model.VLESS {
  1119. hasVisionFlow := false
  1120. for _, c := range settingsClients {
  1121. cm, ok := c.(map[string]any)
  1122. if !ok {
  1123. continue
  1124. }
  1125. if flow, _ := cm["flow"].(string); flow == "xtls-rprx-vision" {
  1126. hasVisionFlow = true
  1127. break
  1128. }
  1129. }
  1130. if !hasVisionFlow {
  1131. delete(oldSettings, "testseed")
  1132. }
  1133. }
  1134. newSettings, err := json.MarshalIndent(oldSettings, "", " ")
  1135. if err != nil {
  1136. return false, err
  1137. }
  1138. oldInbound.Settings = string(newSettings)
  1139. db := database.GetDB()
  1140. tx := db.Begin()
  1141. defer func() {
  1142. if err != nil {
  1143. tx.Rollback()
  1144. } else {
  1145. tx.Commit()
  1146. }
  1147. }()
  1148. if len(clients[0].Email) > 0 {
  1149. if len(oldEmail) > 0 {
  1150. emailUnchanged := strings.EqualFold(oldEmail, clients[0].Email)
  1151. targetExists := int64(0)
  1152. if !emailUnchanged {
  1153. if err = tx.Model(xray.ClientTraffic{}).Where("email = ?", clients[0].Email).Count(&targetExists).Error; err != nil {
  1154. return false, err
  1155. }
  1156. }
  1157. if emailUnchanged || targetExists == 0 {
  1158. err = inboundSvc.UpdateClientStat(tx, oldEmail, &clients[0])
  1159. if err != nil {
  1160. return false, err
  1161. }
  1162. err = inboundSvc.UpdateClientIPs(tx, oldEmail, clients[0].Email)
  1163. if err != nil {
  1164. return false, err
  1165. }
  1166. } else {
  1167. stillUsed, sErr := inboundSvc.emailUsedByOtherInbounds(oldEmail, data.Id)
  1168. if sErr != nil {
  1169. return false, sErr
  1170. }
  1171. if !stillUsed {
  1172. if err = inboundSvc.DelClientStat(tx, oldEmail); err != nil {
  1173. return false, err
  1174. }
  1175. if err = inboundSvc.DelClientIPs(tx, oldEmail); err != nil {
  1176. return false, err
  1177. }
  1178. }
  1179. if err = inboundSvc.UpdateClientStat(tx, clients[0].Email, &clients[0]); err != nil {
  1180. return false, err
  1181. }
  1182. }
  1183. } else {
  1184. inboundSvc.AddClientStat(tx, data.Id, &clients[0])
  1185. }
  1186. } else {
  1187. stillUsed, err := inboundSvc.emailUsedByOtherInbounds(oldEmail, data.Id)
  1188. if err != nil {
  1189. return false, err
  1190. }
  1191. if !stillUsed {
  1192. err = inboundSvc.DelClientStat(tx, oldEmail)
  1193. if err != nil {
  1194. return false, err
  1195. }
  1196. err = inboundSvc.DelClientIPs(tx, oldEmail)
  1197. if err != nil {
  1198. return false, err
  1199. }
  1200. }
  1201. }
  1202. needRestart := false
  1203. if len(oldEmail) > 0 {
  1204. rt, rterr := inboundSvc.runtimeFor(oldInbound)
  1205. if rterr != nil {
  1206. if oldInbound.NodeID != nil {
  1207. err = rterr
  1208. return false, err
  1209. }
  1210. needRestart = true
  1211. } else if oldInbound.NodeID == nil {
  1212. if oldClients[clientIndex].Enable {
  1213. err1 := rt.RemoveUser(context.Background(), oldInbound, oldEmail)
  1214. if err1 == nil {
  1215. logger.Debug("Old client deleted on", rt.Name(), ":", oldEmail)
  1216. } else if strings.Contains(err1.Error(), fmt.Sprintf("User %s not found.", oldEmail)) {
  1217. logger.Debug("User is already deleted. Nothing to do more...")
  1218. } else {
  1219. logger.Debug("Error in deleting client on", rt.Name(), ":", err1)
  1220. needRestart = true
  1221. }
  1222. }
  1223. if clients[0].Enable {
  1224. cipher := ""
  1225. if oldInbound.Protocol == "shadowsocks" {
  1226. cipher = oldSettings["method"].(string)
  1227. }
  1228. err1 := rt.AddUser(context.Background(), oldInbound, map[string]any{
  1229. "email": clients[0].Email,
  1230. "id": clients[0].ID,
  1231. "security": clients[0].Security,
  1232. "flow": clients[0].Flow,
  1233. "auth": clients[0].Auth,
  1234. "password": clients[0].Password,
  1235. "cipher": cipher,
  1236. })
  1237. if err1 == nil {
  1238. logger.Debug("Client edited on", rt.Name(), ":", clients[0].Email)
  1239. } else {
  1240. logger.Debug("Error in adding client on", rt.Name(), ":", err1)
  1241. needRestart = true
  1242. }
  1243. }
  1244. } else {
  1245. if err1 := rt.UpdateUser(context.Background(), oldInbound, oldEmail, clients[0]); err1 != nil {
  1246. err = err1
  1247. return false, err
  1248. }
  1249. }
  1250. } else {
  1251. logger.Debug("Client old email not found")
  1252. needRestart = true
  1253. }
  1254. if err = tx.Save(oldInbound).Error; err != nil {
  1255. return false, err
  1256. }
  1257. finalClients, gcErr := inboundSvc.GetClients(oldInbound)
  1258. if gcErr != nil {
  1259. err = gcErr
  1260. return false, err
  1261. }
  1262. if err = s.SyncInbound(tx, oldInbound.Id, finalClients); err != nil {
  1263. return false, err
  1264. }
  1265. return needRestart, nil
  1266. }
  1267. func (s *ClientService) DelInboundClient(inboundSvc *InboundService, inboundId int, clientId string) (bool, error) {
  1268. defer lockInbound(inboundId).Unlock()
  1269. oldInbound, err := inboundSvc.GetInbound(inboundId)
  1270. if err != nil {
  1271. logger.Error("Load Old Data Error")
  1272. return false, err
  1273. }
  1274. var settings map[string]any
  1275. err = json.Unmarshal([]byte(oldInbound.Settings), &settings)
  1276. if err != nil {
  1277. return false, err
  1278. }
  1279. email := ""
  1280. client_key := "id"
  1281. switch oldInbound.Protocol {
  1282. case "trojan":
  1283. client_key = "password"
  1284. case "shadowsocks":
  1285. client_key = "email"
  1286. case "hysteria", "hysteria2":
  1287. client_key = "auth"
  1288. }
  1289. interfaceClients := settings["clients"].([]any)
  1290. var newClients []any
  1291. needApiDel := false
  1292. clientFound := false
  1293. for _, client := range interfaceClients {
  1294. c := client.(map[string]any)
  1295. c_id := c[client_key].(string)
  1296. if c_id == clientId {
  1297. clientFound = true
  1298. email, _ = c["email"].(string)
  1299. needApiDel, _ = c["enable"].(bool)
  1300. } else {
  1301. newClients = append(newClients, client)
  1302. }
  1303. }
  1304. if !clientFound {
  1305. return false, common.NewError("Client Not Found In Inbound For ID:", clientId)
  1306. }
  1307. db := database.GetDB()
  1308. newClients = compactOrphans(db, newClients)
  1309. if newClients == nil {
  1310. newClients = []any{}
  1311. }
  1312. settings["clients"] = newClients
  1313. newSettings, err := json.MarshalIndent(settings, "", " ")
  1314. if err != nil {
  1315. return false, err
  1316. }
  1317. oldInbound.Settings = string(newSettings)
  1318. emailShared, err := inboundSvc.emailUsedByOtherInbounds(email, inboundId)
  1319. if err != nil {
  1320. return false, err
  1321. }
  1322. if !emailShared {
  1323. err = inboundSvc.DelClientIPs(db, email)
  1324. if err != nil {
  1325. logger.Error("Error in delete client IPs")
  1326. return false, err
  1327. }
  1328. }
  1329. needRestart := false
  1330. if len(email) > 0 {
  1331. var enables []bool
  1332. err = db.Model(xray.ClientTraffic{}).Where("email = ?", email).Limit(1).Pluck("enable", &enables).Error
  1333. if err != nil {
  1334. logger.Error("Get stats error")
  1335. return false, err
  1336. }
  1337. notDepleted := len(enables) > 0 && enables[0]
  1338. if !emailShared {
  1339. err = inboundSvc.DelClientStat(db, email)
  1340. if err != nil {
  1341. logger.Error("Delete stats Data Error")
  1342. return false, err
  1343. }
  1344. }
  1345. if needApiDel && notDepleted && oldInbound.NodeID == nil {
  1346. rt, rterr := inboundSvc.runtimeFor(oldInbound)
  1347. if rterr != nil {
  1348. needRestart = true
  1349. } else {
  1350. err1 := rt.RemoveUser(context.Background(), oldInbound, email)
  1351. if err1 == nil {
  1352. logger.Debug("Client deleted on", rt.Name(), ":", email)
  1353. needRestart = false
  1354. } else if strings.Contains(err1.Error(), fmt.Sprintf("User %s not found.", email)) {
  1355. logger.Debug("User is already deleted. Nothing to do more...")
  1356. } else {
  1357. logger.Debug("Error in deleting client on", rt.Name(), ":", err1)
  1358. needRestart = true
  1359. }
  1360. }
  1361. }
  1362. }
  1363. if oldInbound.NodeID != nil && len(email) > 0 {
  1364. rt, rterr := inboundSvc.runtimeFor(oldInbound)
  1365. if rterr != nil {
  1366. return false, rterr
  1367. }
  1368. if err1 := rt.DeleteUser(context.Background(), oldInbound, email); err1 != nil {
  1369. return false, err1
  1370. }
  1371. }
  1372. if err := db.Save(oldInbound).Error; err != nil {
  1373. return false, err
  1374. }
  1375. finalClients, gcErr := inboundSvc.GetClients(oldInbound)
  1376. if gcErr != nil {
  1377. return false, gcErr
  1378. }
  1379. if err := s.SyncInbound(db, inboundId, finalClients); err != nil {
  1380. return false, err
  1381. }
  1382. return needRestart, nil
  1383. }
  1384. func (s *ClientService) DelInboundClientByEmail(inboundSvc *InboundService, inboundId int, email string) (bool, error) {
  1385. defer lockInbound(inboundId).Unlock()
  1386. oldInbound, err := inboundSvc.GetInbound(inboundId)
  1387. if err != nil {
  1388. logger.Error("Load Old Data Error")
  1389. return false, err
  1390. }
  1391. var settings map[string]any
  1392. if err := json.Unmarshal([]byte(oldInbound.Settings), &settings); err != nil {
  1393. return false, err
  1394. }
  1395. interfaceClients, ok := settings["clients"].([]any)
  1396. if !ok {
  1397. return false, common.NewError("invalid clients format in inbound settings")
  1398. }
  1399. var newClients []any
  1400. needApiDel := false
  1401. found := false
  1402. for _, client := range interfaceClients {
  1403. c, ok := client.(map[string]any)
  1404. if !ok {
  1405. continue
  1406. }
  1407. if cEmail, ok := c["email"].(string); ok && cEmail == email {
  1408. found = true
  1409. needApiDel, _ = c["enable"].(bool)
  1410. } else {
  1411. newClients = append(newClients, client)
  1412. }
  1413. }
  1414. if !found {
  1415. return false, common.NewError(fmt.Sprintf("client with email %s not found", email))
  1416. }
  1417. db := database.GetDB()
  1418. newClients = compactOrphans(db, newClients)
  1419. if newClients == nil {
  1420. newClients = []any{}
  1421. }
  1422. settings["clients"] = newClients
  1423. newSettings, err := json.MarshalIndent(settings, "", " ")
  1424. if err != nil {
  1425. return false, err
  1426. }
  1427. oldInbound.Settings = string(newSettings)
  1428. emailShared, err := inboundSvc.emailUsedByOtherInbounds(email, inboundId)
  1429. if err != nil {
  1430. return false, err
  1431. }
  1432. if !emailShared {
  1433. if err := inboundSvc.DelClientIPs(db, email); err != nil {
  1434. logger.Error("Error in delete client IPs")
  1435. return false, err
  1436. }
  1437. }
  1438. needRestart := false
  1439. if len(email) > 0 && !emailShared {
  1440. traffic, err := inboundSvc.GetClientTrafficByEmail(email)
  1441. if err != nil {
  1442. return false, err
  1443. }
  1444. if traffic != nil {
  1445. if err := inboundSvc.DelClientStat(db, email); err != nil {
  1446. logger.Error("Delete stats Data Error")
  1447. return false, err
  1448. }
  1449. }
  1450. if needApiDel {
  1451. rt, rterr := inboundSvc.runtimeFor(oldInbound)
  1452. if rterr != nil {
  1453. if oldInbound.NodeID != nil {
  1454. return false, rterr
  1455. }
  1456. needRestart = true
  1457. } else if oldInbound.NodeID == nil {
  1458. if err1 := rt.RemoveUser(context.Background(), oldInbound, email); err1 == nil {
  1459. logger.Debug("Client deleted on", rt.Name(), ":", email)
  1460. needRestart = false
  1461. } else if strings.Contains(err1.Error(), fmt.Sprintf("User %s not found.", email)) {
  1462. logger.Debug("User is already deleted. Nothing to do more...")
  1463. } else {
  1464. logger.Debug("Error in deleting client on", rt.Name(), ":", err1)
  1465. needRestart = true
  1466. }
  1467. } else {
  1468. if err1 := rt.DeleteUser(context.Background(), oldInbound, email); err1 != nil {
  1469. return false, err1
  1470. }
  1471. }
  1472. }
  1473. }
  1474. if err := db.Save(oldInbound).Error; err != nil {
  1475. return false, err
  1476. }
  1477. finalClients, gcErr := inboundSvc.GetClients(oldInbound)
  1478. if gcErr != nil {
  1479. return false, gcErr
  1480. }
  1481. if err := s.SyncInbound(db, inboundId, finalClients); err != nil {
  1482. return false, err
  1483. }
  1484. return needRestart, nil
  1485. }
  1486. func (s *ClientService) SetClientTelegramUserID(inboundSvc *InboundService, trafficId int, tgId int64) (bool, error) {
  1487. traffic, inbound, err := inboundSvc.GetClientInboundByTrafficID(trafficId)
  1488. if err != nil {
  1489. return false, err
  1490. }
  1491. if inbound == nil {
  1492. return false, common.NewError("Inbound Not Found For Traffic ID:", trafficId)
  1493. }
  1494. clientEmail := traffic.Email
  1495. oldClients, err := inboundSvc.GetClients(inbound)
  1496. if err != nil {
  1497. return false, err
  1498. }
  1499. clientId := ""
  1500. for _, oldClient := range oldClients {
  1501. if oldClient.Email == clientEmail {
  1502. switch inbound.Protocol {
  1503. case "trojan":
  1504. clientId = oldClient.Password
  1505. case "shadowsocks":
  1506. clientId = oldClient.Email
  1507. default:
  1508. clientId = oldClient.ID
  1509. }
  1510. break
  1511. }
  1512. }
  1513. if len(clientId) == 0 {
  1514. return false, common.NewError("Client Not Found For Email:", clientEmail)
  1515. }
  1516. var settings map[string]any
  1517. err = json.Unmarshal([]byte(inbound.Settings), &settings)
  1518. if err != nil {
  1519. return false, err
  1520. }
  1521. clients := settings["clients"].([]any)
  1522. var newClients []any
  1523. for client_index := range clients {
  1524. c := clients[client_index].(map[string]any)
  1525. if c["email"] == clientEmail {
  1526. c["tgId"] = tgId
  1527. c["updated_at"] = time.Now().Unix() * 1000
  1528. newClients = append(newClients, any(c))
  1529. }
  1530. }
  1531. settings["clients"] = newClients
  1532. modifiedSettings, err := json.MarshalIndent(settings, "", " ")
  1533. if err != nil {
  1534. return false, err
  1535. }
  1536. inbound.Settings = string(modifiedSettings)
  1537. needRestart, err := s.UpdateInboundClient(inboundSvc, inbound, clientId)
  1538. return needRestart, err
  1539. }
  1540. func (s *ClientService) checkIsEnabledByEmail(inboundSvc *InboundService, clientEmail string) (bool, error) {
  1541. _, inbound, err := inboundSvc.GetClientInboundByEmail(clientEmail)
  1542. if err != nil {
  1543. return false, err
  1544. }
  1545. if inbound == nil {
  1546. return false, common.NewError("Inbound Not Found For Email:", clientEmail)
  1547. }
  1548. clients, err := inboundSvc.GetClients(inbound)
  1549. if err != nil {
  1550. return false, err
  1551. }
  1552. isEnable := false
  1553. for _, client := range clients {
  1554. if client.Email == clientEmail {
  1555. isEnable = client.Enable
  1556. break
  1557. }
  1558. }
  1559. return isEnable, err
  1560. }
  1561. func (s *ClientService) ToggleClientEnableByEmail(inboundSvc *InboundService, clientEmail string) (bool, bool, error) {
  1562. _, inbound, err := inboundSvc.GetClientInboundByEmail(clientEmail)
  1563. if err != nil {
  1564. return false, false, err
  1565. }
  1566. if inbound == nil {
  1567. return false, false, common.NewError("Inbound Not Found For Email:", clientEmail)
  1568. }
  1569. oldClients, err := inboundSvc.GetClients(inbound)
  1570. if err != nil {
  1571. return false, false, err
  1572. }
  1573. clientId := ""
  1574. clientOldEnabled := false
  1575. for _, oldClient := range oldClients {
  1576. if oldClient.Email == clientEmail {
  1577. switch inbound.Protocol {
  1578. case "trojan":
  1579. clientId = oldClient.Password
  1580. case "shadowsocks":
  1581. clientId = oldClient.Email
  1582. default:
  1583. clientId = oldClient.ID
  1584. }
  1585. clientOldEnabled = oldClient.Enable
  1586. break
  1587. }
  1588. }
  1589. if len(clientId) == 0 {
  1590. return false, false, common.NewError("Client Not Found For Email:", clientEmail)
  1591. }
  1592. var settings map[string]any
  1593. err = json.Unmarshal([]byte(inbound.Settings), &settings)
  1594. if err != nil {
  1595. return false, false, err
  1596. }
  1597. clients := settings["clients"].([]any)
  1598. var newClients []any
  1599. for client_index := range clients {
  1600. c := clients[client_index].(map[string]any)
  1601. if c["email"] == clientEmail {
  1602. c["enable"] = !clientOldEnabled
  1603. c["updated_at"] = time.Now().Unix() * 1000
  1604. newClients = append(newClients, any(c))
  1605. }
  1606. }
  1607. settings["clients"] = newClients
  1608. modifiedSettings, err := json.MarshalIndent(settings, "", " ")
  1609. if err != nil {
  1610. return false, false, err
  1611. }
  1612. inbound.Settings = string(modifiedSettings)
  1613. needRestart, err := s.UpdateInboundClient(inboundSvc, inbound, clientId)
  1614. if err != nil {
  1615. return false, needRestart, err
  1616. }
  1617. return !clientOldEnabled, needRestart, nil
  1618. }
  1619. func (s *ClientService) SetClientEnableByEmail(inboundSvc *InboundService, clientEmail string, enable bool) (bool, bool, error) {
  1620. current, err := s.checkIsEnabledByEmail(inboundSvc, clientEmail)
  1621. if err != nil {
  1622. return false, false, err
  1623. }
  1624. if current == enable {
  1625. return false, false, nil
  1626. }
  1627. newEnabled, needRestart, err := s.ToggleClientEnableByEmail(inboundSvc, clientEmail)
  1628. if err != nil {
  1629. return false, needRestart, err
  1630. }
  1631. return newEnabled == enable, needRestart, nil
  1632. }
  1633. func (s *ClientService) ResetClientIpLimitByEmail(inboundSvc *InboundService, clientEmail string, count int) (bool, error) {
  1634. _, inbound, err := inboundSvc.GetClientInboundByEmail(clientEmail)
  1635. if err != nil {
  1636. return false, err
  1637. }
  1638. if inbound == nil {
  1639. return false, common.NewError("Inbound Not Found For Email:", clientEmail)
  1640. }
  1641. oldClients, err := inboundSvc.GetClients(inbound)
  1642. if err != nil {
  1643. return false, err
  1644. }
  1645. clientId := ""
  1646. for _, oldClient := range oldClients {
  1647. if oldClient.Email == clientEmail {
  1648. switch inbound.Protocol {
  1649. case "trojan":
  1650. clientId = oldClient.Password
  1651. case "shadowsocks":
  1652. clientId = oldClient.Email
  1653. default:
  1654. clientId = oldClient.ID
  1655. }
  1656. break
  1657. }
  1658. }
  1659. if len(clientId) == 0 {
  1660. return false, common.NewError("Client Not Found For Email:", clientEmail)
  1661. }
  1662. var settings map[string]any
  1663. err = json.Unmarshal([]byte(inbound.Settings), &settings)
  1664. if err != nil {
  1665. return false, err
  1666. }
  1667. clients := settings["clients"].([]any)
  1668. var newClients []any
  1669. for client_index := range clients {
  1670. c := clients[client_index].(map[string]any)
  1671. if c["email"] == clientEmail {
  1672. c["limitIp"] = count
  1673. c["updated_at"] = time.Now().Unix() * 1000
  1674. newClients = append(newClients, any(c))
  1675. }
  1676. }
  1677. settings["clients"] = newClients
  1678. modifiedSettings, err := json.MarshalIndent(settings, "", " ")
  1679. if err != nil {
  1680. return false, err
  1681. }
  1682. inbound.Settings = string(modifiedSettings)
  1683. needRestart, err := s.UpdateInboundClient(inboundSvc, inbound, clientId)
  1684. return needRestart, err
  1685. }
  1686. func (s *ClientService) ResetClientExpiryTimeByEmail(inboundSvc *InboundService, clientEmail string, expiry_time int64) (bool, error) {
  1687. _, inbound, err := inboundSvc.GetClientInboundByEmail(clientEmail)
  1688. if err != nil {
  1689. return false, err
  1690. }
  1691. if inbound == nil {
  1692. return false, common.NewError("Inbound Not Found For Email:", clientEmail)
  1693. }
  1694. oldClients, err := inboundSvc.GetClients(inbound)
  1695. if err != nil {
  1696. return false, err
  1697. }
  1698. clientId := ""
  1699. for _, oldClient := range oldClients {
  1700. if oldClient.Email == clientEmail {
  1701. switch inbound.Protocol {
  1702. case "trojan":
  1703. clientId = oldClient.Password
  1704. case "shadowsocks":
  1705. clientId = oldClient.Email
  1706. default:
  1707. clientId = oldClient.ID
  1708. }
  1709. break
  1710. }
  1711. }
  1712. if len(clientId) == 0 {
  1713. return false, common.NewError("Client Not Found For Email:", clientEmail)
  1714. }
  1715. var settings map[string]any
  1716. err = json.Unmarshal([]byte(inbound.Settings), &settings)
  1717. if err != nil {
  1718. return false, err
  1719. }
  1720. clients := settings["clients"].([]any)
  1721. var newClients []any
  1722. for client_index := range clients {
  1723. c := clients[client_index].(map[string]any)
  1724. if c["email"] == clientEmail {
  1725. c["expiryTime"] = expiry_time
  1726. c["updated_at"] = time.Now().Unix() * 1000
  1727. newClients = append(newClients, any(c))
  1728. }
  1729. }
  1730. settings["clients"] = newClients
  1731. modifiedSettings, err := json.MarshalIndent(settings, "", " ")
  1732. if err != nil {
  1733. return false, err
  1734. }
  1735. inbound.Settings = string(modifiedSettings)
  1736. needRestart, err := s.UpdateInboundClient(inboundSvc, inbound, clientId)
  1737. return needRestart, err
  1738. }
  1739. func (s *ClientService) ResetClientTrafficLimitByEmail(inboundSvc *InboundService, clientEmail string, totalGB int) (bool, error) {
  1740. if totalGB < 0 {
  1741. return false, common.NewError("totalGB must be >= 0")
  1742. }
  1743. _, inbound, err := inboundSvc.GetClientInboundByEmail(clientEmail)
  1744. if err != nil {
  1745. return false, err
  1746. }
  1747. if inbound == nil {
  1748. return false, common.NewError("Inbound Not Found For Email:", clientEmail)
  1749. }
  1750. oldClients, err := inboundSvc.GetClients(inbound)
  1751. if err != nil {
  1752. return false, err
  1753. }
  1754. clientId := ""
  1755. for _, oldClient := range oldClients {
  1756. if oldClient.Email == clientEmail {
  1757. switch inbound.Protocol {
  1758. case "trojan":
  1759. clientId = oldClient.Password
  1760. case "shadowsocks":
  1761. clientId = oldClient.Email
  1762. default:
  1763. clientId = oldClient.ID
  1764. }
  1765. break
  1766. }
  1767. }
  1768. if len(clientId) == 0 {
  1769. return false, common.NewError("Client Not Found For Email:", clientEmail)
  1770. }
  1771. var settings map[string]any
  1772. err = json.Unmarshal([]byte(inbound.Settings), &settings)
  1773. if err != nil {
  1774. return false, err
  1775. }
  1776. clients := settings["clients"].([]any)
  1777. var newClients []any
  1778. for client_index := range clients {
  1779. c := clients[client_index].(map[string]any)
  1780. if c["email"] == clientEmail {
  1781. c["totalGB"] = totalGB * 1024 * 1024 * 1024
  1782. c["updated_at"] = time.Now().Unix() * 1000
  1783. newClients = append(newClients, any(c))
  1784. }
  1785. }
  1786. settings["clients"] = newClients
  1787. modifiedSettings, err := json.MarshalIndent(settings, "", " ")
  1788. if err != nil {
  1789. return false, err
  1790. }
  1791. inbound.Settings = string(modifiedSettings)
  1792. needRestart, err := s.UpdateInboundClient(inboundSvc, inbound, clientId)
  1793. return needRestart, err
  1794. }