setting.go 31 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519520521522523524525526527528529530531532533534535536537538539540541542543544545546547548549550551552553554555556557558559560561562563564565566567568569570571572573574575576577578579580581582583584585586587588589590591592593594595596597598599600601602603604605606607608609610611612613614615616617618619620621622623624625626627628629630631632633634635636637638639640641642643644645646647648649650651652653654655656657658659660661662663664665666667668669670671672673674675676677678679680681682683684685686687688689690691692693694695696697698699700701702703704705706707708709710711712713714715716717718719720721722723724725726727728729730731732733734735736737738739740741742743744745746747748749750751752753754755756757758759760761762763764765766767768769770771772773774775776777778779780781782783784785786787788789790791792793794795796797798799800801802803804805806807808809810811812813814815816817818819820821822823824825826827828829830831832833834835836837838839840841842843844845846847848849850851852853854855856857858859860861862863864865866867868869870871872873874875876877878879880881882883884885886887888889890891892893894895896897898899900901902903904905906907908909910911912913914915916917918919920921922923924925926927928929930931932933934935936937938939940941942943944945946947948949950951952953954955956957958959960961962963964965966967968969970971972973974975976977978979980981982983984985986987988989990991992993994995996997998999100010011002100310041005100610071008100910101011101210131014101510161017101810191020102110221023102410251026102710281029103010311032103310341035103610371038103910401041104210431044104510461047104810491050105110521053105410551056105710581059106010611062106310641065106610671068106910701071107210731074107510761077107810791080108110821083108410851086108710881089109010911092109310941095109610971098109911001101110211031104110511061107110811091110111111121113111411151116111711181119112011211122
  1. package service
  2. import (
  3. _ "embed"
  4. "encoding/json"
  5. "errors"
  6. "fmt"
  7. "net"
  8. "net/http"
  9. "os"
  10. "reflect"
  11. "strconv"
  12. "strings"
  13. "time"
  14. "github.com/google/uuid"
  15. "github.com/mhsanaei/3x-ui/v3/internal/database"
  16. "github.com/mhsanaei/3x-ui/v3/internal/database/model"
  17. "github.com/mhsanaei/3x-ui/v3/internal/logger"
  18. "github.com/mhsanaei/3x-ui/v3/internal/util/common"
  19. "github.com/mhsanaei/3x-ui/v3/internal/util/netproxy"
  20. "github.com/mhsanaei/3x-ui/v3/internal/util/random"
  21. "github.com/mhsanaei/3x-ui/v3/internal/util/reflect_util"
  22. "github.com/mhsanaei/3x-ui/v3/internal/web/entity"
  23. "github.com/mhsanaei/3x-ui/v3/internal/xray"
  24. )
  25. //go:embed config.json
  26. var xrayTemplateConfig string
  27. var defaultValueMap = map[string]string{
  28. "xrayTemplateConfig": xrayTemplateConfig,
  29. "webListen": "",
  30. "webDomain": "",
  31. "webPort": "2053",
  32. "webCertFile": "",
  33. "webKeyFile": "",
  34. "secret": random.Seq(32),
  35. "panelGuid": uuid.NewString(),
  36. "apiToken": "",
  37. "webBasePath": normalizeBasePath(getEnv("XUI_INIT_WEB_BASE_PATH", "/")),
  38. "sessionMaxAge": "360",
  39. "trustedProxyCIDRs": "127.0.0.1/32,::1/128",
  40. "pageSize": "25",
  41. "expireDiff": "0",
  42. "trafficDiff": "0",
  43. "remarkModel": "-ieo",
  44. "timeLocation": "Local",
  45. "tgBotEnable": "false",
  46. "tgBotToken": "",
  47. "tgBotProxy": "",
  48. "tgBotAPIServer": "",
  49. "tgBotChatId": "",
  50. "tgRunTime": "@daily",
  51. "tgBotBackup": "false",
  52. "tgBotLoginNotify": "true",
  53. "tgCpu": "80",
  54. "tgLang": "en-US",
  55. "twoFactorEnable": "false",
  56. "twoFactorToken": "",
  57. "subEnable": "true",
  58. "subJsonEnable": "false",
  59. "subTitle": "",
  60. "subSupportUrl": "",
  61. "subProfileUrl": "",
  62. "subAnnounce": "",
  63. "subEnableRouting": "false",
  64. "subRoutingRules": "",
  65. "subListen": "",
  66. "subPort": "2096",
  67. "subPath": "/sub/",
  68. "subDomain": "",
  69. "subCertFile": "",
  70. "subKeyFile": "",
  71. "subUpdates": "12",
  72. "subEncrypt": "true",
  73. "subShowInfo": "true",
  74. "subEmailInRemark": "true",
  75. "subURI": "",
  76. "subJsonPath": "/json/",
  77. "subJsonURI": "",
  78. "subClashEnable": "false",
  79. "subClashPath": "/clash/",
  80. "subClashURI": "",
  81. "subClashEnableRouting": "false",
  82. "subClashRules": "",
  83. "subJsonMux": "",
  84. "subJsonRules": "",
  85. "subJsonFinalMask": "",
  86. "subThemeDir": "",
  87. "datepicker": "gregorian",
  88. "warp": "",
  89. "warpUpdateInterval": "0",
  90. "nord": "",
  91. "externalTrafficInformEnable": "false",
  92. "externalTrafficInformURI": "",
  93. "restartXrayOnClientDisable": "true",
  94. "xrayOutboundTestUrl": "https://www.google.com/generate_204",
  95. "panelOutbound": "",
  96. // LDAP defaults
  97. "ldapEnable": "false",
  98. "ldapHost": "",
  99. "ldapPort": "389",
  100. "ldapUseTLS": "false",
  101. "ldapBindDN": "",
  102. "ldapPassword": "",
  103. "ldapBaseDN": "",
  104. "ldapUserFilter": "(objectClass=person)",
  105. "ldapUserAttr": "mail",
  106. "ldapVlessField": "vless_enabled",
  107. "ldapSyncCron": "@every 1m",
  108. "ldapFlagField": "",
  109. "ldapTruthyValues": "true,1,yes,on",
  110. "ldapInvertFlag": "false",
  111. "ldapInboundTags": "",
  112. "ldapAutoCreate": "false",
  113. "ldapAutoDelete": "false",
  114. "ldapDefaultTotalGB": "0",
  115. "ldapDefaultExpiryDays": "0",
  116. "ldapDefaultLimitIP": "0",
  117. }
  118. // SettingService provides business logic for application settings management.
  119. // It handles configuration storage, retrieval, and validation for all system settings.
  120. type SettingService struct{}
  121. func (s *SettingService) GetDefaultJSONConfig() (any, error) {
  122. var jsonData any
  123. err := json.Unmarshal([]byte(xrayTemplateConfig), &jsonData)
  124. if err != nil {
  125. return nil, err
  126. }
  127. return jsonData, nil
  128. }
  129. func (s *SettingService) GetAllSetting() (*entity.AllSetting, error) {
  130. db := database.GetDB()
  131. settings := make([]*model.Setting, 0)
  132. err := db.Model(model.Setting{}).Not("key = ?", "xrayTemplateConfig").Find(&settings).Error
  133. if err != nil {
  134. return nil, err
  135. }
  136. allSetting := &entity.AllSetting{}
  137. t := reflect.TypeFor[entity.AllSetting]()
  138. v := reflect.ValueOf(allSetting).Elem()
  139. fields := reflect_util.GetFields(t)
  140. setSetting := func(key, value string) (err error) {
  141. defer func() {
  142. panicErr := recover()
  143. if panicErr != nil {
  144. err = errors.New(fmt.Sprint(panicErr))
  145. }
  146. }()
  147. var found bool
  148. var field reflect.StructField
  149. for _, f := range fields {
  150. if f.Tag.Get("json") == key {
  151. field = f
  152. found = true
  153. break
  154. }
  155. }
  156. if !found {
  157. // Some settings are automatically generated, no need to return to the front end to modify the user
  158. return nil
  159. }
  160. fieldV := v.FieldByName(field.Name)
  161. switch t := fieldV.Interface().(type) {
  162. case int:
  163. n, err := strconv.ParseInt(effectiveSettingValue(key, value), 10, 64)
  164. if err != nil {
  165. return err
  166. }
  167. fieldV.SetInt(n)
  168. case string:
  169. fieldV.SetString(value)
  170. case bool:
  171. fieldV.SetBool(effectiveSettingValue(key, value) == "true")
  172. default:
  173. return common.NewErrorf("unknown field %v type %v", key, t)
  174. }
  175. return
  176. }
  177. keyMap := map[string]bool{}
  178. for _, setting := range settings {
  179. err := setSetting(setting.Key, setting.Value)
  180. if err != nil {
  181. return nil, err
  182. }
  183. keyMap[setting.Key] = true
  184. }
  185. for key, value := range defaultValueMap {
  186. if keyMap[key] {
  187. continue
  188. }
  189. err := setSetting(key, value)
  190. if err != nil {
  191. return nil, err
  192. }
  193. }
  194. return allSetting, nil
  195. }
  196. func (s *SettingService) GetAllSettingView() (*entity.AllSettingView, error) {
  197. allSetting, err := s.GetAllSetting()
  198. if err != nil {
  199. return nil, err
  200. }
  201. view := &entity.AllSettingView{AllSetting: *allSetting}
  202. view.HasTgBotToken = secretConfigured(allSetting.TgBotToken)
  203. view.HasTwoFactorToken = secretConfigured(allSetting.TwoFactorToken)
  204. view.HasLdapPassword = secretConfigured(allSetting.LdapPassword)
  205. view.HasWarpSecret = secretConfigured(mustString(s.GetWarp()))
  206. view.HasNordSecret = secretConfigured(mustString(s.GetNord()))
  207. var apiTokenCount int64
  208. if err := database.GetDB().Model(model.ApiToken{}).Where("enabled = ?", true).Count(&apiTokenCount).Error; err == nil {
  209. view.HasApiToken = apiTokenCount > 0
  210. }
  211. view.TgBotToken = ""
  212. view.TwoFactorToken = ""
  213. view.LdapPassword = ""
  214. return view, nil
  215. }
  216. func secretConfigured(value string) bool {
  217. return strings.TrimSpace(value) != ""
  218. }
  219. func mustString(value string, _ error) string {
  220. return value
  221. }
  222. func getEnv(key, fallback string) string {
  223. val, ok := os.LookupEnv(key)
  224. if !ok {
  225. return fallback
  226. }
  227. val = strings.TrimSpace(val)
  228. if val == "" {
  229. return fallback
  230. }
  231. return val
  232. }
  233. func (s *SettingService) ResetSettings() error {
  234. db := database.GetDB()
  235. err := db.Where("1 = 1").Delete(model.Setting{}).Error
  236. if err != nil {
  237. return err
  238. }
  239. return db.Model(model.User{}).
  240. Where("1 = 1").Error
  241. }
  242. func (s *SettingService) getSetting(key string) (*model.Setting, error) {
  243. db := database.GetDB()
  244. setting := &model.Setting{}
  245. err := db.Model(model.Setting{}).Where("key = ?", key).First(setting).Error
  246. if err != nil {
  247. return nil, err
  248. }
  249. return setting, nil
  250. }
  251. func (s *SettingService) saveSetting(key string, value string) error {
  252. setting, err := s.getSetting(key)
  253. db := database.GetDB()
  254. if database.IsNotFound(err) {
  255. return db.Create(&model.Setting{
  256. Key: key,
  257. Value: value,
  258. }).Error
  259. } else if err != nil {
  260. return err
  261. }
  262. setting.Key = key
  263. setting.Value = value
  264. return db.Save(setting).Error
  265. }
  266. func (s *SettingService) getString(key string) (string, error) {
  267. setting, err := s.getSetting(key)
  268. if database.IsNotFound(err) {
  269. value, ok := defaultValueMap[key]
  270. if !ok {
  271. return "", common.NewErrorf("key <%v> not in defaultValueMap", key)
  272. }
  273. return value, nil
  274. } else if err != nil {
  275. return "", err
  276. }
  277. return setting.Value, nil
  278. }
  279. func (s *SettingService) setString(key string, value string) error {
  280. return s.saveSetting(key, value)
  281. }
  282. func effectiveSettingValue(key, stored string) string {
  283. if stored == "" {
  284. if def, ok := defaultValueMap[key]; ok {
  285. return def
  286. }
  287. }
  288. return stored
  289. }
  290. func (s *SettingService) getBool(key string) (bool, error) {
  291. str, err := s.getString(key)
  292. if err != nil {
  293. return false, err
  294. }
  295. return strconv.ParseBool(effectiveSettingValue(key, str))
  296. }
  297. func (s *SettingService) setBool(key string, value bool) error {
  298. return s.setString(key, strconv.FormatBool(value))
  299. }
  300. func (s *SettingService) getInt(key string) (int, error) {
  301. str, err := s.getString(key)
  302. if err != nil {
  303. return 0, err
  304. }
  305. return strconv.Atoi(effectiveSettingValue(key, str))
  306. }
  307. func (s *SettingService) setInt(key string, value int) error {
  308. return s.setString(key, strconv.Itoa(value))
  309. }
  310. func (s *SettingService) GetWarpLastUpdate() (int64, error) {
  311. val, err := s.getString("warpLastUpdate")
  312. if err != nil || val == "" {
  313. return 0, err
  314. }
  315. return strconv.ParseInt(val, 10, 64)
  316. }
  317. func (s *SettingService) SetWarpLastUpdate(val int64) error {
  318. return s.saveSetting("warpLastUpdate", strconv.FormatInt(val, 10))
  319. }
  320. func (s *SettingService) SetWarpUpdateInterval(val int) error {
  321. return s.setInt("warpUpdateInterval", val)
  322. }
  323. func (s *SettingService) GetXrayConfigTemplate() (string, error) {
  324. return s.getString("xrayTemplateConfig")
  325. }
  326. func (s *SettingService) GetXrayOutboundTestUrl() (string, error) {
  327. return s.getString("xrayOutboundTestUrl")
  328. }
  329. func (s *SettingService) SetXrayOutboundTestUrl(url string) error {
  330. clean, err := SanitizeHTTPURL(url)
  331. if err != nil {
  332. return err
  333. }
  334. return s.setString("xrayOutboundTestUrl", clean)
  335. }
  336. func (s *SettingService) GetListen() (string, error) {
  337. return s.getString("webListen")
  338. }
  339. func (s *SettingService) SetListen(ip string) error {
  340. return s.setString("webListen", ip)
  341. }
  342. func (s *SettingService) GetWebDomain() (string, error) {
  343. return s.getString("webDomain")
  344. }
  345. func (s *SettingService) GetTgBotToken() (string, error) {
  346. return s.getString("tgBotToken")
  347. }
  348. func (s *SettingService) SetTgBotToken(token string) error {
  349. return s.setString("tgBotToken", token)
  350. }
  351. func (s *SettingService) GetTgBotProxy() (string, error) {
  352. return s.getString("tgBotProxy")
  353. }
  354. func (s *SettingService) SetTgBotProxy(token string) error {
  355. return s.setString("tgBotProxy", token)
  356. }
  357. // GetPanelOutbound returns the Xray outbound tag the panel's own outbound
  358. // requests (version checks, Telegram, subscription fetches) are routed through.
  359. func (s *SettingService) GetPanelOutbound() (string, error) {
  360. return s.getString("panelOutbound")
  361. }
  362. func (s *SettingService) SetPanelOutbound(tag string) error {
  363. return s.setString("panelOutbound", tag)
  364. }
  365. // PanelEgressProxyURL resolves the loopback SOCKS bridge that the generated
  366. // config exposes when a panel outbound is configured (see injectPanelEgress).
  367. // It returns "" — meaning a direct connection — when the feature is off or
  368. // the bridge is not present in the running core yet.
  369. func (s *SettingService) PanelEgressProxyURL() string {
  370. tag, err := s.GetPanelOutbound()
  371. if err != nil || tag == "" {
  372. return ""
  373. }
  374. proc := XrayProcess()
  375. if proc == nil || !proc.IsRunning() {
  376. logger.Warning("panel outbound [", tag, "] is set but Xray is not running, using a direct connection")
  377. return ""
  378. }
  379. cfg := proc.GetConfig()
  380. if cfg == nil {
  381. return ""
  382. }
  383. for i := range cfg.InboundConfigs {
  384. if cfg.InboundConfigs[i].Tag == PanelEgressInboundTag {
  385. return fmt.Sprintf("socks5://127.0.0.1:%d", cfg.InboundConfigs[i].Port)
  386. }
  387. }
  388. logger.Warning("panel outbound [", tag, "] is set but the egress bridge is not in the running config, using a direct connection")
  389. return ""
  390. }
  391. func (s *SettingService) NodeEgressProxyURL(nodeID int) string {
  392. tag := NodeEgressInboundTag(nodeID)
  393. proc := XrayProcess()
  394. if proc == nil || !proc.IsRunning() {
  395. logger.Warning("node outbound [", tag, "] is set but Xray is not running, using a direct connection")
  396. return ""
  397. }
  398. cfg := proc.GetConfig()
  399. if cfg == nil {
  400. return ""
  401. }
  402. for i := range cfg.InboundConfigs {
  403. if cfg.InboundConfigs[i].Tag == tag {
  404. return fmt.Sprintf("socks5://127.0.0.1:%d", cfg.InboundConfigs[i].Port)
  405. }
  406. }
  407. logger.Warning("node outbound [", tag, "] is set but the egress bridge is not in the running config, using a direct connection")
  408. return ""
  409. }
  410. // NewProxiedHTTPClient returns an HTTP client that routes the panel's own
  411. // outbound requests through the configured panel outbound (via the loopback
  412. // SOCKS bridge in the running Xray). When the feature is off or the bridge
  413. // is unavailable it falls back to a direct client.
  414. func (s *SettingService) NewProxiedHTTPClient(timeout time.Duration) *http.Client {
  415. proxyUrl := s.PanelEgressProxyURL()
  416. client, err := netproxy.NewHTTPClient(proxyUrl, timeout)
  417. if err != nil {
  418. logger.Warningf("Invalid panel egress proxy %q, using direct connection: %v", proxyUrl, err)
  419. return &http.Client{Timeout: timeout}
  420. }
  421. return client
  422. }
  423. func (s *SettingService) GetTgBotAPIServer() (string, error) {
  424. return s.getString("tgBotAPIServer")
  425. }
  426. func (s *SettingService) SetTgBotAPIServer(token string) error {
  427. return s.setString("tgBotAPIServer", token)
  428. }
  429. func (s *SettingService) GetTgBotChatId() (string, error) {
  430. return s.getString("tgBotChatId")
  431. }
  432. func (s *SettingService) SetTgBotChatId(chatIds string) error {
  433. return s.setString("tgBotChatId", chatIds)
  434. }
  435. func (s *SettingService) GetTgbotEnabled() (bool, error) {
  436. return s.getBool("tgBotEnable")
  437. }
  438. func (s *SettingService) SetTgbotEnabled(value bool) error {
  439. return s.setBool("tgBotEnable", value)
  440. }
  441. func (s *SettingService) GetTgbotRuntime() (string, error) {
  442. return s.getString("tgRunTime")
  443. }
  444. func (s *SettingService) SetTgbotRuntime(time string) error {
  445. return s.setString("tgRunTime", time)
  446. }
  447. func (s *SettingService) GetTgBotBackup() (bool, error) {
  448. return s.getBool("tgBotBackup")
  449. }
  450. func (s *SettingService) GetTgBotLoginNotify() (bool, error) {
  451. return s.getBool("tgBotLoginNotify")
  452. }
  453. func (s *SettingService) GetTgCpu() (int, error) {
  454. return s.getInt("tgCpu")
  455. }
  456. func (s *SettingService) GetTgLang() (string, error) {
  457. return s.getString("tgLang")
  458. }
  459. func (s *SettingService) GetTwoFactorEnable() (bool, error) {
  460. return s.getBool("twoFactorEnable")
  461. }
  462. func (s *SettingService) SetTwoFactorEnable(value bool) error {
  463. return s.setBool("twoFactorEnable", value)
  464. }
  465. func (s *SettingService) GetTwoFactorToken() (string, error) {
  466. return s.getString("twoFactorToken")
  467. }
  468. func (s *SettingService) SetTwoFactorToken(value string) error {
  469. return s.setString("twoFactorToken", value)
  470. }
  471. func (s *SettingService) GetPort() (int, error) {
  472. return s.getInt("webPort")
  473. }
  474. func (s *SettingService) SetPort(port int) error {
  475. return s.setInt("webPort", port)
  476. }
  477. func (s *SettingService) SetCertFile(webCertFile string) error {
  478. return s.setString("webCertFile", webCertFile)
  479. }
  480. func (s *SettingService) GetCertFile() (string, error) {
  481. return s.getString("webCertFile")
  482. }
  483. func (s *SettingService) SetKeyFile(webKeyFile string) error {
  484. return s.setString("webKeyFile", webKeyFile)
  485. }
  486. func (s *SettingService) GetKeyFile() (string, error) {
  487. return s.getString("webKeyFile")
  488. }
  489. func (s *SettingService) GetExpireDiff() (int, error) {
  490. return s.getInt("expireDiff")
  491. }
  492. func (s *SettingService) GetTrafficDiff() (int, error) {
  493. return s.getInt("trafficDiff")
  494. }
  495. func (s *SettingService) GetSessionMaxAge() (int, error) {
  496. return s.getInt("sessionMaxAge")
  497. }
  498. func (s *SettingService) GetTrustedProxyCIDRs() (string, error) {
  499. return s.getString("trustedProxyCIDRs")
  500. }
  501. func (s *SettingService) GetRemarkModel() (string, error) {
  502. return s.getString("remarkModel")
  503. }
  504. func (s *SettingService) GetSecret() ([]byte, error) {
  505. secret, err := s.getString("secret")
  506. if secret == defaultValueMap["secret"] {
  507. err := s.saveSetting("secret", secret)
  508. if err != nil {
  509. logger.Warning("save secret failed:", err)
  510. }
  511. }
  512. return []byte(secret), err
  513. }
  514. // GetPanelGuid returns this panel's stable self-identifier, persisting a
  515. // freshly generated UUID on first read. It is the globally stable node
  516. // identity used to attribute online clients and inbounds to the physical
  517. // node that hosts them across a chain of nodes (#4983), where per-panel
  518. // autoincrement node ids are meaningless one hop away.
  519. func (s *SettingService) GetPanelGuid() (string, error) {
  520. guid, err := s.getString("panelGuid")
  521. if err != nil {
  522. return "", err
  523. }
  524. if guid == defaultValueMap["panelGuid"] {
  525. if saveErr := s.saveSetting("panelGuid", guid); saveErr != nil {
  526. logger.Warning("save panelGuid failed:", saveErr)
  527. }
  528. }
  529. return guid, nil
  530. }
  531. func (s *SettingService) SetBasePath(basePath string) error {
  532. if !strings.HasPrefix(basePath, "/") {
  533. basePath = "/" + basePath
  534. }
  535. if !strings.HasSuffix(basePath, "/") {
  536. basePath += "/"
  537. }
  538. return s.setString("webBasePath", basePath)
  539. }
  540. func (s *SettingService) GetBasePath() (string, error) {
  541. basePath, err := s.getString("webBasePath")
  542. if err != nil {
  543. return "", err
  544. }
  545. return normalizeBasePath(basePath), nil
  546. }
  547. func (s *SettingService) GetTimeLocation() (*time.Location, error) {
  548. l, err := s.getString("timeLocation")
  549. if err != nil {
  550. return nil, err
  551. }
  552. location, err := time.LoadLocation(l)
  553. if err != nil {
  554. defaultLocation := defaultValueMap["timeLocation"]
  555. logger.Errorf("location <%v> not exist, using default location: %v", l, defaultLocation)
  556. location, err = time.LoadLocation(defaultLocation)
  557. if err != nil {
  558. logger.Errorf("failed to load default location, using UTC: %v", err)
  559. return time.UTC, nil
  560. }
  561. return location, nil
  562. }
  563. return location, nil
  564. }
  565. func (s *SettingService) GetSubEnable() (bool, error) {
  566. return s.getBool("subEnable")
  567. }
  568. func (s *SettingService) GetSubJsonEnable() (bool, error) {
  569. return s.getBool("subJsonEnable")
  570. }
  571. func (s *SettingService) GetSubTitle() (string, error) {
  572. return s.getString("subTitle")
  573. }
  574. func (s *SettingService) GetSubSupportUrl() (string, error) {
  575. return s.getString("subSupportUrl")
  576. }
  577. func (s *SettingService) GetSubProfileUrl() (string, error) {
  578. return s.getString("subProfileUrl")
  579. }
  580. func (s *SettingService) GetSubAnnounce() (string, error) {
  581. return s.getString("subAnnounce")
  582. }
  583. func (s *SettingService) GetSubEnableRouting() (bool, error) {
  584. return s.getBool("subEnableRouting")
  585. }
  586. func (s *SettingService) GetSubRoutingRules() (string, error) {
  587. return s.getString("subRoutingRules")
  588. }
  589. func (s *SettingService) GetSubListen() (string, error) {
  590. return s.getString("subListen")
  591. }
  592. func (s *SettingService) GetSubPort() (int, error) {
  593. return s.getInt("subPort")
  594. }
  595. func (s *SettingService) GetSubPath() (string, error) {
  596. return s.getString("subPath")
  597. }
  598. func (s *SettingService) GetSubJsonPath() (string, error) {
  599. return s.getString("subJsonPath")
  600. }
  601. func (s *SettingService) GetSubDomain() (string, error) {
  602. return s.getString("subDomain")
  603. }
  604. func (s *SettingService) SetSubCertFile(subCertFile string) error {
  605. return s.setString("subCertFile", subCertFile)
  606. }
  607. func (s *SettingService) GetSubCertFile() (string, error) {
  608. return s.getString("subCertFile")
  609. }
  610. func (s *SettingService) SetSubKeyFile(subKeyFile string) error {
  611. return s.setString("subKeyFile", subKeyFile)
  612. }
  613. func (s *SettingService) GetSubKeyFile() (string, error) {
  614. return s.getString("subKeyFile")
  615. }
  616. func (s *SettingService) GetSubUpdates() (string, error) {
  617. return s.getString("subUpdates")
  618. }
  619. func (s *SettingService) GetSubEncrypt() (bool, error) {
  620. return s.getBool("subEncrypt")
  621. }
  622. func (s *SettingService) GetSubShowInfo() (bool, error) {
  623. return s.getBool("subShowInfo")
  624. }
  625. func (s *SettingService) GetSubEmailInRemark() (bool, error) {
  626. return s.getBool("subEmailInRemark")
  627. }
  628. func (s *SettingService) GetPageSize() (int, error) {
  629. return s.getInt("pageSize")
  630. }
  631. func (s *SettingService) GetSubURI() (string, error) {
  632. return s.getString("subURI")
  633. }
  634. func (s *SettingService) GetSubJsonURI() (string, error) {
  635. return s.getString("subJsonURI")
  636. }
  637. func (s *SettingService) GetSubClashEnable() (bool, error) {
  638. return s.getBool("subClashEnable")
  639. }
  640. func (s *SettingService) GetSubClashPath() (string, error) {
  641. return s.getString("subClashPath")
  642. }
  643. func (s *SettingService) GetSubClashURI() (string, error) {
  644. return s.getString("subClashURI")
  645. }
  646. func (s *SettingService) GetSubClashEnableRouting() (bool, error) {
  647. return s.getBool("subClashEnableRouting")
  648. }
  649. func (s *SettingService) GetSubClashRules() (string, error) {
  650. return s.getString("subClashRules")
  651. }
  652. func (s *SettingService) GetSubJsonMux() (string, error) {
  653. return s.getString("subJsonMux")
  654. }
  655. func (s *SettingService) GetSubJsonRules() (string, error) {
  656. return s.getString("subJsonRules")
  657. }
  658. func (s *SettingService) GetSubJsonFinalMask() (string, error) {
  659. return s.getString("subJsonFinalMask")
  660. }
  661. func (s *SettingService) GetSubThemeDir() (string, error) {
  662. return s.getString("subThemeDir")
  663. }
  664. func (s *SettingService) GetDatepicker() (string, error) {
  665. return s.getString("datepicker")
  666. }
  667. func (s *SettingService) GetWarp() (string, error) {
  668. return s.getString("warp")
  669. }
  670. func (s *SettingService) SetWarp(data string) error {
  671. return s.setString("warp", data)
  672. }
  673. func (s *SettingService) GetNord() (string, error) {
  674. return s.getString("nord")
  675. }
  676. func (s *SettingService) SetNord(data string) error {
  677. return s.setString("nord", data)
  678. }
  679. func (s *SettingService) GetExternalTrafficInformEnable() (bool, error) {
  680. return s.getBool("externalTrafficInformEnable")
  681. }
  682. func (s *SettingService) SetExternalTrafficInformEnable(value bool) error {
  683. return s.setBool("externalTrafficInformEnable", value)
  684. }
  685. func (s *SettingService) GetExternalTrafficInformURI() (string, error) {
  686. return s.getString("externalTrafficInformURI")
  687. }
  688. func (s *SettingService) SetExternalTrafficInformURI(InformURI string) error {
  689. return s.setString("externalTrafficInformURI", InformURI)
  690. }
  691. func (s *SettingService) GetRestartXrayOnClientDisable() (bool, error) {
  692. return s.getBool("restartXrayOnClientDisable")
  693. }
  694. func (s *SettingService) SetRestartXrayOnClientDisable(value bool) error {
  695. return s.setBool("restartXrayOnClientDisable", value)
  696. }
  697. // GetIpLimitEnable reports whether the IP-limit feature is available. Always
  698. // true since the panel enforces limits via the core's online-stats API; on an
  699. // older core the job falls back to access-log parsing and warns there when the
  700. // log is missing, so the UI no longer hides the field behind that condition.
  701. func (s *SettingService) GetIpLimitEnable() (bool, error) {
  702. return true, nil
  703. }
  704. // GetAccessLogEnable reports whether an Xray access log is configured. Used by
  705. // the UI for features that genuinely read the log file (the xray log viewer) —
  706. // distinct from IP limiting, which works without it.
  707. func (s *SettingService) GetAccessLogEnable() (bool, error) {
  708. accessLogPath, err := xray.GetAccessLogPath()
  709. if err != nil {
  710. return false, err
  711. }
  712. return (accessLogPath != "none" && accessLogPath != ""), nil
  713. }
  714. // GetLdapEnable returns whether LDAP is enabled.
  715. func (s *SettingService) GetLdapEnable() (bool, error) {
  716. return s.getBool("ldapEnable")
  717. }
  718. func (s *SettingService) GetLdapHost() (string, error) {
  719. return s.getString("ldapHost")
  720. }
  721. func (s *SettingService) GetLdapPort() (int, error) {
  722. return s.getInt("ldapPort")
  723. }
  724. func (s *SettingService) GetLdapUseTLS() (bool, error) {
  725. return s.getBool("ldapUseTLS")
  726. }
  727. func (s *SettingService) GetLdapBindDN() (string, error) {
  728. return s.getString("ldapBindDN")
  729. }
  730. func (s *SettingService) GetLdapPassword() (string, error) {
  731. return s.getString("ldapPassword")
  732. }
  733. func (s *SettingService) GetLdapBaseDN() (string, error) {
  734. return s.getString("ldapBaseDN")
  735. }
  736. func (s *SettingService) GetLdapUserFilter() (string, error) {
  737. return s.getString("ldapUserFilter")
  738. }
  739. func (s *SettingService) GetLdapUserAttr() (string, error) {
  740. return s.getString("ldapUserAttr")
  741. }
  742. func (s *SettingService) GetLdapVlessField() (string, error) {
  743. return s.getString("ldapVlessField")
  744. }
  745. func (s *SettingService) GetLdapSyncCron() (string, error) {
  746. return s.getString("ldapSyncCron")
  747. }
  748. func (s *SettingService) GetLdapFlagField() (string, error) {
  749. return s.getString("ldapFlagField")
  750. }
  751. func (s *SettingService) GetLdapTruthyValues() (string, error) {
  752. return s.getString("ldapTruthyValues")
  753. }
  754. func (s *SettingService) GetLdapInvertFlag() (bool, error) {
  755. return s.getBool("ldapInvertFlag")
  756. }
  757. func (s *SettingService) GetLdapInboundTags() (string, error) {
  758. return s.getString("ldapInboundTags")
  759. }
  760. func (s *SettingService) GetLdapAutoCreate() (bool, error) {
  761. return s.getBool("ldapAutoCreate")
  762. }
  763. func (s *SettingService) GetLdapAutoDelete() (bool, error) {
  764. return s.getBool("ldapAutoDelete")
  765. }
  766. func (s *SettingService) GetLdapDefaultTotalGB() (int, error) {
  767. return s.getInt("ldapDefaultTotalGB")
  768. }
  769. func (s *SettingService) GetLdapDefaultExpiryDays() (int, error) {
  770. return s.getInt("ldapDefaultExpiryDays")
  771. }
  772. func (s *SettingService) GetLdapDefaultLimitIP() (int, error) {
  773. return s.getInt("ldapDefaultLimitIP")
  774. }
  775. func (s *SettingService) UpdateAllSetting(allSetting *entity.AllSetting) error {
  776. if err := s.preserveRedactedSecrets(allSetting); err != nil {
  777. return err
  778. }
  779. if err := validateSettingsURLs(allSetting); err != nil {
  780. return err
  781. }
  782. if err := allSetting.CheckValid(); err != nil {
  783. return err
  784. }
  785. v := reflect.ValueOf(allSetting).Elem()
  786. t := reflect.TypeFor[entity.AllSetting]()
  787. fields := reflect_util.GetFields(t)
  788. errs := make([]error, 0)
  789. for _, field := range fields {
  790. key := field.Tag.Get("json")
  791. fieldV := v.FieldByName(field.Name)
  792. value := fmt.Sprint(fieldV.Interface())
  793. err := s.saveSetting(key, value)
  794. if err != nil {
  795. errs = append(errs, err)
  796. }
  797. }
  798. return common.Combine(errs...)
  799. }
  800. func (s *SettingService) preserveRedactedSecrets(allSetting *entity.AllSetting) error {
  801. if strings.TrimSpace(allSetting.TgBotToken) == "" {
  802. value, err := s.GetTgBotToken()
  803. if err != nil {
  804. return err
  805. }
  806. allSetting.TgBotToken = value
  807. }
  808. if strings.TrimSpace(allSetting.LdapPassword) == "" {
  809. value, err := s.GetLdapPassword()
  810. if err != nil {
  811. return err
  812. }
  813. allSetting.LdapPassword = value
  814. }
  815. if allSetting.TwoFactorEnable && strings.TrimSpace(allSetting.TwoFactorToken) == "" {
  816. value, err := s.GetTwoFactorToken()
  817. if err != nil {
  818. return err
  819. }
  820. allSetting.TwoFactorToken = value
  821. }
  822. return nil
  823. }
  824. func validateSettingsURLs(allSetting *entity.AllSetting) error {
  825. if allSetting.ExternalTrafficInformURI != "" {
  826. u, err := SanitizeHTTPURL(allSetting.ExternalTrafficInformURI)
  827. if err != nil {
  828. return common.NewError("external traffic inform URI is invalid:", err)
  829. }
  830. allSetting.ExternalTrafficInformURI = u
  831. }
  832. if allSetting.TgBotAPIServer != "" {
  833. u, err := SanitizeHTTPURL(allSetting.TgBotAPIServer)
  834. if err != nil {
  835. return common.NewError("telegram API server URL is invalid:", err)
  836. }
  837. allSetting.TgBotAPIServer = u
  838. }
  839. return nil
  840. }
  841. func (s *SettingService) UpdateSecret(key string, value string) error {
  842. switch key {
  843. case "tgBotToken", "ldapPassword", "twoFactorToken":
  844. return s.saveSetting(key, strings.TrimSpace(value))
  845. default:
  846. return common.NewError("secret key is not replaceable:", key)
  847. }
  848. }
  849. func (s *SettingService) GetDefaultXrayConfig() (any, error) {
  850. var jsonData any
  851. err := json.Unmarshal([]byte(xrayTemplateConfig), &jsonData)
  852. if err != nil {
  853. return nil, err
  854. }
  855. return jsonData, nil
  856. }
  857. func extractHostname(host string) string {
  858. h, _, err := net.SplitHostPort(host)
  859. // Err is not nil means host does not contain port
  860. if err != nil {
  861. h = host
  862. }
  863. ip := net.ParseIP(h)
  864. // If it's not an IP, return as is
  865. if ip == nil {
  866. return h
  867. }
  868. // If it's an IPv4, return as is
  869. if ip.To4() != nil {
  870. return h
  871. }
  872. // IPv6 needs bracketing
  873. return "[" + h + "]"
  874. }
  875. // BuildSubURIBase is shared by GetDefaultSettings (the panel's Client
  876. // Information page) and the subscription page so both render subscription
  877. // URLs identically.
  878. func (s *SettingService) BuildSubURIBase(host string) string {
  879. subPort, _ := s.GetSubPort()
  880. subDomain, _ := s.GetSubDomain()
  881. subKeyFile, _ := s.GetSubKeyFile()
  882. subCertFile, _ := s.GetSubCertFile()
  883. subTLS := subKeyFile != "" && subCertFile != ""
  884. if subDomain == "" {
  885. subDomain = extractHostname(host)
  886. }
  887. scheme := "http"
  888. if subTLS {
  889. scheme = "https"
  890. }
  891. if (subPort == 443 && subTLS) || (subPort == 80 && !subTLS) {
  892. return scheme + "://" + subDomain
  893. }
  894. return fmt.Sprintf("%s://%s:%d", scheme, subDomain, subPort)
  895. }
  896. func (s *SettingService) GetDefaultSettings(host string) (any, error) {
  897. type settingFunc func() (any, error)
  898. settings := map[string]settingFunc{
  899. "expireDiff": func() (any, error) { return s.GetExpireDiff() },
  900. "trafficDiff": func() (any, error) { return s.GetTrafficDiff() },
  901. "pageSize": func() (any, error) { return s.GetPageSize() },
  902. "defaultCert": func() (any, error) { return s.GetCertFile() },
  903. "defaultKey": func() (any, error) { return s.GetKeyFile() },
  904. "tgBotEnable": func() (any, error) { return s.GetTgbotEnabled() },
  905. "subThemeDir": func() (any, error) { return s.GetSubThemeDir() },
  906. "subEnable": func() (any, error) { return s.GetSubEnable() },
  907. "subJsonEnable": func() (any, error) { return s.GetSubJsonEnable() },
  908. "subClashEnable": func() (any, error) { return s.GetSubClashEnable() },
  909. "subTitle": func() (any, error) { return s.GetSubTitle() },
  910. "subURI": func() (any, error) { return s.GetSubURI() },
  911. "subJsonURI": func() (any, error) { return s.GetSubJsonURI() },
  912. "subClashURI": func() (any, error) { return s.GetSubClashURI() },
  913. "remarkModel": func() (any, error) { return s.GetRemarkModel() },
  914. "datepicker": func() (any, error) { return s.GetDatepicker() },
  915. "ipLimitEnable": func() (any, error) { return s.GetIpLimitEnable() },
  916. "accessLogEnable": func() (any, error) { return s.GetAccessLogEnable() },
  917. "webDomain": func() (any, error) { return s.GetWebDomain() },
  918. "subDomain": func() (any, error) { return s.GetSubDomain() },
  919. }
  920. result := make(map[string]any)
  921. for key, fn := range settings {
  922. value, err := fn()
  923. if err != nil {
  924. return "", err
  925. }
  926. result[key] = value
  927. }
  928. subEnable := result["subEnable"].(bool)
  929. subJsonEnable := false
  930. if v, ok := result["subJsonEnable"]; ok {
  931. if b, ok2 := v.(bool); ok2 {
  932. subJsonEnable = b
  933. }
  934. }
  935. subClashEnable := false
  936. if v, ok := result["subClashEnable"]; ok {
  937. if b, ok2 := v.(bool); ok2 {
  938. subClashEnable = b
  939. }
  940. }
  941. if (subEnable && result["subURI"].(string) == "") || (subJsonEnable && result["subJsonURI"].(string) == "") || (subClashEnable && result["subClashURI"].(string) == "") {
  942. subURI := s.BuildSubURIBase(host)
  943. subTitle, _ := s.GetSubTitle()
  944. subPath, _ := s.GetSubPath()
  945. subJsonPath, _ := s.GetSubJsonPath()
  946. subClashPath, _ := s.GetSubClashPath()
  947. if subEnable && result["subURI"].(string) == "" {
  948. result["subURI"] = subURI + subPath
  949. }
  950. if result["subTitle"].(string) == "" {
  951. result["subTitle"] = subTitle
  952. }
  953. if subJsonEnable && result["subJsonURI"].(string) == "" {
  954. result["subJsonURI"] = subURI + subJsonPath
  955. }
  956. if subClashEnable && result["subClashURI"].(string) == "" {
  957. result["subClashURI"] = subURI + subClashPath
  958. }
  959. }
  960. return result, nil
  961. }