web.go 13 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310311312313314315316317318319320321322323324325326327328329330331332333334335336337338339340341342343344345346347348349350351352353354355356357358359360361362363364365366367368369370371372373374375376377378379380381382383384385386387388389390391392393394395396397398399400401402403404405406407408409410411412413414415416417418419420421422423424425426427428429430431432433434435436437438439440441442443444445446447448449450451452453454455456457458459460461462463464465466467468469470471472473474475476477478479480481482483484485486487488489490491492493494495496497498499500501502503504505506507508509510511512513514515516517518519
  1. // Package web provides the main web server implementation for the 3x-ui panel,
  2. // including HTTP/HTTPS serving, routing, templates, and background job scheduling.
  3. package web
  4. import (
  5. "context"
  6. "crypto/tls"
  7. "embed"
  8. "html/template"
  9. "io"
  10. "io/fs"
  11. "net"
  12. "net/http"
  13. "os"
  14. "strconv"
  15. "strings"
  16. "time"
  17. "github.com/mhsanaei/3x-ui/v2/config"
  18. "github.com/mhsanaei/3x-ui/v2/logger"
  19. "github.com/mhsanaei/3x-ui/v2/util/common"
  20. "github.com/mhsanaei/3x-ui/v2/web/controller"
  21. "github.com/mhsanaei/3x-ui/v2/web/job"
  22. "github.com/mhsanaei/3x-ui/v2/web/locale"
  23. "github.com/mhsanaei/3x-ui/v2/web/middleware"
  24. "github.com/mhsanaei/3x-ui/v2/web/network"
  25. "github.com/mhsanaei/3x-ui/v2/web/service"
  26. "github.com/mhsanaei/3x-ui/v2/web/websocket"
  27. "github.com/gin-contrib/gzip"
  28. "github.com/gin-contrib/sessions"
  29. "github.com/gin-contrib/sessions/cookie"
  30. "github.com/gin-gonic/gin"
  31. "github.com/robfig/cron/v3"
  32. )
  33. //go:embed assets
  34. var assetsFS embed.FS
  35. //go:embed html/*
  36. var htmlFS embed.FS
  37. //go:embed translation/*
  38. var i18nFS embed.FS
  39. var startTime = time.Now()
  40. type wrapAssetsFS struct {
  41. embed.FS
  42. }
  43. func (f *wrapAssetsFS) Open(name string) (fs.File, error) {
  44. file, err := f.FS.Open("assets/" + name)
  45. if err != nil {
  46. return nil, err
  47. }
  48. return &wrapAssetsFile{
  49. File: file,
  50. }, nil
  51. }
  52. type wrapAssetsFile struct {
  53. fs.File
  54. }
  55. func (f *wrapAssetsFile) Stat() (fs.FileInfo, error) {
  56. info, err := f.File.Stat()
  57. if err != nil {
  58. return nil, err
  59. }
  60. return &wrapAssetsFileInfo{
  61. FileInfo: info,
  62. }, nil
  63. }
  64. type wrapAssetsFileInfo struct {
  65. fs.FileInfo
  66. }
  67. func (f *wrapAssetsFileInfo) ModTime() time.Time {
  68. return startTime
  69. }
  70. // EmbeddedHTML returns the embedded HTML templates filesystem for reuse by other servers.
  71. func EmbeddedHTML() embed.FS {
  72. return htmlFS
  73. }
  74. // EmbeddedAssets returns the embedded assets filesystem for reuse by other servers.
  75. func EmbeddedAssets() embed.FS {
  76. return assetsFS
  77. }
  78. // Server represents the main web server for the 3x-ui panel with controllers, services, and scheduled jobs.
  79. type Server struct {
  80. httpServer *http.Server
  81. listener net.Listener
  82. index *controller.IndexController
  83. panel *controller.XUIController
  84. api *controller.APIController
  85. ws *controller.WebSocketController
  86. xrayService service.XrayService
  87. settingService service.SettingService
  88. tgbotService service.Tgbot
  89. customGeoService *service.CustomGeoService
  90. wsHub *websocket.Hub
  91. cron *cron.Cron
  92. ctx context.Context
  93. cancel context.CancelFunc
  94. }
  95. // NewServer creates a new web server instance with a cancellable context.
  96. func NewServer() *Server {
  97. ctx, cancel := context.WithCancel(context.Background())
  98. return &Server{
  99. ctx: ctx,
  100. cancel: cancel,
  101. }
  102. }
  103. // getHtmlFiles walks the local `web/html` directory and returns a list of
  104. // template file paths. Used only in debug/development mode.
  105. func (s *Server) getHtmlFiles() ([]string, error) {
  106. files := make([]string, 0)
  107. dir, _ := os.Getwd()
  108. err := fs.WalkDir(os.DirFS(dir), "web/html", func(path string, d fs.DirEntry, err error) error {
  109. if err != nil {
  110. return err
  111. }
  112. if d.IsDir() {
  113. return nil
  114. }
  115. files = append(files, path)
  116. return nil
  117. })
  118. if err != nil {
  119. return nil, err
  120. }
  121. return files, nil
  122. }
  123. // getHtmlTemplate parses embedded HTML templates from the bundled `htmlFS`
  124. // using the provided template function map and returns the resulting
  125. // template set for production usage.
  126. func (s *Server) getHtmlTemplate(funcMap template.FuncMap) (*template.Template, error) {
  127. t := template.New("").Funcs(funcMap)
  128. err := fs.WalkDir(htmlFS, "html", func(path string, d fs.DirEntry, err error) error {
  129. if err != nil {
  130. return err
  131. }
  132. if d.IsDir() {
  133. newT, err := t.ParseFS(htmlFS, path+"/*.html")
  134. if err != nil {
  135. // ignore
  136. return nil
  137. }
  138. t = newT
  139. }
  140. return nil
  141. })
  142. if err != nil {
  143. return nil, err
  144. }
  145. return t, nil
  146. }
  147. func (s *Server) isDirectHTTPSConfigured() bool {
  148. certFile, certErr := s.settingService.GetCertFile()
  149. keyFile, keyErr := s.settingService.GetKeyFile()
  150. if certErr != nil || keyErr != nil || certFile == "" || keyFile == "" {
  151. return false
  152. }
  153. _, err := tls.LoadX509KeyPair(certFile, keyFile)
  154. return err == nil
  155. }
  156. // initRouter initializes Gin, registers middleware, templates, static
  157. // assets, controllers and returns the configured engine.
  158. func (s *Server) initRouter() (*gin.Engine, error) {
  159. if config.IsDebug() {
  160. gin.SetMode(gin.DebugMode)
  161. } else {
  162. gin.DefaultWriter = io.Discard
  163. gin.DefaultErrorWriter = io.Discard
  164. gin.SetMode(gin.ReleaseMode)
  165. }
  166. engine := gin.Default()
  167. directHTTPS := s.isDirectHTTPSConfigured()
  168. engine.Use(middleware.SecurityHeadersMiddleware(directHTTPS))
  169. webDomain, err := s.settingService.GetWebDomain()
  170. if err != nil {
  171. return nil, err
  172. }
  173. if webDomain != "" {
  174. engine.Use(middleware.DomainValidatorMiddleware(webDomain))
  175. }
  176. secret, err := s.settingService.GetSecret()
  177. if err != nil {
  178. return nil, err
  179. }
  180. basePath, err := s.settingService.GetBasePath()
  181. if err != nil {
  182. return nil, err
  183. }
  184. engine.Use(gzip.Gzip(gzip.DefaultCompression))
  185. assetsBasePath := basePath + "assets/"
  186. store := cookie.NewStore(secret)
  187. // Configure default session cookie options, including expiration (MaxAge)
  188. sessionOptions := sessions.Options{
  189. Path: basePath,
  190. HttpOnly: true,
  191. Secure: directHTTPS,
  192. SameSite: http.SameSiteLaxMode,
  193. }
  194. if sessionMaxAge, err := s.settingService.GetSessionMaxAge(); err == nil && sessionMaxAge > 0 {
  195. sessionOptions.MaxAge = sessionMaxAge * 60 // minutes -> seconds
  196. }
  197. store.Options(sessionOptions)
  198. engine.Use(sessions.Sessions("3x-ui", store))
  199. engine.Use(func(c *gin.Context) {
  200. c.Set("base_path", basePath)
  201. })
  202. engine.Use(func(c *gin.Context) {
  203. uri := c.Request.RequestURI
  204. if strings.HasPrefix(uri, assetsBasePath) {
  205. c.Header("Cache-Control", "max-age=31536000")
  206. }
  207. })
  208. // init i18n
  209. err = locale.InitLocalizer(i18nFS, &s.settingService)
  210. if err != nil {
  211. return nil, err
  212. }
  213. // Apply locale middleware for i18n
  214. i18nWebFunc := func(key string, params ...string) string {
  215. return locale.I18n(locale.Web, key, params...)
  216. }
  217. // Register template functions before loading templates
  218. funcMap := template.FuncMap{
  219. "i18n": i18nWebFunc,
  220. }
  221. engine.SetFuncMap(funcMap)
  222. engine.Use(locale.LocalizerMiddleware())
  223. // set static files and template
  224. if config.IsDebug() {
  225. // for development
  226. files, err := s.getHtmlFiles()
  227. if err != nil {
  228. return nil, err
  229. }
  230. // Use the registered func map with the loaded templates
  231. engine.LoadHTMLFiles(files...)
  232. engine.StaticFS(basePath+"assets", http.FS(os.DirFS("web/assets")))
  233. } else {
  234. // for production
  235. template, err := s.getHtmlTemplate(funcMap)
  236. if err != nil {
  237. return nil, err
  238. }
  239. engine.SetHTMLTemplate(template)
  240. engine.StaticFS(basePath+"assets", http.FS(&wrapAssetsFS{FS: assetsFS}))
  241. }
  242. // Apply the redirect middleware (`/xui` to `/panel`)
  243. engine.Use(middleware.RedirectMiddleware(basePath))
  244. g := engine.Group(basePath)
  245. s.index = controller.NewIndexController(g)
  246. s.panel = controller.NewXUIController(g)
  247. s.api = controller.NewAPIController(g, s.customGeoService)
  248. // Initialize WebSocket hub
  249. s.wsHub = websocket.NewHub()
  250. go s.wsHub.Run()
  251. // Initialize WebSocket controller
  252. s.ws = controller.NewWebSocketController(s.wsHub)
  253. // Register WebSocket route with basePath (g already has basePath prefix)
  254. g.GET("/ws", s.ws.HandleWebSocket)
  255. // Chrome DevTools endpoint for debugging web apps
  256. engine.GET("/.well-known/appspecific/com.chrome.devtools.json", func(c *gin.Context) {
  257. c.JSON(http.StatusOK, gin.H{})
  258. })
  259. // Add a catch-all route to handle undefined paths and return 404
  260. engine.NoRoute(func(c *gin.Context) {
  261. c.AbortWithStatus(http.StatusNotFound)
  262. })
  263. return engine, nil
  264. }
  265. // startTask schedules background jobs (Xray checks, traffic jobs, cron
  266. // jobs) which the panel relies on for periodic maintenance and monitoring.
  267. func (s *Server) startTask() {
  268. s.customGeoService.EnsureOnStartup()
  269. err := s.xrayService.RestartXray(true)
  270. if err != nil {
  271. logger.Warning("start xray failed:", err)
  272. }
  273. // Check whether xray is running every second
  274. s.cron.AddJob("@every 1s", job.NewCheckXrayRunningJob())
  275. // Check if xray needs to be restarted every 30 seconds
  276. s.cron.AddFunc("@every 30s", func() {
  277. if s.xrayService.IsNeedRestartAndSetFalse() {
  278. err := s.xrayService.RestartXray(false)
  279. if err != nil {
  280. logger.Error("restart xray failed:", err)
  281. }
  282. }
  283. })
  284. go func() {
  285. time.Sleep(time.Second * 5)
  286. // Statistics every 10 seconds, start the delay for 5 seconds for the first time, and staggered with the time to restart xray
  287. s.cron.AddJob("@every 10s", job.NewXrayTrafficJob())
  288. }()
  289. // check client ips from log file every 10 sec
  290. s.cron.AddJob("@every 10s", job.NewCheckClientIpJob())
  291. // check client ips from log file every day
  292. s.cron.AddJob("@daily", job.NewClearLogsJob())
  293. // Inbound traffic reset jobs
  294. // Run every hour
  295. s.cron.AddJob("@hourly", job.NewPeriodicTrafficResetJob("hourly"))
  296. // Run once a day, midnight
  297. s.cron.AddJob("@daily", job.NewPeriodicTrafficResetJob("daily"))
  298. // Run once a week, midnight between Sat/Sun
  299. s.cron.AddJob("@weekly", job.NewPeriodicTrafficResetJob("weekly"))
  300. // Run once a month, midnight, first of month
  301. s.cron.AddJob("@monthly", job.NewPeriodicTrafficResetJob("monthly"))
  302. // LDAP sync scheduling
  303. if ldapEnabled, _ := s.settingService.GetLdapEnable(); ldapEnabled {
  304. runtime, err := s.settingService.GetLdapSyncCron()
  305. if err != nil || runtime == "" {
  306. runtime = "@every 1m"
  307. }
  308. j := job.NewLdapSyncJob()
  309. // job has zero-value services with method receivers that read settings on demand
  310. s.cron.AddJob(runtime, j)
  311. }
  312. // Make a traffic condition every day, 8:30
  313. var entry cron.EntryID
  314. isTgbotenabled, err := s.settingService.GetTgbotEnabled()
  315. if (err == nil) && (isTgbotenabled) {
  316. runtime, err := s.settingService.GetTgbotRuntime()
  317. if err != nil {
  318. logger.Warningf("Add NewStatsNotifyJob: failed to load runtime: %v; using default @daily", err)
  319. runtime = "@daily"
  320. } else if strings.TrimSpace(runtime) == "" {
  321. logger.Warning("Add NewStatsNotifyJob runtime is empty, using default @daily")
  322. runtime = "@daily"
  323. }
  324. logger.Infof("Tg notify enabled,run at %s", runtime)
  325. _, err = s.cron.AddJob(runtime, job.NewStatsNotifyJob())
  326. if err != nil {
  327. logger.Warningf("Add NewStatsNotifyJob: failed to schedule runtime %q: %v", runtime, err)
  328. return
  329. }
  330. // check for Telegram bot callback query hash storage reset
  331. s.cron.AddJob("@every 2m", job.NewCheckHashStorageJob())
  332. // Check CPU load and alarm to TgBot if threshold passes
  333. cpuThreshold, err := s.settingService.GetTgCpu()
  334. if (err == nil) && (cpuThreshold > 0) {
  335. s.cron.AddJob("@every 10s", job.NewCheckCpuJob())
  336. }
  337. } else {
  338. s.cron.Remove(entry)
  339. }
  340. }
  341. // Start initializes and starts the web server with configured settings, routes, and background jobs.
  342. func (s *Server) Start() (err error) {
  343. // This is an anonymous function, no function name
  344. defer func() {
  345. if err != nil {
  346. s.Stop()
  347. }
  348. }()
  349. loc, err := s.settingService.GetTimeLocation()
  350. if err != nil {
  351. return err
  352. }
  353. s.cron = cron.New(cron.WithLocation(loc), cron.WithSeconds())
  354. s.cron.Start()
  355. s.customGeoService = service.NewCustomGeoService()
  356. engine, err := s.initRouter()
  357. if err != nil {
  358. return err
  359. }
  360. certFile, err := s.settingService.GetCertFile()
  361. if err != nil {
  362. return err
  363. }
  364. keyFile, err := s.settingService.GetKeyFile()
  365. if err != nil {
  366. return err
  367. }
  368. listen, err := s.settingService.GetListen()
  369. if err != nil {
  370. return err
  371. }
  372. port, err := s.settingService.GetPort()
  373. if err != nil {
  374. return err
  375. }
  376. listenAddr := net.JoinHostPort(listen, strconv.Itoa(port))
  377. listener, err := net.Listen("tcp", listenAddr)
  378. if err != nil {
  379. return err
  380. }
  381. if certFile != "" || keyFile != "" {
  382. cert, err := tls.LoadX509KeyPair(certFile, keyFile)
  383. if err == nil {
  384. c := &tls.Config{
  385. Certificates: []tls.Certificate{cert},
  386. }
  387. listener = network.NewAutoHttpsListener(listener)
  388. listener = tls.NewListener(listener, c)
  389. logger.Info("Web server running HTTPS on", listener.Addr())
  390. } else {
  391. logger.Error("Error loading certificates:", err)
  392. logger.Info("Web server running HTTP on", listener.Addr())
  393. }
  394. } else {
  395. logger.Info("Web server running HTTP on", listener.Addr())
  396. }
  397. s.listener = listener
  398. s.httpServer = &http.Server{
  399. Handler: engine,
  400. }
  401. go func() {
  402. s.httpServer.Serve(listener)
  403. }()
  404. s.startTask()
  405. isTgbotenabled, err := s.settingService.GetTgbotEnabled()
  406. if (err == nil) && (isTgbotenabled) {
  407. tgBot := s.tgbotService.NewTgbot()
  408. tgBot.Start(i18nFS)
  409. }
  410. return nil
  411. }
  412. // Stop gracefully shuts down the web server, stops Xray, cron jobs, and Telegram bot.
  413. func (s *Server) Stop() error {
  414. s.cancel()
  415. s.xrayService.StopXray()
  416. if s.cron != nil {
  417. s.cron.Stop()
  418. }
  419. if s.tgbotService.IsRunning() {
  420. s.tgbotService.Stop()
  421. }
  422. // Gracefully stop WebSocket hub
  423. if s.wsHub != nil {
  424. s.wsHub.Stop()
  425. }
  426. var err1 error
  427. var err2 error
  428. if s.httpServer != nil {
  429. err1 = s.httpServer.Shutdown(s.ctx)
  430. }
  431. if s.listener != nil {
  432. err2 = s.listener.Close()
  433. }
  434. return common.Combine(err1, err2)
  435. }
  436. // GetCtx returns the server's context for cancellation and deadline management.
  437. func (s *Server) GetCtx() context.Context {
  438. return s.ctx
  439. }
  440. // GetCron returns the server's cron scheduler instance.
  441. func (s *Server) GetCron() *cron.Cron {
  442. return s.cron
  443. }
  444. // GetWSHub returns the WebSocket hub instance.
  445. func (s *Server) GetWSHub() any {
  446. return s.wsHub
  447. }
  448. func (s *Server) RestartXray() error {
  449. return s.xrayService.RestartXray(true)
  450. }