txlyre

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • fb7418f7bd fix(mtproto): zero sidecar quotas only for clients whose usage was reset Invariant: the sidecar's quota counter for a client is zeroed exactly when the panel zeroes that client's usage. InboundService.ResetAllTraffics resets only inbound counters, yet it cleared every MTProto client's sidecar quota - on the master and, through its node propagation, on every node - handing out a fresh quota while the panel still counted the old usage. ResetAllClientTraffics for one inbound likewise cleared the quotas of MTProto clients on every other inbound. The inbound-level reset no longer touches sidecar quotas, and the per-inbound client reset zeroes only the clients it reset.
  • 4210a50cb4 fix(traffic): make a client reset reach every counter enforcing its quota Invariant: a client traffic reset zeroes every counter that enforces the client's quota - the master's, each hosting node's, and the local MTProto sidecar's. A node cuts a client on its own local counters, and the master adopts that verdict when both judged the same limits (#4917). Node counters: ResetClientTraffic tried the node once and dropped a failure ("nothing replays a reset"); BulkResetTraffic, ResetAllClientTraffics and ClientService.ResetAllTraffics never told the node at all. The node kept its pre-reset usage, switched the client off again on its next tick, and the master latched that - a client shown at zero usage stayed disabled. Every reset path now queues a node_pending_resets row per hosting node in its own transaction. It is delivered right after commit (per-client endpoint up to the push threshold, bulkResetTraffic above) and replayed by the node sync ahead of its snapshot, and dropped only once the node accepted it. While one is owed, the merge takes only that client's usage from the node, not its enable or limits. Deliveries to a node are serialized so a reset is not sent twice. Sidecar quota: BulkResetTraffic, ClientService.ResetAllTraffics and auto-renew zeroed the panel counters but not mtg's own quota counter, so the sidecar kept refusing a renewed or reset MTProto client. They now reset it too, scoped to the affected clients.
  • 7c84ca9689 fix(runtime): drop depleted clients by email, not by stale inbound_id Invariant: a client whose stats row is switched off is served by no local runtime of any inbound it is attached to. client_traffics is email-keyed, and AddClientStat re-points its inbound_id at the last inbound attached, yet the runtime push builder and the MTProto, TUIC and AmneziaWG desired- instance builders looked the row up by inbound_id. On every other inbound of a multi-inbound client the depletion filter saw nothing, so a depleted client stayed served there whenever its settings entry still read enabled - the state the stale settings writes left in existing databases. All four now resolve the flag through trafficDisabledEmails, keyed by the emails the inbound actually lists. GetXrayConfig already backfills sibling rows by email (backfillClientStats) and is unchanged.
  • View comparison for these 6 commits »

15 hours ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 17d7dd46b5 docs(media): refresh panel screenshots for v3.8.5 The README screenshots still showed the v3.2.5 layout. Retake every panel page in light and dark on the current UI, and redo the annotated Telegram bot setup shot for the new sidebar layout, marking the enable toggle too.
  • feb8451bd1 fix(clients): zero traffic before re-enabling a client on reset Invariant: a traffic reset leaves a quota-disabled client enabled everywhere. ResetTrafficByEmail and BulkResetTraffic enabled the client first and zeroed its counters afterwards. A traffic tick landing between the two still saw the client depleted and switched it off again in client_traffics, the record and settings. Update's direct record write then set the record back to enabled and the reset zeroed the counters, leaving the settings entry disabled: the client showed enabled with zero usage but was dropped from the runtime. The periodic reset job goes through ResetTrafficByEmail for every depleted client on its cycle, and a node push inside Update widens the window to seconds. Zero first, then enable: with the counters at zero the depletion predicate no longer matches, so the tick has nothing to undo. UpdateInboundClient re-adds the enabled user to the runtime itself.
  • 63ffc083e4 fix(clients): stop client ops from reverting a renewal committed mid-op Invariant: an operation on an inbound's clients writes back only what it changed, onto the settings as committed when it writes. Every client op (add, edit, delete, bulk adjust/detach/delete/set-enable) read the inbound outside the serial traffic writer and then tx.Save'd the whole row inside it. A traffic tick that committed in between - auto-renew re-enabling a client, the delayed-start conversion, a node adoption - was overwritten with the stale copy. A renewed neighbour ended up enable=false with its old expiry in settings while client_traffics said enabled, so the next runtime rebuild dropped a healthy client nobody had touched. The bulk ops then ran a full SyncInbound from those stale settings, copying enable=false into the client record too. Each site now commits through commitInboundClientSettings: inside the serialized tx it three-way merges the op's edit (read -> output, per client and per field) onto the committed settings and updates only the settings column, which also stops the stale up/down/enable inbound columns being written back. advancePushedInbound now records what the per-client push delivered rather than the merged settings, so the node's reconcile-skip fingerprint cannot claim a renewal it never received.
  • 15d82a5e47 fix(inbounds): accept v2.x client fields on inbound import Panels up to v2.x stored a client's tgId as a string, "" when unset. The startup migration heals copies already in the database, but an exported inbound imported into a current panel goes straight to AddInbound, whose typed client parse failed with "cannot unmarshal string into Go struct field .0.tgId of type int64", so every such import was refused. AddInbound now runs the legacy normalizer the clients-table seeder already used (moved from database to model so both share it) over the incoming settings before parsing them. String numbers become integers and empty ones are dropped, and the settings are stored in that shape. The same applies to /inbounds/add callers still sending the old types. The seeder change is a pure move; the PostgreSQL lane was not run (no Docker on this host) and is left to CI. Closes #6663
  • 092cbd55e4 fix(x-ui.sh): read the service state without scanning the journal check_status ran `systemctl status x-ui` and grepped its Active line. That command also prints the unit's latest journal lines, so it reads the journal every time the menu is drawn, before most actions, and on hosts with months of logs the script stalled for a long time before showing its options. `systemctl show --property=SubState` returns the same "running" state from the unit alone. The prefix is stripped by hand rather than with --value so it still works on systemd older than 230. No test harness covers x-ui.sh. To demonstrate on a host with a large journal: time systemctl status x-ui >/dev/null time systemctl show --property=SubState x-ui Refs #6629
  • View comparison for these 8 commits »

1 day ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 09617f04f5 feat(panel): let a sponsor slot start at a scheduled time sponsors.json only had an end date, so a booked placement had to be added to the file on the day it started. An optional `from` now hides a sponsor (and its logo) until that instant; entries without it show immediately as before.
  • 044e2926a0 fix(amneziawg): let the wrapped bind build peer endpoints resolvingBind.ParseEndpoint resolved a hostname and then built a StdNetEndpoint itself. That matches StdNetBind, the default bind on Linux, but on Windows the default is WinRingBind, whose Send refuses any endpoint it did not parse ("endpoint type does not correspond with bind type"). Every handshake initiation failed there, so no AmneziaWG tunnel, inbound or outbound, could come up on the Windows builds. ParseEndpoint now hands the resolved literal to the wrapped bind's own parser, which returns the endpoint type that bind sends to; StdNetBind and pinnedBind build the same StdNetEndpoint as before. The resolvingBind tests now read endpoints through the Endpoint interface instead of asserting StdNetEndpoint, which had pinned the bug.
  • 75f3702dd3 fix(amneziawg): fall back to a free egress port when 64900 is refused The panel's SOCKS5 egress for AmneziaWG outbounds bound the fixed 127.0.0.1:64900, and every generated socks bridge dialed that constant. 64900 sits inside Windows' dynamic port range, where the OS can reserve whole blocks (this host excludes 64885-64984), so on the Windows builds release.yml ships the listener could stay down and every AmneziaWG outbound with it. Listen now tries 64900 first and falls back to any free loopback port; bridges, the outbound probe and the port-conflict check use EgressPort(), the port actually held. Bridges are generated apart from the listener, so BuildSocksBridge records the port it wrote and the AmneziaWG job requests an Xray restart while the listener holds a different one. Where 64900 is free nothing changes. The job's restart request is two lines of wiring no test reaches; the staleness it acts on is pinned by TestBridgesStaleUntilRegeneratedForTheBoundPort.
  • 8f47b53879 style(settings): fold the Happ settings into four tabs Seven tabs, several holding one or two settings, made the page hard to scan. The encrypted-links switch moves above the tabs under auto-detection, the colour profile joins the banners under Appearance & Theme, and Android per-app proxy joins Network & TUN Engine. The QR modal's settings link no longer needs a happTab selector, and the three orphaned tab-label keys are dropped from every locale.
  • a33b2341e9 style(clients): put Traffic Reset and Auto renewal on one row The renewal block took a full-width column, pushing Traffic Reset onto its own line. Each now gets a half-width column like the other fields, with its follow-up inputs stacked under it.
  • View comparison for these 13 commits »

1 day ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 12d51d7195 perf(tests): copy a migrated template DB instead of migrating per test Most tests opened a throwaway panel DB with database.InitDB, which runs the full AutoMigrate + seed on an empty file every time: ~230ms, and ~850ms under -race because GORM's reflection-heavy migration is what the detector slows most. internal/web/service does this in ~550 of its 830 tests, so the CI race job spent ~10 of its ~14.6 minutes re-migrating empty databases. internal/database/dbtest.InitDB migrates once per test process, then hands each test its own copy of that file (~130ms under -race) and registers the CloseDB cleanup. The copy then goes through InitDB like a panel restart, so every test still starts from the state a fresh install has. Tests that reopen an existing file, migrate a hand-built legacy DB or target Postgres keep calling database.InitDB. Locally under -race: internal/web/service 626s (last CI run) -> 114s, internal/sub 246s -> 35s.
  • 33a469315a feat(clients): preserve traffic counters in portable export/import (#6469) * feat(clients): preserve traffic counters in portable export/import ExportAll now attaches client_traffics up/down (plus resetCount and last-seen fields) on each portable payload, and ImportClients restores them only for newly created emails so skipped/existing clients keep their live counters. Fixes #5858. * fix(clients): restore imported traffic only onto rows the import created Review of the portable-traffic export/import (#5858) found four defects: - An orphan's restored row was hand-built, dropping reset_weekday and forcing enable=true; a row kept by a keepTraffic delete kept the old client's limits. depletedClientsClause then matched a weekly-renewing over-quota orphan and DelDepleted deleted it. Orphan rows now go through AddClientStat, whose upsert refreshes config and keeps counters, so the unused traffic.total field is dropped from the export. - Created clients were inferred from Skipped emails, so a duplicate email in the file left the created copy with zero counters. bulkCreate now reports which payloads inserted a record, and only those are restored. - Each client took its own serialized-writer commit: 2000 clients spent 3.66s instead of 0.52s. Counters now apply in batched transactions (0.51s). - importClients discarded needRestart when the late restore step failed after clients were committed; it now flags and notifies first, as create already does. The /clients/export and /clients/import API docs now describe traffic. * fix(groups): keep imported traffic out of group totals Group totals keep a deleted client's usage (#5675), and the portable import restores that same usage onto the re-created client. Export, delete, re-import therefore counted it twice in ListGroups, and a fresh panel showed the migrated usage as consumption of its groups. Restored counters are usage from before the import, so the import now shifts each group's baseline up by what it restored, in the same transaction. A group total no longer moves at import time; only traffic consumed afterwards counts. The baseline shift reuses the #5675 helper, now signed. --------- Co-authored-by: Sanaei <[email protected]>
  • ac43b19cfa chore(ci): stop release and CodeQL runs on PRs, drop deploy smoke tests The release matrix (7 Linux cross-builds + a CGO Windows build) ran on every PR and on every branch push, so a PR from a repo branch built everything twice. Release binaries now build only on main (dev channel) and version tags; any other branch can still be built via workflow_dispatch. CodeQL keeps its push-to-main and weekly scans but no longer runs per PR. The deploy smoke workflow fired on every Release completion only to skip its jobs; deploy/test/smoke-noninteractive.sh stays for manual runs.
  • 0ef94b686e feat(tgbot): add /broadcast to relay an admin message to all clients (#6510) * feat(tgbot): add /broadcast to relay an admin message to all clients Admins had no way to reach every client at once: notifications only cover exhausted quotas, so an operator had to copy a message to each client chat by hand. Add an admin-only /broadcast flow to the bot: - /broadcast asks for a message; any message the admin sends — text, rich text, photo, video, file, sticker or a whole album — becomes the broadcast by reference (admin chat + message ids), and a preview self-copy shows the admin exactly what recipients will get while rejecting content Telegram cannot copy before the run starts. - The draft references the original instead of parsing its content, so copyMessage/copyMessages deliver everything 1:1 on behalf of the bot with no forward header (the admin's identity stays private), no caption length pitfalls, and future Telegram message types work without new parsing. - A media group arrives as separate updates; its ids are buffered with a short debounce, sorted, and delivered as one copyMessages call so recipients see the original album. - Delivery runs in a background goroutine (common.GoRecover): sequential sends with a small pause, 429 retry_after honored per recipient, failures counted without stopping the run, progress edited into one card at most every 25 sends or 3 seconds, a cancel button checked between sends, and a final delivered/failed/skipped summary. The summary is edited into the card (only sent separately if the card is gone), so it is never duplicated. - Recipients repeat the notifyExhausted walk: clients with a linked tg_id, deduplicated, admins excluded — they already receive the reports. The message content is never logged. New i18n keys are added to all 13 locales. * fix(tgbot): harden broadcast composition per review - Key the composition per admin chat instead of one process-wide draft: two admins can now compose at once without dropping each other's drafts, and one admin's /broadcast no longer wipes another chat's half-collected album. - Bind each preview card to its own draft via a random token carried in the confirm callback, so a stale Send tap is answered with an error instead of delivering a newer, unapproved draft. - Ignore non-admin senders while a chat composes: the awaiting state is keyed by chat id, and in a group that chat is shared. - Check the cancel flag inside the flood-control retry loop, so a 429 with a long retry_after no longer holds the single broadcast slot after the admin cancelled. - Scale the per-recipient pause by the copied batch size, so an album keeps the same per-second ceiling as a single message. - Trim the comment blocks that exceeded the two-line cap. * fix(tgbot): reset broadcast state on stop and classify 403 as skipped - Clear compositions and cancel the active run from StopBot, next to the per-chat draft resets: an album debounce timer, a confirmable token or a held runner slot must not outlive the receiver that created them. - Sleep flood-control waits in 5 s slices and re-check cancel and bot state between them, so a minutes-long retry_after no longer parks the single-runner slot after the admin cancelled or the bot stopped. - Count Telegram 403 (the chat never started the bot, or blocked it) as skipped instead of failed, log it at debug rather than one warning per recipient, and append one line to the summary naming the reason. - Trim the remaining comment blocks over the two-line cap. * fix(tgbot): count unreachable recipients in broadcast progress throttle The progress card refresh was keyed on sent+failed, which a 403 does not advance since unreachable chats were split out of the failure count. A streak of unreachable recipients while that sum sat on a multiple of broadcastProgressEvery (0 included, so from the very first recipient) edited the card once per chat, doubling the request rate the send delay is sized for and defeating the throttle. Count processed recipients. * fix(tgbot): key broadcast compositions by admin, not chat After #6604 moved conversation state to the admin (chatUser), the broadcast draft map stayed keyed by chat. Two admins composing in one group then shared a slot: the second admin's message dropped the first admin's draft, whose Send tap answered "went wrong" while only the other draft could go out - the same class #6604 fixed for the add-client wizard. Drafts, album buffers and confirm tokens now live under the admin who ran /broadcast. The router now hands handleBroadcastInput only the admin whose own /broadcast is awaiting input, so its sender re-check and the test that fed it a non-admin message directly (an input no route can deliver) are removed. --------- Co-authored-by: MHSanaei <[email protected]>
  • 71e38367c1 feat(sub): add Incy app-management parameters (#6650) * feat(sub): add Incy app-management parameters The panel already pushes a set of Happ headers, but INCY documents its own lowercase header names and its own value domains, so a Happ-shaped payload gets ignored by the client (per-app mode is bypass|proxy, not on|bypass, and per-app-proxy-enable has no Happ counterpart at all). Add a sibling Incy path that emits exactly the documented headers. Covered, per https://docs.incy.cc/en/app-management/: - profile-description, sort-order, support-email, announce-url, premium-url - banner text/button/URL and the two hex colours - hide-url, hide-check, no-limit-enabled - per-app split tunnelling (enable/mode/list) - TCP fragmentation (enable/length/interval/packets) - UDP noise packets (enable/type/packet/delay) - DoH pre-resolution (enable/domain/IP) Each string setting is tri-state: an empty value omits the header, so an untouched panel never overrides the subscriber's own choice in the app. Values are validated against the documented domains and dropped when they do not match, and non-ASCII text is base64-wrapped the way the docs require for Cyrillic. INCY identifies itself as INCY/<version>/<platform>, which gates the headers behind the same auto-detect switch the Happ path uses. Headers the panel already emits for every client (Profile-Title, Support-Url, Profile-Web-Page-Url, Announce, Profile-Update-Interval, Subscription-Userinfo) and Incy's routing line are left as they are. The Premium API (theme, defaultPingProtocol, fallbackHosts, ...) is a separate encrypted endpoint and stays out of scope here. * fix(sub): keep Incy per-app list entries separate on the wire The Incy settings textarea takes one package per line, as Incy documents for per-app-proxy-list, but the header path ran the value through sanitizeHeaderValue, which deletes CR/LF. "com.google.chrome\norg.telegram.messenger" reached the client as the single bogus package "com.google.chromeorg.telegram.messenger", so per-app split tunnelling silently matched no app. Join comma- or line-separated entries as CSV instead. Also drop three tests that could not fail: TestIncyExcludesHappOnlyHeaders (ApplyIncyHeaders has no path that emits Happ headers, and the non-Happ UA gate is already pinned by TestApplyHappHeaders_Gating) and two UI tests that only asserted updateSetting received the key the JSX passes it. --------- Co-authored-by: DIMFLIX <[email protected]> Co-authored-by: MHSanaei <[email protected]>
  • View comparison for these 30 commits »

2 days ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • dcaadd4857 fix(panel): validate sponsor logo name before any file or network use The public /sponsors/logo/:name route only accepted names matching an active sponsor's logo, which was already regex-filtered, but that guard was indirect. Checking sponsorLogoRe on the name itself makes the path/URL safety local and clears CodeQL alerts #113 (go/request-forgery) and #114 (go/path-injection).

2 days ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • fd7b3559bc feat(panel): add sponsor slots fed from sponsors.sanaei.dev Monthly sponsor placements need to change without cutting a panel release. Panels now read 3X/sponsors.json from the MHSanaei/sponsors repo (GitHub Pages on sponsors.sanaei.dev) and show active sponsors in four slots: an overview banner, a rotating sidebar card (max three), the login page and a new Sponsors page that also lists open placements. An entry shows only while enable is not false and until is in the future; links must be https and logos are png/webp/jpg by name only. The list is cached for an hour and the last good copy survives upstream failures; logos are proxied through /sponsors/logo/:name with failures cached, so CSP stays 'self' and admin browsers never reach a third party. Admins can hide a slot for 24h. Under XUI_DEBUG the panel reads a sibling ../sponsors/3X checkout so edits can be previewed before push.

3 days ago

txlyre pushed to master at txlyre/libqirt

3 days ago

txlyre pushed to master at txlyre/qic

3 days ago

txlyre pushed to master at txlyre/libqirt

3 days ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 89e200ead4 fix(frontend): key geo entries by page position and clear test-suite noise Zod 4: use the `error` param instead of the deprecated `message`. lint:deprecated missed these because tsgolint's no-deprecated does not resolve object-literal properties on a `string | Params` union. Geodata: key geo entry rows by page position. antd deprecates rowKey's index argument, and kind:value repeats within a page because the reader drops domain attributes (22 pairs in geosite_IR.dat, 108 in geosite_RU). Nord/PIA: the "All cities/regions" option used a null value, which antd warns on. Map it through a sentinel at the Select boundary so form state stays null, with tests that fail when the sentinel is not mapped back. Tests: - Run the oxlint guard through node; .bin/oxlint is a sh shim Windows cannot spawn, and the swallowed error left both guard cases vacuous. - Start unit workers with --no-experimental-webstorage; msw's localStorage probe made Node 25+ warn once per forked worker. - Set IS_REACT_ACT_ENVIRONMENT, which RTL never sets with globals: false, and settle the async updates it exposed inside act(). The row-cells memo test now fails when memo is removed. - Disable antd's click wave in Storybook; it re-rendered inside the next story's act() and tripped "not configured to support act". - Assert InboundFormModal's validation log instead of leaking it, and give the rule-form test a well-formed clients/list response.

3 days ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • a03228c455 ci: update Claude workflow model settings Use Claude Opus 5.5 with high effort for issue analysis and PR reviews.
  • 86302d2f2d chore(deps): update toolchains and dependencies Raise the frontend baseline to Node 26/npm 11 and refresh contributor documentation. Update frontend, documentation-site, and Go dependencies with regenerated lockfiles and module checksums.
  • View comparison for these 2 commits »

3 days ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/vitest/coverage-v8-5.0.1 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/vitest/browser-playwright-5.0.1 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-5.103.1 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/oxlint-tsgolint-7.0.2002 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/jsdom-30.1.0 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/go_modules/google.golang.org/grpc-1.84.0 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/go_modules/go.uber.org/atomic-1.12.0 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/go_modules/github.com/go-playground/validator/v10-10.30.5 at txlyre/3x-ui from mirror

3 days ago

txlyre synced and deleted reference dependabot/go_modules/github.com/gin-contrib/sessions-1.1.2 at txlyre/3x-ui from mirror

3 days ago