txlyre

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 05a083eaef fix(api-token): keep a token's scope when -getApiToken regenerates it, add -tokenScope (#6700) * fix(api-token): keep a token's scope when the CLI regenerates it RecreateByName deleted the named row and created a new one without a Scope, so the insert took the column default of admin. Since -tokenName lets the CLI regenerate any token, rotating a monitor or node-sync token silently turned it into a full-access one. The replacement now takes the scope of the row it replaces, and a new name still gets admin as before. A stored scope this build does not know, as after a downgrade, fails the rotation and leaves the row alone instead of guessing. Assisted-by: Claude Code:claude-opus-5-5 (mostly) * feat(cli): let -getApiToken choose the scope of the token it issues -tokenScope sets the scope on both branches of -getApiToken: the token minted on a fresh panel and the one regenerated on a populated panel. Without the flag a regenerated token keeps its scope and a new one gets admin, so every existing invocation, install.sh included, behaves as before. An unknown scope is refused before anything is deleted, so a typo cannot revoke the token it meant to rotate. Assisted-by: Claude Code:claude-opus-5-5 (mostly) * fix(api-token): keep a token's expiry when the CLI regenerates it RecreateByName built the replacement row with ExpiresAt 0, so running `x-ui setting -getApiToken -tokenName <name>` on a token issued through the API with a deadline handed back one that never expires, and said nothing about it - the same silent widening this branch fixed for scope. The replacement now carries the replaced row's ExpiresAt. A token whose deadline has already passed is refused instead of rotated, since keeping the deadline would mint a dead token and dropping it would revive an expired credential without limit; the expired row is left untouched. --------- Co-authored-by: Sanaei <[email protected]>
  • 721de5adde Fix fragment exports for older Xray clients (#6702) * Fix fragment exports for older Xray clients * fix(link): tolerate a finalmask without tcp in panel share links withLegacyFragmentRanges called finalmask.tcp.map unguarded, but stored rows reach the link generator unparsed and dropEmptyFinalMask deletes an empty tcp list on save. Any VMess/VLESS/Trojan/SS inbound with only UDP masks or quicParams threw a TypeError in the QR, info and export-links views. The Go counterpart already skipped a missing tcp. Also trims the Go helper's comment to the two-line cap and drops a []string branch no JSON-decoded finalmask can reach. --------- Co-authored-by: Artem K <[email protected]> Co-authored-by: Sanaei <[email protected]>
  • a716122ef2 feat(ci): let the review bot read the discussion, the issue and xray-core The bot never read the replies under its own findings, so a finding a maintainer had already declined came back on the next `@claude review`. It now reads every comment and inline thread first: a maintainer's answer settles a finding for good, anyone else's is a claim checked against the code, and the summary gives each earlier finding a disposition. It also reads the issue the PR claims to fix and reports a partial fix. REVIEW.md asks for an upstream symbol behind every wire-format claim, but the job had no xray-core source (#6718's review said so). The module the base go.mod pins is now unpacked into a hidden dir in the base workspace; nothing from pr-head runs. REVIEW.md gains the rules only /senior-review carried: keep read, reproduced and inferred claims apart, evidence for performance findings, a traced trust boundary for security ones, and duplicated logic as a finding. The summary now says each inline finding in one line.
  • 8ea8f4bb61 fix(ci): stop the review bot naming where the fix belongs 65b9bfed narrowed the fix carve-out to "one clause naming WHERE the fix belongs", but the bot still closes every finding with that clause, and set beside the defect it already named, the location is the fix. On #6718 it listed the two capabilities the bounding set lacks, then wrote "The fix belongs in the capability bounding set". Drop the carve-out from REVIEW.md and the workflow prompt: the finding's file:line already says where.
  • ce221c33d0 fix(sub): carry REALITY ML-KEM hint in VLESS links (#6712) * fix(sub): carry REALITY ML-KEM hint in VLESS links Keep raw share links in parity with Clash subscriptions for Xray 26.9.8+. Preserve the URI hint through Go and frontend imports, expose it in the outbound editor, and update the documentation tooling. * fix(link): accept REALITY ML-KEM boolean aliases * test(frontend): isolate Happ preset notifications * fix(link): keep the ML-KEM hint out of Xray REALITY settings support-x25519mlkem768 is a Mihomo reality-opts option; xray-core's REALITYConfig (infra/conf/transport_security.go) has no such field and its JSON loader drops unknown keys silently. The PR also stored it as realitySettings.supportX25519Mlkem768 in Xray outbounds (form switch, Go and TS link import, docs outbound builders) and as an inbound settings default that is stripped before Xray and read by no link generator. The outbound switch therefore did nothing, and imported links carried a dead key into the JSON subscription. The share-link hint itself stays: Go, frontend and docs still emit support-x25519mlkem768=true on VLESS REALITY links and drop it on a TLS host override. --------- Co-authored-by: libmur-dev <333915961+[email protected]> Co-authored-by: MHSanaei <[email protected]>
  • View comparison for these 7 commits »

3 hours ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 99bc68fa14 chore(deps): update project dependencies Refresh Go, frontend, and documentation dependencies, including MSW 3 and pnpm 12.8.1. Update the MSW test setup to use the renamed `onUnhandledFrame` option.
  • 62423cacd1 feat(xray): update xray-core to v26.9.30 and adapt panel Bump xtls/xray-core to b26a91de4f (v26.9.30) and the three binary pins (DockerInit.sh, release.yml Linux + Windows) in lockstep. No deleted symbols; the sing and sing-shadowsocks indirect deps drop out with the SS2022 rewrite. XDNS finalmask (#6718) replaced its string lists with objects: domains are {name, types, edns0, lenLimit, labelLimit} and client resolvers {type, settings.addr}. The loader no longer parses the old lists, so a single stored xdns mask keeps the whole core from starting. The new leaf package internal/util/maskcompat converts them: "name[:type]" becomes a domain and "name[:type]+udp://addr" a domain plus a udp resolver. A bare name maps to TXT, the type legacy clients queried by default, and each converted domain keeps the 1232-byte EDNS0 the old code always used (without it the server caps answers at 512). It runs from: - the XdnsFinalmaskObjectsFix seeder, over inbound streams, hosts, the xray template, the global sub-JSON mask and cached subscription outbounds; - inbound save (normalizeStreamSettings) and GetXrayConfig, for rows that never went through the seeder; - both link importers, since fm= from an older panel carries the lists. The finalmask form edits the object shape (every key needs a registered field, or the finalmask watch drops it on save) and lifts legacy masks on open. The udp-mask golden fixture moves to the object shape, which TestGoldenStreamFixturesBuildInXray now builds through the core. The wire format changed as well, so pre-upgrade clients need the new core. WireGuard outbound (#6771) dropped settings.domainStrategy and the remoteDNS "local" mode. The endpoint lookup now follows sockopt.domainStrategy and in-tunnel targets the outbound's targetStrategy. The old key is silently ignored, which undid the IPv4-first endpoint lookup the WARP outbound depends on (#5205), and "local" now panics the core at startup because remoteDNS goes through netip.MustParseAddr. The WireguardDomainStrategyFix seeder moves a stored family preference to both keys (a value already set wins) and turns "local" into targetStrategy; the outbound form lifts legacy rows the same way and drops its select, the WARP modal writes the new placement, and the inbound form loses a field the server never read. ValidateOutboundConfig now refuses a non-IP remoteDNS entry, which conf.Build() lets through, on template save and for outbound subscriptions. Noise finalmask items accept type "exp" (#6862), a tag expression. The form offers it for noise items only: header-custom items go through the core's PraseByteSlice, which refuses it. TUN gained autoSystemDnsToGateway (Linux) and autoSystemWfpBlockLeak (Windows). Both pass through the settings schema so a value set in JSON survives the next form save. MASQUE (inbound, outbound, transport) and the XDRIVE transport are new protocols the panel does not offer yet; their new loader refusals only cover configs the panel never generates. The FakeDNS IPv6 pool default, the SS2022 rewrite (same gRPC account; emails are now deduped case-insensitively, as the panel already does), the restored udphop interval default and the rest change no panel-facing config.
  • View comparison for these 2 commits »

11 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-devtools-5.104.0 at txlyre/3x-ui from mirror

11 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-5.104.0 at txlyre/3x-ui from mirror

11 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 at txlyre/3x-ui from mirror

11 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 at txlyre/3x-ui from mirror

11 hours ago

txlyre synced and deleted reference dependabot/go_modules/google.golang.org/grpc-1.86.0-dev at txlyre/3x-ui from mirror

11 hours ago

txlyre synced and deleted reference dependabot/go_modules/github.com/shirou/gopsutil/v4-4.26.9 at txlyre/3x-ui from mirror

11 hours ago

txlyre synced and deleted reference dependabot/go_modules/github.com/goccy/go-json-0.11.1 at txlyre/3x-ui from mirror

11 hours ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/tanstack/react-query-devtools-5.104.0 at txlyre/3x-ui from mirror

  • c696a7dbc1 chore(deps): bump @tanstack/react-query-devtools in /frontend Bumps [@tanstack/react-query-devtools](https://github.com/TanStack/query/tree/HEAD/packages/react-query-devtools) from 5.103.2 to 5.104.0. - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query-devtools/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/[email protected]/packages/react-query-devtools) --- updated-dependencies: - dependency-name: "@tanstack/react-query-devtools" dependency-version: 5.104.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/tanstack/react-query-5.104.0 at txlyre/3x-ui from mirror

  • 3f6c6ebce5 chore(deps): bump @tanstack/react-query in /frontend Bumps [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) from 5.103.2 to 5.104.0. - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/[email protected]/packages/react-query) --- updated-dependencies: - dependency-name: "@tanstack/react-query" dependency-version: 5.104.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 at txlyre/3x-ui from mirror

  • e81536536a chore(deps): bump react-hook-form from 7.88.0 to 7.89.0 in /frontend Bumps [react-hook-form](https://github.com/react-hook-form/react-hook-form) from 7.88.0 to 7.89.0. - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](https://github.com/react-hook-form/react-hook-form/compare/v7.88.0...v7.89.0) --- updated-dependencies: - dependency-name: react-hook-form dependency-version: 7.89.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced new reference dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 to txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 at txlyre/3x-ui from mirror

  • 015656cf1b chore(deps-dev): bump lint-staged from 17.5.1 to 17.6.0 in /frontend Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 17.5.1 to 17.6.0. - [Release notes](https://github.com/lint-staged/lint-staged/releases) - [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md) - [Commits](https://github.com/lint-staged/lint-staged/compare/v17.5.1...v17.6.0) --- updated-dependencies: - dependency-name: lint-staged dependency-version: 17.6.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced new reference dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 to txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/go_modules/google.golang.org/grpc-1.86.0-dev at txlyre/3x-ui from mirror

  • 74f26b5cb0 chore(deps): bump google.golang.org/grpc Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.85.0-dev.0.20260825072537-93e31b48545e to 1.86.0-dev. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](https://github.com/grpc/grpc-go/commits/v1.86.0-dev) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.86.0-dev dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced new reference dependabot/go_modules/google.golang.org/grpc-1.86.0-dev to txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/go_modules/github.com/shirou/gopsutil/v4-4.26.9 at txlyre/3x-ui from mirror

  • 19178b128d chore(deps): bump github.com/shirou/gopsutil/v4 from 4.26.8 to 4.26.9 Bumps [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) from 4.26.8 to 4.26.9. - [Release notes](https://github.com/shirou/gopsutil/releases) - [Commits](https://github.com/shirou/gopsutil/compare/v4.26.8...v4.26.9) --- updated-dependencies: - dependency-name: github.com/shirou/gopsutil/v4 dependency-version: 4.26.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago