txlyre

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 815c9c5772 fix(tuic): accept the server's STOP_SENDING when tests close uni streams The race job failed in TestAudit3ManagerEnsureActualSendersWithPersistentTraffic with "close called for canceled stream 14". The server parses one command per uni stream and then calls CancelRead, as the quinn reference server does on drop, so its STOP_SENDING can reach the client before the client's own Close and quic-go reports that Close as an error. The data was already read. Every test that wrote a command on a uni stream and required Close to succeed shared this race. closeUniStream accepts only a remote StreamError on the stream's context, so any other Close failure still fails the test.

1 hour ago

txlyre synced commits to v3.9.0 at txlyre/3x-ui from mirror

9 hours ago

txlyre synced new reference v3.9.0 to txlyre/3x-ui from mirror

9 hours ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 05eb06f333 fix(tuic): wait for both traffic counters in the relay E2E tests The race job failed on TestServerUDPDatagramE2E with Up:0 Down:1300. BytesUp is added on the sending goroutine after the relay Send returns, while BytesDown is added on the response goroutine, so the mock echo can be counted and delivered before the upload is. The test drained the counters once right after the reply and assumed both were present. Production is unaffected: deltas left for the next collection window are still summed. The TCP E2E test made the same assumption, so both now accumulate drained deltas until up and down reach the payload size.
  • 3cd4bf504c v3.9.0
  • ede275e4dc fix(server): apply the outbound address policy to remote cert pinning The remote certificate fetch now dials through the same netsafe guard as the REALITY target scan. A private or loopback endpoint is refused unless the request carries allowPrivate; the inbound form asks the operator to confirm and retries with the opt-in.
  • d31465e37b fix(database): keep the dump restore inside its own database file A SQL dump replay only has to rebuild the tables of the database it restores into. Run it on a single connection whose attached-database limit is zero, so the script cannot open or create any other file.
  • 7d232a76c9 style(sponsor): stack the banner's sponsor tag above Visit
  • View comparison for these 5 commits »

9 hours ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 0054e671f8 feat(tuic): implement native in-process Go TUIC v5 server (#6577) * feat(tuic): implement native in-process Go TUIC v5 server - Implement native TUIC v5 protocol server on pure Go using quic-go - Bridge decrypted TCP/UDP traffic into Xray-core via loopback SOCKS5 inbound - Support full Xray routing rules (geosite/geoip) and cascading outbounds - Implement atomic per-client traffic accounting with TotalGB and ExpiryTime - Add automatic legacy cleanup for older Rust tuic-server binaries, configs, and orphaned processes - Eliminate external Rust tuic-server downloads from install/CI scripts * fix(tuic): address traffic accounting, client reload, and socket lifecycle issues * fix(service): update checkTuicSocksReverseConflict to use bindAddr for listenOverlaps * fix(tuic): resolve traffic double-accounting, UDP fragmentation, and socket lifecycle issues * feat(tuic): complete native Go integration and address audit findings - Integrate an isolated QUIC fork pinned to a specific commit - Preserve original QUIC dependencies for Xray, Hysteria and Gin - Apply BBR, CUBIC and Reno to server connections and exported client profiles - Bridge Xray BBR with correct monotonic time and congestion type conversions - Handle congestion sender recreation after PMTU changes - Update congestion control for new connections without restarting the listener - Preserve existing connections and their selected congestion controller - Apply per-inbound log levels through the shared panel logger - Add lifecycle, authentication and TCP/UDP relay events without exposing secrets - Rate-limit repeated authentication and relay warnings - Support native and QUIC UDP relay modes on the same listener - Recover UDP associations after relay worker failures - Fix TCP relay cancellation, idle shutdown and half-close handling - Close active sessions when client credentials are revoked or disabled - Track traffic by immutable client statistics IDs across email and UUID changes - Prevent ambiguous accounting and duplicate UUIDs within TUIC inbounds - Persist pending traffic in a durable shutdown journal - Replay journal batches transactionally without duplicate accounting - Report server shutdown failures through the shared logger - Preserve legacy flat and nested TUIC settings compatibility - Normalize congestion controller values consistently across backend and frontend - Preserve controller, UDP mode and SNI in client links and subscriptions - Separate client profile options from server settings in the TUIC form - Keep certificate path autofill explicit when changing client SNI - Align UDP packet size validation with protocol limits - Simplify and localize TUIC field hints and certificate autofill messages - Add controller, TCP/UDP, logging and live settings update tests - Add accounting identity, journal replay and shutdown regression tests - Add relay recovery, session revocation and legacy frontend form tests * fix(service): alias the TUIC duplicate-UUID subquery for PostgreSQL < 16 syncInboundClients runs a COUNT(*) FROM (subquery) for every client sync, whatever the protocol. PostgreSQL before 16 rejects a FROM subquery with no alias, so on the distro PostgreSQL install.sh provisions (14 on Ubuntu 22.04, 15 on Debian 12) every client add or edit failed with SQLSTATE 42601. Reproduced against postgres:15 with the new env-gated test. * fix(database): create tuic_traffic_receipts through the model migration AddTuicTrafficBatch issued CREATE TABLE IF NOT EXISTS at runtime, a schema change outside db.go. The table was invisible to allModels and migrationModels, so x-ui migrate-db dropped the receipts and a retained journal could be counted twice after a SQLite to PostgreSQL move. It is now a GORM model in both lists, and the insert uses OnConflict DoNothing. * chore(tuic): skip the ICMP-dependent relay test on Windows, drop dead collectors Go disables SIO_UDP_CONNRESET on Windows, so a dead UDP bridge never fails a read there and TestAudit3UDPAssociationMustRecoverAfterBridgeReadFailure was red on every Windows run. Server.CollectTotalTraffic and Manager.CollectTraffic had no caller. * refactor(tuic): serve TUIC on apernet/quic-go instead of a personal fork The native server depended on github.com/poise52/quic-go, a personal fork of apernet/quic-go patched only to pick the congestion controller before the handshake. That put a second QUIC/TLS stack in the binary that no upstream security fix reaches. apernet/quic-go is already in the graph through xray-core and exposes SetCongestionControl, so BBR is now installed on each accepted connection with Xray's own congestion.UseBBR; the cross-module BBR adapter is gone. apernet ships New Reno as its only built-in sender, so a cubic setting is served as new_reno server-side (clients still get cubic in their profile). The test inspectors now read the sender under congestionMutex, which the post-handshake install writes under. Linux loopback, single stream through Xray: 2428 -> 3383 Mbit/s (bbr). --------- Co-authored-by: Sanaei <[email protected]>
  • 40ca2cd72f Reformat clientSearchCols slice literal
  • bb18734c77 fix(tgbot): resolve the panel egress bridge per connection The bot read the panel-egress bridge once at start, so when Xray came up after the bot (or Panel Outbound was set later) it kept dialing Telegram directly until restarted - on a filtered host it never connected. With no dedicated bot proxy, the fasthttp client now resolves the bridge on every new connection and falls back to a direct dial when it is absent. Raised in #6682.
  • 4aa9a382b8 Keep a firewalld pulled in by fail2ban from blocking ports on EL7 (#6688)
  • 3948b83405 Write config.json after a hot apply (#6686) * Write config.json after a hot apply tryHotApply only updated the in-memory snapshot, so bin/config.json stayed stale until the next cold start and the Telegram/Discord config backups uploaded old rules. Persist the new config once the API calls succeed; a write failure is logged and does not restart the running core. * Test that a hot apply refreshes config.json
  • View comparison for these 14 commits »

17 hours ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 05a083eaef fix(api-token): keep a token's scope when -getApiToken regenerates it, add -tokenScope (#6700) * fix(api-token): keep a token's scope when the CLI regenerates it RecreateByName deleted the named row and created a new one without a Scope, so the insert took the column default of admin. Since -tokenName lets the CLI regenerate any token, rotating a monitor or node-sync token silently turned it into a full-access one. The replacement now takes the scope of the row it replaces, and a new name still gets admin as before. A stored scope this build does not know, as after a downgrade, fails the rotation and leaves the row alone instead of guessing. Assisted-by: Claude Code:claude-opus-5-5 (mostly) * feat(cli): let -getApiToken choose the scope of the token it issues -tokenScope sets the scope on both branches of -getApiToken: the token minted on a fresh panel and the one regenerated on a populated panel. Without the flag a regenerated token keeps its scope and a new one gets admin, so every existing invocation, install.sh included, behaves as before. An unknown scope is refused before anything is deleted, so a typo cannot revoke the token it meant to rotate. Assisted-by: Claude Code:claude-opus-5-5 (mostly) * fix(api-token): keep a token's expiry when the CLI regenerates it RecreateByName built the replacement row with ExpiresAt 0, so running `x-ui setting -getApiToken -tokenName <name>` on a token issued through the API with a deadline handed back one that never expires, and said nothing about it - the same silent widening this branch fixed for scope. The replacement now carries the replaced row's ExpiresAt. A token whose deadline has already passed is refused instead of rotated, since keeping the deadline would mint a dead token and dropping it would revive an expired credential without limit; the expired row is left untouched. --------- Co-authored-by: Sanaei <[email protected]>
  • 721de5adde Fix fragment exports for older Xray clients (#6702) * Fix fragment exports for older Xray clients * fix(link): tolerate a finalmask without tcp in panel share links withLegacyFragmentRanges called finalmask.tcp.map unguarded, but stored rows reach the link generator unparsed and dropEmptyFinalMask deletes an empty tcp list on save. Any VMess/VLESS/Trojan/SS inbound with only UDP masks or quicParams threw a TypeError in the QR, info and export-links views. The Go counterpart already skipped a missing tcp. Also trims the Go helper's comment to the two-line cap and drops a []string branch no JSON-decoded finalmask can reach. --------- Co-authored-by: Artem K <[email protected]> Co-authored-by: Sanaei <[email protected]>
  • a716122ef2 feat(ci): let the review bot read the discussion, the issue and xray-core The bot never read the replies under its own findings, so a finding a maintainer had already declined came back on the next `@claude review`. It now reads every comment and inline thread first: a maintainer's answer settles a finding for good, anyone else's is a claim checked against the code, and the summary gives each earlier finding a disposition. It also reads the issue the PR claims to fix and reports a partial fix. REVIEW.md asks for an upstream symbol behind every wire-format claim, but the job had no xray-core source (#6718's review said so). The module the base go.mod pins is now unpacked into a hidden dir in the base workspace; nothing from pr-head runs. REVIEW.md gains the rules only /senior-review carried: keep read, reproduced and inferred claims apart, evidence for performance findings, a traced trust boundary for security ones, and duplicated logic as a finding. The summary now says each inline finding in one line.
  • 8ea8f4bb61 fix(ci): stop the review bot naming where the fix belongs 65b9bfed narrowed the fix carve-out to "one clause naming WHERE the fix belongs", but the bot still closes every finding with that clause, and set beside the defect it already named, the location is the fix. On #6718 it listed the two capabilities the bounding set lacks, then wrote "The fix belongs in the capability bounding set". Drop the carve-out from REVIEW.md and the workflow prompt: the finding's file:line already says where.
  • ce221c33d0 fix(sub): carry REALITY ML-KEM hint in VLESS links (#6712) * fix(sub): carry REALITY ML-KEM hint in VLESS links Keep raw share links in parity with Clash subscriptions for Xray 26.9.8+. Preserve the URI hint through Go and frontend imports, expose it in the outbound editor, and update the documentation tooling. * fix(link): accept REALITY ML-KEM boolean aliases * test(frontend): isolate Happ preset notifications * fix(link): keep the ML-KEM hint out of Xray REALITY settings support-x25519mlkem768 is a Mihomo reality-opts option; xray-core's REALITYConfig (infra/conf/transport_security.go) has no such field and its JSON loader drops unknown keys silently. The PR also stored it as realitySettings.supportX25519Mlkem768 in Xray outbounds (form switch, Go and TS link import, docs outbound builders) and as an inbound settings default that is stripped before Xray and read by no link generator. The outbound switch therefore did nothing, and imported links carried a dead key into the JSON subscription. The share-link hint itself stays: Go, frontend and docs still emit support-x25519mlkem768=true on VLESS REALITY links and drop it on a TLS host override. --------- Co-authored-by: libmur-dev <333915961+[email protected]> Co-authored-by: MHSanaei <[email protected]>
  • View comparison for these 7 commits »

1 day ago

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 99bc68fa14 chore(deps): update project dependencies Refresh Go, frontend, and documentation dependencies, including MSW 3 and pnpm 12.8.1. Update the MSW test setup to use the renamed `onUnhandledFrame` option.
  • 62423cacd1 feat(xray): update xray-core to v26.9.30 and adapt panel Bump xtls/xray-core to b26a91de4f (v26.9.30) and the three binary pins (DockerInit.sh, release.yml Linux + Windows) in lockstep. No deleted symbols; the sing and sing-shadowsocks indirect deps drop out with the SS2022 rewrite. XDNS finalmask (#6718) replaced its string lists with objects: domains are {name, types, edns0, lenLimit, labelLimit} and client resolvers {type, settings.addr}. The loader no longer parses the old lists, so a single stored xdns mask keeps the whole core from starting. The new leaf package internal/util/maskcompat converts them: "name[:type]" becomes a domain and "name[:type]+udp://addr" a domain plus a udp resolver. A bare name maps to TXT, the type legacy clients queried by default, and each converted domain keeps the 1232-byte EDNS0 the old code always used (without it the server caps answers at 512). It runs from: - the XdnsFinalmaskObjectsFix seeder, over inbound streams, hosts, the xray template, the global sub-JSON mask and cached subscription outbounds; - inbound save (normalizeStreamSettings) and GetXrayConfig, for rows that never went through the seeder; - both link importers, since fm= from an older panel carries the lists. The finalmask form edits the object shape (every key needs a registered field, or the finalmask watch drops it on save) and lifts legacy masks on open. The udp-mask golden fixture moves to the object shape, which TestGoldenStreamFixturesBuildInXray now builds through the core. The wire format changed as well, so pre-upgrade clients need the new core. WireGuard outbound (#6771) dropped settings.domainStrategy and the remoteDNS "local" mode. The endpoint lookup now follows sockopt.domainStrategy and in-tunnel targets the outbound's targetStrategy. The old key is silently ignored, which undid the IPv4-first endpoint lookup the WARP outbound depends on (#5205), and "local" now panics the core at startup because remoteDNS goes through netip.MustParseAddr. The WireguardDomainStrategyFix seeder moves a stored family preference to both keys (a value already set wins) and turns "local" into targetStrategy; the outbound form lifts legacy rows the same way and drops its select, the WARP modal writes the new placement, and the inbound form loses a field the server never read. ValidateOutboundConfig now refuses a non-IP remoteDNS entry, which conf.Build() lets through, on template save and for outbound subscriptions. Noise finalmask items accept type "exp" (#6862), a tag expression. The form offers it for noise items only: header-custom items go through the core's PraseByteSlice, which refuses it. TUN gained autoSystemDnsToGateway (Linux) and autoSystemWfpBlockLeak (Windows). Both pass through the settings schema so a value set in JSON survives the next form save. MASQUE (inbound, outbound, transport) and the XDRIVE transport are new protocols the panel does not offer yet; their new loader refusals only cover configs the panel never generates. The FakeDNS IPv6 pool default, the SS2022 rewrite (same gRPC account; emails are now deduped case-insensitively, as the panel already does), the restored udphop interval default and the rest change no panel-facing config.
  • View comparison for these 2 commits »

1 day ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-devtools-5.104.0 at txlyre/3x-ui from mirror

1 day ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-5.104.0 at txlyre/3x-ui from mirror

1 day ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 at txlyre/3x-ui from mirror

1 day ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 at txlyre/3x-ui from mirror

1 day ago

txlyre synced and deleted reference dependabot/go_modules/google.golang.org/grpc-1.86.0-dev at txlyre/3x-ui from mirror

1 day ago

txlyre synced and deleted reference dependabot/go_modules/github.com/shirou/gopsutil/v4-4.26.9 at txlyre/3x-ui from mirror

1 day ago

txlyre synced and deleted reference dependabot/go_modules/github.com/goccy/go-json-0.11.1 at txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/tanstack/react-query-devtools-5.104.0 at txlyre/3x-ui from mirror

  • c696a7dbc1 chore(deps): bump @tanstack/react-query-devtools in /frontend Bumps [@tanstack/react-query-devtools](https://github.com/TanStack/query/tree/HEAD/packages/react-query-devtools) from 5.103.2 to 5.104.0. - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query-devtools/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/[email protected]/packages/react-query-devtools) --- updated-dependencies: - dependency-name: "@tanstack/react-query-devtools" dependency-version: 5.104.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

2 days ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/tanstack/react-query-5.104.0 at txlyre/3x-ui from mirror

  • 3f6c6ebce5 chore(deps): bump @tanstack/react-query in /frontend Bumps [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) from 5.103.2 to 5.104.0. - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/[email protected]/packages/react-query) --- updated-dependencies: - dependency-name: "@tanstack/react-query" dependency-version: 5.104.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

2 days ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 at txlyre/3x-ui from mirror

  • e81536536a chore(deps): bump react-hook-form from 7.88.0 to 7.89.0 in /frontend Bumps [react-hook-form](https://github.com/react-hook-form/react-hook-form) from 7.88.0 to 7.89.0. - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](https://github.com/react-hook-form/react-hook-form/compare/v7.88.0...v7.89.0) --- updated-dependencies: - dependency-name: react-hook-form dependency-version: 7.89.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

2 days ago

txlyre synced new reference dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 to txlyre/3x-ui from mirror

2 days ago