txlyre

txlyre synced commits to main at txlyre/3x-ui from mirror

  • 99bc68fa14 chore(deps): update project dependencies Refresh Go, frontend, and documentation dependencies, including MSW 3 and pnpm 12.8.1. Update the MSW test setup to use the renamed `onUnhandledFrame` option.
  • 62423cacd1 feat(xray): update xray-core to v26.9.30 and adapt panel Bump xtls/xray-core to b26a91de4f (v26.9.30) and the three binary pins (DockerInit.sh, release.yml Linux + Windows) in lockstep. No deleted symbols; the sing and sing-shadowsocks indirect deps drop out with the SS2022 rewrite. XDNS finalmask (#6718) replaced its string lists with objects: domains are {name, types, edns0, lenLimit, labelLimit} and client resolvers {type, settings.addr}. The loader no longer parses the old lists, so a single stored xdns mask keeps the whole core from starting. The new leaf package internal/util/maskcompat converts them: "name[:type]" becomes a domain and "name[:type]+udp://addr" a domain plus a udp resolver. A bare name maps to TXT, the type legacy clients queried by default, and each converted domain keeps the 1232-byte EDNS0 the old code always used (without it the server caps answers at 512). It runs from: - the XdnsFinalmaskObjectsFix seeder, over inbound streams, hosts, the xray template, the global sub-JSON mask and cached subscription outbounds; - inbound save (normalizeStreamSettings) and GetXrayConfig, for rows that never went through the seeder; - both link importers, since fm= from an older panel carries the lists. The finalmask form edits the object shape (every key needs a registered field, or the finalmask watch drops it on save) and lifts legacy masks on open. The udp-mask golden fixture moves to the object shape, which TestGoldenStreamFixturesBuildInXray now builds through the core. The wire format changed as well, so pre-upgrade clients need the new core. WireGuard outbound (#6771) dropped settings.domainStrategy and the remoteDNS "local" mode. The endpoint lookup now follows sockopt.domainStrategy and in-tunnel targets the outbound's targetStrategy. The old key is silently ignored, which undid the IPv4-first endpoint lookup the WARP outbound depends on (#5205), and "local" now panics the core at startup because remoteDNS goes through netip.MustParseAddr. The WireguardDomainStrategyFix seeder moves a stored family preference to both keys (a value already set wins) and turns "local" into targetStrategy; the outbound form lifts legacy rows the same way and drops its select, the WARP modal writes the new placement, and the inbound form loses a field the server never read. ValidateOutboundConfig now refuses a non-IP remoteDNS entry, which conf.Build() lets through, on template save and for outbound subscriptions. Noise finalmask items accept type "exp" (#6862), a tag expression. The form offers it for noise items only: header-custom items go through the core's PraseByteSlice, which refuses it. TUN gained autoSystemDnsToGateway (Linux) and autoSystemWfpBlockLeak (Windows). Both pass through the settings schema so a value set in JSON survives the next form save. MASQUE (inbound, outbound, transport) and the XDRIVE transport are new protocols the panel does not offer yet; their new loader refusals only cover configs the panel never generates. The FakeDNS IPv6 pool default, the SS2022 rewrite (same gRPC account; emails are now deduped case-insensitively, as the panel already does), the restored udphop interval default and the rest change no panel-facing config.
  • View comparison for these 2 commits »

4 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-devtools-5.104.0 at txlyre/3x-ui from mirror

4 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/tanstack/react-query-5.104.0 at txlyre/3x-ui from mirror

4 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 at txlyre/3x-ui from mirror

4 hours ago

txlyre synced and deleted reference dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 at txlyre/3x-ui from mirror

4 hours ago

txlyre synced and deleted reference dependabot/go_modules/google.golang.org/grpc-1.86.0-dev at txlyre/3x-ui from mirror

4 hours ago

txlyre synced and deleted reference dependabot/go_modules/github.com/shirou/gopsutil/v4-4.26.9 at txlyre/3x-ui from mirror

4 hours ago

txlyre synced and deleted reference dependabot/go_modules/github.com/goccy/go-json-0.11.1 at txlyre/3x-ui from mirror

4 hours ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/tanstack/react-query-devtools-5.104.0 at txlyre/3x-ui from mirror

  • c696a7dbc1 chore(deps): bump @tanstack/react-query-devtools in /frontend Bumps [@tanstack/react-query-devtools](https://github.com/TanStack/query/tree/HEAD/packages/react-query-devtools) from 5.103.2 to 5.104.0. - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query-devtools/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/[email protected]/packages/react-query-devtools) --- updated-dependencies: - dependency-name: "@tanstack/react-query-devtools" dependency-version: 5.104.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/tanstack/react-query-5.104.0 at txlyre/3x-ui from mirror

  • 3f6c6ebce5 chore(deps): bump @tanstack/react-query in /frontend Bumps [@tanstack/react-query](https://github.com/TanStack/query/tree/HEAD/packages/react-query) from 5.103.2 to 5.104.0. - [Release notes](https://github.com/TanStack/query/releases) - [Changelog](https://github.com/TanStack/query/blob/main/packages/react-query/CHANGELOG.md) - [Commits](https://github.com/TanStack/query/commits/@tanstack/[email protected]/packages/react-query) --- updated-dependencies: - dependency-name: "@tanstack/react-query" dependency-version: 5.104.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 at txlyre/3x-ui from mirror

  • e81536536a chore(deps): bump react-hook-form from 7.88.0 to 7.89.0 in /frontend Bumps [react-hook-form](https://github.com/react-hook-form/react-hook-form) from 7.88.0 to 7.89.0. - [Release notes](https://github.com/react-hook-form/react-hook-form/releases) - [Changelog](https://github.com/react-hook-form/react-hook-form/blob/master/CHANGELOG.md) - [Commits](https://github.com/react-hook-form/react-hook-form/compare/v7.88.0...v7.89.0) --- updated-dependencies: - dependency-name: react-hook-form dependency-version: 7.89.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced new reference dependabot/npm_and_yarn/frontend/react-hook-form-7.89.0 to txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 at txlyre/3x-ui from mirror

  • 015656cf1b chore(deps-dev): bump lint-staged from 17.5.1 to 17.6.0 in /frontend Bumps [lint-staged](https://github.com/lint-staged/lint-staged) from 17.5.1 to 17.6.0. - [Release notes](https://github.com/lint-staged/lint-staged/releases) - [Changelog](https://github.com/lint-staged/lint-staged/blob/main/CHANGELOG.md) - [Commits](https://github.com/lint-staged/lint-staged/compare/v17.5.1...v17.6.0) --- updated-dependencies: - dependency-name: lint-staged dependency-version: 17.6.0 dependency-type: direct:development update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced new reference dependabot/npm_and_yarn/frontend/lint-staged-17.6.0 to txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/go_modules/google.golang.org/grpc-1.86.0-dev at txlyre/3x-ui from mirror

  • 74f26b5cb0 chore(deps): bump google.golang.org/grpc Bumps [google.golang.org/grpc](https://github.com/grpc/grpc-go) from 1.85.0-dev.0.20260825072537-93e31b48545e to 1.86.0-dev. - [Release notes](https://github.com/grpc/grpc-go/releases) - [Commits](https://github.com/grpc/grpc-go/commits/v1.86.0-dev) --- updated-dependencies: - dependency-name: google.golang.org/grpc dependency-version: 1.86.0-dev dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago

txlyre synced new reference dependabot/go_modules/google.golang.org/grpc-1.86.0-dev to txlyre/3x-ui from mirror

1 day ago

txlyre synced commits to dependabot/go_modules/github.com/shirou/gopsutil/v4-4.26.9 at txlyre/3x-ui from mirror

  • 19178b128d chore(deps): bump github.com/shirou/gopsutil/v4 from 4.26.8 to 4.26.9 Bumps [github.com/shirou/gopsutil/v4](https://github.com/shirou/gopsutil) from 4.26.8 to 4.26.9. - [Release notes](https://github.com/shirou/gopsutil/releases) - [Commits](https://github.com/shirou/gopsutil/compare/v4.26.8...v4.26.9) --- updated-dependencies: - dependency-name: github.com/shirou/gopsutil/v4 dependency-version: 4.26.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]>
  • 99047c0a63 fix(frontend): keep the given file name on mobile downloads FileManager typed every download text/plain. Android's MediaStore appends the MIME type's extension whenever the name's own extension maps elsewhere, so a subscriber saving a WireGuard config got peer.conf.txt, which the WireGuard app refuses; .json, .yaml and .log downloads were renamed the same way. Desktop browsers honour the download name, which is why only phones saw it. application/octet-stream carries no extension of its own, so the name the panel chose is kept.
  • aee45ca3fe fix(hosts): advertise Hosts in every WireGuard, AmneziaWG and TUIC config Invariant: an inbound's enabled Hosts are the endpoints every client config for it advertises, whichever surface renders that config. WireGuard and AmneziaWG broke it. Their raw generators ignored the externalProxy entries Hosts are injected as and always emitted resolveInboundAddress, so the raw subscription, the sub page .conf, the clients links API and "export all links" gave out the panel address while the JSON and Clash formats of the same inbound used the Host. advertisedEndpoints now states the fan-out once for mtproto, wireguard and amneziawg. The browser-built configs had the same gap. The Clients page WireGuard and AmneziaWG config blocks and QR panels, and its TUIC Clash config, used the panel hostname next to server links that already used Hosts; the Inbounds page peer configs, QR and export ignored them too. withMtprotoHostEndpoints becomes withHostEndpoints over a shared hostEndpointsFor mirror of the backend, the tunnel fan-outs render one config per Host, and the clients page waits for the hosts list the way the inbounds page does, so an empty list means "no hosts" rather than "not loaded yet".
  • 8c023d13dc docs(architecture): fix table padding flagged by oxfmt The NodePendingReset row added in 4210a50c had one extra space of padding, failing the Docs CI format check.
  • 823db05966 fix(inbounds): keep the stored client list and enable on inbound save Invariant: saving an inbound's configuration never changes which clients it holds nor whether it is enabled; both have their own endpoints. The edit modal posts back the clients and the enable flag it loaded when it opened. A client added meanwhile (another admin, the bot, the API, LDAP) was detached and its stats deleted; a client deleted meanwhile came back with its credentials, restoring access that had been revoked; an inbound switched off meanwhile was switched back on. For every save but a master's node-sync push, UpdateInbound now takes the client list and enable from the row it re-reads inside the writer; this replaces the lifecycle-only carry from the previous commit. Client validation (renewal schedule, Hysteria auth, TUIC credentials) moves after that swap so it judges the clients actually saved: a protocol switch keeps the stored clients, and #6268's refusal must apply to them. The edit form no longer loads or sends clients, so neither the JSON editor nor validation sees a copy the server ignores, and the enable switch shows only when adding; the list toggle (/setEnable) covers existing inbounds. Tests that added or re-keyed clients through a panel inbound save pinned the old rule; they now drive the master-push path, where payload clients still apply.
  • View comparison for these 10 commits »

1 day ago