diff --git a/AGENTS.md b/AGENTS.md index bdc1d6c3..809c5544 100644 --- a/AGENTS.md +++ b/AGENTS.md @@ -11,16 +11,13 @@ 3. [docs/development-plan.md](./docs/development-plan.md) 作用:理解当前开发阶段、实施顺序、阶段目标和验收标准。 -4. [docs/frontend-revamp-plan.md](./docs/frontend-revamp-plan.md) - 作用:理解当前前端从 CRA + Semantic UI 迁移到 Next.js + Tailwind CSS + NextUI 的专项改造目标、实施阶段和风险边界。 - -5. [docs/frontend-development-guidelines.md](./docs/frontend-development-guidelines.md) +4. [docs/frontend-development-guidelines.md](./docs/frontend-development-guidelines.md) 作用:理解新版前端的技术选型、目录分层、组件规范、请求层、状态管理、样式和测试约束。 -6. [docs/deployment.md](./docs/deployment.md) +5. [docs/deployment.md](./docs/deployment.md) 作用:理解当前的部署方式和联调步骤,确保开发过程中产出的功能能够成功部署和验证。 -7. [docs/app-config.md](./docs/app-config.md) +6. [docs/app-config.md](./docs/app-config.md) 作用:系统启动时支持的环境变量和配置项说明,确保开发过程中新增的配置项能够正确使用和文档化。 @@ -29,7 +26,7 @@ * 如果实现内容超出 `docs/design.md` 的范围,先修改设计文档,再继续编码。 * 如果实现方式违反 `docs/development-guidelines.md`,应优先调整方案,而不是绕过规范。 * 如果需求与当前开发阶段冲突,优先遵守 `docs/development-plan.md` 的阶段顺序。 -* 如果任务涉及前端改造或管理端 UI,必须同时阅读 `docs/frontend-revamp-plan.md` 与 `docs/frontend-development-guidelines.md`。 +* 如果任务涉及前端改造或管理端 UI,必须同时阅读 `docs/frontend-development-guidelines.md`。 ## 文档维护要求 @@ -40,6 +37,5 @@ * 产品范围或系统边界变化:更新 `docs/design.md` * 开发约束、代码规范、接口约定变化:更新 `docs/development-guidelines.md` * 阶段目标、顺序、验收标准变化:更新 `docs/development-plan.md` -* 前端技术栈、迁移阶段、页面范围变化:更新 `docs/frontend-revamp-plan.md` * 前端目录分层、组件规范、样式体系、测试基线变化:更新 `docs/frontend-development-guidelines.md` * 环境变量或配置项变化:更新 `docs/app-config.md` diff --git a/README.md b/README.md index 2b8e7c6b..fc6e19b7 100644 --- a/README.md +++ b/README.md @@ -206,10 +206,9 @@ go run ./cmd/agent -config /path/to/agent.json 1. [docs/design.md](./docs/design.md) 2. [docs/development-guidelines.md](./docs/development-guidelines.md) 3. [docs/development-plan.md](./docs/development-plan.md) -4. [docs/frontend-revamp-plan.md](./docs/frontend-revamp-plan.md) -5. [docs/frontend-development-guidelines.md](./docs/frontend-development-guidelines.md) -6. [docs/deployment.md](./docs/deployment.md) -7. [docs/app-config.md](./docs/app-config.md) +4. [docs/frontend-development-guidelines.md](./docs/frontend-development-guidelines.md) +5. [docs/deployment.md](./docs/deployment.md) +6. [docs/app-config.md](./docs/app-config.md) ## 管理端与接口 diff --git a/openflare_server/router/api_phase1_test.go b/openflare_server/router/api_phase1_test.go index 92b337ff..88396a5a 100644 --- a/openflare_server/router/api_phase1_test.go +++ b/openflare_server/router/api_phase1_test.go @@ -326,8 +326,8 @@ func TestPhase1HTTPSAndCertificateImportLifecycle(t *testing.T) { if !strings.Contains(version.MainConfig, "include __OPENFLARE_ROUTE_CONFIG__;") { t.Fatal("expected active config to render managed main config") } - if !strings.Contains(version.RenderedConfig, "listen 443 ssl;") { - t.Fatal("expected active config to render https listener") + if !strings.Contains(version.RenderedConfig, "listen 443 ssl http2;") { + t.Fatal("expected active config to render https listener with http2 enabled") } if !strings.Contains(version.RenderedConfig, "return 301 https://$host$request_uri;") { t.Fatal("expected active config to render redirect server") diff --git a/openflare_server/service/config_version.go b/openflare_server/service/config_version.go index 19d11909..f9b945fb 100644 --- a/openflare_server/service/config_version.go +++ b/openflare_server/service/config_version.go @@ -775,7 +775,7 @@ func renderHTTPRedirectServer(domain string) string { func renderHTTPSServer(domain string, originURL string, originHost string, certificateID uint, customHeaders []ProxyRouteCustomHeaderInput, cfg openRestyConfigSnapshot) string { certPath := fmt.Sprintf("%s/%s", nginxCertDirPlaceholder, certificateCertFileName(certificateID)) keyPath := fmt.Sprintf("%s/%s", nginxCertDirPlaceholder, certificateKeyFileName(certificateID)) - return fmt.Sprintf("server {\n listen 443 ssl;\n server_name %s;\n ssl_certificate %s;\n ssl_certificate_key %s;\n%s\n location / {\n%s%s }\n}\n\n", domain, certPath, keyPath, renderExactHostGuard(domain), renderProxyHeaderBlock(originURL, originHost, customHeaders), renderProxyPassBlock(originURL, cfg)) + return fmt.Sprintf("server {\n listen 443 ssl http2;\n server_name %s;\n ssl_certificate %s;\n ssl_certificate_key %s;\n%s\n location / {\n%s%s }\n}\n\n", domain, certPath, keyPath, renderExactHostGuard(domain), renderProxyHeaderBlock(originURL, originHost, customHeaders), renderProxyPassBlock(originURL, cfg)) } func renderExactHostGuard(domain string) string { diff --git a/openflare_server/service/https_phase1_test.go b/openflare_server/service/https_phase1_test.go index 8d92e0b3..aeac2ff4 100644 --- a/openflare_server/service/https_phase1_test.go +++ b/openflare_server/service/https_phase1_test.go @@ -69,8 +69,8 @@ func TestCreateTLSCertificateAndRenderHTTPSConfig(t *testing.T) { if strings.Contains(result.Version.MainConfig, "allow 127.0.0.1;") { t.Fatal("expected main config to avoid hard-coded allow rules on observability server") } - if !strings.Contains(result.Version.RenderedConfig, "listen 443 ssl;") { - t.Fatal("expected rendered config to include https server block") + if !strings.Contains(result.Version.RenderedConfig, "listen 443 ssl http2;") { + t.Fatal("expected rendered config to include https server block with http2 enabled") } if !strings.Contains(result.Version.RenderedConfig, `if ($host != "app.example.com") {`) { t.Fatal("expected rendered config to reject unmatched host headers with 404") diff --git a/openflare_server/web/features/proxy-routes/components/proxy-routes-page.tsx b/openflare_server/web/features/proxy-routes/components/proxy-routes-page.tsx index a059de3f..7125d094 100644 --- a/openflare_server/web/features/proxy-routes/components/proxy-routes-page.tsx +++ b/openflare_server/web/features/proxy-routes/components/proxy-routes-page.tsx @@ -680,7 +680,7 @@ export function ProxyRoutesPage() { /> { form.setValue('enable_https', checked, {