ryan
4ecec2cf1b
forcetypeassert 6→0(缓存 list 断言、relay/flared 中间件契约断言、图片压缩 flight 断言,全部带检查+安全失败路径);errname 1→0;prealloc 2 处(另 1 处与 repo mnd 冲突,用命名常量解决)。nilnil 保留(not-found/可选结果惯例,含接口契约注释)。
...
Result: {"status":"keep","total_issues":15,"golint_canonicalheader":0,"golint_errname":0,"golint_errorlint":1,"golint_forcetypeassert":0,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":0,"golint_recvcheck":7,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":14,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":43}
2026-08-16 17:58:03 +08:00
ryan
86fad02c41
errorlint 12→1:3 处 cmd 入口 err!=context.Canceled→errors.Is(防御性,当前 runner 不 wrap 语义不变);2 处 strconv.NumError 断言、1 处 viper 断言、2 处 ==io.EOF、2 处 ==redis.Nil、1 处 ==gorm.ErrRecordNotFound→errors.As/Is;8 处 %v→%w 保留错误链。刻意保留 telegram.go 单处 %v(原始错误仅作上下文文本,wrap 会改变 errors.Is 匹配语义)。
...
Result: {"status":"keep","total_issues":22,"golint_canonicalheader":0,"golint_errname":1,"golint_errorlint":1,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":21,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":46}
2026-08-16 17:52:03 +08:00
ryan
288b74d104
intrange 3→0 + modernize 5→3:for i:=0;i<len/N;i++ → range len/N(8 处);time.Time 字段 omitempty→omitzero(wire 输出一致);SplitSeq;min() 简化。刻意保留 lark.go omitzero(会改变 wire 行为)。
...
Result: {"status":"keep","total_issues":33,"golint_canonicalheader":0,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":0,"golint_modernize":3,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":32,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":45}
2026-08-16 17:47:09 +08:00
ryan
ce28f63659
wastedassign 7→0:删除 7 处死初始化(snapshot.go 三连、push 三件套 content、format.go numStr),改 var 声明,零行为变化。
...
Result: {"status":"keep","total_issues":38,"golint_canonicalheader":0,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":3,"golint_modernize":5,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":0,"golint_wastedassign":0,"golint_total":37,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":47}
2026-08-16 17:44:45 +08:00
ryan
d0414b402a
canonicalheader 8→0 + usestdlibvars 3→0:header key 改为 Go 规范大小写(wire 格式本就如此,纯代码修正)、HTTP 方法常量替代字符串字面量。
...
Result: {"status":"keep","total_issues":45,"golint_canonicalheader":0,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":3,"golint_modernize":5,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":0,"golint_wastedassign":7,"golint_total":44,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":38}
2026-08-16 17:38:18 +08:00
ryan
699e95f12c
perfsprint 18→0:strconv.Itoa/FormatInt/FormatUint/FormatBool 替代 fmt.Sprintf、无动词 fmt.Errorf→errors.New、纯字符串拼接。全部语义等价(已核对 diff)。修正 fixer 遗留的 import 问题(引入 goimports 统一整理)。
...
Result: {"status":"keep","total_issues":56,"golint_canonicalheader":8,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":3,"golint_modernize":5,"golint_nilnil":3,"golint_perfsprint":0,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":3,"golint_wastedassign":7,"golint_total":55,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":47}
2026-08-16 17:34:44 +08:00
ryan
b76f707c8b
modernize 37→5(-32):interface{}→any、内置 max/min、slices/maps 辅助、strings.Cut/SplitSeq、strings.Builder(修复 mail.go O(n²) 拼接)。逐 hunk 核对语义等价;omitzero 冲突修复被自动跳过(wire 格式不变);手动清 4 处遗留 sort import + 2 处 QF1012。
...
Result: {"status":"keep","total_issues":74,"golint_canonicalheader":8,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":3,"golint_modernize":5,"golint_nilnil":3,"golint_perfsprint":18,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":3,"golint_wastedassign":7,"golint_total":73,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":38}
2026-08-16 17:28:22 +08:00
ryan
f1f6bb858a
修复 internal/apps/edge/observability/linux.go 的 2 个 gosec G115 整数溢出转换:helper 改为接收 int64 b,用 gosec 认可的饱和乘法模式(uint64 域乘积 + 上界比较),去掉原 //nolint:gosec,语义不变(Bsize 恒为正)。repo 自带 gate 首次全绿。
...
Result: {"status":"keep","total_issues":106,"golint_canonicalheader":8,"golint_errname":1,"golint_errorlint":12,"golint_forcetypeassert":3,"golint_gosec":0,"golint_intrange":3,"golint_modernize":37,"golint_nilnil":3,"golint_perfsprint":18,"golint_prealloc":3,"golint_recvcheck":7,"golint_usestdlibvars":3,"golint_wastedassign":7,"golint_total":105,"eslint_problems":1,"eslint_errors":0,"eslint_warnings":1,"tsc_errors":0,"measure_s":38}
2026-08-16 17:21:04 +08:00
ryan
fa689aedbc
feat(sync): 同步 Wavelet 推送审计、OTel schema 与前端字体
...
自定义 Webhook 在 HTTP 200 但业务 errcode 非零时记为失败,任务日志记录上游响应。
OTel Resource 改为 NewSchemaless,避免 semconv 与 SDK 版本冲突。
前端用 next/font 自托管 Inter,并忽略浏览器扩展改写 body 引起的 hydration 警告。
2026-08-16 11:06:54 +08:00
ryan
465440fa5b
fix(access-logs): 修复状态码自定义
2026-08-13 11:33:12 +08:00
ryan
a4dd5ca9e1
feat(dashboard): 首页请求趋势拆分状态码并合并容量到业务流量
...
- 24 小时请求趋势拆分展示请求总量与 200/400/500 状态码请求量,独占一行;
时间桶聚合新增 status_200/400/500_count(CH countIf、PG FILTER),
请求趋势改为基于原始桶聚合(小时 rollup 无状态码口径)
- 首页移除宿主机磁盘指标,容量趋势(CPU/内存)并入业务流量卡片展示
- 压缩协议 traffic_24h 扩展为 7 元组,前端归一化同步更新
2026-08-13 11:10:37 +08:00
ryan
a9e4237bbf
feat(access-logs): 状态码支持手动输入,新增时间范围筛选
...
- 状态码筛选支持预设快捷选项 + 手动输入任意 100-599 状态码(数字校验)
- 新增时间范围筛选:shadcn 日期+时间选择器(Popover+Calendar+时分 Select),
起止时间以 RFC3339 成对传入,后端校验格式与先后关系,非法值返回 400
- 默认显示来源 IP/访问域名/状态码,节点 ID/请求路径/时间范围折叠进「更多筛选」
2026-08-13 10:27:40 +08:00
ryan
75d1fcf345
feat(access-logs): 日志明细支持按状态码筛选并折叠次要搜索项,修复首页来源分布无数据
...
- 修复 PostgreSQL/SQLite 日志库下首页「来源分布」卡片无数据:RegionCounts 对空
节点 ID 误拼 node_id = '' 恒空条件,改为空节点 ID 表示全节点聚合(对齐 CH 语义),
并过滤空白归属地
- /access-logs?tab=list 新增状态码筛选:状态码下拉含常用 2xx/3xx/4xx/5xx 选项,
校验 100-599,非法值返回 400;ClickHouse 与 PostgreSQL/SQLite 日志库均支持
- 搜索框折叠:默认仅显示来源 IP 与状态码,节点 ID/访问域名/请求路径折叠进
「更多筛选」
2026-08-13 09:59:32 +08:00
ryan
e3f603f72a
fix(security): stop logging UptimeKuma socket payload content
2026-08-09 10:42:21 +08:00
ryan
3b010bb15e
feat(log): disable user access log recording
...
- 移除全局用户访问日志采集中间件与批写入 writer(risk_control 包整包删除),
不再写入 w_user_access_logs;存量数据与管理端访问日志统计页面保留
- 日志库迁移任务不再排空用户访问日志队列,状态接口不再展示其缓冲队列统计
- 迁移测试的系统配置 seed 计数断言更新为当前实际值(86 → 95),
注释改为提示新增配置 seed 时同步更新
2026-08-09 10:35:39 +08:00
ryan
0c22e76f4b
fix(frontend): optimization
2026-08-09 09:14:54 +08:00
ryan
bd2183c8bb
feat(log): add independent short retention for performance metrics
...
性能指标(CPU/内存/磁盘/网络)不再跟随 log_retention_days_*,新增三库共用
的 metric_retention_days 配置(默认 3 天),系统垃圾清理按独立短留存清理
指标快照;访问日志保留时长不变。新增 PG/SQLite 双方言 goose 迁移 seed。
2026-08-09 09:04:33 +08:00
ryan
e8c414aa12
fix: ch migrate
2026-08-09 08:47:56 +08:00
ryan
7e8aa5fa0f
Merge branch 'codex/log-database-decoupling'
...
# Conflicts:
# docs/changelog/index.md
# frontend/app/(main)/error-pages/page.tsx
# internal/infra/persistence/migrator/migrator_test.go
2026-08-09 08:37:37 +08:00
ryan
6487ce666d
fix(security): harden PoW XSS, email header injection and UptimeKuma log redaction
2026-08-08 21:52:46 +08:00
ryan
9797fcdb2f
fix(openflare): improve SWOfflineDomains validation and snapshot diff logic
2026-08-08 20:52:07 +08:00
Ryan
93ec3096f3
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-08-08 20:48:54 +08:00
ryan
7d93d3d2a1
fix(log): address remaining CodeRabbit suggestions for log database switch and migrations
2026-08-08 20:36:04 +08:00
Ryan
074edf17a1
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-08-08 20:30:36 +08:00
Ryan
6faf525af0
Potential fix for pull request finding
...
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com >
2026-08-08 20:30:17 +08:00
ryan
a6fc2b7737
fix(log): address CodeRabbit review findings for log database decoupling
2026-08-08 20:15:36 +08:00
ryan
ca21ff3a5b
feat(option): add sw offline
...
fix(openresty): scope sw injection per cert partition
fix(lint): satisfy revive and biome format for sw offline feature
docs: sw offline scope changelog
fix(frontend): use scoped query key for sw scope zones
fix(frontend): hide preview link in sw contact page editor
feat(frontend): add sw scope domain picker and contact page fields
refactor(frontend): generalize html editor workspace for reuse
feat(openresty): scope sw offline injection by route domains
feat(openresty): add sw offline domains snapshot field
feat(option): add sw offline domains scope option
docs: fill html editor workspace generalization detail
docs: sw offline scope implementation plan
docs: sw offline scope design
test(openresty): assert single merged access block in sw enabled servers
fix(openresty): restrict sw intercept to https server blocks
fix(openresty): version sw offline cache by html content
fix(agent): escape redir in sw challenge page to prevent xss
fix(agent): return sw.runtime module table and add lua spec
docs: sw offline fallback changelog
fix(frontend): memoize option map to preserve unsaved contact page edits
feat(frontend): add response pages module with contact page tab
feat(agent): ship sw offline lua assets and placeholder substitution
feat(config): wire sw offline options into config snapshot
feat(openresty): render sw offline assets and challenge intercept
feat(openresty): add sw offline ConfigSnapshot fields and placeholder
feat(db): seed sw offline options
feat(option): add sw offline config keys and validation
docs: add service worker offline fallback implementation plan
docs: adopt global-option pattern for SW offline fallback (matches origin error page)
docs: unify offline contact page with error pages as response pages
docs: service worker offline fallback design (issue #23 )
2026-08-08 20:14:28 +08:00
ryan
7d71f1e4e1
feat(log): decouple log storage from ClickHouse with switchable logstore
...
- New internal/repository/logstore abstraction: exported domain interfaces
(AccessLogStore/ObservabilityStore/UserAccessLogStore/StatusStore),
config-driven provider (Active/Build/Migrating/SetConfigReader), GORM
implementation for PostgreSQL/SQLite (incl. hourly rollups computed in
real time, migration listers, PG partition maintenance), and a ClickHouse
wrapper preserving the native batch path; repository facade delegates to
logstore; import-lint test enforces apps never import analyticsrepo.
- ClickHouse is now optional: the log DB is either the main DB (postgres
when database.enabled, else sqlite) or clickhouse; boot validation +
first-run seed; log_database / log_db_migration are protected keys.
- New user task 切换日志数据库 (of_log_db_switch): freeze log writes,
drain batch writers, copy all 6 raw log tables by id (preserving IDs)
with target-partition pre-creation for PG, flip log_database on success,
clear the freeze flag on failure.
- Per-store retention (log_retention_days_*) with expiry cleanup folded
into the daily system_cleanup task; legacy database_auto_cleanup_* and
of_database_auto_cleanup decommissioned.
- goose migrations: 6 log tables in PG (2 monthly-partitioned) + SQLite,
retention config seeds, schedule cleanup; GET
/api/v1/admin/status/log-database endpoint; frontend retention settings,
switch-task UI and status badge; changelog and docs updated.
docs(plan): log database decoupling implementation plan
docs(design): log database decoupling design (ClickHouse optional)
2026-08-08 19:43:01 +08:00
ryan
6738abdec1
feat(openresty): add origin error page GET-only option
...
Allow restricting custom origin error HTML to GET requests so other
methods pass through origin responses. Adds option seed, snapshot field,
edge limit_except/Lua handling, and admin UI switch.
2026-08-06 20:22:44 +08:00
ryan
3328d3d121
refactor(agent): stop embedding GeoIP MMDB in agent binary
...
Agent ships without City/Country MMDB in the binary; Docker images COPY
databases into data_dir, bare installs seed via download on first start.
Server keeps Country-only embed for optional MaxMind control-plane use.
Also harden fetch script nonempty check and reject non-file MMDB paths.
2026-08-06 16:24:57 +08:00
ryan
076bf8b95c
Merge branch 'feat/origin-error-page'
2026-08-06 14:16:28 +08:00
ryan
7d47db1f34
feat(option): seed and validate origin error page options
2026-08-06 13:59:54 +08:00
ryan
68d8f786cc
feat(openresty): render origin error page directives
...
Wire origin error page into OpenResty proxy route rendering: ConfigSnapshot
fields, default HTML template SupportFile, proxy_intercept_errors + error_page
with status-preserving internal Lua location, and Agent placeholder substitution
for __OPENFLARE_ERROR_PAGE_TMPL__. Pages routes are excluded.
2026-08-06 13:52:40 +08:00
ryan
1a4a03a20d
fix(agent): clear sticky LastError on successful sync paths
...
Pages reconcile could succeed while agent state retained a previous
network error, so health events stayed active indefinitely. Clear
LastError whenever sync completes successfully without re-applying
config, and cover the paths with regression tests.
2026-08-06 13:47:48 +08:00
ryan
4eced2b721
feat(cloudflare): add DNS pointing integration
2026-08-04 13:30:40 +08:00
ryan
3edcdb9e9f
feat(cloudflare): add DNS pointing integration
...
Implement Cloudflare connection management, pointing groups and members, asynchronous A-record reconciliation, node IP triggers, admin APIs, management pages, migrations, tests, and documentation.
2026-08-04 12:32:37 +08:00
ryan
943818f7d4
refactor(repository): 收敛 model/repository 分层为唯一持久化入口
...
将 OpenFlare 与平台业务的数据访问从 model 与 apps 直连迁入 repository,
model 仅保留实体与无 IO 规则;补充 code-check 架构守卫与开发规范。
2026-07-24 17:00:17 +08:00
ryan
23a5488203
refactor(http): remove dead internal/util HTTP client wrapper
...
Drop internal/util (unused httppool wrapper and dead StringArray) and
rely on pkg/httppool plus oauth context injection for HTTP clients.
2026-07-24 15:49:52 +08:00
ryan
d99c5b7c43
refactor(pkg): merge pkg/utils into pkg/util
...
Consolidate pure helper packages under pkg/util and update imports.
2026-07-24 15:45:10 +08:00
ryan
33a1c32cf8
refactor(structure): group platform, infra, and shared packages
...
Reorganize internal packages into platform/infra/shared layers and update
imports, docs, and seed-count tests to match current system configs.
2026-07-24 15:41:59 +08:00
ryan
f28aa6520e
fix(lint): 消除 linter 告警
2026-07-20 15:53:53 +08:00
ryan
d58b4b6b0e
feat(waf): 自动 IP 组 lookback 支持 60m/1h 时长写法
...
将 lookback_minutes 替换为 lookback,移除最小 5 分钟回看限制,并兼容旧字段。
2026-07-20 15:48:16 +08:00
ryan
866f1df5e3
fix(waf): IP 组同步间隔下限改为 1 分钟
...
移除同步周期 5 分钟限制;回看窗口仍保持最小 5 分钟。
2026-07-20 15:41:31 +08:00
ryan
351e8ce78c
feat(waf): StatusRatio/StatusCount 支持 2xx/4xx/5xx 类写法
...
自动 IP 组表达式可按状态码类汇总占比与计数,兼容原有精确状态码。
2026-07-20 15:39:14 +08:00
ryan
ae5345c03e
feat(rate-limit): add default request rate limit configuration
...
- Support openresty_default_limit_req_per_ip in system_configs.
- Add limit_req and limit_req_status 429 directive generation in openresty renderer.
- Implement route-level limit_req_per_ip override and explicit disable.
- Add frontend UI inputs and validation in rate limits tab config.
- Update swagger API docs and changelog for v3.4.3-beta.3.
2026-07-20 10:58:13 +08:00
ryan
a963b8bf54
chore(prettier): format 并清理无用 import
...
make prettier 统一格式化,goimports 与 eslint unused-imports 自动移除未使用导入。
2026-07-19 20:51:12 +08:00
ryan
4481677ef3
refactor(pages): 公开部署源任务并默认每日扫描
...
移除 Pages 部署源任务的 InternalOnly 限制,任务管理可查看与调度;
将 scanner cron 与 GitHub latest 默认检查间隔调整为每天一次,
并优化部署历史列表展示。
2026-07-19 20:41:09 +08:00
ryan
20249d917c
feat(rate-limits): use 3-minute trend buckets
...
Rate-limit analysis requests overview with bucket_minutes=3; RPS uses
count/180. Overview still defaults to 60-minute buckets.
2026-07-19 20:30:20 +08:00
ryan
abe8fb8268
refactor(pages): 精简部署源模型并重构详情页交互
...
将 Remote 网络策略收敛为 allow_insecure,去掉脱敏与无用字段;
Pages 详情拆为部署/设置 Tab,统一卡片样式与来源信息展示。
2026-07-19 20:23:31 +08:00
ryan
c92f986978
merge: 合并 PR #22 Pages 部署源 V2 到 feat/pages-source-sync-v2
...
基于最新 main 合并 deqiying/feat/pages-source-sync-v2,
解决 docs/changelog/index.md 与限流相关条目的冲突。
2026-07-19 19:36:48 +08:00