Commit Graph

255 Commits

Author SHA1 Message Date
ryan b04a358e5e fix: 配置版本列表按 created_at 倒序展示 2026-06-20 21:32:18 +08:00
ryan 889e79c8b8 fix: 收敛子代理站点标识双轨逻辑 2026-06-20 21:03:13 +08:00
ryan 9bf7e3cd1b fix: 修复 WAF 规则组 PoW 策略发布后边缘不生效 2026-06-20 20:47:38 +08:00
ryan 8751c0dee3 fix(openflare): mmdb 国家名节点在世界地图使用正确质心
- 从 world-geo 生成国家质心表,Server 在仅有 ISO/国家名时补全 geo 坐标
- 全球态势板在缺少经纬度时按 geo_name 解析质心,避免 fallback 到美国
2026-06-20 19:46:33 +08:00
ryan 498a9ed3ff fix(openflare): Agent 上报 IP 后由 Server 自动解析节点地理位置
- 启动时按 of_options.GeoIPProvider 初始化 pkg/geoip(bootstrap + runtime)
- mmdb 模式从内置 GeoLite2 种子到 data/;保存归属方式后热刷新 Provider
- Agent/Relay 心跳在服务端根据 IP 写入 geo 字段,尊重 geo_manual_override
- ipinfo 归属名称改为 City, Region, Country 可读格式
2026-06-20 19:36:17 +08:00
ryan ec53629971 fix(frontend): 修复配置版本快照侧栏无法滚动
将快照与发布预览 Sheet 内容区改为 flex-1 min-h-0 overflow-y-auto,
并固定侧栏高度为 h-svh,与项目内其他可滚动 Sheet 一致。
2026-06-20 19:22:23 +08:00
ryan 6c46f5d24f fix(openflare): Pages 部署包经 upload 存储下载
Agent 下载 Pages 包时统一通过 upload_id 走文件存储 API;legacy
artifact_path 仅用于一次性回填 upload 并清空路径。部署视图暴露
upload_id,并补充回归测试与 changelog。
2026-06-20 19:21:12 +08:00
ryan e077b12328 fix(frontend): cap envelope mismatch 2026-06-20 19:04:55 +08:00
ryan 570b639e07 fix(agent): commit GeoLite2 mmdb as build fallback
Vendor GeoLite2-Country.mmdb in the repository so agent builds still
work when the remote download is unavailable. Update the fetch script
and agent Dockerfile to prefer a fresh download and fall back to the
committed database file.
2026-06-20 14:04:42 +08:00
ryan 3a368119e5 fix(ci): fetch GeoLite2 mmdb before agent build
Agent embeds GeoLite2-Country.mmdb but the file is not checked into the
repository. Download it in CI, Docker, and Makefile build paths via
scripts/fetch-agent-geoip-mmdb.sh, and correct the gitignore exception
path for the geoipdata package.
2026-06-20 14:03:43 +08:00
ryan 6975a6c290 sync ci 2026-06-20 13:44:24 +08:00
ryan 2a0ebd16fa fix(backend): 修复优雅停机失效、系统设置并发读写冲突、文件服务API信封绕过以及测试uploads目录污染
- 修复 ClickHouse Batch Writer 与 RiskControl LogWriter 优雅停机,确保退出前队列数据正确刷盘。
- 修复 OpenFlare 系统配置参数全局变量并发读写的 Data Race 冲突,在读取配置时引入读锁保护。
- 修复 upload 模块的 API 错误响应格式,使用 response.Abort* 代替原始的 c.AbortWithStatus 与 c.JSON,保证全局信封格式统一。
- 修复 pkg/utils/network 的 isPrivateIPv4 以使用标准库 net.IP.IsPrivate() 校验,修复 format 的 Bytes2Size 边界,修改大小单位因子变量为只读常量。
- 重构 upload 文件服务与路由器测试,使用 t.TempDir() 代替硬编码的 uploads 相对路径写入和删除,解决测试目录文件污染问题。
2026-06-20 09:33:42 +08:00
ryan b3a55d4ab5 refactor(core): optimize performance, fix concurrency and clean up AGENTS.md design violations
- Concurrency: Added lock protection to WebSocket writes, fixed timer leaks, and prevented config cache listener context leaks.
- Performance: Added memory cache in ObservabilityBufferStore, periodic cleaning in CH Deduplicator, and buffered ZIP batch download writes.
- Design: Introduced Redis caching for OAuth session/tokens, sanitized raw DB error messages, segregated handlers and logics, and standard CAP response envelopes.
2026-06-20 09:09:02 +08:00
ryan 5bed2bae9f migrate database 2026-06-19 22:18:52 +08:00
ryan b6c4181c70 fix(openflare): serialize access log snowflake IDs as strings
- Return AccessLogView.id as string to avoid JS Number precision loss
- Store OpenFlareAccessLog IDs as uint64 with json id,string
- Update frontend AccessLogItem.id type to string
2026-06-19 20:10:09 +08:00
ryan 3187934f72 fix(openflare): ClickHouse count scan and dashboard traffic metrics
- Scan ClickHouse count()/countIf() aggregates as uint64 before int64 conversion
- Fix access log list count, region stats, and delete pre-count queries
- Aggregate dashboard 24h traffic totals from hourly trend buckets
- Show current hour value in traffic trend chart summary
- Rename docker-compose service to openflare
- Remove redundant config preview section from performance page
2026-06-19 17:34:19 +08:00
ryan 9491b2a744 feat(clickhouse): wire batchwriter into business ingestion paths
Migrate risk_control audit logs to internal/db/batchwriter and add
openflare/chwriter with per-table async flush for observability
timeseries and node access logs.

Replace single-row ClickHouse inserts and pre-insert SELECT count()
dedup with repository BatchInsert* APIs, in-process TTL dedup for
metric/report snapshots, and bootstrap initialization on API startup.
2026-06-19 17:20:39 +08:00
ryan ca6c20ebd9 feat(db): add ClickHouse batchwriter framework and skill
Introduce internal/db/batchwriter as a reusable generic buffered writer
for per-domain ClickHouse flush pipelines, with unit tests and default
batch tuning aligned with audit log ingestion.

Add clickhouse-batchwriter agent skill and cross-references in AGENTS.md
and database-migration. Business layers are not wired yet.
2026-06-19 17:20:39 +08:00
ryan 578110f615 observation clickhouse 2026-06-19 17:20:39 +08:00
ryan 32861c5db9 fix lint 2026-06-19 17:20:39 +08:00
ryan 0b34792709 refactor(edge): Server 协议统一与 wsclient 收敛(Phase 3 Batch 3)
- openflare/agent/relay/flared 协议类型改为 pkg/protocol 别名,删除重复 struct
- 新增 edge/wsclient Preset 表,三组件 wsclient 改为薄包装
- 更新设计文档、计划与 changelog
2026-06-19 15:00:46 +08:00
ryan db9a9f98fd refactor(edge): 抽取边缘运行时共享包并完成 Phase 3 重构
- 新增 internal/apps/edge/,三组件改为薄包装,删除 3000+ 行重复代码
- Agent 心跳周期下沉至 heartbeat/cycle.go
- 协议类型迁入 pkg/protocol/agent.go
- 补充设计文档与 changelog
2026-06-19 14:56:00 +08:00
ryan cc5e53c51e 文档更新 2026-06-19 14:45:17 +08:00
ryan 9eeeb09d2f feat(repo): rename output server binary from wavelet to openflare-server 2026-06-19 14:36:46 +08:00
ryan 63cd906cfc refactor(repo): consolidate openflare-server to root and move subprojects to internal/apps
- Merge all files inside openflare-server to the repository root directory.
- Relocate agent, relay, and flared subprojects from internal/ to internal/apps/.
- Combine docker-compose files and update build context paths to root.
- Update GitHub workflows and Dockerfiles to refer to new directories and package names.
- Rewrite Go package imports across all files.
- Resolve database renew test race condition and clean up docs.
2026-06-19 14:23:29 +08:00
ryan 8506a03f1c refactor(clickhouse): route of_node_access_logs through analytics repository
Move all ClickHouse DML for OpenFlare node access logs into
internal/repository/analytics; model layer keeps domain aggregation and
in-memory test store via a thin adapter. Aligns with goose-managed DDL
and openflare database startup dependency.
2026-06-19 12:13:18 +08:00
ryan 8a00f53b16 feat(clickhouse): integrate goose migrations and analytics repository
Merge upstream Wavelet patch to manage ClickHouse DDL via goose
(goose_clickhouse_version), add GORM ChDB access, and centralize
w_user_access_logs reads/writes in internal/repository/analytics.
OpenFlare of_node_access_logs DDL moves to goose/clickhouse; remove
manual clickhouse_schema startup and support-files SQL duplicates.
2026-06-19 12:11:41 +08:00
ryan fff26aa343 merge: migrate of_node_access_logs to ClickHouse
Integrate clickhouse worktree: node access logs now stored in ClickHouse
(openflare database) with mandatory startup dependency.
2026-06-19 11:45:51 +08:00
ryan 425ca89765 feat(openflare): migrate of_node_access_logs to ClickHouse
Move node access log storage from PostgreSQL/SQLite to ClickHouse
(database: openflare). System startup now requires a healthy ClickHouse
connection and auto-initializes the schema. Agent heartbeat writes access
logs via batch insert; goose migration drops the legacy relational table.
2026-06-19 11:45:48 +08:00
ryan 7eb943f02f update doc 2026-06-19 11:45:22 +08:00
ryan aa11c0f52a merge: replace legacy openflare-server with Wavelet rename 2026-06-19 11:30:05 +08:00
ryan 88360350a0 refactor(repo): replace legacy openflare-server with Wavelet rename
Delete the old monolithic openflare-server implementation and rename
Wavelet/ to openflare-server/ to complete the migration consolidation.
Update CI workflows, agent Dockerfiles, and deployment docs for the new
layout (frontend/, docker/Dockerfile).
2026-06-19 11:29:17 +08:00
ryan e3353cd09d docs(openflare): complete Swagger for protocol and dashboard APIs
Add Swagger annotations for all Agent, Relay, and Tunnel protocol
endpoints under /api/v1. Register AgentTokenAuth and TunnelTokenAuth
security definitions. Align dashboard API docs to return 404 for
insufficient admin permission.
2026-06-19 11:26:56 +08:00
ryan 46123d62ae Merge remote-tracking branch 'origin/dev' into dmux-2026-06-19-110554 2026-06-19 11:23:35 +08:00
ryan 68ddad98fb merge: unify protocol API responses to Wavelet format 2026-06-19 11:23:19 +08:00
ryan 33b4123444 refactor(openflare): unify protocol API responses to Wavelet format
Migrate Agent/Relay/Tunnel handlers from compat {success,message,data}
to response.OK and response.Abort* with real HTTP status codes. Remove
the compat package and update openflare-agent, openflare-relay, and
openflared clients to parse {error_msg,data}.
2026-06-19 11:23:12 +08:00
ryan 16e97d0dc3 merge: remove unused About page and API 2026-06-19 11:18:20 +08:00
ryan 7aa4cc908d merge: remove legacy openflare update API 2026-06-19 11:18:15 +08:00
ryan 8fb988ba0a refactor(openflare): remove unused About page and API
Delete AboutService and GET /api/v1/d/about since the about page was
never implemented in the Wavelet frontend.
2026-06-19 11:18:15 +08:00
ryan 53bd451450 refactor(openflare): remove legacy update API, use admin updater
Drop the migrated /api/v1/openflare/update compatibility layer and point
the OpenFlare upgrade UI at Wavelet's /api/v1/admin/update endpoints.
2026-06-19 11:17:45 +08:00
ryan 42ca0ec642 merge: fix(openflare) align admin permission model with Wavelet
Merge dmux-2026-06-19-110554; resolve changelog conflict keeping /api/v1/d/*
path migration and new AdminMiddlewares permission model.
2026-06-19 11:14:30 +08:00
ryan 49d32d0b25 fix(openflare): align admin permission model with Wavelet
Unify OpenFlare console auth to user.IsAdmin and token_admin instead of
the legacy Admin/Root role tiers. Route groups now use
apiutil.AdminMiddlewares (LoginRequired + LoginAdminRequired) so admin
checks cannot be skipped. Add middleware tests and extend integration
coverage for 401/404/400 responses.
2026-06-19 11:13:57 +08:00
ryan 915c00eb34 docs: 同步 OpenFlare 迁移文档与当前实码
更新后端 handover、实现计划 §12 端点对照表与 changelog,
反映 legacy 层已撤销、控制台 /api/v1/d/* 与协议路径现状,
并消除 OpenFlare-Token 桥接相关矛盾表述。
2026-06-19 11:13:10 +08:00
ryan e3309df336 merge: remove legacy global API rate limit options 2026-06-19 11:09:13 +08:00
ryan c69378f0de refactor(openflare): remove legacy global API rate limit options
Drop unused GlobalApi/Web/Critical rate limit settings migrated from the
old server but never wired up in Wavelet, including validation, defaults,
seed data, and a cleanup migration for existing databases.
2026-06-19 11:08:58 +08:00
ryan 71ebfa555f refactor(api): unify routes under /api/v1/d, agent, relay, tunnel
Remove the /openflare prefix from management APIs (/api/v1/d/*) and move
Agent, Relay, and Tunnel protocol endpoints under /api/v1. Update Wavelet
frontend services and node client binaries to match.
2026-06-19 11:08:06 +08:00
ryan 6bd7dc91fc refactor(openflare): mount console APIs under /api/v1/openflare
Move OpenFlare route registration from RegisterCustomRoutes to
v1.RegisterV1Routes so business APIs are mounted directly at
/api/v1/openflare instead of under the /custom example prefix.
Update handler Swagger annotations, frontend service base paths,
and regenerated swagger docs accordingly.
2026-06-18 21:25:20 +08:00
ryan 399c1bc88d refactor(openflare): migrate console APIs to v1 and centralize routing
Move OpenFlare management endpoints to /api/v1/custom/openflare with
Wavelet response envelopes and Abort* error handling. Keep agent, relay,
and flared protocol routes on /api/* with the legacy compat format.

- Add apiutil helpers and Swagger annotations for console handlers
- Register all OpenFlare routes in internal/router/openflare (not apps)
- Switch frontend services to OpenFlareBaseService and v1 paths
- Remove dead auth/compat code and legacy-base.service.ts
- Update integration tests and changelog
2026-06-18 21:25:20 +08:00
ryan aa348a1b48 merge: 规则组编辑改用 Sheet 抽屉 2026-06-18 20:24:23 +08:00
ryan a2f838605c feat(waf): 规则组新建/编辑改用右侧 Sheet 抽屉
将 RuleGroupDialog 替换为 RuleGroupSheet,使用 shadcn Sheet 侧栏交互,
与站点绑定等操作保持一致;添加规则条目仍保留弹窗。
2026-06-18 20:23:56 +08:00