ryan
fb08002e99
chore(release): v3.4.4
...
### 新增
- 新增全局源站错误页:可在「网站管理 → 错误页」配置开关、触发状态码(支持 `500-599` 区间与单码)与自定义 HTML;默认启用 OpenFlare 极简错误页并保持真实 HTTP 状态码,修改后随配置版本发布下发到边缘,关闭后恢复透传。
- 新增 Cloudflare DNS 指向管理:可复用现有 Cloudflare DNS 账号或配置独立 Token,按分组将 ZoneDomain 的单条 A 记录异步同步到边缘节点 IPv4,并支持成员橙云、同步状态与节点 IP 变更联动。
### 修复
- 修复 Agent 在配置已对齐但磁盘校验和不一致时,Pages 等对账成功后仍保留 `LastError` 的问题,避免偶发网络失败被健康事件长期显示为「活动中」且无法自动恢复。
### 改进
- 删除、撤销与未保存离开等确认操作统一改用页面内 AlertDialog,不再使用浏览器原生 `confirm` 弹窗,交互风格与系统其余对话框保持一致。
2026-08-06 15:52:26 +08:00
ryan
f650214bbb
fix(openresty): preserve origin error status on custom error pages
...
Remove error_page '=' form that adopted the internal URI status (often 200)
and left ngx.status as 0. Resolve the original code from $status/upstream
and set ngx.status before rendering the HTML body.
2026-08-06 15:45:41 +08:00
ryan
ba1c9222c2
refactor(error-pages): preset templates with OpenFlare branding
2026-08-06 15:25:39 +08:00
ryan
076bf8b95c
Merge branch 'feat/origin-error-page'
2026-08-06 14:16:28 +08:00
ryan
835c50dbaa
docs: origin error page configuration and changelog
...
Document three origin error page Option keys in configuration reference
and merge the unreleased changelog entry into a user-readable description.
2026-08-06 14:10:03 +08:00
ryan
42f7f47716
feat(frontend): add origin error page settings under websites
2026-08-06 14:05:21 +08:00
ryan
7d47db1f34
feat(option): seed and validate origin error page options
2026-08-06 13:59:54 +08:00
ryan
68d8f786cc
feat(openresty): render origin error page directives
...
Wire origin error page into OpenResty proxy route rendering: ConfigSnapshot
fields, default HTML template SupportFile, proxy_intercept_errors + error_page
with status-preserving internal Lua location, and Agent placeholder substitution
for __OPENFLARE_ERROR_PAGE_TMPL__. Pages routes are excluded.
2026-08-06 13:52:40 +08:00
ryan
9d93dc0b9f
merge: fix/agent-clear-last-error-on-sync-success
...
Merge agent sticky LastError clear fix into main.
2026-08-06 13:48:14 +08:00
ryan
1a4a03a20d
fix(agent): clear sticky LastError on successful sync paths
...
Pages reconcile could succeed while agent state retained a previous
network error, so health events stayed active indefinitely. Clear
LastError whenever sync completes successfully without re-applying
config, and cover the paths with regression tests.
2026-08-06 13:47:48 +08:00
ryan
07e835c543
feat(openresty): add status code tag expand helper
2026-08-06 13:46:58 +08:00
ryan
1f5bebd18a
docs(plan): add origin error page implementation plan
...
拆分为状态码解析、OpenResty 渲染、Option/快照、前端设置页与文档验收五步任务。
2026-08-06 13:44:45 +08:00
ryan
fd62570431
docs(design): add origin error page design
...
全局可配置源站错误页:默认 500-599、Cloudflare 风格模板、
状态码透传与在线 HTML;配置进 Option 与配置版本快照。
2026-08-06 13:42:41 +08:00
ryan
484b49d79d
fix(frontend): replace browser confirm dialogs with AlertDialog
...
统一删除、撤销与未保存离开等确认操作为 shadcn AlertDialog,避免
window.confirm/alert 打断界面风格;同步更新 WAF 编辑器相关单测与 changelog。
2026-08-06 13:08:43 +08:00
ryan
cffa009b8c
fix
2026-08-04 13:50:41 +08:00
ryan
4eced2b721
feat(cloudflare): add DNS pointing integration
2026-08-04 13:30:40 +08:00
ryan
ea7658815a
fix(migration): quote reserved authorization column
2026-08-04 12:49:58 +08:00
ryan
3edcdb9e9f
feat(cloudflare): add DNS pointing integration
...
Implement Cloudflare connection management, pointing groups and members, asynchronous A-record reconciliation, node IP triggers, admin APIs, management pages, migrations, tests, and documentation.
2026-08-04 12:32:37 +08:00
ryan
99f0f63b99
agents rename
2026-08-04 11:40:32 +08:00
ryan
21fb303ef2
doc: cloudflare 对接
2026-08-04 11:31:11 +08:00
ryan
3aa4d98cd6
ci: canary version
2026-08-03 21:53:52 +08:00
ryan
1f71c9f25b
ci: canary version
2026-08-03 21:53:08 +08:00
ryan
943818f7d4
refactor(repository): 收敛 model/repository 分层为唯一持久化入口
...
将 OpenFlare 与平台业务的数据访问从 model 与 apps 直连迁入 repository,
model 仅保留实体与无 IO 规则;补充 code-check 架构守卫与开发规范。
2026-07-24 17:00:17 +08:00
ryan
23a5488203
refactor(http): remove dead internal/util HTTP client wrapper
...
Drop internal/util (unused httppool wrapper and dead StringArray) and
rely on pkg/httppool plus oauth context injection for HTTP clients.
2026-07-24 15:49:52 +08:00
ryan
d99c5b7c43
refactor(pkg): merge pkg/utils into pkg/util
...
Consolidate pure helper packages under pkg/util and update imports.
2026-07-24 15:45:10 +08:00
ryan
33a1c32cf8
refactor(structure): group platform, infra, and shared packages
...
Reorganize internal packages into platform/infra/shared layers and update
imports, docs, and seed-count tests to match current system configs.
2026-07-24 15:41:59 +08:00
ryan
68d730a388
chore(release): v3.4.3
...
### 🛠 修复
- 修复了 IP 组自动抓取使用预设规则时未写入 ttl 的问题,避免配置缺少封禁时长。
- 修复了限流相关数据库迁移中的表名错误,确保升级脚本正确执行。
### ⚡ ️ 优化与改进
- 边缘缓存对齐 Cloudflare 默认模型:不再因登录 Cookie 等请求头一律跳过缓存,登录用户可命中静态资源;响应 Set-Cookie 不入库,并补充默认 Edge TTL。生效需重新发布节点配置。
- 新增全局与站点级单 IP 请求频率限制,触发时返回 429,并支持继承、关闭与按站点隔离。
- IP 组自动规则支持 2xx/4xx/5xx 类状态码写法,同步间隔下限降至 1 分钟,回看窗口支持 60m/1h 等时长写法。
- 限流页请求压力图 RPS 纵轴按可见窗口峰值动态缩放,低流量更易读。
### 💄 其他/体验
- 补充边缘缓存运维与故障排查说明,并对「所有可缓存 GET」策略增加风险提示。
2026-07-24 00:04:20 +08:00
ryan
f94767fbc7
perf(cache): 边缘缓存对齐 Cloudflare 默认模型
2026-07-23 23:39:15 +08:00
ryan
5b1e27d0a3
feat(frontend): biome
2026-07-22 22:25:30 +08:00
ryan
f28aa6520e
fix(lint): 消除 linter 告警
2026-07-20 15:53:53 +08:00
ryan
d58b4b6b0e
feat(waf): 自动 IP 组 lookback 支持 60m/1h 时长写法
...
将 lookback_minutes 替换为 lookback,移除最小 5 分钟回看限制,并兼容旧字段。
2026-07-20 15:48:16 +08:00
ryan
866f1df5e3
fix(waf): IP 组同步间隔下限改为 1 分钟
...
移除同步周期 5 分钟限制;回看窗口仍保持最小 5 分钟。
2026-07-20 15:41:31 +08:00
ryan
351e8ce78c
feat(waf): StatusRatio/StatusCount 支持 2xx/4xx/5xx 类写法
...
自动 IP 组表达式可按状态码类汇总占比与计数,兼容原有精确状态码。
2026-07-20 15:39:14 +08:00
ryan
67a30eb5ed
fix(waf): IP 组预设规则写入默认 ttl
...
点击自动抓取预设规则时补齐 ttl=-1,并规范化自动配置默认 JSON。
2026-07-20 15:36:06 +08:00
ryan
80c47f6ff3
feat(rate-limit): 站点级请求频率限制支持继承与自定义
...
在站点详情流量限制中配置 limit_req_per_ip;渲染按 effective rate 生成多 limit_req_zone,并以站点+IP 隔离计数。
2026-07-20 15:02:38 +08:00
ryan
a261c01a9c
fix(db): correct table name to of_proxy_routes in migration
2026-07-20 14:06:07 +08:00
ryan
ae5345c03e
feat(rate-limit): add default request rate limit configuration
...
- Support openresty_default_limit_req_per_ip in system_configs.
- Add limit_req and limit_req_status 429 directive generation in openresty renderer.
- Implement route-level limit_req_per_ip override and explicit disable.
- Add frontend UI inputs and validation in rate limits tab config.
- Update swagger API docs and changelog for v3.4.3-beta.3.
2026-07-20 10:58:13 +08:00
ryan
fda8d7fcb1
fix(rate-limits): 请求压力纵轴随 dataZoom 可见区间缩放
...
拖动底部时间范围条时按可见窗口最高 RPS×1.5 更新纵轴,访客轴同步按可见数据重算。
2026-07-20 09:02:31 +08:00
ryan
b91c848256
fix(rate-limits): RPS 纵轴按峰值 1.5 倍动态缩放
...
请求压力图不再使用固定美化刻度上限,改为当前时段最高 RPS × 1.5,低流量更易读、高峰不易裁切。
2026-07-20 08:49:46 +08:00
ryan
36cff502f7
chore(release): v3.4.2
...
### 🛠 修复
- 修复 Pages 部署包路径校验、归档展开限额、历史版本裁剪、代理路由绑定与 Agent
下载过程中的安全和一致性问题;大包改为流式处理,异常中断遗留的部署包会安全补偿清理。
### ⚡ ️ 优化与改进
- Pages 项目新增持久部署源,支持 Remote URL 或公开 GitHub Release;GitHub latest
可按设定间隔自动检查并发布更新,默认间隔为每天一次。
- Remote URL 默认允许公网与内网地址,新增「允许不安全连接」开关。
- Pages 详情页重构为「部署 / 设置」Tab,部署源卡片样式更紧凑统一。
- 安全性新增「限流」设置,可为边缘站点配置默认并发与带宽;填 -1 可关闭。
- 限流页新增分析视图,展示请求压力与独立访客趋势,支持域名过滤与时间预设。
### 💄 其他/体验
- 精简部署源数据模型,去除脱敏与无用字段。
- Pages 部署源任务不再隐藏,可在任务管理中查看。
- make prettier 支持自动清理前后端无用 import。
- 限流趋势桶调整至 3 分钟粒度,范围扩展至 24h/3d。
- Agent 部署命令增加 Pages 命名卷持久化。
2026-07-19 20:54:57 +08:00
ryan
fa588797bf
chore: eslint fix 先于 prettier 执行
2026-07-19 20:52:01 +08:00
ryan
a963b8bf54
chore(prettier): format 并清理无用 import
...
make prettier 统一格式化,goimports 与 eslint unused-imports 自动移除未使用导入。
2026-07-19 20:51:12 +08:00
ryan
d9663f91d6
chore: make prettier 自动清理前后端无用 import
...
前端接入 eslint-plugin-unused-imports,pnpm format 同步执行 eslint --fix;
后端将 gofmt 替换为 goimports,并修复 danger-zone 未使用导入。
2026-07-19 20:47:28 +08:00
ryan
4481677ef3
refactor(pages): 公开部署源任务并默认每日扫描
...
移除 Pages 部署源任务的 InternalOnly 限制,任务管理可查看与调度;
将 scanner cron 与 GitHub latest 默认检查间隔调整为每天一次,
并优化部署历史列表展示。
2026-07-19 20:41:09 +08:00
ryan
20249d917c
feat(rate-limits): use 3-minute trend buckets
...
Rate-limit analysis requests overview with bucket_minutes=3; RPS uses
count/180. Overview still defaults to 60-minute buckets.
2026-07-19 20:30:20 +08:00
ryan
abe8fb8268
refactor(pages): 精简部署源模型并重构详情页交互
...
将 Remote 网络策略收敛为 allow_insecure,去掉脱敏与无用字段;
Pages 详情拆为部署/设置 Tab,统一卡片样式与来源信息展示。
2026-07-19 20:23:31 +08:00
ryan
f0b51a99b3
fix(db): 重编号 Pages 部署源迁移避免版本冲突
...
main 已占用 202607190001(OpenResty 默认限流),
将 Pages source runtime / scanner seed 顺延为
202607190002、202607190003,并同步迁移测试期望配置数。
2026-07-19 19:41:30 +08:00
ryan
c92f986978
merge: 合并 PR #22 Pages 部署源 V2 到 feat/pages-source-sync-v2
...
基于最新 main 合并 deqiying/feat/pages-source-sync-v2,
解决 docs/changelog/index.md 与限流相关条目的冲突。
2026-07-19 19:36:48 +08:00
deqiying
ccea08fe47
docs(pages): 收口部署源 V2 实现
...
同步 Pages、总体架构、Agent 与使用指南,记录阶段提交、验证结果和生产验收边界。
2026-07-19 19:25:28 +08:00
ryan
72962beb0f
feat(rate-limits): use 1m buckets and 24h/3d ranges
...
Allow overview bucket_minutes=1; rate-limit analysis uses 1-minute
buckets and replaces 7d preset with 3 days.
2026-07-19 19:20:59 +08:00
ryan
b56290d79d
feat(rate-limits): use 5m trend buckets and 24h/7d ranges
...
Overview API accepts bucket_minutes (5|60); rate-limit analysis uses
5-minute buckets and drops 15d/30d presets. Widen rank value column.
2026-07-19 19:18:15 +08:00
deqiying
67b051c2bc
feat(frontend): 支持 Pages 自动更新交互
...
在 GitHub latest 来源中提供自动更新开关、检查间隔和运行状态。\n页面按来源到期时间低频刷新,并在自动发布或人工回滚后同步项目与部署历史。
2026-07-19 19:09:57 +08:00
deqiying
999428cf9a
feat(pages): 增加来源扫描与自动更新
...
为 GitHub latest 来源增加五分钟 scanner、按来源间隔检查、精确 revision 自动发布与租约恢复。\n记录退避和投递统计,并为 PostgreSQL 与 SQLite 幂等创建内部排程。
2026-07-19 19:09:21 +08:00
ryan
86d2d6b0ad
feat(rate-limits): add RPS analysis tab with dual-axis chart
...
Split rate-limits into analysis/config tabs; reuse access-log overview
filters; chart hourly RPS vs visits with dataZoom; rank top hosts/IPs
by window-average RPS.
2026-07-19 19:09:01 +08:00
deqiying
848884d8cd
fix(pages): 增加部署包孤儿补偿
...
按项目、来源、运行时与上传记录锁序补偿异常中断遗留的部署包。\n同时隐藏并保护系统内部排程,避免通用任务管理入口修改 scanner。
2026-07-19 19:08:43 +08:00
ryan
f783a1e6fa
docs: add rate-limit analytics design
...
Tabs for analysis/config, dual-axis RPS chart with overview filters
and average RPS rankings from access-log overview.
2026-07-19 19:06:06 +08:00
deqiying
c39a3edcc3
feat(pages): 支持 GitHub Release 部署源
...
增加 latest/tag 手动检查与同步、ETag 与限流退避、资源替换确认,以及对应的前端来源管理和部署来源展示。
2026-07-19 18:31:42 +08:00
ryan
4c17f5277a
feat(agent): persist Pages dir in Docker deploy volume
...
Mount openflare-agent-pages to /data/var/lib/openflare/pages so
container rebuilds keep local Pages packages.
2026-07-19 18:28:35 +08:00
ryan
0e097a66c4
docs: document default edge rate limits
2026-07-19 18:19:20 +08:00
ryan
39cba821d5
feat(frontend): add security rate-limits page and inherit UI
2026-07-19 18:17:16 +08:00
ryan
c5f8105db8
feat(proxy-route): allow -1 to disable rate limits
2026-07-19 18:14:16 +08:00
ryan
2bc2d82ad0
feat(config): add openresty default rate limit system options
2026-07-19 18:12:51 +08:00
ryan
a3125c8276
feat(openresty): merge global default limits at route render
2026-07-19 18:10:51 +08:00
ryan
4d7b63f217
docs: add default edge rate limit implementation plan
...
Task breakdown for global OpenResty limit defaults, route inherit
semantics, security rate-limits page, and render-time merge.
2026-07-19 18:05:43 +08:00
ryan
fada04c373
docs: add edge default rate limit design
...
Specify global OpenResty limit defaults with per-route inherit (-1 off)
and render-time merge in RenderRouteConfig.
2026-07-19 18:02:13 +08:00
deqiying
38b0516937
feat(pages): 支持 Remote 部署源同步
...
新增部署源配置与运行态模型、安全下载、租约续期、原子激活和失败补偿。
接入内部任务与脱敏前端交互,并阻止数据库 Trace 和日志展开敏感查询参数。
2026-07-19 17:36:51 +08:00
deqiying
4e8ec23264
fix(pages): 收紧部署包与 Agent 同步边界
...
完成 V2 Phase 0 安全与一致性前置:统一真实归档限额、流式拉取、候选裁剪、保留上传删除语义及 Pages 路由引用锁。
2026-07-19 16:42:45 +08:00
deqiying
f386674464
docs(pages): 完善部署源 V2 实现方案
2026-07-19 16:14:09 +08:00
ryan
e0398397a9
chore(release): v3.4.1
...
### 🛠 修复
- 收紧 WAF 安全防护特征,降低对常见正常请求的误伤(含避免 SQL 特征 /* */ 误匹配 Accept: */*)。
- 优化 WAF 规则编辑器返回按钮、列表操作与属性栏布局体验。
- 节点详情「运行诊断」摘要不再展示具体错误日志,避免长日志撑破布局。
### ⚡ ️ 优化与改进
- WAF 规则编排新增「UA 检查」与「安全防护」节点,支持浏览器/操作系统白名单、爬虫与自定义正则屏蔽,以及路径穿越、注入类等基础特征检测。
- 优化边缘 WAF 安全防护、UA 检查与 IP 匹配热路径,降低开启基础防护时的 CPU 占用。
- Agent 内嵌 resty.ipmatcher,部署时不再依赖无效 opm 包。
- 新建反代规则时默认开启边缘缓存(标准静态资源策略)。
- 节点详情页调整为「概览」与「状态与部署」,边缘节点支持自动填充部署命令。
### 💄 其他/体验
- WAF 规则编辑器支持节点自定义命名、拖放添加、右键删除与一键格式化布局。
2026-07-19 15:43:05 +08:00
ryan
fafee0055a
feat(nodes): 优化
2026-07-19 15:42:02 +08:00
ryan
6619f5b650
fix(nodes): 运行诊断不再展示具体错误日志
...
摘要区仅保留异常数量与事件类型,避免长日志撑破卡片布局。
2026-07-19 15:25:02 +08:00
ryan
a65d0f291b
feat(nodes): 调整节点详情 Tab
...
将数据看板并入概览,运行状态与配置合并为状态与部署;。
2026-07-19 15:16:26 +08:00
ryan
c00ead9aa0
feat(nodes): 调整节点详情 Tab 并新增边缘部署命令
...
将数据看板并入概览,运行状态与配置合并为状态与部署;
边缘节点支持自动填充 Server URL 与 Agent Token 的 Docker 部署卡片。
2026-07-19 15:01:38 +08:00
ryan
7366832e12
fix(agent): 内嵌 resty.ipmatcher,移除无效 opm 依赖
...
OPM 无 api7/lua-resty-ipmatcher 账号导致镜像构建失败;改为 vendor
api7 v0.6.1 并随 ManagedWAFLuaFiles 部署到 lua 目录。
2026-07-19 14:57:51 +08:00
ryan
1a7e5e6c41
perf(waf): IP 匹配改为索引查询(ipmatcher / 预编译)
...
加载时编译 IP 组与节点 IP/CIDR 索引,优先 resty.ipmatcher 基数树,
否则 exact 哈希 + 预解析 CIDR,避免大名单线性扫描打满边缘 CPU。
2026-07-19 14:48:07 +08:00
ryan
46ce7de513
perf(waf): 收窄安全防护扫描面并优化 UA 热路径
...
注入类检测仅扫 Query/Cookie/Referer/有限 Body,避免全 Header 匹配拖垮边缘 CPU;
按开关采集输入、GET 跳过 read_body,UA 仅 lower 一次并用 set 匹配白名单。
2026-07-19 14:16:34 +08:00
ryan
39473cb370
chore: prettier
2026-07-19 13:00:01 +08:00
ryan
64e40a7c18
fix(waf): 移除编辑器未使用的图标导入以通过 code-check
2026-07-19 12:58:24 +08:00
ryan
53ddb45614
fix(waf): 规则编辑器返回按钮对齐 websites 详情样式
2026-07-19 12:55:49 +08:00
ryan
ad6621fce9
fix(waf): 收紧安全防护特征,降低常见正常请求误伤
...
- SSRF 仅匹配 URL 形态,避免 Chrome/x.0.0.0 误中
- 命令注入去掉裸 &&/|| 与裸 shell 名
- SQL sleep/benchmark 要求数字参数
- XSS javascript:/eval 要求更像代码的上下文
- 路径穿越去掉过宽的 c:\windows;CRLF 去掉单独 %0a/%0d
2026-07-19 12:54:01 +08:00
ryan
60d6e3e846
fix(waf): 调整编辑器返回与格式化布局按钮位置
...
返回置于标题上方;格式化布局移至保存按钮左侧。
2026-07-19 12:52:12 +08:00
ryan
fd9348b7bd
feat(waf): 规则编辑器一键格式化节点布局
...
按从开始节点出发的层次从左到右整理坐标,并 fitView 到画布。
2026-07-19 12:49:42 +08:00
ryan
32113eb790
fix(waf): 列表操作改为直接图标按钮
...
规则组与 IP 组表格去掉「…」菜单,操作以图标平铺展示。
2026-07-19 12:47:02 +08:00
ryan
1ba05ec0bd
fix(waf): 避免 SQL 特征 /* */ 误匹配 Accept: */*
...
开启 SQL 注入防护时不再把正常 Accept 头当成攻击。
2026-07-19 12:46:23 +08:00
ryan
b75f985815
feat(waf): 新增安全防护节点 security_check
...
基础特征检测九项可开关;默认开启路径穿越与文件包含;命中任意规则走 false。
2026-07-19 12:33:13 +08:00
ryan
db89f68547
docs(waf): 规格 — 安全防护节点 security_check
...
九项基础特征检测可开关;默认仅路径穿越与文件包含;命中任意规则 false。
2026-07-19 12:20:51 +08:00
ryan
74106474ca
fix(waf): UA 检查说明改为问号悬浮提示
...
将屏蔽/匹配相关 FieldDescription 收敛为 CircleHelp Tooltip。
2026-07-19 11:52:29 +08:00
ryan
1d97ea69d0
fix(waf): UA 检查属性栏将屏蔽区块移到匹配上方
2026-07-19 11:49:55 +08:00
ryan
53d9572508
refactor(waf): 移除规则画布右上角删除按钮
...
删除改为右键菜单与键盘快捷键。
2026-07-19 11:48:54 +08:00
ryan
8f3ff59567
feat(waf): 规则画布右键删除节点与连线
...
覆盖画布默认右键菜单;节点/连线右键弹出删除项,系统节点禁用。
2026-07-19 11:47:04 +08:00
ryan
d47ceb9971
feat(waf): UA 非正常不含爬虫,并支持自定义正则屏蔽
...
block_abnormal_ua 仅 Other/Unknown;新增 block_custom_ua 与 custom_ua_patterns。
2026-07-19 11:43:45 +08:00
ryan
7476c86976
fix(waf): UA 检查开启后才显示匹配与屏蔽并补充说明
...
未开启 require_ua 时隐藏匹配/屏蔽区块;爬虫与非正常 UA 开关增加分类提示。
2026-07-19 11:38:18 +08:00
ryan
28eef0bbcd
feat(waf): 新增 UA 检查节点 ua_check
...
支持要求携带 UA、浏览器/OS 白名单 and-or 匹配,以及优先屏蔽爬虫与非正常 UA。
2026-07-19 11:35:31 +08:00
ryan
047ed6554d
docs(waf): 规格 — UA 检查节点 ua_check
...
定义 require/白名单 and-or/屏蔽优先级及与访问日志一致的 UA 分类标签。
2026-07-19 11:27:55 +08:00
ryan
b5e27fabde
feat(waf): 规则编辑器节点自定义命名与拖放添加
...
对齐后端 label 字段;属性栏可编辑显示名称;节点库改为拖到画布落点创建。
2026-07-19 11:01:24 +08:00
ryan
4166cc9861
docs(waf): 规格 — 规则编辑器节点命名与拖放添加
...
确认仅前端消费已有 label,节点库改为拖到画布落点,不做备注。
2026-07-19 10:57:28 +08:00
ryan
24862dcbed
chore(release): v3.4.0
...
### 🛠 修复
- 修复了访问日志概览按域名筛选无效的问题,现已兼容 hosts 与 hosts[] 参数。
- 修复了 Agent 观测缓冲合并访问日志时忽略 cache_status 导致缓存状态被去重丢弃的问题。
- 修复了访问日志概览在 ClickHouse 查询失败时静默吞错的问题,现会输出错误日志便于排查。
- 修复了数据看板业务流量趋势与已提供数据口径不一致的问题,业务量统一由访问日志聚合。
- 修复了节点地图在缺少精确经纬度时,把香港/新加坡/台湾等地区错误标到占位坐标的问题。
### ⚡ ️ 优化与改进
- 访问日志重构为概览、IP 明细与日志明细:支持时间窗聚合 IP 请求数/2xx 比例/入出站流量与详情分析,明细展示完整请求字段。
- 边缘访问日志支持 User-Agent 与 cache_status(命中/回源/未缓存),概览增加设备/浏览器/系统与状态码分布。
- 新建站点开启缓存时推荐仅缓存标准静态资源(不含 HTML);存量空策略与按 URL 行为保留为所有可缓存 GET。
- 边缘观测以访问日志为业务唯一真相;Agent 仅上报明细与主机读数,升级需重建或替换 Agent。
- Pages 支持更多压缩格式上传、URL 导入部署包,以及可配置的包大小与历史保留策略。
### 💄 其他/体验
- 优化了访问日志排行榜与饼图布局,页签状态支持 URL 参数记忆。
- 启用 cache_status 与边缘缓存策略变更后,需执行相关迁移并重新发布节点配置。
2026-07-19 10:45:40 +08:00
ryan
920a530aa7
feat(access-logs): 新增 IP 明细 Tab 并完善日志详情字段
...
按时间窗聚合 IP 请求数/2xx 比例/入出站流量,支持排序与详情分析;
日志明细详情仅展示请求业务字段,IP 情报迁至独立详情弹窗。
2026-07-19 00:42:59 +08:00
ryan
bfd9de69af
fix(access-logs): 修复概览域名筛选参数 hosts[] 被 Gin 忽略
...
Axios 默认序列化为 hosts[]=,Gin QueryArray("hosts") 读不到导致筛选失效;
后端兼容 hosts/hosts[],前端改为重复键序列化。
2026-07-19 00:28:37 +08:00
ryan
204f6d9a8b
fix(cache): 存量空/url 策略规范为 all,避免静默收窄
...
评审修复:enabled 且 policy 为空或 url 时,写入/展示/快照/渲染均映射为 all,
保证旧站点宽缓存范围不变;新建 UI 仍显式提交 static 作为推荐默认。
2026-07-19 00:02:52 +08:00
ryan
04f029c705
feat(cache): 开启缓存默认仅缓存标准静态资源
...
路由缓存策略新增 static(内置扩展名,不含 HTML)与 all;
存量 url 规范为 all。OpenResty 渲染与代理路由 UI 同步。
2026-07-18 23:32:49 +08:00
ryan
7401f5d0b4
docs(design): 边缘缓存默认可缓存范围对标 Cloudflare
...
约定开启缓存默认 static 扩展名策略,存量 url 映射为 all,
并明确第一期不做 Edge TTL/Purge/Cache Rules。
2026-07-18 23:24:23 +08:00
ryan
0bb6830047
feat(access-logs): 概览支持 Zone/域名多选筛选
...
概览可按 Zone→Domain 层级多选域名并折叠展开;明细列表 IP 旁展示地区。
后端 overview 支持 hosts 多域名精确匹配。
2026-07-18 23:07:19 +08:00
ryan
6f221b042e
fix(agent): 观测缓冲去重纳入 cache_status 并保留原始 -
...
避免同一请求不同缓存状态被合并丢弃;OpenResty 的 - 原样入库便于详情区分。
2026-07-18 22:56:10 +08:00
ryan
fb5a4e5b59
feat(access-logs): 上报并展示边缘缓存状态 cache_status
...
OpenResty 日志输出 $upstream_cache_status;Agent/协议/ClickHouse 贯通入库。
明细列表与详情按 HIT/MISS 等推导命中、回源、未缓存三态标签。
2026-07-18 22:50:46 +08:00
ryan
ee9d651c8a
docs(obs): 约定访问日志 cache_status 与明细三态展示
...
仅上报 $upstream_cache_status,不上报回源地址;UI 由原始值推导
命中缓存 / 回源 / 未使用缓存。
2026-07-18 22:46:46 +08:00
ryan
9aec984bee
feat(access-logs): 明细详情支持 IP 分析与 URL Tab 记忆
...
- 新增单 IP 分析接口,趋势时间范围支持至 30 天
- 明细详情弹窗展示趋势、汇总与 Top 分布,可快捷管理 IP 组
- 访问日志页签改为 URL 参数记忆,筛选后保持当前 Tab
2026-07-18 22:40:21 +08:00
ryan
bf71bc540b
feat(access-logs): 优化概览饼图布局并在查询出错时增加日志记录
...
- 将设备类型与状态码饼图的断点由 xl 降为 lg,在大屏/笔记本视口下保持双列展示
- 修复 valueCountDistribution 在 ClickHouse 查询出错时静默吞掉错误的缺陷,引入 logger.ErrorF 捕获
- 补充 unreleased 变更日志
2026-07-18 22:02:09 +08:00
ryan
e49078ac3b
feat(access-logs): 接入 User-Agent 与设备/浏览器/状态码分布
...
- Agent 访问日志上报 user_agent,OpenResty log_format 输出 http_user_agent
- of_node_access_logs 新增 user_agent 列并写入 ClickHouse
- 访问日志概览新增:设备类型饼图、状态码饼图、浏览器/OS/User-Agent 排行
- 日志明细列表增加 User-Agent 列
- 扩展 UA 解析工具(browser/os/device)并支持 CLI 识别
2026-07-18 21:18:59 +08:00
ryan
177578ef4e
feat(access-logs): 重构访问日志为概览与明细双 Tab
...
新增访问日志概览 API 与前端页面:汇总请求量/访问量/带宽趋势与 Top 排行,
明细列表保留检索;排行榜改为紧凑列表样式。
2026-07-18 20:58:32 +08:00
ryan
4c0c389122
chore(release): v3.3.1
...
### 🛠 修复
- 修复了看板业务流量趋势与 Zone 已提供数据口径不一致的问题,业务量统一由访问日志聚合,避免边缘预聚合窗口差分导致近 24 小时趋势严重偏低。
- 修复了节点地图在缺少精确经纬度时,将香港、新加坡、台湾等地区错误回退到南美等占位坐标的问题,补全质心数据并改进复合地名匹配。
### ⚡ ️ 优化与改进
- 重构边缘可观测模型:访问日志为业务唯一真相,Agent 仅上报明细、主机指标与 OpenResty 健康连接;新增 edge_health 与 access_log_hourly,删除请求预聚合与 OpenResty 吞吐路径。
- 协议去掉旧兼容层,Agent 升级需销毁重建或二进制替换;旧本地观测缓冲会自动删除并在运行中重建。
- 调整 Agent 默认心跳为 3 秒、离线判定为 60 秒、离线补传窗口为 60 分钟,使节点状态与观测数据刷新更及时。
- 看板 UV 改为窗口内真正去重,Zone 分桶 UV 明确不可跨桶相加;网络趋势仅保留已提供/接收数据,磁盘读写改为按秒速率展示。
- Pages 支持多压缩格式上传、URL 导入部署包,以及可配置的包大小上限与历史保留数量;边缘按项目只保留最新激活部署,切换版本无需重发主配置。
- 新建代理规则时可选择直连、隧道或 Pages 源站类型,与详情页一致。
- 优化 Pages 部署包校验性能,不再为包内每个文件计算哈希,改由整包校验和保障完整性。
### 💄 其他/体验
- 更新可观测设计文档与运维说明,明确健康状态权威源与升级策略。
- 同步 Swagger 与变更日志,便于对照 API 与发布说明。
2026-07-18 16:37:20 +08:00
ryan
a0ccafc6ee
fix(geo): 修复香港等节点地图质心缺失落到南美占位
...
补全 Hong Kong/Singapore/Taiwan 质心数据,并改进复合地名与 ISO 匹配,
避免 geo 无精确经纬度时错误回退到巴西等地的占位坐标。
2026-07-18 13:52:20 +08:00
ryan
26057514a1
feat(obs): 去掉宿主机网卡趋势,磁盘读写改按速率展示
...
Agent 不再采集网卡累计字节,看板与节点网络图仅保留访问日志已提供/接收。
磁盘 IO 按小时换算为 B/s 曲线,摘要为近 24 小时平均速率,并同步 Swagger。
2026-07-18 13:17:13 +08:00
ryan
55f8c9a527
fix(obs): 对齐无兼容层与健康/UV 权威语义
...
Agent 本地旧观测缓冲直接删除并运行重建;设计文档去掉兼容期表述。
健康当前态以 PG status/message 为准,CH 仅存 status 与连接时序;
Zone 曲线标明分桶 UV,顶部为整窗独立访客。
2026-07-18 12:09:27 +08:00
ryan
802d516f5b
docs: 观测重构 changelog 与 Swagger 同步
...
补充 unreleased 变更说明,并重新生成 Swagger 以匹配去兼容层后的 API。
2026-07-18 11:53:11 +08:00
ryan
71ce028f91
feat(frontend): 观测网络字节字段与 UV 文案对齐
...
网络图仅使用 bytes_provided/received;看板与节点 UV 改为 24h/查询窗口
独立访客;清理 traffic_reports 与 openresty 吞吐兼容字段;运维清理目标
改为 node_edge_health。
2026-07-18 11:53:11 +08:00
ryan
f0e234df1f
feat(obs): 访问日志 SSOT 与 edge_health,去掉协议兼容层
...
Agent 仅上报 host_metrics/edge_health/access_logs;业务流量与 UV 由
Server 侧访问日志聚合。新增 of_node_edge_health 与 of_access_log_hourly,
删除 request_reports/openresty 吞吐路径;API 不再暴露 traffic_reports
与 openresty_rx|tx。心跳/离线默认阈值与回填迁移一并入库。
2026-07-18 11:53:11 +08:00
ryan
9a0974cce8
docs(obs): 边缘可观测 SSOT 设计与实施计划
...
补充 observability 设计/数据模型/传输模型,更新架构与 Agent 文档侧栏,
并写入 M5 迁移与小时汇总回填运维说明。
2026-07-18 11:53:11 +08:00
ryan
3b9f4daa4e
perf(pages): skip per-file hashes during package inspect
...
Inspect deployment archives via file handles and declared sizes instead of loading the whole package and hashing every member, while keeping whole-package checksums for Agent integrity checks.
2026-07-17 18:37:34 +08:00
ryan
285f127d48
feat(proxy-routes): align create form with upstream type selection
...
Let new proxy rules choose direct, tunnel, or Pages origin the same way as the detail reverse-proxy section, instead of only accepting a single upstream URL.
2026-07-17 18:20:35 +08:00
ryan
79820b33eb
feat(pages): import deployment packages from URL
...
Add upload-from-url so admins can paste an HTTP(S) link and let the control
plane download the archive with browser-like headers. Private/LAN hosts and
insecure TLS certificates are allowed for internal artifact stores; package
size and format checks reuse the existing local-upload pipeline.
2026-07-17 17:55:12 +08:00
ryan
ce736e2de4
feat(pages): pull latest by project and keep a single edge release
...
Agents now treat pages_project_id as the stable anchor and fetch the
control-plane active package via project latest APIs, so activating a
deployment updates edges without republishing main config. Local roots use
projects/{id}/current, only the newest release is retained after a successful
switch, hash/package races retry, and per-project failures no longer block
siblings.
2026-07-17 17:43:40 +08:00
ryan
a0fcf9f627
feat(pages): configurable limits, multi-format packages, and dual versioning
...
Make Pages package size and history retention system-configurable, support
zip/tar.gz/tar.xz/tar.bz2/tar/7z uploads, prune history with clear keep-N
semantics, and rebind agent config to the live active Pages deployment so
main-config rollback never depends on pruned packages.
2026-07-17 17:16:48 +08:00
ryan
368df3f76b
chore(release): v3.3.0
...
### 🛠 修复
- 修复了 WAF 站点为空绑定规则时请求异常的问题,规范空站点绑定为数组并兼容历史 JSON 空值,避免请求时 Lua 处理失败。
- 修复了 WAF PoW 验证在部分场景下的异常。
- 修复了 Pages 部署文件列表请求与后端路由不一致的问题,并补充回归测试。
- 默认关闭 Redis maintenance notification 自动协商,并应用到平台与 Asynq 客户端,减少在不支持的 Redis 服务上的兼容性警告。
- 修复了 WAF 规则编辑器画布状态不稳定的问题:改用 React Flow 受控节点状态,支持删除节点与连线,节点属性仅在选中后展示。
### ⚡ ️ 优化与改进
- 新增 WAF 可组合规则可视化编排能力,提供基于 React Flow 的规则编辑器、有序图形 API 与运行时 DAG 执行;规则仅在 OpenResty reload 时发布,并通过校验和驱动的 IP 组快照在受界共享内存中协调。
- 完善 WAF 地域匹配数据,使用完整国家与一级行政区数据,国家选项同时显示中文名称与 ISO 代码,行政区支持按名称或代码搜索。
- Agent 现内置国家与城市地址库,首次启动无需下载即可使用地区匹配,并会在后续自动更新数据。
- 优化了 SQL 日志输出:常规查询日志下调至 debug 级别,慢查询与错误日志不再输出 SQL 文本,避免敏感参数在生产日志中暴露。
### 💄 其他/体验
- 优化了 WAF 规则编辑器初始视图,缩小编排区高度与首次适配缩放比例,默认显示更多画布上下文。
- 服务启动监听就绪后再打印服务横幅,避免在监听失败时显示误导性信息。
- 改进了日志打印输出。
2026-07-14 09:07:06 +08:00
ryan
15e614b304
fix(waf): pow
2026-07-13 17:07:49 +08:00
ryan
46941f65d5
fix(waf): handle empty rule bindings
...
Encode empty site bindings as arrays and normalize legacy JSON null values in the OpenResty runtime to prevent request-time Lua failures.
2026-07-13 16:49:55 +08:00
ryan
0c2961ae6d
fix(waf): complete geography match options
...
Use full country and ISO subdivision data, show localized country names with codes, and add searchable region selection.
2026-07-13 16:34:18 +08:00
ryan
a61d55bb1b
chore: improve log print
2026-07-13 16:12:30 +08:00
ryan
6b6c786cfe
feat(startup): print service banner after listener ready
2026-07-13 15:49:19 +08:00
ryan
26be762c3a
prettier
2026-07-13 15:44:03 +08:00
ryan
0548a8a5d4
fix(redis): add maintenance notification startup switch
...
Default Redis maintenance notification negotiation to disabled and apply the startup-only setting to both platform and Asynq clients.
2026-07-13 15:43:15 +08:00
ryan
60bc03f519
fix(db): log SQL statements at debug level
...
Move routine GORM SQL output to debug and omit SQL text from slow-query and query-error logs to prevent sensitive parameters from being emitted at production log levels.
2026-07-13 15:39:48 +08:00
ryan
9dc3983e0f
fix(frontend): WAF 规则编辑器缩小编排区高度和首次适配缩放比例,默认显示更多画布上下文
2026-07-13 15:39:48 +08:00
ryan
1eff7878a1
prettier
2026-07-13 15:10:28 +08:00
ryan
08e8eea932
fix(frontend): prettier config
2026-07-13 15:04:28 +08:00
ryan
85d5c8568c
fix(frontend): stabilize WAF rule canvas
...
Use React Flow controlled node state, support deleting nodes and edges, and show node properties only after selection.
2026-07-13 14:59:20 +08:00
ryan
74ddf97b36
feat(agent): embed GeoLite2 City database
...
Initialize missing Country and City databases from embedded assets and use FyraLabs releases for periodic updates.
2026-07-13 14:38:36 +08:00
ryan
a1a997bcda
feat(waf): complete composable rule orchestration
...
Add the React Flow rule editor, ordered graph APIs and runtime DAG execution.\n\nPublish rules only on OpenResty reload and reconcile checksum-driven IP group snapshots in bounded shared memory.
2026-07-13 14:17:15 +08:00
ryan
d36409fbf9
refactor(frontend): order waf rule bindings
2026-07-13 12:12:49 +08:00
ryan
4000366856
feat(frontend): create orchestrated waf rules
2026-07-13 12:00:24 +08:00
ryan
af20e2e838
feat(waf): add composable rule graph core
2026-07-13 11:57:36 +08:00
ryan
2fff30e188
docs(waf): split orchestration migrations
2026-07-13 11:35:16 +08:00
ryan
74c2f57453
docs(waf): plan composable rule implementation
2026-07-13 11:23:34 +08:00
ryan
30e09f5985
docs(waf): design composable rule graph
2026-07-13 11:14:10 +08:00
ryan
43e293e062
fix: frontend optimization
2026-07-13 10:31:09 +08:00
ryan
439ac41da8
fix(frontend): correct Pages deployment files route
...
Align the Pages deployment file-list request with the backend route and add a regression test.
2026-07-13 09:29:22 +08:00