diff --git a/.agents/skills/security-scan/SKILL.md b/.agents/skills/security-scan/SKILL.md deleted file mode 100644 index dba372e..0000000 --- a/.agents/skills/security-scan/SKILL.md +++ /dev/null @@ -1,165 +0,0 @@ ---- -name: security-scan -description: Scan your Claude Code configuration (.claude/ directory) for security vulnerabilities, misconfigurations, and injection risks using AgentShield. Checks CLAUDE.md, settings.json, MCP servers, hooks, and agent definitions. -origin: ECC ---- - -# Security Scan Skill - -Audit your Claude Code configuration for security issues using [AgentShield](https://github.com/affaan-m/agentshield). - -## When to Activate - -- Setting up a new Claude Code project -- After modifying `.claude/settings.json`, `CLAUDE.md`, or MCP configs -- Before committing configuration changes -- When onboarding to a new repository with existing Claude Code configs -- Periodic security hygiene checks - -## What It Scans - -| File | Checks | -|------|--------| -| `CLAUDE.md` | Hardcoded secrets, auto-run instructions, prompt injection patterns | -| `settings.json` | Overly permissive allow lists, missing deny lists, dangerous bypass flags | -| `mcp.json` | Risky MCP servers, hardcoded env secrets, npx supply chain risks | -| `hooks/` | Command injection via interpolation, data exfiltration, silent error suppression | -| `agents/*.md` | Unrestricted tool access, prompt injection surface, missing model specs | - -## Prerequisites - -AgentShield must be installed. Check and install if needed: - -```bash -# Check if installed -npx ecc-agentshield --version - -# Install globally (recommended) -npm install -g ecc-agentshield - -# Or run directly via npx (no install needed) -npx ecc-agentshield scan . -``` - -## Usage - -### Basic Scan - -Run against the current project's `.claude/` directory: - -```bash -# Scan current project -npx ecc-agentshield scan - -# Scan a specific path -npx ecc-agentshield scan --path /path/to/.claude - -# Scan with minimum severity filter -npx ecc-agentshield scan --min-severity medium -``` - -### Output Formats - -```bash -# Terminal output (default) — colored report with grade -npx ecc-agentshield scan - -# JSON — for CI/CD integration -npx ecc-agentshield scan --format json - -# Markdown — for documentation -npx ecc-agentshield scan --format markdown - -# HTML — self-contained dark-theme report -npx ecc-agentshield scan --format html > security-report.html -``` - -### Auto-Fix - -Apply safe fixes automatically (only fixes marked as auto-fixable): - -```bash -npx ecc-agentshield scan --fix -``` - -This will: -- Replace hardcoded secrets with environment variable references -- Tighten wildcard permissions to scoped alternatives -- Never modify manual-only suggestions - -### Opus 4.6 Deep Analysis - -Run the adversarial three-agent pipeline for deeper analysis: - -```bash -# Requires ANTHROPIC_API_KEY -export ANTHROPIC_API_KEY=your-key -npx ecc-agentshield scan --opus --stream -``` - -This runs: -1. **Attacker (Red Team)** — finds attack vectors -2. **Defender (Blue Team)** — recommends hardening -3. **Auditor (Final Verdict)** — synthesizes both perspectives - -### Initialize Secure Config - -Scaffold a new secure `.claude/` configuration from scratch: - -```bash -npx ecc-agentshield init -``` - -Creates: -- `settings.json` with scoped permissions and deny list -- `CLAUDE.md` with security best practices -- `mcp.json` placeholder - -### GitHub Action - -Add to your CI pipeline: - -```yaml -- uses: affaan-m/agentshield@v1 - with: - path: '.' - min-severity: 'medium' - fail-on-findings: true -``` - -## Severity Levels - -| Grade | Score | Meaning | -|-------|-------|---------| -| A | 90-100 | Secure configuration | -| B | 75-89 | Minor issues | -| C | 60-74 | Needs attention | -| D | 40-59 | Significant risks | -| F | 0-39 | Critical vulnerabilities | - -## Interpreting Results - -### Critical Findings (fix immediately) -- Hardcoded API keys or tokens in config files -- `Bash(*)` in the allow list (unrestricted shell access) -- Command injection in hooks via `${file}` interpolation -- Shell-running MCP servers - -### High Findings (fix before production) -- Auto-run instructions in CLAUDE.md (prompt injection vector) -- Missing deny lists in permissions -- Agents with unnecessary Bash access - -### Medium Findings (recommended) -- Silent error suppression in hooks (`2>/dev/null`, `|| true`) -- Missing PreToolUse security hooks -- `npx -y` auto-install in MCP server configs - -### Info Findings (awareness) -- Missing descriptions on MCP servers -- Prohibitive instructions correctly flagged as good practice - -## Links - -- **GitHub**: [github.com/affaan-m/agentshield](https://github.com/affaan-m/agentshield) -- **npm**: [npmjs.com/package/ecc-agentshield](https://www.npmjs.com/package/ecc-agentshield) diff --git a/.claude/settings.json b/.claude/settings.json deleted file mode 100644 index 5cfa585..0000000 --- a/.claude/settings.json +++ /dev/null @@ -1,84 +0,0 @@ -{ - "hooks": { - "PostToolUse": [ - { - "matcher": "Task", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code post-task" - } - ] - }, - { - "matcher": "TodoWrite", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code post-todo" - } - ] - } - ], - "PreToolUse": [ - { - "matcher": "Task", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code pre-task" - } - ] - } - ], - "SessionEnd": [ - { - "matcher": "", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code session-end" - } - ] - } - ], - "SessionStart": [ - { - "matcher": "", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code session-start" - } - ] - } - ], - "Stop": [ - { - "matcher": "", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code stop" - } - ] - } - ], - "UserPromptSubmit": [ - { - "matcher": "", - "hooks": [ - { - "type": "command", - "command": "entire hooks claude-code user-prompt-submit" - } - ] - } - ] - }, - "permissions": { - "deny": [ - "Read(./.entire/metadata/**)" - ] - } -} diff --git a/.claude/skills/security-scan b/.claude/skills/security-scan deleted file mode 120000 index fbee699..0000000 --- a/.claude/skills/security-scan +++ /dev/null @@ -1 +0,0 @@ -../../.agents/skills/security-scan \ No newline at end of file diff --git a/.sisyphus/plans/001-setup-dev-environment.md b/.sisyphus/plans/001-setup-dev-environment.md deleted file mode 100644 index 5e99166..0000000 --- a/.sisyphus/plans/001-setup-dev-environment.md +++ /dev/null @@ -1,71 +0,0 @@ -# Plan: 搭建开发环境 - -## 目标 -为 Flux Panel 项目安装所有缺失的开发依赖,使 3 个子项目都能本地开发和构建。 - -## 当前状态 - -### ✅ 已安装 -| 工具 | 版本 | 用途 | -|------|------|------| -| Node.js | v20.19.2 | vite-frontend | -| npm | 9.2.0 | vite-frontend | -| Go | 1.24.4 | go-gost | -| Docker | 29.1.4 | 容器化部署 | - -### ❌ 缺失 -| 工具 | 需求版本 | 用途 | -|------|----------|------| -| Java | 21 | springboot-backend | -| Maven | 3.x | 构建后端 | -| Docker Compose | v2 | 容器编排 | - ---- - -## 执行任务 - -### Task 1: 安装 Java 21 -```bash -apt-get update && apt-get install -y openjdk-21-jdk -``` -**验证**: `java -version` 应显示 openjdk 21 - -### Task 2: 安装 Maven -```bash -apt-get install -y maven -``` -**验证**: `mvn -v` 应显示 Maven 3.x - -### Task 3: 安装 Docker Compose Plugin -```bash -apt-get install -y docker-compose-plugin -``` -**验证**: `docker compose version` 应显示版本号 - -### Task 4: 安装前端依赖 -```bash -cd /root/flux-panel/vite-frontend && npm install -``` -**验证**: `node_modules/` 目录存在 - -### Task 5: 验证后端可构建 -```bash -cd /root/flux-panel/springboot-backend && mvn clean compile -q -``` -**验证**: 编译成功无错误 - -### Task 6: 验证 Go 模块 -```bash -cd /root/flux-panel/go-gost && go mod download -``` -**验证**: 依赖下载成功 - ---- - -## 完成标准 -- [ ] `java -version` → openjdk 21 -- [ ] `mvn -v` → Maven 3.x -- [ ] `docker compose version` → v2.x -- [ ] 前端: `npm run dev` 可启动 -- [ ] 后端: `mvn compile` 成功 -- [ ] Go: `go build .` 成功 diff --git a/211-custom-ip-selection.md b/211-custom-ip-selection.md deleted file mode 100644 index 1ae1714..0000000 --- a/211-custom-ip-selection.md +++ /dev/null @@ -1,33 +0,0 @@ -# Issue #211: 转发自定义监听IP / 隧道指定连接IP - -## 需求总结 -1. **节点**: 高级配置增加"额外IP地址"字段(逗号分隔) -2. **转发**: 创建/编辑时可指定入口监听IP -3. **隧道**: 配置出口节点时可指定连接IP - ---- - -## 任务清单 - -### 后端 -- [x] 1. 数据模型扩展 - Node/ForwardPort/ChainTunnel 增加字段 -- [x] 2. Repository - CreateNode/UpdateNode 处理 extraIPs -- [x] 3. Repository - resolveForwardIngress 使用 forward_port.in_ip -- [x] 4. Repository - GetNodeAllIPs 辅助函数(返回节点所有可用IP) -- [x] 5. Handler - 转发创建/更新处理 inIp 参数 -- [x] 6. Handler - 隧道出口节点处理 connectIp 参数 -- [x] 7. Handler - 节点API返回 extraIPs 字段 - -### 前端 -- [x] 8. 节点编辑页 - 高级配置增加"额外IP"输入 -- [x] 9. 转发编辑弹窗 - 增加"监听IP"下拉选择 -- [x] 10. 隧道配置页 - 出口节点增加"连接IP"输入 - ---- - -## 完成进度 -- 开始时间: 2026-03-02 -- 完成时间: 2026-03-02 -- 完成任务: 10/10 -- 后端完成: ✅ -- 前端完成: ✅ diff --git a/IMPLEMENTATION_PLAN.md b/IMPLEMENTATION_PLAN.md deleted file mode 100644 index ec1b3ff..0000000 --- a/IMPLEMENTATION_PLAN.md +++ /dev/null @@ -1,148 +0,0 @@ -# 限速功能重构实施计划 - -## 一、需求概述 - -**原始需求**: 限速功能当前绑定到具体隧道,需要改为不绑定隧道,创建限速后可以自由在隧道上限速,也可以在转发上限速。 - -**核心变更**: -1. 限速规则(SpeedLimit)与隧道的绑定关系改为可选 -2. 转发(Forward)支持独立的限速规则 - ---- - -## 二、实施计划清单 - -### 2.0 计划状态(审计更新:2026-02-26) - -- 总体状态:**进行中(未验收通过)** -- 已完成:模型、仓储查询、限速 CRUD、控制面优先级、限速页与类型改造、编译与测试通过 -- 未完成:**Forward 独立限速写入链路**(前端表单 -> API handler -> repository 落库 `forward.speed_id`) - -### 2.1 后端模型层 (Model) - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| M1 | SpeedLimit.TunnelID 改为 sql.NullInt64 (可空) | `go-backend/internal/store/model/model.go` | ✅ 完成 | -| M2 | SpeedLimit.TunnelName 改为 sql.NullString (可空) | `go-backend/internal/store/model/model.go` | ✅ 完成 | -| M3 | Forward 添加 SpeedID sql.NullInt64 字段 | `go-backend/internal/store/model/model.go` | ✅ 完成 | -| M4 | ForwardRecord 添加 SpeedID sql.NullInt64 字段 | `go-backend/internal/store/model/model.go` | ✅ 完成 | -| M5 | SpeedLimitBackup.TunnelID 改为指针类型 | `go-backend/internal/store/model/model.go` | ✅ 完成 | -| M6 | ForwardBackup 添加 SpeedID *int64 字段 | `go-backend/internal/store/model/model.go` | ✅ 完成 | - -### 2.2 后端仓储层 (Repository) - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| R1 | ListSpeedLimits() 返回可空 tunnelId/tunnelName | `go-backend/internal/store/repo/repository.go` | ✅ 完成 | -| R2 | ListForwards() 返回 speedId 字段 | `go-backend/internal/store/repo/repository.go` | ✅ 完成 | -| R3 | CreateSpeedLimit() 参数 tunnelID 改为 *int64 | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 | -| R4 | UpdateSpeedLimit() 参数 tunnelID 改为 *int64 | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 | -| R5 | GetSpeedLimitTunnelID() 返回 sql.NullInt64 | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 | -| R6 | exportSpeedLimits() 处理可空字段 | `go-backend/internal/store/repo/repository.go` | ✅ 完成 | -| R7 | importSpeedLimits() 处理可空字段 | `go-backend/internal/store/repo/repository.go` | ✅ 完成 | -| R8 | GetSpeedLimitSpeed() 新增方法 | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 | -| R9 | ListForwardsByTunnel() 返回 SpeedID | `go-backend/internal/store/repo/repository_control.go` | ✅ 完成 | -| R10 | ListActiveForwardsByUser() 返回 SpeedID | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 | -| R11 | ListActiveForwardsByUserTunnel() 返回 SpeedID | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 | -| R12 | GetForwardRecord() 返回 SpeedID | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 | - -### 2.3 后端处理器层 (Handler) - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| H1 | speedLimitCreate 处理可选 tunnelId | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 | -| H2 | speedLimitUpdate 处理可选 tunnelId | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 | -| H3 | speedLimitDelete 处理可空 tunnelID | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 | - -### 2.4 后端控制平面 (Control Plane) - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| C1 | syncForwardServices 优先使用 Forward.SpeedID | `go-backend/internal/http/handler/control_plane.go` | ✅ 完成 | -| C2 | 回退到 UserTunnel 的 speed limit | `go-backend/internal/http/handler/control_plane.go` | ✅ 完成 | - -### 2.5 前端类型定义 (TypeScript Types) - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| T1 | SpeedLimitApiItem.tunnelId 改为可选 | `vite-frontend/src/api/types.ts` | ✅ 完成 | -| T2 | ForwardApiItem 添加 speedId 字段 | `vite-frontend/src/api/types.ts` | ✅ 完成 | -| T3 | ForwardMutationPayload 添加 speedId 字段 | `vite-frontend/src/api/types.ts` | ✅ 完成 | -| T4 | SpeedLimitMutationPayload.tunnelId 改为可选 | `vite-frontend/src/api/types.ts` | ✅ 完成 | - -### 2.6 前端页面组件 - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| F1 | SpeedLimitRule 接口更新 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 | -| F2 | SpeedLimitForm 接口更新 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 | -| F3 | validateForm 移除 tunnelId 必填校验 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 | -| F4 | Select 组件改为可选 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 | -| F5 | 显示"未绑定"状态 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 | - -### 2.7 编译验证 - -| 序号 | 任务 | 状态 | -|------|------|------| -| B1 | Go 后端编译通过 | ✅ 完成 | -| B2 | TypeScript 类型检查通过 | ✅ 完成 | -| B3 | `go test ./...` 全量通过 | ✅ 完成 | -| B4 | `go test ./tests/contract/... -run SpeedLimit` 通过 | ✅ 完成 | - -### 2.8 Forward 独立限速写入链路补全(新增) - -| 序号 | 任务 | 文件 | 状态 | -|------|------|------|------| -| N1 | forwardCreate 支持接收并校验可选 speedId,写入 Forward.SpeedID | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 | -| N2 | forwardUpdate 支持更新/清空 speedId,并触发服务重下发 | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 | -| N3 | CreateForwardTx 支持落库 speed_id | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 | -| N4 | UpdateForward 支持更新 speed_id | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 | -| N5 | Forward 页面新增限速选择并透传 speedId | `vite-frontend/src/pages/forward.tsx` | ✅ 完成 | -| N6 | Forward 相关契约测试补充 speedId 写入/清空断言 | `go-backend/tests/contract/forward_contract_test.go` | ✅ 完成 | - ---- - -## 三、优先级说明 - -限速规则应用优先级: -1. **Forward.SpeedID** - 转发级别的限速 (最高优先) -2. **UserTunnel.SpeedID** - 用户隧道权限级别的限速 (回退) - ---- - -## 四、数据库兼容性 - -- SpeedLimit 表: `tunnel_id` 和 `tunnel_name` 字段改为可空 (GORM AutoMigrate 自动处理) -- Forward 表: 新增 `speed_id` 可空字段 (GORM AutoMigrate 自动处理) - ---- - -## 五、验证检查项 - -### 5.1 功能验证(审计后) - -- [x] 创建不限速规则的限速 (不绑定隧道) -- [x] 创建绑定隧道的限速 (兼容旧逻辑) -- [x] 编辑限速规则,切换隧道绑定状态 -- [ ] 删除限速规则 -- [ ] 转发列表正确显示 speedId - -### 5.2 API 验证(审计后) - -- [x] GET /api/speed-limit/list 返回可选 tunnelId -- [x] POST /api/speed-limit/create 接受可选 tunnelId -- [x] POST /api/speed-limit/update 接受可选 tunnelId -- [ ] GET /api/forward/list 返回 speedId - -### 5.3 兼容性验证(审计后) - -- [x] 现有绑定隧道的限速规则继续正常工作 -- [ ] 现有 UserTunnel 的限速继续正常工作 -- [ ] 备份/恢复功能正常 - -### 5.4 Forward 独立限速闭环验证(新增) - -- [x] POST /api/forward/create 接受 speedId 并写入 `forward.speed_id` -- [x] POST /api/forward/update 可更新/清空 speedId -- [x] Forward 表单可选择限速并提交 speedId -- [ ] `syncForwardServices` 实际使用 Forward.SpeedID 而非仅回退 UserTunnel.SpeedID diff --git a/openspec/changes/document-existing-specs/.openspec.yaml b/openspec/changes/document-existing-specs/.openspec.yaml deleted file mode 100644 index c8d3976..0000000 --- a/openspec/changes/document-existing-specs/.openspec.yaml +++ /dev/null @@ -1,2 +0,0 @@ -schema: spec-driven -created: 2026-02-17 diff --git a/openspec/changes/document-existing-specs/design.md b/openspec/changes/document-existing-specs/design.md deleted file mode 100644 index 872fdff..0000000 --- a/openspec/changes/document-existing-specs/design.md +++ /dev/null @@ -1,29 +0,0 @@ -## Context - -FLVX is a distributed system consisting of a central management panel (Backend + Frontend) and multiple forwarding agents (Nodes). The backend manages configuration, users, and billing, while agents handle the actual traffic forwarding using a modified GOST v3 stack. Communication between the panel and agents is secured and synchronized. - -## Goals / Non-Goals - -**Goals:** -- Document the high-level architecture of the system. -- Describe the data model for users, tunnels, and nodes. -- Explain the communication protocol between Panel and Agent. -- Detail the authentication and authorization mechanisms. - -**Non-Goals:** -- Refactoring the existing architecture. -- Detailed code-level documentation of every function. -- Changing the database schema. - -## Decisions - -- **Architecture**: The system follows a client-server model where the Panel acts as the server and Agents act as clients that pull configuration and push status. -- **Data Model**: Core entities are Users, Nodes (Agents), Tunnels (Groups of rules), and Forwarding Rules. -- **Communication**: Agents use a heartbeat mechanism to report status and fetch configuration updates. The protocol uses AES encryption with a pre-shared key (Node Secret). -- **Authentication**: JWT for Frontend-Backend communication; API Key (Node Secret) for Agent-Backend communication. - -## Risks / Trade-offs - -- **Security**: The security of the agent communication relies heavily on the secrecy of the Node Secret. -- **Scalability**: Centralized management might become a bottleneck with a very large number of agents. -- **Complexity**: Synchronizing state across distributed agents introduces complexity in handling failures and inconsistencies. diff --git a/openspec/changes/document-existing-specs/proposal.md b/openspec/changes/document-existing-specs/proposal.md deleted file mode 100644 index c90d106..0000000 --- a/openspec/changes/document-existing-specs/proposal.md +++ /dev/null @@ -1,28 +0,0 @@ -## Why - -The current system lacks formal specification documents describing its capabilities. This makes it difficult for new developers to understand the intended behavior and for existing developers to ensure consistency when adding new features. Documenting the existing functionality will serve as a baseline for future changes and help in identifying gaps or inconsistencies. - -## What Changes - -- Create formal specification documents for core system capabilities. -- Document user management features (roles, limits). -- Document tunnel and forwarding management (protocols, rules). -- Document agent interactions and management. -- Document system-level configurations. - -## Capabilities - -### New Capabilities -- `user-management`: Authentication, user roles, and resource limits. -- `tunnel-management`: Creation and management of traffic tunnels (TCP/UDP). -- `forwarding-rules`: Configuration of port forwarding and tunnel forwarding rules, including rate limiting. -- `agent-management`: Management of forwarding agents, including installation and configuration synchronization. -- `system-config`: Global system settings and configurations. - -### Modified Capabilities - - -## Impact - -- **Documentation**: New spec files in `openspec/specs/`. -- **No Code Changes**: This change is purely documentation-focused. diff --git a/openspec/changes/document-existing-specs/specs/agent-management/spec.md b/openspec/changes/document-existing-specs/specs/agent-management/spec.md deleted file mode 100644 index ac9594b..0000000 --- a/openspec/changes/document-existing-specs/specs/agent-management/spec.md +++ /dev/null @@ -1,29 +0,0 @@ -## ADDED Requirements - -### Requirement: Agent Registration -The system SHALL require new agents (Nodes) to register using a unique node key/secret. - -#### Scenario: Node Connection -- **WHEN** a new agent starts up with a valid configuration -- **THEN** it connects to the backend and is registered as active. - -### Requirement: Heartbeat Monitoring -The system SHALL monitor the status of all registered agents using periodic heartbeats. - -#### Scenario: Agent Status -- **WHEN** an agent sends periodic heartbeats -- **THEN** the system updates its last-seen timestamp and marks it as online. - -### Requirement: Configuration Sync -The system MUST synchronize configuration changes (tunnels, rules) to agents securely and reliably. - -#### Scenario: Push Config -- **WHEN** a configuration change is made in the panel -- **THEN** the agent receives the updated configuration via the next heartbeat or push mechanism. - -### Requirement: Version Management -The system SHOULD track the version of the agent software running on each node. - -#### Scenario: Version Reporting -- **WHEN** an agent connects -- **THEN** it reports its version number to the backend for tracking. diff --git a/openspec/changes/document-existing-specs/specs/forwarding-rules/spec.md b/openspec/changes/document-existing-specs/specs/forwarding-rules/spec.md deleted file mode 100644 index b350b4a..0000000 --- a/openspec/changes/document-existing-specs/specs/forwarding-rules/spec.md +++ /dev/null @@ -1,22 +0,0 @@ -## ADDED Requirements - -### Requirement: Port Forwarding Rules -The system SHALL support configuring port forwarding rules, defining the listening port on the node and the destination IP/port. - -#### Scenario: Rule Configuration -- **WHEN** an admin creates a port forwarding rule -- **THEN** the rule is stored and synchronized to the assigned node. - -### Requirement: Rate Limiting -The system SHALL support configuring bandwidth rate limits for tunnels and users. - -#### Scenario: Bandwidth Restriction -- **WHEN** a rate limit is applied to a user -- **THEN** their total bandwidth usage does not exceed the specified limit across all their tunnels. - -### Requirement: Traffic Accounting -The system MUST track incoming and outgoing traffic volume for each tunnel and user for billing and quota enforcement. - -#### Scenario: Traffic Calculation -- **WHEN** traffic flows through a tunnel -- **THEN** the system increments the user's traffic usage counter accurately. diff --git a/openspec/changes/document-existing-specs/specs/system-config/spec.md b/openspec/changes/document-existing-specs/specs/system-config/spec.md deleted file mode 100644 index 5ed2617..0000000 --- a/openspec/changes/document-existing-specs/specs/system-config/spec.md +++ /dev/null @@ -1,22 +0,0 @@ -## ADDED Requirements - -### Requirement: Site Settings -The system SHALL allow customization of the site title, logo, and other branding elements. - -#### Scenario: Update Branding -- **WHEN** an administrator changes the site logo -- **THEN** the new logo is displayed across the interface. - -### Requirement: Notification Settings -The system SHALL support configuring notifications for user registration, traffic limits, and other events. - -#### Scenario: User Limit Alert -- **WHEN** a user approaches their traffic quota -- **THEN** a notification is sent to the user/admin. - -### Requirement: Backup & Restore -The system SHOULD provide a mechanism to backup and restore database configurations. - -#### Scenario: Restore Database -- **WHEN** initiating a restore operation -- **THEN** the system accepts a valid backup file and overwrites the current database state. diff --git a/openspec/changes/document-existing-specs/specs/tunnel-management/spec.md b/openspec/changes/document-existing-specs/specs/tunnel-management/spec.md deleted file mode 100644 index f55658f..0000000 --- a/openspec/changes/document-existing-specs/specs/tunnel-management/spec.md +++ /dev/null @@ -1,22 +0,0 @@ -## ADDED Requirements - -### Requirement: Tunnel Creation -The system SHALL allow administrators to create tunnels, specifying protocols (TCP, UDP), listening ports, and destination endpoints. - -#### Scenario: Create TCP Tunnel -- **WHEN** an admin creates a new TCP tunnel configuration -- **THEN** the backend stores the tunnel definition and assigns it to a node. - -### Requirement: Tunnel Forwarding Configuration -The system SHALL support both standard port forwarding (listening on a port and forwarding to a destination) and tunnel forwarding modes. - -#### Scenario: Configure Port Forwarding -- **WHEN** configuring a tunnel for port forwarding -- **THEN** traffic arriving at the specified port is forwarded to the destination IP:port. - -### Requirement: Tunnel Assignment -The system SHALL allow tunnels to be assigned to specific users, tracking their usage against the user's quota. - -#### Scenario: User Tunnel Usage -- **WHEN** a user is assigned a tunnel -- **THEN** traffic passing through that tunnel is accounted for under the user's usage. diff --git a/openspec/changes/document-existing-specs/specs/user-management/spec.md b/openspec/changes/document-existing-specs/specs/user-management/spec.md deleted file mode 100644 index 02eeeda..0000000 --- a/openspec/changes/document-existing-specs/specs/user-management/spec.md +++ /dev/null @@ -1,29 +0,0 @@ -## ADDED Requirements - -### Requirement: User Registration -The system SHALL allow new users to register an account with a username and password. - -#### Scenario: Successful Registration -- **WHEN** a user submits valid registration details -- **THEN** a new user account is created and the user can log in. - -### Requirement: User Authentication -The system MUST authenticate users using JWT tokens. The `Authorization` header MUST contain the raw token without a `Bearer` prefix. - -#### Scenario: Valid Login -- **WHEN** a user provides correct credentials -- **THEN** the system returns a valid JWT token. - -### Requirement: Role Management -The system SHALL support different user roles, specifically Administrator and Regular User, with distinct permissions. - -#### Scenario: Admin Access -- **WHEN** an administrator logs in -- **THEN** they have access to system-wide settings and all user management functions. - -### Requirement: Resource Quotas -The system SHALL allow administrators to set traffic limits and connection limits for individual users. - -#### Scenario: Traffic Limit Enforcement -- **WHEN** a user exceeds their traffic quota -- **THEN** the system prevents further traffic forwarding for that user. diff --git a/openspec/changes/document-existing-specs/tasks.md b/openspec/changes/document-existing-specs/tasks.md deleted file mode 100644 index a014a23..0000000 --- a/openspec/changes/document-existing-specs/tasks.md +++ /dev/null @@ -1,30 +0,0 @@ -## 1. User Management Verification - -- [ ] 1.1 Verify User Registration logic in backend -- [ ] 1.2 Verify JWT Authentication implementation -- [ ] 1.3 Verify Role Management checks -- [ ] 1.4 Verify Quota Enforcement logic - -## 2. Tunnel Management Verification - -- [ ] 2.1 Verify Tunnel Creation API -- [ ] 2.2 Verify Forwarding Configuration parsing -- [ ] 2.3 Verify Tunnel Assignment logic - -## 3. Forwarding Rules Verification - -- [ ] 3.1 Verify Port Forwarding rule processing -- [ ] 3.2 Verify Rate Limiting implementation (token bucket/leaky bucket?) -- [ ] 3.3 Verify Traffic Accounting mechanisms - -## 4. Agent Management Verification - -- [ ] 4.1 Verify Agent Registration handshake -- [ ] 4.2 Verify Heartbeat processing -- [ ] 4.3 Verify Config Sync protocol - -## 5. System Config Verification - -- [ ] 5.1 Verify Site Settings API -- [ ] 5.2 Verify Notification triggers -- [ ] 5.3 Verify Backup/Restore functionality diff --git a/openspec/config.yaml b/openspec/config.yaml deleted file mode 100644 index 392946c..0000000 --- a/openspec/config.yaml +++ /dev/null @@ -1,20 +0,0 @@ -schema: spec-driven - -# Project context (optional) -# This is shown to AI when creating artifacts. -# Add your tech stack, conventions, style guides, domain knowledge, etc. -# Example: -# context: | -# Tech stack: TypeScript, React, Node.js -# We use conventional commits -# Domain: e-commerce platform - -# Per-artifact rules (optional) -# Add custom rules for specific artifacts. -# Example: -# rules: -# proposal: -# - Keep proposals under 500 words -# - Always include a "Non-goals" section -# tasks: -# - Break tasks into chunks of max 2 hours diff --git a/openspec/project.md b/openspec/project.md deleted file mode 100644 index bafcf51..0000000 --- a/openspec/project.md +++ /dev/null @@ -1,52 +0,0 @@ -# Project Overview - -**Name**: FLVX (Flux Panel) -**Description**: Traffic forwarding management system built on a forked GOST v3 stack. It provides a web-based panel for managing traffic tunnels, users, and forwarding rules. -**Repository**: Monorepo containing Admin API, Web UI, and Forwarding Agent. - -## Tech Stack - -### Backend (`go-backend/`) -- **Language**: Go -- **Database**: SQLite (default), PostgreSQL (supported) -- **Framework**: Standard library `net/http` (no heavy framework) -- **ORM**: None (Raw SQL via `database/sql`) - -### Frontend (`vite-frontend/`) -- **Framework**: React -- **Build Tool**: Vite (using `rolldown-vite` experimental bundler) -- **UI Library**: HeroUI -- **Styling**: Tailwind CSS -- **Mode**: Hybrid (Desktop + Mobile WebView support) - -### Agent (`go-gost/`) -- **Language**: Go -- **Base**: Fork of `gost` v3 -- **Extensions**: Custom extensions in `go-gost/x/` - -### Infrastructure -- **Containerization**: Docker, Docker Compose (v4/v6) -- **CI/CD**: GitHub Actions -- **Installers**: Shell scripts (`panel_install.sh`, `install.sh`) - -## Architecture - -- **Panel**: Central management server (Go Backend + React Frontend). -- **Agent**: Forwarding node running on remote servers. -- **Communication**: - - Frontend -> Backend: REST API (JWT Auth, raw token in header). - - Agent -> Backend: AES-encrypted heartbeat/config sync. - -## Conventions - -- **Authentication**: `Authorization` header expects raw JWT token (do NOT add `Bearer ` prefix). -- **API Response**: Standard envelope `{code, msg, data, ts}` (code 0 = success). -- **Database**: Backend uses raw SQL queries. Do not introduce an ORM. -- **File Structure**: Flat monorepo with language-prefixed directories (`go-backend`, `go-gost`). -- **Protobuf**: Do not edit generated `.pb.go` files manually. - -## Development - -- **Backend Build**: `cd go-backend && make build` -- **Frontend Dev**: `cd vite-frontend && npm run dev` -- **Agent Run**: `cd go-gost && go run .` diff --git a/skills-lock.json b/skills-lock.json deleted file mode 100644 index 01e0ff2..0000000 --- a/skills-lock.json +++ /dev/null @@ -1,10 +0,0 @@ -{ - "version": 1, - "skills": { - "security-scan": { - "source": "affaan-m/everything-claude-code", - "sourceType": "github", - "computedHash": "92cdcaddc554e318402f066ccc073c2e3dbcfda8c2730ec62ec373f805c41a57" - } - } -}