Commit Graph

1152 Commits

Author SHA1 Message Date
sagitchu 312c9a9c5c fix: harden panel self-upgrade 2026-05-15 23:16:14 +08:00
sagit e1324b8c8c fix: update dependabot vulnerabilities (#505)
* docs: add dependabot remediation design

* docs: add dependabot remediation plan

* fix: update backend pgx dependency

* fix: update frontend vulnerable dependencies

* fix: update gost quic dependencies

* fix: migrate gost dtls dependency

* fix: sync gost main dependencies

* fix: enable webtransport stream reset partial delivery

* fix: restore backend bcrypt dependency
3.0.0-rc2 3.0.0-rc3
2026-05-15 00:16:29 +08:00
sagit c034d0d41f fix: allow public config fallback for cached login (#504)
## Summary
- allow cached/old login clients to read public config keys through
`/api/v1/config/get` without a valid token
- keep sensitive config keys blocked from unauthenticated access
- stabilize the system upgrade fail-fast test by avoiding live
stable-release lookup and using POSIX shell syntax

## Test Plan
- `cd go-backend && go test ./...`
2026-05-14 18:46:43 +08:00
sagitchu fd3ecc38ef fix: allow public config fallback for cached login 2026-05-14 18:45:12 +08:00
sagit 2eee506716 fix: harden auth, config access, and backups (#503)
## Summary
- Migrate password storage to bcrypt with legacy MD5 verification-only
support and best-effort upgrade on successful auth.
- Revoke JWTs on auth-state changes, align WebSocket admin auth, and
split public config reads from protected config reads.
- Filter sensitive configs from backup export/import and update contract
coverage for the new security boundaries.

## Test Plan
- [x] `go test ./... -count=1`
- [x] `pnpm run lint`
- [x] `pnpm run build`
3.0.0-rc1
2026-05-14 11:21:45 +08:00
sagitchu abf13bdac9 fix: close remaining security remediation gaps 2026-05-14 11:10:06 +08:00
sagitchu f0facf6703 fix: block sensitive config writes 2026-05-14 10:37:29 +08:00
sagitchu 583a3834f9 fix: expire websocket admin sessions 2026-05-14 01:24:03 +08:00
sagitchu bd13477fa3 fix: stop caching sensitive configs in browser 2026-05-14 00:34:52 +08:00
sagitchu 106a30bf9d fix: tighten websocket auth and client cache handling 2026-05-14 00:24:56 +08:00
sagitchu 465815cf34 fix: harden auth, config access, and backups 2026-05-13 23:53:06 +08:00
sagitchu ec9fb77eb5 docs: add security remediation design spec 2026-05-13 14:17:51 +08:00
sagitchu 7d63dd4cc3 docs: add proxy protocol analysis and panel self-upgrade plans 2026-05-13 10:49:33 +08:00
sagit 4cfa6adee7 fix: Docker build pnpm/corepack compatibility (#501)
## Summary

- `node:20.19.0` + `corepack` + `pnpm@11` →
`ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING`
- `pnpm@11` blocks `@tailwindcss/oxide` build scripts by default
- Fix: `node:22-alpine` + `corepack prepare pnpm@10 --activate &&
corepack enable pnpm`

## Verification (all local)

| Check | Result |
|-------|--------|
| `docker build ./vite-frontend` | ✅ |
| `go test ./...` | ✅ 498 passed |
| `pnpm run build` | ✅ |
| `pnpm run lint` | ✅ |
3.0.0-beta20
2026-05-07 21:26:54 +08:00
sagitchu bc8f2ec8a1 fix: use corepack prepare pnpm@10 for Docker build compatibility
- node:22-alpine + corepack + pnpm@11 hits ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING
- corepack enable pnpm@10 is invalid syntax; use corepack prepare + enable
- pnpm@10 avoids the build script approval issue entirely
- Verified: docker build, pnpm build, pnpm lint, go test all pass locally
2026-05-07 21:24:47 +08:00
sagit 9a37c2f603 fix: pin pnpm to v10 in Dockerfile (#500)
Pin pnpm to v10 to avoid v11 build script issues in Docker build.
2026-05-07 21:12:57 +08:00
sagitchu ff6d46ddaf fix: pin pnpm to v10 in Dockerfile to avoid v11 build script issues
pnpm v11 blocks build scripts by default and the onlyBuiltDependencies
config is difficult to set in Docker build context. Pin to pnpm@10.
2026-05-07 21:10:41 +08:00
sagit 723534faea fix: use pnpm-workspace.yaml for onlyBuiltDependencies (#499)
Create pnpm-workspace.yaml inline in Dockerfile for pnpm v11 build
scripts.
2026-05-07 20:57:50 +08:00
sagitchu 73490a9be6 fix: use pnpm-workspace.yaml for onlyBuiltDependencies
Create pnpm-workspace.yaml inline in Dockerfile to allow
@tailwindcss/oxide build scripts in pnpm v11.
2026-05-07 20:55:42 +08:00
sagit 5a327459f7 fix: use .npmrc for pnpm onlyBuiltDependencies (#498)
Use .npmrc file for pnpm v11 build scripts approval.
2026-05-07 20:43:29 +08:00
sagitchu f307e7d5eb fix: use .npmrc for pnpm onlyBuiltDependencies config
pnpm config set doesn't support onlyBuiltDependencies in global config.
Use .npmrc file instead.
2026-05-07 20:41:05 +08:00
sagit fdd72979b6 fix: approve @tailwindcss/oxide build script for pnpm v11 (#497)
pnpm v11 blocks build scripts by default. Allow @tailwindcss/oxide via
onlyBuiltDependencies.
2026-05-07 20:26:24 +08:00
sagitchu ad33791a26 fix: approve @tailwindcss/oxide build script for pnpm v11
pnpm v11 blocks build scripts by default; explicitly allow
@tailwindcss/oxide via onlyBuiltDependencies config.
2026-05-07 20:24:17 +08:00
sagit 6320b1f0c1 fix: upgrade Node.js to 22-alpine for corepack/pnpm compat (#496)
## Summary

Node.js 20.19.0 + corepack + pnpm@11.0.8 hits
`ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING` during Docker build. Upgrade
builder image to `node:22-alpine` (LTS).

## Verification

Frontend build passes locally with `pnpm run build`.
2026-05-07 20:11:46 +08:00
sagitchu 91d79b6b3a fix: upgrade Node.js to 22-alpine for corepack/pnpm compatibility
node:20.19.0 + corepack + pnpm@11.0.8 hits ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING
2026-05-07 20:09:42 +08:00
sagit fc7df6bd64 fix: panel self-upgrade helper not recreating containers (#495)
## Summary

- **Helper container `docker compose up` 不会强制重建容器**:原脚本缺少
`--force-recreate`,Docker Compose
在检测不到配置变化时不会替换运行中的容器,导致拉取了新镜像但旧容器继续运行。新增 `--force-recreate
--remove-orphans` 确保容器被替换。
- **无错误日志**:helper 容器执行失败时没有任何可见反馈。新增 `upgrade.log` 写入部署目录,每一步操作和错误都有记录。
- **"立即升级"按钮永久禁用**:按钮 `isDisabled` 绑定了
`!canOpenSystemUpgradeModal`,该条件要求已完成检查更新且有可用更新,但页面本身有点击时自动检查的逻辑,导致按钮永远无法点击。改为
`!canTriggerSystemUpgrade` 允许自动检查流程触发。

## Verification

| Check | Result |
|-------|--------|
| `go test ./...` | ✅ 498 passed |
| `pnpm run build` | ✅ passed |
| `pnpm run lint` | ✅ passed |
2026-05-07 19:53:53 +08:00
sagitchu 25dfb84324 fix: panel self-upgrade helper not recreating containers
- Add --force-recreate --remove-orphans to docker compose up so helper
  actually replaces running containers with newly pulled images
- Add upgrade.log file for post-mortem debugging when helper fails
- Add pre-flight validation for docker-compose.yml and .env
- Fix "立即升级" button permanently disabled by relaxing the disabled
  condition so auto-check on click can fire
2026-05-07 19:51:18 +08:00
sagit 4ebd6703fe fix: harden proxy protocol rollout safety (#494) 3.0.0-beta12 2026-05-07 16:37:51 +08:00
sagit 1f53a39784 Update contact link from group to channel (#493) 2026-05-07 01:26:56 +00:00
sagit 5ebd4c2a91 feat: add panel self-upgrade workflow (#492) 3.0.0-beta11 2026-05-06 17:58:01 +08:00
sagit 6c93d829c6 fix: refine advanced settings layout
Merge PR #491
3.0.0-beta10
2026-05-04 17:33:56 +08:00
sagitchu 5d22d4cb06 fix: refine advanced settings layout 2026-05-04 17:25:58 +08:00
sagit e5cd5af550 Use custom probe targets for diagnostics 3.0.0-beta9 2026-05-02 14:27:20 +08:00
sagitchu cdcdfd8ff0 fix: use custom probe targets for diagnostics
Move custom probe target controls into the tunnel advanced settings and reuse the configured target in tunnel diagnosis output.
2026-05-02 14:23:51 +08:00
sagit 791773fd62 Add custom tunnel probe targets (#488) 3.0.0-beta8 2026-05-02 00:54:54 +08:00
sagitchu 13764b4615 fix: reject malformed probe target updates 2026-05-02 00:12:41 +08:00
sagitchu 4c882d907b fix: preserve probe targets on legacy updates 2026-05-02 00:08:24 +08:00
sagitchu 6033e39466 fix: preserve probe targets in backups 2026-05-02 00:02:23 +08:00
sagitchu 0f3242bf11 fix: reject raw probe target whitespace 2026-05-01 23:54:31 +08:00
sagitchu d97d91801d fix: reject leading zero probe IPv4 2026-05-01 23:50:41 +08:00
sagitchu 727ef56c67 fix: improve probe target form feedback 2026-05-01 23:46:56 +08:00
sagitchu a40150b136 fix: type tunnel probe target payloads 2026-05-01 23:42:21 +08:00
sagitchu a923ec4785 fix: validate probe target port input 2026-05-01 23:39:14 +08:00
sagitchu 42c5492c1d feat: add tunnel probe target UI 2026-05-01 23:36:14 +08:00
sagitchu 869d726b7a fix: preserve type one quality probe owner 2026-05-01 23:32:00 +08:00
sagitchu 55a931510b feat: use probe target for tunnel quality checks 2026-05-01 23:28:26 +08:00
sagitchu a259dd83b2 fix: load probe target with tunnel record 2026-05-01 23:24:48 +08:00
sagitchu cc0b8de2e1 feat: use probe target for best exit scoring 2026-05-01 23:20:50 +08:00
sagitchu 58ef260755 fix: migrate legacy tunnel probe target columns 2026-05-01 23:15:21 +08:00
sagitchu 521fe79b15 fix: validate tunnel probe target before cleanup 2026-05-01 23:10:47 +08:00