sagit
8552a70355
fix: harden panel self-upgrade ( #506 )
...
This fixes panel self-upgrade and monitor realtime access for permitted
non-admin users.
Changes:
- Reuse GitHub proxy config for system upgrade release/API fetches.
- Make panel self-upgrade helper fail fast on compose command errors.
- Allow users with explicit monitor permission to connect to the
realtime websocket and receive broadcasts, not just admins.
Validation:
- cd go-backend && GOCACHE=/private/tmp/flvx-gocache go test
./internal/http/handler -count=1
- cd go-backend && go test ./internal/ws -count=1
3.0.0-rc4
2026-05-15 23:54:27 +08:00
sagitchu
b2454e86c9
fix: allow monitor realtime websocket access
2026-05-15 23:37:08 +08:00
sagitchu
312c9a9c5c
fix: harden panel self-upgrade
2026-05-15 23:16:14 +08:00
sagit
e1324b8c8c
fix: update dependabot vulnerabilities ( #505 )
...
* docs: add dependabot remediation design
* docs: add dependabot remediation plan
* fix: update backend pgx dependency
* fix: update frontend vulnerable dependencies
* fix: update gost quic dependencies
* fix: migrate gost dtls dependency
* fix: sync gost main dependencies
* fix: enable webtransport stream reset partial delivery
* fix: restore backend bcrypt dependency
3.0.0-rc2
3.0.0-rc3
2026-05-15 00:16:29 +08:00
sagit
c034d0d41f
fix: allow public config fallback for cached login ( #504 )
...
## Summary
- allow cached/old login clients to read public config keys through
`/api/v1/config/get` without a valid token
- keep sensitive config keys blocked from unauthenticated access
- stabilize the system upgrade fail-fast test by avoiding live
stable-release lookup and using POSIX shell syntax
## Test Plan
- `cd go-backend && go test ./...`
2026-05-14 18:46:43 +08:00
sagitchu
fd3ecc38ef
fix: allow public config fallback for cached login
2026-05-14 18:45:12 +08:00
sagit
2eee506716
fix: harden auth, config access, and backups ( #503 )
...
## Summary
- Migrate password storage to bcrypt with legacy MD5 verification-only
support and best-effort upgrade on successful auth.
- Revoke JWTs on auth-state changes, align WebSocket admin auth, and
split public config reads from protected config reads.
- Filter sensitive configs from backup export/import and update contract
coverage for the new security boundaries.
## Test Plan
- [x] `go test ./... -count=1`
- [x] `pnpm run lint`
- [x] `pnpm run build`
3.0.0-rc1
2026-05-14 11:21:45 +08:00
sagitchu
abf13bdac9
fix: close remaining security remediation gaps
2026-05-14 11:10:06 +08:00
sagitchu
f0facf6703
fix: block sensitive config writes
2026-05-14 10:37:29 +08:00
sagitchu
583a3834f9
fix: expire websocket admin sessions
2026-05-14 01:24:03 +08:00
sagitchu
bd13477fa3
fix: stop caching sensitive configs in browser
2026-05-14 00:34:52 +08:00
sagitchu
106a30bf9d
fix: tighten websocket auth and client cache handling
2026-05-14 00:24:56 +08:00
sagitchu
465815cf34
fix: harden auth, config access, and backups
2026-05-13 23:53:06 +08:00
sagitchu
ec9fb77eb5
docs: add security remediation design spec
2026-05-13 14:17:51 +08:00
sagitchu
7d63dd4cc3
docs: add proxy protocol analysis and panel self-upgrade plans
2026-05-13 10:49:33 +08:00
sagit
4cfa6adee7
fix: Docker build pnpm/corepack compatibility ( #501 )
...
## Summary
- `node:20.19.0` + `corepack` + `pnpm@11` →
`ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING`
- `pnpm@11` blocks `@tailwindcss/oxide` build scripts by default
- Fix: `node:22-alpine` + `corepack prepare pnpm@10 --activate &&
corepack enable pnpm`
## Verification (all local)
| Check | Result |
|-------|--------|
| `docker build ./vite-frontend` | ✅ |
| `go test ./...` | ✅ 498 passed |
| `pnpm run build` | ✅ |
| `pnpm run lint` | ✅ |
3.0.0-beta20
2026-05-07 21:26:54 +08:00
sagitchu
bc8f2ec8a1
fix: use corepack prepare pnpm@10 for Docker build compatibility
...
- node:22-alpine + corepack + pnpm@11 hits ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING
- corepack enable pnpm@10 is invalid syntax; use corepack prepare + enable
- pnpm@10 avoids the build script approval issue entirely
- Verified: docker build, pnpm build, pnpm lint, go test all pass locally
2026-05-07 21:24:47 +08:00
sagit
9a37c2f603
fix: pin pnpm to v10 in Dockerfile ( #500 )
...
Pin pnpm to v10 to avoid v11 build script issues in Docker build.
2026-05-07 21:12:57 +08:00
sagitchu
ff6d46ddaf
fix: pin pnpm to v10 in Dockerfile to avoid v11 build script issues
...
pnpm v11 blocks build scripts by default and the onlyBuiltDependencies
config is difficult to set in Docker build context. Pin to pnpm@10.
2026-05-07 21:10:41 +08:00
sagit
723534faea
fix: use pnpm-workspace.yaml for onlyBuiltDependencies ( #499 )
...
Create pnpm-workspace.yaml inline in Dockerfile for pnpm v11 build
scripts.
2026-05-07 20:57:50 +08:00
sagitchu
73490a9be6
fix: use pnpm-workspace.yaml for onlyBuiltDependencies
...
Create pnpm-workspace.yaml inline in Dockerfile to allow
@tailwindcss/oxide build scripts in pnpm v11.
2026-05-07 20:55:42 +08:00
sagit
5a327459f7
fix: use .npmrc for pnpm onlyBuiltDependencies ( #498 )
...
Use .npmrc file for pnpm v11 build scripts approval.
2026-05-07 20:43:29 +08:00
sagitchu
f307e7d5eb
fix: use .npmrc for pnpm onlyBuiltDependencies config
...
pnpm config set doesn't support onlyBuiltDependencies in global config.
Use .npmrc file instead.
2026-05-07 20:41:05 +08:00
sagit
fdd72979b6
fix: approve @tailwindcss/oxide build script for pnpm v11 ( #497 )
...
pnpm v11 blocks build scripts by default. Allow @tailwindcss/oxide via
onlyBuiltDependencies.
2026-05-07 20:26:24 +08:00
sagitchu
ad33791a26
fix: approve @tailwindcss/oxide build script for pnpm v11
...
pnpm v11 blocks build scripts by default; explicitly allow
@tailwindcss/oxide via onlyBuiltDependencies config.
2026-05-07 20:24:17 +08:00
sagit
6320b1f0c1
fix: upgrade Node.js to 22-alpine for corepack/pnpm compat ( #496 )
...
## Summary
Node.js 20.19.0 + corepack + pnpm@11.0.8 hits
`ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING` during Docker build. Upgrade
builder image to `node:22-alpine` (LTS).
## Verification
Frontend build passes locally with `pnpm run build`.
2026-05-07 20:11:46 +08:00
sagitchu
91d79b6b3a
fix: upgrade Node.js to 22-alpine for corepack/pnpm compatibility
...
node:20.19.0 + corepack + pnpm@11.0.8 hits ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING
2026-05-07 20:09:42 +08:00
sagit
fc7df6bd64
fix: panel self-upgrade helper not recreating containers ( #495 )
...
## Summary
- **Helper container `docker compose up` 不会强制重建容器**:原脚本缺少
`--force-recreate`,Docker Compose
在检测不到配置变化时不会替换运行中的容器,导致拉取了新镜像但旧容器继续运行。新增 `--force-recreate
--remove-orphans` 确保容器被替换。
- **无错误日志**:helper 容器执行失败时没有任何可见反馈。新增 `upgrade.log` 写入部署目录,每一步操作和错误都有记录。
- **"立即升级"按钮永久禁用**:按钮 `isDisabled` 绑定了
`!canOpenSystemUpgradeModal`,该条件要求已完成检查更新且有可用更新,但页面本身有点击时自动检查的逻辑,导致按钮永远无法点击。改为
`!canTriggerSystemUpgrade` 允许自动检查流程触发。
## Verification
| Check | Result |
|-------|--------|
| `go test ./...` | ✅ 498 passed |
| `pnpm run build` | ✅ passed |
| `pnpm run lint` | ✅ passed |
2026-05-07 19:53:53 +08:00
sagitchu
25dfb84324
fix: panel self-upgrade helper not recreating containers
...
- Add --force-recreate --remove-orphans to docker compose up so helper
actually replaces running containers with newly pulled images
- Add upgrade.log file for post-mortem debugging when helper fails
- Add pre-flight validation for docker-compose.yml and .env
- Fix "立即升级" button permanently disabled by relaxing the disabled
condition so auto-check on click can fire
2026-05-07 19:51:18 +08:00
sagit
4ebd6703fe
fix: harden proxy protocol rollout safety ( #494 )
3.0.0-beta12
2026-05-07 16:37:51 +08:00
sagit
1f53a39784
Update contact link from group to channel ( #493 )
2026-05-07 01:26:56 +00:00
sagit
5ebd4c2a91
feat: add panel self-upgrade workflow ( #492 )
3.0.0-beta11
2026-05-06 17:58:01 +08:00
sagit
6c93d829c6
fix: refine advanced settings layout
...
Merge PR #491
3.0.0-beta10
2026-05-04 17:33:56 +08:00
sagitchu
5d22d4cb06
fix: refine advanced settings layout
2026-05-04 17:25:58 +08:00
sagit
e5cd5af550
Use custom probe targets for diagnostics
3.0.0-beta9
2026-05-02 14:27:20 +08:00
sagitchu
cdcdfd8ff0
fix: use custom probe targets for diagnostics
...
Move custom probe target controls into the tunnel advanced settings and reuse the configured target in tunnel diagnosis output.
2026-05-02 14:23:51 +08:00
sagit
791773fd62
Add custom tunnel probe targets ( #488 )
3.0.0-beta8
2026-05-02 00:54:54 +08:00
sagitchu
13764b4615
fix: reject malformed probe target updates
2026-05-02 00:12:41 +08:00
sagitchu
4c882d907b
fix: preserve probe targets on legacy updates
2026-05-02 00:08:24 +08:00
sagitchu
6033e39466
fix: preserve probe targets in backups
2026-05-02 00:02:23 +08:00
sagitchu
0f3242bf11
fix: reject raw probe target whitespace
2026-05-01 23:54:31 +08:00
sagitchu
d97d91801d
fix: reject leading zero probe IPv4
2026-05-01 23:50:41 +08:00
sagitchu
727ef56c67
fix: improve probe target form feedback
2026-05-01 23:46:56 +08:00
sagitchu
a40150b136
fix: type tunnel probe target payloads
2026-05-01 23:42:21 +08:00
sagitchu
a923ec4785
fix: validate probe target port input
2026-05-01 23:39:14 +08:00
sagitchu
42c5492c1d
feat: add tunnel probe target UI
2026-05-01 23:36:14 +08:00
sagitchu
869d726b7a
fix: preserve type one quality probe owner
2026-05-01 23:32:00 +08:00
sagitchu
55a931510b
feat: use probe target for tunnel quality checks
2026-05-01 23:28:26 +08:00
sagitchu
a259dd83b2
fix: load probe target with tunnel record
2026-05-01 23:24:48 +08:00
sagitchu
cc0b8de2e1
feat: use probe target for best exit scoring
2026-05-01 23:20:50 +08:00