When captcha_enabled=true but cloudflare_secret_key is not configured,
the login flow would block users with "未配置Cloudflare Site Key" error.
Now captcha is treated as disabled if the secret key is missing, allowing
users to log in normally on fresh PostgreSQL installations.
Fixes login issue on new panel setups with PostgreSQL.
- Extract database layer into model and repo packages
- Split repository into focused modules (control, federation, flow, groups, mutations)
- Remove monolithic db.go and sqlite/repository.go
- Update handlers to use new repository structure
- Migrate contract tests to new patterns
- Add migration plan documentation
* feat(announcement): add database schema for SQLite and PostgreSQL
Add announcement table with id, title, content, enabled, created_at, updated_at columns to both SQLite and PostgreSQL schemas to support announcement system.
* feat(announcement): implement SQLite repository for announcement management
Add announcement CRUD operations in SQLite repository including create, read, update, delete, and list methods with proper error handling.
* feat(announcement): add HTTP handlers and auth middleware for announcement API
Implement admin-only update endpoint and public read endpoint for announcements. Add auth middleware to enforce admin-only access for update operations.
* feat(announcement): add frontend API client for announcement endpoints
Implement API client methods for fetching announcements and updating announcement settings with proper error handling.
* feat(announcement): add announcement display component to dashboard
Implement announcement display section in dashboard with real-time updates and proper styling using HeroUI components.
* feat(announcement): add announcement management UI to config page
Implement announcement settings panel with enable/disable toggle and content editor for admin users to manage announcements.
- Add transaction support for import operations with rollback on failure
- Add auto-backup before import to allow recovery on failure
- Convert user import to use INSERT ON CONFLICT pattern
- Add Execer interface to support both DB and Tx in import functions
Allow editing port range, traffic limit, allowed domains, allowed API
IPs and expiry time on existing shares via a new update endpoint and
edit modal in the frontend.
Route diagnosis for shared remote nodes through federation runtime APIs so tunnel and forward diagnostics work across panels, and add contract coverage for single-panel and dual-panel scenarios.
Bridge Java-to-Go runtime behavior by enforcing forward ownership checks, wiring node command dispatch/diagnostics, and adding contract coverage so migrated APIs can run with production semantics.