sagit
8e513a1bae
Fix nftables node updates after panel restart ( #525 )
...
## Summary
- Skip agent protocol SetProtocol commands when updating nftables nodes.
- Preserve existing nftables SSH credentials when edit forms omit secret
fields.
- Add regression coverage for nftables updates and SSH config
persistence across repository reopen.
## Test Plan
- rtk go test ./...
3.0.1-alpha5
2026-07-02 10:28:00 +08:00
sagitchu
f98be845d3
fix: skip agent protocol updates for nftables nodes
2026-07-02 10:26:10 +08:00
sagit
0c2acfdd8a
Fix nftables recovery and diagnostics ( #524 )
...
## Summary
- Reconcile nftables nodes when background jobs start so rules are
restored after server reboot.
- Collect nftables traffic immediately at startup and every 30 seconds
by default.
- Return nftables rule binding status in forward diagnostics and cover
it with regression tests.
## Test Plan
- `cd go-backend && go test ./...`
- `cd go-backend && make build`
3.0.1-alpha4
2026-06-30 17:11:10 +08:00
sagitchu
777db8767f
fix nftables recovery and diagnostics
2026-06-30 17:07:50 +08:00
sagit
82f6047506
fix(forward): split proxy protocol directions
...
Closes #520
3.0.1-alpha3
2026-06-21 21:03:47 +08:00
sagitchu
3ce320da5a
fix(nftables): harden traffic accounting edges
3.0.1-alpha2
2026-06-07 11:55:59 +08:00
sagitchu
7ab0db29ae
fix(nftables): clean counter state on forward delete
2026-06-07 11:55:59 +08:00
sagitchu
006ea97200
feat(nftables): ingest traffic counters
2026-06-07 11:55:59 +08:00
sagitchu
e569aedd3e
feat(nftables): calculate traffic deltas
2026-06-07 11:55:59 +08:00
sagitchu
35080aea2d
feat(flow): expose forward owner metadata
2026-06-07 11:55:59 +08:00
sagitchu
85e588ffe9
feat(nftables): persist counter state
2026-06-07 11:55:59 +08:00
sagitchu
03524f4a65
feat(nftables): collect counters over ssh
2026-06-07 11:55:59 +08:00
sagitchu
9e69e020ab
feat(nftables): parse traffic counters
2026-06-07 11:55:59 +08:00
sagitchu
14bbd3907d
feat(nftables): render traffic counters
2026-06-07 11:55:59 +08:00
sagitchu
ca8d8e92ba
docs: plan nftables traffic stats
2026-06-07 11:55:59 +08:00
sagitchu
079474fa06
docs: design nftables traffic stats
2026-06-07 11:55:59 +08:00
sagit
6e249a54f4
feat: add nftables forwarding mode ( #516 )
...
Adds nftables forwarding support for nodes, including frontend mode
selection, backend rule rendering, SSH-based rule reconciliation, and
online-state handling for nftables nodes.\n\nVerification:\n-
go-backend: go test ./...\n- vite-frontend: pnpm run build
3.0.1-alpha1
2026-06-01 19:56:44 +08:00
sagitchu
fb798a4532
chore(frontend): refresh pnpm lockfile
2026-06-01 19:54:28 +08:00
sagitchu
a599f383f5
feat: add nftables forwarding mode
2026-06-01 19:47:26 +08:00
sagitchu
6bfa7f0166
docs: design nftables forwarding
2026-05-30 22:14:38 +08:00
sagit
2d0c993c90
fix: allow admin access to sensitive configs ( #511 )
3.0.0
3.0.0-rc6
2026-05-17 23:09:31 +08:00
sagitchu
8b64542c94
fix(handler): allow admin access to sensitive configs
2026-05-17 23:07:37 +08:00
sagit
032b0f0cfd
fix: serialize websocket writes in realtime server ( #510 )
3.0.0-rc5
2026-05-17 21:52:54 +08:00
sagitchu
7008717a49
fix(ws): serialize websocket writes in realtime server
2026-05-17 21:48:37 +08:00
sagit
8552a70355
fix: harden panel self-upgrade ( #506 )
...
This fixes panel self-upgrade and monitor realtime access for permitted
non-admin users.
Changes:
- Reuse GitHub proxy config for system upgrade release/API fetches.
- Make panel self-upgrade helper fail fast on compose command errors.
- Allow users with explicit monitor permission to connect to the
realtime websocket and receive broadcasts, not just admins.
Validation:
- cd go-backend && GOCACHE=/private/tmp/flvx-gocache go test
./internal/http/handler -count=1
- cd go-backend && go test ./internal/ws -count=1
3.0.0-rc4
2026-05-15 23:54:27 +08:00
sagitchu
b2454e86c9
fix: allow monitor realtime websocket access
2026-05-15 23:37:08 +08:00
sagitchu
312c9a9c5c
fix: harden panel self-upgrade
2026-05-15 23:16:14 +08:00
sagit
e1324b8c8c
fix: update dependabot vulnerabilities ( #505 )
...
* docs: add dependabot remediation design
* docs: add dependabot remediation plan
* fix: update backend pgx dependency
* fix: update frontend vulnerable dependencies
* fix: update gost quic dependencies
* fix: migrate gost dtls dependency
* fix: sync gost main dependencies
* fix: enable webtransport stream reset partial delivery
* fix: restore backend bcrypt dependency
3.0.0-rc2
3.0.0-rc3
2026-05-15 00:16:29 +08:00
sagit
c034d0d41f
fix: allow public config fallback for cached login ( #504 )
...
## Summary
- allow cached/old login clients to read public config keys through
`/api/v1/config/get` without a valid token
- keep sensitive config keys blocked from unauthenticated access
- stabilize the system upgrade fail-fast test by avoiding live
stable-release lookup and using POSIX shell syntax
## Test Plan
- `cd go-backend && go test ./...`
2026-05-14 18:46:43 +08:00
sagitchu
fd3ecc38ef
fix: allow public config fallback for cached login
2026-05-14 18:45:12 +08:00
sagit
2eee506716
fix: harden auth, config access, and backups ( #503 )
...
## Summary
- Migrate password storage to bcrypt with legacy MD5 verification-only
support and best-effort upgrade on successful auth.
- Revoke JWTs on auth-state changes, align WebSocket admin auth, and
split public config reads from protected config reads.
- Filter sensitive configs from backup export/import and update contract
coverage for the new security boundaries.
## Test Plan
- [x] `go test ./... -count=1`
- [x] `pnpm run lint`
- [x] `pnpm run build`
3.0.0-rc1
2026-05-14 11:21:45 +08:00
sagitchu
abf13bdac9
fix: close remaining security remediation gaps
2026-05-14 11:10:06 +08:00
sagitchu
f0facf6703
fix: block sensitive config writes
2026-05-14 10:37:29 +08:00
sagitchu
583a3834f9
fix: expire websocket admin sessions
2026-05-14 01:24:03 +08:00
sagitchu
bd13477fa3
fix: stop caching sensitive configs in browser
2026-05-14 00:34:52 +08:00
sagitchu
106a30bf9d
fix: tighten websocket auth and client cache handling
2026-05-14 00:24:56 +08:00
sagitchu
465815cf34
fix: harden auth, config access, and backups
2026-05-13 23:53:06 +08:00
sagitchu
ec9fb77eb5
docs: add security remediation design spec
2026-05-13 14:17:51 +08:00
sagitchu
7d63dd4cc3
docs: add proxy protocol analysis and panel self-upgrade plans
2026-05-13 10:49:33 +08:00
sagit
4cfa6adee7
fix: Docker build pnpm/corepack compatibility ( #501 )
...
## Summary
- `node:20.19.0` + `corepack` + `pnpm@11` →
`ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING`
- `pnpm@11` blocks `@tailwindcss/oxide` build scripts by default
- Fix: `node:22-alpine` + `corepack prepare pnpm@10 --activate &&
corepack enable pnpm`
## Verification (all local)
| Check | Result |
|-------|--------|
| `docker build ./vite-frontend` | ✅ |
| `go test ./...` | ✅ 498 passed |
| `pnpm run build` | ✅ |
| `pnpm run lint` | ✅ |
3.0.0-beta20
2026-05-07 21:26:54 +08:00
sagitchu
bc8f2ec8a1
fix: use corepack prepare pnpm@10 for Docker build compatibility
...
- node:22-alpine + corepack + pnpm@11 hits ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING
- corepack enable pnpm@10 is invalid syntax; use corepack prepare + enable
- pnpm@10 avoids the build script approval issue entirely
- Verified: docker build, pnpm build, pnpm lint, go test all pass locally
2026-05-07 21:24:47 +08:00
sagit
9a37c2f603
fix: pin pnpm to v10 in Dockerfile ( #500 )
...
Pin pnpm to v10 to avoid v11 build script issues in Docker build.
2026-05-07 21:12:57 +08:00
sagitchu
ff6d46ddaf
fix: pin pnpm to v10 in Dockerfile to avoid v11 build script issues
...
pnpm v11 blocks build scripts by default and the onlyBuiltDependencies
config is difficult to set in Docker build context. Pin to pnpm@10.
2026-05-07 21:10:41 +08:00
sagit
723534faea
fix: use pnpm-workspace.yaml for onlyBuiltDependencies ( #499 )
...
Create pnpm-workspace.yaml inline in Dockerfile for pnpm v11 build
scripts.
2026-05-07 20:57:50 +08:00
sagitchu
73490a9be6
fix: use pnpm-workspace.yaml for onlyBuiltDependencies
...
Create pnpm-workspace.yaml inline in Dockerfile to allow
@tailwindcss/oxide build scripts in pnpm v11.
2026-05-07 20:55:42 +08:00
sagit
5a327459f7
fix: use .npmrc for pnpm onlyBuiltDependencies ( #498 )
...
Use .npmrc file for pnpm v11 build scripts approval.
2026-05-07 20:43:29 +08:00
sagitchu
f307e7d5eb
fix: use .npmrc for pnpm onlyBuiltDependencies config
...
pnpm config set doesn't support onlyBuiltDependencies in global config.
Use .npmrc file instead.
2026-05-07 20:41:05 +08:00
sagit
fdd72979b6
fix: approve @tailwindcss/oxide build script for pnpm v11 ( #497 )
...
pnpm v11 blocks build scripts by default. Allow @tailwindcss/oxide via
onlyBuiltDependencies.
2026-05-07 20:26:24 +08:00
sagitchu
ad33791a26
fix: approve @tailwindcss/oxide build script for pnpm v11
...
pnpm v11 blocks build scripts by default; explicitly allow
@tailwindcss/oxide via onlyBuiltDependencies config.
2026-05-07 20:24:17 +08:00
sagit
6320b1f0c1
fix: upgrade Node.js to 22-alpine for corepack/pnpm compat ( #496 )
...
## Summary
Node.js 20.19.0 + corepack + pnpm@11.0.8 hits
`ERR_VM_DYNAMIC_IMPORT_CALLBACK_MISSING` during Docker build. Upgrade
builder image to `node:22-alpine` (LTS).
## Verification
Frontend build passes locally with `pnpm run build`.
2026-05-07 20:11:46 +08:00