Compare commits

..

61 Commits

Author SHA1 Message Date
sagit 2ff52e3275 feat: 2.1.7-beta4 release - forward service stability and UI enhancements (#257)
## Summary

This PR consolidates multiple features and fixes for the 2.1.7-beta4
release:

**Forward Service Stability:**
- Handle forward service rebind on self-occupied port conflicts
- Preserve bind IP when editing forward without explicit inIp change

**Import Enhancements:**
- Add ny format support for forward import with node-based tunnel
matching
- Add ny import compatibility with auto port assignment

**Custom IP Selection:**
- Add custom IP selection for nodes, tunnels, and forwards
- Use configured connectIp for tunnel chain diagnosis

**UI Improvements:**
- Add tunnel group collapse and drag sorting in full mode
- Add global compact mode with alpha8 list layout
- Expose forward compact mode switch in settings

**Infrastructure:**
- Add comprehensive migration test for legacy columns

## Commits

- 7efb49b fix: handle forward service rebind on self-occupied port
- 1450b25 fix: preserve bind IP when editing forward without explicit
inIp change
- 7c54192 feat: add ny import compatibility with auto port assignment
- 7ba6877 refactor: simplify forward import tunnel selection
- ef613c1 feat: add ny format support for forward import with node-based
tunnel matching
- 1c10347 fix: use configured connectIp for tunnel chain diagnosis
- e383359 fix: apply custom IP binding to forward and tunnel chain
services
- 9cf9f4f feat: add comprehensive migration test for legacy columns
- b819341 feat: add custom IP selection for nodes, tunnels, and forwards
- 634c6cd feat(forward): add tunnel group collapse and drag sorting in
full mode
- 98a9e5c fix(config): expose forward compact mode switch in settings
- 77e4387 feat(forward): add global compact mode with alpha8 list layout
2026-03-03 20:54:26 +08:00
sagitchu 7efb49bdab fix: handle forward service rebind on self-occupied port
When UpdateService encounters bind address conflicts (port already in use),
the handler now automatically deletes existing forward services and retries
the AddService operation. This resolves issues where a forward's own stale
listener prevents the update.

- Add isBindAddressInUseError() to detect port bind conflicts
- Add rebindForwardServiceOnSelfOccupiedPort() for automatic cleanup and retry
- Add HasOtherForwardOnNodePort() repository method to verify port ownership
- Add unit tests for bind conflict detection
2026-03-03 20:53:55 +08:00
sagit a00b20abf3 feat: forward management enhancements and bind IP preservation (#256)
## Summary
- Fix bind IP preservation when editing forwards without explicit inIp
changes
- Add ny format import support with node-based tunnel matching and auto
port assignment
- Add custom IP selection for nodes, tunnels, and forwards
- Add tunnel group collapse and drag sorting in full mode
- Add global compact mode with alpha8 list layout
- Various bug fixes and improvements

## Test plan
- [x] Unit tests for forward port replacement with preserved InIP
- [x] Manual testing of forward edit flow
- [x] Verified bind IP is preserved when editing forwards without
touching the inIp field
2026-03-03 20:23:29 +08:00
sagitchu 1450b25475 fix: preserve bind IP when editing forward without explicit inIp change
- Add replaceForwardPortsPreservingInIP to maintain existing InIP values
- Track inIpTouched state in frontend to distinguish user changes
- Only send inIp in update request when user explicitly changed it
- Add unit tests for forward port replacement with preserved InIP
2026-03-03 20:22:58 +08:00
sagit b815be54b8 feat: ny import compatibility and forward enhancements (#252)
## Summary
- **ny import compatibility**: 支持可选的 `listen_port` 字段自动分配端口
- **alias field mapping**: 支持字段别名映射 (dest/dst/target, listenPort/port,
name/forward_name)
- **help text update**: 更新帮助文本说明自动端口分配功能
- **parser tests**: 添加解析器测试覆盖别名字段和缺失端口处理
- **tunnel selection refactor**: 简化转发导入隧道选择逻辑
- **custom IP selection**: 为节点、隧道和转发添加自定义IP选择
- **compact mode**: 添加全局紧凑模式和隧道组折叠排序

## Changes
- `vite-frontend/src/pages/forward/import-format.ts`:
ny格式解析器增强,支持字段别名和可选端口
- `vite-frontend/src/pages/forward/import-format.test.ts`: 添加解析器测试
- `vite-frontend/src/pages/forward.tsx`: 更新UI帮助文本
2026-03-03 16:55:31 +08:00
sagitchu 75edeb9afa Merge remote-tracking branch 'origin/main' into opencode/mighty-nebula
# Conflicts:
#	vite-frontend/src/pages/forward.tsx
#	vite-frontend/src/pages/forward/import-format.test.ts
#	vite-frontend/src/pages/forward/import-format.ts
2026-03-03 16:55:14 +08:00
sagitchu 7c54192055 feat: add ny import compatibility with auto port assignment
- Support optional listen_port field for automatic port assignment
- Add alias field mapping (dest/dst/target, listenPort/port, name/forward_name)
- Update help text to document auto port assignment
- Add parser tests for alias fields and missing port handling

Entire-Checkpoint: efae74a1f03c
2026-03-03 16:54:05 +08:00
sagitchu 7ba68778c1 refactor: simplify forward import tunnel selection
- Remove separate entry node selection for ny format
- Unify tunnel selection for both flvx and ny formats
- Remove unused tunnel select modal component
- Simplify import button validation logic
2026-03-03 16:17:36 +08:00
sagit 7b736b2e60 feat: add ny format support for forward import with node-based tunnel matching (#250) 2026-03-03 15:39:07 +08:00
sagitchu ef613c1518 feat: add ny format support for forward import with node-based tunnel matching 2026-03-03 15:38:03 +08:00
sagit b62df6ffa3 feat: custom IP selection and connectIp diagnosis fixes (#248)
## Summary
- Add custom IP selection dropdown for nodes, tunnels, and forwards
(supports IPv4/IPv6 dual-stack)
- Fix connectIp not being used in tunnel chain diagnosis (resolves #211)
- Reconstruct tunnel state with connectIp field preserved
- Fix forward service config when bindIP already contains port
- Add comprehensive migration tests for legacy columns
- Support tunnel-group collapse and ordering in forward full mode
- Add global compact mode for forward list display

## Changes
### Backend
- `control_plane.go`: Pass connectIp through resolveChainProbeTarget in
diagnosis
- `mutations.go`: Include connectIp in tunnel state reconstruction
- `model.go`: Add migration for connect_ip columns
- `repository.go`: Support connect_ip in CRUD operations

### Frontend
- `node.tsx`, `tunnel.tsx`, `forward.tsx`: IP selection dropdowns
- `settings.tsx`: Forward compact mode switch
- `config.tsx`: Expose compact mode setting

### Tests
- Contract tests for connectIp diagnosis scenarios
- Migration tests for legacy column handling
- Unit tests for bindIP with port

## Test Plan
- [x] Contract tests pass (`go test ./tests/contract/...`)
- [x] Unit tests pass (`go test ./...`)
- [x] Manual testing: tunnel diagnosis uses configured connectIp
- [x] Manual testing: IP selection dropdowns work correctly
2026-03-03 14:19:35 +08:00
sagitchu be9d8773ce merge: resolve conflicts with main branch 2026-03-03 14:19:18 +08:00
sagitchu 1c10347357 fix: use configured connectIp for tunnel chain diagnosis
- Pass connectIp through resolveChainProbeTarget in diagnosis stream start items
- Pass connectIp in appendChainHopDiagnosis for full chain probes
- Reconstruct tunnel state with connectIp field preserved
- Fix forward service config when bindIP already contains port
- Add contract tests for connectIp diagnosis scenarios
- Add unit test for bindIP with port in buildForwardServiceConfigs
- Update AGENTS.md with plan document rules

Entire-Checkpoint: 35a2e61c2431
2026-03-03 14:17:36 +08:00
sagit 5bd21e2ac1 feat: custom IP selection and forward list enhancements (#247)
* feat: add comprehensive migration test for legacy columns

- Add ExtraIPs, TCPListenAddr, UDPListenAddr to Node migration
- Add ip_preference to Tunnel migration
- Add test for very legacy database migration (1.x schema)
- Include issue #211 tracking document

Entire-Checkpoint: 0d086883c34a

* fix: apply custom IP binding to forward and tunnel chain services

Entire-Checkpoint: ceff329d4cf4
2026-03-03 10:59:00 +08:00
sagitchu e38335973d fix: apply custom IP binding to forward and tunnel chain services
Entire-Checkpoint: ceff329d4cf4
2026-03-03 10:58:15 +08:00
sagit 95929bf82e feat: add comprehensive migration test for legacy columns (#245)
- Add ExtraIPs, TCPListenAddr, UDPListenAddr to Node migration
- Add ip_preference to Tunnel migration
- Add test for very legacy database migration (1.x schema)
- Include issue #211 tracking document

Entire-Checkpoint: 0d086883c34a
2026-03-03 10:28:10 +08:00
sagitchu 9cf9f4f1f7 feat: add comprehensive migration test for legacy columns
- Add ExtraIPs, TCPListenAddr, UDPListenAddr to Node migration
- Add ip_preference to Tunnel migration
- Add test for very legacy database migration (1.x schema)
- Include issue #211 tracking document

Entire-Checkpoint: 0d086883c34a
2026-03-03 10:27:29 +08:00
sagit ae8dbdd77f feat: add custom IP selection for nodes, tunnels, and forwards (#244)
## Summary

- Add `extra_ips` field to nodes for multi-IP servers (comma-separated)
- Add `connect_ip` field to `chain_tunnel` for specifying which IP to
connect to on multi-IP nodes
- Add `in_ip` field to `forward_port` for specifying which IP to listen
on
- Frontend: add UI controls for extra IPs on node form
- Frontend: add connect IP input for tunnel chain nodes (both relay hops
and exit nodes)
- Frontend: add listen IP input for forward creation/editing
- Backend: resolve forward ingress with custom listen IP priority
(per-port IP > tunnel IP > node IP)

This enables fine-grained control over IP selection on multi-homed
servers.
2026-03-03 09:47:17 +08:00
sagitchu 05bd6a686d feat: add IP selection dropdown for tunnels and forwards
Entire-Checkpoint: fde43d8c94e5
2026-03-03 09:16:05 +08:00
sagitchu b8193417f5 feat: add custom IP selection for nodes, tunnels, and forwards
- Add extra_ips field to nodes for multi-IP servers
- Add connect_ip field to chain_tunnel for specifying connection address
- Add in_ip field to forward_port for specifying listen address
- Frontend: add UI controls for extra IPs on node form
- Frontend: add connect IP input for tunnel chain nodes
- Frontend: add listen IP input for forward form
- Backend: resolve forward ingress with custom listen IP priority

Entire-Checkpoint: 557563462c16
2026-03-03 08:24:15 +08:00
sagit 15e4508be4 feat(forward): support tunnel-group collapse and ordering in full mode (#243)
## Summary
- add collapsible tunnel groups in the forward page when compact mode is
disabled
- add drag-and-drop ordering for tunnel groups within each user section
in full mode
- persist group order/collapse by current login user (admins: local +
global config, normal users: local only)

## Testing
- npm run build (vite-frontend)
2026-03-02 22:25:31 +08:00
sagitchu 634c6cd620 feat(forward): add tunnel group collapse and drag sorting in full mode 2026-03-02 22:24:39 +08:00
sagit 4eaecb289b fix(config): expose forward compact mode switch in settings (#241)
## Summary
- Add `forward_compact_mode` to the `/config` settings item list so the
compact-mode switch is visible in the main settings page.
- Include `forward_compact_mode` in initial config cache keys to keep
switch state consistent on load.

## Verification
- `npm run build` (vite-frontend)
2026-03-02 21:37:10 +08:00
sagitchu 98a9e5c666 fix(config): expose forward compact mode switch in settings 2026-03-02 21:36:33 +08:00
sagit d244920dd4 feat(forward): add global compact mode with alpha8 list layout (#240)
## Summary
- Add a global forward compact mode toggle in settings, persisted via
`config` key `forward_compact_mode`.
- Make forward page read and react to this global setting in real time
through a browser event.
- In compact mode, render forward list using the 2.1.6-alpha8 style
(single grouped table / global direct card grid) while keeping non-list
interactions unchanged.

## Verification
- Installed frontend dependencies with `npm install`.
- Built frontend successfully with `npm run build`.
2026-03-02 21:11:39 +08:00
sagitchu 77e4387b35 feat(forward): add global compact mode with alpha8 list layout 2026-03-02 21:10:56 +08:00
sagit 7a40ddb1ef fix(diagnosis): tighten timeout handling and clarify timeout messaging (#233)
## Summary
- shorten per-item diagnosis command timeout from 2 minutes to 30
seconds while keeping overall request timeout at 2 minutes
- centralize timeout messages in backend constants and apply consistent
timeout fallback handling in diagnosis result assembly
- update frontend forward/tunnel diagnosis timeout copy to clearly
explain single-item and overall timeout limits

## Notes
- includes workspace tool config files under `.claude/` and `.entire/`
as part of this commit
2026-03-01 18:39:19 +08:00
sagitchu d33814e18c fix(diagnosis): tighten timeout handling and clarify timeout messaging 2026-03-01 18:37:53 +08:00
sagit cf51b305b0 fix(diagnosis): prevent progress stream blocking and refine tunnel type chips (#230)
* fix(diagnosis): avoid result channel deadlock in progress stream

Close the diagnosis result channel asynchronously after workers complete so progress can stream without blocking, and improve tunnel card type chip contrast for clearer protocol distinction.

* feat(diagnosis): stream pending items and render in-progress states

Pre-populate diagnosis stream with pending targets so tunnel and forward dialogs can show per-item diagnosing status immediately. Update result typing and UI states to distinguish in-progress, success, and failure rows/cards consistently.
2026-03-01 14:49:38 +08:00
sagit 9ffeb83753 fix(forward): align table columns and fix card layout (#228) 2026-03-01 11:14:12 +08:00
sagit 2f40cf29d4 feat(frontend): group forwards by user with admin priority sorting (#227)
## Summary
- Add user grouping for forwards in both grouped table and card views
- Sort user groups with admin's own group first, then alphabetically by
name
- Restrict drag-and-drop reordering to same user group only to prevent
cross-user data mixing
- Remove redundant user column from grouped table view (user shown in
group header)
- Add user group headers with forward count badges and "管理员本人" chip for
admin's own group
2026-02-28 20:11:18 +08:00
sagitchu a92eb168aa feat(diagnosis): add streaming progress support and tunnel-grouped forward list
- Add SSE streaming endpoints for tunnel/forward diagnosis with real-time progress
- Increase diagnosis timeout to 2 minutes with context propagation
- Group forwards by tunnel within user groups in UI
- Add nginx SSE proxy configuration for streaming endpoints
2026-02-28 20:09:25 +08:00
sagitchu de21a55f37 fix(diagnosis): parallelize runtime checks and raise API timeouts 2026-02-28 18:46:36 +08:00
sagitchu b01dbdb6e5 feat(frontend): group forwards by user with admin priority sorting
- Add ForwardUserGroup interface and helper utilities
- Group forwards by user in both grouped table and card views
- Sort user groups with admin's own group first, then alphabetically
- Restrict drag-and-drop to same user group only
- Remove redundant user column from grouped table view
- Add user group headers with forward count badges
2026-02-28 17:20:10 +08:00
sagit a645cc699b docs: add AI Skill and PostgreSQL nav items (#226) 2026-02-28 06:27:36 +00:00
sagit 528f912aac docs: add AI Skill integration guide (#225)
## Summary
- Add AI Skill documentation for LLM integration with FLVX panel
- Include complete API reference documentation for the skill
- Add publish workflow for skill distribution

## Changes
- New `doc/ai-skill.md` guide
- New `skills/flvx-api/` directory with API references
- New `.github/workflows/publish-skill.yml` workflow
- Update `doc/index.md` navigation
2026-02-28 14:13:34 +08:00
sagit 8bf30a157f Merge branch 'main' into opencode/proud-rocket 2026-02-28 14:12:35 +08:00
sagitchu 58abba7fc0 docs: add AI Skill integration guide 2026-02-28 14:07:54 +08:00
sagit d8cd4b404c refactor(tests): consolidate contract test helpers and add Playwright e2e tests (#224)
## Summary
- Add Playwright e2e test suite for frontend and API
- Consolidate contract test helpers, removing redundant internal test
file
- Simplify test setup across multiple contract test files
2026-02-28 12:15:51 +08:00
sagitchu 9e979aa82a refactor(tests): consolidate contract test helpers 2026-02-28 12:13:28 +08:00
sagit 5caaaf6092 test: add Playwright e2e test suite (#223)
## Summary
- Add comprehensive Playwright e2e test suite for frontend and API
testing
- Include test fixtures, page objects, and API client utilities
- Add tests for auth flow, dashboard, user UI, and API endpoints
2026-02-28 10:35:55 +08:00
sagitchu f23d1c2afd test: add Playwright e2e test suite for frontend and API 2026-02-28 10:33:32 +08:00
sagit 5e00cbf131 feat: speed limit UX improvements and brand customization (#222)
## Summary
- 简化限速选择器 UX,移除冗余的"不限速"选项项
- 默认转发限速规则为不限速
- 移除限速规则与隧道的绑定关系并添加迁移清理
- 改进 favicon 加载逻辑,添加 fallback 到 config API
- 添加品牌资源上传功能(PNG 转换)并改进配置验证
- 改进验证码验证和转发服务同步
- 添加自定义 favicon 和角落 logo 及实时预览
- 统一限速规则选择器的 placeholder 显示
2026-02-27 19:55:30 +08:00
sagitchu 975948dcf6 fix(frontend): simplify speed limit selector UX 2026-02-27 19:53:19 +08:00
sagitchu a9eac6d01f fix(frontend): default forward speed rule to no limit
Make forward create/edit treat empty speed-limit selection as no limit so the dropdown no longer shows the generic placeholder, and remove announcement console logging to keep frontend lint clean.
2026-02-27 19:37:59 +08:00
sagitchu 6e8406f439 feat: remove speed limit tunnel binding and add migration cleanup
- Remove tunnel binding UI from speed limit page (no more Select component)
- Remove /api/v1/speed-limit/tunnels route alias
- Simplify CreateSpeedLimit/UpdateSpeedLimit to not accept tunnel parameters
- Add schema migration v4 to clear historical tunnel_id/tunnel_name bindings
- Update contract tests to verify tunnel binding is ignored
- Add limiter sync failure tests for forward-level rate limiting
2026-02-27 19:30:02 +08:00
sagit db3577afa9 feat(frontend): improve favicon loading with fallback to config API (#221)
## Summary
- Add synchronous config API call in index.html when localStorage cache
is empty
- Prevents favicon flash on login page during first load
- Enhance getCachedConfigs() to fetch public configs as fallback
- Preserve existing siteConfig values when config keys are missing
2026-02-27 18:25:16 +08:00
sagitchu 7285717e34 feat(frontend): improve favicon loading with fallback to config API
- Add synchronous config API call in index.html when localStorage cache is empty
- Prevents favicon flash on login page during first load
- Enhance getCachedConfigs() to fetch public configs as fallback
- Preserve existing siteConfig values when config keys are missing
2026-02-27 18:23:18 +08:00
sagit de6911f219 feat: add brand asset upload with PNG conversion and improve config validation (#220)
## Summary
- Add file upload support for logo and favicon with automatic PNG
conversion (96x96 for logo, 64x64 for favicon)
- Add backend validation for brand asset data URLs (app_logo,
app_favicon)
- Change vite_config.value column type from varchar(200) to text for
PostgreSQL compatibility
- Add schema migration v3 for vite_config.value column type conversion
- Update frontend to use file picker instead of manual URL input
- Add early favicon application in index.html to prevent flash

## Changes
- Backend: Validate brand asset data URLs, support larger config values
- Frontend: File upload with PNG conversion, improved caching
- Migration: PostgreSQL vite_config.value column type migration

## Testing
- Backend contract tests added for migration v3
2026-02-27 15:56:14 +08:00
sagitchu e5ce0501a2 feat: add brand asset upload with PNG conversion and improve config validation
- Add file upload support for logo and favicon with automatic PNG conversion
- Add backend validation for brand asset data URLs (app_logo, app_favicon)
- Change vite_config.value column type from varchar(200) to text for PostgreSQL
- Add schema migration v3 for vite_config.value column type conversion
- Update frontend to use file picker instead of manual URL input
- Add early favicon application in index.html to prevent flash
2026-02-27 15:54:04 +08:00
sagit 25a87e25c5 fix(backend): improve captcha validation and forward service sync (#219)
## Summary
- Add cloudflare site/secret key validation for captcha enabled check to
prevent incomplete captcha config
- Fix forward create to use UpdateService with tolerateExists for
idempotent service sync
- Introduce isAlreadyExistsMessage helper that correctly excludes
"address already in use" errors from being tolerated
- Add contract tests for forward toggle (pause/resume), address-in-use
rollback, and captcha compatibility

## Test Plan
- Contract tests added: `TestForwardCreateThenPauseResumeContract`,
`TestForwardCreateRollbackWhenServiceDispatchReturnsAddressInUseContract`,
`TestIsAlreadyExistsMessage`
- Captcha login flow tests updated for cloudflare key validation
2026-02-27 14:52:14 +08:00
sagitchu a628f31859 fix(backend): improve captcha validation and forward service sync
- Add cloudflare site/secret key validation for captcha enabled check
- Fix forward create to use UpdateService with tolerateExists for idempotent sync
- Introduce isAlreadyExistsMessage helper excluding address-in-use errors
- Add contract tests for forward toggle, address-in-use rollback, captcha compatibility
2026-02-27 14:49:59 +08:00
sagitchu aae138a8cf fix(forward): remove placeholder from speed limit select, default to no limit 2026-02-27 14:49:59 +08:00
sagit d2645589da feat(frontend): add customizable favicon and corner logo with live preview (#218)
* feat(frontend): add customizable favicon and corner logo with live preview

- Add app_logo and app_favicon config fields in config page
- Implement BrandLogo component with URL fallback to SVG logo
- Integrate BrandLogo into all layouts (admin, h5, h5-simple) and navbar
- Add real-time preview for favicon and logo in config page with error state
- Support both relative paths and full image URLs for branding assets
- Sync branding changes (app_name/app_logo/app_favicon) to site config on save

* fix(frontend): preserve tunnel node selection order

* fix(select): use useMemo for option label map to improve performance
2026-02-27 11:50:03 +08:00
sagit 6684a3426b fix(frontend): use placeholder for IP preference select (#217)
## Summary
- Replace empty key SelectItem with proper placeholder for IP preference
dropdown
- Improves UX consistency with other select components
2026-02-27 08:39:26 +08:00
sagitchu 7a8595ec87 fix(frontend): use placeholder for IP preference select instead of empty key item 2026-02-27 08:33:10 +08:00
sagitchu 06f76d918f fix(frontend): unify speed rule placeholders in selects 2026-02-27 08:33:10 +08:00
sagit feb357ff17 fix: tunnel chain order and speed limit UI improvements (#216)
* fix(backend): use correct chain order index for tunnel nodes

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-opencode)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>

* fix(frontend): filter '不限速' from speed limit dropdowns and preserve node order

Ultraworked with [Sisyphus](https://github.com/code-yeongyu/oh-my-opencode)

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>

---------

Co-authored-by: Sisyphus <clio-agent@sisyphuslabs.ai>
2026-02-26 21:30:25 +08:00
sagit 34581e0d18 feat: decouple speed limits from tunnels and add forward-level rate limiting (#214)
## Summary

This PR refactors the speed limiting functionality to decouple it from
tunnel-specific binding and adds support for forward-level rate
limiting.

### Key Changes

**Backend (Go)**:
- `SpeedLimit.TunnelID` and `SpeedLimit.TunnelName` are now nullable,
allowing speed limits to be created without binding to a specific tunnel
- `Forward` model now has `SpeedID sql.NullInt64` field for
forward-level rate limiting
- `ForwardRecord` updated to include `SpeedID` for control plane use
- Repository methods updated to handle optional tunnel binding in CRUD
operations
- Control plane now prioritizes `Forward.SpeedID` over
`UserTunnel.SpeedID`

**Frontend (React/TypeScript)**:
- Updated `limit.tsx` to support creating speed limits without tunnel
binding
- Tunnel selection is now optional in the speed limit form
- Updated TypeScript types for optional `tunnelId` and new `speedId`
fields

### Behavior

**Speed Limit Application Priority**:
1. `Forward.SpeedID` - Forward-level rate limiting (highest priority)
2. `UserTunnel.SpeedID` - User tunnel permission-level rate limiting
(fallback)

### Migration Notes

Database schema changes will be handled automatically by GORM
AutoMigrate:
- `speed_limit.tunnel_id` and `speed_limit.tunnel_name` become nullable
- `forward.speed_id` column added (nullable)

### Docker Images

Built and pushed:
- `ghcr.io/sagit-chu/vite-frontend:beta`
- `ghcr.io/sagit-chu/vite-frontend:latest`
- `ghcr.io/sagit-chu/flux-panel-backend:beta`
- `ghcr.io/sagit-chu/flux-panel-backend:latest`

closes #201 #155
2026-02-26 20:20:11 +08:00
sagitchu 61c5b5e759 feat: add speed limit contract tests and refine limit/user UI 2026-02-26 20:18:29 +08:00
sagitchu c8eb780c67 feat: decouple speed limits from tunnels and add forward-level rate limiting
- Make SpeedLimit.TunnelID and TunnelName nullable (optional binding)
- Add SpeedID field to Forward model for forward-level rate limiting
- Update ForwardRecord to include SpeedID for control plane
- Update repository methods to handle optional tunnel binding
- Update handlers to accept optional tunnelId in create/update
- Modify control plane to prioritize Forward.SpeedID over UserTunnel speed limit
- Update frontend limit.tsx to support creating speed limits without tunnel binding
- Update TypeScript types for optional tunnelId and new speedId fields

This allows speed limits to be created as reusable rules that can be applied
to either tunnels (via UserTunnel.SpeedID) or individual forwards (via Forward.SpeedID).
2026-02-26 13:08:35 +08:00
147 changed files with 55911 additions and 1266 deletions
+84
View File
@@ -0,0 +1,84 @@
{
"hooks": {
"PostToolUse": [
{
"matcher": "Task",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code post-task"
}
]
},
{
"matcher": "TodoWrite",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code post-todo"
}
]
}
],
"PreToolUse": [
{
"matcher": "Task",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code pre-task"
}
]
}
],
"SessionEnd": [
{
"matcher": "",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code session-end"
}
]
}
],
"SessionStart": [
{
"matcher": "",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code session-start"
}
]
}
],
"Stop": [
{
"matcher": "",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code stop"
}
]
}
],
"UserPromptSubmit": [
{
"matcher": "",
"hooks": [
{
"type": "command",
"command": "entire hooks claude-code user-prompt-submit"
}
]
}
]
},
"permissions": {
"deny": [
"Read(./.entire/metadata/**)"
]
}
}
@@ -0,0 +1,24 @@
# Session Context
Session ID: ses_34dfc44d5ffedfgo4G9wPONyXC
Commit Message: 在agent.md里规定,每次计划都必须写一个计划文档,md格式,按序号增加和以计划的总结命名,每次完成一个任务做好标记
## Prompts
### Prompt 1
在agent.md里规定,每次计划都必须写一个计划文档,md格式,按序号增加和以计划的总结命名,每次完成一个任务做好标记
## Summary
已按你的要求更新完成。
我在 `AGENTS.md` 里新增了 `## PLAN DOCUMENT RULE` 章节,内容包括:
- 每次新实现计划都必须有独立 Markdown 计划文档
- 计划文档统一放在 `plans/` 目录
- 文件名采用递增序号 + 计划摘要:`NNN-<plan-summary>.md`
- 序号必须每次 +1
- 文档内使用任务清单,并在每个任务完成后立即打勾标记
修改位置:`AGENTS.md`
File diff suppressed because one or more lines are too long
@@ -0,0 +1 @@
在agent.md里规定,每次计划都必须写一个计划文档,md格式,按序号增加和以计划的总结命名,每次完成一个任务做好标记
@@ -0,0 +1,11 @@
已按你的要求更新完成。
我在 `AGENTS.md` 里新增了 `## PLAN DOCUMENT RULE` 章节,内容包括:
- 每次新实现计划都必须有独立 Markdown 计划文档
- 计划文档统一放在 `plans/` 目录
- 文件名采用递增序号 + 计划摘要:`NNN-<plan-summary>.md`
- 序号必须每次 +1
- 文档内使用任务清单,并在每个任务完成后立即打勾标记
修改位置:`AGENTS.md`
@@ -0,0 +1,71 @@
# Session Context
Session ID: ses_34dfda207ffeiBV2rCgJW708ip
Commit Message: 配置下发也没兼容,请全量检查一下,哪些功能需要一起改造
## Prompts
### Prompt 1
211 任务的没有完全完成1. 选择IP后诊断还会诊断默认IP
2. 选择隧道出口IP后,入口还是会链接默认IP,没有链接选择的IP
请分析后制定修复计划
### Prompt 2
配置下发也没兼容,请全量检查一下,哪些功能需要一起改造
## Summary
你提得很对,我按“配置下发全链路”重新过了一遍(只读分析)。结论是:**需要一起改造的不是一个点,而是“诊断链路 + 重部署链路 + 回归测试链路”**。
目前状态可以分成三类:
- **已兼容(创建/更新时下发)**
- 隧道创建/更新时,`connectIp` 已进入运行时下发选择逻辑(`selectTunnelDialHost`)。
- 本地/联邦 runtime apply 都会吃 `target.ConnectIP`(前提是 state 里有值)。
- 参考:`go-backend/internal/http/handler/mutations.go:2588`, `go-backend/internal/http/handler/mutations.go:2348`
- **未兼容(你反馈的核心问题)**
- 诊断链路未传 `connectIp`,导致总走默认IP。
- 参考:`go-backend/internal/http/handler/control_plane.go:75`, `go-backend/internal/http/handler/control_plane.go:1102`
- **半兼容(配置重建时丢字段)**
- 重部署时从 DB 重建 runtime state,**没把 `ConnectIP` 带回去**,所以 redeploy 后会回退默认IP。
- 参考:`go-backend/internal/http/handler/mutations.go:883`, `go-backend/internal/http/handler/mutations.go:897`
---
**需要一起改造的功能范围(建议一次性做完)**
- `诊断(非流式 + 流式)`
- 隧道诊断、转发诊断都要改(共用 `prepare*Diagnosis` + `appendChainHopDiagnosis`)。
- 流式 start 预览项也要改,否则 UI 一开始仍显示默认IP。
- 目标文件:`go-backend/internal/http/handler/control_plane.go`, `go-backend/internal/http/handler/diagnosis_stream.go`
- `配置下发(重部署路径)`
- 单条重部署、批量重部署都依赖 `reconstructTunnelState`,必须补 `ConnectIP` 回填。
- 目标文件:`go-backend/internal/http/handler/mutations.go`
- `联邦节点运行时下发一致性`
- 逻辑本身已支持 `ConnectIP`,但受上一步 state 丢字段影响;修复后自动恢复一致。
- 重点验证:remote middle hop `ApplyRole.Targets` 的 Host 选取。
- `回归测试`
- 新增诊断用例:选了 `connectIp` 后,`targetIp` 必须是选中值(tunnel/forward + stream start/item)。
- 新增重部署用例:redeploy 后仍使用 `connectIp`,不回退默认IP。
- 目标文件建议:`go-backend/tests/contract/diagnosis_contract_test.go`,补 handler 级或 contract 级 redeploy 用例。
---
**实施计划(修复包)**
1. 修 `diagnosis` 调用链:所有 `resolveChainProbeTarget` 调用传入 `workItem.toNode.ConnectIP`。
2. 修 `reconstructTunnelState`:出口节点和中继节点都回填 `ConnectIP`。
3. 补测试:覆盖“诊断用选中IP”“重部署不丢IP”“connectIp为空仍走默认”的三组场景。
4. 联调验证:创建/更新、诊断、单重部署、批量重部署、联邦节点场景各跑一遍。
---
我建议按这个范围做成一次完整修复(避免只修诊断后你再次遇到“重部署又回退”的问题)。
如果你同意,我下一步就按这个“全量改造范围”进入实施。
File diff suppressed because one or more lines are too long
@@ -0,0 +1,7 @@
211 任务的没有完全完成1. 选择IP后诊断还会诊断默认IP
2. 选择隧道出口IP后,入口还是会链接默认IP,没有链接选择的IP
请分析后制定修复计划
---
配置下发也没兼容,请全量检查一下,哪些功能需要一起改造
@@ -0,0 +1,52 @@
你提得很对,我按“配置下发全链路”重新过了一遍(只读分析)。结论是:**需要一起改造的不是一个点,而是“诊断链路 + 重部署链路 + 回归测试链路”**。
目前状态可以分成三类:
- **已兼容(创建/更新时下发)**
- 隧道创建/更新时,`connectIp` 已进入运行时下发选择逻辑(`selectTunnelDialHost`)。
- 本地/联邦 runtime apply 都会吃 `target.ConnectIP`(前提是 state 里有值)。
- 参考:`go-backend/internal/http/handler/mutations.go:2588`, `go-backend/internal/http/handler/mutations.go:2348`
- **未兼容(你反馈的核心问题)**
- 诊断链路未传 `connectIp`,导致总走默认IP。
- 参考:`go-backend/internal/http/handler/control_plane.go:75`, `go-backend/internal/http/handler/control_plane.go:1102`
- **半兼容(配置重建时丢字段)**
- 重部署时从 DB 重建 runtime state,**没把 `ConnectIP` 带回去**,所以 redeploy 后会回退默认IP。
- 参考:`go-backend/internal/http/handler/mutations.go:883`, `go-backend/internal/http/handler/mutations.go:897`
---
**需要一起改造的功能范围(建议一次性做完)**
- `诊断(非流式 + 流式)`
- 隧道诊断、转发诊断都要改(共用 `prepare*Diagnosis` + `appendChainHopDiagnosis`)。
- 流式 start 预览项也要改,否则 UI 一开始仍显示默认IP。
- 目标文件:`go-backend/internal/http/handler/control_plane.go`, `go-backend/internal/http/handler/diagnosis_stream.go`
- `配置下发(重部署路径)`
- 单条重部署、批量重部署都依赖 `reconstructTunnelState`,必须补 `ConnectIP` 回填。
- 目标文件:`go-backend/internal/http/handler/mutations.go`
- `联邦节点运行时下发一致性`
- 逻辑本身已支持 `ConnectIP`,但受上一步 state 丢字段影响;修复后自动恢复一致。
- 重点验证:remote middle hop `ApplyRole.Targets` 的 Host 选取。
- `回归测试`
- 新增诊断用例:选了 `connectIp` 后,`targetIp` 必须是选中值(tunnel/forward + stream start/item)。
- 新增重部署用例:redeploy 后仍使用 `connectIp`,不回退默认IP。
- 目标文件建议:`go-backend/tests/contract/diagnosis_contract_test.go`,补 handler 级或 contract 级 redeploy 用例。
---
**实施计划(修复包)**
1. 修 `diagnosis` 调用链:所有 `resolveChainProbeTarget` 调用传入 `workItem.toNode.ConnectIP`。
2. 修 `reconstructTunnelState`:出口节点和中继节点都回填 `ConnectIP`。
3. 补测试:覆盖“诊断用选中IP”“重部署不丢IP”“connectIp为空仍走默认”的三组场景。
4. 联调验证:创建/更新、诊断、单重部署、批量重部署、联邦节点场景各跑一遍。
---
我建议按这个范围做成一次完整修复(避免只修诊断后你再次遇到“重部署又回退”的问题)。
如果你同意,我下一步就按这个“全量改造范围”进入实施。
File diff suppressed because it is too large Load Diff
@@ -0,0 +1 @@
提交全部变更并且push,创建pr合并,发布新tag,alpha版本
@@ -0,0 +1,10 @@
已完成:
1. **提交**: `fix: apply custom IP binding to forward and tunnel chain services` (e383359)
2. **PR**: [#247](https://github.com/Sagit-chu/flvx/pull/247) - 已合并
3. **Tag**: `2.1.7-alpha7` 已创建并推送
新功能:
- 自定义 IP 绑定支持(节点、隧道、转发)
- 转发列表紧凑模式与隧道组折叠/排序
- 迁移测试增强
@@ -0,0 +1,40 @@
# Session Context
Session ID: ses_34e68d081ffeyr3uWQwm5venHp
Commit Message: 实施
## Prompts
### Prompt 1
211任务中,如果选择了指定的入口IP或者出口IP,在节点上应该只监听这个IP地址,而不再是[::],请检查
### Prompt 2
connectIp 同时用于“上游拨号目标 + 本节点监听绑定”
### Prompt 3
实施
## Summary
已实施完成,并且按你确认的语义实现为:`connectIp` 同时用于“上游拨号目标 + 本节点监听绑定”。
- 转发服务下发现在会优先使用 `forward_port.in_ip` 作为监听地址,不再固定用节点默认 `[::]`。
- 隧道服务下发现在会优先使用 `connectIp` 作为监听地址;为空时才回退到节点默认监听地址。
- IPv6 监听地址统一通过 `processServerAddress(...)` 处理,确保带方括号格式正确。
改动位置:
- `go-backend/internal/http/handler/control_plane.go:284`
- `go-backend/internal/http/handler/control_plane.go:1306`
- `go-backend/internal/http/handler/mutations.go:2646`
新增测试:
- `go-backend/internal/http/handler/control_plane_test.go:69`
- `go-backend/internal/http/handler/control_plane_test.go:86`
- `go-backend/internal/http/handler/dual_stack_test.go:33`
- `go-backend/internal/http/handler/dual_stack_test.go:49`
验证结果:
- 已运行 `go test ./internal/http/handler/...`,全部通过。
File diff suppressed because one or more lines are too long
@@ -0,0 +1,9 @@
211任务中,如果选择了指定的入口IP或者出口IP,在节点上应该只监听这个IP地址,而不再是[::],请检查
---
connectIp 同时用于“上游拨号目标 + 本节点监听绑定”
---
实施
@@ -0,0 +1,19 @@
已实施完成,并且按你确认的语义实现为:`connectIp` 同时用于“上游拨号目标 + 本节点监听绑定”。
- 转发服务下发现在会优先使用 `forward_port.in_ip` 作为监听地址,不再固定用节点默认 `[::]`。
- 隧道服务下发现在会优先使用 `connectIp` 作为监听地址;为空时才回退到节点默认监听地址。
- IPv6 监听地址统一通过 `processServerAddress(...)` 处理,确保带方括号格式正确。
改动位置:
- `go-backend/internal/http/handler/control_plane.go:284`
- `go-backend/internal/http/handler/control_plane.go:1306`
- `go-backend/internal/http/handler/mutations.go:2646`
新增测试:
- `go-backend/internal/http/handler/control_plane_test.go:69`
- `go-backend/internal/http/handler/control_plane_test.go:86`
- `go-backend/internal/http/handler/dual_stack_test.go:33`
- `go-backend/internal/http/handler/dual_stack_test.go:49`
验证结果:
- 已运行 `go test ./internal/http/handler/...`,全部通过。
File diff suppressed because it is too large Load Diff
@@ -0,0 +1 @@
提交全部变更并且push,创建pr合并,发布新tag,alpha版本
@@ -0,0 +1,5 @@
✅ 完成!
- 提交: `9cf9f4f` (feat: add comprehensive migration test for legacy columns)
- PR: [#245](https://github.com/Sagit-chu/flvx/pull/245) 已合并
- 新 tag: `2.1.7-alpha6` 已发布
@@ -0,0 +1,20 @@
# Session Context
Session ID: ses_34ebc12c1ffePWN7yC0z9iz5Lw
Commit Message: 合并pr,然后发布新tag,alpha版本
## Prompts
### Prompt 1
提交全部变更并且push
### Prompt 2
合并pr,然后发布新tag,alpha版本
## Summary
已完成:
- PR #244 已合并到 main
- 新 tag `2.1.7-alpha5` 已创建并推送
File diff suppressed because one or more lines are too long
@@ -0,0 +1,5 @@
提交全部变更并且push
---
合并pr,然后发布新tag,alpha版本
@@ -0,0 +1,3 @@
已完成:
- PR #244 已合并到 main
- 新 tag `2.1.7-alpha5` 已创建并推送
@@ -0,0 +1,44 @@
# Session Context
Session ID: ses_34ec18cadffeoVVSjfPXGJaxBu
Commit Message: 再做一轮“跨表全量列对比(model vs 旧库补列逻辑)
## Prompts
### Prompt 1
211任务全量再逐一确认一下是否全部完成,并且功能完成
### Prompt 2
添加额外ip的时候报错:SQL logic error: no such column: extra_ips (1)
### Prompt 3
全量排查一下还有没有类似的bug
### Prompt 4
再做一轮“跨表全量列对比(model vs 旧库补列逻辑)
## Summary
已完成这一轮“跨表全量列对比(model vs 旧库补列逻辑)”,并做了可执行验证。
我做了什么:
- 对比了 `model.Node` / `model.Tunnel` 字段与 `prepareSQLiteLegacyColumns` 的补列清单。
- 结论:
- `Node` 目前应补的历史增量列:`server_ip_v4`, `server_ip_v6`, `extra_ips`, `tcp_listen_addr`, `udp_listen_addr`, `inx`, `is_remote`, `remote_url`, `remote_token`, `remote_config`
- `Tunnel` 应补:`inx`, `ip_preference`
- 我已把这个对齐结果固化为回归测试,新增了一个“更老版本库”场景验证:
- 新测试:`TestOpenMigratesVeryLegacyNodeAndTunnelColumns`
- 文件:`go-backend/tests/contract/migration_contract_test.go`
- 该测试从极简旧表结构启动,验证上述所有列都会被自动补齐。
- 测试结果:通过
- `go test ./tests/contract -run "TestOpenMigratesLegacyNodeDualStackColumns|TestOpenMigratesVeryLegacyNodeAndTunnelColumns"`
最终结论(本轮排查范围内):
- **Node/Tunnel 这条旧库升级链路已对齐且有测试兜底**。
- 你这类 “no such column” 的同类风险,针对这两个核心表已经基本封住。
File diff suppressed because one or more lines are too long
@@ -0,0 +1,13 @@
211任务全量再逐一确认一下是否全部完成,并且功能完成
---
添加额外ip的时候报错:SQL logic error: no such column: extra_ips (1)
---
全量排查一下还有没有类似的bug
---
再做一轮“跨表全量列对比(model vs 旧库补列逻辑)
@@ -0,0 +1,19 @@
已完成这一轮“跨表全量列对比(model vs 旧库补列逻辑)”,并做了可执行验证。
我做了什么:
- 对比了 `model.Node` / `model.Tunnel` 字段与 `prepareSQLiteLegacyColumns` 的补列清单。
- 结论:
- `Node` 目前应补的历史增量列:`server_ip_v4`, `server_ip_v6`, `extra_ips`, `tcp_listen_addr`, `udp_listen_addr`, `inx`, `is_remote`, `remote_url`, `remote_token`, `remote_config`
- `Tunnel` 应补:`inx`, `ip_preference`
- 我已把这个对齐结果固化为回归测试,新增了一个“更老版本库”场景验证:
- 新测试:`TestOpenMigratesVeryLegacyNodeAndTunnelColumns`
- 文件:`go-backend/tests/contract/migration_contract_test.go`
- 该测试从极简旧表结构启动,验证上述所有列都会被自动补齐。
- 测试结果:通过
- `go test ./tests/contract -run "TestOpenMigratesLegacyNodeDualStackColumns|TestOpenMigratesVeryLegacyNodeAndTunnelColumns"`
最终结论(本轮排查范围内):
- **Node/Tunnel 这条旧库升级链路已对齐且有测试兜底**。
- 你这类 “no such column” 的同类风险,针对这两个核心表已经基本封住。
@@ -0,0 +1,14 @@
# Session Context
Session ID: ses_34eec2495ffeJvDq7SlEs8mRoH
Commit Message: 提交全部变更并且push,创建pr
## Prompts
### Prompt 1
提交全部变更并且push,创建pr
## Summary
已提交并推送,PR已创建: https://github.com/Sagit-chu/flvx/pull/new/opencode/mighty-nebula
File diff suppressed because one or more lines are too long
@@ -0,0 +1 @@
提交全部变更并且push,创建pr
@@ -0,0 +1 @@
已提交并推送,PR已创建: https://github.com/Sagit-chu/flvx/pull/new/opencode/mighty-nebula
@@ -0,0 +1,14 @@
# Session Context
Session ID: ses_34f0fe1d2ffeH3PJRyokYati7T
Commit Message: 把main更新到本分支
## Prompts
### Prompt 1
把main更新到本分支
## Summary
已完成 `origin/main` 合并到当前分支(Fast-forward)。之前的更改已恢复,`forward.tsx` 自动合并成功。
File diff suppressed because one or more lines are too long
@@ -0,0 +1 @@
把main更新到本分支
@@ -0,0 +1 @@
已完成 `origin/main` 合并到当前分支(Fast-forward)。之前的更改已恢复,`forward.tsx` 自动合并成功。
File diff suppressed because one or more lines are too long
@@ -0,0 +1,11 @@
探索节点API和数据访问层的完整实现:
1. 在 `go-backend/internal/store/repo/` 查找节点创建/更新的函数
2. 查找节点数据如何返回给前端(JSON序列化)
3. 查找 `nodeRecord` 结构体的定义和使用
4. 理解 ServerIP/ServerIPV4/ServerIPV6 字段如何被处理
返回:
- 节点CRUD相关的Repository方法
- 节点数据返回给前端的格式
- 扩展节点IP字段需要改动的位置
@@ -0,0 +1,215 @@
Based on my thorough exploration, here's a comprehensive analysis of the node API and data access layer:
---
## 节点API和数据访问层完整分析
### 1. 节点CRUD相关Repository方法
#### 核心方法 (`go-backend/internal/store/repo/`)
| 方法 | 文件位置 | 功能 |
|------|----------|------|
| `CreateNode()` | `repository_mutations.go:199` | 创建节点,处理 serverIP/serverIPV4/serverIPV6 |
| `UpdateNode()` | `repository_mutations.go:241` | 更新节点,包含所有IP字段 |
| `DeleteNodeCascade()` | `repository_mutations.go:299` | 级联删除节点(关联 ForwardPort、ChainTunnel、FederationTunnelBinding) |
| `GetNodeByID()` | `repository.go:555` | 通过ID获取节点 |
| `GetNodeBySecret()` | `repository.go:540` | 通过Secret获取节点 |
| `GetNodeStatusFields()` | `repository_mutations.go:229` | 获取节点状态字段 |
| `GetNodeSecret()` | `repository_mutations.go:263` | 获取节点密钥 |
| `GetNodeRemoteFields()` | `repository_mutations.go:317` | 获取远程节点字段 |
| `GetNodePortRange()` | `repository_mutations.go:336` | 获取节点端口范围 |
| `UpdateNodeOrder()` | `repository_mutations.go:287` | 更新节点排序 |
| `UpdateNodeOnline()` | `repository.go:570` | 更新节点在线状态 |
| `UpdateNodeStatus()` | `repository.go:580` | 更新节点状态 |
| `ListNodes()` | `repository.go:625` | 列出所有节点(返回JSON map格式) |
| `GetNodeRecord()` | `repository_control.go:131` | 获取 NodeRecord 视图对象 |
| `CreateRemoteNode()` | `repository_federation.go:266` | 创建远程节点(联邦场景) |
| `exportNodes()` | `repository.go:1660` | 导出节点数据(用于备份) |
| `importNodes()` | `repository.go:2016` | 导入节点数据(用于恢复) |
---
### 2. 节点数据结构定义
#### GORM模型 (`model.Node` - 数据库存储)
**文件:** `/go-backend/internal/store/model/model.go:59-82`
```go
type Node struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
Name string `gorm:"type:varchar(100);not null"`
Secret string `gorm:"type:varchar(100);not null"`
ServerIP string `gorm:"column:server_ip;type:varchar(100);not null"`
ServerIPV4 sql.NullString `gorm:"column:server_ip_v4;type:varchar(100)"` // 注意:V大写
ServerIPV6 sql.NullString `gorm:"column:server_ip_v6;type:varchar(100)"`
// ... 其他字段
}
```
#### 控制平面视图 (`model.NodeRecord`)
**文件:** `/go-backend/internal/store/model/model.go:515-531`
```go
type NodeRecord struct {
ID int64
Name string
ServerIP string
ServerIPv4 string // 注意:v小写
ServerIPv6 string
Status int
PortRange string
// ... 其他字段
}
```
#### JSON导出格式 (`model.NodeBackup`)
**文件:** `/go-backend/internal/store/model/model.go:333-356`
```go
type NodeBackup struct {
ID int64 `json:"id"`
Name string `json:"name"`
ServerIP string `json:"serverIp"`
ServerIPv4 string `json:"serverIpV4,omitempty"`
ServerIPv6 string `json:"serverIpV6,omitempty"`
// ... 其他字段
}
```
#### Handler层别名
**文件:** `/go-backend/internal/http/handler/control_plane.go:25`
```go
type nodeRecord = model.NodeRecord // 类型别名
```
---
### 3. 节点数据返回给前端的格式
#### ListNodes API (`repository.go:625-652`)
```go
// 返回 map[string]interface{} 格式
items = append(items, map[string]interface{}{
"id": n.ID, "inx": n.Inx, "name": n.Name,
"ip": n.ServerIP, "serverIp": n.ServerIP, // ip和serverIp都返回
"serverIpV4": nullableString(n.ServerIPV4),
"serverIpV6": nullableString(n.ServerIPV6),
"port": n.Port,
"tcpListenAddr": n.TCPListenAddr,
"udpListenAddr": n.UDPListenAddr,
"version": nullableString(n.Version),
"http": n.HTTP, "tls": n.TLS, "socks": n.Socks,
"status": n.Status, "isRemote": n.IsRemote,
// ...
})
```
#### API端点
| 端点 | Handler | 功能 |
|------|---------|------|
| `POST /api/v1/node/list` | `h.nodeList` | 列出节点 |
| `POST /api/v1/node/create` | `h.nodeCreate` | 创建节点 |
| `POST /api/v1/node/update` | `h.nodeUpdate` | 更新节点 |
| `POST /api/v1/node/delete` | `h.nodeDelete` | 删除节点 |
---
### 4. ServerIP/ServerIPV4/ServerIPV6 字段处理逻辑
#### 字段命名约定
| 层级 | 字段名 | 数据库列名 |
|------|--------|-----------|
| `model.Node` | `ServerIPV4`, `ServerIPV6` | `server_ip_v4`, `server_ip_v6` |
| `model.NodeRecord` | `ServerIPv4`, `ServerIPv6` | - (内存结构) |
| `model.NodeBackup` | `ServerIPv4`, `ServerIPv6` | - (JSON) |
| 前端JSON | `serverIpV4`, `serverIpV6` | - |
#### 模型转换函数 (`repository_control.go:161-201`)
```go
func nodeRecordFromModel(n *model.Node) *model.NodeRecord {
rec := &model.NodeRecord{
ID: n.ID,
Name: n.Name,
ServerIP: n.ServerIP,
// ...
}
if n.ServerIPV4.Valid {
rec.ServerIPv4 = strings.TrimSpace(n.ServerIPV4.String)
}
if n.ServerIPV6.Valid {
rec.ServerIPv6 = strings.TrimSpace(n.ServerIPV6.String)
}
// ...
}
```
#### Dual-Stack辅助函数 (`mutations.go:2715-2772`)
```go
// 判断节点是否支持IPv4
func nodeSupportsV4(node *nodeRecord) bool {
if strings.TrimSpace(node.ServerIPv4) != "" { return true }
if strings.TrimSpace(node.ServerIPv6) != "" { return false }
// 回退到 ServerIP 判断
legacy := strings.Trim(strings.TrimSpace(node.ServerIP), "[]")
if ip := net.ParseIP(legacy); ip != nil {
return ip.To4() != nil
}
return true
}
// 选择IPv4地址(优先显式字段,回退ServerIP)
func pickNodeAddressV4(node *nodeRecord) string {
if v := strings.TrimSpace(node.ServerIPv4); v != "" { return v }
return strings.TrimSpace(node.ServerIP)
}
```
---
### 5. 扩展节点IP字段需要改动的位置
如果要添加新的IP字段(如 `ServerIPV4Alt`),需要修改以下位置:
#### A. 模型层 (`go-backend/internal/store/model/model.go`)
1. **`model.Node`** - 添加 GORM 字段定义(约第64行)
2. **`model.NodeRecord`** - 添加视图字段(约第520行)
3. **`model.NodeBackup`** - 添加JSON字段(约第338行)
#### B. Repository层 (`go-backend/internal/store/repo/`)
1. **`repository_mutations.go`**
- `CreateNode()` 参数和赋值(约第199-227行)
- `UpdateNode()` 参数和Updates map(约第241-261行)
2. **`repository_control.go`**
- `nodeRecordFromModel()` 转换逻辑(约第161-201行)
3. **`repository_federation.go`**
- `CreateRemoteNode()` 参数和赋值(约第266-294行)
4. **`repository.go`**
- `ListNodes()` JSON返回格式(约第625-652行)
- `exportNodes()` 导出逻辑(约第1660-1700行)
- `importNodes()` 导入逻辑(约第2016-2057行)
- `prepareSQLiteLegacyColumns()` 迁移逻辑(约第263行)
#### C. Handler层 (`go-backend/internal/http/handler/`)
1. **`mutations.go`**
- `nodeCreate()` 请求参数解析(约第234-279行)
- `nodeUpdate()` 请求参数解析(约第281-336行)
- `nodeSupportsV4/V6()` 函数逻辑(约第2715-2772行)
- `pickNodeAddressV4/V6()` 函数逻辑
#### D. 测试层 (`go-backend/tests/contract/`)
所有 contract test 中的 `INSERT INTO node` 语句需要更新字段列表
---
### 关键文件汇总
| 文件 | 用途 |
|------|------|
| `/go-backend/internal/store/model/model.go` | 数据模型定义 |
| `/go-backend/internal/store/repo/repository_mutations.go` | CRUD操作实现 |
| `/go-backend/internal/store/repo/repository_control.go` | 控制平面查询+模型转换 |
| `/go-backend/internal/store/repo/repository_federation.go` | 联邦节点操作 |
| `/go-backend/internal/store/repo/repository.go` | 核心查询+导出导入 |
| `/go-backend/internal/http/handler/mutations.go` | HTTP API处理器 |
| `/go-backend/internal/http/handler/control_plane.go` | 控制平面API |
File diff suppressed because one or more lines are too long
@@ -0,0 +1,11 @@
探索隧道链路构建时下一跳连接地址的选择流程:
1. 在 `control_plane.go` 中查找隧道链路构建逻辑
2. 查找 `applyTunnelRuntime` 或类似函数如何向节点发送命令
3. 理解 hop 节点如何连接到下一个节点(连接地址从哪里来)
4. 查找 `ChainTunnel` 表的 `Port` 字段如何被使用
返回:
- 隧道链路配置发送到节点的代码位置
- 下一跳连接地址是如何确定的
- 修改连接地址需要改动的关键位置
@@ -0,0 +1,173 @@
根据我的分析,以下是隧道链路构建时下一跳连接地址选择流程的完整报告:
---
## 隧道链路构建流程分析报告
### 1. 隧道链路配置发送到节点的代码位置
**主函数**: `applyTunnelRuntime()`
- 文件: `go-backend/internal/http/handler/mutations.go`
- 行号: 2454-2521
**核心流程**:
```
applyTunnelRuntime (L2454)
├── 入口节点: 发送 AddChains 命令 (L2474)
├── 跳转节点: 发送 AddChains (L2496) + AddService (L2502) 命令
└── 出口节点: 发送 AddService 命令 (L2514)
```
**配置构建函数**:
| 函数 | 位置 | 作用 |
|------|------|------|
| `buildTunnelChainConfig()` | L2567-2624 | 构建转发链配置 |
| `buildTunnelChainServiceConfig()` | L2626-2652 | 构建服务配置 |
| `selectTunnelDialHost()` | L2654-2699 | **选择下一跳连接地址** |
---
### 2. 下一跳连接地址是如何确定的
**地址选择核心函数**: `selectTunnelDialHost()` (L2654-2699)
```go
// 关键逻辑 (简化版)
func selectTunnelDialHost(fromNode, toNode *nodeRecord, ipPreference string) (string, error) {
// 1. 检测源节点和目标节点的 IPv4/IPv6 支持
fromV4 := nodeSupportsV4(fromNode)
fromV6 := nodeSupportsV6(fromNode)
toV4 := nodeSupportsV4(toNode)
toV6 := nodeSupportsV6(toNode)
// 2. 根据偏好选择地址
switch ipPreference {
case "v6": // 优先 IPv6
if fromV6 && toV6 { return pickNodeAddressV6(toNode) }
if fromV4 && toV4 { return pickNodeAddressV4(toNode) }
case "v4": // 优先 IPv4
if fromV4 && toV4 { return pickNodeAddressV4(toNode) }
if fromV6 && toV6 { return pickNodeAddressV6(toNode) }
default: // 默认优先 IPv4
if fromV4 && toV4 { return pickNodeAddressV4(toNode) }
if fromV6 && toV6 { return pickNodeAddressV6(toNode) }
}
// 3. 不兼容时报错
return "", fmt.Errorf("节点链路不兼容")
}
```
**地址选择优先级** (在 `pickNodeAddressV4/V6` 中, L2755-2773):
- **IPv4**: `ServerIPv4` > `ServerIP` (旧字段)
- **IPv6**: `ServerIPv6` > `ServerIP` (旧字段)
**端口来源** (在 `buildTunnelChainConfig` 中, L2585-2588):
```go
port := target.Port // 来自 ChainTunnel.Port 字段
if port <= 0 {
return nil, errors.New("节点端口不能为空")
}
```
---
### 3. ChainTunnel.Port 字段的使用流程
**数据模型** (`model.go` L127-138):
```go
type ChainTunnel struct {
ID int64
TunnelID int64
ChainType string // "1"=入口, "2"=跳转, "3"=出口
NodeID int64
Port sql.NullInt64 // ★ 连接端口
Strategy sql.NullString
Inx sql.NullInt64 // 跳转序号
Protocol sql.NullString
}
```
**Port 字段流转**:
```
创建隧道时
│
▼
prepareTunnelCreateState (L1970)
├── 出口节点: 从请求读取 port,若为空则调用 PickNodePortTx 自动分配
├── 跳转节点: 从请求读取 port,若为空则调用 PickNodePortTx 自动分配
│
▼
replaceTunnelChainsTx (L2775)
└── CreateChainTunnelTx 写入数据库 (L2809, L2837)
│
▼
读取/重建状态时
│
▼
ListChainNodesForTunnel (repository_control.go L280)
└── 从 chain_tunnel 表读取 Port 字段 (L295)
│
▼
reconstructTunnelState (L845)
└── 将 Port 复制到 tunnelRuntimeNode.Port (L887, L901)
│
▼
buildTunnelChainConfig (L2567)
└── 使用 target.Port 构建连接地址 (L2585)
```
---
### 4. 修改连接地址需要改动的关键位置
如果要修改下一跳连接地址的选择逻辑,需要关注以下位置:
| 修改目标 | 文件 | 行号 | 函数 |
|---------|------|------|------|
| **IP地址选择策略** | `mutations.go` | L2654-2699 | `selectTunnelDialHost()` |
| **IPv4地址提取** | `mutations.go` | L2755-2763 | `pickNodeAddressV4()` |
| **IPv6地址提取** | `mutations.go` | L2765-2773 | `pickNodeAddressV6()` |
| **端口获取** | `mutations.go` | L2585-2588 | `buildTunnelChainConfig()` |
| **端口分配逻辑** | `repository_mutations.go` | ~L459 | `PickNodePortTx()` |
| **端口写入数据库** | `repository_mutations.go` | L398-406 | `CreateChainTunnelTx()` |
| **端口从数据库读取** | `repository_control.go` | L280-343 | `ListChainNodesForTunnel()` |
**关键配置结构**:
```go
// mutations.go L1950-1957
type tunnelRuntimeNode struct {
NodeID int64
Protocol string // 连接协议
Strategy string // 选择策略
Inx int // 跳转序号
ChainType int // 1=入口, 2=跳转, 3=出口
Port int // ★ 连接端口
}
```
---
### 5. 调用链总结
```
用户创建隧道请求
│
▼
tunnelAdd (mutations.go L450)
│
├── prepareTunnelCreateState() ──► 分配端口,构建 state
│
├── replaceTunnelChainsTx() ──► 写入 chain_tunnel 表
│
└── applyTunnelRuntime()
│
├── buildTunnelChainConfig()
│ │
│ ├── selectTunnelDialHost() ──► 选择 IP 地址
│ │
│ └── 使用 target.Port ──► 端口
│
└── sendNodeCommand("AddChains/AddService") ──► 发送到节点
```
File diff suppressed because one or more lines are too long
@@ -0,0 +1,11 @@
探索转发创建时入口IP的生成流程:
1. 查找 `buildTunnelInIP` 函数的完整实现
2. 查找 `resolveForwardIngress` 函数的完整实现
3. 理解 `forward_port` 表如何与节点IP关联
4. 查找转发创建API(createForward)如何处理入口端口分配
返回:
- 关键代码片段和行号
- 入口IP是如何从节点信息中提取的
- 修改入口IP需要改动的关键位置
@@ -0,0 +1,185 @@
现在我已经找到了完整的入口IP生成流程。让我整理并返回关键信息:
---
## 入口IP生成流程分析
### 1. `buildTunnelInIP` 函数 (创建/更新隧道时)
**位置**: `go-backend/internal/http/handler/mutations.go:2112-2152`
```go
func buildTunnelInIP(inNodes []tunnelRuntimeNode, nodes map[int64]*nodeRecord, ipPreference string) string {
set := make(map[string]struct{})
ordered := make([]string, 0)
preferV6 := strings.TrimSpace(ipPreference) == "v6"
for _, inNode := range inNodes {
node := nodes[inNode.NodeID]
if node == nil {
continue
}
v4 := strings.TrimSpace(node.ServerIPv4) // 从节点获取 IPv4
v6 := strings.TrimSpace(node.ServerIPv6) // 从节点获取 IPv6
var addrs []string
if preferV6 {
if v6 != "" { addrs = append(addrs, v6) }
if v4 != "" { addrs = append(addrs, v4) }
} else {
if v4 != "" { addrs = append(addrs, v4) }
if v6 != "" { addrs = append(addrs, v6) }
}
if len(addrs) == 0 {
if v := strings.TrimSpace(node.ServerIP); v != "" { // fallback 到 ServerIP
addrs = append(addrs, v)
}
}
// ... 去重后拼接
}
return strings.Join(ordered, ",")
}
```
**调用位置**:
- 隧道创建: `mutations.go:496`
- 隧道更新: `mutations.go:693`
---
### 2. `resolveForwardIngress` 函数 (查询转发时)
**位置**: `go-backend/internal/store/repo/repository.go:2727-2796`
```go
func resolveForwardIngress(db *gorm.DB, forwardID int64, tunnelID int64) (string, sql.NullInt64, error) {
// 1. 首先从 tunnel 表获取 in_ip (由 buildTunnelInIP 生成)
var tunnelInIP sql.NullString
db.Model(&model.Tunnel{}).Select("in_ip").Where("id = ?", tunnelID).Limit(1).Scan(&tunnelInIP)
// 2. 从 forward_port + node 表获取端口和节点IP
type fpRow struct {
Port sql.NullInt64
ServerIP sql.NullString
}
var fpRows []fpRow
err := db.Model(&model.ForwardPort{}).
Select("forward_port.port, node.server_ip").
Joins("LEFT JOIN node ON node.id = forward_port.node_id").
Where("forward_port.forward_id = ?", forwardID).
Order("forward_port.id ASC").
Find(&fpRows).Error
// 3. 组装入口地址
// - 如果 tunnel.in_ip 存在: "ip1:port,ip2:port..."
// - 否则使用 forward_port 关联的 node.server_ip: "ip:port"
// ...
}
```
**调用位置**:
- `repository.go:495` - 用户转发列表
- `repository.go:730` - 管理员转发列表
---
### 3. `forward_port` 表与节点IP关联
**模型定义**: `go-backend/internal/store/model/model.go:50-57`
```go
type ForwardPort struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
ForwardID int64 `gorm:"column:forward_id;not null"`
NodeID int64 `gorm:"column:node_id;not null"` // 关联到 node.id
Port int `gorm:"not null"`
}
```
**关联查询** (在 `resolveForwardIngress` 中):
```sql
SELECT forward_port.port, node.server_ip
FROM forward_port
LEFT JOIN node ON node.id = forward_port.node_id
WHERE forward_port.forward_id = ?
ORDER BY forward_port.id ASC
```
---
### 4. 转发创建API入口分配流程
**入口函数**: `go-backend/internal/http/handler/mutations.go:1108-1194`
```go
func (h *Handler) forwardCreate(w http.ResponseWriter, r *http.Request) {
// 1. 获取隧道入口节点IDs
entryNodes, _ := h.tunnelEntryNodeIDs(tunnelID) // line 1162
// 2. 获取或选择入口端口
port := asInt(req["inPort"], 0)
if port <= 0 {
port = h.pickTunnelPort(tunnelID) // 自动分配端口 (line 1157)
}
// 3. 创建转发记录 + forward_port 记录
forwardID, err := h.repo.CreateForwardTx(..., entryNodes, port, ...) // line 1179
}
```
**`CreateForwardTx`**: `go-backend/internal/store/repo/repository_mutations.go:1171-1209`
```go
func (r *Repository) CreateForwardTx(..., entryNodeIDs []int64, port int, ...) (int64, error) {
// 创建 forward 记录
// 为每个入口节点创建 forward_port 记录
for _, nodeID := range entryNodeIDs {
fp := model.ForwardPort{
ForwardID: forwardID,
NodeID: nodeID, // 入口节点ID
Port: port, // 入口端口
}
tx.Create(&fp)
}
}
```
**入口节点获取**: `repository_mutations.go:535-548`
```go
func (r *Repository) TunnelEntryNodeIDs(tunnelID int64) ([]int64, error) {
// 从 chain_tunnel 表查询 chain_type = 1 (入口) 的节点
r.db.Model(&model.ChainTunnel{}).
Where("tunnel_id = ? AND chain_type = ?", tunnelID, "1").
Order("inx ASC, id ASC").
Pluck("node_id", &ids)
}
```
---
## 关键修改位置
| 需求 | 修改文件 | 行号 | 说明 |
|------|----------|------|------|
| **修改隧道入口IP生成逻辑** | `mutations.go` | 2112-2152 | `buildTunnelInIP` 函数,控制IPv4/IPv6优先级和组合 |
| **修改转发入口IP解析** | `repository.go` | 2727-2796 | `resolveForwardIngress`,控制入口地址格式 |
| **修改端口自动分配** | `mutations.go` | 2901-2964 | `pickTunnelPort`,控制端口范围选择 |
| **修改入口节点关联** | `repository_mutations.go` | 1196-1205 | `CreateForwardTx` 中的 forward_port 创建 |
| **节点IP来源** | `model.go` | 516-531 | `NodeRecord` 结构体 |
| **节点IP存储** | `model.go` | 59-65 | `Node` 模型: `ServerIP`, `ServerIPV4`, `ServerIPV6` |
---
## 入口IP数据流
```
1. 节点注册 → Node表存储 server_ip, server_ip_v4, server_ip_v6
2. 创建隧道:
chain_tunnel (入口节点) → buildTunnelInIP() → tunnel.in_ip 字段
3. 创建转发:
隧道入口节点IDs → forward_port(forward_id, node_id, port)
4. 查询转发入口:
forward_port JOIN node → resolveForwardIngress()
├─ 优先使用 tunnel.in_ip (多IP组合)
└─ 否则用 forward_port 关联的 node.server_ip
```
File diff suppressed because one or more lines are too long
@@ -0,0 +1,16 @@
Explore the codebase to understand how forwarding/tunnel configuration works. I need to find:
1. Frontend: The forwarding edit/create dialog component (likely in vite-frontend/src/)
2. Backend: The forwarding data model and API handlers (likely in go-backend/)
3. How the current "入口端口" (entry port) is handled
Look for:
- Files related to "forward" or "转发" or "tunnel" or "隧道"
- Data models for forwarding rules
- API handlers for creating/editing forwards
Return:
- Key file paths and their purposes
- Current data model structure for forwards
- How the entry listener is currently configured
- Any existing IP-related fields in the model
@@ -0,0 +1,316 @@
// List in frontend display isPort.)?
if (in_ip !== in.re.selected) {
tunnel ip !== node in_tunnel.port_range value
select(v4 or IPv6, and
.chainType = chainType === 1 ( then chain_node !== node to check if `in_ip` is still used:
"chain_node_id" for `chainTunnels.node_id = nodeId, && `chainType != "hop" fields
//
}
}
}
<Select
<div className="flex flex-col gap-4 mt-6">
<Select
isFilterModalOpen={false}
setFilterUserId, filterTunnelId(tunnelId)}
}}
<form.in_port}
:form.in_port !== null,
}}
} else {
setFilterTunnelId}
}
}}
// handleEntryNodeIDs
hop - entry port assignment
const { entryNodeID, entryPort, entry_ip, resolvedFor forwardIn_ip based on
forward data view:
In entity links the node,entry, remote_addr and`]
tdCompose groups
remote nodes by hostname.
`target_addr` is multiple ones, the `targetAddr`/ `name` || `strategy: data in the form, uses the latest text.
`line text: `grid gap-3 group` leading to border. from UI styles
`.sort order`actions`: data
? `no-frontend for/not directly modify forward model
so it doesn't have `inPort` in model.For forward creation.```
const forwardPort = entryNodeIDs with port = 0
are - but tunnels and tunnels have
after:. Based on.
to reach the entry from. specified port-based" entry_ip, `addr_text` field or tunnel IP-based tunnel values with data not used this rules
step pattern is`node-based:`peer` or a`IP_preference` + `ip_preference` header.
"IP_preference from}
`grep<include="*.tsx"" path="/Users/sagit/.local/share/opencode/worktree/13650be91caa3a9e08a2e63127fef62757658384/mighty-nebula/vite-frontend/src/pages/forward.tsx" />
"peer_share" and "federation" share" APIs.
data models
/>
< Frontend> `in_ip` comes from the tunnel, and not the node model.In Go-gost.
. I will specifically look at `port` and `forward_port` data stored in `forward_port` table (` // When editing, forward, the UI keeps the current port value in the `inPort` state is checked for duplicates (`
forwards list ( addresses with multiple addresses.
</div
}
</div>
}
}
}
}
className="flex flex-col gap-4">
{/* form fields - in edit mode */}
</4-form.inPort in field and handleClick save
validation and numbers? `handleEdit` adds the `inPort` to the and `inPort` state.
// handleDragEnd ref={handleDragEnd} to scroll into view}
if (prev.forwardPorts.length === 0) {
// Create new forward
entry with not auto expanded
const inPort records = || const{index` === 0` ? record and `forward_ports` table
const inPort = records = or can be rendered when the to pickTunnelPort: the empty { inPort = null ?} => to persistent if port === 0 ( automatic assignment).
} else {
toast.error("请选择关联隧道")
}
const minPort =
const ports = oldPorts.map((p) => p)) // values from request
// value === 0 means "端口不能为空, else if (!port) {
const inPort = tunnelPorts.map((t) => {
const inIP = tunnel = in_ip
|| t.IP === the default) 'auto' (available, tunnel.ip_preference` || `:` if` in_ip` and `in_port` values ( listenAddr] which`tcp`/udp` addresses are the respectively
`forward` now supports select/un/selected tunnel. when not found ( a single ` address can be shown, and simplified overview.= `tunnel` but has `in_ip` display name="人口入口IP` and "端口转发" when tunnel is port-forward, the model oftrafficRatio` floats with `type` and `protocol` fields.
// `protocol`: 'tls' | 'wss' | 'mtls' | 'mtcp'
for `type` === 1: 繀 端口转发, 2: 隧道转发, and `type` determines the listeners on which forward ( protocol, and exit node ( configuration. Let `traffic_ratio` be on in/out, and the name` tunnelName, in the `UserTunnel` table
var chainType = chainType === "entry" ? # chainType === 2, value for represents entry node id for chain_type === "hop", fields indicate which hop number (1-based, `strategy` on the current value)
? newErrors.inPort = "端口必须在1-65535之间";
form.inPort = optional
required validation in if filled, values to 0 or null, then the port is is auto-assigned
} ValidateForm()
if (validateForm()) {
setErrors(newErrors);
}
}
};
const handleTunnelChange = (tunnelId: string) => {
setForm((prev) => ({ ...prev, tunnelId}));
: if (prev.inPort !== null && prev.inPort !== old, in port assignment will not assign the new port auto
});
}
);
} else {
inPort = null
: options.speedId = speedLimit }
onChange={(selectedKey) => {
setFilter((prev) => ({ ...prev, speedId, speedName }));
}
});
});
setBatchChangeTunnelModalOpen(false);
setBatchChangeTunnelModalOpen(false);
}
</div>
</div>
);
<input
inport}
*/
.tsx
<Input
description="指定入口端口,留空则从节点可用端口中自动分配"
placeholder="留空则自动分配可用端口"
type="number"
variant="bordered"
onChange={(e) => {
const value = e.target.value ? ""
: parseInt(value) || null)
setForm((prev) => ({ ...prev, inPort: null}));
</div>
</div>
<ModalContent>
<ModalHeader className="flex flex-col gap-1">
<h2 className="text-xl font-bold">
{isEdit ? "编辑转发" : "新增转发"}
</h2>
<p className="text-small text-default-500 mt-4">
{isEdit ? "修改现有转发配置的信息" : "创建新的转发配置"}
</p>
<ModalBody>
<div className="space-y-4 pb-4">
<Input
errorMessage={errors.name}
isInvalid={!!errors.name}
label="转发名称"
placeholder="请输入转发名称"
value={form.name}
variant="bordered"
onChange={(e) =>
setForm((prev) => ({ ...prev, name: e.target.value }))
}
/>
{/* Limit速规则选择 */}
<Select
description="限速规则"
placeholder="不限速"
selectedKeys={
selectedSpeedId !== null ? ?[selectedSpeedId.toString()] : []
}
variant="bordered"
onSelectionChange={(keys) => {
const selectedKey = Array.from(keys)[0] as string | undefined;
setForm((prev) => ({
...prev,
speedId: selectedKey ? Number(selectedKey) : null,
});
}}
/>
{/*隧道选择 */}
<Select
description={
isEdit
? "更改隧道将释放原端口并在新隧道分配端口"
: "更改隧道后重新分配端口并同步到节点"
}
}
errorMessage={errors.tunnelId}
isInvalid={!!errors.tunnelId}
label="选择隧道"
placeholder="请选择关联的隧道"
selectedKeys={
form.tunnelId ? [form.tunnelId.toString()] : []
}
variant="bordered"
onSelectionChange={(keys) => {
const selectedKey = Array.from(keys)[0] as string;
if (selectedKey) {
handleTunnelChange(selectedKey);
}
}
/>
{/*入口端口 */}
<Input
description="指定入口端口,留空则从节点可用端口中自动分配"
errorMessage={errors.inPort}
isInvalid={!!errors.inPort}
label="入口端口"
placeholder="留空则自动分配可用端口"
type="number"
value={form.inPort !== null ? form.inPort.toString() : ""}
variant="bordered"
onChange={(e) => {
const value = e.target.value;
setForm((prev) => ({ ...prev, inPort: value ? parseInt(value) : null }));
}
/>
</div>
</ModalBody>
</ModalContent>
</Modal>
</Modal>
);
};
// ===================== Summary of findings ===================
## Key File Paths and their purposes:
### Frontend: Forward Edit/create dialog component
- **Main file:** `/Users/sagit/.local/share/opencode/worktree/13650be91caa3a9e08a2e63127fef62757658384/mighty-nebula/vite-frontend/src/pages/forward.tsx`
- Displays the forwarding list and handles all create/edit/delete/forwards
- Has `inIp` and `inPort` fields
- Shows entry port and dialog/form with validation
- Uses React-hook-form with state management
- Calls `createForward`, `updateForward`, `deleteForward`, `pauseForwardService`, `resumeForwardService`, APIs
- Imports API functions from `@/api`
### Backend: Forwarding data model and API handlers
- **Main model file:** `/Users/sagit/.local/share/opencode/worktree/13650be91caa3a9e08a2e63127fef62757658384/mighty-nebula/go-backend/internal/store/model/model.go`
- GORM model definition for `Forward` struct does basic forwarding configuration
- Related models: `ForwardPort`, `Tunnel`, `UserForwardDetail` (view struct)
- **API handlers:** `/Users/sagit/.local/share/opencode/worktree/13650be91caa3a9e08a2e63127fef62757658384/mighty-nebula/go-backend/internal/http/handler/mutations.go`
- Create/update/delete operations
- Entry port handling via `inPort` field
- **Repository layer:** `/Users/sagit/.local/share/opencode/worktree/13650be91caa3a9e08a2e63127fef62757658384/mighty-nebula/go-backend/internal/store/repo/repository_mutations.go`
- CRUD operations for - `resolveForwardIngress` function in `/Users/sagit/.local/share/opencode/worktree/13650be91caa3a9e08a2e63127fef62757658384/mighty-nebula/go-backend/internal/store/repo/repository.go`
- Computes `inIp` and `inPort` from joins
### Current data model structure for forwards
From `go-backend/internal/store/model/model.go`:
```go
// Forward maps to the "forward" table.
type Forward struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
UserID int64 `gorm:"column:user_id;not null"`
UserName string `gorm:"column:user_name;type:varchar(100);not null"`
Name string `gorm:"type:varchar(100);not null"`
TunnelID int64 `gorm:"column:tunnel_id;not null"`
RemoteAddr string `gorm:"column:remote_addr;type:text;not null"`
Strategy string `gorm:"type:varchar(100);not null;default:'fifo'"`
InFlow int64 `gorm:"not null;default:0"`
OutFlow int64 `gorm:"column:out_flow;not null;default:0"`
CreatedTime int64 `gorm:"column:created_time;not null"`
UpdatedTime int64 `gorm:"column:updated_time;not null"`
Status int `gorm:"not null"`
Inx int `gorm:"not null;default:0"`
SpeedID sql.NullInt64 `gorm:"column:speed_id"`
}
```
```go
// ForwardPort maps to the "forward_port" table - stores port assignments per entry node
type ForwardPort struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
ForwardID int64 `gorm:"column:forward_id;not null"`
NodeID int64 `gorm:"column:node_id;not null"`
Port int `gorm:"not null"`
}
```
```go
// Tunnel maps to the "tunnel" table - has entry IP configuration
type Tunnel struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
Name string `gorm:"type:varchar(100);not null"`
TrafficRatio float64 `gorm:"column:traffic_ratio;not null;default:1.0"`
Type int `gorm:"not null"`
Protocol string `gorm:"type:varchar(10);not null;default:'tls'"`
Flow int64 `gorm:"not null"`
CreatedTime int64 `gorm:"column:created_time;not null"`
UpdatedTime int64 `gorm:"column:updated_time;not null"`
Status int `gorm:"not null"`
InIP sql.NullString `gorm:"column:in_ip;type:text"` // Optional entry IP hint
Inx int `gorm:"not null;default:0"`
IPPreference string `gorm:"column:ip_preference;type:varchar(10);not null;default:''"`
}
```
### How entry listener is currently configured:
1. **Port Storage**: `ForwardPort` table stores the mapping from `forward_id` -> `node_id` -> `port`
- Port is assigned by the handler or passed via `inPort` parameter ( or auto-picked)
- Entry nodes are determined by `tunnelEntryNodeIDs()` in handler
3. **Entry IP Resolution**: The `resolveForwardIngress()` function resolves `inIp` and `inPort` by:
- Joining `forward_port` with `node` table
- `inIp` comes from `tunnel.in_ip` if set (takes precedence over node.server_ip)
- For multi-entry-node forwards, comma-separated IPs and ports are returned
4. **Current IP-related fields**:
- `Forward` model: No `inIp` field (port is stored in `forward_port` table)
- `Tunnel` model: Has `InIP` field (nullable, - allows specifying of a preferred entry IP hint
- `UserForwardDetail` view struct ( joins tunnel table and includes `InIP` and `InPort`
5. **No explicit entry IP selection UI in current dialog** - The port field is a text input, and form validates range but but UI doesn't allow setting specific IP addresses
File diff suppressed because one or more lines are too long
@@ -0,0 +1,10 @@
总结一下这个issue,结合当前代码,尽量设计简约实现issue的目标
https://github.com/Sagit-chu/flvx/issues/211
---
应该在节点上的高级里面允许添加多个IP
---
继续,允许在节点管理里填写多个地址,然后在组成隧道或者转发的时候选择节点的时候允许选择具体的ip,请开始设计,允许使用并行subagent
@@ -0,0 +1,76 @@
明白了!更新设计:
---
## 最终设计方案
### 核心需求
| 场景 | 配置位置 | 选择内容 |
|------|----------|----------|
| 转发 | 转发创建/编辑 | 入口监听IP(从入口节点IP列表选择) |
| 隧道 | 隧道配置 | 出口节点连接IP(从出口节点IP列表选择) |
---
### 数据模型变更(3处)
```
Node.ExtraIPs sql.NullString `gorm:"column:extra_ips;type:text"` // 逗号分隔
ForwardPort.InIP sql.NullString `gorm:"column:in_ip;type:text"` // 指定监听IP
ChainTunnel.ConnectIP sql.NullString `gorm:"column:connect_ip;type:text"` // 出口连接IP
```
---
### 改动清单
#### 后端 (约200行)
| 文件 | 改动 |
|------|------|
| `model/model.go` | Node/ForwardPort/ChainTunnel 增加3个字段 |
| `repository_mutations.go` | CreateNode/UpdateNode 处理 extraIPs 参数 |
| `repository_control.go` | GetNodeRecord/ListNodeAllIPs 辅助函数 |
| `repository.go` | resolveForwardIngress 使用 forward_port.in_ip |
| `handler/mutations.go` | selectTunnelDialHost 优先使用 connectIP |
#### 前端 (约150行)
| 页面 | 改动 |
|------|------|
| 节点编辑 | 高级配置增加"额外IP" Input(逗号分隔) |
| 转发编辑 | 入口端口旁增加"监听IP" Select(从入口节点IP选择) |
| 隧道配置 | 出口节点行增加"连接IP" Select(从出口节点IP选择) |
---
### UI 示意
**节点编辑 - 高级配置**
```
额外IP地址
┌──────────────────────────────────────────┐
│ 192.168.1.100, 10.0.0.5 │
└──────────────────────────────────────────┘
用于多IP服务器,逗号分隔
```
**转发创建**
```
入口端口: [ 8080 ] 监听IP: [ 192.168.1.100 ▼ ]
├─ 203.0.113.10 (默认)
├─ 192.168.1.100
└─ 10.0.0.5
```
**隧道配置 - 出口节点**
```
出口节点: [ node-1 ▼ ] 端口: [ 8443 ] 连接IP: [ 10.0.0.5 ▼ ]
├─ 203.0.113.10 (默认)
└─ 10.0.0.5
```
---
这个方案简约清晰,是否可以开始实现?
+4
View File
@@ -0,0 +1,4 @@
{
"enabled": true,
"telemetry": false
}
+48
View File
@@ -0,0 +1,48 @@
name: Publish Skill to npm
on:
push:
tags:
- 'v*'
workflow_dispatch:
jobs:
publish:
runs-on: ubuntu-latest
permissions:
contents: write
id-token: write
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Setup Node.js
uses: actions/setup-node@v4
with:
node-version: '20'
registry-url: 'https://registry.npmjs.org'
- name: Get version from tag
id: version
run: |
if [ "${{ github.event_name }}" = "workflow_dispatch" ]; then
VERSION=$(node -p "require('./skills/flvx-api/package.json').version")
else
VERSION="${GITHUB_REF#refs/tags/v}"
fi
echo "version=$VERSION" >> $GITHUB_OUTPUT
echo "Publishing skill version: $VERSION"
- name: Publish to npm
working-directory: skills/flvx-api
run: npm publish --provenance --access public
env:
NODE_AUTH_TOKEN: ${{ secrets.NPM_TOKEN }}
- name: Create GitHub Release
if: github.event_name == 'push'
uses: softprops/action-gh-release@v1
with:
name: Skill v${{ steps.version.outputs.version }}
generate_release_notes: true
files: skills/flvx-api/package.json
+33
View File
@@ -0,0 +1,33 @@
# Issue #211: 转发自定义监听IP / 隧道指定连接IP
## 需求总结
1. **节点**: 高级配置增加"额外IP地址"字段(逗号分隔)
2. **转发**: 创建/编辑时可指定入口监听IP
3. **隧道**: 配置出口节点时可指定连接IP
---
## 任务清单
### 后端
- [x] 1. 数据模型扩展 - Node/ForwardPort/ChainTunnel 增加字段
- [x] 2. Repository - CreateNode/UpdateNode 处理 extraIPs
- [x] 3. Repository - resolveForwardIngress 使用 forward_port.in_ip
- [x] 4. Repository - GetNodeAllIPs 辅助函数(返回节点所有可用IP)
- [x] 5. Handler - 转发创建/更新处理 inIp 参数
- [x] 6. Handler - 隧道出口节点处理 connectIp 参数
- [x] 7. Handler - 节点API返回 extraIPs 字段
### 前端
- [x] 8. 节点编辑页 - 高级配置增加"额外IP"输入
- [x] 9. 转发编辑弹窗 - 增加"监听IP"下拉选择
- [x] 10. 隧道配置页 - 出口节点增加"连接IP"输入
---
## 完成进度
- 开始时间: 2026-03-02
- 完成时间: 2026-03-02
- 完成任务: 10/10
- 后端完成: ✅
- 前端完成: ✅
+8 -1
View File
@@ -112,4 +112,11 @@ docker compose -f docker-compose-v6.yml up -d
- CI workflows: `ci-build.yml` (build check), `docker-build.yml` (multi-arch images + release), `deploy-docs.yml` (MkDocs).
- PostgreSQL migration supported via `panel_install.sh` menu option using pgloader.
- Repository layer is large: `repository.go` (83k LOC), `repository_mutations.go` (43k LOC).
- Button visual parity relies on `vite-frontend/src/shadcn-bridge/heroui/button.tsx` color mapping + `vite-frontend/src/styles/tailwind-theme.pcss` token export.
- Button visual parity relies on `vite-frontend/src/shadcn-bridge/heroui/button.tsx` color mapping + `vite-frontend/src/styles/tailwind-theme.pcss` token export.
## PLAN DOCUMENT RULE
- Every new implementation plan must have a dedicated Markdown plan document.
- Store plan documents under `plans/`.
- Use an incrementing numeric prefix and a short plan-summary name: `NNN-<plan-summary>.md` (for example, `001-auth-refactor.md`, `002-federation-api-cleanup.md`).
- The numeric prefix must increase by 1 for each new plan.
- In each plan document, keep a task checklist and mark each task as completed immediately after finishing it.
+148
View File
@@ -0,0 +1,148 @@
# 限速功能重构实施计划
## 一、需求概述
**原始需求**: 限速功能当前绑定到具体隧道,需要改为不绑定隧道,创建限速后可以自由在隧道上限速,也可以在转发上限速。
**核心变更**:
1. 限速规则(SpeedLimit)与隧道的绑定关系改为可选
2. 转发(Forward)支持独立的限速规则
---
## 二、实施计划清单
### 2.0 计划状态(审计更新:2026-02-26)
- 总体状态:**进行中(未验收通过)**
- 已完成:模型、仓储查询、限速 CRUD、控制面优先级、限速页与类型改造、编译与测试通过
- 未完成:**Forward 独立限速写入链路**(前端表单 -> API handler -> repository 落库 `forward.speed_id`)
### 2.1 后端模型层 (Model)
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| M1 | SpeedLimit.TunnelID 改为 sql.NullInt64 (可空) | `go-backend/internal/store/model/model.go` | ✅ 完成 |
| M2 | SpeedLimit.TunnelName 改为 sql.NullString (可空) | `go-backend/internal/store/model/model.go` | ✅ 完成 |
| M3 | Forward 添加 SpeedID sql.NullInt64 字段 | `go-backend/internal/store/model/model.go` | ✅ 完成 |
| M4 | ForwardRecord 添加 SpeedID sql.NullInt64 字段 | `go-backend/internal/store/model/model.go` | ✅ 完成 |
| M5 | SpeedLimitBackup.TunnelID 改为指针类型 | `go-backend/internal/store/model/model.go` | ✅ 完成 |
| M6 | ForwardBackup 添加 SpeedID *int64 字段 | `go-backend/internal/store/model/model.go` | ✅ 完成 |
### 2.2 后端仓储层 (Repository)
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| R1 | ListSpeedLimits() 返回可空 tunnelId/tunnelName | `go-backend/internal/store/repo/repository.go` | ✅ 完成 |
| R2 | ListForwards() 返回 speedId 字段 | `go-backend/internal/store/repo/repository.go` | ✅ 完成 |
| R3 | CreateSpeedLimit() 参数 tunnelID 改为 *int64 | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 |
| R4 | UpdateSpeedLimit() 参数 tunnelID 改为 *int64 | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 |
| R5 | GetSpeedLimitTunnelID() 返回 sql.NullInt64 | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 |
| R6 | exportSpeedLimits() 处理可空字段 | `go-backend/internal/store/repo/repository.go` | ✅ 完成 |
| R7 | importSpeedLimits() 处理可空字段 | `go-backend/internal/store/repo/repository.go` | ✅ 完成 |
| R8 | GetSpeedLimitSpeed() 新增方法 | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 |
| R9 | ListForwardsByTunnel() 返回 SpeedID | `go-backend/internal/store/repo/repository_control.go` | ✅ 完成 |
| R10 | ListActiveForwardsByUser() 返回 SpeedID | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 |
| R11 | ListActiveForwardsByUserTunnel() 返回 SpeedID | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 |
| R12 | GetForwardRecord() 返回 SpeedID | `go-backend/internal/store/repo/repository_flow.go` | ✅ 完成 |
### 2.3 后端处理器层 (Handler)
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| H1 | speedLimitCreate 处理可选 tunnelId | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 |
| H2 | speedLimitUpdate 处理可选 tunnelId | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 |
| H3 | speedLimitDelete 处理可空 tunnelID | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 |
### 2.4 后端控制平面 (Control Plane)
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| C1 | syncForwardServices 优先使用 Forward.SpeedID | `go-backend/internal/http/handler/control_plane.go` | ✅ 完成 |
| C2 | 回退到 UserTunnel 的 speed limit | `go-backend/internal/http/handler/control_plane.go` | ✅ 完成 |
### 2.5 前端类型定义 (TypeScript Types)
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| T1 | SpeedLimitApiItem.tunnelId 改为可选 | `vite-frontend/src/api/types.ts` | ✅ 完成 |
| T2 | ForwardApiItem 添加 speedId 字段 | `vite-frontend/src/api/types.ts` | ✅ 完成 |
| T3 | ForwardMutationPayload 添加 speedId 字段 | `vite-frontend/src/api/types.ts` | ✅ 完成 |
| T4 | SpeedLimitMutationPayload.tunnelId 改为可选 | `vite-frontend/src/api/types.ts` | ✅ 完成 |
### 2.6 前端页面组件
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| F1 | SpeedLimitRule 接口更新 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 |
| F2 | SpeedLimitForm 接口更新 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 |
| F3 | validateForm 移除 tunnelId 必填校验 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 |
| F4 | Select 组件改为可选 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 |
| F5 | 显示"未绑定"状态 | `vite-frontend/src/pages/limit.tsx` | ✅ 完成 |
### 2.7 编译验证
| 序号 | 任务 | 状态 |
|------|------|------|
| B1 | Go 后端编译通过 | ✅ 完成 |
| B2 | TypeScript 类型检查通过 | ✅ 完成 |
| B3 | `go test ./...` 全量通过 | ✅ 完成 |
| B4 | `go test ./tests/contract/... -run SpeedLimit` 通过 | ✅ 完成 |
### 2.8 Forward 独立限速写入链路补全(新增)
| 序号 | 任务 | 文件 | 状态 |
|------|------|------|------|
| N1 | forwardCreate 支持接收并校验可选 speedId,写入 Forward.SpeedID | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 |
| N2 | forwardUpdate 支持更新/清空 speedId,并触发服务重下发 | `go-backend/internal/http/handler/mutations.go` | ✅ 完成 |
| N3 | CreateForwardTx 支持落库 speed_id | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 |
| N4 | UpdateForward 支持更新 speed_id | `go-backend/internal/store/repo/repository_mutations.go` | ✅ 完成 |
| N5 | Forward 页面新增限速选择并透传 speedId | `vite-frontend/src/pages/forward.tsx` | ✅ 完成 |
| N6 | Forward 相关契约测试补充 speedId 写入/清空断言 | `go-backend/tests/contract/forward_contract_test.go` | ✅ 完成 |
---
## 三、优先级说明
限速规则应用优先级:
1. **Forward.SpeedID** - 转发级别的限速 (最高优先)
2. **UserTunnel.SpeedID** - 用户隧道权限级别的限速 (回退)
---
## 四、数据库兼容性
- SpeedLimit 表: `tunnel_id` 和 `tunnel_name` 字段改为可空 (GORM AutoMigrate 自动处理)
- Forward 表: 新增 `speed_id` 可空字段 (GORM AutoMigrate 自动处理)
---
## 五、验证检查项
### 5.1 功能验证(审计后)
- [x] 创建不限速规则的限速 (不绑定隧道)
- [x] 创建绑定隧道的限速 (兼容旧逻辑)
- [x] 编辑限速规则,切换隧道绑定状态
- [ ] 删除限速规则
- [ ] 转发列表正确显示 speedId
### 5.2 API 验证(审计后)
- [x] GET /api/speed-limit/list 返回可选 tunnelId
- [x] POST /api/speed-limit/create 接受可选 tunnelId
- [x] POST /api/speed-limit/update 接受可选 tunnelId
- [ ] GET /api/forward/list 返回 speedId
### 5.3 兼容性验证(审计后)
- [x] 现有绑定隧道的限速规则继续正常工作
- [ ] 现有 UserTunnel 的限速继续正常工作
- [ ] 备份/恢复功能正常
### 5.4 Forward 独立限速闭环验证(新增)
- [x] POST /api/forward/create 接受 speedId 并写入 `forward.speed_id`
- [x] POST /api/forward/update 可更新/清空 speedId
- [x] Forward 表单可选择限速并提交 speedId
- [ ] `syncForwardServices` 实际使用 Forward.SpeedID 而非仅回退 UserTunnel.SpeedID
+220
View File
@@ -0,0 +1,220 @@
# AI Skill 使用指南
让大模型直接操作 FLVX 面板的技能包。支持 OpenCode、OpenClaw、Claude Code 等工具。
## 安装
### 方式 1: npm (推荐)
```bash
npm install -g @flvx/skill-api
```
postinstall 脚本会自动链接到 `~/.agents/skills/flvx-api/`。
### 方式 2: 手动链接
```bash
# 从 FLVX 源码
cd /path/to/flvx
mkdir -p ~/.agents/skills
ln -sf $(pwd)/skills/flvx-api ~/.agents/skills/
# 或从 GitHub
git clone https://github.com/Sagit-chu/flvx.git
cd flvx
ln -sf $(pwd)/skills/flvx-api ~/.agents/skills/
```
## 配置
设置环境变量:
```bash
export FLVX_BASE_URL="https://your-panel.example.com"
export FLVX_USERNAME="admin"
export FLVX_PASSWORD="your-password"
```
或使用凭证文件:
```bash
mkdir -p ~/.flvx
cat > ~/.flvx/.env << 'EOF'
export FLVX_BASE_URL="https://panel.example.com"
export FLVX_USERNAME="admin"
export FLVX_PASSWORD="your-password"
EOF
chmod 600 ~/.flvx/.env
source ~/.flvx/.env
```
---
## 工具接入方法
### OpenCode
OpenCode 是命令行 AI 编程助手,支持通过 skills 扩展能力。
**安装 skill:**
```bash
npm install -g @flvx/skill-api
```
**使用:**
```bash
export FLVX_BASE_URL="https://panel.example.com"
export FLVX_USERNAME="admin"
export FLVX_PASSWORD="your-password"
opencode
```
**示例对话:**
```
你: 查看我的转发列表
你: 创建一个转发到 192.168.1.100:80 使用隧道 1
你: 检查节点状态
你: 查看流量使用情况
```
---
### OpenClaw
OpenClaw 同样支持 skills 机制。
**安装 skill:**
```bash
npm install -g @flvx/skill-api
# 或手动链接
mkdir -p ~/.openclaw/skills
ln -sf /path/to/flvx/skills/flvx-api ~/.openclaw/skills/flvx-api
```
**使用:**
```bash
openclaw
>>> 查看所有节点状态
>>> 给用户 alice 分配 50GB 流量
>>> 导出系统备份
```
---
### Claude Code
Claude Code 是 Anthropic 官方的命令行工具,支持通过 CLAUDE.md 扩展。
#### 方式 1: 项目级 CLAUDE.md
在项目根目录创建 `CLAUDE.md`:
```markdown
# FLVX API Skill
你可以通过 REST API 操作 FLVX 面板。
## 环境变量
- FLVX_BASE_URL: 面板地址
- FLVX_USERNAME: 用户名
- FLVX_PASSWORD: 密码
## 认证规则
- Authorization 头使用原始 JWT token,不加 "Bearer " 前缀
- 所有 API 使用 POST 方法
## 常用 API
### 登录获取 token
POST /api/v1/user/login
{"username": "...", "password": "..."}
### 查看转发列表
POST /api/v1/forward/list
Authorization: <token>
{}
### 创建转发
POST /api/v1/forward/create
{"name": "xxx", "tunnelId": 1, "remoteAddr": "1.2.3.4:80"}
### 查看节点
POST /api/v1/node/list
{}
```
**使用:**
```bash
cd /path/to/your/project
claude
```
#### 方式 2: 全局 CLAUDE.md
```bash
mkdir -p ~/.claude
cat > ~/.claude/CLAUDE.md << 'EOF'
# FLVX Panel Operations
使用 FLVX REST API 操作流量转发面板。
环境变量: FLVX_BASE_URL, FLVX_USERNAME, FLVX_PASSWORD
调用方式: curl -X POST "$FLVX_BASE_URL/api/v1/..." -H "Authorization: $TOKEN"
注意: Authorization 不要加 Bearer 前缀
EOF
```
#### 方式 3: 复制 SKILL.md
```bash
cat ~/.agents/skills/flvx-api/SKILL.md >> ~/.claude/CLAUDE.md
```
**示例对话:**
```
>>> 帮我查看 FLVX 面板上有哪些节点
>>> 创建一个名为 test 的转发,目标地址 10.0.0.1:80
>>> 查看我的流量使用情况
```
---
## API 覆盖
| 模块 | 操作 |
|------|------|
| 认证 | 登录、Token 管理 |
| 用户 | 增删改查、流量重置、密码 |
| 节点 | 增删改查、安装、升级、状态 |
| 隧道 | 增删改查、用户分配 |
| 转发 | 增删改查、暂停/恢复、诊断 |
| 分组 | 用户/隧道分组、权限 |
| 限速 | 增删改查 |
| 联邦 | 节点共享、远程节点 |
| 备份 | 导出/导入 |
## 安全提示
- ⚠️ 环境变量在进程列表中可见
- 使用 `~/.flvx/.env` 文件并设置 `chmod 600`
- 添加 `export HISTIGNORE="*FLVX_PASSWORD*"` 防止密码进入历史记录
- Token 仅在会话内存中缓存,不写入磁盘
## 发布
维护者可通过以下方式发布新版本:
```bash
# 方式 1: 推送 tag
git tag skill-v2.1.6
git push --tags
# 方式 2: GitHub Actions 手动触发
# 在 Actions 页面运行 publish-skill workflow
```
需要在 GitHub 仓库设置 `NPM_TOKEN` secret。
+1
View File
@@ -18,6 +18,7 @@
- [安装部署](./install.md)
- [使用指南](./usage.md)
- [PostgreSQL 数据库指南](./postgresql.md)
- [AI Skill 接入](./ai-skill.md) - 让大模型直接操作面板
- [常见问题](./faq.md)
## 免责声明
+1 -1
View File
@@ -49,7 +49,7 @@ func New(cfg config.Config) (*App, error) {
Handler: router,
ReadTimeout: 30 * time.Second,
ReadHeaderTimeout: 5 * time.Second,
WriteTimeout: 30 * time.Second,
WriteTimeout: 2 * time.Minute,
IdleTimeout: 60 * time.Second,
}
File diff suppressed because it is too large Load Diff
@@ -1,6 +1,7 @@
package handler
import (
"errors"
"reflect"
"testing"
)
@@ -53,3 +54,76 @@ func TestShouldTryLegacySingleService(t *testing.T) {
t.Fatalf("DeleteService should not require legacy fallback")
}
}
func TestIsAlreadyExistsMessage(t *testing.T) {
if !isAlreadyExistsMessage("service demo already exists") {
t.Fatalf("expected already exists message to be tolerated")
}
if !isAlreadyExistsMessage("服务已存在") {
t.Fatalf("expected Chinese already exists message to be tolerated")
}
if isAlreadyExistsMessage("listen tcp [::]:10001: bind: address already in use") {
t.Fatalf("address already in use must not be treated as already exists")
}
}
func TestIsBindAddressInUseError(t *testing.T) {
if !isBindAddressInUseError(errors.New("listen tcp [::]:10001: bind: address already in use")) {
t.Fatalf("address already in use should be detected")
}
if !isBindAddressInUseError(errors.New("listen tcp4 13.228.170.187:16765: bind: cannot assign requested address")) {
t.Fatalf("cannot assign requested address should be detected")
}
if isBindAddressInUseError(errors.New("service demo already exists")) {
t.Fatalf("already exists should not be treated as bind conflict")
}
if isBindAddressInUseError(nil) {
t.Fatalf("nil error should not be treated as bind conflict")
}
}
func TestBuildForwardServiceConfigs_UsesBindIPForListen(t *testing.T) {
forward := &forwardRecord{RemoteAddr: "1.2.3.4:80", Strategy: "fifo", TunnelID: 7}
node := &nodeRecord{TCPListenAddr: "[::]", UDPListenAddr: "[::]"}
services := buildForwardServiceConfigs("1_2_0", forward, nil, node, 22000, "10.9.8.7", nil, false)
if len(services) != 2 {
t.Fatalf("expected 2 services, got %d", len(services))
}
for _, svc := range services {
addr, _ := svc["addr"].(string)
if addr != "10.9.8.7:22000" {
t.Fatalf("expected bind IP address 10.9.8.7:22000, got %q", addr)
}
}
}
func TestBuildForwardServiceConfigs_DefaultListenAddrWhenBindIPEmpty(t *testing.T) {
forward := &forwardRecord{RemoteAddr: "1.2.3.4:80", Strategy: "fifo", TunnelID: 7}
node := &nodeRecord{TCPListenAddr: "0.0.0.0", UDPListenAddr: "[::]"}
services := buildForwardServiceConfigs("1_2_0", forward, nil, node, 22001, "", nil, false)
if len(services) != 2 {
t.Fatalf("expected 2 services, got %d", len(services))
}
tcpAddr, _ := services[0]["addr"].(string)
udpAddr, _ := services[1]["addr"].(string)
if tcpAddr != "0.0.0.0:22001" {
t.Fatalf("expected tcp addr 0.0.0.0:22001, got %q", tcpAddr)
}
if udpAddr != "[::]:22001" {
t.Fatalf("expected udp addr [::]:22001, got %q", udpAddr)
}
}
func TestBuildForwardServiceConfigs_BindIPAlreadyContainsPort(t *testing.T) {
forward := &forwardRecord{RemoteAddr: "1.2.3.4:80", Strategy: "fifo", TunnelID: 7}
node := &nodeRecord{TCPListenAddr: "[::]", UDPListenAddr: "[::]"}
services := buildForwardServiceConfigs("1_2_0", forward, nil, node, 55555, "3.3.3.3:12345", nil, false)
if len(services) != 2 {
t.Fatalf("expected 2 services, got %d", len(services))
}
for _, svc := range services {
addr, _ := svc["addr"].(string)
if addr != "3.3.3.3:12345" {
t.Fatalf("expected bind IP with port 3.3.3.3:12345, got %q", addr)
}
}
}
@@ -0,0 +1,209 @@
package handler
import (
"context"
"encoding/json"
"errors"
"net/http"
"strings"
"time"
"go-backend/internal/http/response"
)
type diagnosisStreamEvent struct {
Type string `json:"type"`
Data interface{} `json:"data,omitempty"`
TS int64 `json:"ts"`
}
func prepareDiagnosisStreamResponse(w http.ResponseWriter) (http.Flusher, error) {
flusher, ok := w.(http.Flusher)
if !ok {
return nil, errors.New("当前服务不支持流式响应")
}
w.Header().Set("Content-Type", "application/x-ndjson; charset=utf-8")
w.Header().Set("Cache-Control", "no-cache")
w.Header().Set("Connection", "keep-alive")
w.Header().Set("X-Accel-Buffering", "no")
return flusher, nil
}
func writeDiagnosisStreamEvent(encoder *json.Encoder, flusher http.Flusher, eventType string, data interface{}) error {
if encoder == nil || flusher == nil {
return errors.New("流式响应写入器未初始化")
}
event := diagnosisStreamEvent{Type: eventType, Data: data, TS: time.Now().UnixMilli()}
if err := encoder.Encode(event); err != nil {
return err
}
flusher.Flush()
return nil
}
func summarizeDiagnosisProgress(results []map[string]interface{}) diagnosisProgress {
progress := diagnosisProgress{Total: len(results)}
for _, item := range results {
progress.Completed++
if asBool(item["success"], false) {
progress.Success++
} else {
progress.Failed++
}
}
return progress
}
func shouldIgnoreDiagnosisStreamError(err error) bool {
if err == nil {
return false
}
if errors.Is(err, context.Canceled) {
return true
}
msg := strings.ToLower(strings.TrimSpace(err.Error()))
if strings.Contains(msg, "broken pipe") || strings.Contains(msg, "connection reset by peer") {
return true
}
if strings.Contains(msg, "stream already closed") {
return true
}
return false
}
func (h *Handler) streamDiagnosisRuntime(ctx context.Context, cancel context.CancelFunc, w http.ResponseWriter, startPayload map[string]interface{}, workItems []diagnosisWorkItem) error {
flusher, err := prepareDiagnosisStreamResponse(w)
if err != nil {
return err
}
encoder := json.NewEncoder(w)
payload := map[string]interface{}{
"total": len(workItems),
"timestamp": time.Now().UnixMilli(),
"items": h.buildDiagnosisStreamStartItems(workItems),
}
for key, value := range startPayload {
payload[key] = value
}
if err := writeDiagnosisStreamEvent(encoder, flusher, "start", payload); err != nil {
return err
}
streamBroken := false
emitter := func(index int, item map[string]interface{}, progress diagnosisProgress) {
if streamBroken {
return
}
itemPayload := map[string]interface{}{
"index": index,
"result": item,
"progress": progress,
}
if err := writeDiagnosisStreamEvent(encoder, flusher, "item", itemPayload); err != nil {
streamBroken = true
if cancel != nil {
cancel()
}
}
}
results := h.runDiagnosisWorkItems(ctx, workItems, emitter)
if streamBroken {
return context.Canceled
}
progress := summarizeDiagnosisProgress(results)
donePayload := map[string]interface{}{
"progress": progress,
"timedOut": errors.Is(ctx.Err(), context.DeadlineExceeded),
}
return writeDiagnosisStreamEvent(encoder, flusher, "done", donePayload)
}
func (h *Handler) tunnelDiagnoseStream(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodPost {
response.WriteJSON(w, response.ErrDefault("请求失败"))
return
}
id := asInt64FromBodyKey(r, w, "tunnelId")
if id <= 0 {
return
}
tunnelName, tunnelType, workItems, err := h.prepareTunnelDiagnosis(id)
if err != nil {
if strings.Contains(err.Error(), "不存在") || strings.Contains(err.Error(), "不完整") {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
}
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
ctx, cancel := context.WithTimeout(r.Context(), diagnosisRequestTimeout)
defer cancel()
startPayload := map[string]interface{}{
"tunnelName": tunnelName,
"tunnelType": tunnelType,
}
if err := h.streamDiagnosisRuntime(ctx, cancel, w, startPayload, workItems); err != nil {
if shouldIgnoreDiagnosisStreamError(err) {
return
}
if strings.Contains(err.Error(), "不支持流式响应") {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
}
return
}
}
func (h *Handler) forwardDiagnoseStream(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodPost {
response.WriteJSON(w, response.ErrDefault("请求失败"))
return
}
id := asInt64FromBodyKey(r, w, "forwardId")
if id <= 0 {
return
}
forward, _, _, err := h.resolveForwardAccess(r, id)
if err != nil {
if errors.Is(err, errForwardNotFound) {
response.WriteJSON(w, response.ErrDefault("转发不存在"))
return
}
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
forwardName, workItems, err := h.prepareForwardDiagnosis(forward)
if err != nil {
if strings.Contains(err.Error(), "不存在") || strings.Contains(err.Error(), "不能为空") || strings.Contains(err.Error(), "错误") {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
}
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
ctx, cancel := context.WithTimeout(r.Context(), diagnosisRequestTimeout)
defer cancel()
startPayload := map[string]interface{}{
"forwardName": forwardName,
}
if err := h.streamDiagnosisRuntime(ctx, cancel, w, startPayload, workItems); err != nil {
if shouldIgnoreDiagnosisStreamError(err) {
return
}
if strings.Contains(err.Error(), "不支持流式响应") {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
}
return
}
}
@@ -8,9 +8,51 @@ import (
// nodeSupportsV4 / nodeSupportsV6
// ---------------------------------------------------------------------------
func TestNodeSupportsV4_Nil(t *testing.T) {
if nodeSupportsV4(nil) {
t.Fatal("nil node must not support v4")
func TestSelectTunnelDialHost_ConnectIpPriority(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
// Empty connectIp should be ignored, IP preference takes effect
host, err := selectTunnelDialHost(from, to, "", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
if host != "10.0.0.2" {
t.Fatalf("empty connectIp should be ignored (v4 preference applies), got %q", host)
}
// Non-empty connectIp should override IP preference
host, err = selectTunnelDialHost(from, to, "v6", "192.168.0.3")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
if host != "192.168.0.3" {
t.Fatalf("connectIp should override v6 preference, got %q", host)
}
}
func TestBuildTunnelChainServiceConfig_UsesConnectIPForListen(t *testing.T) {
node := &nodeRecord{TCPListenAddr: "[::]"}
chain := tunnelRuntimeNode{Protocol: "tls", Port: 21000, ConnectIP: "2001:db8::88"}
services := buildTunnelChainServiceConfig(99, chain, node)
if len(services) != 1 {
t.Fatalf("expected 1 service, got %d", len(services))
}
addr, _ := services[0]["addr"].(string)
if addr != "[2001:db8::88]:21000" {
t.Fatalf("expected connectIp listen [2001:db8::88]:21000, got %q", addr)
}
}
func TestBuildTunnelChainServiceConfig_DefaultListenAddrWhenConnectIPEmpty(t *testing.T) {
node := &nodeRecord{TCPListenAddr: "[::]"}
chain := tunnelRuntimeNode{Protocol: "tls", Port: 21001}
services := buildTunnelChainServiceConfig(99, chain, node)
if len(services) != 1 {
t.Fatalf("expected 1 service, got %d", len(services))
}
addr, _ := services[0]["addr"].(string)
if addr != "[::]:21001" {
t.Fatalf("expected default listen [::]:21001, got %q", addr)
}
}
@@ -23,14 +65,14 @@ func TestNodeSupportsV6_Nil(t *testing.T) {
func TestNodeSupportsV4_ExplicitV4(t *testing.T) {
n := &nodeRecord{ServerIPv4: "10.0.0.1"}
if !nodeSupportsV4(n) {
t.Fatal("explicit server_ip_v4 must support v4")
t.Fatal("explicit server_ip_v4 needs support v4")
}
}
func TestNodeSupportsV6_ExplicitV6(t *testing.T) {
n := &nodeRecord{ServerIPv6: "2001:db8::1"}
if !nodeSupportsV6(n) {
t.Fatal("explicit server_ip_v6 must support v6")
t.Fatal("explicit server_ip_v6 needs support v6")
}
}
@@ -68,7 +110,7 @@ func TestNodeSupportsV4_LegacyV4Only(t *testing.T) {
t.Fatal("legacy v4 ip in server_ip must support v4")
}
if nodeSupportsV6(n) {
t.Fatal("legacy v4 ip in server_ip must not support v6")
t.Fatal("legacy v4 ip in server_ip should not support v6")
}
}
@@ -78,7 +120,7 @@ func TestNodeSupportsV6_LegacyV6Only(t *testing.T) {
t.Fatal("legacy v6 ip in server_ip must support v6")
}
if nodeSupportsV4(n) {
t.Fatal("legacy v6 ip in server_ip must not support v4")
t.Fatal("legacy v6 ip in server_ip should not support v4")
}
}
@@ -177,15 +219,15 @@ func v6OnlyNode(name, v6 string) *nodeRecord {
}
func TestSelectTunnelDialHost_NilNodes(t *testing.T) {
_, err := selectTunnelDialHost(nil, nil, "")
_, err := selectTunnelDialHost(nil, nil, "", "")
if err == nil {
t.Fatal("expected error for nil nodes")
}
_, err = selectTunnelDialHost(dualStackNode("a", "1.1.1.1", "::1"), nil, "")
_, err = selectTunnelDialHost(dualStackNode("a", "1.1.1.1", "::1"), nil, "", "")
if err == nil {
t.Fatal("expected error for nil toNode")
}
_, err = selectTunnelDialHost(nil, dualStackNode("b", "1.1.1.1", "::1"), "")
_, err = selectTunnelDialHost(nil, dualStackNode("b", "1.1.1.1", "::1"), "", "")
if err == nil {
t.Fatal("expected error for nil fromNode")
}
@@ -194,8 +236,7 @@ func TestSelectTunnelDialHost_NilNodes(t *testing.T) {
func TestSelectTunnelDialHost_DualStack_DefaultPreference(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
host, err := selectTunnelDialHost(from, to, "")
host, err := selectTunnelDialHost(from, to, "", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -208,8 +249,7 @@ func TestSelectTunnelDialHost_DualStack_DefaultPreference(t *testing.T) {
func TestSelectTunnelDialHost_DualStack_PreferV4(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
host, err := selectTunnelDialHost(from, to, "v4")
host, err := selectTunnelDialHost(from, to, "v4", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -221,8 +261,7 @@ func TestSelectTunnelDialHost_DualStack_PreferV4(t *testing.T) {
func TestSelectTunnelDialHost_DualStack_PreferV6(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
host, err := selectTunnelDialHost(from, to, "v6")
host, err := selectTunnelDialHost(from, to, "v6", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -234,9 +273,8 @@ func TestSelectTunnelDialHost_DualStack_PreferV6(t *testing.T) {
func TestSelectTunnelDialHost_V4Only_PreferV6Fallback(t *testing.T) {
from := v4OnlyNode("from", "10.0.0.1")
to := v4OnlyNode("to", "10.0.0.2")
// User prefers v6, but both nodes are v4-only — should fallback to v4
host, err := selectTunnelDialHost(from, to, "v6")
host, err := selectTunnelDialHost(from, to, "v6", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -248,9 +286,8 @@ func TestSelectTunnelDialHost_V4Only_PreferV6Fallback(t *testing.T) {
func TestSelectTunnelDialHost_V6Only_PreferV4Fallback(t *testing.T) {
from := v6OnlyNode("from", "2001:db8::1")
to := v6OnlyNode("to", "2001:db8::2")
// User prefers v4, but both nodes are v6-only — should fallback to v6
host, err := selectTunnelDialHost(from, to, "v4")
host, err := selectTunnelDialHost(from, to, "v4", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -262,8 +299,7 @@ func TestSelectTunnelDialHost_V6Only_PreferV4Fallback(t *testing.T) {
func TestSelectTunnelDialHost_Incompatible(t *testing.T) {
from := v4OnlyNode("from", "10.0.0.1")
to := v6OnlyNode("to", "2001:db8::2")
_, err := selectTunnelDialHost(from, to, "")
_, err := selectTunnelDialHost(from, to, "", "")
if err == nil {
t.Fatal("expected error for incompatible nodes (v4-only -> v6-only)")
}
@@ -272,8 +308,7 @@ func TestSelectTunnelDialHost_Incompatible(t *testing.T) {
func TestSelectTunnelDialHost_Incompatible_Reverse(t *testing.T) {
from := v6OnlyNode("from", "2001:db8::1")
to := v4OnlyNode("to", "10.0.0.2")
_, err := selectTunnelDialHost(from, to, "")
_, err := selectTunnelDialHost(from, to, "", "")
if err == nil {
t.Fatal("expected error for incompatible nodes (v6-only -> v4-only)")
}
@@ -282,9 +317,8 @@ func TestSelectTunnelDialHost_Incompatible_Reverse(t *testing.T) {
func TestSelectTunnelDialHost_WhitespacePreference(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
// Whitespace should be trimmed, treated as "v6"
host, err := selectTunnelDialHost(from, to, " v6 ")
host, err := selectTunnelDialHost(from, to, " v6 ", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -296,9 +330,8 @@ func TestSelectTunnelDialHost_WhitespacePreference(t *testing.T) {
func TestSelectTunnelDialHost_MixedStack_FromDualToV4(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := v4OnlyNode("to", "10.0.0.2")
// v6 preferred, but target only has v4 — should succeed with v4
host, err := selectTunnelDialHost(from, to, "v6")
host, err := selectTunnelDialHost(from, to, "v6", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -310,9 +343,8 @@ func TestSelectTunnelDialHost_MixedStack_FromDualToV4(t *testing.T) {
func TestSelectTunnelDialHost_MixedStack_FromDualToV6(t *testing.T) {
from := dualStackNode("from", "10.0.0.1", "2001:db8::1")
to := v6OnlyNode("to", "2001:db8::2")
// v4 preferred, but target only has v6 — should succeed with v6
host, err := selectTunnelDialHost(from, to, "v4")
host, err := selectTunnelDialHost(from, to, "v4", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -324,9 +356,8 @@ func TestSelectTunnelDialHost_MixedStack_FromDualToV6(t *testing.T) {
func TestSelectTunnelDialHost_MixedStack_FromV4ToDual(t *testing.T) {
from := v4OnlyNode("from", "10.0.0.1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
// v6 preferred, but from only has v4 — should use v4 (from can only reach v4 of target)
host, err := selectTunnelDialHost(from, to, "v6")
host, err := selectTunnelDialHost(from, to, "v6", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -338,9 +369,8 @@ func TestSelectTunnelDialHost_MixedStack_FromV4ToDual(t *testing.T) {
func TestSelectTunnelDialHost_MixedStack_FromV6ToDual(t *testing.T) {
from := v6OnlyNode("from", "2001:db8::1")
to := dualStackNode("to", "10.0.0.2", "2001:db8::2")
// v4 preferred, but from only has v6 — should use v6
host, err := selectTunnelDialHost(from, to, "v4")
host, err := selectTunnelDialHost(from, to, "v4", "")
if err != nil {
t.Fatalf("unexpected error: %v", err)
}
@@ -367,7 +397,6 @@ func TestNodeDisplayName_Named(t *testing.T) {
t.Fatalf("expected 'hk-node', got %q", got)
}
}
func TestNodeDisplayName_Unnamed(t *testing.T) {
n := &nodeRecord{ID: 42}
got := nodeDisplayName(n)
@@ -1232,16 +1232,20 @@ func (h *Handler) federationRuntimeDiagnose(w http.ResponseWriter, r *http.Reque
if req.Count <= 0 {
req.Count = 4
}
if req.Timeout <= 0 {
req.Timeout = 5000
if req.Timeout <= 0 || req.Timeout > int(diagnosisCommandTimeout/time.Millisecond) {
req.Timeout = int(diagnosisCommandTimeout / time.Millisecond)
}
commandTimeout := time.Duration(req.Timeout) * time.Millisecond
if commandTimeout <= 0 || commandTimeout > diagnosisCommandTimeout {
commandTimeout = diagnosisCommandTimeout
}
res, err := h.sendNodeCommand(share.NodeID, "TcpPing", map[string]interface{}{
res, err := h.sendNodeCommandWithTimeout(share.NodeID, "TcpPing", map[string]interface{}{
"ip": req.IP,
"port": req.Port,
"count": req.Count,
"timeout": req.Timeout,
}, false, false)
}, commandTimeout, false, false)
if err != nil {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
@@ -1472,7 +1476,7 @@ func (h *Handler) releasePeerShareForwardRuntimeServices(share *repo.PeerShare,
func isFederationRuntimeCommandAllowed(commandType string) bool {
switch strings.ToLower(strings.TrimSpace(commandType)) {
case "addservice", "updateservice", "deleteservice", "pauseservice", "resumeservice", "addchains", "deletechains", "addlimiters", "deletelimiters", "tcpping", "reload":
case "addservice", "updateservice", "deleteservice", "pauseservice", "resumeservice", "addchains", "deletechains", "addlimiters", "updatelimiters", "deletelimiters", "tcpping", "reload":
return true
default:
return false
+77 -7
View File
@@ -3,6 +3,7 @@ package handler
import (
"context"
"database/sql"
"encoding/base64"
"encoding/json"
"fmt"
"io"
@@ -72,6 +73,11 @@ type flowItem struct {
D int64 `json:"d"`
}
const (
pngDataURLPrefix = "data:image/png;base64,"
maxBrandAssetDataURLBytes = 1024 * 1024
)
func New(repo *repo.Repository, jwtSecret string) *Handler {
h := &Handler{
repo: repo,
@@ -128,6 +134,7 @@ func (h *Handler) Register(mux *http.ServeMux) {
mux.HandleFunc("/api/v1/tunnel/update", h.tunnelUpdate)
mux.HandleFunc("/api/v1/tunnel/delete", h.tunnelDelete)
mux.HandleFunc("/api/v1/tunnel/diagnose", h.tunnelDiagnose)
mux.HandleFunc("/api/v1/tunnel/diagnose/stream", h.tunnelDiagnoseStream)
mux.HandleFunc("/api/v1/tunnel/update-order", h.tunnelUpdateOrder)
mux.HandleFunc("/api/v1/tunnel/batch-delete", h.tunnelBatchDelete)
mux.HandleFunc("/api/v1/tunnel/batch-redeploy", h.tunnelBatchRedeploy)
@@ -143,6 +150,7 @@ func (h *Handler) Register(mux *http.ServeMux) {
mux.HandleFunc("/api/v1/forward/pause", h.forwardPause)
mux.HandleFunc("/api/v1/forward/resume", h.forwardResume)
mux.HandleFunc("/api/v1/forward/diagnose", h.forwardDiagnose)
mux.HandleFunc("/api/v1/forward/diagnose/stream", h.forwardDiagnoseStream)
mux.HandleFunc("/api/v1/forward/update-order", h.forwardUpdateOrder)
mux.HandleFunc("/api/v1/forward/batch-delete", h.forwardBatchDelete)
mux.HandleFunc("/api/v1/forward/batch-pause", h.forwardBatchPause)
@@ -153,7 +161,6 @@ func (h *Handler) Register(mux *http.ServeMux) {
mux.HandleFunc("/api/v1/speed-limit/create", h.speedLimitCreate)
mux.HandleFunc("/api/v1/speed-limit/update", h.speedLimitUpdate)
mux.HandleFunc("/api/v1/speed-limit/delete", h.speedLimitDelete)
mux.HandleFunc("/api/v1/speed-limit/tunnels", h.tunnelList)
mux.HandleFunc("/api/v1/tunnel/user/tunnel", h.userTunnelVisibleList)
mux.HandleFunc("/api/v1/tunnel/user/list", h.userTunnelList)
mux.HandleFunc("/api/v1/group/tunnel/list", h.tunnelGroupList)
@@ -747,7 +754,14 @@ func (h *Handler) updateConfigs(w http.ResponseWriter, r *http.Request) {
if key == "" {
continue
}
if err := h.repo.UpsertConfig(key, v, now); err != nil {
value, err := normalizeAndValidateConfigValue(key, v)
if err != nil {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
}
if err := h.repo.UpsertConfig(key, value, now); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
@@ -767,16 +781,24 @@ func (h *Handler) updateSingleConfig(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.ErrDefault("配置名称不能为空"))
return
}
if strings.TrimSpace(req.Name) == "" {
name := strings.TrimSpace(req.Name)
if name == "" {
response.WriteJSON(w, response.ErrDefault("配置名称不能为空"))
return
}
if strings.TrimSpace(req.Value) == "" {
value, err := normalizeAndValidateConfigValue(name, req.Value)
if err != nil {
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
}
if value == "" && name != "app_logo" && name != "app_favicon" {
response.WriteJSON(w, response.ErrDefault("配置值不能为空"))
return
}
if err := h.repo.UpsertConfig(strings.TrimSpace(req.Name), req.Value, time.Now().UnixMilli()); err != nil {
if err := h.repo.UpsertConfig(name, value, time.Now().UnixMilli()); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
@@ -784,6 +806,37 @@ func (h *Handler) updateSingleConfig(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.OKEmpty())
}
func normalizeAndValidateConfigValue(key, value string) (string, error) {
switch strings.TrimSpace(key) {
case "app_logo", "app_favicon":
normalized := strings.TrimSpace(value)
if normalized == "" {
return "", nil
}
if !strings.HasPrefix(normalized, pngDataURLPrefix) {
return "", fmt.Errorf("品牌图片必须通过上传生成 PNG 数据")
}
if len(normalized) > maxBrandAssetDataURLBytes {
return "", fmt.Errorf("品牌图片过大,请上传更小图片")
}
payload := strings.TrimSpace(strings.TrimPrefix(normalized, pngDataURLPrefix))
if payload == "" {
return "", fmt.Errorf("品牌图片数据不能为空")
}
if _, err := base64.StdEncoding.DecodeString(payload); err != nil {
return "", fmt.Errorf("品牌图片数据格式无效")
}
return pngDataURLPrefix + payload, nil
default:
return value, nil
}
}
func (h *Handler) userPackage(w http.ResponseWriter, r *http.Request) {
if r.Method != http.MethodPost {
response.WriteJSON(w, response.ErrDefault("请求失败"))
@@ -989,10 +1042,27 @@ func (h *Handler) captchaEnabled() (bool, error) {
if err != nil {
return false, err
}
if cfg == nil {
if cfg == nil || !strings.EqualFold(strings.TrimSpace(cfg.Value), "true") {
return false, nil
}
return strings.EqualFold(cfg.Value, "true"), nil
siteCfg, err := h.repo.GetConfigByName("cloudflare_site_key")
if err != nil {
return false, err
}
if siteCfg == nil || strings.TrimSpace(siteCfg.Value) == "" {
return false, nil
}
secretCfg, err := h.repo.GetConfigByName("cloudflare_secret_key")
if err != nil {
return false, err
}
if secretCfg == nil || strings.TrimSpace(secretCfg.Value) == "" {
return false, nil
}
return true, nil
}
func (h *Handler) apiClientCaptchaBypassEnabled(r *http.Request) bool {
+247 -70
View File
@@ -1,6 +1,7 @@
package handler
import (
"context"
"crypto/rand"
"database/sql"
"encoding/hex"
@@ -270,6 +271,7 @@ func (h *Handler) nodeCreate(w http.ResponseWriter, r *http.Request) {
nullableText(asString(req["remoteUrl"])),
nullableText(asString(req["remoteToken"])),
nullableText(asString(req["remoteConfig"])),
nullableText(asString(req["extraIPs"])),
); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
@@ -321,6 +323,7 @@ func (h *Handler) nodeUpdate(w http.ResponseWriter, r *http.Request) {
nullableText(asString(req["serverIpV6"])),
defaultString(asString(req["port"]), "1000-65535"),
nullableText(asString(req["interfaceName"])),
nullableText(asString(req["extraIPs"])),
newHTTP,
newTLS,
newSocks,
@@ -787,7 +790,9 @@ func (h *Handler) tunnelDiagnose(w http.ResponseWriter, r *http.Request) {
if id <= 0 {
return
}
result, err := h.diagnoseTunnelRuntime(id)
ctx, cancel := context.WithTimeout(r.Context(), diagnosisRequestTimeout)
defer cancel()
result, err := h.diagnoseTunnelRuntime(ctx, id)
if err != nil {
if strings.Contains(err.Error(), "不存在") || strings.Contains(err.Error(), "不完整") {
response.WriteJSON(w, response.ErrDefault(err.Error()))
@@ -882,6 +887,7 @@ func (h *Handler) reconstructTunnelState(tunnelID int64) (*tunnelCreateState, er
Strategy: r.Strategy,
ChainType: 3,
Port: r.Port,
ConnectIP: r.ConnectIP,
})
state.NodeIDList = append(state.NodeIDList, r.NodeID)
}
@@ -896,6 +902,7 @@ func (h *Handler) reconstructTunnelState(tunnelID int64) (*tunnelCreateState, er
ChainType: 2,
Inx: int(r.Inx),
Port: r.Port,
ConnectIP: r.ConnectIP,
})
state.NodeIDList = append(state.NodeIDList, r.NodeID)
}
@@ -1048,21 +1055,55 @@ func (h *Handler) userTunnelUpdate(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.ErrDefault("权限ID不能为空"))
return
}
speedID := asAnyToInt64Ptr(req["speedId"])
if err := h.validateSpeedLimitReference(speedID); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
userID, tunnelID, utErr := h.repo.GetUserTunnelUserAndTunnel(id)
if utErr != nil {
response.WriteJSON(w, response.Err(-2, utErr.Error()))
return
}
_, oldFlow, oldNum, oldExpTime, oldFlowReset, oldSpeedID, oldStatus, oldErr :=
h.repo.GetExistingUserTunnel(userID, tunnelID)
if oldErr != nil {
response.WriteJSON(w, response.Err(-2, oldErr.Error()))
return
}
if err := h.repo.UpdateUserTunnel(id,
asInt64(req["flow"], 0),
asInt(req["num"], 0),
asInt64(req["expTime"], time.Now().Add(365*24*time.Hour).UnixMilli()),
asInt64(req["flowResetTime"], 1),
nullableInt(asAnyToInt64Ptr(req["speedId"])),
nullableInt(speedID),
asInt(req["status"], 1),
); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
userID, tunnelID, utErr := h.repo.GetUserTunnelUserAndTunnel(id)
if utErr == nil {
h.syncUserTunnelForwards(userID, tunnelID)
if syncErr := h.syncUserTunnelForwards(userID, tunnelID); syncErr != nil {
rollbackErr := h.repo.UpdateUserTunnel(
id,
oldFlow,
int(oldNum),
oldExpTime,
oldFlowReset,
oldSpeedID,
oldStatus,
)
if rollbackErr != nil {
response.WriteJSON(w, response.Err(-2, fmt.Sprintf("下发失败且回滚失败: %v; 回滚错误: %v", syncErr, rollbackErr)))
return
}
response.WriteJSON(w, response.Err(-2, fmt.Sprintf("下发失败,已回滚: %v", syncErr)))
return
}
response.WriteJSON(w, response.OKEmpty())
@@ -1103,6 +1144,18 @@ func (h *Handler) forwardCreate(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.ErrDefault("转发名称和目标地址不能为空"))
return
}
speedID := asAnyToInt64Ptr(req["speedId"])
if speedID != nil {
exists, speedErr := h.repo.SpeedLimitExists(*speedID)
if speedErr != nil {
response.WriteJSON(w, response.Err(-2, speedErr.Error()))
return
}
if !exists {
response.WriteJSON(w, response.ErrDefault("限速规则不存在"))
return
}
}
port := asInt(req["inPort"], 0)
if port <= 0 {
port = h.pickTunnelPort(tunnelID)
@@ -1127,7 +1180,8 @@ func (h *Handler) forwardCreate(w http.ResponseWriter, r *http.Request) {
if userName == "" {
userName = "user"
}
forwardID, err := h.repo.CreateForwardTx(userID, userName, name, tunnelID, remoteAddr, defaultString(asString(req["strategy"]), "fifo"), now, inx, entryNodes, port)
inIp := strings.TrimSpace(asString(req["inIp"]))
forwardID, err := h.repo.CreateForwardTx(userID, userName, name, tunnelID, remoteAddr, defaultString(asString(req["strategy"]), "fifo"), now, inx, entryNodes, port, inIp, nullableInt(speedID))
if err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
@@ -1137,7 +1191,7 @@ func (h *Handler) forwardCreate(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
if err := h.syncForwardServices(createdForward, "AddService", false); err != nil {
if err := h.syncForwardServices(createdForward, "UpdateService", true); err != nil {
_ = h.deleteForwardByID(forwardID)
response.WriteJSON(w, response.ErrDefault(err.Error()))
return
@@ -1202,6 +1256,24 @@ func (h *Handler) forwardUpdate(w http.ResponseWriter, r *http.Request) {
if strategy == "" {
strategy = forward.Strategy
}
speedID := asAnyToInt64Ptr(req["speedId"])
if speedID != nil {
exists, speedErr := h.repo.SpeedLimitExists(*speedID)
if speedErr != nil {
response.WriteJSON(w, response.Err(-2, speedErr.Error()))
return
}
if !exists {
response.WriteJSON(w, response.ErrDefault("限速规则不存在"))
return
}
}
newSpeedID := forward.SpeedID
if speedID != nil {
newSpeedID = sql.NullInt64{Int64: *speedID, Valid: true}
} else if _, ok := req["speedId"]; ok {
newSpeedID = sql.NullInt64{Valid: false}
}
port := asInt(req["inPort"], 0)
if port <= 0 {
@@ -1213,6 +1285,12 @@ func (h *Handler) forwardUpdate(w http.ResponseWriter, r *http.Request) {
port = h.pickTunnelPort(tunnelID)
}
}
hasInIP := false
inIp := ""
if rawInIP, ok := req["inIp"]; ok {
hasInIP = true
inIp = asString(rawInIP)
}
fwdEntryNodes, _ := h.tunnelEntryNodeIDs(tunnelID)
for _, nodeID := range fwdEntryNodes {
node, nodeErr := h.getNodeRecord(nodeID)
@@ -1225,11 +1303,18 @@ func (h *Handler) forwardUpdate(w http.ResponseWriter, r *http.Request) {
}
}
now := time.Now().UnixMilli()
if err := h.repo.UpdateForward(id, name, tunnelID, remoteAddr, strategy, now); err != nil {
if err := h.repo.UpdateForward(id, name, tunnelID, remoteAddr, strategy, now, newSpeedID); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
if err := h.replaceForwardPorts(id, tunnelID, port); err != nil {
if hasInIP {
err = h.replaceForwardPorts(id, tunnelID, port, inIp)
} else if tunnelID != forward.TunnelID {
err = h.replaceForwardPorts(id, tunnelID, port, "")
} else {
err = h.replaceForwardPortsPreservingInIP(id, tunnelID, port, oldPorts)
}
if err != nil {
h.rollbackForwardMutation(forward, oldPorts)
response.WriteJSON(w, response.Err(-2, err.Error()))
return
@@ -1335,7 +1420,9 @@ func (h *Handler) forwardDiagnose(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
payload, err := h.diagnoseForwardRuntime(forward)
ctx, cancel := context.WithTimeout(r.Context(), diagnosisRequestTimeout)
defer cancel()
payload, err := h.diagnoseForwardRuntime(ctx, forward)
if err != nil {
if strings.Contains(err.Error(), "不存在") || strings.Contains(err.Error(), "不能为空") || strings.Contains(err.Error(), "错误") {
response.WriteJSON(w, response.ErrDefault(err.Error()))
@@ -1559,7 +1646,7 @@ func (h *Handler) forwardBatchChangeTunnel(w http.ResponseWriter, r *http.Reques
fail++
continue
}
if err := h.replaceForwardPorts(id, req.TargetTunnelID, p); err != nil {
if err := h.replaceForwardPorts(id, req.TargetTunnelID, p, ""); err != nil {
h.rollbackForwardMutation(forward, oldPorts)
fail++
continue
@@ -1586,29 +1673,22 @@ func (h *Handler) speedLimitCreate(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.ErrDefault("请求参数错误"))
return
}
tunnelID := asInt64(req["tunnelId"], 0)
if tunnelID <= 0 {
response.WriteJSON(w, response.ErrDefault("隧道ID不能为空"))
return
}
name := asString(req["name"])
if name == "" {
response.WriteJSON(w, response.ErrDefault("名称不能为空"))
return
}
tunnelName := h.repo.GetTunnelNameByID(tunnelID)
if tunnelName == "" {
response.WriteJSON(w, response.ErrDefault("隧道不存在"))
return
}
now := time.Now().UnixMilli()
speed := asInt(req["speed"], 100)
id, err := h.repo.CreateSpeedLimit(name, speed, tunnelID, tunnelName, now, asInt(req["status"], 1))
now := time.Now().UnixMilli()
_, err := h.repo.CreateSpeedLimit(name, speed, now, asInt(req["status"], 1))
if err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
_ = h.sendLimiterConfig(id, speed, tunnelID)
response.WriteJSON(w, response.OKEmpty())
}
@@ -1618,23 +1698,26 @@ func (h *Handler) speedLimitUpdate(w http.ResponseWriter, r *http.Request) {
response.WriteJSON(w, response.ErrDefault("请求参数错误"))
return
}
id := asInt64(req["id"], 0)
tunnelID := asInt64(req["tunnelId"], 0)
if id <= 0 || tunnelID <= 0 {
response.WriteJSON(w, response.ErrDefault("请求参数错误"))
if id <= 0 {
response.WriteJSON(w, response.ErrDefault("限速规则ID不能为空"))
return
}
tunnelName := h.repo.GetTunnelNameByID(tunnelID)
if tunnelName == "" {
response.WriteJSON(w, response.ErrDefault("隧道不存在"))
name := asString(req["name"])
if name == "" {
response.WriteJSON(w, response.ErrDefault("名称不能为空"))
return
}
speed := asInt(req["speed"], 100)
if err := h.repo.UpdateSpeedLimit(id, asString(req["name"]), speed, tunnelID, tunnelName, asInt(req["status"], 1), time.Now().UnixMilli()); err != nil {
if err := h.repo.UpdateSpeedLimit(id, name, speed, asInt(req["status"], 1), time.Now().UnixMilli()); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
_ = h.sendLimiterConfig(id, speed, tunnelID)
response.WriteJSON(w, response.OKEmpty())
}
@@ -1643,15 +1726,12 @@ func (h *Handler) speedLimitDelete(w http.ResponseWriter, r *http.Request) {
if id <= 0 {
return
}
tunnelID := h.repo.GetSpeedLimitTunnelID(id)
if err := h.repo.DeleteSpeedLimit(id); err != nil {
response.WriteJSON(w, response.Err(-2, err.Error()))
return
}
if tunnelID > 0 {
_ = h.sendDeleteLimiterConfig(id, tunnelID)
}
response.WriteJSON(w, response.OKEmpty())
}
@@ -1892,6 +1972,7 @@ type tunnelRuntimeNode struct {
Inx int
ChainType int
Port int
ConnectIP string
}
type tunnelCreateState struct {
@@ -1965,6 +2046,7 @@ func (h *Handler) prepareTunnelCreateState(tx *gorm.DB, req map[string]interface
Strategy: defaultString(asString(item["strategy"]), "round"),
ChainType: 3,
Port: port,
ConnectIP: asString(item["connectIp"]),
})
}
if len(state.OutNodes) == 0 {
@@ -2000,6 +2082,7 @@ func (h *Handler) prepareTunnelCreateState(tx *gorm.DB, req map[string]interface
Inx: hopIdx + 1,
ChainType: 2,
Port: port,
ConnectIP: asString(item["connectIp"]),
})
}
if len(hop) > 0 {
@@ -2276,7 +2359,7 @@ func (h *Handler) applyFederationRuntime(state *tunnelCreateState, localDomain s
h.releaseFederationRuntimeRefs(releaseRefs)
return nil, nil, errors.New("节点不存在")
}
host, hostErr := selectTunnelDialHost(node, targetNode, state.IPPreference)
host, hostErr := selectTunnelDialHost(node, targetNode, state.IPPreference, target.ConnectIP)
if hostErr != nil {
h.releaseFederationRuntimeRefs(releaseRefs)
return nil, nil, hostErr
@@ -2516,7 +2599,7 @@ func buildTunnelChainConfig(tunnelID int64, fromNodeID int64, targets []tunnelRu
if targetNode == nil {
return nil, errors.New("节点不存在")
}
host, err := selectTunnelDialHost(fromNode, targetNode, ipPreference)
host, err := selectTunnelDialHost(fromNode, targetNode, ipPreference, target.ConnectIP)
if err != nil {
return nil, err
}
@@ -2574,7 +2657,7 @@ func buildTunnelChainServiceConfig(tunnelID int64, chainNode tunnelRuntimeNode,
}
service := map[string]interface{}{
"name": fmt.Sprintf("%d_tls", tunnelID),
"addr": fmt.Sprintf("%s:%d", node.TCPListenAddr, chainNode.Port),
"addr": processServerAddress(fmt.Sprintf("%s:%d", defaultString(strings.TrimSpace(chainNode.ConnectIP), node.TCPListenAddr), chainNode.Port)),
"handler": handlerCfg,
"listener": map[string]interface{}{
"type": protocol,
@@ -2589,10 +2672,13 @@ func buildTunnelChainServiceConfig(tunnelID int64, chainNode tunnelRuntimeNode,
return []map[string]interface{}{service}
}
func selectTunnelDialHost(fromNode, toNode *nodeRecord, ipPreference string) (string, error) {
func selectTunnelDialHost(fromNode, toNode *nodeRecord, ipPreference string, connectIp string) (string, error) {
if fromNode == nil || toNode == nil {
return "", errors.New("节点不存在")
}
if strings.TrimSpace(connectIp) != "" {
return strings.TrimSpace(connectIp), nil
}
fromV4 := nodeSupportsV4(fromNode)
fromV6 := nodeSupportsV6(fromNode)
toV4 := nodeSupportsV4(toNode)
@@ -2713,7 +2799,7 @@ func pickNodeAddressV6(node *nodeRecord) string {
func (h *Handler) replaceTunnelChainsTx(tx *gorm.DB, tunnelID int64, req map[string]interface{}) error {
allocated := map[int64]int{}
inNodes := asMapSlice(req["inNodeId"])
for _, n := range inNodes {
for i, n := range inNodes {
nodeID := asInt64(n["nodeId"], 0)
if nodeID <= 0 {
continue
@@ -2725,13 +2811,14 @@ func (h *Handler) replaceTunnelChainsTx(tx *gorm.DB, tunnelID int64, req map[str
nodeID,
sql.NullInt64{},
defaultString(asString(n["strategy"]), "round"),
0,
i+1,
defaultString(asString(n["protocol"]), "tls"),
"",
); err != nil {
return err
}
}
for _, n := range asMapSlice(req["outNodeId"]) {
for i, n := range asMapSlice(req["outNodeId"]) {
nodeID := asInt64(n["nodeId"], 0)
if nodeID <= 0 {
continue
@@ -2744,6 +2831,7 @@ func (h *Handler) replaceTunnelChainsTx(tx *gorm.DB, tunnelID int64, req map[str
return pickErr
}
}
connectIp := asString(n["connectIp"])
if err := h.repo.CreateChainTunnelTx(
tx,
tunnelID,
@@ -2751,8 +2839,9 @@ func (h *Handler) replaceTunnelChainsTx(tx *gorm.DB, tunnelID int64, req map[str
nodeID,
sql.NullInt64{Int64: int64(port), Valid: true},
defaultString(asString(n["strategy"]), "round"),
0,
i+1,
defaultString(asString(n["protocol"]), "tls"),
connectIp,
); err != nil {
return err
}
@@ -2772,6 +2861,7 @@ func (h *Handler) replaceTunnelChainsTx(tx *gorm.DB, tunnelID int64, req map[str
return pickErr
}
}
connectIp := asString(n["connectIp"])
if err := h.repo.CreateChainTunnelTx(
tx,
tunnelID,
@@ -2781,6 +2871,7 @@ func (h *Handler) replaceTunnelChainsTx(tx *gorm.DB, tunnelID int64, req map[str
defaultString(asString(n["strategy"]), "round"),
i+1,
defaultString(asString(n["protocol"]), "tls"),
connectIp,
); err != nil {
return err
}
@@ -2937,34 +3028,62 @@ func parsePorts(portRange string) ([]int, error) {
return ports, nil
}
func (h *Handler) replaceForwardPorts(forwardID, tunnelID int64, port int) error {
type forwardPortReplaceEntry = struct {
NodeID int64
Port int
InIP string
}
func buildForwardPortEntriesWithPreservedInIP(entryNodeIDs []int64, oldPorts []forwardPortRecord, port int) []forwardPortReplaceEntry {
preservedByNode := make(map[int64]string)
for _, fp := range oldPorts {
current, exists := preservedByNode[fp.NodeID]
if !exists {
preservedByNode[fp.NodeID] = fp.InIP
continue
}
if strings.TrimSpace(current) == "" && strings.TrimSpace(fp.InIP) != "" {
preservedByNode[fp.NodeID] = fp.InIP
}
}
entries := make([]forwardPortReplaceEntry, 0, len(entryNodeIDs))
for _, nid := range entryNodeIDs {
entries = append(entries, forwardPortReplaceEntry{
NodeID: nid,
Port: port,
InIP: preservedByNode[nid],
})
}
return entries
}
func (h *Handler) replaceForwardPorts(forwardID, tunnelID int64, port int, inIp string) error {
entryNodes, err := h.tunnelEntryNodeIDs(tunnelID)
if err != nil {
return err
}
entries := make([]struct {
NodeID int64
Port int
}, len(entryNodes))
entries := make([]forwardPortReplaceEntry, len(entryNodes))
for i, nid := range entryNodes {
entries[i] = struct {
NodeID int64
Port int
}{NodeID: nid, Port: port}
entries[i] = forwardPortReplaceEntry{NodeID: nid, Port: port, InIP: inIp}
}
return h.repo.ReplaceForwardPorts(forwardID, entries)
}
func (h *Handler) replaceForwardPortsPreservingInIP(forwardID, tunnelID int64, port int, oldPorts []forwardPortRecord) error {
entryNodes, err := h.tunnelEntryNodeIDs(tunnelID)
if err != nil {
return err
}
entries := buildForwardPortEntriesWithPreservedInIP(entryNodes, oldPorts, port)
return h.repo.ReplaceForwardPorts(forwardID, entries)
}
func (h *Handler) replaceForwardPortsWithRecords(forwardID int64, ports []forwardPortRecord) error {
entries := make([]struct {
NodeID int64
Port int
}, len(ports))
entries := make([]forwardPortReplaceEntry, len(ports))
for i, fp := range ports {
entries[i] = struct {
NodeID int64
Port int
}{NodeID: fp.NodeID, Port: fp.Port}
entries[i] = forwardPortReplaceEntry{NodeID: fp.NodeID, Port: fp.Port, InIP: fp.InIP}
}
return h.repo.ReplaceForwardPorts(forwardID, entries)
}
@@ -2977,6 +3096,7 @@ func (h *Handler) rollbackForwardMutation(oldForward *forwardRecord, oldPorts []
h.repo.RollbackForwardFields(
oldForward.ID, oldForward.UserID, oldForward.UserName, oldForward.Name,
oldForward.TunnelID, oldForward.RemoteAddr, oldForward.Strategy, oldForward.Status,
oldForward.SpeedID,
time.Now().UnixMilli(),
)
@@ -2998,6 +3118,10 @@ func (h *Handler) upsertUserTunnel(req map[string]interface{}) error {
h.repo.GetExistingUserTunnel(userID, tunnelID)
speedID := asAnyToInt64Ptr(req["speedId"])
if err := h.validateSpeedLimitReference(speedID); err != nil {
return err
}
reqFlow := asInt64(req["flow"], -1)
reqNum := asInt(req["num"], -1)
reqExpTime := asInt64(req["expTime"], -1)
@@ -3038,7 +3162,24 @@ func (h *Handler) upsertUserTunnel(req map[string]interface{}) error {
reqStatus = 1
}
return h.repo.InsertUserTunnel(userID, tunnelID, nullableInt(speedID), reqNum, reqFlow, reqFlowReset, reqExpTime, reqStatus)
if err := h.repo.InsertUserTunnel(userID, tunnelID, nullableInt(speedID), reqNum, reqFlow, reqFlowReset, reqExpTime, reqStatus); err != nil {
return err
}
if syncErr := h.syncUserTunnelForwards(userID, tunnelID); syncErr != nil {
insertedID, _, _, _, _, _, _, lookupErr := h.repo.GetExistingUserTunnel(userID, tunnelID)
if lookupErr != nil {
return fmt.Errorf("下发失败且回滚失败: %v; 回滚查询错误: %w", syncErr, lookupErr)
}
if rollbackErr := h.repo.DeleteUserTunnel(insertedID); rollbackErr != nil {
return fmt.Errorf("下发失败且回滚失败: %v; 回滚删除错误: %w", syncErr, rollbackErr)
}
return fmt.Errorf("下发失败,已回滚: %w", syncErr)
}
return nil
}
if err != nil {
return err
@@ -3076,25 +3217,61 @@ func (h *Handler) upsertUserTunnel(req map[string]interface{}) error {
newSpeedID = sql.NullInt64{Valid: false}
}
err = h.repo.UpdateUserTunnelFields(existingID, newSpeedID, newFlow, newNum, newExpTime, newFlowReset, newStatus)
if err == nil {
h.syncUserTunnelForwards(userID, tunnelID)
if err := h.repo.UpdateUserTunnelFields(existingID, newSpeedID, newFlow, newNum, newExpTime, newFlowReset, newStatus); err != nil {
return err
}
return err
if syncErr := h.syncUserTunnelForwards(userID, tunnelID); syncErr != nil {
rollbackErr := h.repo.UpdateUserTunnelFields(
existingID,
currentSpeedID,
currentFlow,
int(currentNum),
currentExpTime,
currentFlowReset,
currentStatus,
)
if rollbackErr != nil {
return fmt.Errorf("下发失败且回滚失败: %v; 回滚错误: %w", syncErr, rollbackErr)
}
return fmt.Errorf("下发失败,已回滚: %w", syncErr)
}
return nil
}
func (h *Handler) syncUserTunnelForwards(userID, tunnelID int64) {
func (h *Handler) syncUserTunnelForwards(userID, tunnelID int64) error {
forwards, err := h.listForwardsByTunnel(tunnelID)
if err != nil {
return
return err
}
for i := range forwards {
f := &forwards[i]
if f.UserID == userID {
_ = h.syncForwardServices(f, "UpdateService", true)
if err := h.syncForwardServices(f, "UpdateService", true); err != nil {
return err
}
}
}
return nil
}
func (h *Handler) validateSpeedLimitReference(speedID *int64) error {
if speedID == nil {
return nil
}
exists, err := h.repo.SpeedLimitExists(*speedID)
if err != nil {
return err
}
if !exists {
return errors.New("限速规则不存在")
}
return nil
}
func asAnySlice(v interface{}) []interface{} {
@@ -0,0 +1,39 @@
package handler
import "testing"
func TestBuildForwardPortEntriesWithPreservedInIP(t *testing.T) {
entryNodeIDs := []int64{10, 20, 30}
oldPorts := []forwardPortRecord{
{NodeID: 10, Port: 10001, InIP: ""},
{NodeID: 10, Port: 10002, InIP: "10.0.0.10"},
{NodeID: 20, Port: 10003, InIP: "10.0.0.20"},
}
entries := buildForwardPortEntriesWithPreservedInIP(entryNodeIDs, oldPorts, 18080)
if len(entries) != 3 {
t.Fatalf("expected 3 entries, got %d", len(entries))
}
if entries[0].NodeID != 10 || entries[0].Port != 18080 || entries[0].InIP != "10.0.0.10" {
t.Fatalf("unexpected first entry: %+v", entries[0])
}
if entries[1].NodeID != 20 || entries[1].Port != 18080 || entries[1].InIP != "10.0.0.20" {
t.Fatalf("unexpected second entry: %+v", entries[1])
}
if entries[2].NodeID != 30 || entries[2].Port != 18080 || entries[2].InIP != "" {
t.Fatalf("unexpected third entry: %+v", entries[2])
}
}
func TestBuildForwardPortEntriesWithPreservedInIP_EmptyOldPorts(t *testing.T) {
entryNodeIDs := []int64{99}
entries := buildForwardPortEntriesWithPreservedInIP(entryNodeIDs, nil, 17000)
if len(entries) != 1 {
t.Fatalf("expected 1 entry, got %d", len(entries))
}
if entries[0].NodeID != 99 || entries[0].Port != 17000 || entries[0].InIP != "" {
t.Fatalf("unexpected entry: %+v", entries[0])
}
}
@@ -0,0 +1,79 @@
package handler
import (
"path/filepath"
"testing"
"time"
"go-backend/internal/store/repo"
)
func TestReconstructTunnelState_PreservesConnectIP(t *testing.T) {
dbPath := filepath.Join(t.TempDir(), "reconstruct-connect-ip.db")
r, err := repo.Open(dbPath)
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() { _ = r.Close() })
h := New(r, "secret")
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO tunnel(id, name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(1, 'reconstruct-tunnel', 1.0, 2, 'tls', 1, ?, ?, 1, NULL, 0)
`, now, now).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
insertNode := func(id int64, name, ip string) {
if err := r.DB().Exec(`
INSERT INTO node(id, name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, id, name, name+"-secret", ip, ip, "", "30000-30010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node %s: %v", name, err)
}
}
insertNode(101, "entry", "10.90.0.10")
insertNode(102, "middle", "10.90.0.20")
insertNode(103, "exit", "10.90.0.30")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(1, '1', 101, 30001, 'round', 1, 'tls')
`).Error; err != nil {
t.Fatalf("insert entry chain: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol, connect_ip)
VALUES(1, '2', 102, 30002, 'round', 1, 'tls', '10.99.9.22')
`).Error; err != nil {
t.Fatalf("insert middle chain: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol, connect_ip)
VALUES(1, '3', 103, 30003, 'round', 1, 'tls', '10.99.9.33')
`).Error; err != nil {
t.Fatalf("insert exit chain: %v", err)
}
state, err := h.reconstructTunnelState(1)
if err != nil {
t.Fatalf("reconstructTunnelState: %v", err)
}
if len(state.ChainHops) != 1 || len(state.ChainHops[0]) != 1 {
t.Fatalf("unexpected chain hops: %+v", state.ChainHops)
}
if got := state.ChainHops[0][0].ConnectIP; got != "10.99.9.22" {
t.Fatalf("expected middle connectIp 10.99.9.22, got %q", got)
}
if len(state.OutNodes) != 1 {
t.Fatalf("unexpected out nodes: %+v", state.OutNodes)
}
if got := state.OutNodes[0].ConnectIP; got != "10.99.9.33" {
t.Fatalf("expected exit connectIp 10.99.9.33, got %q", got)
}
}
+38 -28
View File
@@ -29,28 +29,30 @@ func (User) TableName() string { return "user" }
// Forward maps to the "forward" table.
type Forward struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
UserID int64 `gorm:"column:user_id;not null"`
UserName string `gorm:"column:user_name;type:varchar(100);not null"`
Name string `gorm:"type:varchar(100);not null"`
TunnelID int64 `gorm:"column:tunnel_id;not null"`
RemoteAddr string `gorm:"column:remote_addr;type:text;not null"`
Strategy string `gorm:"type:varchar(100);not null;default:'fifo'"`
InFlow int64 `gorm:"column:in_flow;not null;default:0"`
OutFlow int64 `gorm:"column:out_flow;not null;default:0"`
CreatedTime int64 `gorm:"column:created_time;not null"`
UpdatedTime int64 `gorm:"column:updated_time;not null"`
Status int `gorm:"not null"`
Inx int `gorm:"not null;default:0"`
ID int64 `gorm:"primaryKey;autoIncrement"`
UserID int64 `gorm:"column:user_id;not null"`
UserName string `gorm:"column:user_name;type:varchar(100);not null"`
Name string `gorm:"type:varchar(100);not null"`
TunnelID int64 `gorm:"column:tunnel_id;not null"`
RemoteAddr string `gorm:"column:remote_addr;type:text;not null"`
Strategy string `gorm:"type:varchar(100);not null;default:'fifo'"`
InFlow int64 `gorm:"not null;default:0"`
OutFlow int64 `gorm:"column:out_flow;not null;default:0"`
CreatedTime int64 `gorm:"column:created_time;not null"`
UpdatedTime int64 `gorm:"column:updated_time;not null"`
Status int `gorm:"not null"`
Inx int `gorm:"not null;default:0"`
SpeedID sql.NullInt64 `gorm:"column:speed_id"`
}
func (Forward) TableName() string { return "forward" }
type ForwardPort struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
ForwardID int64 `gorm:"column:forward_id;not null"`
NodeID int64 `gorm:"column:node_id;not null"`
Port int `gorm:"not null"`
ID int64 `gorm:"primaryKey;autoIncrement"`
ForwardID int64 `gorm:"column:forward_id;not null"`
NodeID int64 `gorm:"column:node_id;not null"`
Port int `gorm:"not null"`
InIP sql.NullString `gorm:"column:in_ip;type:text"`
}
func (ForwardPort) TableName() string { return "forward_port" }
@@ -62,6 +64,7 @@ type Node struct {
ServerIP string `gorm:"column:server_ip;type:varchar(100);not null"`
ServerIPV4 sql.NullString `gorm:"column:server_ip_v4;type:varchar(100)"`
ServerIPV6 sql.NullString `gorm:"column:server_ip_v6;type:varchar(100)"`
ExtraIPs sql.NullString `gorm:"column:extra_ips;type:text"`
Port string `gorm:"type:text;not null"`
InterfaceName sql.NullString `gorm:"column:interface_name;type:varchar(200)"`
Version sql.NullString `gorm:"type:varchar(100)"`
@@ -83,14 +86,14 @@ type Node struct {
func (Node) TableName() string { return "node" }
type SpeedLimit struct {
ID int64 `gorm:"primaryKey;autoIncrement"`
Name string `gorm:"type:varchar(100);not null"`
Speed int `gorm:"not null"`
TunnelID int64 `gorm:"column:tunnel_id;not null"`
TunnelName string `gorm:"column:tunnel_name;type:varchar(100);not null"`
CreatedTime int64 `gorm:"column:created_time;not null"`
UpdatedTime sql.NullInt64 `gorm:"column:updated_time"`
Status int `gorm:"not null"`
ID int64 `gorm:"primaryKey;autoIncrement"`
Name string `gorm:"type:varchar(100);not null"`
Speed int `gorm:"not null"`
TunnelID sql.NullInt64 `gorm:"column:tunnel_id"`
TunnelName sql.NullString `gorm:"column:tunnel_name;type:varchar(100)"`
CreatedTime int64 `gorm:"column:created_time;not null"`
UpdatedTime sql.NullInt64 `gorm:"column:updated_time"`
Status int `gorm:"not null"`
}
func (SpeedLimit) TableName() string { return "speed_limit" }
@@ -132,6 +135,7 @@ type ChainTunnel struct {
Strategy sql.NullString `gorm:"type:varchar(10)"`
Inx sql.NullInt64 `gorm:"column:inx"`
Protocol sql.NullString `gorm:"type:varchar(10)"`
ConnectIP sql.NullString `gorm:"column:connect_ip;type:varchar(45)"`
}
func (ChainTunnel) TableName() string { return "chain_tunnel" }
@@ -213,7 +217,7 @@ func (GroupPermissionGrant) TableName() string { return "group_permission_grant"
type ViteConfig struct {
ID int64 `gorm:"primaryKey;autoIncrement" json:"id"`
Name string `gorm:"type:varchar(200);not null;uniqueIndex" json:"name"`
Value string `gorm:"type:varchar(200);not null" json:"value"`
Value string `gorm:"type:text;not null" json:"value"`
Time int64 `gorm:"not null" json:"time"`
}
@@ -336,6 +340,7 @@ type NodeBackup struct {
ServerIP string `json:"serverIp"`
ServerIPv4 string `json:"serverIpV4,omitempty"`
ServerIPv6 string `json:"serverIpV6,omitempty"`
ExtraIPs string `json:"extraIPs,omitempty"`
Port string `json:"port"`
InterfaceName string `json:"interfaceName,omitempty"`
Version string `json:"version,omitempty"`
@@ -395,6 +400,7 @@ type ForwardBackup struct {
UpdatedTime int64 `json:"updatedTime"`
Status int `json:"status"`
Inx int `json:"inx"`
SpeedID *int64 `json:"speedId,omitempty"`
ForwardPorts *[]ForwardPortBackup `json:"forwardPorts,omitempty"`
}
@@ -421,8 +427,8 @@ type SpeedLimitBackup struct {
ID int64 `json:"id"`
Name string `json:"name"`
Speed int64 `json:"speed"`
TunnelID int64 `json:"tunnelId"`
TunnelName string `json:"tunnelName"`
TunnelID *int64 `json:"tunnelId,omitempty"`
TunnelName string `json:"tunnelName,omitempty"`
CreatedTime int64 `json:"createdTime"`
UpdatedTime int64 `json:"updatedTime,omitempty"`
Status int `json:"status"`
@@ -492,6 +498,7 @@ type ForwardRecord struct {
RemoteAddr string
Strategy string
Status int
SpeedID sql.NullInt64
}
// TunnelRecord is a minimal tunnel view used by control plane.
@@ -507,6 +514,7 @@ type TunnelRecord struct {
type ForwardPortRecord struct {
NodeID int64
Port int
InIP string
}
// NodeRecord is a node view used by control plane.
@@ -516,6 +524,7 @@ type NodeRecord struct {
ServerIP string
ServerIPv4 string
ServerIPv6 string
ExtraIPs string
Status int
PortRange string
TCPListenAddr string
@@ -535,6 +544,7 @@ type ChainNodeRecord struct {
NodeName string
Protocol string
Strategy string
ConnectIP string
}
type UserTunnelLimiterInfo struct {
+123 -40
View File
@@ -260,7 +260,7 @@ func prepareSQLiteLegacyColumns(db *gorm.DB) error {
m := db.Migrator()
if m.HasTable(&model.Node{}) {
for _, field := range []string{"ServerIPV4", "ServerIPV6", "Inx", "IsRemote", "RemoteURL", "RemoteToken", "RemoteConfig"} {
for _, field := range []string{"ServerIPV4", "ServerIPV6", "ExtraIPs", "TCPListenAddr", "UDPListenAddr", "Inx", "IsRemote", "RemoteURL", "RemoteToken", "RemoteConfig"} {
if m.HasColumn(&model.Node{}, field) {
continue
}
@@ -637,6 +637,7 @@ func (r *Repository) ListNodes() ([]map[string]interface{}, error) {
"ip": n.ServerIP, "serverIp": n.ServerIP,
"serverIpV4": nullableString(n.ServerIPV4),
"serverIpV6": nullableString(n.ServerIPV6),
"extraIPs": nullableString(n.ExtraIPs),
"port": n.Port,
"tcpListenAddr": n.TCPListenAddr,
"udpListenAddr": n.UDPListenAddr,
@@ -656,7 +657,7 @@ func (r *Repository) ListUsers() ([]map[string]interface{}, error) {
return nil, errors.New("repository not initialized")
}
var users []model.User
if err := r.db.Where("role_id != ?", 0).Order("id ASC").Find(&users).Error; err != nil {
if err := r.db.Where("role_id != ?", 0).Order("id DESC").Find(&users).Error; err != nil {
return nil, err
}
items := make([]map[string]interface{}, 0, len(users))
@@ -678,17 +679,17 @@ func (r *Repository) ListSpeedLimits() ([]map[string]interface{}, error) {
return nil, errors.New("repository not initialized")
}
var limits []model.SpeedLimit
if err := r.db.Order("id ASC").Find(&limits).Error; err != nil {
if err := r.db.Order("id DESC").Find(&limits).Error; err != nil {
return nil, err
}
items := make([]map[string]interface{}, 0, len(limits))
for _, sl := range limits {
items = append(items, map[string]interface{}{
item := map[string]interface{}{
"id": sl.ID, "name": sl.Name, "speed": sl.Speed,
"tunnelId": sl.TunnelID, "tunnelName": sl.TunnelName,
"status": sl.Status, "createdTime": sl.CreatedTime,
"updatedTime": nullableInt64(sl.UpdatedTime),
})
}
items = append(items, item)
}
return items, nil
}
@@ -712,11 +713,12 @@ func (r *Repository) ListForwards() ([]map[string]interface{}, error) {
CreatedTime int64
Status int
Inx int
SpeedID sql.NullInt64
}
var rows []fwdRow
err := r.db.Model(&model.Forward{}).
Select("forward.id, forward.user_id, forward.user_name, forward.name, forward.tunnel_id, COALESCE(tunnel.name, '') AS tunnel_name, forward.remote_addr, COALESCE(forward.strategy, 'fifo') AS strategy, forward.in_flow, forward.out_flow, forward.created_time, forward.status, forward.inx").
Select("forward.id, forward.user_id, forward.user_name, forward.name, forward.tunnel_id, COALESCE(tunnel.name, '') AS tunnel_name, forward.remote_addr, COALESCE(forward.strategy, 'fifo') AS strategy, forward.in_flow, forward.out_flow, forward.created_time, forward.status, forward.inx, forward.speed_id").
Joins("LEFT JOIN tunnel ON tunnel.id = forward.tunnel_id").
Order("forward.inx ASC, forward.id ASC").
Find(&rows).Error
@@ -730,14 +732,18 @@ func (r *Repository) ListForwards() ([]map[string]interface{}, error) {
if err != nil {
return nil, err
}
items = append(items, map[string]interface{}{
item := map[string]interface{}{
"id": row.ID, "userId": row.UserID, "userName": row.UserName,
"name": row.Name, "tunnelId": row.TunnelID, "tunnelName": row.TunnelName,
"inIp": nullableForwardIngress(inIP), "inPort": nullableInt64(inPort),
"remoteAddr": row.RemoteAddr, "strategy": row.Strategy,
"inFlow": row.InFlow, "outFlow": row.OutFlow,
"createdTime": row.CreatedTime, "status": row.Status, "inx": int64(row.Inx),
})
}
if row.SpeedID.Valid {
item["speedId"] = row.SpeedID.Int64
}
items = append(items, item)
}
return items, nil
}
@@ -859,6 +865,9 @@ func (r *Repository) ListTunnels() ([]map[string]interface{}, error) {
if c.Strategy.Valid {
nodeObj["strategy"] = c.Strategy.String
}
if c.ConnectIP.Valid {
nodeObj["connectIp"] = c.ConnectIP.String
}
switch chainTypeInt {
case 1:
@@ -1308,7 +1317,6 @@ func (r *Repository) ListActiveForwardPeerShareRuntimesByNodeAndServiceName(node
return items, nil
}
func (r *Repository) ListActiveForwardPeerShareRuntimeServiceNamesByNode(nodeID int64) ([]string, error) {
if r == nil || r.db == nil {
return nil, errors.New("repository not initialized")
@@ -1813,7 +1821,6 @@ func (r *Repository) exportSpeedLimits() ([]model.SpeedLimitBackup, error) {
for _, sl := range sls {
b := model.SpeedLimitBackup{
ID: sl.ID, Name: sl.Name, Speed: int64(sl.Speed),
TunnelID: sl.TunnelID, TunnelName: sl.TunnelName,
CreatedTime: sl.CreatedTime, Status: sl.Status,
}
if sl.UpdatedTime.Valid {
@@ -2186,8 +2193,8 @@ func importSpeedLimits(tx *gorm.DB, speedLimits []model.SpeedLimitBackup, now in
ID: sl.ID,
Name: sl.Name,
Speed: int(sl.Speed),
TunnelID: sl.TunnelID,
TunnelName: sl.TunnelName,
TunnelID: sql.NullInt64{Int64: 0, Valid: false},
TunnelName: sql.NullString{String: "", Valid: false},
CreatedTime: sl.CreatedTime,
UpdatedTime: sql.NullInt64{Int64: now, Valid: true},
Status: sl.Status,
@@ -2460,9 +2467,11 @@ func (r *Repository) GetUserTunnelByID(id int64) (*model.UserTunnel, error) {
// ─── Migration ───────────────────────────────────────────────────────
const currentSchemaVersion = 2
const currentSchemaVersion = 4
var ensurePostgresIDDefaultsFn = ensurePostgresIDDefaults
var migrateViteConfigValueColumnTypeFn = migrateViteConfigValueColumnType
var migrateSpeedLimitTunnelBindingFn = migrateSpeedLimitTunnelBinding
func getSchemaVersion(db *gorm.DB) int {
var v model.SchemaVersion
@@ -2514,10 +2523,82 @@ func migrateSchema(db *gorm.DB) error {
return err
}
if ver < 3 {
if err := migrateViteConfigValueColumnTypeFn(db); err != nil {
return err
}
}
if ver < 4 {
if err := migrateSpeedLimitTunnelBindingFn(db); err != nil {
return err
}
}
setSchemaVersion(db, currentSchemaVersion)
return nil
}
func migrateViteConfigValueColumnType(db *gorm.DB) error {
if db == nil {
return errors.New("nil db")
}
if !db.Migrator().HasTable(&model.ViteConfig{}) {
return nil
}
if db.Dialector.Name() != "postgres" {
return nil
}
type columnRow struct {
DataType string `gorm:"column:data_type"`
}
var row columnRow
if err := db.Raw(
`SELECT data_type FROM information_schema.columns
WHERE table_schema = current_schema()
AND table_name = ?
AND column_name = ?`,
"vite_config", "value",
).Scan(&row).Error; err != nil {
return fmt.Errorf("inspect vite_config.value type: %w", err)
}
if strings.EqualFold(row.DataType, "text") {
return nil
}
if err := db.Exec(`ALTER TABLE "vite_config" ALTER COLUMN "value" TYPE TEXT`).Error; err != nil {
return fmt.Errorf("alter vite_config.value to text: %w", err)
}
return nil
}
func migrateSpeedLimitTunnelBinding(db *gorm.DB) error {
if db == nil {
return errors.New("nil db")
}
if !db.Migrator().HasTable(&model.SpeedLimit{}) {
return nil
}
if err := db.Model(&model.SpeedLimit{}).
Where("tunnel_id IS NOT NULL OR tunnel_name IS NOT NULL").
UpdateColumns(map[string]interface{}{
"tunnel_id": nil,
"tunnel_name": nil,
}).Error; err != nil {
return fmt.Errorf("clear speed_limit tunnel binding: %w", err)
}
return nil
}
func ensurePostgresIDDefaults(db *gorm.DB) error {
if db.Dialector.Name() != "postgres" {
return nil
@@ -2654,10 +2735,11 @@ func resolveForwardIngress(db *gorm.DB, forwardID int64, tunnelID int64) (string
type fpRow struct {
Port sql.NullInt64
ServerIP sql.NullString
InIP sql.NullString
}
var fpRows []fpRow
err := db.Model(&model.ForwardPort{}).
Select("forward_port.port, node.server_ip").
Select("forward_port.port, node.server_ip, forward_port.in_ip").
Joins("LEFT JOIN node ON node.id = forward_port.node_id").
Where("forward_port.forward_id = ?", forwardID).
Order("forward_port.id ASC").
@@ -2667,10 +2749,22 @@ func resolveForwardIngress(db *gorm.DB, forwardID int64, tunnelID int64) (string
}
ports := make([]int64, 0)
nodePairs := make([]string, 0)
entries := make([]string, 0)
seenPorts := make(map[int64]struct{})
seenPairs := make(map[string]struct{})
var tunnelFirstIP string
if tunnelInIP.Valid && strings.TrimSpace(tunnelInIP.String) != "" {
tunnelIPs := strings.Split(tunnelInIP.String, ",")
for _, ip := range tunnelIPs {
ip = strings.TrimSpace(ip)
if ip != "" {
tunnelFirstIP = ip
break
}
}
}
for _, row := range fpRows {
if !row.Port.Valid {
continue
@@ -2679,11 +2773,21 @@ func resolveForwardIngress(db *gorm.DB, forwardID int64, tunnelID int64) (string
seenPorts[row.Port.Int64] = struct{}{}
ports = append(ports, row.Port.Int64)
}
if row.ServerIP.Valid && strings.TrimSpace(row.ServerIP.String) != "" {
pair := fmt.Sprintf("%s:%d", strings.TrimSpace(row.ServerIP.String), row.Port.Int64)
var ip string
if row.InIP.Valid && strings.TrimSpace(row.InIP.String) != "" {
ip = strings.TrimSpace(row.InIP.String)
} else if tunnelFirstIP != "" {
ip = tunnelFirstIP
} else if row.ServerIP.Valid && strings.TrimSpace(row.ServerIP.String) != "" {
ip = strings.TrimSpace(row.ServerIP.String)
}
if ip != "" {
pair := fmt.Sprintf("%s:%d", ip, row.Port.Int64)
if _, ok := seenPairs[pair]; !ok {
seenPairs[pair] = struct{}{}
nodePairs = append(nodePairs, pair)
entries = append(entries, pair)
}
}
}
@@ -2694,27 +2798,6 @@ func resolveForwardIngress(db *gorm.DB, forwardID int64, tunnelID int64) (string
inPort := sql.NullInt64{Int64: ports[0], Valid: true}
entries := make([]string, 0)
if tunnelInIP.Valid && strings.TrimSpace(tunnelInIP.String) != "" {
tunnelIPs := strings.Split(tunnelInIP.String, ",")
seen := make(map[string]struct{})
for _, ip := range tunnelIPs {
ip = strings.TrimSpace(ip)
if ip == "" {
continue
}
if _, ok := seen[ip]; ok {
continue
}
seen[ip] = struct{}{}
for _, port := range ports {
entries = append(entries, fmt.Sprintf("%s:%d", ip, port))
}
}
} else {
entries = append(entries, nodePairs...)
}
return strings.Join(entries, ","), inPort, nil
}
@@ -46,6 +46,7 @@ func (r *Repository) ListForwardsByTunnel(tunnelID int64) ([]model.ForwardRecord
RemoteAddr: f.RemoteAddr,
Strategy: f.Strategy,
Status: f.Status,
SpeedID: f.SpeedID,
})
}
for i := range rows {
@@ -101,11 +102,34 @@ func (r *Repository) ListForwardPorts(forwardID int64) ([]model.ForwardPortRecor
}
rows := make([]model.ForwardPortRecord, 0, len(ports))
for _, p := range ports {
rows = append(rows, model.ForwardPortRecord{NodeID: p.NodeID, Port: p.Port})
inIP := ""
if p.InIP.Valid {
inIP = p.InIP.String
}
rows = append(rows, model.ForwardPortRecord{NodeID: p.NodeID, Port: p.Port, InIP: inIP})
}
return rows, nil
}
func (r *Repository) HasOtherForwardOnNodePort(nodeID int64, port int, currentForwardID int64) (bool, error) {
if r == nil || r.db == nil {
return false, errors.New("repository not initialized")
}
if nodeID <= 0 || port <= 0 {
return false, nil
}
var count int64
err := r.db.Model(&model.ForwardPort{}).
Where("node_id = ? AND port = ? AND forward_id <> ?", nodeID, port, currentForwardID).
Count(&count).Error
if err != nil {
return false, err
}
return count > 0, nil
}
func (r *Repository) GetTunnelOutProtocol(tunnelID int64) (string, error) {
if r == nil || r.db == nil {
return "", errors.New("repository not initialized")
@@ -176,6 +200,9 @@ func nodeRecordFromModel(n *model.Node) *model.NodeRecord {
if n.ServerIPV6.Valid {
rec.ServerIPv6 = strings.TrimSpace(n.ServerIPV6.String)
}
if n.ExtraIPs.Valid {
rec.ExtraIPs = strings.TrimSpace(n.ExtraIPs.String)
}
if n.InterfaceName.Valid {
rec.InterfaceName = strings.TrimSpace(n.InterfaceName.String)
}
@@ -288,10 +315,11 @@ func (r *Repository) ListChainNodesForTunnel(tunnelID int64) ([]model.ChainNodeR
Name sql.NullString
Protocol sql.NullString
Strategy sql.NullString
ConnectIP sql.NullString
}
var rows []row
err := r.db.Model(&model.ChainTunnel{}).
Select("chain_tunnel.chain_type, chain_tunnel.inx, chain_tunnel.node_id, chain_tunnel.port, node.name, chain_tunnel.protocol, chain_tunnel.strategy").
Select("chain_tunnel.chain_type, chain_tunnel.inx, chain_tunnel.node_id, chain_tunnel.port, node.name, chain_tunnel.protocol, chain_tunnel.strategy, chain_tunnel.connect_ip").
Joins("LEFT JOIN node ON node.id = chain_tunnel.node_id").
Where("chain_tunnel.tunnel_id = ?", tunnelID).
Order("chain_tunnel.chain_type ASC, chain_tunnel.inx ASC, chain_tunnel.id ASC").
@@ -336,6 +364,9 @@ func (r *Repository) ListChainNodesForTunnel(tunnelID int64) ([]model.ChainNodeR
} else {
item.Strategy = row.Strategy.String
}
if row.ConnectIP.Valid {
item.ConnectIP = row.ConnectIP.String
}
result = append(result, item)
}
return result, nil
@@ -228,7 +228,6 @@ func (r *Repository) ListTunnelIDsByNamePrefix(prefix string) ([]int64, error) {
return ids, nil
}
// NextIndex returns COALESCE(MAX(inx), -1) + 1 for the given table.
func (r *Repository) NextIndex(table string) int {
if r == nil || r.db == nil {
return 0
@@ -251,7 +250,7 @@ func (r *Repository) NextIndex(table string) int {
var row inxRow
err := r.db.Model(modelRef).
Select("inx").
Order("inx DESC").
Order("inx ASC, id ASC").
Limit(1).
Take(&row).Error
if errors.Is(err, gorm.ErrRecordNotFound) {
@@ -260,10 +259,7 @@ func (r *Repository) NextIndex(table string) int {
if err != nil {
return 0
}
if row.Inx < 0 {
return 0
}
return row.Inx + 1
return row.Inx - 1
}
// CreateRemoteNode inserts a new remote node.
@@ -38,6 +38,7 @@ func (r *Repository) ListActiveForwardsByUser(userID int64) ([]model.ForwardReco
RemoteAddr: f.RemoteAddr,
Strategy: f.Strategy,
Status: f.Status,
SpeedID: f.SpeedID,
})
}
for i := range rows {
@@ -68,6 +69,7 @@ func (r *Repository) ListActiveForwardsByUserTunnel(userID, tunnelID int64) ([]m
RemoteAddr: f.RemoteAddr,
Strategy: f.Strategy,
Status: f.Status,
SpeedID: f.SpeedID,
})
}
for i := range rows {
@@ -99,6 +101,7 @@ func (r *Repository) GetForwardRecord(forwardID int64) (*model.ForwardRecord, er
RemoteAddr: f.RemoteAddr,
Strategy: f.Strategy,
Status: f.Status,
SpeedID: f.SpeedID,
}
if strings.TrimSpace(fr.Strategy) == "" {
fr.Strategy = "fifo"
@@ -169,3 +172,15 @@ func (r *Repository) SpeedLimitExists(id int64) (bool, error) {
}
return count > 0, nil
}
func (r *Repository) GetSpeedLimitSpeed(id int64) (int, error) {
if r == nil || r.db == nil {
return 0, errors.New("repository not initialized")
}
var sl model.SpeedLimit
err := r.db.Select("speed").Where("id = ?", id).First(&sl).Error
if err != nil {
return 0, err
}
return sl.Speed, nil
}
@@ -1,6 +1,7 @@
package repo
import (
"database/sql"
"errors"
"testing"
@@ -83,3 +84,169 @@ func TestMigrateSchemaReturnsPostgresIDRepairError(t *testing.T) {
t.Fatalf("expected error %v, got %v", wantErr, err)
}
}
func TestMigrateSchemaRunsViteConfigValueMigrationForLegacySchema(t *testing.T) {
db, err := gorm.Open(gsqlite.Open(":memory:"), &gorm.Config{
Logger: logger.Default.LogMode(logger.Silent),
})
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() {
sqlDB, _ := db.DB()
if sqlDB != nil {
_ = sqlDB.Close()
}
})
if err := db.Exec(`CREATE TABLE schema_version (version INTEGER NOT NULL DEFAULT 0)`).Error; err != nil {
t.Fatalf("create schema_version: %v", err)
}
if err := db.Exec(`INSERT INTO schema_version(version) VALUES(?)`, 2).Error; err != nil {
t.Fatalf("seed schema_version: %v", err)
}
originalIDRepair := ensurePostgresIDDefaultsFn
ensurePostgresIDDefaultsFn = func(db *gorm.DB) error {
return nil
}
t.Cleanup(func() {
ensurePostgresIDDefaultsFn = originalIDRepair
})
called := 0
originalMigrate := migrateViteConfigValueColumnTypeFn
migrateViteConfigValueColumnTypeFn = func(db *gorm.DB) error {
called++
return nil
}
t.Cleanup(func() {
migrateViteConfigValueColumnTypeFn = originalMigrate
})
if err := migrateSchema(db); err != nil {
t.Fatalf("migrateSchema: %v", err)
}
if called != 1 {
t.Fatalf("expected vite_config migration to run once, got %d", called)
}
}
func TestMigrateSchemaReturnsViteConfigMigrationError(t *testing.T) {
db, err := gorm.Open(gsqlite.Open(":memory:"), &gorm.Config{
Logger: logger.Default.LogMode(logger.Silent),
})
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() {
sqlDB, _ := db.DB()
if sqlDB != nil {
_ = sqlDB.Close()
}
})
if err := db.Exec(`CREATE TABLE schema_version (version INTEGER NOT NULL DEFAULT 0)`).Error; err != nil {
t.Fatalf("create schema_version: %v", err)
}
if err := db.Exec(`INSERT INTO schema_version(version) VALUES(?)`, 2).Error; err != nil {
t.Fatalf("seed schema_version: %v", err)
}
originalIDRepair := ensurePostgresIDDefaultsFn
ensurePostgresIDDefaultsFn = func(db *gorm.DB) error {
return nil
}
t.Cleanup(func() {
ensurePostgresIDDefaultsFn = originalIDRepair
})
wantErr := errors.New("vite config migration failed")
originalMigrate := migrateViteConfigValueColumnTypeFn
migrateViteConfigValueColumnTypeFn = func(db *gorm.DB) error {
return wantErr
}
t.Cleanup(func() {
migrateViteConfigValueColumnTypeFn = originalMigrate
})
err = migrateSchema(db)
if !errors.Is(err, wantErr) {
t.Fatalf("expected error %v, got %v", wantErr, err)
}
}
func TestMigrateSchemaClearsSpeedLimitTunnelBinding(t *testing.T) {
db, err := gorm.Open(gsqlite.Open(":memory:"), &gorm.Config{
Logger: logger.Default.LogMode(logger.Silent),
})
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() {
sqlDB, _ := db.DB()
if sqlDB != nil {
_ = sqlDB.Close()
}
})
if err := db.Exec(`CREATE TABLE schema_version (version INTEGER NOT NULL DEFAULT 0)`).Error; err != nil {
t.Fatalf("create schema_version: %v", err)
}
if err := db.Exec(`INSERT INTO schema_version(version) VALUES(?)`, 3).Error; err != nil {
t.Fatalf("seed schema_version: %v", err)
}
if err := db.Exec(`
CREATE TABLE speed_limit (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name VARCHAR(100) NOT NULL,
speed INTEGER NOT NULL,
tunnel_id INTEGER,
tunnel_name VARCHAR(100),
created_time INTEGER NOT NULL,
updated_time INTEGER,
status INTEGER NOT NULL
)
`).Error; err != nil {
t.Fatalf("create speed_limit: %v", err)
}
if err := db.Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, ?, ?, ?, ?, ?)
`, "legacy-speed-limit", 100, 101, "legacy-tunnel", 1, 1, 1).Error; err != nil {
t.Fatalf("seed speed_limit: %v", err)
}
originalIDRepair := ensurePostgresIDDefaultsFn
ensurePostgresIDDefaultsFn = func(db *gorm.DB) error {
return nil
}
t.Cleanup(func() {
ensurePostgresIDDefaultsFn = originalIDRepair
})
if err := migrateSchema(db); err != nil {
t.Fatalf("migrateSchema: %v", err)
}
var tunnelID sql.NullInt64
var tunnelName sql.NullString
if err := db.Raw(`SELECT tunnel_id, tunnel_name FROM speed_limit WHERE name = ?`, "legacy-speed-limit").Row().Scan(&tunnelID, &tunnelName); err != nil {
t.Fatalf("query speed_limit: %v", err)
}
if tunnelID.Valid {
t.Fatalf("expected tunnel_id cleared to NULL, got %d", tunnelID.Int64)
}
if tunnelName.Valid {
t.Fatalf("expected tunnel_name cleared to NULL, got %q", tunnelName.String)
}
var schemaVersion int
if err := db.Raw(`SELECT version FROM schema_version LIMIT 1`).Row().Scan(&schemaVersion); err != nil {
t.Fatalf("query schema_version: %v", err)
}
if schemaVersion != currentSchemaVersion {
t.Fatalf("expected schema version %d, got %d", currentSchemaVersion, schemaVersion)
}
}
@@ -196,7 +196,7 @@ func (r *Repository) GetUserDefaultsForTunnel(userID int64) (flow int64, num int
return user.Flow, user.Num, user.ExpTime, user.FlowResetTime, nil
}
func (r *Repository) CreateNode(name, secret, serverIP string, serverIPV4, serverIPV6, port, interfaceName, version interface{}, httpFlag, tlsFlag, socksFlag int, now int64, status int, tcpAddr, udpAddr string, inx, isRemote int, remoteURL, remoteToken, remoteConfig interface{}) error {
func (r *Repository) CreateNode(name, secret, serverIP string, serverIPV4, serverIPV6, port, interfaceName, version interface{}, httpFlag, tlsFlag, socksFlag int, now int64, status int, tcpAddr, udpAddr string, inx, isRemote int, remoteURL, remoteToken, remoteConfig, extraIPs interface{}) error {
if r == nil || r.db == nil {
return errors.New("repository not initialized")
}
@@ -206,6 +206,7 @@ func (r *Repository) CreateNode(name, secret, serverIP string, serverIPV4, serve
ServerIP: serverIP,
ServerIPV4: nullStringFromInterface(serverIPV4),
ServerIPV6: nullStringFromInterface(serverIPV6),
ExtraIPs: nullStringFromInterface(extraIPs),
Port: stringFromInterface(port),
InterfaceName: nullStringFromInterface(interfaceName),
Version: nullStringFromInterface(version),
@@ -238,7 +239,7 @@ func (r *Repository) GetNodeStatusFields(nodeID int64) (status, httpFlag, tlsFla
return node.Status, node.HTTP, node.TLS, node.Socks, nil
}
func (r *Repository) UpdateNode(id int64, name, serverIP string, serverIPV4, serverIPV6, port, interfaceName interface{}, httpFlag, tlsFlag, socksFlag int, tcpAddr, udpAddr string, now int64) error {
func (r *Repository) UpdateNode(id int64, name, serverIP string, serverIPV4, serverIPV6, port, interfaceName, extraIPs interface{}, httpFlag, tlsFlag, socksFlag int, tcpAddr, udpAddr string, now int64) error {
if r == nil || r.db == nil {
return errors.New("repository not initialized")
}
@@ -249,6 +250,7 @@ func (r *Repository) UpdateNode(id int64, name, serverIP string, serverIPV4, ser
"server_ip": serverIP,
"server_ip_v4": nullStringFromInterface(serverIPV4),
"server_ip_v6": nullStringFromInterface(serverIPV6),
"extra_ips": nullStringFromInterface(extraIPs),
"port": stringFromInterface(port),
"interface_name": nullStringFromInterface(interfaceName),
"http": httpFlag,
@@ -395,7 +397,7 @@ func (r *Repository) DeleteChainTunnelsByTunnelTx(tx *gorm.DB, tunnelID int64) e
return tx.Where("tunnel_id = ?", tunnelID).Delete(&model.ChainTunnel{}).Error
}
func (r *Repository) CreateChainTunnelTx(tx *gorm.DB, tunnelID int64, chainType string, nodeID int64, port sql.NullInt64, strategy string, inx int, protocol string) error {
func (r *Repository) CreateChainTunnelTx(tx *gorm.DB, tunnelID int64, chainType string, nodeID int64, port sql.NullInt64, strategy string, inx int, protocol string, connectIp string) error {
if tx == nil {
return errors.New("database unavailable")
}
@@ -407,6 +409,7 @@ func (r *Repository) CreateChainTunnelTx(tx *gorm.DB, tunnelID int64, chainType
Strategy: nullStringFromInterface(strategy),
Inx: nullInt64FromInterface(inx),
Protocol: nullStringFromInterface(protocol),
ConnectIP: sql.NullString{String: connectIp, Valid: connectIp != ""},
}
return tx.Create(&ct).Error
}
@@ -522,9 +525,6 @@ func (r *Repository) DeleteTunnelCascade(tunnelID int64) error {
if err := tx.Where("tunnel_id = ?", tunnelID).Delete(&model.UserTunnel{}).Error; err != nil {
return err
}
if err := tx.Where("tunnel_id = ?", tunnelID).Delete(&model.SpeedLimit{}).Error; err != nil {
return err
}
if err := tx.Where("tunnel_id = ?", tunnelID).Delete(&model.ChainTunnel{}).Error; err != nil {
return err
}
@@ -535,17 +535,6 @@ func (r *Repository) DeleteTunnelCascade(tunnelID int64) error {
})
}
func (r *Repository) GetTunnelNameByID(tunnelID int64) string {
if r == nil || r.db == nil {
return ""
}
var tunnel model.Tunnel
if err := r.db.Select("name").Where("id = ?", tunnelID).First(&tunnel).Error; err != nil {
return ""
}
return tunnel.Name
}
func (r *Repository) TunnelEntryNodeIDs(tunnelID int64) ([]int64, error) {
if r == nil || r.db == nil {
return nil, errors.New("repository not initialized")
@@ -657,7 +646,7 @@ func (r *Repository) GetMinForwardPort(forwardID int64) sql.NullInt64 {
return p
}
func (r *Repository) UpdateForward(id int64, name string, tunnelID int64, remoteAddr, strategy string, now int64) error {
func (r *Repository) UpdateForward(id int64, name string, tunnelID int64, remoteAddr, strategy string, now int64, speedID interface{}) error {
if r == nil || r.db == nil {
return errors.New("repository not initialized")
}
@@ -668,6 +657,7 @@ func (r *Repository) UpdateForward(id int64, name string, tunnelID int64, remote
"tunnel_id": tunnelID,
"remote_addr": remoteAddr,
"strategy": strategy,
"speed_id": nullInt64FromInterface(speedID),
"updated_time": now,
}).Error
}
@@ -705,6 +695,7 @@ func (r *Repository) DeleteForwardCascade(forwardID int64) error {
func (r *Repository) ReplaceForwardPorts(forwardID int64, entries []struct {
NodeID int64
Port int
InIP string
}) error {
if r == nil || r.db == nil {
return errors.New("repository not initialized")
@@ -718,13 +709,18 @@ func (r *Repository) ReplaceForwardPorts(forwardID int64, entries []struct {
}
rows := make([]model.ForwardPort, 0, len(entries))
for _, e := range entries {
rows = append(rows, model.ForwardPort{ForwardID: forwardID, NodeID: e.NodeID, Port: e.Port})
rows = append(rows, model.ForwardPort{
ForwardID: forwardID,
NodeID: e.NodeID,
Port: e.Port,
InIP: sql.NullString{String: e.InIP, Valid: e.InIP != ""},
})
}
return tx.Create(&rows).Error
})
}
func (r *Repository) RollbackForwardFields(id, userID int64, userName, name string, tunnelID int64, remoteAddr, strategy string, status int, now int64) {
func (r *Repository) RollbackForwardFields(id, userID int64, userName, name string, tunnelID int64, remoteAddr, strategy string, status int, speedID interface{}, now int64) {
if r == nil || r.db == nil {
return
}
@@ -738,6 +734,7 @@ func (r *Repository) RollbackForwardFields(id, userID int64, userName, name stri
"remote_addr": remoteAddr,
"strategy": strategy,
"status": status,
"speed_id": nullInt64FromInterface(speedID),
"updated_time": now,
}).Error
}
@@ -764,15 +761,15 @@ func (r *Repository) GetUsedPortsOnNodeAsMap(nodeID int64) (map[int]bool, error)
return used, nil
}
func (r *Repository) CreateSpeedLimit(name string, speed int, tunnelID int64, tunnelName string, now int64, status int) (int64, error) {
func (r *Repository) CreateSpeedLimit(name string, speed int, now int64, status int) (int64, error) {
if r == nil || r.db == nil {
return 0, errors.New("repository not initialized")
}
sl := model.SpeedLimit{
Name: name,
Speed: speed,
TunnelID: tunnelID,
TunnelName: tunnelName,
TunnelID: sql.NullInt64{Int64: 0, Valid: false},
TunnelName: sql.NullString{String: "", Valid: false},
CreatedTime: now,
UpdatedTime: sql.NullInt64{Int64: now, Valid: true},
Status: status,
@@ -783,34 +780,24 @@ func (r *Repository) CreateSpeedLimit(name string, speed int, tunnelID int64, tu
return sl.ID, nil
}
func (r *Repository) UpdateSpeedLimit(id int64, name string, speed int, tunnelID int64, tunnelName string, status int, now int64) error {
func (r *Repository) UpdateSpeedLimit(id int64, name string, speed int, status int, now int64) error {
if r == nil || r.db == nil {
return errors.New("repository not initialized")
}
updates := map[string]interface{}{
"name": name,
"speed": speed,
"status": status,
"tunnel_id": nil,
"tunnel_name": nil,
"updated_time": sql.NullInt64{
Int64: now,
Valid: true,
},
}
return r.db.Model(&model.SpeedLimit{}).
Where("id = ?", id).
Updates(map[string]interface{}{
"name": name,
"speed": speed,
"tunnel_id": tunnelID,
"tunnel_name": tunnelName,
"status": status,
"updated_time": sql.NullInt64{
Int64: now,
Valid: true,
},
}).Error
}
func (r *Repository) GetSpeedLimitTunnelID(speedLimitID int64) int64 {
if r == nil || r.db == nil {
return 0
}
var sl model.SpeedLimit
if err := r.db.Select("tunnel_id").Where("id = ?", speedLimitID).First(&sl).Error; err != nil {
return 0
}
return sl.TunnelID
Updates(updates).Error
}
func (r *Repository) DeleteSpeedLimit(id int64) error {
@@ -1190,7 +1177,7 @@ func (r *Repository) EnsureUserTunnelGrant(userID, tunnelID int64) (int64, bool,
return ut.ID, true, nil
}
func (r *Repository) CreateForwardTx(userID int64, userName, name string, tunnelID int64, remoteAddr, strategy string, now int64, inx int, entryNodeIDs []int64, port int) (int64, error) {
func (r *Repository) CreateForwardTx(userID int64, userName, name string, tunnelID int64, remoteAddr, strategy string, now int64, inx int, entryNodeIDs []int64, port int, inIp string, speedID interface{}) (int64, error) {
if r == nil || r.db == nil {
return 0, errors.New("repository not initialized")
}
@@ -1209,6 +1196,7 @@ func (r *Repository) CreateForwardTx(userID int64, userName, name string, tunnel
UpdatedTime: now,
Status: 1,
Inx: inx,
SpeedID: nullInt64FromInterface(speedID),
}
if err := tx.Create(&fwd).Error; err != nil {
return err
@@ -1219,6 +1207,7 @@ func (r *Repository) CreateForwardTx(userID int64, userName, name string, tunnel
ForwardID: forwardID,
NodeID: nodeID,
Port: port,
InIP: sql.NullString{String: inIp, Valid: inIp != ""},
}
if err := tx.Create(&fp).Error; err != nil {
return err
@@ -1,19 +0,0 @@
package contract
import (
"testing"
"go-backend/internal/store/repo"
)
func mustLastInsertID(t *testing.T, r *repo.Repository, label string) int64 {
t.Helper()
var id int64
if err := r.DB().Raw("SELECT last_insert_rowid()").Row().Scan(&id); err != nil {
t.Fatalf("read last_insert_rowid for %s: %v", label, err)
}
if id <= 0 {
t.Fatalf("invalid last_insert_rowid for %s: %d", label, id)
}
return id
}
@@ -2,6 +2,8 @@ package contract_test
import (
"database/sql"
"strconv"
"strings"
"testing"
"go-backend/internal/store/repo"
@@ -117,3 +119,43 @@ func tryQueryInt(t *testing.T, r *repo.Repository, query string, args ...interfa
}
return v, nil
}
func valueAsInt(v interface{}) int {
switch n := v.(type) {
case float64:
return int(n)
case int:
return n
case int64:
return int(n)
default:
return 0
}
}
func valueAsString(v interface{}) string {
s, _ := v.(string)
return s
}
func valueAsBool(v interface{}) bool {
switch b := v.(type) {
case bool:
return b
case float64:
return b != 0
case int:
return b != 0
case int64:
return b != 0
case string:
s := strings.TrimSpace(strings.ToLower(b))
return s == "1" || s == "t" || s == "true" || s == "yes" || s == "y"
default:
return false
}
}
func jsonInt64(v int64) string {
return strconv.FormatInt(v, 10)
}
@@ -1,11 +1,11 @@
package contract
package contract_test
import (
"bufio"
"bytes"
"encoding/json"
"net/http"
"net/http/httptest"
"path/filepath"
"strconv"
"strings"
"sync/atomic"
@@ -13,15 +13,12 @@ import (
"time"
"go-backend/internal/auth"
httpserver "go-backend/internal/http"
"go-backend/internal/http/handler"
"go-backend/internal/http/response"
"go-backend/internal/store/repo"
)
func TestDiagnosisChainCoverageContracts(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupDiagnosisContractRouter(t, secret)
router, r := setupContractRouter(t, secret)
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
@@ -195,7 +192,7 @@ func TestDiagnosisChainCoverageContracts(t *testing.T) {
func TestForwardDiagnosisRespectsTunnelIPPreferenceContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupDiagnosisContractRouter(t, secret)
router, r := setupContractRouter(t, secret)
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
@@ -315,7 +312,7 @@ func TestForwardDiagnosisRespectsTunnelIPPreferenceContract(t *testing.T) {
func TestDiagnosisUsesFederationRuntimeForRemoteNodes(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupDiagnosisContractRouter(t, secret)
router, r := setupContractRouter(t, secret)
now := time.Now().UnixMilli()
remoteToken := "remote-diagnose-token"
@@ -466,53 +463,166 @@ func TestDiagnosisUsesFederationRuntimeForRemoteNodes(t *testing.T) {
}
}
func valueAsInt(v interface{}) int {
switch n := v.(type) {
case float64:
return int(n)
case int:
return n
case int64:
return int(n)
default:
return 0
func TestTunnelDiagnosisUsesConfiguredConnectIPContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
now := time.Now().UnixMilli()
insertNode := func(name, ip string) int64 {
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, name, name+"-secret", ip, ip, "", "30000-30010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node %s: %v", name, err)
}
return mustLastInsertID(t, r, name)
}
}
func valueAsString(v interface{}) string {
s, _ := v.(string)
return s
}
entryNodeID := insertNode("entry-connectip", "10.80.0.10")
middleNodeID := insertNode("middle-connectip", "10.80.0.20")
exitNodeID := insertNode("exit-connectip", "10.80.0.30")
func valueAsBool(v interface{}) bool {
switch b := v.(type) {
case bool:
return b
case float64:
return b != 0
case int:
return b != 0
case int64:
return b != 0
case string:
s := strings.TrimSpace(strings.ToLower(b))
return s == "1" || s == "t" || s == "true" || s == "yes" || s == "y"
default:
return false
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "diagnose-connectip-tunnel", 1.0, 2, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
}
tunnelID := mustLastInsertID(t, r, "diagnose-connectip-tunnel")
func setupDiagnosisContractRouter(t *testing.T, jwtSecret string) (http.Handler, *repo.Repository) {
t.Helper()
dbPath := filepath.Join(t.TempDir(), "diagnosis-contract.db")
r, err := repo.Open(dbPath)
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 30001, 'round', 1, 'tls')
`, tunnelID, entryNodeID).Error; err != nil {
t.Fatalf("insert entry chain: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol, connect_ip)
VALUES(?, 2, ?, 30002, 'round', 1, 'tls', ?)
`, tunnelID, middleNodeID, "10.99.0.22").Error; err != nil {
t.Fatalf("insert middle chain: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol, connect_ip)
VALUES(?, 3, ?, 30003, 'round', 1, 'tls', ?)
`, tunnelID, exitNodeID, "10.99.0.33").Error; err != nil {
t.Fatalf("insert exit chain: %v", err)
}
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("open sqlite: %v", err)
t.Fatalf("generate admin token: %v", err)
}
t.Cleanup(func() {
_ = r.Close()
t.Run("normal diagnose should use configured connectIp", func(t *testing.T) {
req := httptest.NewRequest(http.MethodPost, "/api/v1/tunnel/diagnose", bytes.NewBufferString(`{"tunnelId":`+strconv.FormatInt(tunnelID, 10)+`}`))
req.Header.Set("Authorization", adminToken)
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected code 0, got %d (%s)", out.Code, out.Msg)
}
payload, ok := out.Data.(map[string]interface{})
if !ok {
t.Fatalf("expected object payload, got %T", out.Data)
}
results, ok := payload["results"].([]interface{})
if !ok || len(results) == 0 {
t.Fatalf("expected non-empty results, got %v", payload["results"])
}
entryToMiddleOK := false
middleToExitOK := false
for _, raw := range results {
item, ok := raw.(map[string]interface{})
if !ok {
continue
}
from := valueAsInt(item["fromChainType"])
to := valueAsInt(item["toChainType"])
targetIP := strings.TrimSpace(valueAsString(item["targetIp"]))
if from == 1 && to == 2 && targetIP == "10.99.0.22" {
entryToMiddleOK = true
}
if from == 2 && to == 3 && targetIP == "10.99.0.33" {
middleToExitOK = true
}
}
if !entryToMiddleOK || !middleToExitOK {
t.Fatalf("expected connectIp targets 10.99.0.22/10.99.0.33, got entry=%v middle=%v", entryToMiddleOK, middleToExitOK)
}
})
h := handler.New(r, jwtSecret)
return httpserver.NewRouter(h, jwtSecret), r
t.Run("stream diagnose start items should use configured connectIp", func(t *testing.T) {
req := httptest.NewRequest(http.MethodPost, "/api/v1/tunnel/diagnose/stream", bytes.NewBufferString(`{"tunnelId":`+strconv.FormatInt(tunnelID, 10)+`}`))
req.Header.Set("Authorization", adminToken)
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
if res.Code != http.StatusOK {
t.Fatalf("expected status 200, got %d", res.Code)
}
scanner := bufio.NewScanner(bytes.NewReader(res.Body.Bytes()))
startFound := false
entryToMiddleOK := false
middleToExitOK := false
for scanner.Scan() {
line := strings.TrimSpace(scanner.Text())
if line == "" {
continue
}
var event map[string]interface{}
if err := json.Unmarshal([]byte(line), &event); err != nil {
continue
}
if strings.TrimSpace(valueAsString(event["type"])) != "start" {
continue
}
startFound = true
data, ok := event["data"].(map[string]interface{})
if !ok {
break
}
items, ok := data["items"].([]interface{})
if !ok {
break
}
for _, raw := range items {
item, ok := raw.(map[string]interface{})
if !ok {
continue
}
from := valueAsInt(item["fromChainType"])
to := valueAsInt(item["toChainType"])
targetIP := strings.TrimSpace(valueAsString(item["targetIp"]))
if from == 1 && to == 2 && targetIP == "10.99.0.22" {
entryToMiddleOK = true
}
if from == 2 && to == 3 && targetIP == "10.99.0.33" {
middleToExitOK = true
}
}
break
}
if err := scanner.Err(); err != nil {
t.Fatalf("scan stream body: %v", err)
}
if !startFound {
t.Fatalf("expected start event in stream response")
}
if !entryToMiddleOK || !middleToExitOK {
t.Fatalf("expected start items with connectIp targets 10.99.0.22/10.99.0.33, got entry=%v middle=%v", entryToMiddleOK, middleToExitOK)
}
})
}
@@ -624,42 +624,6 @@ func waitNodeStatus(t *testing.T, r *repo.Repository, nodeID int64, expectedStat
}
}
func valueAsInt(v interface{}) int {
switch n := v.(type) {
case float64:
return int(n)
case int:
return n
case int64:
return int(n)
default:
return 0
}
}
func valueAsString(v interface{}) string {
s, _ := v.(string)
return s
}
func valueAsBool(v interface{}) bool {
switch b := v.(type) {
case bool:
return b
case float64:
return b != 0
case int:
return b != 0
case int64:
return b != 0
case string:
s := strings.TrimSpace(strings.ToLower(b))
return s == "1" || s == "t" || s == "true" || s == "yes" || s == "y"
default:
return false
}
}
func TestFederationRuntimeCommandPortRangeEnforcement(t *testing.T) {
providerSecret := "provider-portrange-jwt"
providerRouter, providerRepo := setupContractRouter(t, providerSecret)
@@ -759,6 +723,21 @@ func TestFederationRuntimeCommandPortRangeEnforcement(t *testing.T) {
}
// Test: Non-service commands should pass through without port validation
res = sendCommand("share-portrange-token", "UpdateLimiters", map[string]interface{}{
"limiter": "federation-limit-test",
"data": map[string]interface{}{
"name": "federation-limit-test",
"limits": []string{"$ 1MB 1MB"},
},
})
out = response.R{}
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected code 0 for UpdateLimiters command, got %d (msg: %s)", out.Code, out.Msg)
}
res = sendCommand("share-portrange-token", "reload", nil)
out = response.R{}
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
@@ -2,6 +2,7 @@ package contract_test
import (
"bytes"
"database/sql"
"encoding/json"
"net/http"
"net/http/httptest"
@@ -108,7 +109,11 @@ func TestForwardOwnershipAndScopeContracts(t *testing.T) {
if !ok {
t.Fatalf("expected object item, got %T", arr[0])
}
if got := int64(item["id"].(float64)); got != userForwardID {
idFloat, ok := item["id"].(float64)
if !ok {
t.Fatalf("expected id to be float64, got %T", item["id"])
}
if got := int64(idFloat); got != userForwardID {
t.Fatalf("expected forward id %d, got %d", userForwardID, got)
}
})
@@ -143,7 +148,11 @@ func TestForwardOwnershipAndScopeContracts(t *testing.T) {
if _, ok := first["message"]; !ok {
t.Fatalf("expected message field in diagnosis result")
}
if got := int(first["fromChainType"].(float64)); got != 1 {
fromChainTypeFloat, ok := first["fromChainType"].(float64)
if !ok {
t.Fatalf("expected fromChainType to be float64, got %T", first["fromChainType"])
}
if got := int(fromChainTypeFloat); got != 1 {
t.Fatalf("expected fromChainType=1, got %d", got)
}
})
@@ -471,6 +480,234 @@ func TestUserTunnelReassignmentKeepsStableID(t *testing.T) {
}
}
func TestForwardSpeedIDWriteAndClearContracts(t *testing.T) {
secret := "contract-jwt-secret"
router, repo := setupContractRouter(t, secret)
now := time.Now().UnixMilli()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
if err := repo.DB().Exec(`
INSERT INTO user(id, user, pwd, role_id, exp_time, flow, in_flow, out_flow, flow_reset_time, num, created_time, updated_time, status)
VALUES(2, 'speed_user', '3c85cdebade1c51cf64ca9f3c09d182d', 1, 2727251700000, 99999, 0, 0, 1, 99999, ?, ?, 1)
`, now, now).Error; err != nil {
t.Fatalf("insert user: %v", err)
}
if err := repo.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "forward-speed-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, repo, "forward-speed-tunnel")
if err := repo.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "forward-speed-node", "forward-speed-secret", "10.30.0.1", "10.30.0.1", "", "31000-31010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, repo, "forward-speed-node")
if err := repo.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 31001, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
if err := repo.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "forward-speed-limit-a", 2048, now, 1).Error; err != nil {
t.Fatalf("insert speed limit a: %v", err)
}
speedIDA := mustLastInsertID(t, repo, "forward-speed-limit-a")
if err := repo.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "forward-speed-limit-b", 4096, now, 1).Error; err != nil {
t.Fatalf("insert speed limit b: %v", err)
}
speedIDB := mustLastInsertID(t, repo, "forward-speed-limit-b")
server := httptest.NewServer(router)
defer server.Close()
stopNode := startMockNodeSession(t, server.URL, "forward-speed-secret")
defer stopNode()
createPayload := map[string]interface{}{
"name": "forward-speed-target",
"tunnelId": tunnelID,
"remoteAddr": "1.1.1.1:443",
"strategy": "fifo",
"speedId": speedIDA,
}
createBody, err := json.Marshal(createPayload)
if err != nil {
t.Fatalf("marshal create payload: %v", err)
}
createReq := httptest.NewRequest(http.MethodPost, "/api/v1/forward/create", bytes.NewReader(createBody))
createReq.Header.Set("Authorization", adminToken)
createReq.Header.Set("Content-Type", "application/json")
createRes := httptest.NewRecorder()
router.ServeHTTP(createRes, createReq)
assertCode(t, createRes, 0)
forwardID := mustLastInsertID(t, repo, "forward-speed-target")
storedSpeed := repo.DB().Raw(`SELECT speed_id FROM forward WHERE id = ?`, forwardID).Row()
var createdSpeed sql.NullInt64
if err := storedSpeed.Scan(&createdSpeed); err != nil {
t.Fatalf("query created forward speed_id: %v", err)
}
if !createdSpeed.Valid || createdSpeed.Int64 != speedIDA {
t.Fatalf("expected created speed_id=%d, got valid=%v value=%d", speedIDA, createdSpeed.Valid, createdSpeed.Int64)
}
updateToBPayload := map[string]interface{}{
"id": forwardID,
"speedId": speedIDB,
}
updateToBBody, err := json.Marshal(updateToBPayload)
if err != nil {
t.Fatalf("marshal update-to-b payload: %v", err)
}
updateToBReq := httptest.NewRequest(http.MethodPost, "/api/v1/forward/update", bytes.NewReader(updateToBBody))
updateToBReq.Header.Set("Authorization", adminToken)
updateToBReq.Header.Set("Content-Type", "application/json")
updateToBRes := httptest.NewRecorder()
router.ServeHTTP(updateToBRes, updateToBReq)
assertCode(t, updateToBRes, 0)
storedSpeed = repo.DB().Raw(`SELECT speed_id FROM forward WHERE id = ?`, forwardID).Row()
var updatedSpeed sql.NullInt64
if err := storedSpeed.Scan(&updatedSpeed); err != nil {
t.Fatalf("query updated forward speed_id: %v", err)
}
if !updatedSpeed.Valid || updatedSpeed.Int64 != speedIDB {
t.Fatalf("expected updated speed_id=%d, got valid=%v value=%d", speedIDB, updatedSpeed.Valid, updatedSpeed.Int64)
}
clearPayload := map[string]interface{}{
"id": forwardID,
"speedId": nil,
}
clearBody, err := json.Marshal(clearPayload)
if err != nil {
t.Fatalf("marshal clear payload: %v", err)
}
clearReq := httptest.NewRequest(http.MethodPost, "/api/v1/forward/update", bytes.NewReader(clearBody))
clearReq.Header.Set("Authorization", adminToken)
clearReq.Header.Set("Content-Type", "application/json")
clearRes := httptest.NewRecorder()
router.ServeHTTP(clearRes, clearReq)
assertCode(t, clearRes, 0)
storedSpeed = repo.DB().Raw(`SELECT speed_id FROM forward WHERE id = ?`, forwardID).Row()
var clearedSpeed sql.NullInt64
if err := storedSpeed.Scan(&clearedSpeed); err != nil {
t.Fatalf("query cleared forward speed_id: %v", err)
}
if clearedSpeed.Valid {
t.Fatalf("expected cleared speed_id to be NULL, got %d", clearedSpeed.Int64)
}
}
func TestForwardCreateThenPauseResumeContract(t *testing.T) {
secret := "contract-jwt-secret"
router, repo := setupContractRouter(t, secret)
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := repo.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "forward-toggle-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, repo, "forward-toggle-tunnel")
if err := repo.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "forward-toggle-node", "forward-toggle-secret", "10.31.0.1", "10.31.0.1", "", "41000-41010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, repo, "forward-toggle-node")
if err := repo.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 41001, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
server := httptest.NewServer(router)
defer server.Close()
stopNode := startMockNodeSession(t, server.URL, "forward-toggle-secret")
defer stopNode()
createPayload := map[string]interface{}{
"name": "forward-toggle-target",
"tunnelId": tunnelID,
"remoteAddr": "1.1.1.1:443",
"strategy": "fifo",
}
createBody, err := json.Marshal(createPayload)
if err != nil {
t.Fatalf("marshal create payload: %v", err)
}
createReq := httptest.NewRequest(http.MethodPost, "/api/v1/forward/create", bytes.NewReader(createBody))
createReq.Header.Set("Authorization", adminToken)
createReq.Header.Set("Content-Type", "application/json")
createRes := httptest.NewRecorder()
router.ServeHTTP(createRes, createReq)
assertCode(t, createRes, 0)
forwardID := mustLastInsertID(t, repo, "forward-toggle-target")
pauseBody, err := json.Marshal(map[string]interface{}{"id": forwardID})
if err != nil {
t.Fatalf("marshal pause payload: %v", err)
}
pauseReq := httptest.NewRequest(http.MethodPost, "/api/v1/forward/pause", bytes.NewReader(pauseBody))
pauseReq.Header.Set("Authorization", adminToken)
pauseReq.Header.Set("Content-Type", "application/json")
pauseRes := httptest.NewRecorder()
router.ServeHTTP(pauseRes, pauseReq)
assertCode(t, pauseRes, 0)
pausedStatus := mustQueryInt(t, repo, `SELECT status FROM forward WHERE id = ?`, forwardID)
if pausedStatus != 0 {
t.Fatalf("expected status=0 after pause, got %d", pausedStatus)
}
resumeBody, err := json.Marshal(map[string]interface{}{"id": forwardID})
if err != nil {
t.Fatalf("marshal resume payload: %v", err)
}
resumeReq := httptest.NewRequest(http.MethodPost, "/api/v1/forward/resume", bytes.NewReader(resumeBody))
resumeReq.Header.Set("Authorization", adminToken)
resumeReq.Header.Set("Content-Type", "application/json")
resumeRes := httptest.NewRecorder()
router.ServeHTTP(resumeRes, resumeReq)
assertCode(t, resumeRes, 0)
resumedStatus := mustQueryInt(t, repo, `SELECT status FROM forward WHERE id = ?`, forwardID)
if resumedStatus != 1 {
t.Fatalf("expected status=1 after resume, got %d", resumedStatus)
}
}
func jsonNumber(v int64) string {
return strconv.FormatInt(v, 10)
}
@@ -0,0 +1,635 @@
package contract_test
import (
"bytes"
"database/sql"
"encoding/json"
"fmt"
"net/http"
"net/http/httptest"
"net/url"
"strings"
"sync"
"testing"
"time"
"github.com/gorilla/websocket"
"go-backend/internal/auth"
"go-backend/internal/http/response"
"go-backend/internal/security"
)
func TestForwardCreateRollbackWhenLimiterDispatchFailsContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
server := httptest.NewServer(router)
defer server.Close()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "limiter-fail-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, r, "limiter-fail-tunnel")
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "limiter-fail-node", "limiter-fail-secret", "10.20.0.1", "10.20.0.1", "", "32000-32010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, r, "limiter-fail-node")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 32001, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "limiter-fail-rule", 1024, now, 1).Error; err != nil {
t.Fatalf("insert speed limit: %v", err)
}
speedID := mustLastInsertID(t, r, "limiter-fail-rule")
stopNode := startMockNodeSessionWithCommandFailures(t, server.URL, "limiter-fail-secret", map[string]string{
"addlimiters": "mock add limiters failed",
})
defer stopNode()
payload := map[string]interface{}{
"name": "limiter-fail-forward",
"tunnelId": tunnelID,
"remoteAddr": "1.1.1.1:443",
"strategy": "fifo",
"speedId": speedID,
}
body, err := json.Marshal(payload)
if err != nil {
t.Fatalf("marshal payload: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/forward/create", bytes.NewReader(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code == 0 {
t.Fatalf("expected create failure on limiter dispatch, got code=0")
}
forwardCount := mustQueryInt(t, r, `SELECT COUNT(1) FROM forward WHERE name = ?`, "limiter-fail-forward")
if forwardCount != 0 {
t.Fatalf("expected forward rollback delete on limiter failure, got count=%d", forwardCount)
}
}
func TestForwardCreateSucceedsWhenLimiterAlreadyExistsAndUpdateSucceedsContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
server := httptest.NewServer(router)
defer server.Close()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "limiter-exists-update-ok-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, r, "limiter-exists-update-ok-tunnel")
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "limiter-exists-update-ok-node", "limiter-exists-update-ok-secret", "10.20.1.1", "10.20.1.1", "", "32200-32210", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, r, "limiter-exists-update-ok-node")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 32201, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "limiter-exists-update-ok-rule", 1024, now, 1).Error; err != nil {
t.Fatalf("insert speed limit: %v", err)
}
speedID := mustLastInsertID(t, r, "limiter-exists-update-ok-rule")
stopNode := startMockNodeSessionWithCommandFailures(t, server.URL, "limiter-exists-update-ok-secret", map[string]string{
"addlimiters": "limiter 8 already exists",
})
defer stopNode()
payload := map[string]interface{}{
"name": "limiter-exists-update-ok-forward",
"tunnelId": tunnelID,
"remoteAddr": "1.1.1.1:443",
"strategy": "fifo",
"speedId": speedID,
}
body, err := json.Marshal(payload)
if err != nil {
t.Fatalf("marshal payload: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/forward/create", bytes.NewReader(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected create success when updater succeeds, got code=%d msg=%s", out.Code, out.Msg)
}
forwardCount := mustQueryInt(t, r, `SELECT COUNT(1) FROM forward WHERE name = ?`, "limiter-exists-update-ok-forward")
if forwardCount != 1 {
t.Fatalf("expected forward kept when update limiter succeeds, got count=%d", forwardCount)
}
}
func TestForwardCreateRollbackWhenLimiterAlreadyExistsAndUpdateFailsContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
server := httptest.NewServer(router)
defer server.Close()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "limiter-exists-update-fail-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, r, "limiter-exists-update-fail-tunnel")
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "limiter-exists-update-fail-node", "limiter-exists-update-fail-secret", "10.20.2.1", "10.20.2.1", "", "32300-32310", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, r, "limiter-exists-update-fail-node")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 32301, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "limiter-exists-update-fail-rule", 1024, now, 1).Error; err != nil {
t.Fatalf("insert speed limit: %v", err)
}
speedID := mustLastInsertID(t, r, "limiter-exists-update-fail-rule")
stopNode := startMockNodeSessionWithCommandFailures(t, server.URL, "limiter-exists-update-fail-secret", map[string]string{
"addlimiters": "limiter 9 already exists",
"updatelimiters": "mock update limiters failed",
})
defer stopNode()
payload := map[string]interface{}{
"name": "limiter-exists-update-fail-forward",
"tunnelId": tunnelID,
"remoteAddr": "1.1.1.1:443",
"strategy": "fifo",
"speedId": speedID,
}
body, err := json.Marshal(payload)
if err != nil {
t.Fatalf("marshal payload: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/forward/create", bytes.NewReader(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code == 0 {
t.Fatalf("expected create failure when update limiter fails, got code=0")
}
if !strings.Contains(out.Msg, "mock update limiters failed") {
t.Fatalf("expected update failure message, got %q", out.Msg)
}
forwardCount := mustQueryInt(t, r, `SELECT COUNT(1) FROM forward WHERE name = ?`, "limiter-exists-update-fail-forward")
if forwardCount != 0 {
t.Fatalf("expected forward rollback delete when update limiter fails, got count=%d", forwardCount)
}
}
func TestForwardCreateRollbackWhenServiceDispatchReturnsAddressInUseContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
server := httptest.NewServer(router)
defer server.Close()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "addr-in-use-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, r, "addr-in-use-tunnel")
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "addr-in-use-node", "addr-in-use-secret", "10.20.0.11", "10.20.0.11", "", "32100-32110", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, r, "addr-in-use-node")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 32101, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
stopNode := startMockNodeSessionWithCommandFailures(t, server.URL, "addr-in-use-secret", map[string]string{
"updateservice": "listen tcp [::]:32101: bind: address already in use",
"addservice": "listen tcp [::]:32101: bind: address already in use",
})
defer stopNode()
payload := map[string]interface{}{
"name": "addr-in-use-forward",
"tunnelId": tunnelID,
"remoteAddr": "1.1.1.1:443",
"strategy": "fifo",
}
body, err := json.Marshal(payload)
if err != nil {
t.Fatalf("marshal payload: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/forward/create", bytes.NewReader(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code == 0 {
t.Fatalf("expected create failure on address-in-use service dispatch, got code=0")
}
forwardCount := mustQueryInt(t, r, `SELECT COUNT(1) FROM forward WHERE name = ?`, "addr-in-use-forward")
if forwardCount != 0 {
t.Fatalf("expected forward rollback delete on address-in-use failure, got count=%d", forwardCount)
}
}
func TestBatchAssignRollbackWhenLimiterDispatchFailsContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
server := httptest.NewServer(router)
defer server.Close()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO user(id, user, pwd, role_id, exp_time, flow, in_flow, out_flow, flow_reset_time, num, created_time, updated_time, status)
VALUES(2, 'assign_user', '3c85cdebade1c51cf64ca9f3c09d182d', 1, 2727251700000, 99999, 0, 0, 1, 99999, ?, ?, 1)
`, now, now).Error; err != nil {
t.Fatalf("insert user: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "assign-limiter-fail-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, r, "assign-limiter-fail-tunnel")
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "assign-limiter-fail-node", "assign-limiter-fail-secret", "10.21.0.1", "10.21.0.1", "", "33000-33010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, r, "assign-limiter-fail-node")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 33001, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "assign-limiter-fail-rule", 2048, now, 1).Error; err != nil {
t.Fatalf("insert speed limit: %v", err)
}
speedID := mustLastInsertID(t, r, "assign-limiter-fail-rule")
if err := r.DB().Exec(`
INSERT INTO user_tunnel(id, user_id, tunnel_id, speed_id, num, flow, in_flow, out_flow, flow_reset_time, exp_time, status)
VALUES(21, 2, ?, NULL, 999, 99999, 0, 0, 1, 2727251700000, 1)
`, tunnelID).Error; err != nil {
t.Fatalf("insert user_tunnel: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO forward(user_id, user_name, name, tunnel_id, remote_addr, strategy, in_flow, out_flow, created_time, updated_time, status, inx)
VALUES(2, 'assign_user', 'assign-limiter-fail-forward', ?, '9.9.9.9:53', 'fifo', 0, 0, ?, ?, 1, 0)
`, tunnelID, now, now).Error; err != nil {
t.Fatalf("insert forward: %v", err)
}
forwardID := mustLastInsertID(t, r, "assign-limiter-fail-forward")
if err := r.DB().Exec(`INSERT INTO forward_port(forward_id, node_id, port) VALUES(?, ?, ?)`, forwardID, nodeID, 33001).Error; err != nil {
t.Fatalf("insert forward_port: %v", err)
}
stopNode := startMockNodeSessionWithCommandFailures(t, server.URL, "assign-limiter-fail-secret", map[string]string{
"addlimiters": "mock add limiters failed",
})
defer stopNode()
assignPayload := map[string]interface{}{
"userId": 2,
"tunnels": []map[string]interface{}{{
"tunnelId": tunnelID,
"speedId": speedID,
}},
}
body, err := json.Marshal(assignPayload)
if err != nil {
t.Fatalf("marshal assign payload: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/tunnel/user/batch-assign", bytes.NewReader(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code == 0 {
t.Fatalf("expected assign failure on limiter dispatch, got code=0")
}
var persistedSpeedID sql.NullInt64
if err := r.DB().Raw(`SELECT speed_id FROM user_tunnel WHERE user_id = 2 AND tunnel_id = ?`, tunnelID).Row().Scan(&persistedSpeedID); err != nil {
t.Fatalf("query user_tunnel speed_id: %v", err)
}
if persistedSpeedID.Valid {
t.Fatalf("expected speed_id rollback to NULL, got %d", persistedSpeedID.Int64)
}
}
func TestBatchAssignInsertRollbackWhenLimiterDispatchFailsContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
server := httptest.NewServer(router)
defer server.Close()
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO user(id, user, pwd, role_id, exp_time, flow, in_flow, out_flow, flow_reset_time, num, created_time, updated_time, status)
VALUES(3, 'assign_insert_user', '3c85cdebade1c51cf64ca9f3c09d182d', 1, 2727251700000, 99999, 0, 0, 1, 99999, ?, ?, 1)
`, now, now).Error; err != nil {
t.Fatalf("insert user: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "assign-insert-limiter-fail-tunnel", 1.0, 1, "tls", 99999, now, now, 1, nil, 0).Error; err != nil {
t.Fatalf("insert tunnel: %v", err)
}
tunnelID := mustLastInsertID(t, r, "assign-insert-limiter-fail-tunnel")
if err := r.DB().Exec(`
INSERT INTO node(name, secret, server_ip, server_ip_v4, server_ip_v6, port, interface_name, version, http, tls, socks, created_time, updated_time, status, tcp_listen_addr, udp_listen_addr, inx)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "assign-insert-limiter-fail-node", "assign-insert-limiter-fail-secret", "10.22.0.1", "10.22.0.1", "", "34000-34010", "", "v1", 1, 1, 1, now, now, 1, "[::]", "[::]", 0).Error; err != nil {
t.Fatalf("insert node: %v", err)
}
nodeID := mustLastInsertID(t, r, "assign-insert-limiter-fail-node")
if err := r.DB().Exec(`
INSERT INTO chain_tunnel(tunnel_id, chain_type, node_id, port, strategy, inx, protocol)
VALUES(?, 1, ?, 34001, 'round', 1, 'tls')
`, tunnelID, nodeID).Error; err != nil {
t.Fatalf("insert chain_tunnel: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, NULL, NULL, ?, NULL, ?)
`, "assign-insert-limiter-fail-rule", 3072, now, 1).Error; err != nil {
t.Fatalf("insert speed limit: %v", err)
}
speedID := mustLastInsertID(t, r, "assign-insert-limiter-fail-rule")
if err := r.DB().Exec(`
INSERT INTO forward(user_id, user_name, name, tunnel_id, remote_addr, strategy, in_flow, out_flow, created_time, updated_time, status, inx)
VALUES(3, 'assign_insert_user', 'assign-insert-limiter-fail-forward', ?, '8.8.4.4:53', 'fifo', 0, 0, ?, ?, 1, 0)
`, tunnelID, now, now).Error; err != nil {
t.Fatalf("insert forward: %v", err)
}
forwardID := mustLastInsertID(t, r, "assign-insert-limiter-fail-forward")
if err := r.DB().Exec(`INSERT INTO forward_port(forward_id, node_id, port) VALUES(?, ?, ?)`, forwardID, nodeID, 34001).Error; err != nil {
t.Fatalf("insert forward_port: %v", err)
}
stopNode := startMockNodeSessionWithCommandFailures(t, server.URL, "assign-insert-limiter-fail-secret", map[string]string{
"addlimiters": "mock add limiters failed",
})
defer stopNode()
assignPayload := map[string]interface{}{
"userId": 3,
"tunnels": []map[string]interface{}{{
"tunnelId": tunnelID,
"speedId": speedID,
}},
}
body, err := json.Marshal(assignPayload)
if err != nil {
t.Fatalf("marshal assign payload: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/tunnel/user/batch-assign", bytes.NewReader(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code == 0 {
t.Fatalf("expected assign(insert) failure on limiter dispatch, got code=0")
}
insertedCount := mustQueryInt(t, r, `SELECT COUNT(1) FROM user_tunnel WHERE user_id = 3 AND tunnel_id = ?`, tunnelID)
if insertedCount != 0 {
t.Fatalf("expected inserted user_tunnel rollback delete, got count=%d", insertedCount)
}
}
func startMockNodeSessionWithCommandFailures(t *testing.T, baseURL string, nodeSecret string, failCommands map[string]string) func() {
t.Helper()
u, err := url.Parse(baseURL)
if err != nil {
t.Fatalf("parse provider url: %v", err)
}
if strings.EqualFold(u.Scheme, "https") {
u.Scheme = "wss"
} else {
u.Scheme = "ws"
}
u.Path = "/system-info"
q := u.Query()
q.Set("type", "1")
q.Set("secret", nodeSecret)
q.Set("version", "v1")
q.Set("http", "1")
q.Set("tls", "1")
q.Set("socks", "1")
u.RawQuery = q.Encode()
conn, _, err := websocket.DefaultDialer.Dial(u.String(), nil)
if err != nil {
t.Fatalf("dial mock node websocket: %v", err)
}
var wg sync.WaitGroup
wg.Add(1)
go func() {
defer wg.Done()
for {
_, raw, readErr := conn.ReadMessage()
if readErr != nil {
return
}
plain := raw
var wrap struct {
Encrypted bool `json:"encrypted"`
Data string `json:"data"`
}
if err := json.Unmarshal(raw, &wrap); err == nil && wrap.Encrypted && strings.TrimSpace(wrap.Data) != "" {
crypto, cryptoErr := security.NewAESCrypto(nodeSecret)
if cryptoErr == nil {
if dec, decErr := crypto.Decrypt(wrap.Data); decErr == nil {
plain = []byte(dec)
}
}
}
var cmd struct {
Type string `json:"type"`
RequestID string `json:"requestId"`
}
if err := json.Unmarshal(plain, &cmd); err != nil {
continue
}
if strings.TrimSpace(cmd.RequestID) == "" {
continue
}
cmdType := strings.TrimSpace(cmd.Type)
failMsg, shouldFail := failCommands[strings.ToLower(cmdType)]
respType := fmt.Sprintf("%sResponse", cmdType)
respPayload := map[string]interface{}{
"type": respType,
"success": !shouldFail,
"message": "OK",
"requestId": cmd.RequestID,
}
if shouldFail {
if strings.TrimSpace(failMsg) == "" {
failMsg = "mock command failed"
}
respPayload["message"] = failMsg
}
respBytes, err := json.Marshal(respPayload)
if err != nil {
continue
}
_ = conn.WriteMessage(websocket.TextMessage, respBytes)
}
}()
var stopOnce sync.Once
return func() {
stopOnce.Do(func() {
_ = conn.Close()
wg.Wait()
})
}
}
@@ -25,6 +25,7 @@ import (
func TestCaptchaVerifyLoginContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
verifiedToken := ""
if err := r.DB().Exec(`
INSERT INTO vite_config(name, value, time)
@@ -34,6 +35,55 @@ func TestCaptchaVerifyLoginContract(t *testing.T) {
t.Fatalf("enable captcha: %v", err)
}
t.Run("login allowed when cloudflare keys are missing", func(t *testing.T) {
body := bytes.NewBufferString(`{"username":"admin_user","password":"admin_user","captchaId":""}`)
req := httptest.NewRequest(http.MethodPost, "/api/v1/user/login", body)
req.Header.Set("Content-Type", "application/json")
resp := httptest.NewRecorder()
router.ServeHTTP(resp, req)
assertCode(t, resp, 0)
})
t.Run("captcha verify remains compatible without cloudflare secret", func(t *testing.T) {
verifyReq := httptest.NewRequest(http.MethodPost, "/api/v1/captcha/verify", bytes.NewBufferString(`{"id":"captcha-token-1","data":"ok"}`))
verifyReq.Header.Set("Content-Type", "application/json")
verifyResp := httptest.NewRecorder()
router.ServeHTTP(verifyResp, verifyReq)
var verifyOut struct {
Success bool `json:"success"`
Data struct {
ValidToken string `json:"validToken"`
} `json:"data"`
}
if err := json.NewDecoder(verifyResp.Body).Decode(&verifyOut); err != nil {
t.Fatalf("decode captcha verify response: %v", err)
}
if !verifyOut.Success || verifyOut.Data.ValidToken != "captcha-token-1" {
t.Fatalf("unexpected captcha verify payload: success=%v token=%q", verifyOut.Success, verifyOut.Data.ValidToken)
}
verifiedToken = verifyOut.Data.ValidToken
})
if err := r.DB().Exec(`
INSERT INTO vite_config(name, value, time)
VALUES(?, ?, ?)
ON CONFLICT(name) DO UPDATE SET value = excluded.value, time = excluded.time
`, "cloudflare_site_key", "test-site-key", time.Now().UnixMilli()).Error; err != nil {
t.Fatalf("set cloudflare site key: %v", err)
}
if err := r.DB().Exec(`
INSERT INTO vite_config(name, value, time)
VALUES(?, ?, ?)
ON CONFLICT(name) DO UPDATE SET value = excluded.value, time = excluded.time
`, "cloudflare_secret_key", "test-secret-key", time.Now().UnixMilli()).Error; err != nil {
t.Fatalf("set cloudflare secret key: %v", err)
}
t.Run("login denied without verified captcha token", func(t *testing.T) {
body := bytes.NewBufferString(`{"username":"admin_user","password":"admin_user","captchaId":""}`)
req := httptest.NewRequest(http.MethodPost, "/api/v1/user/login", body)
@@ -58,33 +108,18 @@ func TestCaptchaVerifyLoginContract(t *testing.T) {
})
t.Run("captcha token is one-time and consumed by login", func(t *testing.T) {
verifyReq := httptest.NewRequest(http.MethodPost, "/api/v1/captcha/verify", bytes.NewBufferString(`{"id":"captcha-token-1","data":"ok"}`))
verifyReq.Header.Set("Content-Type", "application/json")
verifyResp := httptest.NewRecorder()
router.ServeHTTP(verifyResp, verifyReq)
var verifyOut struct {
Success bool `json:"success"`
Data struct {
ValidToken string `json:"validToken"`
} `json:"data"`
}
if err := json.NewDecoder(verifyResp.Body).Decode(&verifyOut); err != nil {
t.Fatalf("decode captcha verify response: %v", err)
}
if !verifyOut.Success || verifyOut.Data.ValidToken != "captcha-token-1" {
t.Fatalf("unexpected captcha verify payload: success=%v token=%q", verifyOut.Success, verifyOut.Data.ValidToken)
if strings.TrimSpace(verifiedToken) == "" {
t.Fatalf("expected verified token from compatibility captcha verify")
}
loginBody := bytes.NewBufferString(`{"username":"admin_user","password":"admin_user","captchaId":"captcha-token-1"}`)
loginBody := bytes.NewBufferString(`{"username":"admin_user","password":"admin_user","captchaId":"` + verifiedToken + `"}`)
loginReq := httptest.NewRequest(http.MethodPost, "/api/v1/user/login", loginBody)
loginReq.Header.Set("Content-Type", "application/json")
loginResp := httptest.NewRecorder()
router.ServeHTTP(loginResp, loginReq)
assertCode(t, loginResp, 0)
replayBody := bytes.NewBufferString(`{"username":"admin_user","password":"admin_user","captchaId":"captcha-token-1"}`)
replayBody := bytes.NewBufferString(`{"username":"admin_user","password":"admin_user","captchaId":"` + verifiedToken + `"}`)
replayReq := httptest.NewRequest(http.MethodPost, "/api/v1/user/login", replayBody)
replayReq.Header.Set("Content-Type", "application/json")
replayResp := httptest.NewRecorder()
@@ -174,39 +209,24 @@ func TestOpenAPISubStoreContracts(t *testing.T) {
})
}
func TestSpeedLimitTunnelsRouteAlias(t *testing.T) {
func TestSpeedLimitTunnelsRouteRemoved(t *testing.T) {
secret := "contract-jwt-secret"
router, _ := setupContractRouter(t, secret)
t.Run("missing token blocked", func(t *testing.T) {
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/tunnels", nil)
resp := httptest.NewRecorder()
token, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate token: %v", err)
}
router.ServeHTTP(resp, req)
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/tunnels", nil)
req.Header.Set("Authorization", token)
resp := httptest.NewRecorder()
assertCodeMsg(t, resp, 401, "未登录或token已过期")
})
router.ServeHTTP(resp, req)
t.Run("admin token receives success envelope", func(t *testing.T) {
token, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate token: %v", err)
}
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/tunnels", nil)
req.Header.Set("Authorization", token)
resp := httptest.NewRecorder()
router.ServeHTTP(resp, req)
var out response.R
if err := json.NewDecoder(resp.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected code 0, got %d (%s)", out.Code, out.Msg)
}
})
if resp.Code != http.StatusNotFound {
t.Fatalf("expected status 404 after route removal, got %d", resp.Code)
}
}
func TestBackupExportImportRestoreContracts(t *testing.T) {
@@ -664,15 +684,107 @@ func TestOpenMigratesLegacyNodeDualStackColumns(t *testing.T) {
columns := readTableColumns(t, r.DB(), "node")
for _, required := range []string{"server_ip_v4", "server_ip_v6", "inx"} {
for _, required := range []string{"server_ip_v4", "server_ip_v6", "inx", "extra_ips"} {
if !columns[required] {
t.Fatalf("expected node column %q to exist after migration", required)
}
}
tunnelColumns := readTableColumns(t, r.DB(), "tunnel")
if !tunnelColumns["inx"] {
t.Fatalf("expected tunnel column %q to exist after migration", "inx")
for _, required := range []string{"inx", "ip_preference"} {
if !tunnelColumns[required] {
t.Fatalf("expected tunnel column %q to exist after migration", required)
}
}
}
func TestOpenMigratesVeryLegacyNodeAndTunnelColumns(t *testing.T) {
dbPath := filepath.Join(t.TempDir(), "legacy-1.x.db")
legacyDB, err := sql.Open("sqlite", dbPath)
if err != nil {
t.Fatalf("open legacy sqlite: %v", err)
}
t.Cleanup(func() {
_ = legacyDB.Close()
})
if _, err := legacyDB.Exec(`
CREATE TABLE IF NOT EXISTS node (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name VARCHAR(100) NOT NULL,
secret VARCHAR(100) NOT NULL,
server_ip VARCHAR(100) NOT NULL,
port TEXT NOT NULL,
interface_name VARCHAR(200),
version VARCHAR(100),
http INTEGER NOT NULL DEFAULT 0,
tls INTEGER NOT NULL DEFAULT 0,
socks INTEGER NOT NULL DEFAULT 0,
created_time INTEGER NOT NULL,
updated_time INTEGER,
status INTEGER NOT NULL
)
`); err != nil {
t.Fatalf("create very legacy node table: %v", err)
}
if _, err := legacyDB.Exec(`
CREATE TABLE IF NOT EXISTS tunnel (
id INTEGER PRIMARY KEY AUTOINCREMENT,
name VARCHAR(100) NOT NULL,
traffic_ratio REAL NOT NULL DEFAULT 1.0,
type INTEGER NOT NULL,
protocol VARCHAR(10) NOT NULL DEFAULT 'tls',
flow INTEGER NOT NULL,
created_time INTEGER NOT NULL,
updated_time INTEGER NOT NULL,
status INTEGER NOT NULL,
in_ip TEXT
)
`); err != nil {
t.Fatalf("create very legacy tunnel table: %v", err)
}
now := time.Now().UnixMilli()
if _, err := legacyDB.Exec(`
INSERT INTO node(name, secret, server_ip, port, interface_name, version, http, tls, socks, created_time, updated_time, status)
VALUES(?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?, ?)
`, "legacy-node", "legacy-secret", "10.10.0.1", "10000-10010", "eth0", "v-old", 1, 1, 1, now, now, 1); err != nil {
t.Fatalf("seed legacy node row: %v", err)
}
r, err := repo.Open(dbPath)
if err != nil {
t.Fatalf("open migrated sqlite: %v", err)
}
t.Cleanup(func() {
_ = r.Close()
})
columns := readTableColumns(t, r.DB(), "node")
for _, required := range []string{
"server_ip_v4",
"server_ip_v6",
"extra_ips",
"tcp_listen_addr",
"udp_listen_addr",
"inx",
"is_remote",
"remote_url",
"remote_token",
"remote_config",
} {
if !columns[required] {
t.Fatalf("expected node column %q to exist after migration", required)
}
}
tunnelColumns := readTableColumns(t, r.DB(), "tunnel")
for _, required := range []string{"inx", "ip_preference"} {
if !tunnelColumns[required] {
t.Fatalf("expected tunnel column %q to exist after migration", required)
}
}
}
@@ -0,0 +1,313 @@
package contract_test
import (
"bytes"
"database/sql"
"encoding/json"
"net/http"
"net/http/httptest"
"path/filepath"
"testing"
"time"
"go-backend/internal/auth"
"go-backend/internal/http/response"
"go-backend/internal/store/repo"
)
func TestSpeedLimitWithoutTunnelContract(t *testing.T) {
secret := "contract-jwt-secret"
router, _ := setupContractRouter(t, secret)
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
t.Run("create speed limit", func(t *testing.T) {
body := `{"name":"test-limit-no-tunnel","speed":100,"status":1}`
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/create", bytes.NewBufferString(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
assertCode(t, res, 0)
})
t.Run("list does not expose tunnel binding fields", func(t *testing.T) {
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/list", nil)
req.Header.Set("Authorization", adminToken)
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected code 0, got %d", out.Code)
}
data, ok := out.Data.([]interface{})
if !ok {
t.Fatalf("expected data to be array, got %T", out.Data)
}
for _, item := range data {
m, ok := item.(map[string]interface{})
if !ok {
continue
}
if m["name"] != "test-limit-no-tunnel" {
continue
}
if tunnelID, exists := m["tunnelId"]; exists && tunnelID != nil {
t.Fatalf("expected tunnelId to be absent or nil, got %v", tunnelID)
}
if tunnelName, exists := m["tunnelName"]; exists && tunnelName != nil && tunnelName != "" {
t.Fatalf("expected tunnelName to be absent or empty, got %v", tunnelName)
}
return
}
t.Fatal("speed limit 'test-limit-no-tunnel' not found in list")
})
}
func TestSpeedLimitCreateIgnoresTunnelBindingContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
tunnelID := mustCreateSpeedLimitTunnel(t, r, "test-speed-limit-create-ignore-tunnel")
body := `{"name":"test-limit-ignore-tunnel","speed":200,"tunnelId":` + jsonInt(tunnelID) + `,"status":1}`
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/create", bytes.NewBufferString(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
assertCode(t, res, 0)
req = httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/list", nil)
req.Header.Set("Authorization", adminToken)
res = httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected code 0, got %d", out.Code)
}
data, ok := out.Data.([]interface{})
if !ok {
t.Fatalf("expected data to be array, got %T", out.Data)
}
for _, item := range data {
m, ok := item.(map[string]interface{})
if !ok {
continue
}
if m["name"] != "test-limit-ignore-tunnel" {
continue
}
if tunnelIDVal, exists := m["tunnelId"]; exists && tunnelIDVal != nil {
t.Fatalf("expected tunnelId ignored and nil, got %v", tunnelIDVal)
}
if tunnelNameVal, exists := m["tunnelName"]; exists && tunnelNameVal != nil && tunnelNameVal != "" {
t.Fatalf("expected tunnelName ignored and empty, got %v", tunnelNameVal)
}
return
}
t.Fatal("speed limit 'test-limit-ignore-tunnel' not found in list")
}
func TestSpeedLimitUpdateIgnoresTunnelBindingContract(t *testing.T) {
secret := "contract-jwt-secret"
router, r := setupContractRouter(t, secret)
adminToken, err := auth.GenerateToken(1, "admin_user", 0, secret)
if err != nil {
t.Fatalf("generate admin token: %v", err)
}
tunnelID := mustCreateSpeedLimitTunnel(t, r, "test-speed-limit-update-ignore-tunnel")
speedLimitID := mustCreateSpeedLimitRepo(t, r, "test-limit-update-ignore-tunnel")
body := `{"id":` + jsonInt(speedLimitID) + `,"name":"test-limit-update-ignore-tunnel","speed":256,"tunnelId":` + jsonInt(tunnelID) + `,"status":1}`
req := httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/update", bytes.NewBufferString(body))
req.Header.Set("Authorization", adminToken)
req.Header.Set("Content-Type", "application/json")
res := httptest.NewRecorder()
router.ServeHTTP(res, req)
assertCode(t, res, 0)
req = httptest.NewRequest(http.MethodPost, "/api/v1/speed-limit/list", nil)
req.Header.Set("Authorization", adminToken)
res = httptest.NewRecorder()
router.ServeHTTP(res, req)
var out response.R
if err := json.NewDecoder(res.Body).Decode(&out); err != nil {
t.Fatalf("decode response: %v", err)
}
if out.Code != 0 {
t.Fatalf("expected code 0, got %d", out.Code)
}
data, ok := out.Data.([]interface{})
if !ok {
t.Fatalf("expected data to be array, got %T", out.Data)
}
for _, item := range data {
m, ok := item.(map[string]interface{})
if !ok {
continue
}
if m["name"] != "test-limit-update-ignore-tunnel" {
continue
}
if tunnelIDVal, exists := m["tunnelId"]; exists && tunnelIDVal != nil {
t.Fatalf("expected tunnelId ignored and nil after update, got %v", tunnelIDVal)
}
if speedVal, ok := m["speed"].(float64); !ok || int(speedVal) != 256 {
t.Fatalf("expected speed 256 after update, got %v", m["speed"])
}
return
}
t.Fatal("speed limit 'test-limit-update-ignore-tunnel' not found in list")
}
func TestSpeedLimitDatabaseNullableFields(t *testing.T) {
dbPath := filepath.Join(t.TempDir(), "speed-limit-null.db")
r, err := repo.Open(dbPath)
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() { _ = r.Close() })
id, err := r.CreateSpeedLimit("db-test-limit", 100, 1, 1)
if err != nil {
t.Fatalf("CreateSpeedLimit failed: %v", err)
}
if id <= 0 {
t.Fatalf("expected valid id, got %d", id)
}
var tunnelID sql.NullInt64
var tunnelName sql.NullString
err = r.DB().Raw("SELECT tunnel_id, tunnel_name FROM speed_limit WHERE id = ?", id).Row().Scan(&tunnelID, &tunnelName)
if err != nil {
t.Fatalf("query failed: %v", err)
}
if tunnelID.Valid {
t.Fatalf("expected TunnelID to be NULL, got %d", tunnelID.Int64)
}
if tunnelName.Valid && tunnelName.String != "" {
t.Fatalf("expected TunnelName to be NULL or empty, got %s", tunnelName.String)
}
}
func TestSpeedLimitUpdateClearsHistoricalBinding(t *testing.T) {
dbPath := filepath.Join(t.TempDir(), "speed-limit-update-clear.db")
r, err := repo.Open(dbPath)
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() { _ = r.Close() })
tunnelID := mustCreateSpeedLimitTunnel(t, r, "speed-limit-update-clear-tunnel")
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO speed_limit(name, speed, tunnel_id, tunnel_name, created_time, updated_time, status)
VALUES(?, ?, ?, ?, ?, ?, ?)
`, "speed-limit-update-clear", 300, tunnelID, "speed-limit-update-clear-tunnel", now, now, 1).Error; err != nil {
t.Fatalf("insert speed limit with tunnel binding: %v", err)
}
speedLimitID := mustLastInsertID(t, r, "speed-limit-update-clear")
err = r.UpdateSpeedLimit(speedLimitID, "speed-limit-update-clear", 512, 1, time.Now().UnixMilli())
if err != nil {
t.Fatalf("UpdateSpeedLimit failed: %v", err)
}
var dbTunnelID sql.NullInt64
var dbTunnelName sql.NullString
err = r.DB().Raw("SELECT tunnel_id, tunnel_name FROM speed_limit WHERE id = ?", speedLimitID).Row().Scan(&dbTunnelID, &dbTunnelName)
if err != nil {
t.Fatalf("query updated speed limit failed: %v", err)
}
if dbTunnelID.Valid {
t.Fatalf("expected tunnel_id cleared after update, got %d", dbTunnelID.Int64)
}
if dbTunnelName.Valid && dbTunnelName.String != "" {
t.Fatalf("expected tunnel_name cleared after update, got %q", dbTunnelName.String)
}
}
func TestSpeedLimitGetSpeed(t *testing.T) {
dbPath := filepath.Join(t.TempDir(), "speed-limit-getspeed.db")
r, err := repo.Open(dbPath)
if err != nil {
t.Fatalf("open sqlite: %v", err)
}
t.Cleanup(func() { _ = r.Close() })
speedLimitID, err := r.CreateSpeedLimit("get-speed-test", 500, 1, 1)
if err != nil {
t.Fatalf("create speed limit: %v", err)
}
t.Run("GetSpeedLimitSpeed returns correct speed", func(t *testing.T) {
speed, err := r.GetSpeedLimitSpeed(speedLimitID)
if err != nil {
t.Fatalf("GetSpeedLimitSpeed failed: %v", err)
}
if speed != 500 {
t.Fatalf("expected speed 500, got %d", speed)
}
})
t.Run("GetSpeedLimitSpeed returns error for non-existent id", func(t *testing.T) {
_, err := r.GetSpeedLimitSpeed(99999)
if err == nil {
t.Fatal("expected error for non-existent speed limit ID")
}
})
}
func mustCreateSpeedLimitTunnel(t *testing.T, r *repo.Repository, name string) int64 {
t.Helper()
now := time.Now().UnixMilli()
if err := r.DB().Exec(`
INSERT INTO tunnel(name, traffic_ratio, type, protocol, flow, created_time, updated_time, status, in_ip, inx)
VALUES(?, 1.0, 1, 'tls', 99999, ?, ?, 1, NULL, 0)
`, name, now, now).Error; err != nil {
t.Fatalf("create tunnel failed: %v", err)
}
return mustLastInsertID(t, r, name)
}
func mustCreateSpeedLimitRepo(t *testing.T, r *repo.Repository, name string) int64 {
t.Helper()
now := time.Now().UnixMilli()
id, err := r.CreateSpeedLimit(name, 100, now, 1)
if err != nil {
t.Fatalf("create speed limit failed: %v", err)
}
return id
}
@@ -1,4 +1,4 @@
package contract
package contract_test
import (
"encoding/json"
@@ -13,7 +13,7 @@ import (
func TestUserTunnelVisibleListContracts(t *testing.T) {
secret := "contract-jwt-secret"
router, repo := setupDiagnosisContractRouter(t, secret)
router, repo := setupContractRouter(t, secret)
now := time.Now().UnixMilli()
if err := repo.DB().Exec(`
@@ -126,8 +126,11 @@ func collectTunnelIDs(t *testing.T, data interface{}) map[int64]bool {
if !ok {
t.Fatalf("expected object item, got %T", item)
}
id := int64(obj["id"].(float64))
ids[id] = true
idFloat, ok := obj["id"].(float64)
if !ok {
t.Fatalf("expected id to be float64, got %T", obj["id"])
}
ids[int64(idFloat)] = true
}
return ids
}
+2
View File
@@ -30,6 +30,8 @@ nav:
- 首页: index.md
- 安装部署: install.md
- 使用指南: usage.md
- AI Skill 接入: ai-skill.md
- PostgreSQL: postgresql.md
- 常见问题: faq.md
markdown_extensions:
+15
View File
@@ -0,0 +1,15 @@
# 001 Fix 211 ConnectIP Full Chain
## Checklist
- [x] Analyze connectIp/inIp full chain across diagnosis/runtime/redeploy paths.
- [x] Fix diagnosis target resolution to honor selected `connectIp` for chain hops.
- [x] Fix tunnel state reconstruction to preserve `connectIp` on chain/out nodes.
- [x] Add contract regression tests for normal + stream diagnosis target IP behavior.
- [x] Add handler regression test for redeploy state reconstruction preserving `connectIp`.
- [x] Run backend handler and contract test suites.
## Notes
- Diagnosis now uses `chain_tunnel.connect_ip` for both stream start preview and runtime probing.
- Redeploy/batch-redeploy no longer drops `connectIp` during `reconstructTunnelState`.
@@ -0,0 +1,7 @@
- [x] Review current forward import flow and confirm ny import uses tunnel selection
- [x] Define ny compatibility update with tunnel-first behavior and auto port assignment fallback
- [x] Update ny parser to accept alias fields and optional `listen_port`
- [x] Keep import execution bound to selected tunnel and remove entry-selection dependency from ux copy
- [x] Update ny import help text to document optional port auto assignment
- [x] Add parser tests for alias-field compatibility and missing-port auto assignment
- [x] Validate updated import parser tests locally
@@ -0,0 +1,11 @@
# 003 Forward Edit Bind IP Preserve
## Checklist
- [x] Confirm forward edit flow and identify why untouched listen IP gets overwritten.
- [x] Update frontend forward edit submit logic to only send `inIp` when user explicitly changes listen IP.
- [x] On tunnel switch in edit form, reset listen IP to default unless user reselects.
- [x] Update backend forward update logic to preserve existing `forward_port.in_ip` when request omits `inIp` and tunnel is unchanged.
- [x] Keep backend behavior explicit: if `inIp` is sent (including empty), apply requested value; if tunnel changed with no `inIp`, use default bind.
- [x] Add regression tests for preserved bind-IP reconstruction helper behavior.
- [x] Run focused frontend/backend checks for touched files.
@@ -0,0 +1,11 @@
# 004 Forward Explicit Bind Self-Occupy Release
## Checklist
- [x] Confirm current forward edit/save failure path and lock strategy: explicit bind always stays explicit.
- [x] Add repository query to detect whether a node+port is occupied by other forwards (excluding current forward).
- [x] Enhance forward service sync to treat address-in-use as a recoverable case when only self occupies the port.
- [x] On self-occupy conflict, proactively delete current forward services on target node and retry AddService.
- [x] Keep hard failure when the same node+port is occupied by other forwards.
- [x] Add focused unit tests for new error classification helpers.
- [x] Run focused backend tests for touched handler/repo packages.
+302
View File
@@ -0,0 +1,302 @@
---
name: flvx-api
description: Operate FLVX traffic forwarding management system via REST API. Supports user/node/tunnel/forward management, federation clustering, and traffic monitoring. Use when user wants to manage FLVX panel programmatically or via natural language.
metadata:
author: FLVX Team
version: "2.1.5"
requires_env:
- FLVX_BASE_URL
- FLVX_USERNAME
- FLVX_PASSWORD
---
# FLVX API Operations
Operate FLVX panel through REST API. All endpoints use POST method and return JSON with `{code, msg, data, ts}` envelope.
## Supported AI Tools
| Tool | Installation | Notes |
|------|--------------|-------|
| **OpenCode** | `npm i -g @flvx/skill-api` or `ln -s . ~/.agents/skills/flvx-api` | Auto-loads from `~/.agents/skills/` |
| **OpenClaw** | Same as OpenCode | Compatible skill format |
| **Claude Code** | Copy SKILL.md to CLAUDE.md or `~/.claude/CLAUDE.md` | Uses context file instead of skills |
## Prerequisites
Set environment variables before starting:
```bash
export FLVX_BASE_URL="https://your-panel.example.com"
export FLVX_USERNAME="admin"
export FLVX_PASSWORD="your-password"
```
**Security tip:** Add to `~/.flvx/.env` and source on demand:
```bash
mkdir -p ~/.flvx && cat > ~/.flvx/.env << 'EOF'
export FLVX_BASE_URL="https://panel.example.com"
export FLVX_USERNAME="admin"
export FLVX_PASSWORD="your-password"
EOF
chmod 600 ~/.flvx/.env
source ~/.flvx/.env
```
## Authentication Flow
### Session Token Cache
- Token is cached **only for the current conversation**
- New conversation = fresh login required
- Token is NOT written to disk (security)
### Auto-Login Pattern
```
Before ANY API call:
1. Check if TOKEN is cached in current session
├─ Yes → Use cached token, proceed
└─ No →
1. Read FLVX_USERNAME and FLVX_PASSWORD from environment
2. POST /api/v1/user/login with credentials
3. Cache response.data.token in session memory
4. Proceed with original request
```
### Login Request
```bash
curl -X POST "${FLVX_BASE_URL}/api/v1/user/login" \
-H "Content-Type: application/json" \
-d "{\"username\":\"${FLVX_USERNAME}\",\"password\":\"${FLVX_PASSWORD}\"}"
```
**Response:**
```json
{
"code": 0,
"msg": "success",
"data": {
"token": "eyJhbGciOiJIUzI1NiIs...",
"name": "Administrator",
"role_id": 0,
"requirePasswordChange": false
},
"ts": 1706659200000
}
```
## Authentication Rules
| Header | Value | Critical |
|--------|-------|----------|
| `Authorization` | `<jwt_token>` | ⚠️ NO "Bearer" prefix! |
| `Content-Type` | `application/json` | All requests use JSON |
## Quick Start Workflow
```
User request → Check env vars → Auto-login if needed → Call API → Return result
```
## Intent → API Mapping
| User Intent | API Endpoint | Reference |
|-------------|--------------|-----------|
| "登录" / "查看我的信息" | `/api/v1/user/package` | [auth](references/auth.md) |
| "创建用户" / "添加用户" | `/api/v1/user/create` | [users](references/users.md) |
| "查看用户列表" / "所有用户" | `/api/v1/user/list` | [users](references/users.md) |
| "重置流量" | `/api/v1/user/reset` | [users](references/users.md) |
| "添加节点" / "新建节点" | `/api/v1/node/create` | [nodes](references/nodes.md) |
| "查看节点" / "节点状态" | `/api/v1/node/list` | [nodes](references/nodes.md) |
| "安装命令" / "部署节点" | `/api/v1/node/install` | [nodes](references/nodes.md) |
| "升级节点" | `/api/v1/node/upgrade` | [nodes](references/nodes.md) |
| "创建隧道" / "新建隧道" | `/api/v1/tunnel/create` | [tunnels](references/tunnels.md) |
| "分配隧道给用户" | `/api/v1/tunnel/user/assign` | [tunnels](references/tunnels.md) |
| "创建转发" / "新建转发" / "添加转发" | `/api/v1/forward/create` | [forwards](references/forwards.md) |
| "暂停转发" | `/api/v1/forward/pause` | [forwards](references/forwards.md) |
| "恢复转发" | `/api/v1/forward/resume` | [forwards](references/forwards.md) |
| "删除转发" | `/api/v1/forward/delete` | [forwards](references/forwards.md) |
| "查看我的转发" / "转发列表" | `/api/v1/forward/list` | [forwards](references/forwards.md) |
| "查看流量" / "流量统计" | `/api/v1/forward/list` or `/api/v1/user/package` | [forwards](references/forwards.md) |
| "诊断转发" / "测试连通性" | `/api/v1/forward/diagnose` | [forwards](references/forwards.md) |
| "创建限速规则" | `/api/v1/speed-limit/create` | [speed-limits](references/speed-limits.md) |
| "联邦共享" / "节点共享" | `/api/v1/federation/share/create` | [federation](references/federation.md) |
| "导出备份" | `/api/v1/backup/export` | [backup](references/backup.md) |
| "导入备份" | `/api/v1/backup/import` | [backup](references/backup.md) |
## HTTP Request Template
### Bash/curl (with auto-login)
```bash
#!/bin/bash
BASE_URL="${FLVX_BASE_URL}"
USERNAME="${FLVX_USERNAME}"
PASSWORD="${FLVX_PASSWORD}"
# Login and get token
TOKEN=$(curl -s -X POST "${BASE_URL}/api/v1/user/login" \
-H "Content-Type: application/json" \
-d "{\"username\":\"${USERNAME}\",\"password\":\"${PASSWORD}\"}" | jq -r '.data.token')
if [ "$TOKEN" == "null" ] || [ -z "$TOKEN" ]; then
echo "Login failed"
exit 1
fi
# Use token for API calls - NOTE: NO "Bearer" prefix!
curl -s -X POST "${BASE_URL}/api/v1/node/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.'
```
### Python (requests)
```python
import os
import requests
BASE_URL = os.environ.get("FLVX_BASE_URL")
USERNAME = os.environ.get("FLVX_USERNAME")
PASSWORD = os.environ.get("FLVX_PASSWORD")
# Login
resp = requests.post(f"{BASE_URL}/api/v1/user/login",
headers={"Content-Type": "application/json"},
json={"username": USERNAME, "password": PASSWORD})
result = resp.json()
if result["code"] != 0:
raise Exception(f"Login failed: {result['msg']}")
TOKEN = result["data"]["token"]
# Authenticated request - NO "Bearer" prefix!
headers = {
"Content-Type": "application/json",
"Authorization": TOKEN
}
resp = requests.post(f"{BASE_URL}/api/v1/node/list", headers=headers, json={})
print(resp.json())
```
### Node.js (fetch)
```javascript
const BASE_URL = process.env.FLVX_BASE_URL;
const USERNAME = process.env.FLVX_USERNAME;
const PASSWORD = process.env.FLVX_PASSWORD;
// Login
const loginRes = await fetch(`${BASE_URL}/api/v1/user/login`, {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ username: USERNAME, password: PASSWORD })
});
const loginData = await loginRes.json();
if (loginData.code !== 0) throw new Error(loginData.msg);
const TOKEN = loginData.data.token;
// Authenticated request - NO "Bearer" prefix!
const res = await fetch(`${BASE_URL}/api/v1/node/list`, {
method: 'POST',
headers: {
'Content-Type': 'application/json',
'Authorization': TOKEN
},
body: JSON.stringify({})
});
console.log(await res.json());
```
## Response Handling
**Success:**
```json
{"code": 0, "msg": "success", "data": {...}, "ts": 1706659200000}
```
**Error:**
```json
{"code": -1, "msg": "用户名或密码错误", "ts": 1706659200000}
```
**Pattern:**
```
1. Parse JSON response
2. If code === 0 → return data
3. If code === 401 → token expired, re-login and retry
4. If code === 403 → permission denied, need admin
5. Else → show msg to user as error message
```
## Permission Model
| role_id | Type | Access |
|---------|------|--------|
| 0 | Admin | All endpoints |
| 1 | Regular | Forward CRUD, own profile, assigned tunnels only |
Non-admin users can only see/modify their own resources.
## Module Reference
| Module | Endpoints | Reference |
|--------|-----------|-----------|
| Auth | login, captcha | [auth.md](references/auth.md) |
| Users | CRUD, reset, password | [users.md](references/users.md) |
| Nodes | CRUD, install, upgrade, status | [nodes.md](references/nodes.md) |
| Tunnels | CRUD, user assignment | [tunnels.md](references/tunnels.md) |
| Forwards | CRUD, pause/resume, diagnose | [forwards.md](references/forwards.md) |
| Groups | User/tunnel groups, permissions | [groups.md](references/groups.md) |
| Speed Limits | CRUD | [speed-limits.md](references/speed-limits.md) |
| Federation | Share, remote nodes | [federation.md](references/federation.md) |
| Backup | Export/import | [backup.md](references/backup.md) |
| Config | System settings | [config.md](references/config.md) |
| Types | TypeScript interfaces | [types.md](references/types.md) |
| Errors | Error codes | [errors.md](references/errors.md) |
| Examples | Code samples | [examples/](references/examples/) |
## Critical Rules
1. ⚠️ **NO "Bearer" prefix** - `Authorization: <token>`, NOT `Authorization: Bearer <token>`
2. **All endpoints use POST** - Including list/get operations
3. **code === 0 means success** - Any other value is an error
4. **Traffic units**: User.flow is GB, in_flow/out_flow are bytes
5. **Timestamps**: All timestamps are milliseconds since epoch
6. **Token is session-scoped**: Cache in memory only, not on disk
## Common Workflows
### Workflow 1: New User Onboarding (Admin)
```
1. POST /api/v1/user/create → Create user with traffic quota
2. POST /api/v1/tunnel/user/assign → Assign tunnels to user
3. Tell user their username/password
4. User logs in and creates forwards
```
### Workflow 2: Add New Node (Admin)
```
1. POST /api/v1/node/create → Register node in panel
2. POST /api/v1/node/install → Get install command
3. Run install command on target server
4. POST /api/v1/node/check-status → Verify node is online
```
### Workflow 3: Create Forward (Any User)
```
1. POST /api/v1/tunnel/user/tunnel → List available tunnels
2. POST /api/v1/forward/create → Create forward on chosen tunnel
3. POST /api/v1/forward/diagnose → Verify connectivity
```
### Workflow 4: Node Maintenance (Admin)
```
1. POST /api/v1/node/list → Check node statuses
2. POST /api/v1/node/releases → Check available versions
3. POST /api/v1/node/upgrade or /batch-upgrade → Upgrade nodes
4. POST /api/v1/node/rollback → Rollback if needed
```
+44
View File
@@ -0,0 +1,44 @@
{
"name": "@flvx/skill-api",
"version": "2.1.5",
"description": "Skill for AI assistants to operate FLVX panel via REST API. Supports OpenCode, OpenClaw, Claude Code.",
"keywords": [
"opencode",
"openclaw",
"claude-code",
"skill",
"flvx",
"api",
"traffic-forwarding",
"gost"
],
"license": "MIT",
"author": "FLVX Team",
"files": [
"SKILL.md",
"references/**/*"
],
"repository": {
"type": "git",
"url": "git+https://github.com/Sagit-chu/flvx.git",
"directory": "skills/flvx-api"
},
"bugs": {
"url": "https://github.com/Sagit-chu/flvx/issues"
},
"homepage": "https://github.com/Sagit-chu/flvx/tree/main/skills/flvx-api#readme",
"publishConfig": {
"access": "public",
"registry": "https://registry.npmjs.org"
},
"opencode": {
"skill": true,
"installTo": "~/.agents/skills/flvx-api"
},
"scripts": {
"postinstall": "node -e \"const fs=require('fs');const path=require('path');const target=path.join(process.env.HOME,'.agents','skills','flvx-api');const src=process.cwd();try{fs.mkdirSync(path.dirname(target),{recursive:true});if(fs.existsSync(target)||fs.lstatSync(target).isSymbolicLink()){fs.unlinkSync(target)}fs.symlinkSync(src,target);console.log('✓ Installed to',target)}catch(e){console.error('Manual install: ln -s',src,target)}\"",
"preuninstall": "node -e \"const target=require('path').join(process.env.HOME,'.agents','skills','flvx-api');try{require('fs').unlinkSync(target);console.log('✓ Removed',target)}catch(e){}\"",
"link": "node -e \"const fs=require('fs');const path=require('path');const target=path.join(process.env.HOME,'.agents','skills','flvx-api');const src=process.cwd();try{fs.mkdirSync(path.dirname(target),{recursive:true});if(fs.existsSync(target)||fs.lstatSync(target).isSymbolicLink()){fs.unlinkSync(target)}fs.symlinkSync(src,target);console.log('✓ Linked to',target)}catch(e){console.error(e)}\"",
"unlink": "node -e \"const target=require('path').join(process.env.HOME,'.agents','skills','flvx-api');try{require('fs').unlinkSync(target);console.log('✓ Unlinked',target)}catch(e){}\""
}
}
+151
View File
@@ -0,0 +1,151 @@
# Authentication API
## POST /api/v1/user/login
Authenticate and obtain JWT token.
**Request:**
```json
{
"username": "admin",
"password": "secret",
"captchaId": "optional-captcha-id"
}
```
**Response:**
```json
{
"code": 0,
"msg": "success",
"data": {
"token": "eyJhbGciOiJIUzI1NiIs...",
"name": "Administrator",
"role_id": 0,
"requirePasswordChange": false
},
"ts": 1706659200000
}
```
**Response Fields:**
| Field | Type | Description |
|-------|------|-------------|
| token | string | JWT token for subsequent requests |
| name | string | User's display name |
| role_id | number | 0 = admin, 1 = regular user |
| requirePasswordChange | boolean | Whether password change is required |
## JWT Token Details
**Algorithm:** HMAC-SHA256
**Lifetime:** 90 days
**Token Claims:**
```json
{
"sub": "1",
"user": "admin",
"name": "Administrator",
"role_id": 0,
"iat": 1706659200,
"exp": 1738195200
}
```
## POST /api/v1/captcha/check
Check if captcha verification is required.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": {
"enabled": true,
"type": "turnstile"
}
}
```
## POST /api/v1/captcha/verify
Verify captcha response (Cloudflare Turnstile or local captcha).
**Request:**
```json
{
"captchaId": "captcha-session-id",
"captchaValue": "user-captcha-response"
}
```
## Token Usage
Include the token in all authenticated requests:
```bash
curl -X POST "${FLVX_BASE_URL}/api/v1/node/list" \
-H "Authorization: eyJhbGciOiJIUzI1NiIs..." \
-H "Content-Type: application/json" \
-d '{}'
```
⚠️ **CRITICAL: Do NOT add "Bearer " prefix!**
```
✅ Correct: Authorization: eyJhbGciOiJIUzI1NiIs...
❌ Incorrect: Authorization: Bearer eyJhbGciOiJIUzI1NiIs...
```
## POST /api/v1/user/updatePassword
Change current user's password.
**Request:**
```json
{
"oldPassword": "current-password",
"newPassword": "new-password"
}
```
**Response:**
```json
{"code": 0, "msg": "success"}
```
## POST /api/v1/user/package
Get current user's package info (tunnels, forwards, traffic stats).
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": {
"flow": 100,
"inFlow": 1073741824,
"outFlow": 2147483648,
"tunnels": 5,
"forwards": 10,
"expTime": 1735689600000
}
}
```
**Fields:**
| Field | Type | Description |
|-------|------|-------------|
| flow | number | Total traffic quota in GB |
| inFlow | number | Used upload in bytes |
| outFlow | number | Used download in bytes |
| tunnels | number | Number of assigned tunnels |
| forwards | number | Number of forwards created |
| expTime | number | Account expiry timestamp (ms) |
+143
View File
@@ -0,0 +1,143 @@
# Backup & Restore API
Export and import system data for backup, migration, or disaster recovery.
## POST /api/v1/backup/export
Export system data.
**Request:**
```json
{
"types": ["users", "nodes", "tunnels", "forwards", "speed_limits", "groups"]
}
```
If `types` is empty or omitted, exports all data.
**Available types:**
- `users` - User accounts
- `nodes` - Node configurations
- `tunnels` - Tunnel configurations
- `forwards` - Forward rules
- `speed_limits` - Speed limit rules
- `groups` - User/tunnel groups and permissions
- `configs` - System configurations
**Response:**
```json
{
"code": 0,
"data": {
"version": "2.1.5",
"exportedAt": 1706659200000,
"types": ["users", "nodes", "tunnels"],
"users": [...],
"nodes": [...],
"tunnels": [...],
"forwards": [...],
"speedLimits": [...],
"tunnelGroups": [...],
"userGroups": [...],
"groupPermissions": [...],
"configs": {...}
}
}
```
## POST /api/v1/backup/import
Import system data from a backup.
**Request:**
```json
{
"version": "2.1.5",
"exportedAt": 1706659200000,
"types": ["users", "nodes"],
"users": [...],
"nodes": [...]
}
```
**Import Behavior:**
- Existing records are updated if IDs match
- New records are created for non-existent IDs
- Related entities must be included (e.g., forwards require tunnels)
**Response:**
```json
{
"code": 0,
"msg": "success",
"data": {
"imported": {
"users": 5,
"nodes": 3,
"tunnels": 10
},
"skipped": {
"forwards": 2
}
}
}
```
## POST /api/v1/backup/restore
Alias for `/api/v1/backup/import`.
---
## Workflow: Full System Backup
```bash
# Export all data
curl -s -X POST "${FLVX_BASE_URL}/api/v1/backup/export" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' > backup-$(date +%Y%m%d).json
echo "Backup saved to backup-$(date +%Y%m%d).json"
```
## Workflow: Partial Export
```bash
# Export only users and tunnels
curl -s -X POST "${FLVX_BASE_URL}/api/v1/backup/export" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"types":["users","tunnels"]}' > partial-backup.json
```
## Workflow: Restore from Backup
```bash
# Import from backup file
curl -s -X POST "${FLVX_BASE_URL}/api/v1/backup/import" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d @backup-20260226.json | jq '.'
```
## Workflow: Migrate to New Panel
```bash
# On source panel
curl -s -X POST "${SOURCE_URL}/api/v1/backup/export" \
-H "Authorization: ${SOURCE_TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' > migration.json
# On target panel
curl -s -X POST "${TARGET_URL}/api/v1/backup/import" \
-H "Authorization: ${TARGET_TOKEN}" \
-H "Content-Type: application/json" \
-d @migration.json
```
**Note:** After migration, you may need to:
1. Reinstall node agents with new panel URL
2. Update node secrets if they differ
3. Reassign federation tokens
+149
View File
@@ -0,0 +1,149 @@
# System Configuration API
Manage system-wide settings and configurations.
## POST /api/v1/config/get
Get a single configuration by name. This endpoint is public (no auth required).
**Request:**
```json
{"name": "site_name"}
```
**Response:**
```json
{
"code": 0,
"data": {
"name": "site_name",
"value": "My FLVX Panel",
"time": 1706659200000
}
}
```
## POST /api/v1/config/list
List all configurations (requires authentication).
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": {
"site_name": "My FLVX Panel",
"site_logo": "https://example.com/logo.png",
"site_announcement": "System maintenance scheduled",
"captcha_enabled": "true",
"captcha_type": "turnstile",
"turnstile_site_key": "...",
"default_user_flow": "100",
"default_user_exp_days": "30"
}
}
```
## POST /api/v1/config/update
Batch update multiple configurations (admin only).
**Request:**
```json
{
"site_name": "New Panel Name",
"site_announcement": "Welcome to the new panel!",
"default_user_flow": "50"
}
```
Only include the keys you want to update.
**Response:**
```json
{"code": 0, "msg": "success"}
```
## POST /api/v1/config/update-single
Update a single configuration (admin only).
**Request:**
```json
{
"name": "site_name",
"value": "My Awesome Panel"
}
```
## POST /api/v1/announcement/get
Get the site announcement (public endpoint).
**Method:** GET
**Response:**
```json
{
"code": 0,
"data": {
"content": "System maintenance scheduled for tonight"
}
}
```
## POST /api/v1/announcement/update
Update the site announcement (admin only).
**Request:**
```json
{"content": "New announcement message"}
```
---
## Common Configuration Keys
| Key | Description | Example |
|-----|-------------|---------|
| `site_name` | Panel display name | `"My FLVX Panel"` |
| `site_logo` | Logo URL | `"https://example.com/logo.png"` |
| `site_announcement` | Announcement HTML | `"<p>Notice...</p>"` |
| `captcha_enabled` | Enable captcha | `"true"` or `"false"` |
| `captcha_type` | Captcha provider | `"turnstile"` or `"local"` |
| `turnstile_site_key` | Cloudflare Turnstile site key | `"0x4..."` |
| `turnstile_secret_key` | Cloudflare Turnstile secret | `"0x4..."` |
| `default_user_flow` | Default user traffic (GB) | `"100"` |
| `default_user_exp_days` | Default user expiry days | `"30"` |
| `default_user_num` | Default max forwards | `"10"` |
---
## Example: Update Panel Name and Announcement
```bash
curl -s -X POST "${FLVX_BASE_URL}/api/v1/config/update" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"site_name": "Awesome Traffic Panel",
"site_announcement": "<strong>Welcome!</strong> New nodes added."
}'
```
## Example: Enable Cloudflare Turnstile Captcha
```bash
curl -s -X POST "${FLVX_BASE_URL}/api/v1/config/update" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"captcha_enabled": "true",
"captcha_type": "turnstile",
"turnstile_site_key": "0x4AAAAAAAAjq0JN9YQg",
"turnstile_secret_key": "0x4AAAAAAAAjq0JN9YQg_secret"
}'
```
+168
View File
@@ -0,0 +1,168 @@
# Error Codes & Handling
## Response Code Field
| code | Meaning | Action |
|------|---------|--------|
| `0` | Success | Use `data` field |
| `-1` | Business error | Show `msg` to user |
| `-2` | Server/DB error | Retry or report bug |
| `401` | Unauthorized | Token expired/invalid, re-login |
| `403` | Forbidden | Need admin privileges |
## Common Error Messages (Chinese)
| msg | Cause | Solution |
|-----|-------|----------|
| 用户名或密码错误 | Wrong credentials | Check username/password |
| Token已过期 | Token expired | Re-login |
| 权限不足 | Need admin | Use admin account (role_id: 0) |
| 端口已被占用 | Port in use | Choose different port or delete conflicting forward |
| 流量不足 | Out of traffic | Contact admin or upgrade plan |
| 节点离线 | Node offline | Check node status, run install command |
| 隧道不可用 | Tunnel disabled | Enable tunnel first |
| 用户已存在 | Username taken | Choose different username |
| 参数错误 | Invalid request | Check request body format |
| 转发数量已达上限 | Forward limit reached | Delete unused forwards or contact admin |
| 该隧道未分配给当前用户 | No tunnel access | Contact admin to get tunnel assigned |
## Error Handling Pattern
### JavaScript/TypeScript
```typescript
async function callApi<T>(endpoint: string, data: object): Promise<T> {
const res = await fetch(`${BASE_URL}${endpoint}`, {
method: "POST",
headers: {
"Content-Type": "application/json",
"Authorization": TOKEN,
},
body: JSON.stringify(data),
});
const result = await res.json();
if (result.code === 0) {
return result.data;
}
switch (result.code) {
case 401:
// Token expired - clear and retry
TOKEN = null;
throw new Error("登录已过期,请重新登录");
case 403:
throw new Error("权限不足,需要管理员权限");
case -2:
throw new Error("服务器错误,请稍后重试");
default:
throw new Error(result.msg || "操作失败");
}
}
```
### Python
```python
def call_api(endpoint: str, data: dict = None) -> dict:
global TOKEN
headers = {"Content-Type": "application/json"}
if TOKEN:
headers["Authorization"] = TOKEN
resp = requests.post(f"{BASE_URL}{endpoint}", headers=headers, json=data or {})
result = resp.json()
if result["code"] == 0:
return result.get("data")
if result["code"] == 401:
TOKEN = None
raise Exception("登录已过期,请重新登录")
elif result["code"] == 403:
raise Exception("权限不足,需要管理员权限")
elif result["code"] == -2:
raise Exception("服务器错误,请稍后重试")
else:
raise Exception(result["msg"] or "操作失败")
```
### Bash
```bash
call_api() {
local endpoint="$1"
local data="$2"
local response
response=$(curl -s -X POST "${FLVX_BASE_URL}${endpoint}" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d "$data")
local code
code=$(echo "$response" | jq -r '.code')
if [ "$code" == "0" ]; then
echo "$response" | jq '.data'
return 0
fi
local msg
msg=$(echo "$response" | jq -r '.msg')
case "$code" in
401) echo "Error: 登录已过期" >&2 ;;
403) echo "Error: 权限不足" >&2 ;;
-2) echo "Error: 服务器错误" >&2 ;;
*) echo "Error: $msg" >&2 ;;
esac
return 1
}
```
## Retry Logic with Auto Re-login
```typescript
async function callApiWithRetry<T>(
endpoint: string,
data: object,
maxRetries = 1
): Promise<T> {
let lastError: Error;
for (let i = 0; i <= maxRetries; i++) {
try {
if (!TOKEN) {
await login();
}
return await callApi<T>(endpoint, data);
} catch (error) {
lastError = error;
if (error.message.includes("过期") || error.message.includes("expired")) {
TOKEN = null; // Force re-login on next attempt
continue;
}
throw error;
}
}
throw lastError!;
}
```
## Validation Errors
When request validation fails, the API returns code -1 with specific messages:
| Scenario | Error Message |
|----------|--------------|
| Missing required field | `参数错误` or field-specific message |
| Invalid port range | `端口范围无效` |
| Invalid IP format | `IP地址格式错误` |
| Invalid date | `时间格式错误` |
| Username too short | `用户名长度不能少于3个字符` |
| Password too weak | `密码长度不能少于6个字符` |
@@ -0,0 +1,256 @@
# curl Examples
Quick reference for common operations using curl.
## Setup
```bash
# Set environment variables
export FLVX_BASE_URL="https://your-panel.example.com"
export FLVX_USERNAME="admin"
export FLVX_PASSWORD="your-password"
# Login and save token
TOKEN=$(curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/login" \
-H "Content-Type: application/json" \
-d "{\"username\":\"${FLVX_USERNAME}\",\"password\":\"${FLVX_PASSWORD}\"}" \
| jq -r '.data.token')
echo "Token: ${TOKEN:0:20}..."
```
## User Operations
```bash
# Get my package info
curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/package" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.'
# List all users (admin)
curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"page":1,"pageSize":20}' | jq '.'
# Create user (admin)
curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"user": "alice",
"pwd": "SecurePass123!",
"name": "Alice",
"flow": 50,
"num": 10,
"expTime": 1767225600000
}' | jq '.'
# Reset user traffic
curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/reset" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":2,"type":"user"}' | jq '.'
# Delete user
curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/delete" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":2}' | jq '.'
```
## Node Operations
```bash
# List nodes with status
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.data.list[] | {name, status: (.status == 1), ip: .server_ip}'
# Create node
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"name":"US-Node-1","serverIp":"203.0.113.10"}' | jq '.'
# Get install command
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/install" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":2}' | jq -r '.data.command'
# Check node status
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/check-status" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.'
# Upgrade node
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/upgrade" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":2,"version":"2.1.5"}' | jq '.'
# Delete node
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/delete" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":2}' | jq '.'
```
## Tunnel Operations
```bash
# List tunnels
curl -s -X POST "${FLVX_BASE_URL}/api/v1/tunnel/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.data.list[] | {id, name, status}'
# Create tunnel
curl -s -X POST "${FLVX_BASE_URL}/api/v1/tunnel/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "HK-US-Tunnel",
"type": 1,
"inNodeId": [1],
"outNodeId": [2]
}' | jq '.'
# Assign tunnel to user
curl -s -X POST "${FLVX_BASE_URL}/api/v1/tunnel/user/assign" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"userId":2,"tunnelId":1,"flow":30}' | jq '.'
# Get available tunnels (for current user)
curl -s -X POST "${FLVX_BASE_URL}/api/v1/tunnel/user/tunnel" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.'
```
## Forward Operations
```bash
# List forwards with traffic
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.data.list[] | {
name,
tunnel: .tunnel_name,
port: .in_port,
target: .remote_addr,
status: (if .status == 1 then "running" else "paused" end),
upload_gb: ((.in_flow / 1073741824) | floor),
download_gb: ((.out_flow / 1073741824) | floor)
}'
# Create forward
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "my-web-server",
"tunnelId": 1,
"remoteAddr": "192.168.1.100:80",
"strategy": "fifo"
}' | jq '.'
# Create forward with load balancing
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "web-cluster",
"tunnelId": 1,
"remoteAddr": "10.0.0.1:80,10.0.0.2:80,10.0.0.3:80",
"strategy": "round"
}' | jq '.'
# Pause forward
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/pause" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":1}' | jq '.'
# Resume forward
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/resume" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":1}' | jq '.'
# Diagnose forward
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/diagnose" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":1}' | jq '.'
# Delete forward
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/delete" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"id":1}' | jq '.'
# Batch pause forwards
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/batch-pause" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"ids":[1,2,3]}' | jq '.'
```
## Backup Operations
```bash
# Export all data
curl -s -X POST "${FLVX_BASE_URL}/api/v1/backup/export" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' > backup-$(date +%Y%m%d).json
# Export specific types
curl -s -X POST "${FLVX_BASE_URL}/api/v1/backup/export" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"types":["users","tunnels"]}' > partial-backup.json
# Import backup
curl -s -X POST "${FLVX_BASE_URL}/api/v1/backup/import" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d @backup-20260226.json | jq '.'
```
## Helper Functions
```bash
# Add to ~/.bashrc or ~/.zshrc
flvx-login() {
export FLVX_BASE_URL="${1:-$FLVX_BASE_URL}"
TOKEN=$(curl -s -X POST "${FLVX_BASE_URL}/api/v1/user/login" \
-H "Content-Type: application/json" \
-d "{\"username\":\"${FLVX_USERNAME}\",\"password\":\"${FLVX_PASSWORD}\"}" \
| jq -r '.data.token')
export FLVX_TOKEN="$TOKEN"
echo "Logged in. Token: ${TOKEN:0:20}..."
}
flvx-api() {
local endpoint="$1"
local data="${2:-{}}"
curl -s -X POST "${FLVX_BASE_URL}${endpoint}" \
-H "Authorization: ${FLVX_TOKEN}" \
-H "Content-Type: application/json" \
-d "$data" | jq '.'
}
# Usage:
# flvx-login
# flvx-api /api/v1/node/list
# flvx-api /api/v1/forward/list '{"keyword":"web"}'
```
@@ -0,0 +1,603 @@
# HTTP Client Examples
Complete, runnable examples for various languages.
## Bash / curl
### Complete Script with Auto-Login
```bash
#!/bin/bash
set -e
# Configuration
BASE_URL="${FLVX_BASE_URL:?FLVX_BASE_URL not set}"
USERNAME="${FLVX_USERNAME:?FLVX_USERNAME not set}"
PASSWORD="${FLVX_PASSWORD:?FLVX_PASSWORD not set}"
# Login and get token
echo "Logging in..."
LOGIN_RESPONSE=$(curl -s -X POST "${BASE_URL}/api/v1/user/login" \
-H "Content-Type: application/json" \
-d "{\"username\":\"${USERNAME}\",\"password\":\"${PASSWORD}\"}")
TOKEN=$(echo "$LOGIN_RESPONSE" | jq -r '.data.token // empty')
if [ -z "$TOKEN" ]; then
echo "Login failed: $(echo "$LOGIN_RESPONSE" | jq -r '.msg')"
exit 1
fi
echo "Logged in successfully"
# API call helper
api_call() {
local endpoint="$1"
local data="${2:-{}}"
curl -s -X POST "${BASE_URL}${endpoint}" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d "$data"
}
# Examples
echo "=== My Package Info ==="
api_call "/api/v1/user/package" | jq '.'
echo -e "\n=== Node List ==="
api_call "/api/v1/node/list" '{}' | jq '.data.list[] | {name, status: (.status == 1)}'
echo -e "\n=== Forward List ==="
api_call "/api/v1/forward/list" '{}' | jq '.data.list[] | {name, tunnel: .tunnel_name, port: .in_port, target: .remote_addr}'
```
### Create Forward Script
```bash
#!/bin/bash
BASE_URL="${FLVX_BASE_URL}"
TOKEN="${FLVX_TOKEN}" # Pre-obtained token
create_forward() {
local name="$1"
local tunnel_id="$2"
local remote_addr="$3"
curl -s -X POST "${BASE_URL}/api/v1/forward/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d "{
\"name\": \"${name}\",
\"tunnelId\": ${tunnel_id},
\"remoteAddr\": \"${remote_addr}\",
\"strategy\": \"fifo\"
}" | jq '.'
}
# Usage: ./create-forward.sh "my-web" 1 "192.168.1.100:80"
create_forward "$@"
```
---
## Python
### Complete Client Class
```python
#!/usr/bin/env python3
"""FLVX API Client"""
import os
import requests
from typing import Optional, Any, Dict, List
class FlvxError(Exception):
"""FLVX API Error"""
def __init__(self, code: int, message: str):
self.code = code
self.message = message
super().__init__(message)
class FlvxClient:
"""FLVX API Client with auto-login"""
def __init__(
self,
base_url: Optional[str] = None,
username: Optional[str] = None,
password: Optional[str] = None
):
self.base_url = base_url or os.environ.get("FLVX_BASE_URL")
self.username = username or os.environ.get("FLVX_USERNAME")
self.password = password or os.environ.get("FLVX_PASSWORD")
if not all([self.base_url, self.username, self.password]):
raise ValueError("Missing credentials. Set FLVX_BASE_URL, FLVX_USERNAME, FLVX_PASSWORD")
self.token: Optional[str] = None
def _login(self) -> None:
"""Authenticate and store token"""
resp = requests.post(
f"{self.base_url}/api/v1/user/login",
headers={"Content-Type": "application/json"},
json={"username": self.username, "password": self.password}
)
result = resp.json()
if result["code"] != 0:
raise FlvxError(result["code"], result["msg"])
self.token = result["data"]["token"]
def _headers(self) -> Dict[str, str]:
"""Get request headers with auth"""
headers = {"Content-Type": "application/json"}
if self.token:
headers["Authorization"] = self.token # NO "Bearer " prefix!
return headers
def request(self, endpoint: str, data: Any = None) -> Any:
"""Make authenticated API request"""
if not self.token:
self._login()
resp = requests.post(
f"{self.base_url}{endpoint}",
headers=self._headers(),
json=data or {}
)
result = resp.json()
if result["code"] == 0:
return result.get("data")
if result["code"] == 401:
# Token expired, retry once
self.token = None
return self.request(endpoint, data)
raise FlvxError(result["code"], result["msg"])
# Convenience methods
def get_package(self) -> Dict:
"""Get current user's package info"""
return self.request("/api/v1/user/package", {})
def list_nodes(self) -> List[Dict]:
"""List all nodes"""
data = self.request("/api/v1/node/list", {})
return data.get("list", [])
def list_forwards(self, keyword: str = "") -> List[Dict]:
"""List forwards"""
data = self.request("/api/v1/forward/list", {"keyword": keyword})
return data.get("list", [])
def create_forward(
self,
name: str,
tunnel_id: int,
remote_addr: str,
strategy: str = "fifo",
speed_id: int = 0
) -> Dict:
"""Create a forward"""
return self.request("/api/v1/forward/create", {
"name": name,
"tunnelId": tunnel_id,
"remoteAddr": remote_addr,
"strategy": strategy,
"speedId": speed_id
})
def pause_forward(self, forward_id: int) -> None:
"""Pause a forward"""
self.request("/api/v1/forward/pause", {"id": forward_id})
def resume_forward(self, forward_id: int) -> None:
"""Resume a forward"""
self.request("/api/v1/forward/resume", {"id": forward_id})
def delete_forward(self, forward_id: int) -> None:
"""Delete a forward"""
self.request("/api/v1/forward/delete", {"id": forward_id})
# Usage example
if __name__ == "__main__":
client = FlvxClient()
# Get package info
pkg = client.get_package()
print(f"Traffic: {pkg['inFlow'] / 1e9:.2f}GB ↑ / {pkg['outFlow'] / 1e9:.2f}GB ↓")
print(f"Quota: {pkg['flow']}GB")
# List forwards with traffic
print("\nForwards:")
for fwd in client.list_forwards():
print(f" {fwd['name']}: {fwd['in_port']} → {fwd['remote_addr']}")
print(f" Traffic: {fwd['in_flow'] / 1e9:.2f}GB ↑ / {fwd['out_flow'] / 1e9:.2f}GB ↓")
```
---
## Node.js / TypeScript
### Complete Client Class
```typescript
// flvx-client.ts
interface APIResponse<T = unknown> {
code: number;
msg: string;
data?: T;
ts: number;
}
class FlvxError extends Error {
constructor(public code: number, message: string) {
super(message);
this.name = "FlvxError";
}
}
interface UserPackage {
flow: number;
inFlow: number;
outFlow: number;
tunnels: number;
forwards: number;
expTime: number;
}
interface Node {
id: number;
name: string;
status: number;
server_ip: string;
}
interface Forward {
id: number;
name: string;
tunnel_id: number;
tunnel_name: string;
in_port: number;
remote_addr: string;
status: number;
in_flow: number;
out_flow: number;
}
class FlvxClient {
private baseUrl: string;
private username: string;
private password: string;
private token?: string;
constructor(options?: {
baseUrl?: string;
username?: string;
password?: string;
}) {
this.baseUrl = options?.baseUrl ?? process.env.FLVX_BASE_URL ?? "";
this.username = options?.username ?? process.env.FLVX_USERNAME ?? "";
this.password = options?.password ?? process.env.FLVX_PASSWORD ?? "";
if (!this.baseUrl || !this.username || !this.password) {
throw new Error("Missing credentials. Set FLVX_BASE_URL, FLVX_USERNAME, FLVX_PASSWORD");
}
}
private async login(): Promise<void> {
const res = await fetch(`${this.baseUrl}/api/v1/user/login`, {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify({
username: this.username,
password: this.password,
}),
});
const result: APIResponse<{ token: string }> = await res.json();
if (result.code !== 0) {
throw new FlvxError(result.code, result.msg);
}
this.token = result.data!.token;
}
private async request<T>(endpoint: string, data?: object): Promise<T> {
if (!this.token) {
await this.login();
}
const res = await fetch(`${this.baseUrl}${endpoint}`, {
method: "POST",
headers: {
"Content-Type": "application/json",
Authorization: this.token!, // NO "Bearer " prefix!
},
body: JSON.stringify(data ?? {}),
});
const result: APIResponse<T> = await res.json();
if (result.code === 0) {
return result.data!;
}
if (result.code === 401) {
// Token expired, retry once
this.token = undefined;
return this.request<T>(endpoint, data);
}
throw new FlvxError(result.code, result.msg);
}
// Convenience methods
async getPackage(): Promise<UserPackage> {
return this.request("/api/v1/user/package", {});
}
async listNodes(): Promise<Node[]> {
const data = await this.request<{ list: Node[] }>("/api/v1/node/list", {});
return data.list ?? [];
}
async listForwards(keyword = ""): Promise<Forward[]> {
const data = await this.request<{ list: Forward[] }>("/api/v1/forward/list", {
keyword,
});
return data.list ?? [];
}
async createForward(options: {
name: string;
tunnelId: number;
remoteAddr: string;
strategy?: "fifo" | "round";
speedId?: number;
}): Promise<Forward> {
return this.request("/api/v1/forward/create", {
name: options.name,
tunnelId: options.tunnelId,
remoteAddr: options.remoteAddr,
strategy: options.strategy ?? "fifo",
speedId: options.speedId ?? 0,
});
}
async pauseForward(id: number): Promise<void> {
await this.request("/api/v1/forward/pause", { id });
}
async resumeForward(id: number): Promise<void> {
await this.request("/api/v1/forward/resume", { id });
}
async deleteForward(id: number): Promise<void> {
await this.request("/api/v1/forward/delete", { id });
}
}
export { FlvxClient, FlvxError };
// Usage
async function main() {
const client = new FlvxClient();
// Get package info
const pkg = await client.getPackage();
console.log(`Traffic: ${(pkg.inFlow / 1e9).toFixed(2)}GB ↑ / ${(pkg.outFlow / 1e9).toFixed(2)}GB ↓`);
console.log(`Quota: ${pkg.flow}GB`);
// List nodes
console.log("\nNodes:");
const nodes = await client.listNodes();
for (const node of nodes) {
console.log(` ${node.name}: ${node.status ? "Online" : "Offline"}`);
}
// List forwards
console.log("\nForwards:");
const forwards = await client.listForwards();
for (const fwd of forwards) {
console.log(` ${fwd.name}: ${fwd.in_port} → ${fwd.remote_addr}`);
}
}
main().catch(console.error);
```
---
## Go
### Complete Client Package
```go
// flvx/client.go
package flvx
import (
"bytes"
"encoding/json"
"fmt"
"io"
"net/http"
"os"
)
type Client struct {
BaseURL string
Username string
Password string
Token string
}
type Response struct {
Code int `json:"code"`
Msg string `json:"msg"`
Data json.RawMessage `json:"data"`
TS int64 `json:"ts"`
}
type FlvxError struct {
Code int
Message string
}
func (e *FlvxError) Error() string {
return fmt.Sprintf("FLVX error %d: %s", e.Code, e.Message)
}
func NewClient() *Client {
return &Client{
BaseURL: os.Getenv("FLVX_BASE_URL"),
Username: os.Getenv("FLVX_USERNAME"),
Password: os.Getenv("FLVX_PASSWORD"),
}
}
func (c *Client) Login() error {
payload := map[string]string{
"username": c.Username,
"password": c.Password,
}
var result struct {
Code int `json:"code"`
Msg string `json:"msg"`
Data struct {
Token string `json:"token"`
} `json:"data"`
}
if err := c.request("/api/v1/user/login", payload, &result); err != nil {
return err
}
if result.Code != 0 {
return &FlvxError{Code: result.Code, Message: result.Msg}
}
c.Token = result.Data.Token
return nil
}
func (c *Client) Request(endpoint string, data interface{}, result interface{}) error {
// Auto-login if no token
if c.Token == "" {
if err := c.Login(); err != nil {
return err
}
}
return c.request(endpoint, data, result)
}
func (c *Client) request(endpoint string, data interface{}, result interface{}) error {
body, err := json.Marshal(data)
if err != nil {
return err
}
req, err := http.NewRequest("POST", c.BaseURL+endpoint, bytes.NewReader(body))
if err != nil {
return err
}
req.Header.Set("Content-Type", "application/json")
if c.Token != "" {
req.Header.Set("Authorization", c.Token) // NO "Bearer " prefix!
}
resp, err := http.DefaultClient.Do(req)
if err != nil {
return err
}
defer resp.Body.Close()
respBody, err := io.ReadAll(resp.Body)
if err != nil {
return err
}
return json.Unmarshal(respBody, result)
}
// Convenience methods
func (c *Client) ListNodes() ([]map[string]interface{}, error) {
var result struct {
Code int `json:"code"`
Data struct {
List []map[string]interface{} `json:"list"`
} `json:"data"`
}
if err := c.Request("/api/v1/node/list", map[string]interface{}{}, &result); err != nil {
return nil, err
}
if result.Code != 0 {
return nil, &FlvxError{Code: result.Code, Message: "failed to list nodes"}
}
return result.Data.List, nil
}
func (c *Client) CreateForward(name string, tunnelID int, remoteAddr string) (map[string]interface{}, error) {
payload := map[string]interface{}{
"name": name,
"tunnelId": tunnelID,
"remoteAddr": remoteAddr,
"strategy": "fifo",
}
var result struct {
Code int `json:"code"`
Msg string `json:"msg"`
Data map[string]interface{} `json:"data"`
}
if err := c.Request("/api/v1/forward/create", payload, &result); err != nil {
return nil, err
}
if result.Code != 0 {
return nil, &FlvxError{Code: result.Code, Message: result.Msg}
}
return result.Data, nil
}
// Usage example
func Example() {
client := NewClient()
nodes, err := client.ListNodes()
if err != nil {
fmt.Println("Error:", err)
return
}
for _, node := range nodes {
fmt.Printf("Node: %v (status: %v)\n", node["name"], node["status"])
}
fwd, err := client.CreateForward("my-forward", 1, "192.168.1.100:80")
if err != nil {
fmt.Println("Error:", err)
return
}
fmt.Printf("Created forward: %v\n", fwd)
}
```
+281
View File
@@ -0,0 +1,281 @@
# Federation / Clustering API
Federation allows sharing nodes between FLVX panels. One panel can share nodes, and another panel can use them as remote nodes.
## Share Management (Admin)
### POST /api/v1/federation/share/list
List all peer shares.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": [
{
"id": 1,
"name": "Share-to-Partner",
"node_id": 1,
"node_name": "HK-Node-1",
"token": "share-token-abc123",
"max_bandwidth": 107374182400,
"expiry_time": 1767225600000,
"port_range_start": 10000,
"port_range_end": 20000,
"allowed_domains": "example.com,api.example.com",
"allowed_ips": "10.0.0.0/8,192.168.0.0/16",
"status": 1,
"created_at": 1706659200000
}
]
}
```
### POST /api/v1/federation/share/create
Create a peer share (share a node with another panel).
**Request:**
```json
{
"name": "Share-to-Partner",
"nodeId": 1,
"maxBandwidth": 107374182400,
"expiryTime": 1767225600000,
"portRangeStart": 10000,
"portRangeEnd": 20000,
"allowedDomains": "example.com,api.example.com",
"allowedIps": "10.0.0.0/8,192.168.0.0/16"
}
```
**Fields:**
| Field | Type | Required | Description |
|-------|------|----------|-------------|
| name | string | Yes | Share name |
| nodeId | number | Yes | Node to share |
| maxBandwidth | number | No | Max traffic in bytes (0 = unlimited) |
| expiryTime | number | No | Expiry timestamp in ms (0 = never) |
| portRangeStart | number | No | Allowed port range start |
| portRangeEnd | number | No | Allowed port range end |
| allowedDomains | string | No | Comma-separated domains |
| allowedIps | string | No | Comma-separated IPs/CIDRs |
**Response:**
```json
{
"code": 0,
"data": {
"id": 1,
"token": "share-token-abc123"
}
}
```
The `token` is what the remote panel uses to connect.
### POST /api/v1/federation/share/update
Update a peer share.
**Request:** Same as create, with `id` field required.
### POST /api/v1/federation/share/delete
Delete a peer share.
**Request:**
```json
{"id": 1}
```
### POST /api/v1/federation/share/reset-flow
Reset traffic counter for a share.
**Request:**
```json
{"id": 1}
```
### POST /api/v1/federation/share/remote-usage/list
List remote node usage statistics.
**Request:** `{}`
---
## Federation Runtime (Peer-to-Peer)
These endpoints use **Bearer token authentication** (different from JWT).
### POST /api/v1/federation/connect
Connect to a remote panel and get share info.
**Headers:**
```
Authorization: Bearer <share-token>
```
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": {
"nodeName": "HK-Node-1",
"allowedPorts": [10000, 20000],
"allowedDomains": ["example.com"],
"allowedIps": ["10.0.0.0/8"]
}
}
```
### POST /api/v1/federation/tunnel/create
Create a federation tunnel on the remote node.
**Headers:**
```
Authorization: Bearer <share-token>
```
**Request:**
```json
{
"tunnelId": 1,
"role": "entry"
}
```
### POST /api/v1/federation/runtime/reserve-port
Reserve a port on the remote node.
**Request:**
```json
{
"port": 15000,
"tunnelId": 1
}
```
### POST /api/v1/federation/runtime/apply-role
Apply for a role (entry/chain/exit) on the remote node.
**Request:**
```json
{
"tunnelId": 1,
"role": "exit"
}
```
### POST /api/v1/federation/runtime/release-role
Release a role on the remote node.
**Request:**
```json
{
"tunnelId": 1
}
```
### POST /api/v1/federation/runtime/diagnose
TCP ping diagnostics from remote node to target.
**Request:**
```json
{
"target": "10.0.0.1:80"
}
```
### POST /api/v1/federation/runtime/command
Execute a command on the remote node.
**Request:**
```json
{
"command": "status"
}
```
---
## Node Import (Admin)
### POST /api/v1/federation/node/import
Import a remote node from another panel.
**Request:**
```json
{
"name": "Remote-HK-Node",
"remoteUrl": "https://other-panel.example.com",
"remoteToken": "share-token-abc123"
}
```
This creates a node with `is_remote: 1`.
---
## Workflow: Share Node with Another Panel
**On the sharing panel (Panel A):**
```bash
# 1. Create a share
SHARE_RESP=$(curl -s -X POST "${FLVX_BASE_URL}/api/v1/federation/share/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "Share-HK-Node",
"nodeId": 1,
"portRangeStart": 10000,
"portRangeEnd": 20000,
"allowedIps": "0.0.0.0/0"
}')
SHARE_TOKEN=$(echo "$SHARE_RESP" | jq -r '.data.token')
echo "Share Token: $SHARE_TOKEN"
echo "Panel URL: ${FLVX_BASE_URL}"
```
**On the receiving panel (Panel B):**
```bash
# 2. Import the remote node
curl -s -X POST "${FLVX_BASE_URL}/api/v1/federation/node/import" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "Remote-HK-Node",
"remoteUrl": "https://panel-a.example.com",
"remoteToken": "share-token-abc123"
}'
# 3. Use the remote node in tunnels like a local node
curl -s -X POST "${FLVX_BASE_URL}/api/v1/tunnel/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "Federated-Tunnel",
"type": 1,
"inNodeId": [1],
"outNodeId": [2]
}'
```
+270
View File
@@ -0,0 +1,270 @@
# Forward Management API
Forwards are port forwarding rules created by users on their assigned tunnels.
## POST /api/v1/forward/list
List forwards. Non-admin users see only their own forwards.
**Request:**
```json
{
"page": 1,
"pageSize": 20,
"keyword": "",
"status": -1
}
```
**status filter:**
- `-1` = All
- `0` = Paused
- `1` = Running
**Response:**
```json
{
"code": 0,
"data": {
"list": [
{
"id": 1,
"user_id": 2,
"tunnel_id": 1,
"tunnel_name": "HK-US-Tunnel",
"name": "my-web-server",
"in_port": 10001,
"remote_addr": "192.168.1.100:80",
"strategy": "fifo",
"status": 1,
"speed_id": 0,
"speed_name": "",
"in_flow": 1073741824,
"out_flow": 2147483648,
"created_at": 1706659200000,
"updated_at": 1706659200000
}
],
"total": 1
}
}
```
## POST /api/v1/forward/create
Create a new forward.
**Request:**
```json
{
"name": "my-web-server",
"tunnelId": 1,
"remoteAddr": "192.168.1.100:80",
"strategy": "fifo",
"inPort": 0,
"speedId": 0
}
```
**Fields:**
| Field | Type | Required | Description |
|-------|------|----------|-------------|
| name | string | Yes | Forward name |
| tunnelId | number | Yes | Tunnel to use |
| remoteAddr | string | Yes | Target address(es), comma-separated for load balancing |
| strategy | string | No | "fifo" or "round" (default: "fifo") |
| inPort | number | No | Entry port (0 = auto-assign) |
| speedId | number | No | Speed limit rule ID (0 = no limit) |
**Strategy:**
- `fifo` = First target only
- `round` = Round-robin load balancing across targets
**Remote Address Format:**
- Single: `192.168.1.100:80`
- Multiple: `192.168.1.100:80,192.168.1.101:80,192.168.1.102:80`
**Response:**
```json
{
"code": 0,
"msg": "success",
"data": {
"id": 1,
"in_port": 10001
}
}
```
## POST /api/v1/forward/update
Update forward settings.
**Request:** Same as create, with `id` field required.
```json
{
"id": 1,
"name": "my-web-server-updated",
"remoteAddr": "192.168.1.100:8080",
"strategy": "round",
"speedId": 2
}
```
## POST /api/v1/forward/delete
Delete a forward.
**Request:**
```json
{"id": 1}
```
## POST /api/v1/forward/force-delete
Force delete a forward (even if in use).
**Request:**
```json
{"id": 1}
```
## POST /api/v1/forward/pause
Pause a forward (stops traffic but keeps configuration).
**Request:**
```json
{"id": 1}
```
**Response:**
```json
{"code": 0, "msg": "success"}
```
## POST /api/v1/forward/resume
Resume a paused forward.
**Request:**
```json
{"id": 1}
```
## POST /api/v1/forward/diagnose
Diagnose forward connectivity (TCP ping to target).
**Request:**
```json
{"id": 1}
```
**Response:**
```json
{
"code": 0,
"data": {
"reachable": true,
"latency_ms": 15,
"error": ""
}
}
```
## POST /api/v1/forward/update-order
Reorder forwards.
**Request:**
```json
{
"orders": [
{"id": 1, "order": 0},
{"id": 2, "order": 1}
]
}
```
## Batch Operations
### POST /api/v1/forward/batch-delete
```json
{"ids": [1, 2, 3]}
```
### POST /api/v1/forward/batch-pause
```json
{"ids": [1, 2, 3]}
```
### POST /api/v1/forward/batch-resume
```json
{"ids": [1, 2, 3]}
```
### POST /api/v1/forward/batch-redeploy
Recreate forwarding services on nodes.
```json
{"ids": [1, 2, 3]}
```
### POST /api/v1/forward/batch-change-tunnel
Move forwards to a different tunnel.
```json
{
"ids": [1, 2, 3],
"tunnelId": 5
}
```
## Traffic Units
| Field | Unit | Notes |
|-------|------|-------|
| in_flow | Bytes | Upload traffic |
| out_flow | Bytes | Download traffic |
Convert to GB: `in_flow / 1073741824`
## Example: Create Forward with Load Balancing
```bash
# Create forward with 3 backend servers
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{
"name": "web-cluster",
"tunnelId": 1,
"remoteAddr": "10.0.0.1:80,10.0.0.2:80,10.0.0.3:80",
"strategy": "round"
}'
```
## Example: Check Forward Status and Traffic
```bash
curl -s -X POST "${FLVX_BASE_URL}/api/v1/forward/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq '.data.list[] | {
name,
tunnel: .tunnel_name,
entry_port: .in_port,
target: .remote_addr,
status: (if .status == 1 then "running" else "paused" end),
upload_gb: (.in_flow / 1073741824 | floor),
download_gb: (.out_flow / 1073741824 | floor)
}'
```
+240
View File
@@ -0,0 +1,240 @@
# Group & Permission Management API
Groups organize users and tunnels, with permissions controlling access.
## Tunnel Groups
### POST /api/v1/group/tunnel/list
List all tunnel groups.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": [
{
"id": 1,
"name": "Premium-Tunnels",
"status": 1,
"tunnel_ids": [1, 2, 3],
"created_at": 1706659200000
}
]
}
```
### POST /api/v1/group/tunnel/create
Create a tunnel group.
**Request:**
```json
{
"name": "Premium-Tunnels",
"status": 1
}
```
### POST /api/v1/group/tunnel/update
Update tunnel group.
**Request:**
```json
{
"id": 1,
"name": "VIP-Tunnels",
"status": 1
}
```
### POST /api/v1/group/tunnel/delete
Delete tunnel group.
**Request:**
```json
{"id": 1}
```
### POST /api/v1/group/tunnel/assign
Assign tunnels to a group.
**Request:**
```json
{
"groupId": 1,
"tunnelIds": [1, 2, 3]
}
```
---
## User Groups
### POST /api/v1/group/user/list
List all user groups.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": [
{
"id": 1,
"name": "VIP-Users",
"status": 1,
"user_ids": [2, 3, 4],
"created_at": 1706659200000
}
]
}
```
### POST /api/v1/group/user/create
Create a user group.
**Request:**
```json
{
"name": "VIP-Users",
"status": 1
}
```
### POST /api/v1/group/user/update
Update user group.
**Request:**
```json
{
"id": 1,
"name": "Premium-Users",
"status": 1
}
```
### POST /api/v1/group/user/delete
Delete user group.
**Request:**
```json
{"id": 1}
```
### POST /api/v1/group/user/assign
Assign users to a group.
**Request:**
```json
{
"groupId": 1,
"userIds": [2, 3, 4]
}
```
---
## Permissions
Permissions link user groups to tunnel groups, allowing users in a user group to access tunnels in a tunnel group.
### POST /api/v1/group/permission/list
List all permissions.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": [
{
"id": 1,
"user_group_id": 1,
"user_group_name": "VIP-Users",
"tunnel_group_id": 1,
"tunnel_group_name": "Premium-Tunnels",
"created_at": 1706659200000
}
]
}
```
### POST /api/v1/group/permission/assign
Create a permission (grant user group access to tunnel group).
**Request:**
```json
{
"userGroupId": 1,
"tunnelGroupId": 1
}
```
**Response:**
```json
{"code": 0, "msg": "success", "data": {"id": 1}}
```
### POST /api/v1/group/permission/remove
Remove a permission.
**Request:**
```json
{"id": 1}
```
---
## Workflow: Set Up Group-Based Access
```bash
# 1. Create user group
curl -s -X POST "${FLVX_BASE_URL}/api/v1/group/user/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"name":"Standard-Users"}'
# Response: {"data":{"id":1}}
# 2. Create tunnel group
curl -s -X POST "${FLVX_BASE_URL}/api/v1/group/tunnel/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"name":"Standard-Tunnels"}'
# Response: {"data":{"id":1}}
# 3. Add tunnels to tunnel group
curl -s -X POST "${FLVX_BASE_URL}/api/v1/group/tunnel/assign" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"groupId":1,"tunnelIds":[1,2,3]}'
# 4. Add users to user group
curl -s -X POST "${FLVX_BASE_URL}/api/v1/group/user/assign" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"groupId":1,"userIds":[2,3,4]}'
# 5. Grant permission (user group -> tunnel group)
curl -s -X POST "${FLVX_BASE_URL}/api/v1/group/permission/assign" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"userGroupId":1,"tunnelGroupId":1}'
```
Now users 2, 3, 4 can access tunnels 1, 2, 3.
+266
View File
@@ -0,0 +1,266 @@
# Node Management API
All node endpoints require admin privileges (role_id: 0).
## POST /api/v1/node/list
List all nodes with status information.
**Request:**
```json
{
"page": 1,
"pageSize": 20,
"keyword": ""
}
```
**Response:**
```json
{
"code": 0,
"data": {
"list": [
{
"id": 1,
"name": "HK-Node-1",
"secret": "abc123...",
"server_ip": "1.2.3.4",
"server_ip_v4": "1.2.3.4",
"server_ip_v6": "2001:db8::1",
"port": "1000-65535",
"interface_name": "eth0",
"http": 1,
"tls": 1,
"socks": 1,
"tcp_listen_addr": "[::]",
"udp_listen_addr": "[::]",
"status": 1,
"is_remote": 0,
"version": "2.1.5",
"created_at": 1706659200000,
"updated_at": 1706659200000
}
],
"total": 1
}
}
```
**Status Values:**
- `0` = Offline
- `1` = Online
**is_remote Values:**
- `0` = Local node (managed by this panel)
- `1` = Remote node (federation from another panel)
## POST /api/v1/node/create
Create a new node.
**Request:**
```json
{
"name": "US-Node-1",
"serverIp": "5.6.7.8",
"serverIpV4": "5.6.7.8",
"serverIpV6": "2001:db8::2",
"port": "1000-65535",
"interfaceName": "eth0",
"http": 1,
"tls": 1,
"socks": 1,
"tcpListenAddr": "[::]",
"udpListenAddr": "[::]",
"isRemote": 0,
"remoteUrl": "",
"remoteToken": ""
}
```
**Fields:**
| Field | Type | Required | Description |
|-------|------|----------|-------------|
| name | string | Yes | Node name |
| serverIp | string | Yes | Primary server IP (display) |
| serverIpV4 | string | No | IPv4 address |
| serverIpV6 | string | No | IPv6 address |
| port | string | No | Allowed port range (default: "1000-65535") |
| interfaceName | string | No | Network interface for traffic |
| http | number | No | Enable HTTP protocol (1/0) |
| tls | number | No | Enable TLS protocol (1/0) |
| socks | number | No | Enable SOCKS protocol (1/0) |
| tcpListenAddr | string | No | TCP listen address (default: "[::]") |
| udpListenAddr | string | No | UDP listen address (default: "[::]") |
| isRemote | number | No | Federation node (1/0) |
| remoteUrl | string | If isRemote=1 | Remote panel URL |
| remoteToken | string | If isRemote=1 | Federation token |
**Response:**
```json
{"code": 0, "msg": "success", "data": {"id": 2, "secret": "xyz789..."}}
```
## POST /api/v1/node/install
Generate installation command for a node.
**Request:**
```json
{"id": 2}
```
**Response:**
```json
{
"code": 0,
"data": {
"command": "curl -fsSL https://panel.example.com/install.sh | bash -s -- --secret xyz789... --server https://panel.example.com"
}
}
```
## POST /api/v1/node/update
Update node configuration.
**Request:** Same fields as create, with `id` field required.
```json
{
"id": 2,
"name": "US-Node-1-Updated",
"serverIp": "5.6.7.8",
"http": 1,
"tls": 1,
"socks": 0
}
```
## POST /api/v1/node/delete
Delete a node.
**Request:**
```json
{"id": 2}
```
## POST /api/v1/node/batch-delete
Delete multiple nodes.
**Request:**
```json
{"ids": [2, 3, 4]}
```
## POST /api/v1/node/check-status
Refresh and check status of all nodes.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": {
"updated": 5,
"online": 4,
"offline": 1
}
}
```
## POST /api/v1/node/update-order
Reorder nodes (for display purposes).
**Request:**
```json
{
"orders": [
{"id": 1, "order": 0},
{"id": 2, "order": 1}
]
}
```
## POST /api/v1/node/releases
List available FLVX agent releases.
**Request:** `{}`
**Response:**
```json
{
"code": 0,
"data": [
{"version": "2.1.5", "published_at": 1706659200000},
{"version": "2.1.4", "published_at": 1706572800000}
]
}
```
## POST /api/v1/node/upgrade
Upgrade a single node agent.
**Request:**
```json
{
"id": 2,
"version": "2.1.5"
}
```
## POST /api/v1/node/batch-upgrade
Upgrade multiple node agents.
**Request:**
```json
{
"ids": [1, 2, 3],
"version": "2.1.5"
}
```
## POST /api/v1/node/rollback
Rollback node agent to previous version.
**Request:**
```json
{"id": 2}
```
## Example: Full Node Setup Workflow
```bash
# 1. Create node
RESPONSE=$(curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/create" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{"name":"SG-Node-1","serverIp":"203.0.113.10"}')
NODE_ID=$(echo "$RESPONSE" | jq -r '.data.id')
# 2. Get install command
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/install" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d "{\"id\":${NODE_ID}}"
# 3. Run install command on target server (manual step)
# 4. Verify node is online
curl -s -X POST "${FLVX_BASE_URL}/api/v1/node/list" \
-H "Authorization: ${TOKEN}" \
-H "Content-Type: application/json" \
-d '{}' | jq ".data.list[] | select(.id == $NODE_ID) | {name, status}"
```

Some files were not shown because too many files have changed in this diff Show More