Commit Graph
100 Commits
Author SHA1 Message Date
Sanaei 7b03346cfc Set package ecosystem to GitHub Actions in dependabot.yml 2026-03-17 21:03:32 +01:00
MHSanaei 258b08fff3 Update fail2ban filter regex in x-ui.sh 2026-03-08 11:53:34 +01:00
MHSanaei 52fdf5d429 v2.8.11 2026-03-04 13:54:01 +01:00
MHSanaei 34d8885075 Adjust KCP MTU when selecting xDNS mask 2026-03-04 13:39:14 +01:00
MHSanaei 5740996436 update dependencies 2026-03-04 13:05:29 +01:00
MHSanaei 37f0880f8f Bump Go to 1.26 2026-02-16 01:10:43 +01:00
MHSanaei 5b796672e9 Improve telego client robustness and retries
Add a createRobustFastHTTPClient helper to configure fasthttp.Client with better timeouts, connection limits, retries and optional SOCKS5 proxy dialing. Validate and sanitize proxy and API server URLs instead of returning early on invalid values, and build telego.Bot options dynamically. Reduce long-polling timeout to detect connection issues faster and adjust update retrieval comments. Implement exponential-backoff retry logic for SendMessage calls to handle transient connection/timeouts and improve delivery reliability; also reduce inter-message delay for better throughput.
2026-02-14 22:49:19 +01:00
MHSanaei 3fa0da38c9 Add timeouts and delays to backup sends
Add rate-limit friendly delays and context timeouts when sending backups via Telegram. Iterate admin IDs with index to sleep 1s between sends; add 30s context.WithTimeout for each SendDocument call and defer file.Close() for opened files; insert a 500ms pause between sending DB and config files. These changes improve resource cleanup and reduce chance of Telegram rate-limit/timeout failures.
2026-02-14 22:31:41 +01:00
MHSanaei 8eb1225734 translate bug fix #3789 2026-02-14 21:41:20 +01:00
MHSanaei e5c0fe3edf bug fix #3785 2026-02-11 22:21:09 +01:00
MHSanaei f4057989f5 Require HTTP 200 from curl before using IP
Replace simple curl+trim checks with a response+http_code parse to ensure the remote URL returns HTTP 200 and a non-empty body before assigning server_ip. Changes applied to install.sh, update.sh and x-ui.sh: use curl -w to append the status code, extract http_code and ip_result, and only set server_ip when http_code == 200 and ip_result is non-empty. This makes the IP discovery more robust against error pages or partial responses while keeping the existing timeout behavior.
2026-02-11 21:32:23 +01:00
MHSanaei 84013b0b3f v2.8.10 2026-02-11 18:21:43 +01:00
MHSanaei 511adffc5b Remove allowInsecure
Remove the deprecated `allowInsecure`
2026-02-11 18:21:23 +01:00
MHSanaei c2f409c3c4 fix security issue 2026-02-09 23:36:10 +01:00
MHSanaei 4a455aa532 Xray Core v26.2.6 and dependency updates
Update Xray download URLs to v26.2.6 in the GitHub Actions release workflow and DockerInit script. Bump Go toolchain to 1.25.7 and refresh several module versions (telego, xtls/xray-core, klauspost/compress, pires/go-proxyproto, golang.org/x/arch, golang.org/x/sys, google.golang.org/genproto, etc.). Update go.sum to match the new dependency versions.
2026-02-09 12:49:32 +01:00
SanaeiandCopilot Autofix powered by AI 5bb87fd3d4 fix : Uncontrolled data used in path expression
Co-Authored-By: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
2026-02-07 22:54:40 +01:00
MHSanaei f87c68ea68 Add workflow to clean old GitHub Actions caches
Adds a scheduled GitHub Actions workflow (.github/workflows/cleanup_caches.yml) that runs weekly (and via workflow_dispatch) to delete Actions caches not accessed in the last 3 days. The job uses the gh CLI with the repository token and actions: write permission to list caches, filter by last_accessed_at against a 3-day cutoff, and delete matching cache IDs.
2026-02-03 00:19:44 +01:00
MHSanaei ff128a7275 Xray Core v26.2.2 2026-02-02 17:57:56 +01:00
MHSanaei e8d2973be7 Finalmask: Add XICMP 2026-02-02 17:50:30 +01:00
MHSanaei f3d47ebb3f Refactor TLS peer cert verification settings
Removed verifyPeerCertByNames and pinnedPeerCertSha256 from inbound TLS settings and UI. Added verifyPeerCertByName and pinnedPeerCertSha256 to outbound TLS settings and updated the outbound form to support these fields. This change streamlines and clarifies certificate verification configuration between inbound and outbound settings.
2026-02-01 14:03:46 +01:00
MHSanaei 06c49b92f8 v2.8.9 2026-02-01 04:05:02 +01:00
MHSanaei e35213bc73 Update Xray-core to v26.1.31 and related dependencies
Bump Xray-core version to v26.1.31 in build scripts and server logic. Update Go dependencies including gopsutil, bytedance/sonic, circl, miekg/dns, go-proxyproto, sagernet/sing, and others to their latest versions. Adjust version check in GetXrayVersions to require at least v26.1.31.
2026-02-01 03:30:09 +01:00
MHSanaei aa6a886977 Add UDP hop interval min/max support for Hysteria
Replaces single UDP hop interval with separate min and max values in Hysteria stream settings. Updates model, JSON serialization, URL param parsing, and form fields for backward compatibility and enhanced configuration flexibility.
2026-02-01 03:20:29 +01:00
MHSanaei 9d603c5ad2 Add pinnedPeerCertSha256 support to TLS settings
Introduces the pinnedPeerCertSha256 field to TlsStreamSettings in the JS model and adds a corresponding input in the TLS settings form. This allows users to specify SHA256 fingerprints for peer certificate pinning, enhancing security configuration options.
2026-02-01 03:12:54 +01:00
MHSanaei a973fa6d68 XHTTP transport: New options for bypassing CDN's detection
https://github.com/XTLS/Xray-core/pull/5414
2026-02-01 02:58:18 +01:00
MHSanaei 3af6497577 inbound : finalmask 2026-02-01 02:36:57 +01:00
MHSanaei c59f54bb0e outbound: finalmask 2026-02-01 01:56:23 +01:00
MHSanaei d8c783a296 v2.8.8 2026-01-18 18:01:58 +01:00
MHSanaei 809f69729a Update minimum Xray version requirement
Raised the minimum required Xray version from 25.9.11 to 26.1.18 in GetXrayVersions. This ensures only newer versions are considered valid.
2026-01-18 17:50:00 +01:00
MHSanaei 93b7ce199f Add UDP mask support for Hysteria outbound
Introduces a 'congestion' option to Hysteria stream settings and updates the form to allow selection between BBR (Auto) and Brutal. Adds support for UDP masks, including model, serialization, and UI for adding/removing masks with type and password fields.
2026-01-18 17:38:05 +01:00
MHSanaei 2a76cec804 Add Hysteria2 outbound protocol support
Introduces support for the Hysteria2 protocol in outbound settings, including model, parsing, and form UI integration. Adds Hysteria2-specific stream and protocol settings, updates protocol selection, and enables configuration of Hysteria2 parameters in the outbound form.
2026-01-18 17:13:34 +01:00
MHSanaei 88eab032be Add TUN protocol for inbound
Introduces TUN protocol to inbound.js, including a new TunSettings class. Updates inbound form to support TUN protocol and adds a dedicated form template for TUN settings. Translation files are updated with TUN-related strings for all supported languages.
2026-01-18 16:47:01 +01:00
MHSanaei 20ec863f51 Xray Core v26.1.18 2026-01-18 16:06:19 +01:00
MHSanaei 8098d2b1b1 Return nil if no error in GetXrayErr
Added a check to return nil immediately if p.GetErr() returns nil in GetXrayErr, preventing further error handling when no error is present.
2026-01-13 17:40:52 +01:00
MHSanaei f8c9aac97c Add port selection and checks for ACME HTTP-01 listener
Introduces user prompts to select the port for ACME HTTP-01 certificate validation (default 80), checks if the chosen port is available, and provides guidance for port forwarding. Adds is_port_in_use helper to all scripts and improves messaging for certificate issuance and error handling.
2026-01-11 15:28:43 +01:00
MHSanaei e42c17f2b2 Default listen address to 0.0.0.0 in GenXrayInboundConfig
When the listen address is empty, it now defaults to 0.0.0.0 to ensure proper dual-stack IPv4/IPv6 binding, improving compatibility on systems with bindv6only=0.
2026-01-09 20:22:33 +01:00
MHSanaei 7b0a3929ff v2.8.7 2026-01-05 19:00:36 +01:00
MHSanaei 570ab8e5e0 Update OpenSSL installer to version 3.6.0
Replaced Win64OpenSSL_Light-3_5_3.exe with Win64OpenSSL_Light-3_6_0.exe in the windows_files/SSL directory to provide the latest OpenSSL version.
2026-01-05 18:49:30 +01:00
MHSanaei 1240e4c962 Update fasthttp to v1.69.0
Bump github.com/valyala/fasthttp from v1.68.0 to v1.69.0 in go.mod and go.sum to use the latest version.
2026-01-05 18:44:42 +01:00
MHSanaei c117b8b272 mtu to 1250 2026-01-05 18:10:06 +01:00
Sanaei a9770e1da2 ip cert (#3631) 2026-01-05 05:47:15 +01:00
MHSanaei 3f15d21f13 fix #3622 2026-01-03 22:31:31 +01:00
MHSanaei 947fd4fae1 fix 2026-01-03 07:27:39 +01:00
MHSanaei e69a31dd59 v2.8.6 2026-01-03 06:44:39 +01:00
MHSanaei 5bcf6a8aeb minor changes 2026-01-03 05:56:35 +01:00
MHSanaei 945fefde12 update dependencies 2026-01-03 05:36:05 +01:00
Sanaei 69ccdba734 Self-signed SSL (#3611) 2025-12-28 00:03:33 +01:00
MHSanaei 0ea8b5352a fix 2025-12-04 00:09:13 +01:00
MHSanaei 68240061aa Xray Core 25.12.2 2025-12-03 23:45:28 +01:00
MHSanaei 0695f677ba update dependencies 2025-12-03 23:45:11 +01:00
mhsanaei 784ed39930 update dependencies 2025-11-09 00:56:14 +01:00
mhsanaei 713a7328f6 gofmt 2025-10-21 13:02:55 +02:00
mhsanaei 01d4a7488d v2.8.5 2025-10-15 11:40:40 +02:00
mhsanaei 2b2ed3349a Xray-core v25.10.15 2025-10-15 11:40:04 +02:00
mhsanaei d8523bbdac fix(import): prevent sqlite disk I/O error by validating temp DB then swapping 2025-10-14 22:03:17 +02:00
mhsanaei b578a33518 update dependencies 2025-10-07 13:49:08 +02:00
mhsanaei 8153e0ac05 fragment : MaxSplit 2025-10-07 13:46:30 +02:00
mhsanaei 2eb9d2e2e8 DevTools 2025-10-02 01:47:12 +02:00
mhsanaei e7cfee570b first try native CPU implementation 2025-10-01 20:13:32 +02:00
mhsanaei ee0e3093ba Add IPv4 for wget in install 2025-09-25 15:08:13 +02:00
mhsanaei 89def9aee6 fix 2025-09-24 21:30:58 +02:00
mhsanaei b2b0024648 login: autocomplete password 2025-09-24 20:41:32 +02:00
mhsanaei 5822758b7c tiny changes 2025-09-24 19:51:01 +02:00
mhsanaei 49430b3991 Update docker.yml 2025-09-24 15:42:01 +02:00
mhsanaei 104526aab2 v2.8.4 2025-09-24 11:47:43 +02:00
mhsanaei a0c07241c0 minor changes 2025-09-24 11:47:14 +02:00
mhsanaei adf3242602 bug fix 2025-09-24 11:44:02 +02:00
mhsanaei 3f62592e4b API improve security: returns 404 for unauthenticated API requests 2025-09-24 11:29:55 +02:00
mhsanaei 26c6438ec2 fix api : subid, uuid from inbound settings 2025-09-23 11:52:40 +02:00
mhsanaei 1016f3b4f9 fix: outbound address for vless 2025-09-22 00:20:05 +02:00
mhsanaei 020bc9d77c v2.8.3 2025-09-21 21:20:45 +02:00
mhsanaei 5620d739c6 improved sub: BuildURLs 2025-09-21 21:20:37 +02:00
mhsanaei d518979e4f pageSize to 25 2025-09-21 20:47:34 +02:00
mhsanaei 83f8a03b50 TGbot: improved (5x faster) 2025-09-21 19:27:05 +02:00
mhsanaei b45e63a14a API: UUID for getClientTraffics 2025-09-21 19:16:54 +02:00
mhsanaei 55f1d72af5 security fix: Uncontrolled data used in path expression 2025-09-21 18:51:54 +02:00
Sanaei 806ecbd7c5 Merge pull request #3528 from MHSanaei/security
Security issue fixed
2025-09-21 18:05:26 +02:00
mhsanaei ae79b43cdb security fix: Use of insufficient randomness as the key of a cryptographic algorithm 2025-09-21 17:59:17 +02:00
mhsanaei e64e6327ef security fix: Uncontrolled data used in path expression 2025-09-21 17:52:18 +02:00
mhsanaei 9f024b9e6a security fix: Workflow with permissions CWE-275 2025-09-21 17:47:16 +02:00
mhsanaei eacfbc86b5 security fix: Command built from user-controlled sources CWE-78
https://cwe.mitre.org/data/definitions/78.html
https://owasp.org/www-community/attacks/Command_Injection
2025-09-21 17:39:30 +02:00
mhsanaei 37c17357fc undo vnext for vmess 2025-09-20 13:10:57 +02:00
mhsanaei b35d339665 update dependencies 2025-09-20 09:48:54 +02:00
mhsanaei 6ced549dea docs: add comments for all functions 2025-09-20 09:35:50 +02:00
mhsanaei f60682a6b7 new: VACUUM database 2025-09-19 17:14:39 +02:00
mhsanaei 50bd7a8040 better design for dns presets 2025-09-19 15:44:00 +02:00
mhsanaei 7465768ff7 fix: subpath panic 2025-09-19 14:39:21 +02:00
mhsanaei 5b00a52c65 fix: ineffectual assignment to needRestart 2025-09-19 10:47:28 +02:00
mhsanaei 151f1173a1 Fix ineffassign “date” 2025-09-19 10:46:49 +02:00
mhsanaei e262132b9d misspell 2025-09-19 10:35:03 +02:00
mhsanaei ca0a7aeb5a readme: Go Report Card,Go Reference 2025-09-19 10:29:34 +02:00
mhsanaei 7447cec17e go package correction v2 2025-09-19 10:05:43 +02:00
mhsanaei 0ffd27c0aa v2.8.2 2025-09-19 00:22:15 +02:00
mhsanaei 054cb1dea0 go package correction 2025-09-18 23:12:14 +02:00
mhsanaei e3883fca87 donate: nowpayments 2025-09-18 20:14:10 +02:00
mhsanaei b46a0b404b enhancements 2025-09-18 16:28:09 +02:00
mhsanaei 0ce58a095a vscode: Debug for developer 2025-09-18 14:33:51 +02:00
mhsanaei 59ea2645db new: subJsonEnable
after this subEnable by default is true
and subJsonEnable is false
2025-09-18 13:56:04 +02:00
mhsanaei 8c8d280f14 minor change 2025-09-18 12:20:21 +02:00
mhsanaei 170d24499e fix PeriodicTrafficResetJob: log only when there are matching inbound 2025-09-18 11:41:11 +02:00