Compare commits

...
25 Commits
Author SHA1 Message Date
orohiandCursor 53bffbd4fc Fix Mieru mita start RPC EOF by waiting for daemon socket and seeding users.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 14:39:56 +03:00
orohiandCursor 53638cf122 Show Mieru higher in server marketplace templates and add missing i18n keys.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 14:00:43 +03:00
test2 1f1234d217 Merge pull request 'Cursor/client domain and legacy json import' (#1) from cursor/client-domain-and-legacy-json-import into main
Reviewed-on: #1
2026-07-28 10:58:27 +00:00
orohiandCursor 9890e8cc3f Add optional Mieru (mita v3.28.0) install per server with mierus:// share links.
EOF

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 13:47:59 +03:00
orohiandCursor 32a0e90e19 Release v2.6.3: support page with SBP/card/crypto donate placeholders and admin settings.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 13:32:09 +03:00
orohiandCursor 73d0ee277d Add AWG/WireGuard connect-domain UI on server page and fix Traefik port for Dokploy.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 13:21:54 +03:00
orohiandCursor 9b4ef0f9f0 Use client connect domain in VPN configs and fix legacy JSON import to PostgreSQL.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 13:00:37 +03:00
orohiandCursor 78e69d899a Backup panel PostgreSQL database as .sql dump (v2.6.2).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 12:40:59 +03:00
orohiandCursor 2d62758716 Restore move connections between servers (v2.6.1).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 12:33:27 +03:00
orohiandCursor d26843a0d1 Release v2.6.0: stable Dokploy/Docker deployment bundle.
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 12:15:00 +03:00
orohiandCursor 706d2c9c0d Postgres healthcheck verifies password; document volume password mismatch (v2.5.11).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 12:06:07 +03:00
orohiandCursor 2746f981af Simplify Docker CMD to uvicorn directly (v2.5.10).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 11:59:43 +03:00
orohiandCursor 4f5a1d7554 Fix panel startup crash and remove move-connections feature (v2.5.9).
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-28 11:44:35 +03:00
orohi ff7cc5c592 v2.5.6: fix 404 after update without tunnel 2026-07-28 11:00:34 +03:00
orohi 2808a49fa5 v2.5.5: fix 404 after panel update 2026-07-28 10:26:08 +03:00
orohi 2973b96713 v2.5.4: move selected connections between servers 2026-07-28 10:14:08 +03:00
orohi 5d63e5d6ef v2.5.3: fix disabled Update panel button 2026-07-28 10:02:57 +03:00
orohi a5b8f26db1 v2.5.2: redesign Tunnels section in Settings 2026-07-28 09:48:19 +03:00
orohi 599e0a487c Enable true one-click panel update from Settings (v2.5.1).
Download release ZIP from git.evilfox.cc when git is unavailable, add upgrade_panel API, and show a primary Update panel button.
2026-07-28 09:41:51 +03:00
orohi 77c6f0dab7 Add NordVPN outbound control in Tunnels (v2.5.0).
Connect and disconnect via official nordvpn CLI from Settings with optional country/city, alongside Cloudflare WARP.
2026-07-28 09:34:10 +03:00
orohi fd257a59f7 Add one-click panel auto-update from git.evilfox.cc (v2.4.0).
Check Gitea releases in Settings and install the latest tag via git fetch/checkout with pip sync and restart when running from a git checkout.
2026-07-28 09:28:15 +03:00
orohi 6206697e3b Remove Cascade double-VPN (v2.3.0).
Drop cascade manager, API, server UI, and i18n keys after unstable egress/routing behavior.
2026-07-27 05:08:18 +03:00
orohi 4c19099b04 Fix i18n: strip UTF-8 BOM so translations load again.
PowerShell rewrites had added a BOM that made Python json.load fail, so the UI showed raw keys like nav_servers.
2026-07-27 04:40:44 +03:00
orohi 80160d0ef4 Fix Cascade egress verify to bind awg0 IP (v2.2.1).
Use client-subnet policy routing for curl checks instead of cascade peer Address; soft-warn when echo services fail but the route is OK.
2026-07-27 04:27:00 +03:00
orohi ac76a0e540 Release v2.2.0: restore safe Cascade double-VPN for servers.
Reintroduce entry-to-exit AmneziaWG/WireGuard cascade inspired by ryderams/amneziawg-cascade, with handshake and egress checks and no remote curl|bash.
2026-07-27 04:09:16 +03:00
29 changed files with 6758 additions and 2923 deletions
+10 -3
View File
@@ -2,11 +2,18 @@
APP_PORT=5000
SECRET_KEY=change-me-to-a-long-random-string
# PostgreSQL (used by docker-compose)
# PostgreSQL (docker-compose — same password for db + panel via DATABASE_URL)
POSTGRES_USER=amnezia
POSTGRES_PASSWORD=amnezia
POSTGRES_PASSWORD=change-me-strong-password
POSTGRES_DB=amnezia_panel
POSTGRES_PORT=5432
# Set once before first deploy. Changing POSTGRES_PASSWORD later requires resetting
# the amnezia_pgdata volume or the panel cannot connect (Postgres keeps the old password).
# Full DSN (override if panel runs outside compose)
# DATABASE_URL=postgresql://amnezia:amnezia@db:5432/amnezia_panel
# DATABASE_URL=postgresql://amnezia:change-me-strong-password@db:5432/amnezia_panel
# Dokploy / reverse proxy (optional — set in compose for Docker)
# PANEL_IN_DOCKER=1
# PANEL_BEHIND_PROXY=1
+1
View File
@@ -0,0 +1 @@
*.sh text eol=lf
+7 -4
View File
@@ -5,12 +5,15 @@ FROM python:3.12-slim
ENV PYTHONDONTWRITEBYTECODE=1 \
PYTHONUNBUFFERED=1 \
APP_PORT=5000 \
PORT=5000 \
PANEL_IN_DOCKER=1 \
PANEL_BEHIND_PROXY=1 \
PIP_DISABLE_PIP_VERSION_CHECK=1
WORKDIR /app
RUN apt-get update \
&& apt-get install -y --no-install-recommends curl \
&& apt-get install -y --no-install-recommends curl postgresql-client \
&& rm -rf /var/lib/apt/lists/*
COPY requirements.txt .
@@ -20,7 +23,7 @@ COPY . .
EXPOSE 5000
HEALTHCHECK --interval=30s --timeout=10s --start-period=40s --retries=3 \
CMD curl -fsS "http://127.0.0.1:${APP_PORT}/docs" >/dev/null || exit 1
HEALTHCHECK --interval=30s --timeout=10s --start-period=60s --retries=3 \
CMD curl -fsS "http://127.0.0.1:5000/health" >/dev/null || exit 1
CMD ["python3", "app.py"]
CMD ["uvicorn", "app:app", "--host", "0.0.0.0", "--port", "5000", "--proxy-headers", "--forwarded-allow-ips", "*"]
+131 -4
View File
@@ -1,6 +1,6 @@
# Amnezia Web Panel
A modern, high-performance web interface for managing **AmneziaWG**, **Classic WireGuard**, **Xray (XTLS-Reality)**, **Hysteria 2**, **NaiveProxy**, **Telemt (Telegram MTProxy)**, **Cloudflare WARP**, **AmneziaDNS**, **AdGuard Home**, **SOCKS5**, and **NGINX + Let's Encrypt** services on remote Ubuntu servers — from a single dashboard. Designed to provide a premium user experience with robust administrative capabilities.
A modern, high-performance web interface for managing **AmneziaWG**, **Classic WireGuard**, **Xray (XTLS-Reality)**, **Hysteria 2**, **NaiveProxy**, **Telemt (Telegram MTProxy)**, **Cloudflare WARP**, **NordVPN**, **AmneziaDNS**, **AdGuard Home**, **SOCKS5**, and **NGINX + Let's Encrypt** services on remote Ubuntu servers — from a single dashboard. Designed to provide a premium user experience with robust administrative capabilities.
> ### 🔄 Compatibility with Official Amnezia Client
>
@@ -66,6 +66,7 @@ Configuration panel for system parameters and preferences:
* **NaiveProxy** (stable): HTTPS/HTTP2 camouflage proxy via [klzgrad/naiveproxy](https://github.com/klzgrad/naiveproxy) (Caddy + [klzgrad/forwardproxy](https://github.com/klzgrad/forwardproxy) naïve fork). ACME TLS on the domain, per-client basic auth, `naive+https://` share links. Requires free TCP **80** and **443**. **Use Karing** as the client — do **not** use v2rayN; other clients are untested.
* **Telemt (Telegram MTProxy)**: High-performance Telegram MTProxy with TLS emulation and comprehensive management (quotas, IP limits, real-time session tracking). Robust install path that auto-configures Docker's official apt/yum repository when needed.
* **Cloudflare WARP**: Add and manage WARP-powered connectivity from the panel for routing and network flexibility.
* **NordVPN**: Connect/disconnect outbound NordVPN from Settings via the official CLI (optional country/city).
* **🛠 Services**:
* **AmneziaDNS**: Internal DNS resolver on a private docker network (`amnezia-dns-net`, IP `172.29.172.254`) to prevent DNS leaks and blockings.
* **AdGuard Home**: DNS-based ad blocker with a web admin UI. Two install modes: **Replace AmneziaDNS** (takes its IP, all VPN clients use AdGuard immediately) or **Side-by-side** (parallel deployment on `172.29.172.253`, web UI accessible only over the VPN by default). Optional opt-in checkboxes to expose the web UI / DoT / DoH on the host.
@@ -85,6 +86,11 @@ Configuration panel for system parameters and preferences:
* **🌐 Internationalization (i18n)**:
* Full support for **English**, **Russian**, **French**, **Chinese**, and **Persian**.
* Native **RTL (Right-to-Left)** support for Persian language.
* **🔄 Auto-update**:
* Settings → About checks releases on [git.evilfox.cc](https://git.evilfox.cc/test2/Amnezia-Web-Panel-main) and can install the latest tag via git + restart (when the panel runs from a git checkout).
* **🌍 Tunnels & outbound VPN**:
* **Cloudflare Quick Tunnel** and **ngrok** expose the local panel to the internet.
* **Cloudflare WARP** and **NordVPN** route the host outbound (no public panel URL).
* **👥 Advanced User Management**:
* Role-based access (Admin, Support, Regular User).
* Traffic limits, status monitoring, and account expiration.
@@ -182,22 +188,71 @@ Mac
```bash
cp .env.example .env
# set SECRET_KEY and strong POSTGRES_PASSWORD in .env
docker network inspect dokploy-network >/dev/null 2>&1 || docker network create dokploy-network
docker compose up -d --build
```
Panel: `http://localhost:5000` (or `APP_PORT` from `.env`).
### Dokploy (recommended)
The compose file connects the panel to Dokploy's Traefik network (`dokploy-network`) and exposes the app on **container port 5000** (not 80).
1. Deploy as **Docker Compose** from this repo (Dokploy creates `dokploy-network` automatically).
2. In Dokploy → your app → **Environment** (set **before first deploy**):
- `SECRET_KEY` — long random string
- `POSTGRES_PASSWORD` — strong password (same value is used for `db` and `amnezia_panel`)
3. In Dokploy → **Domains**:
- **Service**: `amnezia_panel` (not `db`)
- **Container port**: `5000`
- **Path**: `/`
4. **Deploy / Rebuild** (not Restart) after code or env changes.
**Verify on the server** (replace `PROJECT` and path with yours):
```bash
COMPOSE_DIR=/etc/dokploy/compose/home-vpn-g6rfpd/code
PROJECT=home-vpn-g6rfpd
docker compose -p $PROJECT -f $COMPOSE_DIR/docker-compose.yml exec amnezia_panel \
curl -fsS http://127.0.0.1:5000/health
# → {"status":"ok","version":"v2.6.0"}
docker inspect ${PROJECT}-amnezia_panel-1 \
--format '{{range $k,$v := .NetworkSettings.Networks}}{{$k}} {{end}}'
# must include: dokploy-network
```
**Full redeploy after git update:**
```bash
cd $COMPOSE_DIR && git pull origin main
docker compose -p $PROJECT -f $COMPOSE_DIR/docker-compose.yml down
docker compose -p $PROJECT -f $COMPOSE_DIR/docker-compose.yml build --no-cache amnezia_panel
docker compose -p $PROJECT -f $COMPOSE_DIR/docker-compose.yml up -d --force-recreate
```
**Postgres `password authentication failed`:** the volume keeps the password from the **first** deploy. If you change `POSTGRES_PASSWORD` in Dokploy later, reset the DB volume (wipes panel DB data):
```bash
docker compose -p $PROJECT -f $COMPOSE_DIR/docker-compose.yml down
docker volume rm ${PROJECT}_amnezia_pgdata
docker compose -p $PROJECT -f $COMPOSE_DIR/docker-compose.yml up -d --build
```
**Domain shows `404 page not found` (plain text):** Traefik has no route to the panel — check Domains (service `amnezia_panel`, port `5000`) and that the container is on `dokploy-network` (see verify commands above).
| File | Purpose |
| --- | --- |
| `Dockerfile` | Production image (Python 3.12) |
| `docker-compose.yml` | Panel + PostgreSQL with healthchecks |
| `docker-compose.yml` | Panel + PostgreSQL with healthchecks, Dokploy/Traefik labels |
| `.env.example` | Environment template |
**Environment**
| Variable | Default | Description |
| --- | --- | --- |
| `APP_PORT` | `5000` | Host port / in-container listen port |
| `APP_PORT` / `PORT` | `5000` | Host port / in-container listen port |
| `SECRET_KEY` | (random) | Session signing key — set in production |
| `DATABASE_URL` | compose DSN | PostgreSQL connection string |
| `POSTGRES_*` | `amnezia` | DB credentials for the `db` service |
@@ -222,6 +277,78 @@ GitHub Actions workflows in `.github/workflows/`:
## 📋 Fix / changelog (this fork)
### v2.6.5
* **Mieru install fix** — wait for `/var/run/mita.sock`, seed a bootstrap user (empty `users` caused `mita start` RPC EOF), retry apply/start with systemd restart.
### v2.6.4
* **Mieru (mita v3.28.0)** — optional per-server install from [enfein/mieru](https://github.com/enfein/mieru): native Debian/RPM package, no Docker. Marketplace + server card, TCP port at install, user connections with `mierus://` share links. Pinned release **v3.28.0** (GitHub has no v2.8.0 tag).
### v2.6.3
* **Client connection domain (AWG / WireGuard)** — set a DNS name per server (or per AWG/WG protocol) instead of IP in client configs (`Endpoint = domain:port`). Survives server IP changes — update the A-record only. UI on server list, server page, and when adding a server.
* **Legacy `data.json` → PostgreSQL** — import normalizes old backups (UUIDs, duplicate usernames/tokens, string `server_info`); failed auto-import no longer bricks panel startup; JSON restore returns clear errors.
* **Dokploy / Traefik 404** — `traefik.http.services.amnezia_panel.loadbalancer.server.port=5000` in compose (Traefik must route to container port **5000**).
* **Support the project** — `/support` page for all users (SBP / card / crypto placeholders); admin configures requisites in **Settings** (no popups).
### v2.6.2
* **Panel backup → PostgreSQL dump** — Settings backup downloads `.sql` via `pg_dump`; restore accepts `.sql` or legacy `data.json`. JSON export kept as secondary link.
### v2.6.1
* **Move connections between servers** — restored: select configs on a server page and move to another server (recreates peers, keeps user links). `ToggleConnectionRequest` kept intact.
### v2.6.0 — stable Dokploy / Docker release
* **Dokploy-ready compose** — `dokploy-network`, Traefik labels, port **5000**, no fixed `container_name`.
* **Docker startup** — `uvicorn` with proxy headers; SSL inside container disabled when `PANEL_IN_DOCKER` / `PANEL_BEHIND_PROXY`.
* **Postgres healthcheck** — verifies password (catches `POSTGRES_PASSWORD` vs volume mismatch).
* **Rollback move-connections** — removed server-to-server config move (v2.5.4); restored `ToggleConnectionRequest` (fixes crash loop on deploy).
* **Docs** — full Dokploy deploy/redeploy/password-reset guide in README.
### v2.5.11
* **Postgres healthcheck** — verifies DB password (surfaces `POSTGRES_PASSWORD` / volume mismatch before panel starts).
### v2.5.10
* **Docker startup** — run `uvicorn` directly in `CMD` (no shell entrypoint); rebuild required after deploy.
### v2.5.9
* **Remove move connections between servers** — feature rolled back; fixes startup crash (`ToggleConnectionRequest` was missing after v2.5.4).
### v2.5.8
* **Docker/Dokploy: panel actually serves HTTP** — entrypoint waits for Postgres, runs `uvicorn` with proxy headers; SSL inside the container is forced off when `PANEL_IN_DOCKER` / `PANEL_BEHIND_PROXY` is set (fixes empty replies on port 5000 behind Traefik).
### v2.5.7
* **Dokploy / Traefik 404 fix** — `docker-compose.yml` joins `dokploy-network`, Traefik labels point to port **5000**; removed fixed `container_name`; README Dokploy domain setup.
### v2.5.6
* **Fix 404 after in-panel update (no tunnel)** — safer Docker restart, validate update before restart, friendly 404 page with panel link.
### v2.5.5
* **Fix 404 after panel update** — correct tunnel/local port when `APP_PORT` is set (Docker), health check before reload, auto-restart quick tunnels after reboot, reliable archive download URLs.
### v2.5.3
* **Fix gray Update panel button** — enabled by default; Docker installs allow in-container archive updates when `/app` is writable.
### v2.5.2
* **Tunnels UI redesign** — Settings → Tunnels: grouped layout (public access / outbound VPN), provider cards, status pills, responsive grid.
### v2.5.1
* **One-click panel update** — Settings → About → **Update panel**: downloads release ZIP from Gitea (or `git checkout` when `.git` exists), runs `pip install`, restarts.
### v2.5.0
* **NordVPN in Tunnels** — connect/disconnect outbound NordVPN from Settings (official `nordvpn` CLI; optional country/city).
### v2.4.0
* **Auto-update from Gitea**: Settings → About checks https://git.evilfox.cc/test2/Amnezia-Web-Panel-main releases and can install the latest tag via `git fetch` + checkout, then restart (git install only).
### v2.3.0
* **Cascade removed** — double-VPN feature dropped from the panel (manager, API, UI, i18n).
### v2.2.1
* **Cascade egress verify fix**: bind curl to ENTRY `awg0`/`wg0` IP (client-subnet policy route), not cascade peer Address.
* Soft-warn (no rollback) when policy route via `cascade` is OK but public-IP echo services fail.
### v2.2.0
* **Cascade (double VPN) restored** — later removed in **v2.3.0**.
* Inspired by [ryderams/amneziawg-cascade](https://github.com/ryderams/amneziawg-cascade); logic ran over panel SSH (**no remote curl|bash**).
### v2.1.0
* **NaiveProxy — stable**: production-ready install (Caddy + klzgrad/forwardproxy), share links always include `:443`.
* **Client notes (important)**:
@@ -253,7 +380,7 @@ GitHub Actions workflows in `.github/workflows/`:
### v1.6.0
* **3x-ui multi-panel**: register several 3x-ui servers in Settings; pick a panel and load VLESS inbounds over its API when creating users/invites (share link comes from 3x-ui).
* **Docker / CI**: refreshed `Dockerfile` + compose, `.env.example`, CI checks, GHCR image workflow.
* **Cascade removed** for now (pending redesign — showed active while internet often did not work).
* **Cascade** was temporarily removed in this release (briefly restored in v2.2.x, removed again in **v2.3.0**).
* **WG/AWG backups**: ZIP export of client `.conf` + restore with loading feedback.
* **API performance**: in-memory data cache, faster server check/stats.
* **Share / guest**: one-tap “Copy key”.
+911 -51
View File
File diff suppressed because it is too large Load Diff
+8
View File
@@ -1,28 +1,36 @@
"""Database package for Amnezia Web Panel (PostgreSQL 17)."""
from .backup import backup_filename, export_database_sql, restore_database_sql
from .connection import close_pool, get_database_url, init_schema
from .store import (
clear_tunnel_state,
ensure_db_ready,
export_data_dict,
import_from_json_file,
invalidate_data_cache,
load_data,
load_tunnel_state,
normalize_import_data,
save_data,
save_tunnel_state,
update_tunnel_state,
)
__all__ = [
'backup_filename',
'clear_tunnel_state',
'close_pool',
'ensure_db_ready',
'export_data_dict',
'export_database_sql',
'get_database_url',
'import_from_json_file',
'init_schema',
'invalidate_data_cache',
'load_data',
'load_tunnel_state',
'normalize_import_data',
'restore_database_sql',
'save_data',
'save_tunnel_state',
'update_tunnel_state',
+59
View File
@@ -0,0 +1,59 @@
"""PostgreSQL backup/restore for the panel database."""
from __future__ import annotations
import logging
import subprocess
from datetime import datetime, timezone
from .connection import get_database_url
from .store import invalidate_data_cache
logger = logging.getLogger(__name__)
def backup_filename() -> str:
stamp = datetime.now(timezone.utc).strftime('%Y-%m-%d_%H%M%S')
return f'amnezia_panel_backup_{stamp}.sql'
def export_database_sql() -> bytes:
"""Create a plain SQL dump of the panel PostgreSQL database."""
url = get_database_url()
proc = subprocess.run(
[
'pg_dump',
'--dbname', url,
'--no-owner',
'--no-acl',
'--clean',
'--if-exists',
],
capture_output=True,
check=False,
)
if proc.returncode != 0:
err = proc.stderr.decode('utf-8', errors='replace').strip()
raise RuntimeError(err or 'pg_dump failed')
if not proc.stdout:
raise RuntimeError('pg_dump returned empty dump')
return proc.stdout
def restore_database_sql(data: bytes) -> None:
"""Restore panel data from a plain SQL dump produced by pg_dump."""
if not data or not data.strip():
raise ValueError('Empty backup file')
url = get_database_url()
proc = subprocess.run(
['psql', '--dbname', url, '-v', 'ON_ERROR_STOP=1', '-q'],
input=data,
capture_output=True,
check=False,
)
if proc.returncode != 0:
err = proc.stderr.decode('utf-8', errors='replace').strip()
out = proc.stdout.decode('utf-8', errors='replace').strip()
raise RuntimeError(err or out or 'psql restore failed')
invalidate_data_cache()
logger.info('PostgreSQL backup restored successfully')
+156 -6
View File
@@ -10,8 +10,10 @@ import copy
import json
import logging
import os
import secrets
import shutil
import threading
import uuid
from datetime import datetime, timezone
from pathlib import Path
from typing import Any, Optional
@@ -52,6 +54,13 @@ DEFAULT_SETTINGS = {
'create_protocol': 'awg',
'create_server_id': 0,
},
'donate': {
'enabled': True,
'intro': '',
'sbp': {'enabled': True, 'title': '', 'details': ''},
'card': {'enabled': True, 'title': '', 'details': ''},
'crypto': {'enabled': True, 'title': '', 'details': ''},
},
}
@@ -83,6 +92,147 @@ def _as_uuid(value: Any) -> UUID:
return UUID(str(value))
def _is_valid_uuid(value: Any) -> bool:
if value is None:
return False
try:
UUID(str(value))
return True
except (ValueError, AttributeError, TypeError):
return False
def _coerce_uuid(value: Any, *, default: Optional[str] = None) -> str:
if _is_valid_uuid(value):
return str(UUID(str(value)))
if default is not None:
return default
return str(uuid.uuid4())
def _as_list(value: Any) -> list:
return list(value) if isinstance(value, list) else []
def normalize_import_data(data: dict) -> dict:
"""Prepare legacy data.json (or partial exports) for PostgreSQL constraints."""
data = copy.deepcopy(data or {})
data['servers'] = [s for s in _as_list(data.get('servers')) if isinstance(s, dict)]
data['users'] = [u for u in _as_list(data.get('users')) if isinstance(u, dict)]
data['user_connections'] = [c for c in _as_list(data.get('user_connections')) if isinstance(c, dict)]
data['api_tokens'] = [t for t in _as_list(data.get('api_tokens')) if isinstance(t, dict)]
data['invite_links'] = [l for l in _as_list(data.get('invite_links')) if isinstance(l, dict)]
if not isinstance(data.get('settings'), dict):
data['settings'] = {}
id_map: dict[str, str] = {}
def map_user_id(value: Any) -> Optional[str]:
if value is None or value == '':
return None
key = str(value)
if _is_valid_uuid(key):
resolved = str(UUID(key))
id_map.setdefault(key, resolved)
return resolved
if key not in id_map:
id_map[key] = str(uuid.uuid4())
return id_map[key]
used_usernames: set[str] = set()
for index, user in enumerate(data['users']):
if not isinstance(user, dict):
continue
old_id = user.get('id')
if old_id is None or old_id == '':
user['id'] = str(uuid.uuid4())
else:
key = str(old_id)
if _is_valid_uuid(key):
user['id'] = str(UUID(key))
id_map.setdefault(key, user['id'])
else:
user['id'] = map_user_id(key) or str(uuid.uuid4())
username = (user.get('username') or '').strip() or f'user{index + 1}'
base = username
suffix = 2
while username.lower() in used_usernames:
username = f'{base}_{suffix}'
suffix += 1
user['username'] = username
used_usernames.add(username.lower())
user.setdefault('password_hash', '')
user.setdefault('role', 'user')
user.setdefault('enabled', True)
valid_user_ids = {str(u['id']) for u in data['users'] if isinstance(u, dict) and u.get('id')}
for server in data['servers']:
if not isinstance(server, dict):
continue
server['server_info'] = _as_dict(server.get('server_info'))
server['protocols'] = _as_dict(server.get('protocols'))
for conn in data['user_connections']:
if not isinstance(conn, dict):
continue
conn['id'] = _coerce_uuid(conn.get('id'))
mapped_uid = map_user_id(conn.get('user_id'))
if mapped_uid:
conn['user_id'] = mapped_uid
data['user_connections'] = [
c for c in data['user_connections']
if isinstance(c, dict) and str(c.get('user_id')) in valid_user_ids
]
seen_hashes: set[str] = set()
normalized_tokens = []
for token in data['api_tokens']:
if not isinstance(token, dict):
continue
mapped_uid = map_user_id(token.get('user_id'))
if not mapped_uid or mapped_uid not in valid_user_ids:
continue
token['id'] = _coerce_uuid(token.get('id'))
token['user_id'] = mapped_uid
token_hash = (token.get('token_hash') or '').strip()
if not token_hash or token_hash in seen_hashes:
token_hash = secrets.token_hex(32)
token['token_hash'] = token_hash
seen_hashes.add(token_hash)
token.setdefault('token_prefix', (token_hash[:8] if token_hash else ''))
normalized_tokens.append(token)
data['api_tokens'] = normalized_tokens
seen_invite_tokens: set[str] = set()
for link in data['invite_links']:
if not isinstance(link, dict):
continue
link['id'] = _coerce_uuid(link.get('id'))
mapped_uid = map_user_id(link.get('user_id'))
link['user_id'] = mapped_uid if mapped_uid in valid_user_ids else ''
token = (link.get('token') or '').strip()
if not token or token in seen_invite_tokens:
token = secrets.token_urlsafe(16)
while token in seen_invite_tokens:
token = secrets.token_urlsafe(16)
link['token'] = token
seen_invite_tokens.add(token)
guest = data['settings'].get('guest')
if isinstance(guest, dict):
mapped_guest = map_user_id(guest.get('user_id'))
if mapped_guest in valid_user_ids:
guest['user_id'] = mapped_guest
elif guest.get('user_id'):
guest['user_id'] = ''
return data
def _merge_settings(raw: Optional[dict]) -> dict:
settings = json.loads(json.dumps(DEFAULT_SETTINGS))
if not isinstance(raw, dict):
@@ -293,6 +443,7 @@ def load_data() -> dict:
def save_data(data: dict) -> None:
"""Replace panel state in a single transaction (same semantics as rewriting data.json)."""
global _DATA_CACHE
data = normalize_import_data(data)
init_schema()
servers = data.get('servers') or []
users = data.get('users') or []
@@ -484,12 +635,7 @@ def import_from_json_file(path: str | os.PathLike, *, backup: bool = True) -> bo
if not isinstance(data, dict):
raise ValueError(f'Invalid data.json: expected object, got {type(data).__name__}')
data.setdefault('servers', [])
data.setdefault('users', [])
data.setdefault('user_connections', [])
data.setdefault('api_tokens', [])
data.setdefault('invite_links', [])
data.setdefault('settings', {})
data = normalize_import_data(data)
save_data(data)
@@ -555,4 +701,8 @@ def ensure_db_ready(legacy_data_file: Optional[str] = None) -> None:
init_schema()
if legacy_data_file and is_database_empty() and os.path.exists(legacy_data_file):
logger.info('Empty database — importing legacy %s', legacy_data_file)
try:
import_from_json_file(legacy_data_file)
except Exception:
logger.exception('Legacy data.json import failed — panel will start with empty DB')
invalidate_data_cache()
+27 -7
View File
@@ -1,18 +1,21 @@
services:
db:
image: postgres:17
container_name: amnezia_panel_db
environment:
POSTGRES_USER: ${POSTGRES_USER:-amnezia}
POSTGRES_PASSWORD: ${POSTGRES_PASSWORD:-amnezia}
POSTGRES_DB: ${POSTGRES_DB:-amnezia_panel}
volumes:
- amnezia_pgdata:/var/lib/postgresql/data
ports:
- "${POSTGRES_PORT:-5432}:5432"
restart: unless-stopped
networks:
- internal
healthcheck:
test: ["CMD-SHELL", "pg_isready -U ${POSTGRES_USER:-amnezia} -d ${POSTGRES_DB:-amnezia_panel}"]
test:
[
"CMD-SHELL",
"pg_isready -U $${POSTGRES_USER} -d $${POSTGRES_DB} && PGPASSWORD=$${POSTGRES_PASSWORD} psql -U $${POSTGRES_USER} -d $${POSTGRES_DB} -c 'SELECT 1' >/dev/null",
]
interval: 10s
timeout: 5s
retries: 10
@@ -23,7 +26,6 @@ services:
context: .
dockerfile: Dockerfile
image: amnezia-panel:local
container_name: amnezia_panel
depends_on:
db:
condition: service_healthy
@@ -33,15 +35,33 @@ services:
DATABASE_URL: postgresql://${POSTGRES_USER:-amnezia}:${POSTGRES_PASSWORD:-amnezia}@db:5432/${POSTGRES_DB:-amnezia_panel}
SECRET_KEY: ${SECRET_KEY:-}
APP_PORT: "5000"
PORT: "5000"
PANEL_IN_DOCKER: "1"
PANEL_BEHIND_PROXY: "1"
volumes:
- amnezia_data:/app/data
restart: unless-stopped
networks:
- internal
- dokploy-network
labels:
- traefik.enable=true
- traefik.docker.network=dokploy-network
- traefik.http.services.amnezia_panel.loadbalancer.server.port=5000
expose:
- "5000"
healthcheck:
test: ["CMD-SHELL", "curl -fsS http://127.0.0.1:5000/docs >/dev/null || exit 1"]
test: ["CMD-SHELL", "curl -fsS http://127.0.0.1:5000/health >/dev/null || exit 1"]
interval: 30s
timeout: 10s
retries: 3
start_period: 40s
start_period: 60s
networks:
internal:
dokploy-network:
external: true
name: dokploy-network
volumes:
amnezia_data:
+3
View File
@@ -70,6 +70,9 @@ class BackupManager:
remote_dir = inst_path('/opt/amnezia/naiveproxy')
paths['host'] = [remote_dir]
paths['container'] = ['/etc/caddy']
elif base == 'mieru':
remote_dir = inst_path('/opt/amnezia/mieru')
paths['host'] = [remote_dir]
elif base == 'dns':
paths['host'] = ['/opt/amnezia/dns']
paths['container'] = ['/opt/amnezia/dns']
+585
View File
@@ -0,0 +1,585 @@
"""
Mieru protocol manager native mita server package (systemd).
Installs pinned release from https://github.com/enfein/mieru
Server binary: mita (systemd service), client: mieru.
Share links: mierus://user:pass@host?port=...&protocol=TCP&profile=default
"""
from __future__ import annotations
import json
import logging
import re
import secrets
import shlex
import string
import time
from urllib.parse import quote
logger = logging.getLogger(__name__)
MIERU_RELEASE = '3.28.0'
GITHUB_RELEASE = f'https://github.com/enfein/mieru/releases/download/v{MIERU_RELEASE}'
MITA_SOCK = '/var/run/mita.sock'
def _q(value):
return shlex.quote(str(value))
def _rand_token(length=16):
alphabet = string.ascii_lowercase + string.digits
return ''.join(secrets.choice(alphabet) for _ in range(length))
def _sanitize_username(name):
base = re.sub(r'[^a-zA-Z0-9_-]', '', (name or 'user').strip())[:24] or 'user'
return f'{base}_{_rand_token(4)}'
class MieruManager:
PROTOCOL = 'mieru'
SERVICE_NAME = 'mita'
BASE_DIR = '/opt/amnezia/mieru'
DEFAULT_PORT = 2999
def __init__(self, ssh, protocol='mieru'):
self.ssh = ssh
self.protocol = protocol or self.PROTOCOL
self.base_dir = self.BASE_DIR
self.clients_path = f'{self.base_dir}/clients.json'
self.meta_path = f'{self.base_dir}/metadata.json'
self.config_path = f'{self.base_dir}/server_config.json'
# ===================== STATUS =====================
def check_docker_installed(self):
return True
def _mita_installed(self):
out, _, code = self.ssh.run_command('command -v mita 2>/dev/null')
return code == 0 and bool(out.strip())
def check_protocol_installed(self, protocol_type=None):
return self._mita_installed() and self._panel_installed()
def _panel_installed(self):
out, _, code = self.ssh.run_sudo_command(f"test -f {_q(self.meta_path)} && echo yes")
return code == 0 and 'yes' in out
def _proxy_running(self):
out, _, code = self.ssh.run_sudo_command('mita status 2>/dev/null')
if code != 0:
return False
return 'RUNNING' in (out or '').upper()
def check_container_running(self, protocol_type=None):
return self._proxy_running()
def get_logs(self, protocol_type=None, tail=200):
tail = max(20, min(int(tail or 200), 2000))
out, err, code = self.ssh.run_sudo_command(
f"journalctl -u {self.SERVICE_NAME} -n {tail} --no-pager 2>&1",
timeout=30,
)
text = (out or err or '').strip()
if not text:
status, _, _ = self.ssh.run_sudo_command('mita status 2>&1')
text = (status or '').strip()
if not text:
text = f'(no logs: exit {code})'
return text
def get_container_diagnostics(self, protocol_type=None):
running = self._proxy_running()
out, _, _ = self.ssh.run_sudo_command(
f"systemctl is-active {self.SERVICE_NAME} 2>/dev/null"
)
daemon_active = (out or '').strip() == 'active'
diag = {
'status': 'running' if running else ('idle' if daemon_active else 'stopped'),
'running': running,
'error_summary': '',
'recent_logs': self.get_logs(protocol_type, tail=40),
}
if not self._mita_installed():
diag['status'] = 'missing'
diag['error_summary'] = 'mita package not installed'
elif not running and daemon_active:
status_out, _, _ = self.ssh.run_sudo_command('mita status 2>&1')
if 'IDLE' in (status_out or '').upper():
diag['error_summary'] = 'Proxy stopped (mita status IDLE)'
elif status_out.strip():
diag['error_summary'] = status_out.strip().splitlines()[-1][:160]
elif not daemon_active:
diag['error_summary'] = f'{self.SERVICE_NAME} systemd service is not active'
return diag
def get_server_status(self, protocol_type=None):
protocol_type = protocol_type or self.protocol
exists = self.check_protocol_installed(protocol_type)
running = self.check_container_running(protocol_type) if exists else False
meta = self._read_metadata() if exists else {}
clients = self._read_clients() if exists else []
port = int(meta.get('port') or self.DEFAULT_PORT)
return {
'container_exists': exists,
'container_running': running,
'port': port,
'release': meta.get('release') or MIERU_RELEASE,
'clients_count': len(clients),
'protocol': protocol_type,
'base_protocol': self.PROTOCOL,
'instance': 1,
'container_name': self.SERVICE_NAME,
}
# ===================== IO HELPERS =====================
def _read_file(self, path):
out, _, code = self.ssh.run_sudo_command(f"cat {_q(path)} 2>/dev/null")
return out if code == 0 else ''
def _write_file(self, path, content):
import base64
b64 = base64.b64encode((content or '').encode('utf-8')).decode('ascii')
script = (
f"mkdir -p $(dirname {_q(path)}) && "
f"echo {_q(b64)} | base64 -d > {_q(path)} && "
f"chmod 644 {_q(path)}"
)
out, err, code = self.ssh.run_sudo_command(f"sh -c {_q(script)}", timeout=30)
if code != 0:
raise RuntimeError(f'Failed to write {path}: {err or out}')
def _read_metadata(self):
raw = self._read_file(self.meta_path).strip()
if not raw:
return {}
try:
data = json.loads(raw)
return data if isinstance(data, dict) else {}
except Exception:
return {}
def _write_metadata(self, meta):
self._write_file(self.meta_path, json.dumps(meta, indent=2))
def _read_clients(self):
raw = self._read_file(self.clients_path).strip()
if not raw:
return []
try:
data = json.loads(raw)
return data if isinstance(data, list) else []
except Exception:
return []
def _write_clients(self, clients):
self._write_file(self.clients_path, json.dumps(clients, indent=2))
def _ensure_daemon(self, log=None):
"""Ensure mita systemd unit is up and RPC socket answers."""
self.ssh.run_sudo_command(
f"systemctl enable {self.SERVICE_NAME} 2>/dev/null || true",
timeout=30,
)
self.ssh.run_sudo_command(
f"systemctl start {self.SERVICE_NAME} 2>/dev/null || "
f"systemctl restart {self.SERVICE_NAME} 2>/dev/null || true",
timeout=60,
)
# Official package expects the operating user in group `mita`.
user_out, _, _ = self.ssh.run_command('id -un 2>/dev/null || echo root')
op_user = (user_out or 'root').strip() or 'root'
if op_user != 'root':
self.ssh.run_sudo_command(
f"usermod -a -G mita {_q(op_user)} 2>/dev/null || true",
timeout=15,
)
if not self._wait_for_rpc(timeout=45):
# Stale socket / crashed daemon — hard restart once.
self.ssh.run_sudo_command(
f"systemctl stop {self.SERVICE_NAME} 2>/dev/null || true; "
f"rm -f {_q(MITA_SOCK)} /var/run/mita/*.sock 2>/dev/null || true; "
f"systemctl start {self.SERVICE_NAME}",
timeout=60,
)
if not self._wait_for_rpc(timeout=45):
journal, _, _ = self.ssh.run_sudo_command(
f"journalctl -u {self.SERVICE_NAME} -n 40 --no-pager 2>&1",
timeout=30,
)
raise RuntimeError(
'mita systemd daemon is not ready (RPC socket missing). '
f'journal: {(journal or "").strip()[-500:]}'
)
if log is not None:
log.append('mita daemon is active')
def _wait_for_rpc(self, timeout=30):
deadline = time.time() + timeout
while time.time() < deadline:
sock_out, _, sock_code = self.ssh.run_sudo_command(
f"test -S {_q(MITA_SOCK)} && echo ok"
)
if sock_code == 0 and 'ok' in (sock_out or ''):
status_out, _, status_code = self.ssh.run_sudo_command(
'mita status 2>&1',
timeout=20,
)
text = (status_out or '').upper()
if status_code == 0 and ('IDLE' in text or 'RUNNING' in text):
return True
# Socket exists but CLI still races — brief pause.
time.sleep(1.5)
return False
def _mita_cli(self, args, timeout=60):
"""Run mita CLI as root so group/socket ACL is not an issue."""
cmd = f"mita {' '.join(args)} 2>&1"
return self.ssh.run_sudo_command(cmd, timeout=timeout)
def _build_server_config(self, port, clients):
users = []
for c in clients:
if not c.get('enabled', True):
continue
username = (c.get('username') or c.get('name') or c.get('id') or '').strip()
password = (c.get('password') or '').strip()
if not username or not password:
continue
users.append({'name': username, 'password': password})
# mita rejects / crashes on empty users during `mita start` (RPC EOF).
if not users:
users = [{
'name': f'panel_{_rand_token(6)}',
'password': _rand_token(20),
}]
return {
'portBindings': [{'port': int(port), 'protocol': 'TCP'}],
'users': users,
'loggingLevel': 'INFO',
'mtu': 1400,
}
def _apply_config(self, config, reload_only=False):
self._ensure_daemon()
self._write_file(self.config_path, json.dumps(config, indent=2))
out, err, code = self._mita_cli(
['apply', 'config', _q(self.config_path)],
timeout=60,
)
if code != 0:
# Recover from transient EOF / unavailable RPC.
if self._is_rpc_error(out, err):
self._ensure_daemon()
out, err, code = self._mita_cli(
['apply', 'config', _q(self.config_path)],
timeout=60,
)
if code != 0:
raise RuntimeError((err or out or 'mita apply config failed').strip())
if reload_only:
# users/loggingLevel can hot-reload; fall back to full restart.
reload_out, reload_err, reload_code = self._mita_cli(['reload'], timeout=30)
if reload_code == 0:
return
logger.info('mita reload failed, falling back to stop/start: %s',
(reload_err or reload_out or '').strip())
self._restart_proxy()
def _is_rpc_error(self, *parts):
text = ' '.join(str(p or '') for p in parts).lower()
return any(token in text for token in (
'rpc error',
'unavailable',
'error reading from server',
'eof',
'no such file or directory',
'mita.sock',
'connection refused',
))
def _restart_proxy(self):
self._mita_cli(['stop'], timeout=30)
time.sleep(1)
last_err = ''
for attempt in range(1, 4):
out, err, code = self._mita_cli(['start'], timeout=60)
if code == 0:
# Confirm RUNNING (daemon may report success then die).
time.sleep(1)
if self._proxy_running():
return
last_err = (out or err or 'mita start returned ok but status is not RUNNING').strip()
else:
last_err = (err or out or 'mita start failed').strip()
if self._is_rpc_error(last_err) or attempt < 3:
self.ssh.run_sudo_command(
f"systemctl restart {self.SERVICE_NAME} 2>/dev/null || true",
timeout=60,
)
self._wait_for_rpc(timeout=30)
time.sleep(1)
continue
break
journal, _, _ = self.ssh.run_sudo_command(
f"journalctl -u {self.SERVICE_NAME} -n 30 --no-pager 2>&1",
timeout=30,
)
raise RuntimeError(
f'{last_err}. journal: {(journal or "").strip()[-400:]}'
)
def _sync_server(self, reload_only=True):
meta = self._read_metadata()
port = int(meta.get('port') or self.DEFAULT_PORT)
clients = self._read_clients()
config = self._build_server_config(port, clients)
self._apply_config(config, reload_only=reload_only)
def _open_firewall_port(self, port):
script = f"""
PORT={int(port)}
if command -v ufw >/dev/null 2>&1 && ufw status 2>/dev/null | grep -qi active; then
ufw allow "$PORT"/tcp || true
fi
if command -v firewall-cmd >/dev/null 2>&1; then
firewall-cmd --permanent --add-port="$PORT"/tcp 2>/dev/null || true
firewall-cmd --reload 2>/dev/null || true
fi
"""
self.ssh.run_sudo_script(script, timeout=60)
def _package_url(self):
arch_out, _, _ = self.ssh.run_command('uname -m')
arch = (arch_out or '').strip().lower()
_, _, deb_code = self.ssh.run_command('command -v dpkg 2>/dev/null')
_, _, rpm_code = self.ssh.run_command('command -v rpm 2>/dev/null')
use_deb = deb_code == 0 or rpm_code != 0
if use_deb:
if arch in ('aarch64', 'arm64'):
return f'{GITHUB_RELEASE}/mita_{MIERU_RELEASE}_arm64.deb', 'deb'
return f'{GITHUB_RELEASE}/mita_{MIERU_RELEASE}_amd64.deb', 'deb'
if arch in ('aarch64', 'arm64'):
return f'{GITHUB_RELEASE}/mita-{MIERU_RELEASE}-1.aarch64.rpm', 'rpm'
return f'{GITHUB_RELEASE}/mita-{MIERU_RELEASE}-1.x86_64.rpm', 'rpm'
def _install_package(self, log):
url, pkg_type = self._package_url()
tmp = f'/tmp/mita_{MIERU_RELEASE}'
if pkg_type == 'deb':
tmp += '.deb'
install_cmd = f"dpkg -i {_q(tmp)} || apt-get install -f -y"
else:
tmp += '.rpm'
install_cmd = f"rpm -Uvh --force {_q(tmp)}"
out, err, code = self.ssh.run_sudo_command(
f"curl -fL {_q(url)} -o {_q(tmp)} 2>&1",
timeout=300,
)
if code != 0:
raise RuntimeError(f'Failed to download mita package: {err or out}')
log.append(f'Downloaded mita v{MIERU_RELEASE}')
out, err, code = self.ssh.run_sudo_command(install_cmd, timeout=180)
if code != 0:
raise RuntimeError(f'Failed to install mita package: {err or out}')
log.append('Installed mita package')
self._ensure_daemon(log)
def _build_share_uri(self, host, port, username, password, name=''):
user = quote(username or '', safe='')
pw = quote(password or '', safe='')
params = f"port={int(port)}&protocol=TCP&profile=default"
link = f"mierus://{user}:{pw}@{host}?{params}"
if name:
link += f"#{quote(name, safe='')}"
return link
def _build_client_json(self, host, port, username, password):
return json.dumps({
'profiles': [{
'profileName': 'default',
'user': {'name': username, 'password': password},
'servers': [{
'ipAddress': host,
'domainName': '',
'portBindings': [{'port': int(port), 'protocol': 'TCP'}],
}],
'mtu': 1400,
'multiplexing': {'level': 'MULTIPLEXING_LOW'},
'handshakeMode': 'HANDSHAKE_STANDARD',
}],
'activeProfile': 'default',
'rpcPort': 8964,
'socks5Port': 1080,
'loggingLevel': 'INFO',
'socks5ListenLAN': False,
}, indent=2)
# ===================== INSTALL / REMOVE =====================
def install_protocol(self, protocol_type=None, port=None):
protocol_type = protocol_type or self.protocol
port = int(port or self.DEFAULT_PORT)
if port < 1025 or port > 65535:
return {'status': 'error', 'message': 'Port must be between 1025 and 65535'}
log = []
try:
if not self._mita_installed():
self._install_package(log)
else:
log.append(f'mita already installed, configuring panel (v{MIERU_RELEASE})')
self._ensure_daemon(log)
self.ssh.run_sudo_command(f"mkdir -p {_q(self.base_dir)}")
meta = {'port': port, 'release': MIERU_RELEASE}
self._write_metadata(meta)
# Keep clients empty in panel DB, but seed a real mita user so start works.
self._write_clients([])
bootstrap = {
'id': secrets.token_hex(8),
'name': 'panel-bootstrap',
'username': f'panel_{_rand_token(6)}',
'password': _rand_token(20),
'enabled': True,
'bootstrap': True,
}
self._write_clients([bootstrap])
log.append(f'Prepared {self.base_dir}')
config = self._build_server_config(port, [bootstrap])
self._apply_config(config, reload_only=False)
self._open_firewall_port(port)
log.append(f'Started mita proxy on TCP {port}')
return {
'status': 'success',
'message': f'Mieru v{MIERU_RELEASE} installed',
'log': log,
'port': str(port),
'release': MIERU_RELEASE,
}
except Exception as e:
return {'status': 'error', 'message': str(e), 'log': log}
def remove_container(self, protocol_type=None):
self.ssh.run_sudo_command('mita stop 2>/dev/null || true', timeout=30)
self.ssh.run_sudo_command(f"rm -rf {_q(self.base_dir)}")
return True
def start_service(self):
self._ensure_daemon()
self._restart_proxy()
def stop_service(self):
self.ssh.run_sudo_command('mita stop 2>/dev/null || true', timeout=30)
def get_server_config(self, protocol_type=None):
out, _, code = self.ssh.run_sudo_command('mita describe config 2>/dev/null')
if code == 0 and (out or '').strip():
return out
return self._read_file(self.config_path)
def save_server_config(self, protocol_type=None, config_text=''):
raw = (config_text or '').strip()
if not raw:
raise RuntimeError('Config is empty')
try:
parsed = json.loads(raw)
except Exception as e:
raise RuntimeError(f'Invalid JSON config: {e}') from e
if not isinstance(parsed, dict):
raise RuntimeError('Config must be a JSON object')
self._apply_config(parsed, reload_only=False)
return True
# ===================== CLIENTS =====================
def get_clients(self, protocol_type=None):
clients = self._read_clients()
result = []
for c in clients:
if c.get('bootstrap'):
continue
cname = c.get('name') or c.get('id')
result.append({
'clientId': c.get('id'),
'client_id': c.get('id'),
'id': c.get('id'),
'name': cname,
'email': cname,
'enabled': c.get('enabled', True),
'userData': {'clientName': cname, 'enabled': c.get('enabled', True)},
})
return result
def add_client(self, protocol_type, name, host, port=None):
meta = self._read_metadata()
port = int(port or meta.get('port') or self.DEFAULT_PORT)
client_id = secrets.token_hex(8)
username = _sanitize_username(name)
password = _rand_token(20)
clients = self._read_clients()
clients.append({
'id': client_id,
'name': name or username,
'username': username,
'password': password,
'enabled': True,
})
self._write_clients(clients)
self._sync_server(reload_only=True)
config = self._build_share_uri(host, port, username, password, name or username)
json_config = self._build_client_json(host, port, username, password)
return {
'clientId': client_id,
'client_id': client_id,
'id': client_id,
'name': name or username,
'config': config,
'json_config': json_config,
}
def get_client_config(self, protocol_type, client_id, host, port=None):
meta = self._read_metadata()
port = int(port or meta.get('port') or self.DEFAULT_PORT)
clients = self._read_clients()
client = next((c for c in clients if c.get('id') == client_id), None)
if not client or client.get('bootstrap'):
return ''
if not client.get('enabled', True):
return ''
username = client.get('username') or client.get('name') or client_id
password = client.get('password') or ''
name = client.get('name') or username
return self._build_share_uri(host, port, username, password, name)
def remove_client(self, protocol_type, client_id):
clients = [c for c in self._read_clients() if c.get('id') != client_id]
# Keep at least bootstrap so mita never has empty users.
if not any(not c.get('bootstrap') for c in clients) and not any(c.get('bootstrap') for c in clients):
clients.append({
'id': secrets.token_hex(8),
'name': 'panel-bootstrap',
'username': f'panel_{_rand_token(6)}',
'password': _rand_token(20),
'enabled': True,
'bootstrap': True,
})
self._write_clients(clients)
self._sync_server(reload_only=True)
return True
def toggle_client(self, protocol_type, client_id, enabled):
clients = self._read_clients()
for c in clients:
if c.get('id') == client_id:
c['enabled'] = bool(enabled)
self._write_clients(clients)
self._sync_server(reload_only=True)
return True
+452
View File
@@ -0,0 +1,452 @@
"""Panel self-update from the EvilFox Gitea repository (git or release archive)."""
from __future__ import annotations
import json
import logging
import os
import re
import shutil
import subprocess
import sys
import tempfile
import threading
import time
import urllib.error
import urllib.request
import zipfile
from typing import Optional
logger = logging.getLogger(__name__)
DEFAULT_REPO_URL = 'https://git.evilfox.cc/test2/Amnezia-Web-Panel-main'
DEFAULT_GIT_URL = 'https://git.evilfox.cc/test2/Amnezia-Web-Panel-main.git'
DEFAULT_API_LATEST = 'https://git.evilfox.cc/api/v1/repos/test2/Amnezia-Web-Panel-main/releases/latest'
UPDATE_REMOTE = 'panel-update'
ARCHIVE_SKIP_DIRS = frozenset({
'__pycache__', '.git', 'bin', 'data', 'node_modules', '.venv', 'venv', '.cursor',
})
ARCHIVE_SKIP_FILES = frozenset({
'.env', 'data.json', 'tunnels_state.json',
})
def _env(name: str, default: str) -> str:
return (os.environ.get(name) or default).strip()
def repo_url() -> str:
return _env('PANEL_UPDATE_REPO_URL', DEFAULT_REPO_URL).rstrip('/')
def git_url() -> str:
return _env('PANEL_UPDATE_GIT_URL', DEFAULT_GIT_URL)
def api_latest_url() -> str:
return _env('PANEL_UPDATE_API_LATEST', DEFAULT_API_LATEST)
def parse_version(value: str) -> tuple:
"""Parse semver-ish tags like v2.3.0 / 2.3.0-beta into a comparable tuple."""
raw = (value or '').strip()
if not raw:
return (0, 0, 0, 1, '')
raw = raw.lstrip('vV')
main, _, pre = raw.partition('-')
parts = []
for piece in main.split('.'):
if piece.isdigit():
parts.append(int(piece))
else:
m = re.match(r'(\d+)', piece or '')
parts.append(int(m.group(1)) if m else 0)
while len(parts) < 3:
parts.append(0)
pre_rank = 0 if not pre else 1
return (parts[0], parts[1], parts[2], pre_rank, pre)
def version_gt(a: str, b: str) -> bool:
return parse_version(a) > parse_version(b)
def normalize_tag(value: str) -> str:
tag = (value or '').strip()
if not tag:
return ''
return tag if tag.startswith('v') else f'v{tag}'
def _run(cmd: list, cwd: str, timeout: int = 120) -> tuple[int, str, str]:
try:
proc = subprocess.run(
cmd,
cwd=cwd,
capture_output=True,
text=True,
timeout=timeout,
encoding='utf-8',
errors='replace',
)
return proc.returncode, (proc.stdout or '').strip(), (proc.stderr or '').strip()
except FileNotFoundError:
return 127, '', f'Command not found: {cmd[0]}'
except subprocess.TimeoutExpired:
return 124, '', f'Timeout running: {" ".join(cmd)}'
class UpdateManager:
def __init__(self, app_root: str, current_version: str):
self.app_root = os.path.abspath(app_root)
self.current_version = current_version
def _in_docker(self) -> bool:
return os.path.exists('/.dockerenv') or os.environ.get('PANEL_IN_DOCKER') == '1'
def _docker_update_allowed(self) -> bool:
if os.environ.get('PANEL_UPDATE_DISABLE_DOCKER', '').strip().lower() in ('1', 'true', 'yes'):
return False
# In-container archive updates are allowed by default when /app is writable.
return True
def _app_root_writable(self) -> bool:
probe = os.path.join(self.app_root, '.panel_update_write_probe')
try:
with open(probe, 'w', encoding='utf-8') as fh:
fh.write('ok')
os.remove(probe)
return True
except OSError:
return False
def detect_mode(self) -> dict:
frozen = bool(getattr(sys, 'frozen', False))
in_docker = self._in_docker()
git_dir = os.path.join(self.app_root, '.git')
is_git = os.path.isdir(git_dir)
git_ok = False
if is_git and not frozen:
code, _, _ = _run(['git', '--version'], self.app_root, timeout=10)
git_ok = code == 0
writable = self._app_root_writable()
can_git = bool(git_ok and is_git and not frozen)
can_archive = bool(
writable
and not frozen
and (not in_docker or self._docker_update_allowed())
)
can_auto = can_git or can_archive
if can_git:
method = 'git'
elif can_archive:
method = 'archive'
elif in_docker:
method = 'docker'
elif frozen:
method = 'binary'
else:
method = 'manual'
return {
'mode': method,
'update_method': method,
'can_auto_update': can_auto,
'can_git_update': can_git,
'can_archive_update': can_archive,
'is_git': is_git,
'frozen': frozen,
'in_docker': in_docker,
'writable': writable,
'app_root': self.app_root,
'repo_url': repo_url(),
'git_url': git_url(),
}
def _ensure_update_remote(self) -> Optional[str]:
code, out, err = _run(['git', 'remote'], self.app_root, timeout=15)
if code != 0:
return err or out or 'git remote failed'
remotes = set((out or '').split())
target = git_url()
if UPDATE_REMOTE in remotes:
code, _, err = _run(
['git', 'remote', 'set-url', UPDATE_REMOTE, target],
self.app_root,
timeout=15,
)
else:
code, _, err = _run(
['git', 'remote', 'add', UPDATE_REMOTE, target],
self.app_root,
timeout=15,
)
if code != 0:
return err or 'Failed to configure update remote'
return None
def working_tree_dirty(self) -> bool:
code, out, _ = _run(['git', 'status', '--porcelain'], self.app_root, timeout=30)
return code == 0 and bool(out.strip())
def _pip_install(self) -> tuple[bool, str]:
req = os.path.join(self.app_root, 'requirements.txt')
if not os.path.isfile(req):
return True, ''
code_p, out_p, err_p = _run(
[sys.executable, '-m', 'pip', 'install', '-r', req],
self.app_root,
timeout=300,
)
log = (out_p or err_p or '')[:1500]
return code_p == 0, log
def _apply_git_update(self, target: str, allow_dirty: bool) -> dict:
if not allow_dirty and self.working_tree_dirty():
return {
'status': 'error',
'message': (
'Working tree has local changes. Confirm update anyway to force checkout, '
'or commit/stash changes first.'
),
'needs_confirm_dirty': True,
}
err = self._ensure_update_remote()
if err:
return {'status': 'error', 'message': err}
code, out, stderr = _run(
['git', 'fetch', '--tags', '--force', UPDATE_REMOTE],
self.app_root,
timeout=180,
)
if code != 0:
return {'status': 'error', 'message': f'git fetch failed: {stderr or out or code}'}
# Ensure tag is present locally
code, _, _ = _run(
['git', 'rev-parse', '-q', '--verify', f'refs/tags/{target}'],
self.app_root,
timeout=15,
)
if code != 0:
_run(
['git', 'fetch', '--depth', '1', UPDATE_REMOTE, f'refs/tags/{target}:refs/tags/{target}'],
self.app_root,
timeout=120,
)
checkout_ref = f'tags/{target}'
code, out, stderr = _run(
['git', 'checkout', '--force', checkout_ref],
self.app_root,
timeout=60,
)
if code != 0:
code_m, out_m, err_m = _run(
['git', 'checkout', '--force', '-B', 'main', f'{UPDATE_REMOTE}/main'],
self.app_root,
timeout=60,
)
if code_m != 0:
return {
'status': 'error',
'message': f'git checkout {target} failed: {stderr or out or err_m or out_m}',
}
checkout_ref = f'{UPDATE_REMOTE}/main'
ok, pip_log = self._pip_install()
if not ok:
return {
'status': 'error',
'message': f'pip install failed after checkout: {pip_log[:500]}',
'checkout': checkout_ref,
'method': 'git',
}
return {
'status': 'success',
'message': f'Updated to {target} via git. Panel will restart.',
'target_version': target,
'checkout': checkout_ref,
'pip': pip_log[:500],
'method': 'git',
'restart': True,
}
def _archive_urls(self, tag: str) -> list[str]:
urls: list[str] = []
api_base = api_latest_url().rsplit('/releases/latest', 1)[0]
for endpoint in (f'{api_base}/releases/tags/{tag}', api_latest_url()):
try:
req = urllib.request.Request(
endpoint,
headers={'Accept': 'application/json', 'User-Agent': 'Amnezia-Web-Panel-Updater'},
)
with urllib.request.urlopen(req, timeout=30) as resp:
payload = json.loads(resp.read().decode('utf-8', errors='replace') or '{}')
zipball = (payload.get('zipball_url') or '').strip()
if zipball:
urls.append(zipball)
except Exception:
pass
base = repo_url()
urls.extend([
f'{base}/archive/{tag}.zip',
f'{api_base}/archive/{tag}.zip',
])
seen = set()
ordered: list[str] = []
for url in urls:
if url and url not in seen:
seen.add(url)
ordered.append(url)
return ordered
def _download_archive(self, tag: str, dest_path: str) -> None:
last_err = 'unknown error'
for url in self._archive_urls(tag):
try:
req = urllib.request.Request(url, headers={'User-Agent': 'Amnezia-Web-Panel-Updater'})
with urllib.request.urlopen(req, timeout=180) as resp:
with open(dest_path, 'wb') as out:
shutil.copyfileobj(resp, out)
if os.path.getsize(dest_path) > 1024:
return
last_err = f'empty archive from {url}'
except urllib.error.HTTPError as e:
last_err = f'HTTP {e.code} for {url}'
except Exception as e:
last_err = str(e)
raise RuntimeError(f'Failed to download release archive: {last_err}')
@staticmethod
def _extract_zip_root(extract_dir: str) -> str:
entries = [e for e in os.listdir(extract_dir) if e not in ('.', '..')]
if len(entries) == 1:
only = os.path.join(extract_dir, entries[0])
if os.path.isdir(only):
return only
return extract_dir
def _verify_tree(self, root: str) -> Optional[str]:
app_py = os.path.join(root, 'app.py')
if not os.path.isfile(app_py):
return 'Release archive is missing app.py'
code, _, err = _run([sys.executable, '-m', 'py_compile', app_py], root, timeout=60)
if code != 0:
return f'Updated app.py failed validation: {err or code}'
return None
def _sync_tree(self, src_root: str) -> None:
for root, dirs, files in os.walk(src_root):
dirs[:] = [d for d in dirs if d not in ARCHIVE_SKIP_DIRS]
rel = os.path.relpath(root, src_root)
dest_root = self.app_root if rel in ('.', '') else os.path.join(self.app_root, rel)
os.makedirs(dest_root, exist_ok=True)
for fname in files:
if fname in ARCHIVE_SKIP_FILES:
continue
src_file = os.path.join(root, fname)
dest_file = os.path.join(dest_root, fname)
shutil.copy2(src_file, dest_file)
def _apply_archive_update(self, target: str) -> dict:
tmpdir = tempfile.mkdtemp(prefix='panel-update-')
zip_path = os.path.join(tmpdir, f'{target}.zip')
extract_dir = os.path.join(tmpdir, 'extract')
try:
self._download_archive(target, zip_path)
os.makedirs(extract_dir, exist_ok=True)
with zipfile.ZipFile(zip_path, 'r') as zf:
zf.extractall(extract_dir)
src_root = self._extract_zip_root(extract_dir)
if not os.path.isdir(src_root):
return {'status': 'error', 'message': 'Invalid release archive layout'}
verify_err = self._verify_tree(src_root)
if verify_err:
return {'status': 'error', 'message': verify_err, 'method': 'archive'}
self._sync_tree(src_root)
except Exception as e:
return {'status': 'error', 'message': str(e), 'method': 'archive'}
finally:
shutil.rmtree(tmpdir, ignore_errors=True)
ok, pip_log = self._pip_install()
if not ok:
return {
'status': 'error',
'message': f'Files updated but pip install failed: {pip_log[:500]}',
'method': 'archive',
}
return {
'status': 'success',
'message': f'Updated to {target} from release archive. Panel will restart.',
'target_version': target,
'pip': pip_log[:500],
'method': 'archive',
'restart': True,
}
def apply_update(self, target_version: str, allow_dirty: bool = False) -> dict:
mode = self.detect_mode()
target = normalize_tag(target_version)
if not target or not re.match(r'^v\d+(\.\d+){0,3}([.-][\w.]+)?$', target):
return {'status': 'error', 'message': f'Invalid target version: {target_version}'}
if mode.get('can_git_update'):
return self._apply_git_update(target, allow_dirty)
if mode.get('can_archive_update'):
return self._apply_archive_update(target)
hint = (
'Cannot update from inside this install. '
'Use a git clone or writable source directory, or rebuild the Docker image on the host.'
)
if mode.get('in_docker'):
hint = (
'Docker image install: on the host run '
'`git pull && docker compose up -d --build` '
'(or set PANEL_UPDATE_ALLOW_DOCKER=1 if /app is bind-mounted).'
)
return {'status': 'error', 'message': hint, 'mode': mode}
@staticmethod
def schedule_restart(app_root: str, delay_sec: float = 1.5) -> None:
in_docker = os.path.exists('/.dockerenv') or os.environ.get('PANEL_IN_DOCKER') == '1'
def _restart():
time.sleep(max(0.5, float(delay_sec)))
cwd = os.path.abspath(app_root or os.getcwd())
argv = [sys.executable] + sys.argv
logger.info('Restarting panel after update: %s (cwd=%s, docker=%s)', argv, cwd, in_docker)
if in_docker:
# Let Docker restart policy bring the container back with updated /app files.
os._exit(0)
try:
os.chdir(cwd)
proc = subprocess.Popen(
argv,
cwd=cwd,
start_new_session=True,
close_fds=(os.name != 'nt'),
)
time.sleep(2.0)
if proc.poll() is None:
logger.info('New panel process started (pid=%s), stopping old process', proc.pid)
os._exit(0)
except Exception:
logger.exception('subprocess restart failed; trying execv')
try:
os.chdir(cwd)
os.execv(sys.executable, argv)
except Exception:
logger.exception('Failed to restart after update')
os._exit(1)
threading.Thread(target=_restart, name='panel-update-restart', daemon=False).start()
+367
View File
@@ -949,6 +949,11 @@ a:hover {
color: #38bdf8;
}
.protocol-mieru .protocol-icon {
background: linear-gradient(135deg, rgba(99, 102, 241, 0.2), rgba(168, 85, 247, 0.1));
color: #818cf8;
}
.protocol-dns .protocol-icon {
background: linear-gradient(135deg, rgba(34, 197, 94, 0.2), rgba(16, 185, 129, 0.1));
color: var(--success);
@@ -1282,6 +1287,7 @@ a:hover {
display: flex;
align-items: center;
justify-content: space-between;
gap: var(--space-sm);
padding: var(--space-md) var(--space-lg);
background: var(--bg-card);
border: 1px solid var(--border-color);
@@ -1294,6 +1300,45 @@ a:hover {
background: var(--bg-card-hover);
}
.conn-select-wrap {
flex-shrink: 0;
display: flex;
align-items: center;
cursor: pointer;
}
.conn-select {
width: 16px;
height: 16px;
accent-color: var(--accent);
}
.connections-bulk-bar {
display: flex;
align-items: center;
justify-content: space-between;
gap: var(--space-md);
margin-bottom: var(--space-sm);
padding: var(--space-sm) var(--space-md);
border: 1px dashed var(--border-color);
border-radius: var(--radius-sm);
background: var(--bg-secondary);
}
.connections-select-all {
display: flex;
align-items: center;
gap: var(--space-sm);
font-size: 0.85rem;
color: var(--text-secondary);
cursor: pointer;
}
.connections-selected-count {
font-size: 0.8rem;
color: var(--text-muted);
}
.client-info {
display: flex;
align-items: center;
@@ -1623,6 +1668,319 @@ a:hover {
gap: var(--space-md);
}
/* ===== Tunnels (Settings) ===== */
.tunnels-card .tunnels-header {
margin-bottom: var(--space-lg);
}
.tunnels-card .tunnels-header .card-title {
margin: 0;
display: flex;
align-items: center;
gap: var(--space-sm);
}
.tunnels-card .tunnels-subtitle {
margin: var(--space-xs) 0 0;
font-size: 0.875rem;
color: var(--text-secondary);
line-height: 1.45;
}
.tunnels-local {
display: flex;
align-items: center;
gap: var(--space-md);
padding: var(--space-md) var(--space-lg);
margin-bottom: var(--space-lg);
border-radius: var(--radius-md);
border: 1px solid var(--border-focus);
background: linear-gradient(135deg, rgba(139, 92, 246, 0.08), rgba(59, 130, 246, 0.06));
box-shadow: inset 0 1px 0 rgba(255, 255, 255, 0.04);
}
.tunnels-local-icon {
flex-shrink: 0;
width: 44px;
height: 44px;
display: flex;
align-items: center;
justify-content: center;
border-radius: var(--radius-md);
background: var(--accent-gradient);
font-size: 1.25rem;
box-shadow: var(--shadow-glow);
}
.tunnels-local-body {
flex: 1;
min-width: 0;
}
.tunnels-local-label {
font-size: 0.75rem;
font-weight: 600;
text-transform: uppercase;
letter-spacing: 0.04em;
color: var(--text-muted);
margin-bottom: var(--space-xs);
}
.tunnels-local-url {
display: flex;
align-items: center;
gap: var(--space-sm);
}
.tunnels-local-url code {
flex: 1;
min-width: 0;
overflow: hidden;
text-overflow: ellipsis;
white-space: nowrap;
font-size: 0.9rem;
color: var(--text-primary);
background: transparent;
padding: 0;
}
.tunnels-section {
margin-bottom: var(--space-lg);
}
.tunnels-section:last-of-type {
margin-bottom: var(--space-md);
}
.tunnels-section-title {
font-size: 0.7rem;
font-weight: 700;
text-transform: uppercase;
letter-spacing: 0.08em;
color: var(--text-muted);
margin: 0 0 var(--space-sm) var(--space-xs);
}
.tunnels-grid {
display: grid;
grid-template-columns: repeat(auto-fill, minmax(280px, 1fr));
gap: var(--space-md);
}
.tunnel-card {
display: flex;
flex-direction: column;
gap: var(--space-md);
padding: var(--space-md);
border-radius: var(--radius-md);
border: 1px solid var(--border-color);
background: var(--bg-primary);
transition: border-color var(--transition-base), box-shadow var(--transition-base);
}
.tunnel-card:hover {
border-color: var(--border-hover);
}
.tunnel-card--running {
border-color: var(--success-border);
box-shadow: 0 0 0 1px var(--success-border), inset 0 1px 0 rgba(34, 197, 94, 0.06);
}
.tunnel-card--connected {
border-color: var(--success-border);
box-shadow: 0 0 0 1px var(--success-border);
}
.tunnel-card-head {
display: flex;
align-items: flex-start;
gap: var(--space-md);
}
.tunnel-card-icon {
flex-shrink: 0;
width: 40px;
height: 40px;
display: flex;
align-items: center;
justify-content: center;
border-radius: var(--radius-sm);
font-size: 1.1rem;
font-weight: 700;
color: #fff;
}
.tunnel-card-icon--cloudflare { background: linear-gradient(135deg, #f38020, #faae40); }
.tunnel-card-icon--ngrok { background: linear-gradient(135deg, #1f2d3d, #3d5a80); }
.tunnel-card-icon--warp { background: linear-gradient(135deg, #f38020, #e85d04); }
.tunnel-card-icon--nordvpn { background: linear-gradient(135deg, #4687ff, #2b4eff); }
.tunnel-card-icon--local { background: var(--accent-gradient); }
.tunnel-card-meta {
flex: 1;
min-width: 0;
}
.tunnel-card-title {
font-size: 0.95rem;
font-weight: 600;
margin: 0;
line-height: 1.3;
}
.tunnel-card-desc {
font-size: 0.78rem;
color: var(--text-muted);
margin: var(--space-xs) 0 0;
line-height: 1.4;
}
.tunnel-status-pill {
flex-shrink: 0;
font-size: 0.7rem;
font-weight: 600;
padding: 4px 10px;
border-radius: var(--radius-full);
white-space: nowrap;
background: rgba(255, 255, 255, 0.06);
color: var(--text-secondary);
border: 1px solid var(--border-color);
}
.tunnel-status-pill--ok {
background: var(--success-bg);
color: var(--success);
border-color: var(--success-border);
}
.tunnel-status-pill--info {
background: var(--info-bg);
color: var(--info);
border-color: rgba(59, 130, 246, 0.25);
}
.tunnel-card-body {
display: flex;
flex-direction: column;
gap: var(--space-sm);
}
.tunnel-url-box {
padding: var(--space-sm) var(--space-md);
border-radius: var(--radius-sm);
background: var(--bg-secondary);
border: 1px dashed var(--border-color);
font-size: 0.8rem;
color: var(--text-secondary);
line-height: 1.45;
min-height: 2.5rem;
}
.tunnel-url-box--empty {
font-style: italic;
color: var(--text-muted);
}
.tunnel-url-row {
display: flex;
align-items: center;
gap: var(--space-sm);
margin-top: var(--space-xs);
}
.tunnel-url-row:first-child {
margin-top: 0;
}
.tunnel-url-row code {
flex: 1;
min-width: 0;
overflow: hidden;
text-overflow: ellipsis;
white-space: nowrap;
font-size: 0.8rem;
color: var(--text-accent);
background: transparent;
padding: 0;
}
.tunnel-status-line {
font-size: 0.82rem;
color: var(--text-secondary);
line-height: 1.45;
}
.tunnel-status-line--server {
font-family: ui-monospace, monospace;
font-size: 0.78rem;
color: var(--text-accent);
padding: var(--space-xs) var(--space-sm);
background: var(--bg-secondary);
border-radius: var(--radius-sm);
}
.tunnel-hint {
font-size: 0.75rem;
color: var(--text-muted);
line-height: 1.4;
margin: 0;
}
.tunnel-card-actions {
display: flex;
flex-wrap: wrap;
gap: var(--space-sm);
margin-top: auto;
}
.tunnel-card-actions .btn {
flex: 1;
min-width: 7rem;
justify-content: center;
}
.tunnel-card-actions--triple .btn {
min-width: 5.5rem;
}
.tunnel-nordvpn-fields {
display: grid;
grid-template-columns: 1fr 1fr;
gap: var(--space-sm);
}
.tunnels-footnote {
margin: var(--space-md) 0 0;
padding: var(--space-md);
border-radius: var(--radius-sm);
background: var(--bg-secondary);
border-left: 3px solid var(--accent);
font-size: 0.8rem;
color: var(--text-secondary);
line-height: 1.5;
}
@media (max-width: 640px) {
.tunnels-local {
flex-direction: column;
align-items: stretch;
text-align: center;
}
.tunnels-local-url {
flex-direction: column;
}
.tunnels-grid {
grid-template-columns: 1fr;
}
.tunnel-nordvpn-fields {
grid-template-columns: 1fr;
}
}
.mt-md {
margin-top: var(--space-md);
}
@@ -1854,6 +2212,15 @@ a:hover {
font-weight: 600;
}
.nav-link-support {
opacity: 0.85;
}
.nav-link-support:hover {
opacity: 1;
color: #f472b6;
}
.nav-user {
display: flex;
align-items: center;
+3
View File
@@ -108,4 +108,7 @@
<symbol id="layers" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round">
<path d="m12.83 2.18a2 2 0 0 0-1.66 0L2.6 6.08a1 1 0 0 0 0 1.83l8.58 3.91a2 2 0 0 0 1.66 0l8.58-3.9a1 1 0 0 0 0-1.83Z"/><path d="m22 17.65-9.17 4.16a2 2 0 0 1-1.66 0L2 17.65"/><path d="m22 12.65-9.17 4.16a2 2 0 0 1-1.66 0L2 12.65"/>
</symbol>
<symbol id="heart" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="1.75" stroke-linecap="round" stroke-linejoin="round">
<path d="M19 14c1.49-1.46 3-3.21 3-5.5A5.5 5.5 0 0 0 16.5 3c-1.76 0-3 .5-4.5 2-1.5-1.5-2.74-2-4.5-2A5.5 5.5 0 0 0 2 8.5c0 2.29 1.51 4.04 3 5.5l7 7Z"/>
</symbol>
</svg>
+7 -3
View File
@@ -24,7 +24,7 @@ _bot_task: Optional[asyncio.Task] = None
_callback_refs = {}
_pending_inputs = {}
CLIENT_PROTOCOLS = {"awg", "awg2", "awg_legacy", "xray", "telemt", "hysteria", "naiveproxy", "wireguard"}
CLIENT_PROTOCOLS = {"awg", "awg2", "awg_legacy", "xray", "telemt", "hysteria", "naiveproxy", "mieru", "wireguard"}
SERVICE_PROTOCOLS = {"dns", "adguard", "socks5", "nginx"}
@@ -139,6 +139,7 @@ def _protocol_display_name(protocol: str) -> str:
"telemt": "Telemt",
"hysteria": "Hysteria 2",
"naiveproxy": "NaiveProxy",
"mieru": "Mieru",
"dns": "AmneziaDNS",
"wireguard": "WireGuard",
"socks5": "SOCKS5",
@@ -342,6 +343,7 @@ def _get_ssh_and_manager(server: dict, proto: str):
from managers.telemt_manager import TelemtManager
from managers.hysteria_manager import HysteriaManager
from managers.naiveproxy_manager import NaiveProxyManager
from managers.mieru_manager import MieruManager
from managers.wireguard_manager import WireGuardManager
from managers.dns_manager import DNSManager
from managers.socks5_manager import Socks5Manager
@@ -364,6 +366,8 @@ def _get_ssh_and_manager(server: dict, proto: str):
manager = HysteriaManager(ssh, proto)
elif base == "naiveproxy":
manager = NaiveProxyManager(ssh, proto)
elif base == "mieru":
manager = MieruManager(ssh, proto)
elif base == "wireguard":
manager = WireGuardManager(ssh)
elif base == "dns":
@@ -569,7 +573,7 @@ async def _send_config_by_client(api: TelegramAPI, chat_id: int, server: dict, p
server_name = server.get("name") or server.get("host", "Unknown")
await api.send_message(chat_id, f"✅ <b>{_e(conn_name)}</b>\n🌐 Server: <b>{_e(server_name)}</b>\n🔌 Protocol: <b>{_e(proto.upper())}</b>")
is_link_proto = _proto_base(proto) in ("xray", "telemt", "hysteria", "naiveproxy")
is_link_proto = _proto_base(proto) in ("xray", "telemt", "hysteria", "naiveproxy", "mieru")
if is_link_proto:
await api.send_message(chat_id, f"🔗 <b>Connection link</b> (tap to copy):\n<code>{_e(config)}</code>")
else:
@@ -926,7 +930,7 @@ async def _admin_create_client(api: TelegramAPI, chat_id: int, message_id: int,
async def _send_config_text(api: TelegramAPI, chat_id: int, server: dict, proto: str, conn_name: str, config: str, generate_vpn_link_fn: Callable):
await api.send_message(chat_id, f"✅ <b>{_e(conn_name)}</b>\n🌐 Server: <b>{_e(server.get('name') or server.get('host'))}</b>\n🔌 Protocol: <b>{_e(proto.upper())}</b>")
if _proto_base(proto) in ("xray", "telemt", "hysteria", "naiveproxy"):
if _proto_base(proto) in ("xray", "telemt", "hysteria", "naiveproxy", "mieru"):
await api.send_message(chat_id, f"🔗 <b>Connection link</b>:\n<code>{_e(config)}</code>")
else:
await api.send_message(chat_id, f"<b>📄 Configuration:</b>\n<pre>{_e(config)}</pre>")
+3
View File
@@ -52,6 +52,9 @@
<a href="/settings" class="nav-link">{{ icon('settings') }} {{ _('nav_settings') }}</a>
{% endif %}
<a href="/my" class="nav-link">{{ icon('layers') }} {{ _('nav_connections') }}</a>
{% if donate_enabled %}
<a href="/support" class="nav-link nav-link-support">{{ icon('heart') }} {{ _('nav_support') }}</a>
{% endif %}
</nav>
<div class="nav-user">
+1
View File
@@ -107,6 +107,7 @@
if (p === 'xui') return '3x-ui VLESS';
if (p === 'hysteria') return 'Hysteria 2';
if (p === 'naiveproxy') return 'NaiveProxy';
if (p === 'mieru') return 'Mieru';
if (p === 'telemt') return 'Telemt';
return (p || '').toUpperCase();
}
+20
View File
@@ -21,6 +21,7 @@
data-username="{{ server.username }}" data-auth="{{ 'key' if server.private_key else 'password' }}"
data-ssl-domain="{{ (server.server_info or {}).get('ssl_domain', '') }}"
data-ssl-email="{{ (server.server_info or {}).get('ssl_email', '') }}"
data-connect-domain="{{ (server.server_info or {}).get('connect_domain', '') }}"
draggable="true">
<div class="server-meta">
<div class="server-icon">{{ icon('server') }}</div>
@@ -32,6 +33,10 @@
<span class="ping-ms text-muted" id="ping-ms-{{ loop.index0 }}"></span>
</div>
<div class="server-host">{{ server.host }}:{{ server.ssh_port }}</div>
{% set connect_domain = (server.server_info or {}).get('connect_domain') %}
{% if connect_domain and connect_domain != server.host %}
<div class="server-host text-muted" title="{{ _('server_connect_domain_hint') }}">→ {{ connect_domain }}</div>
{% endif %}
</div>
</div>
@@ -139,6 +144,12 @@
</div>
</div>
<div class="form-group" style="margin-top: var(--space-md)">
<label class="form-label">{{ _('server_connect_domain') }}</label>
<input class="form-input" type="text" id="editServerConnectDomain" placeholder="vpn.example.com">
<div class="form-hint">{{ _('server_connect_domain_hint') }}</div>
</div>
<div class="form-group" style="margin-top: var(--space-md)">
<label class="form-label">{{ _('server_ssl_domain') }}</label>
<input class="form-input" type="text" id="editServerSslDomain" placeholder="vpn.example.com">
@@ -214,6 +225,12 @@
</div>
</div>
<div class="form-group" style="margin-top: var(--space-md)">
<label class="form-label">{{ _('server_connect_domain') }}</label>
<input class="form-input" type="text" id="serverConnectDomain" placeholder="vpn.example.com">
<div class="form-hint">{{ _('server_connect_domain_hint') }}</div>
</div>
<div class="form-group" style="margin-top: var(--space-md)">
<label class="form-label">{{ _('server_ssl_domain') }}</label>
<input class="form-input" type="text" id="serverSslDomain" placeholder="vpn.example.com">
@@ -268,6 +285,7 @@
private_key: document.getElementById('serverKey').value,
ssl_domain: document.getElementById('serverSslDomain').value.trim(),
ssl_email: document.getElementById('serverSslEmail').value.trim(),
connect_domain: document.getElementById('serverConnectDomain').value.trim(),
};
const result = await apiCall('/api/servers/add', 'POST', data);
@@ -318,6 +336,7 @@
document.getElementById('editServerKey').value = '';
document.getElementById('editServerSslDomain').value = card.dataset.sslDomain || '';
document.getElementById('editServerSslEmail').value = card.dataset.sslEmail || '';
document.getElementById('editServerConnectDomain').value = card.dataset.connectDomain || '';
// Pre-select the tab matching the server's current auth method.
const authIsKey = card.dataset.auth === 'key';
@@ -349,6 +368,7 @@
private_key: document.getElementById('editServerKey').value || null,
ssl_domain: document.getElementById('editServerSslDomain').value.trim(),
ssl_email: document.getElementById('editServerSslEmail').value.trim(),
connect_domain: document.getElementById('editServerConnectDomain').value.trim(),
};
await apiCall(`/api/servers/${idx}/edit`, 'POST', body);
showToast(_('server_saved'), 'success');
+2 -1
View File
@@ -196,7 +196,7 @@
const xuiConfigured = {{ 'true' if xui_configured else 'false' }};
const xuiDefaultInbound = {{ xui_default_inbound | int }};
const xuiDefaultPanelId = {{ (xui_default_panel_id or '') | tojson }};
const VPN_PROTO_ORDER = ['awg2', 'awg', 'awg_legacy', 'wireguard', 'xray', 'telemt', 'hysteria', 'naiveproxy'];
const VPN_PROTO_ORDER = ['awg2', 'awg', 'awg_legacy', 'wireguard', 'xray', 'telemt', 'hysteria', 'naiveproxy', 'mieru'];
const PROTO_TITLES = {
awg2: 'AmneziaWG 2.0',
awg: 'AmneziaWG',
@@ -206,6 +206,7 @@
telemt: 'Telemt',
hysteria: 'Hysteria 2',
naiveproxy: 'NaiveProxy',
mieru: 'Mieru',
xui: '3x-ui VLESS',
};
+1 -1
View File
@@ -122,7 +122,7 @@
const vpnTab = document.querySelectorAll('.config-tab')[1];
const vpnPanel = document.getElementById('panel-vpn');
const base = String(proto || '').split('__')[0];
if (proto === 'telemt' || base === 'hysteria' || base === 'naiveproxy') {
if (proto === 'telemt' || base === 'hysteria' || base === 'naiveproxy' || base === 'mieru') {
vpnTab.style.display = 'none';
} else {
vpnTab.style.display = '';
+327 -3
View File
@@ -1,4 +1,4 @@
{% extends "base.html" %}
{% extends "base.html" %}
{% from "macros/icons.html" import icon %}
{% block title_extra %} — {{ server.name }}{% endblock %}
@@ -155,6 +155,25 @@
</div>
</div>
</div>
<div id="connectDomainSection" class="hidden" style="margin-top: var(--space-md);">
<div class="divider"></div>
<div class="form-group" style="margin-bottom: 0;">
<label class="form-label">{{ _('server_connect_domain') }}</label>
<div class="flex gap-sm" style="flex-wrap: wrap; align-items: flex-end;">
<div style="flex: 0 0 200px; min-width: 160px;">
<select class="form-input" id="connectDomainProto" onchange="refreshConnectDomainFields()"></select>
</div>
<div style="flex: 1; min-width: 200px;">
<input class="form-input" type="text" id="connectDomainInput" placeholder="vpn.example.com">
</div>
<button type="button" class="btn btn-primary btn-sm" id="connectDomainSaveBtn" onclick="saveConnectDomain()">
{{ _('save') }}
</button>
</div>
<div class="form-hint" style="margin-top: var(--space-xs);">{{ _('server_connect_domain_awg_hint') }}</div>
<div class="text-muted text-sm" id="connectDomainEffective" style="margin-top: var(--space-xs);"></div>
</div>
</div>
</div>
<!-- Installed Applications Section -->
@@ -295,6 +314,31 @@
</div>
</div>
<!-- Mieru Card -->
<div class="card card-hover protocol-card protocol-mieru" id="proto-mieru">
<div style="display:flex; align-items:center; justify-content:space-between; margin-bottom:var(--space-sm);">
<div class="protocol-icon">{{ icon('zap') }}</div>
<div class="flex gap-sm" id="mieru-ctrl" style="display:none!important;"></div>
</div>
<div class="protocol-name">Mieru <span
style="font-size:0.65rem; background:var(--accent, #6366f1); color:#fff; padding:2px 6px; border-radius:8px; vertical-align:middle;">v3.28.0</span></div>
<div class="protocol-desc">
{{ _('mieru_desc') }}
</div>
<div class="protocol-status" id="mieru-status">
<span class="badge badge-warn"><span class="badge-dot"></span> {{ _('not_checked') }}</span>
</div>
<div id="mieru-info" class="hidden">
<div class="protocol-info" id="mieru-info-grid"></div>
</div>
<div class="flex gap-sm" id="mieru-actions">
<button class="btn btn-primary btn-sm" onclick="openInstallModal('mieru')" id="mieru-install-btn"
style="flex:1">
{{ _('install') }}
</button>
</div>
</div>
<!-- Hysteria Card -->
<div class="card card-hover protocol-card protocol-hysteria" id="proto-hysteria">
<div style="display:flex; align-items:center; justify-content:space-between; margin-bottom:var(--space-sm);">
@@ -544,12 +588,23 @@
<option value="telemt">Telemt</option>
<option value="wireguard">WireGuard</option>
</select>
<button type="button" class="btn btn-secondary btn-sm hidden" id="moveConnectionsBtn" onclick="openMoveConnectionsModal()">
<span>{{ icon('share') }}</span> {{ _('move_connections') }}
</button>
<button class="btn btn-primary btn-sm" onclick="openAddConnectionModal()">
<span>{{ icon('plus') }}</span> {{ _('add') }}
</button>
</div>
</div>
<div id="connectionsBulkBar" class="connections-bulk-bar hidden">
<label class="connections-select-all">
<input type="checkbox" id="connSelectAll" onchange="toggleSelectAllConnections(this.checked)">
<span>{{ _('select_all') }}</span>
</label>
<span class="connections-selected-count" id="connSelectedCount">0</span>
</div>
<div id="connectionsList">
<div class="loading-overlay" id="connectionsLoading" style="display:none;">
<div class="loading-spinner"></div>
@@ -747,6 +802,20 @@
<div class="form-hint" style="margin-top: var(--space-sm); padding: var(--space-sm) var(--space-md); border-radius: var(--radius-sm); background: rgba(234,179,8,0.12); border: 1px solid rgba(234,179,8,0.35);">{{ _('naiveproxy_client_hint') }}</div>
</div>
<div id="mieruOptions"
style="display:none; padding: var(--space-md); background: rgba(0,0,0,0.03); border-radius: var(--radius-md); margin-bottom: var(--space-md);">
<div class="form-hint" style="margin-bottom: var(--space-md); padding: var(--space-sm) var(--space-md); border-radius: var(--radius-sm); background: rgba(234,179,8,0.12); border: 1px solid rgba(234,179,8,0.35); color: var(--text);">
{{ _('mieru_ports_warning') }}
</div>
<div class="form-group">
<label class="form-label">{{ _('port') }} (TCP) *</label>
<input class="form-input" type="number" id="installMieruPort" value="2999" min="1025" max="65535">
<div class="form-hint">{{ _('mieru_port_hint') }}</div>
</div>
<div class="form-hint">{{ _('mieru_install_hint') }}</div>
<div class="form-hint" style="margin-top: var(--space-sm); padding: var(--space-sm) var(--space-md); border-radius: var(--radius-sm); background: rgba(234,179,8,0.12); border: 1px solid rgba(234,179,8,0.35);">{{ _('mieru_client_hint') }}</div>
</div>
<div class="modal-footer">
<button class="btn btn-secondary" onclick="closeModal('installModal')">{{ _('cancel') }}</button>
<button class="btn btn-primary" onclick="installProtocol()" id="installBtn">
@@ -969,6 +1038,35 @@
</div>
</div>
<!-- ===== Move Connections Modal ===== -->
<div class="modal-backdrop" id="moveConnectionsModal">
<div class="modal" style="max-width: 520px;">
<div class="modal-header">
<h2 class="modal-title">{{ _('move_connections_title') }}</h2>
<button class="modal-close" onclick="closeModal('moveConnectionsModal')">×</button>
</div>
<p class="form-hint">{{ _('move_connections_hint') }}</p>
<div class="form-group">
<label class="form-label" for="moveTargetServer">{{ _('move_connections_target') }}</label>
<select class="form-select" id="moveTargetServer"></select>
</div>
<label class="form-check" style="display:flex; align-items:center; gap:var(--space-sm); margin-bottom: var(--space-md);">
<input type="checkbox" id="moveDeleteSource" checked>
<span>{{ _('move_connections_delete_source') }}</span>
</label>
<div class="form-hint" style="border-left: 3px solid var(--warning); padding-left: var(--space-sm);">
{{ _('move_connections_warning') }}
</div>
<div class="modal-footer">
<button type="button" class="btn btn-secondary" onclick="closeModal('moveConnectionsModal')">{{ _('cancel') }}</button>
<button type="button" class="btn btn-primary" onclick="moveSelectedConnections()" id="moveConnectionsSubmitBtn">
<span id="moveConnectionsSubmitText">{{ _('move_connections') }}</span>
<div class="spinner hidden" id="moveConnectionsSpinner" style="width:14px; height:14px;"></div>
</button>
</div>
</div>
</div>
<!-- ===== Connection Config Modal (with Tabs) ===== -->
<div class="modal-backdrop" id="configModal">
<div class="modal" style="max-width: 600px;">
@@ -1090,7 +1188,9 @@
<script src="https://cdnjs.cloudflare.com/ajax/libs/codemirror/5.65.16/mode/htmlmixed/htmlmixed.min.js"></script>
<script>
const SERVER_ID = {{ server_id }};
const ALL_SERVERS = {{ servers_for_move | tojson }};
const SERVER_HOST = "{{ server.host }}";
const SERVER_CONNECT_DOMAIN = {{ ((server.server_info or {}).get('connect_domain') or '') | tojson }};
const SERVER_SSL_DOMAIN = {{ ((server.server_info or {}).get('ssl_domain') or '') | tojson }};
const SERVER_SSL_EMAIL = {{ ((server.server_info or {}).get('ssl_email') or '') | tojson }};
const MARKETPLACE_APPS = [
@@ -1099,6 +1199,7 @@
{ proto: 'awg_legacy', category: 'protocols', icon: 'radio', title: 'AmneziaWG Legacy', descKey: 'awg_legacy_desc' },
{ proto: 'xray', category: 'protocols', icon: 'zap', title: 'Xray (VLESS-Reality)', descKey: 'xray_desc' },
{ proto: 'telemt', category: 'protocols', icon: 'plane', title: 'Telemt (Telegram Proxy)', descKey: 'telemt_desc' },
{ proto: 'mieru', category: 'protocols', icon: 'zap', title: 'Mieru', descKey: 'mieru_desc', badge: 'v3.28.0' },
{ proto: 'hysteria', category: 'protocols', icon: 'refresh', title: 'Hysteria 2', descKey: 'hysteria_desc' },
{ proto: 'naiveproxy', category: 'protocols', icon: 'link', title: 'NaiveProxy', descKey: 'naiveproxy_desc', badge: 'STABLE' },
{ proto: 'wireguard', category: 'protocols', icon: 'lock', title: 'WireGuard', descKey: 'wireguard_desc' },
@@ -1112,6 +1213,8 @@
{ id: 'services', icon: 'wrench', titleKey: 'services' },
{ id: 'web_servers', icon: 'globe', titleKey: 'web_servers' },
];
const WG_AWG_BASES = new Set(['awg', 'awg2', 'awg_legacy', 'wireguard']);
let connectDomainEffective = {};
let currentInstallProto = 'awg';
let currentInstallAnother = false;
let currentConfig = '';
@@ -1171,6 +1274,94 @@
return Object.keys(installedProtocols).some(key => protoBase(key) === base && installedProtocols[key]);
}
function hasWgAwgInstalled() {
return Object.entries(installedProtocols || {}).some(([key, installed]) => installed && WG_AWG_BASES.has(protoBase(key)));
}
function listInstalledWgAwgProtocols() {
const protos = new Set();
Object.entries(installedProtocols || {}).forEach(([key, installed]) => {
if (installed && WG_AWG_BASES.has(protoBase(key))) protos.add(key);
});
return Array.from(protos).sort((a, b) => {
const ao = MARKETPLACE_APPS.findIndex(app => app.proto === protoBase(a));
const bo = MARKETPLACE_APPS.findIndex(app => app.proto === protoBase(b));
if (ao !== bo) return ao - bo;
return protoInstance(a) - protoInstance(b);
});
}
function updateConnectDomainSection() {
const section = document.getElementById('connectDomainSection');
if (!section) return;
const show = hasWgAwgInstalled();
section.classList.toggle('hidden', !show);
if (!show) return;
const select = document.getElementById('connectDomainProto');
if (!select) return;
const prev = select.value;
const installed = listInstalledWgAwgProtocols();
select.innerHTML = `<option value="">${_('server_connect_domain_all')}</option>` +
installed.map(p => `<option value="${p}">${getProtoTitle(p)}</option>`).join('');
if (prev && [...select.options].some(opt => opt.value === prev)) {
select.value = prev;
}
refreshConnectDomainFields();
}
async function refreshConnectDomainFields() {
const proto = document.getElementById('connectDomainProto')?.value || '';
const input = document.getElementById('connectDomainInput');
const eff = document.getElementById('connectDomainEffective');
try {
const query = proto ? `?protocol=${encodeURIComponent(proto)}` : '';
const data = await apiCall(`/api/servers/${SERVER_ID}/connect-domain${query}`, 'GET');
connectDomainEffective = data;
if (input) {
input.value = proto ? (data.protocol_connect_domain || '') : (data.connect_domain || '');
}
if (eff) {
if (data.effective_host && data.effective_host !== data.ssh_host) {
eff.textContent = `${_('server_connect_domain_current')}: ${data.effective_host} (${_('server_connect_domain_ssh')}: ${data.ssh_host})`;
} else {
eff.textContent = `${_('server_connect_domain_current')}: ${data.ssh_host || SERVER_HOST}`;
}
}
Object.entries(currentProtocolStatus || {}).forEach(([p, info]) => {
if (WG_AWG_BASES.has(protoBase(p)) && isAppInstalled(info)) {
updateProtocolCard(p, info);
}
});
} catch (err) {
if (input && !proto) input.value = SERVER_CONNECT_DOMAIN || '';
if (eff) eff.textContent = '';
}
}
async function saveConnectDomain() {
const btn = document.getElementById('connectDomainSaveBtn');
const proto = document.getElementById('connectDomainProto')?.value || '';
const domain = document.getElementById('connectDomainInput')?.value.trim() || '';
if (btn) btn.disabled = true;
try {
await apiCall(`/api/servers/${SERVER_ID}/connect-domain`, 'POST', {
connect_domain: domain,
protocol: proto || null,
});
showToast(_('server_connect_domain_saved'), 'success');
await refreshConnectDomainFields();
Object.entries(currentProtocolStatus || {}).forEach(([p, info]) => {
if (WG_AWG_BASES.has(protoBase(p)) && isAppInstalled(info)) {
updateProtocolCard(p, info);
}
});
} catch (err) {
showToast(err.message, 'error');
} finally {
if (btn) btn.disabled = false;
}
}
function switchCategory(cat) {
if (cat === 'management') {
openManagementModal();
@@ -1329,6 +1520,7 @@
if (empty) empty.classList.toggle('hidden', installedAppsLoading || installedCount > 0);
const loading = document.getElementById('installedAppsLoading');
if (loading) loading.classList.toggle('hidden', !installedAppsLoading);
updateConnectDomainSection();
}
function getProtoTitle(proto) {
@@ -1343,6 +1535,7 @@
case 'telemt': title = 'Telemt'; break;
case 'hysteria': title = 'Hysteria 2'; break;
case 'naiveproxy': title = 'NaiveProxy'; break;
case 'mieru': title = 'Mieru'; break;
case 'wireguard': title = 'WireGuard'; break;
case 'dns': title = 'AmneziaDNS'; break;
case 'socks5': title = 'SOCKS5 Proxy'; break;
@@ -1402,7 +1595,7 @@
for (const [proto, info] of orderedProtocolEntries(data.protocols)) {
updateProtocolCard(proto, info);
const isVPN = ['awg', 'awg2', 'awg_legacy', 'xray', 'telemt', 'hysteria', 'naiveproxy', 'wireguard'].includes(protoBase(proto));
const isVPN = ['awg', 'awg2', 'awg_legacy', 'xray', 'telemt', 'hysteria', 'naiveproxy', 'mieru', 'wireguard'].includes(protoBase(proto));
if (info.container_running && isVPN) {
const opt = document.createElement('option');
opt.value = proto;
@@ -1630,13 +1823,22 @@
if (isService) {
grid = buildServiceInfoGrid(proto, info);
} else if (info.port) {
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('port')}</span><span class="protocol-info-value">${info.port}/${(['xray', 'telemt', 'naiveproxy'].includes(protoBase(proto))) ? 'TCP' : 'UDP'}</span></div>`;
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('port')}</span><span class="protocol-info-value">${info.port}/${(['xray', 'telemt', 'naiveproxy', 'mieru'].includes(protoBase(proto))) ? 'TCP' : 'UDP'}</span></div>`;
if (WG_AWG_BASES.has(protoBase(proto))) {
const endpoint = (connectDomainEffective.effective_host && connectDomainEffective.effective_host !== SERVER_HOST)
? connectDomainEffective.effective_host
: SERVER_HOST;
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('server_endpoint_label')}</span><span class="protocol-info-value">${endpoint}</span></div>`;
}
if (protoBase(proto) === 'hysteria' && info.domain) {
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('hysteria_domain')}</span><span class="protocol-info-value">${info.domain}</span></div>`;
}
if (protoBase(proto) === 'naiveproxy' && info.domain) {
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('naiveproxy_domain')}</span><span class="protocol-info-value">${info.domain}</span></div>`;
}
if (protoBase(proto) === 'mieru' && info.release) {
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('mieru_version')}</span><span class="protocol-info-value">v${info.release}</span></div>`;
}
}
if (!isService && info.clients_count !== undefined) {
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('connections')}</span><span class="protocol-info-value">${info.clients_count}</span></div>`;
@@ -1686,6 +1888,13 @@
<button class="btn btn-danger btn-sm" onclick="uninstallProtocol('${proto}')">${_('uninstall')}</button>
`;
showConnectionsSection();
} else if (protoBase(proto) === 'mieru') {
actionsEl.innerHTML = `
<button class="btn btn-secondary btn-sm" onclick="selectProtocolForConns('${proto}')" style="flex:1">${_('connections')}</button>
<button class="btn btn-secondary btn-sm" onclick="showProtocolBackups('${proto}')">${_('backup')}</button>
<button class="btn btn-danger btn-sm" onclick="uninstallProtocol('${proto}')">${_('uninstall')}</button>
`;
showConnectionsSection();
} else {
actionsEl.innerHTML = `
<button class="btn btn-secondary btn-sm" onclick="selectProtocolForConns('${proto}')" style="flex:1">${_('connections')}</button>
@@ -2089,6 +2298,7 @@
const nginxOpts = document.getElementById('nginxOptions');
const hysteriaOpts = document.getElementById('hysteriaOptions');
const naiveproxyOpts = document.getElementById('naiveproxyOptions');
const mieruOpts = document.getElementById('mieruOptions');
telemtOpts.style.display = 'none';
socks5Opts.style.display = 'none';
@@ -2096,6 +2306,7 @@
nginxOpts.style.display = 'none';
hysteriaOpts.style.display = 'none';
if (naiveproxyOpts) naiveproxyOpts.style.display = 'none';
if (mieruOpts) mieruOpts.style.display = 'none';
if (portGroup) portGroup.style.display = '';
if (base === 'dns') {
@@ -2163,6 +2374,17 @@
if (npDomain && !npDomain.value && SERVER_SSL_DOMAIN) npDomain.value = SERVER_SSL_DOMAIN;
if (npEmail && !npEmail.value && SERVER_SSL_EMAIL) npEmail.value = SERVER_SSL_EMAIL;
updateNaiveproxyDnsHint();
} else if (base === 'mieru') {
if (portGroup) portGroup.style.display = 'none';
const suggested = '2999';
portInput.value = suggested;
portInput.disabled = false;
if (mieruOpts) mieruOpts.style.display = 'block';
const miPort = document.getElementById('installMieruPort');
if (miPort) {
miPort.value = suggested;
miPort.oninput = () => { portInput.value = miPort.value; };
}
} else {
portLabel.textContent = _('port') + ' (UDP)';
portInput.value = currentInstallAnother ? nextSuggestedPort(currentInstallProto, 55424) : '55424';
@@ -2240,6 +2462,11 @@
params.port = '443';
params.naiveproxy_domain = document.getElementById('installNaiveproxyDomain').value.trim();
params.naiveproxy_email = document.getElementById('installNaiveproxyEmail').value.trim();
} else if (protoBase(currentInstallProto) === 'mieru') {
const miPortEl = document.getElementById('installMieruPort');
if (miPortEl && miPortEl.value) {
params.port = miPortEl.value;
}
}
const result = await apiCall(`/api/servers/${SERVER_ID}/install`, 'POST', params);
clearInterval(progressInterval);
@@ -2608,6 +2835,95 @@
document.getElementById('connectionsSection').scrollIntoView({ behavior: 'smooth' });
}
const selectedConnectionIds = new Set();
function updateMoveSelection() {
selectedConnectionIds.clear();
document.querySelectorAll('.conn-select:checked').forEach((el) => {
if (el.dataset.clientId) selectedConnectionIds.add(el.dataset.clientId);
});
const count = selectedConnectionIds.size;
const bulkBar = document.getElementById('connectionsBulkBar');
const moveBtn = document.getElementById('moveConnectionsBtn');
const countEl = document.getElementById('connSelectedCount');
const selectAll = document.getElementById('connSelectAll');
const boxes = document.querySelectorAll('.conn-select');
if (bulkBar) bulkBar.classList.toggle('hidden', boxes.length === 0);
if (moveBtn) moveBtn.classList.toggle('hidden', boxes.length === 0);
if (countEl) countEl.textContent = _('connections_selected_count').replace('{}', String(count));
if (selectAll) {
selectAll.indeterminate = count > 0 && count < boxes.length;
selectAll.checked = boxes.length > 0 && count === boxes.length;
}
}
function toggleSelectAllConnections(checked) {
document.querySelectorAll('.conn-select').forEach((el) => { el.checked = checked; });
updateMoveSelection();
}
function openMoveConnectionsModal() {
if (!selectedConnectionIds.size) {
showToast(_('move_connections_none_selected'), 'error');
return;
}
const select = document.getElementById('moveTargetServer');
select.innerHTML = '';
(ALL_SERVERS || []).forEach((srv) => {
if (srv.id === SERVER_ID) return;
const opt = document.createElement('option');
opt.value = String(srv.id);
opt.textContent = `${srv.name} (${srv.host})`;
select.appendChild(opt);
});
if (!select.options.length) {
showToast(_('move_connections_no_targets'), 'error');
return;
}
openModal('moveConnectionsModal');
}
async function moveSelectedConnections() {
const targetServerId = parseInt(document.getElementById('moveTargetServer').value, 10);
const deleteSource = document.getElementById('moveDeleteSource').checked;
const proto = document.getElementById('connProtoSelect').value;
const clientIds = Array.from(selectedConnectionIds);
if (!clientIds.length || Number.isNaN(targetServerId)) {
showToast(_('move_connections_none_selected'), 'error');
return;
}
if (!confirm(_('move_connections_confirm').replace('{}', String(clientIds.length)))) return;
const btn = document.getElementById('moveConnectionsSubmitBtn');
const text = document.getElementById('moveConnectionsSubmitText');
const spinner = document.getElementById('moveConnectionsSpinner');
btn.disabled = true;
spinner.classList.remove('hidden');
text.textContent = _('loading');
try {
const data = await apiCall(`/api/servers/${SERVER_ID}/connections/move`, 'POST', {
protocol: proto,
target_server_id: targetServerId,
client_ids: clientIds,
delete_source: deleteSource,
});
const moved = (data.moved || []).length;
const failed = (data.failed || []).length;
let msg = _('move_connections_success').replace('{}', String(moved));
if (failed) msg += '. ' + _('move_connections_partial_fail').replace('{}', String(failed));
showToast(msg, failed && !moved ? 'error' : 'success');
closeModal('moveConnectionsModal');
selectedConnectionIds.clear();
loadConnections();
} catch (err) {
showToast(_('error') + ': ' + err.message, 'error');
} finally {
btn.disabled = false;
spinner.classList.add('hidden');
text.textContent = _('move_connections');
}
}
async function loadConnections() {
const proto = document.getElementById('connProtoSelect').value;
const loading = document.getElementById('connectionsLoading');
@@ -2622,11 +2938,14 @@
loading.style.display = '';
emptyEl.classList.add('hidden');
listEl.innerHTML = '';
selectedConnectionIds.clear();
updateMoveSelection();
try {
const data = await apiCall(`/api/servers/${SERVER_ID}/connections?protocol=${proto}`);
loading.style.display = 'none';
if (!data.clients || data.clients.length === 0) {
emptyEl.classList.remove('hidden');
updateMoveSelection();
return;
}
window.connectionsStore = {};
@@ -2670,6 +2989,9 @@
listEl.innerHTML += `
<div class="client-item" style="${disabledStyle}">
<label class="conn-select-wrap">
<input type="checkbox" class="conn-select" data-client-id="${escapeJs(client.clientId)}" onchange="updateMoveSelection()">
</label>
<div class="client-info">
<div class="client-avatar">${initial}</div>
<div>
@@ -2686,6 +3008,7 @@
</div>
`;
});
updateMoveSelection();
} catch (err) {
loading.style.display = 'none';
showToast(_('connections_load_error') + ': ' + err.message, 'error');
@@ -2965,6 +3288,7 @@
}
// ========== Init ==========
applyInstalledAppsVisibility();
checkServer();
+410 -60
View File
@@ -204,88 +204,147 @@
</div>
<!-- BLOCK Tunnels -->
<div class="card">
<h3 class="card-title" style="margin-bottom: var(--space-lg);">🌍 {{ _('tunnels_title') }}</h3>
<div style="display: flex; flex-direction: column; gap: var(--space-md);">
<div style="padding: var(--space-md); border: 1px solid var(--border-color); border-radius: var(--radius-md); background: var(--bg-primary);">
<div style="display:flex; align-items:center; justify-content:space-between; gap:var(--space-md); margin-bottom: var(--space-sm);">
<strong>{{ _('local_server') }}</strong>
<span class="badge badge-info">{{ _('active') }}</span>
<div class="card tunnels-card">
<div class="tunnels-header">
<h3 class="card-title">🌍 {{ _('tunnels_title') }}</h3>
<p class="tunnels-subtitle">{{ _('tunnels_subtitle') }}</p>
</div>
<div style="display:flex; gap:var(--space-sm); align-items:center;">
<code id="localServerUrl" style="flex:1; min-width:0; overflow:hidden; text-overflow:ellipsis; white-space:nowrap; color: var(--text-secondary);">{{ request.url.scheme }}://{{ request.url.netloc }}</code>
<div class="tunnels-local">
<div class="tunnels-local-icon" aria-hidden="true">🏠</div>
<div class="tunnels-local-body">
<div class="tunnels-local-label">{{ _('local_server') }}</div>
<div class="tunnels-local-url">
<code id="localServerUrl">{{ request.url.scheme }}://{{ request.url.netloc }}</code>
<button type="button" class="btn btn-secondary btn-sm" onclick="copyElementText('localServerUrl')">{{ _('copy') }}</button>
</div>
</div>
<div class="tunnel-row" data-provider="cloudflare" style="padding: var(--space-md); border: 1px solid var(--border-color); border-radius: var(--radius-md); background: var(--bg-primary);">
<div style="display:flex; align-items:center; justify-content:space-between; gap:var(--space-md); margin-bottom: var(--space-sm);">
<strong>Cloudflare Quick Tunnel</strong>
<span class="badge badge-secondary" id="cloudflareInstallBadge">{{ _('not_installed') }}</span>
<span class="tunnel-status-pill tunnel-status-pill--ok">{{ _('active') }}</span>
</div>
<div id="cloudflarePublicUrls" class="form-hint" style="margin-bottom: var(--space-sm);">{{ _('tunnel_no_public_url') }}</div>
<div style="display:grid; grid-template-columns: 1fr 1fr 1fr; gap: var(--space-sm);">
<button type="button" class="btn btn-primary" id="cloudflareTunnelBtn" onclick="enableTunnel('cloudflare')">
<div class="tunnels-section">
<h4 class="tunnels-section-title">{{ _('tunnels_section_inbound') }}</h4>
<div class="tunnels-grid">
<article class="tunnel-card tunnel-row" data-provider="cloudflare" id="tunnelCard-cloudflare">
<div class="tunnel-card-head">
<div class="tunnel-card-icon tunnel-card-icon--cloudflare" aria-hidden="true"></div>
<div class="tunnel-card-meta">
<h5 class="tunnel-card-title">Cloudflare Quick Tunnel</h5>
<p class="tunnel-card-desc">{{ _('tunnel_cloudflare_desc') }}</p>
</div>
<span class="tunnel-status-pill" id="cloudflareInstallBadge">{{ _('not_installed') }}</span>
</div>
<div class="tunnel-card-body">
<div id="cloudflarePublicUrls" class="tunnel-url-box tunnel-url-box--empty">{{ _('tunnel_no_public_url') }}</div>
</div>
<div class="tunnel-card-actions tunnel-card-actions--triple">
<button type="button" class="btn btn-primary btn-sm" id="cloudflareTunnelBtn" onclick="enableTunnel('cloudflare')">
<span id="cloudflareTunnelBtnText">{{ _('tunnel_install_enable') }}</span>
<div class="spinner hidden" id="cloudflareTunnelSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-secondary hidden" id="cloudflareStopBtn" onclick="stopTunnel('cloudflare')">
<button type="button" class="btn btn-secondary btn-sm hidden" id="cloudflareStopBtn" onclick="stopTunnel('cloudflare')">
<span id="cloudflareStopBtnText">{{ _('tunnel_stop') }}</span>
<div class="spinner hidden" id="cloudflareStopSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-danger hidden" id="cloudflareDeleteBtn" onclick="deleteTunnel('cloudflare')">
<button type="button" class="btn btn-danger btn-sm hidden" id="cloudflareDeleteBtn" onclick="deleteTunnel('cloudflare')">
<span id="cloudflareDeleteBtnText">{{ _('tunnel_delete') }}</span>
<div class="spinner hidden" id="cloudflareDeleteSpinner" style="width:14px; height:14px;"></div>
</button>
</div>
</div>
</article>
<div class="tunnel-row" data-provider="ngrok" style="padding: var(--space-md); border: 1px solid var(--border-color); border-radius: var(--radius-md); background: var(--bg-primary);">
<div style="display:flex; align-items:center; justify-content:space-between; gap:var(--space-md); margin-bottom: var(--space-sm);">
<strong>ngrok Tunnel + Authtoken</strong>
<span class="badge badge-secondary" id="ngrokInstallBadge">{{ _('not_installed') }}</span>
<article class="tunnel-card tunnel-row" data-provider="ngrok" id="tunnelCard-ngrok">
<div class="tunnel-card-head">
<div class="tunnel-card-icon tunnel-card-icon--ngrok" aria-hidden="true">N</div>
<div class="tunnel-card-meta">
<h5 class="tunnel-card-title">ngrok</h5>
<p class="tunnel-card-desc">{{ _('tunnel_ngrok_desc') }}</p>
</div>
<div class="form-group" style="margin-bottom: var(--space-sm);">
<span class="tunnel-status-pill" id="ngrokInstallBadge">{{ _('not_installed') }}</span>
</div>
<div class="tunnel-card-body">
<input type="password" class="form-input" id="ngrokAuthtoken" placeholder="{{ _('ngrok_authtoken_placeholder') }}" autocomplete="off">
<div id="ngrokPublicUrls" class="tunnel-url-box tunnel-url-box--empty">{{ _('tunnel_no_public_url') }}</div>
</div>
<div id="ngrokPublicUrls" class="form-hint" style="margin-bottom: var(--space-sm);">{{ _('tunnel_no_public_url') }}</div>
<div style="display:grid; grid-template-columns: 1fr 1fr 1fr; gap: var(--space-sm);">
<button type="button" class="btn btn-primary" id="ngrokTunnelBtn" onclick="enableTunnel('ngrok')">
<div class="tunnel-card-actions tunnel-card-actions--triple">
<button type="button" class="btn btn-primary btn-sm" id="ngrokTunnelBtn" onclick="enableTunnel('ngrok')">
<span id="ngrokTunnelBtnText">{{ _('tunnel_install_enable') }}</span>
<div class="spinner hidden" id="ngrokTunnelSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-secondary hidden" id="ngrokStopBtn" onclick="stopTunnel('ngrok')">
<button type="button" class="btn btn-secondary btn-sm hidden" id="ngrokStopBtn" onclick="stopTunnel('ngrok')">
<span id="ngrokStopBtnText">{{ _('tunnel_stop') }}</span>
<div class="spinner hidden" id="ngrokStopSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-danger hidden" id="ngrokDeleteBtn" onclick="deleteTunnel('ngrok')">
<button type="button" class="btn btn-danger btn-sm hidden" id="ngrokDeleteBtn" onclick="deleteTunnel('ngrok')">
<span id="ngrokDeleteBtnText">{{ _('tunnel_delete') }}</span>
<div class="spinner hidden" id="ngrokDeleteSpinner" style="width:14px; height:14px;"></div>
</button>
</div>
</article>
</div>
</div>
<div class="tunnel-row" data-provider="warp" style="padding: var(--space-md); border: 1px solid var(--border-color); border-radius: var(--radius-md); background: var(--bg-primary);">
<div style="display:flex; align-items:center; justify-content:space-between; gap:var(--space-md); margin-bottom: var(--space-sm);">
<strong>Cloudflare WARP</strong>
<span class="badge badge-secondary" id="warpInstallBadge">{{ _('not_installed') }}</span>
<div class="tunnels-section">
<h4 class="tunnels-section-title">{{ _('tunnels_section_outbound') }}</h4>
<div class="tunnels-grid">
<article class="tunnel-card tunnel-row" data-provider="warp" id="tunnelCard-warp">
<div class="tunnel-card-head">
<div class="tunnel-card-icon tunnel-card-icon--warp" aria-hidden="true">W</div>
<div class="tunnel-card-meta">
<h5 class="tunnel-card-title">Cloudflare WARP</h5>
<p class="tunnel-card-desc">{{ _('tunnel_warp_desc') }}</p>
</div>
<div id="warpStatusText" class="form-hint" style="margin-bottom: var(--space-sm);">{{ _('warp_status_unknown') }}</div>
<div id="warpHintText" class="form-hint" style="margin-bottom: var(--space-sm);">{{ _('warp_hint') }}</div>
<div style="display:grid; grid-template-columns: 1fr 1fr; gap: var(--space-sm);">
<button type="button" class="btn btn-primary" id="warpConnectBtn" onclick="connectWarp()">
<span class="tunnel-status-pill" id="warpInstallBadge">{{ _('not_installed') }}</span>
</div>
<div class="tunnel-card-body">
<p id="warpStatusText" class="tunnel-status-line">{{ _('warp_status_unknown') }}</p>
<p id="warpHintText" class="tunnel-hint">{{ _('warp_hint') }}</p>
</div>
<div class="tunnel-card-actions">
<button type="button" class="btn btn-primary btn-sm" id="warpConnectBtn" onclick="connectWarp()">
<span id="warpConnectBtnText">{{ _('warp_connect') }}</span>
<div class="spinner hidden" id="warpConnectSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-secondary hidden" id="warpDisconnectBtn" onclick="disconnectWarp()">
<button type="button" class="btn btn-secondary btn-sm hidden" id="warpDisconnectBtn" onclick="disconnectWarp()">
<span id="warpDisconnectBtnText">{{ _('warp_disconnect') }}</span>
<div class="spinner hidden" id="warpDisconnectSpinner" style="width:14px; height:14px;"></div>
</button>
</div>
</article>
<article class="tunnel-card tunnel-row" data-provider="nordvpn" id="tunnelCard-nordvpn">
<div class="tunnel-card-head">
<div class="tunnel-card-icon tunnel-card-icon--nordvpn" aria-hidden="true">N</div>
<div class="tunnel-card-meta">
<h5 class="tunnel-card-title">NordVPN</h5>
<p class="tunnel-card-desc">{{ _('tunnel_nordvpn_desc') }}</p>
</div>
<span class="tunnel-status-pill" id="nordvpnInstallBadge">{{ _('not_installed') }}</span>
</div>
<div class="tunnel-card-body">
<p id="nordvpnStatusText" class="tunnel-status-line">{{ _('nordvpn_status_unknown') }}</p>
<p id="nordvpnServerText" class="tunnel-status-line tunnel-status-line--server hidden"></p>
<p id="nordvpnHintText" class="tunnel-hint">{{ _('nordvpn_hint') }}</p>
<div class="tunnel-nordvpn-fields">
<input type="text" class="form-input" id="nordvpnCountry" placeholder="{{ _('nordvpn_country_placeholder') }}" autocomplete="off">
<input type="text" class="form-input" id="nordvpnCity" placeholder="{{ _('nordvpn_city_placeholder') }}" autocomplete="off">
</div>
</div>
<p class="form-hint" style="margin-top: var(--space-md);">{{ _('tunnels_hint') }}</p>
<div class="tunnel-card-actions">
<button type="button" class="btn btn-primary btn-sm" id="nordvpnConnectBtn" onclick="connectNordvpn()">
<span id="nordvpnConnectBtnText">{{ _('nordvpn_connect') }}</span>
<div class="spinner hidden" id="nordvpnConnectSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-secondary btn-sm hidden" id="nordvpnDisconnectBtn" onclick="disconnectNordvpn()">
<span id="nordvpnDisconnectBtnText">{{ _('nordvpn_disconnect') }}</span>
<div class="spinner hidden" id="nordvpnDisconnectSpinner" style="width:14px; height:14px;"></div>
</button>
</div>
</article>
</div>
</div>
<p class="tunnels-footnote">{{ _('tunnels_hint') }}</p>
</div>
<!-- BLOCK SSL/HTTPS -->
@@ -545,15 +604,19 @@
<div class="card" style="margin-top: var(--space-lg);">
<h3 class="card-title" style="margin-bottom: var(--space-lg);">📤 {{ _('backup_title') }}</h3>
<div style="display: flex; flex-direction: column; gap: var(--space-md);">
<div style="display: flex; gap: var(--space-sm);">
<div style="display: flex; gap: var(--space-sm); flex-wrap: wrap;">
<a href="/api/settings/backup/download" class="btn btn-secondary"
style="flex:1; text-decoration:none; display:flex; align-items:center; justify-content:center; gap:var(--space-sm);">
style="flex:1; min-width:200px; text-decoration:none; display:flex; align-items:center; justify-content:center; gap:var(--space-sm);">
<span>⬇️</span> {{ _('download_backup') }}
</a>
<a href="/api/settings/backup/download/json" class="btn btn-secondary"
style="flex:1; min-width:200px; text-decoration:none; display:flex; align-items:center; justify-content:center; gap:var(--space-sm);">
<span>📄</span> {{ _('download_backup_json') }}
</a>
</div>
<div style="border-top: 1px solid var(--border-color); padding-top: var(--space-md);">
<div style="display: flex; flex-direction: column; gap: var(--space-sm);">
<input type="file" id="backupFile" accept=".json" style="display: none;"
<input type="file" id="backupFile" accept=".sql,.json" style="display: none;"
onchange="handleRestore(event)">
<button type="button" class="btn btn-secondary"
onclick="document.getElementById('backupFile').click()" id="restoreBtn"
@@ -564,6 +627,9 @@
</div>
</div>
<p class="form-hint" style="margin-top: var(--space-sm);">
{{ _('backup_hint') }}
</p>
<p class="form-hint" style="margin-top: var(--space-xs);">
{{ _('restore_confirm') }}
</p>
</div>
@@ -584,6 +650,41 @@
</div>
</div>
<!-- BLOCK: Support / Donate (admin) -->
{% set donate_cfg = settings.get('donate') or {} %}
<div class="card" style="margin-top: var(--space-lg);">
<h3 class="card-title" style="margin-bottom: var(--space-lg);">{{ icon('heart') }} {{ _('donate_settings_title') }}</h3>
<p class="form-hint" style="margin-top: 0; margin-bottom: var(--space-md);">{{ _('donate_settings_hint') }}</p>
<div class="form-group">
<label class="form-label" style="display:flex; align-items:center; gap:8px; cursor:pointer;">
<input type="checkbox" id="donate_enabled" {% if donate_cfg.get('enabled', True) %}checked{% endif %}>
{{ _('donate_enabled') }}
</label>
</div>
<div class="form-group">
<label class="form-label">{{ _('donate_intro') }}</label>
<textarea class="form-textarea" id="donate_intro" rows="2" placeholder="{{ _('support_intro') }}">{{ donate_cfg.get('intro') or '' }}</textarea>
</div>
{% for key, label_key in [('sbp', 'donate_sbp'), ('card', 'donate_card'), ('crypto', 'donate_crypto')] %}
{% set method = donate_cfg.get(key) or {} %}
<div style="border:1px solid var(--border-color); border-radius:var(--radius-md); padding:var(--space-md); margin-bottom:var(--space-md);">
<label class="form-label" style="display:flex; align-items:center; gap:8px; cursor:pointer; margin-bottom:var(--space-sm);">
<input type="checkbox" id="donate_{{ key }}_enabled" {% if method.get('enabled', True) %}checked{% endif %}>
{{ _(label_key) }}
</label>
<div class="form-group" style="margin-bottom:var(--space-sm);">
<label class="form-label">{{ _('donate_method_title') }}</label>
<input type="text" class="form-input" id="donate_{{ key }}_title" value="{{ method.get('title') or '' }}" placeholder="{{ _(label_key) }}">
</div>
<div class="form-group" style="margin-bottom:0;">
<label class="form-label">{{ _('donate_method_details') }}</label>
<textarea class="form-textarea" id="donate_{{ key }}_details" rows="3" placeholder="{{ _('donate_details_placeholder') }}">{{ method.get('details') or '' }}</textarea>
</div>
</div>
{% endfor %}
<p class="form-hint">{{ _('donate_preview_hint') }} <a href="/support" target="_blank" rel="noopener">/support</a></p>
</div>
<!-- BLOCK: About & Updates -->
<div class="card" style="margin-top: var(--space-lg);">
<h3 class="card-title" style="margin-bottom: var(--space-lg);">️ {{ _('about_title') }}</h3>
@@ -597,15 +698,24 @@
<!-- Updated via JS -->
</div>
<div style="display: flex; gap: var(--space-sm); margin-top: var(--space-sm);">
<button type="button" class="btn btn-secondary" onclick="checkForUpdates()" id="checkUpdateBtn" style="flex:1;">
<div style="display: flex; gap: var(--space-sm); margin-top: var(--space-sm); flex-wrap: wrap;">
<button type="button" class="btn btn-primary" onclick="upgradePanel()" id="upgradePanelBtn" style="flex:1; min-width:180px;">
<span id="upgradePanelBtnText">⬆ {{ _('upgrade_panel') }}</span>
<div class="spinner hidden" id="upgradePanelSpinner" style="width:14px; height:14px;"></div>
</button>
<button type="button" class="btn btn-secondary" onclick="checkForUpdates()" id="checkUpdateBtn" style="flex:1; min-width:140px;">
<span id="checkUpdateBtnText">🔄 {{ _('check_updates') }}</span>
<div class="spinner hidden" id="checkUpdateSpinner" style="width:14px; height:14px;"></div>
</button>
<a href="https://git.evilfox.cc/test2/Amnezia-Web-Panel-main/releases" target="_blank" class="btn btn-primary hidden" id="downloadUpdateBtn" style="flex:1; text-decoration: none; justify-content: center;">
<button type="button" class="btn btn-secondary hidden" onclick="applyPanelUpdate()" id="applyUpdateBtn" style="flex:1; min-width:140px;">
<span id="applyUpdateBtnText">⬆ {{ _('apply_update') }}</span>
<div class="spinner hidden" id="applyUpdateSpinner" style="width:14px; height:14px;"></div>
</button>
<a href="https://git.evilfox.cc/test2/Amnezia-Web-Panel-main/releases" target="_blank" class="btn btn-secondary hidden" id="downloadUpdateBtn" style="flex:1; min-width:140px; text-decoration: none; justify-content: center;">
⬇️ {{ _('download_update') }}
</a>
</div>
<p class="form-hint" id="updateModeHint" style="margin:0;">{{ _('auto_update_hint') }}</p>
</div>
</div>
</div>
@@ -916,31 +1026,45 @@
const el = document.getElementById(`${provider}PublicUrls`);
if (!el) return;
if (!urls || !urls.length) {
el.className = 'tunnel-url-box tunnel-url-box--empty';
el.textContent = _('tunnel_no_public_url');
return;
}
el.className = 'tunnel-url-box';
el.innerHTML = urls.map((url, idx) => `
<div style="display:flex; gap:var(--space-sm); align-items:center; margin-top:${idx ? 'var(--space-xs)' : '0'};">
<code id="${provider}PublicUrl${idx}" style="flex:1; min-width:0; overflow:hidden; text-overflow:ellipsis; white-space:nowrap; color: var(--text-secondary);">${escapeHTML(url)}</code>
<div class="tunnel-url-row">
<code id="${provider}PublicUrl${idx}">${escapeHTML(url)}</code>
<button type="button" class="btn btn-secondary btn-sm" onclick="copyElementText('${provider}PublicUrl${idx}')">${_('copy')}</button>
</div>
`).join('');
}
function setTunnelStatusPill(badge, { ok, info, text }) {
if (!badge) return;
badge.className = 'tunnel-status-pill' + (ok ? ' tunnel-status-pill--ok' : (info ? ' tunnel-status-pill--info' : ''));
badge.textContent = text;
}
function updateTunnelProvider(provider, status) {
const badge = document.getElementById(`${provider}InstallBadge`);
const text = document.getElementById(`${provider}TunnelBtnText`);
const startBtn = document.getElementById(`${provider}TunnelBtn`);
const stopBtn = document.getElementById(`${provider}StopBtn`);
const deleteBtn = document.getElementById(`${provider}DeleteBtn`);
const card = document.getElementById(`tunnelCard-${provider}`);
if (!badge || !text) return;
badge.className = status.installed ? 'badge badge-success' : 'badge badge-secondary';
badge.textContent = status.installed ? _('installed') : _('not_installed');
text.textContent = status.running ? _('tunnel_running') : (status.installed ? _('tunnel_enable') : _('tunnel_install_enable'));
if (startBtn) startBtn.disabled = !!status.running;
if (stopBtn) stopBtn.classList.toggle('hidden', !status.running);
const running = !!status.running;
setTunnelStatusPill(badge, {
ok: running,
info: !running && status.installed,
text: running ? _('tunnel_running') : (status.installed ? _('installed') : _('not_installed')),
});
text.textContent = running ? _('tunnel_running') : (status.installed ? _('tunnel_enable') : _('tunnel_install_enable'));
if (startBtn) startBtn.disabled = running;
if (stopBtn) stopBtn.classList.toggle('hidden', !running);
if (deleteBtn) deleteBtn.classList.toggle('hidden', !status.installed);
if (card) card.classList.toggle('tunnel-card--running', running);
renderTunnelUrls(provider, status.public_urls || (status.public_url ? [status.public_url] : []));
}
@@ -951,6 +1075,7 @@
updateTunnelProvider('cloudflare', data.cloudflare || {});
updateTunnelProvider('ngrok', data.ngrok || {});
updateWarpStatus(data.warp || {});
updateNordvpnStatus(data.nordvpn || {});
} catch (err) {
showToast(`${_('error')}: ` + err.message, 'error');
}
@@ -963,12 +1088,16 @@
const connectBtn = document.getElementById('warpConnectBtn');
const disconnectBtn = document.getElementById('warpDisconnectBtn');
const connectText = document.getElementById('warpConnectBtnText');
const card = document.getElementById('tunnelCard-warp');
if (!badge || !statusText || !connectBtn || !disconnectBtn || !connectText) return;
const installed = !!status.installed;
const connected = !!status.connected || status.status === 'connected';
badge.className = connected ? 'badge badge-success' : (installed ? 'badge badge-info' : 'badge badge-secondary');
badge.textContent = connected ? _('warp_connected') : (installed ? _('installed') : _('not_installed'));
setTunnelStatusPill(badge, {
ok: connected,
info: !connected && installed,
text: connected ? _('warp_connected') : (installed ? _('installed') : _('not_installed')),
});
const statusKey = `warp_status_${status.status || 'unknown'}`;
statusText.textContent = _(statusKey) || status.status || _('warp_status_unknown');
@@ -976,6 +1105,7 @@
connectText.textContent = installed ? _('warp_connect') : _('warp_install_required');
connectBtn.disabled = connected;
disconnectBtn.classList.toggle('hidden', !connected);
if (card) card.classList.toggle('tunnel-card--connected', connected);
}
async function connectWarp() {
@@ -1020,6 +1150,86 @@
}
}
function updateNordvpnStatus(status) {
const badge = document.getElementById('nordvpnInstallBadge');
const statusText = document.getElementById('nordvpnStatusText');
const serverText = document.getElementById('nordvpnServerText');
const hintText = document.getElementById('nordvpnHintText');
const connectBtn = document.getElementById('nordvpnConnectBtn');
const disconnectBtn = document.getElementById('nordvpnDisconnectBtn');
const connectText = document.getElementById('nordvpnConnectBtnText');
const card = document.getElementById('tunnelCard-nordvpn');
if (!badge || !statusText || !connectBtn || !disconnectBtn || !connectText) return;
const installed = !!status.installed;
const connected = !!status.connected || status.status === 'connected';
setTunnelStatusPill(badge, {
ok: connected,
info: !connected && installed,
text: connected ? _('nordvpn_connected') : (installed ? _('installed') : _('not_installed')),
});
const statusKey = `nordvpn_status_${status.status || 'unknown'}`;
statusText.textContent = _(statusKey) || status.status || _('nordvpn_status_unknown');
if (serverText) {
const serverLine = status.server || '';
serverText.textContent = serverLine;
serverText.classList.toggle('hidden', !serverLine);
}
hintText.textContent = status.last_error || (installed ? _('nordvpn_hint') : (status.install_hint || _('nordvpn_install_hint')));
connectText.textContent = installed ? _('nordvpn_connect') : _('nordvpn_install_required');
connectBtn.disabled = connected;
disconnectBtn.classList.toggle('hidden', !connected);
if (card) card.classList.toggle('tunnel-card--connected', connected);
}
async function connectNordvpn() {
const btn = document.getElementById('nordvpnConnectBtn');
const spinner = document.getElementById('nordvpnConnectSpinner');
const text = document.getElementById('nordvpnConnectBtnText');
btn.disabled = true;
spinner.classList.remove('hidden');
text.textContent = _('loading');
try {
const country = (document.getElementById('nordvpnCountry') || {}).value || '';
const city = (document.getElementById('nordvpnCity') || {}).value || '';
const status = await apiCall('/api/settings/nordvpn/connect', 'POST', {
country: country.trim(),
city: city.trim(),
});
updateNordvpnStatus(status);
showToast(_('nordvpn_connected'), 'success');
} catch (err) {
showToast(`${_('error')}: ` + err.message, 'error');
await loadTunnelStatus();
} finally {
spinner.classList.add('hidden');
}
}
async function disconnectNordvpn() {
const btn = document.getElementById('nordvpnDisconnectBtn');
const spinner = document.getElementById('nordvpnDisconnectSpinner');
const text = document.getElementById('nordvpnDisconnectBtnText');
btn.disabled = true;
spinner.classList.remove('hidden');
text.textContent = _('loading');
try {
const status = await apiCall('/api/settings/nordvpn/disconnect', 'POST');
updateNordvpnStatus(status);
showToast(_('nordvpn_disconnected'), 'success');
} catch (err) {
showToast(`${_('error')}: ` + err.message, 'error');
await loadTunnelStatus();
} finally {
btn.disabled = false;
text.textContent = _('nordvpn_disconnect');
spinner.classList.add('hidden');
}
}
async function enableTunnel(provider) {
const btn = document.getElementById(`${provider}TunnelBtn`);
const spinner = document.getElementById(`${provider}TunnelSpinner`);
@@ -1303,11 +1513,24 @@
create_xui_panel_id: document.getElementById('guest_create_xui_panel')?.value || '',
};
const donateMethod = (key) => ({
enabled: document.getElementById(`donate_${key}_enabled`).checked,
title: document.getElementById(`donate_${key}_title`).value.trim(),
details: document.getElementById(`donate_${key}_details`).value.trim(),
});
const donate = {
enabled: document.getElementById('donate_enabled').checked,
intro: document.getElementById('donate_intro').value.trim(),
sbp: donateMethod('sbp'),
card: donateMethod('card'),
crypto: donateMethod('crypto'),
};
try {
const res = await fetch('/api/settings/save', {
method: 'POST',
headers: { 'Content-Type': 'application/json' },
body: JSON.stringify({ appearance, sync, captcha, telegram, ssl, guest })
body: JSON.stringify({ appearance, sync, captcha, telegram, ssl, guest, donate })
});
if (!res.ok) throw new Error(_('error'));
showToast(_('settings_saved'), 'success');
@@ -1321,7 +1544,7 @@
}
const guestServersData = {{ servers | default([]) | tojson }};
const VPN_PROTO_ORDER = ['awg2', 'awg', 'awg_legacy', 'wireguard', 'xray', 'telemt', 'hysteria', 'naiveproxy'];
const VPN_PROTO_ORDER = ['awg2', 'awg', 'awg_legacy', 'wireguard', 'xray', 'telemt', 'hysteria', 'naiveproxy', 'mieru'];
const PROTO_TITLES = {
awg2: 'AmneziaWG 2.0',
awg: 'AmneziaWG',
@@ -1331,6 +1554,7 @@
telemt: 'Telemt',
hysteria: 'Hysteria 2',
naiveproxy: 'NaiveProxy',
mieru: 'Mieru',
xui: '3x-ui VLESS',
};
function protoTitle(key) {
@@ -1482,41 +1706,167 @@
updateProtocolsForSync();
}
async function checkForUpdates() {
let latestUpdateInfo = null;
async function checkForUpdates(silent) {
const btn = document.getElementById('checkUpdateBtn');
const text = document.getElementById('checkUpdateBtnText');
const spinner = document.getElementById('checkUpdateSpinner');
const statusDiv = document.getElementById('updateStatus');
const downloadBtn = document.getElementById('downloadUpdateBtn');
const applyBtn = document.getElementById('applyUpdateBtn');
const modeHint = document.getElementById('updateModeHint');
if (!silent) {
btn.disabled = true;
text.textContent = "{{ _('checking_updates')|default('Checking...') }}";
spinner.classList.remove('hidden');
}
statusDiv.classList.add('hidden');
downloadBtn.classList.add('hidden');
applyBtn.classList.add('hidden');
try {
const data = await apiCall('/api/settings/check_updates');
latestUpdateInfo = data;
const latestVersion = data.latest_version || '';
statusDiv.classList.remove('hidden');
if (modeHint) {
const method = data.update_mode || (data.mode && data.mode.update_method) || (data.mode && data.mode.mode) || '';
if (!data.can_auto_update) {
if (method === 'docker') {
modeHint.textContent = "{{ _('auto_update_docker')|default('Docker: on the host run git pull && docker compose up -d --build.') }}";
} else {
modeHint.textContent = "{{ _('auto_update_manual')|default('One-click update needs a writable install directory or git clone.') }}";
}
} else if (method === 'archive') {
modeHint.textContent = "{{ _('auto_update_archive')|default('One-click update downloads the release ZIP from git.evilfox.cc and restarts the panel.') }}";
} else {
modeHint.textContent = "{{ _('auto_update_ready')|default('Git auto-update is available for this install.') }}";
}
}
const upgradeBtn = document.getElementById('upgradePanelBtn');
if (upgradeBtn) {
upgradeBtn.disabled = false;
upgradeBtn.title = data.can_auto_update ? '' : (modeHint ? modeHint.textContent : '');
}
if (data.update_available && latestVersion) {
statusDiv.innerHTML = `<span style="color: var(--success); font-weight: bold;">{{ _('update_available')|default('Update available') }}: ${latestVersion}</span>`;
statusDiv.style.border = '1px solid var(--success)';
downloadBtn.href = data.html_url || data.releases_url || 'https://git.evilfox.cc/test2/Amnezia-Web-Panel-main/releases';
downloadBtn.classList.remove('hidden');
applyBtn.classList.remove('hidden');
} else {
statusDiv.innerHTML = `<span style="color: var(--text-muted);">{{ _('up_to_date')|default('Up to date') }}</span>`;
statusDiv.style.border = '1px solid var(--border-color)';
}
} catch (err) {
showToast('Failed to check for updates: ' + err.message, 'error');
if (!silent) showToast('Failed to check for updates: ' + err.message, 'error');
} finally {
if (!silent) {
btn.disabled = false;
text.textContent = "🔄 {{ _('check_updates')|default('Check for updates') }}";
spinner.classList.add('hidden');
}
}
}
async function waitForPanelRestart(timeoutMs = 120000, panelUrl) {
const base = String(panelUrl || window.location.origin || '').replace(/\/$/, '');
const started = Date.now();
while (Date.now() - started < timeoutMs) {
try {
const res = await fetch(`${base}/api/health`, { cache: 'no-store' });
if (res.ok) {
window.location.href = base + '/';
return true;
}
} catch (_) {}
await new Promise((resolve) => setTimeout(resolve, 2000));
}
const hint = base ? ` ${base}` : '';
showToast("{{ _('update_restart_timeout')|default('Panel did not come back in time. Refresh the page manually.') }}" + hint, 'error');
return false;
}
async function applyPanelUpdate() {
const applyBtn = document.getElementById('applyUpdateBtn');
const applyText = document.getElementById('applyUpdateBtnText');
const applySpinner = document.getElementById('applyUpdateSpinner');
const target = (latestUpdateInfo && latestUpdateInfo.latest_version) || '';
if (!target) {
showToast("{{ _('update_no_target')|default('No target version. Check for updates first.') }}", 'error');
return;
}
if (!confirm("{{ _('apply_update_confirm')|default('Install update from git.evilfox.cc and restart the panel?') }} " + target)) {
return;
}
applyBtn.disabled = true;
applyText.textContent = "{{ _('applying_update')|default('Updating…') }}";
applySpinner.classList.remove('hidden');
let restarting = false;
try {
const data = await apiCall('/api/settings/apply_update', 'POST', {
target_version: target,
allow_dirty: true,
});
showToast(data.message || "{{ _('update_restarting')|default('Updated. Restarting…') }}", 'success');
restarting = true;
applyText.textContent = "{{ _('update_waiting_restart')|default('Waiting for panel…') }}";
await waitForPanelRestart(120000, data.panel_url);
} catch (err) {
showToast(_('error') + ': ' + err.message, 'error');
} finally {
if (!restarting) {
applyBtn.disabled = false;
applyText.textContent = "⬆ {{ _('apply_update')|default('Install update') }}";
applySpinner.classList.add('hidden');
}
}
}
async function upgradePanel() {
const btn = document.getElementById('upgradePanelBtn');
const text = document.getElementById('upgradePanelBtnText');
const spinner = document.getElementById('upgradePanelSpinner');
const latest = (latestUpdateInfo && latestUpdateInfo.latest_version) || '';
const confirmMsg = latest
? ("{{ _('upgrade_panel_confirm')|default('Download and install') }} " + latest + "?")
: "{{ _('upgrade_panel_confirm_latest')|default('Check for updates and install the latest release?') }}";
if (!confirm(confirmMsg)) return;
btn.disabled = true;
spinner.classList.remove('hidden');
text.textContent = "{{ _('upgrade_panel_working')|default('Updating panel…') }}";
let restarting = false;
try {
const data = await apiCall('/api/settings/upgrade_panel', 'POST', {});
if (data.up_to_date) {
showToast("{{ _('upgrade_panel_up_to_date')|default('Already on the latest version') }}", 'info');
await checkForUpdates(true);
return;
}
showToast(data.message || "{{ _('update_restarting')|default('Updated. Restarting…') }}", 'success');
restarting = true;
text.textContent = "{{ _('update_waiting_restart')|default('Waiting for panel…') }}";
await waitForPanelRestart(120000, data.panel_url);
} catch (err) {
showToast(_('error') + ': ' + err.message, 'error');
await checkForUpdates(true);
} finally {
if (!restarting) {
btn.disabled = false;
spinner.classList.add('hidden');
text.textContent = "⬆ {{ _('upgrade_panel')|default('Update panel') }}";
}
}
}
// Auto-check once on Settings load
setTimeout(() => checkForUpdates(true), 800);
/* ========== API Tokens ========== */
+104
View File
@@ -0,0 +1,104 @@
{% extends "base.html" %}
{% from "macros/icons.html" import icon %}
{% block title_extra %} — {{ _('nav_support') }}{% endblock %}
{% block head_extra %}
<style>
.support-hero {
text-align: center;
padding: var(--space-xl) var(--space-md);
margin-bottom: var(--space-xl);
}
.support-hero-icon {
font-size: 2.5rem;
margin-bottom: var(--space-md);
color: var(--accent);
}
.support-grid {
display: grid;
grid-template-columns: repeat(auto-fit, minmax(260px, 1fr));
gap: var(--space-lg);
max-width: 960px;
margin: 0 auto;
}
.support-card {
border: 1px solid var(--border-color);
border-radius: var(--radius-lg);
padding: var(--space-lg);
background: var(--bg-secondary);
display: flex;
flex-direction: column;
gap: var(--space-md);
}
.support-card-title {
font-weight: 700;
font-size: 1.05rem;
display: flex;
align-items: center;
gap: var(--space-sm);
}
.support-details {
font-family: ui-monospace, SFMono-Regular, Menlo, Consolas, monospace;
font-size: 0.85rem;
white-space: pre-wrap;
word-break: break-word;
padding: var(--space-sm);
border-radius: var(--radius-md);
background: var(--bg-primary);
border: 1px dashed var(--border-color);
min-height: 4rem;
color: var(--text-muted);
}
.support-details.has-content {
color: var(--text-primary);
border-style: solid;
}
</style>
{% endblock %}
{% block content %}
<section class="support-hero">
<div class="support-hero-icon">{{ icon('heart') }}</div>
<h1 class="section-title" style="justify-content: center; margin-bottom: var(--space-sm);">
{{ _('support_title') }}
</h1>
<p class="text-muted" style="max-width: 560px; margin: 0 auto; line-height: 1.5;">
{% if donate.get('intro') %}
{{ donate.intro }}
{% else %}
{{ _('support_intro') }}
{% endif %}
</p>
</section>
<div class="support-grid">
{% set methods = [
('sbp', _('donate_sbp'), '💳'),
('card', _('donate_card'), '🏦'),
('crypto', _('donate_crypto'), '₿'),
] %}
{% for key, default_title, emoji in methods %}
{% set method = donate.get(key) or {} %}
{% if method.get('enabled', True) %}
<div class="card support-card">
<div class="support-card-title">
<span aria-hidden="true">{{ emoji }}</span>
<span>{{ method.get('title') or default_title }}</span>
</div>
{% set details = (method.get('details') or '').strip() %}
<div class="support-details{% if details %} has-content{% endif %}" id="donate-{{ key }}-details">{{ details or _('donate_details_soon') }}</div>
{% if details %}
<button type="button" class="btn btn-secondary btn-sm" onclick="copyToClipboard(document.getElementById('donate-{{ key }}-details').textContent)">
{{ icon('copy') }} {{ _('copy') }}
</button>
{% endif %}
</div>
{% endif %}
{% endfor %}
</div>
<p class="text-muted text-sm" style="text-align: center; margin-top: var(--space-xl); max-width: 520px; margin-left: auto; margin-right: auto;">
{{ _('support_footer') }}
</p>
{% endblock %}
+2 -1
View File
@@ -631,7 +631,7 @@
const select = document.getElementById(selectId);
const group = groupId ? document.getElementById(groupId) : null;
select.innerHTML = '';
const vpnOrder = ['awg2', 'awg', 'awg_legacy', 'wireguard', 'xray', 'telemt', 'hysteria', 'naiveproxy'];
const vpnOrder = ['awg2', 'awg', 'awg_legacy', 'wireguard', 'xray', 'telemt', 'hysteria', 'naiveproxy', 'mieru'];
const titles = {
awg2: 'AmneziaWG 2.0',
awg: 'AmneziaWG',
@@ -641,6 +641,7 @@
telemt: 'Telemt',
hysteria: 'Hysteria 2',
naiveproxy: 'NaiveProxy',
mieru: 'Mieru',
xui: '3x-ui VLESS',
};
const protoTitle = (key) => {
+113 -27
View File
@@ -4,6 +4,7 @@
"nav_invites": "Invite links",
"nav_settings": "Settings",
"nav_connections": "Connections",
"nav_support": "Support",
"nav_logout": "Logout",
"theme_dark": "Dark",
"theme_light": "Light",
@@ -39,7 +40,7 @@
"limit": "Limit",
"manage": "Manage",
"no_protocols": "No protocols",
"add_server_desc": "Add your first VPN server to get started. You'll need SSH credentials to connect.",
"add_server_desc": "Add your first VPN server to get started. You\u0027ll need SSH credentials to connect.",
"ssh_host": "Host / IP",
"ssh_port": "SSH Port",
"ssh_user": "User",
@@ -80,8 +81,8 @@
"no_connections": "No connections",
"no_connections_desc": "Add your first connection to generate a VPN configuration",
"install_protocol": "Install protocol",
"port_default_hint": "Default port: 55424. Make sure it's not busy",
"port_xray_hint": "Default port: 443 (recommended for Xray). Make sure it's not taken by another web server.",
"port_default_hint": "Default port: 55424. Make sure it\u0027s not busy",
"port_xray_hint": "Default port: 443 (recommended for Xray). Make sure it\u0027s not taken by another web server.",
"reinstall": "Reinstall",
"uninstall_confirm": "Uninstall {}? All connections and configurations will be lost.",
"stop_container_confirm": "Stop container {}?",
@@ -101,6 +102,19 @@
"connection_created": "Connection \"{}\" created",
"delete_connection_confirm": "Delete this connection? The configuration will stop working.",
"connection_deleted": "Connection deleted",
"select_all": "Select all",
"connections_selected_count": "{} selected",
"move_connections": "Move",
"move_connections_title": "Move connections to another server",
"move_connections_target": "Target server",
"move_connections_confirm": "Move {} connection(s) to the selected server? Users will need new configs.",
"move_connections_hint": "Recreates selected connections on the target server and updates user assignments.",
"move_connections_warning": "Clients get new keys and IPs. Old configs stop working after move.",
"move_connections_delete_source": "Remove from current server after move",
"move_connections_success": "Moved {} connection(s)",
"move_connections_partial_fail": "{} could not be moved",
"move_connections_none_selected": "Select at least one connection",
"move_connections_no_targets": "No other servers available",
"config_tab": "📄 Config",
"vpn_key_tab": "🔑 VPN-key",
"qr_code_tab": "📱 QR-code",
@@ -265,10 +279,17 @@
"bot_start_btn": "▶️ Start",
"bot_hint": "After changing the token, save the settings — the bot will restart automatically. Users must have a Telegram ID in their profile.",
"api_docs_title": "🔌 API Documentation",
"api_docs_hint": "Use these interfaces to explore the panel's API capabilities",
"api_docs_hint": "Use these interfaces to explore the panel\u0027s API capabilities",
"tunnels_title": "Tunnels",
"tunnels_subtitle": "Expose the panel to the internet or route outbound traffic through a VPN.",
"tunnels_section_inbound": "Public access",
"tunnels_section_outbound": "Outbound VPN",
"tunnel_cloudflare_desc": "Free HTTPS URL via Cloudflare — no account required.",
"tunnel_ngrok_desc": "Stable tunnel with your ngrok authtoken.",
"tunnel_warp_desc": "Route server traffic through Cloudflare WARP.",
"tunnel_nordvpn_desc": "Connect this host to NordVPN servers.",
"local_server": "Local Server",
"tunnel_install_enable": "Install & Enable",
"tunnel_install_enable": "Install \u0026 Enable",
"tunnel_enable": "Enable Tunnel",
"tunnel_running": "Tunnel running",
"tunnel_stop": "Stop",
@@ -317,7 +338,7 @@
"copy_key_big": "Copy key",
"copying_key": "Copying…",
"key_copied": "Key copied — paste it into the app",
"more_qr_download": "QR code & file",
"more_qr_download": "QR code \u0026 file",
"download_config_file": "Download config file",
"show_config_text": "Show config text",
"copied": "Copied!",
@@ -341,40 +362,71 @@
"lang_zh": "中文 (Chinese)",
"lang_fa": "فارسی (Persian)",
"backup_title": "Simple Backup",
"download_backup": "Download data.json",
"restore_backup": "Restore from file",
"restore_confirm": "Are you sure? Current data will be overwritten and the application will restart.",
"download_backup": "Download PostgreSQL dump (.sql)",
"download_backup_json": "Export JSON (legacy)",
"backup_hint": "Full PostgreSQL database dump of the panel. Use .sql for complete backup; JSON export is compatible with older versions.",
"restore_backup": "Restore from .sql or .json",
"restore_confirm": "Restore will overwrite all current panel data in the database.",
"restore_success": "Restore successful! Restarting...",
"invalid_backup_file": "Invalid backup file or structure",
"invalid_backup_file": "Invalid backup file (.sql dump or legacy data.json)",
"config_unavailable": "Configuration unavailable",
"config_unavailable_desc": "This client was created via the native Amnezia app.\\nThe private key is stored only on the user's device and cannot be recovered by the server.",
"config_unavailable_desc": "This client was created via the native Amnezia app.\\nThe private key is stored only on the user\u0027s device and cannot be recovered by the server.",
"client_public_key": "Client public key:",
"telemt_desc": "MTProxy-based Telegram proxy with advanced obfuscation and TLS emulation support.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) via official tobyxdd/hysteria (apernet/hysteria) with Let's Encrypt TLS. Admin sets the domain at install time.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) via official tobyxdd/hysteria (apernet/hysteria) with Let\u0027s Encrypt TLS. Admin sets the domain at install time.",
"hysteria_domain": "Domain",
"hysteria_email": "Let's Encrypt email",
"hysteria_email": "Let\u0027s Encrypt email",
"hysteria_port_hint": "UDP port for Hysteria (default 8998). Avoid 443 if nginx/xray already use UDP/TCP 443. Port 80/TCP must be free for certificate issuance.",
"hysteria_install_hint": "Point the domain A-record to this server before install. Port 80/TCP is used temporarily for Let's Encrypt HTTP-01 validation. BBR and salamander obfuscation are enabled automatically.",
"hysteria_install_hint": "Point the domain A-record to this server before install. Port 80/TCP is used temporarily for Let\u0027s Encrypt HTTP-01 validation. BBR and salamander obfuscation are enabled automatically.",
"hysteria_dns_hint": "Create this DNS record before installation:",
"hysteria_settings_title": "Hysteria settings",
"hysteria_change_port": "Change port",
"hysteria_port_change_hint": "UDP listen port. If you see “address already in use”, pick a free port (e.g. 8443 or 8998), save, then re-import the client link.",
"hysteria_settings_saved": "Hysteria settings updated",
"hysteria_ports_warning": "Warning: free TCP ports 80 and 443 are required for stable operation (Let's Encrypt on 80, HTTPS/QUIC on 443).",
"hysteria_ports_warning": "Warning: free TCP ports 80 and 443 are required for stable operation (Let\u0027s Encrypt on 80, HTTPS/QUIC on 443).",
"hysteria_renew_ssl": "Renew SSL",
"hysteria_ssl_change_hint": "Changing the domain re-issues the Let's Encrypt certificate (port 80 must be free).",
"hysteria_ssl_change_hint": "Changing the domain re-issues the Let\u0027s Encrypt certificate (port 80 must be free).",
"hysteria_ssl_required": "Domain and email are required for SSL",
"naiveproxy_desc": "NaiveProxy (stable) — HTTPS/HTTP2 via Caddy + forwardproxy, Let's Encrypt TLS. Client: use Karing. Do not use v2rayN; other clients untested.",
"naiveproxy_desc": "NaiveProxy (stable) — HTTPS/HTTP2 via Caddy + forwardproxy, Let\u0027s Encrypt TLS. Client: use Karing. Do not use v2rayN; other clients untested.",
"naiveproxy_domain": "Domain",
"naiveproxy_email": "Let's Encrypt email",
"naiveproxy_email": "Let\u0027s Encrypt email",
"naiveproxy_port_hint": "TCP port 443 is fixed for NaiveProxy. Port 80/TCP must be free for certificate issuance.",
"naiveproxy_install_hint": "Point the domain A-record to this server before install. Free TCP ports 80 and 443 are required (Let's Encrypt and HTTPS proxy).",
"naiveproxy_install_hint": "Point the domain A-record to this server before install. Free TCP ports 80 and 443 are required (Let\u0027s Encrypt and HTTPS proxy).",
"naiveproxy_dns_hint": "Create this DNS record before installation:",
"naiveproxy_ports_warning": "Warning: free TCP ports 80 and 443 are required for stable operation (Let's Encrypt on 80, HTTPS proxy on 443).",
"naiveproxy_ports_warning": "Warning: free TCP ports 80 and 443 are required for stable operation (Let\u0027s Encrypt on 80, HTTPS proxy on 443).",
"naiveproxy_client_hint": "Stable build. Do NOT use v2rayN. Confirmed working in Karing. Other clients are untested.",
"mieru_desc": "Mieru (mita v3.28.0) — native TCP proxy from enfein/mieru. No Docker required. Client: mieru app or Clash.Meta/mihomo.",
"mieru_version": "Version",
"mieru_port_hint": "TCP port for mita (102565535). Open it in the server firewall.",
"mieru_install_hint": "Installs the official mita package from GitHub release v3.28.0 (Debian/RPM). Requires Linux with systemd.",
"mieru_ports_warning": "Warning: ensure the chosen TCP port is free and allowed through the firewall.",
"mieru_client_hint": "Share links use mierus:// format. Import into the mieru client or Clash.Meta (type: mieru).",
"server_ssl_domain": "SSL domain (default)",
"server_ssl_email": "SSL email (default)",
"server_ssl_hint": "Used when installing Hysteria / NGINX on this server (Let's Encrypt).",
"server_connect_domain": "Client connection domain",
"server_connect_domain_hint": "Used in VPN configs instead of IP (Endpoint, vless://, etc.). When moving the server, update the DNS A-record — clients keep working.",
"server_connect_domain_awg_hint": "Used in AmneziaWG / WireGuard Endpoint instead of server IP. Leave empty to use SSH host IP.",
"server_connect_domain_all": "All AWG / WireGuard (default)",
"server_connect_domain_current": "Endpoint in configs",
"server_connect_domain_ssh": "SSH",
"server_connect_domain_saved": "Connection domain saved",
"server_endpoint_label": "Endpoint",
"support_title": "Support the project",
"support_intro": "If this panel helps you, you can support development. Choose a convenient method below.",
"support_footer": "Thank you for using Amnezia Web Panel.",
"donate_sbp": "SBP (Fast Payments)",
"donate_card": "Bank card",
"donate_crypto": "Cryptocurrency",
"donate_details_soon": "Payment details will be added soon.",
"donate_settings_title": "Support / donations",
"donate_settings_hint": "Shown on the /support page for all users. No popups — only when they open the page.",
"donate_enabled": "Show support page in navigation",
"donate_intro": "Page intro text (optional)",
"donate_method_title": "Button title (optional)",
"donate_method_details": "Payment details",
"donate_details_placeholder": "Phone, card number, wallet address…",
"donate_preview_hint": "Preview:",
"container_logs": "Container logs",
"logs_btn": "📋 Logs",
"logs_live": "Live",
@@ -433,7 +485,7 @@
"ping_checking": "Checking connectivity...",
"offline": "offline",
"api_tokens_title": "API tokens",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer <token>` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer \u003ctoken\u003e` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_empty": "No API tokens yet. Create one to integrate the panel with an external service.",
"api_tokens_create": "Create token",
"api_tokens_create_title": "Create API token",
@@ -443,8 +495,8 @@
"api_tokens_name_required": "Token name is required",
"api_tokens_created_title": "Token created",
"api_tokens_value_label": "Token value",
"api_tokens_warning_title": "This is the only time you'll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration's secret manager. The panel keeps only a hash — if you lose this value you'll need to revoke and recreate the token.",
"api_tokens_warning_title": "This is the only time you\u0027ll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration\u0027s secret manager. The panel keeps only a hash — if you lose this value you\u0027ll need to revoke and recreate the token.",
"api_tokens_revoke": "Revoke",
"api_tokens_revoke_confirm": "Revoke token \"{}\"? Any integration using it will stop working.",
"api_tokens_revoked": "Token revoked",
@@ -474,13 +526,30 @@
"cert_text_label": "Certificate content (CRT)",
"key_text_label": "Private Key content (KEY)",
"ssl_hint": "After enabling, the panel will be accessible via https:// on the specified domain. Make sure the file paths or text data are correct.",
"about_title": "About & Updates",
"about_title": "About \u0026 Updates",
"current_version": "Current version",
"check_updates": "Check for updates",
"checking_updates": "Checking...",
"update_available": "New version available",
"download_update": "Download update",
"up_to_date": "You have the latest version",
"apply_update": "Install update",
"applying_update": "Updating…",
"apply_update_confirm": "Install update from git.evilfox.cc and restart the panel?",
"update_restarting": "Updated. Restarting panel…",
"update_waiting_restart": "Waiting for panel to restart…",
"update_restart_timeout": "Panel did not come back in time. Refresh the page manually.",
"update_no_target": "No target version. Check for updates first.",
"auto_update_hint": "Auto-update pulls the release tag from git.evilfox.cc (git checkout required).",
"auto_update_ready": "Git auto-update is available for this install.",
"auto_update_docker": "Docker: one-click update downloads the release ZIP into the container. Rebuild the image to persist across container recreation.",
"auto_update_manual": "One-click update needs a writable install directory or git clone. You can still download a release.",
"auto_update_archive": "One-click update downloads the release ZIP from git.evilfox.cc and restarts the panel.",
"upgrade_panel": "Update panel",
"upgrade_panel_confirm": "Download and install",
"upgrade_panel_confirm_latest": "Check for updates and install the latest release?",
"upgrade_panel_working": "Updating panel…",
"upgrade_panel_up_to_date": "Already on the latest version",
"warp_hint": "WARP routes this host outbound through Cloudflare. It does not create a public panel URL like Quick Tunnel or ngrok.",
"warp_install_hint": "Install the official Cloudflare WARP client first, then restart the panel.",
"warp_install_required": "Install WARP first",
@@ -496,6 +565,23 @@
"warp_status_not_registered": "Cloudflare WARP is installed but not registered yet. Connect will try to register automatically.",
"warp_status_service_unavailable": "Cloudflare WARP service is not available. Make sure warp-svc is running.",
"warp_status_error": "Cloudflare WARP returned an error.",
"nordvpn_hint": "NordVPN routes this host outbound through NordVPN servers. It does not create a public panel URL like Quick Tunnel or ngrok. Run nordvpn login on the host once before connecting.",
"nordvpn_install_hint": "Install the official NordVPN client/CLI on this host, run nordvpn login, then restart the panel.",
"nordvpn_install_required": "Install NordVPN first",
"nordvpn_connect": "Connect NordVPN",
"nordvpn_disconnect": "Disconnect",
"nordvpn_connected": "NordVPN connected",
"nordvpn_disconnected": "NordVPN disconnected",
"nordvpn_status_unknown": "NordVPN status is unknown.",
"nordvpn_status_not_installed": "NordVPN CLI is not installed on this host.",
"nordvpn_status_connected": "NordVPN is connected.",
"nordvpn_status_connecting": "NordVPN is connecting.",
"nordvpn_status_disconnected": "NordVPN is disconnected.",
"nordvpn_status_not_logged_in": "NordVPN is installed but not logged in. Run nordvpn login on this host.",
"nordvpn_status_service_unavailable": "NordVPN daemon is not available. Make sure nordvpnd is running.",
"nordvpn_status_error": "NordVPN returned an error.",
"nordvpn_country_placeholder": "Country (optional, e.g. Germany or de)",
"nordvpn_city_placeholder": "City (optional, e.g. Berlin)",
"install_starting": "Starting installation...",
"server_check_complete": "Check completed",
"server_connection_error": "Connection error",
@@ -519,10 +605,10 @@
"port_next_instance_hint": "Choose a free UDP port for the additional instance.",
"checking_server": "Checking server services...",
"web_servers": "Web servers",
"nginx_desc": "NGINX web server with Let's Encrypt HTTPS certificate and editable index.html.",
"nginx_desc": "NGINX web server with Let\u0027s Encrypt HTTPS certificate and editable index.html.",
"nginx_domain": "Domain",
"nginx_email": "Let's Encrypt email",
"nginx_port_hint": "HTTPS port exposed on the server. Port 80/TCP must be free and reachable for Let's Encrypt validation.",
"nginx_email": "Let\u0027s Encrypt email",
"nginx_port_hint": "HTTPS port exposed on the server. Port 80/TCP must be free and reachable for Let\u0027s Encrypt validation.",
"nginx_install_hint": "The domain must already point to this server. Port 80/TCP is used temporarily/permanently for HTTP-01 certificate validation.",
"site": "Site",
"site_editor": "Site editor",
+90 -20
View File
@@ -100,6 +100,19 @@
"connection_created": "اتصال \"{}\" ایجاد شد",
"delete_connection_confirm": "این اتصال حذف شود؟ پیکربندی دیگر کار نخواهد کرد.",
"connection_deleted": "اتصال حذف شد",
"select_all": "انتخاب همه",
"connections_selected_count": "{} انتخاب شده",
"move_connections": "انتقال",
"move_connections_title": "انتقال اتصال‌ها به سرور دیگر",
"move_connections_target": "سرور مقصد",
"move_connections_confirm": "{} اتصال به سرور انتخاب‌شده منتقل شود؟ کاربران به پیکربندی جدید نیاز دارند.",
"move_connections_hint": "اتصال‌های انتخاب‌شده روی سرور مقصد دوباره ساخته می‌شوند و پیوند کاربران حفظ می‌شود.",
"move_connections_warning": "کلیدها و IP جدید صادر می‌شود. پیکربندی‌های قدیمی کار نمی‌کنند.",
"move_connections_delete_source": "پس از انتقال از سرور فعلی حذف شود",
"move_connections_success": "{} اتصال منتقل شد",
"move_connections_partial_fail": "{} منتقل نشد",
"move_connections_none_selected": "حداقل یک اتصال انتخاب کنید",
"move_connections_no_targets": "سرور دیگری برای انتقال وجود ندارد",
"config_tab": "📄 فایل",
"vpn_key_tab": "🔑 کلید-VPN",
"qr_code_tab": "📱 کد-QR",
@@ -256,7 +269,14 @@
"bot_hint": "پس از تغییر توکن تنظیمات را ذخیره کنید تا ربات بازراه‌اندازی شود.",
"api_docs_title": "🔌 مستندات API",
"api_docs_hint": "از این رابط‌ها برای بررسی قابلیت‌های API استفاده کنید",
"tunnels_title": "Tunnels",
"tunnels_title": "تونل‌ها",
"tunnels_subtitle": "پنل را در اینترنت منتشر کنید یا ترافیک خروجی را از طریق VPN هدایت کنید.",
"tunnels_section_inbound": "دسترسی عمومی",
"tunnels_section_outbound": "VPN خروجی",
"tunnel_cloudflare_desc": "آدرس HTTPS رایگان از Cloudflare — بدون ثبت‌نام.",
"tunnel_ngrok_desc": "تونل پایدار با authtoken ngrok شما.",
"tunnel_warp_desc": "هدایت ترافیک سرور از طریق Cloudflare WARP.",
"tunnel_nordvpn_desc": "اتصال این میزبان به سرورهای NordVPN.",
"local_server": "سرور محلی",
"tunnel_install_enable": "نصب و فعال‌سازی",
"tunnel_enable": "فعال‌سازی تونل",
@@ -324,11 +344,13 @@
"lang_zh": "中文 (Chinese)",
"lang_fa": "فارسی (Persian)",
"backup_title": "پشتیبان‌گیری ساده",
"download_backup": "دانلود data.json",
"restore_backup": "بازیابی از فایل",
"restore_confirm": "آیا مطمئن هستید؟ داده‌های فعلی بازنویسی می‌شوند و برنامه دوباره راه‌اندازی خواهد شد.",
"download_backup": "دانلود dump PostgreSQL (.sql)",
"download_backup_json": "خروجی JSON (قدیمی)",
"backup_hint": "Dump کامل پایگاه داده PostgreSQL پنل. برای پشتیبان کامل از .sql استفاده کنید؛ JSON برای نسخه‌های قدیمی.",
"restore_backup": "بازیابی از .sql یا .json",
"restore_confirm": "بازیابی تمام داده‌های فعلی پنل در پایگاه داده را بازنویسی می‌کند.",
"restore_success": "بازیابی موفقیت‌آمیز بود! در حال راه‌اندازی مجدد...",
"invalid_backup_file": "فایل پشتیبان یا ساختار نامعتبر است",
"invalid_backup_file": "فایل نامعتبر (dump .sql یا data.json قدیمی)",
"config_unavailable": "پیکربندی در دسترس نیست",
"config_unavailable_desc": "این کلاینت از طریق اپلیکیشن اصلی Amnezia ایجاد شده است.\\nکلید خصوصی فقط در دستگاه کاربر ذخیره می‌شود و توسط سرور قابل بازیابی نیست.",
"client_public_key": "کلید عمومی کلاینت:",
@@ -340,9 +362,9 @@
"clear_server": "پاک‌سازی سرور",
"remove_server": "حذف سرور از پنل",
"telemt_desc": "پروکسی تلگرام بر پایه‌ی MTProxy با پوشش‌های پیشرفته.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) با تصویر رسمی tobyxdd/hysteria (apernet/hysteria) و TLS از Let's Encrypt. دامنه را ادمین هنگام نصب مشخص می‌کند.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) با تصویر رسمی tobyxdd/hysteria (apernet/hysteria) و TLS از Let\u0027s Encrypt. دامنه را ادمین هنگام نصب مشخص می‌کند.",
"hysteria_domain": "دامنه",
"hysteria_email": "ایمیل Let's Encrypt",
"hysteria_email": "ایمیل Let\u0027s Encrypt",
"hysteria_port_hint": "پورت UDP برای Hysteria (پیش‌فرض 8998). اگر 443 اشغال است پورت دیگری بگذارید.",
"hysteria_install_hint": "قبل از نصب، رکورد A دامنه باید به این سرور اشاره کند. BBR و obfuscation salamander به‌صورت خودکار فعال می‌شوند.",
"hysteria_dns_hint": "قبل از نصب این رکورد DNS را بسازید:",
@@ -350,21 +372,29 @@
"hysteria_change_port": "تغییر پورت",
"hysteria_port_change_hint": "پورت UDP. اگر address already in use دیدید، پورت آزاد بگذارید (8443 یا 8998).",
"hysteria_settings_saved": "پورت Hysteria به‌روز شد",
"hysteria_ports_warning": "هشدار: برای کار پایدار پورت‌های TCP آزاد ۸۰ و ۴۴۳ لازم است (Let's Encrypt روی ۸۰، HTTPS/QUIC روی ۴۴۳).",
"hysteria_ports_warning": "هشدار: برای کار پایدار پورت‌های TCP آزاد ۸۰ و ۴۴۳ لازم است (Let\u0027s Encrypt روی ۸۰، HTTPS/QUIC روی ۴۴۳).",
"hysteria_renew_ssl": "تمدید SSL",
"hysteria_ssl_change_hint": "تغییر دامنه گواهی Let's Encrypt را دوباره صادر می‌کند (پورت ۸۰ باید آزاد باشد).",
"hysteria_ssl_change_hint": "تغییر دامنه گواهی Let\u0027s Encrypt را دوباره صادر می‌کند (پورت ۸۰ باید آزاد باشد).",
"hysteria_ssl_required": "برای SSL دامنه و ایمیل لازم است",
"naiveproxy_desc": "NaiveProxy (پایدار) — HTTPS/HTTP2 با Caddy + forwardproxy و TLS از Let's Encrypt. کلاینت: Karing. از v2rayN استفاده نکنید؛ بقیه آزمایش نشده‌اند.",
"naiveproxy_desc": "NaiveProxy (پایدار) — HTTPS/HTTP2 با Caddy + forwardproxy و TLS از Let\u0027s Encrypt. کلاینت: Karing. از v2rayN استفاده نکنید؛ بقیه آزمایش نشده‌اند.",
"naiveproxy_domain": "دامنه",
"naiveproxy_email": "ایمیل Let's Encrypt",
"naiveproxy_email": "ایمیل Let\u0027s Encrypt",
"naiveproxy_port_hint": "پورت TCP 443 برای NaiveProxy ثابت است. پورت 80/TCP باید برای صدور گواهی آزاد باشد.",
"naiveproxy_install_hint": "قبل از نصب، رکورد A دامنه باید به این سرور اشاره کند. پورت‌های TCP آزاد ۸۰ و ۴۴۳ لازم است (Let's Encrypt و پروکسی HTTPS).",
"naiveproxy_install_hint": "قبل از نصب، رکورد A دامنه باید به این سرور اشاره کند. پورت‌های TCP آزاد ۸۰ و ۴۴۳ لازم است (Let\u0027s Encrypt و پروکسی HTTPS).",
"naiveproxy_dns_hint": "قبل از نصب این رکورد DNS را بسازید:",
"naiveproxy_ports_warning": "هشدار: برای کار پایدار پورت‌های TCP آزاد ۸۰ و ۴۴۳ لازم است (Let's Encrypt روی ۸۰، پروکسی HTTPS روی ۴۴۳).",
"naiveproxy_ports_warning": "هشدار: برای کار پایدار پورت‌های TCP آزاد ۸۰ و ۴۴۳ لازم است (Let\u0027s Encrypt روی ۸۰، پروکسی HTTPS روی ۴۴۳).",
"naiveproxy_client_hint": "نسخه پایدار. از v2rayN استفاده نکنید. در Karing تأیید شده. سایر کلاینت‌ها آزمایش نشده‌اند.",
"mieru_desc": "Mieru (mita v3.28.0) — پروکسی TCP بومی enfein/mieru. بدون Docker. کلاینت: mieru یا Clash.Meta/mihomo.",
"mieru_version": "نسخه",
"mieru_port_hint": "پورت TCP برای mita (۱۰۲۵–۶۵۵۳۵). در فایروال سرور باز کنید.",
"mieru_install_hint": "بسته رسمی mita را از GitHub v3.28.0 نصب می‌کند (Debian/RPM). لینوکس با systemd لازم است.",
"mieru_ports_warning": "هشدار: پورت TCP انتخابی باید آزاد و در فایروال مجاز باشد.",
"mieru_client_hint": "لینک‌ها با فرمت mierus://. در کلاینت mieru یا Clash.Meta (type: mieru) وارد کنید.",
"server_ssl_domain": "دامنه SSL (پیش‌فرض)",
"server_ssl_email": "ایمیل SSL (پیش‌فرض)",
"server_ssl_hint": "هنگام نصب Hysteria / NGINX روی این سرور استفاده می‌شود (Let's Encrypt).",
"server_ssl_hint": "هنگام نصب Hysteria / NGINX روی این سرور استفاده می‌شود (Let\u0027s Encrypt).",
"server_connect_domain": "دامنه اتصال کلاینت",
"server_connect_domain_hint": "در پیکربندی VPN به‌جای IP استفاده می‌شود. هنگام انتقال سرور، رکورد DNS A را به‌روز کنید.",
"container_logs": "لاگ‌های کانتینر",
"logs_btn": "📋 Logs",
"logs_live": "زنده",
@@ -409,7 +439,7 @@
"ping_checking": "Checking connectivity...",
"offline": "offline",
"api_tokens_title": "API tokens",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer <token>` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer \u003ctoken\u003e` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_empty": "No API tokens yet. Create one to integrate the panel with an external service.",
"api_tokens_create": "Create token",
"api_tokens_create_title": "Create API token",
@@ -419,8 +449,8 @@
"api_tokens_name_required": "Token name is required",
"api_tokens_created_title": "Token created",
"api_tokens_value_label": "Token value",
"api_tokens_warning_title": "This is the only time you'll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration's secret manager. The panel keeps only a hash — if you lose this value you'll need to revoke and recreate the token.",
"api_tokens_warning_title": "This is the only time you\u0027ll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration\u0027s secret manager. The panel keeps only a hash — if you lose this value you\u0027ll need to revoke and recreate the token.",
"api_tokens_revoke": "Revoke",
"api_tokens_revoke_confirm": "Revoke token \"{}\"? Any integration using it will stop working.",
"api_tokens_revoked": "Token revoked",
@@ -448,6 +478,23 @@
"warp_status_not_registered": "Cloudflare WARP is installed but not registered yet. Connect will try to register automatically.",
"warp_status_service_unavailable": "Cloudflare WARP service is not available. Make sure warp-svc is running.",
"warp_status_error": "Cloudflare WARP returned an error.",
"nordvpn_hint": "NordVPN routes this host outbound through NordVPN servers. It does not create a public panel URL like Quick Tunnel or ngrok. Run nordvpn login on the host once before connecting.",
"nordvpn_install_hint": "Install the official NordVPN client/CLI on this host, run nordvpn login, then restart the panel.",
"nordvpn_install_required": "Install NordVPN first",
"nordvpn_connect": "Connect NordVPN",
"nordvpn_disconnect": "Disconnect",
"nordvpn_connected": "NordVPN connected",
"nordvpn_disconnected": "NordVPN disconnected",
"nordvpn_status_unknown": "NordVPN status is unknown.",
"nordvpn_status_not_installed": "NordVPN CLI is not installed on this host.",
"nordvpn_status_connected": "NordVPN is connected.",
"nordvpn_status_connecting": "NordVPN is connecting.",
"nordvpn_status_disconnected": "NordVPN is disconnected.",
"nordvpn_status_not_logged_in": "NordVPN is installed but not logged in. Run nordvpn login on this host.",
"nordvpn_status_service_unavailable": "NordVPN daemon is not available. Make sure nordvpnd is running.",
"nordvpn_status_error": "NordVPN returned an error.",
"nordvpn_country_placeholder": "Country (optional, e.g. Germany or de)",
"nordvpn_city_placeholder": "City (optional, e.g. Berlin)",
"install_starting": "Starting installation...",
"server_check_complete": "Check completed",
"server_connection_error": "Connection error",
@@ -470,10 +517,10 @@
"new_instance": "new instance",
"port_next_instance_hint": "Choose a free UDP port for the additional instance.",
"web_servers": "Web servers",
"nginx_desc": "NGINX web server with Let's Encrypt HTTPS certificate and editable index.html.",
"nginx_desc": "NGINX web server with Let\u0027s Encrypt HTTPS certificate and editable index.html.",
"nginx_domain": "Domain",
"nginx_email": "Let's Encrypt email",
"nginx_port_hint": "HTTPS port exposed on the server. Port 80/TCP must be free and reachable for Let's Encrypt validation.",
"nginx_email": "Let\u0027s Encrypt email",
"nginx_port_hint": "HTTPS port exposed on the server. Port 80/TCP must be free and reachable for Let\u0027s Encrypt validation.",
"nginx_install_hint": "The domain must already point to this server. Port 80/TCP is used for HTTP-01 certificate validation.",
"site": "Site",
"site_editor": "Site editor",
@@ -519,4 +566,27 @@
"xui_server_select_label": "سرور 3x-ui",
"xui_server_select_hint": "پنل 3x-ui که URL اشتراک می‌دهد را انتخاب کنید.",
"xui_server_delete_confirm": "این سرور 3x-ui حذف شود؟"
,
"about_title": "About & Updates",
"current_version": "Current version",
"check_updates": "Check for updates",
"checking_updates": "Checking...",
"update_available": "New version available",
"download_update": "Download update",
"up_to_date": "You have the latest version",
"apply_update": "Install update",
"applying_update": "Updating…",
"apply_update_confirm": "Install update from git.evilfox.cc and restart the panel?",
"update_restarting": "Updated. Restarting panel…",
"update_no_target": "No target version. Check for updates first.",
"auto_update_hint": "Auto-update pulls the release tag from git.evilfox.cc (git checkout required).",
"auto_update_ready": "Git auto-update is available for this install.",
"auto_update_docker": "Docker install: rebuild/pull image, or use a git checkout for one-click update.",
"auto_update_manual": "One-click update needs a git clone. You can still download a release.",
"auto_update_archive": "One-click update downloads the release ZIP from git.evilfox.cc and restarts the panel.",
"upgrade_panel": "Update panel",
"upgrade_panel_confirm": "Download and install",
"upgrade_panel_confirm_latest": "Check for updates and install the latest release?",
"upgrade_panel_working": "Updating panel…",
"upgrade_panel_up_to_date": "Already on the latest version"
}
+136 -66
View File
@@ -1,7 +1,7 @@
{
"nav_servers": "Serveurs",
"nav_users": "Utilisateurs",
"nav_invites": "Liens d'invitation",
"nav_invites": "Liens d\u0027invitation",
"nav_settings": "Paramètres",
"nav_connections": "Connexions",
"nav_logout": "Déconnexion",
@@ -56,7 +56,7 @@
"error": "Erreur",
"info": "Info",
"login_title": "Connexion au Panneau",
"username": "Nom d'utilisateur",
"username": "Nom d\u0027utilisateur",
"password": "Mot de passe",
"captcha": "Captcha",
"captcha_placeholder": "Entrez les caractères",
@@ -79,8 +79,8 @@
"no_connections": "Aucune connexion",
"no_connections_desc": "Ajoutez votre première connexion pour générer un fichier VPN",
"install_protocol": "Installer le protocole",
"port_default_hint": "Port par défaut : 55424. Assurez-vous qu'il est libre.",
"port_xray_hint": "Port recommandé : 443. Assurez-vous qu'il n'est pas utilisé par un serveur web.",
"port_default_hint": "Port par défaut : 55424. Assurez-vous qu\u0027il est libre.",
"port_xray_hint": "Port recommandé : 443. Assurez-vous qu\u0027il n\u0027est pas utilisé par un serveur web.",
"reinstall": "Réinstaller",
"uninstall_confirm": "Désinstaller {} ? Toutes les données seront perdues.",
"stop_container_confirm": "Arrêter le conteneur {} ?",
@@ -93,13 +93,26 @@
"add_connection": "Ajouter une connexion",
"connection_name": "Nom de la connexion",
"connection_name_placeholder": "Ex: iPhone, Laptop",
"assign_to_user": "Assigner à l'utilisateur (optionnel)",
"assign_to_user": "Assigner à l\u0027utilisateur (optionnel)",
"no_assign": "— Aucune assignation —",
"create": "Créer",
"creating": "Création...",
"connection_created": "Connexion \"{}\" créée",
"delete_connection_confirm": "Supprimer cette connexion ? Elle cessera de fonctionner.",
"connection_deleted": "Connexion supprimée",
"select_all": "Tout sélectionner",
"connections_selected_count": "{} sélectionné(s)",
"move_connections": "Déplacer",
"move_connections_title": "Déplacer les connexions vers un autre serveur",
"move_connections_target": "Serveur cible",
"move_connections_confirm": "Déplacer {} connexion(s) vers le serveur sélectionné ? Les utilisateurs auront besoin de nouveaux configs.",
"move_connections_hint": "Recrée les connexions sur le serveur cible et conserve les affectations utilisateur.",
"move_connections_warning": "Les clients reçoivent de nouvelles clés et IP. Les anciens configs cessent de fonctionner.",
"move_connections_delete_source": "Supprimer du serveur actuel après le déplacement",
"move_connections_success": "{} connexion(s) déplacée(s)",
"move_connections_partial_fail": "{} n'ont pas pu être déplacées",
"move_connections_none_selected": "Sélectionnez au moins une connexion",
"move_connections_no_targets": "Aucun autre serveur disponible",
"config_tab": "📄 Config",
"vpn_key_tab": "🔑 Clé-VPN",
"qr_code_tab": "📱 Code-QR",
@@ -107,19 +120,19 @@
"download_conf": "⬇ Télécharger .conf",
"copy_key": "📋 Copier la clé",
"vpn_link_hint": "Collez ce lien dans AmneziaVPN pour une config automatique",
"qr_hint": "Scannez le code QR dans l'application AmneziaVPN",
"qr_hint": "Scannez le code QR dans l\u0027application AmneziaVPN",
"no_data": "Aucune donnée",
"start_btn": "▶ Start",
"stop_btn": "⏹ Stop",
"config_btn": "⚙️ Config",
"done": "Terminé",
"installing": "Installation...",
"start_install": "Début de l'installation...",
"start_install": "Début de l\u0027installation...",
"check_docker": "Vérification de Docker...",
"prepare_host": "Préparation de l'hôte...",
"prepare_host": "Préparation de l\u0027hôte...",
"build_container": "Construction du conteneur...",
"install_success": "Protocole installé avec succès !",
"install_error": "Erreur d'installation : ",
"install_error": "Erreur d\u0027installation : ",
"qr_error": "Échec de génération du QR code",
"users_title": "Utilisateurs",
"search_placeholder": "Recherche par nom, email ou Telegram...",
@@ -130,7 +143,7 @@
"loading_users": "Chargement des utilisateurs...",
"nothing_found": "Rien trouvé",
"search_empty_desc": "Essayez une autre requête ou créez un utilisateur",
"username_label": "Nom d'utilisateur",
"username_label": "Nom d\u0027utilisateur",
"password_label": "Mot de passe",
"role_label": "Rôle",
"role_user_desc": "User — voit ses propres connexions",
@@ -149,7 +162,7 @@
"edit_user_email": "Email (optionnel)",
"edit_user_limit": "Limite trafic (Go) (0 = illimité)",
"new_password_hint": "Nouveau mot de passe (laisser vide si inchangé)",
"op_type_label": "Type d'opération",
"op_type_label": "Type d\u0027opération",
"create_new_conn": "Créer nouvelle connexion",
"link_existing_conn": "Lier existante",
"select_existing_conn": "Sélectionner connexion",
@@ -164,18 +177,18 @@
"disabling": "Désactivation",
"user_enabled": "Utilisateur activé",
"user_disabled": "Utilisateur désactivé",
"delete_user_confirm": "Supprimer l'utilisateur ? Ses connexions seront supprimées.",
"share_access": "Partager l'accès",
"enable_public_access": "Activer l'accès public",
"delete_user_confirm": "Supprimer l\u0027utilisateur ? Ses connexions seront supprimées.",
"share_access": "Partager l\u0027accès",
"enable_public_access": "Activer l\u0027accès public",
"share_password_label": "Mot de passe (optionnel)",
"share_password_hint": "Si défini, requis pour l'accès",
"share_password_hint": "Si défini, requis pour l\u0027accès",
"guest_settings_title": "Accès invité",
"guest_enable": "Activer l'accès invité (sans inscription)",
"guest_enable_hint": "Lien public sur la page de connexion. Les invités voient les connexions de l'utilisateur choisi.",
"guest_enable": "Activer l\u0027accès invité (sans inscription)",
"guest_enable_hint": "Lien public sur la page de connexion. Les invités voient les connexions de l\u0027utilisateur choisi.",
"guest_link_label": "Lien invité",
"guest_link_placeholder": "Enregistrez pour générer le lien",
"guest_regen_token": "Régénérer le lien",
"guest_regen_confirm": "Régénérer le lien invité ? L'ancien ne fonctionnera plus.",
"guest_regen_confirm": "Régénérer le lien invité ? L\u0027ancien ne fonctionnera plus.",
"guest_token_updated": "Lien invité mis à jour",
"guest_user_label": "Utilisateur des connexions invitées",
"guest_user_none": "— Choisir —",
@@ -183,7 +196,7 @@
"guest_password_label": "Mot de passe invité (optionnel)",
"guest_password_keep": "Laisser vide pour conserver",
"guest_clear_password": "Retirer le mot de passe",
"guest_allow_create": "Autoriser la création d'une config",
"guest_allow_create": "Autoriser la création d\u0027une config",
"guest_access_btn": "Continuer en invité",
"guest_access_login_hint": "Sans compte",
"guest_title": "Accès invité",
@@ -194,15 +207,15 @@
"guest_not_found": "404 Introuvable",
"guest_not_found_desc": "Accès invité désactivé ou lien invalide.",
"wrong_guest_password": "Mauvais mot de passe",
"invites_title": "Liens d'invitation",
"invites_hint": "Créez des liens partageables. Le destinataire peut créer une config VPN — vous fixez le nombre d'utilisations.",
"invites_title": "Liens d\u0027invitation",
"invites_hint": "Créez des liens partageables. Le destinataire peut créer une config VPN — vous fixez le nombre d\u0027utilisations.",
"invites_empty": "Aucun lien",
"invites_empty_desc": "Créez un lien à partager — sans inscription.",
"invite_create": "Créer un lien",
"invite_edit": "Modifier le lien",
"invite_active": "Actif",
"invite_expired": "Expiré",
"invite_exhausted": "Plus d'utilisations",
"invite_exhausted": "Plus d\u0027utilisations",
"invite_uses": "Utilisations",
"invite_name_label": "Nom du lien",
"invite_max_uses_label": "Configs max",
@@ -213,13 +226,13 @@
"invite_password_label": "Mot de passe (optionnel)",
"invite_expires_label": "Expiration (optionnel)",
"invite_duration_label": "Durée du config (jours)",
"invite_duration_hint": "Commence quand l'utilisateur clique Obtenir. 0 = illimité.",
"invite_duration_hint": "Commence quand l\u0027utilisateur clique Obtenir. 0 = illimité.",
"invite_duration_short": "Durée",
"invite_duration_starts_hint": "Après obtention, valable {} jour(s)",
"invite_config_expires_at": "Valable jusqu'au : {}",
"invite_config_expires_at": "Valable jusqu\u0027au : {}",
"invite_sub_tab": "Abonnement",
"days_short": "j",
"invite_clear_expires": "Retirer l'expiration",
"invite_clear_expires": "Retirer l\u0027expiration",
"invite_note_label": "Note (admin)",
"invite_note_placeholder": "Commentaire interne",
"invite_reset_used": "Réinitialiser le compteur",
@@ -255,8 +268,15 @@
"bot_start_btn": "▶️ Démarrer",
"bot_hint": "Sauvegardez après modification du token. Le bot redémarrera.",
"api_docs_title": "🔌 Documentation API",
"api_docs_hint": "Utilisez ces interfaces pour explorer l'API",
"api_docs_hint": "Utilisez ces interfaces pour explorer l\u0027API",
"tunnels_title": "Tunnels",
"tunnels_subtitle": "Exposez le panneau sur Internet ou routez le trafic sortant via un VPN.",
"tunnels_section_inbound": "Accès public",
"tunnels_section_outbound": "VPN sortant",
"tunnel_cloudflare_desc": "URL HTTPS gratuite via Cloudflare — sans compte.",
"tunnel_ngrok_desc": "Tunnel stable avec votre authtoken ngrok.",
"tunnel_warp_desc": "Routez le trafic du serveur via Cloudflare WARP.",
"tunnel_nordvpn_desc": "Connectez cet hôte aux serveurs NordVPN.",
"local_server": "Serveur local",
"tunnel_install_enable": "Installer et activer",
"tunnel_enable": "Activer le tunnel",
@@ -269,8 +289,8 @@
"tunnel_delete_confirm": "Arrêter et supprimer ce binaire de tunnel géré par le panneau ?",
"tunnel_starting": "Démarrage du tunnel...",
"tunnel_started": "Tunnel démarré",
"tunnel_waiting_url": "Tunnel démarré. En attente de l'URL publique...",
"tunnel_no_public_url": "L'URL publique apparaîtra ici après le démarrage du tunnel.",
"tunnel_waiting_url": "Tunnel démarré. En attente de l\u0027URL publique...",
"tunnel_no_public_url": "L\u0027URL publique apparaîtra ici après le démarrage du tunnel.",
"tunnels_hint": "Les tunnels rapides exposent ce panneau local sur Internet. Gardez des identifiants administrateur robustes et partagez les URL publiques uniquement avec des utilisateurs de confiance.",
"ngrok_authtoken_placeholder": "ngrok authtoken (optionnel pour certains comptes)",
"import_users_title": "📤 Import Utilisateurs",
@@ -294,7 +314,7 @@
"deleting": "Suppression...",
"my_connections_title": "Mes Connexions",
"show_config": "📄 Voir config",
"no_connections_user_desc": "Contactez l'admin pour une connexion",
"no_connections_user_desc": "Contactez l\u0027admin pour une connexion",
"share_title": "Accès Connexion",
"vpn_access": "Accès VPN",
"user_label_share": "Utilisateur",
@@ -313,7 +333,7 @@
"invalid_captcha": "Captcha invalide",
"account_disabled": "Compte désactivé",
"invalid_login": "Login ou password incorrect",
"user_exists": "L'utilisateur existe déjà",
"user_exists": "L\u0027utilisateur existe déjà",
"cannot_delete_self": "Vous ne pouvez pas vous supprimer",
"wrong_share_password": "Mauvais mot de passe",
"saving": "Enregistrement...",
@@ -324,13 +344,15 @@
"lang_zh": "中文 (Chinese)",
"lang_fa": "فارسی (Persian)",
"backup_title": "Sauvegarde Simple",
"download_backup": "Télécharger data.json",
"restore_backup": "Restaurer depuis un fichier",
"restore_confirm": "Êtes-vous sûr ? Les données actuelles seront écrasées et l'application redémarrera.",
"download_backup": "Télécharger le dump PostgreSQL (.sql)",
"download_backup_json": "Exporter JSON (ancien)",
"backup_hint": "Dump complet de la base PostgreSQL du panneau. Utilisez .sql pour une sauvegarde complète ; JSON pour l'ancien format.",
"restore_backup": "Restaurer depuis .sql ou .json",
"restore_confirm": "La restauration écrasera toutes les données actuelles du panneau dans la base.",
"restore_success": "Restauration réussie ! Redémarrage...",
"invalid_backup_file": "Fichier de sauvegarde ou structure invalide",
"invalid_backup_file": "Fichier invalide (dump .sql ou ancien data.json)",
"config_unavailable": "Configuration indisponible",
"config_unavailable_desc": "Ce client a été créé via l'application native Amnezia.\\nLa clé privée est stockée uniquement sur l'appareil de l'utilisateur et ne peut pas être récupérée par le serveur.",
"config_unavailable_desc": "Ce client a été créé via l\u0027application native Amnezia.\\nLa clé privée est stockée uniquement sur l\u0027appareil de l\u0027utilisateur et ne peut pas être récupérée par le serveur.",
"client_public_key": "Clé publique du client :",
"management": "Gestion",
"server_management": "Gestion du serveur",
@@ -340,31 +362,39 @@
"clear_server": "Réinitialiser le serveur",
"remove_server": "Retirer le serveur du panneau",
"telemt_desc": "Proxy Telegram basé sur MTProxy avec obfuscation avancée.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) via l'image officielle tobyxdd/hysteria (apernet/hysteria) avec TLS Let's Encrypt. Le domaine est défini par l'admin à l'installation.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) via l\u0027image officielle tobyxdd/hysteria (apernet/hysteria) avec TLS Let\u0027s Encrypt. Le domaine est défini par l\u0027admin à l\u0027installation.",
"hysteria_domain": "Domaine",
"hysteria_email": "Email Let's Encrypt",
"hysteria_port_hint": "Port UDP pour Hysteria (8998 par défaut). Évitez 443 s'il est déjà pris.",
"hysteria_install_hint": "L'enregistrement A du domaine doit pointer vers ce serveur. BBR et obfuscation salamander sont activés automatiquement.",
"hysteria_dns_hint": "Créez cet enregistrement DNS avant l'installation :",
"hysteria_email": "Email Let\u0027s Encrypt",
"hysteria_port_hint": "Port UDP pour Hysteria (8998 par défaut). Évitez 443 s\u0027il est déjà pris.",
"hysteria_install_hint": "L\u0027enregistrement A du domaine doit pointer vers ce serveur. BBR et obfuscation salamander sont activés automatiquement.",
"hysteria_dns_hint": "Créez cet enregistrement DNS avant l\u0027installation :",
"hysteria_settings_title": "Paramètres Hysteria",
"hysteria_change_port": "Changer le port",
"hysteria_port_change_hint": "Port UDP. Si « address already in use », choisissez un port libre (8443 ou 8998).",
"hysteria_settings_saved": "Port Hysteria mis à jour",
"hysteria_ports_warning": "Attention : les ports TCP 80 et 443 doivent être libres pour un fonctionnement stable (Let's Encrypt sur 80, HTTPS/QUIC sur 443).",
"hysteria_ports_warning": "Attention : les ports TCP 80 et 443 doivent être libres pour un fonctionnement stable (Let\u0027s Encrypt sur 80, HTTPS/QUIC sur 443).",
"hysteria_renew_ssl": "Renouveler SSL",
"hysteria_ssl_change_hint": "Changer le domaine réémet le certificat Let's Encrypt (le port 80 doit être libre).",
"hysteria_ssl_change_hint": "Changer le domaine réémet le certificat Let\u0027s Encrypt (le port 80 doit être libre).",
"hysteria_ssl_required": "Domaine et email requis pour SSL",
"naiveproxy_desc": "NaiveProxy (stable) — HTTPS/HTTP2 via Caddy + forwardproxy, TLS Let's Encrypt. Client : utilisez Karing. N'utilisez pas v2rayN ; autres clients non testés.",
"naiveproxy_desc": "NaiveProxy (stable) — HTTPS/HTTP2 via Caddy + forwardproxy, TLS Let\u0027s Encrypt. Client : utilisez Karing. N\u0027utilisez pas v2rayN ; autres clients non testés.",
"naiveproxy_domain": "Domaine",
"naiveproxy_email": "Email Let's Encrypt",
"naiveproxy_port_hint": "Le port TCP 443 est fixe pour NaiveProxy. Le port 80/TCP doit être libre pour l'émission du certificat.",
"naiveproxy_install_hint": "L'enregistrement A du domaine doit pointer vers ce serveur. Les ports TCP 80 et 443 doivent être libres (Let's Encrypt et proxy HTTPS).",
"naiveproxy_dns_hint": "Créez cet enregistrement DNS avant l'installation :",
"naiveproxy_ports_warning": "Attention : les ports TCP 80 et 443 doivent être libres pour un fonctionnement stable (Let's Encrypt sur 80, proxy HTTPS sur 443).",
"naiveproxy_client_hint": "Version stable. N'utilisez PAS v2rayN. Fonctionne avec Karing. Autres clients non testés.",
"naiveproxy_email": "Email Let\u0027s Encrypt",
"naiveproxy_port_hint": "Le port TCP 443 est fixe pour NaiveProxy. Le port 80/TCP doit être libre pour l\u0027émission du certificat.",
"naiveproxy_install_hint": "L\u0027enregistrement A du domaine doit pointer vers ce serveur. Les ports TCP 80 et 443 doivent être libres (Let\u0027s Encrypt et proxy HTTPS).",
"naiveproxy_dns_hint": "Créez cet enregistrement DNS avant l\u0027installation :",
"naiveproxy_ports_warning": "Attention : les ports TCP 80 et 443 doivent être libres pour un fonctionnement stable (Let\u0027s Encrypt sur 80, proxy HTTPS sur 443).",
"naiveproxy_client_hint": "Version stable. N\u0027utilisez PAS v2rayN. Fonctionne avec Karing. Autres clients non testés.",
"mieru_desc": "Mieru (mita v3.28.0) — proxy TCP natif enfein/mieru. Pas besoin de Docker. Client : mieru ou Clash.Meta/mihomo.",
"mieru_version": "Version",
"mieru_port_hint": "Port TCP pour mita (102565535). Ouvrez-le dans le pare-feu du serveur.",
"mieru_install_hint": "Installe le paquet officiel mita depuis GitHub v3.28.0 (Debian/RPM). Linux avec systemd requis.",
"mieru_ports_warning": "Attention : le port TCP choisi doit être libre et autorisé dans le pare-feu.",
"mieru_client_hint": "Liens au format mierus://. Importez dans le client mieru ou Clash.Meta (type: mieru).",
"server_ssl_domain": "Domaine SSL (par défaut)",
"server_ssl_email": "Email SSL (par défaut)",
"server_ssl_hint": "Utilisé lors de l'installation de Hysteria / NGINX sur ce serveur (Let's Encrypt).",
"server_ssl_hint": "Utilisé lors de l\u0027installation de Hysteria / NGINX sur ce serveur (Let\u0027s Encrypt).",
"server_connect_domain": "Domaine de connexion client",
"server_connect_domain_hint": "Utilisé dans les configs VPN à la place de l\u0027IP. Lors d\u0027un déplacement du serveur, mettez à jour l\u0027enregistrement DNS A.",
"container_logs": "Logs du conteneur",
"logs_btn": "📋 Logs",
"logs_live": "Temps réel",
@@ -409,7 +439,7 @@
"ping_checking": "Checking connectivity...",
"offline": "offline",
"api_tokens_title": "API tokens",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer <token>` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer \u003ctoken\u003e` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_empty": "No API tokens yet. Create one to integrate the panel with an external service.",
"api_tokens_create": "Create token",
"api_tokens_create_title": "Create API token",
@@ -419,8 +449,8 @@
"api_tokens_name_required": "Token name is required",
"api_tokens_created_title": "Token created",
"api_tokens_value_label": "Token value",
"api_tokens_warning_title": "This is the only time you'll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration's secret manager. The panel keeps only a hash — if you lose this value you'll need to revoke and recreate the token.",
"api_tokens_warning_title": "This is the only time you\u0027ll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration\u0027s secret manager. The panel keeps only a hash — if you lose this value you\u0027ll need to revoke and recreate the token.",
"api_tokens_revoke": "Revoke",
"api_tokens_revoke_confirm": "Revoke token \"{}\"? Any integration using it will stop working.",
"api_tokens_revoked": "Token revoked",
@@ -448,6 +478,23 @@
"warp_status_not_registered": "Cloudflare WARP is installed but not registered yet. Connect will try to register automatically.",
"warp_status_service_unavailable": "Cloudflare WARP service is not available. Make sure warp-svc is running.",
"warp_status_error": "Cloudflare WARP returned an error.",
"nordvpn_hint": "NordVPN routes this host outbound through NordVPN servers. It does not create a public panel URL like Quick Tunnel or ngrok. Run nordvpn login on the host once before connecting.",
"nordvpn_install_hint": "Install the official NordVPN client/CLI on this host, run nordvpn login, then restart the panel.",
"nordvpn_install_required": "Install NordVPN first",
"nordvpn_connect": "Connect NordVPN",
"nordvpn_disconnect": "Disconnect",
"nordvpn_connected": "NordVPN connected",
"nordvpn_disconnected": "NordVPN disconnected",
"nordvpn_status_unknown": "NordVPN status is unknown.",
"nordvpn_status_not_installed": "NordVPN CLI is not installed on this host.",
"nordvpn_status_connected": "NordVPN is connected.",
"nordvpn_status_connecting": "NordVPN is connecting.",
"nordvpn_status_disconnected": "NordVPN is disconnected.",
"nordvpn_status_not_logged_in": "NordVPN is installed but not logged in. Run nordvpn login on this host.",
"nordvpn_status_service_unavailable": "NordVPN daemon is not available. Make sure nordvpnd is running.",
"nordvpn_status_error": "NordVPN returned an error.",
"nordvpn_country_placeholder": "Country (optional, e.g. Germany or de)",
"nordvpn_city_placeholder": "City (optional, e.g. Berlin)",
"install_starting": "Starting installation...",
"server_check_complete": "Check completed",
"server_connection_error": "Connection error",
@@ -470,10 +517,10 @@
"new_instance": "new instance",
"port_next_instance_hint": "Choose a free UDP port for the additional instance.",
"web_servers": "Serveurs web",
"nginx_desc": "Serveur web NGINX avec certificat HTTPS Let's Encrypt et index.html modifiable.",
"nginx_desc": "Serveur web NGINX avec certificat HTTPS Let\u0027s Encrypt et index.html modifiable.",
"nginx_domain": "Domaine",
"nginx_email": "Email Let's Encrypt",
"nginx_port_hint": "Port HTTPS exposé sur le serveur. Le port 80/TCP doit être libre et accessible pour la validation Let's Encrypt.",
"nginx_email": "Email Let\u0027s Encrypt",
"nginx_port_hint": "Port HTTPS exposé sur le serveur. Le port 80/TCP doit être libre et accessible pour la validation Let\u0027s Encrypt.",
"nginx_install_hint": "Le domaine doit déjà pointer vers ce serveur. Le port 80/TCP est utilisé pour la validation HTTP-01 du certificat.",
"site": "Site",
"site_editor": "Éditeur du site",
@@ -488,17 +535,17 @@
"no_backups": "No backups yet",
"no_backups_desc": "Create the first backup for this protocol.",
"refresh": "Refresh",
"guest_allow_create_hint": "Crée une config pour l'utilisateur invité (3x-ui VLESS ou protocole serveur).",
"invite_inbound_hint": "Choisissez l'inbound VLESS une fois",
"guest_allow_create_hint": "Crée une config pour l\u0027utilisateur invité (3x-ui VLESS ou protocole serveur).",
"invite_inbound_hint": "Choisissez l\u0027inbound VLESS une fois",
"invite_inbound_loading": "Chargement…",
"invite_inbound_empty": "Aucun inbound VLESS",
"invite_inbound_need_xui": "Configurez 3x-ui d'abord",
"invite_inbound_need_xui": "Configurez 3x-ui d\u0027abord",
"invite_inbound_required": "Sélectionnez un inbound VLESS",
"invite_sub_url_missing_title": "URL d'abonnement manquante",
"invite_sub_url_missing_hint": "Dans Paramètres → 3x-ui, définissez l'URL de base /sub.",
"invite_sub_url_missing_title": "URL d\u0027abonnement manquante",
"invite_sub_url_missing_hint": "Dans Paramètres → 3x-ui, définissez l\u0027URL de base /sub.",
"xui_url_label": "URL 3x-ui",
"xui_url_hint": "Inclure le schéma, le port et webBasePath si configuré",
"xui_sub_url_label": "URL de base d'abonnement",
"xui_sub_url_label": "URL de base d\u0027abonnement",
"xui_sub_url_hint": "Base /sub publique sans slash final (ex: https://host:2096/sub).",
"xui_api_token_label": "Jeton API (préféré)",
"xui_api_token_placeholder": "Settings → Security → API Token",
@@ -508,15 +555,38 @@
"xui_sync_hint": "Les clients 3x-ui deviennent des utilisateurs du panneau (liés par email)",
"xui_inbound_label": "Inbound VLESS",
"xui_inbound_auto": "Auto (premier inbound VLESS)",
"xui_inbound_hint": "Utilisé pour créer des configs 3x-ui VLESS. Créez d'abord un inbound VLESS dans 3x-ui.",
"xui_inbound_hint": "Utilisé pour créer des configs 3x-ui VLESS. Créez d\u0027abord un inbound VLESS dans 3x-ui.",
"xui_servers_title": "Serveurs 3x-ui",
"xui_servers_hint": "Ajoutez plusieurs panneaux 3x-ui. À la création, choisissez le serveur par nom — son URL d'abonnement est utilisée.",
"xui_servers_hint": "Ajoutez plusieurs panneaux 3x-ui. À la création, choisissez le serveur par nom — son URL d\u0027abonnement est utilisée.",
"xui_servers_empty": "Aucun serveur 3x-ui. Cliquez sur Ajouter.",
"xui_servers_manage_hint": "Les URL et bases d'abonnement se gèrent dans la section « Serveurs 3x-ui » ci-dessous.",
"xui_servers_manage_hint": "Les URL et bases d\u0027abonnement se gèrent dans la section « Serveurs 3x-ui » ci-dessous.",
"xui_server_add": "Ajouter un serveur",
"xui_server_name_label": "Nom / description",
"xui_server_name_hint": "Affiché dans les invitations (ex: US, NL).",
"xui_server_select_label": "Serveur 3x-ui",
"xui_server_select_hint": "Choisissez le panneau 3x-ui qui émettra l'URL d'abonnement.",
"xui_server_select_hint": "Choisissez le panneau 3x-ui qui émettra l\u0027URL d\u0027abonnement.",
"xui_server_delete_confirm": "Supprimer ce serveur 3x-ui ?"
,
"about_title": "About & Updates",
"current_version": "Current version",
"check_updates": "Check for updates",
"checking_updates": "Checking...",
"update_available": "New version available",
"download_update": "Download update",
"up_to_date": "You have the latest version",
"apply_update": "Install update",
"applying_update": "Updating…",
"apply_update_confirm": "Install update from git.evilfox.cc and restart the panel?",
"update_restarting": "Updated. Restarting panel…",
"update_no_target": "No target version. Check for updates first.",
"auto_update_hint": "Auto-update pulls the release tag from git.evilfox.cc (git checkout required).",
"auto_update_ready": "Git auto-update is available for this install.",
"auto_update_docker": "Docker install: rebuild/pull image, or use a git checkout for one-click update.",
"auto_update_manual": "One-click update needs a git clone. You can still download a release.",
"auto_update_archive": "One-click update downloads the release ZIP from git.evilfox.cc and restarts the panel.",
"upgrade_panel": "Update panel",
"upgrade_panel_confirm": "Download and install",
"upgrade_panel_confirm_latest": "Check for updates and install the latest release?",
"upgrade_panel_working": "Updating panel…",
"upgrade_panel_up_to_date": "Already on the latest version"
}
+103 -17
View File
@@ -4,6 +4,7 @@
"nav_invites": "Ссылки",
"nav_settings": "Настройки",
"nav_connections": "Подключения",
"nav_support": "Поддержать",
"nav_logout": "Выход",
"theme_dark": "Темная",
"theme_light": "Светлая",
@@ -101,6 +102,19 @@
"connection_created": "Подключение \"{}\" создано",
"delete_connection_confirm": "Удалить это подключение? Конфигурация перестанет работать.",
"connection_deleted": "Подключение удалено",
"select_all": "Выбрать все",
"connections_selected_count": "Выбрано: {}",
"move_connections": "Перенести",
"move_connections_title": "Перенос подключений на другой сервер",
"move_connections_target": "Целевой сервер",
"move_connections_confirm": "Перенести {} подключение(й) на выбранный сервер? Пользователям понадобятся новые конфиги.",
"move_connections_hint": "Подключения будут созданы заново на целевом сервере, привязки к пользователям сохранятся.",
"move_connections_warning": "У клиентов будут новые ключи и IP. Старые конфиги перестанут работать.",
"move_connections_delete_source": "Удалить с текущего сервера после переноса",
"move_connections_success": "Перенесено подключений: {}",
"move_connections_partial_fail": "Не удалось перенести: {}",
"move_connections_none_selected": "Выберите хотя бы одно подключение",
"move_connections_no_targets": "Нет других серверов для переноса",
"config_tab": "📄 Конфиг",
"vpn_key_tab": "🔑 VPN-ключ",
"qr_code_tab": "📱 QR-код",
@@ -267,6 +281,13 @@
"api_docs_title": "🔌 API Документация",
"api_docs_hint": "Используйте эти интерфейсы для изучения возможностей API панели",
"tunnels_title": "Туннели",
"tunnels_subtitle": "Публикация панели в интернете или исходящий трафик через VPN.",
"tunnels_section_inbound": "Публичный доступ",
"tunnels_section_outbound": "Исходящий VPN",
"tunnel_cloudflare_desc": "Бесплатный HTTPS-адрес через Cloudflare — без регистрации.",
"tunnel_ngrok_desc": "Стабильный туннель с вашим authtoken ngrok.",
"tunnel_warp_desc": "Маршрутизация трафика сервера через Cloudflare WARP.",
"tunnel_nordvpn_desc": "Подключение хоста к серверам NordVPN.",
"local_server": "Локальный сервер",
"tunnel_install_enable": "Установить и включить",
"tunnel_enable": "Включить туннель",
@@ -341,40 +362,71 @@
"lang_zh": "中文 (Chinese)",
"lang_fa": "فارسی (Persian)",
"backup_title": "Резервное копирование",
"download_backup": "Скачать data.json",
"restore_backup": "Восстановить из файла",
"restore_confirm": "Вы уверены? Текущие данные будут перезаписаны, и приложение перезагрузится.",
"download_backup": "Скачать дамп PostgreSQL (.sql)",
"download_backup_json": "Экспорт JSON (устар.)",
"backup_hint": "Полный дамп базы данных панели. Для бэкапа используйте .sql; JSON — для совместимости со старыми версиями.",
"restore_backup": "Восстановить из .sql или .json",
"restore_confirm": "Восстановление перезапишет все текущие данные панели в базе.",
"restore_success": "Восстановление успешно! Перезагрузка...",
"invalid_backup_file": "Неверный файл резервной копии или структура",
"invalid_backup_file": "Неверный файл (.sql дамп или устаревший data.json)",
"config_unavailable": "Конфигурация недоступна",
"config_unavailable_desc": "Этот клиент был создан через нативное приложение Amnezia.\\nПриватный ключ хранится только на устройстве пользователя и не может быть восстановлен сервером.",
"client_public_key": "Публичный ключ клиента:",
"telemt_desc": "Прокси для Telegram на базе MTProxy с продвинутой обфускацией и эмуляцией TLS.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) на официальном образе tobyxdd/hysteria (apernet/hysteria) с TLS от Let's Encrypt. Домен указывает админ при установке.",
"hysteria_desc": "Hysteria 2 (QUIC/UDP) на официальном образе tobyxdd/hysteria (apernet/hysteria) с TLS от Let\u0027s Encrypt. Домен указывает админ при установке.",
"hysteria_domain": "Домен",
"hysteria_email": "Email для Let's Encrypt",
"hysteria_email": "Email для Let\u0027s Encrypt",
"hysteria_port_hint": "UDP-порт Hysteria (по умолчанию 8998). Не ставьте 443, если он уже занят nginx/xray. Порт 80/TCP должен быть свободен для выпуска сертификата.",
"hysteria_install_hint": "Перед установкой A-запись домена должна указывать на этот сервер. Порт 80/TCP временно используется для HTTP-01 проверки Let's Encrypt. BBR и obfuscation salamander включаются автоматически.",
"hysteria_install_hint": "Перед установкой A-запись домена должна указывать на этот сервер. Порт 80/TCP временно используется для HTTP-01 проверки Let\u0027s Encrypt. BBR и obfuscation salamander включаются автоматически.",
"hysteria_dns_hint": "Перед установкой создайте DNS-запись:",
"hysteria_settings_title": "Настройки Hysteria",
"hysteria_change_port": "Сменить порт",
"hysteria_port_change_hint": "UDP-порт прослушивания. Если ошибка «address already in use» — выберите свободный порт (8443 или 8998), сохраните и заново импортируйте ссылку в клиент.",
"hysteria_settings_saved": "Настройки Hysteria обновлены",
"hysteria_ports_warning": "Внимание: для стабильной работы нужны свободные TCP-порты 80 и 443 (Let's Encrypt на 80, HTTPS/QUIC на 443).",
"hysteria_ports_warning": "Внимание: для стабильной работы нужны свободные TCP-порты 80 и 443 (Let\u0027s Encrypt на 80, HTTPS/QUIC на 443).",
"hysteria_renew_ssl": "Обновить SSL",
"hysteria_ssl_change_hint": "Смена домена заново выпускает сертификат Let's Encrypt (порт 80 должен быть свободен).",
"hysteria_ssl_change_hint": "Смена домена заново выпускает сертификат Let\u0027s Encrypt (порт 80 должен быть свободен).",
"hysteria_ssl_required": "Для SSL нужны домен и email",
"naiveproxy_desc": "NaiveProxy (стабильный) — HTTPS/HTTP2 через Caddy + forwardproxy, TLS Let's Encrypt. Клиент: используйте Karing. Не используйте v2rayN; остальные клиенты под вопросом.",
"naiveproxy_desc": "NaiveProxy (стабильный) — HTTPS/HTTP2 через Caddy + forwardproxy, TLS Let\u0027s Encrypt. Клиент: используйте Karing. Не используйте v2rayN; остальные клиенты под вопросом.",
"naiveproxy_domain": "Домен",
"naiveproxy_email": "Email для Let's Encrypt",
"naiveproxy_email": "Email для Let\u0027s Encrypt",
"naiveproxy_port_hint": "TCP-порт 443 фиксирован для NaiveProxy. Порт 80/TCP должен быть свободен для выпуска сертификата.",
"naiveproxy_install_hint": "Перед установкой A-запись домена должна указывать на этот сервер. Нужны свободные TCP-порты 80 и 443 (Let's Encrypt и HTTPS-прокси).",
"naiveproxy_install_hint": "Перед установкой A-запись домена должна указывать на этот сервер. Нужны свободные TCP-порты 80 и 443 (Let\u0027s Encrypt и HTTPS-прокси).",
"naiveproxy_dns_hint": "Перед установкой создайте DNS-запись:",
"naiveproxy_ports_warning": "Внимание: для стабильной работы нужны свободные TCP-порты 80 и 443 (Let's Encrypt на 80, HTTPS-прокси на 443).",
"naiveproxy_ports_warning": "Внимание: для стабильной работы нужны свободные TCP-порты 80 и 443 (Let\u0027s Encrypt на 80, HTTPS-прокси на 443).",
"naiveproxy_client_hint": "Стабильная версия. НЕ используйте v2rayN. Точно работает в Karing. Остальные клиенты под вопросом.",
"mieru_desc": "Mieru (mita v3.28.0) — нативный TCP-прокси из enfein/mieru. Docker не нужен. Клиент: приложение mieru или Clash.Meta/mihomo.",
"mieru_version": "Версия",
"mieru_port_hint": "TCP-порт для mita (1025–65535). Откройте его в фаерволе сервера.",
"mieru_install_hint": "Устанавливает официальный пакет mita с GitHub релиза v3.28.0 (Debian/RPM). Нужен Linux со systemd.",
"mieru_ports_warning": "Внимание: выбранный TCP-порт должен быть свободен и разрешён в фаерволе.",
"mieru_client_hint": "Ссылки в формате mierus://. Импорт в клиент mieru или Clash.Meta (type: mieru).",
"server_ssl_domain": "SSL-домен (по умолчанию)",
"server_ssl_email": "SSL-email (по умолчанию)",
"server_ssl_hint": "Подставляется при установке Hysteria / NGINX на этом сервере (Let's Encrypt).",
"server_connect_domain": "Домен для подключения клиентов",
"server_connect_domain_hint": "Подставляется в конфиги VPN вместо IP (Endpoint, vless:// и т.д.). При переносе сервера достаточно обновить A-запись DNS — клиенты продолжат работать.",
"server_connect_domain_awg_hint": "Подставляется в Endpoint конфигов AmneziaWG / WireGuard вместо IP сервера. Пусто — использовать IP из SSH.",
"server_connect_domain_all": "Все AWG / WireGuard (по умолчанию)",
"server_connect_domain_current": "Endpoint в конфигах",
"server_connect_domain_ssh": "SSH",
"server_connect_domain_saved": "Домен подключения сохранён",
"server_endpoint_label": "Endpoint",
"support_title": "Поддержать проект",
"support_intro": "Если панель вам помогает, можно поддержать разработку. Выберите удобный способ ниже.",
"support_footer": "Спасибо, что пользуетесь Amnezia Web Panel.",
"donate_sbp": "СБП",
"donate_card": "Банковская карта",
"donate_crypto": "Криптовалюта",
"donate_details_soon": "Реквизиты будут добавлены позже.",
"donate_settings_title": "Поддержка / донат",
"donate_settings_hint": "Страница /support для всех пользователей. Без всплывающих окон — только по ссылке в меню.",
"donate_enabled": "Показывать страницу поддержки в меню",
"donate_intro": "Текст в начале страницы (необязательно)",
"donate_method_title": "Название кнопки (необязательно)",
"donate_method_details": "Реквизиты",
"donate_details_placeholder": "Телефон, номер карты, адрес кошелька…",
"donate_preview_hint": "Предпросмотр:",
"container_logs": "Логи контейнера",
"logs_btn": "📋 Логи",
"logs_live": "В реальном времени",
@@ -433,7 +485,7 @@
"ping_checking": "Проверяем соединение...",
"offline": "недоступен",
"api_tokens_title": "API-токены",
"api_tokens_hint": "Bearer-токены для внешних интеграций. Передавайте токен в заголовке `Authorization: Bearer <token>`. Токены имеют права администратора и перестают работать, если их владелец отключён или понижен в роли.",
"api_tokens_hint": "Bearer-токены для внешних интеграций. Передавайте токен в заголовке `Authorization: Bearer \u003ctoken\u003e`. Токены имеют права администратора и перестают работать, если их владелец отключён или понижен в роли.",
"api_tokens_empty": "Пока нет ни одного API-токена. Создайте, чтобы подключить панель к внешнему сервису.",
"api_tokens_create": "Создать токен",
"api_tokens_create_title": "Создание API-токена",
@@ -481,6 +533,23 @@
"update_available": "Доступна новая версия",
"download_update": "Скачать обновление",
"up_to_date": "У вас установлена последняя версия",
"apply_update": "Установить обновление",
"applying_update": "Обновление…",
"apply_update_confirm": "Установить обновление с git.evilfox.cc и перезапустить панель?",
"update_restarting": "Обновлено. Перезапуск панели…",
"update_waiting_restart": "Ожидание перезапуска панели…",
"update_restart_timeout": "Панель не ответила вовремя. Обновите страницу вручную.",
"update_no_target": "Нет целевой версии. Сначала проверьте обновления.",
"auto_update_hint": "Автообновление тянет тег релиза с git.evilfox.cc (нужен git clone панели).",
"auto_update_ready": "Для этой установки доступно автообновление через git.",
"auto_update_docker": "Docker: обновление в один клик скачивает ZIP релиза в контейнер. Пересоберите образ, чтобы сохранить изменения при пересоздании контейнера.",
"auto_update_manual": "Обновление в один клик требует git clone или каталог с правами записи. Можно скачать релиз вручную.",
"auto_update_archive": "Обновление в один клик: скачивает ZIP релиза с git.evilfox.cc и перезапускает панель.",
"upgrade_panel": "Обновить панель",
"upgrade_panel_confirm": "Скачать и установить",
"upgrade_panel_confirm_latest": "Проверить обновления и установить последний релиз?",
"upgrade_panel_working": "Обновление панели…",
"upgrade_panel_up_to_date": "Уже установлена последняя версия",
"warp_hint": "WARP направляет исходящий трафик этого хоста через Cloudflare. Он не создаёт публичный URL панели как Quick Tunnel или ngrok.",
"warp_install_hint": "Сначала установите официальный клиент Cloudflare WARP, затем перезапустите панель.",
"warp_install_required": "Сначала установите WARP",
@@ -496,6 +565,23 @@
"warp_status_not_registered": "Cloudflare WARP установлен, но ещё не зарегистрирован. Подключение попробует зарегистрировать его автоматически.",
"warp_status_service_unavailable": "Сервис Cloudflare WARP недоступен. Убедитесь, что warp-svc запущен.",
"warp_status_error": "Cloudflare WARP вернул ошибку.",
"nordvpn_hint": "NordVPN направляет исходящий трафик этого хоста через серверы NordVPN. Не создаёт публичный URL панели как Quick Tunnel или ngrok. Перед подключением один раз выполните nordvpn login на хосте.",
"nordvpn_install_hint": "Установите официальный клиент/CLI NordVPN на этом хосте, выполните nordvpn login и перезапустите панель.",
"nordvpn_install_required": "Сначала установите NordVPN",
"nordvpn_connect": "Подключить NordVPN",
"nordvpn_disconnect": "Отключить",
"nordvpn_connected": "NordVPN подключён",
"nordvpn_disconnected": "NordVPN отключён",
"nordvpn_status_unknown": "Статус NordVPN неизвестен.",
"nordvpn_status_not_installed": "CLI NordVPN не установлен на этом хосте.",
"nordvpn_status_connected": "NordVPN подключён.",
"nordvpn_status_connecting": "NordVPN подключается.",
"nordvpn_status_disconnected": "NordVPN отключён.",
"nordvpn_status_not_logged_in": "NordVPN установлен, но не выполнен вход. Запустите nordvpn login на хосте.",
"nordvpn_status_service_unavailable": "Демон NordVPN недоступен. Убедитесь, что nordvpnd запущен.",
"nordvpn_status_error": "NordVPN вернул ошибку.",
"nordvpn_country_placeholder": "Страна (необяз., напр. Germany или de)",
"nordvpn_city_placeholder": "Город (необяз., напр. Berlin)",
"install_starting": "Начинаем установку...",
"server_check_complete": "Проверка завершена",
"server_connection_error": "Ошибка подключения",
@@ -519,10 +605,10 @@
"port_next_instance_hint": "Выберите свободный UDP-порт для дополнительного экземпляра.",
"checking_server": "Проверяем сервисы сервера...",
"web_servers": "Веб-серверы",
"nginx_desc": "NGINX веб-сервер с HTTPS-сертификатом Let's Encrypt и редактируемым index.html.",
"nginx_desc": "NGINX веб-сервер с HTTPS-сертификатом Let\u0027s Encrypt и редактируемым index.html.",
"nginx_domain": "Домен",
"nginx_email": "Email для Let's Encrypt",
"nginx_port_hint": "HTTPS-порт на сервере. Порт 80/TCP должен быть свободен и доступен для проверки Let's Encrypt.",
"nginx_email": "Email для Let\u0027s Encrypt",
"nginx_port_hint": "HTTPS-порт на сервере. Порт 80/TCP должен быть свободен и доступен для проверки Let\u0027s Encrypt.",
"nginx_install_hint": "Домен уже должен указывать на этот сервер. Порт 80/TCP используется для HTTP-01 проверки сертификата.",
"site": "Сайт",
"site_editor": "Редактор сайта",
+89 -19
View File
@@ -100,6 +100,19 @@
"connection_created": "连接 \"{}\" 已创建",
"delete_connection_confirm": "确定删除此连接?配置将失效。",
"connection_deleted": "连接已删除",
"select_all": "全选",
"connections_selected_count": "已选 {}",
"move_connections": "迁移",
"move_connections_title": "将连接迁移到另一台服务器",
"move_connections_target": "目标服务器",
"move_connections_confirm": "将 {} 个连接迁移到所选服务器?用户需要新的配置。",
"move_connections_hint": "在目标服务器上重新创建所选连接,并保留用户绑定。",
"move_connections_warning": "客户端将获得新密钥和 IP,旧配置将失效。",
"move_connections_delete_source": "迁移后从当前服务器删除",
"move_connections_success": "已迁移 {} 个连接",
"move_connections_partial_fail": "{} 个无法迁移",
"move_connections_none_selected": "请至少选择一个连接",
"move_connections_no_targets": "没有其他可用服务器",
"config_tab": "📄 配置文件",
"vpn_key_tab": "🔑 VPN 密钥",
"qr_code_tab": "📱 二维码",
@@ -257,6 +270,13 @@
"api_docs_title": "🔌 API 文档",
"api_docs_hint": "使用这些接口了解面板功能",
"tunnels_title": "Tunnels",
"tunnels_subtitle": "将面板暴露到互联网,或通过 VPN 路由出站流量。",
"tunnels_section_inbound": "公网访问",
"tunnels_section_outbound": "出站 VPN",
"tunnel_cloudflare_desc": "通过 Cloudflare 获取免费 HTTPS 地址,无需注册。",
"tunnel_ngrok_desc": "使用 ngrok authtoken 的稳定隧道。",
"tunnel_warp_desc": "通过 Cloudflare WARP 路由服务器流量。",
"tunnel_nordvpn_desc": "将此主机连接到 NordVPN 服务器。",
"local_server": "本地服务器",
"tunnel_install_enable": "安装并启用",
"tunnel_enable": "启用隧道",
@@ -324,11 +344,13 @@
"lang_zh": "中文 (Chinese)",
"lang_fa": "فارسی (Persian)",
"backup_title": "简易备份",
"download_backup": "下载 data.json",
"restore_backup": "从文件恢复",
"restore_confirm": "您确定吗?当前数据将被覆盖,应用程序将重新启动。",
"download_backup": "下载 PostgreSQL 转储 (.sql)",
"download_backup_json": "导出 JSON(旧版)",
"backup_hint": "面板 PostgreSQL 数据库的完整转储。请使用 .sql 进行完整备份;JSON 用于兼容旧版本。",
"restore_backup": "从 .sql 或 .json 恢复",
"restore_confirm": "恢复将覆盖数据库中所有当前面板数据。",
"restore_success": "恢复成功!正在重启...",
"invalid_backup_file": "备份文件无效或结构错误",
"invalid_backup_file": "无效的备份文件.sql 转储或旧版 data.json",
"config_unavailable": "配置文件不可用",
"config_unavailable_desc": "此客户端是通过 Amnezia 原生应用创建的。\\n私钥仅存储在用户设备上,服务器无法恢复。",
"client_public_key": "客户端公钥:",
@@ -340,9 +362,9 @@
"clear_server": "清除服务器",
"remove_server": "从面板移除服务器",
"telemt_desc": "基于 MTProxy 的 Telegram 代理,支持高级混淆。",
"hysteria_desc": "Hysteria 2QUIC/UDP,官方 tobyxdd/hysteria / apernet/hysteria),支持 Let's Encrypt TLS。安装时由管理员指定域名。",
"hysteria_desc": "Hysteria 2QUIC/UDP,官方 tobyxdd/hysteria / apernet/hysteria),支持 Let\u0027s Encrypt TLS。安装时由管理员指定域名。",
"hysteria_domain": "域名",
"hysteria_email": "Let's Encrypt 邮箱",
"hysteria_email": "Let\u0027s Encrypt 邮箱",
"hysteria_port_hint": "Hysteria UDP 端口(默认 8998)。若 443 已被占用请换端口。",
"hysteria_install_hint": "安装前请将域名 A 记录指向本服务器。将自动启用 BBR 与 salamander 混淆。",
"hysteria_dns_hint": "安装前请创建此 DNS 记录:",
@@ -350,21 +372,29 @@
"hysteria_change_port": "更改端口",
"hysteria_port_change_hint": "UDP 监听端口。若提示 address already in use,请改用空闲端口(如 8443 或 8998)。",
"hysteria_settings_saved": "Hysteria 端口已更新",
"hysteria_ports_warning": "注意:稳定运行需要空闲的 TCP 端口 80 和 443Let's Encrypt 使用 80HTTPS/QUIC 使用 443)。",
"hysteria_ports_warning": "注意:稳定运行需要空闲的 TCP 端口 80 和 443Let\u0027s Encrypt 使用 80HTTPS/QUIC 使用 443)。",
"hysteria_renew_ssl": "续签 SSL",
"hysteria_ssl_change_hint": "更改域名会重新签发 Let's Encrypt 证书(需空闲端口 80)。",
"hysteria_ssl_change_hint": "更改域名会重新签发 Let\u0027s Encrypt 证书(需空闲端口 80)。",
"hysteria_ssl_required": "签发 SSL 需要域名和邮箱",
"naiveproxy_desc": "NaiveProxy(稳定)— Caddy + forwardproxy 的 HTTPS/HTTP2Let's Encrypt TLS。客户端请用 Karing,不要用 v2rayN;其他客户端未测试。",
"naiveproxy_desc": "NaiveProxy(稳定)— Caddy + forwardproxy 的 HTTPS/HTTP2Let\u0027s Encrypt TLS。客户端请用 Karing,不要用 v2rayN;其他客户端未测试。",
"naiveproxy_domain": "域名",
"naiveproxy_email": "Let's Encrypt 邮箱",
"naiveproxy_email": "Let\u0027s Encrypt 邮箱",
"naiveproxy_port_hint": "NaiveProxy 固定使用 TCP 443。签发证书需空闲 TCP 80。",
"naiveproxy_install_hint": "安装前请将域名 A 记录指向本服务器。需空闲 TCP 端口 80 和 443Let's Encrypt 与 HTTPS 代理)。",
"naiveproxy_install_hint": "安装前请将域名 A 记录指向本服务器。需空闲 TCP 端口 80 和 443Let\u0027s Encrypt 与 HTTPS 代理)。",
"naiveproxy_dns_hint": "安装前请创建此 DNS 记录:",
"naiveproxy_ports_warning": "注意:稳定运行需要空闲的 TCP 端口 80 和 443Let's Encrypt 使用 80HTTPS 代理使用 443)。",
"naiveproxy_ports_warning": "注意:稳定运行需要空闲的 TCP 端口 80 和 443Let\u0027s Encrypt 使用 80HTTPS 代理使用 443)。",
"naiveproxy_client_hint": "稳定版。请勿使用 v2rayN。已确认 Karing 可用。其他客户端未测试。",
"mieru_desc": "Mierumita v3.28.0)— enfein/mieru 原生 TCP 代理,无需 Docker。客户端:mieru 或 Clash.Meta/mihomo。",
"mieru_version": "版本",
"mieru_port_hint": "mita 的 TCP 端口(1025–65535)。请在服务器防火墙中放行。",
"mieru_install_hint": "从 GitHub v3.28.0 安装官方 mita 包(Debian/RPM)。需要带 systemd 的 Linux。",
"mieru_ports_warning": "注意:所选 TCP 端口必须空闲,并在防火墙中允许。",
"mieru_client_hint": "分享链接为 mierus:// 格式。可导入 mieru 客户端或 Clash.Metatype: mieru)。",
"server_ssl_domain": "SSL 域名(默认)",
"server_ssl_email": "SSL 邮箱(默认)",
"server_ssl_hint": "安装 Hysteria / NGINX 时自动填入(Let's Encrypt)。",
"server_ssl_hint": "安装 Hysteria / NGINX 时自动填入(Let\u0027s Encrypt)。",
"server_connect_domain": "客户端连接域名",
"server_connect_domain_hint": "在 VPN 配置中替代 IP 使用。迁移服务器时只需更新 DNS A 记录。",
"container_logs": "容器日志",
"logs_btn": "📋 日志",
"logs_live": "实时",
@@ -409,7 +439,7 @@
"ping_checking": "Checking connectivity...",
"offline": "offline",
"api_tokens_title": "API tokens",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer <token>` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_hint": "Bearer tokens for external integrations. Send the token in the `Authorization: Bearer \u003ctoken\u003e` header. Tokens have admin-equivalent rights and stop working if their owner is disabled or demoted.",
"api_tokens_empty": "No API tokens yet. Create one to integrate the panel with an external service.",
"api_tokens_create": "Create token",
"api_tokens_create_title": "Create API token",
@@ -419,8 +449,8 @@
"api_tokens_name_required": "Token name is required",
"api_tokens_created_title": "Token created",
"api_tokens_value_label": "Token value",
"api_tokens_warning_title": "This is the only time you'll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration's secret manager. The panel keeps only a hash — if you lose this value you'll need to revoke and recreate the token.",
"api_tokens_warning_title": "This is the only time you\u0027ll see this token.",
"api_tokens_warning_body": "Copy it now and store it in your integration\u0027s secret manager. The panel keeps only a hash — if you lose this value you\u0027ll need to revoke and recreate the token.",
"api_tokens_revoke": "Revoke",
"api_tokens_revoke_confirm": "Revoke token \"{}\"? Any integration using it will stop working.",
"api_tokens_revoked": "Token revoked",
@@ -448,6 +478,23 @@
"warp_status_not_registered": "Cloudflare WARP is installed but not registered yet. Connect will try to register automatically.",
"warp_status_service_unavailable": "Cloudflare WARP service is not available. Make sure warp-svc is running.",
"warp_status_error": "Cloudflare WARP returned an error.",
"nordvpn_hint": "NordVPN routes this host outbound through NordVPN servers. It does not create a public panel URL like Quick Tunnel or ngrok. Run nordvpn login on the host once before connecting.",
"nordvpn_install_hint": "Install the official NordVPN client/CLI on this host, run nordvpn login, then restart the panel.",
"nordvpn_install_required": "Install NordVPN first",
"nordvpn_connect": "Connect NordVPN",
"nordvpn_disconnect": "Disconnect",
"nordvpn_connected": "NordVPN connected",
"nordvpn_disconnected": "NordVPN disconnected",
"nordvpn_status_unknown": "NordVPN status is unknown.",
"nordvpn_status_not_installed": "NordVPN CLI is not installed on this host.",
"nordvpn_status_connected": "NordVPN is connected.",
"nordvpn_status_connecting": "NordVPN is connecting.",
"nordvpn_status_disconnected": "NordVPN is disconnected.",
"nordvpn_status_not_logged_in": "NordVPN is installed but not logged in. Run nordvpn login on this host.",
"nordvpn_status_service_unavailable": "NordVPN daemon is not available. Make sure nordvpnd is running.",
"nordvpn_status_error": "NordVPN returned an error.",
"nordvpn_country_placeholder": "Country (optional, e.g. Germany or de)",
"nordvpn_city_placeholder": "City (optional, e.g. Berlin)",
"install_starting": "Starting installation...",
"server_check_complete": "Check completed",
"server_connection_error": "Connection error",
@@ -470,10 +517,10 @@
"new_instance": "new instance",
"port_next_instance_hint": "Choose a free UDP port for the additional instance.",
"web_servers": "Web servers",
"nginx_desc": "NGINX web server with Let's Encrypt HTTPS certificate and editable index.html.",
"nginx_desc": "NGINX web server with Let\u0027s Encrypt HTTPS certificate and editable index.html.",
"nginx_domain": "Domain",
"nginx_email": "Let's Encrypt email",
"nginx_port_hint": "HTTPS port exposed on the server. Port 80/TCP must be free and reachable for Let's Encrypt validation.",
"nginx_email": "Let\u0027s Encrypt email",
"nginx_port_hint": "HTTPS port exposed on the server. Port 80/TCP must be free and reachable for Let\u0027s Encrypt validation.",
"nginx_install_hint": "The domain must already point to this server. Port 80/TCP is used for HTTP-01 certificate validation.",
"site": "Site",
"site_editor": "Site editor",
@@ -519,4 +566,27 @@
"xui_server_select_label": "3x-ui 服务器",
"xui_server_select_hint": "选择签发订阅 URL 的 3x-ui 面板。",
"xui_server_delete_confirm": "从面板删除此 3x-ui 服务器?"
,
"about_title": "About & Updates",
"current_version": "Current version",
"check_updates": "Check for updates",
"checking_updates": "Checking...",
"update_available": "New version available",
"download_update": "Download update",
"up_to_date": "You have the latest version",
"apply_update": "Install update",
"applying_update": "Updating…",
"apply_update_confirm": "Install update from git.evilfox.cc and restart the panel?",
"update_restarting": "Updated. Restarting panel…",
"update_no_target": "No target version. Check for updates first.",
"auto_update_hint": "Auto-update pulls the release tag from git.evilfox.cc (git checkout required).",
"auto_update_ready": "Git auto-update is available for this install.",
"auto_update_docker": "Docker install: rebuild/pull image, or use a git checkout for one-click update.",
"auto_update_manual": "One-click update needs a git clone. You can still download a release.",
"auto_update_archive": "One-click update downloads the release ZIP from git.evilfox.cc and restarts the panel.",
"upgrade_panel": "Update panel",
"upgrade_panel_confirm": "Download and install",
"upgrade_panel_confirm_latest": "Check for updates and install the latest release?",
"upgrade_panel_working": "Updating panel…",
"upgrade_panel_up_to_date": "Already on the latest version"
}