Template
Compare commits
4
Commits
v2.6.0
...
73d0ee277d
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
73d0ee277d | ||
|
|
9b4ef0f9f0 | ||
|
|
78e69d899a | ||
|
|
2d62758716 |
+1
-1
@@ -13,7 +13,7 @@ ENV PYTHONDONTWRITEBYTECODE=1 \
|
||||
WORKDIR /app
|
||||
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends curl \
|
||||
&& apt-get install -y --no-install-recommends curl postgresql-client \
|
||||
&& rm -rf /var/lib/apt/lists/*
|
||||
|
||||
COPY requirements.txt .
|
||||
|
||||
@@ -277,6 +277,12 @@ GitHub Actions workflows in `.github/workflows/`:
|
||||
|
||||
## 📋 Fix / changelog (this fork)
|
||||
|
||||
### v2.6.2
|
||||
* **Panel backup → PostgreSQL dump** — Settings backup downloads `.sql` via `pg_dump`; restore accepts `.sql` or legacy `data.json`. JSON export kept as secondary link.
|
||||
|
||||
### v2.6.1
|
||||
* **Move connections between servers** — restored: select configs on a server page and move to another server (recreates peers, keeps user links). `ToggleConnectionRequest` kept intact.
|
||||
|
||||
### v2.6.0 — stable Dokploy / Docker release
|
||||
* **Dokploy-ready compose** — `dokploy-network`, Traefik labels, port **5000**, no fixed `container_name`.
|
||||
* **Docker startup** — `uvicorn` with proxy headers; SSL inside container disabled when `PANEL_IN_DOCKER` / `PANEL_BEHIND_PROXY`.
|
||||
|
||||
@@ -103,7 +103,7 @@ else:
|
||||
application_path = os.path.dirname(__file__)
|
||||
|
||||
DATA_FILE = os.path.join(application_path, 'data.json') # legacy JSON; used only for one-shot import / export
|
||||
CURRENT_VERSION = "v2.6.0"
|
||||
CURRENT_VERSION = "v2.6.5"
|
||||
RELEASES_REPO_URL = repo_url()
|
||||
RELEASES_API_LATEST = api_latest_url()
|
||||
BIN_DIR = os.environ.get('TUNNEL_BIN_DIR', os.path.join(application_path, 'bin'))
|
||||
@@ -111,11 +111,16 @@ TUNNEL_STATE_FILE = os.environ.get('TUNNEL_STATE_FILE', os.path.join(application
|
||||
|
||||
# Panel state lives in PostgreSQL 17 (see db/). load_data/save_data keep the old dict API.
|
||||
from db import ( # noqa: E402
|
||||
backup_filename,
|
||||
clear_tunnel_state,
|
||||
ensure_db_ready,
|
||||
export_data_dict,
|
||||
export_database_sql,
|
||||
invalidate_data_cache,
|
||||
load_data,
|
||||
load_tunnel_state,
|
||||
normalize_import_data,
|
||||
restore_database_sql,
|
||||
save_data,
|
||||
save_tunnel_state,
|
||||
update_tunnel_state,
|
||||
@@ -194,6 +199,34 @@ def get_ssh(server):
|
||||
)
|
||||
|
||||
|
||||
WG_AWG_PROTOCOLS = frozenset({'awg', 'awg2', 'awg_legacy', 'wireguard'})
|
||||
|
||||
|
||||
def get_server_connect_host(server: dict, protocol: Optional[str] = None) -> str:
|
||||
"""Hostname embedded in client VPN configs (Endpoint, vless://, etc.).
|
||||
|
||||
SSH still uses server['host']; this value can be a DNS name so clients
|
||||
keep working after the server IP changes — update the A-record only.
|
||||
Per-protocol connect_domain (AWG / WireGuard) overrides the server default.
|
||||
"""
|
||||
protocols = server.get('protocols') or {}
|
||||
if protocol:
|
||||
base = protocol_base(protocol)
|
||||
if base in WG_AWG_PROTOCOLS:
|
||||
for key in (protocol, base):
|
||||
pinfo = protocols.get(key) if key else None
|
||||
if isinstance(pinfo, dict):
|
||||
domain = (pinfo.get('connect_domain') or '').strip()
|
||||
if domain:
|
||||
return domain.lower().rstrip('.')
|
||||
info = server.get('server_info') or {}
|
||||
for key in ('connect_domain', 'ssl_domain'):
|
||||
val = (info.get(key) or '').strip()
|
||||
if val:
|
||||
return val.lower().rstrip('.')
|
||||
return (server.get('host') or '').strip()
|
||||
|
||||
|
||||
def get_current_user(request: Request, data: Optional[dict] = None):
|
||||
user_id = request.session.get('user_id')
|
||||
if not user_id:
|
||||
@@ -1396,6 +1429,188 @@ async def perform_toggle_user(data: dict, user_id: str, enable: bool) -> bool:
|
||||
return True
|
||||
|
||||
|
||||
def resolve_protocol_on_server(server: dict, protocol: str) -> Optional[str]:
|
||||
"""Pick an installed protocol key on server matching the requested protocol/base."""
|
||||
protocols = server.get('protocols') or {}
|
||||
if protocol in protocols and protocols[protocol].get('installed'):
|
||||
return protocol
|
||||
base = protocol_base(protocol)
|
||||
candidates = [
|
||||
key for key, info in protocols.items()
|
||||
if protocol_base(key) == base and info.get('installed')
|
||||
]
|
||||
if not candidates:
|
||||
return None
|
||||
return sorted(candidates, key=protocol_instance)[0]
|
||||
|
||||
|
||||
def _client_display_name(client: dict) -> str:
|
||||
user_data = client.get('userData') or {}
|
||||
return (
|
||||
user_data.get('clientName')
|
||||
or client.get('clientName')
|
||||
or client.get('clientId')
|
||||
or 'Connection'
|
||||
)
|
||||
|
||||
|
||||
def _create_remote_client(manager, protocol: str, server: dict, name: str, source_client: Optional[dict] = None):
|
||||
proto_info = server.get('protocols', {}).get(protocol, {})
|
||||
port = proto_info.get('port', '55424')
|
||||
base = protocol_base(protocol)
|
||||
if base == 'telemt':
|
||||
user_data = (source_client or {}).get('userData') or {}
|
||||
connect_host = get_server_connect_host(server, protocol)
|
||||
return manager.add_client(
|
||||
protocol, name, connect_host, port,
|
||||
telemt_quota=user_data.get('quota'),
|
||||
telemt_expiry=user_data.get('expiry'),
|
||||
secret=user_data.get('token'),
|
||||
user_ad_tag=user_data.get('user_ad_tag'),
|
||||
max_tcp_conns=user_data.get('max_tcp_conns'),
|
||||
)
|
||||
connect_host = get_server_connect_host(server, protocol)
|
||||
if base == 'wireguard':
|
||||
return manager.add_client(name, connect_host)
|
||||
return manager.add_client(protocol, name, connect_host, port)
|
||||
|
||||
|
||||
def _move_connections_sync(
|
||||
source_server_id: int,
|
||||
target_server_id: int,
|
||||
protocol: str,
|
||||
client_ids: List[str],
|
||||
target_protocol: Optional[str] = None,
|
||||
delete_source: bool = True,
|
||||
) -> dict:
|
||||
data = load_data()
|
||||
if source_server_id >= len(data['servers']) or target_server_id >= len(data['servers']):
|
||||
raise ValueError('Server not found')
|
||||
if source_server_id == target_server_id:
|
||||
raise ValueError('Source and target server must be different')
|
||||
if protocol_base(protocol) == 'xui':
|
||||
raise ValueError('Moving 3x-ui connections between servers is not supported')
|
||||
|
||||
source_server = data['servers'][source_server_id]
|
||||
target_server = data['servers'][target_server_id]
|
||||
resolved_target_protocol = target_protocol or resolve_protocol_on_server(target_server, protocol)
|
||||
if not resolved_target_protocol:
|
||||
raise ValueError(
|
||||
f'Target server does not have {protocol_display_name(protocol)} installed'
|
||||
)
|
||||
|
||||
source_ssh = get_ssh(source_server)
|
||||
target_ssh = get_ssh(target_server)
|
||||
source_ssh.connect()
|
||||
target_ssh.connect()
|
||||
|
||||
source_manager = get_protocol_manager(source_ssh, protocol)
|
||||
source_clients = _manager_call(source_manager, 'get_clients', protocol) or []
|
||||
clients_map = {c.get('clientId'): c for c in source_clients if c.get('clientId')}
|
||||
|
||||
target_manager = get_protocol_manager(target_ssh, resolved_target_protocol)
|
||||
moved = []
|
||||
failed = []
|
||||
|
||||
try:
|
||||
for client_id in client_ids:
|
||||
client = clients_map.get(client_id)
|
||||
if not client:
|
||||
failed.append({'client_id': client_id, 'error': 'Client not found on source server'})
|
||||
continue
|
||||
|
||||
user_data = client.get('userData') or {}
|
||||
base = protocol_base(protocol)
|
||||
if user_data.get('externalClient') and not user_data.get('clientPrivateKey') and base in (
|
||||
'awg', 'awg2', 'awg_legacy', 'wireguard',
|
||||
):
|
||||
failed.append({
|
||||
'client_id': client_id,
|
||||
'error': 'External/native client cannot be moved (no private key)',
|
||||
})
|
||||
continue
|
||||
|
||||
name = _client_display_name(client)
|
||||
enabled = client.get('enabled', True)
|
||||
if user_data.get('enabled') is False:
|
||||
enabled = False
|
||||
|
||||
try:
|
||||
created = _create_remote_client(
|
||||
target_manager, resolved_target_protocol, target_server, name, client,
|
||||
)
|
||||
new_client_id = created.get('client_id')
|
||||
if not new_client_id:
|
||||
failed.append({'client_id': client_id, 'error': 'Failed to create client on target server'})
|
||||
continue
|
||||
|
||||
if not enabled:
|
||||
_manager_call(
|
||||
target_manager, 'toggle_client',
|
||||
resolved_target_protocol, new_client_id, False,
|
||||
)
|
||||
|
||||
user_conn = next(
|
||||
(
|
||||
uc for uc in data.get('user_connections', [])
|
||||
if uc.get('client_id') == client_id
|
||||
and uc.get('server_id') == source_server_id
|
||||
and uc.get('protocol') == protocol
|
||||
),
|
||||
None,
|
||||
)
|
||||
if user_conn:
|
||||
user_conn['server_id'] = target_server_id
|
||||
user_conn['client_id'] = new_client_id
|
||||
user_conn['protocol'] = resolved_target_protocol
|
||||
user_conn['name'] = name
|
||||
elif client.get('assigned_user_id'):
|
||||
data.setdefault('user_connections', []).append({
|
||||
'id': str(uuid.uuid4()),
|
||||
'user_id': client['assigned_user_id'],
|
||||
'server_id': target_server_id,
|
||||
'protocol': resolved_target_protocol,
|
||||
'client_id': new_client_id,
|
||||
'name': name,
|
||||
'created_at': datetime.now().isoformat(),
|
||||
})
|
||||
|
||||
if delete_source:
|
||||
_manager_call(source_manager, 'remove_client', protocol, client_id)
|
||||
data['user_connections'] = [
|
||||
uc for uc in data.get('user_connections', [])
|
||||
if not (
|
||||
uc.get('client_id') == client_id
|
||||
and uc.get('server_id') == source_server_id
|
||||
and uc.get('protocol') == protocol
|
||||
)
|
||||
]
|
||||
|
||||
moved.append({
|
||||
'client_id': client_id,
|
||||
'new_client_id': new_client_id,
|
||||
'name': name,
|
||||
})
|
||||
except Exception as exc:
|
||||
logger.exception('Failed to move client %s', client_id)
|
||||
failed.append({'client_id': client_id, 'error': str(exc)})
|
||||
finally:
|
||||
source_ssh.disconnect()
|
||||
target_ssh.disconnect()
|
||||
|
||||
if moved:
|
||||
save_data(data)
|
||||
|
||||
return {
|
||||
'status': 'success' if moved else 'error',
|
||||
'moved': moved,
|
||||
'failed': failed,
|
||||
'target_server_id': target_server_id,
|
||||
'target_protocol': resolved_target_protocol,
|
||||
'message': f'Moved {len(moved)} connection(s)' + (f', {len(failed)} failed' if failed else ''),
|
||||
}
|
||||
|
||||
|
||||
async def perform_mass_operations(delete_uids: List[str] = None, toggle_uids: List[tuple] = None, create_conns: List[dict] = None):
|
||||
"""
|
||||
Executes multiple SSH operations efficiently.
|
||||
@@ -1462,9 +1677,9 @@ async def perform_mass_operations(delete_uids: List[str] = None, toggle_uids: Li
|
||||
manager = get_protocol_manager(ssh, c_req['protocol'])
|
||||
|
||||
if c_req['protocol'] == 'wireguard':
|
||||
res = await asyncio.to_thread(manager.add_client, c_req['name'], srv['host'])
|
||||
res = await asyncio.to_thread(manager.add_client, c_req['name'], get_server_connect_host(srv, 'wireguard'))
|
||||
else:
|
||||
res = await asyncio.to_thread(_manager_call, manager, 'add_client', c_req['protocol'], c_req['name'], srv['host'], port)
|
||||
res = await asyncio.to_thread(_manager_call, manager, 'add_client', c_req['protocol'], c_req['name'], get_server_connect_host(srv, c_req['protocol']), port)
|
||||
|
||||
if res.get('client_id'):
|
||||
new_conn = {
|
||||
@@ -1910,6 +2125,7 @@ class AddServerRequest(BaseModel):
|
||||
name: str = ''
|
||||
ssl_domain: str = ''
|
||||
ssl_email: str = ''
|
||||
connect_domain: str = ''
|
||||
|
||||
|
||||
class EditServerRequest(BaseModel):
|
||||
@@ -1924,6 +2140,12 @@ class EditServerRequest(BaseModel):
|
||||
private_key: Optional[str] = None
|
||||
ssl_domain: Optional[str] = None
|
||||
ssl_email: Optional[str] = None
|
||||
connect_domain: Optional[str] = None
|
||||
|
||||
|
||||
class ConnectDomainRequest(BaseModel):
|
||||
connect_domain: str = ''
|
||||
protocol: Optional[str] = None
|
||||
|
||||
|
||||
class ReorderServersRequest(BaseModel):
|
||||
@@ -2020,6 +2242,14 @@ class ToggleConnectionRequest(BaseModel):
|
||||
enable: bool = True
|
||||
|
||||
|
||||
class MoveConnectionsRequest(BaseModel):
|
||||
protocol: str = 'awg'
|
||||
target_server_id: int
|
||||
client_ids: List[str]
|
||||
target_protocol: Optional[str] = None
|
||||
delete_source: bool = True
|
||||
|
||||
|
||||
class AddUserRequest(BaseModel):
|
||||
username: str
|
||||
password: str
|
||||
@@ -2560,12 +2790,21 @@ async def server_detail(request: Request, server_id: int):
|
||||
return RedirectResponse(url='/')
|
||||
server = data['servers'][server_id]
|
||||
users_list = data.get('users', [])
|
||||
servers_for_move = [
|
||||
{
|
||||
'id': idx,
|
||||
'name': srv.get('name') or srv.get('host') or f'Server {idx + 1}',
|
||||
'host': srv.get('host') or '',
|
||||
}
|
||||
for idx, srv in enumerate(data['servers'])
|
||||
]
|
||||
return tpl(
|
||||
request,
|
||||
'server.html',
|
||||
server=server,
|
||||
server_id=server_id,
|
||||
users=users_list,
|
||||
servers_for_move=servers_for_move,
|
||||
)
|
||||
|
||||
|
||||
@@ -2729,10 +2968,13 @@ async def api_add_server(request: Request, req: AddServerRequest):
|
||||
}
|
||||
ssl_domain = (req.ssl_domain or '').strip().lower()
|
||||
ssl_email = (req.ssl_email or '').strip()
|
||||
connect_domain = (req.connect_domain or '').strip().lower()
|
||||
if ssl_domain:
|
||||
server_info['ssl_domain'] = ssl_domain
|
||||
if ssl_email:
|
||||
server_info['ssl_email'] = ssl_email
|
||||
if connect_domain:
|
||||
server_info['connect_domain'] = connect_domain
|
||||
server['server_info'] = server_info
|
||||
data = load_data()
|
||||
data['servers'].append(server)
|
||||
@@ -2798,7 +3040,7 @@ async def api_edit_server(request: Request, server_id: int, req: EditServerReque
|
||||
info = dict(server.get('server_info') or {})
|
||||
if isinstance(server_info, dict):
|
||||
for k, v in server_info.items():
|
||||
if k not in ('ssl_domain', 'ssl_email'):
|
||||
if k not in ('ssl_domain', 'ssl_email', 'connect_domain'):
|
||||
info[k] = v
|
||||
if req.ssl_domain is not None:
|
||||
domain = (req.ssl_domain or '').strip().lower()
|
||||
@@ -2812,6 +3054,12 @@ async def api_edit_server(request: Request, server_id: int, req: EditServerReque
|
||||
info['ssl_email'] = email
|
||||
else:
|
||||
info.pop('ssl_email', None)
|
||||
if req.connect_domain is not None:
|
||||
domain = (req.connect_domain or '').strip().lower()
|
||||
if domain:
|
||||
info['connect_domain'] = domain
|
||||
else:
|
||||
info.pop('connect_domain', None)
|
||||
server['server_info'] = info
|
||||
save_data(data)
|
||||
return {'status': 'success', 'server_info': info}
|
||||
@@ -2820,6 +3068,75 @@ async def api_edit_server(request: Request, server_id: int, req: EditServerReque
|
||||
return JSONResponse({'error': str(e)}, status_code=500)
|
||||
|
||||
|
||||
@app.get('/api/servers/{server_id}/connect-domain', tags=["Servers"])
|
||||
async def api_get_connect_domain(request: Request, server_id: int, protocol: Optional[str] = None):
|
||||
if not _check_admin(request):
|
||||
return JSONResponse({'error': 'Forbidden'}, status_code=403)
|
||||
data = load_data()
|
||||
if server_id >= len(data['servers']):
|
||||
return JSONResponse({'error': 'Server not found'}, status_code=404)
|
||||
server = data['servers'][server_id]
|
||||
proto = (protocol or '').strip()
|
||||
info = server.get('server_info') or {}
|
||||
proto_domain = ''
|
||||
if proto:
|
||||
pinfo = (server.get('protocols') or {}).get(proto) or {}
|
||||
proto_domain = (pinfo.get('connect_domain') or '').strip()
|
||||
return {
|
||||
'connect_domain': (info.get('connect_domain') or '').strip(),
|
||||
'protocol_connect_domain': proto_domain,
|
||||
'protocol': proto,
|
||||
'effective_host': get_server_connect_host(server, proto or None),
|
||||
'ssh_host': server.get('host') or '',
|
||||
}
|
||||
|
||||
|
||||
@app.post('/api/servers/{server_id}/connect-domain', tags=["Servers"])
|
||||
async def api_set_connect_domain(request: Request, server_id: int, req: ConnectDomainRequest):
|
||||
"""Set client Endpoint hostname for AWG / WireGuard without re-verifying SSH."""
|
||||
if not _check_admin(request):
|
||||
return JSONResponse({'error': 'Forbidden'}, status_code=403)
|
||||
try:
|
||||
data = load_data()
|
||||
if server_id >= len(data['servers']):
|
||||
return JSONResponse({'error': 'Server not found'}, status_code=404)
|
||||
server = data['servers'][server_id]
|
||||
domain = (req.connect_domain or '').strip().lower().rstrip('.')
|
||||
proto = (req.protocol or '').strip()
|
||||
|
||||
if proto:
|
||||
base = protocol_base(proto)
|
||||
if base not in WG_AWG_PROTOCOLS:
|
||||
return JSONResponse(
|
||||
{'error': 'Per-protocol domain is only supported for AmneziaWG / WireGuard'},
|
||||
status_code=400,
|
||||
)
|
||||
protocols = server.setdefault('protocols', {})
|
||||
proto_info = protocols.setdefault(proto, {})
|
||||
if domain:
|
||||
proto_info['connect_domain'] = domain
|
||||
else:
|
||||
proto_info.pop('connect_domain', None)
|
||||
else:
|
||||
info = dict(server.get('server_info') or {})
|
||||
if domain:
|
||||
info['connect_domain'] = domain
|
||||
else:
|
||||
info.pop('connect_domain', None)
|
||||
server['server_info'] = info
|
||||
|
||||
save_data(data)
|
||||
return {
|
||||
'status': 'success',
|
||||
'connect_domain': domain,
|
||||
'protocol': proto,
|
||||
'effective_host': get_server_connect_host(server, proto or None),
|
||||
}
|
||||
except Exception as e:
|
||||
logger.exception('Error saving connect domain')
|
||||
return JSONResponse({'error': str(e)}, status_code=500)
|
||||
|
||||
|
||||
@app.get('/api/servers/{server_id}/ping', tags=["Servers"])
|
||||
async def api_server_ping(request: Request, server_id: int):
|
||||
"""Cheap reachability check: opens a TCP connection to the SSH port,
|
||||
@@ -3754,7 +4071,7 @@ async def api_protocol_export_clients(request: Request, server_id: int, req: Pro
|
||||
continue
|
||||
try:
|
||||
config = _manager_call(
|
||||
manager, 'get_client_config', req.protocol, client_id, server['host'], port
|
||||
manager, 'get_client_config', req.protocol, client_id, get_server_connect_host(server, req.protocol), port
|
||||
)
|
||||
except Exception as exc:
|
||||
skipped.append(f'{client_name}: {exc}')
|
||||
@@ -4238,7 +4555,7 @@ async def api_add_connection(request: Request, server_id: int, req: AddConnectio
|
||||
|
||||
if protocol_base(req.protocol) == 'telemt':
|
||||
result = manager.add_client(
|
||||
req.protocol, req.name, server['host'], port,
|
||||
req.protocol, req.name, get_server_connect_host(server, req.protocol), port,
|
||||
telemt_quota=req.telemt_quota,
|
||||
telemt_max_ips=req.telemt_max_ips,
|
||||
telemt_expiry=req.telemt_expiry,
|
||||
@@ -4247,9 +4564,9 @@ async def api_add_connection(request: Request, server_id: int, req: AddConnectio
|
||||
max_tcp_conns=req.telemt_max_conns
|
||||
)
|
||||
elif protocol_base(req.protocol) == 'wireguard':
|
||||
result = manager.add_client(req.name, server['host'])
|
||||
result = manager.add_client(req.name, get_server_connect_host(server, req.protocol))
|
||||
else:
|
||||
result = manager.add_client(req.protocol, req.name, server['host'], port)
|
||||
result = manager.add_client(req.protocol, req.name, get_server_connect_host(server, req.protocol), port)
|
||||
ssh.disconnect()
|
||||
|
||||
if result.get('config'):
|
||||
@@ -4372,7 +4689,7 @@ async def api_get_connection_config(request: Request, server_id: int, req: Conne
|
||||
ssh = get_ssh(server)
|
||||
ssh.connect()
|
||||
manager = get_protocol_manager(ssh, req.protocol)
|
||||
config = _manager_call(manager, 'get_client_config', req.protocol, req.client_id, server['host'], port)
|
||||
config = _manager_call(manager, 'get_client_config', req.protocol, req.client_id, get_server_connect_host(server, req.protocol), port)
|
||||
ssh.disconnect()
|
||||
vpn_link = generate_vpn_link(config) if config else ''
|
||||
return {'config': config, 'vpn_link': vpn_link}
|
||||
@@ -4381,6 +4698,35 @@ async def api_get_connection_config(request: Request, server_id: int, req: Conne
|
||||
return JSONResponse({'error': str(e)}, status_code=500)
|
||||
|
||||
|
||||
@app.post('/api/servers/{server_id}/connections/move', tags=["Connections"])
|
||||
async def api_move_connections(request: Request, server_id: int, req: MoveConnectionsRequest):
|
||||
if not _check_admin(request):
|
||||
return JSONResponse({'error': 'Forbidden'}, status_code=403)
|
||||
if not req.client_ids:
|
||||
return JSONResponse({'error': 'No connections selected'}, status_code=400)
|
||||
try:
|
||||
result = await asyncio.to_thread(
|
||||
_move_connections_sync,
|
||||
server_id,
|
||||
req.target_server_id,
|
||||
req.protocol,
|
||||
req.client_ids,
|
||||
req.target_protocol,
|
||||
bool(req.delete_source),
|
||||
)
|
||||
if not result.get('moved'):
|
||||
return JSONResponse(
|
||||
{'error': result.get('message') or 'Move failed', **result},
|
||||
status_code=400,
|
||||
)
|
||||
return result
|
||||
except ValueError as e:
|
||||
return JSONResponse({'error': str(e)}, status_code=400)
|
||||
except Exception as e:
|
||||
logger.exception('Error moving connections')
|
||||
return JSONResponse({'error': str(e)}, status_code=500)
|
||||
|
||||
|
||||
@app.post('/api/servers/{server_id}/connections/toggle', tags=["Connections"])
|
||||
async def api_toggle_connection(request: Request, server_id: int, req: ToggleConnectionRequest):
|
||||
if not _check_admin(request):
|
||||
@@ -4526,7 +4872,7 @@ async def api_add_user(request: Request, req: AddUserRequest):
|
||||
manager = get_protocol_manager(ssh, req.protocol)
|
||||
if protocol_base(req.protocol) == 'telemt':
|
||||
conn_result = manager.add_client(
|
||||
req.protocol, conn_name, server['host'], port,
|
||||
req.protocol, conn_name, get_server_connect_host(server, req.protocol), port,
|
||||
telemt_quota=req.telemt_quota,
|
||||
telemt_max_ips=req.telemt_max_ips,
|
||||
telemt_expiry=req.telemt_expiry,
|
||||
@@ -4535,7 +4881,7 @@ async def api_add_user(request: Request, req: AddUserRequest):
|
||||
max_tcp_conns=req.telemt_max_conns
|
||||
)
|
||||
else:
|
||||
conn_result = manager.add_client(req.protocol, conn_name, server['host'], port)
|
||||
conn_result = manager.add_client(req.protocol, conn_name, get_server_connect_host(server, req.protocol), port)
|
||||
ssh.disconnect()
|
||||
|
||||
if conn_result.get('client_id'):
|
||||
@@ -4743,12 +5089,12 @@ async def api_add_user_connection(request: Request, user_id: str, req: AddUserCo
|
||||
# Link existing client
|
||||
config = await asyncio.to_thread(
|
||||
_manager_call, manager, 'get_client_config',
|
||||
req.protocol, req.client_id, server['host'], port,
|
||||
req.protocol, req.client_id, get_server_connect_host(server, req.protocol), port,
|
||||
)
|
||||
result = {'client_id': req.client_id, 'config': config}
|
||||
elif protocol_base(req.protocol) == 'telemt':
|
||||
result = await asyncio.to_thread(
|
||||
manager.add_client, req.protocol, req.name, server['host'], port,
|
||||
manager.add_client, req.protocol, req.name, get_server_connect_host(server, req.protocol), port,
|
||||
telemt_quota=req.telemt_quota,
|
||||
telemt_max_ips=req.telemt_max_ips,
|
||||
telemt_expiry=req.telemt_expiry,
|
||||
@@ -4757,11 +5103,11 @@ async def api_add_user_connection(request: Request, user_id: str, req: AddUserCo
|
||||
max_tcp_conns=req.telemt_max_conns,
|
||||
)
|
||||
elif protocol_base(req.protocol) == 'wireguard':
|
||||
result = await asyncio.to_thread(manager.add_client, req.name, server['host'])
|
||||
result = await asyncio.to_thread(manager.add_client, req.name, get_server_connect_host(server, req.protocol))
|
||||
else:
|
||||
result = await asyncio.to_thread(
|
||||
_manager_call, manager, 'add_client',
|
||||
req.protocol, req.name, server['host'], port,
|
||||
req.protocol, req.name, get_server_connect_host(server, req.protocol), port,
|
||||
)
|
||||
finally:
|
||||
await asyncio.to_thread(ssh.disconnect)
|
||||
@@ -4952,7 +5298,7 @@ async def api_share_config(token: str, connection_id: str, request: Request):
|
||||
ssh.connect()
|
||||
# Use appropriate manager for the protocol
|
||||
manager = get_protocol_manager(ssh, conn['protocol'])
|
||||
config = _manager_call(manager, 'get_client_config', conn['protocol'], conn['client_id'], server['host'], port)
|
||||
config = _manager_call(manager, 'get_client_config', conn['protocol'], conn['client_id'], get_server_connect_host(server, conn['protocol']), port)
|
||||
ssh.disconnect()
|
||||
vpn_link = generate_vpn_link(config) if config else ''
|
||||
return {'config': config, 'vpn_link': vpn_link, 'expires_at': user.get('expiration_date')}
|
||||
@@ -5112,7 +5458,7 @@ async def api_guest_config(token: str, connection_id: str, request: Request):
|
||||
ssh = get_ssh(server)
|
||||
ssh.connect()
|
||||
manager = get_protocol_manager(ssh, conn['protocol'])
|
||||
config = _manager_call(manager, 'get_client_config', conn['protocol'], conn['client_id'], server['host'], port)
|
||||
config = _manager_call(manager, 'get_client_config', conn['protocol'], conn['client_id'], get_server_connect_host(server, conn['protocol']), port)
|
||||
ssh.disconnect()
|
||||
vpn_link = generate_vpn_link(config) if config else ''
|
||||
return {'config': config, 'vpn_link': vpn_link, 'expires_at': holder.get('expiration_date')}
|
||||
@@ -5176,11 +5522,11 @@ async def api_guest_create(token: str, req: GuestCreateRequest, request: Request
|
||||
try:
|
||||
manager = get_protocol_manager(ssh, protocol)
|
||||
if protocol_base(protocol) == 'wireguard':
|
||||
result = await asyncio.to_thread(manager.add_client, name, server['host'])
|
||||
result = await asyncio.to_thread(manager.add_client, name, get_server_connect_host(server, protocol))
|
||||
else:
|
||||
result = await asyncio.to_thread(
|
||||
_manager_call, manager, 'add_client',
|
||||
protocol, name, server['host'], port,
|
||||
protocol, name, get_server_connect_host(server, protocol), port,
|
||||
)
|
||||
finally:
|
||||
await asyncio.to_thread(ssh.disconnect)
|
||||
@@ -5338,11 +5684,11 @@ async def _create_config_for_protocol(
|
||||
try:
|
||||
manager = get_protocol_manager(ssh, protocol)
|
||||
if protocol_base(protocol) == 'wireguard':
|
||||
result = await asyncio.to_thread(manager.add_client, name, server['host'])
|
||||
result = await asyncio.to_thread(manager.add_client, name, get_server_connect_host(server, protocol))
|
||||
else:
|
||||
result = await asyncio.to_thread(
|
||||
_manager_call, manager, 'add_client',
|
||||
protocol, name, server['host'], port,
|
||||
protocol, name, get_server_connect_host(server, protocol), port,
|
||||
)
|
||||
finally:
|
||||
await asyncio.to_thread(ssh.disconnect)
|
||||
@@ -5713,7 +6059,7 @@ async def api_my_connection_config(request: Request, connection_id: str):
|
||||
ssh.connect()
|
||||
# Use appropriate manager for the protocol (fixes Telemt/Xray not working for users)
|
||||
manager = get_protocol_manager(ssh, conn['protocol'])
|
||||
config = _manager_call(manager, 'get_client_config', conn['protocol'], conn['client_id'], server['host'], port)
|
||||
config = _manager_call(manager, 'get_client_config', conn['protocol'], conn['client_id'], get_server_connect_host(server, conn['protocol']), port)
|
||||
ssh.disconnect()
|
||||
vpn_link = generate_vpn_link(config) if config else ''
|
||||
expires_at = None
|
||||
@@ -6365,6 +6711,24 @@ async def api_revoke_token(request: Request, token_id: str):
|
||||
|
||||
@app.get('/api/settings/backup/download', tags=["Settings"])
|
||||
async def api_backup_download(request: Request):
|
||||
if not _check_admin(request):
|
||||
return JSONResponse({'error': 'Forbidden'}, status_code=403)
|
||||
try:
|
||||
content = await asyncio.to_thread(export_database_sql)
|
||||
except Exception as e:
|
||||
logger.exception('Database backup failed')
|
||||
return JSONResponse({'error': str(e)}, status_code=500)
|
||||
filename = backup_filename()
|
||||
return StreamingResponse(
|
||||
io.BytesIO(content),
|
||||
media_type='application/sql',
|
||||
headers={'Content-Disposition': f'attachment; filename="{filename}"'},
|
||||
)
|
||||
|
||||
|
||||
@app.get('/api/settings/backup/download/json', tags=["Settings"])
|
||||
async def api_backup_download_json(request: Request):
|
||||
"""Legacy JSON export (same shape as old data.json)."""
|
||||
if not _check_admin(request):
|
||||
return JSONResponse({'error': 'Forbidden'}, status_code=403)
|
||||
payload = await asyncio.to_thread(export_data_dict)
|
||||
@@ -6384,33 +6748,45 @@ async def api_backup_restore(request: Request, file: UploadFile = File(...)):
|
||||
content = await file.read()
|
||||
if not content:
|
||||
return JSONResponse({'error': 'Empty file'}, status_code=400)
|
||||
|
||||
|
||||
filename = (file.filename or '').lower()
|
||||
is_json = filename.endswith('.json') or content.lstrip().startswith(b'{')
|
||||
|
||||
if is_json:
|
||||
try:
|
||||
backup_data = json.loads(content)
|
||||
except json.JSONDecodeError:
|
||||
return JSONResponse({'error': 'Invalid JSON format'}, status_code=400)
|
||||
|
||||
required_keys = ['servers', 'users']
|
||||
missing = [k for k in required_keys if k not in backup_data]
|
||||
if missing:
|
||||
return JSONResponse({'error': f'Invalid structure. Missing keys: {", ".join(missing)}'}, status_code=400)
|
||||
|
||||
if not isinstance(backup_data['servers'], list) or not isinstance(backup_data['users'], list):
|
||||
return JSONResponse({'error': 'Invalid structure: servers and users must be lists'}, status_code=400)
|
||||
|
||||
backup_data.setdefault('user_connections', [])
|
||||
backup_data.setdefault('api_tokens', [])
|
||||
backup_data.setdefault('invite_links', [])
|
||||
backup_data.setdefault('settings', {})
|
||||
|
||||
try:
|
||||
backup_data = normalize_import_data(backup_data)
|
||||
async with DATA_LOCK:
|
||||
save_data(backup_data)
|
||||
except Exception as e:
|
||||
invalidate_data_cache()
|
||||
logger.exception('JSON backup restore failed')
|
||||
return JSONResponse({'error': f'Import failed: {e}'}, status_code=400)
|
||||
return {'status': 'success', 'format': 'json'}
|
||||
|
||||
try:
|
||||
backup_data = json.loads(content)
|
||||
except json.JSONDecodeError:
|
||||
return JSONResponse({'error': 'Invalid JSON format'}, status_code=400)
|
||||
|
||||
# Basic structure validation
|
||||
required_keys = ['servers', 'users']
|
||||
missing = [k for k in required_keys if k not in backup_data]
|
||||
if missing:
|
||||
return JSONResponse({'error': f'Invalid structure. Missing keys: {", ".join(missing)}'}, status_code=400)
|
||||
|
||||
# Ensure types are correct
|
||||
if not isinstance(backup_data['servers'], list) or not isinstance(backup_data['users'], list):
|
||||
return JSONResponse({'error': 'Invalid structure: servers and users must be lists'}, status_code=400)
|
||||
|
||||
backup_data.setdefault('user_connections', [])
|
||||
backup_data.setdefault('api_tokens', [])
|
||||
backup_data.setdefault('invite_links', [])
|
||||
backup_data.setdefault('settings', {})
|
||||
|
||||
# Save the new data
|
||||
async with DATA_LOCK:
|
||||
save_data(backup_data)
|
||||
|
||||
# In a real app we might want to restart or re-init background tasks
|
||||
return {'status': 'success'}
|
||||
await asyncio.to_thread(restore_database_sql, content)
|
||||
except Exception as e:
|
||||
logger.exception('Database restore failed')
|
||||
return JSONResponse({'error': str(e)}, status_code=400)
|
||||
return {'status': 'success', 'format': 'sql'}
|
||||
except Exception as e:
|
||||
logger.exception("Error during restore")
|
||||
return JSONResponse({'error': str(e)}, status_code=500)
|
||||
|
||||
@@ -1,28 +1,36 @@
|
||||
"""Database package for Amnezia Web Panel (PostgreSQL 17)."""
|
||||
|
||||
from .backup import backup_filename, export_database_sql, restore_database_sql
|
||||
from .connection import close_pool, get_database_url, init_schema
|
||||
from .store import (
|
||||
clear_tunnel_state,
|
||||
ensure_db_ready,
|
||||
export_data_dict,
|
||||
import_from_json_file,
|
||||
invalidate_data_cache,
|
||||
load_data,
|
||||
load_tunnel_state,
|
||||
normalize_import_data,
|
||||
save_data,
|
||||
save_tunnel_state,
|
||||
update_tunnel_state,
|
||||
)
|
||||
|
||||
__all__ = [
|
||||
'backup_filename',
|
||||
'clear_tunnel_state',
|
||||
'close_pool',
|
||||
'ensure_db_ready',
|
||||
'export_data_dict',
|
||||
'export_database_sql',
|
||||
'get_database_url',
|
||||
'import_from_json_file',
|
||||
'init_schema',
|
||||
'invalidate_data_cache',
|
||||
'load_data',
|
||||
'load_tunnel_state',
|
||||
'normalize_import_data',
|
||||
'restore_database_sql',
|
||||
'save_data',
|
||||
'save_tunnel_state',
|
||||
'update_tunnel_state',
|
||||
|
||||
@@ -0,0 +1,59 @@
|
||||
"""PostgreSQL backup/restore for the panel database."""
|
||||
|
||||
from __future__ import annotations
|
||||
|
||||
import logging
|
||||
import subprocess
|
||||
from datetime import datetime, timezone
|
||||
|
||||
from .connection import get_database_url
|
||||
from .store import invalidate_data_cache
|
||||
|
||||
logger = logging.getLogger(__name__)
|
||||
|
||||
|
||||
def backup_filename() -> str:
|
||||
stamp = datetime.now(timezone.utc).strftime('%Y-%m-%d_%H%M%S')
|
||||
return f'amnezia_panel_backup_{stamp}.sql'
|
||||
|
||||
|
||||
def export_database_sql() -> bytes:
|
||||
"""Create a plain SQL dump of the panel PostgreSQL database."""
|
||||
url = get_database_url()
|
||||
proc = subprocess.run(
|
||||
[
|
||||
'pg_dump',
|
||||
'--dbname', url,
|
||||
'--no-owner',
|
||||
'--no-acl',
|
||||
'--clean',
|
||||
'--if-exists',
|
||||
],
|
||||
capture_output=True,
|
||||
check=False,
|
||||
)
|
||||
if proc.returncode != 0:
|
||||
err = proc.stderr.decode('utf-8', errors='replace').strip()
|
||||
raise RuntimeError(err or 'pg_dump failed')
|
||||
if not proc.stdout:
|
||||
raise RuntimeError('pg_dump returned empty dump')
|
||||
return proc.stdout
|
||||
|
||||
|
||||
def restore_database_sql(data: bytes) -> None:
|
||||
"""Restore panel data from a plain SQL dump produced by pg_dump."""
|
||||
if not data or not data.strip():
|
||||
raise ValueError('Empty backup file')
|
||||
url = get_database_url()
|
||||
proc = subprocess.run(
|
||||
['psql', '--dbname', url, '-v', 'ON_ERROR_STOP=1', '-q'],
|
||||
input=data,
|
||||
capture_output=True,
|
||||
check=False,
|
||||
)
|
||||
if proc.returncode != 0:
|
||||
err = proc.stderr.decode('utf-8', errors='replace').strip()
|
||||
out = proc.stdout.decode('utf-8', errors='replace').strip()
|
||||
raise RuntimeError(err or out or 'psql restore failed')
|
||||
invalidate_data_cache()
|
||||
logger.info('PostgreSQL backup restored successfully')
|
||||
+150
-7
@@ -10,8 +10,10 @@ import copy
|
||||
import json
|
||||
import logging
|
||||
import os
|
||||
import secrets
|
||||
import shutil
|
||||
import threading
|
||||
import uuid
|
||||
from datetime import datetime, timezone
|
||||
from pathlib import Path
|
||||
from typing import Any, Optional
|
||||
@@ -83,6 +85,147 @@ def _as_uuid(value: Any) -> UUID:
|
||||
return UUID(str(value))
|
||||
|
||||
|
||||
def _is_valid_uuid(value: Any) -> bool:
|
||||
if value is None:
|
||||
return False
|
||||
try:
|
||||
UUID(str(value))
|
||||
return True
|
||||
except (ValueError, AttributeError, TypeError):
|
||||
return False
|
||||
|
||||
|
||||
def _coerce_uuid(value: Any, *, default: Optional[str] = None) -> str:
|
||||
if _is_valid_uuid(value):
|
||||
return str(UUID(str(value)))
|
||||
if default is not None:
|
||||
return default
|
||||
return str(uuid.uuid4())
|
||||
|
||||
|
||||
def _as_list(value: Any) -> list:
|
||||
return list(value) if isinstance(value, list) else []
|
||||
|
||||
|
||||
def normalize_import_data(data: dict) -> dict:
|
||||
"""Prepare legacy data.json (or partial exports) for PostgreSQL constraints."""
|
||||
data = copy.deepcopy(data or {})
|
||||
data['servers'] = [s for s in _as_list(data.get('servers')) if isinstance(s, dict)]
|
||||
data['users'] = [u for u in _as_list(data.get('users')) if isinstance(u, dict)]
|
||||
data['user_connections'] = [c for c in _as_list(data.get('user_connections')) if isinstance(c, dict)]
|
||||
data['api_tokens'] = [t for t in _as_list(data.get('api_tokens')) if isinstance(t, dict)]
|
||||
data['invite_links'] = [l for l in _as_list(data.get('invite_links')) if isinstance(l, dict)]
|
||||
if not isinstance(data.get('settings'), dict):
|
||||
data['settings'] = {}
|
||||
|
||||
id_map: dict[str, str] = {}
|
||||
|
||||
def map_user_id(value: Any) -> Optional[str]:
|
||||
if value is None or value == '':
|
||||
return None
|
||||
key = str(value)
|
||||
if _is_valid_uuid(key):
|
||||
resolved = str(UUID(key))
|
||||
id_map.setdefault(key, resolved)
|
||||
return resolved
|
||||
if key not in id_map:
|
||||
id_map[key] = str(uuid.uuid4())
|
||||
return id_map[key]
|
||||
|
||||
used_usernames: set[str] = set()
|
||||
for index, user in enumerate(data['users']):
|
||||
if not isinstance(user, dict):
|
||||
continue
|
||||
old_id = user.get('id')
|
||||
if old_id is None or old_id == '':
|
||||
user['id'] = str(uuid.uuid4())
|
||||
else:
|
||||
key = str(old_id)
|
||||
if _is_valid_uuid(key):
|
||||
user['id'] = str(UUID(key))
|
||||
id_map.setdefault(key, user['id'])
|
||||
else:
|
||||
user['id'] = map_user_id(key) or str(uuid.uuid4())
|
||||
|
||||
username = (user.get('username') or '').strip() or f'user{index + 1}'
|
||||
base = username
|
||||
suffix = 2
|
||||
while username.lower() in used_usernames:
|
||||
username = f'{base}_{suffix}'
|
||||
suffix += 1
|
||||
user['username'] = username
|
||||
used_usernames.add(username.lower())
|
||||
|
||||
user.setdefault('password_hash', '')
|
||||
user.setdefault('role', 'user')
|
||||
user.setdefault('enabled', True)
|
||||
|
||||
valid_user_ids = {str(u['id']) for u in data['users'] if isinstance(u, dict) and u.get('id')}
|
||||
|
||||
for server in data['servers']:
|
||||
if not isinstance(server, dict):
|
||||
continue
|
||||
server['server_info'] = _as_dict(server.get('server_info'))
|
||||
server['protocols'] = _as_dict(server.get('protocols'))
|
||||
|
||||
for conn in data['user_connections']:
|
||||
if not isinstance(conn, dict):
|
||||
continue
|
||||
conn['id'] = _coerce_uuid(conn.get('id'))
|
||||
mapped_uid = map_user_id(conn.get('user_id'))
|
||||
if mapped_uid:
|
||||
conn['user_id'] = mapped_uid
|
||||
|
||||
data['user_connections'] = [
|
||||
c for c in data['user_connections']
|
||||
if isinstance(c, dict) and str(c.get('user_id')) in valid_user_ids
|
||||
]
|
||||
|
||||
seen_hashes: set[str] = set()
|
||||
normalized_tokens = []
|
||||
for token in data['api_tokens']:
|
||||
if not isinstance(token, dict):
|
||||
continue
|
||||
mapped_uid = map_user_id(token.get('user_id'))
|
||||
if not mapped_uid or mapped_uid not in valid_user_ids:
|
||||
continue
|
||||
token['id'] = _coerce_uuid(token.get('id'))
|
||||
token['user_id'] = mapped_uid
|
||||
token_hash = (token.get('token_hash') or '').strip()
|
||||
if not token_hash or token_hash in seen_hashes:
|
||||
token_hash = secrets.token_hex(32)
|
||||
token['token_hash'] = token_hash
|
||||
seen_hashes.add(token_hash)
|
||||
token.setdefault('token_prefix', (token_hash[:8] if token_hash else ''))
|
||||
normalized_tokens.append(token)
|
||||
data['api_tokens'] = normalized_tokens
|
||||
|
||||
seen_invite_tokens: set[str] = set()
|
||||
for link in data['invite_links']:
|
||||
if not isinstance(link, dict):
|
||||
continue
|
||||
link['id'] = _coerce_uuid(link.get('id'))
|
||||
mapped_uid = map_user_id(link.get('user_id'))
|
||||
link['user_id'] = mapped_uid if mapped_uid in valid_user_ids else ''
|
||||
token = (link.get('token') or '').strip()
|
||||
if not token or token in seen_invite_tokens:
|
||||
token = secrets.token_urlsafe(16)
|
||||
while token in seen_invite_tokens:
|
||||
token = secrets.token_urlsafe(16)
|
||||
link['token'] = token
|
||||
seen_invite_tokens.add(token)
|
||||
|
||||
guest = data['settings'].get('guest')
|
||||
if isinstance(guest, dict):
|
||||
mapped_guest = map_user_id(guest.get('user_id'))
|
||||
if mapped_guest in valid_user_ids:
|
||||
guest['user_id'] = mapped_guest
|
||||
elif guest.get('user_id'):
|
||||
guest['user_id'] = ''
|
||||
|
||||
return data
|
||||
|
||||
|
||||
def _merge_settings(raw: Optional[dict]) -> dict:
|
||||
settings = json.loads(json.dumps(DEFAULT_SETTINGS))
|
||||
if not isinstance(raw, dict):
|
||||
@@ -293,6 +436,7 @@ def load_data() -> dict:
|
||||
def save_data(data: dict) -> None:
|
||||
"""Replace panel state in a single transaction (same semantics as rewriting data.json)."""
|
||||
global _DATA_CACHE
|
||||
data = normalize_import_data(data)
|
||||
init_schema()
|
||||
servers = data.get('servers') or []
|
||||
users = data.get('users') or []
|
||||
@@ -484,12 +628,7 @@ def import_from_json_file(path: str | os.PathLike, *, backup: bool = True) -> bo
|
||||
if not isinstance(data, dict):
|
||||
raise ValueError(f'Invalid data.json: expected object, got {type(data).__name__}')
|
||||
|
||||
data.setdefault('servers', [])
|
||||
data.setdefault('users', [])
|
||||
data.setdefault('user_connections', [])
|
||||
data.setdefault('api_tokens', [])
|
||||
data.setdefault('invite_links', [])
|
||||
data.setdefault('settings', {})
|
||||
data = normalize_import_data(data)
|
||||
|
||||
save_data(data)
|
||||
|
||||
@@ -555,4 +694,8 @@ def ensure_db_ready(legacy_data_file: Optional[str] = None) -> None:
|
||||
init_schema()
|
||||
if legacy_data_file and is_database_empty() and os.path.exists(legacy_data_file):
|
||||
logger.info('Empty database — importing legacy %s', legacy_data_file)
|
||||
import_from_json_file(legacy_data_file)
|
||||
try:
|
||||
import_from_json_file(legacy_data_file)
|
||||
except Exception:
|
||||
logger.exception('Legacy data.json import failed — panel will start with empty DB')
|
||||
invalidate_data_cache()
|
||||
|
||||
@@ -47,6 +47,7 @@ services:
|
||||
labels:
|
||||
- traefik.enable=true
|
||||
- traefik.docker.network=dokploy-network
|
||||
- traefik.http.services.amnezia_panel.loadbalancer.server.port=5000
|
||||
expose:
|
||||
- "5000"
|
||||
healthcheck:
|
||||
|
||||
@@ -1295,6 +1295,45 @@ a:hover {
|
||||
background: var(--bg-card-hover);
|
||||
}
|
||||
|
||||
.conn-select-wrap {
|
||||
flex-shrink: 0;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
.conn-select {
|
||||
width: 16px;
|
||||
height: 16px;
|
||||
accent-color: var(--accent);
|
||||
}
|
||||
|
||||
.connections-bulk-bar {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: space-between;
|
||||
gap: var(--space-md);
|
||||
margin-bottom: var(--space-sm);
|
||||
padding: var(--space-sm) var(--space-md);
|
||||
border: 1px dashed var(--border-color);
|
||||
border-radius: var(--radius-sm);
|
||||
background: var(--bg-secondary);
|
||||
}
|
||||
|
||||
.connections-select-all {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: var(--space-sm);
|
||||
font-size: 0.85rem;
|
||||
color: var(--text-secondary);
|
||||
cursor: pointer;
|
||||
}
|
||||
|
||||
.connections-selected-count {
|
||||
font-size: 0.8rem;
|
||||
color: var(--text-muted);
|
||||
}
|
||||
|
||||
.client-info {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
|
||||
@@ -21,6 +21,7 @@
|
||||
data-username="{{ server.username }}" data-auth="{{ 'key' if server.private_key else 'password' }}"
|
||||
data-ssl-domain="{{ (server.server_info or {}).get('ssl_domain', '') }}"
|
||||
data-ssl-email="{{ (server.server_info or {}).get('ssl_email', '') }}"
|
||||
data-connect-domain="{{ (server.server_info or {}).get('connect_domain', '') }}"
|
||||
draggable="true">
|
||||
<div class="server-meta">
|
||||
<div class="server-icon">{{ icon('server') }}</div>
|
||||
@@ -32,6 +33,10 @@
|
||||
<span class="ping-ms text-muted" id="ping-ms-{{ loop.index0 }}"></span>
|
||||
</div>
|
||||
<div class="server-host">{{ server.host }}:{{ server.ssh_port }}</div>
|
||||
{% set connect_domain = (server.server_info or {}).get('connect_domain') %}
|
||||
{% if connect_domain and connect_domain != server.host %}
|
||||
<div class="server-host text-muted" title="{{ _('server_connect_domain_hint') }}">→ {{ connect_domain }}</div>
|
||||
{% endif %}
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -139,6 +144,12 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="form-group" style="margin-top: var(--space-md)">
|
||||
<label class="form-label">{{ _('server_connect_domain') }}</label>
|
||||
<input class="form-input" type="text" id="editServerConnectDomain" placeholder="vpn.example.com">
|
||||
<div class="form-hint">{{ _('server_connect_domain_hint') }}</div>
|
||||
</div>
|
||||
|
||||
<div class="form-group" style="margin-top: var(--space-md)">
|
||||
<label class="form-label">{{ _('server_ssl_domain') }}</label>
|
||||
<input class="form-input" type="text" id="editServerSslDomain" placeholder="vpn.example.com">
|
||||
@@ -214,6 +225,12 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div class="form-group" style="margin-top: var(--space-md)">
|
||||
<label class="form-label">{{ _('server_connect_domain') }}</label>
|
||||
<input class="form-input" type="text" id="serverConnectDomain" placeholder="vpn.example.com">
|
||||
<div class="form-hint">{{ _('server_connect_domain_hint') }}</div>
|
||||
</div>
|
||||
|
||||
<div class="form-group" style="margin-top: var(--space-md)">
|
||||
<label class="form-label">{{ _('server_ssl_domain') }}</label>
|
||||
<input class="form-input" type="text" id="serverSslDomain" placeholder="vpn.example.com">
|
||||
@@ -268,6 +285,7 @@
|
||||
private_key: document.getElementById('serverKey').value,
|
||||
ssl_domain: document.getElementById('serverSslDomain').value.trim(),
|
||||
ssl_email: document.getElementById('serverSslEmail').value.trim(),
|
||||
connect_domain: document.getElementById('serverConnectDomain').value.trim(),
|
||||
};
|
||||
|
||||
const result = await apiCall('/api/servers/add', 'POST', data);
|
||||
@@ -318,6 +336,7 @@
|
||||
document.getElementById('editServerKey').value = '';
|
||||
document.getElementById('editServerSslDomain').value = card.dataset.sslDomain || '';
|
||||
document.getElementById('editServerSslEmail').value = card.dataset.sslEmail || '';
|
||||
document.getElementById('editServerConnectDomain').value = card.dataset.connectDomain || '';
|
||||
|
||||
// Pre-select the tab matching the server's current auth method.
|
||||
const authIsKey = card.dataset.auth === 'key';
|
||||
@@ -349,6 +368,7 @@
|
||||
private_key: document.getElementById('editServerKey').value || null,
|
||||
ssl_domain: document.getElementById('editServerSslDomain').value.trim(),
|
||||
ssl_email: document.getElementById('editServerSslEmail').value.trim(),
|
||||
connect_domain: document.getElementById('editServerConnectDomain').value.trim(),
|
||||
};
|
||||
await apiCall(`/api/servers/${idx}/edit`, 'POST', body);
|
||||
showToast(_('server_saved'), 'success');
|
||||
|
||||
@@ -155,6 +155,25 @@
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
<div id="connectDomainSection" class="hidden" style="margin-top: var(--space-md);">
|
||||
<div class="divider"></div>
|
||||
<div class="form-group" style="margin-bottom: 0;">
|
||||
<label class="form-label">{{ _('server_connect_domain') }}</label>
|
||||
<div class="flex gap-sm" style="flex-wrap: wrap; align-items: flex-end;">
|
||||
<div style="flex: 0 0 200px; min-width: 160px;">
|
||||
<select class="form-input" id="connectDomainProto" onchange="refreshConnectDomainFields()"></select>
|
||||
</div>
|
||||
<div style="flex: 1; min-width: 200px;">
|
||||
<input class="form-input" type="text" id="connectDomainInput" placeholder="vpn.example.com">
|
||||
</div>
|
||||
<button type="button" class="btn btn-primary btn-sm" id="connectDomainSaveBtn" onclick="saveConnectDomain()">
|
||||
{{ _('save') }}
|
||||
</button>
|
||||
</div>
|
||||
<div class="form-hint" style="margin-top: var(--space-xs);">{{ _('server_connect_domain_awg_hint') }}</div>
|
||||
<div class="text-muted text-sm" id="connectDomainEffective" style="margin-top: var(--space-xs);"></div>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Installed Applications Section -->
|
||||
@@ -544,12 +563,23 @@
|
||||
<option value="telemt">Telemt</option>
|
||||
<option value="wireguard">WireGuard</option>
|
||||
</select>
|
||||
<button type="button" class="btn btn-secondary btn-sm hidden" id="moveConnectionsBtn" onclick="openMoveConnectionsModal()">
|
||||
<span>{{ icon('share') }}</span> {{ _('move_connections') }}
|
||||
</button>
|
||||
<button class="btn btn-primary btn-sm" onclick="openAddConnectionModal()">
|
||||
<span>{{ icon('plus') }}</span> {{ _('add') }}
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<div id="connectionsBulkBar" class="connections-bulk-bar hidden">
|
||||
<label class="connections-select-all">
|
||||
<input type="checkbox" id="connSelectAll" onchange="toggleSelectAllConnections(this.checked)">
|
||||
<span>{{ _('select_all') }}</span>
|
||||
</label>
|
||||
<span class="connections-selected-count" id="connSelectedCount">0</span>
|
||||
</div>
|
||||
|
||||
<div id="connectionsList">
|
||||
<div class="loading-overlay" id="connectionsLoading" style="display:none;">
|
||||
<div class="loading-spinner"></div>
|
||||
@@ -969,6 +999,35 @@
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ===== Move Connections Modal ===== -->
|
||||
<div class="modal-backdrop" id="moveConnectionsModal">
|
||||
<div class="modal" style="max-width: 520px;">
|
||||
<div class="modal-header">
|
||||
<h2 class="modal-title">{{ _('move_connections_title') }}</h2>
|
||||
<button class="modal-close" onclick="closeModal('moveConnectionsModal')">×</button>
|
||||
</div>
|
||||
<p class="form-hint">{{ _('move_connections_hint') }}</p>
|
||||
<div class="form-group">
|
||||
<label class="form-label" for="moveTargetServer">{{ _('move_connections_target') }}</label>
|
||||
<select class="form-select" id="moveTargetServer"></select>
|
||||
</div>
|
||||
<label class="form-check" style="display:flex; align-items:center; gap:var(--space-sm); margin-bottom: var(--space-md);">
|
||||
<input type="checkbox" id="moveDeleteSource" checked>
|
||||
<span>{{ _('move_connections_delete_source') }}</span>
|
||||
</label>
|
||||
<div class="form-hint" style="border-left: 3px solid var(--warning); padding-left: var(--space-sm);">
|
||||
{{ _('move_connections_warning') }}
|
||||
</div>
|
||||
<div class="modal-footer">
|
||||
<button type="button" class="btn btn-secondary" onclick="closeModal('moveConnectionsModal')">{{ _('cancel') }}</button>
|
||||
<button type="button" class="btn btn-primary" onclick="moveSelectedConnections()" id="moveConnectionsSubmitBtn">
|
||||
<span id="moveConnectionsSubmitText">{{ _('move_connections') }}</span>
|
||||
<div class="spinner hidden" id="moveConnectionsSpinner" style="width:14px; height:14px;"></div>
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- ===== Connection Config Modal (with Tabs) ===== -->
|
||||
<div class="modal-backdrop" id="configModal">
|
||||
<div class="modal" style="max-width: 600px;">
|
||||
@@ -1090,7 +1149,9 @@
|
||||
<script src="https://cdnjs.cloudflare.com/ajax/libs/codemirror/5.65.16/mode/htmlmixed/htmlmixed.min.js"></script>
|
||||
<script>
|
||||
const SERVER_ID = {{ server_id }};
|
||||
const ALL_SERVERS = {{ servers_for_move | tojson }};
|
||||
const SERVER_HOST = "{{ server.host }}";
|
||||
const SERVER_CONNECT_DOMAIN = {{ ((server.server_info or {}).get('connect_domain') or '') | tojson }};
|
||||
const SERVER_SSL_DOMAIN = {{ ((server.server_info or {}).get('ssl_domain') or '') | tojson }};
|
||||
const SERVER_SSL_EMAIL = {{ ((server.server_info or {}).get('ssl_email') or '') | tojson }};
|
||||
const MARKETPLACE_APPS = [
|
||||
@@ -1112,6 +1173,8 @@
|
||||
{ id: 'services', icon: 'wrench', titleKey: 'services' },
|
||||
{ id: 'web_servers', icon: 'globe', titleKey: 'web_servers' },
|
||||
];
|
||||
const WG_AWG_BASES = new Set(['awg', 'awg2', 'awg_legacy', 'wireguard']);
|
||||
let connectDomainEffective = {};
|
||||
let currentInstallProto = 'awg';
|
||||
let currentInstallAnother = false;
|
||||
let currentConfig = '';
|
||||
@@ -1171,6 +1234,94 @@
|
||||
return Object.keys(installedProtocols).some(key => protoBase(key) === base && installedProtocols[key]);
|
||||
}
|
||||
|
||||
function hasWgAwgInstalled() {
|
||||
return Object.entries(installedProtocols || {}).some(([key, installed]) => installed && WG_AWG_BASES.has(protoBase(key)));
|
||||
}
|
||||
|
||||
function listInstalledWgAwgProtocols() {
|
||||
const protos = new Set();
|
||||
Object.entries(installedProtocols || {}).forEach(([key, installed]) => {
|
||||
if (installed && WG_AWG_BASES.has(protoBase(key))) protos.add(key);
|
||||
});
|
||||
return Array.from(protos).sort((a, b) => {
|
||||
const ao = MARKETPLACE_APPS.findIndex(app => app.proto === protoBase(a));
|
||||
const bo = MARKETPLACE_APPS.findIndex(app => app.proto === protoBase(b));
|
||||
if (ao !== bo) return ao - bo;
|
||||
return protoInstance(a) - protoInstance(b);
|
||||
});
|
||||
}
|
||||
|
||||
function updateConnectDomainSection() {
|
||||
const section = document.getElementById('connectDomainSection');
|
||||
if (!section) return;
|
||||
const show = hasWgAwgInstalled();
|
||||
section.classList.toggle('hidden', !show);
|
||||
if (!show) return;
|
||||
const select = document.getElementById('connectDomainProto');
|
||||
if (!select) return;
|
||||
const prev = select.value;
|
||||
const installed = listInstalledWgAwgProtocols();
|
||||
select.innerHTML = `<option value="">${_('server_connect_domain_all')}</option>` +
|
||||
installed.map(p => `<option value="${p}">${getProtoTitle(p)}</option>`).join('');
|
||||
if (prev && [...select.options].some(opt => opt.value === prev)) {
|
||||
select.value = prev;
|
||||
}
|
||||
refreshConnectDomainFields();
|
||||
}
|
||||
|
||||
async function refreshConnectDomainFields() {
|
||||
const proto = document.getElementById('connectDomainProto')?.value || '';
|
||||
const input = document.getElementById('connectDomainInput');
|
||||
const eff = document.getElementById('connectDomainEffective');
|
||||
try {
|
||||
const query = proto ? `?protocol=${encodeURIComponent(proto)}` : '';
|
||||
const data = await apiCall(`/api/servers/${SERVER_ID}/connect-domain${query}`, 'GET');
|
||||
connectDomainEffective = data;
|
||||
if (input) {
|
||||
input.value = proto ? (data.protocol_connect_domain || '') : (data.connect_domain || '');
|
||||
}
|
||||
if (eff) {
|
||||
if (data.effective_host && data.effective_host !== data.ssh_host) {
|
||||
eff.textContent = `${_('server_connect_domain_current')}: ${data.effective_host} (${_('server_connect_domain_ssh')}: ${data.ssh_host})`;
|
||||
} else {
|
||||
eff.textContent = `${_('server_connect_domain_current')}: ${data.ssh_host || SERVER_HOST}`;
|
||||
}
|
||||
}
|
||||
Object.entries(currentProtocolStatus || {}).forEach(([p, info]) => {
|
||||
if (WG_AWG_BASES.has(protoBase(p)) && isAppInstalled(info)) {
|
||||
updateProtocolCard(p, info);
|
||||
}
|
||||
});
|
||||
} catch (err) {
|
||||
if (input && !proto) input.value = SERVER_CONNECT_DOMAIN || '';
|
||||
if (eff) eff.textContent = '';
|
||||
}
|
||||
}
|
||||
|
||||
async function saveConnectDomain() {
|
||||
const btn = document.getElementById('connectDomainSaveBtn');
|
||||
const proto = document.getElementById('connectDomainProto')?.value || '';
|
||||
const domain = document.getElementById('connectDomainInput')?.value.trim() || '';
|
||||
if (btn) btn.disabled = true;
|
||||
try {
|
||||
await apiCall(`/api/servers/${SERVER_ID}/connect-domain`, 'POST', {
|
||||
connect_domain: domain,
|
||||
protocol: proto || null,
|
||||
});
|
||||
showToast(_('server_connect_domain_saved'), 'success');
|
||||
await refreshConnectDomainFields();
|
||||
Object.entries(currentProtocolStatus || {}).forEach(([p, info]) => {
|
||||
if (WG_AWG_BASES.has(protoBase(p)) && isAppInstalled(info)) {
|
||||
updateProtocolCard(p, info);
|
||||
}
|
||||
});
|
||||
} catch (err) {
|
||||
showToast(err.message, 'error');
|
||||
} finally {
|
||||
if (btn) btn.disabled = false;
|
||||
}
|
||||
}
|
||||
|
||||
function switchCategory(cat) {
|
||||
if (cat === 'management') {
|
||||
openManagementModal();
|
||||
@@ -1329,6 +1480,7 @@
|
||||
if (empty) empty.classList.toggle('hidden', installedAppsLoading || installedCount > 0);
|
||||
const loading = document.getElementById('installedAppsLoading');
|
||||
if (loading) loading.classList.toggle('hidden', !installedAppsLoading);
|
||||
updateConnectDomainSection();
|
||||
}
|
||||
|
||||
function getProtoTitle(proto) {
|
||||
@@ -1631,6 +1783,12 @@
|
||||
grid = buildServiceInfoGrid(proto, info);
|
||||
} else if (info.port) {
|
||||
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('port')}</span><span class="protocol-info-value">${info.port}/${(['xray', 'telemt', 'naiveproxy'].includes(protoBase(proto))) ? 'TCP' : 'UDP'}</span></div>`;
|
||||
if (WG_AWG_BASES.has(protoBase(proto))) {
|
||||
const endpoint = (connectDomainEffective.effective_host && connectDomainEffective.effective_host !== SERVER_HOST)
|
||||
? connectDomainEffective.effective_host
|
||||
: SERVER_HOST;
|
||||
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('server_endpoint_label')}</span><span class="protocol-info-value">${endpoint}</span></div>`;
|
||||
}
|
||||
if (protoBase(proto) === 'hysteria' && info.domain) {
|
||||
grid += `<div class="protocol-info-item"><span class="protocol-info-label">${_('hysteria_domain')}</span><span class="protocol-info-value">${info.domain}</span></div>`;
|
||||
}
|
||||
@@ -2608,6 +2766,95 @@
|
||||
document.getElementById('connectionsSection').scrollIntoView({ behavior: 'smooth' });
|
||||
}
|
||||
|
||||
const selectedConnectionIds = new Set();
|
||||
|
||||
function updateMoveSelection() {
|
||||
selectedConnectionIds.clear();
|
||||
document.querySelectorAll('.conn-select:checked').forEach((el) => {
|
||||
if (el.dataset.clientId) selectedConnectionIds.add(el.dataset.clientId);
|
||||
});
|
||||
const count = selectedConnectionIds.size;
|
||||
const bulkBar = document.getElementById('connectionsBulkBar');
|
||||
const moveBtn = document.getElementById('moveConnectionsBtn');
|
||||
const countEl = document.getElementById('connSelectedCount');
|
||||
const selectAll = document.getElementById('connSelectAll');
|
||||
const boxes = document.querySelectorAll('.conn-select');
|
||||
if (bulkBar) bulkBar.classList.toggle('hidden', boxes.length === 0);
|
||||
if (moveBtn) moveBtn.classList.toggle('hidden', boxes.length === 0);
|
||||
if (countEl) countEl.textContent = _('connections_selected_count').replace('{}', String(count));
|
||||
if (selectAll) {
|
||||
selectAll.indeterminate = count > 0 && count < boxes.length;
|
||||
selectAll.checked = boxes.length > 0 && count === boxes.length;
|
||||
}
|
||||
}
|
||||
|
||||
function toggleSelectAllConnections(checked) {
|
||||
document.querySelectorAll('.conn-select').forEach((el) => { el.checked = checked; });
|
||||
updateMoveSelection();
|
||||
}
|
||||
|
||||
function openMoveConnectionsModal() {
|
||||
if (!selectedConnectionIds.size) {
|
||||
showToast(_('move_connections_none_selected'), 'error');
|
||||
return;
|
||||
}
|
||||
const select = document.getElementById('moveTargetServer');
|
||||
select.innerHTML = '';
|
||||
(ALL_SERVERS || []).forEach((srv) => {
|
||||
if (srv.id === SERVER_ID) return;
|
||||
const opt = document.createElement('option');
|
||||
opt.value = String(srv.id);
|
||||
opt.textContent = `${srv.name} (${srv.host})`;
|
||||
select.appendChild(opt);
|
||||
});
|
||||
if (!select.options.length) {
|
||||
showToast(_('move_connections_no_targets'), 'error');
|
||||
return;
|
||||
}
|
||||
openModal('moveConnectionsModal');
|
||||
}
|
||||
|
||||
async function moveSelectedConnections() {
|
||||
const targetServerId = parseInt(document.getElementById('moveTargetServer').value, 10);
|
||||
const deleteSource = document.getElementById('moveDeleteSource').checked;
|
||||
const proto = document.getElementById('connProtoSelect').value;
|
||||
const clientIds = Array.from(selectedConnectionIds);
|
||||
if (!clientIds.length || Number.isNaN(targetServerId)) {
|
||||
showToast(_('move_connections_none_selected'), 'error');
|
||||
return;
|
||||
}
|
||||
if (!confirm(_('move_connections_confirm').replace('{}', String(clientIds.length)))) return;
|
||||
|
||||
const btn = document.getElementById('moveConnectionsSubmitBtn');
|
||||
const text = document.getElementById('moveConnectionsSubmitText');
|
||||
const spinner = document.getElementById('moveConnectionsSpinner');
|
||||
btn.disabled = true;
|
||||
spinner.classList.remove('hidden');
|
||||
text.textContent = _('loading');
|
||||
try {
|
||||
const data = await apiCall(`/api/servers/${SERVER_ID}/connections/move`, 'POST', {
|
||||
protocol: proto,
|
||||
target_server_id: targetServerId,
|
||||
client_ids: clientIds,
|
||||
delete_source: deleteSource,
|
||||
});
|
||||
const moved = (data.moved || []).length;
|
||||
const failed = (data.failed || []).length;
|
||||
let msg = _('move_connections_success').replace('{}', String(moved));
|
||||
if (failed) msg += '. ' + _('move_connections_partial_fail').replace('{}', String(failed));
|
||||
showToast(msg, failed && !moved ? 'error' : 'success');
|
||||
closeModal('moveConnectionsModal');
|
||||
selectedConnectionIds.clear();
|
||||
loadConnections();
|
||||
} catch (err) {
|
||||
showToast(_('error') + ': ' + err.message, 'error');
|
||||
} finally {
|
||||
btn.disabled = false;
|
||||
spinner.classList.add('hidden');
|
||||
text.textContent = _('move_connections');
|
||||
}
|
||||
}
|
||||
|
||||
async function loadConnections() {
|
||||
const proto = document.getElementById('connProtoSelect').value;
|
||||
const loading = document.getElementById('connectionsLoading');
|
||||
@@ -2622,11 +2869,14 @@
|
||||
loading.style.display = '';
|
||||
emptyEl.classList.add('hidden');
|
||||
listEl.innerHTML = '';
|
||||
selectedConnectionIds.clear();
|
||||
updateMoveSelection();
|
||||
try {
|
||||
const data = await apiCall(`/api/servers/${SERVER_ID}/connections?protocol=${proto}`);
|
||||
loading.style.display = 'none';
|
||||
if (!data.clients || data.clients.length === 0) {
|
||||
emptyEl.classList.remove('hidden');
|
||||
updateMoveSelection();
|
||||
return;
|
||||
}
|
||||
window.connectionsStore = {};
|
||||
@@ -2670,6 +2920,9 @@
|
||||
|
||||
listEl.innerHTML += `
|
||||
<div class="client-item" style="${disabledStyle}">
|
||||
<label class="conn-select-wrap">
|
||||
<input type="checkbox" class="conn-select" data-client-id="${escapeJs(client.clientId)}" onchange="updateMoveSelection()">
|
||||
</label>
|
||||
<div class="client-info">
|
||||
<div class="client-avatar">${initial}</div>
|
||||
<div>
|
||||
@@ -2686,6 +2939,7 @@
|
||||
</div>
|
||||
`;
|
||||
});
|
||||
updateMoveSelection();
|
||||
} catch (err) {
|
||||
loading.style.display = 'none';
|
||||
showToast(_('connections_load_error') + ': ' + err.message, 'error');
|
||||
|
||||
+10
-3
@@ -604,15 +604,19 @@
|
||||
<div class="card" style="margin-top: var(--space-lg);">
|
||||
<h3 class="card-title" style="margin-bottom: var(--space-lg);">📤 {{ _('backup_title') }}</h3>
|
||||
<div style="display: flex; flex-direction: column; gap: var(--space-md);">
|
||||
<div style="display: flex; gap: var(--space-sm);">
|
||||
<div style="display: flex; gap: var(--space-sm); flex-wrap: wrap;">
|
||||
<a href="/api/settings/backup/download" class="btn btn-secondary"
|
||||
style="flex:1; text-decoration:none; display:flex; align-items:center; justify-content:center; gap:var(--space-sm);">
|
||||
style="flex:1; min-width:200px; text-decoration:none; display:flex; align-items:center; justify-content:center; gap:var(--space-sm);">
|
||||
<span>⬇️</span> {{ _('download_backup') }}
|
||||
</a>
|
||||
<a href="/api/settings/backup/download/json" class="btn btn-secondary"
|
||||
style="flex:1; min-width:200px; text-decoration:none; display:flex; align-items:center; justify-content:center; gap:var(--space-sm);">
|
||||
<span>📄</span> {{ _('download_backup_json') }}
|
||||
</a>
|
||||
</div>
|
||||
<div style="border-top: 1px solid var(--border-color); padding-top: var(--space-md);">
|
||||
<div style="display: flex; flex-direction: column; gap: var(--space-sm);">
|
||||
<input type="file" id="backupFile" accept=".json" style="display: none;"
|
||||
<input type="file" id="backupFile" accept=".sql,.json" style="display: none;"
|
||||
onchange="handleRestore(event)">
|
||||
<button type="button" class="btn btn-secondary"
|
||||
onclick="document.getElementById('backupFile').click()" id="restoreBtn"
|
||||
@@ -623,6 +627,9 @@
|
||||
</div>
|
||||
</div>
|
||||
<p class="form-hint" style="margin-top: var(--space-sm);">
|
||||
{{ _('backup_hint') }}
|
||||
</p>
|
||||
<p class="form-hint" style="margin-top: var(--space-xs);">
|
||||
{{ _('restore_confirm') }}
|
||||
</p>
|
||||
</div>
|
||||
|
||||
+28
-5
@@ -101,6 +101,19 @@
|
||||
"connection_created": "Connection \"{}\" created",
|
||||
"delete_connection_confirm": "Delete this connection? The configuration will stop working.",
|
||||
"connection_deleted": "Connection deleted",
|
||||
"select_all": "Select all",
|
||||
"connections_selected_count": "{} selected",
|
||||
"move_connections": "Move",
|
||||
"move_connections_title": "Move connections to another server",
|
||||
"move_connections_target": "Target server",
|
||||
"move_connections_confirm": "Move {} connection(s) to the selected server? Users will need new configs.",
|
||||
"move_connections_hint": "Recreates selected connections on the target server and updates user assignments.",
|
||||
"move_connections_warning": "Clients get new keys and IPs. Old configs stop working after move.",
|
||||
"move_connections_delete_source": "Remove from current server after move",
|
||||
"move_connections_success": "Moved {} connection(s)",
|
||||
"move_connections_partial_fail": "{} could not be moved",
|
||||
"move_connections_none_selected": "Select at least one connection",
|
||||
"move_connections_no_targets": "No other servers available",
|
||||
"config_tab": "📄 Config",
|
||||
"vpn_key_tab": "🔑 VPN-key",
|
||||
"qr_code_tab": "📱 QR-code",
|
||||
@@ -348,11 +361,13 @@
|
||||
"lang_zh": "中文 (Chinese)",
|
||||
"lang_fa": "فارسی (Persian)",
|
||||
"backup_title": "Simple Backup",
|
||||
"download_backup": "Download data.json",
|
||||
"restore_backup": "Restore from file",
|
||||
"restore_confirm": "Are you sure? Current data will be overwritten and the application will restart.",
|
||||
"download_backup": "Download PostgreSQL dump (.sql)",
|
||||
"download_backup_json": "Export JSON (legacy)",
|
||||
"backup_hint": "Full PostgreSQL database dump of the panel. Use .sql for complete backup; JSON export is compatible with older versions.",
|
||||
"restore_backup": "Restore from .sql or .json",
|
||||
"restore_confirm": "Restore will overwrite all current panel data in the database.",
|
||||
"restore_success": "Restore successful! Restarting...",
|
||||
"invalid_backup_file": "Invalid backup file or structure",
|
||||
"invalid_backup_file": "Invalid backup file (.sql dump or legacy data.json)",
|
||||
"config_unavailable": "Configuration unavailable",
|
||||
"config_unavailable_desc": "This client was created via the native Amnezia app.\\nThe private key is stored only on the user\u0027s device and cannot be recovered by the server.",
|
||||
"client_public_key": "Client public key:",
|
||||
@@ -381,7 +396,15 @@
|
||||
"naiveproxy_client_hint": "Stable build. Do NOT use v2rayN. Confirmed working in Karing. Other clients are untested.",
|
||||
"server_ssl_domain": "SSL domain (default)",
|
||||
"server_ssl_email": "SSL email (default)",
|
||||
"server_ssl_hint": "Used when installing Hysteria / NGINX on this server (Let\u0027s Encrypt).",
|
||||
"server_ssl_hint": "Used when installing Hysteria / NGINX on this server (Let's Encrypt).",
|
||||
"server_connect_domain": "Client connection domain",
|
||||
"server_connect_domain_hint": "Used in VPN configs instead of IP (Endpoint, vless://, etc.). When moving the server, update the DNS A-record — clients keep working.",
|
||||
"server_connect_domain_awg_hint": "Used in AmneziaWG / WireGuard Endpoint instead of server IP. Leave empty to use SSH host IP.",
|
||||
"server_connect_domain_all": "All AWG / WireGuard (default)",
|
||||
"server_connect_domain_current": "Endpoint in configs",
|
||||
"server_connect_domain_ssh": "SSH",
|
||||
"server_connect_domain_saved": "Connection domain saved",
|
||||
"server_endpoint_label": "Endpoint",
|
||||
"container_logs": "Container logs",
|
||||
"logs_btn": "📋 Logs",
|
||||
"logs_live": "Live",
|
||||
|
||||
+21
-4
@@ -100,6 +100,19 @@
|
||||
"connection_created": "اتصال \"{}\" ایجاد شد",
|
||||
"delete_connection_confirm": "این اتصال حذف شود؟ پیکربندی دیگر کار نخواهد کرد.",
|
||||
"connection_deleted": "اتصال حذف شد",
|
||||
"select_all": "انتخاب همه",
|
||||
"connections_selected_count": "{} انتخاب شده",
|
||||
"move_connections": "انتقال",
|
||||
"move_connections_title": "انتقال اتصالها به سرور دیگر",
|
||||
"move_connections_target": "سرور مقصد",
|
||||
"move_connections_confirm": "{} اتصال به سرور انتخابشده منتقل شود؟ کاربران به پیکربندی جدید نیاز دارند.",
|
||||
"move_connections_hint": "اتصالهای انتخابشده روی سرور مقصد دوباره ساخته میشوند و پیوند کاربران حفظ میشود.",
|
||||
"move_connections_warning": "کلیدها و IP جدید صادر میشود. پیکربندیهای قدیمی کار نمیکنند.",
|
||||
"move_connections_delete_source": "پس از انتقال از سرور فعلی حذف شود",
|
||||
"move_connections_success": "{} اتصال منتقل شد",
|
||||
"move_connections_partial_fail": "{} منتقل نشد",
|
||||
"move_connections_none_selected": "حداقل یک اتصال انتخاب کنید",
|
||||
"move_connections_no_targets": "سرور دیگری برای انتقال وجود ندارد",
|
||||
"config_tab": "📄 فایل",
|
||||
"vpn_key_tab": "🔑 کلید-VPN",
|
||||
"qr_code_tab": "📱 کد-QR",
|
||||
@@ -331,11 +344,13 @@
|
||||
"lang_zh": "中文 (Chinese)",
|
||||
"lang_fa": "فارسی (Persian)",
|
||||
"backup_title": "پشتیبانگیری ساده",
|
||||
"download_backup": "دانلود data.json",
|
||||
"restore_backup": "بازیابی از فایل",
|
||||
"restore_confirm": "آیا مطمئن هستید؟ دادههای فعلی بازنویسی میشوند و برنامه دوباره راهاندازی خواهد شد.",
|
||||
"download_backup": "دانلود dump PostgreSQL (.sql)",
|
||||
"download_backup_json": "خروجی JSON (قدیمی)",
|
||||
"backup_hint": "Dump کامل پایگاه داده PostgreSQL پنل. برای پشتیبان کامل از .sql استفاده کنید؛ JSON برای نسخههای قدیمی.",
|
||||
"restore_backup": "بازیابی از .sql یا .json",
|
||||
"restore_confirm": "بازیابی تمام دادههای فعلی پنل در پایگاه داده را بازنویسی میکند.",
|
||||
"restore_success": "بازیابی موفقیتآمیز بود! در حال راهاندازی مجدد...",
|
||||
"invalid_backup_file": "فایل پشتیبان یا ساختار نامعتبر است",
|
||||
"invalid_backup_file": "فایل نامعتبر (dump .sql یا data.json قدیمی)",
|
||||
"config_unavailable": "پیکربندی در دسترس نیست",
|
||||
"config_unavailable_desc": "این کلاینت از طریق اپلیکیشن اصلی Amnezia ایجاد شده است.\\nکلید خصوصی فقط در دستگاه کاربر ذخیره میشود و توسط سرور قابل بازیابی نیست.",
|
||||
"client_public_key": "کلید عمومی کلاینت:",
|
||||
@@ -372,6 +387,8 @@
|
||||
"server_ssl_domain": "دامنه SSL (پیشفرض)",
|
||||
"server_ssl_email": "ایمیل SSL (پیشفرض)",
|
||||
"server_ssl_hint": "هنگام نصب Hysteria / NGINX روی این سرور استفاده میشود (Let\u0027s Encrypt).",
|
||||
"server_connect_domain": "دامنه اتصال کلاینت",
|
||||
"server_connect_domain_hint": "در پیکربندی VPN بهجای IP استفاده میشود. هنگام انتقال سرور، رکورد DNS A را بهروز کنید.",
|
||||
"container_logs": "لاگهای کانتینر",
|
||||
"logs_btn": "📋 Logs",
|
||||
"logs_live": "زنده",
|
||||
|
||||
+21
-4
@@ -100,6 +100,19 @@
|
||||
"connection_created": "Connexion \"{}\" créée",
|
||||
"delete_connection_confirm": "Supprimer cette connexion ? Elle cessera de fonctionner.",
|
||||
"connection_deleted": "Connexion supprimée",
|
||||
"select_all": "Tout sélectionner",
|
||||
"connections_selected_count": "{} sélectionné(s)",
|
||||
"move_connections": "Déplacer",
|
||||
"move_connections_title": "Déplacer les connexions vers un autre serveur",
|
||||
"move_connections_target": "Serveur cible",
|
||||
"move_connections_confirm": "Déplacer {} connexion(s) vers le serveur sélectionné ? Les utilisateurs auront besoin de nouveaux configs.",
|
||||
"move_connections_hint": "Recrée les connexions sur le serveur cible et conserve les affectations utilisateur.",
|
||||
"move_connections_warning": "Les clients reçoivent de nouvelles clés et IP. Les anciens configs cessent de fonctionner.",
|
||||
"move_connections_delete_source": "Supprimer du serveur actuel après le déplacement",
|
||||
"move_connections_success": "{} connexion(s) déplacée(s)",
|
||||
"move_connections_partial_fail": "{} n'ont pas pu être déplacées",
|
||||
"move_connections_none_selected": "Sélectionnez au moins une connexion",
|
||||
"move_connections_no_targets": "Aucun autre serveur disponible",
|
||||
"config_tab": "📄 Config",
|
||||
"vpn_key_tab": "🔑 Clé-VPN",
|
||||
"qr_code_tab": "📱 Code-QR",
|
||||
@@ -331,11 +344,13 @@
|
||||
"lang_zh": "中文 (Chinese)",
|
||||
"lang_fa": "فارسی (Persian)",
|
||||
"backup_title": "Sauvegarde Simple",
|
||||
"download_backup": "Télécharger data.json",
|
||||
"restore_backup": "Restaurer depuis un fichier",
|
||||
"restore_confirm": "Êtes-vous sûr ? Les données actuelles seront écrasées et l\u0027application redémarrera.",
|
||||
"download_backup": "Télécharger le dump PostgreSQL (.sql)",
|
||||
"download_backup_json": "Exporter JSON (ancien)",
|
||||
"backup_hint": "Dump complet de la base PostgreSQL du panneau. Utilisez .sql pour une sauvegarde complète ; JSON pour l'ancien format.",
|
||||
"restore_backup": "Restaurer depuis .sql ou .json",
|
||||
"restore_confirm": "La restauration écrasera toutes les données actuelles du panneau dans la base.",
|
||||
"restore_success": "Restauration réussie ! Redémarrage...",
|
||||
"invalid_backup_file": "Fichier de sauvegarde ou structure invalide",
|
||||
"invalid_backup_file": "Fichier invalide (dump .sql ou ancien data.json)",
|
||||
"config_unavailable": "Configuration indisponible",
|
||||
"config_unavailable_desc": "Ce client a été créé via l\u0027application native Amnezia.\\nLa clé privée est stockée uniquement sur l\u0027appareil de l\u0027utilisateur et ne peut pas être récupérée par le serveur.",
|
||||
"client_public_key": "Clé publique du client :",
|
||||
@@ -372,6 +387,8 @@
|
||||
"server_ssl_domain": "Domaine SSL (par défaut)",
|
||||
"server_ssl_email": "Email SSL (par défaut)",
|
||||
"server_ssl_hint": "Utilisé lors de l\u0027installation de Hysteria / NGINX sur ce serveur (Let\u0027s Encrypt).",
|
||||
"server_connect_domain": "Domaine de connexion client",
|
||||
"server_connect_domain_hint": "Utilisé dans les configs VPN à la place de l\u0027IP. Lors d\u0027un déplacement du serveur, mettez à jour l\u0027enregistrement DNS A.",
|
||||
"container_logs": "Logs du conteneur",
|
||||
"logs_btn": "📋 Logs",
|
||||
"logs_live": "Temps réel",
|
||||
|
||||
+28
-5
@@ -101,6 +101,19 @@
|
||||
"connection_created": "Подключение \"{}\" создано",
|
||||
"delete_connection_confirm": "Удалить это подключение? Конфигурация перестанет работать.",
|
||||
"connection_deleted": "Подключение удалено",
|
||||
"select_all": "Выбрать все",
|
||||
"connections_selected_count": "Выбрано: {}",
|
||||
"move_connections": "Перенести",
|
||||
"move_connections_title": "Перенос подключений на другой сервер",
|
||||
"move_connections_target": "Целевой сервер",
|
||||
"move_connections_confirm": "Перенести {} подключение(й) на выбранный сервер? Пользователям понадобятся новые конфиги.",
|
||||
"move_connections_hint": "Подключения будут созданы заново на целевом сервере, привязки к пользователям сохранятся.",
|
||||
"move_connections_warning": "У клиентов будут новые ключи и IP. Старые конфиги перестанут работать.",
|
||||
"move_connections_delete_source": "Удалить с текущего сервера после переноса",
|
||||
"move_connections_success": "Перенесено подключений: {}",
|
||||
"move_connections_partial_fail": "Не удалось перенести: {}",
|
||||
"move_connections_none_selected": "Выберите хотя бы одно подключение",
|
||||
"move_connections_no_targets": "Нет других серверов для переноса",
|
||||
"config_tab": "📄 Конфиг",
|
||||
"vpn_key_tab": "🔑 VPN-ключ",
|
||||
"qr_code_tab": "📱 QR-код",
|
||||
@@ -348,11 +361,13 @@
|
||||
"lang_zh": "中文 (Chinese)",
|
||||
"lang_fa": "فارسی (Persian)",
|
||||
"backup_title": "Резервное копирование",
|
||||
"download_backup": "Скачать data.json",
|
||||
"restore_backup": "Восстановить из файла",
|
||||
"restore_confirm": "Вы уверены? Текущие данные будут перезаписаны, и приложение перезагрузится.",
|
||||
"download_backup": "Скачать дамп PostgreSQL (.sql)",
|
||||
"download_backup_json": "Экспорт JSON (устар.)",
|
||||
"backup_hint": "Полный дамп базы данных панели. Для бэкапа используйте .sql; JSON — для совместимости со старыми версиями.",
|
||||
"restore_backup": "Восстановить из .sql или .json",
|
||||
"restore_confirm": "Восстановление перезапишет все текущие данные панели в базе.",
|
||||
"restore_success": "Восстановление успешно! Перезагрузка...",
|
||||
"invalid_backup_file": "Неверный файл резервной копии или структура",
|
||||
"invalid_backup_file": "Неверный файл (.sql дамп или устаревший data.json)",
|
||||
"config_unavailable": "Конфигурация недоступна",
|
||||
"config_unavailable_desc": "Этот клиент был создан через нативное приложение Amnezia.\\nПриватный ключ хранится только на устройстве пользователя и не может быть восстановлен сервером.",
|
||||
"client_public_key": "Публичный ключ клиента:",
|
||||
@@ -381,7 +396,15 @@
|
||||
"naiveproxy_client_hint": "Стабильная версия. НЕ используйте v2rayN. Точно работает в Karing. Остальные клиенты под вопросом.",
|
||||
"server_ssl_domain": "SSL-домен (по умолчанию)",
|
||||
"server_ssl_email": "SSL-email (по умолчанию)",
|
||||
"server_ssl_hint": "Подставляется при установке Hysteria / NGINX на этом сервере (Let\u0027s Encrypt).",
|
||||
"server_ssl_hint": "Подставляется при установке Hysteria / NGINX на этом сервере (Let's Encrypt).",
|
||||
"server_connect_domain": "Домен для подключения клиентов",
|
||||
"server_connect_domain_hint": "Подставляется в конфиги VPN вместо IP (Endpoint, vless:// и т.д.). При переносе сервера достаточно обновить A-запись DNS — клиенты продолжат работать.",
|
||||
"server_connect_domain_awg_hint": "Подставляется в Endpoint конфигов AmneziaWG / WireGuard вместо IP сервера. Пусто — использовать IP из SSH.",
|
||||
"server_connect_domain_all": "Все AWG / WireGuard (по умолчанию)",
|
||||
"server_connect_domain_current": "Endpoint в конфигах",
|
||||
"server_connect_domain_ssh": "SSH",
|
||||
"server_connect_domain_saved": "Домен подключения сохранён",
|
||||
"server_endpoint_label": "Endpoint",
|
||||
"container_logs": "Логи контейнера",
|
||||
"logs_btn": "📋 Логи",
|
||||
"logs_live": "В реальном времени",
|
||||
|
||||
+21
-4
@@ -100,6 +100,19 @@
|
||||
"connection_created": "连接 \"{}\" 已创建",
|
||||
"delete_connection_confirm": "确定删除此连接?配置将失效。",
|
||||
"connection_deleted": "连接已删除",
|
||||
"select_all": "全选",
|
||||
"connections_selected_count": "已选 {}",
|
||||
"move_connections": "迁移",
|
||||
"move_connections_title": "将连接迁移到另一台服务器",
|
||||
"move_connections_target": "目标服务器",
|
||||
"move_connections_confirm": "将 {} 个连接迁移到所选服务器?用户需要新的配置。",
|
||||
"move_connections_hint": "在目标服务器上重新创建所选连接,并保留用户绑定。",
|
||||
"move_connections_warning": "客户端将获得新密钥和 IP,旧配置将失效。",
|
||||
"move_connections_delete_source": "迁移后从当前服务器删除",
|
||||
"move_connections_success": "已迁移 {} 个连接",
|
||||
"move_connections_partial_fail": "{} 个无法迁移",
|
||||
"move_connections_none_selected": "请至少选择一个连接",
|
||||
"move_connections_no_targets": "没有其他可用服务器",
|
||||
"config_tab": "📄 配置文件",
|
||||
"vpn_key_tab": "🔑 VPN 密钥",
|
||||
"qr_code_tab": "📱 二维码",
|
||||
@@ -331,11 +344,13 @@
|
||||
"lang_zh": "中文 (Chinese)",
|
||||
"lang_fa": "فارسی (Persian)",
|
||||
"backup_title": "简易备份",
|
||||
"download_backup": "下载 data.json",
|
||||
"restore_backup": "从文件恢复",
|
||||
"restore_confirm": "您确定吗?当前数据将被覆盖,应用程序将重新启动。",
|
||||
"download_backup": "下载 PostgreSQL 转储 (.sql)",
|
||||
"download_backup_json": "导出 JSON(旧版)",
|
||||
"backup_hint": "面板 PostgreSQL 数据库的完整转储。请使用 .sql 进行完整备份;JSON 用于兼容旧版本。",
|
||||
"restore_backup": "从 .sql 或 .json 恢复",
|
||||
"restore_confirm": "恢复将覆盖数据库中所有当前面板数据。",
|
||||
"restore_success": "恢复成功!正在重启...",
|
||||
"invalid_backup_file": "备份文件无效或结构错误",
|
||||
"invalid_backup_file": "无效的备份文件(.sql 转储或旧版 data.json)",
|
||||
"config_unavailable": "配置文件不可用",
|
||||
"config_unavailable_desc": "此客户端是通过 Amnezia 原生应用创建的。\\n私钥仅存储在用户设备上,服务器无法恢复。",
|
||||
"client_public_key": "客户端公钥:",
|
||||
@@ -372,6 +387,8 @@
|
||||
"server_ssl_domain": "SSL 域名(默认)",
|
||||
"server_ssl_email": "SSL 邮箱(默认)",
|
||||
"server_ssl_hint": "安装 Hysteria / NGINX 时自动填入(Let\u0027s Encrypt)。",
|
||||
"server_connect_domain": "客户端连接域名",
|
||||
"server_connect_domain_hint": "在 VPN 配置中替代 IP 使用。迁移服务器时只需更新 DNS A 记录。",
|
||||
"container_logs": "容器日志",
|
||||
"logs_btn": "📋 日志",
|
||||
"logs_live": "实时",
|
||||
|
||||
Reference in New Issue
Block a user