Compare commits

...

35 Commits

Author SHA1 Message Date
mercury 95c5b5b8fd update version 2024-12-26 18:29:55 +04:00
mercury efbe20485a ability to change subdomain for naiveproxy 2024-12-26 18:28:24 +04:00
mercury 475eea1f47 ability to change subdomain for openconnect 2024-12-26 18:12:42 +04:00
mercury 02d9cdcccc improve update script 2024-12-26 16:59:06 +04:00
mercury d633799f11 update version 2024-12-26 16:26:34 +04:00
Konstantin ead66c3951 Merge pull request #29 from legiz-ru/dev
sb1.10+tun-inbound + sb-win64-1.10.5
2024-12-26 09:46:35 +04:00
legiz-ru bd7742d8b2 update tun inbound (changes in sb 1.10+)
change inet4_address to address

https://sing-box.sagernet.org/migration/#tun-address-fields-are-merged
2024-12-24 16:32:07 +03:00
legiz-ru ac593629a8 update singbox 1.10.5 windows x64 2024-12-24 16:24:58 +03:00
mercury 9932ee1e00 update version 2024-12-22 18:48:13 +04:00
mercury 1a6e9f43e8 show branch 2024-12-22 18:25:54 +04:00
mercury 76373ffcf2 fix first start nginx 2024-12-22 16:57:27 +04:00
mercury 43c59a9ed6 cloak main 2024-12-22 16:24:42 +04:00
mercury 8b3c6ca547 cloak static 2024-12-22 15:32:27 +04:00
mercury 63654e7ad7 cloak donate 2024-12-22 15:23:58 +04:00
mercury dcb4f72f07 fix cloak DoT 2024-12-22 15:16:35 +04:00
mercury 90afbbedb0 cloak DoH 2024-12-22 15:04:19 +04:00
mercury 1964ed0079 fix adguard 2024-12-22 14:58:02 +04:00
mercury 2525181655 fix nginx 2024-12-22 14:39:58 +04:00
mercury ef690349fd fix change transport xray 2024-12-22 14:33:00 +04:00
mercury 2c1db5f233 cloak xray 2024-12-22 13:32:01 +04:00
mercury 554d7f3a25 fix cloak nginx 2024-12-21 20:39:17 +04:00
mercury f2a1ec1b71 cloak nginx 2024-12-21 20:12:21 +04:00
mercury 04f1bf564c cloak for np/oc subdomain 2024-12-21 01:09:17 +04:00
mercury 1116f8ec75 delete backup shadowsocks 2024-12-21 01:04:18 +04:00
mercury f8e5b54a98 fix tlgrm handle 2024-12-20 03:25:35 +04:00
mercury 3929032e7a fix add domain and ssl 2024-12-20 02:46:09 +04:00
mercury 057917a24a delete x-powered-by php 2024-12-20 01:12:21 +04:00
mercury 941fc05e21 fix tlgrm location 2024-12-20 00:57:21 +04:00
mercury 797088a328 improve nginx config 2024-12-20 00:52:49 +04:00
mercury 45614eaf3b delete shadowsocks 2024-12-20 00:21:55 +04:00
mercury 47113b4940 hide ports 2024-12-19 23:42:27 +04:00
mercury 3febfe1d3d Merge branch 'dev' into stealth 2024-12-19 20:38:41 +04:00
mercury b3366edb6e Merge branch 'dev' into stealth 2024-11-14 02:36:55 +04:00
mercury 1edc9e8608 fix input timer autoscan 2024-11-14 02:32:03 +04:00
mercury 8a3d9c1007 server headers off 2024-11-14 01:44:31 +04:00
16 changed files with 900 additions and 1072 deletions
+373 -358
View File
File diff suppressed because it is too large Load Diff
+3 -3
View File
@@ -2,8 +2,8 @@
$i = [
'warp' => [
'en' => 'warp',
'ru' => 'warp',
'en' => 'Warp',
'ru' => 'Warp',
],
'wg_title' => [
'en' => 'Wireguard',
@@ -22,7 +22,7 @@ $i = [
'ru' => 'AdGuard',
],
'config' => [
'en' => 'config',
'en' => 'Settings',
'ru' => 'настройки',
],
'pac' => [
+131 -137
View File
@@ -1,129 +1,18 @@
<?php
require __DIR__ . '/timezone.php';
// bot
require __DIR__ . '/config.php';
if ('POST' == $_SERVER['REQUEST_METHOD'] && $_GET['k'] == $c['key']) {
if ($c['debug']) {
require __DIR__ . '/debug.php';
}
require __DIR__ . '/calc.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
if (file_exists(__DIR__ . '/override.php')) {
include __DIR__ . '/override.php';
}
$bot = new Bot($c['key'], $i);
$bot->input();
exit;
if ($c['debug']) {
require __DIR__ . '/debug.php';
}
// pac
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
$_GET = array_merge($_GET, $t);
}
$type = $_GET['t'] ?? 'pac';
$address = $_GET['a'] ?: '127.0.0.1';
$port = $_GET['p'] ?: '1080';
$hash = $_GET['h'];
if ($hash == substr(md5($c['key']), 0, 8)) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
switch ($type) {
case 'mirror':
$bot->getMirror();
break;
case 's':
case 'si':
case 'cl':
$bot->subscription();
exit;
case 'te':
if (!empty($_GET['te'])) {
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
} else {
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
}
if ($t) {
header('Content-Type: text/html');
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
$name = $_GET['te'] ?: 'origin';
$type = $_GET['ty'];
echo <<<HTML
<!DOCTYPE HTML>
<html lang="en" style="height:100%">
<head>
<!-- when using the mode "code", it's important to specify charset utf-8 -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link href="jsoneditor.min.css" rel="stylesheet" type="text/css">
<script src="jsoneditor.min.js"></script>
<script src="jquery-3.7.1.min.js"></script>
<script src="https://telegram.org/js/telegram-web-app.js"></script>
</head>
<body style="height:100%">
<div id="jsoneditor" style="height:100%"></div>
<script>
jQuery(function($) {
var tg = window.Telegram.WebApp;
// create the editor
const container = document.getElementById("jsoneditor")
const options = {}
const editor = new JSONEditor(container, options)
editor.set({$t})
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
var self = this;
$.ajax({
url: '/webapp/save?' + tg.initData,
method: 'POST',
data: {
name: '$name',
type: '$type',
json: editor.getText()
},
dataType: 'json'
}).done(function (r) {
if (r.status == true) {
tg.MainButton.setText('{$bot->i18n('success')}')
setTimeout(() => {
tg.close();
}, 500);
} else {
tg.MainButton.setText(r.message);
}
}).fail(function (r) {
tg.MainButton.setText('{$bot->i18n('error')}')
});
});
});
</script>
</body>
</html>
HTML;
exit;
}
default:
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
$pac = file_get_contents($file);
header('Content-Type: text/plain');
echo str_replace([
'~address~',
'~port~',
], [
$address,
$port,
], $pac);
exit;
}
break;
}
require __DIR__ . '/calc.php';
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
if (file_exists(__DIR__ . '/override.php')) {
include __DIR__ . '/override.php';
}
$bot = new Bot($c['key'], $i);
$hash = $bot->getHashBot();
if (!empty($_GET['hash'])) {
$t = $_GET;
unset($t['hash']);
@@ -131,22 +20,127 @@ if (!empty($_GET['hash'])) {
foreach ($t as $k => $v) {
$s[] = "$k=$v";
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
if (hash_hmac('sha256', $s, $sk) == $_GET['hash']) {
require __DIR__ . '/bot.php';
require __DIR__ . '/i18n.php';
$bot = new Bot($c['key'], $i);
if (!empty($_POST['json'])) {
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
die();
} else {
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
setcookie('a', $bot->adguardBasicAuth(), 0, '/');
}
die('ok');
}
$s = implode("\n", $s);
$sk = hash_hmac('sha256', $c['key'], "WebAppData", true);
$webapp = hash_hmac('sha256', $s, $sk) == $_GET['hash'];
}
header('500', true, 500);
exit;
switch (true) {
// tlgrm
case 'POST' == $_SERVER['REQUEST_METHOD'] && preg_match('~^/tlgrm~', $_SERVER['REQUEST_URI']) && $_GET['k'] == $c['key']:
$bot->input();
break;
// save template
case preg_match('~^' . preg_quote("/webapp$hash/save") . '~', $_SERVER['REQUEST_URI']) && $webapp && !empty($_POST['json']):
echo json_encode($bot->saveTemplate($_POST['name'], $_POST['type'], $_POST['json']));
break;
// adguard cookie
case preg_match('~^' . preg_quote("/webapp$hash/check") . '~', $_SERVER['REQUEST_URI']) && $webapp:
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
echo "/adguard$hash/";
break;
// subs & pac
case preg_match('~^' . preg_quote("/pac$hash") . '~', $_SERVER['REQUEST_URI']):
if (!empty($t = unserialize(base64_decode(explode('/', $_SERVER['REQUEST_URI'])[2])))) { // fix sing-box import
$_GET = array_merge($_GET, $t);
}
$type = $_GET['t'] ?? 'pac';
$address = $_GET['a'] ?: '127.0.0.1';
$port = $_GET['p'] ?: '1080';
switch ($type) {
case 's':
case 'si':
case 'cl':
$bot->subscription();
exit;
case 'te':
if (!empty($_GET['te'])) {
$t = $bot->getPacConf()["{$_GET['ty']}templates"][$_GET['te']];
} else {
$t = json_decode(file_get_contents("/config/{$_GET['ty']}.json"), true);
}
if ($t) {
header('Content-Type: text/html');
$t = json_encode($t, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES);
$name = $_GET['te'] ?: 'origin';
$type = $_GET['ty'];
echo <<<HTML
<!DOCTYPE HTML>
<html lang="en" style="height:100%">
<head>
<!-- when using the mode "code", it's important to specify charset utf-8 -->
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<link href="/webapp$hash/jsoneditor.min.css" rel="stylesheet" type="text/css">
<script src="/webapp$hash/jsoneditor.min.js"></script>
<script src="/webapp$hash/jquery-3.7.1.min.js"></script>
<script src="https://telegram.org/js/telegram-web-app.js"></script>
</head>
<body style="height:100%">
<div id="jsoneditor" style="height:100%"></div>
<script>
jQuery(function($) {
var tg = window.Telegram.WebApp;
// create the editor
const container = document.getElementById("jsoneditor")
const options = {}
const editor = new JSONEditor(container, options)
editor.set({$t})
tg.MainButton.show().setText('{$bot->i18n('save')}').onClick(function (e) {
var self = this;
$.ajax({
url: '/webapp$hash/save?' + tg.initData,
method: 'POST',
data: {
name: '$name',
type: '$type',
json: editor.getText()
},
dataType: 'json'
}).done(function (r) {
if (r.status == true) {
tg.MainButton.setText('{$bot->i18n('success')}')
setTimeout(() => {
tg.close();
}, 500);
} else {
tg.MainButton.setText(r.message);
}
}).fail(function (r) {
tg.MainButton.setText('{$bot->i18n('error')}')
});
});
});
</script>
</body>
</html>
HTML;
exit;
}
default:
if (file_exists($file = __DIR__ . "/zapretlists/$type")) {
$pac = file_get_contents($file);
header('Content-Type: text/plain');
echo str_replace([
'~address~',
'~port~',
], [
$address,
$port,
], $pac);
exit;
}
break;
}
break;
default:
header('500', true, 500);
}
+1 -1
View File
@@ -13,7 +13,6 @@ if ($c['debug']) {
$bot = new Bot($c['key'], $i);
$bot->selfUpdate();
$bot->ssPswdCheck();
$bot->restartTG();
if (!empty($bot->selfupdate)) {
$bot->offWarp();
@@ -21,5 +20,6 @@ if (!empty($bot->selfupdate)) {
$bot->dontshowcron = 1;
$bot->sslip();
$bot->adguardSync();
$bot->cloakNginx();
$bot->syncDeny();
$bot->cleanDocker();
+1 -1
View File
@@ -14,7 +14,7 @@
$.ajax({
'url': 'check?' + tg.initData,
}).done(function (r) {
location.replace('/adguard/');
location.replace(r);
}).fail(function (r) {
location.replace('/');
});
-117
View File
@@ -1,117 +0,0 @@
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<meta name="viewport" content="width=device-width, initial-scale=1.0">
<title>Login</title>
<style>
/* Design based on Blue Login Field of Kevin Sleger https://codepen.io/MurmeltierS/pen/macKb */
body {
background: #44c4e7 url("https://photos-6.dropbox.com/t/2/AAC_bdqR8LMkjEe-HPIf4K1DhtseMLRHPklBSzJSuzglvA/12/5714737/jpeg/1024x768/3/1418346000/0/2/bkg-blur.jpg/CLHm3AIgASgBKAI/b7RrveA2022yJyfO9RyRvv7LjJQESukGHssHUxVThzw") no-repeat center center fixed;
background-size: cover;
font-family: "Roboto";
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
&::before {
z-index: -1;
content: '';
position: fixed;
top: 0;
left: 0;
background: #44c4e7;
/* IE Fallback */
background: rgba(68, 196, 231, 0.8);
width: 100%;
height: 100%;
}
}
.form {
position: absolute;
top: 50%;
left: 50%;
background: #fff;
width: 285px;
margin: -140px 0 0 -182px;
padding: 40px;
box-shadow: 0 0 3px rgba(0, 0, 0, 0.3);
h2 {
margin: 0 0 20px;
line-height: 1;
color: #44c4e7;
font-size: 18px;
font-weight: 400;
}
input {
outline: none;
display: block;
width: 100%;
margin: 0 0 20px;
padding: 10px 15px;
border: 1px solid #ccc;
color: #ccc;
font-family: "Roboto";
box-sizing: border-box;
font-size: 14px;
font-wieght: 400;
-webkit-font-smoothing: antialiased;
-moz-osx-font-smoothing: grayscale;
transition: 0.2s linear;
&input:focus {
color: #333;
border: 1px solid #44c4e7;
}
}
button {
cursor: pointer;
background: #44c4e7;
width: 100%;
padding: 10px 15px;
border: 0;
color: #fff;
font-family: "Roboto";
font-size: 14px;
font-weight: 400;
&:hover {
background: #369cb8;
}
}
}
.error,
.valid {
display: none;
}
</style>
<script src="jquery-3.7.1.min.js"></script>
</head>
<body>
<section class="form animated flipInX">
<h2>Login To Your Account</h2>
<p class="valid">Valid. Please wait a moment.</p>
<p class="error">Error. Please enter correct Username &amp; password.</p>
<form class="loginbox" autocomplete="off">
<input placeholder="Username" type="text" id="username"></input>
<input placeholder="Password" type="password" id="password"></input>
<button id="submit">Login</button>
</form>
</section>
<script>
$(document).ready(function() {
$('#submit').click(function () {
event.preventDefault(); // prevent PageReLoad
$('.error').css('display', 'block'); // show error msg
});
});
</script>
</body>
</html>
+170 -176
View File
@@ -1,197 +1,191 @@
user nginx;
worker_processes auto;
user nginx;
worker_processes auto;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
worker_connections 1024;
}
http {
server_names_hash_bucket_size 64;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
server_names_hash_bucket_size 64;
server_tokens off;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
server {
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
server {
listen 80 default_server;
access_log /logs/nginx_default_access;
location / {
root /app;
index override.html login.html;
try_files $uri $uri/ =404;
location / {
return 301 https://$host$request_uri;
}
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
proxy_pass http://ad:80/;
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
server {
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
listen 10.10.1.2:443 ssl http2 default_server;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_ip_access;
location = / {
root /app;
try_files $uri /override.html @auth;
}
location / {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location @auth {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location @php {
proxy_pass http://php;
}
location /adguard/ {
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ @php;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
location /dns-query {
access_log /logs/nginx_doh_access;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Host $remote_addr;
proxy_cache doh_cache;
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
proxy_pass https://ad/dns-query;
}
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location /v2ray {
access_log /logs/nginx_v2ray_access;
proxy_redirect off;
proxy_buffering off;
proxy_http_version 1.1;
proxy_pass http://ss:8388/;
proxy_set_header Host $http_host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
#~
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
#-domain
# server {
# server_name domain;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#~
# access_log /logs/nginx_domain_access;
#-domain
# server {
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
# location = / {
# root /app;
# try_files $uri /override.html @auth;
# }
#-domain
# access_log /logs/nginx_domain_access;
# location / {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location @auth {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location / {
# root /app;
# index override.html login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
# proxy_pass http://ad:80/;
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location ~\.well-known {
# access_log /logs/nginx_certbot_access;
# root /certs/;
# try_files $uri =404;
# }
# location /v2ray {
# access_log /logs/nginx_v2ray_access;
# proxy_redirect off;
# proxy_buffering off;
# proxy_http_version 1.1;
# proxy_pass http://ss:8388/;
# proxy_set_header Host $http_host;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
#-domain
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# location @php {
# proxy_pass http://php;
# }
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# location /adguard/ {
# }
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
#-domain
# }
#-domain
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ @php;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
# location /dns-query {
# access_log /logs/nginx_doh_access;
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# proxy_pass https://ad/dns-query;
# }
# }
#-domain
}
+170 -176
View File
@@ -1,197 +1,191 @@
user nginx;
worker_processes auto;
user nginx;
worker_processes auto;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
error_log /logs/nginx_error;
pid /var/run/nginx.pid;
events {
worker_connections 1024;
worker_connections 1024;
}
http {
server_names_hash_bucket_size 64;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
server_names_hash_bucket_size 64;
server_tokens off;
include include.conf;
include /etc/nginx/mime.types;
default_type application/octet-stream;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
# Proxy Cache storage - so we can cache the DoH response from the upstream
proxy_cache_path /var/cache/nginx/doh_cache levels=1:2 keys_zone=doh_cache:10m;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
real_ip_header proxy_protocol;
real_ip_recursive on;
set_real_ip_from 10.10.0.10;
server {
listen 10.10.0.2:80 default_server;
listen 10.10.0.2:443 ssl http2 default_server proxy_protocol;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
server {
listen 80 default_server;
access_log /logs/nginx_default_access;
location / {
root /app;
index override.html login.html;
try_files $uri $uri/ =404;
location / {
return 301 https://$host$request_uri;
}
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
location /adguard/ {
access_log /logs/nginx_adguard_access;
proxy_pass http://ad:80/;
proxy_redirect / /adguard/;
proxy_cookie_path / /adguard/;
server {
listen 10.10.0.2:443 ssl http2 proxy_protocol default_server;
listen 10.10.1.2:443 ssl http2 default_server;
ssl_certificate /certs/self_public;
ssl_certificate_key /certs/self_private;
access_log /logs/nginx_ip_access;
location = / {
root /app;
try_files $uri /override.html @auth;
}
location / {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location @auth {
root /app;
auth_basic "Restricted Content";
auth_basic_user_file /app/.htpasswd;
try_files $uri =404;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location @php {
proxy_pass http://php;
}
location /adguard/ {
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ @php;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
location /dns-query {
access_log /logs/nginx_doh_access;
proxy_http_version 1.1;
proxy_set_header Connection "";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-Proto https;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header X-Forwarded-Host $remote_addr;
proxy_cache doh_cache;
proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
proxy_pass https://ad/dns-query;
}
}
location /webapp {
access_log /logs/nginx_webapp_access;
alias /app;
index index.html;
try_files $uri $uri/ /pac?$query_string;
}
location /pac {
access_log /logs/nginx_pac_access;
proxy_set_header Host $http_host;
proxy_pass http://php;
}
location /tlgrm {
access_log /logs/nginx_tlgrm_access;
proxy_pass http://php;
}
location /v2ray {
access_log /logs/nginx_v2ray_access;
proxy_redirect off;
proxy_buffering off;
proxy_http_version 1.1;
proxy_pass http://ss:8388/;
proxy_set_header Host $http_host;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
}
location /ws {
proxy_pass http://xr:443;
proxy_redirect off;
proxy_http_version 1.1;
proxy_set_header Upgrade $http_upgrade;
proxy_set_header Connection "upgrade";
proxy_set_header Host $host;
proxy_set_header X-Real-IP $remote_addr;
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
proxy_read_timeout 5d;
}
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
#~
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
location ~\.well-known {
access_log /logs/nginx_certbot_access;
root /certs/;
try_files $uri =404;
}
}
#-domain
# server {
# server_name domain;
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#~
# access_log /logs/nginx_domain_access;
#-domain
# server {
# listen 10.10.0.2:80;
# server_name ;
#-domain
#-ssl
# listen 10.10.0.2:443 ssl http2 proxy_protocol;
# listen 10.10.1.2:443 ssl http2;
# ssl_certificate /certs/cert_public;
# ssl_certificate_key /certs/cert_private;
#-ssl
# location = / {
# root /app;
# try_files $uri /override.html @auth;
# }
#-domain
# access_log /logs/nginx_domain_access;
# location / {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location @auth {
# root /app;
# auth_basic "Restricted Content";
# auth_basic_user_file /app/.htpasswd;
# try_files $uri =404;
# }
# location / {
# root /app;
# index override.html login.html;
# try_files $uri $uri/ =404;
# }
# location /adguard/ {
# access_log /logs/nginx_adguard_access;
# proxy_pass http://ad:80/;
# proxy_redirect / /adguard/;
# proxy_cookie_path / /adguard/;
# }
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ /pac?$query_string;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location ~\.well-known {
# access_log /logs/nginx_certbot_access;
# root /certs/;
# try_files $uri =404;
# }
# location /v2ray {
# access_log /logs/nginx_v2ray_access;
# proxy_redirect off;
# proxy_buffering off;
# proxy_http_version 1.1;
# proxy_pass http://ss:8388/;
# proxy_set_header Host $http_host;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
#-domain
#-ssl
# # The DoH server block
# location /dns-query {
# access_log /logs/nginx_doh_access;
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# location @php {
# proxy_pass http://php;
# }
# # Enable Cache, and set the cache_key to include the request_body
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# location /adguard/ {
# }
# # proxy pass to the dohloop upstream
# proxy_pass https://ad/dns-query;
# }
#-ssl
#-domain
# }
#-domain
# location /webapp {
# access_log /logs/nginx_webapp_access;
# alias /app;
# index index.html;
# try_files $uri $uri/ @php;
# }
# location /pac {
# access_log /logs/nginx_pac_access;
# proxy_set_header Host $http_host;
# proxy_pass http://php;
# }
# location /ws {
# proxy_pass http://xr:443;
# proxy_redirect off;
# proxy_http_version 1.1;
# proxy_set_header Upgrade $http_upgrade;
# proxy_set_header Connection "upgrade";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
# proxy_read_timeout 5d;
# }
# location /dns-query {
# access_log /logs/nginx_doh_access;
# proxy_http_version 1.1;
# proxy_set_header Connection "";
# proxy_set_header Host $host;
# proxy_set_header X-Real-IP $remote_addr;
# proxy_set_header X-Forwarded-Proto https;
# proxy_set_header X-Forwarded-For $remote_addr;
# proxy_set_header X-Forwarded-Host $remote_addr;
# proxy_cache doh_cache;
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
# proxy_pass https://ad/dns-query;
# }
# }
#-domain
}
+1 -3
View File
@@ -397,7 +397,7 @@ zend.exception_string_param_max_len = 0
; threat in any way, but it makes it possible to determine whether you use PHP
; on your server or not.
; https://php.net/expose-php
expose_php = On
expose_php = Off
;;;;;;;;;;;;;;;;;;;
; Resource Limits ;
@@ -1955,5 +1955,3 @@ opcache.enable=1
opcache.jit_buffer_size=128M
opcache.enable_cli=1
pcre.jit=1
+6 -2
View File
@@ -9,7 +9,7 @@
"tag": "tun-in",
"domain_strategy": "prefer_ipv4",
"interface_name": "sing-tun",
"inet4_address": "172.19.0.1\/30",
"address": ["172.19.0.1\/30"],
"mtu": 1400,
"gso": true,
"auto_route": true,
@@ -110,6 +110,10 @@
"protocol": "dns",
"outbound": "dns-out"
},
{
"addruleset": true,
"outbound": "direct"
},
{
"addruleset": true,
"createruleset": [
@@ -188,4 +192,4 @@
],
"final": "direct"
}
}
}
+1 -1
View File
@@ -35,7 +35,7 @@ stream {
map_hash_bucket_size 128;
map $ssl_preread_server_name $sni_name {
#domain
telegram.org reality;
t reality;
#domain
#ocserv
+5 -22
View File
@@ -16,27 +16,10 @@
"enabled": true
},
"streamSettings": {
"network": "tcp",
"realitySettings": {
"dest": "telegram.org:443",
"maxClientVer": "",
"maxTimeDiff": 0,
"minClientVer": "",
"privateKey": "",
"serverNames": [
"telegram.org"
],
"shortIds": [],
"show": false,
"xver": 0
},
"tcpSettings": {
"acceptProxyProtocol": true
},
"sockopt": {
"acceptProxyProtocol": true
},
"security": "reality"
"network": "ws",
"wsSettings": {
"path": "/ws"
}
},
"tag": "vless_tls"
}
@@ -59,4 +42,4 @@
"domainStrategy": "AsIs",
"rules": []
}
}
}
-73
View File
@@ -44,8 +44,6 @@ services:
condition: service_healthy
ad:
condition: service_started
ss:
condition: service_started
env_file:
- path: ./.env
required: true # default
@@ -187,45 +185,13 @@ services:
- up
- ng
- php
- proxy
- wg
- wg1
- ad
- ss
- tg
- xr
- oc
- np
proxy:
image: mercurykd/vpnbot-ss:1.2
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/sslocal.json:/config.json
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_proxy.sh:/start_proxy.sh
hostname: proxy
container_name: proxy-${VER}
depends_on:
php:
condition: service_healthy
networks:
default:
ipv4_address: 10.10.0.3
environment:
TZ: ${TZ}
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_proxy.sh"]
logging: *default-logging
wg:
image: mercurykd/vpnbot-wg:1.1
build:
@@ -247,8 +213,6 @@ services:
depends_on:
php:
condition: service_healthy
ports:
- ${WGPORT}:${WGPORT}/udp
env_file:
- path: ./.env
required: true # default
@@ -287,8 +251,6 @@ services:
depends_on:
php:
condition: service_healthy
ports:
- ${WG1PORT}:${WG1PORT}/udp
env_file:
- path: ./.env
required: true # default
@@ -312,8 +274,6 @@ services:
dockerfile: dockerfile/adguard.dockerfile
args:
image: ${IMAGE}
ports:
- 853:853
volumes:
- ./config/.profile:/root/.ashrc:ro
- type: volume
@@ -343,37 +303,6 @@ services:
- NET_ADMIN
entrypoint: ["/bin/sh", "/start_ad.sh"]
logging: *default-logging
ss:
image: mercurykd/vpnbot-ss:1.2
build:
dockerfile: dockerfile/shadowsocks.dockerfile
args:
image: ${IMAGE}
volumes:
- ./config/.profile:/root/.ashrc:ro
- ./config/ssserver.json:/config.json
- ./ssh:/ssh
- ./config/sshd_config:/etc/ssh/sshd_config
- ./scripts/start_ss.sh:/start_ss.sh
hostname: shadowsocks
container_name: shadowsocks-${VER}
depends_on:
php:
condition: service_healthy
ports:
- ${SSPORT}:${SSPORT}/tcp
- ${SSPORT}:${SSPORT}/udp
env_file:
- path: ./.env
required: true # default
- path: ./override.env
required: false
stop_grace_period: 1s
command: ["/bin/sh", "/start_ss.sh"]
networks:
default:
ipv4_address: 10.10.0.6
logging: *default-logging
tg:
image: mercurykd/vpnbot-tg:1.1
build:
@@ -389,8 +318,6 @@ services:
depends_on:
php:
condition: service_healthy
ports:
- ${TGPORT}:${TGPORT}
environment:
IP: ${IP}
env_file:
Binary file not shown.
+11 -2
View File
@@ -1,5 +1,14 @@
#!/bin/bash
pwd=`pwd`
process_name="$pwd/update/update.sh"
current_pid=$$
pids=$(pgrep -f $process_name)
for pid in $pids; do
if [ $pid -ne $current_pid ]; then
kill -9 $pid
fi
done
> $pwd/update/pipe
echo "$$" > $pwd/update/update_pid
@@ -27,10 +36,10 @@ do
git pull > ./update/message
fi
curl -H "Content-Type: application/json" -X POST https://api.telegram.org/bot$key/editMessageText -d "$(cat $pwd/update/curl | sed 's/"text":"~t~"/"text": "launching the bot"/')"
IP=$(curl ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
bash $pwd/update/update.sh &
> $pwd/update/key
> $pwd/update/curl
IP=$(curl -s -t 1 2ip.io || curl -s -t 1 ipinfo.io/ip || curl -s -t 1 ifconfig.me) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
bash $pwd/update/update.sh &
exit 0
fi
sleep 1
+27
View File
@@ -1,3 +1,30 @@
26.12.2024 v2.2
- возможность менять поддомен для naive/openconnect
26.12.2024 v2.1
- обновление версии singbox и конфига под него
22.12.2024 v2.0
!!! версия не совместима с предыдущими, возможно прийдется накатывать руками. старые конфиги (кроме вг) не будут работать! перед обновлением:
- включить все порты или удалить docker-compose.override.yml
- переключить vless на вебсокет
- запустить обновление, если бот запуститься:
- перевыпустить сертификаты
- все ссылки на конфиги будут новыми (старые не будут работать)
- переключить vless на нужный режим (передернуть тумблер)
- включить нужные вам порты (по умолчанию включено только 80 и 443)
что нового:
- по умолчанию включены только 80, 443 порты
- у каждого инстанса бота теперь индивидуальные ссылки и поддомены
- отключены заголовки в ответах по которым можно было идентифицировать бота
- стандартная заглушка на главной заменена на basic auth. если есть override.html - то покажет его
- любая ссылка 'не по адресам бота' выдает непроходимый basic auth
- поддомены np и oc теперь у каждого индивидуальные
- выпилен shadowsocks (10.10.0.3 прокси теперь нет)
- добавлен direct rule в origin-singbox шаблон
- заменены значки для silence mode анализатора логов
- переработано главное меню аля дашбоард
- куча отрефакторенного кода - возможны баги
19.12.2024 v1.115
- генерация устойчивого пароля shadowsocks, если он равен test или пуст
19.12.2024 v1.114