Compare commits
22 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| d7ed7042ec | |||
| 4496a30552 | |||
| ca1a596f85 | |||
| b3edf1bdcc | |||
| c6306aa918 | |||
| d5bbc9a564 | |||
| d2aab8ee4b | |||
| 304217d36e | |||
| 2622397542 | |||
| 702123e39c | |||
| 01ef7707c4 | |||
| 064d39d80b | |||
| 1b93d41421 | |||
| e41c8e30a4 | |||
| 260f988360 | |||
| ca4905220d | |||
| 08c5ff136e | |||
| 8709531717 | |||
| 71f53c3575 | |||
| 2607f1f264 | |||
| a94cab7dc1 | |||
| 694d446402 |
+57
-34
@@ -40,7 +40,7 @@ class Bot
|
||||
$this->reg = '~' . implode('|', [
|
||||
'GET / HTTP',
|
||||
'GET /favicon.ico HTTP',
|
||||
preg_quote($this->getHashBot())
|
||||
preg_quote($this->getHashBot(1))
|
||||
]) . '~';
|
||||
}
|
||||
|
||||
@@ -1188,8 +1188,7 @@ class Bot
|
||||
$this->ssh('ssserver -v -d -c /config.json', 'ss');
|
||||
$this->ssh('sslocal -v -d -c /config.json', 'proxy');
|
||||
|
||||
$this->sd($c, 1);
|
||||
if (!empty($nomenu)) {
|
||||
if (empty($nomenu)) {
|
||||
$this->menu('ss');
|
||||
}
|
||||
}
|
||||
@@ -4324,47 +4323,47 @@ DNS-over-HTTPS with IP:
|
||||
'data' => [
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n($this->getPacConf()['amnezia'] ? 'amnezia' : 'wg_title'),
|
||||
'text' => $this->i18n($this->getPacConf()['amnezia'] ? 'amnezia' : 'wg_title') . ' ' . $this->i18n($this->ssh($this->getPacConf()['amnezia'] ? 'awg' : 'wg', 'wg') ? 'on' : 'off'),
|
||||
'callback_data' => "/changeWG 0",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n($this->getPacConf()['wg1_amnezia'] ? 'amnezia' : 'wg_title'),
|
||||
'text' => $this->i18n($this->getPacConf()['wg1_amnezia'] ? 'amnezia' : 'wg_title') . ' ' . $this->i18n($this->ssh($this->getPacConf()['wg1_amnezia'] ? 'awg' : 'wg', 'wg1') ? 'on' : 'off'),
|
||||
'callback_data' => "/changeWG 1",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('xray'),
|
||||
'text' => $this->i18n('xray') . ' ' . $this->i18n($this->ssh('pgrep xray', 'xr') ? 'on' : 'off'),
|
||||
'callback_data' => "/xray",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('naive'),
|
||||
'text' => $this->i18n('naive') . ' ' . $this->i18n($this->ssh('pgrep caddy', 'np') ? 'on' : 'off'),
|
||||
'callback_data' => "/menu naive",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('ocserv'),
|
||||
'text' => $this->i18n('ocserv') . ' ' . $this->i18n($this->ssh('pgrep ocserv', 'oc') ? 'on' : 'off'),
|
||||
'callback_data' => "/menu oc",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('mtproto'),
|
||||
'text' => $this->i18n('mtproto') . ' ' . $this->i18n($this->ssh('pgrep mtproto-proxy', 'tg') ? 'on' : 'off'),
|
||||
'callback_data' => "/mtproto",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('ad_title'),
|
||||
'text' => $this->i18n('ad_title') . ' ' . $this->i18n(exec("JSON=1 timeout 2 dnslookup google.com ad") ? 'on' : 'off'),
|
||||
'callback_data' => "/menu adguard",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('warp') . ': ' . $this->warpStatus(),
|
||||
'text' => $this->i18n('warp') . ' ' . $this->i18n($this->warpStatus()),
|
||||
'callback_data' => "/warp",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('sh_title'),
|
||||
'text' => $this->i18n('sh_title') . ' ' . $this->i18n($this->ssh('pgrep ssserver', 'ss') ? 'on' : 'off'),
|
||||
'callback_data' => "/menu ss",
|
||||
],
|
||||
[
|
||||
@@ -5346,8 +5345,16 @@ DNS-over-HTTPS with IP:
|
||||
$p = $this->getPacConf();
|
||||
$users = array_map(fn ($e) => trim($e), explode(',', $users));
|
||||
$users = array_map(fn ($e) => explode(':', $e), $users);
|
||||
foreach ($c['inbounds'][0]['settings']['clients'] as $k => $v) {
|
||||
$uuids[] = $v['id'];
|
||||
$emails[] = $v['email'];
|
||||
}
|
||||
foreach ($users as $user) {
|
||||
$uuid = $user[1] ?: trim($this->ssh('xray uuid', 'xr'));
|
||||
if (in_array($uuid, $uuids ?: []) || in_array($user[0], $emails ?: [])) {
|
||||
$this->send($this->input['chat'], "user {$user[0]} already exists");
|
||||
return $this->xray();
|
||||
}
|
||||
$c['inbounds'][0]['settings']['clients'][] = $p['transport'] != 'Reality' ? [
|
||||
'id' => $uuid,
|
||||
'email' => $user[0],
|
||||
@@ -5377,20 +5384,22 @@ DNS-over-HTTPS with IP:
|
||||
$this->send($this->input['chat'], 'wrong format');
|
||||
return;
|
||||
}
|
||||
if (!empty($c['inbounds'][0]['settings']['clients'][$i]['off'])) {
|
||||
$this->switchXr($i, 1);
|
||||
$c = $this->getXray();
|
||||
}
|
||||
$c['inbounds'][0]['settings']['clients'][$i]['time'] = $time;
|
||||
}
|
||||
file_put_contents('/config/xray.json', json_encode($c, JSON_PRETTY_PRINT | JSON_UNESCAPED_UNICODE | JSON_UNESCAPED_SLASHES));
|
||||
$this->userXr($i);
|
||||
$this->restartXray($c, 1);
|
||||
if (!empty($c['inbounds'][0]['settings']['clients'][$i]['off'])) {
|
||||
$this->switchXr($i, 0, 1);
|
||||
} else {
|
||||
$this->userXr($i);
|
||||
}
|
||||
}
|
||||
|
||||
public function switchXr($i, $nm = 0)
|
||||
public function switchXr($i, $nm = 0, $time = false)
|
||||
{
|
||||
$c = $this->getXray();
|
||||
unset($c['inbounds'][0]['settings']['clients'][$i]['time']);
|
||||
if (empty($time)) {
|
||||
unset($c['inbounds'][0]['settings']['clients'][$i]['time']);
|
||||
}
|
||||
if (empty($c['inbounds'][0]['settings']['clients'][$i]['off'])) {
|
||||
$c['inbounds'][0]['settings']['clients'][$i]['off'] = $c['inbounds'][0]['settings']['clients'][$i]['id'];
|
||||
$c['inbounds'][0]['settings']['clients'][$i]['id'] = trim($this->ssh('xray uuid', 'xr'));
|
||||
@@ -5608,6 +5617,7 @@ DNS-over-HTTPS with IP:
|
||||
<code>~block~</code>
|
||||
<code>~warp~</code>
|
||||
<code>~dns~</code>
|
||||
<code>~dnspath~</code>
|
||||
<code>~uid~</code>
|
||||
<code>~domain~</code>
|
||||
<code>~directdomain~</code>
|
||||
@@ -5998,7 +6008,6 @@ DNS-over-HTTPS with IP:
|
||||
|
||||
public function frequencyAnalyze($line, $pac)
|
||||
{
|
||||
preg_match('~(?<date>.+)\sfrom\s(?<ip>\d+\.\d+\.\d+\.\d+)(?=.+email:\s(?<email>.+))~', $line, $m);
|
||||
if (!empty($this->pool)) {
|
||||
foreach ($this->pool as $i => $j) {
|
||||
if (!empty($j['ips'])) {
|
||||
@@ -6010,6 +6019,9 @@ DNS-over-HTTPS with IP:
|
||||
}
|
||||
}
|
||||
}
|
||||
if (empty(preg_match('~(?<date>.+)\sfrom\s(?<ip>\d+\.\d+\.\d+\.\d+)(?=.+email:\s(?<email>.+))~', $line, $m))) {
|
||||
return;
|
||||
}
|
||||
if (!empty($m['ip']) && !empty($m['email'])) {
|
||||
$ip = ip2long($m['ip']);
|
||||
if (!empty($this->pool[$m['email']]['ip']) && $this->pool[$m['email']]['ip'] != $ip) {
|
||||
@@ -6020,19 +6032,20 @@ DNS-over-HTTPS with IP:
|
||||
foreach ($xr['inbounds'][0]['settings']['clients'] as $k => $v) {
|
||||
if (empty($v['off']) && $v['email'] == $m['email']) {
|
||||
require __DIR__ . '/config.php';
|
||||
foreach ($c['admin'] as $k => $v) {
|
||||
$this->send($v, "vless: {$m['email']} is turned off (limit by one IP)");
|
||||
foreach ($c['admin'] as $admin) {
|
||||
$this->send($admin, "vless: {$m['email']} limit ip " . count($this->pool[$m['email']]['ips']) . ' > ' . ($pac['ip_count'] ?: 1), button: [[
|
||||
[
|
||||
'text' => $this->i18n($c['off'] ? 'off' : 'on'),
|
||||
'callback_data' => "/switchXr $k",
|
||||
],
|
||||
]]);
|
||||
}
|
||||
unset($this->pool[$m['email']]);
|
||||
$this->switchXr($k, 1);
|
||||
$flag = 1;
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
if (empty($flag)) {
|
||||
$this->pool[$m['email']]['ip'] = $ip;
|
||||
}
|
||||
$this->pool[$m['email']]['ip'] = $ip;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -6357,7 +6370,7 @@ DNS-over-HTTPS with IP:
|
||||
header("Location: hiddify://install-config/?url=$si");
|
||||
exit;
|
||||
case 'c':
|
||||
header("Location: clash://install-config/?url=$cl&name=$email");
|
||||
header("Location: clash://install-config/?url=$cl&overwrite=no&name=$email");
|
||||
exit;
|
||||
case 'w':
|
||||
$link = htmlspecialchars($si, ENT_XML1, 'UTF-8');
|
||||
@@ -6497,6 +6510,7 @@ DNS-over-HTTPS with IP:
|
||||
'"~package~"' => json_encode(array_keys(array_filter($pac['packagelist'] ?: []))),
|
||||
'"~subnet~"' => json_encode(array_keys(array_filter($pac['subnetlist'] ?: []))),
|
||||
'~dns~' => "https://$domain/dns-query$hash/$uid",
|
||||
'~dnspath~' => "/dns-query$hash/$uid",
|
||||
'~uid~' => $uid,
|
||||
'~domain~' => $domain,
|
||||
'~directdomain~' => $pac['domain'],
|
||||
@@ -6803,14 +6817,16 @@ DNS-over-HTTPS with IP:
|
||||
$this->ssh("nginx -s reload 2>&1", 'up');
|
||||
}
|
||||
|
||||
public function getHashBot()
|
||||
public function getHashBot($notset = false)
|
||||
{
|
||||
$p = $this->getPacConf();
|
||||
if (!empty($p['hashbot'])) {
|
||||
return $p['hashbot'];
|
||||
}
|
||||
$p['hashbot'] = substr(hash('sha256', $this->key), 0, 8);
|
||||
$this->setPacConf($p);
|
||||
if (empty($notset)) {
|
||||
$this->setPacConf($p);
|
||||
}
|
||||
return $p['hashbot'];
|
||||
}
|
||||
|
||||
@@ -6855,7 +6871,13 @@ DNS-over-HTTPS with IP:
|
||||
|
||||
public function getHashSubdomain($subdomain)
|
||||
{
|
||||
return $this->getPacConf()["{$subdomain}_domain"] ?: substr(hash('sha256', "$subdomain{$this->key}"), 0, 8);
|
||||
$p = $this->getPacConf();
|
||||
if (!empty($p["{$subdomain}_domain"])) {
|
||||
return $p["{$subdomain}_domain"];
|
||||
}
|
||||
$p["{$subdomain}_domain"] = substr(hash('sha256', "$subdomain{$this->key}"), 0, 8);
|
||||
$this->setPacConf($p);
|
||||
return $p["{$subdomain}_domain"];
|
||||
}
|
||||
|
||||
public function addWg($page)
|
||||
@@ -8075,8 +8097,9 @@ DNS-over-HTTPS with IP:
|
||||
}
|
||||
echo "$ip\n";
|
||||
var_dump($r = $this->request('setWebhook', [
|
||||
'url' => "https://$ip/tlgrm?k={$this->key}",
|
||||
'certificate' => curl_file_create('/certs/self_public'),
|
||||
'url' => "https://$ip/tlgrm?k={$this->key}",
|
||||
'certificate' => curl_file_create('/certs/self_public'),
|
||||
'allowed_updates' => json_encode(['*']),
|
||||
]));
|
||||
if (!empty($r['result']) && $r['result'] == true) {
|
||||
file_put_contents('/start', 1);
|
||||
|
||||
+1
-1
@@ -38,7 +38,7 @@ switch (true) {
|
||||
|
||||
// adguard cookie
|
||||
case preg_match('~^' . preg_quote("/webapp$hash/check") . '~', $_SERVER['REQUEST_URI']) && $webapp:
|
||||
setcookie('c', substr(hash('sha256', $c['key']), 0, 8), 0, '/');
|
||||
setcookie('c', $hash, 0, '/');
|
||||
echo "/adguard$hash/";
|
||||
break;
|
||||
|
||||
|
||||
@@ -72,6 +72,7 @@
|
||||
"uuid": "~uid~",
|
||||
"network": "tcp",
|
||||
"flow": "xtls-rprx-vision",
|
||||
"udp": true,
|
||||
"tls": true,
|
||||
"reality-opts": {
|
||||
"public-key": "~public_key~",
|
||||
|
||||
+14
-6
@@ -42,10 +42,18 @@ services:
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
ng:
|
||||
condition: service_started
|
||||
ad:
|
||||
condition: service_started
|
||||
ss:
|
||||
condition: service_started
|
||||
xr:
|
||||
condition: service_started
|
||||
oc:
|
||||
condition: service_started
|
||||
np:
|
||||
condition: service_started
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
@@ -79,9 +87,6 @@ services:
|
||||
- 80:80
|
||||
hostname: nginx
|
||||
container_name: nginx-${VER}
|
||||
depends_on:
|
||||
up:
|
||||
condition: service_started
|
||||
env_file:
|
||||
- path: ./.env
|
||||
required: true # default
|
||||
@@ -95,6 +100,9 @@ services:
|
||||
xray:
|
||||
ipv4_address: 10.10.1.2
|
||||
logging: *default-logging
|
||||
depends_on:
|
||||
php:
|
||||
condition: service_healthy
|
||||
php:
|
||||
image: mercurykd/vpnbot-php:1.7
|
||||
build:
|
||||
@@ -147,7 +155,7 @@ services:
|
||||
timeout: 5s
|
||||
retries: 5
|
||||
service:
|
||||
image: mercurykd/vpnbot-php:1.6
|
||||
image: mercurykd/vpnbot-php:1.7
|
||||
build:
|
||||
dockerfile: dockerfile/php.dockerfile
|
||||
args:
|
||||
@@ -432,7 +440,7 @@ services:
|
||||
ipv4_address: 10.10.0.12
|
||||
logging: *default-logging
|
||||
wp:
|
||||
image: mercurykd/vpnbot-wp:1.2
|
||||
image: mercurykd/vpnbot-wp:1.3
|
||||
build:
|
||||
dockerfile: dockerfile/warp.dockerfile
|
||||
args:
|
||||
@@ -442,7 +450,7 @@ services:
|
||||
devices:
|
||||
- /dev/net/tun:/dev/net/tun
|
||||
volumes:
|
||||
- ./config/.profile:/root/.ashrc:ro
|
||||
- ./config/.profile:/root/.bashrc:ro
|
||||
- ./ssh:/ssh
|
||||
- ./config/sshd_config:/etc/ssh/sshd_config
|
||||
- ./config:/config
|
||||
|
||||
@@ -1,16 +1,6 @@
|
||||
FROM ubuntu:22.04 AS build
|
||||
RUN apt update && apt install -y curl gpg lsb-release \
|
||||
FROM ubuntu:22.04
|
||||
RUN apt update && apt install -y curl gpg socat jq lsb-release openssh-server \
|
||||
&& curl -fsSL https://pkg.cloudflareclient.com/pubkey.gpg | gpg --yes --dearmor --output /usr/share/keyrings/cloudflare-warp-archive-keyring.gpg \
|
||||
&& echo "deb [signed-by=/usr/share/keyrings/cloudflare-warp-archive-keyring.gpg] https://pkg.cloudflareclient.com/ $(lsb_release -cs) main" | tee /etc/apt/sources.list.d/cloudflare-client.list \
|
||||
&& apt update && apt install -y cloudflare-warp
|
||||
|
||||
FROM alpine:3.17
|
||||
ARG GLIBC_VERSION=2.34-r0
|
||||
COPY --from=build /usr/bin/warp-cli /usr/bin/warp-svc /usr/local/bin/
|
||||
RUN apk add --no-cache dbus-libs wget socat openssh-server jq curl \
|
||||
&& mkdir /tmp/glibc-pkgs \
|
||||
&& for PKG in glibc-$GLIBC_VERSION.apk glibc-bin-$GLIBC_VERSION.apk; do wget -q --directory-prefix /tmp/glibc-pkgs https://github.com/sgerrand/alpine-pkg-glibc/releases/download/$GLIBC_VERSION/$PKG; done \
|
||||
&& apk add --no-cache --allow-untrusted --force-overwrite /tmp/glibc-pkgs/* \
|
||||
&& rm -rf /tmp/glibc-pkgs \
|
||||
&& /usr/glibc-compat/sbin/ldconfig /lib /usr/glibc-compat/lib \
|
||||
&& apt update && apt install -y cloudflare-warp \
|
||||
&& mkdir /root/.ssh
|
||||
|
||||
@@ -32,7 +32,7 @@ up: # консоль сервиса
|
||||
ad: # консоль сервиса
|
||||
docker compose exec ad /bin/sh
|
||||
wp: # консоль сервиса
|
||||
docker compose exec wp /bin/sh
|
||||
docker compose exec wp bash
|
||||
proxy: # консоль сервиса
|
||||
docker compose exec proxy /bin/sh
|
||||
tg: # консоль сервиса
|
||||
@@ -41,6 +41,8 @@ xr: # консоль сервиса
|
||||
docker compose exec xr /bin/sh
|
||||
oc: # консоль сервиса
|
||||
docker compose exec oc /bin/sh
|
||||
service: # консоль сервиса
|
||||
docker compose exec service /bin/sh
|
||||
clean:
|
||||
docker image prune
|
||||
docker builder prune
|
||||
|
||||
+4
-3
@@ -1,9 +1,10 @@
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
echo 'HostKeyAlgorithms +ssh-rsa' >> /etc/ssh/sshd_config
|
||||
echo 'PubkeyAcceptedKeyTypes +ssh-rsa' >> /etc/ssh/sshd_config
|
||||
service ssh start
|
||||
off=$(cat /config/pac.json | jq -r .warpoff)
|
||||
key=$(cat /config/pac.json | jq -r .warp)
|
||||
if [ "$off" == 'null' ]
|
||||
if [ "$off" = 'null' ]
|
||||
then
|
||||
warp-svc > /dev/null &
|
||||
sleep 3
|
||||
|
||||
Binary file not shown.
@@ -1,6 +1,24 @@
|
||||
17.05.2025 v2.19
|
||||
- фикс падения vless при одинаковом имени пользователей
|
||||
- фикс падения vless при установке таймера для выключенного пользователя
|
||||
- подсветка в меню работы процесса контейнера
|
||||
- overwrite=no для импорта клеш подписки (legiz)
|
||||
18.04.2025 v2.18
|
||||
- фикс отсутствия ssl при первом старте
|
||||
- iplimit уведомляет без отключения пользователя
|
||||
- включение udp в mihomo-шаблоне
|
||||
- удаление лишнего образа пхп
|
||||
07.04.2025 v2.17
|
||||
- фикс циклической перезагрузки панели adguardHome
|
||||
07.04.2025 v2.16
|
||||
- фикс warp
|
||||
07.04.2025 v2.15
|
||||
- миграция поддоменов np/oc вместе в с бэкапом
|
||||
02.03.2025 v2.14
|
||||
- vless ip limit: фикс выключения юзера
|
||||
22.02.2025 v2.13
|
||||
- vless: улучшение сбора статы
|
||||
- vless: фикс добавлениея правил srs для block outbound
|
||||
- vless: фикс добавления правил srs для block outbound
|
||||
11.02.2025 v2.12
|
||||
- vless: хранение статы в отдельном файле
|
||||
- vless ip limit: возможность указать кол-во айпи
|
||||
|
||||
Reference in New Issue
Block a user