Compare commits
39 Commits
| Author | SHA1 | Date | |
|---|---|---|---|
| 486a2c5959 | |||
| 39643bf681 | |||
| 5f1fc6d912 | |||
| 0538d04397 | |||
| af9933676d | |||
| 7bfebe8096 | |||
| ae61a38dbc | |||
| e727f6552c | |||
| cfd500d48a | |||
| ff87ee1055 | |||
| 3375293be5 | |||
| 6e5f198e23 | |||
| b10aaff459 | |||
| 3271561418 | |||
| 295ee6f2aa | |||
| 7ce7c56c1b | |||
| dca34de723 | |||
| eb1ad21c88 | |||
| a3ca7d9ed8 | |||
| 60ba3cf15c | |||
| cd8bcbe05a | |||
| 6cc05c88e7 | |||
| 795c357897 | |||
| e172868f39 | |||
| 4ef38775b0 | |||
| abdb4d791a | |||
| 6948239144 | |||
| ff0fd177c7 | |||
| 28e66d46fd | |||
| edee9c78c5 | |||
| 6ad8b3aa92 | |||
| 31f1825d37 | |||
| 10d84da53e | |||
| c7cc0f31ad | |||
| e3ddb642d7 | |||
| 589823e45d | |||
| 0364188fe8 | |||
| 72edcc4757 | |||
| 5988c4fcee |
+2
-1
@@ -19,4 +19,5 @@ mirror/.env
|
||||
update/*
|
||||
!update/update.sh
|
||||
|
||||
override.env
|
||||
override.env
|
||||
override.html
|
||||
+487
-76
@@ -133,12 +133,27 @@ class Bot
|
||||
case preg_match('~^/changeWG (\d+)$~', $this->input['callback'], $m):
|
||||
$this->changeWG($m[1]);
|
||||
break;
|
||||
case preg_match('~^/changeTransport(?: (\d+))?$~', $this->input['callback'], $m):
|
||||
$this->changeTransport($m[1] ?: false);
|
||||
break;
|
||||
case preg_match('~^/mirror$~', $this->input['message'], $m):
|
||||
$this->menu('mirror');
|
||||
break;
|
||||
case preg_match('~^/autoupdate$~', $this->input['message'], $m):
|
||||
$this->autoupdate();
|
||||
break;
|
||||
case preg_match('~^/appOutbound$~', $this->input['callback'], $m):
|
||||
$this->appOutbound();
|
||||
break;
|
||||
case preg_match('~^/offWarp$~', $this->input['callback'], $m):
|
||||
$this->offWarp();
|
||||
break;
|
||||
case preg_match('~^/addSubdomain$~', $this->input['callback'], $m):
|
||||
$this->addSubdomain();
|
||||
break;
|
||||
case preg_match('~^/addLinkDomain$~', $this->input['callback'], $m):
|
||||
$this->addLinkDomain();
|
||||
break;
|
||||
case preg_match('~^/id$~', $this->input['message'], $m):
|
||||
$this->send($this->input['chat'], $this->input['from'], $this->input['message_id']);
|
||||
break;
|
||||
@@ -331,6 +346,9 @@ class Bot
|
||||
case preg_match('~^/switchTorrent (\d+)$~', $this->input['callback'], $m):
|
||||
$this->switchTorrent($m[1]);
|
||||
break;
|
||||
case preg_match('~^/switchEndpoint (\d+)$~', $this->input['callback'], $m):
|
||||
$this->switchEndpoint($m[1]);
|
||||
break;
|
||||
case preg_match('~^/switchAmnezia (-?\d+)$~', $this->input['callback'], $m):
|
||||
$this->switchAmnezia($m[1]);
|
||||
break;
|
||||
@@ -464,8 +482,8 @@ class Bot
|
||||
case preg_match('~^/proxy$~', $this->input['callback'], $m):
|
||||
$this->proxy();
|
||||
break;
|
||||
case preg_match('~^/showpac$~', $this->input['callback'], $m):
|
||||
$this->showpac();
|
||||
case preg_match('~^/addOverrideHtml$~', $this->input['callback'], $m):
|
||||
$this->addOverrideHtml();
|
||||
break;
|
||||
case preg_match('~^/export$~', $this->input['callback'], $m):
|
||||
$this->exportManual();
|
||||
@@ -791,6 +809,30 @@ class Bot
|
||||
];
|
||||
}
|
||||
|
||||
public function addOverrideHtml()
|
||||
{
|
||||
$r = $this->send(
|
||||
$this->input['chat'],
|
||||
"@{$this->input['username']} attach html",
|
||||
$this->input['message_id'],
|
||||
reply: 'attach html',
|
||||
);
|
||||
$_SESSION['reply'][$r['result']['message_id']] = [
|
||||
'start_message' => $this->input['message_id'],
|
||||
'start_callback' => $this->input['callback_id'],
|
||||
'callback' => 'setOverrideHtml',
|
||||
'args' => [],
|
||||
];
|
||||
}
|
||||
|
||||
public function setOverrideHtml()
|
||||
{
|
||||
$r = $this->request('getFile', ['file_id' => $this->input['file_id']]);
|
||||
if (!empty($f = file_get_contents($this->file . $r['result']['file_path']))) {
|
||||
file_put_contents('/app/webapp/override.html', $f);
|
||||
}
|
||||
}
|
||||
|
||||
public function restartOcserv($conf)
|
||||
{
|
||||
file_put_contents('/config/ocserv.conf', $conf);
|
||||
@@ -1084,6 +1126,10 @@ class Bot
|
||||
]
|
||||
]);
|
||||
}
|
||||
if ($this->getPacConf()['autoupdate']) {
|
||||
$this->input['chat'] = $this->input['from'] = $c['admin'][0];
|
||||
$this->applyupdatebot();
|
||||
}
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -1095,7 +1141,7 @@ class Bot
|
||||
{
|
||||
try {
|
||||
require __DIR__ . '/config.php';
|
||||
if (!empty($c['admin']) && (empty($this->time2) || ((time() - $this->time2) > 3600))) {
|
||||
if (!empty($c['admin']) && date('H') == 12 && (empty($this->time2) || ((time() - $this->time2) > 4600))) {
|
||||
$this->time2 = time();
|
||||
$cert = $this->expireCert();
|
||||
if (!empty($cert) && $cert - 60 * 60 * 24 * 14 < time()) {
|
||||
@@ -1350,7 +1396,8 @@ class Bot
|
||||
$out[] = 'update xray';
|
||||
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
|
||||
$this->restartXray($json['xray']);
|
||||
$this->setUpstreamDomain($json['xray']['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]);
|
||||
$this->adguardXrayClients();
|
||||
$this->setUpstreamDomain($json['pac']['transport'] == 'Websocket' ? 't' : ($json['pac']['reality']['domain'] ?: $json['xray']['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]));
|
||||
}
|
||||
// ocserv
|
||||
if (!empty($json['oc'])) {
|
||||
@@ -1369,7 +1416,7 @@ class Bot
|
||||
|
||||
$t = file_get_contents('/config/nginx_default.conf');
|
||||
if (!empty($json['pac']['domain'])) {
|
||||
$t = preg_replace('/server_name ([^\n]+)?/', "server_name {$json['pac']['domain']};", $t);
|
||||
$t = preg_replace('/server_name ([^\n]+)?/', "server_name *.{$json['pac']['domain']} {$json['pac']['domain']};", $t);
|
||||
preg_match_all('~#-domain.+?#-domain~s', $t, $m);
|
||||
foreach ($m[0] as $k => $v) {
|
||||
$t = preg_replace('~#-domain.+?#-domain~s', $this->uncomment($v, 'domain'), $t, 1);
|
||||
@@ -1520,6 +1567,14 @@ class Bot
|
||||
$this->menu('wg', $page);
|
||||
}
|
||||
|
||||
public function switchEndpoint($page = 0)
|
||||
{
|
||||
$c = $this->getPacConf();
|
||||
$c[$this->getInstanceWG(1) . 'endpoint'] = $c[$this->getInstanceWG(1) . 'endpoint'] ? 0 : 1;
|
||||
$this->setPacConf($c);
|
||||
$this->menu('wg', $page);
|
||||
}
|
||||
|
||||
public function iptablesWG()
|
||||
{
|
||||
$c = $this->getPacConf();
|
||||
@@ -1584,7 +1639,7 @@ class Bot
|
||||
{
|
||||
$conf = $this->getPacConf();
|
||||
$ip = $this->ip;
|
||||
$domain = $conf['domain'] ?: $ip;
|
||||
$domain = $this->getDomain();
|
||||
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$ss = $this->getSSConfig();
|
||||
$port = !empty($ss['plugin']) ? (!empty($ssl) ? 443 : 80) : getenv('SSPORT');
|
||||
@@ -1690,7 +1745,7 @@ class Bot
|
||||
$conf = $this->getPacConf();
|
||||
$conf['domain'] = idn_to_ascii($domain);
|
||||
$nginx = file_get_contents('/config/nginx.conf');
|
||||
$t = preg_replace('/server_name ([^\n]+)?/', "server_name {$conf['domain']};", $nginx);
|
||||
$t = preg_replace('/server_name ([^\n]+)?/', "server_name {$conf['domain']} *.{$conf['domain']};", $nginx);
|
||||
preg_match_all('~#-domain.+?#-domain~s', $t, $m);
|
||||
foreach ($m[0] as $k => $v) {
|
||||
$t = preg_replace('~#-domain.+?#-domain~s', $this->uncomment($v, 'domain'), $t, 1);
|
||||
@@ -1800,9 +1855,13 @@ class Bot
|
||||
case 'letsencrypt':
|
||||
$out[] = 'Install certificate:';
|
||||
$this->update($this->input['chat'], $this->input['message_id'], implode("\n", $out));
|
||||
$adguardClient = $this->getPacConf()['adguardkey'];
|
||||
$adguardClient = $adguardClient ? "-d $adguardClient.{$conf['domain']}" : '';
|
||||
exec("certbot certonly --force-renew --preferred-chain 'ISRG Root X1' -n --agree-tos --email mail@{$conf['domain']} -d {$conf['domain']} -d oc.{$conf['domain']} -d np.{$conf['domain']} $adguardClient --webroot -w /certs/ --logs-dir /logs --max-log-backups 0 2>&1", $out, $code);
|
||||
$adguardClient = $conf['adguardkey'] ? "-d {$conf['adguardkey']}.{$conf['domain']}" : '';
|
||||
if (!empty($conf['subdomain'])) {
|
||||
foreach ($conf['subdomain'] as $v) {
|
||||
$custom .= " -d $v";
|
||||
}
|
||||
}
|
||||
exec("certbot certonly --force-renew --preferred-chain 'ISRG Root X1' -n --agree-tos --email mail@{$conf['domain']} -d {$conf['domain']} -d oc.{$conf['domain']} -d np.{$conf['domain']} $adguardClient $custom --webroot -w /certs/ --logs-dir /logs --max-log-backups 0 2>&1", $out, $code);
|
||||
if ($code > 0) {
|
||||
$this->send($this->input['chat'], "ERROR\n" . implode("\n", $out));
|
||||
break;
|
||||
@@ -2051,6 +2110,61 @@ class Bot
|
||||
'args' => [],
|
||||
];
|
||||
}
|
||||
|
||||
public function addSubdomain()
|
||||
{
|
||||
$r = $this->send(
|
||||
$this->input['chat'],
|
||||
"@{$this->input['username']} enter subdomain",
|
||||
$this->input['message_id'],
|
||||
reply: 'enter subdomain',
|
||||
);
|
||||
$_SESSION['reply'][$r['result']['message_id']] = [
|
||||
'start_message' => $this->input['message_id'],
|
||||
'callback' => 'setSubdomain',
|
||||
'args' => [],
|
||||
];
|
||||
}
|
||||
|
||||
public function addLinkDomain()
|
||||
{
|
||||
$r = $this->send(
|
||||
$this->input['chat'],
|
||||
"@{$this->input['username']} enter domain for link",
|
||||
$this->input['message_id'],
|
||||
reply: 'enter domain for link',
|
||||
);
|
||||
$_SESSION['reply'][$r['result']['message_id']] = [
|
||||
'start_message' => $this->input['message_id'],
|
||||
'callback' => 'setLinkDomain',
|
||||
'args' => [],
|
||||
];
|
||||
}
|
||||
|
||||
public function setLinkDomain($text)
|
||||
{
|
||||
$c = $this->getPacConf();
|
||||
if (empty($text)) {
|
||||
unset($c['linkdomain']);
|
||||
} else {
|
||||
$c['linkdomain'] = trim($text);
|
||||
}
|
||||
$this->setPacConf($c);
|
||||
$this->xray();
|
||||
}
|
||||
|
||||
public function setSubdomain($text)
|
||||
{
|
||||
$c = $this->getPacConf();
|
||||
if (empty($text)) {
|
||||
unset($c['subdomain']);
|
||||
} else {
|
||||
$c['subdomain'] = array_filter(explode(',', $text), fn($e) => !empty(trim($e)));
|
||||
}
|
||||
$this->setPacConf($c);
|
||||
$this->menu('config');
|
||||
}
|
||||
|
||||
public function enterPage()
|
||||
{
|
||||
$r = $this->send(
|
||||
@@ -2118,6 +2232,61 @@ class Bot
|
||||
$this->menu('adguard');
|
||||
}
|
||||
|
||||
public function guidv4($data = null) {
|
||||
// Generate 16 bytes (128 bits) of random data or use the data passed into the function.
|
||||
$data = $data ?? random_bytes(16);
|
||||
assert(strlen($data) == 16);
|
||||
|
||||
// Set version to 0100
|
||||
$data[6] = chr(ord($data[6]) & 0x0f | 0x40);
|
||||
// Set bits 6-7 to 10
|
||||
$data[8] = chr(ord($data[8]) & 0x3f | 0x80);
|
||||
|
||||
// Output the 36 character UUID.
|
||||
return vsprintf('%s%s-%s-%s-%s-%s%s%s', str_split(bin2hex($data), 4));
|
||||
}
|
||||
|
||||
public function adguardXrayClients()
|
||||
{
|
||||
$xr = $this->getXray();
|
||||
$ad = yaml_parse_file($this->adguard);
|
||||
foreach ($xr['inbounds'][0]['settings']['clients'] as $k => $v) {
|
||||
$tmp[] = [
|
||||
'safe_search' => [
|
||||
'enabled' => true,
|
||||
'bing' => true,
|
||||
'duckduckgo' => true,
|
||||
'google' => true,
|
||||
'pixabay' => true,
|
||||
'yandex' => true,
|
||||
'youtube' => true,
|
||||
],
|
||||
'blocked_services' => [
|
||||
'schedule' => ['time_zone' => date_default_timezone_get()],
|
||||
'ids' => [],
|
||||
],
|
||||
'name' => $v['email'],
|
||||
'ids' => [$v['id']],
|
||||
'tags' => [],
|
||||
'upstreams' => [],
|
||||
'uid' => $v['id'],
|
||||
'upstreams_cache_size' => 0,
|
||||
'upstreams_cache_enabled' => false,
|
||||
'use_global_settings' => true,
|
||||
'filtering_enabled' => false,
|
||||
'parental_enabled' => false,
|
||||
'safebrowsing_enabled' => false,
|
||||
'use_global_blocked_services' => true,
|
||||
'ignore_querylog' => false,
|
||||
'ignore_statistics' => false,
|
||||
];
|
||||
}
|
||||
$ad['clients']['persistent'] = $tmp;
|
||||
yaml_emit_file($this->adguard, $ad);
|
||||
$this->stopAd();
|
||||
$this->startAd();
|
||||
}
|
||||
|
||||
public function checkdns()
|
||||
{
|
||||
$r = $this->send(
|
||||
@@ -2544,6 +2713,7 @@ DNS-over-HTTPS with IP:
|
||||
$dns = $c[$this->getInstanceWG(1) . 'dns'];
|
||||
$mtu = $c[$this->getInstanceWG(1) . 'mtu'] ?: $this->mtu;
|
||||
$am = $c[$this->getInstanceWG(1) . 'amnezia'];
|
||||
$end = $c[$this->getInstanceWG(1) . 'endpoint'];
|
||||
$data = [
|
||||
[
|
||||
[
|
||||
@@ -2575,6 +2745,12 @@ DNS-over-HTTPS with IP:
|
||||
'callback_data' => "/defaultMTU $page",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('endpoint') . ': ' . ($end ? $this->ip : $this->getDomain()),
|
||||
'callback_data' => "/switchEndpoint $page",
|
||||
],
|
||||
],
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('add peer'),
|
||||
@@ -3141,7 +3317,7 @@ DNS-over-HTTPS with IP:
|
||||
$mpac = stat(__DIR__ . '/zapretlists/mpac');
|
||||
$pac = stat(__DIR__ . '/zapretlists/pac');
|
||||
$conf = $this->getPacConf();
|
||||
$ip = $conf['domain'] ?: $this->ip;
|
||||
$ip = $this->getDomain();
|
||||
$hash = substr(md5($this->key), 0, 8);
|
||||
$scheme = empty($this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$text = <<<text
|
||||
@@ -3553,7 +3729,7 @@ DNS-over-HTTPS with IP:
|
||||
{
|
||||
$conf = $this->getPacConf();
|
||||
$ip = $this->ip;
|
||||
$domain = $conf['domain'] ?: $ip;
|
||||
$domain = $this->getDomain();
|
||||
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$ss = $this->getSSConfig();
|
||||
$v2ray = !empty($ss['plugin']) ? 'ON' : 'OFF';
|
||||
@@ -3680,7 +3856,7 @@ DNS-over-HTTPS with IP:
|
||||
[
|
||||
[
|
||||
'text' => $this->i18n('chat'),
|
||||
'url' => "https://t.me/vpnbot_group",
|
||||
'url' => "https://t.me/+BYuWVd36cZYwNTMy",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('donate'),
|
||||
@@ -3733,7 +3909,7 @@ DNS-over-HTTPS with IP:
|
||||
{
|
||||
$c = $this->getXray();
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $pac['domain'] ?: $this->ip;
|
||||
$domain = $this->getDomain($pac['transport'] == 'Websocket');
|
||||
$scheme = empty($this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$hash = substr(md5($this->key), 0, 8);
|
||||
$si = "$scheme://{$domain}/pac/" . base64_encode(serialize([
|
||||
@@ -3741,14 +3917,22 @@ DNS-over-HTTPS with IP:
|
||||
't' => 'si',
|
||||
's' => $c['inbounds'][0]['settings']['clients'][$i]['id'],
|
||||
]));
|
||||
$v2 = "$scheme://{$domain}/pac/" . base64_encode(serialize([
|
||||
'h' => $hash,
|
||||
't' => 's',
|
||||
's' => $c['inbounds'][0]['settings']['clients'][$i]['id'],
|
||||
]));
|
||||
|
||||
switch ($s) {
|
||||
case 1:
|
||||
return "$scheme://{$domain}/pac?h=$hash&t=s&s={$c['inbounds'][0]['settings']['clients'][$i]['id']}";
|
||||
return "v2rayng://install-config?url=$v2#{$c['inbounds'][0]['settings']['clients'][$i]['id']}";
|
||||
case 2:
|
||||
return "sing-box://import-remote-profile/?url={$si}#{$c['inbounds'][0]['settings']['clients'][$i]['email']}";
|
||||
|
||||
default:
|
||||
if ($pac['transport'] == 'Websocket') {
|
||||
return "vless://{$c['inbounds'][0]['settings']['clients'][$i]['id']}@$domain:443?flow=&path=%2Fws&security=tls&sni=$domain&fp=chrome&type=ws#{$c['inbounds'][0]['settings']['clients'][$i]['email']}";
|
||||
}
|
||||
return "vless://{$c['inbounds'][0]['settings']['clients'][$i]['id']}@$domain:443?security=reality&sni={$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]}&fp=chrome&pbk={$pac['xray']}&sid={$c['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0]}&type=tcp&flow=xtls-rprx-vision#{$c['inbounds'][0]['settings']['clients'][$i]['email']}";
|
||||
}
|
||||
}
|
||||
@@ -3799,8 +3983,9 @@ DNS-over-HTTPS with IP:
|
||||
public function naiveMenu()
|
||||
{
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $this->getDomain();
|
||||
$text[] = "Menu -> NaiveProxy";
|
||||
$text[] = "<code>https://{$pac['naive']['user']}:{$pac['naive']['pass']}@np.{$pac['domain']}</code>";
|
||||
$text[] = "<code>https://{$pac['naive']['user']}:{$pac['naive']['pass']}@np.$domain</code>";
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('change login'),
|
||||
@@ -3892,6 +4077,7 @@ DNS-over-HTTPS with IP:
|
||||
public function ocMenu()
|
||||
{
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $this->getDomain();
|
||||
$ocserv = file_get_contents('/config/ocserv.conf');
|
||||
preg_match('~^camouflage_secret[^\n]+?"([^"]+)*"~sm', $ocserv, $m);
|
||||
$cs = $m[1];
|
||||
@@ -3900,7 +4086,7 @@ DNS-over-HTTPS with IP:
|
||||
$pass = htmlspecialchars($pac['ocserv']);
|
||||
$text[] = "Menu -> OpenConnect";
|
||||
if (!empty($m[1])) {
|
||||
$text[] = "<code>https://oc.{$pac['domain']}/?$cs</code>";
|
||||
$text[] = "<code>https://oc.$domain/?$cs</code>";
|
||||
}
|
||||
$text[] = "password: <span class='tg-spoiler'>$pass</span>";
|
||||
$data[] = [
|
||||
@@ -3963,6 +4149,7 @@ DNS-over-HTTPS with IP:
|
||||
if ($i == $k) {
|
||||
unset($r['inbounds'][0]['settings']['clients'][$k]);
|
||||
$this->restartXray($r);
|
||||
$this->adguardXrayClients();
|
||||
break;
|
||||
}
|
||||
}
|
||||
@@ -3985,13 +4172,18 @@ DNS-over-HTTPS with IP:
|
||||
public function addxrus($user)
|
||||
{
|
||||
$c = $this->getXray();
|
||||
$p = $this->getPacConf();
|
||||
$uuid = trim($this->ssh('xray uuid', 'xr'));
|
||||
$c['inbounds'][0]['settings']['clients'][] = [
|
||||
'id' => $uuid,
|
||||
'flow' => 'xtls-rprx-vision',
|
||||
'email' => $user,
|
||||
$c['inbounds'][0]['settings']['clients'][] = $p['transport'] == 'Websocket' ? [
|
||||
'id' => $uuid,
|
||||
'email' => $user,
|
||||
] : [
|
||||
'id' => $uuid,
|
||||
'flow' => 'xtls-rprx-vision',
|
||||
'email' => $user,
|
||||
];
|
||||
$this->restartXray($c);
|
||||
$this->adguardXrayClients();
|
||||
$this->userXr(count($c['inbounds'][0]['settings']['clients']) - 1);
|
||||
}
|
||||
|
||||
@@ -4038,6 +4230,7 @@ DNS-over-HTTPS with IP:
|
||||
$c = $this->getXray();
|
||||
$c['inbounds'][0]['settings']['clients'][$i]['email'] = $name;
|
||||
$this->restartXray($c);
|
||||
$this->adguardXrayClients();
|
||||
$this->userXr($i);
|
||||
}
|
||||
|
||||
@@ -4113,7 +4306,7 @@ DNS-over-HTTPS with IP:
|
||||
public function templates($type)
|
||||
{
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $pac['domain'] ?: $this->ip;
|
||||
$domain = $this->getDomain();
|
||||
$hash = substr(md5($this->key), 0, 8);
|
||||
$text[] = "Menu -> " . $this->i18n('xray') . " -> $type templates";
|
||||
$templates = $pac["{$type}templates"];
|
||||
@@ -4175,18 +4368,40 @@ DNS-over-HTTPS with IP:
|
||||
$this->generateSecretXray();
|
||||
}
|
||||
$c = $this->getXray();
|
||||
$p = $this->getPacConf();
|
||||
$text[] = "Menu -> " . $this->i18n('xray');
|
||||
$text[] = "fake domain: <code>{$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]}</code>";
|
||||
if (!empty($fake = $c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0])) {
|
||||
$text[] = "fake domain: <code>$fake</code>";
|
||||
}
|
||||
$text[] = 'transport: ' . ($p['transport'] ?: 'Reality');
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('changeFakeDomain'),
|
||||
'callback_data' => "/changeFakeDomain",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('selfFakeDomain'),
|
||||
'callback_data' => "/selfFakeDomain",
|
||||
'text' => $p['linkdomain'] ?: $this->i18n('cdn'),
|
||||
'callback_data' => '/addLinkDomain',
|
||||
],
|
||||
];
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('Reality') . ' ' . ($p['transport'] != 'Websocket' ? $this->i18n('on') : $this->i18n('off')),
|
||||
'callback_data' => "/changeTransport",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('Websocket') . ' ' . ($p['transport'] == 'Websocket' ? $this->i18n('on') : $this->i18n('off')),
|
||||
'callback_data' => "/changeTransport 1",
|
||||
],
|
||||
];
|
||||
if ($p['transport'] != 'Websocket') {
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('changeFakeDomain'),
|
||||
'callback_data' => "/changeFakeDomain",
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('selfFakeDomain'),
|
||||
'callback_data' => "/selfFakeDomain",
|
||||
],
|
||||
];
|
||||
}
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('v2ray templates'),
|
||||
@@ -4322,32 +4537,67 @@ DNS-over-HTTPS with IP:
|
||||
|
||||
public function addWarpPlus($key)
|
||||
{
|
||||
$c = $this->getPacConf();
|
||||
$c['warp'] = $key;
|
||||
$c = $this->getPacConf();
|
||||
if (!empty($key)) {
|
||||
$c['warp'] = $key;
|
||||
$this->send($this->input['chat'], 'Warp registration license: ' . $this->ssh("warp-cli --accept-tos registration license $key 2>&1", 'wp'));
|
||||
} else {
|
||||
unset($c['warp']);
|
||||
}
|
||||
$this->setPacConf($c);
|
||||
$this->send($this->input['chat'], 'Warp registration license: ' . $this->ssh("warp-cli --accept-tos registration license $key", 'wp'));
|
||||
sleep(1);
|
||||
$this->warp();
|
||||
}
|
||||
|
||||
public function warpStatus()
|
||||
{
|
||||
$st = $this->ssh('curl -m 1 -x socks5://127.0.0.1:40000 https://cloudflare.com/cdn-cgi/trace', 'wp');
|
||||
preg_match('~warp=(\w+)~', $st, $m);
|
||||
return $m[1];
|
||||
if (!empty($this->ssh('pgrep warp-svc', 'wp'))) {
|
||||
$st = $this->ssh('curl -m 1 -x socks5://127.0.0.1:40000 https://cloudflare.com/cdn-cgi/trace', 'wp');
|
||||
preg_match('~warp=(\w+)~', $st, $m);
|
||||
return $m[1];
|
||||
}
|
||||
return 'off';
|
||||
}
|
||||
|
||||
public function offWarp()
|
||||
{
|
||||
$p = $this->getPacConf();
|
||||
if (empty($p['warpoff'])) {
|
||||
$this->ssh('pkill warp-svc', 'wp');
|
||||
$p['warpoff'] = 1;
|
||||
} else {
|
||||
$this->ssh('warp-svc > /dev/null 2>&1 &', 'wp');
|
||||
sleep(3);
|
||||
$this->send($this->input['chat'], 'Registration: ' . $this->ssh('warp-cli --accept-tos registration new 2>&1', 'wp'));
|
||||
if (!empty($p['warp'])) {
|
||||
$this->send($this->input['chat'], 'License: ' . $this->ssh("warp-cli --accept-tos registration license {$p['warp']} 2>&1", 'wp'));
|
||||
}
|
||||
$this->send($this->input['chat'], 'Proxy mode: ' . $this->ssh('warp-cli --accept-tos mode proxy 2>&1', 'wp'));
|
||||
$this->send($this->input['chat'], 'Connect: ' . $this->ssh('warp-cli --accept-tos connect 2>&1', 'wp'));
|
||||
unset($p['warpoff']);
|
||||
}
|
||||
$this->setPacConf($p);
|
||||
$this->warp();
|
||||
}
|
||||
|
||||
public function warp()
|
||||
{
|
||||
$p = $this->getPacConf();
|
||||
$text[] = "Menu -> " . $this->i18n('warp');
|
||||
$text[] = "status: " . $this->warpStatus();
|
||||
$text[] = "key: " . $this->getPacConf()['warp'];
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n($p['warpoff'] ? 'off' : 'on'),
|
||||
'callback_data' => "/offWarp",
|
||||
],
|
||||
];
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('set key'),
|
||||
'callback_data' => "/warpPlus",
|
||||
],
|
||||
];
|
||||
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('back'),
|
||||
@@ -4419,26 +4669,39 @@ DNS-over-HTTPS with IP:
|
||||
{
|
||||
$c = $this->getXray()['inbounds'][0]['settings']['clients'][$i];
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $pac['domain'] ?: $this->ip;
|
||||
$domain = $this->getDomain($pac['transport'] == 'Websocket');
|
||||
$scheme = empty($this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$hash = substr(md5($this->key), 0, 8);
|
||||
|
||||
$text[] = "Menu -> " . $this->i18n('xray') . " -> {$c['email']}\n";
|
||||
$text[] = "<code>{$this->linkXray($i)}</code>\n";
|
||||
$text[] = "<pre><code>{$this->linkXray($i)}</code></pre>\n";
|
||||
|
||||
$text[] = "import subscribe:";
|
||||
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=s&r=v&s={$c['id']}#{$c['email']}'>v2rayng</a>";
|
||||
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=si&s={$c['id']}#{$c['email']}'>sing-box</a>";
|
||||
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=s&r=st&s={$c['id']}#{$c['email']}'>streisand</a>";
|
||||
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=h&s={$c['id']}#{$c['email']}'>hiddify</a>";
|
||||
$text[] = "<a href='$scheme://{$domain}/pac?h=$hash&t=si&r=k&s={$c['id']}#{$c['email']}'>karing</a>";
|
||||
|
||||
$si = "$scheme://{$domain}/pac/" . base64_encode(serialize([
|
||||
'h' => $hash,
|
||||
't' => 'si',
|
||||
's' => $c['id'],
|
||||
]));
|
||||
$xr = "$scheme://{$domain}/pac/" . base64_encode(serialize([
|
||||
'h' => $hash,
|
||||
't' => 's',
|
||||
's' => $c['id'],
|
||||
]));
|
||||
|
||||
$text[] = "\nxray config: <pre><code>$xr</code></pre>";
|
||||
$text[] = "sing-box config: <pre><code>$si</code></pre>";
|
||||
|
||||
$text[] = "\nv2ray config: <code>$scheme://{$domain}/pac?h=$hash&t=s&s={$c['id']}</code>";
|
||||
$text[] = "sing-box config: <code>$scheme://{$domain}/pac?h=$hash&t=si&s={$c['id']}</code>";
|
||||
$text[] = "sing-box windows: <a href='$scheme://{$domain}/pac?h=$hash&t=si&r=w&s={$c['id']}'>windows service</a>";
|
||||
|
||||
$data[] = [
|
||||
[
|
||||
'text' => 'v2ray',
|
||||
'text' => 'xray',
|
||||
'web_app' => ['url' => "https://{$domain}/pac?h=$hash&t=s&s={$c['id']}"],
|
||||
],
|
||||
[
|
||||
@@ -4506,17 +4769,26 @@ DNS-over-HTTPS with IP:
|
||||
);
|
||||
}
|
||||
|
||||
public function getDomain($cdn = false)
|
||||
{
|
||||
$c = $this->getPacConf();
|
||||
if ($cdn && $c['linkdomain']) {
|
||||
return $c['linkdomain'];
|
||||
}
|
||||
return $c['domain'] ?: $this->ip;
|
||||
}
|
||||
|
||||
public function v2raySubscription($key, $fs = 0)
|
||||
{
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $pac['domain'] ?: $this->ip;
|
||||
$domain = $this->getDomain();
|
||||
$xr = $this->getXray();
|
||||
|
||||
$flag = true;
|
||||
foreach ($xr['inbounds'][0]['settings']['clients'] as $k => $v) {
|
||||
if ($v['id'] == $key) {
|
||||
if (!empty($fs)) {
|
||||
return $this->userXr($k, 0, 1);
|
||||
return $this->userXr($k);
|
||||
}
|
||||
if (empty($v['off'])) {
|
||||
$flag = false;
|
||||
@@ -4549,7 +4821,7 @@ DNS-over-HTTPS with IP:
|
||||
{
|
||||
$type = $_GET['t'] == 's' ? 'v2ray' : 'sing';
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $pac['domain'] ?: $this->ip;
|
||||
$domain = $_GET['cdn'] ?: ($_SERVER['SERVER_NAME'] ?: $this->getDomain($pac['transport'] == 'Websocket'));
|
||||
$xr = $this->getXray();
|
||||
$scheme = empty($this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$hash = substr(md5($this->key), 0, 8);
|
||||
@@ -4562,6 +4834,7 @@ DNS-over-HTTPS with IP:
|
||||
}
|
||||
$template = base64_decode($v["{$type}template"]);
|
||||
$uid = $v['id'];
|
||||
$email = $v['email'];
|
||||
break;
|
||||
}
|
||||
}
|
||||
@@ -4575,31 +4848,35 @@ DNS-over-HTTPS with IP:
|
||||
't' => 'si',
|
||||
's' => $uid,
|
||||
]));
|
||||
$v2 = "$scheme://{$domain}/pac?h=$hash&t=s&s=$uid";
|
||||
$v2 = "$scheme://{$domain}/pac/" . base64_encode(serialize([
|
||||
'h' => $hash,
|
||||
't' => 's',
|
||||
's' => $uid,
|
||||
]));
|
||||
switch ($_GET['r']) {
|
||||
case 'si':
|
||||
header("Location: sing-box://import-remote-profile/?url=" . $si);
|
||||
header("Location: sing-box://import-remote-profile/?url=$si");
|
||||
exit;
|
||||
case 'st':
|
||||
header("Location: streisand://import/$v2");
|
||||
exit;
|
||||
case 'v':
|
||||
header("Location: v2rayng://install-config?url=" . urlencode($v2));
|
||||
header("Location: v2rayng://install-config?url=$v2");
|
||||
exit;
|
||||
case 'k':
|
||||
header("Location: karing://install-config?url=$si");
|
||||
exit;
|
||||
case 'h':
|
||||
header("Location: hiddify://install-config/?url=" . $si);
|
||||
header("Location: hiddify://install-config/?url=$si");
|
||||
exit;
|
||||
case 'w':
|
||||
$link = htmlspecialchars($si, ENT_XML1, 'UTF-8');
|
||||
file_put_contents('/singbox/winsw3.xml', preg_replace('#~url~#', $link, file_get_contents('/singbox/winsw3.xml')));
|
||||
$zip = new ZipArchive();
|
||||
$n = "singbox_$uid.zip";
|
||||
$zip->open($n, ZipArchive::CREATE | ZipArchive::OVERWRITE);
|
||||
foreach (scandir('/singbox') as $k => $v) {
|
||||
if (!empty(!in_array($v, ['.', '..']))) {
|
||||
$zip->addFile("/singbox/$v", $v);
|
||||
}
|
||||
}
|
||||
copy('/singbox/singbox.zip', $n);
|
||||
$zip = new ZipArchive();
|
||||
$zip->open($n, ZipArchive::CREATE);
|
||||
$zip->addFromString('winsw3.xml', preg_replace('#~url~#', $link, file_get_contents('/singbox/winsw3.xml')));
|
||||
$zip->close();
|
||||
header('Content-Disposition: attachment; filename="singbox.zip"');
|
||||
echo file_get_contents($n);
|
||||
@@ -4625,11 +4902,42 @@ DNS-over-HTTPS with IP:
|
||||
|
||||
switch ($_GET['t']) {
|
||||
case 's':
|
||||
$c['outbounds'][0]['settings']['vnext'][0]['address'] = $domain;
|
||||
$c['outbounds'][0]['settings']['vnext'][0]['users'][0]['id'] = $uid;
|
||||
$c['outbounds'][0]['streamSettings']['realitySettings']['serverName'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
|
||||
$c['outbounds'][0]['streamSettings']['realitySettings']['publicKey'] = $pac['xray'];
|
||||
$c['outbounds'][0]['streamSettings']['realitySettings']['shortId'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
|
||||
$c['outbounds'][0]['settings']['vnext'][0]['address'] = $domain;
|
||||
$c['outbounds'][0]['settings']['vnext'][0]['users'][0] = [
|
||||
'id' => $uid,
|
||||
'encryption' => 'none',
|
||||
];
|
||||
if ($pac['transport'] == 'Websocket') {
|
||||
$c['outbounds'][0]['streamSettings'] = [
|
||||
"network" => "ws",
|
||||
"security" => "tls",
|
||||
"wsSettings" => [
|
||||
"path" => "/ws?ed=2560"
|
||||
],
|
||||
"tlsSettings" => [
|
||||
"allowInsecure" => false,
|
||||
"serverName" => $domain,
|
||||
"fingerprint" => "chrome"
|
||||
]
|
||||
];
|
||||
unset($c['outbounds'][0]['mux']);
|
||||
} else {
|
||||
$c['outbounds'][0]['settings']['vnext'][0]['users'][0]["flow"] = "xtls-rprx-vision";
|
||||
$c['outbounds'][0]['streamSettings'] = [
|
||||
"network" => "tcp",
|
||||
"security" => "reality",
|
||||
"realitySettings" => [
|
||||
"serverName" => $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0],
|
||||
"fingerprint" => "chrome",
|
||||
"publicKey" => $pac['xray'],
|
||||
"shortId" => $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0],
|
||||
]
|
||||
];
|
||||
$c['outbounds'][0]['mux'] = [
|
||||
"enabled" => false,
|
||||
"concurrency" => -1
|
||||
];
|
||||
}
|
||||
|
||||
foreach ($c['routing']['rules'] as $k => $v) {
|
||||
if (array_key_exists('domain', $v) && $v['domain'] == '~pac~') {
|
||||
@@ -4643,14 +4951,27 @@ DNS-over-HTTPS with IP:
|
||||
break;
|
||||
case 'si':
|
||||
if ($c['dns']['servers'][0]['address'] == '~dns~') {
|
||||
$c['dns']['servers'][0]['address'] = "tls://" . ($pac['adguardkey'] ? "{$pac['adguardkey']}." : '') . "$domain";
|
||||
$c['dns']['servers'][0]['address'] = "https://$domain/dns-query/$uid";
|
||||
}
|
||||
|
||||
$c['outbounds'][0]['server'] = $domain;
|
||||
$c['outbounds'][0]['uuid'] = $uid;
|
||||
if ($pac['transport'] == 'Websocket') {
|
||||
unset($c['outbounds'][0]['tls']['reality']);
|
||||
unset($c['outbounds'][0]['flow']);
|
||||
$c['outbounds'][0]["transport"] = [
|
||||
"type" => "ws",
|
||||
"path" => "/ws"
|
||||
];
|
||||
$c['outbounds'][0]['tls']['server_name'] = $domain;
|
||||
} else {
|
||||
unset($c['outbounds'][0]["transport"]);
|
||||
$c['outbounds'][0]['flow'] = 'xtls-rprx-vision';
|
||||
$c['outbounds'][0]['tls']['reality']['public_key'] = $pac['xray'];
|
||||
$c['outbounds'][0]['tls']['server_name'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
|
||||
$c['outbounds'][0]['tls']['reality']['short_id'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
|
||||
}
|
||||
|
||||
$c['outbounds'][0]['server'] = $domain;
|
||||
$c['outbounds'][0]['uuid'] = $uid;
|
||||
$c['outbounds'][0]['tls']['reality']['public_key'] = $pac['xray'];
|
||||
$c['outbounds'][0]['tls']['server_name'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0];
|
||||
$c['outbounds'][0]['tls']['reality']['short_id'] = $xr['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0];
|
||||
foreach ($c['route']['rules'] as $k => $v) {
|
||||
if (array_key_exists('domain_suffix', $v) && $v['domain_suffix'] == '~pac~') {
|
||||
$c['route']['rules'][$k]['domain_suffix'] = array_keys(array_filter($pac['includelist'] ?: []));
|
||||
@@ -4662,7 +4983,7 @@ DNS-over-HTTPS with IP:
|
||||
$c['route']['rules'] = array_values($c['route']['rules']);
|
||||
$c['route'] = $this->addRuleSet($c['route']);
|
||||
$c['route'] = $this->addPackageRule($c['route']);
|
||||
$c['route'] = $this->createRuleSet($c['route'], $uid);
|
||||
$c['route'] = $this->createRuleSet($c['route'], $uid, $domain);
|
||||
$c['route'] = $this->clearEmptyRules($c['route']);
|
||||
break;
|
||||
}
|
||||
@@ -4719,10 +5040,9 @@ DNS-over-HTTPS with IP:
|
||||
return $route;
|
||||
}
|
||||
|
||||
public function createRuleSet($route, $uid)
|
||||
public function createRuleSet($route, $uid, $domain)
|
||||
{
|
||||
$pac = $this->getPacConf();
|
||||
$domain = $pac['domain'] ?: $this->ip;
|
||||
$scheme = empty($this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$hash = substr(md5($this->key), 0, 8);
|
||||
|
||||
@@ -4765,12 +5085,12 @@ DNS-over-HTTPS with IP:
|
||||
}
|
||||
$ruleset[] = [
|
||||
"tag" => $r['name'],
|
||||
"url" => "$scheme://{$domain}/pac?" . http_build_query([
|
||||
"url" => "$scheme://{$domain}/pac/" . base64_encode(serialize([
|
||||
'h' => $hash,
|
||||
't' => 'si',
|
||||
's' => $uid,
|
||||
'r' => $r['name'],
|
||||
]),
|
||||
])),
|
||||
"update_interval" => $r['interval'],
|
||||
"type" => "remote",
|
||||
"format" => "binary",
|
||||
@@ -4810,6 +5130,8 @@ DNS-over-HTTPS with IP:
|
||||
$c['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0] = $shortId;
|
||||
$pac = $this->getPacConf();
|
||||
$pac['xray'] = $public;
|
||||
$pac['reality']['shortId'] = $shortId;
|
||||
$pac['reality']['privateKey'] = $private;
|
||||
$this->setPacConf($pac);
|
||||
$this->restartXray($c);
|
||||
}
|
||||
@@ -4937,7 +5259,7 @@ DNS-over-HTTPS with IP:
|
||||
{
|
||||
$conf = $this->getPacConf();
|
||||
$ip = $this->ip;
|
||||
$domain = $conf['domain'] ?: $ip;
|
||||
$domain = $this->getDomain();
|
||||
$scheme = empty($ssl = $this->nginxGetTypeCert()) ? 'http' : 'https';
|
||||
$text = "$scheme://$domain/adguard\nLogin: admin\nPass: <span class='tg-spoiler'>{$conf['adpswd']}</span>\n\n";
|
||||
if ($ssl) {
|
||||
@@ -5041,6 +5363,15 @@ DNS-over-HTTPS with IP:
|
||||
return openssl_x509_parse($c)["validTo_time_t"] ?: false;
|
||||
}
|
||||
|
||||
public function domainsCert()
|
||||
{
|
||||
$domains = openssl_x509_parse(openssl_x509_read(file_get_contents("/certs/cert_public")))['extensions']["subjectAltName"];
|
||||
if (empty($domains)) {
|
||||
return false;
|
||||
}
|
||||
return implode("\n", array_map(fn($e) => trim($e), explode(',', str_replace('DNS:', '', $domains))));
|
||||
}
|
||||
|
||||
public function updatebot()
|
||||
{
|
||||
$b = exec('git -C / rev-parse --abbrev-ref HEAD');
|
||||
@@ -5094,10 +5425,16 @@ DNS-over-HTTPS with IP:
|
||||
public function configMenu()
|
||||
{
|
||||
exec('git -C / fetch');
|
||||
$conf = $this->getPacConf();
|
||||
$text[] = $conf['domain'] ? "Domains:\n{$conf['domain']}\nnp.{$conf['domain']}\noc.{$conf['domain']}" . ($conf['adguardkey'] ? "\n{$conf['adguardkey']}.{$conf['domain']}" : '') : $this->i18n('domain explain');
|
||||
$conf = $this->getPacConf();
|
||||
if (!empty($conf['subdomain'])) {
|
||||
$custom = "\ncustom:\n";
|
||||
foreach ($conf['subdomain'] as $v) {
|
||||
$custom .= "$v\n";
|
||||
}
|
||||
}
|
||||
$text[] = $conf['domain'] ? "Domains:\n{$conf['domain']}\nnp.{$conf['domain']} (for naiveproxy)\noc.{$conf['domain']} (for openconnect)" . ($conf['adguardkey'] ? "\n{$conf['adguardkey']}.{$conf['domain']} (for adguard DoT)" : '') . $custom : $this->i18n('domain explain');
|
||||
$ssl = $this->expireCert();
|
||||
$text[] = $conf['domain'] ? "\nSSL: " . ($ssl ? date('Y-m-d H:i:s', $this->expireCert()) : 'none') : '';
|
||||
$text[] = $conf['domain'] ? "\nSSL: " . ($ssl ? date('Y-m-d H:i:s', $this->expireCert()) . "\n" . $this->domainsCert() : 'none') : '';
|
||||
|
||||
$data = [
|
||||
[
|
||||
@@ -5105,6 +5442,10 @@ DNS-over-HTTPS with IP:
|
||||
'text' => $conf['domain'] ? "{$this->i18n('delete')} {$conf['domain']}" : $this->i18n('install domain'),
|
||||
'callback_data' => $conf['domain'] ? '/deldomain' : '/domain',
|
||||
],
|
||||
[
|
||||
'text' => $this->i18n('+ subdomain'),
|
||||
'callback_data' => '/addSubdomain',
|
||||
],
|
||||
],
|
||||
];
|
||||
if ($conf['domain']) {
|
||||
@@ -5201,6 +5542,12 @@ DNS-over-HTTPS with IP:
|
||||
'callback_data' => "/backup",
|
||||
],
|
||||
];
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('fake html'),
|
||||
'callback_data' => "/addOverrideHtml",
|
||||
],
|
||||
];
|
||||
$data[] = [
|
||||
[
|
||||
'text' => $this->i18n('logs'),
|
||||
@@ -5383,8 +5730,12 @@ DNS-over-HTTPS with IP:
|
||||
public function setFakeDomain($domain, $self = false)
|
||||
{
|
||||
$c = $this->getXray();
|
||||
$p = $this->getPacConf();
|
||||
$c['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0] = $domain;
|
||||
$c['inbounds'][0]['streamSettings']['realitySettings']['dest'] = $self ? "10.10.1.2:443" : "$domain:443";
|
||||
$p['reality']['domain'] = $domain;
|
||||
$p['reality']['destination'] = $self ? "10.10.1.2:443" : "$domain:443";
|
||||
$this->setPacConf($p);
|
||||
$this->restartXray($c);
|
||||
$this->setUpstreamDomain($domain);
|
||||
$this->xray();
|
||||
@@ -5400,6 +5751,58 @@ DNS-over-HTTPS with IP:
|
||||
}
|
||||
}
|
||||
|
||||
public function changeTransport($ws = null)
|
||||
{
|
||||
$p = $this->getPacConf();
|
||||
$x = $this->getXray();
|
||||
$p['transport'] = $ws ? 'Websocket' : 'Reality';
|
||||
if (!empty($ws)) {
|
||||
$p['reality']['domain'] = $x['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0] ?: $p['reality']['domain'];
|
||||
$p['reality']['destination'] = $x['inbounds'][0]['streamSettings']['realitySettings']['dest'] ?: $p['reality']['destination'];
|
||||
$p['reality']['shortId'] = $x['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0] ?: $p['reality']['shortId'];
|
||||
foreach ($x['inbounds'][0]['settings']['clients'] as $k => $v) {
|
||||
unset($x['inbounds'][0]['settings']['clients'][$k]['flow']);
|
||||
}
|
||||
$x['inbounds'][0]['streamSettings'] = [
|
||||
"network" => "ws",
|
||||
"wsSettings" => [
|
||||
"path" => "/ws"
|
||||
]
|
||||
];
|
||||
} else {
|
||||
foreach ($x['inbounds'][0]['settings']['clients'] as $k => $v) {
|
||||
$x['inbounds'][0]['settings']['clients'][$k]['flow'] = 'xtls-rprx-vision';
|
||||
}
|
||||
$x['inbounds'][0]['streamSettings'] = [
|
||||
"network" => "tcp",
|
||||
"realitySettings" => [
|
||||
"dest" => $p['reality']['destination'] ?: $x['inbounds'][0]['streamSettings']['realitySettings']['dest'],
|
||||
"maxClientVer" => "",
|
||||
"maxTimeDiff" => 0,
|
||||
"minClientVer" => "",
|
||||
"privateKey" => $p['reality']['privateKey'],
|
||||
"serverNames" => [
|
||||
$p['reality']['domain'] ?: $x['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]
|
||||
],
|
||||
"shortIds" => [$p['reality']['shortId']] ?: $x['inbounds'][0]['streamSettings']['realitySettings']['shortIds'][0],
|
||||
"show" => false,
|
||||
"xver" => 0
|
||||
],
|
||||
"tcpSettings" => [
|
||||
"acceptProxyProtocol" => true
|
||||
],
|
||||
"sockopt" => [
|
||||
"acceptProxyProtocol" => true
|
||||
],
|
||||
"security" => "reality"
|
||||
];
|
||||
}
|
||||
$this->setUpstreamDomain($ws ? 't' : ($p['reality']['domain'] ?: $x['inbounds'][0]['streamSettings']['realitySettings']['serverNames'][0]));
|
||||
$this->setPacConf($p);
|
||||
$this->restartXray($x);
|
||||
$this->xray();
|
||||
}
|
||||
|
||||
public function setBackup($text)
|
||||
{
|
||||
$text = trim($text);
|
||||
@@ -5544,7 +5947,7 @@ DNS-over-HTTPS with IP:
|
||||
$conf[] = '';
|
||||
$conf[] = $peer['# PublicKey'] ? '# [Peer]' : '[Peer]';
|
||||
if (!empty($peer['Endpoint'])) {
|
||||
$peer['Endpoint'] = ($pac['domain'] && !$pac[$this->getInstanceWG(1) . 'amnezia'] ? $pac['domain'] : $this->ip) . ":" . getenv($this->getInstanceWG(1) ? 'WG1PORT' : 'WGPORT');
|
||||
$peer['Endpoint'] = ($this->getPacConf()[$this->getInstanceWG(1) . 'endpoint'] ? $this->ip : $this->getDomain()) . ":" . getenv($this->getInstanceWG(1) ? 'WG1PORT' : 'WGPORT');
|
||||
}
|
||||
foreach ($peer as $k => $v) {
|
||||
$conf[] = "$k = $v";
|
||||
@@ -5703,6 +6106,14 @@ DNS-over-HTTPS with IP:
|
||||
return true;
|
||||
}
|
||||
|
||||
public function autoupdate()
|
||||
{
|
||||
$p = $this->getPacConf();
|
||||
$p['autoupdate'] = !$p['autoupdate'];
|
||||
$this->setPacConf($p);
|
||||
$this->send($this->input['from'], $this->i18n('autoupdate') . ' ' . $this->i18n($p['autoupdate'] ? 'on' : 'off'));
|
||||
}
|
||||
|
||||
public function disconnect(...$args)
|
||||
{
|
||||
$this->send($this->input['chat'], "disconnect: \n" . var_export($args, true) . "\n", $this->input['message_id']);
|
||||
|
||||
+6
-2
@@ -262,8 +262,8 @@ $i = [
|
||||
'ru' => 'очистить',
|
||||
],
|
||||
'xray' => [
|
||||
'en' => 'XTLS-Reality',
|
||||
'ru' => 'XTLS-Reality',
|
||||
'en' => 'Xray',
|
||||
'ru' => 'Xray',
|
||||
],
|
||||
'geodb' => [
|
||||
'en' => 'GeoIp/GeoSite',
|
||||
@@ -337,4 +337,8 @@ $i = [
|
||||
'en' => '🟢 have updates',
|
||||
'ru' => '🟢 есть обновления',
|
||||
],
|
||||
'fake html' => [
|
||||
'en' => 'fake html',
|
||||
'ru' => 'фейк заглушка',
|
||||
],
|
||||
];
|
||||
|
||||
+47
-2
@@ -31,7 +31,7 @@ http {
|
||||
|
||||
location / {
|
||||
root /app;
|
||||
index login.html;
|
||||
index override.html login.html;
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
location /adguard/ {
|
||||
@@ -48,6 +48,7 @@ http {
|
||||
}
|
||||
location /pac {
|
||||
access_log /logs/nginx_pac_access;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
location /tlgrm {
|
||||
@@ -64,6 +65,38 @@ http {
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
location /ws {
|
||||
proxy_pass http://xr:443;
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_read_timeout 5d;
|
||||
}
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
|
||||
# # Enable Cache, and set the cache_key to include the request_body
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
|
||||
# # proxy pass to the dohloop upstream
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
#-ssl
|
||||
location ~\.well-known {
|
||||
access_log /logs/nginx_certbot_access;
|
||||
root /certs/;
|
||||
@@ -90,7 +123,7 @@ http {
|
||||
|
||||
# location / {
|
||||
# root /app;
|
||||
# index login.html;
|
||||
# index override.html login.html;
|
||||
# try_files $uri $uri/ =404;
|
||||
# }
|
||||
# location /adguard/ {
|
||||
@@ -107,6 +140,7 @@ http {
|
||||
# }
|
||||
# location /pac {
|
||||
# access_log /logs/nginx_pac_access;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
# location ~\.well-known {
|
||||
@@ -124,6 +158,17 @@ http {
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# }
|
||||
# location /ws {
|
||||
# proxy_pass http://xr:443;
|
||||
# proxy_redirect off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
# proxy_read_timeout 5d;
|
||||
# }
|
||||
#-domain
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
|
||||
@@ -31,7 +31,7 @@ http {
|
||||
|
||||
location / {
|
||||
root /app;
|
||||
index login.html;
|
||||
index override.html login.html;
|
||||
try_files $uri $uri/ =404;
|
||||
}
|
||||
location /adguard/ {
|
||||
@@ -48,6 +48,7 @@ http {
|
||||
}
|
||||
location /pac {
|
||||
access_log /logs/nginx_pac_access;
|
||||
proxy_set_header Host $http_host;
|
||||
proxy_pass http://php;
|
||||
}
|
||||
location /tlgrm {
|
||||
@@ -64,6 +65,38 @@ http {
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
}
|
||||
location /ws {
|
||||
proxy_pass http://xr:443;
|
||||
proxy_redirect off;
|
||||
proxy_http_version 1.1;
|
||||
proxy_set_header Upgrade $http_upgrade;
|
||||
proxy_set_header Connection "upgrade";
|
||||
proxy_set_header Host $host;
|
||||
proxy_set_header X-Real-IP $remote_addr;
|
||||
proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
proxy_read_timeout 5d;
|
||||
}
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
# location /dns-query {
|
||||
# access_log /logs/nginx_doh_access;
|
||||
# # Proxy HTTP/1.1, clear the connection header to enable Keep-Alive
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Connection "";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Proto https;
|
||||
# proxy_set_header X-Forwarded-For $remote_addr;
|
||||
# proxy_set_header X-Forwarded-Host $remote_addr;
|
||||
|
||||
# # Enable Cache, and set the cache_key to include the request_body
|
||||
# proxy_cache doh_cache;
|
||||
# proxy_cache_key $scheme$proxy_host$uri$is_args$args$request_body;
|
||||
|
||||
# # proxy pass to the dohloop upstream
|
||||
# proxy_pass https://ad/dns-query;
|
||||
# }
|
||||
#-ssl
|
||||
location ~\.well-known {
|
||||
access_log /logs/nginx_certbot_access;
|
||||
root /certs/;
|
||||
@@ -90,7 +123,7 @@ http {
|
||||
|
||||
# location / {
|
||||
# root /app;
|
||||
# index login.html;
|
||||
# index override.html login.html;
|
||||
# try_files $uri $uri/ =404;
|
||||
# }
|
||||
# location /adguard/ {
|
||||
@@ -107,6 +140,7 @@ http {
|
||||
# }
|
||||
# location /pac {
|
||||
# access_log /logs/nginx_pac_access;
|
||||
# proxy_set_header Host $http_host;
|
||||
# proxy_pass http://php;
|
||||
# }
|
||||
# location ~\.well-known {
|
||||
@@ -124,6 +158,17 @@ http {
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# }
|
||||
# location /ws {
|
||||
# proxy_pass http://xr:443;
|
||||
# proxy_redirect off;
|
||||
# proxy_http_version 1.1;
|
||||
# proxy_set_header Upgrade $http_upgrade;
|
||||
# proxy_set_header Connection "upgrade";
|
||||
# proxy_set_header Host $host;
|
||||
# proxy_set_header X-Real-IP $remote_addr;
|
||||
# proxy_set_header X-Forwarded-For $proxy_add_x_forwarded_for;
|
||||
# proxy_read_timeout 5d;
|
||||
# }
|
||||
#-domain
|
||||
#-ssl
|
||||
# # The DoH server block
|
||||
|
||||
+14
-14
@@ -110,6 +110,20 @@
|
||||
"protocol": "dns",
|
||||
"outbound": "dns-out"
|
||||
},
|
||||
{
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "block",
|
||||
"interval": "15s",
|
||||
"rules": [
|
||||
{
|
||||
"domain_suffix": "~block~"
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "block"
|
||||
},
|
||||
{
|
||||
"createruleset": [
|
||||
{
|
||||
@@ -133,20 +147,6 @@
|
||||
],
|
||||
"outbound": "proxy"
|
||||
},
|
||||
{
|
||||
"createruleset": [
|
||||
{
|
||||
"name": "block",
|
||||
"interval": "15s",
|
||||
"rules": [
|
||||
{
|
||||
"domain_suffix": "~block~"
|
||||
}
|
||||
]
|
||||
}
|
||||
],
|
||||
"outbound": "block"
|
||||
},
|
||||
{
|
||||
"outbound": "direct"
|
||||
}
|
||||
|
||||
@@ -3,7 +3,7 @@ b:
|
||||
u: # запуск контейнеров
|
||||
bash ./update/update.sh &
|
||||
touch ./override.env
|
||||
IP=$(shell curl https://ipinfo.io/ip) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||
IP=$(shell curl ipinfo.io/ip) VER=$(shell git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||
d: # остановка контейнеров
|
||||
-kill -9 $(shell cat ./update/update_pid) > /dev/null
|
||||
docker compose down --remove-orphans
|
||||
|
||||
+5
-1
@@ -16,7 +16,11 @@ echo \
|
||||
"deb [arch=$(dpkg --print-architecture) signed-by=/etc/apt/keyrings/docker.gpg] https://download.docker.com/linux/$(lsb_release -is | tr '[:upper:]' '[:lower:]') \
|
||||
$(lsb_release -cs) stable" | tee /etc/apt/sources.list.d/docker.list > /dev/null
|
||||
apt update
|
||||
apt install -y docker-ce docker-ce-cli containerd.io docker-compose-plugin
|
||||
apt install -y docker-ce docker-ce-cli containerd.io
|
||||
DOCKER_CONFIG=${DOCKER_CONFIG:-$HOME/.docker}
|
||||
mkdir -p $DOCKER_CONFIG/cli-plugins
|
||||
curl -SL https://github.com/docker/compose/releases/download/v2.29.6/docker-compose-linux-x86_64 -o $DOCKER_CONFIG/cli-plugins/docker-compose
|
||||
chmod +x $DOCKER_CONFIG/cli-plugins/docker-compose
|
||||
git clone https://github.com/mercurykd/vpnbot.git
|
||||
cd ./vpnbot
|
||||
echo "<?php
|
||||
|
||||
+11
-7
@@ -1,14 +1,18 @@
|
||||
cat /ssh/key.pub > /root/.ssh/authorized_keys
|
||||
ssh-keygen -A
|
||||
exec /usr/sbin/sshd -D -e "$@" &
|
||||
warp-svc > /dev/null &
|
||||
sleep 3
|
||||
warp-cli --accept-tos registration new
|
||||
off=$(cat /config/pac.json | jq -r .warpoff)
|
||||
key=$(cat /config/pac.json | jq -r .warp)
|
||||
if [ ! -z "$key" ]
|
||||
if [ "$off" == 'null' ]
|
||||
then
|
||||
warp-cli --accept-tos registration license $key
|
||||
warp-svc > /dev/null &
|
||||
sleep 3
|
||||
warp-cli --accept-tos registration new
|
||||
if [ ! -z "$key" ]
|
||||
then
|
||||
warp-cli --accept-tos registration license $key
|
||||
fi
|
||||
warp-cli --accept-tos mode proxy
|
||||
warp-cli --accept-tos connect
|
||||
fi
|
||||
warp-cli --accept-tos mode proxy
|
||||
warp-cli --accept-tos connect
|
||||
socat TCP-LISTEN:4000,fork TCP:127.0.0.1:40000
|
||||
|
||||
@@ -1,2 +0,0 @@
|
||||
winsw3.exe install
|
||||
pause
|
||||
@@ -1,2 +0,0 @@
|
||||
winsw3.exe stop
|
||||
winsw3.exe start
|
||||
Binary file not shown.
Binary file not shown.
@@ -1 +0,0 @@
|
||||
winsw3.exe start
|
||||
@@ -1,2 +0,0 @@
|
||||
winsw3.exe status
|
||||
pause
|
||||
@@ -1 +0,0 @@
|
||||
winsw3.exe stop
|
||||
@@ -1,2 +0,0 @@
|
||||
winsw3.exe uninstall
|
||||
pause
|
||||
+1
-1
@@ -24,7 +24,7 @@ do
|
||||
curl -H "Content-Type: application/json" -X POST https://api.telegram.org/bot$key/editMessageText -d "$(cat $pwd/update/curl | sed 's/"text":"~t~"/"text": "применяю обновления"/')"
|
||||
git pull > ./update/message
|
||||
curl -H "Content-Type: application/json" -X POST https://api.telegram.org/bot$key/editMessageText -d "$(cat $pwd/update/curl | sed 's/"text":"~t~"/"text": "запускаю бота"/')"
|
||||
IP=$(curl https://ipinfo.io/ip) VER=$(git describe --tags) docker compose up -d --force-recreate
|
||||
IP=$(curl ipinfo.io/ip) VER=$(git describe --tags) docker compose --env-file ./.env --env-file ./override.env up -d --force-recreate
|
||||
bash $pwd/update/update.sh &
|
||||
> $pwd/update/key
|
||||
> $pwd/update/curl
|
||||
|
||||
@@ -1,3 +1,61 @@
|
||||
09.10.2024 v1.65
|
||||
- фикс создания архива windows service singbox
|
||||
06.10.2024 v1.64.1
|
||||
- добавление html заглушки через меню
|
||||
06.10.2024 v1.64
|
||||
- возможность установить свою html-заглушку
|
||||
06.10.2024 v1.63
|
||||
- приоритет правила block над остальными в стандартном шаблоне sing-box
|
||||
30.09.2024 v1.62
|
||||
- импорт профиля xray в karing
|
||||
30.09.2024 v1.61.1
|
||||
- фикс удаления ключа варпа через ноль
|
||||
29.09.2024 v1.61
|
||||
- включение/отключение процесса warp
|
||||
29.09.2024 v1.60
|
||||
- ускорение сборки архива sing-box windows
|
||||
23.09.2024 v1.59
|
||||
- docker compose v2.29.6 (при установке бота)
|
||||
22.09.2024 v1.58
|
||||
- фикс запуска бота с правильными параметрами после обновления
|
||||
22.09.2024 v1.57
|
||||
- выбор типа endpoint для wireguard/amnezia
|
||||
22.09.2024 v1.56.2
|
||||
- фикс разных доменов при указании cdn для xray
|
||||
19.09.2024 v1.56.1
|
||||
- cdn для xray
|
||||
17.09.2024 v1.55
|
||||
- возможность подменить домен в ссылках на конфиги
|
||||
16.09.2024 v1.54.2
|
||||
- фикс нэйминга клиентов в adguardHome: замена на uuid
|
||||
16.09.2024 v1.54.1
|
||||
- фикс нэйминга клиентов в adguardHome
|
||||
16.09.2024 v1.54
|
||||
- ~dns~ в шаблоне сингбокса подменяятся на https://DOMAIN/dns-query/USERNAME
|
||||
- при добавлении пользователя в XRAY, он также добавляется в AdguardHome как сохраненый клиент
|
||||
10.09.2024 v1.53
|
||||
- домен в endpoint для амнезии
|
||||
10.09.2024 v1.52
|
||||
- фикс спамящего уведомления о просрочке сертификата
|
||||
10.09.2024 v1.51
|
||||
- фикс ipinfo
|
||||
08.09.2024 v1.50
|
||||
- fix import with transport
|
||||
08.09.2024 v1.49
|
||||
- fix add user xray with transport
|
||||
08.09.2024 v1.48
|
||||
- fix change xray transport, save private key xray
|
||||
08.09.2024 v1.47
|
||||
- fix websocket -> reality
|
||||
03.09.2024 v1.46.2
|
||||
- fix link v2ray
|
||||
03.09.2024 v1.46.1
|
||||
- fix import
|
||||
- fix websocket domain
|
||||
03.09.2024 v1.46
|
||||
- возможность добавить кастомный поддомен для Letsencrypt
|
||||
03.09.2024 v1.45
|
||||
- выбор транспорта reality/websocket
|
||||
26.08.2024 v1.44
|
||||
- qr для xtls
|
||||
- фикс действий на элементом списков
|
||||
|
||||
Reference in New Issue
Block a user