mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-29 10:42:24 +03:00
feat(amneziawg): add frontend support and fix a Go->Zod generator gap
Wires the amneziawg protocol through the panel UI the same way every
other protocol is registered: a Zod settings schema (nested
{server, clients}, matching the Go JSON exactly), the protocol enum,
the inbound-form's per-protocol fields component and its
tab-visibility allowlist, the default-settings factory, the client
schema dispatcher, and the sniffing-capability exclusion (no Xray
inbound exists for amneziawg, same as mtproto).
Client key/allowedIPs fields are reused rather than duplicated: since
AmneziaWG clients are wire-identical to WireGuard clients (same
model.Client fields), ClientFormModal renders one shared field block
for both, switching only the visible label by which protocol is
active. The private-key input also gets a live public-key sync via a
new useEffect, because unlike WireGuard's Xray-native inbound (which
re-derives its public key at runtime and never stores one),
AmneziaWG's server.publicKey is a real persisted field the Go backend
reads directly — free-typing a new private key without this would
silently save a mismatched keypair.
Adds a downloadable per-client .conf (amneziawgConfig.ts, mirroring
wireguardConfig.ts) with the obfuscation lines, and an
InboundOption.AwgServer field on the Go side so the config builder
gets the full server block in one round trip.
Along the way, running tools/openapigen surfaced a real bug: it
doesn't flatten anonymously-embedded Go structs the way encoding/json
does, so ServerSettings embedding Obfuscation20 produced a Zod schema
with a nested `obfuscation20` key that never matches the real wire
JSON. Fixed by un-embedding (flat fields + an accessor method) and
registering internal/amneziawg in the generator's own package list,
which had been silently emitting a dangling schema reference.
English and Russian translations are complete; the other 10 locale
files still fall back to English for the new keys.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
@@ -1,5 +1,6 @@
|
||||
import { RandomUtil, Wireguard } from '@/utils';
|
||||
|
||||
import type { AmneziawgInboundSettings } from '@/schemas/protocols/inbound/amneziawg';
|
||||
import type { HttpInboundSettings } from '@/schemas/protocols/inbound/http';
|
||||
import type { HysteriaClient, HysteriaInboundSettings } from '@/schemas/protocols/inbound/hysteria';
|
||||
import type { MixedInboundSettings } from '@/schemas/protocols/inbound/mixed';
|
||||
@@ -274,6 +275,43 @@ export function createDefaultWireguardInboundSettings(
|
||||
};
|
||||
}
|
||||
|
||||
// AmneziaWG is multi-client, like WireGuard, and uses the same Curve25519
|
||||
// keypair format — Wireguard.generateKeypair() works unchanged. Unlike
|
||||
// WireGuard's Xray-native inbound, the server's publicKey is a real
|
||||
// persisted field here (the Go backend reads it directly rather than
|
||||
// re-deriving it), so it's seeded alongside privateKey. The obfuscation
|
||||
// parameters (jc/jmin/.../i1) use the same starting values the Go backend's
|
||||
// own generator range-checks against; the user (or the backend's own
|
||||
// defaulting on save) can randomize/edit them further — see
|
||||
// internal/amneziawg.GenerateObfuscation20 on the Go side.
|
||||
export function createDefaultAmneziawgInboundSettings(): AmneziawgInboundSettings {
|
||||
const kp = Wireguard.generateKeypair();
|
||||
return {
|
||||
server: {
|
||||
privateKey: kp.privateKey,
|
||||
publicKey: kp.publicKey,
|
||||
subnetIp: '10.8.1.0',
|
||||
subnetCidr: 24,
|
||||
primaryDns: '8.8.8.8',
|
||||
secondaryDns: '8.8.4.4',
|
||||
externalInterface: '',
|
||||
jc: 5,
|
||||
jmin: 10,
|
||||
jmax: 50,
|
||||
s1: 30,
|
||||
s2: 45,
|
||||
s3: 10,
|
||||
s4: 5,
|
||||
h1: '',
|
||||
h2: '',
|
||||
h3: '',
|
||||
h4: '',
|
||||
i1: '',
|
||||
},
|
||||
clients: [],
|
||||
};
|
||||
}
|
||||
|
||||
// Protocol-aware dispatch over every inbound-settings factory. Mirrors
|
||||
// the legacy `Inbound.Settings.getSettings(protocol)` dispatcher, but
|
||||
// returns a plain Zod-parsable object instead of a class instance.
|
||||
@@ -290,7 +328,8 @@ export type AnyInboundSettings =
|
||||
| TunInboundSettings
|
||||
| TunnelInboundSettings
|
||||
| WireguardInboundSettings
|
||||
| MtprotoInboundSettings;
|
||||
| MtprotoInboundSettings
|
||||
| AmneziawgInboundSettings;
|
||||
|
||||
export function createDefaultInboundSettings(protocol: string): AnyInboundSettings | null {
|
||||
switch (protocol) {
|
||||
@@ -305,6 +344,7 @@ export function createDefaultInboundSettings(protocol: string): AnyInboundSettin
|
||||
case 'tun': return createDefaultTunInboundSettings();
|
||||
case 'wireguard': return createDefaultWireguardInboundSettings();
|
||||
case 'mtproto': return createDefaultMtprotoInboundSettings();
|
||||
case 'amneziawg': return createDefaultAmneziawgInboundSettings();
|
||||
default: return null;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
import type { InboundFormValues, ShareAddrStrategy, TrafficReset } from '@/schemas/forms/inbound-form';
|
||||
import type { InboundSettings } from '@/schemas/protocols/inbound';
|
||||
import {
|
||||
AmneziawgClientSchema,
|
||||
HysteriaClientSchema,
|
||||
MtprotoClientSchema,
|
||||
ShadowsocksClientSchema,
|
||||
@@ -252,6 +253,7 @@ function clientSchemaForProtocol(protocol: string): z.ZodType | null {
|
||||
case 'hysteria': return HysteriaClientSchema;
|
||||
case 'wireguard': return WireguardClientSchema;
|
||||
case 'mtproto': return MtprotoClientSchema;
|
||||
case 'amneziawg': return AmneziawgClientSchema;
|
||||
default: return null;
|
||||
}
|
||||
}
|
||||
|
||||
@@ -67,10 +67,11 @@ export function canEnableStream(values: { protocol: string }): boolean {
|
||||
return STREAM_PROTOCOLS.includes(values.protocol);
|
||||
}
|
||||
|
||||
// mtproto is served by an external mtg process, not Xray, so the Xray sniffing
|
||||
// block does not apply to it. Every other inbound supports sniffing.
|
||||
// mtproto and amneziawg are served by an external process/interface, not
|
||||
// Xray, so the Xray sniffing block does not apply to either. Every other
|
||||
// inbound supports sniffing.
|
||||
export function canEnableSniffing(values: { protocol: string }): boolean {
|
||||
return values.protocol !== 'mtproto';
|
||||
return values.protocol !== 'mtproto' && values.protocol !== 'amneziawg';
|
||||
}
|
||||
|
||||
// Vision seed applies only when XTLS Vision (TCP/TLS) flow is selected
|
||||
|
||||
Reference in New Issue
Block a user