mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-10-11 00:15:02 +03:00
fix(sub): make Happ require auth on its local SOCKS/HTTP proxy (#6628)
Happ ships its local SOCKS5 (127.0.0.1:10808) and HTTP inbounds with authorization disabled by default. Any app on the same device can then connect to that proxy, bypassing Android's per-app VPN routing, and learn the VPN server address - the leak publicly described in March-April 2026 for Happ, v2rayNG and other VLESS clients. Happ fixed its Xray API exposure, but the unauthenticated local proxy remained. Happ exposes a standard subscription header for this (no Provider ID required): socks-auth-mode / http-auth-mode = auto|manual|from-json| disable. A new subscription setting, subHappLocalProxyAuth (default "auto"), sends both headers to Happ clients. Like every other Happ header it is emitted only when Happ auto-detect is enabled and the User-Agent is Happ, so panels that never opted into the Happ integration see no change. An empty value sends nothing and keeps the client's own setting. Verified on Happ Android 4.4.1 (Xray 26.7.28): a subscription carrying socks-auth-mode manual + a test user/password switched the client's Inbounds screen to Manual with those credentials on "refresh subscription", and "auto" switched it to Auto with generated credentials. Co-authored-by: Kirill Rudenko <rudenko@npp-energy.ru> Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com> Co-authored-by: Sanaei <ho3ein.sanaei@gmail.com>
This commit is contained in:
@@ -1558,6 +1558,11 @@
|
||||
"subHappColorProfileDesc": "Своя цветовая тема для iOS в виде JSON-строки или resetcolors для сброса к стандартным цветам.",
|
||||
"subHappPingType": "Метод проверки пинга",
|
||||
"subHappPingTypeDesc": "Способ измерения задержки узлов в Happ: через прокси (GET или HEAD), TCP или ICMP.",
|
||||
"subHappLocalProxyAuth": "Авторизация локального прокси",
|
||||
"subHappLocalProxyAuthDesc": "Отправляет Happ заголовки socks-auth-mode / http-auth-mode. Без авторизации любое приложение на устройстве может через локальный SOCKS5/HTTP-прокси Happ попасть в туннель и узнать адрес сервера. «Авто» — Happ сам создаёт случайные учётные данные; Provider ID не нужен.",
|
||||
"subHappLocalProxyAuthAuto": "Авто (случайные учётные данные)",
|
||||
"subHappLocalProxyAuthDisable": "Отключена",
|
||||
"subHappLocalProxyAuthUnset": "Не отправлять (по умолчанию клиента)",
|
||||
"subHappAutoConnect": "Автоподключение при запуске",
|
||||
"subHappAutoConnectDesc": "Автоматически подключаться к серверу при запуске приложения.",
|
||||
"subHappAutoConnectType": "Критерий автоподключения",
|
||||
|
||||
Reference in New Issue
Block a user