mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-29 02:32:07 +03:00
7aa5fc085f
* feat(tgbot): gate the bot behind three user levels Every Telegram account that found the bot could run /help, /status and /usage, and tap any client button it could forge: nothing separated an account no admin had bound from a customer. Each update now resolves to stranger, client or admin, and commands are allowlisted per level so a command added later stays admin-only until it is listed. A stranger may run /start and /id only, and /start answers with the ChatID an admin needs to bind it; a stranger's callbacks are answered and dropped. Client detection reads the same tgId lookup as clientOwnedByTgUser, so the level gate and the ownership check agree. The bot also ignores everything outside private chats: authorization keys on the sender while wizard state keys on the chat, and the two are the same identity only in a private chat. * feat(tgbot): bind Telegram accounts through /start deep links Linking a customer meant the customer sending /id and an admin copying the ChatID into the client by hand, which does not scale past a few customers and is easy to get wrong. The admin client card now offers an invite link, t.me/<bot>?start=<subId>, and the first account to open it is bound through the existing SetClientTelegramUserID. A subId already grants the subscription, so binding gives the holder nothing the token did not. A subscription that spans several clients binds all of them, and is refused if any part belongs to another account; re-opening your own link is idempotent. Unknown and already-claimed tokens share one reply, so the link cannot be used to probe for valid subIds. * fix(tgbot): harden invite claims after review Review of the access-level and binding change found five problems: - Concurrent claims of one link all read the client as unbound, all bound and all were told so, while only the last write held. Resolving and binding now share one lock, and a bind that fails part-way through a multi-client subscription undoes the bindings it already made. - A subId has no minimum strength and the bot needs only its public username, so /start was an unthrottled guessing oracle. Non-admin claim attempts are capped at five per account per hour, the first refused one notifies the admins, and the Subscription ID field now says it doubles as the bot invite code. - levelOf expanded every inbound's client JSON on every non-admin update. It now reads the indexed tg_id column of the clients table. - A button tapped in a group chat was dropped unanswered and kept spinning, with nothing logged. It is answered now, and each ignored chat is logged once. - The subId was pasted raw into the t.me link, so '#' or '&' truncated it and Telegram rejects anything outside A-Za-z0-9_-. The payload is now base64url, and a subId too long for the 64-character limit is refused. * fix(tgbot): answer group chats again and make the claim race test bite ignoredChat dropped every non-private chat because wizard state was keyed by chat while authorization keyed on the sender. #6604 on main re-keyed that state by (chat, user) so admins can drive the bot from a group, so after the merge the drop only took the whole bot away from those admins, report keyboards sent to a group included. The level gate already keys on the sender, so group chats need no special case. TestConcurrentClaimsBindOnlyOneAccount passed with inviteClaimMu removed: the first claimant took the pool's idle connection and bound before the rest had opened theirs, so no two ever raced. It now holds the inbound write the binds need until every claimant has resolved, and fails without the lock ("6 accounts told they bound"). TestCommandAllowed restated the commandsByLevel map; TestGateCommand drives the same allowlist through gateCommand. TestIgnoredChat goes with the code it pinned. * docs(tgbot): document access levels and invite links The command table still said /help and /status answer anyone. An account no admin has linked now reaches only /start and /id, and a customer is linked through the client card's Invite Link, whose token is the Subscription ID. Updated in en, fa, ru and zh. --------- Co-authored-by: MHSanaei <ho3ein.sanaei@gmail.com>
306 lines
9.2 KiB
Go
306 lines
9.2 KiB
Go
package service
|
|
|
|
import (
|
|
"encoding/json"
|
|
"errors"
|
|
"strings"
|
|
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
|
|
"github.com/mhsanaei/3x-ui/v3/internal/xray"
|
|
|
|
"gorm.io/gorm"
|
|
)
|
|
|
|
func (s *ClientService) GetRecordByEmail(tx *gorm.DB, email string) (*model.ClientRecord, error) {
|
|
if tx == nil {
|
|
tx = database.GetDB()
|
|
}
|
|
row := &model.ClientRecord{}
|
|
err := tx.Where("email = ?", email).First(row).Error
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return row, nil
|
|
}
|
|
|
|
// EffectiveFlow returns the client's flow from the first flow-capable inbound
|
|
// it is attached to (lowest inbound_id with a non-empty flow_override). The
|
|
// canonical clients.Flow column is unreliable for multi-inbound clients: a
|
|
// non-flow inbound (Hysteria, WS, gRPC, …) carries an empty flow and, when its
|
|
// SyncInbound runs last, overwrites the column to "" even though a VLESS Reality
|
|
// inbound stored a real flow. The per-inbound flow_override is always correct,
|
|
// so derive the display flow from it (order-independent). See issue #4792.
|
|
func (s *ClientService) EffectiveFlow(tx *gorm.DB, recordId int) (string, error) {
|
|
if tx == nil {
|
|
tx = database.GetDB()
|
|
}
|
|
var flows []string
|
|
err := tx.Model(&model.ClientInbound{}).
|
|
Where("client_id = ? AND flow_override <> ?", recordId, "").
|
|
Order("inbound_id ASC").
|
|
Limit(1).
|
|
Pluck("flow_override", &flows).Error
|
|
if err != nil {
|
|
return "", err
|
|
}
|
|
if len(flows) == 0 {
|
|
return "", nil
|
|
}
|
|
return flows[0], nil
|
|
}
|
|
|
|
// EffectiveFlowsByEmails resolves the intended flow (non-empty flow_override,
|
|
// lowest inbound_id first — same rule as EffectiveFlow) for many clients in one
|
|
// query, keyed by email. Emails absent from the result carry no flow anywhere.
|
|
// Batched so flow restoration on an inbound with many clients is O(1) queries
|
|
// instead of O(clients). Used to restore a stripped flow onto an inbound that
|
|
// has just become flow-eligible.
|
|
func (s *ClientService) EffectiveFlowsByEmails(tx *gorm.DB, emails []string) (map[string]string, error) {
|
|
if tx == nil {
|
|
tx = database.GetDB()
|
|
}
|
|
out := make(map[string]string, len(emails))
|
|
if len(emails) == 0 {
|
|
return out, nil
|
|
}
|
|
type row struct {
|
|
Email string
|
|
Flow string `gorm:"column:flow_override"`
|
|
}
|
|
for _, batch := range chunkStrings(emails, sqlInChunk) {
|
|
var rows []row
|
|
err := tx.Table("client_inbounds").
|
|
Select("clients.email AS email, client_inbounds.flow_override AS flow_override").
|
|
Joins("JOIN clients ON clients.id = client_inbounds.client_id").
|
|
Where("clients.email IN ? AND client_inbounds.flow_override <> ?", batch, "").
|
|
Order("client_inbounds.inbound_id ASC").
|
|
Scan(&rows).Error
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
for _, r := range rows {
|
|
if _, seen := out[r.Email]; !seen { // ordered by inbound_id ASC → first = lowest
|
|
out[r.Email] = r.Flow
|
|
}
|
|
}
|
|
}
|
|
return out, nil
|
|
}
|
|
|
|
func (s *ClientService) GetInboundIdsForEmail(tx *gorm.DB, email string) ([]int, error) {
|
|
if tx == nil {
|
|
tx = database.GetDB()
|
|
}
|
|
var ids []int
|
|
err := tx.Table("client_inbounds").
|
|
Select("client_inbounds.inbound_id").
|
|
Joins("JOIN clients ON clients.id = client_inbounds.client_id").
|
|
Where("clients.email = ?", email).
|
|
Scan(&ids).Error
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return ids, nil
|
|
}
|
|
|
|
// sub_id carries a plain index, not a unique one: one subscription can cover
|
|
// several clients, so callers acting on a subId must handle all of them.
|
|
func (s *ClientService) GetRecordsBySubID(subId string) ([]*model.ClientRecord, error) {
|
|
if subId == "" {
|
|
return nil, errors.New("sub_id must not be empty")
|
|
}
|
|
var rows []*model.ClientRecord
|
|
err := database.GetDB().Where("sub_id = ?", subId).Order("id ASC").Find(&rows).Error
|
|
return rows, err
|
|
}
|
|
|
|
func (s *ClientService) GetRecordsByTgID(tgId int64) ([]*model.ClientRecord, error) {
|
|
if tgId <= 0 {
|
|
return nil, errors.New("tg_id must be a positive integer")
|
|
}
|
|
var rows []*model.ClientRecord
|
|
err := database.GetDB().Where("tg_id = ?", tgId).Find(&rows).Error
|
|
return rows, err
|
|
}
|
|
|
|
func (s *ClientService) GetByID(id int) (*model.ClientRecord, error) {
|
|
row := &model.ClientRecord{}
|
|
if err := database.GetDB().Where("id = ?", id).First(row).Error; err != nil {
|
|
return nil, err
|
|
}
|
|
return row, nil
|
|
}
|
|
|
|
func (s *ClientService) GetInboundIdsForRecord(id int) ([]int, error) {
|
|
var ids []int
|
|
err := database.GetDB().Table("client_inbounds").
|
|
Where("client_id = ?", id).
|
|
Order("inbound_id ASC").
|
|
Pluck("inbound_id", &ids).Error
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
return ids, nil
|
|
}
|
|
|
|
// TunnelAllowedIPsByInbound returns, for each given WireGuard/AmneziaWG
|
|
// inbound id, the real AllowedIPs this email currently has on that specific
|
|
// inbound's own settings JSON -- joined comma-separated, matching the form
|
|
// value shape a single AllowedIPs field already uses. Non-tunnel inbounds
|
|
// and ids the email isn't actually attached to are simply absent from the
|
|
// result (not an error): callers use this to seed a per-protocol display
|
|
// field, and ClientRecord's own single AllowedIPs column can't tell two
|
|
// different protocol addresses apart, which is exactly the gap this closes.
|
|
func (s *ClientService) TunnelAllowedIPsByInbound(inboundSvc *InboundService, email string, inboundIds []int) (map[int]string, error) {
|
|
result := make(map[int]string, len(inboundIds))
|
|
for _, ibId := range inboundIds {
|
|
inbound, err := inboundSvc.GetInbound(ibId)
|
|
if err != nil {
|
|
if errors.Is(err, gorm.ErrRecordNotFound) {
|
|
continue
|
|
}
|
|
return nil, err
|
|
}
|
|
if inbound.Protocol != model.WireGuard && inbound.Protocol != model.AmneziaWG {
|
|
continue
|
|
}
|
|
clients, err := inboundSvc.GetClients(inbound)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
for i := range clients {
|
|
if strings.EqualFold(clients[i].Email, email) {
|
|
result[ibId] = strings.Join(clients[i].AllowedIPs, ",")
|
|
break
|
|
}
|
|
}
|
|
}
|
|
return result, nil
|
|
}
|
|
|
|
func (s *ClientService) List() ([]ClientWithAttachments, error) {
|
|
db := database.GetDB()
|
|
var rows []model.ClientRecord
|
|
if err := db.Order("id ASC").Find(&rows).Error; err != nil {
|
|
return nil, err
|
|
}
|
|
if len(rows) == 0 {
|
|
return []ClientWithAttachments{}, nil
|
|
}
|
|
|
|
clientIds := make([]int, 0, len(rows))
|
|
emails := make([]string, 0, len(rows))
|
|
for i := range rows {
|
|
clientIds = append(clientIds, rows[i].Id)
|
|
if rows[i].Email != "" {
|
|
emails = append(emails, rows[i].Email)
|
|
}
|
|
}
|
|
|
|
attachments := make(map[int][]int, len(rows))
|
|
for _, batch := range chunkInts(clientIds, sqlInChunk) {
|
|
var links []model.ClientInbound
|
|
if err := db.Where("client_id IN ?", batch).Find(&links).Error; err != nil {
|
|
return nil, err
|
|
}
|
|
for _, l := range links {
|
|
attachments[l.ClientId] = append(attachments[l.ClientId], l.InboundId)
|
|
}
|
|
}
|
|
|
|
trafficByEmail := make(map[string]*xray.ClientTraffic, len(emails))
|
|
if len(emails) > 0 {
|
|
var stats []xray.ClientTraffic
|
|
for _, batch := range chunkStrings(emails, sqlInChunk) {
|
|
var batchStats []xray.ClientTraffic
|
|
if err := db.Where("email IN ?", batch).Find(&batchStats).Error; err != nil {
|
|
return nil, err
|
|
}
|
|
stats = append(stats, batchStats...)
|
|
}
|
|
overlayGlobalTrafficValues(db, stats)
|
|
for i := range stats {
|
|
trafficByEmail[stats[i].Email] = &stats[i]
|
|
}
|
|
}
|
|
|
|
out := make([]ClientWithAttachments, 0, len(rows))
|
|
for i := range rows {
|
|
out = append(out, ClientWithAttachments{
|
|
ClientRecord: rows[i],
|
|
InboundIds: attachments[rows[i].Id],
|
|
Traffic: trafficByEmail[rows[i].Email],
|
|
})
|
|
}
|
|
return out, nil
|
|
}
|
|
|
|
func (s *ClientService) HasPendingNode(inboundSvc *InboundService, email string) bool {
|
|
if strings.TrimSpace(email) == "" {
|
|
return false
|
|
}
|
|
ids, err := s.GetInboundIdsForEmail(nil, email)
|
|
if err != nil {
|
|
return false
|
|
}
|
|
return inboundSvc.AnyNodePending(ids)
|
|
}
|
|
|
|
// findInboundIdsByClientEmail returns every inbound whose settings.clients[]
|
|
// JSON contains an entry with the given email. Driver-portable (no JSON
|
|
// operators) by parsing in Go — fine for the rare fallback path.
|
|
func (s *ClientService) findInboundIdsByClientEmail(email string) ([]int, error) {
|
|
var inbounds []model.Inbound
|
|
if err := database.GetDB().
|
|
Select("id, settings").
|
|
Where("settings LIKE ?", "%"+email+"%").
|
|
Find(&inbounds).Error; err != nil {
|
|
return nil, err
|
|
}
|
|
out := make([]int, 0, len(inbounds))
|
|
for _, ib := range inbounds {
|
|
var settings map[string]any
|
|
if err := json.Unmarshal([]byte(ib.Settings), &settings); err != nil {
|
|
continue
|
|
}
|
|
clients, ok := settings["clients"].([]any)
|
|
if !ok {
|
|
continue
|
|
}
|
|
for _, c := range clients {
|
|
cm, ok := c.(map[string]any)
|
|
if !ok {
|
|
continue
|
|
}
|
|
if cEmail, _ := cm["email"].(string); cEmail == email {
|
|
out = append(out, ib.Id)
|
|
break
|
|
}
|
|
}
|
|
}
|
|
return out, nil
|
|
}
|
|
|
|
// clientRecordsByEmail batch-loads client rows for emails, keyed by email.
|
|
// Callers pass an already-deduplicated list; absent addresses are simply
|
|
// missing from the map.
|
|
func clientRecordsByEmail(tx *gorm.DB, emails []string) (map[string]*model.ClientRecord, error) {
|
|
if tx == nil {
|
|
tx = database.GetDB()
|
|
}
|
|
var records []model.ClientRecord
|
|
for _, batch := range chunkStrings(emails, sqlInChunk) {
|
|
var rows []model.ClientRecord
|
|
if err := tx.Where("email IN ?", batch).Find(&rows).Error; err != nil {
|
|
return nil, err
|
|
}
|
|
records = append(records, rows...)
|
|
}
|
|
byEmail := make(map[string]*model.ClientRecord, len(records))
|
|
for i := range records {
|
|
byEmail[records[i].Email] = &records[i]
|
|
}
|
|
return byEmail, nil
|
|
}
|