Files
3x-ui/internal/web/service/inbound_mtproto_apply_test.go
T
MHSanaei 823db05966 fix(inbounds): keep the stored client list and enable on inbound save
Invariant: saving an inbound's configuration never changes which clients it
holds nor whether it is enabled; both have their own endpoints. The edit
modal posts back the clients and the enable flag it loaded when it opened.
A client added meanwhile (another admin, the bot, the API, LDAP) was
detached and its stats deleted; a client deleted meanwhile came back with
its credentials, restoring access that had been revoked; an inbound
switched off meanwhile was switched back on.

For every save but a master's node-sync push, UpdateInbound now takes the
client list and enable from the row it re-reads inside the writer; this
replaces the lifecycle-only carry from the previous commit. Client
validation (renewal schedule, Hysteria auth, TUIC credentials) moves after
that swap so it judges the clients actually saved: a protocol switch keeps
the stored clients, and #6268's refusal must apply to them.

The edit form no longer loads or sends clients, so neither the JSON editor
nor validation sees a copy the server ignores, and the enable switch shows
only when adding; the list toggle (/setEnable) covers existing inbounds.

Tests that added or re-keyed clients through a panel inbound save pinned
the old rule; they now drive the master-push path, where payload clients
still apply.
2026-09-28 13:23:48 +02:00

101 lines
3.2 KiB
Go

package service
import (
"fmt"
"os"
"path/filepath"
"strings"
"testing"
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
"github.com/mhsanaei/3x-ui/v3/internal/mtproto"
"github.com/mhsanaei/3x-ui/v3/internal/web/runtime"
)
func mtgConfigPath(t *testing.T, inboundId int) string {
t.Helper()
return filepath.Join(os.Getenv("XUI_BIN_FOLDER"), "mtproto", fmt.Sprintf("mtg-%d.toml", inboundId))
}
func readMtgConfig(t *testing.T, inboundId int) string {
t.Helper()
data, err := os.ReadFile(mtgConfigPath(t, inboundId))
if err != nil {
t.Fatalf("read mtg config: %v", err)
}
return string(data)
}
func TestUpdateInboundMtprotoUnchangedDoesNotRestart(t *testing.T) {
setupConflictDB(t)
pidFile := installFakeMtg(t)
runtime.SetManager(runtime.NewManager(runtime.LocalDeps{APIPort: func() int { return 0 }}))
t.Cleanup(func() { runtime.SetManager(nil) })
seedInboundConflict(t, "mt-apply", "", 46101, model.MTProto,
"",
`{"clients":[`+
`{"email":"mtga","secret":"`+mtprotoTestSecretA+`","enable":true},`+
`{"email":"mtgb","secret":"`+mtprotoTestSecretB+`","enable":true}]}`)
seeded := loadInboundByTag(t, "mt-apply")
seedClientTraffic(t, seeded.Id, "mtga", true)
seedClientTraffic(t, seeded.Id, "mtgb", true)
svc := &InboundService{}
primed, ok := mtproto.InstanceFromInbound(seeded)
if !ok {
t.Fatal("seed inbound must produce an mtg instance")
}
if err := mtproto.GetManager().Ensure(primed); err != nil {
t.Fatalf("prime mtg: %v", err)
}
t.Cleanup(func() { mtproto.GetManager().Remove(seeded.Id) })
waitForSpawns(t, pidFile, 1)
primedConfig := readMtgConfig(t, seeded.Id)
saveAndAssertKept := func(t *testing.T, mutate func(*model.Inbound)) {
t.Helper()
update := *loadInboundByTag(t, "mt-apply")
mutate(&update)
_, needRestart, err := svc.UpdateInbound(&update)
if err != nil {
t.Fatalf("UpdateInbound: %v", err)
}
if needRestart {
t.Fatal("an mtproto-only edit must not request an xray restart")
}
assertNoNewSpawns(t, pidFile, 1)
if got := readMtgConfig(t, seeded.Id); got != primedConfig {
t.Fatalf("config rewritten on a no-op edit:\nbefore:\n%s\nafter:\n%s", primedConfig, got)
}
}
t.Run("unchangedSaveKeepsProcess", func(t *testing.T) {
saveAndAssertKept(t, func(*model.Inbound) {})
})
t.Run("remarkOnlyEditKeepsProcess", func(t *testing.T) {
saveAndAssertKept(t, func(ib *model.Inbound) { ib.Remark = "renamed while users stay connected" })
})
t.Run("rekeyedSecretRestartsProcess", func(t *testing.T) {
update := *loadInboundByTag(t, "mt-apply")
update.Settings = strings.Replace(update.Settings, mtprotoTestSecretA, mtprotoTestSecretD, 1)
if !strings.Contains(update.Settings, mtprotoTestSecretD) {
t.Fatal("fixture must contain the re-keyed secret")
}
// Clients reach an inbound save only as a master's push to its node.
_, needRestart, err := (&InboundService{FromNodeSync: true}).UpdateInbound(&update)
if err != nil {
t.Fatalf("UpdateInbound: %v", err)
}
if needRestart {
t.Fatal("an mtproto secret change must not request an xray restart")
}
waitForSpawns(t, pidFile, 2)
if got := readMtgConfig(t, seeded.Id); !strings.Contains(got, mtprotoTestSecretD) {
t.Fatalf("restarted config must carry the new secret:\n%s", got)
}
})
}