Files
3x-ui/docs/content/docs/fa/config/clients.mdx
T
BlindMaster24 e790f46757 fix(xray): restart when a diff strands a client's live session (#6550)
* fix(xray): restart when a diff strands a client's live session

Disabling or deleting a client took it out of the generated config and the
hot path applied that with AlterInbound/RemoveUser, which only drops the
credential (vless, vmess, trojan and shadowsocks all keep the established
session running) -- so the panel showed a disabled client whose connection
kept passing traffic, and the core offers no API to close one session.

A diff that removes a user without re-adding the same email under the same
tag is that case: honour the operator's restart-on-client-disable setting and
let the caller replace the process, which is already how an auto-disabled
client loses its session. An edit re-adds the email and keeps the hot path.

* chore(i18n): cover manual disable and delete in the restart-setting description

The setting now also decides what happens when a client is disabled or deleted
by hand, so the description cannot keep naming only the automatic path. All 13
locales updated in the same commit to keep the wording consistent.

* fix(xray): reach the guard from the manual switch and from every protocol

Round-1 findings on this PR. The guard sat in tryHotApply, but a manual disable
or delete applies through runtime.Runtime and finishes with needRestart false,
so none of the three RestartXray schedulers fired and the predicate was never
reached: the session in #6533 kept flowing. The apply layer now asks for the
restart the setting promises when the client actually leaves the config, on the
single-client update and delete paths and on bulk disable, and only for local
inbounds so a node row cannot make the master restart its own core.

The predicate itself could not fire for shadowsocks or hysteria either, because
RemovedUsers is only produced for the protocols diffInboundUsers will diff. The
diff now also compares settings.clients of an inbound present in both configs,
which is the one shape every account list shares, so those protocols reach the
guard through the inbound instead of through nothing.

TestManualClientDisableHonoursRestartSetting fails without the apply-layer fix
("needRestart = false, want true" with the setting on) and
TestHotDiffDropsUsersOnProtocolsItCannotDiff fails without the diff fix -- both
watched red. The two three-line comments this PR added are back inside the cap.

* docs(i18n): stop scoping restartXrayOnClientDisable to auto-disable

The setting now covers a client disabled or deleted by hand as well, so its
title no longer says "Auto" in all 13 locales, and the docs callouts in en, ru,
zh and fa describe the same behaviour instead of the auto-only one.
2026-09-15 15:39:40 +03:00

68 lines
6.0 KiB
Plaintext

---
title: کلاینت‌ها
description: مدیریت کلاینت‌های 3x-ui — اعتبارنامه‌ها، محدودیت ترافیک و انقضا، محدودیت IP، گروه‌ها، اقدامات گروهی، لینک‌های خارجی و وضعیت آنلاین.
icon: Users
---
یک **کلاینت** یک کاربر منفرد است که با یک **ایمیل** یکتا شناسایی می‌شود. در پنل
فعلی، کلاینت‌ها رکوردهای درجه‌یک هستند که می‌توانند هم‌زمان به **چندین ورودی**
متصل شوند و حساب‌داری ترافیک به‌صورت جداگانه برای هر کلاینت انجام می‌شود.
## فیلدهای کلاینت
| فیلد | اعمال بر | معنی |
| -------------- | --------------------- | ------------------------------------------------------------------ |
| **Email** | همه | شناسه‌ی یکتا که برای حساب‌داری و جست‌وجوها استفاده می‌شود. |
| **ID (UUID)** | VLESS, VMess, TUIC | اعتبارنامه‌ی کلاینت. |
| **Password** | Trojan, Shadowsocks, TUIC | اعتبارنامه‌ی کلاینت. |
| **Auth** | Hysteria2 | اعتبارنامه‌ی کلاینت. |
| **Flow** | VLESS | جریان XTLS، برای مثال `xtls-rprx-vision`. |
| **Limit IP** | همه (به‌جز TUIC) | بیشینه‌ی تعداد IPهای مبدأ هم‌زمان (با Fail2ban اعمال می‌شود). |
| **Total (GB)** | همه (به‌جز TUIC) | سهمیه‌ی ترافیک؛ هنگام اتمام، کلاینت غیرفعال می‌شود (برای TUIC محدودیت در سطح ورودی تعیین می‌شود). |
| **Expiry** | همه | تاریخی که پس از آن کلاینت از کار می‌افتد. |
| **Reset** | همه | دوره‌ی تمدید خودکار به **روز** (سهمیه را از نو می‌چرخاند). |
| **Telegram ID**| همه | کلاینت را به یک کاربر Telegram برای سلف‌سرویس/اعلان‌ها پیوند می‌دهد.|
| **Sub ID** | همه | شناسه‌ی اشتراک که لینک‌های این کلاینت را گروه‌بندی می‌کند. |
| **Group** | همه | گروه اختیاری کلاینت برای سازمان‌دهی و فیلترکردن گروهی. |
| **Comment** | همه | یادداشت متنی آزاد. |
<Callout type="info">
رسیدن به محدودیت **ترافیک** یا **انقضا** کلاینت را غیرفعال می‌کند؛ غیرفعال‌سازی یا
حذف دستی کلاینت هم همین اثر را دارد؛ در این حالت پنل Xray را راه‌اندازی مجدد می‌کند
(`restartXrayOnClientDisable`، به‌صورت پیش‌فرض فعال).
</Callout>
## محدودیت‌ها و کنترل IP
- سقف‌های **ترافیک / انقضا** هنگام رسیدن، کلاینت را غیرفعال می‌کنند؛ یک دوره‌ی
**Reset** سهمیه را به‌صورت خودکار تمدید می‌کند.
- **Limit IP** تعداد IPهای مبدأ هم‌زمان را محدود می‌کند. اعمال آن به Fail2ban متکی
است — به [امنیت](/docs/operations/security) مراجعه کنید. می‌توانید IPهای اخیر یک
کلاینت را مشاهده کرده و آن‌ها را از بخش اقدامات کلاینت پاک کنید.
- **وضعیت آنلاین** و زمان‌های **آخرین‌بار آنلاین** برای هر کلاینت (و در پیکربندی‌های
چندنودی برای هر نود) ثبت می‌شوند.
## لینک‌های اشتراک‌گذاری و لینک‌های خارجی
هر کلاینت برای ورودی‌هایش لینک‌های اشتراک‌گذاری و یک کد QR دارد، به‌علاوه‌ی یک
[اشتراک](/docs/config/subscription) ترکیبی. همچنین می‌توانید **لینک‌های خارجی** به
یک کلاینت متصل کنید — لینک‌های اضافی `vless://`، `vmess://`، `trojan://`، `ss://`،
`hysteria2://` یا `wireguard://`، یا یک URL اشتراک از راه دور — تا در کنار
لینک‌های تولیدشده توسط پنل، در اشتراک کلاینت نمایش داده شوند.
برای بررسی دقیق محتویات یک لینک، آن را در
[بازرس لینک اشتراک‌گذاری](/docs/config/share-links) جای‌گذاری کنید.
## اقدامات گروهی
برای مدیریت هم‌زمان تعداد زیادی کلاینت، پنل از اقدامات گروهی **ساخت، فعال‌سازی،
غیرفعال‌سازی، حذف، اتصال/قطع اتصال** (به ورودی‌ها)، **بازنشانی ترافیک** و
**تنظیم** (افزودن روز / افزودن بایت / تعیین flow) پشتیبانی می‌کند. اقدامات
نگه‌داری همچنین به شما امکان می‌دهند کلاینت‌های **تمام‌شده** (سهمیه/انقضای پایان‌یافته)
و کلاینت‌های **یتیم** (متصل‌نشده به هیچ ورودی) را حذف کنید.
<Callout type="warn">
لینک اشتراک‌گذاری یک کلاینت حاوی اعتبارنامه‌ی آن است. با لینک‌ها و کدهای QR مانند
رمز عبور رفتار کنید و در صورت نشت یکی از آن‌ها، اعتبارنامه را تعویض کنید.
</Callout>