mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-10-02 12:12:08 +03:00
e790f46757
* fix(xray): restart when a diff strands a client's live session Disabling or deleting a client took it out of the generated config and the hot path applied that with AlterInbound/RemoveUser, which only drops the credential (vless, vmess, trojan and shadowsocks all keep the established session running) -- so the panel showed a disabled client whose connection kept passing traffic, and the core offers no API to close one session. A diff that removes a user without re-adding the same email under the same tag is that case: honour the operator's restart-on-client-disable setting and let the caller replace the process, which is already how an auto-disabled client loses its session. An edit re-adds the email and keeps the hot path. * chore(i18n): cover manual disable and delete in the restart-setting description The setting now also decides what happens when a client is disabled or deleted by hand, so the description cannot keep naming only the automatic path. All 13 locales updated in the same commit to keep the wording consistent. * fix(xray): reach the guard from the manual switch and from every protocol Round-1 findings on this PR. The guard sat in tryHotApply, but a manual disable or delete applies through runtime.Runtime and finishes with needRestart false, so none of the three RestartXray schedulers fired and the predicate was never reached: the session in #6533 kept flowing. The apply layer now asks for the restart the setting promises when the client actually leaves the config, on the single-client update and delete paths and on bulk disable, and only for local inbounds so a node row cannot make the master restart its own core. The predicate itself could not fire for shadowsocks or hysteria either, because RemovedUsers is only produced for the protocols diffInboundUsers will diff. The diff now also compares settings.clients of an inbound present in both configs, which is the one shape every account list shares, so those protocols reach the guard through the inbound instead of through nothing. TestManualClientDisableHonoursRestartSetting fails without the apply-layer fix ("needRestart = false, want true" with the setting on) and TestHotDiffDropsUsersOnProtocolsItCannotDiff fails without the diff fix -- both watched red. The two three-line comments this PR added are back inside the cap. * docs(i18n): stop scoping restartXrayOnClientDisable to auto-disable The setting now covers a client disabled or deleted by hand as well, so its title no longer says "Auto" in all 13 locales, and the docs callouts in en, ru, zh and fa describe the same behaviour instead of the auto-only one.
68 lines
6.0 KiB
Plaintext
68 lines
6.0 KiB
Plaintext
---
|
|
title: کلاینتها
|
|
description: مدیریت کلاینتهای 3x-ui — اعتبارنامهها، محدودیت ترافیک و انقضا، محدودیت IP، گروهها، اقدامات گروهی، لینکهای خارجی و وضعیت آنلاین.
|
|
icon: Users
|
|
---
|
|
|
|
یک **کلاینت** یک کاربر منفرد است که با یک **ایمیل** یکتا شناسایی میشود. در پنل
|
|
فعلی، کلاینتها رکوردهای درجهیک هستند که میتوانند همزمان به **چندین ورودی**
|
|
متصل شوند و حسابداری ترافیک بهصورت جداگانه برای هر کلاینت انجام میشود.
|
|
|
|
## فیلدهای کلاینت
|
|
|
|
| فیلد | اعمال بر | معنی |
|
|
| -------------- | --------------------- | ------------------------------------------------------------------ |
|
|
| **Email** | همه | شناسهی یکتا که برای حسابداری و جستوجوها استفاده میشود. |
|
|
| **ID (UUID)** | VLESS, VMess, TUIC | اعتبارنامهی کلاینت. |
|
|
| **Password** | Trojan, Shadowsocks, TUIC | اعتبارنامهی کلاینت. |
|
|
| **Auth** | Hysteria2 | اعتبارنامهی کلاینت. |
|
|
| **Flow** | VLESS | جریان XTLS، برای مثال `xtls-rprx-vision`. |
|
|
| **Limit IP** | همه (بهجز TUIC) | بیشینهی تعداد IPهای مبدأ همزمان (با Fail2ban اعمال میشود). |
|
|
| **Total (GB)** | همه (بهجز TUIC) | سهمیهی ترافیک؛ هنگام اتمام، کلاینت غیرفعال میشود (برای TUIC محدودیت در سطح ورودی تعیین میشود). |
|
|
| **Expiry** | همه | تاریخی که پس از آن کلاینت از کار میافتد. |
|
|
| **Reset** | همه | دورهی تمدید خودکار به **روز** (سهمیه را از نو میچرخاند). |
|
|
| **Telegram ID**| همه | کلاینت را به یک کاربر Telegram برای سلفسرویس/اعلانها پیوند میدهد.|
|
|
| **Sub ID** | همه | شناسهی اشتراک که لینکهای این کلاینت را گروهبندی میکند. |
|
|
| **Group** | همه | گروه اختیاری کلاینت برای سازماندهی و فیلترکردن گروهی. |
|
|
| **Comment** | همه | یادداشت متنی آزاد. |
|
|
|
|
<Callout type="info">
|
|
رسیدن به محدودیت **ترافیک** یا **انقضا** کلاینت را غیرفعال میکند؛ غیرفعالسازی یا
|
|
حذف دستی کلاینت هم همین اثر را دارد؛ در این حالت پنل Xray را راهاندازی مجدد میکند
|
|
(`restartXrayOnClientDisable`، بهصورت پیشفرض فعال).
|
|
</Callout>
|
|
|
|
## محدودیتها و کنترل IP
|
|
|
|
- سقفهای **ترافیک / انقضا** هنگام رسیدن، کلاینت را غیرفعال میکنند؛ یک دورهی
|
|
**Reset** سهمیه را بهصورت خودکار تمدید میکند.
|
|
- **Limit IP** تعداد IPهای مبدأ همزمان را محدود میکند. اعمال آن به Fail2ban متکی
|
|
است — به [امنیت](/docs/operations/security) مراجعه کنید. میتوانید IPهای اخیر یک
|
|
کلاینت را مشاهده کرده و آنها را از بخش اقدامات کلاینت پاک کنید.
|
|
- **وضعیت آنلاین** و زمانهای **آخرینبار آنلاین** برای هر کلاینت (و در پیکربندیهای
|
|
چندنودی برای هر نود) ثبت میشوند.
|
|
|
|
## لینکهای اشتراکگذاری و لینکهای خارجی
|
|
|
|
هر کلاینت برای ورودیهایش لینکهای اشتراکگذاری و یک کد QR دارد، بهعلاوهی یک
|
|
[اشتراک](/docs/config/subscription) ترکیبی. همچنین میتوانید **لینکهای خارجی** به
|
|
یک کلاینت متصل کنید — لینکهای اضافی `vless://`، `vmess://`، `trojan://`، `ss://`،
|
|
`hysteria2://` یا `wireguard://`، یا یک URL اشتراک از راه دور — تا در کنار
|
|
لینکهای تولیدشده توسط پنل، در اشتراک کلاینت نمایش داده شوند.
|
|
|
|
برای بررسی دقیق محتویات یک لینک، آن را در
|
|
[بازرس لینک اشتراکگذاری](/docs/config/share-links) جایگذاری کنید.
|
|
|
|
## اقدامات گروهی
|
|
|
|
برای مدیریت همزمان تعداد زیادی کلاینت، پنل از اقدامات گروهی **ساخت، فعالسازی،
|
|
غیرفعالسازی، حذف، اتصال/قطع اتصال** (به ورودیها)، **بازنشانی ترافیک** و
|
|
**تنظیم** (افزودن روز / افزودن بایت / تعیین flow) پشتیبانی میکند. اقدامات
|
|
نگهداری همچنین به شما امکان میدهند کلاینتهای **تمامشده** (سهمیه/انقضای پایانیافته)
|
|
و کلاینتهای **یتیم** (متصلنشده به هیچ ورودی) را حذف کنید.
|
|
|
|
<Callout type="warn">
|
|
لینک اشتراکگذاری یک کلاینت حاوی اعتبارنامهی آن است. با لینکها و کدهای QR مانند
|
|
رمز عبور رفتار کنید و در صورت نشت یکی از آنها، اعتبارنامه را تعویض کنید.
|
|
</Callout>
|