Files
3x-ui/docs
Namso9 89ee1242bd feat(sub): add read-only HWID device-slot status endpoint (#6380)
* feat(sub): add read-only HWID device-slot status endpoint

Closes #6357

A client with an HWID limit had no way to tell a subscriber how many device
slots were left: /{subPath}/{subId} only exposes the gate as a boolean through
X-Hwid-* headers on a 404, and ?format=info carries no limitHwid or registered
count. Every "why can't I connect on my new phone" case therefore had to be
answered by the operator by hand.

GET /{subPath}/{subId}/hwid-status now returns the aggregate counters:

  {"active":true,"limit":2,"registered":1,"remaining":1,"full":false}

- SELECT-only. It never registers an hwid, never touches last_seen and never
  calls the enforcement path, so asking about a slot cannot spend one.
- Counters only: no hwid value or hash, no email, no device metadata, no IP,
  no User-Agent, and none of the X-Hwid-* gate headers.
- The subscription id is already the bearer secret for /{subPath}/{subId}, so
  no admin token and no new auth mechanism.
- Unknown and disabled subscriptions both answer a bare 404, with identical
  status, headers and body, so the route cannot be used to probe which
  subscription ids exist.
- No HWID limit configured returns {"active":false,"limit":0,...}.
- No schema change and no migration.

Scoped to enabled clients exactly like effectiveHwidLimitForSubID, so the
reported limit is always the limit the gate enforces on a shared sub_id, and
remaining clamps at zero when the effective limit drops below the number of
registered devices. A separate route leaves /{subPath}/{subId}, ?format=info
and the JSON/Clash routes byte-for-byte unchanged.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>

* fix(sub): document hwid-status as the bare object it returns

The OpenAPI operation for GET /{subPath}/{subId}/hwid-status inherited the
{success,msg,obj} panel envelope from build-openapi.mjs's default 200
response, while the handler writes the HwidSlotStatus struct bare. A client
generated from the spec would read `obj` and never find the counters, and
the description prose contradicted the schema with a hand-written example.

HwidSlotStatus now sits in openapigen's StructAllow with example: tags, the
entry references the generated schema through a `responses` block, and
build-openapi.mjs attaches the generated example to any `responses` entry
that $refs a generated schema, so no example is hand-written. The HEAD
variant the controller registers is documented like its siblings, and the
summary follows the "path prefix is configured by subPath" wording now that
fresh panels randomise the prefix.

Regenerated frontend/public/openapi.json, docs/public/openapi.json and the
subscription-server MDX. openapi-runtime-contracts.test.ts pins the bare
schema, the generated example and the HEAD operation.

---------

Co-authored-by: Claude Opus 5 (1M context) <noreply@anthropic.com>
Co-authored-by: Sanaei <ho3ein.sanaei@gmail.com>
2026-09-11 11:59:35 +02:00
..
2026-07-09 00:45:35 +02:00

3x-ui

3x-ui Documentation

The official documentation and product site for 3x-ui — an advanced web panel for managing Xray-core servers.

Live site CI License: GPL-3.0 Next.js 16 Fumadocs 16

Read the docs →


Overview

This directory (docs/ in the 3x-ui monorepo) contains the source for docs.sanaei.dev — a static-first documentation and marketing site built with Fumadocs on Next.js. It has no backend, no database, and no auth: every page is prerendered and every tool runs entirely in the browser.

What's inside

The documentation walks you through 3x-ui from first install to day-to-day operation:

  • Getting Started — installation, first login, and updating or uninstalling the panel.
  • Configuration — the panel, inbounds, REALITY, transports, clients, subscriptions, and share links.
  • Operations — reverse proxy, multi-node setups, outbounds & routing, backup/restore, the Telegram bot, and security.
  • Reference — environment variables, the database, ports & firewall, and the HTTP API.
  • Help — troubleshooting, FAQ, migration, and how to contribute.

Interactive tools

The site ships with in-browser helpers that generate configuration for you — no data ever leaves your browser:

Tool What it does
REALITY Config Generator Build a valid REALITY inbound configuration.
Share Link Inspector Decode and inspect vless:// / vmess:// share links.
Install Command Builder Assemble the right install command for your setup.
Reverse Proxy Generator Generate reverse-proxy configs (Nginx / Caddy).
Protocol Wizard Pick and configure the right protocol for your needs.
Firewall Rules Generator Produce firewall rules for your ports.

Tech stack

Layer Technology
Framework Next.js 16 (App Router) · React 19
Docs Fumadocs (-ui / -core / -mdx)
Styling Tailwind CSS v4
Search Orama static index
Language TypeScript (strict)
Tests Vitest for the pure lib/xray logic
Tooling pnpm · oxlint · oxfmt

Quick start

This project uses pnpm (npm lockfiles are gitignored). Run everything from the docs/ directory:

cd docs
pnpm install
pnpm dev        # http://localhost:3000

Useful scripts:

Script Description
pnpm dev Start the dev server
pnpm build Production build (also typechecks)
pnpm typecheck Generate MDX/route types and tsc --noEmit
pnpm lint Run oxlint (.oxlintrc.json)
pnpm test Run unit tests (Vitest)

See CONTRIBUTING.md for the full list and project conventions.

Project structure

app/             # Next.js App Router — layouts, home, docs, OG images, search, llms.txt
components/      # React components — interactive tools, home sections, MDX bindings
content/docs/    # MDX documentation, one folder per locale (en · fa · ru · zh)
lib/             # source config, i18n, GitHub stats, and the unit-tested lib/xray logic
public/          # static assets — logos, favicon, openapi.json, CNAME
scripts/         # build-time scripts (API reference generation)
source.config.ts # Fumadocs MDX schema & collection config
next.config.mjs  # Next.js config (static-export gating)
proxy.ts         # i18n middleware

Internationalization

Documentation is authored in English. Persian (fa, RTL), Russian (ru), and Chinese (zh) locales are wired up; untranslated pages fall back to English so they never 404. English URLs are unprefixed; other locales live under /fa, /ru, /zh.

Deployment

The site builds for two targets:

  • Vercel / Nodepnpm build (static search index + prerendered OG images).
  • GitHub Pages (static export)DEPLOY_TARGET=static pnpm buildout/.

Contributing

Contributions are welcome! Setup, scripts, and project conventions live in CONTRIBUTING.md.

License

Licensed under GPL-3.0.