Files
3x-ui/docs/content/docs/ru/config/clients.mdx
T
BlindMaster24 e790f46757 fix(xray): restart when a diff strands a client's live session (#6550)
* fix(xray): restart when a diff strands a client's live session

Disabling or deleting a client took it out of the generated config and the
hot path applied that with AlterInbound/RemoveUser, which only drops the
credential (vless, vmess, trojan and shadowsocks all keep the established
session running) -- so the panel showed a disabled client whose connection
kept passing traffic, and the core offers no API to close one session.

A diff that removes a user without re-adding the same email under the same
tag is that case: honour the operator's restart-on-client-disable setting and
let the caller replace the process, which is already how an auto-disabled
client loses its session. An edit re-adds the email and keeps the hot path.

* chore(i18n): cover manual disable and delete in the restart-setting description

The setting now also decides what happens when a client is disabled or deleted
by hand, so the description cannot keep naming only the automatic path. All 13
locales updated in the same commit to keep the wording consistent.

* fix(xray): reach the guard from the manual switch and from every protocol

Round-1 findings on this PR. The guard sat in tryHotApply, but a manual disable
or delete applies through runtime.Runtime and finishes with needRestart false,
so none of the three RestartXray schedulers fired and the predicate was never
reached: the session in #6533 kept flowing. The apply layer now asks for the
restart the setting promises when the client actually leaves the config, on the
single-client update and delete paths and on bulk disable, and only for local
inbounds so a node row cannot make the master restart its own core.

The predicate itself could not fire for shadowsocks or hysteria either, because
RemovedUsers is only produced for the protocols diffInboundUsers will diff. The
diff now also compares settings.clients of an inbound present in both configs,
which is the one shape every account list shares, so those protocols reach the
guard through the inbound instead of through nothing.

TestManualClientDisableHonoursRestartSetting fails without the apply-layer fix
("needRestart = false, want true" with the setting on) and
TestHotDiffDropsUsersOnProtocolsItCannotDiff fails without the diff fix -- both
watched red. The two three-line comments this PR added are back inside the cap.

* docs(i18n): stop scoping restartXrayOnClientDisable to auto-disable

The setting now covers a client disabled or deleted by hand as well, so its
title no longer says "Auto" in all 13 locales, and the docs callouts in en, ru,
zh and fa describe the same behaviour instead of the auto-only one.
2026-09-15 15:39:40 +03:00

73 lines
6.4 KiB
Plaintext
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
---
title: Клиенты
description: Управление клиентами 3x-ui — учётные данные, лимиты трафика и срока действия, ограничения по IP, группы, массовые операции, внешние ссылки и статус онлайн.
icon: Users
---
**Клиент** — это отдельный пользователь, идентифицируемый по уникальному
**email**. В текущей версии панели клиенты являются полноценными записями,
которые можно одновременно привязать к **нескольким входящим подключениям**
(inbounds), с учётом трафика по каждому клиенту.
## Поля клиента
| Поле | Применяется к | Значение |
| -------------- | --------------------- | ------------------------------------------------------------------ |
| **Email** | все | Уникальный идентификатор для учёта трафика и поиска. |
| **ID (UUID)** | VLESS, VMess, TUIC | Учётные данные клиента. |
| **Password** | Trojan, Shadowsocks, TUIC | Учётные данные клиента. |
| **Auth** | Hysteria2 | Учётные данные клиента. |
| **Flow** | VLESS | Поток XTLS, например `xtls-rprx-vision`. |
| **Limit IP** | все (кроме TUIC) | Максимум одновременных IP-адресов источника (контролируется через Fail2ban). |
| **Total (GB)** | все (кроме TUIC) | Квота трафика; при исчерпании клиент отключается (для TUIC лимит задаётся на уровне инбаунда). |
| **Expiry** | все | Дата, после которой клиент перестаёт работать. |
| **Reset** | все | Период автопродления в **днях** (обнуляет квоту). |
| **Telegram ID**| все | Привязывает клиента к пользователю Telegram для самообслуживания/уведомлений.|
| **Sub ID** | все | Идентификатор подписки, группирующий ссылки этого клиента. |
| **Group** | все | Необязательная группа клиента для организации и массовой фильтрации.|
| **Comment** | все | Произвольная текстовая заметка. |
<Callout type="info">
Достижение лимита **трафика** или **срока действия** отключает клиента, как и
ручное отключение или удаление; тогда панель перезапускает Xray
(`restartXrayOnClientDisable`, включено по умолчанию).
</Callout>
## Лимиты и контроль IP
- Ограничения по **трафику / сроку действия** отключают клиента при достижении;
период **Reset** автоматически обновляет квоту.
- **Limit IP** ограничивает количество одновременных IP-адресов источника.
Контроль осуществляется с помощью Fail2ban — см.
[Безопасность](/docs/operations/security). Вы можете просмотреть недавние
IP-адреса клиента и очистить их из действий клиента.
- **Статус онлайн** и время **последнего входа** отслеживаются по каждому
клиенту (и по каждому узлу в конфигурациях с несколькими узлами).
## Ссылки для общего доступа и внешние ссылки
У каждого клиента есть ссылки для общего доступа и QR-код для его входящих
подключений, а также объединённая [подписка](/docs/config/subscription). К
клиенту также можно привязать **внешние ссылки** — дополнительные ссылки
`vless://`, `vmess://`, `trojan://`, `ss://`, `hysteria2://` или
`wireguard://`, либо удалённый URL подписки, — чтобы они отображались рядом со
сгенерированными панелью в подписке клиента.
Чтобы точно узнать, что содержит ссылка, вставьте её в
[инспектор ссылок для общего доступа](/docs/config/share-links).
## Массовые операции
Для управления множеством клиентов одновременно панель поддерживает массовые
операции **создания, включения, отключения, удаления, привязки/отвязки** (к
входящим подключениям), **сброса трафика** и **корректировки** (добавить дни /
добавить байты / задать flow). Операции обслуживания также позволяют удалять
**исчерпанных** клиентов (исчерпана квота/срок действия) и **осиротевших**
клиентов (не привязанных ни к одному входящему подключению).
<Callout type="warn">
Ссылка клиента для общего доступа содержит его учётные данные. Относитесь к
ссылкам и QR-кодам как к паролям и меняйте учётные данные, если что-то из
этого утекло.
</Callout>