Files
3x-ui/internal/web/service/inbound_hysteria_auth_test.go
T
MHSanaei 823db05966 fix(inbounds): keep the stored client list and enable on inbound save
Invariant: saving an inbound's configuration never changes which clients it
holds nor whether it is enabled; both have their own endpoints. The edit
modal posts back the clients and the enable flag it loaded when it opened.
A client added meanwhile (another admin, the bot, the API, LDAP) was
detached and its stats deleted; a client deleted meanwhile came back with
its credentials, restoring access that had been revoked; an inbound
switched off meanwhile was switched back on.

For every save but a master's node-sync push, UpdateInbound now takes the
client list and enable from the row it re-reads inside the writer; this
replaces the lifecycle-only carry from the previous commit. Client
validation (renewal schedule, Hysteria auth, TUIC credentials) moves after
that swap so it judges the clients actually saved: a protocol switch keeps
the stored clients, and #6268's refusal must apply to them.

The edit form no longer loads or sends clients, so neither the JSON editor
nor validation sees a copy the server ignores, and the enable switch shows
only when adding; the list toggle (/setEnable) covers existing inbounds.

Tests that added or re-keyed clients through a panel inbound save pinned
the old rule; they now drive the master-push path, where payload clients
still apply.
2026-09-28 13:23:48 +02:00

110 lines
3.6 KiB
Go

package service
import (
"strings"
"testing"
"github.com/mhsanaei/3x-ui/v3/internal/database"
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
)
// An inbound save keeps the stored clients, so switching to Hysteria is judged
// on them: ones with no auth would leave an inbound nobody can connect to.
func TestUpdateInbound_RejectsHysteriaClientWithoutAuth(t *testing.T) {
setupConflictDB(t)
seedInboundConflict(t, "in-45001-tcp", "0.0.0.0", 45001, model.VLESS,
`{"network":"tcp"}`, `{"clients":[{"email":"hysteria@x","enable":true,"password":"not-hysteria-auth"}]}`)
var existing model.Inbound
if err := database.GetDB().Where("tag = ?", "in-45001-tcp").First(&existing).Error; err != nil {
t.Fatalf("read seeded row: %v", err)
}
update := existing
update.Protocol = model.Hysteria
update.Settings = `{"clients":[]}`
svc := &InboundService{}
if _, _, err := svc.UpdateInbound(&update); err == nil || !strings.Contains(err.Error(), "empty client ID") {
t.Fatalf("UpdateInbound error = %v, want empty client ID", err)
}
var reloaded model.Inbound
if err := database.GetDB().First(&reloaded, existing.Id).Error; err != nil {
t.Fatalf("reload: %v", err)
}
if reloaded.Protocol != existing.Protocol {
t.Fatalf("persisted protocol = %q, want unchanged %q", reloaded.Protocol, existing.Protocol)
}
if reloaded.Settings != existing.Settings {
t.Fatalf("rejected settings were persisted\ngot: %s\nwant: %s", reloaded.Settings, existing.Settings)
}
}
func TestUpdateInbound_PreservesHysteriaClientAuth(t *testing.T) {
setupConflictDB(t)
seedInboundConflict(t, "in-45002-udp", "0.0.0.0", 45002, model.Hysteria,
`{"network":"hysteria"}`, `{"clients":[]}`)
var existing model.Inbound
if err := database.GetDB().Where("tag = ?", "in-45002-udp").First(&existing).Error; err != nil {
t.Fatalf("read seeded row: %v", err)
}
const wantAuth = "hysteria-auth"
const password = "not-hysteria-auth"
update := existing
update.Settings = `{"clients":[{"email":"hysteria@x","enable":true,"password":"` + password + `","auth":"` + wantAuth + `"}]}`
// Only a master's push still carries clients through an inbound save.
svc := &InboundService{FromNodeSync: true}
if _, _, err := svc.UpdateInbound(&update); err != nil {
t.Fatalf("UpdateInbound: %v", err)
}
var reloaded model.Inbound
if err := database.GetDB().First(&reloaded, existing.Id).Error; err != nil {
t.Fatalf("reload: %v", err)
}
clients, err := ParseInboundSettingsClients(reloaded.Settings)
if err != nil {
t.Fatalf("parse persisted clients: %v", err)
}
if len(clients) != 1 {
t.Fatalf("persisted clients = %d, want 1", len(clients))
}
if clients[0].Auth != wantAuth {
t.Fatalf("persisted auth = %q, want %q", clients[0].Auth, wantAuth)
}
if clients[0].Password != password {
t.Fatalf("persisted password = %q, want %q", clients[0].Password, password)
}
}
func TestUpdateInbound_AllowsHysteriaWithoutClients(t *testing.T) {
setupConflictDB(t)
seedInboundConflict(t, "in-45003-udp", "0.0.0.0", 45003, model.Hysteria,
`{"network":"hysteria"}`, `{"clients":[]}`)
var existing model.Inbound
if err := database.GetDB().Where("tag = ?", "in-45003-udp").First(&existing).Error; err != nil {
t.Fatalf("read seeded row: %v", err)
}
update := existing
update.Remark = "updated without clients"
svc := &InboundService{}
if _, _, err := svc.UpdateInbound(&update); err != nil {
t.Fatalf("UpdateInbound: %v", err)
}
var reloaded model.Inbound
if err := database.GetDB().First(&reloaded, existing.Id).Error; err != nil {
t.Fatalf("reload: %v", err)
}
if reloaded.Remark != update.Remark {
t.Fatalf("persisted remark = %q, want %q", reloaded.Remark, update.Remark)
}
}