mirror of
https://github.com/diegosouzapw/OmniRoute.git
synced 2026-07-31 12:22:14 +03:00
* feat(proxy-subscriptions): src/lib/proxySubscription/parse.ts * feat(proxy-subscriptions): src/lib/proxySubscription/subscriptionService.ts * feat(proxy-subscriptions): src/lib/proxySubscription/index.ts * feat(proxy-subscriptions): src/lib/db/migrations/123_proxy_subscriptions.sql * feat(proxy-subscriptions): src/app/api/v1/management/proxy-subscriptions/route.ts * feat(proxy-subscriptions): src/app/api/v1/management/proxy-subscriptions/[id]/route.ts * feat(proxy-subscriptions): src/app/api/v1/management/proxy-subscriptions/[id]/refresh/route.ts * feat(proxy-subscriptions): src/app/api/v1/management/proxy-subscriptions/[id]/nodes/route.ts * feat(proxy-subscriptions): src/app/(dashboard)/dashboard/settings/components/proxy/SubscriptionTab.tsx * feat(proxy-subscriptions): tests/unit/proxySubscription.parse.test.ts * feat(proxy-subscriptions): tests/unit/proxySubscription.service.test.ts * feat(proxy-subscriptions): docs/proxy-subscriptions.md * feat(proxy-subscriptions): src/lib/db/proxies/types.ts * feat(proxy-subscriptions): src/lib/db/proxies/mappers.ts * feat(proxy-subscriptions): src/lib/db/proxies.ts * feat(proxy-subscriptions): src/app/(dashboard)/dashboard/settings/components/ProxyTab.tsx * i18n(proxy-subscriptions): add proxySubscriptionsTab key + use in ProxyTab * i18n(proxy-subscriptions): add proxySubscriptionsTab key + use in ProxyTab * i18n(proxy-subscriptions): add proxySubscriptionsTab key + use in ProxyTab * i18n(proxy-subscriptions): add proxySubscriptionsTab key + use in ProxyTab * test(proxy-subscriptions): extract isSubscriptionDue + unit tests * test(proxy-subscriptions): extract isSubscriptionDue + unit tests * test(proxy-subscriptions): extract isSubscriptionDue + unit tests * test(proxy-subscriptions): add global->rule switch re-bind integration test * feat(proxy-subscriptions): inline needs-local-core guidance in SubscriptionTab * i18n: add proxySubscriptionsTab to en (rebased on current main) * i18n: add proxySubscriptionsTab to zh-CN (rebased on current main) * i18n: add proxySubscriptionsTab to pt-BR (rebased on current main) * test(proxy-subscriptions): extract needsCore detection into pure module + unit tests * test(proxy-subscriptions): extract needsCore detection into pure module + unit tests * test(proxy-subscriptions): extract needsCore detection into pure module + unit tests * refactor(proxy-subscriptions): extract scopes.ts into pure module + unit tests (#65) * refactor(proxy-subscriptions): extract coreEndpoint.ts into pure module + unit tests (#65) * refactor(proxy-subscriptions): extract subscriptionService.ts into pure module + unit tests (#65) * refactor(proxy-subscriptions): extract proxySubscription.scopes.test.ts into pure module + unit tests (#65) * refactor(proxy-subscriptions): extract proxySubscription.coreEndpoint.test.ts into pure module + unit tests (#65) * security(proxy-subscriptions): fetchGuard.ts — SSRF guard + core scheme (#P0) * security(proxy-subscriptions): coreEndpoint.ts — SSRF guard + core scheme (#P0) * security(proxy-subscriptions): subscriptionService.ts — SSRF guard + core scheme (#P0) * security(proxy-subscriptions): proxySubscription.fetchGuard.test.ts — SSRF guard + core scheme (#P0) * security(proxy-subscriptions): proxySubscription.coreEndpoint.test.ts — SSRF guard + core scheme (#P0) * refactor(proxy-subscriptions): subscriptionService.ts — concurrency lock / resilience / url redaction (#P1) * refactor(proxy-subscriptions): url.ts — concurrency lock / resilience / url redaction (#P1) * refactor(proxy-subscriptions): index.ts — concurrency lock / resilience / url redaction (#P1) * refactor(proxy-subscriptions): route.ts — concurrency lock / resilience / url redaction (#P1) * refactor(proxy-subscriptions): route.ts — concurrency lock / resilience / url redaction (#P1) * refactor(proxy-subscriptions): proxySubscription.url.test.ts — concurrency lock / resilience / url redaction (#P1) * i18n(proxy-subscriptions): subscriptionService.ts — stable error codes + locale keys (#P2-6) * i18n(proxy-subscriptions): SubscriptionTab.tsx — stable error codes + locale keys (#P2-6) * i18n(proxy-subscriptions): en.json — stable error codes + locale keys (#P2-6) * i18n(proxy-subscriptions): zh-CN.json — stable error codes + locale keys (#P2-6) * i18n(proxy-subscriptions): pt-BR.json — stable error codes + locale keys (#P2-6) * i18n(proxy-subscriptions): en.json — normalize to LF line endings (#P2-6) * i18n(proxy-subscriptions): zh-CN.json — normalize to LF line endings (#P2-6) * i18n(proxy-subscriptions): pt-BR.json — normalize to LF line endings (#P2-6) * enhance(proxy-subscriptions): reject subscription fetch if ANY resolved DNS address is blocked (P3-1) * enhance(proxy-subscriptions): add withRetry() exponential-backoff helper (P3-2) * enhance(proxy-subscriptions): DNS multi-record guard + retry/backoff fetch + batch scope writes + observability (P3-1..P3-4) * enhance(proxy-subscriptions): batch addProxiesToScopePool() to drop N+1 writes (P3-3) * enhance(proxy-subscriptions): add last_error_at + consecutive_failures observability columns (P3-4) * enhance(proxy-subscriptions): surface consecutive failures + last error time in subscription cards (P3-4) * test(proxy-subscriptions): cover multi-record DNS SSRF (block if ANY address internal) (P3-1) * test(proxy-subscriptions): cover withRetry() first-success / retries / backoff / non-retryable stop (P3-2) * fix(proxy-subscriptions): resolve js-yaml import + missing backup/generation-bump imports Two bugs made the feature non-functional and its own test suite false: 1. parse.ts used `import yaml from "js-yaml"` (default import), but js-yaml@^5 is ESM-only with no default export — this threw a SyntaxError at module load, crashing every caller (index.ts re-exports parse.ts, so every API route hit this too). Switch to `import * as yaml`, matching how the rest of the codebase already imports js-yaml (hermes-agent.ts, openapiParser.ts, openapi/spec route.ts, guide-settings route.ts). 2. subscriptionService.ts's unapplySubscription() called backupDbFile() and bumpProxyRegistryGeneration() without importing either — backupDbFile exists but wasn't imported; bumpProxyRegistryGeneration was a private, non-exported function in db/proxies.ts. This threw a ReferenceError whenever a subscription with bound proxies was disabled/deleted (the normal path). Import backupDbFile from ../db/backup and export+import bumpProxyRegistryGeneration from ../db/proxies, matching the identical backup+bump pattern already used by deleteProxyById for the same proxy_assignments/proxy_registry mutation shape. Fixing both unmasked a third, previously-unreachable bug (both crashes happened before any test assertion could run): recomputeProxyEnabled() checked `proxy_subscriptions.enabled = 1` alone, which stays true across an unapply/disable cycle since unapplySubscription() never touches that column — the proxyEnabled flag would get stuck on `true` even after the subscription's proxies were fully detached. Changed the check to require an actually-bound proxy_assignments row for an enabled subscription, matching hasNonSubscriptionGlobalProxy()'s existing bound-check pattern. Traced all 3 production call sites (mode/rule switch, disable, delete) to confirm this doesn't change their outcome — only the previously-wrong "unapply in isolation" case. Also fixed the test file's own pre-existing bug: its provider_connections inserts omitted created_at/updated_at (NOT NULL, no default in the schema since 001_initial_schema.sql), which 0 assertions had ever reached before because the SyntaxError always crashed the file first. All 9 proxySubscription test files now run clean: 49/49 pass (previously 2 files crashed outright at import time, 0 assertions ever ran). Separately confirmed via testing against the pristine PR head: this PR has 3 more pre-existing gate failures unrelated to the above (file-size on db/proxies.ts, cognitive-complexity, complexity, changelog-integrity vs the current release tip) plus 3 pre-existing TS2345 errors in parse.ts (lines 228/233/263, unrelated to the yaml import). All are the PR's own scope/base-drift, out of scope for this fix — the PR has never had a real CI run (base=main), so no gate has ever surfaced them; they need the base retarget + a full CI pass called out in the plan file's own remaining mandatory items. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> * fix(db): renumber proxy-subscriptions migrations to avoid version collision release/v3.8.49 already ships 123_quota_auto_ping.sql and 124_generic_session_affinity_ttl.sql; this PR's 123/124 files collided, tripping migrationRunner's version-collision guard and failing all proxySubscription.service tests. Renumber to 127/128 (next free slots after 126_reasoning_routing_rules.sql). Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouzapw@users.noreply.github.com> * refactor(db): extract proxySubscriptions + registryGeneration to keep proxies.ts under file-size cap Moves addProxiesToScopePool to ./proxySubscriptions.ts and the registry-generation helpers to ./proxies/registryGeneration.ts (re-exported from proxies.ts), keeping the module under its frozen 1177-line cap after the operator-proxy-subscriptions feature. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> * fix(db): renumber proxy-subscriptions migrations past release collision Rebasing onto release/v3.8.49 surfaced a migration version collision: this branch's 127_proxy_subscriptions.sql and 128_proxy_subscriptions_meta.sql now collide with 127_usage_history_account_identity.sql and 128_auto_candidate_overrides.sql that landed on release since this branch last synced. Renumbered to 131/132 (next free prefixes after the current 130_remove_unregistered_qwen_data.sql) and updated the in-file header comments to match. No schema/behavior change. Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> --------- Co-authored-by: diegosouzapw <8016841+diegosouzapw@users.noreply.github.com> Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouza.pw@gmail.com> Co-authored-by: Diego Rodrigues de Sa e Souza <diegosouzapw@users.noreply.github.com> Co-authored-by: xier2012 <xier2012@users.noreply.github.com>
134 lines
3.8 KiB
TypeScript
134 lines
3.8 KiB
TypeScript
import test from "node:test";
|
|
import assert from "node:assert/strict";
|
|
|
|
const parse = await import("../../src/lib/proxySubscription/parse.ts");
|
|
const { parseSubscription, redactedNodeSummary } = parse;
|
|
|
|
test("parses a Clash YAML subscription with direct + needs-core nodes", () => {
|
|
const yaml = `
|
|
proxies:
|
|
- name: "Direct HTTP"
|
|
type: http
|
|
server: 1.2.3.4
|
|
port: 8080
|
|
username: u
|
|
password: p
|
|
- name: "Direct SOCKS5"
|
|
type: socks5
|
|
server: 5.6.7.8
|
|
port: 1080
|
|
- name: "Shadowsocks node"
|
|
type: ss
|
|
server: 9.9.9.9
|
|
port: 8388
|
|
- name: "VMess node"
|
|
type: vmess
|
|
server: 11.11.11.11
|
|
port: 443
|
|
`;
|
|
const res = parseSubscription(yaml);
|
|
assert.equal(res.format, "clash-yaml");
|
|
// http + socks5 are directly usable
|
|
assert.equal(res.nodes.length, 2);
|
|
assert.deepEqual(res.nodes.map((n) => n.type).sort(), ["http", "socks5"]);
|
|
// ss + vmess need a local core
|
|
assert.equal(res.needsCore.length, 2);
|
|
assert.deepEqual(
|
|
res.needsCore.map((n) => n.rawProtocol).sort(),
|
|
["ss", "vmess"]
|
|
);
|
|
});
|
|
|
|
test("decodes a base64-wrapped Clash YAML subscription", () => {
|
|
const yaml = `proxies:
|
|
- name: "B64 node"
|
|
type: https
|
|
server: 2.2.2.2
|
|
port: 443
|
|
`;
|
|
const b64 = Buffer.from(yaml, "utf-8").toString("base64");
|
|
const res = parseSubscription(b64);
|
|
assert.equal(res.format, "base64-lines");
|
|
assert.equal(res.nodes.length, 1);
|
|
assert.equal(res.nodes[0].type, "https");
|
|
assert.equal(res.nodes[0].host, "2.2.2.2");
|
|
});
|
|
|
|
test("parses a V2Ray-style JSON array of URI strings", () => {
|
|
const arr = [
|
|
"socks5://127.0.0.1:1080",
|
|
"ss://example.com:8388",
|
|
"vmess://eyJhZGQiOiIxLjIuMy40IiwicG9ydCI6NDQzLCJ2IjoiMiJ9",
|
|
"trojan://secretpass@5.5.5.5:443",
|
|
"vless://uuid@6.6.6.6:443",
|
|
];
|
|
const res = parseSubscription(JSON.stringify(arr));
|
|
assert.equal(res.format, "v2ray-json");
|
|
// socks5 direct; the rest need a local core
|
|
assert.equal(res.nodes.length, 1);
|
|
assert.equal(res.nodes[0].type, "socks5");
|
|
assert.equal(res.needsCore.length, 4);
|
|
});
|
|
|
|
test("parses a plain list of URI lines", () => {
|
|
const lines = [
|
|
"http://user:pass@10.0.0.1:8080",
|
|
"socks5://10.0.0.2:1080",
|
|
"trojan://pw@10.0.0.3:443",
|
|
].join("\n");
|
|
const res = parseSubscription(lines);
|
|
assert.equal(res.format, "lines");
|
|
assert.equal(res.nodes.length, 2);
|
|
assert.equal(res.needsCore.length, 1);
|
|
const http = res.nodes.find((n) => n.type === "http");
|
|
assert.ok(http);
|
|
assert.equal(http?.username, "user");
|
|
assert.equal(http?.password, "pass");
|
|
});
|
|
|
|
test("parses Clash.Meta outbounds array", () => {
|
|
const yaml = `
|
|
outbounds:
|
|
- name: "meta-http"
|
|
type: http
|
|
server: 3.3.3.3
|
|
port: 8080
|
|
- name: "meta-vless"
|
|
type: vless
|
|
server: 4.4.4.4
|
|
port: 443
|
|
`;
|
|
const res = parseSubscription(yaml);
|
|
assert.equal(res.nodes.length, 1);
|
|
assert.equal(res.needsCore.length, 1);
|
|
assert.equal(res.needsCore[0].rawProtocol, "vless");
|
|
});
|
|
|
|
test("returns empty for blank / unrecognized input", () => {
|
|
assert.equal(parseSubscription("").format, "empty");
|
|
const res = parseSubscription("just some random text that is not a subscription");
|
|
assert.equal(res.format, "unknown");
|
|
assert.equal(res.nodes.length, 0);
|
|
assert.equal(res.needsCore.length, 0);
|
|
});
|
|
|
|
test("redactedNodeSummary excludes secrets for direct nodes", () => {
|
|
const yaml = `
|
|
proxies:
|
|
- name: "Direct HTTP"
|
|
type: http
|
|
server: 1.2.3.4
|
|
port: 8080
|
|
username: secretuser
|
|
password: secretpass
|
|
`;
|
|
const res = parseSubscription(yaml);
|
|
const summary = redactedNodeSummary(res);
|
|
assert.equal(summary.length, 1);
|
|
assert.equal(summary[0].name, "Direct HTTP");
|
|
assert.equal(summary[0].host, "1.2.3.4");
|
|
assert.equal("username" in summary[0], false);
|
|
assert.equal("password" in summary[0], false);
|
|
assert.equal(summary[0].hasAuth, true);
|
|
});
|