feat(nodes): add per-node TLS verification mode for self-signed certs (#4757)

Adds a per-node TLS verification mode to the Add/Edit Node dialog so the panel can reach nodes that serve HTTPS with a self-signed certificate:

- verify (default): normal CA validation.
- skip: InsecureSkipVerify, with a clear UI warning that it drops MITM protection.
- pin: validates the leaf certificate's SHA-256 (base64 or hex) via VerifyConnection while bypassing the default chain/name check — keeps MITM protection for self-signed certs, the secure alternative to skip.

New Node model fields tlsVerifyMode + pinnedCertSha256 (gorm auto-migrated). Probe() selects the HTTP client per node via nodeHTTPClientFor, keeping the SSRF-guarded dialer. A new POST /panel/api/nodes/certFingerprint endpoint (FetchCertFingerprint) lets the UI fetch and pin the node's current certificate in one click. Endpoint documented in api-docs/openapi; i18n added across all locales. Verified end-to-end in Docker (verify rejects, skip bypasses, fetch matches, pin accepts correct / rejects wrong).
This commit is contained in:
MHSanaei
2026-06-02 01:24:27 +02:00
parent b2e2120eb3
commit 56ec359041
22 changed files with 457 additions and 15 deletions
+13 -1
View File
@@ -869,7 +869,19 @@
"updateStarted": "به‌روزرسانی پنل آغاز شد",
"updateResult": "به‌روزرسانی روی {ok} نود آغاز شد، {failed} ناموفق",
"updateNoneEligible": "حداقل یک نود آنلاین و فعال انتخاب کنید"
}
},
"tlsVerifyMode": "اعتبارسنجی TLS",
"tlsVerifyModeHint": "اینکه پنل گواهی HTTPS نود را چطور بررسی کند. Pin یا Skip برای گواهی‌های self-signed است (فقط نودهای https).",
"tlsVerify": "اعتبارسنجی (CA پیش‌فرض)",
"tlsPin": "Pin گواهی (SHA-256)",
"tlsSkip": "رد کردن اعتبارسنجی",
"tlsSkipWarning": "رد کردن اعتبارسنجی محافظت در برابر حملهٔ مرد میانی را از بین می‌برد و توکن API ممکن است شنود شود. ترجیحاً به‌جای آن گواهی را Pin کنید.",
"pinnedCert": "SHA-256 گواهیِ Pin‌شده",
"pinnedCertHint": "SHA-256 گواهیِ نود به‌صورت base64 یا hex. برای خواندنِ همین حالا از نود، از دکمهٔ Fetch استفاده کنید.",
"pinnedCertPlaceholder": "SHA-256 به‌صورت base64 یا hex",
"fetchPin": "دریافت",
"pinFetched": "گواهیِ فعلیِ نود دریافت شد",
"pinFetchFailed": "دریافت گواهی ممکن نشد"
},
"settings": {
"title": "تنظیمات پنل",