fix(nodes): apply a rotated master mTLS certificate without restarting the panel (#6194)

* fix(mtls): invalidate pooled clients after credential rotation

* fix(mtls): make connection reload read-only

---------

Co-authored-by: n0ctal <293235942+n0ctal@users.noreply.github.com>
This commit is contained in:
n0ctal
2026-08-15 19:03:42 +05:00
committed by GitHub
parent 1230559e69
commit 7ecd88b9e3
24 changed files with 747 additions and 101 deletions
+19
View File
@@ -15,6 +15,7 @@ import (
"github.com/mhsanaei/3x-ui/v3/internal/database/model"
"github.com/mhsanaei/3x-ui/v3/internal/util/common"
"github.com/mhsanaei/3x-ui/v3/internal/util/crypto"
"github.com/mhsanaei/3x-ui/v3/internal/web/runtime"
)
var masterClientCredentialMu sync.Mutex
@@ -133,6 +134,7 @@ func (s *SettingService) EnsureMasterClientCert() (crypto.CertKeyPEM, error) {
if err := saveMasterClientCredential(client, pin); err != nil {
return crypto.CertKeyPEM{}, err
}
runtime.InvalidateMasterClientConnections()
return client, nil
}
@@ -158,6 +160,23 @@ func saveMasterClientCredential(client crypto.CertKeyPEM, pin string) error {
})
}
// LoadMasterClientCert returns only the already-persisted credential. It never
// mints or changes CA/client settings.
func (s *SettingService) LoadMasterClientCert() (crypto.CertKeyPEM, error) {
certPem, err := s.getString(settingNodeMtlsClientCert)
if err != nil {
return crypto.CertKeyPEM{}, err
}
keyPem, err := s.getString(settingNodeMtlsClientKey)
if err != nil {
return crypto.CertKeyPEM{}, err
}
if certPem == "" || keyPem == "" {
return crypto.CertKeyPEM{}, common.NewError("master client certificate is not fully configured")
}
return crypto.CertKeyPEM{CertPEM: []byte(certPem), KeyPEM: []byte(keyPem)}, nil
}
// NodeMtlsClientCAPool builds the trust pool used as the panel listener's
// ClientCAs for incoming node-API client certificates. It returns (nil, nil)
// when no trust CA is configured, so mTLS stays off and the listener behaves