feat: replace panel proxy URL with outbound-based egress bridge

Instead of requiring a manual SOCKS5/HTTP URL, the panel now lets the
admin pick an Xray outbound from a dropdown (same UX as Geodata
Auto-Update). At runtime, injectPanelEgress appends a loopback SOCKS
inbound (tag: panel-egress) and prepends a routing rule so the panel's
own HTTP traffic — version checks, Telegram, normal geo-file updates —
is routed through the chosen outbound. Xray-native Geodata Auto-Update
is unaffected (it uses its own geodata.outbound inside Xray). Blackhole
outbounds are excluded from both picker dropdowns since routing any
download through one just drops it. Translations updated for all 13
locales.
This commit is contained in:
MHSanaei
2026-06-10 23:52:20 +02:00
parent 6b16d8c37a
commit ca4f32e3da
29 changed files with 352 additions and 73 deletions
+5 -6
View File
@@ -234,13 +234,12 @@ func (t *Tgbot) Start(i18nFS embed.FS) error {
logger.Warning("Failed to get Telegram bot proxy URL:", err)
}
// Fall back to the panel-wide proxy when no dedicated bot proxy is set.
// Fall back to the panel-wide egress bridge when no dedicated bot proxy is
// set. Resolved once at bot start: if Xray comes up later, the bot keeps
// its direct connection until it is restarted.
if tgBotProxy == "" {
panelProxy, perr := t.settingService.GetPanelProxy()
if perr != nil {
logger.Warning("Failed to get panel proxy URL:", perr)
} else if isSupportedBotProxyScheme(panelProxy) {
tgBotProxy = panelProxy
if egress := t.settingService.PanelEgressProxyURL(); egress != "" && isSupportedBotProxyScheme(egress) {
tgBotProxy = egress
}
}