mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-08-15 07:40:59 +00:00
feat(mtproto): adopt dolonet/mtg-multi and make MTProto inbounds multi-client
Replace the upstream 9seconds/mtg sidecar with the dolonet/mtg-multi fork so a single MTProto inbound can serve many per-user secrets. Each panel client is now one named FakeTLS secret in the fork's [secrets] section: clients are first-class (attach/detach, limits, expiry, per-client tg:// links) exactly like every other protocol, mirroring the WireGuard multi-client model. Per-client traffic and online status come from the fork's /stats JSON API (its Prometheus output has no per-user label), fed into the existing email-keyed client_traffics accumulator; an optional throttle caps concurrent connections. A one-time seeder converts each legacy single-secret inbound into a one-client inbound. The fork ships only linux/darwin amd64/arm64 binaries but is pure Go, so provisioning builds it from source for every supported platform (release.yml, DockerInit.sh) while keeping the panel-expected mtg-<os>-<arch> filename and the 'run' verb, so process.go is untouched. Also fixes a pre-existing update.sh gap that never renamed the mtg binary for armv6/armv7 updates.
This commit is contained in:
@@ -69,3 +69,40 @@ func TestHealMtprotoSecret(t *testing.T) {
|
||||
t.Fatal("expected no change when fakeTlsDomain is missing")
|
||||
}
|
||||
}
|
||||
|
||||
func TestHealMtprotoClientSecrets(t *testing.T) {
|
||||
// An empty client secret is filled from the inbound-level default domain.
|
||||
in := `{"fakeTlsDomain":"a.com","clients":[{"email":"x","secret":""}]}`
|
||||
out, changed := HealMtprotoClientSecrets(in)
|
||||
if !changed {
|
||||
t.Fatal("expected an empty client secret to be filled")
|
||||
}
|
||||
var parsed map[string]any
|
||||
if err := json.Unmarshal([]byte(out), &parsed); err != nil {
|
||||
t.Fatalf("healed settings not valid json: %v", err)
|
||||
}
|
||||
clients := parsed["clients"].([]any)
|
||||
got := clients[0].(map[string]any)["secret"].(string)
|
||||
if !strings.HasPrefix(got, "ee") || !strings.HasSuffix(got, hex.EncodeToString([]byte("a.com"))) {
|
||||
t.Fatalf("filled client secret malformed: %q", got)
|
||||
}
|
||||
|
||||
// Healing is idempotent once every client secret is valid.
|
||||
if _, changed2 := HealMtprotoClientSecrets(out); changed2 {
|
||||
t.Fatal("expected no change for already-valid client secrets")
|
||||
}
|
||||
|
||||
// A client's own embedded domain is preserved even when it differs from the
|
||||
// inbound-level default (per-client domain fronting).
|
||||
own := "ee00112233445566778899aabbccddeeff" + hex.EncodeToString([]byte("b.com"))
|
||||
in3 := `{"fakeTlsDomain":"a.com","clients":[{"email":"y","secret":"` + own + `"}]}`
|
||||
out3, changed3 := HealMtprotoClientSecrets(in3)
|
||||
if changed3 {
|
||||
t.Fatalf("a valid per-client secret must be left untouched, got %q", out3)
|
||||
}
|
||||
|
||||
// No clients array — nothing to heal.
|
||||
if _, changed4 := HealMtprotoClientSecrets(`{"fakeTlsDomain":"a.com"}`); changed4 {
|
||||
t.Fatal("expected no change when there are no clients")
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user