mirror of
https://github.com/MHSanaei/3x-ui.git
synced 2026-09-09 11:48:18 +00:00
df6d2f7652
- manager.go: serverAddress assumed subnetIp always ends in ".0"; a base like "10.8.1.5" was used verbatim as the server's own address, eventually colliding with peer allocation (which starts at .2 upward). Now derives the first host of the actual subnetIp/subnetCidr network via netip, matching serverAddressV6's own approach. A /32 base (no host bits at all) is still used as-is. (Finding 12, partial -- the /16 pool-widening half of this finding only exists on the upstream-pr/amneziawg branch's merged client_wireguard.go, not here; handled separately on that branch.) - manager.go: ensureLocked carried the previous per-peer traffic counters (`last`) forward even through a full restart, but awg-quick down+up resets the kernel's own counters to zero -- the next CollectTraffic computed a large negative delta (clamped to 0), silently discarding real traffic. Extracted the decision into nextTrafficBaseline: only a reload (syncconf) preserves the baseline. (Finding 13) - portfwd.go: exported ForwardedPortsInclude; inbound_amneziawg.go's new checkForwardedPortsConflict uses it to reject, at save time, a client's forwardedPorts that would DNAT the panel's own port or another enabled inbound's port to the tunnel client -- portForwardLines has no destination restriction, so this collision was previously silent. Wired into both the single-client update path and the add-client path (client_inbound_apply.go), plus normalizeAmneziaWGSettings for the whole-inbound save path. (Finding 14) - inbound.go: InboundOption.AwgServer sent the whole ServerSettings struct including PrivateKey to GetInboundOptions callers -- a shared, admin-wide dropdown-filling endpoint the frontend's own AwgServerOptionSchema never reads that field from. Redacted it before assigning. (Finding 11) Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
26 lines
553 B
Go
26 lines
553 B
Go
package amneziawg
|
|
|
|
import "testing"
|
|
|
|
func TestForwardedPortsInclude(t *testing.T) {
|
|
cases := []struct {
|
|
spec string
|
|
port int
|
|
want bool
|
|
}{
|
|
{"80,443", 80, true},
|
|
{"80,443", 443, true},
|
|
{"80,443", 8080, false},
|
|
{"8000-8100", 8050, true},
|
|
{"8000-8100", 7999, false},
|
|
{"8000-8100", 8101, false},
|
|
{"", 80, false},
|
|
{"not-a-port", 80, false},
|
|
}
|
|
for _, c := range cases {
|
|
if got := ForwardedPortsInclude(c.spec, c.port); got != c.want {
|
|
t.Errorf("ForwardedPortsInclude(%q, %d) = %v, want %v", c.spec, c.port, got, c.want)
|
|
}
|
|
}
|
|
}
|