Commit graph

35 commits

Author SHA1 Message Date
f9ee4f5933 fix: 18-point audit pass — payment races, hwid limit bugs, blocking SSH/HTTP in event loops, N+1 queries, ssh host-key pinning, dead code
payments: _grant_paid_subscription now validates plan/node exist before
marking a payment paid instead of after (was leaving charged-but-ungranted
payments with no error trail); mark_payment_paid is now a single atomic
UPDATE ... WHERE status='pending' instead of check-then-act, closing a
double-grant race between webhooks and the periodic reconciler; yookassa
webhook now re-verifies payment status server-side via the API instead of
trusting the posted body (platega already had HMAC verification).

hwid: 'user["hwid_limit"] or FALLBACK' treated an explicit 0 (admin fully
blocking a user) as unset — now an explicit None check. Device count-check
and insert are now one atomic transaction (db.add_device_if_under_limit)
instead of two raceable statements.

perf: payment webhooks and _grant_paid_subscription's SSH/HTTP calls now
run via asyncio.to_thread instead of blocking the event loop; same for
bot.py's periodic_sync/reconcile_pending_payments and the manual admin
sync button. Admin endpoints (traffic/subscriptions/payments/gift-codes/
user-card) now resolve node labels from one db.list_nodes() call instead
of a fresh db.get_node() per row. revoke/reset-traffic use a direct PK
lookup instead of scanning up to 5000 rows. Dashboard now asks the API
for 8 rows instead of fetching 200 and slicing client-side.

security: mbs.db (and -wal/-shm) now chmod 600 right after creation —
it held session tokens and subscription bearer tokens world-readable
by default. Node SSH connections now pin host keys via a persisted
known_hosts file (TOFU) instead of accepting any key on every connection.
delete_node now refuses to delete a node with active subscriptions
instead of silently orphaning their xray clients.

deadcode: removed unused xray_manager.list_client_ids and admin.html's
superseded staggerReveal (rows animate via rowAttr() inline now).

Also guards gift-code redemption against a plan/node deleted after the
code was created (was an unhandled KeyError/TypeError crash).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 22:20:54 +05:00
2604c2dfe7 feat: mirror repo on api.savsis.xyz as primary update source, github as fallback
install.sh clones from the mirror first (falls back to github.com if
unreachable); mbs update fetches origin (mirror) first, falls back to
a github remote if that fetch fails. Mirror itself is a bare repo on
финка2, kept in sync from GitHub every 10 min via an authenticated
token (needed because that box's IP gets rate-limited/blocked by
GitHub for anonymous git clones).

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 17:02:22 +05:00
36fa7d55b0 fix: xray (runs as nobody) couldn't read root-only letsencrypt certs for WS+TLS — copy to /etc/xray/certs with correct perms, keep it fresh via renewal hook
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-11 08:23:21 +05:00
a8deb1fa8b fix: no-cache headers on admin panel HTML so updates show up without a hard refresh
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 23:34:23 +05:00
320742bd63 cli: mbs update now also refreshes /usr/local/bin/mbs itself after pulling
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 23:32:20 +05:00
bfc2fd7b4c settings: change Telegram bot token/username from the admin UI (validated via getMe); mbs restart now covers bot+api+xray+nginx
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 23:29:58 +05:00
04db4a359e ui: dark scrollbars everywhere, Документация section (architecture/nodes/password/fail2ban)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 23:25:37 +05:00
5725922bdc fix: refresh node cache on Gifts/User card open (new nodes weren't showing up); preselect country flag in node edit modal
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 23:06:46 +05:00
8a3ac30dbb chore: trigger CI (diagnosing missing runs)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:59:05 +05:00
76eef6fece cli: mbs update — safe git pull with syntax check + auto-rollback on failure
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:57:49 +05:00
f5f8f21f5d payments: status verification (check + auto-reconcile pending), admin Payments view
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:46:55 +05:00
44d738f8a4 docs: badges (CI, license, release, python, xray-core)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:39:44 +05:00
Welfizx
cea0bffe68
Update README.md 2026-09-10 22:38:49 +05:00
c80f860a82 docs: diagram for panel<->node connectivity (local vs SSH-managed)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:36:14 +05:00
dde311aab1 docs: mermaid architecture/payment/node-add diagrams, stability notes, troubleshooting
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:30:18 +05:00
235b61cd34 install: retry flaky network steps (apt/git/pip/certbot/xray), pipefail safety
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:28:31 +05:00
603d88acae perf: indices on hot query columns, WAL+NORMAL synchronous for write throughput
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:24:52 +05:00
453270d1aa docs: update feature list with HWID limit, user card, traffic reset
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:20:25 +05:00
ca6e928f98 design: staggered reveal animation on every table/list row across the panel
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:19:34 +05:00
a275000b5d admin: full user card — subscription history, manual grant, devices/HWID in one modal
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:17:16 +05:00
9a86b8cb03 admin: reset traffic counter per subscription (xray api statsquery -reset)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:14:16 +05:00
fb11aafda6 ci: import api/bot at CI time, exercise payments+HWID db logic
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:06:15 +05:00
fe579430bd hwid: per-user device limit like Remnawave (x-hwid header, opt-in)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 22:06:15 +05:00
7b5fd8dceb site: offer + privacy policy templates for YooKassa compliance, README payments section
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 21:49:10 +05:00
5b30d1f148 payments: Platega + YooKassa integration, opt-in via PAYMENTS_ENABLED
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 21:44:45 +05:00
c9955b2774 chore: point install/clone URL at devsavsis/mbs-panel
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 21:44:45 +05:00
1965ef9f62 install: anonymous install-count ping (opt-out via MBS_SKIP_STATS)
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 21:13:44 +05:00
f657644ce6 admin: full node editing (label/address/port/sni/keys), country picker in edit modal
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:21:13 +05:00
5308b9a446 ci: use a valid dummy password for the smoke test
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:14:40 +05:00
84ffb8363d security: reject weak/default admin panel passwords at startup
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 18:14:05 +05:00
0333f33b29 docs: readme, MIT license, CI workflow
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:45:43 +05:00
b7792421dd deploy: one-command installer, systemd units, mbs CLI
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:45:43 +05:00
23bb0da6c0 frontend: admin panel SPA and public site pages
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:45:43 +05:00
073c4fb9f0 bot + api: telegram bot (aiogram) and FastAPI backend
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:45:43 +05:00
e4c2012cf8 core: env-driven config, sqlite schema, xray/node management, subscription links
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-10 17:45:36 +05:00