Commit Graph

34 Commits

Author SHA1 Message Date
andrey271192
8e5d51ab2c fix: auto-detect wg binary in containers 2026-06-22 15:46:43 +03:00
andrey271192
b3600959ef fix: auto-discover amnezia client sources 2026-06-22 00:34:12 +03:00
andrey271192
4e6ab2dd6a fix: parse legacy clients table formats 2026-06-21 19:29:08 +03:00
andrey271192
dfeabe02d7 feat: sync app-created peers into clients table 2026-06-21 19:19:49 +03:00
andrey271192
fd66b0a024 fix: show peers missing clients table 2026-06-21 19:16:01 +03:00
andrey271192
cb5fca3d0f fix: load clients for selected profile 2026-06-21 19:00:51 +03:00
andrey271192
a9a67afb54 fix: show distinct awg instance labels 2026-06-21 18:34:26 +03:00
andrey271192
8c67d7df93 fix: dedupe duplicate awg instances 2026-06-21 18:32:10 +03:00
andrey271192
cff27e27b6 feat: import clients from amnezia configs 2026-06-21 18:22:36 +03:00
andrey271192
cdd47f157b feat(instances): show app-installed AmneziaWG, not only panel-created
The instances section listed only panel-managed instances, so an
AmneziaWG container set up by the Amnezia desktop app (e.g.
amnezia-awg2) did not appear as a card.

/api/instances now iterates ALL effective profiles (env-discovered +
managed): resolves each container, reads ListenPort and peer count,
and detects the variant from the interface config (S3/S4 -> awg2,
S1/S2 -> awg, wg0 -> legacy). Native (non-managed) instances are
flagged managed:false.

UI: native cards get an "приложение Amnezia" tag and hide the Удалить
button (the panel must not tear down app-managed containers); they
keep Подключения and Стоп/Старт. Stop/start now resolve the real
container name so they work for native instances too.

Verified live: native amnezia-awg2 shows as "AmneziaWG 2.0" port
37395 (managed:false) alongside a panel-created Legacy :5534.
2026-06-16 21:40:42 +03:00
andrey271192
546c1127f8 feat: deploy AmneziaWG instances from the panel (no Amnezia app)
Add a "Протоколы / инстансы" section that spins up AmneziaWG server
containers straight from the panel, with port + variant selection —
no need to run the Amnezia desktop app to set up the server.

Core (scripts/awg-instance.sh):
- create <awg2|awg|legacy> <port> [name]: pulls the public image
  (amneziavpn/amneziawg-go:2.0.0 / :0.2.18 / amneziavpn/amnezia-wg),
  generates server keys + psk, writes awg0.conf/wg0.conf with a free
  10.8.<N>.0/24 subnet (scans running containers to avoid clashes),
  random AmneziaWG obfuscation (Jc/Jmin/Jmax/S1..S4/H1..H4 as single
  uint32 values — ranges break awg setconf), and a start.sh that
  brings the iface up via userspace amneziawg-go + NAT MASQUERADE.
  remove <name>, list.

Backend (server.js):
- Profiles are now dynamic: env AWG_PROFILES merged with managed
  instances persisted in /data/instances.json (getProfiles()), so a
  new instance is usable immediately without restarting the panel.
- /api/instances (list with running/peers), /api/instances/create,
  /delete, /stop, /start. create runs the script then registers the
  profile; delete tears down container + data + profile.

Infra:
- Dockerfile: add bash iproute2 coreutils, COPY scripts.
- install.sh: mkdir /opt/amnezia-instances and bind-mount it into the
  panel so docker-in-docker bind paths line up.

UI (index.html/app.js/styles.css):
- Cards per instance (icon, NEW badge, description, РАБОТАЕТ/ОСТАНОВЛЕН,
  port, connections) with Стоп/Старт, Подключения (switches the active
  instance), Удалить; plus a create form (variant + port).

Verified end to end on a live VPS: create awg2/awg/legacy instances,
interfaces come up, a client created on a new instance gets the right
subnet (10.8.20.2) and Endpoint (host:51850).
2026-06-16 21:33:02 +03:00
andrey271192
f1b7fa522c fix: runtime auto-discovery of AmneziaWG container
Tester hit 'No such container: amnezia-awg' after a stock install
on a VPS where Amnezia created the WG container as amnezia-awg2.
Install-time detection was not enough.

The panel now resolves the real container at runtime: if the
configured AWG_CONTAINER lacks the conf file (or does not exist),
it scans running containers for one holding awg0.conf, preferring
amnezia-awg* names. All docker exec paths (clients list/create/
enable/disable/delete, WARP, host-setup) and the API container
field use the resolved name. Clear error lists running containers
if none match.

Result: install -> login -> change password -> create client works
with no manual AWG_CONTAINER/AWG_PROFILES on single-instance setups.
2026-06-16 21:11:36 +03:00
andrey271192
e498e98e12 fix(export): Amnezia-standard DNS + drop empty I2-I5 junk lines
Two issues reported on direct/cascade client creation:
- DNS hardcoded to Google (8.8.8.8/8.8.4.4). Default now 1.1.1.1/
  1.0.0.1 (Amnezia standard); still overridable via
  CLIENT_EXPORT_DNS1/DNS2 env.
- Config emitted empty I2 =/I3 =/I4 =/I5 = lines when the server
  only defines I1. Now only non-empty I-params are written, so the
  client's AmneziaWG obfuscation matches the server head exactly
  (mismatched/empty junk lines could break some clients).
2026-06-16 20:10:00 +03:00
andrey271192
c49e7eea8d feat: direct client creation + auto-detect AWG container
Add "Новый клиент" (direct) flow alongside cascade:
- server.js: POST /api/clients/create — Endpoint = this server's
  public IP:ListenPort (CLIENT_CONFIG_ENDPOINT or request host),
  reuses the same key/peer/conf pipeline as create-cascade.
- public/index.html: "Новый клиент" panel with #direct-form
  (name + optional tunnel IP).
- public/app.js: downloadDirectConf() handler + form binding.

install.sh hardening so fresh installs work out of the box:
- Auto-detect a single amnezia-awg* container (e.g. amnezia-awg2,
  Amnezia AWG 2.0 default) -> AWG_CONTAINER, instead of the fixed
  "amnezia-awg" default that mismatched and blocked client ops.
- Auto-default CLIENT_CONFIG_ENDPOINT to the host primary IP so
  direct .conf exports get a correct Endpoint without manual env.

Fixes "cannot create users" on servers whose WG container is
named amnezia-awg2.
2026-06-16 19:30:11 +03:00
Андрей Бобырев
d21419cfdb fix: default awg container name 2026-06-06 14:46:37 +03:00
Андрей Бобырев
05e6d007e2 docs: make pro repo public install source 2026-06-06 14:16:56 +03:00
Андрей Бобырев
0e7a7df636 feat(mtproto): Telegram proxy panel and /api routes
- Docker telegrammessenger/proxy: install/restart/remove from UI
- GET/POST /api/mtproto/*, UI_HIDE_MTPROTO / UI_HIDE_SECTIONS=mtproto
- install.sh vars MTPRO_*; /health returns version; docs

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-15 04:39:19 +03:00
Андрей Бобырев
74163944c2 chore: align community default Boosty URL with PRO subscription link
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 22:38:30 +03:00
Андрей Бобырев
c454b9e701 feat: split community (read-only) vs PRO panel editions
Add AMNEZIA_EDITION=community with API/UI locks for client mutations,
export, cascade, WARP and host time sync; banner + Boosty CTA.
Install passes edition from AMNEZIA_EDITION env or .amnezia-panel-edition.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 21:51:24 +03:00
Андрей Бобырев
62f40f92fb feat(warp): host install/uninstall via panel SSH + clarify status
POST /api/warp/host-setup runs warp-amnezia.sh on VPS root SSH.
UI buttons when sshpass available; explain missing warp.conf status.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 20:18:23 +03:00
Андрей Бобырев
8f1d7a7c4a feat(ui): optional UI_HIDE_* panels; doc WARP free vs paid plans
Hide users/warp/cascade blocks via env; block warp/cascade APIs when hidden.
install.sh passes UI_HIDE_* and restores from previous container on upgrade.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 20:01:43 +03:00
Андрей Бобырев
50558aff63 docsfeat(warp): clarify optional install + add uninstall command
README/panel-guide/UI explain WARP is not required; document uninstall.
Add warp-amnezia.sh uninstall to strip warp conf, rules, and start.sh block.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 19:53:14 +03:00
Андрей Бобырев
aec8a2f89e fix: ASCII-safe export filenames and trim landing footer
Content-Disposition rejects non-ASCII in Node; sanitize export names.
Public landing keeps admin link only; donate links stay in admin UI.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 19:10:57 +03:00
Андрей Бобырев
f3aab6cc6e feat: cascade client — custom Endpoint + AWG_PROFILES hint
- POST /api/clients/create-cascade: genkeys, add peer, save last_config, download .conf
- Optional tunnel IP in VPN subnet; obfuscation from server [Interface] when present
- /api/protocols: singleProfile hint for missing instance selector
- UI: cascade form, profile banner; README cascade section

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 18:44:11 +03:00
Андрей Бобырев
227bb94627 fix: preserve AWG_PROFILES on reinstall; GET export URL + token
- install.sh: snapshot /root/amnezia-admin.awg-profiles.json + restore from old container
- GET /api/clients/export-config (+ profileId); optional EXPORT_CONFIG_SECRET
- UI: direct link, copy URL, hint when last_config missing

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 18:32:51 +03:00
Андрей Бобырев
75a3e56354 feat: export client .conf from last_config
Adds POST /api/clients/export-config, UI button when exportAvailable, CLIENT_* env for Endpoint/DNS in install.sh.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 18:27:10 +03:00
Андрей Бобырев
ecb64b8b33 fix: ssh time sync — drop BatchMode blocking sshpass
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 18:13:03 +03:00
Андрей Бобырев
6f6fb5f9b9 feat: Cloudflare WARP routing for AmneziaWG
Web toggles per IPv4 peer; wgcf install script on host (no Telegram/QR).

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 18:00:39 +03:00
Андрей Бобырев
40d236c228 fix(ui): separate server vs browser TZ; highlight sync from device
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 17:08:07 +03:00
Андрей Бобырев
dfae0d8256 feat(time): server TZ display; optional SSH host sync via root pw
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 16:44:01 +03:00
Андрей Бобырев
860a56dc5d feat: AWG profile switcher; scheduled tunnel disconnect
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 16:37:27 +03:00
Андрей Бобырев
1c22f89d5a feat(ui): show server and browser date/time in toolbar
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 16:14:27 +03:00
Андрей Бобырев
e93a7e9f60 docs: add upgrade steps; no-store cache for admin static
Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 15:56:57 +03:00
Андрей Бобырев
ede0c66415 docs: publish install/uninstall scripts, README, FUNDING, support footer
Add curl-one-liner install with generated password file; uninstall flags for image/data/src; optional ALLOW_DEFAULT_PASSWORD; footer mirroring GitHub/Boosty/Telegram layout.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-05-14 15:40:55 +03:00