The SSH log page formatted dates with the browser timezone, so logs looked shifted when the client timezone differed from the server. Format the timestamp with the offset returned by the API so the page matches auth.log, the terminal and the CSV export. Refs #13860.
Use net.IPNet.Contains to check CIDR membership directly and remove the address increment loop. Large authorized subnets no longer cause per-request address enumeration and excessive CPU usage.
* feat: Remote download supports server file name options and improves error handling
* feat: Remote download supports server file name options and improves error handling
* feat(terminal): keep ssh sessions alive server-side with reattach
Split the terminal ws handling into a Session (pty + ssh backend) and an
Attachment (one websocket). A session outlives its websocket: a clean close
(1000) ends the pty, any other disconnect keeps it for a 30-minute grace
period and it can be reattached via `?session=<id>`. Output goes through a
fixed 128KB ring buffer so a reattaching client gets the recent tail, with a
truncation marker if it fell behind. Sessions are owner-scoped; a second
attachment kicks the first (4409), unknown ids get 4404.
New endpoints under /hosts/terminal/sessions (search, close) let the
frontend list and recover sessions after a tab or browser is closed.
* feat(terminal): floating terminal dock with session recovery
Terminals now live in a layout-level host and are teleported into whichever
view shows them, so leaving the terminal page no longer kills them. A dock
handle on the right edge opens a non-modal dialog from any page with every
live session, a picker for local shell / ssh hosts, minimize, and
close-all. On page load the store recovers sessions the server still holds,
so an accidentally closed tab or browser can resume within the grace period.
The menu-tab label shows the live session count.
* fix(terminal): page re-claims its slots under a locked menu tab
With the terminal menu tab locked (keep-alive), leaving the page deactivates
it instead of unmounting it, so the slot ref callback never re-runs on
return. After the dock had taken the Terminal over and released it, nobody
claimed it for the page again and it stayed parked in the hidden host.
Claim/release slots explicitly on mount, activated, deactivated and unmount,
the same ownership rule the dock uses, instead of relying on the ref callback.
* fix(terminal): logout closes every kept-alive terminal session
A logged-out panel has nobody watching it, so nothing it left running should
survive: core now tells the local agent to close all terminal sessions when the
user logs out, changes the password, or changes the bind domain. Until now the
teardown relied on the logging-out tab sending close code 1000; a second tab or
a websocket held outside the SPA kept its shell after logout.
Agent: terminal.CloseAll and POST /hosts/terminal/sessions/closeAll.
Core: LogOut / deleteCurrentSession / BindDomain call it via proxy_local,
best effort.
* fix(terminal): pin a local shell to the node it was opened on
The node a local shell connects to was resolved from the current node every
time the websocket was built, so after switching nodes a reconnect carried the
old session id to the new node (4404) and then opened a shell there instead.
Store the operateNode on the entry when it is created; ssh shells keep going to
the master. Shells on a non-master node get the node name in their title so a
restore in another node's view can tell them apart.
* feat(openresty): manage http-context directives via conf/http.d
Add a managed-file mechanism for http-context nginx directives, mirroring
the existing one for conf/modules-enabled.
A separate directory is required because load_module is a main-context
directive, so modules-enabled is included at the top level of nginx.conf and
cannot host http-context directives.
Files carry a 1panel-http- prefix; anything else in the directory is left
untouched. Writes are atomic via a temporary file plus rename, and the
directory is snapshotted so a failed nginx -t can be rolled back.
The mechanism is inert when conf/http.d does not exist, which is the case
for OpenResty installations predating the directory.
* fix(openresty): correct gzip defaults and add missing compressible types
Bring the embedded gzip template in line with how sites are actually served.
It was previously dead code: nothing referenced gzip.conf, so the values
never reached an installation. It is now embedded and used by the migration
that follows.
gzip_types was missing application/json, so JSON API responses were served
uncompressed. Also add ld+json, text/xml, xhtml+xml, rss+xml, atom+xml,
wasm, svg+xml and ttf/otf. Already compressed formats (images, woff2,
archives) stay out on purpose.
gzip_comp_level 6 -> 5, at the cost/ratio knee for gzip.
gzip_proxied any, so that proxied responses are compressed regardless of
their Cache-Control semantics.
gzip_static is intentionally not enabled: nginx does not verify that a .gz
file is newer than its source, so a stale artifact would be served
indefinitely with no error.
* feat(openresty): activate brotli directives when the module is enabled
Enabling ngx_brotli only emitted load_module, leaving the module loaded but
inert: no response was ever brotli-encoded until the user added
`brotli on` and `brotli_types` to nginx.conf by hand. The module is
prebuilt into the OpenResty image and listed in the catalog, so the only
missing step was the runtime configuration.
Enabling the module now also writes its http-context directives to
conf/http.d, and disabling or deleting it removes them. Removal matters:
leaving `brotli on` behind after the .so is unloaded makes nginx fail to
start on an unknown directive.
Both directory sets are written before nginx -t runs, so nginx only ever
observes a consistent state, and a failed check rolls back load_module
files and runtime directives together.
Runtime defaults are declared per module in a table, so other modules
needing http-context configuration can be added without touching the
reconcile logic.
brotli_types matches gzip_types so both encoders cover the same content.
brotli_comp_level is 5 rather than the nginx default of 6: level 5 reaches
roughly gzip level 9 ratio at a fraction of the cost, while 6 is tuned for
static assets and is too expensive for dynamic responses.
brotli_static is deliberately omitted, for the same reason gzip_static is:
nginx does not verify that a precompressed artifact is newer than its
source, so a stale file would be served indefinitely with no error.
Installations without conf/http.d keep the previous behaviour instead of
failing.
* feat(openresty): refresh stock gzip defaults on upgrade
Upgrades deliberately preserve the user's nginx.conf, so corrected gzip
defaults shipped with a new OpenResty version never reach existing
installations. Rewrite the values in place during upgrade, but only when the
block is provably untouched.
The rewrite requires every gzip directive to match the factory values byte
for byte, with none missing, none added and none duplicated. Any deviation
means the user tuned compression, and their configuration is left alone.
gzip stays in the http block of nginx.conf rather than moving to an included
file: nginx rejects a duplicate gzip directive across contexts, and the
compression settings page reads and writes these same keys in nginx.conf, so
a relocated block would be reintroduced on the next save and break nginx -t.
The config parser is not used either. Its dumper regenerates the whole file,
drops standalone comments and reorders proxy includes, which would be
destructive on a user's main config. Lines are edited individually so
everything outside the gzip block stays byte-identical.
The rewrite is idempotent, and a failed nginx -t restores the previous file.
A failure is logged as a warning instead of failing the upgrade.
* fix(website): preserve size units in nginx performance settings
The form stripped the unit suffix when reading a directive and then always
appended a fixed one when saving, so the unit was silently reinterpreted.
A config carrying `gzip_min_length 512;`, meaning 512 bytes, was read as 512
and written back as `512k`, inflating the threshold by 1024 and effectively
disabling compression for every response under 512 KB. The same applied to
client_header_buffer_size and client_max_body_size, where the value grew by
a factor of 1024 in the opposite, riskier direction.
Remember the unit that was read and write it back unchanged, defaulting to
the previous suffix only when the directive carries no unit information. The
input suffix now shows the unit actually in use instead of a hardcoded
label.
Also fix the value parsing itself: `Number(value.match(/\d+/g))` coerces a
multi-number match to NaN, so a directive such as `gzip_buffers 4 16k` would
blank the field. Take the first captured number instead.
* feat(website): expose brotli settings in the compression page
Brotli could be enabled as a module but never configured from the panel, so
its behaviour was invisible and unchangeable without editing nginx.conf by
hand.
The section appears only once the module is enabled and built, since the
directives are rejected by nginx while the module is not loaded. Values are
read from and written to the panel-managed http.d file rather than
nginx.conf, so they are removed together with the module.
brotli_types stays out of the form on purpose: it is kept aligned with
gzip_types so both encoders cover the same content, and exposing it would
invite the two lists to drift apart.
Saving reuses the existing scope endpoint with a dedicated brotli scope,
which keeps the managed file as the single source of truth instead of
duplicating the values into nginx.conf.
* fix(openresty): stop a stale build option from forcing a full rebuild
Manual builds and upgrades disagreed on when a full OpenResty image rebuild
is required. `executeNginxModuleBuild` used `staticNginxBuildRequired`, which
also treated a non-empty `RESTY_CONFIG_OPTIONS_MORE` in .env as a reason to
rebuild, while `buildNginx` looked only at the module list.
The env value is derived state, not an input: `configureStaticNginxModules`
rewrites it from the current module list, and every build path calls that
function before building. With no static module enabled it writes an empty
string, so the rebuild the latch triggered ran with an empty option list and
could only reproduce the image it started from — up to 120 minutes of build
time to arrive back where it began.
Decide on the module list alone, which is what the upgrade path already did.
An install that genuinely has an enabled static module is unaffected: both
predicates already agreed in that case. Leftover values are still cleared, by
`configureStaticNginxModules` on the next build or upgrade.
* feat(openresty): build modules on versions without a dynamic builder
Module state written before build modes existed carries no buildMode.
validateNginxModuleBuildMode rejects the empty value, which fails
loadNginxModules and with it every module operation and the upgrade itself —
the whole module subsystem, not just the static feature.
Infer the missing value from what the install can actually do instead:
dynamic when the builder and catalog are present, static when the compose
file still has a build section and build/Dockerfile to recompile the image.
Builds follow the same principle. Asking a pre-dynamic install to build a
module used to return "the installed OpenResty version does not support
dynamic module builds", which is a dead end: these versions produce modules
by compiling them into the image, and they still can. Such a build is now
retargeted to the static path, with --add-dynamic-module rewritten back to
--add-module and =dynamic switches reduced to their plain form. The error is
kept only for installs that reference a prebuilt image and genuinely cannot
compile anything, and it now says so and points at the upgrade.
The retarget applies to a copy that drives one build and is never persisted,
so the catalog stays authoritative and modules return to dynamic once the
install gains a builder.
Verified end to end against 1.27.1.2-5-1-focal, which ships no
Dockerfile.modules and no module.catalog.json: ngx_brotli compiles into the
image, nginx -t accepts the brotli directives with no load_module present,
and the server responds with Content-Encoding: br.
* feat(openresty): respect a hand-written brotli configuration
A user who enabled brotli before the panel managed it did so by editing their
configuration by hand. Emitting a managed file alongside it defined every
directive twice and nginx refused to start, so these users — the very ones
this feature is for — broke on upgrade.
Detection now scans every file nginx loads brotli from: nginx.conf and the
conf.d and default includes. Any active brotli* directive counts, so a lone
tuning directive is enough to treat the module as user-managed, and a
commented-out line never triggers it.
When the user owns the configuration, the panel stays out of the way:
- No managed http.d file is written, so the user's definition stays the only
one and their values are never overridden.
- brotli_types diverging from gzip_types is left exactly as written; the panel
does not widen them.
- The settings page reports their real values and shows a notice that brotli
is managed manually, rather than presenting defaults that do not match the
running configuration.
- Saving edits their own lines in place, keeping indentation and comments,
instead of writing a second copy. The flag is localised in all 12 languages.
Detection re-runs on every reconcile, so once the user deletes their
hand-written config the panel takes over again automatically.
* feat(openresty): wire conf/http.d from the agent instead of upgrade scripts
Following review feedback: setup scripts no longer create conf/http.d or
inject its include into existing installations' nginx.conf. The agent owns
the directory, the include, the runtime directives and the rollback, and only
touches nginx.conf when a module that needs http-context configuration is
actually enabled.
Insertion is a line-level edit, never the config parser: the include lands
before the conf.d include, or at the top of the http block when that anchor
is absent, keeping the surrounding indentation and leaving the rest of the
file byte-identical. A config without a locatable http block degrades to the
previous behaviour — module loads, runtime directives skipped, warning logged
— instead of failing the operation. Detection re-runs on every reconcile, so
an install recovers on its own once nginx.conf can be edited again.
Rollback now covers three artefacts: modules-enabled, http.d, and the
inserted line in nginx.conf.
The include is kept when the last module is disabled. Pointing at an empty
directory is harmless, and removing it would mean another edit of the user's
main config with its own failure surface.
When the include is missing and cannot be inserted, the brotli settings
report ManagedUnavailable and the settings page warns that the values shown
will not take effect, instead of presenting inert settings as live.
* fix(openresty): tighten brotli ownership handling and build guards
The settings page could not save brotli values for users who wrote their own
directives after the panel had started managing the module: the stale managed
file was still on disk, so every save ended in a duplicate directive error.
That file is now removed before the in-place edit, and a failed nginx -t
rolls back both sides.
User-managed detection now also covers conf/default, which is included at
http scope like conf.d, and the http.d include check no longer depends on the
exact container path literal, so an include written in a slightly different
form is recognised instead of duplicated.
The dynamic-to-static build fallback is dropped. The catalog and the dynamic
builder ship together, and installs without the catalog fail to load their
module state earlier anyway, so the branch could never run; what remains is
an error that says the version cannot build modules and to upgrade first.
The embedded gzip template is no longer wired to an unused variable, and a
test keeps it in sync with the defaults the upgrade writes.
Smaller fixes in the same area: a custom module named ngx_brotli no longer
inherits the built-in runtime defaults; nginx.conf edits go through temp file
renames and inserted lines follow the file's own line endings; the gzip
rewrite keeps each line's own indentation; the settings page resets its unit
cache on load, warns when the brotli half of a save fails after gzip already
applied, and no longer coerces unrendered keys to zero.
* fix(openresty): prove brotli reached the running server, not just disk
nginx -t and a successful reload both pass even when the managed directory
never reaches the container: the include is a glob, so a missing bind mount
or an unrecognised include variant silently loads nothing. The brotli save
now reads the effective configuration back with nginx -T and rolls the write
back with an actionable error when the directives are not there, instead of
reporting success for settings nobody will ever see.
The include match also accepts the quoted form nginx permits, so a
hand-written or legacy variant no longer invites a second include of the same
directory.
Values written into nginx.conf are checked against a whitelist before any
file is touched. The UI only ever sends on/off, numbers and sizes, but the
endpoint is reachable directly, and an unfiltered value could inject a
directive or trip the group-reference expansion of regexp.ReplaceAllString in
the in-place rewrite.
llmman (https://github.com/llmmanorg/llmman) is a local model runner
serving Ollama- and OpenAI-compatible routes on 127.0.0.1:17434.
Register it in the agent provider catalog next to Ollama and extend
every Ollama special case (no API key, verification skipped, OpenClaw
placeholder key, manual initial model) to cover it as well.
Fail2ban UI currently keys isActive only on systemd fail2ban.service.
If the daemon is alive under another process manager, whitelist and
blacklist stay disabled. Detect liveness with fail2ban-client ping.
Fixes#13678
Co-authored-by: zhudaguaneren <218366267+zhudaguaneren@users.noreply.github.com>
Updated the README to enhance the description of 1Panel's features, including AI management, security, and backup capabilities. Adjusted the Pro Edition feature comparison to include the Enterprise edition.
* feat: enhance archiving and extraction capabilities with additional compression formats and ownership preservation
* feat: enhance archiving and extraction capabilities with additional compression formats and ownership preservation
* feat: enhance archiving and extraction capabilities with additional compression formats and ownership preservation
* feat(auth): implement OIDC authentication endpoints and error handling
* feat(auth): add OIDC provider discovery endpoint and related functionality
* feat(auth): add SAML2 authentication support and related functionality
* feat(auth): add LDAP authentication support and related functionality
* fix(auth): improve login keydown handler for better event handling
Port forwarding no longer shares the filter client. FilterClient keeps only
filter capabilities, and forwarding gets its own adapter, service and boot
replay:
- utils/firewall/forwarding holds the provider adapters. firewalld uses native
forward-port, ufw and iptables share the NAT implementation moved out of
client/iptables/forward.go.
- service/forwarding.go owns base info, search, operate, enable and replay.
The API keeps its routes and dispatches on name/type/operate.
- init/firewall replays forwarding through that service instead of loading NAT
rule files inline.
Also adds 1PANEL_FORWARD to the IptablesOp name enum: the frontend already
sends {"name":"1PANEL_FORWARD","operate":"init-forward"} and the validator
rejected it with 400 before reaching the service. Besides that, the only
observable difference is that a forward-tab search no longer triggers the
port/address record cleanup goroutine on the side.
* feat(auth): add LDAP authentication support and related configurations
* feat(ldap): implement LDAP synchronization features and enhance user import logic
* feat(auth): add authSource and authSourceStatus to user information
* feat(i18n): update LDAP synchronization error messages in multiple languages
* feat(i18n): update LDAP synchronization error messages in multiple languages
* feat(i18n): update LDAP synchronization error messages in multiple languages
* feat: support dynamic module build for OpenResty
* feat: add dynamic module build page for OpenResty
* refactor: drop auto fallback, gate dynamic build by version support
- remove auto-to-static fallback; dynamic build failure now reports the
error and hints switching to static build manually
- gate dynamic builds on module support files (Dockerfile.modules +
module.catalog.json) instead of version numbers, expose
dynamicSupported in the modules API
- collect repeated path/status/operate strings into constants
- move nginx module regex patterns into utils/re with semantic helpers
- reorganize nginx_module.go around the main build flows and inline
single-use thin helpers
* feat: limit nginx module build mode options by version support
- build mode radio offers only dynamic and static (auto maps to dynamic
for legacy data)
- disable the dynamic option with a hint when the installed OpenResty
version lacks dynamic build support
* feat: complete i18n for nginx module pages
Fill in the new nginx module keys for all eleven language files
(translations other than zh/en are draft machine translations).
* feat: probe dynamic module support on load and drop the auto build mode
- probe each non-static module's configure params when loading the
module list and report dynamicSupport=supported/unsupported up front
- normalize the legacy auto build mode to dynamic
* feat: clarify module build modes in the UI
- build drawer lists dynamic modules (tagged, hot-reload) and static
modules (tagged, full rebuild + container restart) separately
- disable the dynamic option per module when its params do not support
dynamic build, distinct from the version gate hint
- drop the auto build mode wording everywhere and sync all eleven
language files
* feat: clarify purpose of the nginx module build drawer
- add a purpose hint explaining dynamic (hot reload) vs static (full
rebuild + container restart)
- drop the per-module mode tags now that section headers carry the
semantics
- allow submitting with zero dynamic modules selected when static
modules are present, so static-only users can trigger a build
* feat: pass apt mirror through to dynamic module builds
The mirror selected in the build dialog (or CONTAINER_PACKAGE_URL in the
app env as fallback) is now forwarded as a build arg so the module
builder uses the same apt source as the static build path. test-builder
gains a --mirror option.
* feat: add Lao translations for nginx module pages
* Add Lao language localization for lo.ts
* Add support for Lao language module
* Add Lao language translations to fu.ts
* Add Lao language support in i18n.go
* Add Lao language localization for lo.yaml
Pin the third-party actions referenced by mutable @master/@main tags to their
current commit SHA (tag kept in a trailing comment). Several run in jobs holding
secrets:
- SonarSource/sonarcloud-github-action@master (sonarcloud-scan.yml) — SONAR_TOKEN
- Yikun/hub-mirror-action@master (sync2gitee.yml) — GITEE_PRIVATE_KEY, GITEE_TOKEN
- fit2cloud/LLM-CodeReview-Action@main (llm-code-review.yml) — tokens + LLM API key
- crate-ci/typos@master (tyops-check.yml)
A moved tag would run unreviewed code with those secrets. Behaviour unchanged;
per GitHub's guidance to pin actions to a full-length commit SHA.
Signed-off-by: Kobi Hikri <kobi.hikri@gmail.com>
* Add Persian (fa) translations
* Update index.ts
Add fa to LOCALE_LOADERS
* Update fu.ts
Add fa item
* Update index.vue
enable Persian (fa) in language selector
* Update login-form.vue
enable Persian (fa) in language selector
* Create fa.yaml
add fa backend translations
* Update i18n.go
Add fa to langFiles variable
* Add Persian (fa) Translation to agent
* Add Persian README file
Add Persian (fa) README.fa.md to project
* fix(i18n): add Persian (fa) to backend validation and login dropdown
* Update README.fa.md
* Upade link in readme
Add the latest MiniMax-M3 flagship model to the MiniMax provider model
list and set it as the default. M3 offers a 1M context window, 128K max
output, reasoning, and image input. Drop the older M2.5 entries while
keeping M2.7 as an alternative, and update the account verification probe
to use M3.
Co-authored-by: octo-patch <266937838+octo-patch@users.noreply.github.com>
* Add Persian (fa) translations
* Update index.ts
Add fa to LOCALE_LOADERS
* Update fu.ts
Add fa item
* Update index.vue
enable Persian (fa) in language selector
* Update login-form.vue
enable Persian (fa) in language selector
* Create fa.yaml
add fa backend translations
* Update i18n.go
Add fa to langFiles variable
* Add Persian (fa) Translation to agent
* feat: add username/password support for hermes-agent
* feat: add username/password support for hermes-agent
* feat: add username/password support for hermes-agent
* feat: Add support for syncing self-signed certificates and manually uploaded certificates to other nodes.
* feat: Add support for syncing self-signed certificates and manually
* refactor: enhance rewrite configuration handling by introducing safe name validation and custom rewrite existence checks
* test: cover custom rewrite name handling
lego v5.2.2 (released 2026-06-02) is a single-fix patch on top of v5.2.1: the Namecheap DNS provider now derives the record key sub-domain correctly. 1Panel exposes the Namecheap provider through agent/utils/ssl/dns_provider.go, so this patch is meaningful for users issuing certificates against Namecheap-hosted zones.
Changes are confined to agent/go.mod and agent/go.sum; the source files under agent/utils/ssl/ already use the import path github.com/go-acme/lego/v5/... and require no code changes. Diff is a 6-line dependency bump (1 line in go.mod plus 4 lines of refreshed go.sum hashes); lego itself did not move any of its own dependency pins between v5.2.1 and v5.2.2.
Built and verified on linux/amd64:
GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' ./...
agent and core binaries link cleanly against the upgraded lego release; no source-level adaptations needed.
lego v5.2.1 (released 2026-06-01) is a small follow-up patch on top of v5.2.0; the only fixed item is a CLI/migration ergonomics tweak (printing the suggested configuration when the file cannot be created) that does not affect 1Panel, but moving to the latest tag keeps us on a published release rather than the previous one.
Changes are confined to agent/go.mod and agent/go.sum; the source files under agent/utils/ssl/ already use the import path github.com/go-acme/lego/v5/... and require no code changes. Compared with the previous v5.2.0 step, this revision is a 6-line dependency bump (1 line in go.mod plus 4 lines of refreshed go.sum hashes), since lego itself did not move any of its own dependency pins between v5.2.0 and v5.2.1.
Indirect dependency bumps (carried over from the v5.2.0 -> v5.2.1 rebase, produced by 'go mod tidy' on a fresh checkout):
- alibabacloud-go/darabonba-openapi v2.1.16 -> v2.2.1, alibabacloud-go/tea v1.4.0 -> v1.5.0 (alidns provider chain)
- aws-sdk-go-v2 family v1.41.7 -> v1.41.8 plus matching service modules (route53 provider chain)
- baidubce/bce-sdk-go v0.9.266 -> v0.9.267, huaweicloud/huaweicloud-sdk-go-v3 v0.1.197 -> v0.1.198, tencentcloud-sdk-go v1.3.102 -> v1.3.106, volcengine/volc-sdk-golang v1.0.248 -> v1.0.249
- go-acme/alidns-20150109 major bump v4 -> v5, go-acme/esa-20240910 major bump v2 -> v3 (required by lego v5.2.x directly)
- fsnotify/fsnotify v1.9.0 -> v1.10.1 (also targeted by dependabot PRs #12864 / #12865)
Built and verified on linux/amd64:
GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -trimpath -ldflags='-s -w' ./...
agent and core binaries link cleanly against the upgraded lego and indirect dependencies; no source-level adaptations needed.
The auto-renew flow in obtainSSL returned early when OpenResty was not
installed or `nginx -s reload` failed, skipping reloadSystemSSL. The new
certificate was persisted to the DB and written into website Nginx
configs, but the panel's own server.crt / server.key on disk and the
in-memory constant.CertStore were left pointing at the old material.
Because the cert was now fresh, subsequent cron ticks did not retry the
renewal, so the panel kept serving the stale cert until a user manually
re-applied it from 面板设置 → SSL.
Two changes:
1. agent/app/service/website_ssl.go
reloadSystemSSL is now called unconditionally after a successful
renewal, regardless of whether OpenResty is present or nginx reload
succeeded. The function already short-circuits for non-panel SSLs,
so this is safe.
2. agent/app/service/website_ssl.go + agent/cron/job/ssl.go
Add SyncSystemSSL, invoked at the start of every renew cron tick.
It compares the panel's on-disk cert/key with the WebsiteSSL row
referenced by the SSLID setting and rewrites the files + notifies
core when they diverge. This recovers existing installs that are
already in the "DB ahead of disk" state and self-heals any future
drift introduced by transient failures.
https://github.com/1Panel-dev/1Panel/issues/12472
* feat: enhance upgrade process with space check and file handling improvements
* fix: update minimum upgrade free space requirement to 500MB and simplify space check logic
#### What this PR does / why we need it?
Refs https://github.com/1Panel-dev/1Panel/issues/12681
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
cmd.Which() previously shelled out to `which <name>` to determine whether
a binary was on PATH. On distributions that do not ship a `which` package
by default — Arch Linux is the canonical example, but the same applies to
several minimal container images — `which` itself is missing, so every
call to Which() returned false and 1Panel reported core dependencies
(notably Docker) as 'not installed' even when they were running normally.
Switch the primary path to Go's exec.LookPath, which uses the process
PATH directly and has no external dependency. The original shell-out is
preserved as a fallback so any environment where the agent's PATH
differs from the user's interactive shell PATH (the original reason the
shell-out existed) keeps working unchanged.
Both copies are updated (agent/utils/cmd/cmd.go and core/utils/cmd/cmd.go)
and a small unit test is added to each package to guard the regression.
Fixes#12605
Signed-off-by: Sanjay Santhanam <51058514+Sanjays2402@users.noreply.github.com>
Enabling Panel SSL with the self-sign provider rejected IPv6 hosts with
"domain format invalid". Two coupled bugs caused this:
1. The frontend extracted the host from window.location.href with
href.split('//')[1].split(':')[0]. For an IPv6 URL like
https://[::1]:1234 that yields '[' \u2014 not a valid host \u2014 because
the second split splits on the first colon inside the bracketed
address. Use window.location.hostname, which natively returns the
bracket-stripped IPv6 host.
2. The backend ObtainSSL flow used net.ParseIP(domain) directly. Even if
the frontend sent the bracketed form ('[::1]'), net.ParseIP rejects
brackets, so the value flowed into IsValidDomain() and failed the
regex.
Add common.ParseIPLoose() that accepts both bare and bracketed IPv6 in
addition to bare IPv4. Use it at both call sites in ObtainSSL (renew
path and create path). A unit test guards the regression.
Files:
- agent/utils/common/common.go (new ParseIPLoose helper)
- agent/utils/common/parse_ip_test.go (12 cases, all green)
- agent/app/service/website_ca.go (call sites switched)
- frontend/src/views/setting/safe/ssl/index.vue
(host extraction fix)
Fixes#12646
Signed-off-by: Sanjay Santhanam <51058514+Sanjays2402@users.noreply.github.com>
`NewIFileService` returns the bare struct type `FileService`, but its
body returns a pointer (`&FileService{}`), and the function name suggests
it should return the interface (`IFileService`). The current signature
breaks `go build ./...` on the `agent` module:
app/service/file.go:95:9: cannot use &FileService{} (value of type
*FileService) as FileService value in return statement
app/service/website_proxy.go:276:36: cannot call pointer method
GetFileList on FileService
Both errors resolve when the constructor returns the interface, since
`*FileService` implements every method on `IFileService` (verified with
`go vet ./...`).
After this change, `go build ./...` and `go vet ./...` are clean on the
`agent` module.
#### What this PR does / why we need it?
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
#### What this PR does / why we need it?
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
#### What this PR does / why we need it?
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
#### What this PR does / why we need it?
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
#### What this PR does / why we need it?
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
* feat: Enhance file and recycle bin services with metadata handling and validation
* refactor: Rename recycle bin metadata handling to trash info and update related functions
* refactor: Remove orphan trash info pruning logic and related map usage in recycle bin service
The bug only appeared when the same process had both TCP and UDP sockets:
every listening port on that process was attributed to whichever protocol
was encountered first. For example, if a process listened on TCP 8000 and
UDP 8001, the UI could wrongly show TCP 8001 as in use while UDP 8001
looked unused.
Use (PID, conn.Type) as the cache key so each protocol has its own
ListeningProcess entry.
* chore: update dependencies and migrate S3 client to MinIO SDK
- Removed AWS SDK dependency and replaced S3 client implementation with MinIO SDK.
- Updated various dependencies in go.mod and go.sum, including version upgrades for `klauspost/compress`, `minio/minio-go`, and `rs/xid`.
- Adjusted S3 client methods to utilize MinIO's API for bucket listing, object existence checks, uploads, downloads, and deletions.
* refactor: enhance S3 client with context management and TLS support
- Introduced context management with timeouts for S3 client operations to improve reliability.
- Added TLS configuration to support secure connections based on the endpoint scheme.
- Updated S3 client methods to utilize the new context and transport settings for enhanced performance and security.
---------
Co-authored-by: ssongliu <sloooop1x@gmail.com>
#### What this PR does / why we need it?
Refs https://github.com/1Panel-dev/1Panel/issues/12488
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
#### What this PR does / why we need it?
Refs https://github.com/1Panel-dev/1Panel/issues/12482
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
#### What this PR does / why we need it?
Refs https://github.com/1Panel-dev/1Panel/issues/7759
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
* fix: Ensure proper resource management in file operations by closing files after creation and compression
* fix: Improve error handling for log file operations in MediaFile function
#### What this PR does / why we need it?
#### Summary of your change
#### Please indicate you've done the following:
- [ ] Made sure tests are passing and test coverage is added if needed.
- [ ] Made sure commit message follow the rule of [Conventional Commits specification](https://www.conventionalcommits.org/).
- [ ] Considered the docs impact and opened a new docs issue or PR with docs changes if needed.
When theme is set to "auto" (follow system), changing the OS from
light to dark (or vice versa) without reloading the page had no
effect. The theme was only evaluated once on page load.
Added a matchMedia 'change' event listener that calls switchTheme()
whenever the OS color scheme changes, but only when theme is "auto".
Listener is properly cleaned up on component unmount.
Fixes#6813 (point 1)
When clicking "Directory" on a container, the file browser always
opened at `/` (root). Now it inspects the container first and opens
at the container's configured WorkingDir (e.g., `/app`, `/var/www`).
Falls back to `/` if WorkingDir is not set or inspect fails.
Fixes#12255
- Added visual indicators for container status and creation date.
- Introduced a new radio button for environment configuration alongside existing options.
- Improved layout and styling for better user experience.
- Adjusted table column widths and added a class for styling.
- Introduced concurrent processing for app synchronization tasks to improve performance.
- Added structures for managing app work items and results.
- Implemented detailed logging of synchronization progress and HTTP request outcomes.
- Enhanced error handling for icon downloads and app details updates.
* Optimize sorting-related issues, disable the "favorite stars" function during sorting, and optimize sorting behavior caused by DOM conflicts.
* fix: prevent app icon from being squished in detail drawer
- Updated the compose item to include a new class for active state, improving visual feedback.
- Refactored action buttons into a dedicated container for better organization and hover effects.
- Added CSS transitions for smoother interactions on hover and active states.
Add a copy connection URL button to the MySQL, PostgreSQL, and Redis connection info drawers, allowing users to one-click copy the full connection URI for both container and remote connections.
* feat: Implement caching for settings retrieval and update logic
- Introduced a caching mechanism for settings using go-cache to improve performance.
- Updated the Create, Update, and UpdateOrCreate methods to cache values after database operations.
- Modified the Get and GetValueByKey methods to utilize the cache for faster access.
- Adjusted middleware to use the new GetValueByKey method for retrieving settings, enhancing code consistency.
* feat: Enhance setting cache management with dynamic TTL
- Introduced a function to determine cache TTL based on setting keys, allowing critical settings to have shorter cache durations.
- Updated cache logic in Create, Update, Get, and GetValueByKey methods to utilize the new TTL management, improving performance and consistency in settings retrieval.
* refactor: Simplify setting cache TTL management
- Removed the dynamic TTL function and standardized the cache TTL to a fixed duration for all settings.
- Updated cache logic in Create, Update, Get, and GetValueByKey methods to use the new fixed TTL, enhancing code clarity and maintainability.
- Added a new function to restart the core service after resetting settings, improving the reset command's functionality.
* refactor: Remove core restart functionality from reset commands
- Eliminated the restartCoreAfterReset function to simplify the reset command logic.
- Updated reset commands to return nil after setting changes, enhancing clarity and reducing unnecessary complexity.
- Added iconfont directory to .prettierignore
- Removed jsxBracketSameLine option from .prettierrc.js
- Fixed indentation in common.scss and reset.scss files
- Modified the logic to retain app details computed from remote sources, only falling back to existing details when necessary.
- Enhanced the synchronization process to ensure only remote resources are included in the synced app IDs for both addition and update scenarios.
* refactor: replace DownloadFileWithProxy with DownloadFileWithProxyStream for improved file downloading logic
* refactor: remove commented-out DownloadFileWithProxy function to clean up code
* fix: enhance app icon download logic to include file existence check
- Updated the downloadAppIcon function to parse the icon field for the file name and ETag.
- Added a condition to check if the icon file exists before setting the If-None-Match header for the request.
* fix: improve app icon retrieval logic by adding filename check
- Updated GetAppIcon method to include filename in the response.
- Added a condition to ensure the ETag header is set only if both ETag and filename are present, enhancing the integrity of the caching mechanism.
* fix: update browser cache handling in website proxy service
- Adjusted cache time condition to allow for negative values, introducing a no-cache option.
- Updated TypeScript interface to specify browser cache options as 'enable', 'disable', or 'noModify' for better clarity.
* refactor: clean up imports and enhance browser cache comments in website proxy service
- Removed unused import statements for better code clarity.
- Added detailed comments to clarify the behavior of the cache time settings in the OperateProxy function.
* fix: update SSL setting check to include 'Mux' option in GetSystemSSL function
* fix: update language files to clarify muxHelper descriptions for security implications
* feat: add keepdeps.go to preserve enterprise-only dependencies in OSS builds
* revert: revert cherrypick
- Introduced functionality to track if the auto passkey login has been attempted using session storage.
- Implemented methods to initialize and mark the auto passkey trial status.
- Automatically trigger passkey login if conditions are met during settings retrieval.
- Updated app icon handling to use a dedicated function for improved clarity and maintainability.
- Introduced a new method, getAppIconSrc, to manage icon source retrieval based on app properties.
- Ensured proper handling of base64 and URL-based icons for better performance and consistency.
* feat: implement app icon management and caching mechanism
* feat: enhance app synchronization and icon management
- Refactored app synchronization tasks to improve structure and clarity.
- Introduced shared context for managing app sync state and metadata.
- Updated icon handling to ensure proper content type and caching.
- Adjusted cache control settings for app icons to extend cache duration.
- Improved error handling and logging during app sync processes.
* refactor: streamline app icon retrieval by removing unused fileName return
- Removed the fileName return value from GetAppIcon function as it was not utilized.
- Enhanced the GetAppIcon method in BaseApi to improve clarity and maintainability.
- Ensured proper caching headers are set for app icons.
* feat: Add passkey authentication support with registration and login endpoints
* style: Refactor import statements and improve button formatting in login and settings views
* chore: Update dependencies in go.mod and go.sum, including adding go-webauthn and updating indirect dependencies
* refactor: Consolidate passkey session management and update related structures for improved clarity and functionality
* feat: Add passkey support in multiple languages with corresponding error messages and management options
* feat: Implement passkey reset command and enhance internationalization support for passkey-related messages
* refactor: Simplify login form structure by removing commented sections and unused passkey login function
* fix: Update passkey failure messages across multiple languages to include SSL certificate verification instructions
* chore: update go mod
* refactor: Update passkey handling by consolidating status checks and renaming related fields for clarity
* style: Format i18n file
* refactor: Enhance passkey configuration checks
* feat: Implement AppStore synchronization task
- Introduced a new `syncAppStoreTask` function to handle the synchronization of applications from the AppStore.
- The function checks for updates, retrieves the application list, and manages the synchronization process, including downloading app icons and updating app details.
- Refactored the existing app synchronization logic from `SyncAppListFromRemote` into the new task for improved maintainability and clarity.
- Added logging for progress tracking during the synchronization process.
* feat: Refactor HTTP request handling to support custom client
- Introduced `HandleRequestWithClient` function to allow custom HTTP clients for requests.
- Moved the transport loading logic into the new function for better separation of concerns.
- Updated `HandleRequest` to utilize the new function, enhancing flexibility in request handling.
* refactor: Simplify HTTP request handling in app synchronization
- Replaced direct HTTP request handling with `HandleRequestWithClient` for downloading app icons and Docker Compose files.
- Removed unused variables and logging related to icon download updates for cleaner code.
- Improved error handling and logging for failed requests.
* feat: Add endpoint to retrieve listening processes and update related services
* fix: Update listening process retrieval logic to include socket type checks
* refactor: accept context for improved request handling
* feat: Add pullImage option to ComposeCreate and update related logic
- Introduced a new optional field `pullImage` in the `ComposeCreate` struct to control image pulling behavior.
- Updated `CreateCompose` method to handle the `pullImage` flag when invoking the compose up command.
- Modified `UpWithTask` function to conditionally skip image pulling based on the `pullImages` parameter.
- Enhanced frontend form to include a checkbox for the `pullImage` option, with default value set to true.
* feat: Add label for environment variable input in Compose form
This fix addresses three bugs in the DNS Manual SSL certificate flow:
1. **Order caching fails when Expires is zero**: ACME orders often have
zero Expires initially. The condition `!Expires.IsZero()` caused valid
cached orders to be deleted and recreated with different TXT values.
Fixed by checking `Expires.IsZero() || Expires.After(now)`.
2. **Wildcard and base domain TXT records overwrite each other**: When
requesting SSL for both `example.com` and `*.example.com`, both
authorizations have identifier `example.com`, causing one TXT value
to overwrite the other. Fixed by using `*.domain` as the map key.
3. **Only first TXT record checked**: When multiple TXT records exist,
only the first was checked. Fixed by returning all TXT values and
checking if expected value exists in any of them.
```release-note
Fix DNS Manual SSL certificate issues for wildcard domains
```
Co-authored-by: DeployThemAll <deploythemall@users.noreply.github.com>
Co-authored-by: Claude Opus 4.5 <noreply@anthropic.com>
* refactor: enhance Mux connection handling in server
* fix: Increase maximum allowed length for RequestURI in Mux connection handling
* feat: Add support for HTTP/2 in Mux mode
* fix: Update regex patterns for log highlighting in custom component
* feat: Add new regex pattern for HTTP status codes highlighting in custom log component
* refactor: Update HTTP status code regex patterns in custom log component for improved highlighting
* feat: Add support for Mux SSL mode and update related settings
- Introduced a new SSL mode "Mux" in the settings, allowing for HTTP to HTTPS redirection.
- Updated the `SSL` field in the `SettingUpdate` struct to include "Mux" as a valid option.
- Modified the server logic to handle Mux connections, including certificate management and HTTP redirection.
- Updated frontend components to reflect the new SSL options and improved user guidance in multiple languages.
* fix: Update HTTPS related messages for improved clarity and security guidance in multiple languages
* feat: Enhance browser cache management and localization support
- Updated browser cache handling in WebsiteService to include a 'noModify' option.
- Introduced new method AddBroswerNoCache in Location to manage no-cache directives.
- Added localization for 'noModify' in multiple languages.
- Updated frontend to support the new browser cache options in the proxy configuration.
* fix: Update cache display logic in proxy configuration
- Adjusted the rendering of cache tags in the proxy configuration to conditionally display based on cache time values.
- Improved user interface by adding margin classes for better spacing between cache tags.
- Introduced ProcessStore for managing process and network data via WebSocket.
- Enhanced TableSearch component to synchronize search parameters with props.
- Updated network and process views to utilize ProcessStore for data fetching and state management.
- Improved data filtering and sorting in network and process views.
- Added WebSocket connection management with polling for real-time updates.
* feat: Enhance WebSocket client functionality and improve data processing
- Reduced message queue size in WebSocket client from 100 to 32.
- Introduced atomic boolean to track client closure state.
- Added SendPayload method to handle message sending with queue management.
- Updated ProcessData function to utilize SendPayload for sending responses.
- Expanded netTypes to include both IPv4 and IPv6 protocols in network connection retrieval.
- Improved net connection processing by using a map for process names, enhancing efficiency.
* feat: Enhance WebSocket client and process data handling
- Added synchronization with sync.Once for safe closure of WebSocket client.
- Updated message queue size to a constant for better maintainability.
- Implemented context timeouts for process data retrieval to prevent blocking.
- Improved network connection handling by utilizing a more efficient method for retrieving connections.
- Introduced a new function to determine connection types based on protocol family.
* feat: Enhance network connection retrieval and process name mapping
- Updated getNetConnections function to improve efficiency by using maps for process names and connections.
- Introduced a new helper function to retrieve process names from the filesystem or process context.
- Enhanced filtering logic for network connections based on process ID, name, and port.
- Increased initial capacity for connection results to optimize performance.
* refactor: Rename SendPayload method to Send in WebSocket client
- Updated the SendPayload method to be more succinctly named Send for clarity.
- Ensured the method continues to handle message sending while maintaining existing functionality.
* refactor: Update ProcessData and getNetConnections for improved clarity and efficiency
- Replaced SendPayload method calls with Send for consistency in WebSocket message handling.
- Enhanced getNetConnections function by refining process name retrieval and filtering logic.
- Improved error handling in getProcessNameWithContext for better robustness.
* refactor: Simplify WebSocket client closure and reading logic
- Removed unnecessary synchronization for closing the WebSocket client.
- Updated the Read method to handle message reading directly without a separate Close method.
- Ensured the Socket is closed properly after reading messages to prevent resource leaks.
* refactor: Simplify process data handling and improve performance
- Replaced goroutine-based processing with a direct loop for handling process data.
- Introduced context support for process and connection retrieval.
- Enhanced error handling and data structuring for process information.
- Improved SSH session retrieval by mapping users by host for better efficiency.
* chore: go fmt
* feat: Add file content preview functionality
- Implemented a new API endpoint for previewing file content.
- Added PreviewContent method in BaseApi to handle requests.
- Introduced GetPreviewContent method in FileService to retrieve file previews.
- Updated frontend to include a TextPreview component for displaying file previews.
- Added localization support for preview-related messages in multiple languages.
- Enhanced file management view to support previewing large files.
* feat: Update file preview functionality and interface
- Added PreviewContentReq interface to define request parameters for file preview.
- Updated getPreviewContent function to use the new PreviewContentReq type.
- Modified text-preview component to align with updated API, removing unnecessary parameters.
* feat: Enhance proxy initialization and error handling
* Add a timeout to the dialer for Unix socket connections
* Improve error response by including the error message in the "Bad Gateway" response
* refactor: Change sockPath variable to constant in proxy initialization
* Update sockPath to a constant SockPath for improved clarity and consistency
* Ensure the new constant is used in the dialer function for Unix socket connections
* feat: Add PrettyDistro field to dashboard information and update related services and frontend components
* fix: Trim whitespace and parentheses from detected Linux distribution name in GetDistro method
* fix: Correctly trim parentheses from detected Linux distribution name in GetDistro method
* refactor: Simplify Linux distribution detection by removing unnecessary checks and consolidating logic
* fix: Update CPU usage retrieval to include detailed percentage information
* feat: Enhance CPU metrics by adding CPU frequency and detailed usage percentages
* feat: Add CPU frequency metric to dashboard base information
* feat: Add copy button for raw JSON in container and network detail views
* refactor: Change CodemirrorPro component from disabled to readonly in container and network detail views
* feat: Add readonly prop to CodemirrorPro component for enhanced editing control
* perf: use gzipped data for improved load speed in big files
* perf: switch to gzipped response for GetFileTree to enhance performance
* perf: switch to gzipped response for SearchApp to improve performance
* perf: update file size conditions for gzipped response to enhance performance
* feat: Add path protection mechanism to prevent deletion of critical system directories
* feat: Enhance recycle bin service with path protection for deletion requests
* feat: async load data of top CPU and memory processes data
* refactor: Update CPU and memory top toggle functionality and state management
---------
Co-authored-by: 王贺 <wanghe@fit2cloud.com>
* refactor: Optimize log file reading with buffered reader pool and improve pagination logic
* refactor: Enhance file reading logic with improved buffer management and constant usage
* refactor: Adjust maximum read file size and enhance line reading functionality
* feat: Add ComposeDetail view for enhanced container management
* feat: Update container log management with new table layout and improved stats display
* feat: Update log search mode to 'all' for comprehensive log retrieval
* cleanup
* feat: Enhance log container and compose management with new UI components and improved functionality
* refactor: Remove unused ComposeDetail route and enhance UI components in container management
* refactor: Improve UI styling and interaction for compose list items in container management
* refactor: Update styling and hover effects for compose list items in container management
* refactor: Enhance container compose header with additional context and improve port handling in inspect view
* refactor: Update .env label to use translation for improved localization in container compose view
* refactor: Adjust height and placeholder text for YAML editor in container compose view
* refactor: Adjust docker compose layout
---------
Co-authored-by: ssongliu <songlius11@163.com>
* feat: Implement language caching and improve language handling in i18n module
* refactor: Optimize i18n initialization with sync.Once for thread safety
* fix: Replace logging with fmt.Println for language file loading errors in i18n module
* fix: Correct format string in error logging for language file loading in i18n module
* fix: Update language files and improve error handling in i18n module
* fix: Update Malay language file extension from .yml to .yaml and add new translations in i18n module
* fix: Improve error messages for language file loading in i18n module
* fix: Ensure cached database language is set correctly during i18n initialization
* fix: Enhance language detection in i18n module by using Accept-Language header
* feat: enhance S3 region selection with dropdown and custom input option
* refactor: streamline S3 region selection and endpoint handling in backup account settings
Optimize the default selection logic after the SSL list is loaded.
Add a flagging mechanism for manual SSL certificate selection, which disables automatic selection once triggered.
Add listeners for changes to the primary and more domains to trigger this automatic selection logic.
* feat: Enhance caching options for proxy configuration
* fix: typo
* feat: Update caching and directive handling in proxy configuration
* feat: Update default cache time and unit to improve caching configuration
* feat: Implement RemoveCorsOption method to streamline CORS directive removal
* feat: Enhance cache display and initialization in proxy configuration
* refactor: Clean up AddBrowserCache and RemoveCache methods by removing commented-out code
* Tweak button spacing and fix color issue on App upgrade comparison pages
* update button styles and replace inline margin with utility class
---------
Co-authored-by: fanbook-wangdage <124357765+fanbook-wangdage@users.noreply.github.com>
PROMPT:"Please check the following code differences for any irregularities, potential issues, or optimization suggestions, and provide your answers in English."
@@ -10,10 +10,12 @@ PR are always welcome, even if they only contain small fixes like typos or a few
Please submit a PR broken down into small changes bit by bit. A PR consisting of a lot of features and code changes may be hard to review. It is recommended to submit PRs in an incremental fashion.
This [development guideline](https://docs.1panel.pro/dev_manual/dev_manual/) contains information about repository structure, how to set up development environment, how to run it, and more.
Note: If you split your pull request to small changes, please make sure any of the changes goes to master will not break anything. Otherwise, it can not be merged until this feature complete.
## Add a new translation
If you'd like to help translate 1Panel into a new language, please read the [Translation Contribution Guide](docs/TRANSLATION.md). It lists every file you need to create or modify, along with a reference PR you can use as a concrete example.
## Report issues
It is a great way to contribute by reporting an issue. Well-written and complete bug reports are always welcome! Please open an issue and follow the template to fill in required information.
1Panel is an open-source, modern web-based control panel for Linux server management.
## What is 1Panel?
- **Efficient Management**: Through a user-friendly web graphical interface, 1Panel enables users to effortlessly manage their Linux servers. Key features include host monitoring, file management, database administration, container management, LLMs management.
- **Rapid Website Deployment**: With deep integration of the popular open-source website building software WordPress, 1Panel streamlines the process of domain binding and SSL certificate configuration, all achievable with just one click.
- **Application Store**: 1Panel curates a wide range of high-quality open-source tools and applications, facilitating easy installation and updates for its users.
- **Security and Reliability**: By leveraging containerization and secure application deployment practices, 1Panel minimizes vulnerability exposure. It further enhances security through integrated firewall management and log auditing capabilities.
- **One-Click Backup & Restore**: Data protection is made simple with 1Panel's one-click backup and restore functionality, supporting various cloud storage solutions to ensure data integrity and availability.
1Panel is a modern, open-source Linux server management panel and a lightweight AI management platform. Through an intuitive web interface, it provides users with comprehensive, one-stop server management capabilities:
- **AI Management**: Offers a unified management platform from bare metal to agents (Metal-to-Agent). It integrates an AI gateway, and Skills Hub, while supporting centralized management of agents and models.
- **Efficient Visual Operations**: Easily manage Linux servers through a web-based GUI, streamlining tasks such as host monitoring, file management, database management, and container management.
- **Rapid Website Deployment**: Deeply integrates with popular website builders like WordPress and Halo. It enables one-click domain binding and SSL certificate configuration, significantly lowering the barrier to website creation.
- **Curated App Store**: Features a built-in store of high-quality open-source applications, providing one-click installation and upgrade services to effortlessly extend server capabilities.
- **Enterprise-Grade Security**: Deploys applications based on container technology to effectively minimize vulnerability exposure. It also provides security features such as WAF and log auditing to ensure comprehensive server protection.
- **One-Click Data Backup**: Supports one-click backup and restoration, and integrates with various cloud storage solutions to ensure data security and prevent loss.
Compared to the OSS Edition, 1Panel Pro Edition provides users with a wealth of enhanced features and technical support services. Enhanced features include WAF enhancement, website tamper protection, website monitoring, GPU monitoring, custom logo and theme color, etc. [Click to view the detailed introduction of the Pro Edition](https://1panel.pro/pricing).
1Panel OSS is free forever. 1Panel Pro and Ent adds features built for teams and production workloads:
- **Issues** — [GitHub Issues](https://github.com/1Panel-dev/1Panel/issues) for bug reports
## Security
Found a vulnerability? Please read [SECURITY.md](/SECURITY.md) before disclosing.
## License
Licensed under The GNU General Public License version 3 (GPLv3) (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at
<https://www.gnu.org/licenses/gpl-3.0.html>
Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License.
Licensed under the [GNU General Public License v3.0](https://www.gnu.org/licenses/gpl-3.0.html).
// @Param request body dto.CronjobDownload true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /cronjobs/download [post]
// @x-panel-log {"bodyKeys":["recordID"],"paramKeys":[],"BeforeFunctions":[{"input_column":"id","input_value":"recordID","isList":false,"db":"job_records","output_column":"file","output_value":"file"}],"formatZH":"下载计划任务记录 [file]","formatEN":"download the cronjob record [file]"}
// @Param request body dto.MysqlUserCreate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/users [post]
// @x-panel-log {"bodyKeys":["database","username","host"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"创建 mysql 数据库 [database] 用户 [username]@[host]","formatEN":"create mysql database [database] user [username]@[host]"}
// @Param request body dto.MysqlUserDelete true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/users/del [post]
// @x-panel-log {"bodyKeys":["database","username","host"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"删除 mysql 数据库 [database] 用户 [username]@[host]","formatEN":"delete mysql database [database] user [username]@[host]"}
// @Param request body dto.MysqlUserPassword true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/users/password [post]
// @x-panel-log {"bodyKeys":["database","username","host"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新 mysql 数据库 [database] 用户 [username]@[host] 密码","formatEN":"update mysql database [database] user [username]@[host] password"}
// @Param request body dto.MysqlGrantCreate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/grants [post]
// @x-panel-log {"bodyKeys":["database","db","username","host"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"授权 mysql 数据库 [database] 用户 [username]@[host] 访问 [db]","formatEN":"grant mysql database [database] user [username]@[host] access to [db]"}
// @Param request body dto.MysqlGrantDelete true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /databases/grants/del [post]
// @x-panel-log {"bodyKeys":["database","db","username","host"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"取消 mysql 数据库 [database] 用户 [username]@[host] 对 [db] 的授权","formatEN":"revoke mysql database [database] user [username]@[host] access to [db]"}
// @Description Create partition and format disk with specified filesystem
// @Accept json
// @Param request body request.DiskPartitionRequest true "partition request"
// @Success 200 {string} string "Partition created successfully"
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/disks/partition [post]
// @x-panel-log {"bodyKeys":["device", "filesystem", "mountPoint"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"对磁盘 [device] 进行分区,文件系统 [filesystem],挂载点 [mountPoint]","formatEN":"Partition disk [device] with filesystem [filesystem], mount point [mountPoint]"}
// @Description Deletes managed rules by UUID or unprotected before-chain rules by instance key. Returns a taskID immediately; results are written to the task log.
// @Accept json
// @Param request body dto.FirewallRuleDelete true "request"
// @Description Saves whitelist configuration only. Missing rules are added on startup, restart, initialization, or synchronization; existing rules are not removed.
// @Accept json
// @Param request body dto.FirewallPortWhitelistCreate true "request"
// @Description Saves whitelist configuration only. Missing rules are added on startup, restart, initialization, or synchronization; existing rules are not removed.
// @Accept json
// @Param request body dto.AddrRuleOperate true "request"
// @Param request body dto.FirewallPortWhitelistUpdate true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /hosts/firewall/ip [post]
// @x-panel-log {"bodyKeys":["strategy","address"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"添加 ip 规则 [strategy] [address]","formatEN":"create address rules [strategy][address]"}
// @Description Saves whitelist configuration only. Missing rules are added on startup, restart, initialization, or synchronization; existing rules are not removed.
// @Accept json
// @Param request body dto.BatchRuleOperate true "request"
// @Param request body dto.FirewallPortWhitelistDelete true "request"
// @Param request body dto.TerminalAIInfo true "request"
// @Success 200
// @Security ApiKeyAuth
// @Security Timestamp
// @Router /settings/terminal/ai/update [post]
// @x-panel-log {"bodyKeys":["aiStatus","aiAccountId"],"paramKeys":[],"BeforeFunctions":[],"formatZH":"更新终端 AI 设置 [aiStatus][aiAccountId]","formatEN":"update terminal AI setting [aiStatus][aiAccountId]"}
// @x-panel-log {"bodyKeys":["websiteID"],"paramKeys":[],"BeforeFunctions":[{"input_column":"id","input_value":"websiteID","isList":false,"db":"websites","output_column":"primary_domain","output_value":"domain"}],"formatZH":"修改 [domain] 网站真实IP配置 ","formatEN":"Modify the real IP configuration of [domain] website"}
Some files were not shown because too many files have changed in this diff
Show More
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.