Skip to content

Releases: Rain-kl/OpenFlare

v3.5.5

Choose a tag to compare

@github-actions github-actions released this 19 Sep 04:47

chore(release): v3.5.5

🛠 修复

  • 修复 Cloudflare 指向分组引用的节点已被删除时,分组列表/详情接口整体返回「Cloudflare 资源不存在」的问题;现会跳过缺失节点并继续返回其余分组。
  • 修复静态导出部署下访问 Cloudflare 指向分组详情(/cloudflare/groups/{id},id 不为 1)会跳回首页并触发 React hydration 报错的问题。

⚡️ 优化与改进

  • 优化 openflare-agent Docker 镜像体积:精简运行时依赖并消除离线 IP 库冗余层,镜像总体积从 500MB+ 缩减至约 150MB。

v3.5.4

Choose a tag to compare

@github-actions github-actions released this 29 Aug 10:42

chore(release): v3.5.4

✨ 新功能

  • 控制台接入中英双语(next-intl,无 URL 语言前缀):默认中文,可在顶栏或「外观设置」切换。

🛠 修复

  • 修复在网站列表中删除已加入 Cloudflare 指向分组的域名后,访问 Cloudflare 指向分组详情报错「Cloudflare 资源不存在」的问题。
  • 修复自定义 Webhook 推送在企业微信/钉钉返回 HTTP 200 但 errcode 非零时仍记为成功的问题;任务日志会记录上游响应体。
  • 修复 OpenTelemetry Resource 绑定 semconv schema 版本导致 SDK 升级后可能无法启动的问题。
  • 修复静态导出(build:embed)部署下切换语言无效的问题:此前页面在构建时固定为默认中文,运行时不再读取 NEXT_LOCALE;现在客户端会按 cookie/浏览器语言重新解析并切换界面语言与 html lang。
  • 修复 frpc 子进程在被杀后孤儿进程继续持有管道导致退出阻塞的问题。

💄 其他/体验

  • 前端使用 next/font 自托管 Inter 字体,并忽略浏览器扩展改写 body 属性引起的 hydration 警告。

v1.4.2

Choose a tag to compare

@github-actions github-actions released this 17 Sep 14:01

feat(core): sync framework security hardening and accessibility improvements

  • add util.Go with panic recovery for background goroutines
  • add util.EscapeLike and explicit ESCAPE clause for SQL LIKE queries
  • add DummyCheckPassword and subtle.ConstantTimeCompare against timing attacks
  • enforce session ID rotation upon login/oauth callback to prevent session fixation
  • add sliding window login failure rate limiting and oauth state rate limiting
  • fix redis client capture race in pubsub listeners and wait on stop channel
  • adjust global --primary to oklch(51.1% 0.262 276.966) for WCAG AA contrast
  • fix semantic heading levels and missing aria-labels across UI components
  • document security, concurrency, and a11y standards in AGENTS.md

v3.5.3

Choose a tag to compare

@github-actions github-actions released this 13 Aug 03:45

杂务(发布):v3.5.3
chore(release): v3.5.3

新增

New

  • 访问日志「日志明细」支持按 HTTP 状态码筛选,可直接输入任意状态码。
  • The access log "Log Details" supports filtering by HTTP status code, and you can directly enter any status code.
  • 访问日志「日志明细」支持自定义时间范围筛选,可按起止时间检索日志。
  • Access log "Log Details" supports custom time range filtering, and logs can be retrieved by start and end time.
  • 首页看板改版:24 小时请求趋势拆分展示请求总量与 2xx/4xx/5xx 状态码类请求量并独占一行;移除宿主机磁盘指标,24 小时容量趋势(CPU/内存)并入业务流量卡片展示。
  • Revision of the homepage dashboard: 24-hour request trend is split to display the total request volume and 2xx/4xx/5xx status code request volume in an exclusive line; the host disk indicator is removed, and the 24-hour capacity trend (CPU/memory) is merged into the business traffic card display.

🛠 修复

🛠 Fix

  • 修复首页「来源分布」卡片在 PostgreSQL/SQLite 日志库下无数据的问题。
  • Fixed the issue where the "Source Distribution" card on the homepage has no data under the PostgreSQL/SQLite log library.
  • 修复源站错误页「仅针对 GET 请求」未真正透传非 GET 响应的问题:POST/PUT 等非 GET 请求现可完整看到源站原始报错内容。
  • Fixed the issue where the origin site error page "Only for GET requests" does not truly transparently transmit non-GET responses: Non-GET requests such as POST/PUT can now fully see the original error content of the origin site.

v3.5.2

Choose a tag to compare

@github-actions github-actions released this 09 Aug 06:08

杂务(发布):v3.5.2
chore(release): v3.5.2

修复几个遗漏bug
Fixed several missing bugs

v3.5.1

Choose a tag to compare

@github-actions github-actions released this 09 Aug 03:40

Important

该版本解耦了日志存储,ClickHouse 变为可选项,如果想切换数据库, 点击 「任务管理」 -> 「切换日志数据库」任务,按提示迁移数据并切换主库。

✨ 新功能

  • 日志存储解耦:ClickHouse 变为可选项,不启用时由 PostgreSQL/SQLite 承担全部日志功能;新增「切换日志数据库」任务支持 PostgreSQL/SQLite 与 ClickHouse 间数据迁移(迁移期间冻结日志写入,成功后自动切换主库并保留源数据);log_database / log_db_migration 设为受保护配置;ClickHouse 改为默认关闭。
  • Log storage decoupling: ClickHouse becomes optional, and PostgreSQL/SQLite assumes all log functions when not enabled; the new "Switch Log Database" task supports data migration between PostgreSQL/SQLite and ClickHouse (log writing is frozen during the migration, and the main database is automatically switched and the source data is retained after success); log_database / log_db_migration is set to protected configuration; ClickHouse is changed to closed by default.
  • 新增 PostgreSQL/SQLite 日志存储实现:节点访问日志按月分区,统计查询合并为单次扫描、IP 汇总归属地取查询窗口内最新记录、WAF 按 IP 聚合减少扫描次数,并新增 logged_at 前导索引与主机名小写表达式索引;过期清理直接删除完全过期的整月分区,启动时兜底预建当月及未来 2 个月分区。
  • Added PostgreSQL/SQLite log storage implementation: node access logs are partitioned by month, statistical queries are merged into a single scan, IP aggregation is used to retrieve the latest records in the query window, WAF aggregates by IP to reduce the number of scans, and a new logged_at leading index and host name lowercase expression index are added; expiration cleanup directly deletes completely expired partitions for the entire month, and pre-builds the current month and the next 2-month partitions at startup.
  • 性能指标与访问日志的保留时长解耦:新增三库共用的 metric_retention_days 配置(默认 3 天),每日垃圾清理按独立短留存清理指标快照。
  • Decoupling performance indicators from the retention period of access logs: adding the metric_retention_days configuration shared by the three databases (default 3 days), daily garbage cleaning cleans indicator snapshots based on independent short retention.

🛠 修复

🛠 Fix

  • 修复 UptimeKuma 同步调试日志泄露凭据:Socket.IO 事件日志不再打印 payload 内容(仅记录长度),避免凭据进入日志。
  • Fix UptimeKuma synchronization debug log leaking credentials: Socket.IO event log no longer prints payload content (only record length) to prevent credentials from entering the log.
  • 修复日志保留天数配置继承旧键导致的误删风险:log_retention_days_* 不再继承 database_auto_cleanup_retention_days,统一默认 30 天。
  • Fixed the risk of accidental deletion caused by inheritance of old keys in the log retention days configuration: log_retention_days_* no longer inherits database_auto_cleanup_retention_days, and the default is 30 days.

⚡️ 优化与改进

⚡️ Optimization and improvement

  • 系统定期垃圾清理由每 2 小时改为每日执行一次(凌晨 3 点,Asia/Shanghai),降低非必要高频扫描。
  • The system's regular garbage cleaning is changed from every 2 hours to once a day (3 a.m., Asia/Shanghai) to reduce unnecessary high-frequency scanning.

💄 其他/体验

💄 Other/Experience

Error 500 (Server Error)!!1500.That’s an error.There was an error. Please try again later.That’s all we know.

  • The service worker (SW) injection challenge page has been changed to a front-end non-awareness: "Loading..." text is no longer displayed, the page is blank, and only [sw-challenge] debugging information is output through the browser console, and the injection process does not disturb visitors.
  • 用户访问日志(w_user_access_logs)记录禁用:不再采集与写入新的用户访问日志,存量数据与管理端访问日志统计页面保留。
  • User access log (w_user_access_logs) recording is disabled: new user access logs will no longer be collected and written, and the existing data and management-end access log statistics page will be retained.

v3.5.0

Choose a tag to compare

@github-actions github-actions released this 08 Aug 15:09

杂务(发布):v3.5.0
chore(release): v3.5.0

🛠 修复

🛠 Fix

  • 修复 PoW 挑战页潜在 XSS 风险,状态与错误文案改用纯文本渲染,并限制跳转 URL 仅允许 http/https 协议。
  • Fixed the potential XSS risk on the PoW challenge page, changed the status and error text to plain text rendering, and restricted the jump URL to only allow http/https protocols.
  • 修复邮件发送的邮件头注入风险,写入邮件头前自动清除 CR/LF 换行符(CWE-93)。
  • Fixed header injection risk in email sending, automatically clearing CR/LF newlines before writing the header (CWE-93).
  • 修复 UptimeKuma 同步调试日志泄露凭据问题,输出日志前对密码和 Token 等敏感字段打码。
  • Fixed the issue of credential leakage in UptimeKuma synchronization debug log, and code sensitive fields such as password and Token before outputting the log.

⚡️ 优化与改进

⚡️ Optimization and improvement

  • 新增 Service Worker 离线兜底功能,为启用 HTTPS 的网站自动下发 Service Worker 并缓存离线页,域名不可达时展示离线兜底页面。
  • Added Service Worker offline backup function, which automatically delivers Service Worker to HTTPS-enabled websites and caches offline pages. When the domain name is unreachable, the offline backup page is displayed.
  • 重构响应页面设置,将源站错误页与 Service Worker 离线页整合至统一的「响应页面」(/responses)标签页,并增加 URL 查询参数 tab 状态同步。
  • Reconstruct the response page settings, integrate the origin site error page and Service Worker offline page into a unified "response page" (/responses) tab, and add URL query parameter tab status synchronization.

💄 其他/体验

💄 Other/Experience

  • 新增离线页内置预制模板套件(「极简白底」、「线框拓扑」、「包豪斯」),与源站错误页模板风格保持一致,支持编辑界面一键加载与预览。
  • Added a new set of built-in premade templates for offline pages ("Minimalist White Background", "Wireframe Topology", "Bauhaus"), which are consistent with the source site error page template style, and support one-click loading and preview on the editing interface.

v3.4.5

Choose a tag to compare

@github-actions github-actions released this 08 Aug 03:26

杂务(发布):v3.4.5
chore(release): v3.4.5

⚡️ 优化与改进

⚡️ Optimization and improvement

  • 源站错误页新增「仅针对 GET 请求」开关:开启后仅对 GET 请求的匹配错误状态码返回自定义错误页,其它 HTTP 方法透传源站响应。
  • A new "Only for GET request" switch is added to the origin site error page: when enabled, only the matching error status code of the GET request will be returned to a custom error page, and other HTTP methods will transparently transmit the origin site response.
  • 升级前后端依赖至最新稳定版
  • Upgrade front-end and back-end dependencies to the latest stable version
  • Agent 不再将 GeoLite2 Country/City MMDB 嵌入二进制:Docker 镜像在默认数据目录 COPY 数据库文件,裸二进制首次启动时按需下载,显着减小 Agent 包体积;OpenResty 仍从磁盘路径读取 MMDB,Server 控制面仍仅内嵌 Country MMDB(不含 City)。
  • Agent no longer embeds GeoLite2 Country/City MMDB into the binary: the Docker image COPYs the database file in the default data directory, and the bare binary is downloaded on demand when it is first started, significantly reducing the Agent package size; OpenResty still reads MMDB from the disk path, and the Server control plane still only embeds Country MMDB (excluding City).

v3.4.4

Choose a tag to compare

@github-actions github-actions released this 06 Aug 07:53

杂务(发布):v3.4.4
chore(release): v3.4.4

新增

New

  • 新增全局源站错误页:可在「网站管理 → 错误页」配置开关、触发状态码(支持 500-599 区间与单码)与自定义 HTML;默认启用 OpenFlare 极简错误页并保持真实 HTTP 状态码,修改后随配置版本发布下发到边缘,关闭后恢复透传。
  • Added global origin site error page: You can configure switches, trigger status codes (supports 500-599 range and single code) and custom HTML in "Website Management → Error Page"; the OpenFlare minimalist error page is enabled by default and maintains the real HTTP status code. After modification, it will be distributed to the edge with the configuration version release, and transparent transmission will be restored after closing.
  • 新增 Cloudflare DNS 指向管理:可复用现有 Cloudflare DNS 账号或配置独立 Token,按分组将 ZoneDomain 的单条 A 记录异步同步到边缘节点 IPv4,并支持成员橙云、同步状态与节点 IP 变更联动。
  • Added Cloudflare DNS pointing management: you can reuse the existing Cloudflare DNS account or configure an independent Token, asynchronously synchronize a single A record of the ZoneDomain to the edge node IPv4 by group, and support linkage between member Orange Cloud, synchronization status and node IP changes.

修复

Fix

  • 修复 Agent 在配置已对齐但磁盘校验和不一致时,Pages 等对账成功后仍保留 LastError 的问题,避免偶发网络失败被健康事件长期显示为「活动中」且无法自动恢复。
  • Fixed the issue where LastError will remain in Pages after the reconciliation is successful when Agent configurations are aligned but disk checksums are inconsistent, to avoid occasional network failures being displayed as "Active" by health events for a long time and unable to automatically recover.

改进

Improvements

  • 删除、撤销与未保存离开等确认操作统一改用页面内 AlertDialog,不再使用浏览器原生 confirm 弹窗,交互风格与系统其余对话框保持一致。
  • Confirmation operations such as deletion, undo, and leaving without saving are all changed to the on-page AlertDialog instead of the browser's native confirm pop-up window. The interaction style is consistent with the rest of the system's dialog boxes.

v3.4.3

Choose a tag to compare

@github-actions github-actions released this 23 Jul 16:05

杂务(发布):v3.4.3
chore(release): v3.4.3

🛠 修复

🛠 Fix

  • 修复了 IP 组自动抓取使用预设规则时未写入 ttl 的问题,避免配置缺少封禁时长。
  • Fixed the issue where ttl was not written when using preset rules for IP group automatic capture to avoid missing ban duration in the configuration.
  • 修复了限流相关数据库迁移中的表名错误,确保升级脚本正确执行。
  • Fixed the table name error in current-limiting related database migration to ensure that the upgrade script is executed correctly.

⚡️ 优化与改进

⚡️ Optimization and improvement

  • 边缘缓存对齐 Cloudflare 默认模型:不再因登录 Cookie 等请求头一律跳过缓存,登录用户可命中静态资源;响应 Set-Cookie 不入库,并补充默认 Edge TTL。生效需重新发布节点配置。
  • Edge cache alignment Cloudflare default model: no longer skip cache due to request headers such as login cookies, logged in users can hit static resources; the response Set-Cookie is not stored in the library, and the default Edge TTL is supplemented. To take effect, the node configuration needs to be republished.
  • 新增全局与站点级单 IP 请求频率限制,触发时返回 429,并支持继承、关闭与按站点隔离。
  • Added global and site-level single IP request frequency limits, which will return 429 when triggered, and support inheritance, shutdown and per-site isolation.
  • IP 组自动规则支持 2xx/4xx/5xx 类状态码写法,同步间隔下限降至 1 分钟,回看窗口支持 60m/1h 等时长写法。
  • IP group automatic rules support 2xx/4xx/5xx status code writing, the lower limit of the synchronization interval is reduced to 1 minute, and the lookback window supports 60m/1h equal length writing.
  • 限流页请求压力图 RPS 纵轴按可见窗口峰值动态缩放,低流量更易读。
  • The RPS vertical axis of the current-limited page request pressure graph is dynamically scaled according to the peak value of the visible window, making it easier to read at low traffic rates.

💄 其他/体验

💄 Other/Experience

  • 补充边缘缓存运维与故障排查说明,并对「所有可缓存 GET」策略增加风险提示。
  • Supplemented edge cache operation and troubleshooting instructions, and added risk warnings for the "all cacheable GET" policy.