Commit Graph

117 Commits

Author SHA1 Message Date
0xJacky
ffc29affca feat(node): show authentication upgrade progress 2026-08-17 19:11:00 +08:00
0xJacky
7cbc4db8cf feat(cert): support disabling authoritative DNS propagation checks 2026-08-17 19:04:29 +08:00
VXNCXNX
2b053db38f fix(cluster): building the WebSocket URL rewrites every http in it 2026-08-16 09:45:00 +00:00
0xJacky
af2dc9aee9 fix(cluster): survive unsupported config names in a directory sync
An end-to-end run against a two node cluster surfaced two problems in the
synchronization added by 9f70d47.

A real Nginx configuration directory holds files the config validator rejects,
such as nginx.conf.bak.1738662518. The collector pushed them anyway and the
receiver aborted the whole batch on the first one, so a single stale backup
stopped every other file from being deployed. Names the receiver would reject
are now skipped while collecting, and the receiver reports a per-file failure
list instead of discarding the batch, keeping the reply an error only when
nothing could be applied at all. The caller turns a partially applied batch
into a failed result so a summary never claims a clean run.

sync_interval_minutes also advertised a minimum of one minute that the
omitempty rule never enforced. Zero is what the model already treats as "use
the default", so the rule now says so and rejects negatives instead.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 23:17:57 +08:00
Jacky
5784d4f389 feat(cli): add scoped remote management (#1771) 2026-07-30 22:19:14 +08:00
0xJacky
9f70d47b35 feat(cluster): unify multi-node configuration synchronization
Deployment to other nodes was file by file, manual, and always validated
against the local Nginx. One synchronization engine now backs every path.

- Directory deployment: a directory carries its own deployment targets and
  every file below it inherits them, so a whole tree replicates in one
  request per node (#1559).
- Node sync: one action pushes all configurations, sites and streams to the
  selected nodes, which is what a freshly added node needs (#1484).
- Namespace replication: the namespace record is mirrored to its member nodes
  and synced sites and streams carry the namespace name, so every node groups
  them identically (#1744).
- Automatic sync: a namespace can switch to the auto strategy with its own
  interval and a cron job re-pushes its content (#1582).
- deploy_mode=remote no longer touches the local Nginx: no sites-enabled
  symlink, no local nginx -t and no local reload. The deployment intent moves
  to the database, and moving a site into a remote namespace detaches its
  leftover local symlink (#1505).

The receiving side gains a batch config endpoint that writes every file and
reloads once, with a per-file fallback for nodes that predate it. Disabling a
site or stream became idempotent so converging a node reports no spurious
failures, renaming only tests and reloads when the enabled tree actually
changed, and stream delete now removes the stream record instead of a site one.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-30 18:07:34 +08:00
0xJacky
771cb9f820 feat: add unified health check control plane 2026-07-30 15:52:43 +08:00
0xJacky
9794228148 refactor(node): authenticate node traffic with HMAC instead of the plaintext secret
The shared node secret used to travel as an X-Node-Secret header on every
proxied request, so anyone able to observe a plain HTTP link between two
instances collected a reusable full-access credential. Requests from a node that
authenticates with the secret are now signed with an HMAC derived from it,
reusing the same signature envelope, covered components, clock skew and replay
cache as the paired Ed25519 path. The secret itself never leaves either end.

With the transport already proving knowledge of the secret, the upgrade to a
dedicated key pair no longer needs a proof of its own: /api/node/pair/upgrade
moves back behind the authentication middleware and keeps only the return
direction, where the target signs the credential it issues so the controller can
tell it reached the node holding the same secret before relying on it.

The node secret is therefore the single trust root, which makes the one-time
pairing code redundant: adopting a node means supplying its secret, and the
maintenance pass swaps the relationship onto a key pair on its own. Removing
that path also removes the last HTTPS requirement in the system. The node form
gains the Node Secret field it never exposed, without which no node could be
added from the UI at all.

The LegacyAuthEnabled and LegacyMCPAuthEnabled switches are gone as well. They
existed to tell an upgraded installation from a fresh one, which is not a
distinction this migration needs anymore.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
2026-07-29 13:40:26 +08:00
0xJacky
0ecbd106c3 feat: automate node credential lifecycle 2026-07-28 17:11:09 +08:00
0xJacky
a3999bd78a feat: add signed node authentication 2026-07-28 15:44:33 +08:00
0xJacky
5b80ae7e30 fix(cert): adapt short-lived renewal and alerts 2026-07-28 09:32:45 +08:00
0xJacky
30297feaa7 fix(cert): use certificate identifier as name 2026-07-28 00:00:19 +08:00
0xJacky
53413d51ad feat(cert): support ACME IP certificates 2026-07-27 20:43:14 +08:00
0xJacky
e0cbc1ee38 feat(site): support multiple DNS record links 2026-07-27 15:21:47 +08:00
milkfish
2cb7ee9102 fix(model): remove gorm default:true from UpstreamConfig.Enabled (#1758) 2026-07-23 19:28:38 +08:00
0xJacky
f92218e010 fix: harden auto backup filenames 2026-07-15 20:17:09 +08:00
0xJacky
30aeb2716a fix: support ACME common name option 2026-07-07 14:42:59 +08:00
Mr-Robot-ops
f40e57cea5 Add certificate import CLI and discovery UI (#1716)
* Add certificate import discovery workflow

* Add certificate discovery translations

* Guard imported certificate file paths

* Address certificate discovery review feedback

* Add certificate discovery review tests
2026-06-23 18:31:16 +08:00
Jacky
69cfa82b1d feat: self-signed certificate support (#1655) (#1688)
* feat(cert): add self-signed certificate type and config to model

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): generate self-signed leaf certificates

Add GenerateSelfSigned / SelfSignedOptions plus five new error codes
(50032-50036) and a full TDD test suite covering valid cert output,
multiple key types, empty-SAN rejection, and invalid-IP rejection.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): regenerate self-signed certificates with key reuse

Add RegenerateSelfSigned, SelfSignedOptionsFromModel, deriveSelfSignedCommonName,
loadSelfSignedKey, and parsePrivateKeyPEM to support re-issuing self-signed
certificates for the auto-renewal job, reusing the on-disk private key when possible.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): add self-signed certificate renewal worker

Add auto-renewal worker for self-signed certificates that mirrors the
ACME renewal logic, using a dedicated shouldRenewSelfSignedCert threshold
function verified with TDD.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cron): schedule self-signed certificate renewal

Register setupSelfSignedCertRenewalJob as a periodic cron job (every
30 minutes) in InitCronJobs, mirroring the existing setupAutoCertJob
pattern.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(api): add self-signed certificate generation endpoints

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): add self-signed certificate frontend API

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): add shared self-signed certificate fields component

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): add self-signed certificate generation modal and list entry

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): support self-signed certificates in the editor

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(site): generate self-signed certificates from the site editor

Extract hasTLSListen/ensureDirective/ensureTLSDirectives into a shared
useTLSDirectives composable, refactor ObtainCert.vue to use it, and add
SelfSignedCert.vue to the site cert tab so users can generate and apply
a self-signed certificate directly from the site editor.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cert): validate self-signed key type and name IP-only renewals

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(cert): apply code-review cleanup

- reuse certcrypto.ParsePEMPrivateKey instead of a hand-rolled PEM
  private-key parser
- stop exporting the unused ensureDirective from useTLSDirectives
- use the AutoCertState enum instead of integer literals in certColumns
- allocate the renewal Logger only when renewal is attempted, avoiding a
  per-tick goroutine and empty-log database write for non-due certificates

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cert): address PR #1688 review feedback

- clean up the partial certificate directory when the initial write
  fails, not just the database row
- log a warning when the existing self-signed private key cannot be
  reused so operators notice the public-key fingerprint has changed
- defensively copy the model's Domains and IPAddresses slices in
  SelfSignedOptionsFromModel
- require an explicit "Save now" confirmation after generating from the
  site editor, and write the directives into the editor first so the
  user can review the diff before saving

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cert): harden self-signed certificate lifecycle

Reuse private keys on manual self-signed edits, make certificate writes safer, clean managed self-signed files on delete, and guard renewal against missing config.

* fix(cert): harden self-signed frontend handling

Avoid undefined certificate redirects, rely on payload defaults for self-signed fields, and parse TLS listen directives precisely.

* fix(site): satisfy strict listen regex lint

Escape the IPv6 listen closing bracket explicitly so the strict regexp lint rule accepts TLS listen parsing.

* fix(cert): harden self-signed key handling

Co-authored-by: Jacky <me@jackyu.cn>

* docs(cert): design merging self-signed entry into issue dialog

Spec for collapsing the Certificate list header from three actions to
two by adding a Self-signed option inside the existing Issue Certificate
dialog.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cert): plan merging self-signed into issue dialog

Step-by-step plan that turns the spec into two scoped commits:
extend DNSIssueCertificate with a self-signed type, then drop the
standalone header button from the certificate list view.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): add self-signed option in issue certificate dialog

Extend the Issue Certificate dialog's Certificate Type select with a
"Self-signed" option that swaps the form body to SelfSignedCertFields
and routes submission through cert.generate_self_signed(). ACME paths
(Wildcard / Custom Domains) are unchanged.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(cert): drop standalone self-signed button from list header

Certificate creation is now consolidated under the Issue Certificate
dialog (which exposes Self-signed as a Certificate Type option), so
the duplicate header entry, its ref, handler, and modal mount are
removed.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cert): design self-signed UX enhancements

Adds a reusable StringListInput, renewal-policy hint in the self-signed
form, and a required Name field (frontend + backend). Builds on the
prior merge spec.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* docs(cert): plan self-signed UX enhancements

Six-task plan: extract StringListInput, require Name backend + test,
refactor SelfSignedCertFields with renewal hint, hide duplicate alert
in editor, seed/filter payloads with Name validation, and adopt
StringListInput in the ACME Custom Domains branch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(ui): add StringListInput component

Reusable multi-row text input with Add/Remove buttons. Used in the
upcoming refactor of Custom Domains and self-signed Domains / IP
Addresses editors so all three share a single editor pattern.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(ui): simplify StringListInput model write and add a11y label

Replace the captured-index update closure with v-model:value on
items[index] so input events are guaranteed to write to the array
slot currently bound to the DOM input. Add an aria-label suffix
on the Remove button so screen readers can distinguish rows.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): require Name when generating self-signed certificates

Adds binding:"required" to SelfSignedCertRequest.Name so an empty name
is rejected at the request boundary, and covers the contract with a
new API-level test.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): unify self-signed editor and surface renewal hint

Switch Domains and IP Addresses to the shared StringListInput so all
self-signed field editors match the Custom Domains pattern. Add an
auto-renewal hint (suppressible via hideRenewalNote) and mark Name as
required to match the new backend contract.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(cert): suppress duplicate renewal alert in cert editor

SelfSignedCertManagement already has its own renewal-status alert;
pass hide-renewal-note to SelfSignedCertFields to avoid showing two
adjacent alerts saying the same thing.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* feat(cert): seed and filter self-signed payloads, validate Name

StringListInput preserves empty placeholder rows for editing; seed
arrays with [''] in toSelfSignedPayload / emptySelfSignedPayload /
emptyForm so the editor always renders an empty row to type into.

Each submit/save path trims and filters the arrays before sending and
now rejects an empty Name client-side to match the new server contract.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(cert): make SelfSignedCertPayload.name required

Every factory already seeds name as ''; the optional marker forced
defensive (name ?? '').trim() at three call sites. Align the type
with reality.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* refactor(cert): use StringListInput for Custom Domains

Drop the inline multi-row template + add/remove helpers in favour of
the shared StringListInput component, matching the editor used by the
self-signed branch.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore(ui): regenerate components.d.ts for StringListInput

Auto-generated by unplugin-vue-components after the new component
was added under app/src/components/StringListInput/.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* fix(cert): render key_type for both legacy and canonical forms

The backend's helper.GetKeyType normalizes key_type to its canonical
form (EC256, RSA2048…) on every write — self-signed generation as well
as the ModifyCert BeforeExecuteHook. The frontend PrivateKeyTypeMask
was keyed only by the legacy form (P256, 2048…), so maskRender returned
"/" for every cert that took a write path through normalization.

Two reported symptoms with the same root cause:
- New self-signed cert always shows "/" in the Key Type column
- Editing any ACME cert (issue #1697) flips its column to "/" after save

Add formatPrivateKeyType / normalizePrivateKeyType helpers that map both
forms to the frontend's legacy key. Use them in the list column renderer
and when loading certs into the self-signed and ACME editor forms so the
ASelect highlights the correct option.

Fixes #1697.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* style(cert): cap self-signed fields width at 600px

The fields stretched full-width inside the certificate editor page; cap
the form at 600px to match AutoCertManagement and keep the editing area
readable. Modal consumers were already bounded by their own width, so
the change is invisible there.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>

* chore: update translations

---------

Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Hintay <hintay@me.com>
2026-05-24 09:22:21 +08:00
Hintay
8a787e2485 feat(dns): support IP version selection for DDNS (#1695)
* feat(dns): support IP version selection for DDNS

- Add ip_version setting (ipv4 / ipv6 / ipv4_ipv6 / ipv6_ipv4 /
  both_required) persisted on DDNSConfig and exposed via the API
- Validate target record types against the selected version and reject
  inconsistent combinations on save
- Probe public IPv4 and IPv6 endpoints concurrently so a stalled family
  no longer eats the shared timeout budget
- Atomically create A/AAAA records when adding missing names and roll
  back partial successes on failure
- Surface per-family resolution warnings instead of failing the whole
  tick when at least one family resolves
- Frontend exposes an IP version selector and filters record options to
  the families allowed by the active selection

* fix(dns): preserve DDNS missing record creation

Co-authored-by: Jacky <me@jackyu.cn>

* fix(dns): restore best-effort dual-stack semantics in record creation

Two fixes after reviewing a cursor agent commit that introduced
regressions:

- DDNSManager.vue: revert mode="tags" back to mode="multiple" and
  drop the now-dead findSelectedRecordType helper. The placeholder
  text is also updated to remove the misleading "Type or" prefix
  since multiple-mode does not allow free input.
- createDDNSRecordsForMissingName: revert the unified "create whatever
  family is available" behaviour. best-effort modes (ipv4_ipv6 /
  ipv6_ipv4) again create only the first available family in policy
  order; both_required keeps creating both atomically.

* refactor(dns): remove both_required DDNS mode

The "all-or-nothing" runtime semantic of both_required conflicts with the
user-accessibility goal of the upcoming sibling cleanup logic, and the
mode itself overlaps with dual-stack best-effort once cleanup exists.
Remove the constant, policy case, validation function, runtime
short-circuit, and error code.

* test(dns): drop both_required test coverage

* feat(dns/ui): drop both_required option from DDNS mode select

* feat(dns): persist cleanup flag and family failure timestamps

Add CleanupConflictingRecords (default true), IPv4FailedSince, and
IPv6FailedSince to model.DDNSConfig and the request/response DTOs.
toDDNSResponse seeds CleanupConflictingRecords=true for unconfigured
domains so the frontend form starts in the desired default state.
The new fields are wired through but no behavior changes yet.

* feat(dns): add isDualStackMode helper

* refactor(dns): silently skip records outside policy during save

UI filters records to the active IP version policy, so an explicit
mismatch error only fires for stale form state or direct API misuse.
Silent skip is more graceful and lets the existing empty-targets
check surface the real failure mode (ErrDDNSTargetRequired).

* feat(dns): auto-pair existing sibling records on save (dual-stack, flag on)

* feat(dns): auto-create missing sibling records on save (dual-stack, flag on)

* feat(dns): delete records of unreachable families on save

When dual-stack mode is active and CleanupConflictingRecords is on,
sibling records at managed names whose family is currently unreachable
get deleted from the provider. The handler returns the deleted-record
list so the frontend can surface a confirmation toast.

* test(dns): cover flag-off and single-stack save-time behavior

* feat(dns): track per-family IP detection failure timestamps

* feat(dns): evict targets of persistently failed families

Dual-stack DDNS configs with CleanupConflictingRecords enabled now
delete records of any family whose public IP has been undetectable for
longer than ddnsFamilyFailureGrace (default 1 hour). Single-stack
modes and the flag-off path skip this branch entirely.

* test(dns): cover runtime no-eviction and delete-failure retry paths

* feat(dns/ui): add cleanup conflicting records toggle (dual-stack only)

* feat(dns/ui): notify users of unmanaged sibling records in single-stack modes

* feat(dns/ui): toast when conflicting records are removed on save

* style(dns/ui): fix indent-binary-ops lint warning

* fix(dns): refuse save when no public IP detected (dual-stack cleanup mode)

Previously the §6.3 completion phase would happily delete every existing
sibling record of unreachable families even when neither family was
detected, leaving cfg.Targets empty and the domain at NXDOMAIN. Now we
short-circuit with ErrDDNSIPUnavailable before running §6.3, preserving
the user's DNS state until they recover connectivity.

* fix(dns): delete in-target records when family IP becomes unreachable

The §6.3 completion phase short-circuited on containsTargetForName
before checking whether the family's IP was still reachable. That meant
a user-selected A record at "home" survived a save under ipv4_ipv6 +
cleanup-on even when IPv4 stopped resolving, contradicting the
Appendix A "✗ / ✓ / on" row of the design spec.

Move the in-targets check inside the IP-detected branch so the
IP-undetected branch can still delete the stale record and pull it
out of targets. Adds tests covering the cross-family pivot plus the
previously-missing spec §10.2 cases (#4, #7, #11, #12, #13).

* fix(dns): persist cleanup flag and preserve failure timestamps on save

UpdateDDNSConfigWithDetails was constructing the new cfg without
carrying CleanupConflictingRecords from the input and without
preserving IPv4FailedSince / IPv6FailedSince from the existing
config. The former meant runtime eviction never triggered in
production (the cfg was always persisted with the flag at zero
value); the latter meant every save reset the family failure
grace timer to nil, indefinitely delaying eviction.

Both gaps slipped through the test matrix because no test
reloaded the cfg from the database after save. Add round-trip
regression tests for both fields plus the new GetDDNSConfig
default alignment.

Also surface delete-record provider failures via a dedicated
ErrDDNSRecordDeleteFailed code so users can distinguish them
from genuine "record not found" cases.

* fix(dns): use standard RFC3339 time format

Co-authored-by: Jacky <me@jackyu.cn>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Jacky <me@jackyu.cn>
2026-05-23 20:46:00 +08:00
Hintay
013634e8ca feat(cert): preserve config and add retry on issuance failure (#1694)
* feat(cert): add Status, LastError, LastAttemptAt fields

* feat(cert): sweep stale pending certs at startup

* feat(cert): invoke SweepStalePending at cron startup

* feat(cert): skip non-success status in auto-renew worker

* feat(cert): persist draft on issuance entry, status transitions on completion

* feat(cert): expose status, last_error, last_attempt_at on Cert type

* feat(cert): show Pending/Failed status badges in cert list

* feat(cert): add RetryCert component and wire into list actions

* feat(cert): inline Retry button on issuance error in wildcard modal

* chore(cert): minor cleanups after retry-on-failure review

- Remove unused model.FirstOrInit helper (last caller was rewritten in the issuance handler change).
- Normalize cleanup_test setupTestDB DSN to ":memory:" for per-test isolation, matching issue_test.go.
- Reset errored state in DNSIssueCertificate.open() as a defensive guard against stale state on modal reopen.

* refactor(cert): extract IssueCertModal wrapper shared by Renew and Retry

Both RenewCert.vue and RetryCert.vue carried near-identical AModal +
ObtainCertLive scaffolding (modalVisible/modalClosable refs, template ref,
modal props). Lift the shared shell into IssueCertModal.vue and expose a
single start() method returning Promise<CertificateResult>. The trigger
components now own only the parts that actually differ: button styling,
emit name, pre-issuance hook (certStore.save for Renew), and success toast.

* chore(cert): fix small bugs with review

- shortError now truncates by rune count instead of bytes, so non-ASCII
  error messages (e.g. localized ACME / DNS provider errors) cannot be
  split mid-rune. TestShortError gains a CJK case asserting valid UTF-8.
- Cert.last_attempt_at is typed string | null on the frontend to reflect
  that the *time.Time pointer serializes as null for legacy / pre-attempt
  rows.
- Drop redundant ?. on refModal / refObtainCertLive in the three click
  handlers. The refs are bound to components rendered alongside their
  trigger button, so they are guaranteed to be mounted by the time the
  handler fires.

* fix(cert): guard certificate issuance ref before retry

Co-authored-by: Jacky <me@jackyu.cn>

---------

Co-authored-by: Cursor Agent <cursoragent@cursor.com>
Co-authored-by: Jacky <me@jackyu.cn>
2026-05-23 20:34:52 +08:00
Hintay
10867218d4 feat: migrate legacy recovery codes (#1684) 2026-05-21 16:31:41 +08:00
0xJacky
6859e18d4b fix(cert): migrate ACME client to lego v5 2026-05-13 08:38:20 +08:00
0xJacky
3f04b3e776 fix(cert): normalize legacy key types 2026-05-12 14:52:25 +00:00
0xJacky
899c9f1995 fix(cert): throttle auto-renew retries and expose renewal errors 2026-04-20 23:19:50 +08:00
0xJacky
95ab34bbe1 feat: implement migration to encrypt sensitive JSON fields in database models 2026-03-16 11:34:10 +08:00
Nemer Y Tamimi
93b10d7759 feat: Integrate DNS record management into site configuration (#1519)
* feat: Integrate DNS record management into site configuration

- Removed the 'External Notification Test' notification.
- Enhanced SiteAdd.vue to include DNS record integration, allowing users to select or create DNS records linked to the site.
- Added DNSRecordIntegration component for managing DNS records, including selection and creation of new records.
- Implemented DNS linking functionality in the RightPanel component, enabling users to link existing DNS records to their site configuration.
- Updated SiteEditor to provide DNS link status to child components.
- Extended the site model to include fields for linked DNS domain and record information.
- Added logic to handle DNS record recreation if a linked record is missing.

* fix: remove unnecessary type assertion for selectedDomainId and selectedRecordId

* feat: add computed properties for selectedDomainId and selectedRecordId to handle null values

* refactor: simplify setter syntax for computed properties of selectedDomainId and selectedRecordId

* fix: update computed properties to return undefined for null values in selectedDomainId and selectedRecordId

---------

Co-authored-by: Nemer Tamimi <nemer.tamimi@uopeople.edu>
2026-01-14 13:35:03 +08:00
0xJacky
cb1fb691af refactor: improve provider selection logic in DNSChallenge component and update column definition in ACMEUser view 2025-12-09 17:35:47 +08:00
Jacky
9225c96250 feat/dns (#1466)
* feat: dns management

* refactor(dns): streamline domain management functions and enhance validation

* feat(dns): add value suggestions for DNS record input with autocomplete functionality

* fix(dns): handle edge case in record listing pagination

* fix(dns): update credential property name for consistency and add cleanup on component unmount

* feat(dns): implement DDNS management #1194, #1140
2025-12-08 17:45:30 +08:00
0xJacky
cfb6cae78a refactor: add config to disable site health check #1427, #1415, #1413 2025-11-09 09:41:33 +00:00
0xJacky
e71293cd76 feat: add deploy_mode field to namespace and implement sandbox testing for nginx config #1350 2025-10-04 04:51:23 +00:00
0xJacky
de0467b9e7 feat: allow disabling proxy targets availability test #1327 2025-10-03 13:51:12 +00:00
0xJacky
1626c6117b perf: optimize indexer config for multi-core systems 2025-09-08 09:36:07 +08:00
0xJacky
c355cb8e65 feat: add llm sessions and update related logic 2025-09-02 08:01:09 +00:00
0xJacky
a982c04898 enhance: llm and code completion 2025-09-01 10:52:43 +08:00
0xJacky
1f478a2cac perf(nginx_log): improve indexer throughput 2025-08-31 10:14:57 +08:00
0xJacky
8d15d1fcab enhance(nginx_log): indexing status management 2025-08-31 08:25:51 +08:00
0xJacky
fc968a3b39 refactor(nginx-log): optimized parser, indexer, searcher and analyzer 2025-08-25 16:21:29 +08:00
0xJacky
0ff4a6e4ed refactor: nginx log with indexer parse and search 2025-08-19 23:01:12 +08:00
0xJacky
e2b66fd8dd feat(dashboard): add sites navigation #1054 2025-08-14 11:04:49 +08:00
0xJacky
261c76686e refactor: rename env to node, env group to namespace 2025-08-13 10:50:37 +08:00
0xJacky
5ea20871c9 feat(external_notify): add WeCom supports 2025-08-03 11:43:45 +08:00
0xJacky
38ee12f587 feat: add EAB supports for ACME user register #1255 2025-08-02 21:18:32 +08:00
0xJacky
152569a2e7 feat(env_group): add upstream test type: local, remote, mirror 2025-07-29 16:18:54 +08:00
Jacky
06570b51db refactor:(cert) migrate domains to json array 2025-07-06 09:38:08 +08:00
Jacky
544d2badec refactor: add bleve search integration and enhance config list #1207 2025-07-05 20:37:28 +08:00
Jacky
a3f8f90668 feat(auth): implement short token for user authentication and update related login responses 2025-07-03 10:10:05 +00:00
Jacky
1dbb852a57 feat(user): persists prefer language in db #1155 2025-06-23 07:31:15 +00:00
Jacky
3cc3c573bc fix(backup): update backup type handling and improve naming conventions for auto backup 2025-05-28 06:04:02 +00:00
Jacky
8a9d0d7e44 fix(backup): change backup route from POST to GET and update name retrieval method in auto backup 2025-05-28 04:11:21 +00:00