util

package
v1.7.1 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 20, 2026 License: GPL-3.0 Imports: 26 Imported by: 0

Documentation

Index

Constants

This section is empty.

Variables

View Source
var InboundTypeWithLink = []string{"socks", "http", "mixed", "shadowsocks", "naive", "hysteria", "hysteria2", "anytls", "tuic", "vless", "trojan", "vmess"}

Functions

func B64StrToByte

func B64StrToByte(str string) ([]byte, error)

func ByteToB64Str

func ByteToB64Str(b []byte) string

func CertIsSelfSigned added in v1.5.4

func CertIsSelfSigned(pemData string) bool

CertIsSelfSigned reports whether the leaf certificate in pemData is self-signed, i.e. its signature verifies against its own public key. Only self-signed certificates should be pinned via certificate_public_key_sha256; CA-signed certificates are validated normally.

func CertPEMFromTLS added in v1.5.4

func CertPEMFromTLS(tlsConfig map[string]interface{}) string

func CertPublicKeySha256 added in v1.5.4

func CertPublicKeySha256(pemData string) string

CertPublicKeySha256 returns the base64-encoded SHA256 of the certificate's SubjectPublicKeyInfo (sing-box `certificate_public_key_sha256` / link pinSHA256).

func CertSha256Hex added in v1.5.4

func CertSha256Hex(pemData string) string

CertSha256Hex returns the lowercase hex SHA256 of the whole certificate (DER), matching `openssl x509 -fingerprint -sha256` and Clash/mihomo's `fingerprint`.

func CheckPassword added in v1.5.4

func CheckPassword(plain, stored string) bool

func FillOutJson

func FillOutJson(i *model.Inbound, hostname string) error

Fill Inbound's out_json

func GenerateTOTPSecret added in v1.7.1

func GenerateTOTPSecret() (string, error)

GenerateTOTPSecret returns a fresh base32 shared secret.

func GetExternalLink(url string) string

func GetExternalSub

func GetExternalSub(url string) ([]map[string]interface{}, error)

func GetHeaders

func GetHeaders(client *model.Client, updateInterval int) []string

func GetOutbound

func GetOutbound(uri string, i int) (*map[string]interface{}, string, error)

func GetTlsPing added in v1.5.4

func GetTlsPing(domain string, port string) (any, error)

GetTlsPing performs a TLS handshake against domain:port (uTLS Chrome hello, no verification -- the point is to fetch whatever certificate is served) and returns the leaf certificate's SPKI SHA256 so the UI can show/pin it.

func HashPassword added in v1.5.4

func HashPassword(plain string) (string, error)

func IsHashedPassword added in v1.5.4

func IsHashedPassword(stored string) bool

func LinkGenerator

func LinkGenerator(clientConfig json.RawMessage, i *model.Inbound, hostname string, clientRemark string) []string

func ShadowsocksClientConfigKey added in v1.6.3

func ShadowsocksClientConfigKey(method string) string

ShadowsocksClientConfigKey returns the key a client's config blob stores its Shadowsocks secret under, for the given inbound method.

A client config only ever carries two of them (see the frontend's randomConfigs): "shadowsocks16" holds a 16-byte secret and "shadowsocks" a 32-byte one. 2022-blake3-aes-128-gcm is the only method deriving a 128-bit key, so it is the only one that reads the short secret. Everything else reads "shadowsocks" — including 2022-blake3-aes-256-gcm and -chacha20-poly1305, which need the full 32 bytes.

Upstream s-ui routes those two to a third key, "shadowsocks32", that no client config contains; the lookup then yields "" and the inbound ends up with an empty user list. Keep the two-key mapping.

func StrOrBase64Encoded

func StrOrBase64Encoded(str string) string

Function to return decoded bytes if a string is Base64 encoded

func StripServerTlsFields added in v1.5.7

func StripServerTlsFields(tls map[string]interface{}) bool

StripServerTlsFields removes server-only TLS fields from a client-facing TLS object in place and reports whether anything was removed.

func TOTPKeyURI added in v1.7.1

func TOTPKeyURI(secret, account, issuer string) string

TOTPKeyURI builds the otpauth:// URI the enrolment QR code encodes. issuer is repeated in the label as well as the parameter because that is what apps that predate the parameter read, and dropping it there makes every 2S-UI panel show up under the bare account name.

func ValidateTOTPAfter added in v1.7.1

func ValidateTOTPAfter(secret, code string, after int64) (int64, bool)

ValidateTOTPAfter validates a code and rejects replays: after is the counter the last accepted code matched, and anything at or below it is refused (RFC 6238 §5.2). A malformed secret fails closed. The returned counter is what the caller persists, so the same six digits cannot be replayed for the rest of their acceptance window -- which is up to 90 seconds here, long enough for a code read over someone's shoulder to be worth something on its own.

Types

type LinkParam

type LinkParam struct {
	Key   string
	Value string
}

Directories

Path Synopsis

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL