feat: add embedded web UI
Adds an optional web dashboard served by OpenGFW itself, enabled with a new `web` section in the config file. Backend (web package, decoupled from engine/io so it builds on any OS): - hub.go collects statistics off the engine logger callbacks: atomic counters, two ring-buffered time series (10s and 1min buckets), top N hosts/blocked destinations/rules/analyzers, and a 512 entry event buffer fanned out to connected clients over SSE. Slow clients drop frames instead of blocking the engine. - api.go exposes /api/v1 for info, meta, metrics, events, the SSE stream and ruleset read/validate/replace. - auth.go implements password login with in-memory session tokens and login rate limiting. Mutating endpoints require the bearer token (the session cookie is only accepted for GET), which makes them CSRF-safe. - cmd/web.go implements the rule manager: rules are compiled before anything is written, the file is replaced atomically and the engine is hot reloaded. The SIGHUP handler now shares that same path. - web/devserver serves the UI with synthetic traffic for frontend work on machines where the engine itself cannot be built. Frontend (web/frontend, Vue 3 + Vite + Tailwind CSS v4 + Reka UI): dashboard, live event feed with analyzer property inspection, visual and YAML rule editors, analyzer overview and settings. Responsive down to phone sizes with a bottom tab bar and bottom-sheet dialogs, plus light/dark themes and English/Chinese translations. The built UI in web/dist is committed and embedded with go:embed so that `go build` works without Node; CI builds the frontend and checks that the committed output is up to date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
+22
-1
@@ -29,7 +29,28 @@ Telegram グループ: https://t.me/OpGFW
|
||||
- ルールのホットリロード (`SIGHUP` を送信してリロード)
|
||||
- 柔軟なアナライザ&モディファイアフレームワーク
|
||||
- 拡張可能な IO 実装 (今のところ NFQueue のみ)
|
||||
- [WIP] ウェブ UI
|
||||
- リアルタイムのトラフィックダッシュボードとルールエディタを備えたウェブ UI
|
||||
|
||||
## ウェブ UI
|
||||
|
||||
OpenGFW にはオプションのウェブダッシュボードが同梱されています。リアルタイムのトラフィック統計、
|
||||
アナライザのプロパティを含むイベントフィード、そしてルールを検証してホットリロードできるルールエディタが利用できます。
|
||||
スマートフォンでもデスクトップでも使えるレスポンシブ対応です。
|
||||
|
||||
設定ファイルで有効にします:
|
||||
|
||||
```yaml
|
||||
web:
|
||||
enabled: true
|
||||
listen: :8080
|
||||
secret: パスワード # 空の場合は起動時にランダム生成されログに出力されます
|
||||
# cert: /path/to/fullchain.pem
|
||||
# key: /path/to/privkey.pem
|
||||
```
|
||||
|
||||
UI はバイナリに埋め込まれているため、追加のファイルを配置する必要はありません。
|
||||
パスワードを知る人はルールを変更できるため、信頼できるネットワークにのみ公開してください。
|
||||
開発方法は [web/README.md](web/README.md) を参照してください。
|
||||
|
||||
## ユースケース
|
||||
|
||||
|
||||
Reference in New Issue
Block a user