Adds an optional web dashboard served by OpenGFW itself, enabled with a new `web` section in the config file. Backend (web package, decoupled from engine/io so it builds on any OS): - hub.go collects statistics off the engine logger callbacks: atomic counters, two ring-buffered time series (10s and 1min buckets), top N hosts/blocked destinations/rules/analyzers, and a 512 entry event buffer fanned out to connected clients over SSE. Slow clients drop frames instead of blocking the engine. - api.go exposes /api/v1 for info, meta, metrics, events, the SSE stream and ruleset read/validate/replace. - auth.go implements password login with in-memory session tokens and login rate limiting. Mutating endpoints require the bearer token (the session cookie is only accepted for GET), which makes them CSRF-safe. - cmd/web.go implements the rule manager: rules are compiled before anything is written, the file is replaced atomically and the engine is hot reloaded. The SIGHUP handler now shares that same path. - web/devserver serves the UI with synthetic traffic for frontend work on machines where the engine itself cannot be built. Frontend (web/frontend, Vue 3 + Vite + Tailwind CSS v4 + Reka UI): dashboard, live event feed with analyzer property inspection, visual and YAML rule editors, analyzer overview and settings. Responsive down to phone sizes with a bottom tab bar and bottom-sheet dialogs, plus light/dark themes and English/Chinese translations. The built UI in web/dist is committed and embedded with go:embed so that `go build` works without Node; CI builds the frontend and checks that the committed output is up to date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
63 lines
3.4 KiB
Markdown
63 lines
3.4 KiB
Markdown
# 
|
|
|
|
[](https://github.com/apernet/OpenGFW/actions/workflows/check.yaml)
|
|
[![License][1]][2]
|
|
|
|
[1]: https://img.shields.io/badge/License-MPL_2.0-brightgreen.svg
|
|
[2]: LICENSE
|
|
|
|
OpenGFW は、あなた専用の DIY 中国のグレートファイアウォール (https://en.wikipedia.org/wiki/Great_Firewall) です。Linux 上で利用可能な柔軟で使いやすいオープンソースプログラムとして提供されています。なぜ権力者だけが楽しむのでしょうか?権力を人々に与え、検閲を民主化する時が来ました。自宅のルーターにサイバー主権のスリルをもたらし、プロのようにフィルタリングを始めましょう - あなたもビッグブラザーになることができます。
|
|
|
|
**ドキュメントウェブサイト: https://gfw.dev/**
|
|
|
|
Telegram グループ: https://t.me/OpGFW
|
|
|
|
> [!CAUTION]
|
|
> 本プロジェクトはまだ初期開発段階にあります。テスト時のリスクは自己責任でお願いします。私たちは、このプロジェクトを一緒に改善するために貢献者を探しています。
|
|
|
|
## 特徴
|
|
|
|
- フル IP/TCP 再アセンブル、各種プロトコルアナライザー
|
|
- HTTP、TLS、QUIC、DNS、SSH、SOCKS4/5、WireGuard、OpenVPN、その他多数
|
|
- Shadowsocks、VMess の「完全に暗号化されたトラフィック」の検出など (https://gfw.report/publications/usenixsecurity23/en/)
|
|
- Trojan プロキシプロトコルの検出
|
|
- [WIP] 機械学習に基づくトラフィック分類
|
|
- IPv4 と IPv6 をフルサポート
|
|
- フローベースのマルチコア負荷分散
|
|
- 接続オフロード
|
|
- [expr](https://github.com/expr-lang/expr) に基づく強力なルールエンジン
|
|
- ルールのホットリロード (`SIGHUP` を送信してリロード)
|
|
- 柔軟なアナライザ&モディファイアフレームワーク
|
|
- 拡張可能な IO 実装 (今のところ NFQueue のみ)
|
|
- リアルタイムのトラフィックダッシュボードとルールエディタを備えたウェブ UI
|
|
|
|
## ウェブ UI
|
|
|
|
OpenGFW にはオプションのウェブダッシュボードが同梱されています。リアルタイムのトラフィック統計、
|
|
アナライザのプロパティを含むイベントフィード、そしてルールを検証してホットリロードできるルールエディタが利用できます。
|
|
スマートフォンでもデスクトップでも使えるレスポンシブ対応です。
|
|
|
|
設定ファイルで有効にします:
|
|
|
|
```yaml
|
|
web:
|
|
enabled: true
|
|
listen: :8080
|
|
secret: パスワード # 空の場合は起動時にランダム生成されログに出力されます
|
|
# cert: /path/to/fullchain.pem
|
|
# key: /path/to/privkey.pem
|
|
```
|
|
|
|
UI はバイナリに埋め込まれているため、追加のファイルを配置する必要はありません。
|
|
パスワードを知る人はルールを変更できるため、信頼できるネットワークにのみ公開してください。
|
|
開発方法は [web/README.md](web/README.md) を参照してください。
|
|
|
|
## ユースケース
|
|
|
|
- 広告ブロック
|
|
- ペアレンタルコントロール
|
|
- マルウェア対策
|
|
- VPN/プロキシサービスの不正利用防止
|
|
- トラフィック分析(ログのみモード)
|
|
- 独裁的な野心を実現するのを助ける
|