Adds an optional web dashboard served by OpenGFW itself, enabled with a new `web` section in the config file. Backend (web package, decoupled from engine/io so it builds on any OS): - hub.go collects statistics off the engine logger callbacks: atomic counters, two ring-buffered time series (10s and 1min buckets), top N hosts/blocked destinations/rules/analyzers, and a 512 entry event buffer fanned out to connected clients over SSE. Slow clients drop frames instead of blocking the engine. - api.go exposes /api/v1 for info, meta, metrics, events, the SSE stream and ruleset read/validate/replace. - auth.go implements password login with in-memory session tokens and login rate limiting. Mutating endpoints require the bearer token (the session cookie is only accepted for GET), which makes them CSRF-safe. - cmd/web.go implements the rule manager: rules are compiled before anything is written, the file is replaced atomically and the engine is hot reloaded. The SIGHUP handler now shares that same path. - web/devserver serves the UI with synthetic traffic for frontend work on machines where the engine itself cannot be built. Frontend (web/frontend, Vue 3 + Vite + Tailwind CSS v4 + Reka UI): dashboard, live event feed with analyzer property inspection, visual and YAML rule editors, analyzer overview and settings. Responsive down to phone sizes with a bottom tab bar and bottom-sheet dialogs, plus light/dark themes and English/Chinese translations. The built UI in web/dist is committed and embedded with go:embed so that `go build` works without Node; CI builds the frontend and checks that the committed output is up to date. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
61 lines
2.3 KiB
Markdown
61 lines
2.3 KiB
Markdown
# 
|
|
|
|
[](https://github.com/apernet/OpenGFW/actions/workflows/check.yaml)
|
|
[![License][1]][2]
|
|
|
|
[1]: https://img.shields.io/badge/License-MPL_2.0-brightgreen.svg
|
|
[2]: LICENSE
|
|
|
|
OpenGFW 是一个 Linux 上灵活、易用、开源的 DIY [GFW](https://zh.wikipedia.org/wiki/%E9%98%B2%E7%81%AB%E9%95%BF%E5%9F%8E) 实现,并且在许多方面比真正的 GFW 更强大。为何让那些掌权者独享乐趣?是时候把权力归还给人民,人人有墙建了。立即安装可以部署在家用路由器上的网络主权 - 你也能是老大哥。
|
|
|
|
**文档网站: https://gfw.dev/**
|
|
|
|
Telegram 群组: https://t.me/OpGFW
|
|
|
|
> [!CAUTION]
|
|
> 本项目仍处于早期开发阶段。测试时自行承担风险。我们正在寻求贡献者一起完善本项目。
|
|
|
|
## 功能
|
|
|
|
- 完整的 IP/TCP 重组,各种协议解析器
|
|
- HTTP, TLS, QUIC, DNS, SSH, SOCKS4/5, WireGuard, OpenVPN, 更多协议正在开发中
|
|
- Shadowsocks, VMess 等 "全加密流量" 检测 (https://gfw.report/publications/usenixsecurity23/zh/)
|
|
- Trojan 协议检测
|
|
- [开发中] 基于机器学习的流量分类
|
|
- 同等支持 IPv4 和 IPv6
|
|
- 基于流的多核负载均衡
|
|
- 连接 offloading
|
|
- 基于 [expr](https://github.com/expr-lang/expr) 的强大规则引擎
|
|
- 规则可以热重载 (发送 `SIGHUP` 信号)
|
|
- 灵活的协议解析和修改框架
|
|
- 可扩展的 IO 实现 (目前只有 NFQueue)
|
|
- Web UI,包含实时流量面板与规则编辑器
|
|
|
|
## Web UI
|
|
|
|
OpenGFW 内置了一个可选的 Web 控制面板:实时流量统计、带解析器属性的实时事件流,以及可以校验并热加载规则的规则编辑器。
|
|
界面同时适配手机和桌面浏览器。
|
|
|
|
在配置文件中启用:
|
|
|
|
```yaml
|
|
web:
|
|
enabled: true
|
|
listen: :8080
|
|
secret: 你的密码 # 留空则启动时随机生成并打印到日志
|
|
# cert: /path/to/fullchain.pem
|
|
# key: /path/to/privkey.pem
|
|
```
|
|
|
|
前端已经打包进二进制文件,无需额外部署静态资源。请只在可信网络中开放该端口——拿到密码即可修改你的规则。
|
|
开发说明见 [web/README.md](web/README.md)。
|
|
|
|
## 使用场景
|
|
|
|
- 广告拦截
|
|
- 家长控制
|
|
- 恶意软件防护
|
|
- VPN/代理服务滥用防护
|
|
- 流量分析 (纯日志模式)
|
|
- 助你实现你的独裁野心
|