diff --git a/CHANGELOG.md b/CHANGELOG.md index ac9aa7f..c65a0fd 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,7 @@ * 新增服务器定时任务功能(TODO * 连接服务器下拉菜单分组展示(TODO * 增加升级更新内容展示(TODO +* 面板支持灵活配置IP白名单 ## [3.0.4](https://github.com/chaos-zhu/easynode/releases) (2025-03-15) diff --git a/README.md b/README.md index b2f8017..40be5ea 100644 --- a/README.md +++ b/README.md @@ -67,7 +67,7 @@ docker run -d -p 8082:8082 --restart=always -v /root/easynode/db:/easynode/app/d ``` 环境变量: - `DEBUG`: 启动debug日志 0:关闭 1:开启, 默认关闭 -- `ALLOWED_IPS`: 可以访问服务的IP白名单, 多个使用逗号分隔, 支持填写部分ip前缀, 例如: `-e ALLOWED_IPS=127.0.0.1,196.168` +- `ALLOWED_IPS`: 可以访问服务的IP白名单, 多个使用逗号分隔, 支持填写部分ip前缀,支持在面板设置。例如: `-e ALLOWED_IPS=127.0.0.1,196.168` ## 监控服务安装 diff --git a/server/app/controller/log.js b/server/app/controller/log.js index a84ea49..198415e 100644 --- a/server/app/controller/log.js +++ b/server/app/controller/log.js @@ -1,17 +1,27 @@ -const { LogDB } = require('../utils/db-class') +const { KeyDB, LogDB } = require('../utils/db-class') +const keyDB = new KeyDB().getInstance() const logDB = new LogDB().getInstance() -let whiteList = process.env.ALLOWED_IPS ? process.env.ALLOWED_IPS.split(',') : [] - async function getLog({ res }) { let list = await logDB.findAsync({}) + let { ipWhiteList } = await keyDB.findOneAsync({}) list = list.map(item => { return { ...item, id: item._id } }) list?.sort((a, b) => Number(b.date) - Number(a.date)) - res.success({ data: { list, whiteList } }) + res.success({ data: { list, ipWhiteList } }) +} + +const saveIpWhiteList = async ({ res, request }) => { + const { body: { ipWhiteList } } = request + console.log('ipWhiteList:', ipWhiteList) + if (!Array.isArray(ipWhiteList)) return res.fail({ msg: 'ip list输入非法' }) + let { _id } = await keyDB.findOneAsync({}) + await keyDB.updateAsync({ _id }, { $set: { ipWhiteList } }) + res.success({ msg: 'success' }) } module.exports = { - getLog + getLog, + saveIpWhiteList } diff --git a/server/app/db.js b/server/app/db.js index 29501dc..bff1912 100644 --- a/server/app/db.js +++ b/server/app/db.js @@ -5,8 +5,18 @@ const { KeyDB, GroupDB, NotifyDB, NotifyConfigDB, ScriptGroupDB } = require('./u async function initKeyDB() { const keyDB = new KeyDB().getInstance() - let count = await keyDB.countAsync({}) - if (count !== 0) return consola.info('公私钥已存在[重新生成会导致已保存的ssh密钥信息失效]') + let keyData = await keyDB.findOneAsync({}) + if (keyData?.user) { + const { _id, ipWhiteList } = keyData + let allowedIPs = process.env.ALLOWED_IPS ? process.env.ALLOWED_IPS.split(',') : [] + if (allowedIPs.length > 0) { + consola.info('[存在白名单IP环境变量,合并到本地数据库中]') + allowedIPs = [...new Set([...ipWhiteList, ...allowedIPs])].filter(item => item) + await keyDB.updateAsync({ _id }, { $set: { ipWhiteList: allowedIPs } }) + } + consola.info('公私钥已存在[重新生成会导致已保存的ssh密钥信息失效]') + return + } let newConfig = { user: 'admin', pwd: 'admin', diff --git a/server/app/router/routes.js b/server/app/router/routes.js index 075daf5..8e32a72 100644 --- a/server/app/router/routes.js +++ b/server/app/router/routes.js @@ -6,7 +6,7 @@ const { getGroupList, addGroupList, updateGroupList, removeGroup } = require('.. const { getScriptList, getLocalScriptList, addScript, updateScriptList, removeScript, batchRemoveScript, importScript } = require('../controller/scripts') const { getScriptGroupList, addScriptGroup, removeScriptGroup, updateScriptGroup } = require('../controller/script-group') const { getOnekeyRecord, removeOnekeyRecord } = require('../controller/onekey') -const { getLog } = require('../controller/log') +const { getLog, saveIpWhiteList } = require('../controller/log') const ssh = [ { @@ -259,6 +259,11 @@ const log = [ method: 'get', path: '/log', controller: getLog + }, + { + method: 'post', + path: '/ip-white-list', + controller: saveIpWhiteList } ] module.exports = [].concat(ssh, host, user, notify, group, scripts, scriptGroup, onekey, log) diff --git a/web/src/api/index.js b/web/src/api/index.js index 1a07db8..83037cd 100644 --- a/web/src/api/index.js +++ b/web/src/api/index.js @@ -58,6 +58,9 @@ export default { getLoginRecord() { return axios({ url: '/log', method: 'get' }) }, + saveIpWhiteList(data) { + return axios({ url: '/ip-white-list', method: 'post', data }) + }, updatePwd(data) { return axios({ url: '/pwd', method: 'put', data }) }, diff --git a/web/src/views/setting/components/record.vue b/web/src/views/setting/components/record.vue index cca1729..09212a2 100644 --- a/web/src/views/setting/components/record.vue +++ b/web/src/views/setting/components/record.vue @@ -1,15 +1,21 @@