🔧 v3.6.0-lucx.125 — в подписке больше не появляется чужой адрес
Если панель стоит за nginx, в ссылках и подписках мог оказаться IP самого
подписчика вместо вашего домена. Заметнее всего это на AmneziaWG: в
Clash-профиле server: вёл на роутер клиента, и пинг до ноды, разумеется, не
проходил.
Почему страдал только AWG
У VLESS/Reality/WS адрес обычно берётся раньше — из host-записи, listen или
share-адреса инбаунда. У AWG-инбаунда своего адреса нет, поэтому панель
доходила до последнего звена цепочки — хоста запроса, а там лежал заголовок
X-Real-IP, то есть адрес того, кто скачал подписку.
Что изменилось
- 🔘 Адрес чинится сразу везде:
/sub/,/json/,/clash/,/awg/, а также
ссылки и QR-коды в самой панели (туда утекал IP администратора). - 🔘
X-Real-IPбольше не участвует в выборе адреса — толькоHostи
X-Forwarded-Hostот доверенного прокси. Этот заголовок отвечает на вопрос
«кто пришёл», а не «куда подключаться». - 🔘 В
lucx.90дыру закрыли только для.confиvpn://— теперь закрыта
целиком. - 📘 Новый раздел в документации (RU/EN/FA): в каком порядке выбирается адрес
для ссылок и что делать, если он неправильный.
⚠️ В блоке nginx оставьте proxy_set_header Host $host; — генератор конфига из
документации его ставит.
Не готовы обновляться прямо сейчас? Задайте Sub Domain или Web
Domain в настройках панели либо пропишите инбаунду явный share-адрес —
цепочка возьмёт их раньше хоста запроса.
Проверить, течёт ли ваша панель:
curl -s -H 'X-Real-IP: 203.0.113.77' https://ваш-домен/clash/<subId> | grep -B2 'type: wireguard'Появился 203.0.113.77 в server: — обновляйтесь.
Обновление: x-ui update или кнопка в панели. Миграций данных нет,
инбаунды и выданные конфиги не трогаются.
Спасибо Aleksandr SacredX за репорт — второй раз по этой же теме, и в этот раз
до самого корня. 🫡
⚡️ Приятного использования!
🔧 v3.6.0-lucx.125 — no more stranger's address in your subscription
With the panel behind nginx, links and subscriptions could carry the
subscriber's own IP instead of your domain. Most visible on AmneziaWG: the
Clash profile's server: pointed at the client's own router, so nothing could
ever connect.
Why only AWG was hit
VLESS/Reality/WS inbounds usually get their address earlier — from a host row,
listen, or an explicit share address. An AWG inbound has no address of its
own, so the panel fell through to the last link in the chain — the request
host — and that was taken from the X-Real-IP header, i.e. whoever fetched the
subscription.
What changed
- 🔘 Fixed everywhere at once:
/sub/,/json/,/clash/,/awg/, plus the
links and QR codes inside the panel itself (those leaked the admin's IP). - 🔘
X-Real-IPno longer takes part in picking the address — onlyHostand
X-Forwarded-Hostfrom a trusted proxy. That header answers "who came in",
not "where to connect". - 🔘
lucx.90only plugged this for.confandvpn://— now it's plugged
for good. - 📘 New docs section (RU/EN/FA): the order the link address is resolved in,
and what to do when it's wrong.
⚠️ Keep proxy_set_header Host $host; in your nginx block — the config
generator in the docs emits it.
Not upgrading right now? Set Sub Domain or Web Domain in panel
settings, or give the inbound an explicit share address — both are picked
before the request host.
Check whether your panel leaks:
curl -s -H 'X-Real-IP: 203.0.113.77' https://your-domain/clash/<subId> | grep -B2 'type: wireguard'If 203.0.113.77 shows up in server: — time to upgrade.
Upgrade: x-ui update or the button in the panel. No data migrations;
inbounds and already-issued configs are untouched.
⚡️ Enjoy!