github AlexeyLCP/lucx-ui v3.6.0-lucx.125

latest releases: v3.8.5-lucx.275, dev-latest, v3.8.5-lucx.274...
one month ago

🔧 v3.6.0-lucx.125 — в подписке больше не появляется чужой адрес

Если панель стоит за nginx, в ссылках и подписках мог оказаться IP самого
подписчика
вместо вашего домена. Заметнее всего это на AmneziaWG: в
Clash-профиле server: вёл на роутер клиента, и пинг до ноды, разумеется, не
проходил.

Почему страдал только AWG

У VLESS/Reality/WS адрес обычно берётся раньше — из host-записи, listen или
share-адреса инбаунда. У AWG-инбаунда своего адреса нет, поэтому панель
доходила до последнего звена цепочки — хоста запроса, а там лежал заголовок
X-Real-IP, то есть адрес того, кто скачал подписку.

Что изменилось

  • 🔘 Адрес чинится сразу везде: /sub/, /json/, /clash/, /awg/, а также
    ссылки и QR-коды в самой панели (туда утекал IP администратора).
  • 🔘 X-Real-IP больше не участвует в выборе адреса — только Host и
    X-Forwarded-Host от доверенного прокси. Этот заголовок отвечает на вопрос
    «кто пришёл», а не «куда подключаться».
  • 🔘 В lucx.90 дыру закрыли только для .conf и vpn:// — теперь закрыта
    целиком.
  • 📘 Новый раздел в документации (RU/EN/FA): в каком порядке выбирается адрес
    для ссылок и что делать, если он неправильный.

⚠️ В блоке nginx оставьте proxy_set_header Host $host; — генератор конфига из
документации его ставит.

Не готовы обновляться прямо сейчас? Задайте Sub Domain или Web
Domain
в настройках панели либо пропишите инбаунду явный share-адрес —
цепочка возьмёт их раньше хоста запроса.

Проверить, течёт ли ваша панель:

curl -s -H 'X-Real-IP: 203.0.113.77' https://ваш-домен/clash/<subId> | grep -B2 'type: wireguard'

Появился 203.0.113.77 в server: — обновляйтесь.

Обновление: x-ui update или кнопка в панели. Миграций данных нет,
инбаунды и выданные конфиги не трогаются.

Спасибо Aleksandr SacredX за репорт — второй раз по этой же теме, и в этот раз
до самого корня. 🫡

⚡️ Приятного использования!


🔧 v3.6.0-lucx.125 — no more stranger's address in your subscription

With the panel behind nginx, links and subscriptions could carry the
subscriber's own IP instead of your domain. Most visible on AmneziaWG: the
Clash profile's server: pointed at the client's own router, so nothing could
ever connect.

Why only AWG was hit

VLESS/Reality/WS inbounds usually get their address earlier — from a host row,
listen, or an explicit share address. An AWG inbound has no address of its
own, so the panel fell through to the last link in the chain — the request
host — and that was taken from the X-Real-IP header, i.e. whoever fetched the
subscription.

What changed

  • 🔘 Fixed everywhere at once: /sub/, /json/, /clash/, /awg/, plus the
    links and QR codes inside the panel itself (those leaked the admin's IP).
  • 🔘 X-Real-IP no longer takes part in picking the address — only Host and
    X-Forwarded-Host from a trusted proxy. That header answers "who came in",
    not "where to connect".
  • 🔘 lucx.90 only plugged this for .conf and vpn:// — now it's plugged
    for good.
  • 📘 New docs section (RU/EN/FA): the order the link address is resolved in,
    and what to do when it's wrong.

⚠️ Keep proxy_set_header Host $host; in your nginx block — the config
generator in the docs emits it.

Not upgrading right now? Set Sub Domain or Web Domain in panel
settings, or give the inbound an explicit share address — both are picked
before the request host.

Check whether your panel leaks:

curl -s -H 'X-Real-IP: 203.0.113.77' https://your-domain/clash/<subId> | grep -B2 'type: wireguard'

If 203.0.113.77 shows up in server: — time to upgrade.

Upgrade: x-ui update or the button in the panel. No data migrations;
inbounds and already-issued configs are untouched.

⚡️ Enjoy!

Don't miss a new lucx-ui release

NewReleases is sending notifications on new releases.