Skip to content
CAI
Software that uses CAICheck a score

cedar2025/Xboard

56.1

Adequate · 19 September 2026

34.9k

lines of production code

PHP

primary language

1

measurement over time

CAI band scale
CAI lens gauges

What this system is

This system is a self-hosted proxy management platform that handles user subscriptions, server node orchestration, and administrative operations via a modernized V2 API. It supports a wide range of proxy protocols (including VLESS, Trojan, and Hysteria) and provides real-time synchronization between clients and nodes through WebSocket connections. The platform features a plugin-based architecture for extensibility, integrated payment processing, and a comprehensive admin interface for managing users, traffic, and system configurations.

How it got here

2023 — Laravel 12 migration and V2 API overhaul

41 changes.

The project upgraded to Laravel 12 and PHP 8.2, replacing LaravelS with Octane and migrating authentication to Sanctum. A comprehensive V2 API was introduced while legacy V1 controllers and routes were removed, accompanied by a major consolidation of server models and the introduction of a gift card system.

2025–2026 — Plugin architecture and V2 API migration

14 changes.

This period focused on restructuring the application around a formal plugin system, migrating core components like payment gateways to extendable modules, and migrating the server management API to V2. Concurrently, the project enhanced operational reliability through Docker containerization improvements, automated traffic synchronization via model observers, and dedicated authentication services.

Features

Introduce structured API resource classes for core entities

Added dedicated Laravel API resource classes (ComissionLog, Coupon, InviteCode, Knowledge, Message, Node, Order, Plan, Ticket, and TrafficLog) to standardize JSON responses. These resources ensure consistent field exposure, handle legacy period mapping for plans and coupons, format plan content with template variables, and conditionally expose user identifiers based on the 'hidden\_features.enable\_exposed\_user\_count\_fix' configuration.

app/Http/Resources · high confidence

Introduction of PluginController base class and ApiResponse trait integration

A new abstract PluginController base class has been added to provide common functionality for all plugin controllers, including a beforePluginAction check that prevents execution if a plugin is not enabled. Additionally, the base Controller class now includes the ApiResponse trait, enabling standardized API response formatting across the application.

app/Http/Controllers · high confidence

Major model consolidation and new gift card system

The application has undergone a significant architectural shift in the data layer. Protocol-specific server models (ServerHysteria, ServerTrojan, ServerVless, ServerVmess, ServerShadowsocks) have been removed and consolidated into a unified Server model, which now supports multiple protocols including AnyTLS, TUIC, and VLESS, along with new machine-based load tracking via ServerMachine and ServerMachineLoadHistory. A new gift card system has been introduced with GiftCardTemplate, GiftCardCode, and GiftCardUsage models, enabling admins to create and manage redeemable codes with various reward types. Additionally, the system now supports email template management via MailTemplate, plugin management via Plugin, and detailed traffic reset logging via TrafficResetLog. The old Log model has been renamed to AdminAuditLog, and the Order model has been expanded with new status types and relationships.

app/Models · high confidence

Major service layer overhaul and new capabilities

This update introduces several new services and significantly refactors existing ones. New capabilities include CaptchaService for Cloudflare Turnstile and reCAPTCHA verification, DeviceStateService for tracking user devices via Redis, GiftCardService for redeeming gift cards, NodeRegistry and NodeSyncService for WebSocket-based node synchronization, and UpdateService for automated system updates. Existing services have been rewritten: AuthService now uses Laravel Sanctum instead of JWT, MailService supports chunked processing and template placeholders, OrderService handles one-time and reset plans with improved locking, and CouponService uses exceptions for validation. TrafficResetService now supports monthly and yearly reset schedules based on plan expiration.

app/Services · high confidence

New Docker entrypoint with auto-tuned resources and Redis-independent startup

The .docker/entrypoint.sh script has been introduced to replace previous startup logic, providing automatic resource tuning for Octane and Horizon workers based on available CPU and memory. It supports a split-mode architecture where Caddy can act as a reverse proxy or be disabled for direct binding. The startup process is now resilient to Redis unavailability by falling back to array/sync drivers during the initial update phase, and it cleans up stale process state files to prevent errors on container restart.

.docker · high confidence

New V2 API endpoints for client configuration, node reporting, and machine status

This change introduces three new controllers in the V2 API layer to support updated client and server interactions. The AppController provides a centralized configuration endpoint for client apps, exposing UI themes, feature flags, business rules, and security settings, along with platform-specific version and download information. The ServerController adds a handshake endpoint to enable WebSocket connections for real-time sync and a report endpoint that consolidates node traffic, alive status, online counts, and metrics into a single call. The MachineController introduces endpoints for machines to retrieve their assigned nodes and report detailed system load (CPU, memory, disk, network) which is stored with automatic 24-hour history cleanup.

app/Http/Controllers/V2/Server · high confidence

New V2 Admin API controllers for system configuration, plugins, themes, and gift cards

The admin panel now exposes a new V2 API layer for managing core system settings, plugins, themes, and gift cards. Administrators can now configure site-wide settings (including invite commissions, subscription rules, and security options like reCAPTCHA v3 and Cloudflare Turnstile) via the ConfigController, manage the full lifecycle of plugins (install, uninstall, upgrade) through the PluginController, and upload, switch, and configure themes using the ThemeController. Additionally, a new GiftCardController allows for the creation and management of gift card templates, while dedicated controllers for Mail Templates, Orders, Tickets, Traffic Resets, and User management provide structured endpoints for these administrative tasks.

app/Http/Controllers/V2/Admin · high confidence

New dedicated authentication service classes for login, registration, and magic links

The authentication logic has been extracted into three new service classes in app/Services/Auth: LoginService, RegisterService, and MailLinkService. LoginService now handles password-based login with rate limiting, password reset with secure code validation, and quick login URL generation. RegisterService manages the registration flow, including IP rate limiting, CAPTCHA verification, email whitelist checks, and invite code validation. MailLinkService implements the magic link login feature, generating secure temporary tokens and sending login emails. These services centralize auth logic and improve security through proper token handling and rate limiting.

app/Services/Auth · high confidence

New plugin architecture with hook system and configuration management

The plugin subsystem has been restructured to introduce a formal plugin lifecycle and extensibility model. A new \AbstractPlugin\ base class standardizes plugin behavior, providing methods for boot, install, cleanup, and update operations, as well as helpers for registering Artisan commands and accessing plugin assets. A dedicated \HookManager\ enables plugins to register action and filter hooks with priority support, allowing for non-invasive system modifications. Additionally, a \PluginConfigService\ manages plugin settings by merging default configurations defined in \config.json\ with user-defined values stored in the database, ensuring a consistent configuration experience across core and user plugins.

app/Services/Plugin · high confidence

New plugin configuration trait and query operator utilities

Added the HasPluginConfig trait to enable models to retrieve and cache plugin settings from the database, including automatic plugin code detection from namespaces and cache management. Also added the QueryOperators trait to provide standardized query condition handling, supporting operators like equality, comparison, and null checks while properly formatting values for database queries.

app/Traits · high confidence

New protocol abstraction and refactored settings management

The system introduces a new protocol handling architecture in app/Support, adding AbstractProtocol and ProtocolManager to standardize subscription delivery, filter servers by client version compatibility, and dynamically register protocol handlers. Additionally, the Setting class has been refactored to replace its previous Fluent-based implementation with a Redis-backed cache store, improving admin settings retrieval and persistence performance.

app/Support · high confidence

New server management capabilities and V2 API migration

Administrators can now manage server groups and physical machines via new GroupController and MachineController endpoints, including creating machines with install commands, resetting tokens, and viewing load history. The existing server management API has been migrated to V2 (ManageController), adding batch node deletion and traffic reset features, while the RouteController has also been updated to V2 with expanded action types (block, direct, dns, proxy) and improved error handling.

app/Http/Controllers/V2/Admin/Server · high confidence

Removals

Removal of MySQL-based logging infrastructure

The application no longer supports logging directly to a MySQL database. The \MysqlLogger\ and \MysqlLoggerHandler\ classes, which previously formatted log records and inserted them into the \logs\ table via the \LogModel\, have been deleted. Users relying on this specific storage mechanism will need to switch to alternative logging channels (such as file-based logging) as the database-specific handler is no longer available.

app/Logging · high confidence

Removal of legacy Telegram plugin commands

The legacy Telegram integration commands (Bind, UnBind, Traffic, GetLatestUrl, ReplyTicket) and the base Telegram class have been removed from the application. Users can no longer use these specific Telegram commands to bind accounts, check traffic, retrieve URLs, or reply to tickets via the old Telegram plugin interface.

app/Plugins/Telegram · high confidence

Removal of legacy V1 Admin API controllers

The V1 Admin API endpoints for managing system configuration, orders, statistics, themes, tickets, and users have been removed. This eliminates the legacy administrative interfaces for these areas, requiring users to rely on the updated admin panel or API versions for these operations.

app/Http/Controllers/V1/Admin · high confidence

Removal of legacy V1 admin server management controllers

The V1 admin API endpoints for managing server groups and individual protocol nodes (Shadowsocks, Vmess, Trojan, Vless, and Hysteria) have been removed. This deletes the GroupController, ManageController, and the specific protocol controllers, eliminating the ability to create, update, copy, or delete these server resources through the V1 admin interface.

app/Http/Controllers/V1/Admin/Server · high confidence

Removal of legacy bin scripts (fswatch, inotify, laravels)

The \bin/fswatch\, \bin/inotify\, and \bin/laravels\ scripts have been removed from the project. These files previously provided manual file-watching capabilities (using \fswatch\ or \inotifywait\) to automatically reload the LaravelS server upon PHP file changes, as well as a custom PHP CLI wrapper for the LaravelS console. Users relying on these specific shell scripts for development hot-reloading or direct server management will need to adopt the new tooling introduced in this change.

bin · high confidence

Removed legacy Nginx configuration and cron job

The legacy Nginx configuration file (default.conf) and the root cron job for Laravel scheduler have been removed from the Docker environment. This eliminates the previous setup that handled static assets, gzip compression, and proxying requests to port 7010, indicating a shift in how the application is served or managed within the container.

.docker/etc/nginx · high confidence

Removed legacy payment gateways (EPay, Stripe variants, WechatPay Native)

The EPay, StripeAlipay, StripeCheckout, StripeCredit, StripeWepay, and WechatPayNative payment handlers have been removed from the application. Users can no longer process payments through these specific methods; the system now relies on the remaining payment integrations.

app/Payments · high confidence

Architecture

Admin assets moved to a Git submodule

The admin frontend assets are now managed as a Git submodule (commit ef5f43d) instead of being tracked directly in the repository. This change simplifies asset versioning and updates for the admin interface by delegating the source code to an external repository.

public/assets · high confidence

Behavioural changes

Admin interface components refactored and removed

The bundled admin interface JavaScript file (components.async.js) has been deleted. This file previously contained the compiled source for core UI components including date pickers (DatePicker, RangePicker, WeekPicker), time pickers, buttons, selects, drawers, and layout elements. Its removal indicates a structural change to how these administrative UI assets are loaded or bundled, likely shifting to a different build configuration or component loading strategy.

public/assets/admin · high confidence

Automated traffic reset and node synchronization via new model observers

The application now introduces four new Eloquent observers (Plan, Server, ServerRoute, and User) to automatically handle backend synchronization tasks. When a user's plan or expiration details change, the system automatically recalculates and updates their traffic reset schedule. Additionally, modifications to server configurations, routes, or user group assignments trigger immediate synchronization jobs to ensure connected nodes and clients receive the updated settings without manual intervention.

app/Observers · high confidence

Caddy reverse proxy now preserves client IP chain for accurate Laravel TrustProxies resolution

The Caddy configuration in .docker/caddy has been updated to explicitly trust all proxy IPs and append the X-Forwarded-For header, ensuring that the full proxy chain is passed to the backend. This allows Laravel's TrustProxies middleware to correctly identify the real client IP address. Additionally, the X-Real-IP header is set to the direct peer address for logging and admin tool compatibility. Two configuration variants are provided: Caddyfile for the all-in-one deployment and Caddyfile.split for the separated compose setup, both implementing this IP preservation logic.

.docker/caddy · high confidence

Core payment plugins and Telegram bot moved to plugins-core with plugin architecture

The AlipayF2F, BTCPay, CoinPayments, Coinbase, EPay, and MGate payment gateways, along with the Telegram Bot integration, have been migrated from the application core into the new plugins-core directory. These components now follow a standardized plugin structure, extending AbstractPlugin and implementing PaymentInterface (for payments) or utilizing the TelegramService for bot interactions. This change introduces a plugin-based lifecycle with a boot method to register hooks (such as available\_payment\_methods and telegram message handlers), replaces direct configuration access with a getConfig method, and standardizes error handling by throwing ApiException instead of using abort(). Additionally, the AlipayF2F library's timestamp format was corrected from 'H:m:s' to 'H:i:s' to ensure valid request timestamps.

plugins-core · high confidence

Database schema overhaul and migration updates

The database schema has been significantly restructured to support new features and improve performance. Plan pricing is now stored in a single JSON 'prices' column instead of multiple individual price fields, and plans now support device limits. Server management has been consolidated into a unified 'v2\_server' table with JSON-based protocol settings, adding support for tags, dynamic traffic rates, per-server traffic limits, and machine-based hosting with load monitoring. New tables have been introduced for gift cards, admin audit logs, traffic reset history, and email templates, while subscription templates have been moved from settings to a dedicated table. Performance is improved via new indexes on user, order, and statistics tables, and legacy data has been backfilled for traffic resets and VLESS uTLS settings.

database · high confidence

Enforce 6-digit format for password reset verification codes

The password reset flow now strictly validates that the email verification code provided by the user is exactly 6 digits long. Previously, the system only checked that the code field was present; it now rejects non-numeric or incorrectly sized inputs, providing a specific error message for invalid formats.

app/Http/Requests/Passport · high confidence

Enhanced console scheduling with plugin support and concurrency controls

The application's scheduled tasks now include concurrency safeguards to prevent overlapping executions, with most commands restricted to a single server instance and specific limits on execution duration. A new command, cleanup:online-status, runs every five minutes to manage stale online counts, and the system now integrates with the PluginManager to dynamically register plugin-specific schedules. Additionally, the remindMail command is forced to run, and the kernel initializes enabled plugins during boot to ensure consistent state.

app/Console · high confidence

Guest API controllers refactored with plugin hooks and improved error handling

The guest-facing API endpoints (Comm, Payment, Plan, and Telegram) have been refactored to support a plugin-based extension system and more robust error responses. The configuration endpoint now exposes additional captcha settings (including reCAPTCHA v3 and Cloudflare Turnstile keys) and allows plugins to filter the output via the \guest\_comm\config\ hook. Payment notifications now trigger specific hooks (\payment.notify.before\, \payment.notify.failed\, \payment.notify.verified\, \payment.notify.success\) and return structured error responses instead of generic HTTP 500 aborts, with logging added for exceptions. Plan fetching now uses a dedicated service and resource collection for consistent data formatting. The Telegram webhook handler has been rewritten to use dependency injection, validates access tokens via exceptions, and integrates with the hook system for message processing (\telegram.message.\\ hooks), replacing the previous manual command loading logic.

app/Http/Controllers/V1/Guest · high confidence

Introduces Gift Card redemption and standardizes API response formats

Users can now redeem gift cards to receive subscription rewards and view their redemption history via the new GiftCardController. Across the user API, all endpoints now return a consistent JSON structure using the standard success/fail helper methods instead of raw response objects, and data is formatted through dedicated API Resources (e.g., PlanResource, OrderResource, TicketResource). Additionally, the Knowledge API now supports fetching articles by language and keyword, and the Ticket system allows users to configure a mandatory wait period before replying to their own support requests.

app/Http/Controllers/V1/User · high confidence

Middleware overhaul: new runtime, plugin, and transaction guards; auth migration to Sanctum; server API v2

The middleware layer has been significantly restructured. New middleware includes ApplyRuntimeSettings (applies app\_url and force\_https per-request), InitializePlugins (boots enabled plugins at request start), and EnsureTransactionState (rolls back stale DB transactions, critical for long-running processes like Octane). Server authentication is split: ServerV2 handles machine-token or server-token auth without node\_type, while the legacy Server middleware is deprecated but updated to support v2node. Admin and User authentication now use Laravel Sanctum guards instead of custom auth\_data decryption. The custom CORS middleware is replaced by Laravel's built-in HandleCors. Audit logging (RequestLog) now records admin actions with sensitive data redaction. Client token handling is updated to support route parameters, and TrimStrings excludes encrypted\_data and signature.

app/Http/Middleware · high confidence

Migration from LaravelS to Laravel Octane and Sanctum authentication

The application has replaced the LaravelS Swoole integration with Laravel Octane for high-performance serving, introducing a new \config/octane.php\ file and removing the legacy \laravels\, \swoole\_http\, and \swoole\_websocket\ configuration files. This architectural shift is accompanied by a transition in API authentication from the legacy token driver to Laravel Sanctum, configured via a new \config/sanctum.php\ file and updates to \config/auth.php\. To support the new Octane environment, a dedicated \octane\ cache driver has been added, and the \app.php\ service provider list has been updated to register Octane and plugin services while removing the LaravelS provider. Additionally, the system version has been reset to 1.0.0, and Horizon's memory limit has been increased to 256MB with expanded queue definitions.

config · high confidence

New Xboard theme with dark mode and responsive layout

The theme area now includes a new Xboard theme, replacing the previous v2board theme. This update introduces a modern interface featuring full dark mode support, a responsive grid layout for cards, and a carousel for announcements. The visual design has been updated with a new background image and comprehensive styling for markdown content and UI components.

theme · high confidence

New maintenance commands and enhanced traffic reset logic

The application introduces several new console commands to improve maintenance and operational visibility: \backup:database\ now supports creating compressed SQL backups and optionally uploading them to Google Cloud Storage; \check:traffic-exceeded\ detects users who have surpassed their data limits and notifies the relevant nodes via WebSocket; \cleanup:online-status\ resets stale device connection counts for inactive users; and \hook:list\ scans the codebase to display all supported plugin hooks. Existing commands have been significantly refactored for performance and reliability: \reset:traffic\ is rewritten to use a dedicated service and supports \--fix-null\ and \--force\ modes for better control over reset schedules; \check:order\ and \check:ticket\ now process records in lazy chunks to prevent memory exhaustion; \send:remindMail\ uses chunked processing with a progress bar; and \check:commission\ improves transaction safety. Additionally, \xboard-install\ now supports PostgreSQL and validates Redis connectivity, while \xboard-update\ automatically installs default plugins and refreshes themes.

app/Console/Commands · high confidence

Protocol handlers refactored to use centralized template system and modern data structures

The protocol generation classes in app/Protocols have been refactored to extend a new AbstractProtocol base class, replacing the previous standalone structure. This change introduces a centralized subscription template system (replacing direct file-based YAML parsing) and standardizes server data access via protocol\_settings, allowing for more consistent configuration across clients. Several legacy protocol handlers (Passwall, SSRPlus, SagerNet, V2rayN, V2rayNG) have been removed as their functionality is now consolidated into the General protocol handler, which now supports a broader range of protocols including Hysteria, AnyTLS, TUIC, and HTTP. Additionally, the refactored handlers now enforce client-specific version requirements for protocols like Hysteria and ECH, and improve compatibility by correctly handling network settings, plugin options, and TLS configurations.

app/Protocols · high confidence

Redesigned Docker deployment with modular compose templates and admin asset submodules

The Docker deployment experience has been restructured to support flexible, per-mode configurations. The previous single \docker-compose.yaml\ and \php.ini\ files have been replaced by a set of dedicated sample templates: \compose.sample.yaml\ (default bridge network), \compose.1panel.sample.yaml\ (for 1Panel users connecting to external MySQL/Redis), \compose.host.sample.yaml\ (for host networking), and \compose.split.sample.yaml\ (for distributed K8s-style deployments separating Caddy, Web, Horizon, and WS-Server). The Dockerfile has been updated to use PHP 8.2, install the \bcmath\ extension, and run as a non-root user (\www\). Additionally, the admin panel assets are now managed via a Git submodule (\public/assets/admin\ from \xboard-admin-dist\), and the \init.sh\ and \update.sh\ scripts have been updated to handle submodule initialization and correct directory permissions for Docker environments.

(repo-wide) · high confidence

Redesigned email templates and modernized admin panel asset loading

The default email templates (login, verification, notifications, and expiration alerts) have been completely redesigned with a modern card-based layout, improved typography, and clearer calls to action, replacing the previous table-based structure. Additionally, the admin panel view now dynamically loads JavaScript and CSS assets from a manifest file instead of using hardcoded paths, ensuring correct asset resolution for the new frontend build system.

resources/views · high confidence

Refactored WebSocket node connection and device synchronization logic

The WebSocket server's handling of node connections and device state synchronization has been restructured. A new \NodeEventHandlers\ class centralizes logic for processing node heartbeats, status updates, and device reports, replacing previous inline or scattered implementations. The \NodeWorker\ now uses this handler for routing messages like \report.devices\ and \request.devices\. Device synchronization is managed via a Redis-backed pending queue (\device:push\_pending\_nodes\), ensuring that device state changes are pushed to connected nodes efficiently. Authentication for nodes now explicitly uses \ServerService::getServer()\ for node lookup, improving reliability during connection establishment.

app/WebSocket · high confidence

Refactored authentication and registration logic into dedicated service classes

The authentication and registration endpoints in the Passport API have been refactored to delegate core logic to new service classes (LoginService, RegisterService, MailLinkService, and CaptchaService). This change removes direct handling of reCAPTCHA verification, email whitelist checks, rate limiting, and user creation from the controllers, replacing them with cleaner service calls. For users, this results in a more consistent error handling approach (using standardized fail/success responses) and maintains existing security features like bot protection and email validation while improving code maintainability.

app/Http/Controllers/V1/Passport · high confidence

Refactored cache key management and enhanced utility functions

The CacheKey class now uses a pattern-based approach with wildcard support (e.g., SERVER\\\_ONLINE\_USER) instead of a hardcoded list of specific protocol keys, allowing for more flexible caching of node status and metrics. Helper functions have been updated to support SHA256-salted password hashing, IPv6 address wrapping, and random port generation with validation to prevent min/max errors. Additionally, subscription URL retrieval now supports pattern-based replacement (e.g., \[min-max\] expressions) and integrates with a plugin hook system for URL filtering.

app/Utils · high confidence

Refactored server backend controllers to use middleware-provided node info and centralized services

The server backend controllers (Deepbwork, ShadowsocksTidalab, TrojanTidalab, and UniProxy) have been refactored to retrieve node information from request attributes instead of manually querying the database via node\_id. This change, combined with the removal of the DeepbworkController, simplifies the controller logic and delegates traffic processing, user retrieval, and configuration building to centralized ServerService methods. Staff management controllers (Notice, Plan, Ticket, User) have been removed, indicating a shift in how administrative operations are handled.

app/Http/Controllers/V1/Server · high confidence

Removal of Hiddify, Hysteria2, and Sing-box client icons from Xboard theme

The Xboard theme has removed the SVG icon assets for Hiddify, Hysteria2, and Sing-box clients from the public theme directory. This change likely reflects a decision to stop displaying these specific client logos in the user interface, possibly due to compatibility updates or a shift in supported client recommendations.

public/theme · high confidence

Removal of WebSocket support and overhaul of theme rendering and host validation

The application no longer supports WebSocket connections, as the dedicated websocket routes file has been deleted. The main web route has been significantly refactored: host validation in safe mode now uses the proper getHost() method for accurate comparison, and theme rendering has been moved to a dedicated ThemeService that handles theme existence checks, view path validation, and public directory initialization with robust error logging and fallback to the default theme. Additionally, the version information now dynamically retrieves the current version via UpdateService instead of using a static config value, and a new client subscription route has been added.

routes · high confidence

Removal of legacy Admin and Staff route definitions and migration to explicit controller references

The legacy route definitions for the Admin and Staff panels (AdminRoute.php and StaffRoute.php) have been removed, eliminating the previous centralized routing structure for administrative and support functions. In the remaining route files (Client, Guest, Passport, Server, and User), all route registrations have been migrated from string-based controller references (e.g., 'Controller@method') to explicit class-based references (e.g., \[Controller::class, 'method'\]). Additionally, the Server routes have been restructured to replace a dynamic, catch-all endpoint with specific, named groups for UniProxy, ShadowsocksTidalab, and TrojanTidalab, each with their own dedicated middleware. The User routes also now include new endpoints for Gift Card management.

app/Http/Routes/V1 · high confidence

Removal of legacy Supervisor configuration

The Docker environment no longer uses the previous Supervisor configuration file for managing processes like Nginx, cron, and the application adapter. This change removes the explicit definition of these services, indicating a shift in how the container's processes are orchestrated or managed within the Docker setup.

.docker/etc/supervisor · medium confidence

Standardized API response format and enhanced settings management

The application now uses a new \ApiResponse\ trait and \ResponseEnum\ class to enforce a consistent JSON response structure (status, message, data, error) across the API, replacing previous ad-hoc response patterns. Settings management has been refactored to use a dedicated \Setting\ service, introducing an \admin\_settings\_batch\ helper for improved performance when retrieving multiple configuration keys, and adding a \subscribe\_template\ helper to fetch subscription content from the database. Additionally, a \source\_base\_url\ helper was added to correctly determine the base URL for requests by prioritizing the Referer header.

app/Helpers · high confidence

Structured API error responses and plugin interception support

The application now provides structured error responses for API consumers through new exception classes (ApiException, BusinessException) and updated handling in the exception handler. ApiException allows controllers to return specific error codes, messages, and detailed error arrays via the fail helper, while BusinessException supports custom status code mappings. The handler also suppresses logging for InterceptResponseException to reduce noise and enables plugin-based response interception, ensuring consistent JSON error formats for API clients instead of generic HTML or plain text errors.

app/Exceptions · high confidence

Subscription endpoint refactored with plugin hooks and protocol prefixing

The client subscription logic has been restructured to support extensibility and cleaner client identification. The subscribe endpoint now integrates a plugin hook system, triggering 'client.subscribe.before' and 'client.subscribe.unavailable' events, and allows server lists to be filtered via the 'client.subscribe.servers' hook. Additionally, server names in subscriptions are now automatically prefixed with protocol indicators (e.g., \[Hy2\], \[vless\]) based on a new mapping, and the codebase has migrated from direct service instantiation to static calls and updated protocol class references to ensure compatibility with the new plugin architecture.

app/Http/Controllers/V1/Client · high confidence

Supervisor configuration for all-in-one Docker deployment

The Docker supervisor now manages the full application stack within a single container, running Octane, Horizon, Redis, the WebSocket server, and Caddy as distinct processes. Redis is configured to listen exclusively on a Unix socket (port 0) rather than TCP, and the WebSocket server process is explicitly defined to handle real-time connections.

.docker/supervisor · high confidence

Unified server validation and expanded admin configuration options

The admin panel now uses a single, comprehensive validation class (ServerSave) for all server types, replacing the previous protocol-specific request classes (ServerShadowsocksSave, ServerTrojanSave, ServerVmessSave, etc.). This change introduces validation support for new protocol features including uTLS, Multiplex, ECH, Reality, Vless encryption, AnyTLS, and Mieru. Additionally, the ConfigSave request has been updated to support new system settings such as custom Telegram webhook URLs, reCAPTCHA v3 and Cloudflare Turnstile captcha types, device limits, and subscription templates for various clients (Singbox, Clash, Surge, etc.). The PlanSave request now uses a unified 'prices' array structure instead of individual period fields and supports plan tags.

app/Http/Requests/Admin · high confidence

V2 API route structure reorganization and expansion

The V2 API routing layer has been restructured to improve modularity and expand administrative capabilities. New dedicated route files (ClientRoute, PassportRoute, ServerRoute, UserRoute) now handle client, authentication, server, and user endpoints respectively, replacing the previous monolithic or less-organized structure. The AdminRoute has been significantly expanded to include new administrative features such as mail template management, plan management, server group/route/machine management, order processing, user management (including CSV export and ban/reset), statistics, notices, tickets, coupons, and gift card templates. This change provides a more organized and feature-rich API for both clients and administrators.

app/Http/Routes/V2 · high confidence

Fixes

Fixes database locking issues and improves reliability in traffic and order processing jobs

This update resolves database locking and timeout issues that could cause failures in background jobs. The new StatServerJob and StatUserJob replace previous implementations with database-specific upsert logic (using ON CONFLICT for PostgreSQL and transactions for SQLite) to prevent record locks during traffic statistics aggregation. The OrderHandleJob no longer holds a database lock during construction, instead fetching the order by trade number at runtime to avoid lock wait timeouts. Additionally, the TrafficFetchJob now uses atomic increment operations and Redis for pending checks, and the SendEmailJob delegates to a centralized service to ensure proper error handling and retry behavior.

app/Jobs · high confidence

Laravel Octane compatibility and protocol management overhaul

The application has been refactored to support Laravel Octane, ensuring stable operation in long-running worker environments. A new OctaneServiceProvider manages worker lifecycle events and implements a 30-second scheduler tick to handle periodic tasks safely. The previous method of forcing HTTPS and app URLs in the RouteServiceProvider and SettingServiceProvider has been removed in favor of per-request middleware, preventing state leakage between requests. Additionally, the original AppServiceProvider was renamed to ProtocolServiceProvider to centralize protocol management, and the EventServiceProvider now registers observers for User, Plan, Server, and ServerRoute models to handle entity lifecycle events.

app/Providers · high confidence

Test coverage

Added tests for V2 server handshake and report endpoints; Added unit tests for authentication and order concurrency logic.

Dependencies

Upgrade to Laravel 12 and PHP 8.2 with expanded dependency ecosystem

The project has upgraded its core framework from Laravel 10 to Laravel 12 and raised the minimum PHP version requirement from 8.1 to 8.2. This update introduces several new dependencies including Laravel Octane, Laravel Sanctum, Laravel Prompts, Doctrine DBAL 4, and Symfony HTTP client and Mailgun mailer, while removing older packages like hhxsv5/laravel-s and joanhey/adapterman. Development tooling has also been updated, adding Larastan 3 and updating PHPUnit to version 11, alongside the addition of a new Plugin namespace for autoloaded classes.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 56.

Lenses

  • Code Health 87
  • Architecture 76
  • Maturity 52
  • Readiness 51
  • Security 71
  • Accessibility 60

Changes since last survey

  • 300 commits — 155 feature/other, 145 fixes

By area

  • app/Http — 57 commits
  • app/Protocols — 50 commits
  • app/Services — 34 commits
  • public/assets — 33 commits
  • (repo) — 25 commits
  • (root) — 19 commits
  • app/Console — 16 commits
  • docs/en — 12 commits
  • app/Models — 9 commits
  • app/Utils — 5 commits
  • database/migrations — 5 commits
  • app/Jobs — 4 commits
  • theme/Xboard — 3 commits
  • .docker/entrypoint.sh — 2 commits
  • app/Helpers — 2 commits
  • app/Traits — 2 commits
  • plugins/Telegram — 2 commits
  • resources/lang — 2 commits
  • resources/rules — 2 commits
  • .docker/caddy — 1 commit

Notable commits

  • fix: Fix TUIC congestion control at Shadowrocket.php (#968)
  • fix: Fix environment variable declaration in Dockerfile. #806
  • fix: Fix redis ownership (#927)
  • fix: Fix service names in v2board migration steps
  • fix: Fix the bug of sub-node ss password mismatch
  • fix: Fix: [CVE redacted] - Magic link token leak in loginWithMailLink (#873)
  • fix: Fix: Handle raw DB expressions in user filter
  • fix: Merge pull request #638 from zytakeshi/fix/singbox-sni-domain-issue
  • fix: Merge pull request #689 from socksprox/fix-user-generation-multiple-prefix
  • fix: Merge pull request #832 from Dlphine/fix/raw-array-access-data-get
  • fix: Merge pull request #841 from cedar2025/revert-755-feat/server-id-stat-user
  • fix: Revert "Combine data with node_id in api output, so its all still "one day", and fits vanilla xboard behaviour"
  • fix: Revert "feat: Track user traffic per node (server_id)"
  • fix: Revert "fix: escape Telegram Markdown special characters (fix #450)"
  • fix: fix
  • fix: fix (General.php): VLESS parsing issue (#1017)
  • fix: fix(Shadowrocket.php): add missing bandwidth params for Hysteria2 (#1031)
  • fix: fix(admin): fix giftcard form validation and template creation issues
  • fix: fix(admin): Fix order assignment issue in admin panel
  • fix: fix(admin): correct language pack errors in admin panel
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

cedar2025/Xboard was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 19 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 4f48e61a2cbc6db5338872b6bdb45ef954ec1256 — the exact code this score is about.
  • Scored under rubric-2026.09.15 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-13a154b7f5d1.