diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 139980b..2c53740 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -158,7 +158,7 @@ jobs: docker run --rm proxy-workbench:ci clear-data --yes docker run --rm --entrypoint python proxy-workbench:ci -c "from proxy_workbench import source_catalog; assert source_catalog.load_bundled()['sources']" - # The .app users install (F23). This job builds it on a real macOS runner, + # The .app users install. This job builds it on a real macOS runner, # starts it, and checks the page it serves, its per-user data folder, a second # start and the untouched bundle. It is unsigned - no identity exists in # this project - and the manifest says so. diff --git a/.github/workflows/release.yml b/.github/workflows/release.yml index 2613984..a1e4b66 100644 --- a/.github/workflows/release.yml +++ b/.github/workflows/release.yml @@ -99,7 +99,7 @@ jobs: tag_name: ${{ env.TAG }} files: dist/*.whl - # The two Windows binaries F23 asks for: a windowed GUI and a separate + # The two Windows binaries: a windowed GUI and a separate # console CLI, plus the per-user installer. Nothing here is signed - a # certificate would have to exist in the runner's certificate store and be # named by PROXY_WORKBENCH_SIGN_THUMBPRINT, and until one does the manifest diff --git a/.github/workflows/windows.yml b/.github/workflows/windows.yml index 93809a7..137cf58 100644 --- a/.github/workflows/windows.yml +++ b/.github/workflows/windows.yml @@ -1,6 +1,6 @@ name: Windows desktop artifact -# The Windows half of F23. A .exe can only be built and started on Windows, +# The Windows delivery. A .exe can only be built and started on Windows, # so a macOS or Linux build never proves anything about this one: the job below # is what makes the claim checkable by whoever has a Windows machine, and by # everyone else through the run log. diff --git a/CHANGELOG.md b/CHANGELOG.md index 1c9621c..a8b8d2e 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1,56 +1,78 @@ # Changelog / История изменений -Формат следует Keep a Changelog и semantic versioning. +The format follows Keep a Changelog and semantic versioning. -## [Unreleased] +## [3.0.0] — 2026-09-27 -### Added +The biggest release so far: a new interface, a source catalog of 150 lists, a desktop app that lives in the menu bar, persistent proxy pools with schedules, API keys, diagnostics that explain an empty result, and backups you can preview before restoring. Existing data folders are upgraded in place, with an automatic copy taken first. -- **Точка входа доходит до фонового слоя.** `proxy-workbench` и `python -m proxy_workbench` без аргументов запускают приложение (`proxy_workbench.desktop`): меню-бар на macOS, один экземпляр, запуск при входе по желанию, сон/пробуждение. `gui` и `--no-desktop` открывают только интерфейс; всё остальное уходит в CLI, как и раньше. Раньше обычный запуск уходил в `gui.main`, и фоновый слой не работал в том виде, в котором его запускает пользователь. -- **Меню-бар входит в собранный `.app`.** Helper на Swift компилируется сборкой (`packaging/tray_helper.py`) и кладётся в bundle; spec без него прерывает сборку. Раньше приложение запускалось и не имело меню-бара. -- **Замороженная сборка умеет выполнять проверку.** Worker — это повторный запуск того же исполняемого файла с командой `scan`; frozen launcher маршрутизирует командные слова в CLI тем же правилом, что и консольный скрипт. Раньше такая попытка заканчивалась `unrecognized arguments: scan`, то есть установленное приложение не могло проверить ни одного прокси. -- **`packaging/verify_delivery.py`** — per-user пути, portable mode и перенос старой папки, проверенные на настоящем собранном артефакте, а не на коде. -- **Windows-поставка проверяется сама.** Сборщик читает PE-subsystem из готового `.exe` и отказывается выпускать пару, в которой GUI-бинарник не windowed или CLI не console; запускает GUI-бинарник с пустым `%LOCALAPPDATA%` и проверяет второй запуск; передаёт установщику абсолютные пути и ищет `iscc` в стандартных папках. -- **CI, который проверяет артефакты.** `.github/workflows/windows.yml` собирает и запускает Windows-поставку на настоящем Windows-runner; job `macos-artifact` в `ci.yml` собирает `.app`, прогоняет smoke по собранному бинарнику и сверяет манифест; `release.yml` отдаёт два Windows-бинарника с per-user installer и macOS-артефакт. -- **Версия пакета приведена к версии продукта:** `pyproject.toml` был `2.2.1`, `branding.PRODUCT_VERSION` — `2.3.0`, и bundle объявлял одно число, а wheel — другое. - -- **Версионированный control API `/v1`** — 82 маршрута: коллекции, источники, профили, задания, результаты, пулы, шлюз, расписания, экспорты, бронирования, импорты и ключи. Машиночитаемое описание — `proxy_workbench/openapi.json`, генерируется из той же таблицы маршрутов, по которой отвечает сервер. -- **Менеджер API-ключей** в GUI и CLI (`api-key`): именованные ключи, права, resource scope (коллекции и пулы), лимит частоты, параллелизм, срок, ротация с окном Grace, отзыв и журнал аудита. Первый административный ключ выдаёт только локальный доверенный bootstrap. -- **Именованные профили с ревизиями и пресеты**, **пулы** с реальным циклом поддержания, **расписания**, **менеджер источников** с отчётами по каждому источнику. -- **`diagnose funnel|zero|control|health|bundle`** — счётчики воронки, объяснение нулевого результата, контроль устройства и целей, редактированный диагностический пакет. Слой диагностики существовал и был недостижим. -- **`backup verify|preview|restore|rollback|retention|cleanup|rebind`** — вторая половина F24. Каждое изменяющее действие сначала печатает, что сделает, и выполняется только с `--apply`. -- **Подписки** как узкое, ограниченное по сроку и отзываемое identity, и настольная поставка для macOS (`.app`/`.dmg`), Windows и Linux с per-user путями данных и portable-режимом. -- `include_secrets` публикует **ссылку** на запись хранилища, а не значение секрета. +### Highlights -### Fixed +- **Redesigned interface.** A new dark-first design layer with a reworked light theme, consistent typography, micro-animations and a live feed of the running check. The layout adapts to phones and tablets (a side rail on tablets, a compact layout on phones), and heavy tables stay smooth on large result sets. +- **12 interface languages.** English and Russian are joined by German, Spanish, French, Italian, Japanese, Polish, Portuguese, Turkish, Ukrainian and Chinese, every one of them complete. +- **Source catalog: 150 sources, 117 of them fully free and public; 106 feeds are collected out of the box.** Every entry says who publishes it, what it serves (proxy list, subscription config, API), whether an account is needed, which protocols it carries and how it was verified. Ready-made sets (quick, all supported, extended, by protocol), one-click enable/disable, per-source reports and a comparison that spots lists which republish each other. Only sources marked safe to collect are fetched; commercial, trial and rejected entries are shown for reference. +- **Desktop app.** Starting `proxy-workbench` without arguments now launches the desktop app: a macOS menu-bar icon, a single running instance, optional start at login, and correct recovery after sleep/wake. `proxy-workbench gui` (or `--no-desktop`) opens only the web interface, as before. +- **Proper installers.** A macOS `.app`/`.dmg` (Apple Silicon and Intel) and Windows GUI and CLI executables with a per-user installer; Linux installs with `pipx` or Docker. Data lives in per-user folders, with a portable mode and automatic migration of an old `data/` folder. -- **Поколение снова множество адресов.** Повторная проверка добавляла вторую строку того же адреса, каждый потребитель судил строки независимо, и адрес попадал дважды в `proxies.txt`, `ranked.json`, `ranked.csv`, `proxy.pac`, `clash.yaml`, `singbox.json` и в `/proxies`. Теперь у `results` одна строка на (профиль, доступ, адрес), схлопнутая история суммируется, `job_id` остаётся колонкой последнего измерения. Версия схемы 15. -- **Свежий провал отменяет старый успех.** Строка с ошибкой отвергалась, а устаревшая сохраняла свой не истёкший `valid_until`, и опубликованный набор продолжал отдавать адрес, который последнее измерение только что отвергло. -- **Обновление промежуточной сборки обратимо.** Техническая копия с manifest берётся перед любой неаддитивной миграцией, а не только для legacy-файла с `user_version = 0`: сборка линии 1.x переписывала `results` без страховки, и `list_backups()` показывал пусто. -- **Legacy-результаты остаются читаемыми.** Миграция 13 писала восстановленное происхождение в колонки, которые никто не читает, и каждая historic-строка отказывала по коллекции, в которой не измерялась. Теперь оно доходит до payload; то, чего файл 2.x не содержал (сеть, lifetime), отсутствует по-прежнему, и отказ называет эту настоящую причину. -- **Штатная retention-политика выполняется.** Она удаляла `observations` раньше ссылающихся на них `results`, SQLite отвергал, откат оставлял данные на месте — после того, как preview уже пообещал удаление. -- **Object-level scope проверяется.** Чтение и скачивание артефакта чужой коллекции отвечали 200; список заданий, профилей, источников или расписаний возвращался ключу, ограниченному одной коллекцией, потому что фильтр спрашивал вид scope, которого у ключа нет. Один объект вне scope — 404; список теряет только чужие строки. -- **Чувствительный экспорт работает.** `include_secrets` передавал имя режима вне словаря движка, запрос отвергался после уже пройденной проверки права, а отказ выдавался за «операция не подключена к сервисному слою». Доменный отказ теперь отвечает своим кодом. -- **Пароль шлюза не равен токену API.** `serve` и `gateway` использовали одно значение `--api-token` и как пароль ротирующего прокси, и как read-only bearer. У шлюза свой `--gateway-token` / `PROXY_WORKBENCH_GATEWAY_TOKEN`; поставляемый compose использует обе переменные. -- **`POST /v1/pools/{id}/refill` наполняет пул.** Он не читал путь, ставил в очередь проверку коллекции из тела и оставлял пул на 0/desired, отвечая «job queued». `/start` теперь запускает пул, `/recheck` измеряет его собственную коллекцию, а `/start`, `/pause` и `/members` больше не отвечают 500. -- **`/v1/results/{id}` и `/v1/results/{id}/observations` возвращают данные.** Сегмент пути не может нести полный адрес, а строка не публиковала `endpoint_id`, поэтому detail был всегда 404, а observations — пустым списком. -- **`--max-requests` и `--run-max-bytes` считают.** Ресурсный шлюз не начислял потраченное измерением, и оба лимита были молчаливыми no-op. Исчерпанный бюджет теперь останавливает прогон, а не записывает нетронутый адрес как недостижимый. -- **N endpoint, N уникальных IP и N подтверждённых exit-IP — три разных числа.** Последние два были одним выражением и всегда давали 0, потому что подтверждённый адрес выхода искали не там. Прогон, закончившийся недобором `--want`, называет недостижимую единицу вместо `complete`. +### Added + +- **Pools.** A named pool keeps N working proxies for a profile, with a reserve, quotas and resource budgets; it refills and re-checks itself, and tells you why it is short. +- **Schedules.** Re-check collections or pools on an interval, in your time zone, with quiet hours, request/byte budgets and notifications when a proxy's state changes. +- **Named profiles with revisions and presets.** Target rules, success criteria and settings are saved as profiles; every change is a revision, and profiles can be shared without secrets. +- **Collections and import.** Bring your own lists from TXT, URI, CSV, JSON, Clash or sing-box files with a preview, column mapping and a report of every rejected line; imports are transactional and merge or replace. +- **Service catalog.** Ready-made checks for popular services, grouped into sets, with an explicit rule for which fields a preset overwrites. +- **Geography and exit country.** Filter by the proxy's own country, the country traffic actually exits from, or either; exclude countries; choose how unknown locations are treated. +- **Rotating gateway, upgraded.** Bind the gateway to a pool from the GUI, serve it on your LAN (`--lan`, `--gateway-interface`), and use upstream proxies that need a login (HTTP Basic, SOCKS5 username/password). The gateway has its own password (`--gateway-token`), separate from the API token. +- **API keys.** Create named keys with permissions, collection/pool scope, rate and concurrency limits, expiry, rotation with a grace window, revocation and an audit log — in the GUI (Keys page) and the CLI (`api-key`). A secret is shown exactly once. +- **Secret store and access identities.** Proxy credentials are stored separately and referenced, never copied into exports or diagnostics. +- **Diagnostics.** A funnel shows where candidates were lost; "why 0 results" explains an empty run in plain words; a health check; and a redacted diagnostic bundle you can review before saving (`diagnose funnel|zero|control|health|bundle`). +- **Backup, restore and retention with preview.** `backup create|list|verify|preview|restore|rollback|retention|cleanup|rebind`; every change is previewed first and runs only with `--apply` (or the confirm button in the GUI). +- **Run budgets and "find N".** `--want N` with `--count-what endpoint|ip|exit`, `--deadline`, `--max-requests`, `--run-max-bytes`; a run that falls short says which unit it could not reach. +- **Export targets.** `--client-target` / `--client-binary` validate sing-box output for a specific client version. +- **Versioned control API `/v1`** for scripts and integrations: collections, sources, profiles, jobs, results, pools, gateway, schedules, exports, imports and keys. A machine-readable description ships as `proxy_workbench/openapi.json`. ### Changed -- Схема базы на версии 15; за ней следуют константа настольной поставки и `openapi.json`. -- Лимиты по умолчанию на источник — 32 МиБ и 500 000 кандидатов, чтобы крупнейшие публичные списки не обрезались. +- **Breaking:** running `proxy-workbench` / `python -m proxy_workbench` with no arguments opens the desktop app instead of only the web interface. Use `proxy-workbench gui` for the old behaviour. All CLI commands are unchanged. +- **Breaking:** the database schema moves to version 20. Older data folders (1.x and 2.x) are migrated on first start; a backup is taken before any non-additive step and can be restored with `backup rollback`. Do not open an upgraded folder with 2.x. +- **Breaking:** the rotating gateway no longer accepts the API token as its password; set `--gateway-token` / `PROXY_WORKBENCH_GATEWAY_TOKEN`. The bundled `compose.yml` already does. +- Each proxy address is now one row per profile and access identity, so an address no longer appears twice in `proxies.txt`, `ranked.*`, `proxy.pac`, `clash.yaml`, `singbox.json` or `/proxies`. +- Python 3.11 or newer; CI tests 3.11, 3.12 and 3.14 on Linux, macOS and Windows. -### Known gaps +### Fixed -- Аутентификация на прокси (HTTP Basic и SOCKS5 username/password) не реализована ни в одном движке проб: credentials в URL отвергаются, а идентичность доступа записывается, но сам секрет не отправляется. Поэтому `results.access_id` всегда называет identity, под которым строка измерена, а для встроенного скана это публичная, без пароля. -- **Windows-поставка не собрана и не запущена.** Машина сборки — macOS, а PyInstaller собирает под свою машину. Проверено без Windows: разбор и фактический запуск всех spec'ов, entry point, `console=False`/`console=True`, наличие ресурсов, чтение PE-subsystem, передача путей установщику, поиск `iscc`. Воспроизводимая проверка добавлена в `.github/workflows/windows.yml`, но ещё ни разу не выполнялась. Матрица сборок и точные команды — в `docs/packaging/RELEASE-NOTES.ru.md`. -- **Артефакты не подписаны и не нотарифицированы.** Signing credentials у проекта нет, и пайплайн их не создаёт; macOS-сборка получает ad-hoc подпись, Windows остаётся без Authenticode. Пайплайн подхватит уже имеющийся Developer ID и учётные данные нотаризации, когда они появятся. -- Меню-бар есть только на macOS. Sleep/wake на Windows не определяется: сон входит в монотонные часы, а нативного наблюдателя для Windows в слое нет. На Linux работает сравнение часов, но и оно не проверялось на живой машине. -- Автоматической загрузки обновлений нет: есть проверка происхождения, backup, проверка схемы, откат и `--update-notice`. Публикующего сервера у проекта нет. -- Карточка сравнения источников и провайдеров (F21) не реализована. -- `pipeline.Pipeline`/`run_pipeline` проверяются своими бенчмарками, но продукт сканирует через `proxytool.scan`, который делит с ними бюджеты, шлюз, ledger и политику find-N. +- **Checks are much faster on real-world lists.** A scan no longer waits on its own database lock for every job item, and dead proxies no longer push the number of parallel checks down to one: 3,000 mostly dead candidates now take seconds instead of hours. Running out of file descriptors is no longer recorded as a dead proxy. +- **The database no longer grows without limit under `--watch`.** Each source keeps its last three downloaded lists; older ones are pruned right after a collection, and `backup retention` cleans up history left by earlier versions. A list the server reports as unchanged is re-applied to collections that lost it, and a retry after a broken download no longer counts the first attempt against the size limit. +- **Collecting is faster and reads more lists.** Addresses are written in batches (a full collection of the 106 default feeds went from 133 s to 79 s); four sources that returned nothing (hideip.me, spys.me and others with `ip:port` lines and comments) now return addresses; a list that exceeds the size limit is reported as a partial read instead of a failing provider and is no longer put into backoff; a list without country data no longer erases a country learned elsewhere; cached lists are re-read after a failed or refused download. +- **Control API checked operation by operation.** The audit log is written; a key limited to one collection or pool can no longer act on others through body or query fields; event streams deliver events; result paging moves past the first page and every declared filter and sort works; unknown jobs, pools and sources answer 404; refreshing a source returns a job; PUT and wrong methods get JSON errors; `localhost` reaches `/v1`. +- The web interface no longer puts the administrator key in a URL. +- Collections can be renamed, archived and restored through the API with revision checks; merge and replace work; members are validated; pools and schedules refuse unknown profiles and collections; gateway settings and bindings set through the API are stored and listed; an active key must be revoked before it is deleted; with `serve --host 0.0.0.0` the API accepts the machine's own addresses and hostname. +- **Stopping and resuming works.** A stopped or crashed check no longer leaves its job running, which made every later check fail with “Busy”; running the same command again continues where it stopped without re-measuring finished addresses. +- **`--watch` really re-checks.** Every round now measures the passing proxies again; before, rounds after the first measured nothing and republished old results. +- **A busy host no longer holds up other hosts**, and `--want` stops as soon as the target is reached even when workers waited for a host (30 ports on one IP with `--want 5`: 8 measured instead of 30). +- `hostport.txt` lists an address once even when it passed as several protocols; a speed test sample below 1 MiB is refused because it can never give a result. +- The chosen interface language is kept after a restart; before, ten of the twelve languages fell back to English on the next start. +- Results table cells stay under their own headers when some columns are hidden. +- Results table text is readable in the light theme. +- A fresh failure now withdraws an older success, so a published list no longer serves an address the latest check rejected. +- Retention cleanup runs instead of being rolled back by SQLite. +- Keys limited to one collection can no longer read other collections' jobs, profiles, sources, schedules or artifacts. +- `--max-requests` and `--run-max-bytes` actually limit a run. +- Pool refill, start, pause and member listing through the API work. +- Collecting treats HTTP 304 as a cached answer, not an empty list; oversized sources are capped without losing already parsed data. +- Windows: time zones, HTTP handling and coarse-clock timing issues. +- Windows installer: the “Command line” shortcuts open a console with the CLI instead of doing nothing, and a new PATH entry works in new consoles without signing out. +- Windows: the app can be quit from the Start menu (“Quit Proxy Workbench”, or `proxy-workbench --quit`), and uninstalling quits a running app first. + +### Known limitations + +- Checking your own proxies that require a login is not supported yet: the checker refuses credentials in proxy URLs (the gateway can use them). +- The menu-bar icon exists on macOS only; sleep/wake is not detected natively on Windows. +- Builds are not code-signed or notarized: macOS will ask you to confirm the first launch, Windows SmartScreen may warn. +- There is no automatic updater; the app can tell you an update exists. +- Gateway settings saved through the API are stored and listed but not yet applied when the gateway starts; the command line and interface options are used. +- The Windows uninstaller leaves the optional PATH entry in place. +- Figures in this release come from local tests and mock services; the quality of public proxies was not measured. ## [2.2.1] — 2026-09-25 diff --git a/README.md b/README.md index d90d56f..0907c0c 100644 --- a/README.md +++ b/README.md @@ -4,9 +4,11 @@ # Proxy Workbench -**Collect free public proxies from a catalog of 150 entries with 106 collectable feeds, test every one against _your_ services, and keep only the fast, stable, clean and anonymous ones.** +### Finds free proxies that actually work — on the sites you need -Local browser GUI (English / Russian) + CLI · HTTP / HTTPS (CONNECT) / SOCKS5 · anonymity levels · resumable · no accounts, no telemetry +Proxy Workbench collects free proxies from **150 public sources**, tests every one against the sites and services **you** care about, and keeps only the ones that work. You get ready-made lists, one **rotating proxy** for your browser, Telegram and any app, or an **API** for your scripts. + +Runs on your own computer: macOS and Windows app, command line, Docker · HTTP, HTTPS, SOCKS4, SOCKS5 · 12 languages · no sign-up, no telemetry ![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-3776AB?logo=python&logoColor=white) ![License: MIT](https://img.shields.io/badge/license-MIT-2ea44f) @@ -16,27 +18,25 @@ Local browser GUI (English / Russian) + CLI · HTTP / HTTPS (CONNECT) / SOCKS5 **English** · [Русский](README.ru.md) -[Quick start](#-quick-start) · [Features](#-features) · [How it works](#-how-it-works) · [CLI](#-command-line) · [FAQ](#-faq) · [Roadmap](#-roadmap) · [Contributing](CONTRIBUTING.md) +[Quick start](#-quick-start) · [Features](#-features) · [How it works](#-how-it-works) · [CLI](#-command-line) · [FAQ](#-faq) · [Roadmap](#-roadmap)
Proxy Workbench demo: scan, rank, filter elite proxies -15-second tour: start a scan → ranking → “Elite only” filter → per-attempt details → EN/RU switch (synthetic data). +Quick tour: set up a check → ranking → “Elite only” filter → per-attempt details → sources → switching language (synthetic data). --- -## Why - -Free proxy lists are everywhere, but most of what they contain is dead, slow, or blocked by the site you actually care about. A proxy that answers `example.com` may still fail your API, return a captcha page with status `200`, or sit on a spam blacklist. +## What it does -**Proxy Workbench answers one practical question: _which of these proxies really work for my service, right now, and how well?_** +Free proxy lists are everywhere, but most addresses in them are dead, slow or blocked by exactly the site you care about. Proxy Workbench does the tedious part for you: -- It gathers candidates from dozens of public lists (or your own files) and de-duplicates them. -- It sends **real HTTP(S) requests through each proxy** to every service you specify — several times — and checks status codes, body text, or even a SHA-256 of the response. -- It ranks survivors by **median latency, jitter and success rate**, flags **blacklisted IPs** (local denylist + optional DNSBL), rates **anonymity** (transparent / anonymous / elite) and exports TXT / CSV / JSON plus ready-to-use `host:port` lists per protocol. +1. **Collect.** Downloads addresses from 150 public sources (106 enabled out of the box) or your own files and removes duplicates. +2. **Check.** Sends real requests through every proxy to your sites — several times — and checks the status code, required text on the page and speed. It also finds the country, the anonymity level (transparent / anonymous / elite) and whether the IP is blacklisted. +3. **Deliver.** The best proxies land in TXT / CSV / JSON files, browser, Clash and sing-box configs, a rotating proxy at `127.0.0.1:8899`, and an API. Pools and schedules keep the list fresh on their own. Everything runs on your machine. The GUI binds to `127.0.0.1` only. @@ -53,7 +53,7 @@ Everything runs on your machine. The GUI binds to `127.0.0.1` only. -Screenshots use synthetic data from documentation IP ranges (RFC 5737). The interface is available in English and Russian (EN/RU toggle in the header). +Screenshots use synthetic data from documentation IP ranges (RFC 5737). The interface speaks 12 languages (language menu in the header). ## ✨ Features @@ -83,8 +83,15 @@ Everything runs on your machine. The GUI binds to `127.0.0.1` only. | **Exit country** | The anonymity judge also reports the address the traffic really leaves from; the table shows `DE → NL` when it differs from the proxy's own country. | | **Local API for your code** | The GUI (or `serve` on a server) answers `GET /random?protocol=socks5&country=DE` or `/proxies?max_latency=800&format=txt` with the freshest working proxies, so scripts, scrapers and bots can pick a proxy with one HTTP request. | | **Safe by default** | Loopback-only GUI with a per-session token, CSRF/Host checks, SSRF-hardened source fetching (no private/metadata IPs, validated redirects, size limits), credential-like headers rejected. | -| **English & Russian UI** | Switch with the EN/RU button; defaults to your browser language. Dark and light themes. | -| **Zero setup** | A Windows `.exe` that needs nothing else, `pipx install`, Docker Compose, or a double-click launcher that creates its own virtual environment. | +| **Desktop app** | Runs in the macOS menu bar with pause/start, optional start at login and one running instance; recovers correctly after sleep. The browser interface opens from it. | +| **Pools** | A named pool keeps N working proxies for a profile, with a reserve, quotas and budgets; it refills and re-checks itself and says why it is short. | +| **Schedules** | Re-check a collection or a pool on an interval in your time zone, with quiet hours, request/byte budgets and notifications when a proxy changes state. | +| **Profiles and import** | Save targets and rules as named profiles with revisions. Import your own lists from TXT, URI, CSV, JSON, Clash or sing-box with a preview, column mapping and a report of every rejected line. | +| **API keys** | Named keys with permissions, collection/pool scope, rate and concurrency limits, expiry, rotation and an audit log — on the **Keys** page or with `api-key`. | +| **Diagnostics** | A funnel shows where candidates were lost, “why 0 results” explains an empty run in plain words, and a redacted diagnostic bundle can be reviewed before saving. | +| **Backup and restore** | Backups, restore, rollback and retention cleanup, each previewed before it runs; data folders from older versions are upgraded automatically with a backup taken first. | +| **12 languages** | English, Russian, Ukrainian, German, Spanish, French, Italian, Portuguese, Polish, Turkish, Japanese and Chinese; defaults to your system language. Redesigned dark and light themes that adapt to phones and tablets. | +| **Zero setup** | A macOS `.dmg`, a Windows installer (or portable `.zip`), `pipx install`, Docker Compose, or a double-click launcher that creates its own virtual environment. | ## 🚀 Quick start @@ -92,7 +99,7 @@ Pick one way to install: | Way | How | Needs | | --- | --- | --- | -| **macOS app** | Download `proxy-workbench-…-macos-arm64.dmg` from the [latest release](https://github.com/DavidVoitenko/proxy-workbench/releases/latest) and drag `Proxy Workbench.app` into Applications | macOS 11+, Apple Silicon | +| **macOS app** | Download `proxy-workbench-…-macos-arm64.dmg` from the [latest release](https://github.com/DavidVoitenko/proxy-workbench/releases/latest) and drag `Proxy Workbench.app` into Applications | macOS 11+, Apple Silicon (`arm64`) or Intel (`x86_64`) | | **Windows app** | Download `proxy-workbench-…-windows-x64-setup.exe` from the [latest release](https://github.com/DavidVoitenko/proxy-workbench/releases/latest) and run it; there is a portable `.zip` too, and a separate `proxy-workbench-cli.exe` for the command line | nothing else | | **pipx** (Windows, macOS, Linux) | `pipx install git+https://github.com/DavidVoitenko/proxy-workbench` then `proxy-workbench` | Python 3.11+ and [pipx](https://pypa.io/pipx/) | | **Source folder** | Download the code (**Code → Download ZIP** or `git clone`), then double-click `Start.bat` (Windows) / `Start.command` (macOS) or run `./run.sh` (Linux) | Python 3.11+ | @@ -107,7 +114,7 @@ proxy-workbench --no-desktop # the same, spelled the other way proxy-workbench --print-paths # which data/cache/log folders this launch would use ``` -Installed builds keep their data in your own per-user folders (`%LOCALAPPDATA%\proxy-workbench`, `~/Library/Application Support/proxy-workbench` or `~/.local/share/proxy-workbench`) and never write into their own program folder; a source checkout keeps `data/` next to the project; `PROXY_WORKBENCH_DATA` overrides all of it. Portable mode is opt-in — see [docs/packaging/README.md](docs/packaging/README.md). +Installed builds keep their data in your own per-user folders (`%LOCALAPPDATA%\proxy-workbench`, `~/Library/Application Support/proxy-workbench` or `~/.local/share/proxy-workbench`) and never write into their own program folder; a source checkout keeps `data/` next to the project; `PROXY_WORKBENCH_DATA` overrides all of it. Portable mode is opt-in: put an empty `proxy-workbench-portable.json` next to the program and it keeps its data beside itself. Release artifacts are **not code-signed**: this project has no signing certificate, and the release notes and the manifest say `signed: false` rather than claiming otherwise. macOS Gatekeeper therefore asks you to confirm the first start, and Windows SmartScreen may too (**More info → Run anyway**). Every release lists its SHA-256 checksum, which proves the file is the one that was published — it does not identify a publisher. @@ -283,7 +290,7 @@ curl -x socks5h://127.0.0.1:8899 https://example.org/ On a server, start it with `./run.sh gateway` and narrow the pool with the usual filters, for example `gateway --protocol socks5 --country DE --max-latency 1500`. Binding to a network address (`--host 0.0.0.0`) requires a password: `--gateway-token `, or the `PROXY_WORKBENCH_GATEWAY_TOKEN` variable; when it is not given the gateway makes one and prints it. Clients then log in with any user name and that password, over HTTP Basic or SOCKS5 user/password. -**The gateway password is not the API token.** They are separate identities on purpose (`CONTRACTS §5.1`): whoever knows the password you handed to a phone must not be able to read the published snapshot, and a leaked API token must not be a working proxy. Pass `--api-token` to `serve` and `--gateway-token` to `gateway`; `compose.yml` shows both variables. +**The gateway password is not the API token.** They are separate identities on purpose: whoever knows the password you handed to a phone must not be able to read the published snapshot, and a leaked API token must not be a working proxy. Pass `--api-token` to `serve` and `--gateway-token` to `gateway`; `compose.yml` shows both variables. Browser without extensions: use `http://127.0.0.1:8765/pac` as the automatic proxy configuration URL. It serves the 10 best matching proxies and accepts the same filters as the API, for example `/pac?country=DE`. `/clash` returns a complete Clash / Mihomo config. @@ -393,7 +400,7 @@ Everything is written to one data folder. Which folder that is depends on how yo | Installed build (`.app`, `.exe`) | your own per-user folders: `~/Library/Application Support/proxy-workbench` on macOS, `%LOCALAPPDATA%\proxy-workbench` on Windows, `$XDG_DATA_HOME/proxy-workbench` on Linux | | Portable build (only if you ask for it) | next to the program, inside the `.app` or beside the `.exe` | -An installed program **never** writes into its own folder: `.app` bundles and `Program Files` are read-only, and a build that tried would not start. Portable mode is opt-in and never happens just because a folder happens to be writable — see `docs/packaging/README.md`. +An installed program **never** writes into its own folder: `.app` bundles and `Program Files` are read-only, and a build that tried would not start. Portable mode is opt-in (a `proxy-workbench-portable.json` file next to the program) and never happens just because a folder happens to be writable. | Path | Content | | --- | --- | @@ -417,7 +424,7 @@ Delete it any time with `./run.sh clear-data --yes` or the button on the **How i ## ❓ FAQ **Does this make me anonymous?** -No. Proxy Workbench measures _reachability and latency_. A public proxy sees your IP, your destination and — for plain HTTP — your traffic. Never send passwords, cookies or tokens through untrusted public proxies. See [PRIVACY.md](PRIVACY.md). +No. Proxy Workbench measures _reachability and latency_. A public proxy sees your IP, your destination and — for plain HTTP — your traffic. Never send passwords, cookies or tokens through untrusted public proxies. Proxy Workbench itself sends no telemetry and has no accounts. **How long does a full scan take?** It depends on how many candidates respond. With the defaults (3 attempts, 8 s request timeout, 4 s connect timeout, fail-fast, 128 workers) even ~190,000 completely dead addresses take about 3.5 hours, because each dead proxy is dropped after two short connect failures; in practice most fail much faster. Raise `--workers`, lower `--connect-timeout`, or use fewer sources for quicker runs. You can stop and resume at any time. @@ -457,8 +464,15 @@ Checking public lists is generally fine, but you are responsible for respecting ## 🗺 Roadmap -- [x] English interface with an EN/RU switch -- [ ] `pipx install` / PyPI package and a single `proxy-workbench` command +- [x] Interface in 12 languages +- [x] `pipx install` and a single `proxy-workbench` command +- [x] Desktop app: macOS menu bar, Windows installer, per-user data folders +- [x] Persistent pools, schedules, profiles with revisions and list import +- [x] API keys with permissions, scope, rotation and audit +- [x] Diagnostics funnel, backups and restore with preview +- [ ] Checking proxies that need a login +- [ ] Signed and notarized builds, automatic updates +- [ ] PyPI package - [x] Anonymity level detection (transparent / anonymous / elite) - [x] Per-protocol `host:port` exports - [x] Country column and filters from a local GeoIP database @@ -471,13 +485,13 @@ Have an idea? Open a [feature request](../../issues/new/choose) or start a [disc ## 🤝 Contributing -Contributions of every size are welcome — bug reports, new sources, docs, translations and code. Read [CONTRIBUTING.md](CONTRIBUTING.md) to get started. Tests run entirely on local mocks: +Bug reports, new sources, translations and code are welcome — open an [issue](../../issues) or a pull request. Tests run entirely on local mocks: ```sh python -m unittest discover -s tests -v ``` -Please also read the [Code of Conduct](CODE_OF_CONDUCT.md). Found a vulnerability? Follow [SECURITY.md](SECURITY.md) and report it privately. +Found a vulnerability? Please report it privately through [GitHub security advisories](../../security/advisories/new) rather than a public issue. If Proxy Workbench saved you time, **a ⭐ on GitHub helps other people find it.** diff --git a/README.ru.md b/README.ru.md index f369889..a5c3a87 100644 --- a/README.ru.md +++ b/README.ru.md @@ -4,9 +4,11 @@ # Proxy Workbench -**Собирает бесплатные публичные прокси из каталога на 150 записей, включая 98 доступных для сбора лент, проверяет каждый на _ваших_ сервисах и оставляет только быстрые, стабильные, чистые и анонимные.** +### Находит бесплатные прокси, которые реально работают — на нужных вам сайтах -Локальный GUI в браузере (русский / английский) + CLI · HTTP / HTTPS (CONNECT) / SOCKS5 · уровни анонимности · продолжение после остановки · без аккаунтов и телеметрии +Программа сама собирает бесплатные прокси из **150 открытых источников**, проверяет каждый на тех сайтах и сервисах, которые нужны **именно вам**, и оставляет только рабочие. Результат — готовые списки, один **ротирующий прокси** для браузера, Telegram и любых программ или **API** для ваших скриптов. + +Работает на вашем компьютере: приложение для macOS и Windows, командная строка, Docker · HTTP, HTTPS, SOCKS4, SOCKS5 · 12 языков · без регистрации и телеметрии ![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-3776AB?logo=python&logoColor=white) ![License: MIT](https://img.shields.io/badge/license-MIT-2ea44f) @@ -22,7 +24,7 @@ Демо Proxy Workbench: проверка, рейтинг, фильтр элитных прокси -15 секунд: запуск проверки → рейтинг → фильтр «только элитные» → детали попыток → переключение EN/RU (синтетические данные). +Коротко: настройка проверки → рейтинг → фильтр «только элитные» → детали попыток → источники → смена языка (синтетические данные). @@ -30,15 +32,13 @@ > **Статус:** публичная beta. Проект измеряет доступность и задержку; он не обещает анонимность, безопасность или стабильную работу сторонних прокси. -## Зачем это нужно - -Списков бесплатных прокси много, но большая часть адресов в них мёртвые, медленные или заблокированы именно на том сайте, который вам нужен. Прокси, который открывает `example.com`, может не работать с вашим API, отдавать капчу с кодом `200` или находиться в спам-блеклисте. +## Что делает программа -**Proxy Workbench отвечает на практический вопрос: _какие из этих прокси действительно работают с моим сервисом прямо сейчас и насколько хорошо?_** +Списков бесплатных прокси много, но большинство адресов в них мёртвые, медленные или заблокированы как раз на том сайте, который вам нужен. Proxy Workbench делает всю грязную работу за три шага: -- Собирает кандидатов из десятков публичных списков (или ваших файлов) и убирает дубликаты. -- Делает **настоящие HTTP(S)-запросы через каждый прокси** ко всем указанным сервисам — несколько раз — и проверяет HTTP-код, текст ответа или SHA-256. -- Ранжирует прошедшие по **медианной задержке, разбросу и доле успехов**, отмечает **адреса из блеклистов** (локальный denylist + опциональные DNSBL), определяет **уровень анонимности** (прозрачный / анонимный / элитный) и экспортирует TXT / CSV / JSON и готовые списки `host:port` по протоколам. +1. **Собирает.** Скачивает адреса из 150 открытых источников (106 подключены сразу) или из ваших файлов и убирает дубликаты. +2. **Проверяет.** Отправляет через каждый прокси настоящие запросы к вашим сайтам — по несколько раз — и смотрит код ответа, нужный текст на странице и скорость. Дополнительно определяет страну, анонимность (прозрачный / анонимный / элитный) и чистоту IP. +3. **Отдаёт готовое.** Лучшие прокси — в файлах TXT / CSV / JSON, в конфигурациях для браузера, Clash и sing-box, через ротирующий прокси `127.0.0.1:8899` или через API. Пулы и расписания держат список свежим сами. Всё работает на вашем компьютере. Интерфейс слушает только `127.0.0.1`. @@ -86,8 +86,15 @@ | **Страна выхода** | Judge показывает, с какого адреса трафик на самом деле выходит в интернет; если страна отличается от страны прокси, в таблице видно `DE → NL`. | | **Готовые конфиги** | `proxy.pac` для браузера и `clash.yaml` для Clash / Mihomo с автоматическим выбором самого быстрого прокси; над файлами сводка по протоколам и странам. | | **Безопасность по умолчанию** | GUI только на loopback с токеном сессии и проверкой Host/Origin, защищённая загрузка источников (без private/metadata IP, проверка redirects, лимиты размера), credential-like заголовки отклоняются. | -| **Русский и английский интерфейс** | Кнопка EN/RU; по умолчанию язык браузера. Тёмная и светлая темы. | -| **Без настройки** | `.exe` для Windows без установки Python, `pipx install`, Docker Compose или запуск двойным кликом, который сам создаёт виртуальное окружение. | +| **Приложение для рабочего стола** | Живёт в меню-баре macOS: пауза и запуск, автозапуск при входе по желанию, один экземпляр, корректное восстановление после сна. Интерфейс в браузере открывается из него. | +| **Пулы** | Именованный пул держит N рабочих прокси для профиля с резервом, квотами и бюджетами; сам пополняется, перепроверяется и объясняет, почему не хватает. | +| **Расписания** | Перепроверка коллекции или пула по интервалу в вашем часовом поясе, тихие часы, бюджеты запросов и трафика, уведомления о смене состояния прокси. | +| **Профили и импорт** | Цели и правила сохраняются как именованные профили с ревизиями. Импорт своих списков из TXT, URI, CSV, JSON, Clash и sing-box с предпросмотром, сопоставлением колонок и отчётом по каждой отклонённой строке. | +| **API-ключи** | Именованные ключи с правами, областью действия (коллекции и пулы), лимитами, сроком, ротацией и журналом аудита — на странице **Ключи** или командой `api-key`. | +| **Диагностика** | Воронка показывает, где потерялись кандидаты; «почему 0 результатов» объясняет пустой прогон простыми словами; диагностический пакет без секретов можно просмотреть перед сохранением. | +| **Резервные копии** | Backup, восстановление, откат и очистка по сроку хранения — каждое действие сначала показывает предпросмотр; папки данных старых версий обновляются автоматически, перед этим делается копия. | +| **12 языков** | Русский, английский, украинский, немецкий, испанский, французский, итальянский, португальский, польский, турецкий, японский и китайский; по умолчанию язык системы. Переработанные тёмная и светлая темы, адаптация под телефоны и планшеты. | +| **Без настройки** | `.dmg` для macOS, установщик (или portable `.zip`) для Windows, `pipx install`, Docker Compose или запуск двойным кликом, который сам создаёт виртуальное окружение. | ## 🚀 Быстрый старт @@ -95,7 +102,7 @@ | Способ | Как | Что нужно | | --- | --- | --- | -| **Программа для macOS** | Скачайте `proxy-workbench-…-macos-arm64.dmg` из [последнего релиза](https://github.com/DavidVoitenko/proxy-workbench/releases/latest) и перетащите `Proxy Workbench.app` в «Программы» | macOS 11+, Apple Silicon | +| **Программа для macOS** | Скачайте `proxy-workbench-…-macos-arm64.dmg` из [последнего релиза](https://github.com/DavidVoitenko/proxy-workbench/releases/latest) и перетащите `Proxy Workbench.app` в «Программы» | macOS 11+, Apple Silicon (`arm64`) или Intel (`x86_64`) | | **Программа для Windows** | Скачайте `proxy-workbench-…-windows-x64-setup.exe` из [последнего релиза](https://github.com/DavidVoitenko/proxy-workbench/releases/latest) и запустите установщик; есть portable-архив `.zip` и отдельный `proxy-workbench-cli.exe` для командной строки | больше ничего | | **pipx** (Windows, macOS, Linux) | `pipx install git+https://github.com/DavidVoitenko/proxy-workbench`, затем `proxy-workbench` | Python 3.11+ и [pipx](https://pypa.io/pipx/) | | **Папка с кодом** | Скачайте код (**Code → Download ZIP** или `git clone`) и запустите, как в таблице ниже | Python 3.11+ | @@ -110,7 +117,7 @@ proxy-workbench --no-desktop # то же самое, другими слов proxy-workbench --print-paths # какие папки data/cache/logs выберет этот запуск ``` -Установленная сборка хранит данные в персональных папках пользователя (`%LOCALAPPDATA%\proxy-workbench`, `~/Library/Application Support/proxy-workbench` или `~/.local/share/proxy-workbench`) и **никогда** не пишет в собственную папку программы; исходники продолжают использовать `data/` рядом с проектом; переменная `PROXY_WORKBENCH_DATA` задаёт папку явно. Portable mode включается только по явному запросу — см. [docs/packaging/README.md](docs/packaging/README.md). +Установленная сборка хранит данные в персональных папках пользователя (`%LOCALAPPDATA%\proxy-workbench`, `~/Library/Application Support/proxy-workbench` или `~/.local/share/proxy-workbench`) и **никогда** не пишет в собственную папку программы; исходники продолжают использовать `data/` рядом с проектом; переменная `PROXY_WORKBENCH_DATA` задаёт папку явно. Portable-режим включается только явно: положите пустой файл `proxy-workbench-portable.json` рядом с программой, и она будет хранить данные рядом с собой. Артефакты релизов **не подписаны сертификатом**: у проекта нет ключа подписи, и в заметках о релизе и в манифесте стоит `signed: false`, а не утверждение о подписи. Поэтому при первом запуске macOS попросит подтвердить открытие, а SmartScreen может попросить то же (**Подробнее → Выполнить в любом случае**). У каждого релиза опубликована контрольная сумма SHA-256: она доказывает, что файл именно тот, что опубликован, но не называет издателя. @@ -374,7 +381,7 @@ curl -x socks5h://127.0.0.1:8899 https://example.org/ На сервере шлюз запускает `./run.sh gateway`; пул сужается обычными фильтрами, например `gateway --protocol socks5 --country DE --max-latency 1500`. Для сетевого адреса (`--host 0.0.0.0`) нужен пароль: `--gateway-token <секрет>` или переменная `PROXY_WORKBENCH_GATEWAY_TOKEN`; если он не задан, шлюз придумывает свой и печатает его. Клиенты входят с любым именем и этим паролем через HTTP Basic или логин/пароль SOCKS5. -**Пароль шлюза — не токен API.** Это разные идентичности намеренно (CONTRACTS §5.1): тот, кому вы дали пароль для телефона в сети, не должен читать опубликованный снапшот, а утёкший токен API не должен работать как прокси. `serve` получает `--api-token`, `gateway` — `--gateway-token`; в `compose.yml` показаны обе переменные. +**Пароль шлюза — не токен API.** Это разные идентичности намеренно: тот, кому вы дали пароль для телефона в сети, не должен читать опубликованный снапшот, а утёкший токен API не должен работать как прокси. `serve` получает `--api-token`, `gateway` — `--gateway-token`; в `compose.yml` показаны обе переменные. Браузер без расширений: укажите `http://127.0.0.1:8765/pac` как адрес автоматической настройки прокси. Он отдаёт 10 лучших подходящих прокси и принимает те же фильтры, что API, например `/pac?country=DE`. `/clash` возвращает готовый конфиг Clash / Mihomo. @@ -498,7 +505,7 @@ docker run -d --name pw-gateway -p 127.0.0.1:8899:8899 -e PROXY_WORKBENCH_API_TO - `maintenance.py` — блокировка папки `data` и очистка локальных данных; - `sources.json` — встроенные источники. - `proxytool.py`, `gui.py` — запуск из папки с кодом (их вызывают `Start.bat`, `Start.command`, `run.sh`). -- `packaging/` — сборка `.app`/`.dmg` для macOS и GUI/CLI `.exe` + per-user installer для Windows (PyInstaller), сборка helper меню-бара, манифест артефактов и сквозные проверки собранного пакета. Подробности и честная матрица проверенных сборок — в [`docs/packaging/README.md`](docs/packaging/README.md). +- `packaging/` — сборка `.app`/`.dmg` для macOS и GUI/CLI `.exe` + per-user installer для Windows (PyInstaller), сборка helper меню-бара, манифест артефактов и сквозные проверки собранного пакета. - `compose.yml` — проверка, API и ротирующий прокси в Docker. - `tests/` — isolated unit and local mock tests. - `docs/assets/` — скриншоты и изображение для превью. @@ -524,7 +531,7 @@ docker run -d --name pw-gateway -p 127.0.0.1:8899:8899 -e PROXY_WORKBENCH_API_TO ## ❓ Частые вопросы **Это делает меня анонимным?** -Нет. Proxy Workbench измеряет _доступность и задержку_. Публичный прокси видит ваш IP, адрес назначения и — для обычного HTTP — сам трафик. Не отправляйте пароли, cookies и токены через непроверенные публичные прокси. См. [PRIVACY.md](PRIVACY.md). +Нет. Proxy Workbench измеряет _доступность и задержку_. Публичный прокси видит ваш IP, адрес назначения и — для обычного HTTP — сам трафик. Не отправляйте пароли, cookies и токены через непроверенные публичные прокси. Сам Proxy Workbench не отправляет телеметрию и не требует аккаунтов. **Почему прокси работает в браузере, а здесь не прошёл?** Редиректы не выполняются, TLS-сертификаты проверяются, а каждый сервис должен пройти свой порог. Откройте **Детали** — там ошибка каждой попытки. @@ -546,8 +553,15 @@ IP нет в вашем локальном denylist и (если включен ## 🗺 Планы -- [x] Английский интерфейс и переключатель EN/RU -- [ ] Установка через `pipx` / PyPI и единая команда `proxy-workbench` +- [x] Интерфейс на 12 языках +- [x] Установка через `pipx` и единая команда `proxy-workbench` +- [x] Приложение: меню-бар macOS, установщик Windows, персональные папки данных +- [x] Постоянные пулы, расписания, профили с ревизиями и импорт списков +- [x] API-ключи с правами, областью действия, ротацией и аудитом +- [x] Воронка диагностики, резервные копии и восстановление с предпросмотром +- [ ] Проверка прокси с логином и паролем +- [ ] Подписанные сборки и автообновление +- [ ] Пакет на PyPI - [x] Определение уровня анонимности (transparent / anonymous / elite) - [x] Экспорт `host:port` по протоколам - [x] Колонка страны и фильтры по локальной базе GeoIP @@ -560,7 +574,7 @@ IP нет в вашем локальном denylist и (если включен ## 🤝 Участие -Рады любому вкладу: баг-репорты, новые источники, документация, переводы и код. Начните с [CONTRIBUTING.md](CONTRIBUTING.md), соблюдайте [Code of Conduct](CODE_OF_CONDUCT.md). Уязвимости сообщайте приватно по [SECURITY.md](SECURITY.md). +Рады баг-репортам, новым источникам, переводам и коду — откройте [issue](../../issues) или pull request. Об уязвимостях сообщайте приватно через [GitHub security advisories](../../security/advisories/new), а не в публичном issue. Если проект сэкономил вам время — **поставьте ⭐, это помогает другим его найти.** diff --git a/compose.yml b/compose.yml index 3877cef..11beccd 100644 --- a/compose.yml +++ b/compose.yml @@ -10,8 +10,8 @@ # the read-only API; `PROXY_WORKBENCH_GATEWAY_TOKEN` is the password a proxy client # gives the gateway. They are deliberately never the same value: whoever knows the # gateway password (a phone on the LAN, a QR code) must not be able to read the -# published snapshot, and a leaked API token must not be a working proxy -# (CONTRACTS §5.1, defect 18). Leave the gateway variable unset and the gateway +# published snapshot, and a leaked API token must not be a working proxy. +# Leave the gateway variable unset and the gateway # makes its own password and prints it in its log. # # Edit the check command to test your own service: --url https://example.org/health diff --git a/docs/assets/demo.gif b/docs/assets/demo.gif index 4da5fb3..1e98757 100644 Binary files a/docs/assets/demo.gif and b/docs/assets/demo.gif differ diff --git a/docs/assets/screenshots/details-dark.png b/docs/assets/screenshots/details-dark.png index ce2ca38..ead8005 100644 Binary files a/docs/assets/screenshots/details-dark.png and b/docs/assets/screenshots/details-dark.png differ diff --git a/docs/assets/screenshots/results-dark.png b/docs/assets/screenshots/results-dark.png index 02c740b..e606226 100644 Binary files a/docs/assets/screenshots/results-dark.png and b/docs/assets/screenshots/results-dark.png differ diff --git a/docs/assets/screenshots/results-light.png b/docs/assets/screenshots/results-light.png index 93c7896..aee9def 100644 Binary files a/docs/assets/screenshots/results-light.png and b/docs/assets/screenshots/results-light.png differ diff --git a/docs/assets/screenshots/ru/details-dark.png b/docs/assets/screenshots/ru/details-dark.png index d7b03b5..f9e573f 100644 Binary files a/docs/assets/screenshots/ru/details-dark.png and b/docs/assets/screenshots/ru/details-dark.png differ diff --git a/docs/assets/screenshots/ru/results-dark.png b/docs/assets/screenshots/ru/results-dark.png index c534f74..b47d3b9 100644 Binary files a/docs/assets/screenshots/ru/results-dark.png and b/docs/assets/screenshots/ru/results-dark.png differ diff --git a/docs/assets/screenshots/ru/results-light.png b/docs/assets/screenshots/ru/results-light.png index 7870c92..d7c58b6 100644 Binary files a/docs/assets/screenshots/ru/results-light.png and b/docs/assets/screenshots/ru/results-light.png differ diff --git a/docs/assets/screenshots/ru/scan-dark.png b/docs/assets/screenshots/ru/scan-dark.png index a479c4a..270802f 100644 Binary files a/docs/assets/screenshots/ru/scan-dark.png and b/docs/assets/screenshots/ru/scan-dark.png differ diff --git a/docs/assets/screenshots/scan-dark.png b/docs/assets/screenshots/scan-dark.png index 7d85f1f..2201610 100644 Binary files a/docs/assets/screenshots/scan-dark.png and b/docs/assets/screenshots/scan-dark.png differ diff --git a/docs/assets/social-preview.png b/docs/assets/social-preview.png index 433ba22..a7f55bb 100644 Binary files a/docs/assets/social-preview.png and b/docs/assets/social-preview.png differ diff --git a/docs/index.html b/docs/index.html index 16ce6e9..c2e4cd2 100644 --- a/docs/index.html +++ b/docs/index.html @@ -4,11 +4,11 @@ Proxy Workbench — free proxy checker for your own sites - + - + @@ -67,13 +67,13 @@

Find every free proxy.
Keep the ones that work.

-

Proxy Workbench collects public HTTP, HTTPS, SOCKS4 and SOCKS5 proxies from 55 open lists and web pages, tests every one against your own sites, rates anonymity and drops blacklisted IPs, all on your own machine.

+

Proxy Workbench collects public HTTP, HTTPS, SOCKS4 and SOCKS5 proxies from a catalog of 150 sources (106 collected out of the box), tests every one against your own sites, rates anonymity and drops blacklisted IPs, all on your own machine.

-
Free & open source (MIT) · Windows · macOS · Linux · Docker · English / Russian
-
Proxy Workbench demo: start a scan, see ranked proxies, filter elite ones
+
Free & open source (MIT) · Windows · macOS · Linux · Docker · 12 languages
+
Proxy Workbench demo: set up a check, see ranked proxies, filter elite ones, open details, switch language
@@ -89,6 +89,10 @@

Why people use it

Real speed and provider

Optional speed test in Mbit/s; every proxy shows its provider, and hosting or data-centre ranges can be skipped.

Built for scrapers

Pick country, protocol and a sticky session in the proxy user name: country-de-session-1. Or script it: proxy-workbench get --top 5.

Rotating proxy gateway

Point a browser, Telegram or any app at 127.0.0.1:8899: every connection goes out through the next working proxy, dead ones are skipped.

+

Desktop app

A macOS menu-bar app and a Windows installer. One running instance, optional start at login, correct recovery after sleep.

+

Pools and schedules

Keep N working proxies per profile with a reserve and budgets, and re-check them on a schedule in your time zone with quiet hours.

+

12 languages, new design

English, Russian, Ukrainian, German, Spanish, French, Italian, Portuguese, Polish, Turkish, Japanese and Chinese. Dark and light themes for desktop, tablet and phone.

+

Keys, diagnostics, backups

API keys with permissions and audit, a funnel that explains an empty result, and backups you can preview before restoring.

Local API for your code

GET /random?protocol=socks5&country=DE returns a fresh working proxy, so scripts and bots pick one with a single request.

@@ -106,8 +110,8 @@

What the anonymity levels mean

Get started in a minute

-
1

Download

Windows: the .exe from the latest release, nothing else needed. Anywhere else: pipx install git+https://github.com/DavidVoitenko/proxy-workbench, or Docker Compose.

-
2

Start it

Double-click the .exe or run proxy-workbench: the interface opens in your browser, together with the local API and the rotating proxy.

+
1

Download

macOS: the .dmg; Windows: the installer or portable .zip from the latest release, nothing else needed. Anywhere else: pipx install git+https://github.com/DavidVoitenko/proxy-workbench, or Docker Compose.

+
2

Start it

Open the app or run proxy-workbench: the interface opens in your browser, together with the local API and the rotating proxy.

3

Check & export

Add your site, press Find and check, then download the best proxies from the Results tab.

Prefer the terminal or a server?

@@ -130,7 +134,7 @@

Private by design