drjones e18bdb1b41 Audit fixes for SMS tool (5 issues)
- XSS: render from_number/code via textContent, drop innerHTML string concat
- Poll throttle: last_check column + 3s min between SMSPool /sms/check calls
- provider_cost: store REAL + CAST in admin SUM (was silently summing text as 0)
- Atomic debit: _debit() with balance_sats >= ? guard, debit-before-provision,
  refund ledger entry on provision failure (no double-spend window)
- _extract_sms: defensive field parsing (text/body/message/content, number/sender/from)
- admin: add PROVIDER COST card (USD)
2026-09-20 20:24:07 -07:00
2026-09-20 20:24:07 -07:00

Clean Proxys — "Pleiades"

Residential + dedicated proxy store, no-KYC, Bitcoin checkout. SOCKS5 & HTTP. clean-proxys.thetempleofdoom.com (Cloudflare fleet tunnel). Node CT 777 @ 10.30.20.178.

What it is

A white-label proxy middleman. Customers (humans and AI agents) buy clean residential/ISP/datacenter proxies with Bitcoin. The gateway authenticates each user, geo-targets their egress through the IPRoyal upstream, and meters GB usage.

Three tiers:

  1. Residential rotating — per-GB, any country/city on the fly.
  2. ISP Dedicated — one clean residential-ISP IP (premium, $4/30d wholesale).
  3. Datacenter Dedicated — one static DC IP (budget, $1.80/30d wholesale).

Architecture

customer / agent
   │ HTTPS
   ▼
CF tunnel → nginx → Flask storefront (gunicorn 127.0.0.1:5000, SQLite)
   │                       ├─ BTCPay webhook → activate on payment
   │                       ├─ /admin (revenue, users, orders, inventory)
   │                       └─ /api/v1/* (agent discovery + one-call purchase)
   ▼
gateway.py (SOCKS5 :1080 + HTTP CONNECT :8080)  ← per-user auth → geo → IPRoyal
   ▼
IPRoyal upstream (geo.iproyal.com:12321 residential / dedicated IPs)

Components

  • gateway.py — asyncio SOCKS5 + HTTP CONNECT relay. Per-user scrypt auth, geo/sticky rewrite, GB byte metering. No traffic-content logging.
  • app.py — Flask storefront + admin + agent API + BTCPay webhook.
  • db.py — SQLite schema + auth helpers (scrypt).
  • iproyal.py — IPRoyal reseller API wrapper (balance/products/orders).
  • admin.py — CLI (create-user, set-country, add-balance, list).
  • provision.py — dedicated-IP provisioning poll (systemd provision.timer).

Services (systemd)

gateway.service, app.service, provision.timer (5-min poll).

Agent API

  • GET /llms.txt — machine-readable service description
  • GET /api/v1/info, GET /api/v1/plans
  • POST /api/v1/proxy — one-call purchase → creds + BTCPay checkout URL
  • GET /api/v1/order/<id> — payment status
  • GET /api/v1/dedicated/locations?product=3|9 — dedicated location catalog

Key facts (IPRoyal)

  • Residential: geo.iproyal.com:12321, geo suffix on the password (_country-US_city-NewYork_session-XXXXXXXX_lifetime-30m).
  • Dedicated: connect directly to the IP — socks5://user:pass@IP:12324, http://user:pass@IP:12323. Order via apid.iproyal.com/v1/reseller (X-Access-Token), poll GET /orders/{id} until confirmed, read proxy_data.proxies[0] = {username, password, ip}.

Deploy

cd ~/pleiades && tar czf /tmp/e.tar.gz . && scp /tmp/e.tar.gz root@10.30.20.85:/tmp/ \
  && ssh root@10.30.20.85 "pct push 777 /tmp/e.tar.gz /tmp/e.tar.gz && pct exec 777 -- \
  bash -c 'cd /opt/pleiades && tar xzf /tmp/e.tar.gz && systemctl restart gateway app'"

config.json holds secrets (gitignored); see config.example.json.

Description
Clean Proxys — residential SOCKS5/HTTP proxy store (CT777, clean-proxys.thetempleofdoom.com)
Readme 351 KiB
Languages
Python 59.5%
HTML 32.4%
CSS 7.3%
Shell 0.8%