Skip to content
colituPublic

About

Colitu VPN for iPhone and iPad: Flutter app + Swift Network Extension with Xray-core, open source (GPL-3.0)

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

14 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Colitu VPN for iOS

Build Release License Colitu Network

English · Русский

The open-source iPhone and iPad client of Colitu VPN. A Flutter interface drives a Swift Network Extension (packet tunnel) that runs Xray-core through libXray, and every account, plan and server detail comes from the Colitu API.

Bundle IDs com.colitu.vpn (app), com.colitu.vpn.tun (packet tunnel)
Minimum iOS 15.0
Languages Russian, English, Turkish (switch instantly in the app)
Install TestFlight (public beta)
Website https://colitu.com
License GPL-3.0

A Colitu account is required to connect. The app has no hard-coded servers: the server list and connection profiles are issued per device by the Colitu API.

Features

  • Automatic protocol selection. Hysteria2, VLESS Reality / XHTTP, Trojan and Shadowsocks endpoints are tried in order, the tunnel is verified with a real request, and the app moves to the next candidate if one fails.
  • Full account flow in the app. Onboarding, sign-in and registration, password reset, approving a TV sign-in by QR code, plan status, devices, usage and a support inbox. Nothing is sold inside the app: plans are bought and renewed in the customer account on app.colitu.com.
  • Server locations with on-device latency and a remembered location.
  • Always-on VPN through iOS on-demand rules, and auto-connect.
  • Optional ad and tracker blocking through Colitu's own DNS servers (DNS-over-HTTPS inside the tunnel; the servers keep no query log).
  • Secure storage. Session tokens live in the iOS Keychain; the tunnel configuration is only shared with the extension through the app group.
  • No tracking. No Firebase, analytics, advertising or crash-reporting SDK. Diagnostics stay on the device until you share a report yourself, with credentials and e-mail addresses masked.

How it connects

  1. POST /auth/login (or /auth/register) returns an access/refresh token pair.
  2. POST /devices/register binds the install to a device slot.
  3. GET /client/bootstrap, /me, /me/usage and /servers fill the UI.
  4. Picking a location calls PUT /me/preferences, then GET /config returns a device-bound configuration envelope with a primary profile and alternatives.
  5. The app turns the envelope into an Xray configuration and starts the packet tunnel. The extension runs Xray with a local SOCKS inbound, and hev-socks5-tunnel turns the tunnel's packets into connections to it (see docs/core-provenance.md).

The app never computes prices, eligibility or device limits itself; the server decides. The endpoints are listed in lib/colitu/api/api_endpoint.dart and summarised in COLITU_API_CONTRACT.md.

Repository layout

Path Contents
lib/colitu/ Colitu API client, account and connection logic, theme, translations
lib/pages/colitu/ Colitu screens (onboarding, sign-in, home, locations, account, support)
lib/service/ Xray configuration builder, VPN service and native bridge
swift/App, swift/Tunnel, swift/All VPN manager, packet tunnel provider and shared Swift code
ios/ Xcode project, app and tunnel targets, entitlements, privacy manifests
c/include/libXray.h C header of libXray; Dart FFI bindings are generated from it
scripts/ libXray build, FFI binding generation, icon generation
test/ Unit tests and golden screenshots of the Colitu screens

Building

You need macOS with Xcode, Flutter (stable), Go and Python 3.

flutter pub get
scripts/build-libxray.sh          # builds swift/All/LibXray.xcframework from source
scripts/generate-ffi-bindings.sh  # regenerates the Dart FFI bindings
flutter analyze --no-fatal-infos
flutter test
flutter build ios --simulator --no-codesign

scripts/build-libxray.sh fetches libXray, Xray-core and hev-socks5-tunnel at pinned commits and fails if they do not match; see docs/core-provenance.md.

Optional build-time settings (--dart-define):

Name Purpose
COLITU_API_BASE_URL API base URL, default https://api.colitu.com/api/v1
COLITU_ADBLOCK_DOH Comma-separated DNS-over-HTTPS URLs of the ad-blocking servers. Without it the ad-blocking switch is hidden.

Running on a device needs your own Apple developer team, bundle IDs, app group and provisioning profiles for both targets. Release builds are made by Codemagic (codemagic.yaml) and uploaded to TestFlight; details are in docs/build.md and docs/release.md.

Security

Please report vulnerabilities privately to [email protected], not in a public issue. See SECURITY.md and the Colitu Security Whitepaper.

Contributing

Bug reports, translation fixes and focused pull requests are welcome; see CONTRIBUTING.md. Account, payment and connection problems are handled by support at https://colitu.com/support.

License

Colitu VPN for iOS is free software under the GNU GPL v3.0. Third-party components and their licences are listed in NOTICE. The Colitu name and logo are not covered by the GPL: if you publish your own build, use your own name and logo.

About

Colitu VPN for iPhone and iPad: Flutter app + Swift Network Extension with Xray-core, open source (GPL-3.0)

Topics

Resources

Code of conduct

Contributing

Security policy

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages