nemu-x 说明 mikan 订阅页公告与品牌头的审查修正

nemu-x 在 Miroshka000/mikan 的 PR #27 审查回复中说明已按意见完成修正(提交 d356f8c):X-Hwid-Limit 头改为只在 default 分支设置,与 X-Hwid-Max-Devices-Reached 相邻,避免 v2RayTun 在无代理、无 HWID 等其他原因下也显示设备数限制提示;app/operator_test.go 新增检查——以 v2RayTun 请求且关闭全部入站时不返回这两个头。app/authz_test.go 把五个新设置字段加入「完整 API key 必须返回 403 session_only」的清单。非法的 sub_announce_url 改为返回 support_url_invalid(提示 https:// 或 tg://),url_invalid 只保留给仅支持 https 的 logo。订阅页头与 Renew-URL 改用订阅基础地址(与 bot、计费共用的 subBase)构造,因此跟随订阅端口与域名,仅在面板尚无地址时使用 r.Host。公告链接与 logo 经 subs.ValidLink 校验:url.Parse、https 且带主机(链接另允许 tg://)、不允许空格与控制字符,TestValidLink 覆盖。go vet ./... 与 subs、app、api 测试通过,openapi.json 无变化。

作者原文

Thanks, all five done in d356f8c:

  1. X-Hwid-Limit moved into the default branch, next to X-Hwid-Max-Devices-Reached. A new check in app/operator_test.go fetches as v2RayTun with every inbound off and expects neither header.
  2. authz_test.go: the five fields are in the list a full key must get 403 session_only on.
  3. A bad sub_announce_url now returns support_url_invalid ("https:// or tg://"). url_invalid stays only for the logo, which is https only.

The two non-blocking ones too:

  • The page header and Renew-URL are built from the subscription base (the same subBase the bot and billing use), so they follow the subscription port and domain. r.Host is used only when the panel has no address yet.
  • The announcement link and the logo go through subs.ValidLink: url.Parse, https with a host (or tg:// for the link), and no spaces or control characters. TestValidLink covers it.

go vet ./... and the subs, app and api tests pass; openapi.json does not change.