nemu-x 说明 mikan 订阅页公告与品牌头的审查修正
nemu-x 在 Miroshka000/mikan 的 PR #27 审查回复中说明已按意见完成修正(提交 d356f8c):X-Hwid-Limit 头改为只在 default 分支设置,与 X-Hwid-Max-Devices-Reached 相邻,避免 v2RayTun 在无代理、无 HWID 等其他原因下也显示设备数限制提示;app/operator_test.go 新增检查——以 v2RayTun 请求且关闭全部入站时不返回这两个头。app/authz_test.go 把五个新设置字段加入「完整 API key 必须返回 403 session_only」的清单。非法的 sub_announce_url 改为返回 support_url_invalid(提示 https:// 或 tg://),url_invalid 只保留给仅支持 https 的 logo。订阅页头与 Renew-URL 改用订阅基础地址(与 bot、计费共用的 subBase)构造,因此跟随订阅端口与域名,仅在面板尚无地址时使用 r.Host。公告链接与 logo 经 subs.ValidLink 校验:url.Parse、https 且带主机(链接另允许 tg://)、不允许空格与控制字符,TestValidLink 覆盖。go vet ./... 与 subs、app、api 测试通过,openapi.json 无变化。
作者原文@Nemu-xThanks, all five done in d356f8c:
X-Hwid-Limitmoved into thedefaultbranch, next toX-Hwid-Max-Devices-Reached. A new check inapp/operator_test.gofetches as v2RayTun with every inbound off and expects neither header.authz_test.go: the five fields are in the list a full key must get403 session_onlyon.- A bad
sub_announce_urlnow returnssupport_url_invalid("https:// or tg://").url_invalidstays only for the logo, which is https only.The two non-blocking ones too:
- The page header and
Renew-URLare built from the subscription base (the samesubBasethe bot and billing use), so they follow the subscription port and domain.r.Hostis used only when the panel has no address yet.- The announcement link and the logo go through
subs.ValidLink:url.Parse, https with a host (ortg://for the link), and no spaces or control characters.TestValidLinkcovers it.
go vet ./...and thesubs,appandapitests pass;openapi.jsondoes not change.