Upstream panels (Remnawave and friends) pin a subscription to one device
through the x-hwid header. Prizma holds that HWID per source, presents it on
every upstream fetch, and hands out its own link that any number of devices
may use. Everything else — the client's User-Agent, the response body, the
profile-title / subscription-userinfo / announce headers — is proxied through
untouched.
Two link kinds behind /sub/{token}:
source byte-for-byte proxy of one upstream, format chosen by the client
group several sources merged into one link: parallel fetch, parse, regex
filtering by node name and by node content, protocol allow-list,
dedupe, rename template, rendered in the negotiated format
Formats parse and render both ways: URI lists, base64, Clash/Mihomo YAML,
sing-box JSON, and Xray JSON including the Happ-style array of whole configs.
A node keeps the raw payload it was born from, so same-format rendering is
byte-identical and no vendor-specific field is ever dropped.
Access control is HWID-based and self-switching: an empty whitelist means
everyone passes except banned devices; whitelisting a single device locks the
links to the whitelist. Every device that fetches a link is recorded with its
UA, IP, hit count and timestamps, and can be banned, whitelisted or labelled
from the panel.
Ships as one static binary with the React admin panel embedded (CGO-free, so
linux/amd64+arm64, windows and darwin cross-compile from anywhere), as a
docker image, and with Gitea CI that gates releases on the test suite.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
48 lines
1.0 KiB
Plaintext
48 lines
1.0 KiB
Plaintext
# Keep the build context small and, more importantly, HERMETIC: the image must
|
|
# be built from sources only, never from whatever happens to be lying around in
|
|
# a developer's working tree.
|
|
|
|
.git
|
|
.gitea
|
|
.gitignore
|
|
.dockerignore
|
|
|
|
# Host-built artifacts. The image builds its own; copying a linux/amd64 binary
|
|
# from a Windows checkout (or vice versa) would silently poison the image.
|
|
dist/
|
|
prizma
|
|
prizma.exe
|
|
*.test
|
|
|
|
# node_modules is reinstalled by `npm ci` inside the node stage — a host copy
|
|
# carries the host's optional platform binaries (esbuild/rollup) and breaks the
|
|
# alpine build.
|
|
web/node_modules
|
|
web/dist
|
|
node_modules
|
|
|
|
# The SPA is copied in from the node stage; the committed placeholder would
|
|
# otherwise shadow it if the copy order ever changed.
|
|
internal/webui/dist
|
|
|
|
# Live state and secrets must never enter an image layer.
|
|
data/
|
|
*.db
|
|
*.db-wal
|
|
*.db-shm
|
|
.env
|
|
.env.*
|
|
!.env.example
|
|
|
|
# Docs and examples do not affect the binary.
|
|
docs/
|
|
*.md
|
|
!README.md
|
|
docker-compose*.yml
|
|
LICENSE
|
|
|
|
.idea/
|
|
.vscode/
|
|
.DS_Store
|
|
Thumbs.db
|