Upstream panels (Remnawave and friends) pin a subscription to one device
through the x-hwid header. Prizma holds that HWID per source, presents it on
every upstream fetch, and hands out its own link that any number of devices
may use. Everything else — the client's User-Agent, the response body, the
profile-title / subscription-userinfo / announce headers — is proxied through
untouched.
Two link kinds behind /sub/{token}:
source byte-for-byte proxy of one upstream, format chosen by the client
group several sources merged into one link: parallel fetch, parse, regex
filtering by node name and by node content, protocol allow-list,
dedupe, rename template, rendered in the negotiated format
Formats parse and render both ways: URI lists, base64, Clash/Mihomo YAML,
sing-box JSON, and Xray JSON including the Happ-style array of whole configs.
A node keeps the raw payload it was born from, so same-format rendering is
byte-identical and no vendor-specific field is ever dropped.
Access control is HWID-based and self-switching: an empty whitelist means
everyone passes except banned devices; whitelisting a single device locks the
links to the whitelist. Every device that fetches a link is recorded with its
UA, IP, hit count and timestamps, and can be banned, whitelisted or labelled
from the panel.
Ships as one static binary with the React admin panel embedded (CGO-free, so
linux/amd64+arm64, windows and darwin cross-compile from anywhere), as a
docker image, and with Gitea CI that gates releases on the test suite.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
19 lines
634 B
Plaintext
19 lines
634 B
Plaintext
# Normalize to LF in the repository. Without this, a Windows checkout with
|
|
# core.autocrlf=true hands CRLF files to CI, and the runner's /bin/sh dies on
|
|
# `\r` in ci/*.sh with the classic "not found" error.
|
|
* text=auto eol=lf
|
|
|
|
# Never touched by line-ending conversion.
|
|
*.png binary
|
|
*.jpg binary
|
|
*.ico binary
|
|
*.gz binary
|
|
*.zip binary
|
|
|
|
# Fixtures are byte-compared by the round-trip tests: any rewrite breaks them.
|
|
internal/subfmt/testdata/live_* -text
|
|
|
|
# Keep generated lockfiles and the vendored SPA placeholder out of diff noise.
|
|
web/package-lock.json linguist-generated=true
|
|
internal/webui/dist/index.html linguist-generated=true
|