Files
omarandClaude Opus 5 9605b906f7
test / go vet + go test + spa build (push) Successful in 6m41s
release / test gate (push) Successful in 17s
release / binaries + release (push) Successful in 56s
release / docker image (push) Successful in 34s
feat: Prizma — a subscription panel in front of other subscription panels
Upstream panels (Remnawave and friends) pin a subscription to one device
through the x-hwid header. Prizma holds that HWID per source, presents it on
every upstream fetch, and hands out its own link that any number of devices
may use. Everything else — the client's User-Agent, the response body, the
profile-title / subscription-userinfo / announce headers — is proxied through
untouched.

Two link kinds behind /sub/{token}:

  source  byte-for-byte proxy of one upstream, format chosen by the client
  group   several sources merged into one link: parallel fetch, parse, regex
          filtering by node name and by node content, protocol allow-list,
          dedupe, rename template, rendered in the negotiated format

Formats parse and render both ways: URI lists, base64, Clash/Mihomo YAML,
sing-box JSON, and Xray JSON including the Happ-style array of whole configs.
A node keeps the raw payload it was born from, so same-format rendering is
byte-identical and no vendor-specific field is ever dropped.

Access control is HWID-based and self-switching: an empty whitelist means
everyone passes except banned devices; whitelisting a single device locks the
links to the whitelist. Every device that fetches a link is recorded with its
UA, IP, hit count and timestamps, and can be banned, whitelisted or labelled
from the panel.

Ships as one static binary with the React admin panel embedded (CGO-free, so
linux/amd64+arm64, windows and darwin cross-compile from anywhere), as a
docker image, and with Gitea CI that gates releases on the test suite.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-07-31 13:18:23 +03:00

87 lines
2.5 KiB
Go

// Package webui serves the compiled React admin panel out of the binary.
//
// The whole SPA is embedded so that a Prizma release is one file with no
// assets to deploy alongside it. web/dist is copied to internal/webui/dist by
// the build; a committed placeholder index.html keeps `go build` green before
// the frontend has ever been built.
package webui
import (
"embed"
"io/fs"
"net/http"
"path"
"strings"
"time"
)
//go:embed all:dist
var dist embed.FS
// Handler serves the built SPA with history fallback to index.html.
func Handler() http.Handler {
sub, err := fs.Sub(dist, "dist")
if err != nil {
// Only reachable if the embed directive above stops matching, which is
// a build-time mistake, not a runtime condition.
panic("webui: embedded dist is missing: " + err.Error())
}
files := http.FileServer(http.FS(sub))
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
name := strings.TrimPrefix(path.Clean("/"+r.URL.Path), "/")
if name == "" {
serveIndex(w, r, sub)
return
}
f, err := sub.Open(name)
if err != nil {
// Any unknown path is a client-side route: hand back index.html and
// let the router in the browser deal with it. Deep links and page
// reloads inside the panel depend on this.
serveIndex(w, r, sub)
return
}
info, statErr := f.Stat()
_ = f.Close()
if statErr != nil || info.IsDir() {
serveIndex(w, r, sub)
return
}
// Vite emits content-hashed asset names, so they may be cached hard;
// everything else must be revalidated or a deploy would never land.
if strings.HasPrefix(name, "assets/") {
w.Header().Set("Cache-Control", "public, max-age=31536000, immutable")
} else {
w.Header().Set("Cache-Control", "no-cache")
}
files.ServeHTTP(w, r)
})
}
func serveIndex(w http.ResponseWriter, r *http.Request, sub fs.FS) {
body, err := fs.ReadFile(sub, "index.html")
if err != nil {
http.Error(w, "admin panel is not built", http.StatusNotFound)
return
}
w.Header().Set("Content-Type", "text/html; charset=utf-8")
w.Header().Set("Cache-Control", "no-cache")
w.Header().Set("X-Content-Type-Options", "nosniff")
http.ServeContent(w, r, "index.html", indexModTime(sub), strings.NewReader(string(body)))
}
// indexModTime keeps ServeContent's Last-Modified stable across restarts by
// using the embedded file's own (zero) time rather than time.Now().
func indexModTime(sub fs.FS) (t time.Time) {
if f, err := sub.Open("index.html"); err == nil {
defer f.Close()
if info, err := f.Stat(); err == nil {
return info.ModTime()
}
}
return t
}