fix(sub): honor trustedProxyCIDRs before forwarded URLs (#6135)

* fix(sub): honor trustedProxyCIDRs before forwarded URLs

* fix(sub): avoid unused trust-setting lookups

Skip the trustedProxyCIDRs lookup when no forwarded header can affect a subscription URL. Keep the shipped proxy default in one exported setting constant and document the subscription-link behavior for custom proxy boundaries.

* fix(frontend): meet config text contrast requirements

Keep compact configuration text readable in the light theme and satisfy the Storybook accessibility check.

---------

Co-authored-by: PathGao <gaoyanbo@gaoyanbodeMacBook-Air.local>
This commit is contained in:
PathGao
2026-07-30 03:01:59 +08:00
committed by GitHub
parent ad5f2a28cb
commit ad288a7ecc
10 changed files with 325 additions and 12 deletions
+1 -1
View File
@@ -71,7 +71,7 @@ func isTrustedProxy(ip string) bool {
}
func trustedProxyCIDRs() (trusted string) {
trusted = "127.0.0.1/32,::1/128"
trusted = service.DefaultTrustedProxyCIDRs
defer func() {
_ = recover()
}()
+2 -1
View File
@@ -37,6 +37,7 @@ const (
DefaultSubClashUserAgentRegex = `(?i)(clash|mihomo)`
DefaultSubJsonUserAgentRegex = ``
DefaultRemarkTemplate = "{{INBOUND}}-{{EMAIL}}|📊{{TRAFFIC_LEFT}}|⏳{{DAYS_LEFT}}D"
DefaultTrustedProxyCIDRs = "127.0.0.1/32,::1/128"
maxRegexLength = 2048
)
@@ -61,7 +62,7 @@ var defaultValueMap = map[string]string{
"nodeMtlsClientCAPem": "",
"webBasePath": normalizeBasePath(getEnv("XUI_INIT_WEB_BASE_PATH", "/")),
"sessionMaxAge": "360",
"trustedProxyCIDRs": "127.0.0.1/32,::1/128",
"trustedProxyCIDRs": DefaultTrustedProxyCIDRs,
"pageSize": "25",
"expireDiff": "0",
"trafficDiff": "0",