subJsons and subClashs served the raw body and returned before enforceHwid ran,
so appending ?view=raw to a JSON or Clash subscription URL handed out a complete,
client-consumable config however many devices were already registered. The branch
exists to stop a browser's Accept: text/html from being answered with the info
page, not to skip the gate.
Gate the raw branch and leave the other gate where it was, below
maybeServeSubPage, so the HTML info page stays ungated as before.
* feat(sub): add per-client subscription HWID limits
* fix(sub): address HWID review on shared subId and bulk create
* fix(sub): store HWID devices by sub_id and drop anchor client workaround
* fix(sub): restore UA auto-detect and HTML page routing in subs()
The cherry-pick of the HWID gate onto main's refactored SUBController
had dropped main's UA-based format auto-detection and sub-page handling
from subs(). Restore those branches, slotting enforceHwid after the
HTML page and before format detection so the gate only applies to
machine-readable subscription bodies.
Also adapt tests to main's options-struct constructor and to the
ClientService.Update signature extended with limitHwid.
* fix(frontend): drop axios from HttpUtil.delete
The bulk-delete rework's committed version still referenced axios,
which this file no longer imports, breaking typecheck in CI. Use the
httpRequest wrapper like the other verbs.
---------
Co-authored-by: Sanaei <ho3ein.sanaei@gmail.com>