User ask, paraphrased: install it, get help wiring up payments, and
immediately have a ready site under your own name — not "MBS Panel"
plastered everywhere and a bunch of manual follow-up.
Two things were actually broken/missing, found by tracing every surface
a real customer or the operator would see:
1. "MBS Panel" was hardcoded in ~20 places (bot messages, subscription
page, admin panel splash/title/sidebar, legal pages, 2FA issuer,
install.sh) with zero way to change it short of editing source.
New BRAND_NAME config value (config.py default "MBS Panel", so this
is 100% backward compatible for existing installs) wired through
everywhere via the same live-settings pattern from the last commit
(settings.get_brand_name(), no restart needed anywhere it's used).
New Настройки → «Название» section in the admin panel to change it.
2. site/index.html and site/cabinet.html — a fully-built landing page +
personal-cabinet template, already in the repo — were never actually
served by anything. Not mounted by FastAPI, not deployed by
install.sh, not linked from anywhere. Pure dead weight: a repo that
looked like it shipped a client site but didn't. Now legal.py gets a
render_site_page() (same {{TOKEN}} substitution + HTML-escaping as
the existing offer/privacy renderer, new tokens: BRAND_NAME,
SITE_DOMAIN, SUB_DOMAIN, BOT_USERNAME) and GET "/" serves the branded
landing page on any host that isn't PANEL_DOMAIN (in practice:
SUB_DOMAIN, which nginx already routes to this backend — zero
install.sh/nginx/certbot changes needed, so this is live on every
existing install without an upgrade step beyond `mbs update`).
GET /cabinet.html serves the cabinet. Landing page's pricing section
now fetches real, live prices from a new public GET /api/plans
instead of showing static duration labels with no numbers.
Also fixed along the way, same staleness-bug class as the payments/HWID
fix last commit, found by grepping for every remaining frozen `from
config import ...` in api.py: BOT_TOKEN/BOT_USERNAME were still frozen
constants in api.py (mbs-api never restarts itself). Concretely this
meant: changing the bot via Настройки → Telegram-бот would leave
_tg_send_message (payment-received notifications) silently trying the
OLD token, admin_get_bot_settings showing the OLD username right after
a successful save, and gift-code links pointing at the OLD bot — all
until a manual mbs restart, same shape as the Platega-secret bug fixed
last commit. Added settings.bot_credentials(), wired it through every
call site (hoisted out of loops where relevant, same N+1 discipline as
always), removed the now-stale "выполни mbs restart" copy from the bot
settings hint.
legal.py's own BOT_USERNAME import was frozen too (used by the /offer
and /privacy {{BOT_USERNAME}} token) — switched to reading it live
in-module (no settings.py import from legal.py, would've been circular
since settings.py already imports legal.py for the env reader).
install.sh: new interactive prompt for the brand name (default "MBS
Panel", so hitting enter reproduces today's behavior exactly), written
to .env, echoed in the final summary along with the now-live site URL.
Verification: same story as always — api.py/bot.py still can't import
locally (no pydantic-core wheel for Python 3.14 on this machine).
py_compile + pyflakes clean across the whole repo. Real runtime test
against an isolated .env fixture: brand name and bot-credential live
reads (no reimport), render_site_page() token substitution correctness
on the actual site/index.html and site/cabinet.html files including an
XSS check (brand name containing <script> comes out HTML-escaped), and
a regression check that adding the BRAND_NAME token to the existing
legal.render() didn't break offer.html/privacy.html. Extracted
SUB_PAGE_TEMPLATE/SUB_PAGE_EXPIRED_TEMPLATE via ast from api.py (can't
import the module, but can pull the string constants) and ran the real
.format() calls against them to catch any brace-escaping mistake in the
new {brand_name} placeholder — CSS braces in those templates are
already double-escaped for .format(), easy to get wrong. Extracted and
node --check'd admin.html's whole inline script, div-tag-balance check
on the full file. install.sh's new prompt+heredoc snippet run standalone
with piped stdin (both a brand name with spaces and an empty/default
input), round-tripped the resulting .env back through the real
env-parsing logic. Extended the existing CI "app wiring" step (which
does import api/bot for real on Linux) with branding assertions calling
the actual route functions directly (api.root(), api.public_plans(),
api.public_branding()) — ran every part of that step's new logic that
doesn't need api.py locally first, to catch what's catchable before
trusting the rest to CI once the account's abuse-review lifts.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
137 lines
5.8 KiB
HTML
137 lines
5.8 KiB
HTML
<!doctype html>
|
|
<html lang="ru">
|
|
<head>
|
|
<meta charset="utf-8">
|
|
<meta name="viewport" content="width=device-width, initial-scale=1">
|
|
<title>Личный кабинет — {{BRAND_NAME}}</title>
|
|
<style>
|
|
:root {
|
|
--bg: #0a0b0f; --card: #131519; --border: #1e2128;
|
|
--text: #eceef2; --muted: #868c99; --accent: #7c6cf0;
|
|
--ease: cubic-bezier(0.16, 1, 0.3, 1);
|
|
}
|
|
* { box-sizing: border-box; }
|
|
body {
|
|
margin: 0; min-height: 100vh; background: var(--bg); color: var(--text);
|
|
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, sans-serif;
|
|
-webkit-font-smoothing: antialiased;
|
|
display: flex; align-items: center; justify-content: center; padding: 24px;
|
|
}
|
|
.card {
|
|
max-width: 420px; width: 100%; background: var(--card); border: 1px solid var(--border);
|
|
border-radius: 16px; padding: 32px 28px;
|
|
opacity: 0; transform: translateY(10px); filter: blur(6px);
|
|
animation: enter 0.6s var(--ease) forwards;
|
|
}
|
|
@keyframes enter { to { opacity: 1; transform: translateY(0); filter: blur(0); } }
|
|
h1 { font-size: 17px; margin: 0 0 20px; font-weight: 600; letter-spacing: -0.01em; }
|
|
.row { display: flex; gap: 8px; margin-bottom: 4px; }
|
|
input {
|
|
flex: 1; background: var(--bg); border: 1px solid var(--border); border-radius: 8px;
|
|
padding: 11px 13px; color: var(--text); font-size: 14px;
|
|
transition: border-color 0.2s var(--ease);
|
|
}
|
|
input:focus { outline: none; border-color: var(--accent); }
|
|
.btn {
|
|
padding: 11px 16px; border-radius: 8px; border: none; cursor: pointer;
|
|
background: var(--text); color: var(--bg); font-weight: 600; font-size: 14px;
|
|
transition: transform 0.15s var(--ease), opacity 0.15s var(--ease);
|
|
}
|
|
.btn:hover { opacity: 0.85; }
|
|
.btn:active { transform: scale(0.96); }
|
|
|
|
.sub-item {
|
|
background: var(--bg); border: 1px solid var(--border); border-radius: 10px;
|
|
padding: 13px 15px; margin-top: 12px; font-size: 14px;
|
|
opacity: 0; transform: translateY(8px);
|
|
animation: enter 0.5s var(--ease) forwards;
|
|
}
|
|
.sub-item .top { display: flex; justify-content: space-between; margin-bottom: 4px; }
|
|
.sub-item .days { color: var(--accent); font-weight: 600; font-variant-numeric: tabular-nums; }
|
|
.muted { color: var(--muted); font-size: 13px; }
|
|
.linkbox {
|
|
background: var(--bg); border: 1px solid var(--border); border-radius: 8px; padding: 10px 12px;
|
|
font-size: 12px; word-break: break-all; color: var(--muted); margin-top: 16px;
|
|
opacity: 0; animation: fadeIn 0.5s var(--ease) 0.15s forwards;
|
|
}
|
|
@keyframes fadeIn { to { opacity: 1; } }
|
|
.hint { text-align: center; color: var(--muted); font-size: 13px; margin-top: 18px; margin-bottom: 0; }
|
|
a.tglink { color: var(--accent); text-decoration: none; }
|
|
a.tglink:hover { text-decoration: underline; }
|
|
#err { color: #e5686b; font-size: 13px; margin-top: 8px; min-height: 0; }
|
|
.qr-box {
|
|
display: flex; justify-content: center; margin-top: 16px;
|
|
opacity: 0; animation: fadeIn 0.5s var(--ease) 0.2s forwards;
|
|
}
|
|
.qr-box img, .qr-box canvas { border-radius: 8px; background: #fff; padding: 6px; }
|
|
|
|
@media (prefers-reduced-motion: reduce) {
|
|
*, *::before, *::after { animation-duration: 0.01ms !important; transition-duration: 0.01ms !important; }
|
|
.card, .sub-item, .linkbox, .qr-box { opacity: 1 !important; transform: none !important; filter: none !important; }
|
|
}
|
|
</style>
|
|
<script src="https://cdnjs.cloudflare.com/ajax/libs/qrcodejs/1.0.0/qrcode.min.js"></script>
|
|
</head>
|
|
<body>
|
|
<div class="card">
|
|
<h1>Личный кабинет</h1>
|
|
<div class="row">
|
|
<input id="tokenInput" placeholder="вставь свой токен" autocomplete="off">
|
|
<button class="btn" onclick="load()">Войти</button>
|
|
</div>
|
|
<div id="err"></div>
|
|
<div id="content"></div>
|
|
<p class="hint">Токен выдаёт бот <a class="tglink" href="https://t.me/{{BOT_USERNAME}}" target="_blank">@{{BOT_USERNAME}}</a> — «Моя подписка»</p>
|
|
</div>
|
|
|
|
<script>
|
|
const API = "https://{{SUB_DOMAIN}}";
|
|
|
|
function esc(s) {
|
|
if (s === null || s === undefined) return "";
|
|
return String(s).replace(/[&<>"']/g, (c) => ({ "&": "&", "<": "<", ">": ">", '"': """, "'": "'" }[c]));
|
|
}
|
|
|
|
function fillFromUrl() {
|
|
const params = new URLSearchParams(location.search);
|
|
const t = params.get("token");
|
|
if (t) { document.getElementById("tokenInput").value = t; load(); }
|
|
}
|
|
|
|
async function load() {
|
|
const token = document.getElementById("tokenInput").value.trim();
|
|
const err = document.getElementById("err");
|
|
const content = document.getElementById("content");
|
|
err.textContent = ""; content.innerHTML = "";
|
|
if (!token) return;
|
|
try {
|
|
const res = await fetch(`${API}/api/cabinet/${encodeURIComponent(token)}`);
|
|
if (!res.ok) { err.textContent = "Токен не найден"; return; }
|
|
const data = await res.json();
|
|
history.replaceState(null, "", `?token=${encodeURIComponent(token)}`);
|
|
let html = "";
|
|
if (data.subscriptions.length === 0) {
|
|
html += `<p class="muted" style="margin-top:14px">Активных подписок нет</p>`;
|
|
} else {
|
|
data.subscriptions.forEach((s, i) => {
|
|
html += `<div class="sub-item" style="animation-delay:${i * 0.06}s"><div class="top"><span>${esc(s.node)}</span><span class="days">${s.days_left} дн.</span></div><div class="muted">${esc(s.plan_label)}, до ${s.expires_at.slice(0,10)}</div></div>`;
|
|
});
|
|
}
|
|
html += `<div class="qr-box" id="qr"></div>`;
|
|
html += `<div class="linkbox">${esc(data.sub_link)}</div>`;
|
|
content.innerHTML = html;
|
|
if (data.sub_link) {
|
|
new QRCode(document.getElementById("qr"), {
|
|
text: data.sub_link, width: 150, height: 150,
|
|
colorDark: "#0a0b0f", colorLight: "#ffffff", correctLevel: QRCode.CorrectLevel.M,
|
|
});
|
|
}
|
|
} catch (e) {
|
|
err.textContent = "Ошибка соединения";
|
|
}
|
|
}
|
|
|
|
fillFromUrl();
|
|
</script>
|
|
</body>
|
|
</html>
|