mbs-panel/site/index.html
savsis 7cc50973f6 feat: custom brand name everywhere + a working client-facing site out of the box
User ask, paraphrased: install it, get help wiring up payments, and
immediately have a ready site under your own name — not "MBS Panel"
plastered everywhere and a bunch of manual follow-up.

Two things were actually broken/missing, found by tracing every surface
a real customer or the operator would see:

1. "MBS Panel" was hardcoded in ~20 places (bot messages, subscription
   page, admin panel splash/title/sidebar, legal pages, 2FA issuer,
   install.sh) with zero way to change it short of editing source.
   New BRAND_NAME config value (config.py default "MBS Panel", so this
   is 100% backward compatible for existing installs) wired through
   everywhere via the same live-settings pattern from the last commit
   (settings.get_brand_name(), no restart needed anywhere it's used).
   New Настройки → «Название» section in the admin panel to change it.

2. site/index.html and site/cabinet.html — a fully-built landing page +
   personal-cabinet template, already in the repo — were never actually
   served by anything. Not mounted by FastAPI, not deployed by
   install.sh, not linked from anywhere. Pure dead weight: a repo that
   looked like it shipped a client site but didn't. Now legal.py gets a
   render_site_page() (same {{TOKEN}} substitution + HTML-escaping as
   the existing offer/privacy renderer, new tokens: BRAND_NAME,
   SITE_DOMAIN, SUB_DOMAIN, BOT_USERNAME) and GET "/" serves the branded
   landing page on any host that isn't PANEL_DOMAIN (in practice:
   SUB_DOMAIN, which nginx already routes to this backend — zero
   install.sh/nginx/certbot changes needed, so this is live on every
   existing install without an upgrade step beyond `mbs update`).
   GET /cabinet.html serves the cabinet. Landing page's pricing section
   now fetches real, live prices from a new public GET /api/plans
   instead of showing static duration labels with no numbers.

Also fixed along the way, same staleness-bug class as the payments/HWID
fix last commit, found by grepping for every remaining frozen `from
config import ...` in api.py: BOT_TOKEN/BOT_USERNAME were still frozen
constants in api.py (mbs-api never restarts itself). Concretely this
meant: changing the bot via Настройки → Telegram-бот would leave
_tg_send_message (payment-received notifications) silently trying the
OLD token, admin_get_bot_settings showing the OLD username right after
a successful save, and gift-code links pointing at the OLD bot — all
until a manual mbs restart, same shape as the Platega-secret bug fixed
last commit. Added settings.bot_credentials(), wired it through every
call site (hoisted out of loops where relevant, same N+1 discipline as
always), removed the now-stale "выполни mbs restart" copy from the bot
settings hint.

legal.py's own BOT_USERNAME import was frozen too (used by the /offer
and /privacy {{BOT_USERNAME}} token) — switched to reading it live
in-module (no settings.py import from legal.py, would've been circular
since settings.py already imports legal.py for the env reader).

install.sh: new interactive prompt for the brand name (default "MBS
Panel", so hitting enter reproduces today's behavior exactly), written
to .env, echoed in the final summary along with the now-live site URL.

Verification: same story as always — api.py/bot.py still can't import
locally (no pydantic-core wheel for Python 3.14 on this machine).
py_compile + pyflakes clean across the whole repo. Real runtime test
against an isolated .env fixture: brand name and bot-credential live
reads (no reimport), render_site_page() token substitution correctness
on the actual site/index.html and site/cabinet.html files including an
XSS check (brand name containing <script> comes out HTML-escaped), and
a regression check that adding the BRAND_NAME token to the existing
legal.render() didn't break offer.html/privacy.html. Extracted
SUB_PAGE_TEMPLATE/SUB_PAGE_EXPIRED_TEMPLATE via ast from api.py (can't
import the module, but can pull the string constants) and ran the real
.format() calls against them to catch any brace-escaping mistake in the
new {brand_name} placeholder — CSS braces in those templates are
already double-escaped for .format(), easy to get wrong. Extracted and
node --check'd admin.html's whole inline script, div-tag-balance check
on the full file. install.sh's new prompt+heredoc snippet run standalone
with piped stdin (both a brand name with spaces and an empty/default
input), round-tripped the resulting .env back through the real
env-parsing logic. Extended the existing CI "app wiring" step (which
does import api/bot for real on Linux) with branding assertions calling
the actual route functions directly (api.root(), api.public_plans(),
api.public_branding()) — ran every part of that step's new logic that
doesn't need api.py locally first, to catch what's catchable before
trusting the rest to CI once the account's abuse-review lifts.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-13 23:52:54 +05:00

212 lines
8.6 KiB
HTML

<!doctype html>
<html lang="ru">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1">
<title>{{BRAND_NAME}}</title>
<style>
:root {
--bg: #0a0b0f; --card: #131519; --border: #1e2128;
--text: #eceef2; --muted: #868c99; --accent: #7c6cf0;
--ease: cubic-bezier(0.16, 1, 0.3, 1);
}
* { box-sizing: border-box; }
html { scroll-behavior: smooth; }
body {
margin: 0; background: var(--bg); color: var(--text);
font-family: -apple-system, BlinkMacSystemFont, "Segoe UI", Roboto, sans-serif;
-webkit-font-smoothing: antialiased;
}
a { color: inherit; }
.wrap { max-width: 880px; margin: 0 auto; padding: 0 24px; }
header {
display: flex; align-items: center; justify-content: space-between;
padding: 28px 0;
}
.logo { font-weight: 600; font-size: 15px; letter-spacing: -0.01em; }
nav { display: flex; gap: 28px; }
nav a {
position: relative; text-decoration: none; color: var(--muted); font-size: 14px;
transition: color 0.25s var(--ease);
}
nav a::after {
content: ""; position: absolute; left: 0; bottom: -4px; width: 100%; height: 1px;
background: currentColor; transform: scaleX(0); transform-origin: left;
transition: transform 0.3s var(--ease);
}
nav a:hover { color: var(--text); }
nav a:hover::after { transform: scaleX(1); }
.btn {
display: inline-block; padding: 13px 24px; border-radius: 10px;
background: var(--text); color: var(--bg);
text-decoration: none; font-weight: 600; font-size: 14px; border: none; cursor: pointer;
transition: transform 0.15s var(--ease), opacity 0.15s var(--ease);
}
.btn:hover { opacity: 0.85; }
.btn:active { transform: scale(0.97); }
.btn.ghost {
background: transparent; color: var(--text); border: 1px solid var(--border);
transition: transform 0.15s var(--ease), border-color 0.25s var(--ease), background 0.25s var(--ease);
}
.btn.ghost:hover { border-color: #333947; background: var(--card); opacity: 1; }
.reveal {
opacity: 0; transform: translateY(14px);
filter: blur(6px);
transition: opacity 0.7s var(--ease), transform 0.7s var(--ease), filter 0.7s var(--ease);
}
.reveal.in { opacity: 1; transform: translateY(0); filter: blur(0); }
.hero { padding: 88px 0 64px; }
.hero h1 {
font-size: 46px; line-height: 1.12; margin: 0 0 20px; letter-spacing: -0.03em;
font-weight: 600; max-width: 620px;
}
.hero .accent { color: var(--accent); }
.hero p { color: var(--muted); font-size: 17px; max-width: 460px; margin: 0 0 32px; line-height: 1.55; }
.divider { height: 1px; background: var(--border); margin: 0; }
.grid { display: grid; grid-template-columns: repeat(3, 1fr); gap: 1px; background: var(--border); margin: 64px 0; }
.feature { background: var(--bg); padding: 32px 28px; }
.feature .idx { font-size: 13px; color: var(--muted); font-variant-numeric: tabular-nums; margin-bottom: 14px; }
.feature h3 { font-size: 16px; margin: 0 0 8px; font-weight: 600; }
.feature p { color: var(--muted); font-size: 14px; margin: 0; line-height: 1.55; }
.steps { padding: 64px 0; }
.section-label { font-size: 13px; color: var(--muted); text-transform: uppercase; letter-spacing: 0.06em; margin-bottom: 12px; }
.steps h2, .plans h2 { font-size: 24px; margin: 0 0 40px; font-weight: 600; letter-spacing: -0.01em; }
.step-list { display: grid; grid-template-columns: repeat(3, 1fr); gap: 32px; }
.step .num { font-size: 13px; color: var(--accent); font-variant-numeric: tabular-nums; margin-bottom: 10px; }
.step p { color: var(--muted); font-size: 14px; margin: 0; line-height: 1.5; }
.plans { padding: 8px 0 72px; }
.plan-row { display: flex; gap: 1px; background: var(--border); border-radius: 12px; overflow: hidden; }
.plan {
flex: 1; background: var(--card); padding: 20px 16px; text-align: center;
transition: background 0.25s var(--ease);
}
.plan:hover { background: #171a20; }
.plan .d { font-weight: 600; font-size: 15px; }
.plan .l { color: var(--muted); font-size: 12px; margin-top: 4px; }
.cta { text-align: center; padding: 16px 0 88px; }
footer { border-top: 1px solid var(--border); padding: 28px 0; color: var(--muted); font-size: 13px; }
footer a { text-decoration: underline; text-underline-offset: 2px; }
@media (max-width: 640px) {
.hero h1 { font-size: 32px; }
.grid { grid-template-columns: 1fr; }
.step-list { grid-template-columns: 1fr; gap: 24px; }
.plan-row { flex-wrap: wrap; }
.plan { min-width: 45%; }
}
@media (prefers-reduced-motion: reduce) {
*, *::before, *::after {
animation-duration: 0.01ms !important;
transition-duration: 0.01ms !important;
}
.reveal { opacity: 1 !important; transform: none !important; filter: none !important; }
}
</style>
</head>
<body>
<div class="wrap">
<header>
<div class="logo">{{BRAND_NAME}}</div>
<nav>
<a href="#features">Возможности</a>
<a href="#plans">Тарифы</a>
<a href="/cabinet.html">Кабинет</a>
</nav>
</header>
<section class="hero">
<h1 class="reveal">Интернет без границ<br><span class="accent">и без замедлений</span></h1>
<p class="reveal">Быстрый доступ к любимым сайтам и сервисам. Трафик не отличить от обычного HTTPS, скорость — на выделенных мощностях.</p>
<a class="btn reveal" href="https://t.me/{{BOT_USERNAME}}" target="_blank">Получить доступ</a>
</section>
</div>
<div class="divider"></div>
<div class="wrap">
<div class="grid" id="features">
<div class="feature reveal">
<div class="idx">01</div>
<h3>Незаметный трафик</h3>
<p>VLESS + Reality маскирует соединение под обычный HTTPS — не режется и не палится провайдером.</p>
</div>
<div class="feature reveal">
<div class="idx">02</div>
<h3>Реальная скорость</h3>
<p>Выделенные мощности, без переподписки и очередей — видео и игры без лагов.</p>
</div>
<div class="feature reveal">
<div class="idx">03</div>
<h3>Одна ссылка</h3>
<p>Подписка сама добавляет все сервера в Happ. Никаких конфигов вручную.</p>
</div>
</div>
<section class="steps">
<div class="section-label reveal">Как подключиться</div>
<div class="step-list">
<div class="step reveal"><div class="num">01</div><p>Открой бота в Telegram</p></div>
<div class="step reveal"><div class="num">02</div><p>Выбери срок подписки</p></div>
<div class="step reveal"><div class="num">03</div><p>Открой ссылку — добавится в Happ сама</p></div>
</div>
</section>
<section class="plans" id="plans">
<h2 class="reveal">Тарифы</h2>
<div class="plan-row reveal" id="plan-row">
<div class="plan"><div class="d">…</div></div>
</div>
</section>
<div class="cta reveal">
<a class="btn ghost" href="https://t.me/{{BOT_USERNAME}}" target="_blank">Выбрать тариф в боте</a>
</div>
</div>
<footer>
<div class="wrap">
{{SITE_DOMAIN}} — <a href="/cabinet.html">личный кабинет</a> — подписка через <a href="https://{{SUB_DOMAIN}}" target="_blank">{{SUB_DOMAIN}}</a> — <a href="/offer">оферта</a> — <a href="/privacy">конфиденциальность</a>
</div>
</footer>
<script>
const io = new IntersectionObserver((entries) => {
entries.forEach((e, i) => {
if (e.isIntersecting) {
e.target.style.transitionDelay = (i % 3) * 0.08 + "s";
e.target.classList.add("in");
io.unobserve(e.target);
}
});
}, { threshold: 0.15 });
document.querySelectorAll(".reveal").forEach((el) => io.observe(el));
function esc(s) {
return String(s).replace(/[&<>"']/g, (c) => ({ "&": "&amp;", "<": "&lt;", ">": "&gt;", '"': "&quot;", "'": "&#39;" }[c]));
}
const PLAN_TAGLINES = { "7d": "пробный", "1m": "стандарт", "3m": "выгодно", "6m": "выгоднее", "1y": "максимум" };
fetch("/api/plans").then((r) => r.json()).then((data) => {
const row = document.getElementById("plan-row");
row.innerHTML = data.plans.map((p) => `
<div class="plan">
<div class="d">${esc(p.label)}</div>
<div class="l">${data.payments_enabled && p.price > 0 ? esc(p.price) + " ₽" : esc(PLAN_TAGLINES[p.code] || "")}</div>
</div>
`).join("");
}).catch(() => {});
</script>
</body>
</html>