fix: audit findings - PUT response rechargeURL, NaN guard, debug logs

- Add BalanceLowNotifyRechargeURL to admin PUT response (fixes save-then-stale)
- Add ?? 1 guard for account_rate_multiplier in UsageTable else branch
- Downgrade high-frequency notify logs from Info to Debug
- Extract "Sub2API" magic string to defaultSiteName constant
This commit is contained in:
erio
2026-04-13 19:45:45 +08:00
parent 6307aff1d3
commit b0305fef11
5 changed files with 10 additions and 7 deletions
+1 -1
View File
@@ -1 +1 @@
0.1.110.42
0.1.110.43
@@ -1072,6 +1072,7 @@ func (h *SettingHandler) UpdateSettings(c *gin.Context) {
EnableCCHSigning: updatedSettings.EnableCCHSigning,
BalanceLowNotifyEnabled: updatedSettings.BalanceLowNotifyEnabled,
BalanceLowNotifyThreshold: updatedSettings.BalanceLowNotifyThreshold,
BalanceLowNotifyRechargeURL: updatedSettings.BalanceLowNotifyRechargeURL,
AccountQuotaNotifyEnabled: updatedSettings.AccountQuotaNotifyEnabled,
AccountQuotaNotifyEmails: dto.NotifyEmailEntriesFromService(updatedSettings.AccountQuotaNotifyEmails),
PaymentEnabled: updatedPaymentCfg.Enabled,
@@ -21,6 +21,8 @@ const (
quotaDimDaily = "daily"
quotaDimWeekly = "weekly"
quotaDimTotal = "total"
defaultSiteName = "Sub2API"
)
// quotaDimLabels maps dimension names to display labels.
@@ -79,7 +81,7 @@ func (s *BalanceNotifyService) CheckBalanceAfterDeduction(ctx context.Context, u
globalEnabled, globalThreshold, rechargeURL := s.getBalanceNotifyConfig(ctx)
if !globalEnabled {
slog.Info("CheckBalanceAfterDeduction: global notify disabled", "user_id", user.ID)
slog.Debug("CheckBalanceAfterDeduction: global notify disabled", "user_id", user.ID)
return
}
@@ -100,7 +102,7 @@ func (s *BalanceNotifyService) CheckBalanceAfterDeduction(ctx context.Context, u
}
newBalance := oldBalance - cost
slog.Info("CheckBalanceAfterDeduction: crossing check",
slog.Debug("CheckBalanceAfterDeduction: crossing check",
"user_id", user.ID,
"old_balance", oldBalance,
"new_balance", newBalance,
@@ -324,7 +326,7 @@ func (s *BalanceNotifyService) getAccountQuotaNotifyEmails(ctx context.Context)
func (s *BalanceNotifyService) getSiteName(ctx context.Context) string {
name, err := s.settingRepo.GetValue(ctx, SettingKeySiteName)
if err != nil || name == "" {
return "Sub2API"
return defaultSiteName
}
return name
}
+2 -2
View File
@@ -7555,7 +7555,7 @@ func notifyBalanceLow(p *postUsageBillingParams, deps *billingDeps, result *Usag
}
oldBalance := resolveOldBalance(p, result)
slog.Info("notifyBalanceLow: calling CheckBalanceAfterDeduction",
slog.Debug("notifyBalanceLow: calling CheckBalanceAfterDeduction",
"user_id", p.User.ID,
"old_balance", oldBalance,
"cost", p.Cost.ActualCost,
@@ -7599,7 +7599,7 @@ func notifyAccountQuota(p *postUsageBillingParams, deps *billingDeps, result *Us
if result != nil {
quotaState = result.QuotaState
}
slog.Info("notifyAccountQuota: calling CheckAccountQuotaAfterIncrement",
slog.Debug("notifyAccountQuota: calling CheckAccountQuotaAfterIncrement",
"account_id", p.Account.ID,
"account_cost", accountCost,
"has_quota_state", quotaState != nil,
@@ -155,7 +155,7 @@
</div>
</div>
<div v-if="row.account_rate_multiplier != null" class="mt-0.5 text-[11px] text-gray-400">
A ${{ (row.account_stats_cost != null ? row.account_stats_cost * (row.account_rate_multiplier ?? 1) : row.total_cost * row.account_rate_multiplier).toFixed(6) }}
A ${{ (row.account_stats_cost != null ? row.account_stats_cost * (row.account_rate_multiplier ?? 1) : row.total_cost * (row.account_rate_multiplier ?? 1)).toFixed(6) }}
</div>
</div>
</template>