From b0305fef1173e69a5c83c8f9c0e22fe8e44fea6d Mon Sep 17 00:00:00 2001 From: erio Date: Mon, 13 Apr 2026 19:45:45 +0800 Subject: [PATCH] fix: audit findings - PUT response rechargeURL, NaN guard, debug logs - Add BalanceLowNotifyRechargeURL to admin PUT response (fixes save-then-stale) - Add ?? 1 guard for account_rate_multiplier in UsageTable else branch - Downgrade high-frequency notify logs from Info to Debug - Extract "Sub2API" magic string to defaultSiteName constant --- backend/cmd/server/VERSION | 2 +- backend/internal/handler/admin/setting_handler.go | 1 + backend/internal/service/balance_notify_service.go | 8 +++++--- backend/internal/service/gateway_service.go | 4 ++-- frontend/src/components/admin/usage/UsageTable.vue | 2 +- 5 files changed, 10 insertions(+), 7 deletions(-) diff --git a/backend/cmd/server/VERSION b/backend/cmd/server/VERSION index ab6fbb6e18..94c52464ea 100644 --- a/backend/cmd/server/VERSION +++ b/backend/cmd/server/VERSION @@ -1 +1 @@ -0.1.110.42 +0.1.110.43 diff --git a/backend/internal/handler/admin/setting_handler.go b/backend/internal/handler/admin/setting_handler.go index bc6d183cbb..b55eb9f6bd 100644 --- a/backend/internal/handler/admin/setting_handler.go +++ b/backend/internal/handler/admin/setting_handler.go @@ -1072,6 +1072,7 @@ func (h *SettingHandler) UpdateSettings(c *gin.Context) { EnableCCHSigning: updatedSettings.EnableCCHSigning, BalanceLowNotifyEnabled: updatedSettings.BalanceLowNotifyEnabled, BalanceLowNotifyThreshold: updatedSettings.BalanceLowNotifyThreshold, + BalanceLowNotifyRechargeURL: updatedSettings.BalanceLowNotifyRechargeURL, AccountQuotaNotifyEnabled: updatedSettings.AccountQuotaNotifyEnabled, AccountQuotaNotifyEmails: dto.NotifyEmailEntriesFromService(updatedSettings.AccountQuotaNotifyEmails), PaymentEnabled: updatedPaymentCfg.Enabled, diff --git a/backend/internal/service/balance_notify_service.go b/backend/internal/service/balance_notify_service.go index 3951e88f50..bf9fb89617 100644 --- a/backend/internal/service/balance_notify_service.go +++ b/backend/internal/service/balance_notify_service.go @@ -21,6 +21,8 @@ const ( quotaDimDaily = "daily" quotaDimWeekly = "weekly" quotaDimTotal = "total" + + defaultSiteName = "Sub2API" ) // quotaDimLabels maps dimension names to display labels. @@ -79,7 +81,7 @@ func (s *BalanceNotifyService) CheckBalanceAfterDeduction(ctx context.Context, u globalEnabled, globalThreshold, rechargeURL := s.getBalanceNotifyConfig(ctx) if !globalEnabled { - slog.Info("CheckBalanceAfterDeduction: global notify disabled", "user_id", user.ID) + slog.Debug("CheckBalanceAfterDeduction: global notify disabled", "user_id", user.ID) return } @@ -100,7 +102,7 @@ func (s *BalanceNotifyService) CheckBalanceAfterDeduction(ctx context.Context, u } newBalance := oldBalance - cost - slog.Info("CheckBalanceAfterDeduction: crossing check", + slog.Debug("CheckBalanceAfterDeduction: crossing check", "user_id", user.ID, "old_balance", oldBalance, "new_balance", newBalance, @@ -324,7 +326,7 @@ func (s *BalanceNotifyService) getAccountQuotaNotifyEmails(ctx context.Context) func (s *BalanceNotifyService) getSiteName(ctx context.Context) string { name, err := s.settingRepo.GetValue(ctx, SettingKeySiteName) if err != nil || name == "" { - return "Sub2API" + return defaultSiteName } return name } diff --git a/backend/internal/service/gateway_service.go b/backend/internal/service/gateway_service.go index a4571db28d..4f9086d9ab 100644 --- a/backend/internal/service/gateway_service.go +++ b/backend/internal/service/gateway_service.go @@ -7555,7 +7555,7 @@ func notifyBalanceLow(p *postUsageBillingParams, deps *billingDeps, result *Usag } oldBalance := resolveOldBalance(p, result) - slog.Info("notifyBalanceLow: calling CheckBalanceAfterDeduction", + slog.Debug("notifyBalanceLow: calling CheckBalanceAfterDeduction", "user_id", p.User.ID, "old_balance", oldBalance, "cost", p.Cost.ActualCost, @@ -7599,7 +7599,7 @@ func notifyAccountQuota(p *postUsageBillingParams, deps *billingDeps, result *Us if result != nil { quotaState = result.QuotaState } - slog.Info("notifyAccountQuota: calling CheckAccountQuotaAfterIncrement", + slog.Debug("notifyAccountQuota: calling CheckAccountQuotaAfterIncrement", "account_id", p.Account.ID, "account_cost", accountCost, "has_quota_state", quotaState != nil, diff --git a/frontend/src/components/admin/usage/UsageTable.vue b/frontend/src/components/admin/usage/UsageTable.vue index d29fc52401..5bc48206b0 100644 --- a/frontend/src/components/admin/usage/UsageTable.vue +++ b/frontend/src/components/admin/usage/UsageTable.vue @@ -155,7 +155,7 @@
- A ${{ (row.account_stats_cost != null ? row.account_stats_cost * (row.account_rate_multiplier ?? 1) : row.total_cost * row.account_rate_multiplier).toFixed(6) }} + A ${{ (row.account_stats_cost != null ? row.account_stats_cost * (row.account_rate_multiplier ?? 1) : row.total_cost * (row.account_rate_multiplier ?? 1)).toFixed(6) }}