fix(api): 服务器显示名称限 64 个可见字符,拒绝换行、控制符和不可见格式符

This commit is contained in:
Lemon-miaow committed 2026-09-27 13:30:28 +08:00
1 parent b8da4e2318
commit 67a7e27f8d
19 files changed
+197 -20

No files matched your search

+11 -2
View File
@@ -455,6 +455,11 @@ func (a *API) handleCreateServer(w http.ResponseWriter, r *http.Request) {
writeError(w, r, newError(http.StatusBadRequest, "bad_subdomain", "invalid subdomain: %v", err))
return
}
displayName, err := naming.CleanDisplayName(body.DisplayName)
if err != nil {
writeError(w, r, newError(http.StatusBadRequest, "bad_display_name", "invalid display name: %v", err))
return
}
policy, err := parseAutostartPolicy(body.AutostartPolicy)
if err != nil {
@@ -569,7 +574,7 @@ func (a *API) handleCreateServer(w http.ResponseWriter, r *http.Request) {
in := CreateServerInput{
Name: body.Name,
Subdomain: body.Subdomain,
DisplayName: body.DisplayName,
DisplayName: displayName,
Image: image,
JavaMemory: javaMemory,
StorageSize: storage,
@@ -930,7 +935,11 @@ func (a *API) handlePatchServer(w http.ResponseWriter, r *http.Request) {
if body.DisplayName != nil {
// An empty name is allowed: the panel then shows the server's name.
displayName := strings.TrimSpace(*body.DisplayName)
displayName, err := naming.CleanDisplayName(*body.DisplayName)
if err != nil {
writeError(w, r, newError(http.StatusBadRequest, "bad_display_name", "invalid display name: %v", err))
return
}
patch.DisplayName = &displayName
changed = append(changed, "displayName")
}