Skip to content

feat(customize): runtime inject customize_head/body for static frontend - #671

Open
PIKACHUIM wants to merge 3 commits into
mainfrom
feat/customize-injection
Open

PIKACHUIM wants to merge 3 commits into
mainfrom
feat/customize-injection

Conversation

@PIKACHUIM

@PIKACHUIM PIKACHUIM commented Sep 9, 2026

Copy link
Copy Markdown
Member

Summary / 摘要

Go backend injects customize_head/body at server-side into index.html placeholders; the TS/static frontend serves HTML without backend so customization never applies. Inject them at runtime after /public/settings loads, rebuilding <script> nodes so custom JS actually executes.

  • This PR has breaking changes.
    / 此 PR 包含破坏性变更。
  • This PR changes public API, config, storage format, or migration behavior.
    / 此 PR 修改了公开 API、配置、存储格式或迁移行为。
  • This PR requires corresponding changes in related repositories.
    / 此 PR 需要关联仓库同步修改。

Related repository PRs / 关联仓库 PR:

  • OpenList:
  • OpenList-Docs:

Related Issues / 关联 Issue

Testing / 测试

  • go test ./...
  • Manual test / 手动测试:

Checklist / 检查清单

  • I have read CONTRIBUTING.
    / 我已阅读 CONTRIBUTING
  • I confirm this contribution follows the repository license, contribution policy, and code of conduct.
    / 我确认此贡献符合仓库许可证、贡献规范和行为准则。
  • I have formatted the changed code with gofmt, go fmt, or prettier where applicable.
    / 我已按适用情况使用 gofmtgo fmtprettier 格式化变更代码。
  • I have requested review from relevant maintainers or code owners where applicable.
    / 我已在适用情况下请求相关维护者或代码所有者审查。

AI Disclosure / AI 使用声明

  • This PR includes AI-assisted content.
    / 此 PR 包含 AI 辅助内容。

Tools used / 使用工具:

  • ChatGPT
  • Codex
  • GitHub Copilot
  • Claude
  • Gemini
  • Other (please specify) / 其他(请注明):

Usage scope / 使用范围:

  • Code generation / 代码生成

  • Refactoring / 重构

  • Documentation / 文档

  • Tests / 测试

  • Translation / 翻译

  • Review assistance / 审查辅助

  • I have reviewed and validated all AI-assisted content included in this PR.
    / 我已审核并验证此 PR 中的所有 AI 辅助内容。

  • I have ensured that all AI-assisted commits include Co-Authored-By attribution.
    / 我已确保所有 AI 辅助提交都包含 Co-Authored-By 归属信息。

  • I can reproduce all AI-assisted content included in this PR without any AI tools.
    / 我可以在没有任何 AI 工具的情况下重现此 PR 中包含的所有 AI 辅助内容。

Go backend injects customize_head/body at server-side into index.html
placeholders; the TS/static frontend serves HTML without backend so
customization never applies. Inject them at runtime after /public/settings
loads, rebuilding <script> nodes so custom JS actually executes.
The restore logic used Object.values(data) and started decrypting from
length-4, which skips the settings array entirely. For password-protected
backups this left settings (customize_head/body, tokens, site title) as
ciphertext after restore. Decrypt all five arrays explicitly.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant