mirror of
https://github.com/Wei-Shaw/sub2api.git
synced 2026-10-07 15:38:22 +08:00
PR #5423 relaxed the email suffix whitelist: once a whitelist is configured, non-whitelisted registrable domains are each allowed to register one account. That behavior activated unconditionally. Add registration_email_domain_quota_enabled (default false) to gate it: - Off (default): restore pre-#5423 strict whitelist semantics — with a non-empty whitelist, non-whitelisted domains are rejected with EMAIL_SUFFIX_NOT_ALLOWED; the register/verify views restore the client-side whitelist pre-check and allowed-domain hint. - On: keep #5423 behavior — one account per non-whitelisted registrable domain (EMAIL_DOMAIN_REGISTRATION_LIMIT). - Empty whitelist keeps allowing all domains in both states. Gating lives in validateRegistrationEmailQuota and (as a race-safety backstop) createUserWithRegistrationEmailGuard; the repository-level domain lock + in-tx recheck is unchanged. The admin update field is *bool (omitted = keep current) so stale full-payload saves cannot silently flip the switch. Email binding and OAuth auto-signup keep their strict policy, and pending-OAuth bind-login for existing accounts is unaffected because the handler resolves existing emails before the quota check. Frontend adds the toggle to admin settings (zh/en copy; whitelist hint restored to strict wording, quota wording moved to the new toggle) and exposes the flag via public settings + SSR injection payload. Tests: #5423 quota tests now enable the switch explicitly; new default-off regression tests cover register/send-code/async/pending OAuth/OIDC create-account plus both register views; API contract JSON and the injection drift guard are updated.