From 5b7d356456c36fd98e0181ee7f10aa0df5372292 Mon Sep 17 00:00:00 2001 From: huangjiajun Date: Fri, 17 Jul 2026 16:32:05 +0800 Subject: [PATCH 1/2] fix(123pan): proxy IP-bound downloads 123Pan now binds download URLs to the IP that requests them. Forwarding the client IP no longer affects that binding, so direct links fail with download error 50001 when AList and the client use different egress IPs.\n\nForce this driver through AList's download proxy and remove the ineffective forwarded-IP headers. --- drivers/123/driver.go | 12 ++---------- drivers/123/meta.go | 2 ++ drivers/123/meta_test.go | 9 +++++++++ 3 files changed, 13 insertions(+), 10 deletions(-) create mode 100644 drivers/123/meta_test.go diff --git a/drivers/123/driver.go b/drivers/123/driver.go index 3a51f092225..1814c0989f7 100644 --- a/drivers/123/driver.go +++ b/drivers/123/driver.go @@ -81,16 +81,9 @@ func (d *Pan123) List(ctx context.Context, dir model.Obj, args model.ListArgs) ( }) } -func (d *Pan123) Link(ctx context.Context, file model.Obj, args model.LinkArgs) (*model.Link, error) { +func (d *Pan123) Link(ctx context.Context, file model.Obj, _ model.LinkArgs) (*model.Link, error) { if f, ok := file.(File); ok { //var resp DownResp - var headers map[string]string - if !utils.IsLocalIPAddr(args.IP) { - headers = map[string]string{ - //"X-Real-IP": "1.1.1.1", - "X-Forwarded-For": args.IP, - } - } data := base.Json{ "driveId": 0, "etag": f.Etag, @@ -101,8 +94,7 @@ func (d *Pan123) Link(ctx context.Context, file model.Obj, args model.LinkArgs) "type": f.Type, } resp, err := d.Request(DownloadInfo, http.MethodPost, func(req *resty.Request) { - - req.SetBody(data).SetHeaders(headers) + req.SetBody(data) }, nil) if err != nil { return nil, err diff --git a/drivers/123/meta.go b/drivers/123/meta.go index 6c5f013ad4a..a1e19ae97a4 100644 --- a/drivers/123/meta.go +++ b/drivers/123/meta.go @@ -19,6 +19,8 @@ var config = driver.Config{ Name: "123Pan", DefaultRoot: "0", LocalSort: true, + // Download URLs are bound to the IP that requests them from 123Pan. + OnlyProxy: true, } func init() { diff --git a/drivers/123/meta_test.go b/drivers/123/meta_test.go new file mode 100644 index 00000000000..4fc7317e35a --- /dev/null +++ b/drivers/123/meta_test.go @@ -0,0 +1,9 @@ +package _123 + +import "testing" + +func TestConfigRequiresProxy(t *testing.T) { + if !config.MustProxy() { + t.Fatal("123Pan downloads must be proxied because direct links are bound to the requester's IP") + } +} From b4701cb4fc088999a5e46c796dbcfe552dfae592 Mon Sep 17 00:00:00 2001 From: huangjiajun Date: Fri, 17 Jul 2026 17:27:13 +0800 Subject: [PATCH 2/2] fix(123pan): preserve login error messages Use errors.New for API-provided login errors so the driver passes the Go printf analyzer without treating provider messages as format strings. --- drivers/123/util.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/123/util.go b/drivers/123/util.go index 377c719465b..f02e3fc8347 100644 --- a/drivers/123/util.go +++ b/drivers/123/util.go @@ -174,7 +174,7 @@ func (d *Pan123) login() error { return err } if utils.Json.Get(res.Body(), "code").ToInt() != 200 { - err = fmt.Errorf(utils.Json.Get(res.Body(), "message").ToString()) + err = errors.New(utils.Json.Get(res.Body(), "message").ToString()) } else { d.AccessToken = utils.Json.Get(res.Body(), "data", "token").ToString() }