feat: 重构认证流程,升级工具功能并优化后端配置
- 修复token泄露风险:改用X-Local-Creds-Token请求头传递token,从URL Hash读取set_token避免日志记录 - 重构全站认证逻辑:提取公用工具函数统一各服务的认证校验流程 - 升级投资账本工具:支持本地上传CSV和粘贴文本,移除硬编码路径,适配新参数格式 - 新增403/404/500标准错误响应文件,统一API错误返回格式 - 优化后端配置:关闭ETag,重构CORS中间件,新增全局错误捕获,限制敏感文件访问 - 优化web zen box的Service Worker,支持音频分片请求与断点续传 - 清理冗余前端代码,调整页面格式与权限控制
This commit is contained in:
@@ -228,12 +228,22 @@ const saveModal = () => {
|
||||
refreshAll()
|
||||
}
|
||||
|
||||
const readSelectedFileText = async () => {
|
||||
const input = $('fileInput')
|
||||
const file = input && input.files && input.files[0]
|
||||
if (!file) return ''
|
||||
return file.text()
|
||||
}
|
||||
|
||||
const parseFile = async () => {
|
||||
try {
|
||||
setStatus('解析中...')
|
||||
$('btnParse').disabled = true
|
||||
const fileText = await readSelectedFileText()
|
||||
const rawText = String((fileText || $('rawText').value || '')).trim()
|
||||
if (!rawText) throw new Error('请选择 CSV 文件,或粘贴 CSV 文本')
|
||||
const payload = {
|
||||
file_path: $('filePath').value.trim(),
|
||||
raw_text: rawText,
|
||||
symbol: $('symbol').value.trim()
|
||||
}
|
||||
const resp = await fetch('/api/investment_ledger/parse', {
|
||||
|
||||
Reference in New Issue
Block a user