feat: 重构认证流程,升级工具功能并优化后端配置

- 修复token泄露风险:改用X-Local-Creds-Token请求头传递token,从URL Hash读取set_token避免日志记录
- 重构全站认证逻辑:提取公用工具函数统一各服务的认证校验流程
- 升级投资账本工具:支持本地上传CSV和粘贴文本,移除硬编码路径,适配新参数格式
- 新增403/404/500标准错误响应文件,统一API错误返回格式
- 优化后端配置:关闭ETag,重构CORS中间件,新增全局错误捕获,限制敏感文件访问
- 优化web zen box的Service Worker,支持音频分片请求与断点续传
- 清理冗余前端代码,调整页面格式与权限控制
This commit is contained in:
yangxiangyuan
2026-08-01 21:50:05 +08:00
parent 2143adb3bb
commit a6f763ffd8
26 changed files with 304 additions and 72 deletions
+10 -4
View File
@@ -980,12 +980,17 @@ const createFolder = async () => {
}
const init = async () => {
// ===== set_token 处理:必须在 clearUrlQuery 之前 =====
// ===== set_token 仅允许从 hash 读取,避免进入服务端日志 =====
try {
const params = new URLSearchParams(window.location.search)
const setToken = params.get('set_token')
const currentUrl = new URL(window.location.href)
const hashRaw = String(currentUrl.hash || '').replace(/^#/, '')
const hashParams = new URLSearchParams(hashRaw.startsWith('?') ? hashRaw.slice(1) : hashRaw)
const setToken = hashParams.get('set_token')
if (setToken) {
localStorage.setItem('toolbox_creds_token', setToken)
hashParams.delete('set_token')
currentUrl.hash = hashParams.toString() ? `#${hashParams.toString()}` : ''
window.history.replaceState(null, '', currentUrl.toString())
}
} catch {}
@@ -1038,7 +1043,8 @@ const init = async () => {
try {
const token = localStorage.getItem('toolbox_creds_token') || ''
if (!token) return
const res = await fetch(apiBase + '/auth/local_creds?token=' + encodeURIComponent(token), {
const res = await fetch(apiBase + '/auth/local_creds', {
headers: { 'X-Local-Creds-Token': token },
credentials: 'same-origin',
cache: 'no-store'
})