feat: 重构认证流程,升级工具功能并优化后端配置
- 修复token泄露风险:改用X-Local-Creds-Token请求头传递token,从URL Hash读取set_token避免日志记录 - 重构全站认证逻辑:提取公用工具函数统一各服务的认证校验流程 - 升级投资账本工具:支持本地上传CSV和粘贴文本,移除硬编码路径,适配新参数格式 - 新增403/404/500标准错误响应文件,统一API错误返回格式 - 优化后端配置:关闭ETag,重构CORS中间件,新增全局错误捕获,限制敏感文件访问 - 优化web zen box的Service Worker,支持音频分片请求与断点续传 - 清理冗余前端代码,调整页面格式与权限控制
This commit is contained in:
@@ -2,10 +2,13 @@
|
||||
;(function handleSetToken() {
|
||||
try {
|
||||
const u = new URL(window.location.href)
|
||||
const token = u.searchParams.get('set_token')
|
||||
const hashRaw = String(u.hash || '').replace(/^#/, '')
|
||||
const hashParams = new URLSearchParams(hashRaw.startsWith('?') ? hashRaw.slice(1) : hashRaw)
|
||||
const token = hashParams.get('set_token')
|
||||
if (token) {
|
||||
localStorage.setItem('toolbox_creds_token', token)
|
||||
u.searchParams.delete('set_token')
|
||||
hashParams.delete('set_token')
|
||||
u.hash = hashParams.toString() ? `#${hashParams.toString()}` : ''
|
||||
window.history.replaceState(null, '', u.toString())
|
||||
}
|
||||
} catch {}
|
||||
@@ -2002,8 +2005,11 @@
|
||||
;(async function tryAutoFill() {
|
||||
try {
|
||||
const token = localStorage.getItem('toolbox_creds_token') || ''
|
||||
const url = '/api/rational_lock/auth/local_creds' + (token ? '?token=' + encodeURIComponent(token) : '')
|
||||
const r = await fetch(url, { credentials: 'same-origin', cache: 'no-store' })
|
||||
const r = await fetch('/api/rational_lock/auth/local_creds', {
|
||||
headers: token ? { 'X-Local-Creds-Token': token } : {},
|
||||
credentials: 'same-origin',
|
||||
cache: 'no-store'
|
||||
})
|
||||
const d = await r.json().catch(() => null)
|
||||
if (d && d.ok && d.creds) {
|
||||
if (d.creds.username) $('login-username').value = d.creds.username
|
||||
|
||||
Reference in New Issue
Block a user