chore: 初始提交 - 移除所有硬编码凭据,统一从环境变量读取
This commit is contained in:
@@ -0,0 +1,164 @@
|
||||
(() => {
|
||||
const originalFetch = window.fetch;
|
||||
window.fetch = (input, init = {}) => {
|
||||
const opts = Object.assign({}, init);
|
||||
if (!opts.credentials) opts.credentials = 'include';
|
||||
return originalFetch(input, opts);
|
||||
};
|
||||
const overlayId = 'authOverlay';
|
||||
const ensureOverlay = () => {
|
||||
let ov = document.getElementById(overlayId);
|
||||
if (ov) return ov;
|
||||
ov = document.createElement('div');
|
||||
ov.id = overlayId;
|
||||
ov.style.position = 'fixed';
|
||||
ov.style.left = '0'; ov.style.top = '0'; ov.style.right = '0'; ov.style.bottom = '0';
|
||||
ov.style.display = 'none';
|
||||
ov.style.alignItems = 'center';
|
||||
ov.style.justifyContent = 'center';
|
||||
ov.style.background = 'rgba(0,0,0,0.6)';
|
||||
ov.style.zIndex = '9999';
|
||||
const panel = document.createElement('div');
|
||||
panel.style.background = '#fff';
|
||||
panel.style.padding = '20px';
|
||||
panel.style.borderRadius = '8px';
|
||||
panel.style.boxShadow = '0 4px 12px rgba(0,0,0,0.2)';
|
||||
const title = document.createElement('div');
|
||||
title.textContent = '鉴权失败,请重新校验';
|
||||
title.style.fontSize = '16px';
|
||||
title.style.marginBottom = '12px';
|
||||
title.style.color = '#333';
|
||||
const debug = document.createElement('pre');
|
||||
debug.id = 'authDebug';
|
||||
debug.style.fontSize = '12px';
|
||||
debug.style.lineHeight = '1.5';
|
||||
debug.style.background = '#f7f7f8';
|
||||
debug.style.border = '1px solid #e3e3e7';
|
||||
debug.style.padding = '10px';
|
||||
debug.style.margin = '0 0 12px 0';
|
||||
debug.style.maxWidth = '520px';
|
||||
debug.style.maxHeight = '240px';
|
||||
debug.style.overflow = 'auto';
|
||||
debug.textContent = '正在收集诊断信息...';
|
||||
const btn = document.createElement('button');
|
||||
btn.textContent = '重新校验';
|
||||
btn.style.padding = '8px 16px';
|
||||
btn.addEventListener('click', async () => {
|
||||
await handshake();
|
||||
});
|
||||
panel.appendChild(title);
|
||||
panel.appendChild(debug);
|
||||
panel.appendChild(btn);
|
||||
ov.appendChild(panel);
|
||||
document.body.appendChild(ov);
|
||||
return ov;
|
||||
};
|
||||
const showOverlay = () => { ensureOverlay().style.display = 'flex'; };
|
||||
const hideOverlay = () => { const ov = ensureOverlay(); ov.style.display = 'none'; };
|
||||
let cfg = { enableCookieAuth: true, cookieName: 'picker_jwt' };
|
||||
const loadConfig = async () => {
|
||||
try {
|
||||
const res = await fetch('assets/auth_config.json', { cache: 'no-store' });
|
||||
if (!res.ok) return;
|
||||
const data = await res.json();
|
||||
cfg = Object.assign({}, cfg, data || {});
|
||||
} catch (_) {}
|
||||
};
|
||||
const debugState = {
|
||||
url: '',
|
||||
config: {},
|
||||
tokenInUrl: false,
|
||||
tokenCall: { tried: false, ok: false, status: 0 },
|
||||
handshake: { tried: false, ok: false, status: 0 },
|
||||
server: {}
|
||||
};
|
||||
const removeTokenFromUrl = () => {
|
||||
try {
|
||||
const nu = new URL(window.location.href);
|
||||
nu.searchParams.delete('token');
|
||||
window.history.replaceState(null, document.title, nu.toString());
|
||||
} catch (_) {}
|
||||
};
|
||||
const handleTokenInUrl = async () => {
|
||||
try {
|
||||
const u = new URL(window.location.href);
|
||||
const token = u.searchParams.get('token');
|
||||
debugState.url = u.toString();
|
||||
debugState.config = { enableCookieAuth: !!cfg.enableCookieAuth, cookieName: String(cfg.cookieName || '') };
|
||||
debugState.tokenInUrl = !!token;
|
||||
if (token) {
|
||||
if (cfg.enableCookieAuth) {
|
||||
const r = await fetch(`/auth/token?token=${encodeURIComponent(token)}`, { method: 'GET' });
|
||||
debugState.tokenCall.tried = true;
|
||||
debugState.tokenCall.ok = r.ok;
|
||||
debugState.tokenCall.status = r.status || 0;
|
||||
removeTokenFromUrl();
|
||||
return r.ok;
|
||||
} else {
|
||||
removeTokenFromUrl();
|
||||
return true;
|
||||
}
|
||||
}
|
||||
} catch (_) {}
|
||||
return true;
|
||||
};
|
||||
const handshake = async () => {
|
||||
if (!cfg.enableCookieAuth) { hideOverlay(); return true; }
|
||||
try {
|
||||
const r = await fetch('/auth/handshake', { cache: 'no-store' });
|
||||
debugState.handshake.tried = true;
|
||||
debugState.handshake.ok = r.ok;
|
||||
debugState.handshake.status = r.status || 0;
|
||||
try {
|
||||
const dbgRes = await fetch('/auth/debug', { cache: 'no-store' });
|
||||
if (dbgRes.ok) {
|
||||
debugState.server = await dbgRes.json();
|
||||
} else {
|
||||
debugState.server = { error: 'debug endpoint unavailable', status: dbgRes.status || 0 };
|
||||
}
|
||||
} catch (e) {
|
||||
debugState.server = { error: 'debug request failed' };
|
||||
}
|
||||
const box = document.getElementById('authDebug');
|
||||
if (box) {
|
||||
const lines = [];
|
||||
lines.push(`URL: ${debugState.url}`);
|
||||
lines.push(`Config: enableCookieAuth=${debugState.config.enableCookieAuth} cookieName=${debugState.config.cookieName}`);
|
||||
lines.push(`TokenInUrl: ${debugState.tokenInUrl}`);
|
||||
lines.push(`TokenCall: tried=${debugState.tokenCall.tried} ok=${debugState.tokenCall.ok} status=${debugState.tokenCall.status}`);
|
||||
lines.push(`Handshake: tried=${debugState.handshake.tried} ok=${debugState.handshake.ok} status=${debugState.handshake.status}`);
|
||||
if (debugState.server && typeof debugState.server === 'object') {
|
||||
lines.push(`Server.enableAuth: ${debugState.server.enableAuth}`);
|
||||
lines.push(`Server.jwkLoaded: ${debugState.server.jwkLoaded}`);
|
||||
lines.push(`Server.cookieName: ${debugState.server.cookieName}`);
|
||||
lines.push(`Server.cookiePresent: ${debugState.server.cookiePresent}`);
|
||||
lines.push(`Server.verified: ${debugState.server.verified}`);
|
||||
const rq = debugState.server.request || {};
|
||||
lines.push(`Server.request.host: ${rq.host || ''}`);
|
||||
lines.push(`Server.request.path: ${rq.path || ''}`);
|
||||
lines.push(`Server.request.origin: ${rq.origin || ''}`);
|
||||
lines.push(`Server.request.secFetchMode: ${rq.secFetchMode || ''}`);
|
||||
lines.push(`Server.request.forwardedProto: ${rq.forwardedProto || ''}`);
|
||||
lines.push(`Server.request.secure: ${rq.secure}`);
|
||||
lines.push(`Server.request.proto: ${rq.proto || ''}`);
|
||||
} else {
|
||||
lines.push(`Server: ${String(debugState.server)}`);
|
||||
}
|
||||
lines.push(`Expected URLs: /auth/token?token=... , /auth/handshake , /api/...`);
|
||||
box.textContent = lines.join('\n');
|
||||
}
|
||||
if (r.ok) { hideOverlay(); return true; }
|
||||
showOverlay(); return false;
|
||||
} catch (_) { showOverlay(); return false; }
|
||||
};
|
||||
const init = async () => {
|
||||
await loadConfig();
|
||||
await handleTokenInUrl();
|
||||
await handshake();
|
||||
};
|
||||
if (document.readyState === 'complete' || document.readyState === 'interactive') {
|
||||
init();
|
||||
} else {
|
||||
document.addEventListener('DOMContentLoaded', init);
|
||||
}
|
||||
})();
|
||||
Reference in New Issue
Block a user