a6f763ffd8
- 修复token泄露风险:改用X-Local-Creds-Token请求头传递token,从URL Hash读取set_token避免日志记录 - 重构全站认证逻辑:提取公用工具函数统一各服务的认证校验流程 - 升级投资账本工具:支持本地上传CSV和粘贴文本,移除硬编码路径,适配新参数格式 - 新增403/404/500标准错误响应文件,统一API错误返回格式 - 优化后端配置:关闭ETag,重构CORS中间件,新增全局错误捕获,限制敏感文件访问 - 优化web zen box的Service Worker,支持音频分片请求与断点续传 - 清理冗余前端代码,调整页面格式与权限控制
67 lines
2.5 KiB
JavaScript
67 lines
2.5 KiB
JavaScript
const el = id => document.getElementById(id)
|
|
const highlight = (text, terms) => {
|
|
if (!terms || terms.length === 0) return text
|
|
let s = text
|
|
terms.forEach((t, i) => {
|
|
const cls = `kw-${i % 6}`
|
|
const re = new RegExp(`(${t.replace(/[.*+?^${}()|[\]\\]/g, '\\$&')})`, 'gi')
|
|
s = s.replace(re, `<mark class="${cls}">$1</mark>`)
|
|
})
|
|
return s
|
|
}
|
|
|
|
const fmtCNDateTime = (d) => {
|
|
const date = d instanceof Date ? d : new Date()
|
|
try {
|
|
const s = new Intl.DateTimeFormat('zh-CN', { timeZone: 'Asia/Shanghai', year: 'numeric', month: '2-digit', day: '2-digit', hour: '2-digit', minute: '2-digit', second: '2-digit', hour12: false }).format(date)
|
|
return s.replace(/\//g, '-').replace(/\u200E/g, '')
|
|
} catch {
|
|
const pad = n => String(n).padStart(2, '0')
|
|
const y = date.getFullYear(), m = pad(date.getMonth()+1), day = pad(date.getDate()), hh = pad(date.getHours()), mm = pad(date.getMinutes()), ss = pad(date.getSeconds())
|
|
return `${y}-${m}-${day} ${hh}:${mm}:${ss}`
|
|
}
|
|
}
|
|
|
|
const fmtCNSimpleTime = (d) => {
|
|
const date = d instanceof Date ? d : new Date()
|
|
try {
|
|
const s = new Intl.DateTimeFormat('zh-CN', { timeZone: 'Asia/Shanghai', hour: '2-digit', minute: '2-digit', hour12: false }).format(date)
|
|
return s.replace(/\u200E/g, '')
|
|
} catch {
|
|
const pad = n => String(n).padStart(2, '0')
|
|
return `${pad(date.getHours())}:${pad(date.getMinutes())}`
|
|
}
|
|
}
|
|
|
|
const cnDateStr = (d) => {
|
|
const date = d instanceof Date ? d : new Date()
|
|
try {
|
|
const s = new Intl.DateTimeFormat('zh-CN', { timeZone: 'Asia/Shanghai', year: 'numeric', month: '2-digit', day: '2-digit' }).format(date)
|
|
return s.replace(/\//g, '-').replace(/\u200E/g, '')
|
|
} catch {
|
|
const pad = n => String(n).padStart(2, '0')
|
|
return `${date.getFullYear()}-${pad(date.getMonth()+1)}-${pad(date.getDate())}`
|
|
}
|
|
}
|
|
|
|
window.fmtCNDateTime = fmtCNDateTime
|
|
window.fmtCNSimpleTime = fmtCNSimpleTime
|
|
window.cnDateStr = cnDateStr
|
|
|
|
;(function handleSetToken() {
|
|
try {
|
|
const u = new URL(window.location.href)
|
|
const hashRaw = String(u.hash || '').replace(/^#/, '')
|
|
if (!/(^|[?&])set_token=/.test(hashRaw)) return
|
|
const hashParams = new URLSearchParams(hashRaw.startsWith('?') ? hashRaw.slice(1) : hashRaw)
|
|
const token = hashParams.get('set_token')
|
|
if (token) {
|
|
localStorage.setItem('toolbox_creds_token', token)
|
|
hashParams.delete('set_token')
|
|
const nextHash = hashParams.toString()
|
|
u.hash = nextHash ? `#${nextHash}` : ''
|
|
window.history.replaceState(null, '', u.toString())
|
|
}
|
|
} catch {}
|
|
})()
|