|
|
3441eb9478
|
chore: pure-random 32-char secret, no default source, legacy migration
- genSecret: drop SeaReport- prefix, plain 32-char random hex
- users.source: no default anywhere (register/admin/external), ADD COLUMN
migration now VARCHAR DEFAULT '' (was ENUM netease default)
- legacy upgrade path kept: ENUM->VARCHAR MODIFY + user_identities MODIFY
+ sources seeded netease/skin idempotently
- docs updated (credential format, no prefix)
|
2026-08-19 20:16:16 +08:00 |
|
|
|
65edbaf157
|
refactor: session-based external auth, dynamic sources, drop netease UID
Auth (external API):
- ID: 16-digit random (non-sequential); Secret: SeaReport- + 32 hex
- POST /auth/session: ID+Secret -> Bearer SESSION (24h, single-session,
old session invalidated on re-issue, disabled client invalidates)
- clientAuth now validates Bearer SESSION via api_sessions JOIN api_clients
Sources (dynamic, no default, open-source friendly):
- sources table + CRUD route (/api/sources, owner; delete guarded by usage)
- users/user_identities.source ENUM -> VARCHAR, seeded netease/skin
- register/admin create/identity bind: validate against enabled sources
- UI: 来源管理 page; source dropdowns loaded dynamically everywhere
(register, dashboard identity, users admin, bans), labels dynamic
UID removal:
- game_uid/reporter_game_uid no longer required (db default '', validations
dropped, frontend fields optional)
Docs: EXTERNAL-API.md session flow + new credential format; API.md updated
Verified: 37 checks (syntax, session logic, source CRUD, UID removal, docs)
|
2026-08-19 20:08:06 +08:00 |
|
|
|
6056153f57
|
security: external API - only ID+Secret auth, remove legacy key & JWT
- removed x-external-key (single key) auth path + getExternalKey
- removed JWT passthrough in clientAuth (Bearer no longer accepted)
- removed /auth/login (JWT endpoint) and /my-tickets (JWT-only)
- clientAuth now mandatory: missing/invalid/disabled client -> 401
(closed the 'no config = allow all' authorization bypass)
- moved /auth/register BEHIND clientAuth (was anonymous abuse surface)
- clients mgmt endpoints keep authenticate + role check (admin UI)
- docs + UI copy updated to single auth method
- verified: 30 checks incl. full-tree scan for legacy key refs
|
2026-08-19 19:44:34 +08:00 |
|
|
|
257cd14051
|
feat: external API for QQ bot - client id+secret auth, ticket tracking, bans, per-server data
- db: api_clients table + server_groups.alias + tickets/bans server_name (auto-migrate)
- external.js: client_id+secret auth (multi-client, bcrypt, show-once secret),
legacy x-external-key compat, JWT pass-through
- POST /tickets (optional server), GET /tickets/track?token= (full lifecycle)
- GET/POST /bans, reported-players/stats/all-tickets with server filter
- GET /servers (alias list), client CRUD (owner/admin, audit logged)
- resolveServer: alias | 分组/子服 | server_name
- polls.js: server_groups CRUD with alias (add/edit, dup check)
- servers page: alias display + edit; new 外部API page: client mgmt + quick docs
- API.md: full external API section (auth matrix, server param syntax)
- verified: 37 checks incl. resolveServer sandbox (alias/group/fallback)
|
2026-08-19 19:12:34 +08:00 |
|
|
|
559970c5b7
|
feat: one account can bind both netease + skin identities
- db: user_identities table (UNIQUE user_id+source), migrate backfill from users
- auth: GET/POST/DELETE /api/auth/identities - bind/unbind/list identities
(netease requires UID, one per source, name uniqueness, keep >=1)
- register/external/plugin/admin-created users auto-write primary identity
- tickets: submit uses selected identity (validated belongs to user)
- dashboard: 我的身份 card with bind/unbind UI
- ticket-create: identity selector when >1 identity
|
2026-08-17 01:17:09 +08:00 |
|
|
|
efe6b084be
|
sync: add source field to user list, create, edit, and external API
|
2026-07-15 04:43:30 +08:00 |
|
|
|
125b4f99fc
|
fix: only two sources (netease/skin), plugin uses skin
|
2026-07-15 04:36:01 +08:00 |
|
|
|
c493c1204b
|
feat: registration source selector (netease/skin/java)
|
2026-07-15 04:34:06 +08:00 |
|
|
|
befd51dbd5
|
fix: prevent username/email enumeration via registration error messages
|
2026-07-13 18:29:32 +08:00 |
|
|
|
b24f8cd74d
|
fix: critical - external POST parameter count mismatch (11 vs 10)
|
2026-07-13 18:26:49 +08:00 |
|
|
|
532efb962f
|
fix: HIGH+MEDIUM bugs from full audit - listen error, JWT, upload, mailer, webhook
|
2026-07-13 03:49:02 +08:00 |
|
|
|
7c03fe7635
|
fix: external register verify token mismatch, add type validation
|
2026-07-13 03:36:53 +08:00 |
|
|
|
a51e841fc9
|
refactor: English subcommands, plugin login/track redesign, clean external API routes
|
2026-07-13 03:35:13 +08:00 |
|
|
|
2a5c25f41c
|
refactor: unified /report command with login/register/track, external auth endpoints
|
2026-07-13 03:25:39 +08:00 |
|
|
|
de5a46f392
|
feat: Paper plugin + external API POST endpoint
|
2026-07-13 01:28:33 +08:00 |
|
|
|
ea3cd67e02
|
feat: external API for Java server integration with dedicated key
|
2026-07-13 01:24:03 +08:00 |
|