65edbaf157
refactor: session-based external auth, dynamic sources, drop netease UID
...
Auth (external API):
- ID: 16-digit random (non-sequential); Secret: SeaReport- + 32 hex
- POST /auth/session: ID+Secret -> Bearer SESSION (24h, single-session,
old session invalidated on re-issue, disabled client invalidates)
- clientAuth now validates Bearer SESSION via api_sessions JOIN api_clients
Sources (dynamic, no default, open-source friendly):
- sources table + CRUD route (/api/sources, owner; delete guarded by usage)
- users/user_identities.source ENUM -> VARCHAR, seeded netease/skin
- register/admin create/identity bind: validate against enabled sources
- UI: 来源管理 page; source dropdowns loaded dynamically everywhere
(register, dashboard identity, users admin, bans), labels dynamic
UID removal:
- game_uid/reporter_game_uid no longer required (db default '', validations
dropped, frontend fields optional)
Docs: EXTERNAL-API.md session flow + new credential format; API.md updated
Verified: 37 checks (syntax, session logic, source CRUD, UID removal, docs)
2026-08-19 20:08:06 +08:00
1d669fd1d0
feat: skin site UUID lookup - auto-fetch UUID from player name
...
- GET /settings/uuid-lookup?site=&name= : proxy Yggdrasil API
(POST {site}/api/yggdrasil/api/profiles/minecraft), SSRF guard,
10s timeout, name regex, UUID formatting (with dashes)
- GET /settings/skin-site : public read of configured skin site
- settings page: 皮肤站地址 config
- bind identity modals (player dashboard + admin users): 获取UUID button,
auto-fill site from settings, auto-fill UID from lookup
- verified live against littleskin.cn (Steve -> df273bda...)
- API docs updated
2026-08-17 02:05:21 +08:00
a6a548b1ce
fix: identity bind row layout - select stole full width, inputs invisible
...
Root cause: .form-group select global width:100% inherited inside flex row,
pushing the two text inputs to zero width. Fix: fixed 92px select
(flex:0 0 92px), inputs flex:1 1 30% with min-width:0 + width:auto,
button flex:0 0 auto, no wrap.
2026-08-17 01:52:20 +08:00
25a766591e
feat: admin user management supports multi-identity bind/unbind
...
- users list: identity_count column (backend subquery)
- user detail: returns identities array
- POST /users/:id/identities, DELETE /users/:id/identities/:identityId
(owner protection, dup checks, keep >=1, audit logs)
- users page: identity column in table + manage section in edit modal
- API docs updated
2026-08-17 01:34:20 +08:00
6e9101a506
fix: deploy crash + multiple bug fixes + cleanup
...
- server.js: fix getSiteName() returning string when not installed causing
'getSiteName(...).then is not a function' crash on homepage (deploy blocker)
- server.js: auto-load business routes after install completes (no restart needed),
HTML cache keyed by api_key
- install: validate db name/email/password, trigger route loading after complete
- app.js: fix forgot/reset/verify pages rendering HomePage (missing page mapping)
- verify.js: support URL token auto-verification for external registration links
- auth: new email_code template for 6-digit code, reset_password template
(forgot-password was using verify_email template)
- upload.js: fix MP4 magic-bytes check using undefined buf variable
- tickets.js: status enum validation, anonymous submission rate limit
- security.js: XSS whitelist preserves email template HTML, strips scripts,
blocks javascript:/data: hrefs; CORS reject returns 403
- bans.js: allow clearing reason/duration, status enum validation
- users.js: fix req.user.role ReferenceError in create user modal
- home.js: tracking results now have detail view button
- .gitignore: ignore data/ (db credentials), logs, session files, temp scripts
2026-08-16 21:21:25 +08:00
c3cd97676e
fix: create user server toggle only shows for admin/owner, initial state correct
2026-07-17 00:07:58 +08:00
09f0d8f2aa
fix: 12 issues - admin permission scope, player sidebar nav, SMTP label, user create servers
2026-07-16 23:04:15 +08:00
a8309aa456
refactor: use user_servers junction table instead of JSON column
2026-07-15 04:55:57 +08:00
a34314ac9d
feat: admin server assignment in user management
2026-07-15 04:53:27 +08:00
efe6b084be
sync: add source field to user list, create, edit, and external API
2026-07-15 04:43:30 +08:00
021351d898
fix: restore from regex corruption, JS-bind modal close, data-action delegation
2026-07-15 03:53:16 +08:00
f0e891b17c
fix: data-action delegation + convert onclick to event listeners, sidebar+logout+modals
2026-07-15 02:44:18 +08:00
6657c05dec
fix: add escJs for JS string escaping in onclick attributes, apply to users/templates/notifications
2026-07-12 13:09:52 +08:00
247a4e851d
feat: MC Report System - MySQL + Express + Vanilla JS SPA
2026-07-12 01:23:19 +08:00