feat: Mediabot PSK 签名恢复 + 注册自动提权

- par.mediabot.psk 配置项(环境变量 PAR_MEDIABOT_PSK)
- HmacUtil.verifyMediabotPsk() PSK 签名验证
- POST /auth/recover: PSK 签名 → 返回/重建 apiKey/apiSecret → 自动 TRUSTED
- POST /auth/register: 携带 PSK 头 → 自动提升为 TRUSTED
- AccountService 新增 updateAccount

mediabot 端只需:
  const PSK = '内置密钥'
  sig = HMAC('email:timestamp', PSK)
  POST /auth/recover {email} + X-Medibot-* 头 → 拿回凭据
This commit is contained in:
mediabot-pt
2026-06-29 16:44:59 +08:00
parent aed8035995
commit 11d0840e42
5 changed files with 110 additions and 7 deletions

View File

@@ -43,6 +43,11 @@ public interface AccountService {
*/
void registerByInterceptor(Account account);
/**
* 更新账户
*/
void updateAccount(Account account);
/**
* 转换为 DTO(脱敏)
*/

View File

@@ -117,6 +117,11 @@ public class AccountServiceImpl implements AccountService {
accountMapper.insert(account);
}
@Override
public void updateAccount(Account account) {
accountMapper.updateById(account);
}
@Override
public AccountDTO toDTO(Account account) {
if (account == null) return null;