feat: 注册时自动生成 API Key,mediabot 自注册即可获得凭据
- AccountService.register() 自动生成 api_key + api_secret - POST /auth/register 返回 apiKey + apiSecret(一次性) - POST /auth/login 返回 apiKey(不含 secret) - V3 迁移自动为已有管理员生成 key mediabot 集成流程: 1. POST /auth/register → 得到 apiKey + apiSecret → 保存 2. 管理员在后台提升 trustLevel 为 TRUSTED 3. 用 apiKey/apiSecret 做 HMAC 签名调用写入接口
This commit is contained in:
@@ -11,6 +11,8 @@ import jakarta.validation.Valid;
|
||||
import lombok.RequiredArgsConstructor;
|
||||
import org.springframework.web.bind.annotation.*;
|
||||
|
||||
import java.util.Map;
|
||||
|
||||
/**
|
||||
* 认证控制器
|
||||
* 注册、登录(读取公开,无需鉴权)
|
||||
@@ -24,22 +26,28 @@ public class AuthController {
|
||||
private final HmacAuthInterceptor hmacAuthInterceptor;
|
||||
|
||||
/**
|
||||
* 用户注册
|
||||
* 用户注册(自动生成 API Key,apiSecret 仅此时返回一次)
|
||||
*/
|
||||
@PostMapping("/register")
|
||||
public ApiResponse<AccountDTO> register(@Valid @RequestBody RegisterRequest request) {
|
||||
public ApiResponse<Map<String, Object>> register(@Valid @RequestBody RegisterRequest request) {
|
||||
Account account = accountService.register(request);
|
||||
return ApiResponse.success(accountService.toDTO(account));
|
||||
AccountDTO dto = accountService.toDTO(account);
|
||||
Map<String, Object> result = new java.util.LinkedHashMap<>();
|
||||
result.put("account", dto);
|
||||
result.put("apiKey", account.getApiKey());
|
||||
result.put("apiSecret", account.getApiSecret()); // 仅注册时返回,请立即保存
|
||||
return ApiResponse.success(result);
|
||||
}
|
||||
|
||||
/**
|
||||
* 用户登录,返回 Bearer token(有效期 24 小时)
|
||||
* 用户登录,返回 Bearer token + api_key
|
||||
*/
|
||||
@PostMapping("/login")
|
||||
public ApiResponse<AccountDTO> login(@Valid @RequestBody LoginRequest request) {
|
||||
Account account = accountService.login(request);
|
||||
AccountDTO dto = accountService.toDTO(account);
|
||||
dto.setToken(hmacAuthInterceptor.generateToken(account.getEmail()));
|
||||
dto.setApiKey(account.getApiKey());
|
||||
return ApiResponse.success(dto);
|
||||
}
|
||||
}
|
||||
|
||||
@@ -54,6 +54,15 @@ public class AccountServiceImpl implements AccountService {
|
||||
account.setTrustLevel(TrustLevel.MEMBER);
|
||||
account.setIsActive(true);
|
||||
|
||||
// 自动生成 API Key(静默认证凭据)
|
||||
byte[] keyBytes = new byte[12];
|
||||
SECURE_RANDOM.nextBytes(keyBytes);
|
||||
account.setApiKey("par_" + bytesToHex(keyBytes));
|
||||
|
||||
byte[] secretBytes = new byte[32];
|
||||
SECURE_RANDOM.nextBytes(secretBytes);
|
||||
account.setApiSecret(Base64.getUrlEncoder().withoutPadding().encodeToString(secretBytes));
|
||||
|
||||
accountMapper.insert(account);
|
||||
|
||||
// 关联匿名统计记录
|
||||
|
||||
Reference in New Issue
Block a user