feat: 注册时自动生成 API Key,mediabot 自注册即可获得凭据

- AccountService.register() 自动生成 api_key + api_secret
- POST /auth/register 返回 apiKey + apiSecret(一次性)
- POST /auth/login 返回 apiKey(不含 secret)
- V3 迁移自动为已有管理员生成 key

mediabot 集成流程:
  1. POST /auth/register → 得到 apiKey + apiSecret → 保存
  2. 管理员在后台提升 trustLevel 为 TRUSTED
  3. 用 apiKey/apiSecret 做 HMAC 签名调用写入接口
This commit is contained in:
mediabot-pt
2026-06-29 16:34:39 +08:00
parent 2d91552ea4
commit 26c686fa69
2 changed files with 21 additions and 4 deletions

View File

@@ -54,6 +54,15 @@ public class AccountServiceImpl implements AccountService {
account.setTrustLevel(TrustLevel.MEMBER);
account.setIsActive(true);
// 自动生成 API Key(静默认证凭据)
byte[] keyBytes = new byte[12];
SECURE_RANDOM.nextBytes(keyBytes);
account.setApiKey("par_" + bytesToHex(keyBytes));
byte[] secretBytes = new byte[32];
SECURE_RANDOM.nextBytes(secretBytes);
account.setApiSecret(Base64.getUrlEncoder().withoutPadding().encodeToString(secretBytes));
accountMapper.insert(account);
// 关联匿名统计记录