feat: API Key 静默认证 + 多邮箱支持

核心改动:
- V3 迁移: accounts 加 api_key/api_secret + account_emails 多邮箱关联表
- HMAC 验签改用 api_secret 替代密码哈希(改密码不影响集成)
- findByAnyEmail 支持主邮箱 + 关联邮箱查找
- AdminController: API Key 生成/重置 + 邮箱绑定/解绑/列表
- 前端 Users.vue: API Key 列 + 生成按钮 + Secret 复制弹窗
- 现有邮箱自动迁移到 account_emails 表

认证流程:
  旧: X-Email → account.email → passwordHash 作 HMAC key
  新: X-Email → account_emails ∪ account.email → api_secret 作 HMAC key
This commit is contained in:
mediabot-pt
2026-06-29 16:30:53 +08:00
parent c4877f983a
commit 2d91552ea4
11 changed files with 349 additions and 13 deletions

View File

@@ -0,0 +1,29 @@
-- PAR (PT Adapter Registry) Schema - Phase 3
-- Flyway Migration V3: API Key auth + multi-email support
-- accounts 表新增 api_key + api_secret
ALTER TABLE accounts
ADD api_key VARCHAR(64) NULL UNIQUE COMMENT 'API 密钥(public)',
ADD api_secret VARCHAR(128) NULL COMMENT 'API 密钥(secret,用于 HMAC 签名)';
-- 为已有管理员账号生成默认 key
UPDATE accounts SET
api_key = CONCAT('par_', LOWER(LEFT(MD5(RAND()), 16))),
api_secret = LEFT(SHA2(CONCAT(email, RAND()), 256), 64)
WHERE api_key IS NULL AND trust_level = 2;
-- 多邮箱关联表
CREATE TABLE account_emails (
id BIGINT UNSIGNED NOT NULL AUTO_INCREMENT COMMENT '主键',
account_id BIGINT UNSIGNED NOT NULL COMMENT '关联账户ID',
email VARCHAR(255) NOT NULL COMMENT '邮箱地址',
verified TINYINT(1) NOT NULL DEFAULT 1 COMMENT '是否已验证',
created_at DATETIME NOT NULL DEFAULT CURRENT_TIMESTAMP COMMENT '绑定时间',
PRIMARY KEY (id),
UNIQUE KEY uk_email (email),
KEY idx_account (account_id)
) ENGINE=InnoDB DEFAULT CHARSET=utf8mb4 COLLATE=utf8mb4_unicode_ci COMMENT='账户多邮箱关联表';
-- 现有邮箱迁移到关联表
INSERT INTO account_emails (account_id, email, verified)
SELECT id, email, 1 FROM accounts WHERE deleted = 0;