feat: API Key 静默认证 + 多邮箱支持

核心改动:
- V3 迁移: accounts 加 api_key/api_secret + account_emails 多邮箱关联表
- HMAC 验签改用 api_secret 替代密码哈希(改密码不影响集成)
- findByAnyEmail 支持主邮箱 + 关联邮箱查找
- AdminController: API Key 生成/重置 + 邮箱绑定/解绑/列表
- 前端 Users.vue: API Key 列 + 生成按钮 + Secret 复制弹窗
- 现有邮箱自动迁移到 account_emails 表

认证流程:
  旧: X-Email → account.email → passwordHash 作 HMAC key
  新: X-Email → account_emails ∪ account.email → api_secret 作 HMAC key
This commit is contained in:
mediabot-pt
2026-06-29 16:30:53 +08:00
parent c4877f983a
commit 2d91552ea4
11 changed files with 349 additions and 13 deletions

View File

@@ -44,7 +44,8 @@ export default {
},
users: {
list: () => api.get('/admin/accounts'),
setTrustLevel: (id, level) => api.post(`/admin/accounts/${id}/trust-level`, null, { params: { level } })
setTrustLevel: (id, level) => api.post(`/admin/accounts/${id}/trust-level`, null, { params: { level } }),
genApiKey: (id) => api.post(`/admin/accounts/${id}/api-key`)
},
health: () => api.get('/health', { baseURL: '' })
}