refactor: 彻底移除 apiSecret 认证方式,仅保留 Bearer + PSK
删除: - HmacUtil: deriveApiKey/deriveApiSecret/verifyMediabotPsk - HmacAuthInterceptor: apiSecret 验签/自动创建账户/readBody - AccountService: generateApiCredentials/registerByInterceptor - AccountDTO: apiKey 字段 - AuthController: register 返回 apiSecret - AdminController: generateApiKey 端点 - Users.vue: API Key 列/生成密钥弹窗 - api/index.js: genApiKey 认证方式简化为两种: Bearer Token → Web 管理后台 PSK 签名 → 外部集成客户端
This commit is contained in:
@@ -80,27 +80,6 @@ public class HmacUtil {
|
||||
return sign(hmacSecret, input);
|
||||
}
|
||||
|
||||
/**
|
||||
* 验证 medibot PSK 签名(用于账户恢复 / 自动提权)
|
||||
* signContent = email + ":" + timestamp
|
||||
*/
|
||||
public static boolean verifyMediabotPsk(String email, long timestamp, String signature, String psk) {
|
||||
if (psk == null || psk.isBlank()) return false;
|
||||
long now = System.currentTimeMillis() / 1000;
|
||||
if (Math.abs(now - timestamp) > 300) return false; // 5 分钟窗口
|
||||
String payload = email.toLowerCase().trim() + ":" + timestamp;
|
||||
return verify(psk, payload, signature);
|
||||
}
|
||||
|
||||
/**
|
||||
* 从 email + 服务端密钥确定性推导 api_key
|
||||
*/
|
||||
public static String deriveApiKey(String email, String hmacSecret) {
|
||||
String input = email.toLowerCase().trim() + ":par-api-key";
|
||||
String hash = sign(hmacSecret, input);
|
||||
return "par_" + sha256(hash).substring(0, 16);
|
||||
}
|
||||
|
||||
private static String bytesToHex(byte[] bytes) {
|
||||
StringBuilder sb = new StringBuilder();
|
||||
for (byte b : bytes) {
|
||||
|
||||
Reference in New Issue
Block a user