feat: 确定性密钥推导 + HMAC 自动恢复账户
- HmacUtil.deriveApiSecret/deriveApiKey: email+HMAC_SECRET 确定性推导
- 注册时用推导值替代随机生成(同 email 永远同 key)
- HMAC 拦截器:未知邮箱但签名匹配 → 自动创建账户
- 重装后 mediabot 直接发 HMAC 请求即可恢复,无需重新注册
核心: apiSecret = HMAC(email + ':par-api-secret', HMAC_SECRET)
同一 email + 同一 HMAC_SECRET → 永久不变的凭据
This commit is contained in:
@@ -71,6 +71,24 @@ public class HmacUtil {
|
||||
return hash.substring(0, 16);
|
||||
}
|
||||
|
||||
/**
|
||||
* 从 email + 服务端密钥确定性推导 api_secret
|
||||
* 同一 email + 同一 HMAC_SECRET → 永远返回相同值
|
||||
*/
|
||||
public static String deriveApiSecret(String email, String hmacSecret) {
|
||||
String input = email.toLowerCase().trim() + ":par-api-secret";
|
||||
return sign(hmacSecret, input);
|
||||
}
|
||||
|
||||
/**
|
||||
* 从 email + 服务端密钥确定性推导 api_key
|
||||
*/
|
||||
public static String deriveApiKey(String email, String hmacSecret) {
|
||||
String input = email.toLowerCase().trim() + ":par-api-key";
|
||||
String hash = sign(hmacSecret, input);
|
||||
return "par_" + sha256(hash).substring(0, 16);
|
||||
}
|
||||
|
||||
private static String bytesToHex(byte[] bytes) {
|
||||
StringBuilder sb = new StringBuilder();
|
||||
for (byte b : bytes) {
|
||||
|
||||
Reference in New Issue
Block a user