feat: 确定性密钥推导 + HMAC 自动恢复账户

- HmacUtil.deriveApiSecret/deriveApiKey: email+HMAC_SECRET 确定性推导
- 注册时用推导值替代随机生成(同 email 永远同 key)
- HMAC 拦截器:未知邮箱但签名匹配 → 自动创建账户
- 重装后 mediabot 直接发 HMAC 请求即可恢复,无需重新注册

核心: apiSecret = HMAC(email + ':par-api-secret', HMAC_SECRET)
      同一 email + 同一 HMAC_SECRET → 永久不变的凭据
This commit is contained in:
mediabot-pt
2026-06-29 16:38:37 +08:00
parent 92f4ed7a2a
commit aed8035995
4 changed files with 73 additions and 21 deletions

View File

@@ -71,6 +71,24 @@ public class HmacUtil {
return hash.substring(0, 16);
}
/**
* 从 email + 服务端密钥确定性推导 api_secret
* 同一 email + 同一 HMAC_SECRET → 永远返回相同值
*/
public static String deriveApiSecret(String email, String hmacSecret) {
String input = email.toLowerCase().trim() + ":par-api-secret";
return sign(hmacSecret, input);
}
/**
* 从 email + 服务端密钥确定性推导 api_key
*/
public static String deriveApiKey(String email, String hmacSecret) {
String input = email.toLowerCase().trim() + ":par-api-key";
String hash = sign(hmacSecret, input);
return "par_" + sha256(hash).substring(0, 16);
}
private static String bytesToHex(byte[] bytes) {
StringBuilder sb = new StringBuilder();
for (byte b : bytes) {