diff --git a/par-core/src/main/java/com/par/core/interceptor/HmacAuthInterceptor.java b/par-core/src/main/java/com/par/core/interceptor/HmacAuthInterceptor.java index 54a940e..1ab603e 100644 --- a/par-core/src/main/java/com/par/core/interceptor/HmacAuthInterceptor.java +++ b/par-core/src/main/java/com/par/core/interceptor/HmacAuthInterceptor.java @@ -14,6 +14,7 @@ import org.springframework.web.servlet.HandlerInterceptor; import java.io.IOException; import java.nio.charset.StandardCharsets; import java.util.Base64; +import java.util.Enumeration; /** * API 鉴权拦截器 @@ -62,17 +63,23 @@ public class HmacAuthInterceptor implements HandlerInterceptor { // 方式 2:PSK 签名 String sig = request.getHeader(HEADER_SIGNATURE); String ts = request.getHeader(HEADER_TIMESTAMP); - String email = request.getHeader(HEADER_EMAIL); - if (sig != null && ts != null && email != null) { + if (sig != null && ts != null) { try { if (pskService.verify(request.getMethod(), request.getRequestURI(), Long.parseLong(ts), sig) != null) { - // X-Email 仅标识身份,不参与签名 - Account account = accountService.findByAnyEmail(email); + // X-Email 支持多值,依次尝试匹配账户 + Account account = null; + String matchedEmail = null; + var emails = request.getHeaders(HEADER_EMAIL); + while (emails != null && emails.hasMoreElements()) { + String e = emails.nextElement(); + account = accountService.findByAnyEmail(e); + if (account != null) { matchedEmail = e; break; } + } request.setAttribute("accountId", account != null ? account.getId() : 0L); request.setAttribute("trustLevel", account != null ? account.getTrustLevel() : com.par.core.enums.TrustLevel.TRUSTED); - request.setAttribute("authEmail", email); + request.setAttribute("authEmail", matchedEmail); return true; } } catch (NumberFormatException ignored) {}