Commit Graph

6 Commits

Author SHA1 Message Date
mediabot-pt
2d91552ea4 feat: API Key 静默认证 + 多邮箱支持
核心改动:
- V3 迁移: accounts 加 api_key/api_secret + account_emails 多邮箱关联表
- HMAC 验签改用 api_secret 替代密码哈希(改密码不影响集成)
- findByAnyEmail 支持主邮箱 + 关联邮箱查找
- AdminController: API Key 生成/重置 + 邮箱绑定/解绑/列表
- 前端 Users.vue: API Key 列 + 生成按钮 + Secret 复制弹窗
- 现有邮箱自动迁移到 account_emails 表

认证流程:
  旧: X-Email → account.email → passwordHash 作 HMAC key
  新: X-Email → account_emails ∪ account.email → api_secret 作 HMAC key
2026-06-29 16:30:53 +08:00
mediabot-pt
7575d65428 fix: 补全管理后台缺失的 API 端点 + 修复 @RequestParam 参数名
- AdminController: 新增 GET /admin/accounts 用户列表
- ConfigController: 新增 GET /configs/pending 待审核列表
- AdminController: 修复 @RequestParam 缺少参数名导致参数绑定失败
- SiteConfigMapper/ConfigService: 新增 selectPending/listPendingConfigs
2026-06-29 14:41:36 +08:00
mediabot-pt
bb26695c34 fix: 补回 @RequiredArgsConstructor 修复编译失败 + 移除过时 Maven 参数 2026-06-29 14:29:11 +08:00
mediabot-pt
c15016d57c feat: Bearer Token 认证,修复 Web 管理后台 401 问题
- HmacAuthInterceptor 增加 Bearer Token 优先认证(Web 管理后台)
- AuthController.login 使用 hmac.secret 签发 24h 有效 token
- AccountDTO 新增 token 字段(@JsonInclude NON_NULL)
- 前端 Login.vue 存储登录返回的 token
- 原有 HMAC 签名认证不受影响(外部 API 客户端继续可用)
2026-06-29 14:20:29 +08:00
mediabot-pt
d2c226c25f feat: 添加 Flyway V2 迁移,自动初始化默认管理员账号
- 首次部署自动创建 admin@par.local (trust_level=2)
- 已有账号自动提权(member→admin)
- 幂等安全,重复执行无副作用
- 使用项目 PasswordUtil 生成 bcrypt 哈希,无外部依赖
2026-06-29 14:14:16 +08:00
mediabot-pt
baa04b5138 Initial commit: PAR Server with Spring Boot 3.2, MyBatis-Plus, Flyway 2026-06-29 10:43:24 +08:00