Commit Graph
100 Commits
Author SHA1 Message Date
19174616018 d5b45c7aef feat: adjust confirm button order and improve file name wrapping 2026-02-19 20:09:05 +08:00
19174616018 14bc3f98fb chore: release desktop client 0.1.7 2026-02-19 19:44:15 +08:00
19174616018 f17dc2fda2 fix: unify client confirmations and inline rename UX 2026-02-19 19:36:52 +08:00
19174616018 c595cf28cb chore: bump desktop client version to 0.1.6 2026-02-19 19:14:35 +08:00
19174616018 6cdac7ddfb fix: restore login by defining getClientIp helper 2026-02-19 19:08:12 +08:00
19174616018 f253d542d9 feat: add online device management and desktop settings integration 2026-02-19 17:34:41 +08:00
19174616018 85039fcd29 feat(desktop): remember login in sqlite and streamline update flow 2026-02-19 00:12:33 +08:00
19174616018 2c30ae12e3 chore(release): bump desktop client to 0.1.4 2026-02-18 22:55:52 +08:00
19174616018 7549361d0a fix(desktop): require in-app confirmation before deleting shares 2026-02-18 22:53:53 +08:00
19174616018 0870bae3f2 fix(frontend): replace share delete confirm with in-app modal 2026-02-18 22:48:31 +08:00
19174616018 9dd2b2774b chore(release): bump desktop client to 0.1.3 2026-02-18 22:27:20 +08:00
19174616018 e40b9ff82c feat(desktop): stream download progress and auto-launch installer 2026-02-18 22:24:41 +08:00
19174616018 8297bee1ea docs(desktop): rewrite README in Chinese with integration and build guide 2026-02-18 22:16:20 +08:00
19174616018 f88505b829 feat(update): auto-clean old desktop installer packages 2026-02-18 22:14:26 +08:00
19174616018 134025b7a5 feat(share): reuse existing share and direct links per file 2026-02-18 22:13:14 +08:00
19174616018 18d92f37aa fix(frontend): use native confirm for share/direct-link deletion 2026-02-18 22:11:55 +08:00
19174616018 a3b8e4249a chore(release): publish desktop 0.1.2 with manual update checks 2026-02-18 22:02:34 +08:00
19174616018 e5c4b8f418 feat(security): shorten download signed URLs to 30s and remove update polling 2026-02-18 21:59:14 +08:00
19174616018 8617856388 chore(release): sync tauri cargo lock to 0.1.1 2026-02-18 21:25:47 +08:00
19174616018 7db94bf23c chore(release): bump desktop client to 0.1.1 2026-02-18 21:23:05 +08:00
19174616018 b560da04c7 feat(desktop): implement startup and scheduled auto update flow 2026-02-18 21:11:59 +08:00
19174616018 b0490e360f fix(desktop-ui): stabilize files toolbar layout 2026-02-18 21:08:18 +08:00
19174616018 0cff938756 chore(desktop): align update panel copy with one-click installer flow 2026-02-18 20:28:08 +08:00
19174616018 46b7f5dfcf feat(desktop): align requested 4/5/6/8 with resume queue batch and one-click update 2026-02-18 20:26:16 +08:00
19174616018 62c8fdc200 feat(desktop): add sort/filter, update center, and local sync workspace 2026-02-18 20:07:21 +08:00
19174616018 f1654165b8 perf(desktop): stream drag-upload and improve transfer status UX 2026-02-18 19:50:34 +08:00
19174616018 1776f8eb6d feat(desktop): add drag-and-drop upload for file view 2026-02-18 19:46:11 +08:00
19174616018 5c3fb759b3 style(desktop): improve alignment and spacing across file/share views 2026-02-18 19:33:39 +08:00
19174616018 e3d3823639 fix(desktop): enforce square file cards and icon tiles 2026-02-18 19:29:25 +08:00
19174616018 1d34ada9b7 feat(desktop): native download and working context menu actions 2026-02-18 19:25:52 +08:00
19174616018 3846c489e6 feat(desktop): square file cards and context-menu file actions 2026-02-18 18:30:53 +08:00
19174616018 3a0040793d feat(desktop): implement share management and hide endpoint settings 2026-02-18 17:17:49 +08:00
19174616018 a45aaf59ea feat(desktop): add tauri desktop client for cs.workyai.cn 2026-02-18 16:53:22 +08:00
19174616018 9b3abdbe6a fix: correct local datetime display and remove false devtools detection 2026-02-18 11:23:34 +08:00
19174616018 6b26b73ab0 fix: keep expired reservations reconcilable for delayed OSS logs 2026-02-18 10:49:58 +08:00
19174616018 2bd74b9eeb fix: ingest oss traffic logs without file extensions 2026-02-18 10:24:00 +08:00
19174616018 5688057607 fix: bump app.js cache busting version 2026-02-18 10:08:11 +08:00
19174616018 863c23f946 feat: add configurable stealth download security policies 2026-02-18 09:48:14 +08:00
19174616018 51b84d4966 fix: improve reservation cleanup and share popup handling 2026-02-17 23:55:31 +08:00
19174616018 01b15e1c28 feat: add share security, resumable upload, global search and reservation ops panel 2026-02-17 23:36:30 +08:00
19174616018 78f5f02f83 fix: bump app.js cache-busting version 2026-02-17 22:56:49 +08:00
19174616018 8d6ffa3448 ui: show file names instead of full paths in shares 2026-02-17 22:54:12 +08:00
19174616018 71733a5efc style: align share and direct-link table layout 2026-02-17 22:42:11 +08:00
19174616018 88a64b44cd fix: unify share/direct link click and copy actions 2026-02-17 22:39:19 +08:00
19174616018 d003ab711e fix: normalize traffic range buttons layout in settings 2026-02-17 22:14:40 +08:00
19174616018 4d226f3b86 feat: add independent direct-link sharing flow 2026-02-17 21:57:38 +08:00
19174616018 77bdda5fdb test: update admin/share edge scripts for cookie+csrf auth 2026-02-17 21:32:07 +08:00
19174616018 fede6c3b70 feat: add server-side admin user pagination and align traffic report accounting 2026-02-17 20:30:02 +08:00
19174616018 0791082fde feat: improve admin user management with filters and pagination 2026-02-17 20:13:32 +08:00
19174616018 807d5e5fcb feat: improve media preview UX with caching and loading states 2026-02-17 20:03:02 +08:00
19174616018 3c86e18bad fix: remove preview content-type override for aliyun oss compatibility 2026-02-17 19:51:01 +08:00
19174616018 60e7e5bb78 fix: use preview-mode signed URLs and graceful media preview fallback 2026-02-17 19:36:49 +08:00
19174616018 d6ceac5dbe fix: precheck local downloads to avoid JSON file download on quota errors 2026-02-17 19:32:48 +08:00
19174616018 3ace94d767 fix: fallback to file icon when thumbnail load fails 2026-02-17 19:29:42 +08:00
19174616018 0c660f65d6 feat: make zero download quota block downloads and use -1 for unlimited 2026-02-17 19:25:39 +08:00
19174616018 725c252100 fix: precheck local share download quota at download-url stage 2026-02-17 19:08:47 +08:00
19174616018 b93547d111 chore: properly ignore runtime storage and data directories 2026-02-17 19:07:11 +08:00
19174616018 ef67cd2a44 fix: move share quota block to download and add 3s download alert 2026-02-17 19:05:12 +08:00
19174616018 7983ab504a feat: switch OSS download quota to reservation plus log reconcile 2026-02-17 18:12:33 +08:00
19174616018 5cdd8e9c84 fix: force OSS direct download even when traffic quota is enabled 2026-02-17 17:40:55 +08:00
19174616018 536e807b38 feat: add user download traffic reports and restore OSS direct downloads 2026-02-17 17:36:26 +08:00
19174616018 753434ff49 feat: enhance download traffic quota lifecycle controls 2026-02-17 17:19:25 +08:00
19174616018 83937db680 feat(quota): add downloadable traffic quota with local/OSS/share metering 2026-02-17 16:52:26 +08:00
19174616018 854b1374ab fix(security): harden CORS/cookie policy and share path validation 2026-02-12 21:39:01 +08:00
19174616018 7cab8516de fix(ui): apply true large-screen scaling and mobile overflow safeguards 2026-02-12 20:33:36 +08:00
19174616018 63392ea1b2 fix(frontend): improve 2k/4k scaling and mobile overflow responsiveness 2026-02-12 20:28:08 +08:00
19174616018 08b3c41d79 feat: apply UI/storage/share optimizations and quota improvements 2026-02-12 18:02:57 +08:00
19174616018 05fc04258d feat(frontend): unify landing style and add product/scenes/start pages 2026-02-12 18:02:28 +08:00
19174616018andClaude Opus 4.5 4809be5bae chore: 移除系统设置的密码二次验证
移除 /api/admin/settings 路由的 requirePasswordConfirmation 中间件,
简化管理员操作流程。系统设置更新现在仅依赖管理员登录认证。

注意:此修改降低了安全性,建议在生产环境中考虑其他安全措施。

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-21 11:58:39 +08:00
19174616018andClaude Opus 4.5 ed383e596d fix: 部署脚本添加 ENCRYPTION_KEY 和 ENABLE_CSRF 配置
修复问题:
1. 新安装时自动生成 ENCRYPTION_KEY(用于加密 OSS 敏感信息)
2. 新安装时默认启用 CSRF 保护(ENABLE_CSRF=true)
3. 升级时自动检查并补充缺失的 ENCRYPTION_KEY 和 ENABLE_CSRF

解决了部署后服务因缺少 ENCRYPTION_KEY 而无法启动的问题。

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-21 11:50:25 +08:00
19174616018andClaude Opus 4.5 a30b3cac77 fix: 自动生成 SESSION_SECRET 配置
- 新安装时自动生成随机 SESSION_SECRET
- 更新时自动补充缺失的 SESSION_SECRET
- 避免生产环境因缺少密钥而启动失败

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 11:00:17 +08:00
19174616018andClaude Opus 4.5 8eee63436c feat: 全面优化代码质量至 8.55/10 分
## 安全增强
- 添加 CSRF 防护机制(Double Submit Cookie 模式)
- 增强密码强度验证(8字符+两种字符类型)
- 添加 Session 密钥安全检查
- 修复 .htaccess 文件上传漏洞
- 统一使用 getSafeErrorMessage() 保护敏感错误信息
- 增强数据库原型污染防护
- 添加被封禁用户分享访问检查

## 功能修复
- 修复模态框点击外部关闭功能
- 修复 share.html 未定义方法调用
- 修复 verify.html 和 reset-password.html API 路径
- 修复数据库 SFTP->OSS 迁移逻辑
- 修复 OSS 未配置时的错误提示
- 添加文件夹名称长度限制
- 添加文件列表 API 路径验证

## UI/UX 改进
- 添加 6 个按钮加载状态(登录/注册/修改密码等)
- 将 15+ 处 alert() 替换为 Toast 通知
- 添加防重复提交机制(创建文件夹/分享)
- 优化 loadUserProfile 防抖调用

## 代码质量
- 消除 formatFileSize 重复定义
- 集中模块导入到文件顶部
- 添加 JSDoc 注释
- 创建路由拆分示例 (routes/)

## 测试套件
- 添加 boundary-tests.js (60 用例)
- 添加 network-concurrent-tests.js (33 用例)
- 添加 state-consistency-tests.js (38 用例)
- 添加 test_share.js 和 test_admin.js

## 文档和配置
- 新增 INSTALL_GUIDE.md 手动部署指南
- 新增 VERSION.txt 版本历史
- 完善 .env.example 配置说明
- 新增 docker-compose.yml
- 完善 nginx.conf.example

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 10:45:51 +08:00
19174616018andClaude Opus 4.5 e4d418645c fix: 全面修复和优化 OSS 功能
## 安全修复
- 修复 /api/user/profile 接口泄露 OSS 密钥的安全漏洞
- 增强 getObjectKey 路径安全检查(空字节注入、URL 编码绕过)
- 修复 storage.end() 重复调用问题
- 增强上传签名接口的安全检查

## Bug 修复
- 修复 rename 使用错误的 PutObjectCommand,改为 CopyObjectCommand
- 修复 CopySource 编码问题,正确处理特殊字符
- 修复签名 URL 生成功能(添加 @aws-sdk/s3-request-presigner)
- 修复 S3Client 配置(阿里云 region 格式、endpoint 处理)
- 修复分页删除和列表功能(超过 1000 文件的处理)
- 修复分享下载使用错误的存储类型字段
- 修复前端媒体预览异步处理错误
- 修复 OSS 直传 objectKey 格式不一致问题
- 修复包名错误 @aws-sdk/request-presigner -> @aws-sdk/s3-request-presigner
- 修复前端下载错误处理不完善

## 新增功能
- 添加 OSS 连接测试 API (/api/user/test-oss)
- 添加重命名失败回滚机制
- 添加 OSS 配置前端验证

## 其他改进
- 更新 install.sh 仓库地址为 git.workyai.cn
- 添加 crypto 模块导入
- 修复代码格式和重复定义问题
- 添加缺失的表单对象定义

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
2026-01-20 09:46:00 +08:00
19174616018 a7c577acef 更新 README:迁移到 Gitea 仓库
- 更新一键部署命令(curl/wget)
- 更新 Docker 部署的 git clone 命令
- 更新开发环境的 git clone 命令
- 更新项目地址,Gitea 为主仓库,Gitee 为镜像
- 更新问题反馈说明
2025-12-10 22:59:34 +08:00
19174616018andClaude e2c8bf2c23 🎨 调整文件列表hover颜色
- 暗色主题:rgba(255, 255, 255, 0.05) 微亮
- 亮色主题:rgba(0, 0, 0, 0.04) 微暗

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 16:35:45 +08:00
19174616018andClaude 300a17c5da 🐛 修复文件列表hover时变白的问题
- 移除硬编码的mouseover/mouseout颜色
- 添加.file-list-row类使用CSS处理hover效果
- 深色/浅色主题都使用半透明紫色作为hover背景

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 16:30:16 +08:00
19174616018andClaude 310553e0e3 🐛 修复文件名包含反引号时变成undefined的问题
- 从sanitizeInput正则表达式中移除反引号
- 之前map中没有反引号映射导致返回undefined

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 15:27:59 +08:00
19174616018andClaude 8d3962b67e 🐛 加强文件名解码的空值处理
- 后端decodeHtmlEntities添加空字符串默认值
- 前端decodeHtmlEntities非字符串时返回空字符串
- getFileDisplayName增强类型检查

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 14:56:26 +08:00
19174616018andClaude ac91fe7484 前端添加HTML实体解码兜底
- 添加decodeHtmlEntities方法解码文件名
- 添加getFileDisplayName统一获取显示名称
- 确保文件名正确显示,即使后端未解码

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 14:04:50 +08:00
19174616018andClaude 1221c0d5c9 添加displayName字段显示解码后的文件名
- 后端返回文件列表时添加displayName字段(解码HTML实体)
- 前端使用displayName显示文件名,保持原始name用于操作

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 13:54:58 +08:00
19174616018andClaude d111c63e8b 🐛 修复特殊字符文件名的处理问题
- 添加decodeHtmlEntities函数解码HTML实体
- 在rename/mkdir/folder-info/delete接口中解码文件名和路径
- 删除操作支持多候选路径,处理二次编码情况
- 移除sanitizeInput中对反引号的转义

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 13:44:23 +08:00
19174616018andClaude 0ba370dc83 🐛 优化弹窗被拦截时的处理方式
- 弹窗被阻止时改为toast提示,避免当前页跳转

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 13:12:41 +08:00
19174616018andClaude f4e76696d9 🐛 修复分享链接打开方式
- 添加openShare方法替代直接调用window.open
- 处理弹窗被浏览器阻止的情况,自动退回当前页跳转

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 13:04:11 +08:00
19174616018andClaude 00e1cadbed 重新设计分享管理页面
- 添加搜索/筛选功能(关键字、类型、状态、排序)
- 重新设计卡片视图,展示更多信息(状态、类型、加密、存储来源等)
- 添加filteredShares计算属性实现筛选和排序
- 添加辅助方法:getShareTypeLabel、getShareStatus、getShareProtection等
- 优化分享卡片样式,支持深色/浅色主题

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 12:57:35 +08:00
19174616018andClaude b580ddecd7 优化监控页面加载体验
- 添加monitorTabLoading整体加载遮罩
- 创建openMonitorTab()和initMonitorTab()方法
- 使用Promise.all并行加载健康检测和系统日志
- 数据全部加载完成后才显示监控内容,彻底解决刷新闪烁问题

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 12:00:43 +08:00
19174616018andClaude c3ec191354 🐛 优化监控页面初始状态设置
- 将adminTab计算提取为initialAdminTab变量
- healthCheck.loading和systemLogs.loading根据initialAdminTab设置初始值
- 确保data()执行时所有状态一致,避免刷新闪烁

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:50:59 +08:00
19174616018andClaude aab7e1ff36 🐛 修复监控页面loading状态 - 在mounted中提前设置
- 将healthCheck.loading和systemLogs.loading初始值改回false
- 在mounted中、checkLoginStatus之前,判断adminTab并设置loading
- 确保在appReady变为true之前loading状态已正确设置

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:28:18 +08:00
19174616018andClaude 1c49d34afb 🐛 修复监控页面刷新时的"没有数据"闪烁
- 健康检测:添加loading状态显示,使用v-else-if链
- 系统日志:修复v-if逻辑,loading优先于空状态显示
- 确保在数据加载完成前显示"加载中"而不是"暂无数据"

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:24:07 +08:00
19174616018andClaude 6c1c07919f 🐛 修复监控页面刷新时显示"没有数据"的闪烁
- 当adminTab为monitor时,healthCheck和systemLogs的loading初始值设为true
- 这样在数据加载完成前显示"加载中"而不是"没有数据"

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:19:19 +08:00
19174616018andClaude 3e68f57fc5 🐛 修复管理员标签页刷新时的UI闪烁
- adminTab初始值直接从localStorage读取,而非在checkLoginStatus中恢复
- 这样Vue初始化时就已经是正确的标签页,避免先显示概览再切换的闪烁

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:11:20 +08:00
19174616018andClaude c5b1d514be 🐛 修复页面刷新时UI闪烁问题
- 添加appReady状态控制应用显示时机
- 在checkLoginStatus完成后才显示主界面
- 添加加载占位符动画(云图标脉冲效果)
- 使用v-if/v-else确保UI状态一致性

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:07:07 +08:00
19174616018andClaude 07d8e41380 添加管理员标签页持久化功能
- 刷新页面后管理员标签页保持不变(概览/设置/监控/用户/工具)
- 使用localStorage存储当前标签页状态
- 登出时自动清理保存的标签页状态

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 11:03:55 +08:00
19174616018andClaude 34e874e1e6 ui: 优化监控页面交互体验
- 点击监控标签时自动加载健康检查和系统日志
- 缩小清理/刷新按钮尺寸,更简洁美观
- 按钮文字精简:"清理旧日志" → "清理"

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 10:54:26 +08:00
19174616018andClaude c99b19a86d security: refreshToken 也存储在 HttpOnly Cookie 中
## 后端修改
- 登录时同时设置 token 和 refreshToken 的 HttpOnly Cookie
- refreshToken 有效期7天,token 有效期2小时
- 刷新接口优先从 Cookie 读取 refreshToken(向后兼容请求体)
- 登出时同时清除两个 Cookie

## 前端修改
- 移除 refreshToken 变量和相关逻辑
- 简化 doRefreshToken(),不再手动传递 refreshToken
- 简化 tryRefreshOrLogout(),直接尝试刷新

## 好处
- 页面刷新后 refreshToken 不会丢失
- 完全无感刷新,用户体验更好
- 前端代码更简洁(减少约20行)
- refreshToken 也无法被 XSS 窃取

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 10:38:40 +08:00
19174616018andClaude 38d18018a5 security: 实施 HttpOnly Cookie 鉴权方案
## 后端修改
- 新增 /api/logout 接口清除认证 Cookie

## 前端修改
- 移除 localStorage 存储 token/refreshToken(防止 XSS 窃取)
- 移除所有手动 Authorization 头(共36处)
- checkLoginStatus 改为直接调用 API 验证(Cookie 自动携带)
- logout 改为调用后端接口清除 Cookie
- 简化 token 刷新逻辑

## 安全性提升
- Token 从 localStorage 迁移到 HttpOnly Cookie
- XSS 攻击无法通过 JS 读取 token
- 配合 SameSite 属性防御 CSRF 攻击

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 10:33:27 +08:00
19174616018andClaude e81b1dd89e fix: 修复移动端文件列表滑动问题
- 移除 touchstart 中的 event.preventDefault(),不再阻止默认滚动
- 添加 handleLongPressMove 方法检测手指移动
- 滑动超过 10px 时自动取消长按,允许正常滚动
- 为 grid 和 list 视图的文件项添加 @touchmove 事件

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-30 10:12:46 +08:00
19174616018andClaude ae27ee3791 fix: 修复验证码session保存时序问题
问题原因:
- 验证码API在session.save()完成前就发送响应
- 导致客户端获取验证码图片时session可能未保存成功

修复:
- 将res.send()移到session.save()回调内
- 确保session保存成功后再返回验证码图片
- 添加验证码验证调试日志帮助诊断

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-28 14:11:36 +08:00
19174616018andClaude a9cc3a56ad fix: 修复验证码请求429错误
问题:
- 短时间内多次请求验证码触发限流(429 Too Many Requests)

修复:
- 后端:验证码最小请求间隔从3秒改为1秒
- 前端:添加2秒防抖,避免重复请求
- 前端:429错误时保留已有验证码图片

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-28 14:06:23 +08:00
19174616018andClaude 06f60bec06 fix: 修复验证码session不一致的问题
问题原因:
- 验证码图片通过<img src>加载,可能不携带session cookie
- 导致验证码生成和表单提交使用不同的session

修复方案:
- 改用axios请求获取验证码(blob格式)
- 确保验证码请求携带withCredentials
- 点击"忘记密码"时立即加载验证码
- 切换到注册模式时立即加载验证码

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-28 13:50:06 +08:00
19174616018andClaude 6722d70666 feat: 实现Token刷新机制,缩短登录有效期
安全改进:
- Access Token有效期从7天缩短为2小时
- 添加Refresh Token机制(有效期7天)
- 关闭浏览器后较快失效,提升安全性

后端修改(auth.js):
- 添加generateRefreshToken函数生成刷新令牌
- 添加refreshAccessToken函数验证并刷新access token
- 分离ACCESS_TOKEN_EXPIRES和REFRESH_TOKEN_EXPIRES配置

后端修改(server.js):
- 登录时返回refreshToken和expiresIn
- 添加/api/refresh-token接口用于刷新token
- Cookie有效期同步调整为2小时

前端修改(app.js):
- 保存refreshToken到localStorage
- 添加自动刷新定时器(过期前5分钟刷新)
- 页面加载时若token过期自动尝试刷新
- 登出时清除refreshToken和定时器

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>
2025-11-28 13:46:51 +08:00