评论登录新增 Google OAuth 与 Telegram Login Widget
- Google:授权码流程(openid email profile),handle 优先用已验证邮箱,头像取 picture - Telegram:官方 widget 直接回传签名资料,后端按官方算法验签(secret=SHA256(bot_token),除 hash 外全字段排序比对)+ auth_date 24h 时效 - providers 列表自动按配置下发(未配置的不显示);widget 型带 bot 用户名 - 三个登录方式共用读者会话与 upsert;Telegram 走 POST 无跳转 - .env.example 补 ONE_GOOGLE_* / ONE_TELEGRAM_* 模板
This commit is contained in:
@@ -8,3 +8,13 @@ Bucket=
|
||||
# 回调地址填 http://localhost:8080/api/auth/callback/github(线上换成正式域名)
|
||||
ONE_GITHUB_CLIENT_ID=
|
||||
ONE_GITHUB_CLIENT_SECRET=
|
||||
|
||||
# Telegram 登录(Login Widget):@BotFather 建 bot 拿 token,
|
||||
# 再用 /setdomain 把域名登记给 bot(本地开发填 localhost)
|
||||
ONE_TELEGRAM_BOT=
|
||||
ONE_TELEGRAM_BOT_TOKEN=
|
||||
|
||||
# Google 登录:https://console.cloud.google.com/apis/credentials 建 OAuth 客户端,
|
||||
# 回调地址填 http://localhost:8080/api/auth/callback/google(线上换成正式域名)
|
||||
ONE_GOOGLE_CLIENT_ID=
|
||||
ONE_GOOGLE_CLIENT_SECRET=
|
||||
|
||||
Reference in New Issue
Block a user