系统设置迁入后台:站点地址 / OAuth 凭据 / R2 存储 / 管理员账号,保存即生效无需重启
- 生效规则统一为「后台填了用后台的,没填回落环境变量」,老部署不改 env 照常跑 - config.Resolver:短缓存解析有效配置,存储后端按配置签名热重建;后台保存主动失效 - 秘密项(client secret / bot token / R2 密钥 / 管理员密码)接口永不回显明文, 只报「是否已配置、来自哪里」;留空保存 = 保持现值 - 管理员密码 bcrypt 入库,DB 哈希优先、显式设置的 env 密码作解锁后路; 后台改过密码后 admin/admin 开发模式立即失效 - 设置页新增「登录与存储」标签,基础信息加站点地址;秘密项带来源提示 - 监听地址 / 数据库 / 目录 / ONE_SECRET / Passkey 仍留环境变量(启动期依赖)
This commit is contained in:
1 parent
bf3ce934dd
commit
e68400b389
23 files changed
+957
-126
No files matched your search
@@ -8,6 +8,8 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"golang.org/x/crypto/bcrypt"
|
||||
|
||||
"oneblog/internal/config"
|
||||
"oneblog/internal/db"
|
||||
"oneblog/internal/model"
|
||||
@@ -176,10 +178,15 @@ func TestSettingsUIRoundTrip(t *testing.T) {
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("get settings: got %d", rec.Code)
|
||||
}
|
||||
var got model.Settings
|
||||
if err := json.NewDecoder(rec.Body).Decode(&got); err != nil {
|
||||
var wrap struct {
|
||||
Settings model.Settings `json:"settings"`
|
||||
CredentialMeta map[string]any `json:"credential_meta"`
|
||||
Secrets map[string]string `json:"-"`
|
||||
}
|
||||
if err := json.NewDecoder(rec.Body).Decode(&wrap); err != nil {
|
||||
t.Fatalf("decode: %v", err)
|
||||
}
|
||||
got := wrap.Settings
|
||||
if got.UIID != "vivid" {
|
||||
t.Errorf("ui_id = %q, want vivid", got.UIID)
|
||||
}
|
||||
@@ -189,6 +196,11 @@ func TestSettingsUIRoundTrip(t *testing.T) {
|
||||
if _, ok := got.CustomCSS["bogus"]; ok {
|
||||
t.Error("unknown section should not be persisted")
|
||||
}
|
||||
// 秘密项在任何响应里都不该出现明文
|
||||
if strings.Contains(rec.Body.String(), "client_secret\":") &&
|
||||
!strings.Contains(rec.Body.String(), "credential_meta") {
|
||||
t.Error("settings response should not carry raw secrets")
|
||||
}
|
||||
|
||||
// An invalid ui_id falls back rather than being stored verbatim.
|
||||
rec = put(`{"site_title":"ONE","posts_per_page":10,"light_skin_id":"paper","ui_id":"neon","custom_css":{}}`)
|
||||
@@ -197,7 +209,8 @@ func TestSettingsUIRoundTrip(t *testing.T) {
|
||||
}
|
||||
rec = httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, get)
|
||||
_ = json.NewDecoder(rec.Body).Decode(&got)
|
||||
_ = json.NewDecoder(rec.Body).Decode(&wrap)
|
||||
got = wrap.Settings
|
||||
if got.UIID != "classic" {
|
||||
t.Errorf("invalid ui_id should fall back to classic, got %q", got.UIID)
|
||||
}
|
||||
@@ -205,3 +218,109 @@ func TestSettingsUIRoundTrip(t *testing.T) {
|
||||
t.Error("custom_css should be non-nil")
|
||||
}
|
||||
}
|
||||
|
||||
// 系统设置迁移项:secrets 走单独通道写入且不可读回;DB 值在有效配置里
|
||||
// 覆盖环境变量;登录改用 DB 密码后 env 密码是否还作数取决于是否显式配置。
|
||||
func TestSettingsCredentialsRoundTrip(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
a.Cfg = &config.Config{SiteURL: "http://env.example", AdminUser: "admin",
|
||||
AdminPass: "s3cret", GitHubClientID: "env-id", GitHubClientSecret: "env-sec",
|
||||
GoogleClientID: "env-google"}
|
||||
a.Res = config.NewResolver(a.Cfg, a.Store)
|
||||
token := login(t, h, "admin", "s3cret")
|
||||
var sess struct {
|
||||
Token string `json:"token"`
|
||||
}
|
||||
_ = json.NewDecoder(token.Body).Decode(&sess)
|
||||
|
||||
put := func(body string) *httptest.ResponseRecorder {
|
||||
req := httptest.NewRequest(http.MethodPut, "/api/admin/settings", strings.NewReader(body))
|
||||
req.Header.Set("Authorization", "Bearer "+sess.Token)
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, req)
|
||||
return rec
|
||||
}
|
||||
|
||||
// 写入 DB 值(含一个 secret);响应与 GET 都不能回显 secret 明文
|
||||
rec := put(`{"site_url":"https://db.example","github_client_id":"db-id",
|
||||
"secrets":{"github_client_secret":"db-sec","admin_password":"newpass1"}}`)
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("put: got %d body=%s", rec.Code, rec.Body.String())
|
||||
}
|
||||
if strings.Contains(rec.Body.String(), "db-sec") || strings.Contains(rec.Body.String(), "newpass1") {
|
||||
t.Fatal("secret echoed back in plaintext")
|
||||
}
|
||||
|
||||
// 来源标记:site_url 来自 db,client_id 来自 db,secret 来自 db;
|
||||
// 未写的项回落 env
|
||||
if meta, err := a.credentialMeta(); err != nil {
|
||||
t.Fatal(err)
|
||||
} else {
|
||||
want := map[string]string{
|
||||
"site_url": "db", "github_client_id": "db",
|
||||
"github_client_secret": "db", "google_client_id": "env",
|
||||
"admin_password_hash": "db",
|
||||
}
|
||||
for k, src := range want {
|
||||
m, _ := meta[k].(map[string]any)
|
||||
if m == nil || m["source"] != src {
|
||||
t.Errorf("meta[%s] = %+v, want source=%s", k, m, src)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
// 有效配置:DB 值覆盖 env;没配的项回落 env
|
||||
c := a.cfg()
|
||||
if c.SiteURL != "https://db.example" || c.GitHubClientID != "db-id" {
|
||||
t.Errorf("overlay failed: site_url=%q client_id=%q", c.SiteURL, c.GitHubClientID)
|
||||
}
|
||||
if c.GitHubClientSecret != "db-sec" {
|
||||
t.Errorf("secret overlay failed: %q", c.GitHubClientSecret)
|
||||
}
|
||||
|
||||
// DB 密码立即生效;显式设置的 env 密码仍作后路;错误的都不行
|
||||
if _, ok := a.verifyAdmin("admin", "newpass1"); !ok {
|
||||
t.Error("db password should work right after save")
|
||||
}
|
||||
if _, ok := a.verifyAdmin("admin", "s3cret"); !ok {
|
||||
t.Error("explicit env password should stay as backstop")
|
||||
}
|
||||
if _, ok := a.verifyAdmin("admin", "wrong"); ok {
|
||||
t.Error("wrong password must fail")
|
||||
}
|
||||
|
||||
// admin_password 6 位下限
|
||||
if rec := put(`{"secrets":{"admin_password":"123"}}`); rec.Code != http.StatusBadRequest {
|
||||
t.Errorf("short password: got %d, want 400", rec.Code)
|
||||
}
|
||||
}
|
||||
|
||||
// InsecureDev(env 未显式设密码)时 admin/admin 有效,但后台一旦改了密码
|
||||
// admin/admin 必须立刻失效。
|
||||
func TestInsecureDevDisabledByDBPassword(t *testing.T) {
|
||||
a, _ := newTestAPI(t)
|
||||
a.Cfg = &config.Config{AdminUser: "admin", AdminPass: "admin", InsecureDev: true}
|
||||
if _, ok := a.verifyAdmin("admin", "admin"); !ok {
|
||||
t.Fatal("insecure default should work before any password is set")
|
||||
}
|
||||
h := bcryptHash(t, "newpass1")
|
||||
if err := a.Store.SetSetting("admin_password_hash", h); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, ok := a.verifyAdmin("admin", "admin"); ok {
|
||||
t.Error("admin/admin must stop working once a DB password exists")
|
||||
}
|
||||
if _, ok := a.verifyAdmin("admin", "newpass1"); !ok {
|
||||
t.Error("db password should be accepted")
|
||||
}
|
||||
}
|
||||
|
||||
func bcryptHash(t *testing.T, pw string) string {
|
||||
t.Helper()
|
||||
b, err := bcrypt.GenerateFromPassword([]byte(pw), bcrypt.MinCost)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
return string(b)
|
||||
}
|
||||
Reference in new issue
Block a user