Compare commits
25
Commits
1db1698174
...
main
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
1b3eb870da | ||
|
|
f1e639e0ba | ||
|
|
7e302c51a6 | ||
|
|
e6e4bdc71c | ||
|
|
baf14897aa | ||
|
|
8ff9878e91 | ||
|
|
1a43199ca0 | ||
|
|
84f88cb473 | ||
|
|
c6eb0bbe5b | ||
|
|
165f87d086 | ||
|
|
2674bea223 | ||
|
|
ce07f4a347 | ||
|
|
c2d5e9db89 | ||
|
|
3eb0aab788 | ||
|
|
f7669badf2 | ||
|
|
6e6196d68b | ||
|
|
23771f0661 | ||
|
|
44a24736aa | ||
|
|
55d898cd42 | ||
|
|
ab96426489 | ||
|
|
c84a383e5c | ||
|
|
f7a2e83727 | ||
|
|
b93fe9847c | ||
|
|
a74299d716 | ||
|
|
da0333e09c |
No files matched your search
@@ -18,3 +18,5 @@ ONE_TELEGRAM_BOT_TOKEN=
|
||||
# 回调地址填 http://localhost:8080/api/auth/callback/google(线上换成正式域名)
|
||||
ONE_GOOGLE_CLIENT_ID=
|
||||
ONE_GOOGLE_CLIENT_SECRET=
|
||||
|
||||
ONE_SECRET=# 任意字符串,用于加密
|
||||
@@ -12,6 +12,10 @@ data/
|
||||
# 开发进程日志 / pid
|
||||
.run/
|
||||
|
||||
# 其他 agent 工具的本地草稿(计划、忽略清单),不进仓库
|
||||
.zcode/
|
||||
.zcodeignore
|
||||
|
||||
# 二进制
|
||||
one-server
|
||||
backend/one-server
|
||||
|
||||
+11
-3
@@ -1,15 +1,16 @@
|
||||
module oneblog
|
||||
|
||||
go 1.24
|
||||
go 1.24.0
|
||||
|
||||
require (
|
||||
github.com/aws/aws-sdk-go-v2 v1.47.1
|
||||
github.com/aws/aws-sdk-go-v2/config v1.33.6
|
||||
github.com/aws/aws-sdk-go-v2/credentials v1.20.6
|
||||
github.com/aws/aws-sdk-go-v2/service/s3 v1.113.4
|
||||
github.com/go-webauthn/webauthn v0.15.0
|
||||
github.com/lib/pq v1.10.9
|
||||
github.com/yuin/goldmark v1.7.13
|
||||
golang.org/x/text v0.21.0
|
||||
golang.org/x/text v0.30.0
|
||||
modernc.org/sqlite v1.39.0
|
||||
)
|
||||
|
||||
@@ -29,12 +30,19 @@ require (
|
||||
github.com/aws/aws-sdk-go-v2/service/sts v1.51.1 // indirect
|
||||
github.com/aws/smithy-go v1.28.1 // indirect
|
||||
github.com/dustin/go-humanize v1.0.1 // indirect
|
||||
github.com/fxamacker/cbor/v2 v2.9.0 // indirect
|
||||
github.com/go-viper/mapstructure/v2 v2.4.0 // indirect
|
||||
github.com/go-webauthn/x v0.1.26 // indirect
|
||||
github.com/golang-jwt/jwt/v5 v5.3.0 // indirect
|
||||
github.com/google/go-tpm v0.9.6 // indirect
|
||||
github.com/google/uuid v1.6.0 // indirect
|
||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||
github.com/ncruces/go-strftime v0.1.9 // indirect
|
||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec // indirect
|
||||
github.com/x448/float16 v0.8.4 // indirect
|
||||
golang.org/x/crypto v0.43.0 // indirect
|
||||
golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b // indirect
|
||||
golang.org/x/sys v0.34.0 // indirect
|
||||
golang.org/x/sys v0.37.0 // indirect
|
||||
modernc.org/libc v1.66.3 // indirect
|
||||
modernc.org/mathutil v1.7.1 // indirect
|
||||
modernc.org/memory v1.11.0 // indirect
|
||||
|
||||
+36
-10
@@ -34,8 +34,22 @@ github.com/aws/aws-sdk-go-v2/service/sts v1.51.1 h1:0HOqZXRvMytH6bFHVIc0oJX07sZj
|
||||
github.com/aws/aws-sdk-go-v2/service/sts v1.51.1/go.mod h1:26zA0GhDrLo+yiLI2yXWxqB1PdsShfLikoI7GOEgugM=
|
||||
github.com/aws/smithy-go v1.28.1 h1:R/nXH00c8qcfCzQVELtRw+eLQWtzv+VAIEFJ1/xxXlQ=
|
||||
github.com/aws/smithy-go v1.28.1/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
|
||||
github.com/davecgh/go-spew v1.1.1 h1:vj9j/u1bqnvCEfJOwUhtlOARqs3+rkHYY13jYWTU97c=
|
||||
github.com/davecgh/go-spew v1.1.1/go.mod h1:J7Y8YcW2NihsgmVo/mv3lAwl/skON4iLHjSsI+c5H38=
|
||||
github.com/dustin/go-humanize v1.0.1 h1:GzkhY7T5VNhEkwH0PVJgjz+fX1rhBrR7pRT3mDkpeCY=
|
||||
github.com/dustin/go-humanize v1.0.1/go.mod h1:Mu1zIs6XwVuF/gI1OepvI0qD18qycQx+mFykh5fBlto=
|
||||
github.com/fxamacker/cbor/v2 v2.9.0 h1:NpKPmjDBgUfBms6tr6JZkTHtfFGcMKsw3eGcmD/sapM=
|
||||
github.com/fxamacker/cbor/v2 v2.9.0/go.mod h1:vM4b+DJCtHn+zz7h3FFp/hDAI9WNWCsZj23V5ytsSxQ=
|
||||
github.com/go-viper/mapstructure/v2 v2.4.0 h1:EBsztssimR/CONLSZZ04E8qAkxNYq4Qp9LvH92wZUgs=
|
||||
github.com/go-viper/mapstructure/v2 v2.4.0/go.mod h1:oJDH3BJKyqBA2TXFhDsKDGDTlndYOZ6rGS0BRZIxGhM=
|
||||
github.com/go-webauthn/webauthn v0.15.0 h1:LR1vPv62E0/6+sTenX35QrCmpMCzLeVAcnXeH4MrbJY=
|
||||
github.com/go-webauthn/webauthn v0.15.0/go.mod h1:hcAOhVChPRG7oqG7Xj6XKN1mb+8eXTGP/B7zBLzkX5A=
|
||||
github.com/go-webauthn/x v0.1.26 h1:eNzreFKnwNLDFoywGh9FA8YOMebBWTUNlNSdolQRebs=
|
||||
github.com/go-webauthn/x v0.1.26/go.mod h1:jmf/phPV6oIsF6hmdVre+ovHkxjDOmNH0t6fekWUxvg=
|
||||
github.com/golang-jwt/jwt/v5 v5.3.0 h1:pv4AsKCKKZuqlgs5sUmn4x8UlGa0kEVt/puTpKx9vvo=
|
||||
github.com/golang-jwt/jwt/v5 v5.3.0/go.mod h1:fxCRLWMO43lRc8nhHWY6LGqRcf+1gQWArsqaEUEa5bE=
|
||||
github.com/google/go-tpm v0.9.6 h1:Ku42PT4LmjDu1H5C5ISWLlpI1mj+Zq7sPGKoRw2XROA=
|
||||
github.com/google/go-tpm v0.9.6/go.mod h1:h9jEsEECg7gtLis0upRBQU+GhYVH6jMjrFxI8u6bVUY=
|
||||
github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e h1:ijClszYn+mADRFY17kjQEVQ1XRhq2/JR1M3sGqeJoxs=
|
||||
github.com/google/pprof v0.0.0-20250317173921-a4b03ec1a45e/go.mod h1:boTsfXsheKC2y+lKOCMpSfarhxDeIzfZG1jqGcPl3cA=
|
||||
github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
|
||||
@@ -46,23 +60,35 @@ github.com/mattn/go-isatty v0.0.20 h1:xfD0iDuEKnDkl03q4limB+vH+GxLEtL/jb4xVJSWWE
|
||||
github.com/mattn/go-isatty v0.0.20/go.mod h1:W+V8PltTTMOvKvAeJH7IuucS94S2C6jfK/D7dTCTo3Y=
|
||||
github.com/ncruces/go-strftime v0.1.9 h1:bY0MQC28UADQmHmaF5dgpLmImcShSi2kHU9XLdhx/f4=
|
||||
github.com/ncruces/go-strftime v0.1.9/go.mod h1:Fwc5htZGVVkseilnfgOVb9mKy6w1naJmn9CehxcKcls=
|
||||
github.com/pmezard/go-difflib v1.0.0 h1:4DBwDE0NGyQoBHbLQYPwSUPoCMWR5BEzIk/f1lZbAQM=
|
||||
github.com/pmezard/go-difflib v1.0.0/go.mod h1:iKH77koFhYxTK1pcRnkKkqfTogsbg7gZNVY4sRDYZ/4=
|
||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec h1:W09IVJc94icq4NjY3clb7Lk8O1qJ8BdBEF8z0ibU0rE=
|
||||
github.com/remyoudompheng/bigfft v0.0.0-20230129092748-24d4a6f8daec/go.mod h1:qqbHyh8v60DhA7CoWK5oRCqLrMHRGoxYCSS9EjAz6Eo=
|
||||
github.com/stretchr/testify v1.11.1 h1:7s2iGBzp5EwR7/aIZr8ao5+dra3wiQyKjjFuvgVKu7U=
|
||||
github.com/stretchr/testify v1.11.1/go.mod h1:wZwfW3scLgRK+23gO65QZefKpKQRnfz6sD981Nm4B6U=
|
||||
github.com/x448/float16 v0.8.4 h1:qLwI1I70+NjRFUR3zs1JPUCgaCXSh3SW62uAKT1mSBM=
|
||||
github.com/x448/float16 v0.8.4/go.mod h1:14CWIYCyZA/cWjXOioeEpHeN/83MdbZDRQHoFcYsOfg=
|
||||
github.com/yuin/goldmark v1.7.13 h1:GPddIs617DnBLFFVJFgpo1aBfe/4xcvMc3SB5t/D0pA=
|
||||
github.com/yuin/goldmark v1.7.13/go.mod h1:ip/1k0VRfGynBgxOz0yCqHrbZXhcjxyuS66Brc7iBKg=
|
||||
go.uber.org/mock v0.6.0 h1:hyF9dfmbgIX5EfOdasqLsWD6xqpNZlXblLB/Dbnwv3Y=
|
||||
go.uber.org/mock v0.6.0/go.mod h1:KiVJ4BqZJaMj4svdfmHM0AUx4NJYO8ZNpPnZn1Z+BBU=
|
||||
golang.org/x/crypto v0.43.0 h1:dduJYIi3A3KOfdGOHX8AVZ/jGiyPa3IbBozJ5kNuE04=
|
||||
golang.org/x/crypto v0.43.0/go.mod h1:BFbav4mRNlXJL4wNeejLpWxB7wMbc79PdRGhWKncxR0=
|
||||
golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b h1:M2rDM6z3Fhozi9O7NWsxAkg/yqS/lQJ6PmkyIV3YP+o=
|
||||
golang.org/x/exp v0.0.0-20250620022241-b7579e27df2b/go.mod h1:3//PLf8L/X+8b4vuAfHzxeRUl04Adcb341+IGKfnqS8=
|
||||
golang.org/x/mod v0.25.0 h1:n7a+ZbQKQA/Ysbyb0/6IbB1H/X41mKgbhfv7AfG/44w=
|
||||
golang.org/x/mod v0.25.0/go.mod h1:IXM97Txy2VM4PJ3gI61r1YEk/gAj6zAHN3AdZt6S9Ww=
|
||||
golang.org/x/sync v0.15.0 h1:KWH3jNZsfyT6xfAfKiz6MRNmd46ByHDYaZ7KSkCtdW8=
|
||||
golang.org/x/sync v0.15.0/go.mod h1:1dzgHSNfp02xaA81J2MS99Qcpr2w7fw1gpm99rleRqA=
|
||||
golang.org/x/mod v0.28.0 h1:gQBtGhjxykdjY9YhZpSlZIsbnaE2+PgjfLWUQTnoZ1U=
|
||||
golang.org/x/mod v0.28.0/go.mod h1:yfB/L0NOf/kmEbXjzCPOx1iK1fRutOydrCMsqRhEBxI=
|
||||
golang.org/x/sync v0.17.0 h1:l60nONMj9l5drqw6jlhIELNv9I0A4OFgRsG9k2oT9Ug=
|
||||
golang.org/x/sync v0.17.0/go.mod h1:9KTHXmSnoGruLpwFjVSX0lNNA75CykiMECbovNTZqGI=
|
||||
golang.org/x/sys v0.6.0/go.mod h1:oPkhp1MJrh7nUepCBck5+mAzfO9JrbApNNgaTdGDITg=
|
||||
golang.org/x/sys v0.34.0 h1:H5Y5sJ2L2JRdyv7ROF1he/lPdvFsd0mJHFw2ThKHxLA=
|
||||
golang.org/x/sys v0.34.0/go.mod h1:BJP2sWEmIv4KK5OTEluFJCKSidICx8ciO85XgH3Ak8k=
|
||||
golang.org/x/text v0.21.0 h1:zyQAAkrwaneQ066sspRyJaG9VNi/YJ1NfzcGB3hZ/qo=
|
||||
golang.org/x/text v0.21.0/go.mod h1:4IBbMaMmOPCJ8SecivzSH54+73PCFmPWxNTLm+vZkEQ=
|
||||
golang.org/x/tools v0.34.0 h1:qIpSLOxeCYGg9TrcJokLBG4KFA6d795g0xkBkiESGlo=
|
||||
golang.org/x/tools v0.34.0/go.mod h1:pAP9OwEaY1CAW3HOmg3hLZC5Z0CCmzjAF2UQMSqNARg=
|
||||
golang.org/x/sys v0.37.0 h1:fdNQudmxPjkdUTPnLn5mdQv7Zwvbvpaxqs831goi9kQ=
|
||||
golang.org/x/sys v0.37.0/go.mod h1:OgkHotnGiDImocRcuBABYBEXf8A9a87e/uXjp9XT3ks=
|
||||
golang.org/x/text v0.30.0 h1:yznKA/E9zq54KzlzBEAWn1NXSQ8DIp/NYMy88xJjl4k=
|
||||
golang.org/x/text v0.30.0/go.mod h1:yDdHFIX9t+tORqspjENWgzaCVXgk0yYnYuSZ8UzzBVM=
|
||||
golang.org/x/tools v0.37.0 h1:DVSRzp7FwePZW356yEAChSdNcQo6Nsp+fex1SUW09lE=
|
||||
golang.org/x/tools v0.37.0/go.mod h1:MBN5QPQtLMHVdvsbtarmTNukZDdgwdwlO5qGacAzF0w=
|
||||
gopkg.in/yaml.v3 v3.0.1 h1:fxVm/GzAzEWqLHuvctI91KS9hhNmmWOoWu0XTYJS7CA=
|
||||
gopkg.in/yaml.v3 v3.0.1/go.mod h1:K4uyk7z7BCEPqu6E+C64Yfv1cQ7kz7rIZviUmN+EgEM=
|
||||
modernc.org/cc/v4 v4.26.2 h1:991HMkLjJzYBIfha6ECZdjrIYz2/1ayr+FL8GN+CNzM=
|
||||
modernc.org/cc/v4 v4.26.2/go.mod h1:uVtb5OGqUKpoLWhqwNQo/8LwvoiEBLvZXIQ/SmO6mL0=
|
||||
modernc.org/ccgo/v4 v4.28.0 h1:rjznn6WWehKq7dG4JtLRKxb52Ecv8OUGah8+Z/SfpNU=
|
||||
|
||||
@@ -0,0 +1,254 @@
|
||||
// 账户页的后端:站主资料、身份绑定列表、passkey 管理。
|
||||
//
|
||||
// 和「站点设置」的分工:站点设置管站点(标题、皮肤、评论开关),账户页管
|
||||
// 「你是谁 + 你能用什么方式登录」。昵称/简介仍是 author_name/author_bio
|
||||
// 两个 settings 键(单一来源,前端各处照旧读),头像另用 owner_avatar_key
|
||||
// 单键写入,避开 UpdateSettings 的全量替换。
|
||||
package admin
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
"strings"
|
||||
|
||||
"oneblog/internal/httpx"
|
||||
"oneblog/internal/model"
|
||||
"oneblog/internal/storage"
|
||||
"oneblog/internal/store"
|
||||
)
|
||||
|
||||
const maxAvatarKeyLen = 160
|
||||
|
||||
// accountView 是账户页一次拉取的全部数据。
|
||||
type accountView struct {
|
||||
Name string `json:"name"`
|
||||
Bio string `json:"bio"`
|
||||
AvatarKey string `json:"avatar_key"`
|
||||
AvatarURL string `json:"avatar_url"`
|
||||
Handle string `json:"handle"`
|
||||
Password passwordInfo `json:"password"`
|
||||
Identities []model.UserIdentity `json:"identities"`
|
||||
Passkeys []model.Passkey `json:"passkeys"`
|
||||
// Providers 告诉前端哪些平台可以绑(未配凭据的平台不出现)。
|
||||
Providers []string `json:"providers"`
|
||||
}
|
||||
|
||||
type passwordInfo struct {
|
||||
// 站主密码由环境变量管理,不进库也不做哈希 —— 这条退路保证
|
||||
// 「解绑所有身份 + 删光 passkey」也不会把自已锁在门外。
|
||||
ManagedBy string `json:"managed_by"`
|
||||
Username string `json:"username"`
|
||||
}
|
||||
|
||||
func (a *API) account(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodGet {
|
||||
httpx.Error(w, http.StatusMethodNotAllowed, "GET required")
|
||||
return
|
||||
}
|
||||
v, err := a.buildAccount()
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, v)
|
||||
}
|
||||
|
||||
func (a *API) buildAccount() (accountView, error) {
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
return accountView{}, err
|
||||
}
|
||||
st, err := a.Store.GetSettings()
|
||||
if err != nil {
|
||||
return accountView{}, err
|
||||
}
|
||||
ids, err := a.Store.ListIdentities(owner.ID)
|
||||
if err != nil {
|
||||
return accountView{}, err
|
||||
}
|
||||
pks, err := a.Store.ListPasskeys(owner.ID)
|
||||
if err != nil {
|
||||
return accountView{}, err
|
||||
}
|
||||
v := accountView{
|
||||
// 昵称以站主行的 name 为准;老数据里它是空的,回落到站点设置的作者名。
|
||||
Name: firstNonEmptyStr(owner.Name, st.AuthorName),
|
||||
Bio: st.AuthorBio,
|
||||
AvatarKey: st.AuthorAvatarKey,
|
||||
AvatarURL: a.avatarURL(st.AuthorAvatarKey),
|
||||
Handle: owner.Handle,
|
||||
Password: passwordInfo{ManagedBy: "env:ONE_ADMIN_PASSWORD", Username: a.Cfg.AdminUser},
|
||||
Identities: ids,
|
||||
Passkeys: pks,
|
||||
}
|
||||
// 可绑定的平台:只有跳转式 OAuth 能在后台发起。Telegram 是评论区里的
|
||||
// 登录 widget,后台没有它的入口,所以不进这个列表(已绑的记录仍会显示)。
|
||||
for _, p := range []string{"github", "google"} {
|
||||
if a.providerEnabled(p) {
|
||||
v.Providers = append(v.Providers, p)
|
||||
}
|
||||
}
|
||||
return v, nil
|
||||
}
|
||||
|
||||
// providerEnabled 判断某个第三方平台是否配了凭据。绑定入口只列已配置的,
|
||||
// 否则点了必然报错。
|
||||
func (a *API) providerEnabled(name string) bool {
|
||||
switch name {
|
||||
case "github":
|
||||
return a.Cfg.GitHubClientID != "" && a.Cfg.GitHubClientSecret != ""
|
||||
case "google":
|
||||
return a.Cfg.GoogleClientID != "" && a.Cfg.GoogleClientSecret != ""
|
||||
case "telegram":
|
||||
return a.Cfg.TelegramBot != "" && a.Cfg.TelegramToken != ""
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// avatarURL 把 files key 解析成可访问 URL。key 指向的文件已删除时返回空串
|
||||
// (前端会自动回落到站标),不留一个打不开的链接。
|
||||
func (a *API) avatarURL(key string) string {
|
||||
if key == "" {
|
||||
return ""
|
||||
}
|
||||
f, err := a.Store.GetFileByKey(key)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return storage.FileURL(f.Store, f.Key, a.Cfg.UploadsPublicBase)
|
||||
}
|
||||
|
||||
type patchAccountRequest struct {
|
||||
Name *string `json:"name"`
|
||||
Bio *string `json:"bio"`
|
||||
AvatarKey *string `json:"avatar_key"`
|
||||
}
|
||||
|
||||
// patchAccount 改资料。只动传了的字段;头像 key 必须是 files 表里真实存在的
|
||||
// 图片,免得存一个指向任意字符串的死链。
|
||||
func (a *API) patchAccount(w http.ResponseWriter, r *http.Request) {
|
||||
var in patchAccountRequest
|
||||
if err := httpx.Decode(r, &in); err != nil {
|
||||
httpx.BadRequest(w, "invalid body")
|
||||
return
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
st, err := a.Store.GetSettings()
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
changed := false
|
||||
|
||||
if in.Name != nil {
|
||||
name := strings.TrimSpace(*in.Name)
|
||||
if len([]rune(name)) > 40 {
|
||||
httpx.BadRequest(w, "昵称最多 40 字")
|
||||
return
|
||||
}
|
||||
if name == "" {
|
||||
httpx.BadRequest(w, "昵称不能为空")
|
||||
return
|
||||
}
|
||||
// 站主行与站点设置两处都要写:前者是身份来源,后者是既有前端读的地方。
|
||||
if _, err := a.Store.UpdateProfile(owner.ID, name); err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
st.AuthorName = name
|
||||
changed = true
|
||||
}
|
||||
if in.Bio != nil {
|
||||
bio := strings.TrimSpace(*in.Bio)
|
||||
if len([]rune(bio)) > 200 {
|
||||
httpx.BadRequest(w, "简介最多 200 字")
|
||||
return
|
||||
}
|
||||
st.AuthorBio = bio
|
||||
changed = true
|
||||
}
|
||||
if in.AvatarKey != nil {
|
||||
key := strings.TrimSpace(*in.AvatarKey)
|
||||
if len(key) > maxAvatarKeyLen {
|
||||
httpx.BadRequest(w, "头像 key 过长")
|
||||
return
|
||||
}
|
||||
if key != "" {
|
||||
f, err := a.Store.GetFileByKey(key)
|
||||
if errors.Is(err, store.ErrNotFound) {
|
||||
httpx.BadRequest(w, "头像文件不存在,请重新上传")
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
if !strings.HasPrefix(f.Mime, "image/") {
|
||||
httpx.BadRequest(w, "头像必须是图片")
|
||||
return
|
||||
}
|
||||
}
|
||||
st.AuthorAvatarKey = key
|
||||
changed = true
|
||||
}
|
||||
if !changed {
|
||||
httpx.BadRequest(w, "没有要更新的字段")
|
||||
return
|
||||
}
|
||||
// AuthorAvatarURL 是算出来的,不入库;写库前清掉免得误读。
|
||||
st.AuthorAvatarURL = ""
|
||||
if err := a.Store.UpdateSettings(st); err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
// 头像键单独写:UpdateSettings 是全量替换,不含这个键。
|
||||
if in.AvatarKey != nil {
|
||||
if err := a.Store.SetSetting("owner_avatar_key", st.AuthorAvatarKey); err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
}
|
||||
v, err := a.buildAccount()
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, v)
|
||||
}
|
||||
|
||||
// unbindIdentity 解绑一个第三方登录方式。
|
||||
// 站主始终有环境变量密码兜底,所以这里不需要「不能解绑唯一登录方式」的护栏。
|
||||
func (a *API) unbindIdentity(w http.ResponseWriter, r *http.Request) {
|
||||
provider := strings.Trim(strings.TrimPrefix(r.URL.Path, "/api/admin/account/identities/"), "/")
|
||||
if provider == "" || strings.Contains(provider, "/") {
|
||||
httpx.BadRequest(w, "bad provider")
|
||||
return
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
if err := a.Store.UnbindIdentity(owner.ID, provider); err != nil {
|
||||
if errors.Is(err, store.ErrNotFound) {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"ok": true})
|
||||
}
|
||||
|
||||
func firstNonEmptyStr(vals ...string) string {
|
||||
for _, v := range vals {
|
||||
if strings.TrimSpace(v) != "" {
|
||||
return v
|
||||
}
|
||||
}
|
||||
return ""
|
||||
}
|
||||
@@ -0,0 +1,166 @@
|
||||
package admin
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
// doAs 带着有效后台会话发一个请求。
|
||||
func doAs(t *testing.T, h http.Handler, method, path string, body string) *httptest.ResponseRecorder {
|
||||
t.Helper()
|
||||
req := httptest.NewRequest(method, path, strings.NewReader(body))
|
||||
if body != "" {
|
||||
req.Header.Set("Content-Type", "application/json")
|
||||
}
|
||||
// 用与 newTestAPI 里 NewSessions 相同的 secret 签一个会话
|
||||
sess := NewSessions("test-secret", time.Hour)
|
||||
tok, _ := sess.Issue("admin")
|
||||
req.AddCookie(&http.Cookie{Name: cookieName, Value: tok})
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, req)
|
||||
return rec
|
||||
}
|
||||
|
||||
func TestAccountGET(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
if _, err := a.Store.EnsureOwner("admin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
rec := doAs(t, h, http.MethodGet, "/api/admin/account", "")
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
var v struct {
|
||||
Name string `json:"name"`
|
||||
Handle string `json:"handle"`
|
||||
Password struct{} `json:"password"`
|
||||
Providers []string `json:"providers"`
|
||||
}
|
||||
if err := json.Unmarshal(rec.Body.Bytes(), &v); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if v.Handle != "admin" {
|
||||
t.Fatalf("handle=%q", v.Handle)
|
||||
}
|
||||
// 测试配置里没有 OAuth 凭据,可绑平台应为空
|
||||
if len(v.Providers) != 0 {
|
||||
t.Fatalf("providers=%v, want empty", v.Providers)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAccountPATCHProfile(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
if _, err := a.Store.EnsureOwner("admin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
rec := doAs(t, h, http.MethodPatch, "/api/admin/account", `{"name":"麻衣","bio":"活着就是为了樱岛麻衣"}`)
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
// 昵称要同时落在站主行与 settings(前端各处仍读 settings.author_name)
|
||||
owner, err := a.Store.GetOwner()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if owner.Name != "麻衣" {
|
||||
t.Fatalf("owner.name=%q", owner.Name)
|
||||
}
|
||||
st, err := a.Store.GetSettings()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if st.AuthorName != "麻衣" || st.AuthorBio != "活着就是为了樱岛麻衣" {
|
||||
t.Fatalf("settings 未同步: %+v", st)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAccountPATCHAvatarKey(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
if _, err := a.Store.EnsureOwner("admin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
// 不存在的 key 必须拒:否则会存下一个永远解析不出的头像
|
||||
rec := doAs(t, h, http.MethodPatch, "/api/admin/account", `{"avatar_key":"2026/09/nope.png"}`)
|
||||
if rec.Code != http.StatusBadRequest {
|
||||
t.Fatalf("不存在的 key: got %d, want 400", rec.Code)
|
||||
}
|
||||
// 真实存在但不是图片的也要拒
|
||||
f, err := a.Store.CreateFile(model.File{
|
||||
Key: "2026/09/notes.txt", Name: "notes.txt", Mime: "text/plain",
|
||||
Size: 4, SHA256: strings.Repeat("a", 64), Store: "local",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
rec = doAs(t, h, http.MethodPatch, "/api/admin/account", `{"avatar_key":"`+f.Key+`"}`)
|
||||
if rec.Code != http.StatusBadRequest {
|
||||
t.Fatalf("非图片: got %d, want 400", rec.Code)
|
||||
}
|
||||
// 图片就放行,并且单独写 owner_avatar_key(绕开 UpdateSettings 全量替换)
|
||||
img, err := a.Store.CreateFile(model.File{
|
||||
Key: "2026/09/me.png", Name: "me.png", Mime: "image/png",
|
||||
Size: 4, SHA256: strings.Repeat("b", 64), Store: "local",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
rec = doAs(t, h, http.MethodPatch, "/api/admin/account", `{"avatar_key":"`+img.Key+`"}`)
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("图片头像: got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
st, _ := a.Store.GetSettings()
|
||||
if st.AuthorAvatarKey != img.Key {
|
||||
t.Fatalf("avatar key=%q", st.AuthorAvatarKey)
|
||||
}
|
||||
if !strings.Contains(rec.Body.String(), "/uploads/"+img.Key) {
|
||||
t.Fatalf("响应里没解析出头像 URL: %s", rec.Body.String())
|
||||
}
|
||||
// 站点设置的整体 PUT 不该把头像键冲掉(两者写入路径分开)
|
||||
if err := a.Store.UpdateSettings(st); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
after, _ := a.Store.GetSettings()
|
||||
if after.AuthorAvatarKey != img.Key {
|
||||
t.Fatalf("UpdateSettings 把头像键清了: %q", after.AuthorAvatarKey)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAccountRejectsAnonymous(t *testing.T) {
|
||||
_, h := newTestAPI(t)
|
||||
for _, path := range []string{"/api/admin/account", "/api/admin/account/passkeys"} {
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil))
|
||||
if rec.Code != http.StatusUnauthorized {
|
||||
t.Errorf("%s: got %d, want 401", path, rec.Code)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestAccountUnbindUnknown(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
if _, err := a.Store.EnsureOwner("admin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
rec := doAs(t, h, http.MethodDelete, "/api/admin/account/identities/github", "")
|
||||
if rec.Code != http.StatusNotFound {
|
||||
t.Fatalf("没绑过还解绑: got %d, want 404", rec.Code)
|
||||
}
|
||||
}
|
||||
|
||||
// passkey 未配置时必须明确不可用,而不是假装成功
|
||||
func TestPasskeysUnavailableWhenNil(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
if a.Passkeys != nil {
|
||||
t.Skip("测试构造里不该有 Passkeys")
|
||||
}
|
||||
rec := doAs(t, h, http.MethodPost, "/api/admin/account/passkeys/begin", "")
|
||||
if rec.Code != http.StatusServiceUnavailable {
|
||||
t.Fatalf("got %d, want 503", rec.Code)
|
||||
}
|
||||
}
|
||||
@@ -13,16 +13,20 @@ import (
|
||||
"io"
|
||||
"mime/multipart"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"os"
|
||||
"path"
|
||||
"path/filepath"
|
||||
"strconv"
|
||||
"strings"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"oneblog/internal/auth"
|
||||
"oneblog/internal/config"
|
||||
"oneblog/internal/httpx"
|
||||
"oneblog/internal/hub"
|
||||
"oneblog/internal/linkmeta"
|
||||
"oneblog/internal/model"
|
||||
"oneblog/internal/storage"
|
||||
"oneblog/internal/store"
|
||||
@@ -42,6 +46,8 @@ type API struct {
|
||||
// Thumbs 是缩略图磁盘缓存(main.go 装配)。删上传文件时顺手清掉它的
|
||||
// 缩略图产物,否则已删图片会一直占着缓存。
|
||||
Thumbs *thumbs.Store
|
||||
// Passkeys 是 WebAuthn 服务(main.go 装配;未配置时为 nil,相关端点直接 503)
|
||||
Passkeys *auth.Passkeys
|
||||
|
||||
loginOnce sync.Once
|
||||
logins *loginLimiter
|
||||
@@ -79,8 +85,25 @@ func (a *API) Routes() http.Handler {
|
||||
mux.HandleFunc("/api/admin/projects", a.guard(a.listProjects))
|
||||
mux.HandleFunc("/api/admin/projects/", a.guard(a.projectByID))
|
||||
mux.HandleFunc("/api/admin/files", a.guard(a.files))
|
||||
mux.HandleFunc("/api/admin/files/import", a.guard(a.importFiles))
|
||||
mux.HandleFunc("/api/admin/files/", a.guard(a.fileByID))
|
||||
mux.HandleFunc("/api/admin/settings", a.guard(a.settings))
|
||||
// 账户页:资料 + 身份绑定 + passkey
|
||||
mux.HandleFunc("/api/admin/account", a.guard(func(w http.ResponseWriter, r *http.Request) {
|
||||
switch r.Method {
|
||||
case http.MethodGet:
|
||||
a.account(w, r)
|
||||
case http.MethodPatch, http.MethodPut:
|
||||
a.patchAccount(w, r)
|
||||
default:
|
||||
httpx.Error(w, http.StatusMethodNotAllowed, "GET/PATCH required")
|
||||
}
|
||||
}))
|
||||
mux.HandleFunc("/api/admin/account/identities/", a.guard(a.unbindIdentity))
|
||||
mux.HandleFunc("/api/admin/account/passkeys", a.guard(a.listPasskeys))
|
||||
mux.HandleFunc("/api/admin/account/passkeys/begin", a.guard(a.beginPasskey))
|
||||
mux.HandleFunc("/api/admin/account/passkeys/finish", a.guard(a.finishPasskey))
|
||||
mux.HandleFunc("/api/admin/account/passkeys/", a.guard(a.deletePasskey))
|
||||
mux.HandleFunc("/api/admin/comments", a.guard(a.adminComments))
|
||||
mux.HandleFunc("/api/admin/comments/", a.guard(a.adminCommentByID))
|
||||
mux.HandleFunc("/api/admin/readers", a.guard(a.adminReaders))
|
||||
@@ -227,6 +250,7 @@ func (a *API) listPosts(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
in.Status = store.NormalizeStatus(in.Status)
|
||||
attachLinkCard(r.Context(), &in, nil)
|
||||
autoMeta(&in, nil)
|
||||
p, err := a.Store.Create(in)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
@@ -266,12 +290,16 @@ func (a *API) postByID(w http.ResponseWriter, r *http.Request) {
|
||||
if in.Status != "" {
|
||||
in.Status = store.NormalizeStatus(in.Status)
|
||||
}
|
||||
// 多读一次当前行只为拿到已有卡片:链接没变就不必再打远端
|
||||
// 多读一次当前行:链接卡片没变就不必再打远端;摘要/封面自动
|
||||
// 生成也以它为准——「新值与旧值都为空」才补,主动清空的保得住
|
||||
var curCard *model.LinkCard
|
||||
var curPost *model.Post
|
||||
if cur, err := a.Store.Get(id); err == nil {
|
||||
curCard = cur.LinkCard
|
||||
curPost = &cur
|
||||
}
|
||||
attachLinkCard(r.Context(), &in, curCard)
|
||||
autoMeta(&in, curPost)
|
||||
p, err := a.Store.Update(id, in)
|
||||
writeOne(w, p, err)
|
||||
case http.MethodDelete:
|
||||
@@ -727,6 +755,12 @@ func (a *API) storeOne(ctx context.Context, fh *multipart.FileHeader) (model.Fil
|
||||
}
|
||||
|
||||
sum := hex.EncodeToString(hasher.Sum(nil))
|
||||
return a.persistFile(ctx, fh.Filename, ext, mime, tmp.Name(), size, sum)
|
||||
}
|
||||
|
||||
// persistFile 落库共享段:内容哈希做 key(同年月分目录)、去重复用、
|
||||
// Put 对象存储、建行。storeOne(本地上传)与 importOne(外链转存)共用。
|
||||
func (a *API) persistFile(ctx context.Context, name, ext, mime, tmpPath string, size int64, sum string) (model.File, error) {
|
||||
key := fmt.Sprintf("%s/%s%s", time.Now().UTC().Format("2006/01"), sum[:12], ext)
|
||||
// S3Api 端点带路径段时(如 .../oss),该段会折进对象 key——
|
||||
// 数据库必须记录同样的完整 key,直链才不会 404
|
||||
@@ -734,12 +768,15 @@ func (a *API) storeOne(ctx context.Context, fh *multipart.FileHeader) (model.Fil
|
||||
key = p + "/" + key
|
||||
}
|
||||
|
||||
// 内容去重:同一份内容只存一份,复用已有行
|
||||
// 内容去重:同一份内容只存一份,复用已有行。
|
||||
// URL 必须按当前存储配置重新解析——去重路径不走下面的 created 赋值,
|
||||
// 漏了它转存替换会拿到空 URL(真实事故:正文图片链接被清空)。
|
||||
if exist, err := a.Store.GetFileByKey(key); err == nil {
|
||||
exist.URL = storage.FileURL(exist.Store, exist.Key, a.Cfg.UploadsPublicBase)
|
||||
return exist, nil
|
||||
}
|
||||
|
||||
f, err := os.Open(tmp.Name())
|
||||
f, err := os.Open(tmpPath)
|
||||
if err != nil {
|
||||
return model.File{}, err
|
||||
}
|
||||
@@ -750,7 +787,7 @@ func (a *API) storeOne(ctx context.Context, fh *multipart.FileHeader) (model.Fil
|
||||
|
||||
created, err := a.Store.CreateFile(model.File{
|
||||
Key: key,
|
||||
Name: fh.Filename,
|
||||
Name: name,
|
||||
Mime: mime,
|
||||
Size: size,
|
||||
SHA256: sum,
|
||||
@@ -763,14 +800,121 @@ func (a *API) storeOne(ctx context.Context, fh *multipart.FileHeader) (model.Fil
|
||||
return created, nil
|
||||
}
|
||||
|
||||
// mimeToExt 是 allowFileExt 的反向映射:外链转存时内容嗅探出 mime,
|
||||
// 反推扩展名(URL 本身可能不带后缀或后缀不可信)。
|
||||
var mimeToExt = func() map[string]string {
|
||||
m := make(map[string]string, len(allowFileExt))
|
||||
for ext, mime := range allowFileExt {
|
||||
m[mime] = ext
|
||||
}
|
||||
return m
|
||||
}()
|
||||
|
||||
// importFiles 外链转存:POST /api/admin/files/import {"urls": [...]}。
|
||||
// 站主把别处的图片贴进正文后一键搬进自己的存储——与手动上传同一套
|
||||
// 白名单、内容嗅探与内容去重;抓取走 linkmeta 的 SSRF 防护拨号。
|
||||
func (a *API) importFiles(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodPost {
|
||||
httpx.Error(w, http.StatusMethodNotAllowed, "POST required")
|
||||
return
|
||||
}
|
||||
var in struct {
|
||||
URLs []string `json:"urls"`
|
||||
}
|
||||
if err := httpx.Decode(r, &in); err != nil {
|
||||
httpx.BadRequest(w, "invalid body")
|
||||
return
|
||||
}
|
||||
if len(in.URLs) == 0 || len(in.URLs) > 20 {
|
||||
httpx.BadRequest(w, "urls 需要1-20个")
|
||||
return
|
||||
}
|
||||
// files 带上 source(原址),前端按它做正文替换
|
||||
type imported struct {
|
||||
Source string `json:"source"`
|
||||
File model.File `json:"file"`
|
||||
}
|
||||
files := make([]imported, 0, len(in.URLs))
|
||||
errs := map[string]string{}
|
||||
for _, u := range in.URLs {
|
||||
f, err := a.importOne(r.Context(), u)
|
||||
if err != nil {
|
||||
if bu, ok := err.(badUpload); ok {
|
||||
errs[u] = string(bu)
|
||||
} else {
|
||||
errs[u] = err.Error()
|
||||
}
|
||||
continue
|
||||
}
|
||||
files = append(files, imported{Source: u, File: f})
|
||||
}
|
||||
httpx.OK(w, map[string]any{"files": files, "errors": errs})
|
||||
}
|
||||
|
||||
func (a *API) importOne(ctx context.Context, rawURL string) (model.File, error) {
|
||||
cctx, cancel := context.WithTimeout(ctx, 20*time.Second)
|
||||
defer cancel()
|
||||
data, ct, err := linkmeta.FetchBytes(cctx, rawURL, maxFileUpload)
|
||||
if err != nil {
|
||||
return model.File{}, fmt.Errorf("抓取失败:%w", err)
|
||||
}
|
||||
if len(data) == 0 {
|
||||
return model.File{}, badUpload("空内容")
|
||||
}
|
||||
// 类型必须落在本站白名单里:嗅探优先(不信响应头,更不信 URL 后缀)
|
||||
detected := strings.SplitN(http.DetectContentType(data[:512]), ";", 2)[0]
|
||||
ext, ok := mimeToExt[detected]
|
||||
if !ok {
|
||||
return model.File{}, badUpload("不支持的类型 " + detected)
|
||||
}
|
||||
_ = ct
|
||||
// 落临时文件:persistFile / S3 PutObject 都要确定的文件与长度
|
||||
tmp, err := os.CreateTemp("", "one-import-*")
|
||||
if err != nil {
|
||||
return model.File{}, err
|
||||
}
|
||||
defer os.Remove(tmp.Name())
|
||||
size, err := tmp.Write(data)
|
||||
if err != nil {
|
||||
tmp.Close()
|
||||
return model.File{}, err
|
||||
}
|
||||
if err := tmp.Close(); err != nil {
|
||||
return model.File{}, err
|
||||
}
|
||||
sum := sha256.Sum256(data)
|
||||
// 名字取 URL 路径末段(仅用于文件管理页展示,不参与存储路径)
|
||||
name := rawURL
|
||||
if u, err := url.Parse(rawURL); err == nil && u.Path != "" {
|
||||
if base := path.Base(u.Path); base != "" && base != "/" && base != "." {
|
||||
name = base
|
||||
}
|
||||
}
|
||||
return a.persistFile(ctx, name, ext, detected, tmp.Name(), int64(size), hex.EncodeToString(sum[:]))
|
||||
}
|
||||
|
||||
func (a *API) fileByID(w http.ResponseWriter, r *http.Request) {
|
||||
id, err := parseInt(strings.Trim(strings.TrimPrefix(r.URL.Path, "/api/admin/files/"), "/"))
|
||||
rest := strings.Trim(strings.TrimPrefix(r.URL.Path, "/api/admin/files/"), "/")
|
||||
idPart, sub := rest, ""
|
||||
if i := strings.Index(rest, "/"); i >= 0 {
|
||||
idPart, sub = rest[:i], rest[i+1:]
|
||||
}
|
||||
// /files/{id} 与 /files/{id}/refs 两种形态,别的一律不收
|
||||
if sub != "" && (sub != "refs" || r.Method != http.MethodGet) {
|
||||
httpx.BadRequest(w, "bad file path")
|
||||
return
|
||||
}
|
||||
id, err := parseInt(idPart)
|
||||
if err != nil {
|
||||
httpx.BadRequest(w, "bad file id")
|
||||
return
|
||||
}
|
||||
switch r.Method {
|
||||
case http.MethodGet:
|
||||
if sub == "refs" {
|
||||
a.fileRefs(w, r, id)
|
||||
return
|
||||
}
|
||||
f, err := a.Store.GetFile(id)
|
||||
if errors.Is(err, store.ErrNotFound) {
|
||||
httpx.NotFound(w)
|
||||
@@ -792,6 +936,15 @@ func (a *API) fileByID(w http.ResponseWriter, r *http.Request) {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
// 正文/封面/项目/站主头像里还在用就先挡住,除非明确带 force=1。
|
||||
// 检查放在删对象之前:一旦 blob 删了就没法回头。
|
||||
if refs, err := a.Store.FileReferences(f.Key); err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
} else if len(refs) > 0 && httpx.QueryString(r, "force") != "1" {
|
||||
httpx.Error(w, http.StatusConflict, fileInUseMessage(refs))
|
||||
return
|
||||
}
|
||||
// 先删对象存储再删行:存储端失败时行保留,可以重试
|
||||
if err := a.Blobs.Delete(r.Context(), f.Key); err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
@@ -810,6 +963,49 @@ func (a *API) fileByID(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
}
|
||||
|
||||
// fileRefs 报告这个文件被谁引用,供前端在删除弹层里列出来。
|
||||
func (a *API) fileRefs(w http.ResponseWriter, r *http.Request, id int64) {
|
||||
f, err := a.Store.GetFile(id)
|
||||
if errors.Is(err, store.ErrNotFound) {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
refs, err := a.Store.FileReferences(f.Key)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"key": f.Key, "count": len(refs), "items": refs})
|
||||
}
|
||||
|
||||
// fileInUseMessage 是挡住删除时回给调用方的一句话,只列前三个引用。
|
||||
func fileInUseMessage(refs []model.FileRef) string {
|
||||
names := make([]string, 0, 3)
|
||||
for _, x := range refs {
|
||||
if x.Kind == "avatar" {
|
||||
names = append(names, "站主头像")
|
||||
continue
|
||||
}
|
||||
t := x.Title
|
||||
if t == "" {
|
||||
t = x.Slug
|
||||
}
|
||||
names = append(names, "《"+t+"》")
|
||||
if len(names) == 3 {
|
||||
break
|
||||
}
|
||||
}
|
||||
label := strings.Join(names, "、")
|
||||
if len(refs) > len(names) {
|
||||
label += " 等"
|
||||
}
|
||||
return fmt.Sprintf("该文件正被 %d 处引用:%s,删除后这些位置会失效(确认要删带 force=1)", len(refs), label)
|
||||
}
|
||||
|
||||
// ---------- comments(评论审核与管理) ----------
|
||||
|
||||
func (a *API) adminComments(w http.ResponseWriter, r *http.Request) {
|
||||
|
||||
@@ -0,0 +1,147 @@
|
||||
package admin
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"net/http"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strconv"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"oneblog/internal/model"
|
||||
"oneblog/internal/storage"
|
||||
"oneblog/internal/store"
|
||||
)
|
||||
|
||||
func itoa(n int64) string { return strconv.FormatInt(n, 10) }
|
||||
|
||||
// seed 放一个本地 blob + 一行 files,再按 body 建一篇引用它的短文(body 为空表示不引用)。
|
||||
func seed(t *testing.T, a *API, key, body string) model.File {
|
||||
t.Helper()
|
||||
if err := a.Blobs.Put(t.Context(), key, strings.NewReader("pngbytes"), 8, "image/png"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
f, err := a.Store.CreateFile(model.File{
|
||||
Key: key, Name: filepath.Base(key), Mime: "image/png",
|
||||
Size: 8, SHA256: strings.Repeat("f", 64), Store: "local",
|
||||
})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if body != "" {
|
||||
if _, err := a.Store.Create(model.PostInput{
|
||||
Kind: model.KindShort, Slug: "s-" + key, ContentMd: body, Status: model.StatusPublished,
|
||||
}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
return f
|
||||
}
|
||||
|
||||
func TestFileRefsEndpoint(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
a.Blobs = storage.NewLocal(t.TempDir())
|
||||
f := seed(t, a, "2026/09/aaa.png", `看图 `)
|
||||
// 顺手把站主头像也指到同一张图,refs 要把这一路也报出来
|
||||
if err := a.Store.SetSetting("owner_avatar_key", f.Key); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
rec := doAs(t, h, http.MethodGet, "/api/admin/files/"+itoa(f.ID)+"/refs", "")
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
var v struct {
|
||||
Key string `json:"key"`
|
||||
Count int `json:"count"`
|
||||
Items []model.FileRef `json:"items"`
|
||||
}
|
||||
if err := json.Unmarshal(rec.Body.Bytes(), &v); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if v.Key != f.Key || v.Count != 2 || len(v.Items) != 2 {
|
||||
t.Fatalf("refs 不对: %+v", v)
|
||||
}
|
||||
var kinds = map[string]bool{}
|
||||
for _, x := range v.Items {
|
||||
kinds[x.Kind] = true
|
||||
}
|
||||
if !kinds["post"] || !kinds["avatar"] {
|
||||
t.Fatalf("缺引用类型: %+v", v.Items)
|
||||
}
|
||||
|
||||
// 不存在的文件:404 而不是空列表
|
||||
rec = doAs(t, h, http.MethodGet, "/api/admin/files/9999/refs", "")
|
||||
if rec.Code != http.StatusNotFound {
|
||||
t.Fatalf("want 404, got %d", rec.Code)
|
||||
}
|
||||
// 乱七八糟的子路径不收
|
||||
rec = doAs(t, h, http.MethodGet, "/api/admin/files/1/nope", "")
|
||||
if rec.Code != http.StatusBadRequest {
|
||||
t.Fatalf("want 400, got %d", rec.Code)
|
||||
}
|
||||
}
|
||||
|
||||
// 有引用时默认挡住,而且挡住之后 blob 和行都得还在(可重试)。
|
||||
func TestFileDeleteBlockedByRefs(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
dir := t.TempDir()
|
||||
a.Blobs = storage.NewLocal(dir)
|
||||
f := seed(t, a, "2026/09/bbb.png", ``)
|
||||
|
||||
rec := doAs(t, h, http.MethodDelete, "/api/admin/files/"+itoa(f.ID), "")
|
||||
if rec.Code != http.StatusConflict {
|
||||
t.Fatalf("want 409, got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
var e struct {
|
||||
Error string `json:"error"`
|
||||
}
|
||||
if err := json.Unmarshal(rec.Body.Bytes(), &e); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if !strings.Contains(e.Error, "1 处引用") {
|
||||
t.Fatalf("错误消息没报引用数: %q", e.Error)
|
||||
}
|
||||
if _, err := os.Stat(filepath.Join(dir, "2026/09/bbb.png")); err != nil {
|
||||
t.Fatalf("被挡住时不该动存储: %v", err)
|
||||
}
|
||||
if _, err := a.Store.GetFile(f.ID); err != nil {
|
||||
t.Fatalf("被挡住时不该删行: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// 明确带 force=1 才真删:行、blob 一起走。
|
||||
func TestFileDeleteForceProceeds(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
dir := t.TempDir()
|
||||
a.Blobs = storage.NewLocal(dir)
|
||||
f := seed(t, a, "2026/09/ccc.png", ``)
|
||||
|
||||
rec := doAs(t, h, http.MethodDelete, "/api/admin/files/"+itoa(f.ID)+"?force=1", "")
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("want 200, got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
if _, err := a.Store.GetFile(f.ID); !errors.Is(err, store.ErrNotFound) {
|
||||
t.Fatalf("行应已删除, got %v", err)
|
||||
}
|
||||
if _, err := os.Stat(filepath.Join(dir, "2026/09/ccc.png")); !os.IsNotExist(err) {
|
||||
t.Fatalf("blob 应已删除, got %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
// 没被引用的文件不用 force 也能删(守卫不能把所有删除都挡死)。
|
||||
func TestFileDeleteUnreferenced(t *testing.T) {
|
||||
a, h := newTestAPI(t)
|
||||
a.Blobs = storage.NewLocal(t.TempDir())
|
||||
f := seed(t, a, "2026/09/ddd.png", "")
|
||||
|
||||
rec := doAs(t, h, http.MethodDelete, "/api/admin/files/"+itoa(f.ID), "")
|
||||
if rec.Code != http.StatusOK {
|
||||
t.Fatalf("want 200, got %d %s", rec.Code, rec.Body.String())
|
||||
}
|
||||
if _, err := a.Store.GetFile(f.ID); !errors.Is(err, store.ErrNotFound) {
|
||||
t.Fatalf("行应已删除, got %v", err)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,68 @@
|
||||
// 长文的自动摘要与自动封面:站主没填这两项时从正文派生——
|
||||
// 摘要取正文开头的一段纯文本,封面取正文第一张图。
|
||||
// 更新路径只在「新值与旧值都为空」时才生成,站主主动清空的要保得住。
|
||||
package admin
|
||||
|
||||
import (
|
||||
"regexp"
|
||||
"strings"
|
||||
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
const autoSummaryLen = 110
|
||||
|
||||
var (
|
||||
mdImageRe = regexp.MustCompile(`!\[[^\]]*\]\(([^)\s]+)[^)]*\)`)
|
||||
mdCodeFence = regexp.MustCompile("(?s)```.*?```")
|
||||
mdLinkRe = regexp.MustCompile(`\[([^\]]*)\]\([^)]*\)`)
|
||||
mdHeadingRe = regexp.MustCompile(`(?m)^#{1,6}\s+.*$`) // 标题行整行不进摘要(与文章标题重复)
|
||||
mdNoiseRe = regexp.MustCompile(`(?m)^([>\s*-]+|\d+\.\s)+`)
|
||||
mdEmphasis = strings.NewReplacer("**", "", "__", "", "~~", "", "*", "", "_", "")
|
||||
wsRe = regexp.MustCompile(`\s+`)
|
||||
)
|
||||
|
||||
// autoMeta 按需填充 in.Summary / in.CoverURL。
|
||||
// cur 为更新前的旧文章(新建时传 nil)。
|
||||
func autoMeta(in *model.PostInput, cur *model.Post) {
|
||||
if in.Kind != model.KindLong || strings.TrimSpace(in.ContentMd) == "" {
|
||||
return
|
||||
}
|
||||
if strings.TrimSpace(in.Summary) == "" && (cur == nil || strings.TrimSpace(cur.Summary) == "") {
|
||||
in.Summary = summarizeMarkdown(in.ContentMd, autoSummaryLen)
|
||||
}
|
||||
if strings.TrimSpace(in.CoverURL) == "" && (cur == nil || strings.TrimSpace(cur.CoverURL) == "") {
|
||||
in.CoverURL = firstImage(in.ContentMd)
|
||||
}
|
||||
}
|
||||
|
||||
// summarizeMarkdown 剥掉 markdown 语法后取正文开头一段纯文本
|
||||
func summarizeMarkdown(md string, maxRunes int) string {
|
||||
s := mdCodeFence.ReplaceAllString(md, " ") // 代码块整段不进摘要
|
||||
s = mdHeadingRe.ReplaceAllString(s, " ")
|
||||
s = mdImageRe.ReplaceAllString(s, " ")
|
||||
s = mdLinkRe.ReplaceAllString(s, "$1")
|
||||
s = mdNoiseRe.ReplaceAllString(s, " ")
|
||||
s = mdEmphasis.Replace(s)
|
||||
s = strings.ReplaceAll(s, "`", "")
|
||||
s = wsRe.ReplaceAllString(s, " ")
|
||||
s = strings.TrimSpace(s)
|
||||
runes := []rune(s)
|
||||
if len(runes) > maxRunes {
|
||||
return string(runes[:maxRunes]) + "…"
|
||||
}
|
||||
return s
|
||||
}
|
||||
|
||||
// firstImage 取正文第一张图片的地址(markdown 图;http/站内路径均可)
|
||||
func firstImage(md string) string {
|
||||
m := mdImageRe.FindStringSubmatch(md)
|
||||
if m == nil {
|
||||
return ""
|
||||
}
|
||||
u := m[1]
|
||||
if strings.HasPrefix(u, "http://") || strings.HasPrefix(u, "https://") || strings.HasPrefix(u, "/uploads/") {
|
||||
return u
|
||||
}
|
||||
return ""
|
||||
}
|
||||
@@ -0,0 +1,62 @@
|
||||
package admin
|
||||
|
||||
import (
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
func TestSummarizeMarkdown(t *testing.T) {
|
||||
md := "## 标题\n\n这是**正文**的第一段,含[链接](https://x.com)与图片:\n\n\n\n```go\ncode ignored\n```\n\n后续内容"
|
||||
got := summarizeMarkdown(md, 110)
|
||||
for _, bad := range []string{"#", "**", "![]", "```", "code ignored"} {
|
||||
if strings.Contains(got, bad) {
|
||||
t.Errorf("summary 含语法残留 %q: %q", bad, got)
|
||||
}
|
||||
}
|
||||
if !strings.Contains(got, "链接") || !strings.HasPrefix(got, "这是") {
|
||||
t.Errorf("summary 应以正文开头并保留链接文字: %q", got)
|
||||
}
|
||||
long := strings.Repeat("长", 200)
|
||||
if got := summarizeMarkdown(long, 110); len([]rune(got)) != 111 || !strings.HasSuffix(got, "…") {
|
||||
t.Errorf("超长应截到 110+省略号, got %d runes", len([]rune(got)))
|
||||
}
|
||||
}
|
||||
|
||||
func TestFirstImage(t *testing.T) {
|
||||
md := "前言\n\n\n\n"
|
||||
if got := firstImage(md); got != "https://a.com/1.png" {
|
||||
t.Errorf("firstImage = %q", got)
|
||||
}
|
||||
if got := firstImage("没有图片"); got != "" {
|
||||
t.Errorf("无图应返回空, got %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAutoMeta(t *testing.T) {
|
||||
in := model.PostInput{Kind: model.KindLong, ContentMd: "# T\n\n正文内容 "}
|
||||
autoMeta(&in, nil)
|
||||
if in.Summary == "" || in.CoverURL != "https://a.com/x.png" {
|
||||
t.Errorf("空字段应自动填充: summary=%q cover=%q", in.Summary, in.CoverURL)
|
||||
}
|
||||
// 站主已填的不能覆盖
|
||||
in2 := model.PostInput{Kind: model.KindLong, ContentMd: "正文", Summary: "手写的", CoverURL: ""}
|
||||
autoMeta(&in2, nil)
|
||||
if in2.Summary != "手写的" {
|
||||
t.Errorf("手写摘要不应被覆盖: %q", in2.Summary)
|
||||
}
|
||||
// 更新路径:新值与旧值都空才补——主动清空的保得住
|
||||
cleared := model.PostInput{Kind: model.KindLong, ContentMd: "正文", Summary: "", CoverURL: ""}
|
||||
cur := model.Post{Summary: "旧摘要", CoverURL: "旧封面"}
|
||||
autoMeta(&cleared, &cur)
|
||||
if cleared.Summary != "" || cleared.CoverURL != "" {
|
||||
t.Errorf("主动清空不应复活: summary=%q cover=%q", cleared.Summary, cleared.CoverURL)
|
||||
}
|
||||
// 新旧都空 → 生成
|
||||
never := model.PostInput{Kind: model.KindLong, ContentMd: "正文 "}
|
||||
autoMeta(&never, &model.Post{})
|
||||
if never.CoverURL != "/uploads/a.png" {
|
||||
t.Errorf("新旧都空应取首图: %q", never.CoverURL)
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,141 @@
|
||||
// Passkey 的管理端点:列出、注册(两步)、删除。
|
||||
//
|
||||
// 全部在 guard 之后 —— 注册凭据等于发放永久登录方式,必须已是管理员。
|
||||
// 删光 passkey 也不会把自已锁死:站主密码走环境变量,不在这张表里。
|
||||
package admin
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"net/http"
|
||||
"strconv"
|
||||
"strings"
|
||||
|
||||
"oneblog/internal/auth"
|
||||
"oneblog/internal/httpx"
|
||||
"oneblog/internal/store"
|
||||
)
|
||||
|
||||
// passkeyName 是站主给这把凭据起的名字(「MacBook 指纹」「iPhone」)。
|
||||
type passkeyNameRequest struct {
|
||||
Name string `json:"name"`
|
||||
}
|
||||
|
||||
func (a *API) listPasskeys(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodGet {
|
||||
httpx.Error(w, http.StatusMethodNotAllowed, "GET required")
|
||||
return
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
list, err := a.Store.ListPasskeys(owner.ID)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"passkeys": list})
|
||||
}
|
||||
|
||||
func (a *API) beginPasskey(w http.ResponseWriter, r *http.Request) {
|
||||
if a.Passkeys == nil {
|
||||
httpx.Error(w, http.StatusServiceUnavailable, "passkey 未启用")
|
||||
return
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
existing, err := a.Store.ListPasskeys(owner.ID)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
creation, token, err := a.Passkeys.BeginRegistration(owner.ID, owner.Handle, owner.Name, existing)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"options": creation, "token": token})
|
||||
}
|
||||
|
||||
func (a *API) finishPasskey(w http.ResponseWriter, r *http.Request) {
|
||||
if a.Passkeys == nil {
|
||||
httpx.Error(w, http.StatusServiceUnavailable, "passkey 未启用")
|
||||
return
|
||||
}
|
||||
var in struct {
|
||||
Token string `json:"token"`
|
||||
Name string `json:"name"`
|
||||
Credential json.RawMessage `json:"credential"`
|
||||
}
|
||||
if err := httpx.Decode(r, &in); err != nil || in.Token == "" || len(in.Credential) == 0 {
|
||||
httpx.BadRequest(w, "token 与 credential 都要传")
|
||||
return
|
||||
}
|
||||
name := strings.TrimSpace(in.Name)
|
||||
if len([]rune(name)) > 40 {
|
||||
httpx.BadRequest(w, "名称最多 40 字")
|
||||
return
|
||||
}
|
||||
if name == "" {
|
||||
name = "未命名设备"
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
existing, err := a.Store.ListPasskeys(owner.ID)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
pk, err := a.Passkeys.FinishRegistration(in.Token, owner.ID, owner.Handle, owner.Name, existing, in.Credential)
|
||||
if errors.Is(err, auth.ErrSessionExpired) {
|
||||
httpx.Error(w, http.StatusGone, "注册已过期,请重新开始")
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
httpx.Error(w, http.StatusBadRequest, "passkey 校验失败:"+err.Error())
|
||||
return
|
||||
}
|
||||
pk.Name = name
|
||||
created, err := a.Store.AddPasskey(pk)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
// 公钥不回传:前端不需要,少一处能误用的字段
|
||||
created.PublicKey = ""
|
||||
httpx.Created(w, created)
|
||||
}
|
||||
|
||||
func (a *API) deletePasskey(w http.ResponseWriter, r *http.Request) {
|
||||
if r.Method != http.MethodDelete {
|
||||
httpx.Error(w, http.StatusMethodNotAllowed, "DELETE required")
|
||||
return
|
||||
}
|
||||
id, err := strconv.ParseInt(strings.Trim(strings.TrimPrefix(r.URL.Path, "/api/admin/account/passkeys/"), "/"), 10, 64)
|
||||
if err != nil || id <= 0 {
|
||||
httpx.BadRequest(w, "bad passkey id")
|
||||
return
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
if err := a.Store.DeletePasskey(id, owner.ID); err != nil {
|
||||
if errors.Is(err, store.ErrNotFound) {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"ok": true})
|
||||
}
|
||||
@@ -0,0 +1,280 @@
|
||||
// 账户相关的公开端点:第三方身份绑定、passkey 登录。
|
||||
//
|
||||
// 绑定复用登录的 OAuth 跳转,只在发起时多打一个一次性 cookie 表明意图;
|
||||
// 回调拿到身份后统一走 afterIdentity 分流,免得三个 provider 各写一遍判断。
|
||||
//
|
||||
// 分流规则(顺序即优先级):
|
||||
// 1. 带绑定意图 + 当前是有效管理员会话 → 把该外部身份绑到站主账号,回账户页
|
||||
// 2. 该外部身份已绑到某账号 → 站主发后台会话,读者发读者会话
|
||||
// 3. 谁都不认识 → 按老路建/更新读者档案,发读者会话
|
||||
//
|
||||
// 第 1 步必须校验管理员会话:否则任何人都能跑一遍自己的 OAuth 流程,
|
||||
// 把身份塞进别人的账号上。
|
||||
package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"log"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"strings"
|
||||
|
||||
"oneblog/internal/auth"
|
||||
"oneblog/internal/httpx"
|
||||
"oneblog/internal/model"
|
||||
"oneblog/internal/ratelimit"
|
||||
"oneblog/internal/store"
|
||||
)
|
||||
|
||||
const oauthBindCook = "one_oauth_bind"
|
||||
|
||||
// startOAuth 备好 state(防 CSRF)与回跳地址,然后跳到 provider 授权页。
|
||||
// authorize 拿到 state 拼出最终授权 URL —— state 必须在这里生成,
|
||||
// 又要出现在 URL 里,所以用回调而不是先算好传进来。
|
||||
func (a *API) startOAuth(w http.ResponseWriter, r *http.Request, authorize func(state string) string) {
|
||||
state := randHex(16)
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthStateCook, Value: state, Path: "/",
|
||||
HttpOnly: true, MaxAge: 600})
|
||||
// 记下发起登录的前台 origin:开发时前端 :3000、后端 :8080 分离,
|
||||
// 回调只有靠它才知道该跳回哪儿。
|
||||
if ref := r.Referer(); ref != "" {
|
||||
if u, err := url.Parse(ref); err == nil && u.Scheme != "" && u.Host != "" {
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBackCook,
|
||||
Value: u.Scheme + "://" + u.Host, Path: "/", HttpOnly: true, MaxAge: 600})
|
||||
}
|
||||
}
|
||||
http.Redirect(w, r, authorize(state), http.StatusFound)
|
||||
}
|
||||
|
||||
// beginBind 发起绑定。只有已登录的后台管理员能发起,且平台必须已配置。
|
||||
func (a *API) beginBind(w http.ResponseWriter, r *http.Request) {
|
||||
provider := strings.Trim(strings.TrimPrefix(r.URL.Path, "/api/auth/"), "/")
|
||||
provider = strings.TrimSuffix(provider, "/bind")
|
||||
if !a.adminSessionValid(r) {
|
||||
httpx.Unauthorized(w)
|
||||
return
|
||||
}
|
||||
setBindCookie(w)
|
||||
switch provider {
|
||||
case "github":
|
||||
if !a.GH.Enabled() {
|
||||
clearBindCookie(w)
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
a.startOAuth(w, r, func(state string) string {
|
||||
return a.GH.LoginURL(a.Cfg.SiteURL+"/api/auth/callback/github", state)
|
||||
})
|
||||
case "google":
|
||||
if !a.GG.Enabled() {
|
||||
clearBindCookie(w)
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
a.startOAuth(w, r, func(state string) string {
|
||||
return a.GG.LoginURL(a.Cfg.SiteURL+"/api/auth/callback/google", state)
|
||||
})
|
||||
default:
|
||||
clearBindCookie(w)
|
||||
httpx.NotFound(w)
|
||||
}
|
||||
}
|
||||
|
||||
func setBindCookie(w http.ResponseWriter) {
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBindCook, Value: "1", Path: "/",
|
||||
HttpOnly: true, MaxAge: 600, SameSite: http.SameSiteLaxMode})
|
||||
}
|
||||
|
||||
func clearBindCookie(w http.ResponseWriter) {
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBindCook, Value: "", Path: "/", MaxAge: -1})
|
||||
}
|
||||
|
||||
func bindRequested(r *http.Request) bool {
|
||||
ck, err := r.Cookie(oauthBindCook)
|
||||
return err == nil && ck.Value == "1"
|
||||
}
|
||||
|
||||
// adminSessionValid 判断当前请求带的是不是有效后台会话。
|
||||
// 公开 API 只依赖注入的接口(不 import admin 包,免得两个 API 互相引用成环)。
|
||||
func (a *API) adminSessionValid(r *http.Request) bool {
|
||||
if a.AdminSessions == nil {
|
||||
return false
|
||||
}
|
||||
ck, err := r.Cookie(adminCookieName)
|
||||
if err != nil || ck.Value == "" {
|
||||
return false
|
||||
}
|
||||
_, verr := a.AdminSessions.Verify(ck.Value)
|
||||
return verr == nil
|
||||
}
|
||||
|
||||
const adminCookieName = "one_session"
|
||||
|
||||
// afterIdentity 见文件头的分流规则。返回空串表示响应已写好,调用方直接 return。
|
||||
func (a *API) afterIdentity(w http.ResponseWriter, r *http.Request, provider, externUID, display string, persona model.Reader) string {
|
||||
defer clearBindCookie(w) // 意图用完即清,免得下次普通登录误判成绑定
|
||||
if externUID == "" {
|
||||
// provider 没给稳定 id:宁可退回老流程按 handle 认人,也不建一条
|
||||
// 空 extern_uid 的绑定 —— 空值会和别人的空值撞唯一键。
|
||||
return a.issueReaderLogin(w, r, persona)
|
||||
}
|
||||
|
||||
if bindRequested(r) {
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return ""
|
||||
}
|
||||
if err := a.Store.BindIdentity(owner.ID, provider, externUID, display); err != nil {
|
||||
if errors.Is(err, store.ErrConflict) {
|
||||
httpx.Error(w, http.StatusConflict, "该账号已绑定到其他用户")
|
||||
return ""
|
||||
}
|
||||
httpx.ServerError(w, err)
|
||||
return ""
|
||||
}
|
||||
http.Redirect(w, r, strings.TrimRight(a.Cfg.SiteURL, "/")+"/admin/account?bound="+url.QueryEscape(provider), http.StatusFound)
|
||||
return ""
|
||||
}
|
||||
|
||||
// 已绑定的身份优先于新建档案:站主用绑定的 GitHub 登录要拿到后台会话
|
||||
u, err := a.Store.GetUserByIdentity(provider, externUID)
|
||||
switch {
|
||||
case err == nil && u.Role == model.RoleOwner:
|
||||
a.issueAdminSession(w, r)
|
||||
return ""
|
||||
case err == nil:
|
||||
return a.issueReaderSession(w, r, u.ID)
|
||||
case !errors.Is(err, store.ErrNotFound):
|
||||
httpx.ServerError(w, err)
|
||||
return ""
|
||||
}
|
||||
return a.issueReaderLogin(w, r, persona)
|
||||
}
|
||||
|
||||
func (a *API) issueReaderLogin(w http.ResponseWriter, r *http.Request, persona model.Reader) string {
|
||||
reader, err := a.Store.UpsertReader(persona)
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return ""
|
||||
}
|
||||
return a.issueReaderSession(w, r, reader.ID)
|
||||
}
|
||||
|
||||
func (a *API) issueReaderSession(w http.ResponseWriter, r *http.Request, readerID int64) string {
|
||||
token, _ := a.ReaderSessions.Issue(readerID)
|
||||
http.SetCookie(w, &http.Cookie{Name: auth.ReaderCookie, Value: token, Path: "/",
|
||||
HttpOnly: true, SameSite: http.SameSiteLaxMode, MaxAge: a.ReaderSessions.TTL()})
|
||||
return a.loginBack(w, r)
|
||||
}
|
||||
|
||||
// loginBack 决定登录完跳回哪儿:优先回发起登录的前台 origin
|
||||
// (开发时前端 :3000、后端 :8080 分离,只有它才不会跳错站),
|
||||
// 没有记录(直接敲 URL 进来的)就回站点根。
|
||||
func (a *API) loginBack(w http.ResponseWriter, r *http.Request) string {
|
||||
back := a.Cfg.SiteURL
|
||||
if ck, err := r.Cookie(oauthBackCook); err == nil && ck.Value != "" {
|
||||
if u, err := url.Parse(ck.Value); err == nil && (u.Scheme == "http" || u.Scheme == "https") && u.Host != "" && u.Path == "" {
|
||||
back = u.Scheme + "://" + u.Host
|
||||
}
|
||||
}
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBackCook, Value: "", Path: "/", MaxAge: -1})
|
||||
return back
|
||||
}
|
||||
|
||||
// issueAdminSession 让已绑定的第三方身份直接换发后台会话 —— 「绑定即提权」
|
||||
// 的落点。Secure / SameSite 与密码登录发的 cookie 完全一致,否则 HTTPS 下
|
||||
// 浏览器会把它当不安全 cookie 丢掉。
|
||||
func (a *API) issueAdminSession(w http.ResponseWriter, r *http.Request) {
|
||||
token, exp := a.AdminSessions.Issue(a.Cfg.AdminUser)
|
||||
http.SetCookie(w, &http.Cookie{
|
||||
Name: adminCookieName, Value: token, Path: "/", HttpOnly: true,
|
||||
Secure: isTLS(r), SameSite: http.SameSiteLaxMode,
|
||||
Expires: exp, MaxAge: a.AdminSessions.TTL(),
|
||||
})
|
||||
}
|
||||
|
||||
// isTLS 判断最终用户看到的是不是 HTTPS(含反代 X-Forwarded-Proto)。
|
||||
// admin 包有一份同名私有函数:两边各自独立,不为三行代码造共享包。
|
||||
func isTLS(r *http.Request) bool {
|
||||
if r.TLS != nil {
|
||||
return true
|
||||
}
|
||||
return r.Header.Get("X-Forwarded-Proto") == "https"
|
||||
}
|
||||
|
||||
// ---------- passkey 登录(公开) ----------
|
||||
|
||||
// passkeyBegin 发起一次发现式登录:不预先要用户名,凭据自己带出身份。
|
||||
func (a *API) passkeyBegin(w http.ResponseWriter, r *http.Request) {
|
||||
if a.Passkeys == nil {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
if a.passkeyFails.Blocked(ratelimit.SourceKey(r)) {
|
||||
httpx.Error(w, http.StatusTooManyRequests, "尝试次数过多,请稍后再试")
|
||||
return
|
||||
}
|
||||
options, token, err := a.Passkeys.BeginLogin()
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"options": options, "token": token})
|
||||
}
|
||||
|
||||
// passkeyFinish 校验断言。命中站主发后台会话,命中读者发读者会话。
|
||||
func (a *API) passkeyFinish(w http.ResponseWriter, r *http.Request) {
|
||||
if a.Passkeys == nil {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
var in struct {
|
||||
Token string `json:"token"`
|
||||
Credential json.RawMessage `json:"credential"`
|
||||
}
|
||||
if err := httpx.Decode(r, &in); err != nil || in.Token == "" || len(in.Credential) == 0 {
|
||||
httpx.BadRequest(w, "token 与 credential 都要传")
|
||||
return
|
||||
}
|
||||
ip := ratelimit.SourceKey(r)
|
||||
if a.passkeyFails.Blocked(ip) {
|
||||
httpx.Error(w, http.StatusTooManyRequests, "尝试次数过多,请稍后再试")
|
||||
return
|
||||
}
|
||||
res, err := a.Passkeys.FinishLogin(in.Token, in.Credential, func(credID string) (model.Passkey, error) {
|
||||
return a.Store.GetPasskeyByCredentialID(credID)
|
||||
})
|
||||
if err != nil {
|
||||
a.passkeyFails.Add(ip)
|
||||
httpx.Error(w, http.StatusUnauthorized, "passkey 校验失败")
|
||||
return
|
||||
}
|
||||
pk, err := a.Store.GetPasskeyByCredentialID(res.CredentialID)
|
||||
if err != nil {
|
||||
a.passkeyFails.Add(ip)
|
||||
httpx.Unauthorized(w)
|
||||
return
|
||||
}
|
||||
if err := a.Store.TouchPasskey(pk.ID, res.SignCount); err != nil {
|
||||
// 计数回写失败不该挡住已验签成功的登录,但要留痕:
|
||||
// 丢了计数就等于丢了克隆检测能力。
|
||||
log.Printf("passkey: 回写签名计数失败 (id=%d): %v", pk.ID, err)
|
||||
}
|
||||
if res.CloneWarning {
|
||||
log.Printf("passkey: 凭据 %q 签名计数回退,可能被克隆或多设备同步", pk.Name)
|
||||
}
|
||||
u, err := a.Store.GetReader(pk.UserID)
|
||||
if err != nil {
|
||||
httpx.Unauthorized(w)
|
||||
return
|
||||
}
|
||||
if u.Role == model.RoleOwner {
|
||||
a.issueAdminSession(w, r)
|
||||
httpx.OK(w, map[string]any{"ok": true, "role": u.Role})
|
||||
return
|
||||
}
|
||||
a.issueReaderSession(w, r, u.ID)
|
||||
httpx.OK(w, map[string]any{"ok": true, "role": u.Role})
|
||||
}
|
||||
@@ -0,0 +1,187 @@
|
||||
package api
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"net/http"
|
||||
"net/http/httptest"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"oneblog/internal/auth"
|
||||
"oneblog/internal/config"
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
// fakeAdmin 满足 API.AdminSessions 接口。不 import admin 包 ——
|
||||
// 两个 API 之间不该为了测试互相依赖。
|
||||
type fakeAdmin struct{ valid map[string]bool }
|
||||
|
||||
func (f fakeAdmin) Verify(token string) (string, error) {
|
||||
if f.valid[token] {
|
||||
return "admin", nil
|
||||
}
|
||||
return "", errors.New("bad session")
|
||||
}
|
||||
func (f fakeAdmin) Issue(string) (string, time.Time) {
|
||||
return "issued-admin-token", time.Now().Add(time.Hour)
|
||||
}
|
||||
func (f fakeAdmin) TTL() int { return 3600 }
|
||||
|
||||
func newAccountAPI(t *testing.T) (*API, http.Handler) {
|
||||
t.Helper()
|
||||
a, h := newTestAPI(t)
|
||||
a.Cfg = &config.Config{SiteURL: "http://localhost:8080", AdminUser: "admin"}
|
||||
a.AdminSessions = fakeAdmin{valid: map[string]bool{"good-session": true}}
|
||||
a.GH = auth.GitHub{ClientID: "id", ClientSecret: "sec"}
|
||||
return a, h
|
||||
}
|
||||
|
||||
// 绑定动作必须已登录后台 —— 否则任何人都能往别人账号上塞身份
|
||||
func TestBindRequiresAdminSession(t *testing.T) {
|
||||
_, h := newAccountAPI(t)
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, "/api/auth/github/bind", nil))
|
||||
if rec.Code != http.StatusUnauthorized {
|
||||
t.Fatalf("无会话绑定: got %d, want 401", rec.Code)
|
||||
}
|
||||
}
|
||||
|
||||
func TestBindWithAdminSessionLinksAndRedirects(t *testing.T) {
|
||||
a, h := newAccountAPI(t)
|
||||
owner, err := a.Store.EnsureOwner("admin")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
back := a.Cfg.SiteURL + "/admin/account"
|
||||
req := httptest.NewRequest(http.MethodGet, "/api/auth/github/bind", nil)
|
||||
req.AddCookie(&http.Cookie{Name: "one_session", Value: "good-session"})
|
||||
req.AddCookie(&http.Cookie{Name: oauthBackCook, Value: back})
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, req)
|
||||
|
||||
if rec.Code != http.StatusFound {
|
||||
t.Fatalf("got %d %s, want 302 跳 GitHub", rec.Code, rec.Body.String())
|
||||
}
|
||||
loc := rec.Header().Get("Location")
|
||||
if !strings.HasPrefix(loc, "https://github.com/login/oauth/authorize") {
|
||||
t.Fatalf("没跳授权页: %s", loc)
|
||||
}
|
||||
// 绑定意图必须落到一次性 cookie 上
|
||||
var sawBind bool
|
||||
for _, ck := range rec.Result().Cookies() {
|
||||
if ck.Name == oauthBindCook && ck.Value == "1" {
|
||||
sawBind = true
|
||||
}
|
||||
}
|
||||
if !sawBind {
|
||||
t.Fatal("绑定 cookie 没设上,回调时无从判断意图")
|
||||
}
|
||||
_ = owner
|
||||
}
|
||||
|
||||
// 回调命中「已绑定给站主」的身份 → 必须发后台会话,而不是读者会话
|
||||
func TestBoundOwnerIdentityGrantsAdminSession(t *testing.T) {
|
||||
a, _ := newAccountAPI(t)
|
||||
owner, err := a.Store.EnsureOwner("admin")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := a.Store.BindIdentity(owner.ID, "github", "4242", "littleckin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
req := httptest.NewRequest(http.MethodPost, "/api/auth/callback/github", strings.NewReader("code=x&state=y"))
|
||||
req.Header.Set("Content-Type", "application/x-www-form-urlencoded")
|
||||
rec := httptest.NewRecorder()
|
||||
// 直接测分流函数:绕开真 GitHub
|
||||
back := a.afterIdentity(rec, req, "github", "4242", "littleckin",
|
||||
model.Reader{Provider: "github", Handle: "littleckin", Name: "n"})
|
||||
if back != "" {
|
||||
t.Fatalf("站主命中绑定应自己收尾(不发跳),got back=%q", back)
|
||||
}
|
||||
var admin, reader bool
|
||||
for _, ck := range rec.Result().Cookies() {
|
||||
switch ck.Name {
|
||||
case "one_session":
|
||||
admin = ck.Value == "issued-admin-token"
|
||||
case auth.ReaderCookie:
|
||||
reader = true
|
||||
}
|
||||
}
|
||||
if !admin {
|
||||
t.Fatal("没发后台会话")
|
||||
}
|
||||
if reader {
|
||||
t.Fatal("站主登录不该只拿到读者会话")
|
||||
}
|
||||
}
|
||||
|
||||
// 陌生身份(没绑定)走老路:建读者档案 + 发读者会话 + 回跳
|
||||
func TestUnknownIdentityFallsBackToReader(t *testing.T) {
|
||||
a, _ := newAccountAPI(t)
|
||||
if _, err := a.Store.EnsureOwner("admin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
req := httptest.NewRequest(http.MethodGet, "/x", nil)
|
||||
req.AddCookie(&http.Cookie{Name: oauthBackCook, Value: "http://localhost:3000"})
|
||||
rec := httptest.NewRecorder()
|
||||
back := a.afterIdentity(rec, req, "github", "999", "stranger",
|
||||
model.Reader{Provider: "github", Handle: "stranger", Name: "Stranger"})
|
||||
if back != "http://localhost:3000" {
|
||||
t.Fatalf("回跳地址不对: %q", back)
|
||||
}
|
||||
var reader bool
|
||||
for _, ck := range rec.Result().Cookies() {
|
||||
if ck.Name == auth.ReaderCookie && ck.Value != "" {
|
||||
reader = true
|
||||
}
|
||||
if ck.Name == "one_session" {
|
||||
t.Fatal("陌生身份拿到了后台会话")
|
||||
}
|
||||
}
|
||||
if !reader {
|
||||
t.Fatal("没发读者会话")
|
||||
}
|
||||
}
|
||||
|
||||
// 已被别人绑走的外部账号,不能再绑给站主
|
||||
func TestBindConflictReturns409(t *testing.T) {
|
||||
a, _ := newAccountAPI(t)
|
||||
owner, _ := a.Store.EnsureOwner("admin")
|
||||
other, err := a.Store.UpsertReader(model.Reader{Provider: "github", Handle: "real-owner", Name: "x"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := a.Store.BindIdentity(other.ID, "github", "4242", "real-owner"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
req := httptest.NewRequest(http.MethodGet, "/x", nil)
|
||||
req.AddCookie(&http.Cookie{Name: oauthBindCook, Value: "1"})
|
||||
rec := httptest.NewRecorder()
|
||||
a.afterIdentity(rec, req, "github", "4242", "hijack",
|
||||
model.Reader{Provider: "github", Handle: "hijack", Name: "h"})
|
||||
if rec.Code != http.StatusConflict {
|
||||
t.Fatalf("got %d, want 409", rec.Code)
|
||||
}
|
||||
// 确认没被抢走
|
||||
got, err := a.Store.GetUserByIdentity("github", "4242")
|
||||
if err != nil || got.ID != other.ID {
|
||||
t.Fatalf("身份归属被改动: %+v err=%v", got, err)
|
||||
}
|
||||
_ = owner
|
||||
}
|
||||
|
||||
// passkey 未启用时公开端点要 404,不能 500
|
||||
func TestPasskeyEndpointsAbsentWhenDisabled(t *testing.T) {
|
||||
a, h := newAccountAPI(t)
|
||||
if a.Passkeys != nil {
|
||||
t.Skip("Passkeys 应未装配")
|
||||
}
|
||||
for _, p := range []string{"/api/auth/passkey/begin", "/api/auth/passkey/finish"} {
|
||||
rec := httptest.NewRecorder()
|
||||
h.ServeHTTP(rec, httptest.NewRequest(http.MethodPost, p, strings.NewReader("{}")))
|
||||
if rec.Code != http.StatusNotFound {
|
||||
t.Errorf("%s: got %d, want 404", p, rec.Code)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -18,6 +18,7 @@ import (
|
||||
"oneblog/internal/hub"
|
||||
"oneblog/internal/model"
|
||||
"oneblog/internal/ratelimit"
|
||||
"oneblog/internal/render"
|
||||
"oneblog/internal/storage"
|
||||
"oneblog/internal/store"
|
||||
"oneblog/internal/thumbs"
|
||||
@@ -33,14 +34,23 @@ type API struct {
|
||||
// 评论区读者会话与 GitHub OAuth(main.go 装配)
|
||||
ReaderSessions *auth.ReaderSessions
|
||||
GH auth.GitHub
|
||||
// AdminSessions 是后台管理员会话验证器(admin.Sessions 满足它)。
|
||||
// 管理员登录后台后无需再走读者登录即可用站主身份评论。
|
||||
// AdminSessions 是后台管理员会话(admin.Sessions 满足它)。
|
||||
// 前台访客登录时命中「已绑定给站主」的身份就靠它发后台会话,
|
||||
// 所以除了 Verify 还要 Issue/TTL。
|
||||
AdminSessions interface {
|
||||
Verify(token string) (string, error)
|
||||
Issue(user string) (string, time.Time)
|
||||
TTL() int
|
||||
}
|
||||
// 其余登录方式(main.go 装配,未配置的自动不开放)
|
||||
GG auth.Google
|
||||
TG auth.Telegram
|
||||
// Passkeys 是 WebAuthn 服务(main.go 装配;nil 表示未启用,路由不开放)
|
||||
Passkeys *auth.Passkeys
|
||||
|
||||
// passkeyFails 按 IP 限失败次数:passkey 登录是公开端点,
|
||||
// 虽然伪造断言过不了验签,但不该让人无限次试。
|
||||
passkeyFails *ratelimit.Window
|
||||
// Hub 是评论变更的进程内广播(SSE 用;与后台 admin 共享同一实例)
|
||||
Hub *hub.Hub
|
||||
|
||||
@@ -63,6 +73,9 @@ func (a *API) Routes() http.Handler {
|
||||
a.authFails = ratelimit.New(maxAuthFails, authFailWindow)
|
||||
a.commentNew = ratelimit.New(maxComments, commentWindow)
|
||||
}
|
||||
if a.passkeyFails == nil {
|
||||
a.passkeyFails = ratelimit.New(maxAuthFails, authFailWindow)
|
||||
}
|
||||
mux := http.NewServeMux()
|
||||
mux.HandleFunc("/api/health", func(w http.ResponseWriter, r *http.Request) {
|
||||
if err := a.Store.Ping(r.Context()); err != nil {
|
||||
@@ -80,6 +93,11 @@ func (a *API) Routes() http.Handler {
|
||||
mux.HandleFunc("/api/auth/google/login", a.googleLogin)
|
||||
mux.HandleFunc("/api/auth/callback/google", a.googleCallback)
|
||||
mux.HandleFunc("/api/auth/telegram", a.telegramAuth)
|
||||
// 第三方身份绑定(需已登录后台)与 passkey 登录
|
||||
mux.HandleFunc("/api/auth/github/bind", a.beginBind)
|
||||
mux.HandleFunc("/api/auth/google/bind", a.beginBind)
|
||||
mux.HandleFunc("/api/auth/passkey/begin", a.passkeyBegin)
|
||||
mux.HandleFunc("/api/auth/passkey/finish", a.passkeyFinish)
|
||||
mux.HandleFunc("/api/comments", a.comments)
|
||||
mux.HandleFunc("/api/comments/stream", a.commentsStream)
|
||||
mux.HandleFunc("/api/comments/", a.commentSub)
|
||||
@@ -107,10 +125,25 @@ func (a *API) site(w http.ResponseWriter, r *http.Request) {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
st.AuthorAvatarURL = a.avatarURL(st.AuthorAvatarKey)
|
||||
// uploads_public_base 告诉前端哪些图片直链是自己的存储(可转 /uploads/thumb/ 缩略图)
|
||||
httpx.OK(w, map[string]any{"settings": st, "uploads_public_base": a.Cfg.UploadsPublicBase})
|
||||
}
|
||||
|
||||
// avatarURL 把 settings 里的头像 key 解析成可访问 URL。
|
||||
// key 指向的文件已被删除时返回空串 —— 前台据此回落到站标,
|
||||
// 而不是留一个打不开的裂图。
|
||||
func (a *API) avatarURL(key string) string {
|
||||
if key == "" {
|
||||
return ""
|
||||
}
|
||||
f, err := a.Store.GetFileByKey(key)
|
||||
if err != nil {
|
||||
return ""
|
||||
}
|
||||
return storage.FileURL(f.Store, f.Key, a.Cfg.UploadsPublicBase)
|
||||
}
|
||||
|
||||
func listOptions(r *http.Request, defSize int) store.ListOptions {
|
||||
return store.ListOptions{
|
||||
Kind: httpx.QueryString(r, "kind"),
|
||||
@@ -128,6 +161,12 @@ func (a *API) listPosts(w http.ResponseWriter, r *http.Request) {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
// 时间线上短文直接铺正文:出口处做盘古之白(库里存的是原始渲染结果)
|
||||
for i := range page.Items {
|
||||
if page.Items[i].Kind == model.KindShort {
|
||||
page.Items[i].ContentHTML = render.PanguHTML(page.Items[i].ContentHTML)
|
||||
}
|
||||
}
|
||||
httpx.OK(w, page)
|
||||
}
|
||||
|
||||
@@ -156,6 +195,8 @@ func (a *API) getPost(w http.ResponseWriter, r *http.Request) {
|
||||
if err != nil {
|
||||
nb = nil
|
||||
}
|
||||
// 详情正文出口做盘古之白(存库不动,改的是渲染层)
|
||||
p.ContentHTML = render.PanguHTML(p.ContentHTML)
|
||||
httpx.OK(w, struct {
|
||||
model.Post
|
||||
Neighbors []model.Post `json:"neighbors"`
|
||||
@@ -255,7 +296,7 @@ func (a *API) RSS(w http.ResponseWriter, r *http.Request) {
|
||||
}
|
||||
desc := p.Summary
|
||||
if desc == "" {
|
||||
desc = trimRunes(stripTags(p.ContentHTML), 160)
|
||||
desc = trimRunes(stripTags(render.PanguHTML(p.ContentHTML)), 160)
|
||||
}
|
||||
item := rssItem{
|
||||
Title: title,
|
||||
|
||||
@@ -10,7 +10,6 @@ import (
|
||||
"encoding/hex"
|
||||
"errors"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"strconv"
|
||||
"strings"
|
||||
"time"
|
||||
@@ -94,29 +93,19 @@ func (a *API) authLogout(w http.ResponseWriter, r *http.Request) {
|
||||
httpx.OK(w, map[string]any{"ok": true})
|
||||
}
|
||||
|
||||
// githubLogin 跳转 GitHub 授权页。state 防 CSRF 存短命 cookie;
|
||||
// 授权完成回到 callback 后必须带上同一个值。
|
||||
// 同时把发起登录的前台 origin 记下来(one_oauth_back),
|
||||
// callback 用它跳回去——开发时前端 3000 / 后端 8080 分离才不会落错站。
|
||||
// githubLogin 跳转 GitHub 授权页。state / 回跳地址的处理抽到 startOAuth,
|
||||
// 与「绑定」入口共用同一套跳转(bind 只是多打一个一次性 cookie)。
|
||||
func (a *API) githubLogin(w http.ResponseWriter, r *http.Request) {
|
||||
if !a.GH.Enabled() {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
state := randHex(16)
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthStateCook, Value: state, Path: "/",
|
||||
HttpOnly: true, MaxAge: 600})
|
||||
if ref := r.Referer(); ref != "" {
|
||||
if u, err := url.Parse(ref); err == nil && u.Scheme != "" && u.Host != "" {
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBackCook,
|
||||
Value: u.Scheme + "://" + u.Host, Path: "/", HttpOnly: true, MaxAge: 600})
|
||||
}
|
||||
}
|
||||
http.Redirect(w, r, a.GH.LoginURL(a.Cfg.SiteURL+"/api/auth/callback/github", state), http.StatusFound)
|
||||
a.startOAuth(w, r, func(state string) string {
|
||||
return a.GH.LoginURL(a.Cfg.SiteURL+"/api/auth/callback/github", state)
|
||||
})
|
||||
}
|
||||
|
||||
// githubCallback 用 code 换身份:GitHub 用户 → upsert 读者 → 发会话 →
|
||||
// 回到首页。
|
||||
// githubCallback 用 code 换身份,交给统一分流(绑定 / 已绑账号 / 新读者)。
|
||||
func (a *API) githubCallback(w http.ResponseWriter, r *http.Request) {
|
||||
if !a.GH.Enabled() {
|
||||
httpx.NotFound(w)
|
||||
@@ -145,19 +134,27 @@ func (a *API) githubCallback(w http.ResponseWriter, r *http.Request) {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
if u.Login == "" {
|
||||
a.authFails.Add(ip)
|
||||
httpx.ServerError(w, errors.New("github 未返回用户名"))
|
||||
return
|
||||
}
|
||||
name := u.Name
|
||||
if name == "" {
|
||||
name = u.Login
|
||||
}
|
||||
reader, err := a.Store.UpsertReader(model.Reader{
|
||||
persona := model.Reader{
|
||||
Provider: "github", Handle: u.Login, Name: name,
|
||||
AvatarURL: u.AvatarURL, URL: u.HTMLURL,
|
||||
})
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
http.Redirect(w, r, a.issueReaderCookie(w, r, reader.ID), http.StatusFound)
|
||||
// 稳定 id 才是绑定键;老接口没返回 id 时退化为按 handle 认人
|
||||
extern := strconv.FormatInt(u.ID, 10)
|
||||
if u.ID == 0 {
|
||||
extern = ""
|
||||
}
|
||||
if back := a.afterIdentity(w, r, "github", extern, u.Login, persona); back != "" {
|
||||
http.Redirect(w, r, back, http.StatusFound)
|
||||
}
|
||||
}
|
||||
|
||||
func randHex(n int) string {
|
||||
|
||||
@@ -5,16 +5,16 @@ package api
|
||||
|
||||
import (
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/url"
|
||||
"strconv"
|
||||
"time"
|
||||
|
||||
"oneblog/internal/auth"
|
||||
"oneblog/internal/httpx"
|
||||
"oneblog/internal/model"
|
||||
"oneblog/internal/ratelimit"
|
||||
"oneblog/internal/store"
|
||||
)
|
||||
|
||||
// authProviders 列出已配置的登录方式。
|
||||
@@ -40,41 +40,18 @@ func (a *API) authProviders(w http.ResponseWriter, r *http.Request) {
|
||||
httpx.OK(w, map[string]any{"providers": providers})
|
||||
}
|
||||
|
||||
// issueReaderCookie 登录成功后的公共收尾:发读者会话 + 决定跳回去的地址
|
||||
func (a *API) issueReaderCookie(w http.ResponseWriter, r *http.Request, readerID int64) string {
|
||||
token, _ := a.ReaderSessions.Issue(readerID)
|
||||
http.SetCookie(w, &http.Cookie{Name: auth.ReaderCookie, Value: token, Path: "/",
|
||||
HttpOnly: true, SameSite: http.SameSiteLaxMode, MaxAge: int((30 * 24 * time.Hour).Seconds())})
|
||||
// 回到发起登录的前台;没有记录(直接敲 URL 进来的)就回站点根
|
||||
back := a.Cfg.SiteURL
|
||||
if ck, err := r.Cookie(oauthBackCook); err == nil && ck.Value != "" {
|
||||
if u, err := url.Parse(ck.Value); err == nil && (u.Scheme == "http" || u.Scheme == "https") && u.Host != "" && u.Path == "" {
|
||||
back = u.Scheme + "://" + u.Host
|
||||
}
|
||||
}
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBackCook, Value: "", Path: "/", MaxAge: -1})
|
||||
return back
|
||||
}
|
||||
|
||||
// googleLogin 跳 Google 授权页(state 防 CSRF 同 GitHub)
|
||||
func (a *API) googleLogin(w http.ResponseWriter, r *http.Request) {
|
||||
if !a.GG.Enabled() {
|
||||
httpx.NotFound(w)
|
||||
return
|
||||
}
|
||||
state := randHex(16)
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthStateCook, Value: state, Path: "/",
|
||||
HttpOnly: true, MaxAge: 600})
|
||||
if ref := r.Referer(); ref != "" {
|
||||
if u, err := url.Parse(ref); err == nil && u.Scheme != "" && u.Host != "" {
|
||||
http.SetCookie(w, &http.Cookie{Name: oauthBackCook,
|
||||
Value: u.Scheme + "://" + u.Host, Path: "/", HttpOnly: true, MaxAge: 600})
|
||||
}
|
||||
}
|
||||
http.Redirect(w, r, a.GG.LoginURL(a.Cfg.SiteURL+"/api/auth/callback/google", state), http.StatusFound)
|
||||
a.startOAuth(w, r, func(state string) string {
|
||||
return a.GG.LoginURL(a.Cfg.SiteURL+"/api/auth/callback/google", state)
|
||||
})
|
||||
}
|
||||
|
||||
// googleCallback 用 code 换身份:Google 用户 → upsert 读者 → 发会话
|
||||
// googleCallback 用 code 换身份,交给统一分流(绑定 / 已绑账号 / 新读者)。
|
||||
func (a *API) googleCallback(w http.ResponseWriter, r *http.Request) {
|
||||
if !a.GG.Enabled() {
|
||||
httpx.NotFound(w)
|
||||
@@ -112,15 +89,12 @@ func (a *API) googleCallback(w http.ResponseWriter, r *http.Request) {
|
||||
if name == "" {
|
||||
name = handle
|
||||
}
|
||||
reader, err := a.Store.UpsertReader(model.Reader{
|
||||
Provider: "google", Handle: handle, Name: name,
|
||||
AvatarURL: u.Picture,
|
||||
})
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
persona := model.Reader{
|
||||
Provider: "google", Handle: handle, Name: name, AvatarURL: u.Picture,
|
||||
}
|
||||
if back := a.afterIdentity(w, r, "google", u.Sub, handle, persona); back != "" {
|
||||
http.Redirect(w, r, back, http.StatusFound)
|
||||
}
|
||||
http.Redirect(w, r, a.issueReaderCookie(w, r, reader.ID), http.StatusFound)
|
||||
}
|
||||
|
||||
// telegramAuth 校验 Login Widget 回传的签名资料并登录。
|
||||
@@ -164,6 +138,52 @@ func (a *API) telegramAuth(w http.ResponseWriter, r *http.Request) {
|
||||
// 没有公开 username 的用户用数字 id,保证 provider+handle 稳定唯一
|
||||
handle = strconv.FormatInt(in.IDInt(), 10)
|
||||
}
|
||||
externUID := strconv.FormatInt(in.IDInt(), 10)
|
||||
|
||||
// Telegram 是 XHR + JSON 响应(不是整页跳转),所以这里走与 afterIdentity
|
||||
// 同语义、但自己写响应的一份分流。
|
||||
if bindRequested(r) {
|
||||
if !a.adminSessionValid(r) {
|
||||
clearBindCookie(w)
|
||||
httpx.Unauthorized(w)
|
||||
return
|
||||
}
|
||||
owner, err := a.Store.EnsureOwner(a.Cfg.AdminUser)
|
||||
if err != nil {
|
||||
clearBindCookie(w)
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
err = a.Store.BindIdentity(owner.ID, "telegram", externUID, handle)
|
||||
clearBindCookie(w)
|
||||
if errors.Is(err, store.ErrConflict) {
|
||||
httpx.Error(w, http.StatusConflict, "该账号已绑定到其他用户")
|
||||
return
|
||||
}
|
||||
if err != nil {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
httpx.OK(w, map[string]any{"ok": true, "bound": "telegram"})
|
||||
return
|
||||
}
|
||||
clearBindCookie(w)
|
||||
|
||||
// 已绑定的身份优先:站主用绑定的 Telegram 登录要拿到后台会话
|
||||
if u, err := a.Store.GetUserByIdentity("telegram", externUID); err == nil {
|
||||
if u.Role == model.RoleOwner {
|
||||
a.issueAdminSession(w, r)
|
||||
httpx.OK(w, map[string]any{"ok": true, "role": u.Role})
|
||||
return
|
||||
}
|
||||
a.issueReaderSession(w, r, u.ID)
|
||||
httpx.OK(w, map[string]any{"ok": true, "role": u.Role})
|
||||
return
|
||||
} else if !errors.Is(err, store.ErrNotFound) {
|
||||
httpx.ServerError(w, err)
|
||||
return
|
||||
}
|
||||
|
||||
reader, err := a.Store.UpsertReader(model.Reader{
|
||||
Provider: "telegram", Handle: handle, Name: in.DisplayName(),
|
||||
AvatarURL: in.PhotoURL,
|
||||
@@ -174,13 +194,11 @@ func (a *API) telegramAuth(w http.ResponseWriter, r *http.Request) {
|
||||
return
|
||||
}
|
||||
// 会话同样落 httpOnly cookie,前端 POST 完刷新 /api/auth/me 即可见
|
||||
token, _ := a.ReaderSessions.Issue(reader.ID)
|
||||
http.SetCookie(w, &http.Cookie{Name: auth.ReaderCookie, Value: token, Path: "/",
|
||||
HttpOnly: true, SameSite: http.SameSiteLaxMode, MaxAge: int((30 * 24 * time.Hour).Seconds())})
|
||||
a.issueReaderSession(w, r, reader.ID)
|
||||
httpx.OK(w, map[string]any{"user": map[string]any{
|
||||
"id": reader.ID, "name": reader.Name, "handle": reader.Handle,
|
||||
"avatar_url": reader.AvatarURL, "url": reader.URL,
|
||||
"provider": reader.Provider, "is_owner": false, "banned": reader.Banned,
|
||||
"provider": reader.Provider, "is_owner": reader.Role == model.RoleOwner, "banned": reader.Banned,
|
||||
}})
|
||||
}
|
||||
|
||||
|
||||
@@ -43,6 +43,10 @@ func (s *ReaderSessions) Issue(readerID int64) (string, time.Time) {
|
||||
return enc + "." + s.sign(payload), exp
|
||||
}
|
||||
|
||||
// TTL 是会话秒数,供 cookie 的 MaxAge 用。
|
||||
// 之前两处硬编码 30*24h,改 ttl 时容易和 Issue 不同步。
|
||||
func (s *ReaderSessions) TTL() int { return int(s.ttl.Seconds()) }
|
||||
|
||||
func (s *ReaderSessions) Verify(token string) (int64, error) {
|
||||
parts := strings.Split(token, ".")
|
||||
if len(parts) != 2 {
|
||||
@@ -119,6 +123,9 @@ func (g GitHub) LoginURL(redirectURI, state string) string {
|
||||
|
||||
// GitHubUser 是 GitHub 用户接口里我们关心的字段
|
||||
type GitHubUser struct {
|
||||
// ID 是 GitHub 的数字主键:永不复用、改名不变。身份绑定必须用它,
|
||||
// 用 login 的话对方一改用户名,绑定就指向了另一个人。
|
||||
ID int64 `json:"id"`
|
||||
Login string `json:"login"`
|
||||
Name string `json:"name"`
|
||||
AvatarURL string `json:"avatar_url"`
|
||||
|
||||
@@ -0,0 +1,277 @@
|
||||
// Passkey(WebAuthn)封装。
|
||||
//
|
||||
// 两件事分开:注册必须在管理员会话之下发起(否则任何人都能往站主账号上塞凭据),
|
||||
// 登录是公开的、发现式的(不需要先输用户名,浏览器直接问系统要凭据)。
|
||||
//
|
||||
// challenge 与会话放进程内存而不是签名 cookie:单进程博客够用,重启只会让
|
||||
// 正在进行中的注册/登录作废(下次重点即可),不会留下可复用的状态。
|
||||
// 用完即删 —— challenge 是一次性的,留着就有重放面。
|
||||
package auth
|
||||
|
||||
import (
|
||||
"bytes"
|
||||
"crypto/rand"
|
||||
"encoding/base64"
|
||||
"encoding/hex"
|
||||
"encoding/json"
|
||||
"errors"
|
||||
"fmt"
|
||||
"strconv"
|
||||
"sync"
|
||||
"time"
|
||||
|
||||
"github.com/go-webauthn/webauthn/protocol"
|
||||
"github.com/go-webauthn/webauthn/webauthn"
|
||||
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
const sessionTTL = 5 * time.Minute
|
||||
|
||||
var ErrSessionExpired = errors.New("passkey session expired or already used")
|
||||
|
||||
type Passkeys struct {
|
||||
w *webauthn.WebAuthn
|
||||
|
||||
mu sync.Mutex
|
||||
sessions map[string]*pkSession
|
||||
}
|
||||
|
||||
type pkSession struct {
|
||||
data webauthn.SessionData
|
||||
userID int64 // 注册时=目标账号;登录时发现式则为 0
|
||||
exp time.Time
|
||||
}
|
||||
|
||||
// userAdapter 把我们的账号 + 凭据行喂给库的 webauthn.User 接口。
|
||||
type userAdapter struct {
|
||||
id int64
|
||||
name string
|
||||
disp string
|
||||
creds []webauthn.Credential
|
||||
}
|
||||
|
||||
func (u userAdapter) WebAuthnID() []byte { return []byte(strconv.FormatInt(u.id, 10)) }
|
||||
func (u userAdapter) WebAuthnName() string { return u.name }
|
||||
func (u userAdapter) WebAuthnDisplayName() string {
|
||||
if u.disp != "" {
|
||||
return u.disp
|
||||
}
|
||||
return u.name
|
||||
}
|
||||
func (u userAdapter) WebAuthnCredentials() []webauthn.Credential { return u.creds }
|
||||
|
||||
// NewPasskeys 构造一个 passkey 服务。rpID 是域名(不含 scheme/port),
|
||||
// origin 是完整来源(开发时是 http://localhost:3000,两者可以不同)。
|
||||
func NewPasskeys(displayName, rpID string, origins []string) (*Passkeys, error) {
|
||||
w, err := webauthn.New(&webauthn.Config{
|
||||
RPDisplayName: displayName,
|
||||
RPID: rpID,
|
||||
RPOrigins: origins,
|
||||
// 站内凭据不需要证明来源可信:attestation 一律 none,
|
||||
// 既避免解析各家认证报告的复杂度,也不把它当授权依据。
|
||||
AttestationPreference: protocol.PreferNoAttestation,
|
||||
AuthenticatorSelection: protocol.AuthenticatorSelection{
|
||||
UserVerification: protocol.VerificationRequired,
|
||||
// 可发现凭据:登录时不用先报用户名。
|
||||
ResidentKey: protocol.ResidentKeyRequirementRequired,
|
||||
},
|
||||
})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
return &Passkeys{w: w, sessions: make(map[string]*pkSession)}, nil
|
||||
}
|
||||
|
||||
func toCredentials(pks []model.Passkey) ([]webauthn.Credential, error) {
|
||||
out := make([]webauthn.Credential, 0, len(pks))
|
||||
for _, p := range pks {
|
||||
key, err := base64.StdEncoding.DecodeString(p.PublicKey)
|
||||
if err != nil {
|
||||
return nil, fmt.Errorf("passkey %d public key: %w", p.ID, err)
|
||||
}
|
||||
id, err := base64.StdEncoding.DecodeString(p.CredentialID)
|
||||
if err != nil {
|
||||
// 兼容:credential_id 也可能是原始字符串(非 base64)
|
||||
id = []byte(p.CredentialID)
|
||||
}
|
||||
out = append(out, webauthn.Credential{
|
||||
ID: id,
|
||||
PublicKey: key,
|
||||
Authenticator: webauthn.Authenticator{
|
||||
SignCount: p.SignCount,
|
||||
},
|
||||
})
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// BeginRegistration 发起注册。返回给前端的创建参数与一次性 token。
|
||||
func (p *Passkeys) BeginRegistration(userID int64, name, display string, existing []model.Passkey) (creationJSON json.RawMessage, token string, err error) {
|
||||
creds, err := toCredentials(existing)
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
u := userAdapter{id: userID, name: name, disp: display, creds: creds}
|
||||
// 已存在的凭据要排除,免得同一台设备被重复登记
|
||||
opts := []webauthn.RegistrationOption{}
|
||||
if len(creds) > 0 {
|
||||
exclude := make([]protocol.CredentialDescriptor, 0, len(creds))
|
||||
for _, c := range creds {
|
||||
exclude = append(exclude, protocol.CredentialDescriptor{
|
||||
Type: protocol.PublicKeyCredentialType,
|
||||
CredentialID: c.ID,
|
||||
})
|
||||
}
|
||||
opts = append(opts, webauthn.WithExclusions(exclude))
|
||||
}
|
||||
creation, session, err := p.w.BeginRegistration(u, opts...)
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
tok, err := randomToken()
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
p.put(tok, &pkSession{data: *session, userID: userID, exp: time.Now().Add(sessionTTL)})
|
||||
b, err := json.Marshal(creation)
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
return b, tok, nil
|
||||
}
|
||||
|
||||
// FinishRegistration 校验浏览器返回的凭据并交回要落库的字段。
|
||||
// credJSON 是 PublicKeyCredential 的 JSON —— challenge/token 走外层字段,
|
||||
// 凭据对象原样交给库解析(库自己校验 clientDataJSON.challenge 是否对得上)。
|
||||
func (p *Passkeys) FinishRegistration(token string, userID int64, name, display string, existing []model.Passkey, credJSON []byte) (model.Passkey, error) {
|
||||
sess, err := p.take(token, userID)
|
||||
if err != nil {
|
||||
return model.Passkey{}, err
|
||||
}
|
||||
creds, err := toCredentials(existing)
|
||||
if err != nil {
|
||||
return model.Passkey{}, err
|
||||
}
|
||||
u := userAdapter{id: userID, name: name, disp: display, creds: creds}
|
||||
parsed, err := protocol.ParseCredentialCreationResponseBody(bytes.NewReader(credJSON))
|
||||
if err != nil {
|
||||
return model.Passkey{}, err
|
||||
}
|
||||
cred, err := p.w.CreateCredential(u, *sess, parsed)
|
||||
if err != nil {
|
||||
return model.Passkey{}, err
|
||||
}
|
||||
return model.Passkey{
|
||||
UserID: userID,
|
||||
CredentialID: base64.StdEncoding.EncodeToString(cred.ID),
|
||||
PublicKey: base64.StdEncoding.EncodeToString(cred.PublicKey),
|
||||
SignCount: cred.Authenticator.SignCount,
|
||||
}, nil
|
||||
}
|
||||
|
||||
// BeginLogin 发起发现式登录(不预先指定账号,由凭据自己带出身份)。
|
||||
func (p *Passkeys) BeginLogin() (assertionJSON json.RawMessage, token string, err error) {
|
||||
assertion, session, err := p.w.BeginDiscoverableLogin()
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
tok, err := randomToken()
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
p.put(tok, &pkSession{data: *session, exp: time.Now().Add(sessionTTL)})
|
||||
b, err := json.Marshal(assertion)
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
return b, tok, nil
|
||||
}
|
||||
|
||||
// LoginResult 是一次 passkey 登录的结果。
|
||||
// CloneWarning 透传库的判定:新计数 ≤ 已存计数时库认为凭据可能被克隆。
|
||||
// 这里只上报不拦 —— 云同步的 passkey(iCloud Keychain 等)计数本就不单调,
|
||||
// 硬拦会把合法用户挡在门外;但它是必须让站主看得见的信号。
|
||||
type LoginResult struct {
|
||||
CredentialID string // base64,交给 resolver 时用的同一个键
|
||||
UserID int64
|
||||
SignCount uint32
|
||||
CloneWarning bool
|
||||
}
|
||||
|
||||
// FinishLogin 完成登录:resolver 按 credential id 反查凭据(含所属账号),
|
||||
// 验签通过后返回该凭据与新计数,调用方据此决定发哪种会话。
|
||||
// credJSON 同 FinishRegistration,是客户端原样回传的 PublicKeyCredential JSON。
|
||||
func (p *Passkeys) FinishLogin(token string, credJSON []byte, resolve func(credentialIDB64 string) (model.Passkey, error)) (LoginResult, error) {
|
||||
var out LoginResult
|
||||
sess, err := p.take(token, 0)
|
||||
if err != nil {
|
||||
return out, err
|
||||
}
|
||||
handler := func(rawID, userHandle []byte) (webauthn.User, error) {
|
||||
pk, err := resolve(base64.StdEncoding.EncodeToString(rawID))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
creds, err := toCredentials([]model.Passkey{pk})
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out.CredentialID = pk.CredentialID
|
||||
out.UserID = pk.UserID
|
||||
// 名字只用于日志/报错,登录路径不展示
|
||||
return userAdapter{id: pk.UserID, name: strconv.FormatInt(pk.UserID, 10), creds: creds}, nil
|
||||
}
|
||||
parsed, err := protocol.ParseCredentialRequestResponseBytes(credJSON)
|
||||
if err != nil {
|
||||
return out, err
|
||||
}
|
||||
cred, err := p.w.ValidateDiscoverableLogin(handler, *sess, parsed)
|
||||
if err != nil {
|
||||
return out, err
|
||||
}
|
||||
out.SignCount = cred.Authenticator.SignCount
|
||||
out.CloneWarning = cred.Authenticator.CloneWarning
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// put 存会话并顺手清掉过期的:map 只在这几个流程里活几分钟,
|
||||
// 清扫是防泄漏而不是防攻击。
|
||||
func (p *Passkeys) put(token string, s *pkSession) {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
now := time.Now()
|
||||
for k, v := range p.sessions {
|
||||
if v.exp.Before(now) {
|
||||
delete(p.sessions, k)
|
||||
}
|
||||
}
|
||||
p.sessions[token] = s
|
||||
}
|
||||
|
||||
// take 取出并删除会话(一次性),并核对发起时的账号。
|
||||
func (p *Passkeys) take(token string, userID int64) (*webauthn.SessionData, error) {
|
||||
p.mu.Lock()
|
||||
defer p.mu.Unlock()
|
||||
s, ok := p.sessions[token]
|
||||
if !ok {
|
||||
return nil, ErrSessionExpired
|
||||
}
|
||||
delete(p.sessions, token)
|
||||
if time.Now().After(s.exp) {
|
||||
return nil, ErrSessionExpired
|
||||
}
|
||||
// 注册会话绑账号:不能拿自己发起的 challenge 去给别人的账号注册
|
||||
if userID != 0 && s.userID != userID {
|
||||
return nil, ErrSessionExpired
|
||||
}
|
||||
return &s.data, nil
|
||||
}
|
||||
|
||||
func randomToken() (string, error) {
|
||||
b := make([]byte, 16)
|
||||
if _, err := rand.Read(b); err != nil {
|
||||
return "", err
|
||||
}
|
||||
return hex.EncodeToString(b), nil
|
||||
}
|
||||
@@ -4,6 +4,7 @@ import (
|
||||
"crypto/rand"
|
||||
"encoding/hex"
|
||||
"log"
|
||||
"net/url"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"strings"
|
||||
@@ -34,6 +35,14 @@ type Config struct {
|
||||
TelegramBot string
|
||||
TelegramToken string
|
||||
|
||||
// Passkey(WebAuthn)。RPID 是域名(不含端口),Origins 是允许的完整来源。
|
||||
// 必须显式配 ONE_WEBAUTHN_ORIGINS 才启用(它是发放永久登录凭据的功能);
|
||||
// 启用后 RPID 默认取 SiteURL 的主机名,Origin 列表会自动并入 SiteURL 本身。
|
||||
// 开发时前端在 :3000、后端在 :8080,所以要把两个来源都写上:
|
||||
// ONE_WEBAUTHN_ORIGINS=http://localhost:3000,http://localhost:8080
|
||||
WebauthnRPID string // env: ONE_WEBAUTHN_RP_ID
|
||||
WebauthnOrigins []string // env: ONE_WEBAUTHN_ORIGINS(空 = 不启用)
|
||||
|
||||
// 对象存储(文件上传)。变量名与站主 .env 里的写法一致(站主已整理):
|
||||
// S3Api = R2 的 S3 API 端点(https://<账户ID>.r2.cloudflarestorage.com,
|
||||
// 控制台 R2 概览可复制),上传走它 —— 公开域名收不了上传请求
|
||||
@@ -143,9 +152,50 @@ func Load() (*Config, error) {
|
||||
c.TelegramBot = getenv("ONE_TELEGRAM_BOT", "")
|
||||
c.TelegramToken = getenv("ONE_TELEGRAM_BOT_TOKEN", "")
|
||||
|
||||
// Passkey:默认跟着 SiteURL,显式配了 ONE_WEBAUTHN_ORIGINS 才算启用
|
||||
// (没配就不注册相关路由,也不给前端暴露入口)。
|
||||
c.WebauthnRPID, c.WebauthnOrigins = webauthnFromSite(c.SiteURL, getenv("ONE_WEBAUTHN_RP_ID", ""), getenv("ONE_WEBAUTHN_ORIGINS", ""))
|
||||
|
||||
return c, nil
|
||||
}
|
||||
|
||||
// webauthnFromSite 推导 RPID 与允许的 Origin 列表。
|
||||
// 只有显式配了 ONE_WEBAUTHN_ORIGINS 才返回非空列表 —— 没配就视为不启用
|
||||
// (返回 nil,调用方跳过构造)。这是个发放永久登录凭据的功能,
|
||||
// 默认关闭比默认开启安全;SiteURL 推导出的 origin 只在启用后作为额外来源。
|
||||
func webauthnFromSite(siteURL, rpID, origins string) (string, []string) {
|
||||
list := []string{}
|
||||
for _, o := range strings.Split(origins, ",") {
|
||||
if o = strings.TrimRight(strings.TrimSpace(o), "/"); o != "" {
|
||||
list = append(list, o)
|
||||
}
|
||||
}
|
||||
if u, err := url.Parse(strings.TrimRight(siteURL, "/")); err == nil && u.Host != "" {
|
||||
if rpID == "" {
|
||||
rpID = u.Hostname() // Hostname() 会去掉端口
|
||||
}
|
||||
}
|
||||
if len(list) == 0 {
|
||||
return "", nil // 未启用:RPID 一并清空,免得调用方误判成可用
|
||||
}
|
||||
// 启用后把站点自身来源也加上(生产环境页面就来自这里)
|
||||
if u, err := url.Parse(strings.TrimRight(siteURL, "/")); err == nil && u.Host != "" {
|
||||
if origin := u.Scheme + "://" + u.Host; !containsStr(list, origin) {
|
||||
list = append(list, origin)
|
||||
}
|
||||
}
|
||||
return rpID, list
|
||||
}
|
||||
|
||||
func containsStr(list []string, s string) bool {
|
||||
for _, v := range list {
|
||||
if strings.EqualFold(v, s) {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
type badDriver struct{ d string }
|
||||
|
||||
func (e *badDriver) Error() string {
|
||||
|
||||
@@ -18,6 +18,11 @@ func New() *Hub {
|
||||
// Subscribe 订阅某主题;返回信号 channel 和退订函数。
|
||||
// channel 容量 1:订阅者处理不过来时新信号直接丢弃(合并刷新)。
|
||||
func (h *Hub) Subscribe(topic int64) (<-chan struct{}, func()) {
|
||||
// nil hub(测试/未装配场景)静默降级:永远收不到信号的通道
|
||||
if h == nil {
|
||||
ch := make(chan struct{})
|
||||
return ch, func() {}
|
||||
}
|
||||
ch := make(chan struct{}, 1)
|
||||
h.mu.Lock()
|
||||
if h.subs[topic] == nil {
|
||||
@@ -38,6 +43,9 @@ func (h *Hub) Subscribe(topic int64) (<-chan struct{}, func()) {
|
||||
|
||||
// Broadcast 唤醒某主题的全部订阅者;积压的订阅者不阻塞。
|
||||
func (h *Hub) Broadcast(topic int64) {
|
||||
if h == nil {
|
||||
return
|
||||
}
|
||||
h.mu.Lock()
|
||||
defer h.mu.Unlock()
|
||||
for ch := range h.subs[topic] {
|
||||
|
||||
@@ -75,25 +75,7 @@ func (f *Fetcher) Fetch(ctx context.Context, rawURL string) (*Card, error) {
|
||||
return nil, errors.New("linkmeta: empty host")
|
||||
}
|
||||
|
||||
dial := f.Dial
|
||||
if dial == nil {
|
||||
dial = safeDial
|
||||
}
|
||||
timeout := f.Timeout
|
||||
if timeout <= 0 {
|
||||
timeout = 5 * time.Second
|
||||
}
|
||||
client := &http.Client{
|
||||
Transport: &http.Transport{
|
||||
DialContext: dial,
|
||||
TLSHandshakeTimeout: 3 * time.Second,
|
||||
// 每个跳转目标都过一遍 dial(transport 会复用),无需额外校验
|
||||
ForceAttemptHTTP2: false,
|
||||
},
|
||||
Timeout: timeout,
|
||||
CheckRedirect: limitRedirects,
|
||||
}
|
||||
|
||||
client := f.client()
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, u.String(), nil)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
@@ -125,6 +107,78 @@ func (f *Fetcher) Fetch(ctx context.Context, rawURL string) (*Card, error) {
|
||||
return card, nil
|
||||
}
|
||||
|
||||
// client 组装带 SSRF 防护的 HTTP 客户端(Fetch 与 FetchBytes 共用)
|
||||
func (f *Fetcher) client() *http.Client {
|
||||
dial := f.Dial
|
||||
if dial == nil {
|
||||
dial = safeDial
|
||||
}
|
||||
timeout := f.Timeout
|
||||
if timeout <= 0 {
|
||||
timeout = 5 * time.Second
|
||||
}
|
||||
return &http.Client{
|
||||
Transport: &http.Transport{
|
||||
DialContext: dial,
|
||||
TLSHandshakeTimeout: 3 * time.Second,
|
||||
// 每个跳转目标都过一遍 dial(transport 会复用),无需额外校验
|
||||
ForceAttemptHTTP2: false,
|
||||
},
|
||||
Timeout: timeout,
|
||||
CheckRedirect: limitRedirects,
|
||||
}
|
||||
}
|
||||
|
||||
// FetchBytes 抓二进制内容(外链图片转存用):与 Fetch 共用同一套
|
||||
// SSRF 防护与跳转限制,字节数有 maxBytes 硬上限。
|
||||
// 返回内容与 Content-Type(响应头缺失时用内容嗅探兜底)。
|
||||
func FetchBytes(ctx context.Context, rawURL string, maxBytes int64) ([]byte, string, error) {
|
||||
return (&Fetcher{}).fetchBytes(ctx, rawURL, maxBytes)
|
||||
}
|
||||
|
||||
func (f *Fetcher) fetchBytes(ctx context.Context, rawURL string, maxBytes int64) ([]byte, string, error) {
|
||||
u, err := url.Parse(strings.TrimSpace(rawURL))
|
||||
if err != nil {
|
||||
return nil, "", fmt.Errorf("linkmeta: bad url: %w", err)
|
||||
}
|
||||
if u.Scheme != "http" && u.Scheme != "https" {
|
||||
return nil, "", fmt.Errorf("linkmeta: scheme %q not allowed", u.Scheme)
|
||||
}
|
||||
if u.Host == "" {
|
||||
return nil, "", errors.New("linkmeta: empty host")
|
||||
}
|
||||
client := f.client()
|
||||
// 二进制传输放宽时限:大图慢链路 5 秒的元信息默认值不够用
|
||||
if f.Timeout <= 0 {
|
||||
client.Timeout = 30 * time.Second
|
||||
}
|
||||
req, err := http.NewRequestWithContext(ctx, http.MethodGet, u.String(), nil)
|
||||
if err != nil {
|
||||
return nil, "", err
|
||||
}
|
||||
req.Header.Set("User-Agent", userAgent)
|
||||
resp, err := client.Do(req)
|
||||
if err != nil {
|
||||
return nil, "", fmt.Errorf("linkmeta: fetch: %w", err)
|
||||
}
|
||||
defer resp.Body.Close()
|
||||
if resp.StatusCode >= 300 {
|
||||
return nil, "", fmt.Errorf("linkmeta: status %d", resp.StatusCode)
|
||||
}
|
||||
data, err := io.ReadAll(io.LimitReader(resp.Body, maxBytes+1))
|
||||
if err != nil {
|
||||
return nil, "", fmt.Errorf("linkmeta: read: %w", err)
|
||||
}
|
||||
if int64(len(data)) > maxBytes {
|
||||
return nil, "", fmt.Errorf("linkmeta: exceeds %d bytes", maxBytes)
|
||||
}
|
||||
ct := resp.Header.Get("Content-Type")
|
||||
if ct == "" {
|
||||
ct = http.DetectContentType(data)
|
||||
}
|
||||
return data, ct, nil
|
||||
}
|
||||
|
||||
func limitRedirects(req *http.Request, via []*http.Request) error {
|
||||
if len(via) > maxRedirects {
|
||||
return fmt.Errorf("linkmeta: too many redirects")
|
||||
|
||||
@@ -147,6 +147,16 @@ type FilePage struct {
|
||||
Size int `json:"size"`
|
||||
}
|
||||
|
||||
// FileRef 是「谁在用这个文件」的一处记录,供删除前的引用检查。
|
||||
// Kind 取 post / project / avatar;avatar 没有可跳转的行,ID 为 0。
|
||||
type FileRef struct {
|
||||
Kind string `json:"kind"`
|
||||
ID int64 `json:"id"`
|
||||
Title string `json:"title"`
|
||||
Slug string `json:"slug"`
|
||||
Status string `json:"status"`
|
||||
}
|
||||
|
||||
// CommentPage 是后台评论管理的分页容器(含文章标题与发表者)。
|
||||
type CommentPage struct {
|
||||
Items []Comment `json:"items"`
|
||||
@@ -221,9 +231,25 @@ type Settings struct {
|
||||
// of either UI, never on /admin. Stored raw — it's the owner's own code,
|
||||
// sanitizing it would only break the snippet.
|
||||
CustomJS string `json:"custom_js"`
|
||||
// AuthorAvatarKey 是站主头像在 files 表里的 key(不是 URL):换存储端不破坏
|
||||
// 存量链接,和 images/link_card 一样属于「存标识、读时解析」。
|
||||
// 故意不并进 UpdateSettings 的全量替换 —— 后台「站点设置」PUT 不该顺手清掉
|
||||
// 账户页设置的头像,两者写入路径分开。
|
||||
AuthorAvatarKey string `json:"author_avatar_key,omitempty"`
|
||||
// AuthorAvatarURL 由 API 层按 AuthorAvatarKey + 存储端解析出来,
|
||||
// 不落库;key 指向的文件已删除时为空串。
|
||||
AuthorAvatarURL string `json:"author_avatar_url"`
|
||||
}
|
||||
|
||||
// Reader 是评论区的登录用户(GitHub OAuth)。Banned = 禁言中。
|
||||
// 账号角色。owner 全库唯一(站主),reader 是评论区登录进来的访客。
|
||||
const (
|
||||
RoleOwner = "owner"
|
||||
RoleReader = "reader"
|
||||
)
|
||||
|
||||
// Reader 是一条评论区身份:既包括站主(role=owner,provider=admin),
|
||||
// 也包括通过 GitHub / Google / Telegram 登录进来的访客(role=reader)。
|
||||
// Banned = 禁言中。
|
||||
type Reader struct {
|
||||
ID int64 `json:"id"`
|
||||
Provider string `json:"provider"`
|
||||
@@ -232,11 +258,39 @@ type Reader struct {
|
||||
AvatarURL string `json:"avatar_url"`
|
||||
URL string `json:"url"`
|
||||
Banned bool `json:"banned"`
|
||||
// Role 区分站主与访客:绑定到 owner 的第三方身份登录时会话升级为管理员。
|
||||
Role string `json:"role"`
|
||||
// CommentCount 是累计评论数(后台用户列表展示用)
|
||||
CommentCount int64 `json:"comment_count"`
|
||||
CreatedAt string `json:"created_at"`
|
||||
}
|
||||
|
||||
// UserIdentity 是「这个账号绑定了哪个第三方身份」。
|
||||
// ExternUID 用各平台的稳定主键(GitHub 数字 id / Google sub / Telegram id),
|
||||
// 不用可改的用户名;Display 只是列表里给人看的标签。
|
||||
type UserIdentity struct {
|
||||
ID int64 `json:"id"`
|
||||
UserID int64 `json:"user_id"`
|
||||
Provider string `json:"provider"`
|
||||
ExternUID string `json:"extern_uid"`
|
||||
Display string `json:"display"`
|
||||
CreatedAt string `json:"created_at"`
|
||||
}
|
||||
|
||||
// Passkey 是一把已注册的 WebAuthn 凭据。PublicKey 以 base64 存
|
||||
// (model 包保持零依赖,字节解码在 auth 层做);SignCount 用于检测
|
||||
// 凭据被克隆(计数回退即异常),LastUsedAt 给管理页显示「上次使用」。
|
||||
type Passkey struct {
|
||||
ID int64 `json:"id"`
|
||||
UserID int64 `json:"user_id"`
|
||||
CredentialID string `json:"credential_id"`
|
||||
PublicKey string `json:"public_key"`
|
||||
SignCount uint32 `json:"sign_count"`
|
||||
Name string `json:"name"`
|
||||
CreatedAt string `json:"created_at"`
|
||||
LastUsedAt string `json:"last_used_at"`
|
||||
}
|
||||
|
||||
// Comment 是一条评论。回复扁平存储(parent_id/root_id),渲染时挂到 replies。
|
||||
// User 是发表者快照;is_deleted = 软删(留壳显示「已删除」,保住楼层上下文)。
|
||||
type Comment struct {
|
||||
|
||||
@@ -0,0 +1,92 @@
|
||||
// 盘古之白:在 CJK 与拉丁字母/数字之间补一个空格,中文混排的阅读观感
|
||||
// 差别很大(「把MVP搬进仓库」→「把 MVP 搬进仓库」)。
|
||||
// 在 HTML 层做:标签原样保留,<code>/<pre>/<script>/<style> 内的文本
|
||||
// 一律不动(代码语义容不得我们加空格),其余文本段做补空格。
|
||||
package render
|
||||
|
||||
import (
|
||||
"regexp"
|
||||
"strings"
|
||||
"unicode"
|
||||
)
|
||||
|
||||
var tagRe = regexp.MustCompile(`<[^>]*>`)
|
||||
|
||||
// code 上下文里的文本不处理
|
||||
var codeOpenRe = regexp.MustCompile(`(?i)<(code|pre|script|style|kbd|samp)\b[^>]*>`)
|
||||
var codeCloseRe = regexp.MustCompile(`(?i)</(code|pre|script|style|kbd|samp)>`)
|
||||
|
||||
// CJK 统一表意区 + 扩展A/兼容 + 日文假名已在 2E80-9FFF 覆盖,
|
||||
// 再补全角标点区(FF00-FFEF)与 CJK 标点(3000-303F)
|
||||
var cjkRe = regexp.MustCompile(`[\x{2E80}-\x{9FFF}\x{3000}-\x{303F}\x{F900}-\x{FAFF}\x{FF00}-\x{FFEF}]`)
|
||||
var latinTailRe = regexp.MustCompile(`([\x{2E80}-\x{9FFF}\x{3000}-\x{303F}\x{F900}-\x{FAFF}\x{FF00}-\x{FFEF}])([A-Za-z0-9_$@])`)
|
||||
var latinHeadRe = regexp.MustCompile(`([A-Za-z0-9+%,.;:!?%)\]])([\x{2E80}-\x{9FFF}\x{3000}-\x{303F}\x{F900}-\x{FAFF}\x{FF00}-\x{FFEF}])`)
|
||||
|
||||
func isCJK(r rune) bool {
|
||||
return cjkRe.MatchString(string(r))
|
||||
}
|
||||
|
||||
// panguText 对纯文本做补空格。已经隔着空格的不动(正则天然要求相邻)。
|
||||
func panguText(s string) string {
|
||||
if !hasCJKAndLatin(s) {
|
||||
return s
|
||||
}
|
||||
prev := ""
|
||||
for prev != s {
|
||||
prev = s
|
||||
s = latinTailRe.ReplaceAllString(s, "$1 $2")
|
||||
s = latinHeadRe.ReplaceAllString(s, "$1 $2")
|
||||
}
|
||||
return s
|
||||
}
|
||||
|
||||
func hasCJKAndLatin(s string) bool {
|
||||
var cjk, latin bool
|
||||
for _, r := range s {
|
||||
if isCJK(r) {
|
||||
cjk = true
|
||||
} else if unicode.IsLetter(r) || unicode.IsNumber(r) {
|
||||
latin = true
|
||||
}
|
||||
if cjk && latin {
|
||||
return true
|
||||
}
|
||||
}
|
||||
return false
|
||||
}
|
||||
|
||||
// PanguHTML 给渲染出的正文 HTML 做盘古之白。流式扫描:标签原样输出,
|
||||
// 普通文本段补空格,代码上下文里的文本跳过。
|
||||
func PanguHTML(html string) string {
|
||||
if !strings.Contains(html, "<") {
|
||||
return html
|
||||
}
|
||||
var b strings.Builder
|
||||
inCode := false
|
||||
for {
|
||||
loc := tagRe.FindStringIndex(html)
|
||||
if loc == nil {
|
||||
rest := html
|
||||
if !inCode {
|
||||
rest = panguText(rest)
|
||||
}
|
||||
b.WriteString(rest)
|
||||
return b.String()
|
||||
}
|
||||
head, tag := html[:loc[0]], html[loc[0]:loc[1]]
|
||||
if !inCode {
|
||||
head = panguText(head)
|
||||
}
|
||||
b.WriteString(head)
|
||||
b.WriteString(tag)
|
||||
if !inCode {
|
||||
if m := codeOpenRe.FindStringSubmatch(tag); m != nil {
|
||||
// 自闭合或行内 code 直接开着也按进/出配对处理(</code> 总会出现)
|
||||
inCode = true
|
||||
}
|
||||
} else if codeCloseRe.MatchString(tag) {
|
||||
inCode = false
|
||||
}
|
||||
html = html[loc[1]:]
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,40 @@
|
||||
package render
|
||||
|
||||
import "testing"
|
||||
|
||||
func TestPanguText(t *testing.T) {
|
||||
cases := map[string]string{
|
||||
"把MVP搬进仓库": "把 MVP 搬进仓库",
|
||||
"今天写了3个小时代码": "今天写了 3 个小时代码",
|
||||
"使用Go和Vue3开发": "使用 Go 和 Vue3 开发",
|
||||
"纯中文没有混排": "纯中文没有混排",
|
||||
"已经隔了空格的 Go 语言": "已经隔了空格的 Go 语言",
|
||||
"数字100在前": "数字 100 在前",
|
||||
"英文后接标点。followed": "英文后接标点。 followed",
|
||||
}
|
||||
for in, want := range cases {
|
||||
if got := panguText(in); got != want {
|
||||
t.Errorf("panguText(%q) = %q, want %q", in, got, want)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
func TestPanguHTML(t *testing.T) {
|
||||
cases := map[string]string{
|
||||
// 普通文本:处理
|
||||
"<p>把MVP搬进仓库</p>": "<p>把 MVP 搬进仓库</p>",
|
||||
// 行内 code:不动
|
||||
"<p>运行<code>go build ./...</code>即可</p>": "<p>运行<code>go build ./...</code>即可</p>",
|
||||
// pre 代码块:整个内部不动
|
||||
"<pre><code>把MVP搬进仓库\nfmt.Println(1)</code></pre>": "<pre><code>把MVP搬进仓库\nfmt.Println(1)</code></pre>",
|
||||
// 属性里不是文本:不动(src 含字母数字混合不受影响)
|
||||
`<img alt="测试图1" src="a1.png">`: `<img alt="测试图1" src="a1.png">`,
|
||||
// 嵌套:code 结束后恢复处理
|
||||
"<p>先<code>跑起来</code>再看结果100%</p>": "<p>先<code>跑起来</code>再看结果 100%</p>",
|
||||
}
|
||||
for in, want := range cases {
|
||||
if got := PanguHTML(in); got != want {
|
||||
t.Errorf("PanguHTML(%q) = %q, want %q", in, got, want)
|
||||
}
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,180 @@
|
||||
package store
|
||||
|
||||
import (
|
||||
"errors"
|
||||
"testing"
|
||||
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
func TestEnsureOwner(t *testing.T) {
|
||||
s := openTestStore(t)
|
||||
|
||||
owner, err := s.EnsureOwner("admin")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if owner.Role != model.RoleOwner || owner.Provider != "admin" {
|
||||
t.Fatalf("owner row wrong: %+v", owner)
|
||||
}
|
||||
// 幂等:再取一次是同一行
|
||||
again, err := s.EnsureOwner("admin")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if again.ID != owner.ID {
|
||||
t.Fatalf("重复 EnsureOwner 建了两行: %d vs %d", owner.ID, again.ID)
|
||||
}
|
||||
// 改了环境变量里的用户名,handle 要跟上
|
||||
got, err := s.EnsureOwner("newname")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got.ID != owner.ID || got.Handle != "newname" {
|
||||
t.Fatalf("handle 未同步: %+v", got)
|
||||
}
|
||||
// 全库只应有一个 owner
|
||||
all, err := s.ListReaders()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
n := 0
|
||||
for _, r := range all {
|
||||
if r.Role == model.RoleOwner {
|
||||
n++
|
||||
}
|
||||
}
|
||||
if n != 1 {
|
||||
t.Fatalf("owner 行数 = %d, want 1", n)
|
||||
}
|
||||
}
|
||||
|
||||
func TestOwnerNotClobberedByReaderUpsert(t *testing.T) {
|
||||
// 站主行是 provider=admin,OAuth 登录建的是 provider=github 行,
|
||||
// 两者不能互相覆盖 —— 这是「站主能自定义资料」成立的前提。
|
||||
s := openTestStore(t)
|
||||
owner, err := s.EnsureOwner("admin")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := s.UpsertReader(model.Reader{Provider: "github", Handle: "someone", Name: "路人"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
got, err := s.GetOwner()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got.ID != owner.ID || got.Provider != "admin" {
|
||||
t.Fatalf("站主行被改动: %+v", got)
|
||||
}
|
||||
}
|
||||
|
||||
func TestBindIdentityGuards(t *testing.T) {
|
||||
s := openTestStore(t)
|
||||
owner, _ := s.EnsureOwner("admin")
|
||||
other, err := s.UpsertReader(model.Reader{Provider: "github", Handle: "intruder", Name: "n"})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
if err := s.BindIdentity(owner.ID, "github", "12345", "littleckin"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
// 重复绑同一个:幂等
|
||||
if err := s.BindIdentity(owner.ID, "github", "12345", "littleckin"); err != nil {
|
||||
t.Fatalf("重复绑定应幂等,got %v", err)
|
||||
}
|
||||
// 关键护栏:同一个外部账号不能被第二个用户占走
|
||||
if err := s.BindIdentity(other.ID, "github", "12345", "hijack"); !errors.Is(err, ErrConflict) {
|
||||
t.Fatalf("抢占他人身份应 ErrConflict, got %v", err)
|
||||
}
|
||||
// 换平台可以(UNIQUE 是 user_id+provider)
|
||||
if err := s.BindIdentity(owner.ID, "telegram", "999", "tg"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
ids, err := s.ListIdentities(owner.ID)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(ids) != 2 {
|
||||
t.Fatalf("绑定数 = %d, want 2", len(ids))
|
||||
}
|
||||
// 登录查找:按外部身份找到站主,且 role 正确
|
||||
u, err := s.GetUserByIdentity("github", "12345")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if u.ID != owner.ID || u.Role != model.RoleOwner {
|
||||
t.Fatalf("身份反查结果错: %+v", u)
|
||||
}
|
||||
if _, err := s.GetUserByIdentity("github", "nope"); !errors.Is(err, ErrNotFound) {
|
||||
t.Fatalf("未绑定应 ErrNotFound, got %v", err)
|
||||
}
|
||||
// 解绑
|
||||
if err := s.UnbindIdentity(owner.ID, "github"); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := s.GetUserByIdentity("github", "12345"); !errors.Is(err, ErrNotFound) {
|
||||
t.Fatal("解绑后仍能查到")
|
||||
}
|
||||
if err := s.UnbindIdentity(owner.ID, "github"); !errors.Is(err, ErrNotFound) {
|
||||
t.Fatalf("重复解绑应 ErrNotFound, got %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestPasskeyLifecycle(t *testing.T) {
|
||||
s := openTestStore(t)
|
||||
owner, _ := s.EnsureOwner("admin")
|
||||
other, _ := s.UpsertReader(model.Reader{Provider: "github", Handle: "x", Name: "x"})
|
||||
|
||||
p, err := s.AddPasskey(model.Passkey{UserID: owner.ID, CredentialID: "cred-1", PublicKey: "base64key", Name: "MacBook", SignCount: 3})
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if p.ID == 0 {
|
||||
t.Fatal("没拿到自增 id")
|
||||
}
|
||||
// 同一把凭据不能注册两次
|
||||
if _, err := s.AddPasskey(model.Passkey{UserID: other.ID, CredentialID: "cred-1", PublicKey: "k", Name: "dup"}); err == nil {
|
||||
t.Fatal("重复 credential_id 应被拒")
|
||||
}
|
||||
|
||||
list, err := s.ListPasskeys(owner.ID)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(list) != 1 || list[0].Name != "MacBook" {
|
||||
t.Fatalf("list=%+v", list)
|
||||
}
|
||||
if list[0].PublicKey != "" {
|
||||
t.Fatal("列表接口不该回传公钥")
|
||||
}
|
||||
|
||||
got, err := s.GetPasskeyByCredentialID("cred-1")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got.PublicKey != "base64key" || got.SignCount != 3 {
|
||||
t.Fatalf("got=%+v", got)
|
||||
}
|
||||
|
||||
if err := s.TouchPasskey(got.ID, 9); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
after, _ := s.GetPasskeyByCredentialID("cred-1")
|
||||
if after.SignCount != 9 || after.LastUsedAt == "" {
|
||||
t.Fatalf("TouchPasskey 未生效: %+v", after)
|
||||
}
|
||||
|
||||
// 越权删除必须失败:id 是站主的,user_id 给别人
|
||||
if err := s.DeletePasskey(after.ID, other.ID); !errors.Is(err, ErrNotFound) {
|
||||
t.Fatalf("跨用户删除应 ErrNotFound, got %v", err)
|
||||
}
|
||||
if err := s.DeletePasskey(after.ID, owner.ID); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if rest, _ := s.ListPasskeys(owner.ID); len(rest) != 0 {
|
||||
t.Fatalf("删除后仍有 %d 条", len(rest))
|
||||
}
|
||||
}
|
||||
@@ -0,0 +1,109 @@
|
||||
package store
|
||||
|
||||
import (
|
||||
"testing"
|
||||
|
||||
"oneblog/internal/model"
|
||||
)
|
||||
|
||||
func countKind(refs []model.FileRef, kind string) int {
|
||||
n := 0
|
||||
for _, r := range refs {
|
||||
if r.Kind == kind {
|
||||
n++
|
||||
}
|
||||
}
|
||||
return n
|
||||
}
|
||||
|
||||
// 同一个 key 在正文里的三种形态都要认出来:R2 直链、本地 /uploads、缩略图路径。
|
||||
func TestFileReferencesMatchesKeyNotURL(t *testing.T) {
|
||||
s := openTestStore(t)
|
||||
const key = "2026/09/deadbeefcafe.png"
|
||||
|
||||
if _, err := s.Create(model.PostInput{
|
||||
Kind: model.KindLong, Title: "直链引用", Slug: "r2",
|
||||
CoverURL: "https://cdn.example.com/" + key,
|
||||
ContentMd: "正文配图 ",
|
||||
Status: model.StatusPublished,
|
||||
}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if _, err := s.Create(model.PostInput{
|
||||
Kind: model.KindShort, Slug: "local",
|
||||
ContentMd: "本地形态  和缩略图 ",
|
||||
Status: model.StatusDraft,
|
||||
}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
refs, err := s.FileReferences(key)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
// 两篇文章各算一处:同一行里多次命中不重复计
|
||||
if len(refs) != 2 {
|
||||
t.Fatalf("want 2 refs, got %+v", refs)
|
||||
}
|
||||
if countKind(refs, "post") != 2 {
|
||||
t.Fatalf("两条都该是 post: %+v", refs)
|
||||
}
|
||||
// 草稿也要报出来(发布后就会图裂)
|
||||
if refs[1].Status != model.StatusDraft {
|
||||
t.Fatalf("草稿状态没带出来: %+v", refs[1])
|
||||
}
|
||||
}
|
||||
|
||||
func TestFileReferencesProjectsAndAvatar(t *testing.T) {
|
||||
s := openTestStore(t)
|
||||
const key = "2026/09/111122223333.webp"
|
||||
|
||||
if _, err := s.CreateProject(model.ProjectInput{
|
||||
Title: "ONE", Slug: "one", CoverURL: "/uploads/" + key, Status: model.StatusPublished,
|
||||
}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := s.SetSetting("owner_avatar_key", key); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
refs, err := s.FileReferences(key)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if countKind(refs, "project") != 1 {
|
||||
t.Fatalf("项目封面没查到: %+v", refs)
|
||||
}
|
||||
if countKind(refs, "avatar") != 1 {
|
||||
t.Fatalf("站主头像没查到: %+v", refs)
|
||||
}
|
||||
}
|
||||
|
||||
// 没被引用、以及 key 为空时都不能误报——空 pattern 会 LIKE '%%' 命中全库。
|
||||
func TestFileReferencesNoFalsePositive(t *testing.T) {
|
||||
s := openTestStore(t)
|
||||
if _, err := s.Create(model.PostInput{
|
||||
Kind: model.KindLong, Title: "无关", Slug: "x",
|
||||
ContentMd: "正文里没有这张图", CoverURL: "/uploads/2026/09/aaaa.png",
|
||||
Status: model.StatusPublished,
|
||||
}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
// 同内容不同月上传出的 key 只是月份段不同,不该互相命中
|
||||
refs, err := s.FileReferences("2026/10/aaaa.png")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(refs) != 0 {
|
||||
t.Fatalf("换月的 key 误报: %+v", refs)
|
||||
}
|
||||
|
||||
empty, err := s.FileReferences("")
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if len(empty) != 0 {
|
||||
t.Fatalf("空 key 不该匹配任何东西,得到 %+v", empty)
|
||||
}
|
||||
}
|
||||
+310
-10
@@ -23,6 +23,9 @@ func readingMinutes(md string) int { return render.ReadingMinutes(md) }
|
||||
|
||||
var ErrNotFound = errors.New("not found")
|
||||
|
||||
// ErrConflict 表示要建的唯一键已被占(例如某个外部身份已绑到别的账号)。
|
||||
var ErrConflict = errors.New("conflict")
|
||||
|
||||
type Store struct {
|
||||
db *db.DB
|
||||
}
|
||||
@@ -120,6 +123,30 @@ func (s *Store) migrate() error {
|
||||
created_at TEXT NOT NULL,
|
||||
edited_at TEXT NOT NULL DEFAULT ''
|
||||
)`, ai),
|
||||
// 第三方身份绑定:一个账号每个平台只能绑一条(UNIQUE(user_id,provider)),
|
||||
// 同一个外部账号也只能属于一个用户(UNIQUE(provider,extern_uid))——
|
||||
// 后者是防接管的关键:不能靠「先用我的 GitHub 登录、再把你的账号绑上来」占位。
|
||||
fmt.Sprintf(`CREATE TABLE IF NOT EXISTS user_identities (
|
||||
id %s,
|
||||
user_id INTEGER NOT NULL,
|
||||
provider TEXT NOT NULL,
|
||||
extern_uid TEXT NOT NULL,
|
||||
display TEXT NOT NULL DEFAULT '',
|
||||
created_at TEXT NOT NULL,
|
||||
UNIQUE(provider, extern_uid),
|
||||
UNIQUE(user_id, provider)
|
||||
)`, ai),
|
||||
// Passkey 一人可多把(笔记本 + 手机),所以不加 UNIQUE(user_id)
|
||||
fmt.Sprintf(`CREATE TABLE IF NOT EXISTS passkeys (
|
||||
id %s,
|
||||
user_id INTEGER NOT NULL,
|
||||
credential_id TEXT NOT NULL UNIQUE,
|
||||
public_key TEXT NOT NULL,
|
||||
sign_count INTEGER NOT NULL DEFAULT 0,
|
||||
name TEXT NOT NULL DEFAULT '',
|
||||
created_at TEXT NOT NULL,
|
||||
last_used_at TEXT NOT NULL DEFAULT ''
|
||||
)`, ai),
|
||||
}
|
||||
for _, q := range stmts {
|
||||
if _, err := s.db.Exec(s.db.Q(q)); err != nil {
|
||||
@@ -137,6 +164,8 @@ func (s *Store) migrate() error {
|
||||
`ALTER TABLE posts ADD COLUMN images TEXT NOT NULL DEFAULT '[]'`,
|
||||
// 正文首个外链的预览卡片(og 标题/描述/封面),JSON 对象或空串
|
||||
`ALTER TABLE posts ADD COLUMN link_card TEXT NOT NULL DEFAULT ''`,
|
||||
// 账号角色:owner(站主,全库唯一)/ reader(评论区访客)
|
||||
`ALTER TABLE users ADD COLUMN role TEXT NOT NULL DEFAULT 'reader'`,
|
||||
}
|
||||
for _, q := range columnAdds {
|
||||
if _, err := s.db.Exec(s.db.Q(q)); err != nil && !strings.Contains(err.Error(), "already exists") &&
|
||||
@@ -157,6 +186,8 @@ func (s *Store) migrate() error {
|
||||
{"idx_comments_post", `CREATE INDEX IF NOT EXISTS idx_comments_post ON comments(post_id, created_at)`},
|
||||
{"idx_comments_user", `CREATE INDEX IF NOT EXISTS idx_comments_user ON comments(user_id)`},
|
||||
{"idx_comments_status", `CREATE INDEX IF NOT EXISTS idx_comments_status ON comments(status, created_at DESC)`},
|
||||
{"idx_identities_user", `CREATE INDEX IF NOT EXISTS idx_identities_user ON user_identities(user_id)`},
|
||||
{"idx_passkeys_user", `CREATE INDEX IF NOT EXISTS idx_passkeys_user ON passkeys(user_id)`},
|
||||
}
|
||||
for _, ix := range indexes {
|
||||
if _, err := s.db.Exec(s.db.Q(ix.ddl)); err != nil && !strings.Contains(err.Error(), "already exists") {
|
||||
@@ -240,6 +271,7 @@ func settingsFromMap(m map[string]string) model.Settings {
|
||||
st.CustomCSS = decodeCSSMap(m["custom_css"])
|
||||
st.CustomJS = m["custom_js"]
|
||||
st.SocialLinks = decodeSocialLinks(m["social_links"])
|
||||
st.AuthorAvatarKey = m["owner_avatar_key"]
|
||||
// 开关类:'1' / 'true' 都算开,其余(含空)算关
|
||||
st.CommentsEnabled = m["comments_enabled"] == "1" || strings.EqualFold(m["comments_enabled"], "true")
|
||||
st.CommentsReview = m["comments_review"] == "1" || strings.EqualFold(m["comments_review"], "true")
|
||||
@@ -447,6 +479,19 @@ func (s *Store) UpdateSettings(st model.Settings) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// SetSetting 只写一个 KV,绕开 UpdateSettings 的全量替换。
|
||||
// 账户页改头像用它的自己的键,免得「站点设置」保存时被顺带清掉。
|
||||
func (s *Store) SetSetting(key, value string) error {
|
||||
if s.db.Dialect == db.Postgres {
|
||||
_, err := s.db.Exec(s.db.Q(`INSERT INTO settings(key,value) VALUES (?,?)
|
||||
ON CONFLICT (key) DO UPDATE SET value = EXCLUDED.value`), key, value)
|
||||
return err
|
||||
}
|
||||
_, err := s.db.Exec(s.db.Q(`INSERT INTO settings(key,value) VALUES (?,?)
|
||||
ON CONFLICT(key) DO UPDATE SET value = excluded.value`), key, value)
|
||||
return err
|
||||
}
|
||||
|
||||
// ---------- posts ----------
|
||||
|
||||
type ListOptions struct {
|
||||
@@ -995,7 +1040,12 @@ func (s *Store) Create(in model.PostInput) (model.Post, error) {
|
||||
}
|
||||
}
|
||||
p.ID = id
|
||||
if err := s.setTags(id, in.Tags); err != nil {
|
||||
// 标签是长文的组织方式;短文(类推微博)一律不打标签
|
||||
tags := in.Tags
|
||||
if p.Kind == model.KindShort {
|
||||
tags = nil
|
||||
}
|
||||
if err := s.setTags(id, tags); err != nil {
|
||||
return p, err
|
||||
}
|
||||
return s.Get(id)
|
||||
@@ -1054,8 +1104,13 @@ func (s *Store) Update(id int64, in model.PostInput) (model.Post, error) {
|
||||
p.PublishedAt, p.UpdatedAt, p.ReadingMinutes, encodeImages(p.Images), encodeLinkCard(p.LinkCard), id); err != nil {
|
||||
return p, err
|
||||
}
|
||||
if in.Tags != nil {
|
||||
if err := s.setTags(id, in.Tags); err != nil {
|
||||
// 短文一律无标签:切换类型或直接保存时都把旧标签清掉
|
||||
if in.Tags != nil || p.Kind == model.KindShort {
|
||||
tags := in.Tags
|
||||
if p.Kind == model.KindShort {
|
||||
tags = nil
|
||||
}
|
||||
if err := s.setTags(id, tags); err != nil {
|
||||
return p, err
|
||||
}
|
||||
}
|
||||
@@ -1595,6 +1650,68 @@ func (s *Store) GetFileByKey(key string) (model.File, error) {
|
||||
return f, nil
|
||||
}
|
||||
|
||||
// FileReferences 反查谁在用这个文件:文章(封面或正文)、项目封面、站主头像。
|
||||
// 匹配的键是 files.key 本身而不是完整 URL——本地存成 /uploads/{key}、R2 存成
|
||||
// {publicBase}/{key}、缩略图是 /uploads/thumb/{key},三种形态都以 key 结尾,
|
||||
// 换存储端后正文里的老链接也照样能查到。
|
||||
// 用 LIKE 现扫而不维护计数表:写入口有编辑器、外链转存、短文、项目、头像好几处,
|
||||
// 计数一旦漂移就再也信不过;删文件是低频操作,扫全表几十毫秒换一个永远正确的答案。
|
||||
func (s *Store) FileReferences(key string) ([]model.FileRef, error) {
|
||||
if key == "" {
|
||||
return []model.FileRef{}, nil
|
||||
}
|
||||
like := "%" + key + "%"
|
||||
out := []model.FileRef{}
|
||||
|
||||
rows, err := s.db.Query(s.db.Q(`SELECT id,title,slug,status FROM posts
|
||||
WHERE cover_url LIKE ? OR content_md LIKE ? OR content_html LIKE ?
|
||||
ORDER BY published_at DESC LIMIT 100`), like, like, like)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
for rows.Next() {
|
||||
var r model.FileRef
|
||||
r.Kind = "post"
|
||||
if err := rows.Scan(&r.ID, &r.Title, &r.Slug, &r.Status); err != nil {
|
||||
rows.Close()
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, r)
|
||||
}
|
||||
if err := rows.Err(); err != nil {
|
||||
rows.Close()
|
||||
return nil, err
|
||||
}
|
||||
rows.Close()
|
||||
|
||||
proj, err := s.db.Query(s.db.Q(`SELECT id,title,slug,status FROM projects WHERE cover_url LIKE ? LIMIT 100`), like)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
for proj.Next() {
|
||||
var r model.FileRef
|
||||
r.Kind = "project"
|
||||
if err := proj.Scan(&r.ID, &r.Title, &r.Slug, &r.Status); err != nil {
|
||||
proj.Close()
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, r)
|
||||
}
|
||||
if err := proj.Err(); err != nil {
|
||||
proj.Close()
|
||||
return nil, err
|
||||
}
|
||||
proj.Close()
|
||||
|
||||
// 头像存的就是 key(不是 URL),等值比较
|
||||
if st, err := s.GetSettings(); err != nil {
|
||||
return nil, err
|
||||
} else if st.AuthorAvatarKey == key {
|
||||
out = append(out, model.FileRef{Kind: "avatar"})
|
||||
}
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// DeleteFile 删索引行并返回被删的行(调用方负责先删对象存储里的本体)。
|
||||
func (s *Store) DeleteFile(id int64) (model.File, error) {
|
||||
f, err := s.GetFile(id)
|
||||
@@ -1645,8 +1762,15 @@ func (s *Store) UpsertReader(r model.Reader) (model.Reader, error) {
|
||||
return s.GetReaderByProviderHandle(r.Provider, r.Handle)
|
||||
}
|
||||
|
||||
// userCols 是 users 表的读取列清单。列在多处 SELECT 复用,抽出来免得加一列
|
||||
// 就要同步改一遍(漏一处就是扫错位置)。
|
||||
const userCols = `id,provider,handle,name,avatar_url,url,banned,role,created_at`
|
||||
|
||||
// userColsU 是 JOIN 查询里带 u. 前缀的同一份列清单。和 userCols 成对改。
|
||||
const userColsU = `u.id,u.provider,u.handle,u.name,u.avatar_url,u.url,u.banned,u.role,u.created_at`
|
||||
|
||||
func (s *Store) GetReader(id int64) (model.Reader, error) {
|
||||
r, err := scanReader(s.db.QueryRow(s.db.Q(`SELECT id,provider,handle,name,avatar_url,url,banned,created_at FROM users WHERE id = ?`), id))
|
||||
r, err := scanReader(s.db.QueryRow(s.db.Q(`SELECT `+userCols+` FROM users WHERE id = ?`), id))
|
||||
if err != nil {
|
||||
if errors.Is(err, sql.ErrNoRows) {
|
||||
return model.Reader{}, ErrNotFound
|
||||
@@ -1657,7 +1781,7 @@ func (s *Store) GetReader(id int64) (model.Reader, error) {
|
||||
}
|
||||
|
||||
func (s *Store) GetReaderByProviderHandle(provider, handle string) (model.Reader, error) {
|
||||
r, err := scanReader(s.db.QueryRow(s.db.Q(`SELECT id,provider,handle,name,avatar_url,url,banned,created_at FROM users WHERE provider = ? AND handle = ?`), provider, handle))
|
||||
r, err := scanReader(s.db.QueryRow(s.db.Q(`SELECT `+userCols+` FROM users WHERE provider = ? AND handle = ?`), provider, handle))
|
||||
if err != nil {
|
||||
if errors.Is(err, sql.ErrNoRows) {
|
||||
return model.Reader{}, ErrNotFound
|
||||
@@ -1678,11 +1802,11 @@ func (s *Store) SetReaderBanned(id int64, banned bool) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// ListReaders 后台的用户列表:带评论数,禁言中的排前面
|
||||
// ListReaders 后台的用户列表:带评论数,站主最前、禁言中的排前面
|
||||
func (s *Store) ListReaders() ([]model.Reader, error) {
|
||||
rows, err := s.db.Query(s.db.Q(`SELECT u.id,u.provider,u.handle,u.name,u.avatar_url,u.url,u.banned,u.created_at,
|
||||
rows, err := s.db.Query(s.db.Q(`SELECT u.id,u.provider,u.handle,u.name,u.avatar_url,u.url,u.banned,u.role,u.created_at,
|
||||
(SELECT COUNT(*) FROM comments c WHERE c.user_id = u.id AND c.is_deleted = 0) AS cnt
|
||||
FROM users u ORDER BY u.banned DESC, u.created_at DESC`))
|
||||
FROM users u ORDER BY CASE WHEN u.role = 'owner' THEN 0 ELSE 1 END, u.banned DESC, u.created_at DESC`))
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
@@ -1691,7 +1815,7 @@ func (s *Store) ListReaders() ([]model.Reader, error) {
|
||||
for rows.Next() {
|
||||
var r model.Reader
|
||||
var cnt int64
|
||||
if err := rows.Scan(&r.ID, &r.Provider, &r.Handle, &r.Name, &r.AvatarURL, &r.URL, &r.Banned, &r.CreatedAt, &cnt); err != nil {
|
||||
if err := rows.Scan(&r.ID, &r.Provider, &r.Handle, &r.Name, &r.AvatarURL, &r.URL, &r.Banned, &r.Role, &r.CreatedAt, &cnt); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
r.CommentCount = cnt
|
||||
@@ -1700,6 +1824,182 @@ func (s *Store) ListReaders() ([]model.Reader, error) {
|
||||
return out, rows.Err()
|
||||
}
|
||||
|
||||
// UpdateProfile 改站主行的显示名。只碰 name —— provider/handle/role 是身份锚,
|
||||
// 不随资料编辑变动。
|
||||
func (s *Store) UpdateProfile(userID int64, name string) (model.Reader, error) {
|
||||
if _, err := s.db.Exec(s.db.Q(`UPDATE users SET name = ? WHERE id = ?`), name, userID); err != nil {
|
||||
return model.Reader{}, err
|
||||
}
|
||||
return s.GetReader(userID)
|
||||
}
|
||||
|
||||
// ---------- 站主账号 / 身份绑定 / passkey ----------
|
||||
|
||||
// EnsureOwner 取(或创建)站主账号行:provider=admin、role=owner。
|
||||
// handle 跟着 ONE_ADMIN_USER 走——改了环境变量后这里会同步,
|
||||
// 但 role=owner 只此一行,是「哪些身份登录算管理员」的锚点。
|
||||
func (s *Store) EnsureOwner(handle string) (model.Reader, error) {
|
||||
cur, err := s.GetOwner()
|
||||
if err == nil {
|
||||
if cur.Handle != handle {
|
||||
if _, uerr := s.db.Exec(s.db.Q(`UPDATE users SET handle = ? WHERE id = ?`), handle, cur.ID); uerr != nil {
|
||||
return model.Reader{}, uerr
|
||||
}
|
||||
cur.Handle = handle
|
||||
}
|
||||
return cur, nil
|
||||
}
|
||||
if !errors.Is(err, ErrNotFound) {
|
||||
return model.Reader{}, err
|
||||
}
|
||||
if _, err := s.db.Exec(s.db.Q(`INSERT INTO users (provider,handle,name,avatar_url,url,banned,role,created_at)
|
||||
VALUES (?,?,?,?,?,0,'owner',?)`), "admin", handle, "", "", "", now()); err != nil {
|
||||
return model.Reader{}, err
|
||||
}
|
||||
return s.GetOwner()
|
||||
}
|
||||
|
||||
// GetOwner 取站主行。role='owner' 全库唯一,按 provider 兜底兼容老数据
|
||||
// (老库里站主行只有 provider='admin',没有 role)。
|
||||
func (s *Store) GetOwner() (model.Reader, error) {
|
||||
r, err := scanReader(s.db.QueryRow(s.db.Q(
|
||||
`SELECT ` + userCols + ` FROM users WHERE role = 'owner' OR provider = 'admin' ORDER BY id LIMIT 1`)))
|
||||
if errors.Is(err, sql.ErrNoRows) {
|
||||
return model.Reader{}, ErrNotFound
|
||||
}
|
||||
return r, err
|
||||
}
|
||||
|
||||
// BindIdentity 把 (provider, extern_uid) 绑到某个用户上。
|
||||
// 外部账号已被别人占用时返回 ErrConflict —— 调用方必须原样拒绝,
|
||||
// 不能「后来者覆盖」,否则任何人都能抢先把别人的 GitHub 账号登记成自己的。
|
||||
func (s *Store) BindIdentity(userID int64, provider, externUID, display string) error {
|
||||
owner, err := s.GetUserByIdentity(provider, externUID)
|
||||
if err == nil {
|
||||
if owner.ID == userID {
|
||||
return nil // 重复绑定同一个,幂等放过
|
||||
}
|
||||
return ErrConflict
|
||||
}
|
||||
if !errors.Is(err, ErrNotFound) {
|
||||
return err
|
||||
}
|
||||
_, err = s.db.Exec(s.db.Q(`INSERT INTO user_identities (user_id,provider,extern_uid,display,created_at)
|
||||
VALUES (?,?,?,?,?)`), userID, provider, externUID, display, now())
|
||||
return err
|
||||
}
|
||||
|
||||
// UnbindIdentity 解绑某平台的绑定。站主始终还有环境变量密码这条退路,
|
||||
// 所以这里不需要「不能解绑唯一登录方式」的护栏。
|
||||
func (s *Store) UnbindIdentity(userID int64, provider string) error {
|
||||
res, err := s.db.Exec(s.db.Q(`DELETE FROM user_identities WHERE user_id = ? AND provider = ?`), userID, provider)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if n, _ := res.RowsAffected(); n == 0 {
|
||||
return ErrNotFound
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func (s *Store) ListIdentities(userID int64) ([]model.UserIdentity, error) {
|
||||
rows, err := s.db.Query(s.db.Q(`SELECT id,user_id,provider,extern_uid,display,created_at
|
||||
FROM user_identities WHERE user_id = ? ORDER BY created_at`), userID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []model.UserIdentity{}
|
||||
for rows.Next() {
|
||||
var it model.UserIdentity
|
||||
if err := rows.Scan(&it.ID, &it.UserID, &it.Provider, &it.ExternUID, &it.Display, &it.CreatedAt); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
out = append(out, it)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
|
||||
// GetUserByIdentity 按外部身份找用户:登录时先问它,命中即知道该发哪种会话。
|
||||
func (s *Store) GetUserByIdentity(provider, externUID string) (model.Reader, error) {
|
||||
r, err := scanReader(s.db.QueryRow(s.db.Q(
|
||||
`SELECT `+userColsU+`
|
||||
FROM user_identities i JOIN users u ON u.id = i.user_id
|
||||
WHERE i.provider = ? AND i.extern_uid = ?`), provider, externUID))
|
||||
if errors.Is(err, sql.ErrNoRows) {
|
||||
return model.Reader{}, ErrNotFound
|
||||
}
|
||||
return r, err
|
||||
}
|
||||
|
||||
// ---------- passkey ----------
|
||||
|
||||
func (s *Store) AddPasskey(p model.Passkey) (model.Passkey, error) {
|
||||
p.CreatedAt = now()
|
||||
res, err := s.db.Exec(s.db.Q(`INSERT INTO passkeys (user_id,credential_id,public_key,sign_count,name,created_at,last_used_at)
|
||||
VALUES (?,?,?,?,?,?,?)`), p.UserID, p.CredentialID, p.PublicKey, int64(p.SignCount), p.Name, p.CreatedAt, "")
|
||||
if err != nil {
|
||||
return model.Passkey{}, err
|
||||
}
|
||||
p.ID, _ = res.LastInsertId()
|
||||
return p, nil
|
||||
}
|
||||
|
||||
// ListPasskeys 不返回 public_key:管理页只列名字与时间,凭据公钥
|
||||
// 没必要顺着列表接口到处走。
|
||||
func (s *Store) ListPasskeys(userID int64) ([]model.Passkey, error) {
|
||||
rows, err := s.db.Query(s.db.Q(`SELECT id,user_id,credential_id,'',sign_count,name,created_at,last_used_at
|
||||
FROM passkeys WHERE user_id = ? ORDER BY created_at`), userID)
|
||||
if err != nil {
|
||||
return nil, err
|
||||
}
|
||||
defer rows.Close()
|
||||
out := []model.Passkey{}
|
||||
for rows.Next() {
|
||||
var p model.Passkey
|
||||
var sc int64
|
||||
if err := rows.Scan(&p.ID, &p.UserID, &p.CredentialID, &p.PublicKey, &sc, &p.Name, &p.CreatedAt, &p.LastUsedAt); err != nil {
|
||||
return nil, err
|
||||
}
|
||||
p.SignCount = uint32(sc)
|
||||
out = append(out, p)
|
||||
}
|
||||
return out, rows.Err()
|
||||
}
|
||||
|
||||
func (s *Store) GetPasskeyByCredentialID(credentialID string) (model.Passkey, error) {
|
||||
var p model.Passkey
|
||||
var sc int64
|
||||
err := s.db.QueryRow(s.db.Q(`SELECT id,user_id,credential_id,public_key,sign_count,name,created_at,last_used_at
|
||||
FROM passkeys WHERE credential_id = ?`), credentialID).
|
||||
Scan(&p.ID, &p.UserID, &p.CredentialID, &p.PublicKey, &sc, &p.Name, &p.CreatedAt, &p.LastUsedAt)
|
||||
if errors.Is(err, sql.ErrNoRows) {
|
||||
return model.Passkey{}, ErrNotFound
|
||||
}
|
||||
p.SignCount = uint32(sc)
|
||||
return p, err
|
||||
}
|
||||
|
||||
// TouchPasskey 回写签名计数与使用时间。计数只增不减:
|
||||
// 新计数比库里记的小,说明凭据被克隆到多个 authenticator 上用过。
|
||||
func (s *Store) TouchPasskey(id int64, signCount uint32) error {
|
||||
_, err := s.db.Exec(s.db.Q(`UPDATE passkeys SET sign_count = ?, last_used_at = ? WHERE id = ?`),
|
||||
int64(signCount), now(), id)
|
||||
return err
|
||||
}
|
||||
|
||||
// DeletePasskey 带 user_id 条件删:免得拿别人的 id 越权删凭据。
|
||||
func (s *Store) DeletePasskey(id, userID int64) error {
|
||||
res, err := s.db.Exec(s.db.Q(`DELETE FROM passkeys WHERE id = ? AND user_id = ?`), id, userID)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if n, _ := res.RowsAffected(); n == 0 {
|
||||
return ErrNotFound
|
||||
}
|
||||
return nil
|
||||
}
|
||||
|
||||
func b2i(b bool) int64 {
|
||||
if b {
|
||||
return 1
|
||||
@@ -1710,7 +2010,7 @@ func b2i(b bool) int64 {
|
||||
func scanReader(sc interface{ Scan(...any) error }) (model.Reader, error) {
|
||||
var r model.Reader
|
||||
var banned int64
|
||||
err := sc.Scan(&r.ID, &r.Provider, &r.Handle, &r.Name, &r.AvatarURL, &r.URL, &banned, &r.CreatedAt)
|
||||
err := sc.Scan(&r.ID, &r.Provider, &r.Handle, &r.Name, &r.AvatarURL, &r.URL, &banned, &r.Role, &r.CreatedAt)
|
||||
r.Banned = banned == 1
|
||||
return r, err
|
||||
}
|
||||
|
||||
@@ -71,6 +71,17 @@ func main() {
|
||||
commentHub := hub.New()
|
||||
// 缩略图懒生成 + 磁盘缓存(首次请求生成一次,之后直接供缓存)
|
||||
thumbCache := thumbs.NewStore(filepath.Join(cfg.DataDir, ".thumbnail_cache"))
|
||||
// Passkey(WebAuthn):只有显式配了 ONE_WEBAUTHN_ORIGINS 才启用。
|
||||
// 没配就不构造 —— 相关端点保持 404,前端也不会显示入口。
|
||||
// 显示名固定 "ONE":站点标题存在 settings 表里,为浏览器弹窗去读库不值当。
|
||||
var passkeys *auth.Passkeys
|
||||
if cfg.WebauthnRPID != "" && len(cfg.WebauthnOrigins) > 0 {
|
||||
passkeys, err = auth.NewPasskeys("ONE", cfg.WebauthnRPID, cfg.WebauthnOrigins)
|
||||
if err != nil {
|
||||
log.Fatalf("passkeys: %v", err)
|
||||
}
|
||||
log.Printf("passkey 登录已启用 (rp_id=%s origins=%s)", cfg.WebauthnRPID, strings.Join(cfg.WebauthnOrigins, ","))
|
||||
}
|
||||
|
||||
public := &api.API{
|
||||
Store: st,
|
||||
@@ -82,12 +93,14 @@ func main() {
|
||||
GG: auth.Google{ClientID: cfg.GoogleClientID, ClientSecret: cfg.GoogleClientSecret},
|
||||
TG: auth.Telegram{Bot: cfg.TelegramBot, Token: cfg.TelegramToken},
|
||||
AdminSessions: adminSessions,
|
||||
Passkeys: passkeys,
|
||||
Hub: commentHub,
|
||||
}
|
||||
adminAPI := admin.NewAPI(st, cfg, adminSessions)
|
||||
adminAPI.Hub = commentHub
|
||||
adminAPI.Blobs = blobs
|
||||
adminAPI.Thumbs = thumbCache // 删文件时连带清掉它的缩略图
|
||||
adminAPI.Passkeys = passkeys
|
||||
|
||||
root := http.NewServeMux()
|
||||
root.Handle("/api/admin/", adminAPI.Routes())
|
||||
|
||||
@@ -7,7 +7,13 @@
|
||||
<meta name="theme-color" content="#1f1d1a" media="(prefers-color-scheme: dark)" />
|
||||
<title>ONE · 一个博客</title>
|
||||
<meta name="description" content="长文与短文,同一种节奏。" />
|
||||
<!-- 方案 A「一横」:SVG 优先(内部有 prefers-color-scheme,深浅皮肤各自变色),
|
||||
PNG 只给不认 SVG 的老浏览器;apple-touch-icon 必须 PNG(iOS 不支持 SVG,
|
||||
且会把透明压成黑底,所以那张铺了纸色实底)。 -->
|
||||
<link rel="icon" type="image/svg+xml" href="/favicon.svg" />
|
||||
<link rel="icon" type="image/png" sizes="32x32" href="/favicon-32.png" />
|
||||
<link rel="icon" type="image/png" sizes="16x16" href="/favicon-16.png" />
|
||||
<link rel="apple-touch-icon" href="/apple-touch-icon.png" />
|
||||
<link rel="alternate" type="application/rss+xml" title="RSS" href="/rss.xml" />
|
||||
<!--
|
||||
UI 版本在 <html> 上以 data-ui 表达,服务端设置要等 /api/site 才知道。
|
||||
|
||||
@@ -10,6 +10,11 @@
|
||||
"preview": "vite preview"
|
||||
},
|
||||
"dependencies": {
|
||||
"@codemirror/commands": "^6.11.1",
|
||||
"@codemirror/lang-markdown": "^6.5.2",
|
||||
"@codemirror/language": "^6.12.4",
|
||||
"@codemirror/state": "^6.7.6",
|
||||
"@codemirror/view": "^6.43.13",
|
||||
"@milkdown/crepe": "^7.22.1",
|
||||
"dompurify": "^3.1.6",
|
||||
"vue": "^3.4.0",
|
||||
|
||||
Generated
+63
-48
@@ -8,6 +8,21 @@ importers:
|
||||
|
||||
.:
|
||||
dependencies:
|
||||
'@codemirror/commands':
|
||||
specifier: ^6.11.1
|
||||
version: 6.11.1
|
||||
'@codemirror/lang-markdown':
|
||||
specifier: ^6.5.2
|
||||
version: 6.5.2
|
||||
'@codemirror/language':
|
||||
specifier: ^6.12.4
|
||||
version: 6.12.4
|
||||
'@codemirror/state':
|
||||
specifier: ^6.7.6
|
||||
version: 6.7.6
|
||||
'@codemirror/view':
|
||||
specifier: ^6.43.13
|
||||
version: 6.43.13
|
||||
'@milkdown/crepe':
|
||||
specifier: ^7.22.1
|
||||
version: 7.22.1(prosemirror-model@1.25.11)(prosemirror-state@1.4.4)(prosemirror-view@1.42.4)(typescript@5.9.3)
|
||||
@@ -140,14 +155,14 @@ packages:
|
||||
'@codemirror/search@6.7.2':
|
||||
resolution: {integrity: sha512-gUYkYhT2+n/+VGZ+8EzE5WFkYZUZYm1VOKDudIsNqh42uRVQJ0a6Yss9sdKT3MeOYfuL1N6AZA57oza0Oyr0LA==}
|
||||
|
||||
'@codemirror/state@6.7.5':
|
||||
resolution: {integrity: sha512-QjLbZmY1Au3JiRrDVYFLRD0BZ3SOKS9pR3yjIkd7u27YY8TFD9/Q9fhPnLV5l1mHFSo3hHU/N31vpwEJOx4owQ==}
|
||||
'@codemirror/state@6.7.6':
|
||||
resolution: {integrity: sha512-kAz+AncRtKuIknedxT1bq4XwXv4UowhbkHU1myPrtVb/jZtImWuV5BXzv5vK6i3kYACsdiZiQKFQQ5Mq7elW8w==}
|
||||
|
||||
'@codemirror/theme-one-dark@6.1.3':
|
||||
resolution: {integrity: sha512-NzBdIvEJmx6fjeremiGp3t/okrLPYT0d9orIc7AFun8oZcRk58aejkqhv6spnz4MLAevrKNPMQYXEWMg4s+sKA==}
|
||||
|
||||
'@codemirror/view@6.43.12':
|
||||
resolution: {integrity: sha512-Nv0vxQ19NAqvB/c2pFzjIzFlzzJl7jmdtNkwOwGbn0Ks9mFAzibvumz7cQem5cRsFA2cEw2fg+uHZGbcHupLQQ==}
|
||||
'@codemirror/view@6.43.13':
|
||||
resolution: {integrity: sha512-sihaFrUzAsYBQsL9J2t69y8nfMQGwcYmggAZsk+kjPbjYZMyuf2hU8tUNTZ+P+isb6XRr8JE22TZlJxBoVdH1A==}
|
||||
|
||||
'@esbuild/aix-ppc64@0.21.5':
|
||||
resolution: {integrity: sha512-1SDgH6ZSPTlggy1yI6+Dbkiz8xzpHJEVAlF/AM1tHPLsf5STom9rwtjE4hKAF20FfXXNTFqEYXyJNWh1GiZedQ==}
|
||||
@@ -1118,15 +1133,15 @@ snapshots:
|
||||
'@codemirror/autocomplete@6.20.3':
|
||||
dependencies:
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
|
||||
'@codemirror/commands@6.11.1':
|
||||
dependencies:
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
|
||||
'@codemirror/lang-angular@0.1.4':
|
||||
@@ -1147,7 +1162,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/css': 1.3.6
|
||||
|
||||
@@ -1155,7 +1170,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/go': 1.0.1
|
||||
|
||||
@@ -1165,8 +1180,8 @@ snapshots:
|
||||
'@codemirror/lang-css': 6.3.1
|
||||
'@codemirror/lang-javascript': 6.2.5
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/css': 1.3.6
|
||||
'@lezer/html': 1.3.13
|
||||
@@ -1181,8 +1196,8 @@ snapshots:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/lint': 6.9.7
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/javascript': 1.5.5
|
||||
|
||||
@@ -1191,8 +1206,8 @@ snapshots:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/lang-html': 6.4.12
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/highlight': 1.2.3
|
||||
'@lezer/lr': 1.4.10
|
||||
@@ -1215,8 +1230,8 @@ snapshots:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/lang-html': 6.4.12
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/highlight': 1.2.3
|
||||
'@lezer/lr': 1.4.10
|
||||
@@ -1226,8 +1241,8 @@ snapshots:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/lang-html': 6.4.12
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/markdown': 1.7.2
|
||||
|
||||
@@ -1235,7 +1250,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/lang-html': 6.4.12
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/php': 1.0.6
|
||||
|
||||
@@ -1243,7 +1258,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/python': 1.1.19
|
||||
|
||||
@@ -1256,7 +1271,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/lang-css': 6.3.1
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/sass': 1.1.0
|
||||
|
||||
@@ -1264,7 +1279,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/highlight': 1.2.3
|
||||
'@lezer/lr': 1.4.10
|
||||
@@ -1289,8 +1304,8 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/xml': 1.0.6
|
||||
|
||||
@@ -1298,7 +1313,7 @@ snapshots:
|
||||
dependencies:
|
||||
'@codemirror/autocomplete': 6.20.3
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/highlight': 1.2.3
|
||||
'@lezer/lr': 1.4.10
|
||||
@@ -1332,8 +1347,8 @@ snapshots:
|
||||
|
||||
'@codemirror/language@6.12.4':
|
||||
dependencies:
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/common': 1.5.2
|
||||
'@lezer/highlight': 1.2.3
|
||||
'@lezer/lr': 1.4.10
|
||||
@@ -1345,30 +1360,30 @@ snapshots:
|
||||
|
||||
'@codemirror/lint@6.9.7':
|
||||
dependencies:
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
crelt: 1.0.7
|
||||
|
||||
'@codemirror/search@6.7.2':
|
||||
dependencies:
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
crelt: 1.0.7
|
||||
|
||||
'@codemirror/state@6.7.5':
|
||||
'@codemirror/state@6.7.6':
|
||||
dependencies:
|
||||
'@marijn/find-cluster-break': 1.0.4
|
||||
|
||||
'@codemirror/theme-one-dark@6.1.3':
|
||||
dependencies:
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@lezer/highlight': 1.2.3
|
||||
|
||||
'@codemirror/view@6.43.12':
|
||||
'@codemirror/view@6.43.13':
|
||||
dependencies:
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
crelt: 1.0.7
|
||||
style-mod: 4.1.4
|
||||
w3c-keyname: 2.2.8
|
||||
@@ -1550,11 +1565,11 @@ snapshots:
|
||||
|
||||
'@marijn/find-cluster-break@1.0.4': {}
|
||||
|
||||
'@milkdown/components@7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.5)(@codemirror/view@6.43.12)(typescript@5.9.3)':
|
||||
'@milkdown/components@7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.6)(@codemirror/view@6.43.13)(typescript@5.9.3)':
|
||||
dependencies:
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
'@floating-ui/dom': 1.8.0
|
||||
'@milkdown/core': 7.22.1
|
||||
'@milkdown/ctx': 7.22.1
|
||||
@@ -1594,10 +1609,10 @@ snapshots:
|
||||
'@codemirror/commands': 6.11.1
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/language-data': 6.5.2
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/theme-one-dark': 6.1.3
|
||||
'@codemirror/view': 6.43.12
|
||||
'@milkdown/kit': 7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.5)(@codemirror/view@6.43.12)(typescript@5.9.3)
|
||||
'@codemirror/view': 6.43.13
|
||||
'@milkdown/kit': 7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.6)(@codemirror/view@6.43.13)(typescript@5.9.3)
|
||||
'@types/lodash-es': 4.17.12
|
||||
clsx: 2.1.1
|
||||
codemirror: 6.0.2
|
||||
@@ -1621,9 +1636,9 @@ snapshots:
|
||||
|
||||
'@milkdown/exception@7.22.1': {}
|
||||
|
||||
'@milkdown/kit@7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.5)(@codemirror/view@6.43.12)(typescript@5.9.3)':
|
||||
'@milkdown/kit@7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.6)(@codemirror/view@6.43.13)(typescript@5.9.3)':
|
||||
dependencies:
|
||||
'@milkdown/components': 7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.5)(@codemirror/view@6.43.12)(typescript@5.9.3)
|
||||
'@milkdown/components': 7.22.1(@codemirror/language@6.12.4)(@codemirror/state@6.7.6)(@codemirror/view@6.43.13)(typescript@5.9.3)
|
||||
'@milkdown/core': 7.22.1
|
||||
'@milkdown/ctx': 7.22.1
|
||||
'@milkdown/exception': 7.22.1
|
||||
@@ -2036,8 +2051,8 @@ snapshots:
|
||||
'@codemirror/language': 6.12.4
|
||||
'@codemirror/lint': 6.9.7
|
||||
'@codemirror/search': 6.7.2
|
||||
'@codemirror/state': 6.7.5
|
||||
'@codemirror/view': 6.43.12
|
||||
'@codemirror/state': 6.7.6
|
||||
'@codemirror/view': 6.43.13
|
||||
|
||||
commander@15.0.0: {}
|
||||
|
||||
|
||||
Binary file not shown.
|
After Width: | Height: | Size: 3.4 KiB |
Binary file not shown.
|
After Width: | Height: | Size: 358 B |
Binary file not shown.
|
After Width: | Height: | Size: 700 B |
@@ -1,32 +1,10 @@
|
||||
<?xml version="1.0" encoding="UTF-8"?>
|
||||
<svg id="Layer_2" data-name="Layer 2" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" viewBox="0 0 128.81 128.17">
|
||||
<defs>
|
||||
<svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 64 64" role="img" aria-label="ONE">
|
||||
<!-- 方案 A「一横」:墨圆 + 一道白横,既是字母 O 也是汉字「一」。
|
||||
横杠用 fill-rule="evenodd" 挖成真洞(不是叠一块纸色矩形),
|
||||
所以它在任何底色上都是透明的——不需要为深浅皮肤各出一版。 -->
|
||||
<style>
|
||||
.cls-1 {
|
||||
fill: url(#gradient3);
|
||||
}
|
||||
|
||||
.cls-2 {
|
||||
fill: #000;
|
||||
}
|
||||
|
||||
@media (prefers-color-scheme: dark) {
|
||||
.cls-2 {
|
||||
fill: #fff;
|
||||
}
|
||||
}
|
||||
.m { fill: #33302b }
|
||||
@media (prefers-color-scheme: dark) { .m { fill: #e8e3d9 } }
|
||||
</style>
|
||||
<linearGradient id="gradient3" x1="57.54" y1="31.44" x2="128.81" y2="31.44" gradientUnits="userSpaceOnUse">
|
||||
<stop offset="0" stop-color="#ff4d4d"/>
|
||||
<stop offset=".99" stop-color="#f9cb28"/>
|
||||
</linearGradient>
|
||||
</defs>
|
||||
<g id="b">
|
||||
<g>
|
||||
<path class="cls-2" d="M56.32,100.47c0,15.98-11.84,27.61-27.85,27.61S.33,116.45,.33,100.47s11.83-27.45,28.08-27.45,27.91,11.63,27.91,27.45Z"/>
|
||||
<path class="cls-2" d="M120,101.26v19.31c-4.87,4.63-12.9,7.6-21.65,7.6-18.33,0-30-10.49-30-26.7s12.92-28.34,31.07-28.34v28.13h20.58Z"/>
|
||||
<polygon class="cls-1" points="119.7 21.48 128.81 38.51 83.27 62.88 57.54 14.79 85.17 0 101.79 31.06 119.7 21.48"/>
|
||||
<polygon class="cls-2" points="0 63.11 16.54 32.82 .68 8.17 55.98 8.17 40.12 32.82 56.65 63.11 0 63.11"/>
|
||||
</g>
|
||||
</g>
|
||||
<path class="m" fill-rule="evenodd" d="M32 4a28 28 0 1 0 0 56 28 28 0 1 0 0-56Zm-16 23.5h32a1 1 0 0 1 1 1v7a1 1 0 0 1-1 1H16a1 1 0 0 1-1-1v-7a1 1 0 0 1 1-1Z"/>
|
||||
</svg>
|
||||
|
Before Width: | Height: | Size: 1.2 KiB After Width: | Height: | Size: 648 B |
+26
-1
@@ -1,5 +1,5 @@
|
||||
<script setup>
|
||||
import { computed, watch } from 'vue'
|
||||
import { computed, onMounted, onBeforeUnmount, watch } from 'vue'
|
||||
import { useRoute } from 'vue-router'
|
||||
import TopBar from './components/TopBar.vue'
|
||||
import ThemeSwitcher from './components/ThemeSwitcher.vue'
|
||||
@@ -9,6 +9,31 @@ import YohakuFoot from './ui/yohaku/YohakuFoot.vue'
|
||||
import { site, setAdminScope } from './site'
|
||||
|
||||
const route = useRoute()
|
||||
|
||||
// 正文代码块复制按钮(事件委托:复制按钮是 enhanceProse 注入的静态 HTML)
|
||||
function onCopyClick(e) {
|
||||
const btn = e.target.closest?.('.pre-copy')
|
||||
if (!btn) return
|
||||
const pre = btn.closest('.pre-wrap')?.querySelector('pre')
|
||||
if (!pre) return
|
||||
navigator.clipboard
|
||||
.writeText(pre.innerText.replace(/\n$/, ''))
|
||||
.then(() => {
|
||||
btn.textContent = '已复制'
|
||||
btn.classList.add('done')
|
||||
setTimeout(() => {
|
||||
btn.textContent = '复制'
|
||||
btn.classList.remove('done')
|
||||
}, 1600)
|
||||
})
|
||||
.catch(() => {
|
||||
btn.textContent = '复制失败'
|
||||
setTimeout(() => (btn.textContent = '复制'), 1600)
|
||||
})
|
||||
}
|
||||
onMounted(() => document.addEventListener('click', onCopyClick))
|
||||
onBeforeUnmount(() => document.removeEventListener('click', onCopyClick))
|
||||
|
||||
const isAdmin = computed(() => route.path.startsWith('/admin'))
|
||||
// vivid 只在公开前台生效:后台永远走 classic 那套(--admin-* token + 原 data-ui/data-theme),
|
||||
// 不受 ui_id 影响。vivid.css 会命中 .btn / .input 这类全局类,后台表单正在用,
|
||||
|
||||
@@ -0,0 +1,362 @@
|
||||
<script setup>
|
||||
import { onMounted, ref } from 'vue'
|
||||
import { useRoute, useRouter } from 'vue-router'
|
||||
import { adminApi } from '../api'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { isSupported as waSupported, register as waRegister } from '../webauthn'
|
||||
|
||||
// 账户页:我是谁(头像 / 昵称 / 简介)+ 我能用什么方式登录
|
||||
// (密码走环境变量、第三方身份绑定、passkey)。
|
||||
//
|
||||
// 和「设置」的分工是刻意的:站点的事在设置,账号的事在这里。
|
||||
// 作者昵称/简介以前在设置里,已移过来 —— 同一字段两处编辑迟早漂移。
|
||||
|
||||
const acct = ref(null)
|
||||
const loading = ref(true)
|
||||
const saving = ref(false)
|
||||
const uploading = ref(false)
|
||||
const regBusy = ref(false)
|
||||
const fileInput = ref(null)
|
||||
|
||||
const route = useRoute()
|
||||
const router = useRouter()
|
||||
|
||||
async function load() {
|
||||
loading.value = true
|
||||
try {
|
||||
acct.value = await adminApi.account()
|
||||
} catch (e) {
|
||||
toastErr(e.message || '读取账户信息失败')
|
||||
} finally {
|
||||
loading.value = false
|
||||
}
|
||||
}
|
||||
|
||||
// 绑定完成是从 provider 整页跳回来的,用 query 带平台名:
|
||||
// 提示一次就把参数抹掉,免得刷新页面重复弹。
|
||||
async function reportBindResult() {
|
||||
const p = route.query.bound
|
||||
if (typeof p !== 'string' || !p) return
|
||||
toastOk(p === 'github' ? '已绑定 GitHub' : '已绑定 ' + p)
|
||||
router.replace({ path: route.path })
|
||||
}
|
||||
|
||||
async function save(patch) {
|
||||
saving.value = true
|
||||
try {
|
||||
acct.value = await adminApi.saveAccount(patch)
|
||||
toastOk('已保存')
|
||||
} catch (e) {
|
||||
toastErr(e.message || '保存失败')
|
||||
} finally {
|
||||
saving.value = false
|
||||
}
|
||||
}
|
||||
|
||||
async function onPickAvatar(ev) {
|
||||
const file = ev.target.files && ev.target.files[0]
|
||||
ev.target.value = '' // 允许连续选同一个文件
|
||||
if (!file) return
|
||||
uploading.value = true
|
||||
try {
|
||||
const data = await adminApi.uploadFile(file)
|
||||
const f = Array.isArray(data) ? data[0] : null
|
||||
if (!f || !f.key) throw new Error('上传失败')
|
||||
await save({ avatar_key: f.key })
|
||||
} catch (e) {
|
||||
toastErr(e.message || '头像上传失败')
|
||||
} finally {
|
||||
uploading.value = false
|
||||
}
|
||||
}
|
||||
|
||||
async function removeAvatar() {
|
||||
await save({ avatar_key: '' })
|
||||
}
|
||||
|
||||
function startBind(provider) {
|
||||
// 整页跳转:OAuth 回来后由后端重定向回本页并带 ?bound=
|
||||
window.location.assign('/api/auth/' + provider + '/bind')
|
||||
}
|
||||
|
||||
async function unbind(provider) {
|
||||
const label = provider === 'github' ? 'GitHub' : provider
|
||||
if (!window.confirm('解绑 ' + label + '?之后就不能再用它登录后台了。')) return
|
||||
try {
|
||||
await adminApi.unbindIdentity(provider)
|
||||
toastOk('已解绑')
|
||||
await load()
|
||||
} catch (e) {
|
||||
toastErr(e.message || '解绑失败')
|
||||
}
|
||||
}
|
||||
|
||||
async function addPasskey() {
|
||||
if (!waSupported()) {
|
||||
toastErr('这个浏览器不支持 passkey')
|
||||
return
|
||||
}
|
||||
const name = window.prompt('给这把凭据起个名字(如「MacBook 指纹」)', '')
|
||||
if (name === null) return
|
||||
regBusy.value = true
|
||||
try {
|
||||
const { options, token } = await adminApi.passkeyBegin()
|
||||
const cred = await waRegister(options)
|
||||
await adminApi.passkeyFinish({ token, name: name.trim(), credential: cred })
|
||||
toastOk('passkey 已添加')
|
||||
await load()
|
||||
} catch (e) {
|
||||
toastErr(e.message || 'passkey 注册失败')
|
||||
} finally {
|
||||
regBusy.value = false
|
||||
}
|
||||
}
|
||||
|
||||
async function removePasskey(pk) {
|
||||
if (!window.confirm('删除 passkey「' + (pk.name || '未命名') + '」?')) return
|
||||
try {
|
||||
await adminApi.deletePasskey(pk.id)
|
||||
toastOk('已删除')
|
||||
await load()
|
||||
} catch (e) {
|
||||
toastErr(e.message || '删除失败')
|
||||
}
|
||||
}
|
||||
|
||||
function fmtDate(s) {
|
||||
if (!s) return ''
|
||||
const d = new Date(s)
|
||||
return Number.isNaN(d.getTime()) ? s : d.toLocaleDateString('zh-CN')
|
||||
}
|
||||
|
||||
const providerLabel = { github: 'GitHub', google: 'Google', telegram: 'Telegram' }
|
||||
|
||||
onMounted(async () => {
|
||||
await load()
|
||||
reportBindResult()
|
||||
})
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<section v-if="loading" class="loading">载入中…</section>
|
||||
<section v-else-if="acct">
|
||||
<h1 style="font-family: var(--serif); font-size: 22px; margin-bottom: 4px;">账户</h1>
|
||||
<p class="field-hint" style="margin-bottom: 20px;">
|
||||
头像、昵称与登录方式。站点标题、皮肤这些站点级配置在
|
||||
<router-link to="/admin/settings">设置</router-link>。
|
||||
</p>
|
||||
|
||||
<!-- ---------- 资料 ---------- -->
|
||||
<div class="panel">
|
||||
<div class="panel-title"><h2>公开资料</h2></div>
|
||||
|
||||
<div class="field">
|
||||
<label>头像</label>
|
||||
<div class="avatar-row">
|
||||
<span class="avatar-box">
|
||||
<img v-if="acct.avatar_url" :src="acct.avatar_url" alt="" />
|
||||
<span v-else class="avatar-ph">无</span>
|
||||
</span>
|
||||
<div class="avatar-acts">
|
||||
<input ref="fileInput" type="file" accept="image/png,image/jpeg,image/gif" hidden @change="onPickAvatar" />
|
||||
<button class="btn" :disabled="uploading" @click="fileInput.click()">
|
||||
{{ uploading ? '上传中…' : (acct.avatar_key ? '换一个' : '上传头像') }}
|
||||
</button>
|
||||
<button v-if="acct.avatar_key" class="btn" :disabled="saving" @click="removeAvatar">移除</button>
|
||||
</div>
|
||||
</div>
|
||||
<p class="field-hint">
|
||||
头像会出现在时间线、文章页与关于页。没设置时那些位置显示站标。
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label>昵称</label>
|
||||
<input v-model="acct.name" class="input" maxlength="40" spellcheck="false" />
|
||||
<p class="field-hint">评论区与文章署名用的名字。</p>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label>简介</label>
|
||||
<textarea v-model="acct.bio" class="textarea" rows="2" maxlength="200" />
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<label>用户名(handle)</label>
|
||||
<input :value="acct.handle" class="input" disabled />
|
||||
<p class="field-hint">
|
||||
由环境变量 <code>ONE_ADMIN_USER</code> 决定,不在这里改 ——
|
||||
它是账号的身份锚点,改了要连密码一起换。
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<button class="btn btn-primary" :disabled="saving" @click="save({ name: acct.name, bio: acct.bio })">
|
||||
{{ saving ? '保存中…' : '保存资料' }}
|
||||
</button>
|
||||
</div>
|
||||
|
||||
<!-- ---------- 登录方式 ---------- -->
|
||||
<div class="panel" style="margin-top: 18px;">
|
||||
<div class="panel-title"><h2>登录方式</h2></div>
|
||||
|
||||
<div class="method">
|
||||
<div class="method-head">
|
||||
<b>密码</b>
|
||||
<span class="tag on">始终可用</span>
|
||||
</div>
|
||||
<p class="field-hint">
|
||||
站主密码由环境变量 <code>ONE_ADMIN_PASSWORD</code> 管理,不存在数据库里,
|
||||
因此也就无法在这里被改掉或解绑。这条退路保证:哪怕解绑了所有第三方、
|
||||
删光所有 passkey,你仍然能登录进来。
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="method">
|
||||
<div class="method-head">
|
||||
<b>第三方账号</b>
|
||||
<span v-if="acct.identities.length" class="tag on">已绑定 {{ acct.identities.length }}</span>
|
||||
<span v-else class="tag">未绑定</span>
|
||||
</div>
|
||||
<ul v-if="acct.identities.length" class="list">
|
||||
<li v-for="it in acct.identities" :key="it.id">
|
||||
<span>{{ providerLabel[it.provider] || it.provider }}</span>
|
||||
<code>{{ it.display }}</code>
|
||||
<span class="when">绑于 {{ fmtDate(it.created_at) }}</span>
|
||||
<button class="btn btn-sm" @click="unbind(it.provider)">解绑</button>
|
||||
</li>
|
||||
</ul>
|
||||
<p v-else class="field-hint">还没有绑定任何第三方账号。</p>
|
||||
<div v-if="acct.providers.length" class="bind-acts">
|
||||
<button
|
||||
v-for="p in acct.providers"
|
||||
:key="p"
|
||||
class="btn btn-sm"
|
||||
:disabled="acct.identities.some((i) => i.provider === p)"
|
||||
@click="startBind(p)"
|
||||
>
|
||||
绑定 {{ providerLabel[p] || p }}
|
||||
</button>
|
||||
</div>
|
||||
<p class="field-hint">
|
||||
绑定后,用该账号 OAuth 登录会<b>直接进入后台</b>(等于站主身份)。
|
||||
所以绑定动作必须在已登录后台时发起,且一个外部账号只能属于一个用户。
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<div class="method">
|
||||
<div class="method-head">
|
||||
<b>Passkey</b>
|
||||
<span v-if="acct.passkeys.length" class="tag on">{{ acct.passkeys.length }} 把</span>
|
||||
<span v-else class="tag">未添加</span>
|
||||
</div>
|
||||
<ul v-if="acct.passkeys.length" class="list">
|
||||
<li v-for="pk in acct.passkeys" :key="pk.id">
|
||||
<span>{{ pk.name || '未命名设备' }}</span>
|
||||
<span class="when">
|
||||
加于 {{ fmtDate(pk.created_at) }}<template v-if="pk.last_used_at"> · 上次用 {{ fmtDate(pk.last_used_at) }}</template>
|
||||
</span>
|
||||
<button class="btn btn-sm" @click="removePasskey(pk)">删除</button>
|
||||
</li>
|
||||
</ul>
|
||||
<button class="btn btn-sm" :disabled="regBusy" @click="addPasskey">
|
||||
{{ regBusy ? '等待浏览器…' : '添加 passkey' }}
|
||||
</button>
|
||||
<p class="field-hint">
|
||||
用设备指纹 / 面容 / 安全密钥登录,无需密码,也无需先输用户名。
|
||||
<template v-if="!acct.passkeys.length && !acct.providers.length">
|
||||
服务端需配置 <code>ONE_WEBAUTHN_ORIGINS</code> 才会开放此入口。
|
||||
</template>
|
||||
</p>
|
||||
</div>
|
||||
</div>
|
||||
</section>
|
||||
</template>
|
||||
|
||||
<style scoped>
|
||||
.avatar-row {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 14px;
|
||||
}
|
||||
.avatar-box {
|
||||
width: 64px;
|
||||
height: 64px;
|
||||
border-radius: 50%;
|
||||
overflow: hidden;
|
||||
background: var(--admin-sunken, #f3efe6);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
flex: none;
|
||||
}
|
||||
.avatar-box img {
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
object-fit: cover;
|
||||
display: block;
|
||||
}
|
||||
.avatar-ph {
|
||||
font-size: 12px;
|
||||
color: var(--admin-muted);
|
||||
}
|
||||
.avatar-acts {
|
||||
display: flex;
|
||||
gap: 8px;
|
||||
flex-wrap: wrap;
|
||||
}
|
||||
.method {
|
||||
padding: 14px 0;
|
||||
border-top: 1px solid var(--admin-line, #e6e0d4);
|
||||
}
|
||||
.method:first-of-type {
|
||||
border-top: 0;
|
||||
padding-top: 0;
|
||||
}
|
||||
.method-head {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 10px;
|
||||
margin-bottom: 6px;
|
||||
}
|
||||
.tag {
|
||||
font-size: 11px;
|
||||
padding: 1px 7px;
|
||||
border-radius: 999px;
|
||||
border: 1px solid var(--admin-line, #e6e0d4);
|
||||
color: var(--admin-muted);
|
||||
}
|
||||
.tag.on {
|
||||
border-color: var(--accent-line, rgba(61, 127, 156, 0.35));
|
||||
color: var(--admin-accent, #3d7f9c);
|
||||
}
|
||||
.list {
|
||||
list-style: none;
|
||||
margin: 0 0 10px;
|
||||
padding: 0;
|
||||
}
|
||||
.list li {
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 10px;
|
||||
padding: 7px 0;
|
||||
font-size: 13.5px;
|
||||
}
|
||||
.list code {
|
||||
font-size: 12px;
|
||||
color: var(--admin-muted);
|
||||
}
|
||||
.when {
|
||||
margin-left: auto;
|
||||
font-size: 12px;
|
||||
color: var(--admin-muted);
|
||||
}
|
||||
.bind-acts {
|
||||
display: flex;
|
||||
gap: 8px;
|
||||
margin: 8px 0;
|
||||
}
|
||||
.btn-sm {
|
||||
padding: 4px 12px;
|
||||
font-size: 12.5px;
|
||||
}
|
||||
</style>
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, onBeforeUnmount, ref, watch } from 'vue'
|
||||
import ToastStack from './ToastStack.vue'
|
||||
import { useRoute, useRouter, RouterLink, RouterView } from 'vue-router'
|
||||
import { checkAuth } from './auth'
|
||||
import { adminApi, session } from '../api'
|
||||
@@ -96,6 +97,7 @@ watch(() => route.path, () => loadCounts())
|
||||
|
||||
<template>
|
||||
<div v-if="ready" class="admin-shell">
|
||||
<ToastStack />
|
||||
<aside class="admin-side">
|
||||
<div class="brand">
|
||||
<RouterLink to="/admin" class="name">{{ site.site_title || 'ONE' }}</RouterLink>
|
||||
@@ -138,6 +140,10 @@ watch(() => route.path, () => loadCounts())
|
||||
<span class="ic">⚙</span>
|
||||
<span>设置</span>
|
||||
</RouterLink>
|
||||
<RouterLink to="/admin/account" class="item">
|
||||
<span class="ic">◉</span>
|
||||
<span>账户</span>
|
||||
</RouterLink>
|
||||
<div class="group">前台</div>
|
||||
<a href="/" target="_blank" class="item">
|
||||
<span class="ic">↗</span>
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, ref, watch } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { useRoute, useRouter } from 'vue-router'
|
||||
import { adminApi } from '../api'
|
||||
import { relativeDate, stripTags } from '../utils'
|
||||
@@ -46,12 +47,14 @@ function setStatus(v) {
|
||||
|
||||
async function approve(id) {
|
||||
await adminApi.approveComment(id)
|
||||
toastOk('已通过,前台可见')
|
||||
load()
|
||||
}
|
||||
|
||||
async function remove(id) {
|
||||
if (!window.confirm('删除这条评论?正文清空,楼层保留为「已删除」。')) return
|
||||
await adminApi.deleteComment(id)
|
||||
toastOk('已删除')
|
||||
load()
|
||||
}
|
||||
|
||||
@@ -59,6 +62,7 @@ async function banToggle(c) {
|
||||
const banned = !c.user?.banned
|
||||
if (!window.confirm(banned ? `禁言「${c.user?.name || '该用户'}」?禁言后其无法再发表评论。` : '解除禁言?')) return
|
||||
await adminApi.setReaderBanned(c.user?.id, banned)
|
||||
toastOk(banned ? '已禁言' : '已解除禁言')
|
||||
c.user = { ...(c.user || {}), banned }
|
||||
}
|
||||
|
||||
|
||||
@@ -1,10 +1,16 @@
|
||||
<script setup>
|
||||
import { computed, nextTick, onBeforeUnmount, onMounted, reactive, ref, watch } from 'vue'
|
||||
import { toast, toastOk, toastErr, toastUpdate, toastDone } from './toast'
|
||||
import { onBeforeRouteLeave, useRoute, useRouter } from 'vue-router'
|
||||
import { adminApi } from '../api'
|
||||
import { site } from '../site'
|
||||
import { Crepe, CrepeFeature } from '@milkdown/crepe'
|
||||
import '@milkdown/crepe/theme/common/style.css'
|
||||
import '@milkdown/crepe/theme/frame.css'
|
||||
import { EditorView as CMView, keymap } from '@codemirror/view'
|
||||
import { EditorState } from '@codemirror/state'
|
||||
import { markdown as markdownLang } from '@codemirror/lang-markdown'
|
||||
import { history, defaultKeymap, historyKeymap, indentWithTab } from '@codemirror/commands'
|
||||
|
||||
const route = useRoute()
|
||||
const router = useRouter()
|
||||
@@ -184,6 +190,10 @@ onBeforeUnmount(() => {
|
||||
crepe.destroy()
|
||||
crepe = null
|
||||
}
|
||||
if (cmView) {
|
||||
cmView.destroy()
|
||||
cmView = null
|
||||
}
|
||||
})
|
||||
|
||||
// ---------- mode switching ----------
|
||||
@@ -195,6 +205,10 @@ async function switchMode(next) {
|
||||
crepe.destroy()
|
||||
crepe = null
|
||||
}
|
||||
// CM 懒挂载;已挂载就把 wysiwyg 期间产生的 markdown 灌回来
|
||||
await nextTick()
|
||||
mountCM()
|
||||
syncCM()
|
||||
} else {
|
||||
// MD → WYSIWYG: spin up crepe with the current markdown
|
||||
await nextTick()
|
||||
@@ -267,6 +281,9 @@ async function autosave() {
|
||||
function applySaved(saved) {
|
||||
form.slug = saved.slug
|
||||
form.status = saved.status
|
||||
// 自动摘要/自动封面在服务端补齐的,回写表单让站主看见(清空仍会保留为空)
|
||||
if (typeof saved.summary === 'string') form.summary = saved.summary
|
||||
if (typeof saved.cover_url === 'string') form.cover_url = saved.cover_url
|
||||
publishedLocal.value = isoToLocal(saved.published_at)
|
||||
}
|
||||
|
||||
@@ -303,7 +320,7 @@ function buildPayload() {
|
||||
async function save(status) {
|
||||
if (status) form.status = status
|
||||
if (!isEdit.value && !form.content_md.trim() && !form.title.trim()) {
|
||||
error.value = '先写点什么再保存'
|
||||
toastErr('先写点什么再保存')
|
||||
return
|
||||
}
|
||||
saving.value = true
|
||||
@@ -317,12 +334,17 @@ async function save(status) {
|
||||
const created = await adminApi.createPost(payload)
|
||||
localStorage.removeItem(DRAFT_KEY)
|
||||
dirty.value = false
|
||||
toastOk('已创建')
|
||||
router.replace(`/admin/${created.id}`)
|
||||
return
|
||||
}
|
||||
dirty.value = false
|
||||
savedAt.value = new Date().toLocaleTimeString('zh-CN', { hour12: false })
|
||||
// 手动保存(按钮/⌘S/发布)给回音;自动保存静默,不打扰
|
||||
const label = status === 'published' ? '已发布' : status === 'draft' ? '已转回草稿' : '已保存'
|
||||
toastOk(label + ' · ' + savedAt.value)
|
||||
} catch (e) {
|
||||
toastErr(e.message || '保存失败')
|
||||
error.value = e.message || '保存失败'
|
||||
} finally {
|
||||
saving.value = false
|
||||
@@ -365,6 +387,14 @@ onBeforeRouteLeave(() => {
|
||||
|
||||
// ---------- 标签 ----------
|
||||
|
||||
// 标签是长文的组织方式;切到短文时把已选的清掉(后端落库时也会强制丢弃)
|
||||
watch(
|
||||
() => form.kind,
|
||||
(k) => {
|
||||
if (k === 'short') form.tags = []
|
||||
}
|
||||
)
|
||||
|
||||
function addTag() {
|
||||
const v = tagInput.value.trim().replace(/[,,]$/, '')
|
||||
if (!v) return
|
||||
@@ -391,6 +421,82 @@ function clearCover() {
|
||||
// ---------- 工具栏:Markdown 模式插入 + 通用动作 ----------
|
||||
|
||||
const mdPane = ref(null)
|
||||
|
||||
// ---------- CodeMirror 源码模式 ----------
|
||||
// md 页签不是裸 textarea:语法高亮 + 行内历史(⌘Z),粘贴/拖图片直接上传。
|
||||
// markdown 仍是唯一真相源——CM 的改动写回 form.content_md,
|
||||
// 外部改动(转存替换、wysiwyg 切回)用 syncCM 全量灌回。
|
||||
let cmView = null
|
||||
const cmTheme = CMView.theme({
|
||||
'&': { color: 'var(--admin-ink)', backgroundColor: 'transparent', fontSize: '13.5px' },
|
||||
'.cm-content': { fontFamily: 'ui-monospace, SFMono-Regular, Menlo, monospace', lineHeight: '1.75', padding: '12px 0 40vh' },
|
||||
'.cm-scroller': { overflow: 'auto', maxHeight: '70vh' },
|
||||
'.cm-line': { padding: '0 2px' },
|
||||
'&.cm-focused': { outline: 'none' },
|
||||
'.cm-cursor': { borderLeftColor: 'var(--admin-accent)' },
|
||||
'.cm-selectionBackground, ::selection': { backgroundColor: 'color-mix(in srgb, var(--admin-accent) 18%, transparent) !important' },
|
||||
'.cm-activeLine': { backgroundColor: 'color-mix(in srgb, var(--admin-accent) 6%, transparent)' },
|
||||
'.cm-heading, .cm-header': { color: 'var(--admin-accent)', fontWeight: '600' },
|
||||
'.cm-link, .cm-url': { color: 'var(--admin-accent)', textDecoration: 'underline' },
|
||||
'.cm-emphasis': { fontStyle: 'italic' },
|
||||
'.cm-strong': { fontWeight: '700' },
|
||||
'.cm-code, .cm-monospace': { fontFamily: 'ui-monospace, SFMono-Regular, Menlo, monospace', color: 'var(--admin-muted)' }
|
||||
})
|
||||
|
||||
function handleEditorFiles(files, view) {
|
||||
const list = [...files].filter((f) => f.type.startsWith('image/'))
|
||||
if (!list.length) return false
|
||||
view.dispatch({
|
||||
changes: { from: view.state.selection.main.from, insert: ' ' }
|
||||
})
|
||||
;[...list].forEach((f) => uploadOne(f, { insertImage: true }))
|
||||
return true
|
||||
}
|
||||
|
||||
function mountCM() {
|
||||
if (cmView || !mdPane.value) return
|
||||
cmView = new CMView({
|
||||
parent: mdPane.value,
|
||||
state: EditorState.create({
|
||||
doc: form.content_md,
|
||||
extensions: [
|
||||
history(),
|
||||
keymap.of([
|
||||
{ key: 'Mod-b', run: () => { tbBold(); return true } },
|
||||
{ key: 'Mod-i', run: () => { tbItalic(); return true } },
|
||||
{ key: 'Mod-e', run: () => { tbCode(); return true } },
|
||||
{ key: 'Mod-k', run: () => { openLink(); return true } }
|
||||
]),
|
||||
keymap.of([...defaultKeymap, ...historyKeymap, indentWithTab]),
|
||||
markdownLang(),
|
||||
cmTheme,
|
||||
CMView.updateListener.of((u) => {
|
||||
if (u.docChanged) form.content_md = u.state.doc.toString()
|
||||
}),
|
||||
CMView.domEventHandlers({
|
||||
paste: (e, view) => handleEditorFiles(e.clipboardData?.files, view),
|
||||
drop: (e, view) => {
|
||||
if (e.dataTransfer?.files?.length) {
|
||||
e.preventDefault()
|
||||
return handleEditorFiles(e.dataTransfer.files, view)
|
||||
}
|
||||
return false
|
||||
}
|
||||
})
|
||||
]
|
||||
})
|
||||
})
|
||||
}
|
||||
|
||||
// 用 form.content_md 的当前值整段灌回(进入 md 页签、转存替换后调用)
|
||||
function syncCM() {
|
||||
if (!cmView) return
|
||||
const cur = cmView.state.doc.toString()
|
||||
if (cur === form.content_md) return
|
||||
cmView.dispatch({
|
||||
changes: { from: 0, to: cur.length, insert: form.content_md }
|
||||
})
|
||||
}
|
||||
const showLinkInput = ref(false)
|
||||
const showImageInput = ref(false)
|
||||
const linkText = ref('')
|
||||
@@ -399,22 +505,31 @@ const imageUrl = ref('')
|
||||
const imageAlt = ref('')
|
||||
|
||||
function insertAtCursor(text, selStart, selEnd) {
|
||||
if (cmView) {
|
||||
if (selStart == null) {
|
||||
const s = cmView.state.selection.main
|
||||
selStart = s.from
|
||||
selEnd = s.to
|
||||
}
|
||||
cmView.dispatch({
|
||||
changes: { from: selStart, to: selEnd, insert: text },
|
||||
selection: { anchor: selStart + text.length }
|
||||
})
|
||||
cmView.focus()
|
||||
return
|
||||
}
|
||||
const before = form.content_md.slice(0, selStart)
|
||||
const after = form.content_md.slice(selEnd)
|
||||
form.content_md = before + text + after
|
||||
nextTick(() => {
|
||||
if (!mdPane.value) return
|
||||
const newPos = selStart + text.length
|
||||
mdPane.value.focus()
|
||||
mdPane.value.setSelectionRange(newPos, newPos)
|
||||
})
|
||||
}
|
||||
|
||||
function withSelection(fn) {
|
||||
const el = mdPane.value
|
||||
const start = el ? el.selectionStart : form.content_md.length
|
||||
const end = el ? el.selectionEnd : form.content_md.length
|
||||
fn(start, end)
|
||||
if (cmView) {
|
||||
const sel = cmView.state.selection.main
|
||||
fn(sel.from, sel.to)
|
||||
return
|
||||
}
|
||||
fn(form.content_md.length, form.content_md.length)
|
||||
}
|
||||
|
||||
function tbBold() {
|
||||
@@ -499,6 +614,15 @@ function tbTask() {
|
||||
function tbHr() {
|
||||
withSelection((s, e) => insertAtCursor('\n---\n', s, e))
|
||||
}
|
||||
function tbTable() {
|
||||
withSelection((s, e) =>
|
||||
insertAtCursor(
|
||||
'\n| 列 A | 列 B |\n| --- | --- |\n| 内容 | 内容 |\n| 内容 | 内容 |\n',
|
||||
s,
|
||||
e
|
||||
)
|
||||
)
|
||||
}
|
||||
|
||||
function openLink() {
|
||||
showLinkInput.value = true
|
||||
@@ -526,23 +650,110 @@ function commitImage() {
|
||||
}
|
||||
|
||||
// ---------- 上传(封面 / 编辑器插图共用) ----------
|
||||
// toast 用共享的 ./toast(ToastStack 渲染在 AdminLayout)。
|
||||
// 后台「高级 → 自定义 JS」无关;走 /api/admin/files(FormData)。
|
||||
const uploadingImage = ref(false)
|
||||
|
||||
async function uploadOne(file) {
|
||||
const fd = new FormData()
|
||||
fd.append('file', file)
|
||||
// 与后端 allowFileExt / 50MB 上限一致:上传前本地校验,省一趟白跑
|
||||
const ALLOW_UPLOAD_EXT = ['jpg', 'jpeg', 'png', 'webp', 'gif', 'avif', 'pdf', 'zip', 'txt']
|
||||
const MAX_UPLOAD_MB = 50
|
||||
|
||||
function validateFile(file) {
|
||||
const ext = (file.name.split('.').pop() || '').toLowerCase()
|
||||
if (!ALLOW_UPLOAD_EXT.includes(ext)) {
|
||||
return `不支持的类型 .${ext}(允许:${ALLOW_UPLOAD_EXT.join('/')})`
|
||||
}
|
||||
if (file.size > MAX_UPLOAD_MB * 1024 * 1024) {
|
||||
return `${file.name} 超过 ${MAX_UPLOAD_MB}MB 上限`
|
||||
}
|
||||
return ''
|
||||
}
|
||||
|
||||
// opts.cmView 传了就把结果以 markdown 图片插到该编辑器光标处(md 页签粘贴/拖拽)
|
||||
async function uploadOne(file, opts = {}) {
|
||||
const bad = validateFile(file)
|
||||
if (bad) {
|
||||
toast(bad, 'err')
|
||||
throw new Error(bad)
|
||||
}
|
||||
const tid = toast(`上传 ${file.name} 0%`, 'info', 60000)
|
||||
try {
|
||||
const data = await adminApi.uploadFiles(fd)
|
||||
const data = await adminApi.uploadFile(file, (p) =>
|
||||
toastUpdate(tid, `上传 ${file.name} ${Math.round(p * 100)}%`)
|
||||
)
|
||||
const f = Array.isArray(data) ? data[0] : null
|
||||
if (!f || !f.url) throw new Error('上传失败')
|
||||
toastDone(tid, `${file.name} 上传完成`)
|
||||
if (opts.cmView) {
|
||||
const v = opts.cmView
|
||||
const pos = v.state.selection.main.from
|
||||
v.dispatch({ changes: { from: pos, insert: `\n` } })
|
||||
}
|
||||
return f.url
|
||||
} catch (e) {
|
||||
toastUpdate(tid, `${file.name} 上传失败:${e.message || '未知错误'}`, 'err')
|
||||
error.value = e.message || '上传失败'
|
||||
throw e
|
||||
}
|
||||
}
|
||||
|
||||
// ---------- 外链图片转存 ----------
|
||||
// xLog 的 Cloud:正文里的外链 <img> 一键抓回自己的存储(后端走 SSRF
|
||||
// 防护拨号 + 同一套白名单/去重),成功后原地替换 markdown 里的 URL。
|
||||
const importing = ref(false)
|
||||
|
||||
function externalImages(md) {
|
||||
const own = [site.uploads_public_base, location.origin].filter(Boolean)
|
||||
const out = []
|
||||
const re = /!\[[^\]]*\]\((https?:\/\/[^)\s]+)\)/g
|
||||
let m
|
||||
while ((m = re.exec(md))) {
|
||||
const u = m[1]
|
||||
if (!own.some((b) => u.startsWith(b)) && !u.startsWith('/uploads/')) out.push(u)
|
||||
}
|
||||
return [...new Set(out)]
|
||||
}
|
||||
|
||||
async function importExternal() {
|
||||
if (importing.value) return
|
||||
const urls = externalImages(form.content_md)
|
||||
if (!urls.length) {
|
||||
toast('正文里没有外链图片', 'info')
|
||||
return
|
||||
}
|
||||
importing.value = true
|
||||
const tid = toast(`转存外链图片 0/${urls.length}…`, 'info', 120000)
|
||||
try {
|
||||
const data = await adminApi.importFiles(urls)
|
||||
// 后端按原址回:source -> 转存后的文件(同内容去重时可能是已有行)
|
||||
const ok = new Map((data.files || []).map((e) => [e.source, e.file]))
|
||||
const errs = data.errors || {}
|
||||
let done = 0
|
||||
let changed = false
|
||||
form.content_md = form.content_md.replace(
|
||||
/!\[([^\]]*)\]\((https?:\/\/[^)\s]+)\)/g,
|
||||
(whole, alt, u) => {
|
||||
if (!ok.has(u)) return whole
|
||||
done++
|
||||
toastUpdate(tid, `转存外链图片 ${done}/${urls.length}…`)
|
||||
changed = true
|
||||
return `.url})`
|
||||
}
|
||||
)
|
||||
if (changed) syncCM()
|
||||
const fail = Object.keys(errs).length
|
||||
if (fail) {
|
||||
toastUpdate(tid, `转存完成:${done} 成功,${fail} 失败(${Object.values(errs)[0]})`, fail ? 'err' : 'ok')
|
||||
} else {
|
||||
toastDone(tid, `转存完成:${done} 张已入自己的存储`)
|
||||
}
|
||||
} catch (e) {
|
||||
toastUpdate(tid, '转存失败:' + (e.message || ''), 'err')
|
||||
} finally {
|
||||
importing.value = false
|
||||
}
|
||||
}
|
||||
|
||||
const coverInput = ref(null)
|
||||
async function onCoverPick(e) {
|
||||
const file = e.target.files && e.target.files[0]
|
||||
@@ -610,15 +821,29 @@ function insertDate() {
|
||||
}
|
||||
|
||||
// 工具栏按钮的统一定义(用作 v-for 渲染)
|
||||
// 快捷键的展示形态(xLog 同款):Mod 在 Mac 上显示 ⌘,其余显示 Ctrl
|
||||
const isMac = typeof navigator !== 'undefined' && /Mac|iP(hone|ad|od)/.test(navigator.platform || '')
|
||||
function keyDisplay(shortcut) {
|
||||
if (!shortcut) return ''
|
||||
return '(' + shortcut
|
||||
.replace('Mod', isMac ? '⌘' : 'Ctrl')
|
||||
.replace(/-([a-z])$/i, (_, c) => c.toUpperCase()) + ')'
|
||||
}
|
||||
|
||||
const tbGroups = computed(() => [
|
||||
{
|
||||
label: '格式',
|
||||
items: [
|
||||
{ key: 'b', label: 'B', title: '加粗', run: tbBold, show: mode.value === 'md' },
|
||||
{ key: 'i', label: 'I', title: '斜体', run: tbItalic, italic: true, show: mode.value === 'md' },
|
||||
{ key: 's', label: 'S', title: '删除线', run: tbStrike, show: mode.value === 'md' },
|
||||
{ key: 'code', label: '<>', title: '行内代码', run: tbCode, mono: true, show: mode.value === 'md' },
|
||||
{ key: 'cb', label: '```', title: '代码块', run: tbCodeBlock, mono: true, show: mode.value === 'md' }
|
||||
{ key: 'b', title: '加粗', shortcut: 'Mod-b', run: tbBold, show: mode.value === 'md',
|
||||
icon: 'M6 4h8a4 4 0 0 1 0 8H6zM6 12h9a4 4 0 0 1 0 8H6z', fill: true },
|
||||
{ key: 'i', title: '斜体', shortcut: 'Mod-i', run: tbItalic, show: mode.value === 'md',
|
||||
icon: 'M19 4h-9M14 20H5M15 4L9 20' },
|
||||
{ key: 's', title: '删除线', run: tbStrike, show: mode.value === 'md',
|
||||
icon: 'M16 4H9a3 3 0 0 0-2.83 4M14 12a4 4 0 0 1 0 8H6M4 12h16' },
|
||||
{ key: 'code', title: '行内代码', shortcut: 'Mod-e', run: tbCode, show: mode.value === 'md',
|
||||
icon: 'M16 18l6-6-6-6M8 6l-6 6 6 6' },
|
||||
{ key: 'cb', title: '代码块', run: tbCodeBlock, show: mode.value === 'md',
|
||||
icon: 'M9 10l-2 2.5L9 15M15 10l2 2.5-2 2.5M4 5h16a1 1 0 0 1 1 1v12a1 1 0 0 1-1 1H4a1 1 0 0 1-1-1V6a1 1 0 0 1 1-1z' }
|
||||
]
|
||||
},
|
||||
{
|
||||
@@ -626,19 +851,29 @@ const tbGroups = computed(() => [
|
||||
items: [
|
||||
{ key: 'h2', label: 'H2', title: '二级标题', run: tbH2, show: mode.value === 'md' },
|
||||
{ key: 'h3', label: 'H3', title: '三级标题', run: tbH3, show: mode.value === 'md' },
|
||||
{ key: 'q', label: '"', title: '引用', run: tbQuote, show: mode.value === 'md' },
|
||||
{ key: 'ul', label: '•', title: '无序列表', run: tbUl, show: mode.value === 'md' },
|
||||
{ key: 'ol', label: '1.', title: '有序列表', run: tbOl, show: mode.value === 'md' },
|
||||
{ key: 'task', label: '☐', title: '任务列表', run: tbTask, show: mode.value === 'md' },
|
||||
{ key: 'hr', label: '—', title: '分隔线', run: tbHr, show: mode.value === 'md' }
|
||||
{ key: 'q', title: '引用', run: tbQuote, show: mode.value === 'md',
|
||||
icon: 'M3 21c3 0 7-1 7-8V5c0-1.25-.76-2.02-2-2H4c-1.25 0-2 .75-2 1.97V11c0 1.25.75 2 2 2 1 0 1 0 1 1v1c0 1-1 2-2 2s-1 .01-1 1.03V20c0 1 0 1 1 1zM15 21c3 0 7-1 7-8V5c0-1.25-.76-2.02-2-2h-4c-1.25 0-2 .75-2 1.97V11c0 1.25.75 2 2 2 1 0 1 0 1 1v1c0 1-1 2-2 2s-1 .01-1 1.03V20c0 1 0 1 1 1z', fill: true },
|
||||
{ key: 'ul', title: '无序列表', run: tbUl, show: mode.value === 'md',
|
||||
icon: 'M8 6h13M8 12h13M8 18h13M3 6h.01M3 12h.01M3 18h.01' },
|
||||
{ key: 'ol', title: '有序列表', run: tbOl, show: mode.value === 'md',
|
||||
icon: 'M10 6h11M10 12h11M10 18h11M4 6h1v4M4 10h2M6 18H4c0-1 2-2 2-3s-1-1.5-2-1' },
|
||||
{ key: 'task', title: '任务列表', run: tbTask, show: mode.value === 'md',
|
||||
icon: 'M9 11l3 3L22 4M21 12v7a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V5a2 2 0 0 1 2-2h11' },
|
||||
{ key: 'hr', title: '分隔线', run: tbHr, show: mode.value === 'md',
|
||||
icon: 'M5 12h14' }
|
||||
]
|
||||
},
|
||||
{
|
||||
label: '插入',
|
||||
items: [
|
||||
{ key: 'link', label: '🔗', title: '链接', run: openLink, show: mode.value === 'md' },
|
||||
{ key: 'img', label: '🖼', title: '图片', run: openImage, show: mode.value === 'md' },
|
||||
{ key: 'date', label: '📅', title: '插入今天日期', run: insertDate, show: mode.value === 'md' }
|
||||
{ key: 'link', title: '链接', shortcut: 'Mod-k', run: openLink, show: mode.value === 'md',
|
||||
icon: 'M10 13a5 5 0 0 0 7.54.54l3-3a5 5 0 0 0-7.07-7.07l-1.72 1.71M14 11a5 5 0 0 0-7.54-.54l-3 3a5 5 0 0 0 7.07 7.07l1.71-1.71' },
|
||||
{ key: 'img', title: '图片', run: openImage, show: mode.value === 'md',
|
||||
icon: 'M21 15l-5-5L5 21M3 5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2zM8.5 8.5h.01' },
|
||||
{ key: 'table', title: '表格', run: tbTable, show: mode.value === 'md',
|
||||
icon: 'M3 5a2 2 0 0 1 2-2h14a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2zM3 10h18M10 21V10' },
|
||||
{ key: 'date', title: '插入今天日期', run: insertDate, show: mode.value === 'md',
|
||||
icon: 'M16 2v4M8 2v4M3 10h18M5 4h14a2 2 0 0 1 2 2v14a2 2 0 0 1-2 2H5a2 2 0 0 1-2-2V6a2 2 0 0 1 2-2z' }
|
||||
]
|
||||
}
|
||||
])
|
||||
@@ -685,6 +920,14 @@ const tbGroups = computed(() => [
|
||||
<div class="editor-mode">
|
||||
<button :class="{ on: mode === 'wysiwyg' }" @click="switchMode('wysiwyg')">富文本</button>
|
||||
<button :class="{ on: mode === 'md' }" @click="switchMode('md')">Markdown</button>
|
||||
<button
|
||||
class="btn"
|
||||
:disabled="importing"
|
||||
title="把正文里的外链图片抓回自己的存储"
|
||||
@click="importExternal"
|
||||
>
|
||||
{{ importing ? '转存中…' : '⇲ 转存外链图' }}
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -704,11 +947,18 @@ const tbGroups = computed(() => [
|
||||
:key="it.key"
|
||||
type="button"
|
||||
class="tb-btn"
|
||||
:class="{ italic: it.italic, mono: it.mono }"
|
||||
:title="it.title"
|
||||
:title="it.title + keyDisplay(it.shortcut)"
|
||||
:aria-label="it.title"
|
||||
@click="it.run()"
|
||||
>{{ it.label }}</button>
|
||||
>
|
||||
<svg v-if="it.icon" viewBox="0 0 24 24" aria-hidden="true"
|
||||
:fill="it.fill ? 'currentColor' : 'none'"
|
||||
:stroke="it.fill ? 'none' : 'currentColor'" stroke-width="2"
|
||||
stroke-linecap="round" stroke-linejoin="round">
|
||||
<path :d="it.icon" />
|
||||
</svg>
|
||||
<span v-else class="tb-text">{{ it.label }}</span>
|
||||
</button>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
@@ -767,16 +1017,13 @@ const tbGroups = computed(() => [
|
||||
|
||||
<!-- editor area -->
|
||||
<div v-show="mode === 'wysiwyg'" ref="editorEl"></div>
|
||||
<textarea
|
||||
v-show="mode === 'md'"
|
||||
ref="mdPane"
|
||||
class="md-pane"
|
||||
v-model="form.content_md"
|
||||
placeholder="直接写 Markdown…"
|
||||
aria-label="Markdown 正文"
|
||||
@paste="onMdPaste"
|
||||
@drop="onMdDrop"
|
||||
></textarea>
|
||||
<!-- md 页签:CodeMirror 6(语法高亮/历史/粘贴拖拽上传),markdown 唯一真相源 -->
|
||||
<div v-show="mode === 'md'" ref="mdPane" class="md-pane" aria-label="Markdown 正文"></div>
|
||||
|
||||
<!-- 轻提示栈 -->
|
||||
<div class="toast-stack" aria-live="polite">
|
||||
<div v-for="t in toasts" :key="t.id" class="toast" :class="t.type">{{ t.text }}</div>
|
||||
</div>
|
||||
|
||||
<div class="editor-stats">
|
||||
<span><strong>{{ cjkChars }}</strong> 汉字</span>
|
||||
@@ -848,7 +1095,7 @@ const tbGroups = computed(() => [
|
||||
></textarea>
|
||||
</div>
|
||||
|
||||
<div class="field">
|
||||
<div v-if="form.kind !== 'short'" class="field">
|
||||
<label>标签</label>
|
||||
<div v-if="form.tags.length" style="display: flex; flex-wrap: wrap; gap: 6px; margin-bottom: 8px;">
|
||||
<span v-for="t in form.tags" :key="t" class="chip">
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { computed, onBeforeUnmount, onMounted, ref, watch } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { useRoute, useRouter } from 'vue-router'
|
||||
import { adminApi } from '../api'
|
||||
import { relativeDate } from '../utils'
|
||||
@@ -55,8 +56,10 @@ async function upload(files) {
|
||||
const fd = new FormData()
|
||||
for (const f of files) fd.append('file', f)
|
||||
await adminApi.uploadFiles(fd)
|
||||
toastOk(`已上传 ${files.length} 个文件`)
|
||||
await load()
|
||||
} catch (e) {
|
||||
toastErr(e.message || '上传失败')
|
||||
uploadError.value = e.message || '上传失败'
|
||||
} finally {
|
||||
uploading.value = false
|
||||
@@ -75,6 +78,7 @@ function onDrop(e) {
|
||||
async function copyUrl(f) {
|
||||
try {
|
||||
await navigator.clipboard.writeText(f.url)
|
||||
toastOk('链接已复制')
|
||||
copiedId.value = f.id
|
||||
setTimeout(() => {
|
||||
if (copiedId.value === f.id) copiedId.value = 0
|
||||
@@ -85,14 +89,38 @@ async function copyUrl(f) {
|
||||
}
|
||||
}
|
||||
|
||||
// 引用位置的展示文案:文章/项目带标题,头像没有标题可指。
|
||||
// 草稿也列出来——现在没发布,删了图将来发出来就是裂的。
|
||||
function refLabel(x) {
|
||||
if (x.kind === 'avatar') return '站主头像'
|
||||
const head = x.kind === 'project' ? '项目' : '文章'
|
||||
const name = x.title || x.slug || '未命名'
|
||||
return `${head}《${name}》${x.status === 'draft' ? '(草稿)' : ''}`
|
||||
}
|
||||
|
||||
async function remove(f) {
|
||||
if (!window.confirm(`删除「${f.name}」?存储里的文件会一并删除,引用它的文章将失效。`)) return
|
||||
// 删除前查一次引用:后端默认会挡住被引用的文件(409),这里先把清单摊出来,
|
||||
// 用户看完仍然要删才带 force=1 过去。
|
||||
let refs = []
|
||||
try {
|
||||
await adminApi.deleteFile(f.id)
|
||||
refs = (await adminApi.fileRefs(f.id)).items || []
|
||||
} catch (_) {
|
||||
// 查询失败就按无引用走:真被引用时后端会返回 409,不会静默删掉在用文件
|
||||
}
|
||||
let tip = `删除「${f.name}」?存储里的文件会一并删除。`
|
||||
if (refs.length) {
|
||||
const list = refs.slice(0, 3).map(refLabel).join('、')
|
||||
tip = `删除「${f.name}」?\n它正被 ${refs.length} 处引用:${list}${refs.length > 3 ? ' 等' : ''}。\n删掉这些地方会图裂。`
|
||||
}
|
||||
if (!window.confirm(tip)) return
|
||||
try {
|
||||
await adminApi.deleteFile(f.id, refs.length > 0)
|
||||
toastOk(`已删除「${f.name}」`)
|
||||
// 当前页删空时退一页,其余直接重载
|
||||
if (items.value.length === 1 && page.value > 1) router.replace({ query: { ...route.query, page: page.value - 1 } })
|
||||
else load()
|
||||
} catch (e) {
|
||||
toastErr(e.message || '删除失败')
|
||||
error.value = e.message || '删除失败'
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,5 +1,7 @@
|
||||
<script setup>
|
||||
import { ref } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import ToastStack from './ToastStack.vue'
|
||||
import { useRouter } from 'vue-router'
|
||||
import { adminApi, session } from '../api'
|
||||
import { site } from '../site'
|
||||
@@ -17,8 +19,10 @@ async function submit() {
|
||||
const data = await adminApi.login(username.value, password.value)
|
||||
session.user = username.value
|
||||
void data
|
||||
toastOk('登录成功')
|
||||
router.push('/admin')
|
||||
} catch (e) {
|
||||
toastErr('用户名或密码不对')
|
||||
error.value = '用户名或密码不对'
|
||||
} finally {
|
||||
busy.value = false
|
||||
@@ -27,6 +31,7 @@ async function submit() {
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<ToastStack />
|
||||
<div class="page">
|
||||
<form class="card" @submit.prevent="submit">
|
||||
<p class="eyebrow">后台</p>
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, ref, watch } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { useRoute, useRouter } from 'vue-router'
|
||||
import { adminApi } from '../api'
|
||||
import { formatDateShort, relativeDate } from '../utils'
|
||||
@@ -125,7 +126,7 @@ async function bulk(action) {
|
||||
await adminApi.bulkPosts([...selected.value], action)
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '操作失败')
|
||||
toastErr(e.message || '操作失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -135,7 +136,7 @@ async function remove(id, title) {
|
||||
await adminApi.deletePost(id)
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '删除失败')
|
||||
toastErr(e.message || '删除失败')
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { onMounted, ref } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { adminApi } from '../api'
|
||||
|
||||
const projects = ref([])
|
||||
@@ -40,7 +41,7 @@ onMounted(load)
|
||||
|
||||
async function create() {
|
||||
if (!form.value.title.trim()) {
|
||||
alert('请填写作品名称')
|
||||
toastErr('请填写作品名称')
|
||||
return
|
||||
}
|
||||
try {
|
||||
@@ -56,7 +57,7 @@ async function create() {
|
||||
form.value = blank()
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '创建失败')
|
||||
toastErr(e.message || '创建失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -81,7 +82,7 @@ function cancelEdit() {
|
||||
|
||||
async function saveEdit() {
|
||||
if (!draft.value.title.trim()) {
|
||||
alert('请填写作品名称')
|
||||
toastErr('请填写作品名称')
|
||||
return
|
||||
}
|
||||
try {
|
||||
@@ -97,7 +98,7 @@ async function saveEdit() {
|
||||
editing.value = null
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '保存失败')
|
||||
toastErr(e.message || '保存失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -107,7 +108,7 @@ async function toggleStatus(p) {
|
||||
await adminApi.updateProject(p.id, { status: next })
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '更新失败')
|
||||
toastErr(e.message || '更新失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -117,7 +118,7 @@ async function remove(p) {
|
||||
await adminApi.deleteProject(p.id)
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '删除失败')
|
||||
toastErr(e.message || '删除失败')
|
||||
}
|
||||
}
|
||||
</script>
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, ref } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { adminApi } from '../api'
|
||||
import { SKIN_CONSTANTS, UI_CONSTANTS } from '../site'
|
||||
import { SECTIONS } from '../ui/sections'
|
||||
@@ -35,14 +36,11 @@ function textToSocial(text) {
|
||||
.filter(Boolean)
|
||||
}
|
||||
|
||||
// 这里只能选亮色皮肤(paper / sage / rose)。暗色端固定 ink,由访客在前台
|
||||
// 右下角 ThemeSwitcher 切到「深色」或「自动 + 系统暗」时启用。
|
||||
// 皮肤已精简:亮端固定纸感,暗端固定墨色(2026 重设计)。下面只做展示。
|
||||
const lightSkins = [
|
||||
{ id: 'paper', label: '纸感(默认)', bg: '#faf7f1', fg: '#3d7f9c' },
|
||||
{ id: 'sage', label: '鼠尾草', bg: '#eef0e6', fg: '#5f7b5c' },
|
||||
{ id: 'rose', label: '玫瑰', bg: '#f7eee6', fg: '#a55a4a' }
|
||||
{ id: 'paper', label: '纸感(默认)', bg: '#faf7f1', fg: '#3d7f9c' }
|
||||
]
|
||||
const darkSkin = { id: 'ink', label: '墨色', bg: '#1f1d1a', fg: '#c3b58f' }
|
||||
const darkSkin = { id: 'ink', label: '墨色', bg: '#191817', fg: '#d9b97c' }
|
||||
|
||||
// ---------- 界面与自定义(第二套 UI) ----------
|
||||
|
||||
@@ -186,7 +184,9 @@ async function save() {
|
||||
}
|
||||
}
|
||||
savedAt.value = new Date().toLocaleTimeString('zh-CN', { hour12: false })
|
||||
toastOk('设置已保存')
|
||||
} catch (e) {
|
||||
toastErr('保存失败:' + (e.message || ''))
|
||||
error.value = e.message || '保存失败'
|
||||
} finally {
|
||||
saving.value = false
|
||||
@@ -220,18 +220,17 @@ async function save() {
|
||||
<label>站点副标题</label>
|
||||
<input v-model="settings.site_desc" class="input" spellcheck="false" />
|
||||
</div>
|
||||
<div class="field">
|
||||
<label>作者昵称</label>
|
||||
<input v-model="settings.author_name" class="input" spellcheck="false" />
|
||||
</div>
|
||||
<div class="field">
|
||||
<label>作者简介</label>
|
||||
<textarea v-model="settings.author_bio" class="textarea" rows="3" />
|
||||
</div>
|
||||
<!-- 作者昵称/简介不在这里改:它们和头像、登录方式同属「账户」,
|
||||
两处编辑同一个字段迟早漂移,所以收归账户页独占。 -->
|
||||
<div class="field">
|
||||
<label>页脚备注</label>
|
||||
<input v-model="settings.footer_note" class="input" spellcheck="false" />
|
||||
</div>
|
||||
<p class="field-hint">
|
||||
作者昵称、简介与头像在
|
||||
<RouterLink to="/admin/account">账户</RouterLink>
|
||||
页设置(它们和登录方式属于同一件事,两处编辑同一个字段迟早漂移)。
|
||||
</p>
|
||||
</div>
|
||||
|
||||
<!-- theme -->
|
||||
@@ -241,19 +240,12 @@ async function save() {
|
||||
<div class="field">
|
||||
<label>亮色皮肤</label>
|
||||
<div class="theme-swatches">
|
||||
<div
|
||||
v-for="sk in lightSkins"
|
||||
:key="sk.id"
|
||||
class="sw"
|
||||
:class="{ on: settings.light_skin_id === sk.id }"
|
||||
:style="{ background: sk.bg, borderColor: settings.light_skin_id === sk.id ? sk.fg : 'var(--admin-line)' }"
|
||||
@click="settings.light_skin_id = sk.id"
|
||||
>
|
||||
<span :style="{ background: sk.fg }">{{ sk.label }}</span>
|
||||
<div class="sw on" :style="{ background: lightSkins[0].bg, borderColor: lightSkins[0].fg }" :title="lightSkins[0].label + '(固定)'">
|
||||
<span :style="{ background: lightSkins[0].fg }">{{ lightSkins[0].label }}</span>
|
||||
</div>
|
||||
</div>
|
||||
<p style="margin: 6px 0 0; font-size: 12px; color: var(--admin-muted);">
|
||||
访客在前台选择「自动」且系统偏好浅色时使用。
|
||||
亮端固定为纸感。访客在前台选择「自动」且系统偏好浅色时使用。
|
||||
</p>
|
||||
</div>
|
||||
|
||||
|
||||
@@ -1,5 +1,6 @@
|
||||
<script setup>
|
||||
import { onMounted, ref } from 'vue'
|
||||
import { toastOk, toastErr } from './toast'
|
||||
import { adminApi } from '../api'
|
||||
|
||||
const tags = ref([])
|
||||
@@ -30,7 +31,7 @@ async function create() {
|
||||
newColor.value = ''
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '创建失败')
|
||||
toastErr(e.message || '创建失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -39,7 +40,7 @@ async function update(t) {
|
||||
await adminApi.updateTag(t.id, { name: t.name, color: t.color })
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '更新失败')
|
||||
toastErr(e.message || '更新失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -49,7 +50,7 @@ async function remove(t) {
|
||||
await adminApi.deleteTag(t.id)
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '删除失败')
|
||||
toastErr(e.message || '删除失败')
|
||||
}
|
||||
}
|
||||
|
||||
@@ -69,7 +70,7 @@ function cancelMerge() {
|
||||
async function doMerge(fromTag) {
|
||||
const toId = Number(mergeInto.value)
|
||||
if (!toId || toId === fromTag.id) {
|
||||
alert('选一个不同的目标标签')
|
||||
toastErr('选一个不同的目标标签')
|
||||
return
|
||||
}
|
||||
if (!window.confirm(`把「${fromTag.name}」合并到选中的标签?此操作不可撤销。`)) return
|
||||
@@ -78,7 +79,7 @@ async function doMerge(fromTag) {
|
||||
cancelMerge()
|
||||
await load()
|
||||
} catch (e) {
|
||||
alert(e.message || '合并失败')
|
||||
toastErr(e.message || '合并失败')
|
||||
}
|
||||
}
|
||||
</script>
|
||||
|
||||
@@ -0,0 +1,11 @@
|
||||
<script setup>
|
||||
// 后台共享 toast 的渲染层:挂在 AdminLayout(所有管理页)与 LoginView。
|
||||
// 样式在全局 styles.css(.toast-stack / .toast),与编辑器共用一份。
|
||||
import { toasts } from './toast'
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<div class="toast-stack" aria-live="polite">
|
||||
<div v-for="t in toasts" :key="t.id" class="toast" :class="t.type">{{ t.text }}</div>
|
||||
</div>
|
||||
</template>
|
||||
@@ -0,0 +1,47 @@
|
||||
import { reactive } from 'vue'
|
||||
|
||||
// 后台共享的轻提示:所有视图的操作反馈(成功/失败/进度)从这里发,
|
||||
// ToastStack.vue 负责渲染(挂在 AdminLayout 与 LoginView)。
|
||||
// EditorView 的上传/转存也走它——原先那套局部实现已并入。
|
||||
export const toasts = reactive([])
|
||||
let seq = 0
|
||||
|
||||
export function toast(text, type = 'info', ttl = 2600) {
|
||||
const id = ++seq
|
||||
toasts.push({ id, text, type })
|
||||
setTimeout(() => {
|
||||
const i = toasts.findIndex((t) => t.id === id)
|
||||
if (i >= 0) toasts.splice(i, 1)
|
||||
}, ttl)
|
||||
return id
|
||||
}
|
||||
|
||||
export function toastOk(text) {
|
||||
return toast(text, 'ok', 2200)
|
||||
}
|
||||
|
||||
export function toastErr(text) {
|
||||
return toast(text, 'err', 4200)
|
||||
}
|
||||
|
||||
// 更新一条已存在的 toast(上传进度用)
|
||||
export function toastUpdate(id, text, type = 'info') {
|
||||
const t = toasts.find((x) => x.id === id)
|
||||
if (t) {
|
||||
t.text = text
|
||||
t.type = type
|
||||
}
|
||||
}
|
||||
|
||||
// 标记成功并很快消失(进度条收尾)
|
||||
export function toastDone(id, text) {
|
||||
toastUpdate(id, text, 'ok')
|
||||
const idx = toasts.findIndex((t) => t.id === id)
|
||||
if (idx >= 0) {
|
||||
const t = toasts[idx]
|
||||
setTimeout(() => {
|
||||
const i = toasts.indexOf(t)
|
||||
if (i >= 0) toasts.splice(i, 1)
|
||||
}, 1600)
|
||||
}
|
||||
}
|
||||
+44
-1
@@ -83,6 +83,17 @@ export const adminApi = {
|
||||
deleteProject: (id) => request('/api/admin/projects/' + id, { method: 'DELETE' }),
|
||||
settings: () => request('/api/admin/settings'),
|
||||
saveSettings: (body) => request('/api/admin/settings', { method: 'PUT', body }),
|
||||
// ---------- 账户(资料 / 身份绑定 / passkey) ----------
|
||||
account: () => request('/api/admin/account'),
|
||||
saveAccount: (body) => request('/api/admin/account', { method: 'PATCH', body }),
|
||||
unbindIdentity: (provider) =>
|
||||
request('/api/admin/account/identities/' + encodeURIComponent(provider), { method: 'DELETE' }),
|
||||
passkeyBegin: () => request('/api/admin/account/passkeys/begin', { method: 'POST' }),
|
||||
passkeyFinish: (body) => request('/api/admin/account/passkeys/finish', { method: 'POST', body }),
|
||||
deletePasskey: (id) => request('/api/admin/account/passkeys/' + id, { method: 'DELETE' }),
|
||||
// 前台 passkey 登录(公开端点)
|
||||
passkeyLoginBegin: () => request('/api/auth/passkey/begin', { method: 'POST' }),
|
||||
passkeyLoginFinish: (body) => request('/api/auth/passkey/finish', { method: 'POST', body }),
|
||||
// ---------- 评论管理 ----------
|
||||
comments: (params = {}) => request('/api/admin/comments?' + new URLSearchParams(params)),
|
||||
approveComment: (id) =>
|
||||
@@ -93,9 +104,41 @@ export const adminApi = {
|
||||
request('/api/admin/readers/' + id + '/ban', { method: 'POST', body: { banned } }),
|
||||
// ---------- 文件上传 ----------
|
||||
files: (params = {}) => request('/api/admin/files?' + new URLSearchParams(params)),
|
||||
deleteFile: (id) => request('/api/admin/files/' + id, { method: 'DELETE' }),
|
||||
// 删除前查引用(被哪些文章/项目/站主头像用着);force 用于明知有引用仍要删
|
||||
fileRefs: (id) => request('/api/admin/files/' + id + '/refs'),
|
||||
deleteFile: (id, force = false) =>
|
||||
request('/api/admin/files/' + id + (force ? '?force=1' : ''), { method: 'DELETE' }),
|
||||
// 上传走 FormData:request() 是 JSON helper,这里单独 fetch。
|
||||
// 401 同样广播 one:unauthorized,错误消息从 JSON body 里取(与 request 一致)。
|
||||
// 单文件上传(XHR):fetch 拿不到上传进度,编辑器的进度提示走这里
|
||||
uploadFile: (file, onProgress) =>
|
||||
new Promise((resolve, reject) => {
|
||||
const xhr = new XMLHttpRequest()
|
||||
xhr.open('POST', base + '/api/admin/files')
|
||||
xhr.withCredentials = true
|
||||
xhr.upload.onprogress = (e) => {
|
||||
if (e.lengthComputable && onProgress) onProgress(e.loaded / e.total)
|
||||
}
|
||||
xhr.onload = () => {
|
||||
if (xhr.status === 401) {
|
||||
window.dispatchEvent(new CustomEvent('one:unauthorized'))
|
||||
reject(new Error('未登录或登录已过期'))
|
||||
return
|
||||
}
|
||||
let data = {}
|
||||
try {
|
||||
data = JSON.parse(xhr.responseText)
|
||||
} catch {}
|
||||
if (xhr.status >= 200 && xhr.status < 300) resolve(data)
|
||||
else reject(new Error(data.error || `上传失败(${xhr.status})`))
|
||||
}
|
||||
xhr.onerror = () => reject(new Error('网络错误,上传中止'))
|
||||
const fd = new FormData()
|
||||
fd.append('file', file)
|
||||
xhr.send(fd)
|
||||
}),
|
||||
// 外链转存:把正文里的外链图片抓回自己的存储,返回 { files, errors }
|
||||
importFiles: (urls) => request('/api/admin/files/import', { method: 'POST', body: { urls } }),
|
||||
uploadFiles: async (formData) => {
|
||||
const res = await fetch(base + '/api/admin/files', {
|
||||
method: 'POST',
|
||||
|
||||
@@ -0,0 +1,30 @@
|
||||
<script setup>
|
||||
import { computed } from 'vue'
|
||||
import { site } from '../site'
|
||||
import { thumbURL } from '../utils'
|
||||
import LogoMark from './LogoMark.vue'
|
||||
|
||||
// 作者头像位:站主设了头像就用图,没设就回落到站标「一横」。
|
||||
// 尺寸由外层容器决定(和 LogoMark 一样靠 width/height:100%)。
|
||||
//
|
||||
// 走缩略图路由:头像位最大也才 64px,没必要拉原图。
|
||||
// thumbURL 的签名是 (url, width) —— 公开域名由 site.js 经 setThumbBase 注入,
|
||||
// 不在参数里传。
|
||||
const url = computed(() => thumbURL(site.author_avatar_url, 128))
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<img v-if="url" class="author-avatar" :src="url" alt="" decoding="async" />
|
||||
<LogoMark v-else />
|
||||
</template>
|
||||
|
||||
<style scoped>
|
||||
.author-avatar {
|
||||
display: block;
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
object-fit: cover;
|
||||
flex-shrink: 0;
|
||||
border-radius: 50%;
|
||||
}
|
||||
</style>
|
||||
@@ -2,34 +2,70 @@
|
||||
import { onBeforeUnmount, watch } from 'vue'
|
||||
import { lightboxState as st, closeLightbox, stepLightbox } from '../lightbox'
|
||||
|
||||
// 图片预览层:App.vue 全局挂一次。铺满全屏的暗底 + 居中大图,
|
||||
// 多图时左右箭头 / 方向键切换,角标显示第几张;Esc / 点空白收起。
|
||||
// 图片预览层(手机重做版):App.vue 全局挂一次。
|
||||
//
|
||||
// 手机上出过两次事故,这次的实现原则:
|
||||
// 1. 不碰 body 的 overflow——之前用 inline overflow 锁背景,把样式表的
|
||||
// overflow-x: clip 覆盖成 hidden,横向从「裁剪」变「可滚动容器」,
|
||||
// 整页被拖宽。现在滚动封锁靠遮罩自己的 @wheel/@touchmove.prevent:
|
||||
// 事件不落到页面里,背景自然滚不动,滚动位置也天然保留。
|
||||
// 2. 图片尺寸全部用百分比(max-width/height: 100%),不引入 vw/vh/dvh——
|
||||
// 这些单位在全面屏 URL 栏收展时各有各的坑,遮罩本身就是视口大小。
|
||||
// 3. 手势全归遮罩:touch-action: none + touchend 位移判滑动翻页,
|
||||
// 双击缩放/长按菜单/下拉刷新这些浏览器手势都不会来捣乱。
|
||||
// 4. 桌面能力不变:Esc / 方向键 / 点空白关闭 / 悬停箭头。
|
||||
|
||||
function onKey(e) {
|
||||
if (e.key === 'Escape') closeLightbox()
|
||||
if (e.key === 'ArrowLeft') stepLightbox(-1)
|
||||
if (e.key === 'ArrowRight') stepLightbox(1)
|
||||
}
|
||||
|
||||
// 吸顶栏带 backdrop-filter,真机上其合成层会盖在遮罩之上
|
||||
// (z-index 更高也拦不住)——开预览时整个藏掉
|
||||
watch(
|
||||
() => st.open,
|
||||
(v) => {
|
||||
if (v) window.addEventListener('keydown', onKey)
|
||||
else window.removeEventListener('keydown', onKey)
|
||||
document.body.classList.toggle('lb-open', v)
|
||||
}
|
||||
)
|
||||
onBeforeUnmount(() => window.removeEventListener('keydown', onKey))
|
||||
onBeforeUnmount(() => {
|
||||
window.removeEventListener('keydown', onKey)
|
||||
document.body.classList.remove('lb-open')
|
||||
})
|
||||
|
||||
// 滑动翻页:横向位移超 44px 且明显大于纵向才算一次滑动
|
||||
let touchX = 0
|
||||
let touchY = 0
|
||||
function onTouchStart(e) {
|
||||
touchX = e.touches[0].clientX
|
||||
touchY = e.touches[0].clientY
|
||||
}
|
||||
function onTouchEnd(e) {
|
||||
if (st.list.length < 2) return
|
||||
const dx = e.changedTouches[0].clientX - touchX
|
||||
const dy = e.changedTouches[0].clientY - touchY
|
||||
if (Math.abs(dx) > 44 && Math.abs(dx) > Math.abs(dy) * 1.4) {
|
||||
stepLightbox(dx < 0 ? 1 : -1)
|
||||
}
|
||||
}
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<Teleport to="body">
|
||||
<Transition name="lb">
|
||||
<div v-if="st.open" class="lb-overlay" @click="closeLightbox">
|
||||
<img
|
||||
class="lb-img"
|
||||
:src="st.list[st.index]"
|
||||
alt=""
|
||||
@click.stop
|
||||
/>
|
||||
<Transition name="lb" :duration="220">
|
||||
<div
|
||||
v-if="st.open"
|
||||
class="lb-overlay"
|
||||
@click="closeLightbox"
|
||||
@touchstart.passive="onTouchStart"
|
||||
@touchend.passive="onTouchEnd"
|
||||
@wheel.prevent
|
||||
@touchmove.prevent
|
||||
>
|
||||
<img class="lb-img" :src="st.list[st.index]" alt="" @click.stop />
|
||||
<button v-if="st.list.length > 1" class="lb-nav prev" type="button" aria-label="上一张" @click.stop="stepLightbox(-1)">‹</button>
|
||||
<button v-if="st.list.length > 1" class="lb-nav next" type="button" aria-label="下一张" @click.stop="stepLightbox(1)">›</button>
|
||||
<button class="lb-close" type="button" aria-label="关闭预览" @click="closeLightbox">×</button>
|
||||
@@ -44,19 +80,23 @@ onBeforeUnmount(() => window.removeEventListener('keydown', onKey))
|
||||
position: fixed;
|
||||
inset: 0;
|
||||
z-index: 130;
|
||||
background: rgba(12, 11, 10, 0.88);
|
||||
background: rgba(12, 11, 10, 0.92);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
/* 遮罩全权处理手势:杜绝双击缩放/长按菜单/下拉刷新来添乱 */
|
||||
touch-action: none;
|
||||
}
|
||||
|
||||
/* 百分比尺寸:遮罩即视口,图片永远不会超出屏幕半像素 */
|
||||
.lb-img {
|
||||
max-width: min(1200px, 92vw);
|
||||
max-height: 88vh;
|
||||
max-width: 100%;
|
||||
max-height: 100%;
|
||||
object-fit: contain;
|
||||
border-radius: 6px;
|
||||
box-shadow: 0 30px 80px -20px rgba(0, 0, 0, 0.6);
|
||||
user-select: none;
|
||||
-webkit-user-drag: none;
|
||||
}
|
||||
|
||||
.lb-nav {
|
||||
@@ -123,29 +163,36 @@ onBeforeUnmount(() => window.removeEventListener('keydown', onKey))
|
||||
font-variant-numeric: tabular-nums;
|
||||
}
|
||||
|
||||
@media (max-width: 640px) {
|
||||
/* 手机:滑动翻页为主,箭头贴边缩小;位置全走安全区 */
|
||||
@media (pointer: coarse) {
|
||||
.lb-img {
|
||||
max-width: 96vw;
|
||||
max-height: 74vh;
|
||||
border-radius: 0;
|
||||
}
|
||||
|
||||
.lb-nav {
|
||||
width: 38px;
|
||||
height: 38px;
|
||||
width: 40px;
|
||||
height: 40px;
|
||||
font-size: 22px;
|
||||
background: rgba(255, 255, 255, 0.12);
|
||||
}
|
||||
|
||||
.lb-nav.prev {
|
||||
left: 10px;
|
||||
left: calc(6px + env(safe-area-inset-left));
|
||||
}
|
||||
|
||||
.lb-nav.next {
|
||||
right: 10px;
|
||||
right: calc(6px + env(safe-area-inset-right));
|
||||
}
|
||||
|
||||
.lb-close {
|
||||
top: 10px;
|
||||
right: 10px;
|
||||
top: calc(10px + env(safe-area-inset-top));
|
||||
right: calc(10px + env(safe-area-inset-right));
|
||||
width: 42px;
|
||||
height: 42px;
|
||||
}
|
||||
|
||||
.lb-count {
|
||||
bottom: calc(14px + env(safe-area-inset-bottom));
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
@@ -3,6 +3,7 @@ import { computed } from 'vue'
|
||||
import { site } from '../site'
|
||||
import { socialIcon } from '../socialIcons'
|
||||
import ThemeSwitcher from './ThemeSwitcher.vue'
|
||||
import LogoMark from './LogoMark.vue'
|
||||
|
||||
// vivid 用顶部导航(VividNav)代替左栏。这里直接不渲染。
|
||||
const isVivid = computed(() => site.ui_id === 'vivid')
|
||||
@@ -15,7 +16,7 @@ const social = computed(() => (site.social_links || []).filter((s) => s && s.url
|
||||
<aside v-if="!isVivid" class="rail-left">
|
||||
<div class="inner">
|
||||
<RouterLink to="/" class="brand">
|
||||
<span class="mark">○</span>
|
||||
<span class="mark"><LogoMark /></span>
|
||||
<span class="name">{{ site.site_title || 'ONE' }}</span>
|
||||
</RouterLink>
|
||||
<p class="desc">{{ site.site_desc }}</p>
|
||||
@@ -86,9 +87,13 @@ const social = computed(() => (site.social_links || []).filter((s) => s && s.url
|
||||
gap: 8px;
|
||||
}
|
||||
|
||||
/* 原来这里是一个排版字符 ○ 充当标记,换成真站标。
|
||||
flex:none:它是 .brand(flex)的子项,不锁住会被长站名压成椭圆 */
|
||||
.mark {
|
||||
color: var(--accent);
|
||||
font-size: 18px;
|
||||
width: 22px;
|
||||
height: 22px;
|
||||
flex: none;
|
||||
color: var(--ink);
|
||||
}
|
||||
|
||||
.name {
|
||||
|
||||
@@ -83,6 +83,9 @@ function open() {
|
||||
letter-spacing: 0.04em;
|
||||
text-transform: lowercase;
|
||||
color: var(--v-muted, var(--faint));
|
||||
/* 主机名是最典型的不可断行长 token(子域一长串),不给它 anywhere
|
||||
就会把卡片左列顶宽、整行溢出 */
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
|
||||
.lc-title {
|
||||
|
||||
@@ -0,0 +1,26 @@
|
||||
<script setup>
|
||||
// 站标「一横」:墨圆 + 一道白横 —— 字母 O 与汉字「一」同形,对应站名 ONE / 一个博客。
|
||||
//
|
||||
// 横杠是 fill-rule="evenodd" 挖出来的真洞,不是叠一块纸色矩形,所以任何底色
|
||||
// (纸感 / 墨色暗端 / 后台卡片)都直接透过去,不必为皮肤各出一版。
|
||||
// 颜色跟随 currentColor,尺寸由外层容器决定。
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<svg class="logo-mark" viewBox="0 0 64 64" aria-hidden="true" focusable="false">
|
||||
<path
|
||||
fill="currentColor"
|
||||
fill-rule="evenodd"
|
||||
d="M32 4a28 28 0 1 0 0 56 28 28 0 1 0 0-56Zm-16 23.5h32a1 1 0 0 1 1 1v7a1 1 0 0 1-1 1H16a1 1 0 0 1-1-1v-7a1 1 0 0 1 1-1Z"
|
||||
/>
|
||||
</svg>
|
||||
</template>
|
||||
|
||||
<style scoped>
|
||||
.logo-mark {
|
||||
display: block;
|
||||
width: 100%;
|
||||
height: 100%;
|
||||
flex-shrink: 0;
|
||||
}
|
||||
</style>
|
||||
@@ -5,6 +5,7 @@ import { site } from '../site'
|
||||
import { openLightbox } from '../lightbox'
|
||||
import { relativeDate, stripTags, minutesLabel, sanitizeHtml, thumbURL, thumbifyHtml } from '../utils'
|
||||
import LinkCard from './LinkCard.vue'
|
||||
import AuthorAvatar from './AuthorAvatar.vue'
|
||||
|
||||
const router = useRouter()
|
||||
|
||||
@@ -34,15 +35,13 @@ const summaryText = computed(() => {
|
||||
return text.length > 110 ? text.slice(0, 110) + '…' : text
|
||||
})
|
||||
|
||||
const initial = computed(() => (site.author_name || 'O').trim().slice(0, 1).toUpperCase())
|
||||
|
||||
// 配图缩略图宽度:单图全宽格取宽一些,多图小格 480 足够(2x 屏也清晰)
|
||||
const gridW = computed(() => (props.post.images && props.post.images.length === 1 ? 720 : 480))
|
||||
</script>
|
||||
|
||||
<template>
|
||||
<article class="row-feed" :class="{ short: isShort }" @click="openPost">
|
||||
<div class="avatar" aria-hidden="true">{{ initial }}</div>
|
||||
<div class="avatar"><AuthorAvatar /></div>
|
||||
|
||||
<div class="body">
|
||||
<div class="byline">
|
||||
@@ -126,18 +125,12 @@ const gridW = computed(() => (props.post.images && props.post.images.length ===
|
||||
background: var(--paper-sunken);
|
||||
}
|
||||
|
||||
/* 站标本身就是个圆,所以原来那层 accent-soft 圆底 / 衬线首字母都不需要了,
|
||||
只留尺寸与颜色。想换回降饱和蓝只需改 color 一行。 */
|
||||
.avatar {
|
||||
width: 40px;
|
||||
height: 40px;
|
||||
border-radius: 50%;
|
||||
background: var(--accent-soft);
|
||||
color: var(--accent);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
font-family: var(--serif);
|
||||
font-size: 17px;
|
||||
user-select: none;
|
||||
color: var(--ink);
|
||||
}
|
||||
|
||||
.byline {
|
||||
@@ -274,11 +267,19 @@ const gridW = computed(() => (props.post.images && props.post.images.length ===
|
||||
gap: 6px;
|
||||
}
|
||||
|
||||
/* 出血必须跟 .shell 的页边距同步:styles.css 里 .shell 在 640px 断点从 20px
|
||||
收到 12px,这里就得同时从 -16px 收到 -12px。之前写的是 520px,于是
|
||||
521~640 这段(窄窗口 / 横屏手机)出血比父容器内边距多 4px,整页横向溢出。 */
|
||||
@media (max-width: 640px) {
|
||||
.row-feed {
|
||||
margin: 0 -12px;
|
||||
}
|
||||
}
|
||||
|
||||
@media (max-width: 520px) {
|
||||
.row-feed {
|
||||
grid-template-columns: 34px minmax(0, 1fr);
|
||||
padding: 16px 12px;
|
||||
margin: 0 -12px;
|
||||
}
|
||||
|
||||
.avatar {
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, ref } from 'vue'
|
||||
import { adminApi } from '../api'
|
||||
import AuthorAvatar from './AuthorAvatar.vue'
|
||||
|
||||
// Twitter 式短文发布盒,挂在时间线顶部。
|
||||
//
|
||||
@@ -17,7 +18,6 @@ import { adminApi } from '../api'
|
||||
const emit = defineEmits(['published'])
|
||||
|
||||
const shown = ref(false)
|
||||
const userName = ref('')
|
||||
const draft = ref('')
|
||||
const publishing = ref(false)
|
||||
const error = ref('')
|
||||
@@ -53,7 +53,6 @@ function removeImage(i) {
|
||||
images.value.splice(i, 1)
|
||||
}
|
||||
|
||||
const initial = computed(() => (userName.value || 'O').trim().slice(0, 1).toUpperCase())
|
||||
const canPost = computed(
|
||||
() => (draft.value.trim().length > 0 || images.value.length > 0) && !publishing.value
|
||||
)
|
||||
@@ -62,7 +61,6 @@ onMounted(async () => {
|
||||
try {
|
||||
const d = await adminApi.me()
|
||||
if (d.user) {
|
||||
userName.value = String(d.user)
|
||||
shown.value = true
|
||||
}
|
||||
} catch {
|
||||
@@ -110,7 +108,7 @@ async function publish() {
|
||||
<!-- 桌面:内联 -->
|
||||
<div class="qs-inline">
|
||||
<div class="qs-card">
|
||||
<span class="qs-av">{{ initial }}</span>
|
||||
<span class="qs-av"><AuthorAvatar /></span>
|
||||
<div class="qs-body">
|
||||
<textarea v-model="draft" class="qs-input" rows="2" placeholder="记点短的…" @keydown="onKey" />
|
||||
<div v-if="images.length" class="qs-thumbs">
|
||||
@@ -197,17 +195,12 @@ async function publish() {
|
||||
background: var(--card);
|
||||
}
|
||||
|
||||
/* 站标自身是圆,去掉原来的 accent-soft 圆底与首字母字号;flex:none 防被压扁 */
|
||||
.qs-av {
|
||||
flex: none;
|
||||
width: 34px;
|
||||
height: 34px;
|
||||
border-radius: 50%;
|
||||
background: var(--accent-soft);
|
||||
color: var(--accent);
|
||||
display: grid;
|
||||
place-items: center;
|
||||
font-weight: 700;
|
||||
font-size: 14px;
|
||||
color: var(--ink);
|
||||
}
|
||||
|
||||
.qs-body {
|
||||
|
||||
@@ -1,13 +1,42 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, ref } from 'vue'
|
||||
import { computed, nextTick, onBeforeUnmount, onMounted, ref, watch } from 'vue'
|
||||
import { publicApi } from '../api'
|
||||
import { site } from '../site'
|
||||
import { socialIcon } from '../socialIcons'
|
||||
import { relativeDate } from '../utils'
|
||||
import { relativeDate, stripTags, thumbURL } from '../utils'
|
||||
|
||||
// vivid 是单栏布局,右栏整体不渲染(省掉 latest/tags 两次请求)。
|
||||
const isVivid = computed(() => site.ui_id === 'vivid')
|
||||
|
||||
// 文章页目录(PostView 传入 headings;空数组时不渲染这张卡)。
|
||||
// 高亮跟随滚动:视口上方最近的那个标题算「当前」。
|
||||
const props = defineProps({
|
||||
toc: { type: Array, default: () => [] }
|
||||
})
|
||||
const activeId = ref('')
|
||||
let tocObserver = null
|
||||
|
||||
function watchToc() {
|
||||
if (tocObserver) tocObserver.disconnect()
|
||||
if (!props.toc.length) return
|
||||
tocObserver = new IntersectionObserver(
|
||||
(entries) => {
|
||||
for (const e of entries) {
|
||||
if (e.isIntersecting) activeId.value = e.target.id
|
||||
}
|
||||
},
|
||||
{ rootMargin: '0px 0px -65% 0px' }
|
||||
)
|
||||
nextTick(() => {
|
||||
for (const t of props.toc) {
|
||||
const el = document.getElementById(t.id)
|
||||
if (el) tocObserver.observe(el)
|
||||
}
|
||||
})
|
||||
}
|
||||
watch(() => props.toc, watchToc, { deep: false })
|
||||
onBeforeUnmount(() => tocObserver && tocObserver.disconnect())
|
||||
|
||||
// 项目源码仓库是固定入口(本站 git remote),不来自后台配置 —— 和版权一样
|
||||
// 固定渲染在自己的那排;后台填的社交账号单独一排,URL 撞车的去重。
|
||||
const PROJECT_REPO = 'https://git.gopher.ink/mirrors2/ONE'
|
||||
@@ -27,6 +56,26 @@ const links = [
|
||||
const latest = ref([])
|
||||
const tags = ref([])
|
||||
|
||||
// 短文没有标题,侧栏拿正文开头当标识(flomo/Twitter 的做法),
|
||||
// 纯图片短文显示占位;有配图时右侧带一张小缩略图。
|
||||
const EXCERPT_LEN = 22
|
||||
function excerpt(p) {
|
||||
if (p.kind !== 'short') return p.title || '无题'
|
||||
// 先剥 <a>:贴链接的短文开头是 URL 本身,摘出来没有信息量;
|
||||
// 剥完没字了(纯链接贴)就退到链接卡片的标题
|
||||
const noLinks = (p.content_html || '').replace(/<a\b[^>]*>[\s\S]*?<\/a>/gi, ' ')
|
||||
const text = stripTags(noLinks).replace(/\s+/g, ' ').trim()
|
||||
if (text) return text.length > EXCERPT_LEN ? text.slice(0, EXCERPT_LEN) + '…' : text
|
||||
if (p.link_card && p.link_card.title) {
|
||||
const t = p.link_card.title
|
||||
return t.length > EXCERPT_LEN ? t.slice(0, EXCERPT_LEN) + '…' : t
|
||||
}
|
||||
return p.images && p.images.length ? '📷 图片' : '短文'
|
||||
}
|
||||
function thumbOf(p) {
|
||||
return p.kind === 'short' && p.images && p.images.length ? thumbURL(p.images[0], 160) : ''
|
||||
}
|
||||
|
||||
onMounted(async () => {
|
||||
if (isVivid.value) return
|
||||
try {
|
||||
@@ -42,6 +91,15 @@ onMounted(async () => {
|
||||
|
||||
<template>
|
||||
<aside v-if="!isVivid" class="rail-right">
|
||||
<section v-if="toc.length" class="card toc-card">
|
||||
<p class="eyebrow">目录</p>
|
||||
<ul class="toc-list">
|
||||
<li v-for="t in toc" :key="t.id" :class="{ h3: t.level >= 3, on: activeId === t.id }">
|
||||
<a :href="'#' + t.id" :class="{ on: activeId === t.id }">{{ t.text }}</a>
|
||||
</li>
|
||||
</ul>
|
||||
</section>
|
||||
|
||||
<section class="card">
|
||||
<p class="eyebrow">关于这里</p>
|
||||
<p class="bio">{{ site.author_bio || site.site_desc }}</p>
|
||||
@@ -52,12 +110,22 @@ onMounted(async () => {
|
||||
<p class="eyebrow">最近更新</p>
|
||||
<ul class="list">
|
||||
<li v-for="p in latest" :key="p.id">
|
||||
<RouterLink :to="`/post/${p.slug}`" class="row">
|
||||
<RouterLink :to="`/post/${p.slug}`" class="row" :class="{ withThumb: thumbOf(p) }">
|
||||
<span class="row-main">
|
||||
<span class="title">
|
||||
{{ p.kind === 'short' ? '短文' : p.title || '无题' }}
|
||||
{{ excerpt(p) }}
|
||||
<span v-if="p.kind === 'short'" class="badge">短</span>
|
||||
</span>
|
||||
<span class="date">{{ relativeDate(p.published_at) }}</span>
|
||||
</span>
|
||||
<img
|
||||
v-if="thumbOf(p)"
|
||||
class="thumb"
|
||||
:src="thumbOf(p)"
|
||||
alt=""
|
||||
loading="lazy"
|
||||
decoding="async"
|
||||
/>
|
||||
</RouterLink>
|
||||
</li>
|
||||
</ul>
|
||||
@@ -78,15 +146,6 @@ onMounted(async () => {
|
||||
已删:右栏在窄屏会堆到信息流下方,卡片之后正好接页脚小字,
|
||||
所有宽度都不缺位。 -->
|
||||
<footer class="rail-foot">
|
||||
<nav class="foot-links" aria-label="页脚导航">
|
||||
<template v-for="(l, i) in links" :key="l.to">
|
||||
<span v-if="i" class="dot">·</span>
|
||||
<RouterLink :to="l.to">{{ l.label }}</RouterLink>
|
||||
</template>
|
||||
<span class="dot">·</span>
|
||||
<a href="/rss.xml">RSS</a>
|
||||
</nav>
|
||||
<!-- 后台填的社交账号:单独一排 -->
|
||||
<div v-if="social.length" class="social-row">
|
||||
<a
|
||||
v-for="s in social"
|
||||
@@ -102,6 +161,14 @@ onMounted(async () => {
|
||||
<span v-else>{{ s.label }}</span>
|
||||
</a>
|
||||
</div>
|
||||
<nav class="foot-links" aria-label="页脚导航">
|
||||
<template v-for="(l, i) in links" :key="l.to">
|
||||
<span v-if="i" class="dot">·</span>
|
||||
<RouterLink :to="l.to">{{ l.label }}</RouterLink>
|
||||
</template>
|
||||
<span class="dot">·</span>
|
||||
<a href="/rss.xml">RSS</a>
|
||||
</nav>
|
||||
<!-- 项目信息:固定的源码图标 + 版权,永远在 -->
|
||||
<div class="foot-meta">
|
||||
<a class="social-icon" :href="PROJECT_REPO" title="项目源码" aria-label="项目源码" target="_blank" rel="noopener">
|
||||
@@ -145,6 +212,24 @@ onMounted(async () => {
|
||||
color: var(--accent);
|
||||
}
|
||||
|
||||
/* 文章目录:当前小节高亮,层级缩进 */
|
||||
.toc-list {
|
||||
list-style: none;
|
||||
margin: 8px 0 0;
|
||||
padding: 0;
|
||||
font-size: 13px;
|
||||
line-height: 1.6;
|
||||
}
|
||||
.toc-list li {margin: 2px 0;
|
||||
border-left: 2px solid transparent;
|
||||
padding-left: 8px;}
|
||||
.toc-list li.h3 {padding-left: 20px;
|
||||
font-size: 12.5px;}
|
||||
.toc-list li.on {border-left-color: var(--accent);}
|
||||
.toc-list a {color: var(--muted);
|
||||
text-decoration: none;}
|
||||
.toc-list li.on a, .toc-list a:hover {color: var(--accent);}
|
||||
|
||||
.list {
|
||||
list-style: none;
|
||||
margin: 8px 0 0;
|
||||
@@ -152,7 +237,9 @@ onMounted(async () => {
|
||||
}
|
||||
|
||||
.row {
|
||||
display: block;
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 10px;
|
||||
padding: 7px 0;
|
||||
border-bottom: 1px dashed var(--line-soft);
|
||||
}
|
||||
@@ -161,10 +248,27 @@ onMounted(async () => {
|
||||
border-bottom: 0;
|
||||
}
|
||||
|
||||
/* 文字列吃满剩余宽度,缩略图固定在右 */
|
||||
.row-main {
|
||||
flex: 1;
|
||||
min-width: 0;
|
||||
}
|
||||
|
||||
.title {
|
||||
display: block;
|
||||
font-size: 14px;
|
||||
line-height: 1.7;
|
||||
overflow-wrap: anywhere;
|
||||
}
|
||||
|
||||
.thumb {
|
||||
flex: 0 0 auto;
|
||||
width: 34px;
|
||||
height: 34px;
|
||||
object-fit: cover;
|
||||
border-radius: 6px;
|
||||
background: var(--card);
|
||||
border: 1px solid var(--line-soft);
|
||||
}
|
||||
|
||||
.badge {
|
||||
@@ -219,12 +323,13 @@ onMounted(async () => {
|
||||
opacity: 0.6;
|
||||
}
|
||||
|
||||
/* 图标 + 版权同排:源码等入口是单色小图标,hover 才亮成强调色 */
|
||||
/* 社交按钮:页脚第一排居中 */
|
||||
.social-row {
|
||||
display: flex;
|
||||
flex-wrap: wrap;
|
||||
gap: 4px;
|
||||
margin-top: 2px;
|
||||
justify-content: center;
|
||||
gap: 6px;
|
||||
margin-bottom: 10px;
|
||||
}
|
||||
|
||||
.foot-meta {
|
||||
|
||||
@@ -3,6 +3,7 @@ import { nextTick, onBeforeUnmount, onMounted, ref, watch } from 'vue'
|
||||
import { RouterLink, useRoute } from 'vue-router'
|
||||
import { site } from '../site'
|
||||
import NavBurger from './NavBurger.vue'
|
||||
import LogoMark from './LogoMark.vue'
|
||||
|
||||
// 手机端导航。原来把 5 个链接平铺在顶栏里:375px 挤成一排小字,
|
||||
// 触点只有十几像素高,320px 的屏还会折行。改成 brand + 汉堡钮,
|
||||
@@ -105,7 +106,10 @@ onBeforeUnmount(() => {
|
||||
<template>
|
||||
<!-- 窄屏时左栏收起,导航回到顶部;下滑隐藏、上滑唤回 -->
|
||||
<header class="topbar" :class="{ hidden }">
|
||||
<RouterLink to="/" class="brand">{{ site.site_title || 'ONE' }}</RouterLink>
|
||||
<RouterLink to="/" class="brand">
|
||||
<span class="mk"><LogoMark /></span>
|
||||
<span>{{ site.site_title || 'ONE' }}</span>
|
||||
</RouterLink>
|
||||
<NavBurger
|
||||
ref="burger"
|
||||
class="burger"
|
||||
@@ -179,6 +183,16 @@ onBeforeUnmount(() => {
|
||||
font-family: var(--serif);
|
||||
font-size: 17px;
|
||||
color: var(--ink);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
gap: 8px;
|
||||
}
|
||||
|
||||
.brand .mk {
|
||||
width: 20px;
|
||||
height: 20px;
|
||||
flex: none;
|
||||
color: var(--ink);
|
||||
}
|
||||
|
||||
.burger {
|
||||
|
||||
@@ -3,7 +3,11 @@ import { reactive } from 'vue'
|
||||
// 全站通用的图片预览(lightbox)。任何地方的配图都可以
|
||||
// openLightbox(list, index) 打开:list 是同组图片的 URL 数组,index 是
|
||||
// 点击的那张。Esc / 点空白 / 关闭钮收起,左右键或箭头在同组图片间切换。
|
||||
// 打开时锁 body 滚动(和菜单 sheet 同一套做法)。
|
||||
//
|
||||
// 注意:这里绝不能碰 body 的 inline overflow——样式表的 overflow-x: clip
|
||||
// 会被整个 overflow: hidden 覆盖,横向从「裁剪」变「可滚动容器」,
|
||||
// 手机上整页能被拖宽(真实事故)。背景滚动由 ImgLightbox 遮罩自己的
|
||||
// @wheel/@touchmove.prevent 拦截,滚动位置天然保留。
|
||||
const state = reactive({
|
||||
list: [],
|
||||
index: 0,
|
||||
@@ -17,12 +21,10 @@ export function openLightbox(list, index = 0) {
|
||||
state.list = list
|
||||
state.index = Math.max(0, Math.min(index, list.length - 1))
|
||||
state.open = true
|
||||
document.body.style.overflow = 'hidden'
|
||||
}
|
||||
|
||||
export function closeLightbox() {
|
||||
state.open = false
|
||||
document.body.style.overflow = ''
|
||||
}
|
||||
|
||||
export function stepLightbox(delta) {
|
||||
|
||||
@@ -22,7 +22,8 @@ const routes = [
|
||||
{ path: ':id', name: 'admin-edit', component: () => import('./admin/EditorView.vue') },
|
||||
{ path: 'tags', name: 'admin-tags', component: () => import('./admin/TagsView.vue') },
|
||||
{ path: 'projects', name: 'admin-projects', component: () => import('./admin/ProjectsView.vue') },
|
||||
{ path: 'settings', name: 'admin-settings', component: () => import('./admin/SettingsView.vue') }
|
||||
{ path: 'settings', name: 'admin-settings', component: () => import('./admin/SettingsView.vue') },
|
||||
{ path: 'account', name: 'admin-account', component: () => import('./admin/AccountView.vue') }
|
||||
]
|
||||
},
|
||||
|
||||
|
||||
+10
-4
@@ -5,7 +5,7 @@ import { setThumbBase } from './utils'
|
||||
// 暗色皮肤固定为 ink —— 是当前唯一支持的暗端皮肤。
|
||||
const DARK_SKIN = 'ink'
|
||||
// 亮色皮肤的合法集合(后台 Settings 也只让站主从这里选)
|
||||
const LIGHT_SKINS = ['paper', 'sage', 'rose']
|
||||
const LIGHT_SKINS = ['paper']
|
||||
|
||||
// 客户端显示模式 —— 持久化在 localStorage
|
||||
const MODE_KEY = 'one.themeMode'
|
||||
@@ -53,7 +53,7 @@ function systemPrefersDark() {
|
||||
|
||||
// 模式 → 实际 data-theme 值
|
||||
//
|
||||
// light / auto 亮端 → site.light_skin_id(站主在后台选的"基础亮色皮肤")
|
||||
// light / auto 亮端 → 固定纸感(paper);皮肤选择已精简,暗端固定墨色
|
||||
// dark → ink(强制暗色)
|
||||
//
|
||||
// 后台的"基础亮色皮肤"是访客在任何「浅色偏好」下都会看到的;
|
||||
@@ -97,11 +97,16 @@ export const site = reactive({
|
||||
custom_css: {},
|
||||
// 站主自定义 JS(统计脚本等),公开页注入一次,/admin 不注入
|
||||
custom_js: '',
|
||||
// 上传文件的公开域名(R2 直链前缀)。前端靠它判断哪些图片可以转本站缩略图,
|
||||
// 也用它解析头像 URL。
|
||||
uploads_public_base: '',
|
||||
// 站主头像的解析结果(后端按 owner_avatar_key + 存储端算出来;空=未设置)
|
||||
author_avatar_url: '',
|
||||
themeMode: readMode(),
|
||||
loaded: false
|
||||
})
|
||||
|
||||
// data-theme → 前台皮肤。classic: paper/sage/rose/ink;vivid: vivid/vivid-dark
|
||||
// data-theme → 前台皮肤。classic: paper/ink(亮端固定纸感);vivid: vivid/vivid-dark
|
||||
// data-admin-theme → 后台明暗(light / dark),跟 site.themeMode 同步
|
||||
// data-ui → 整站 UI 版本(classic / vivid)
|
||||
//
|
||||
@@ -129,7 +134,7 @@ function applyTheme(animate = false) {
|
||||
setTimeout(() => el.classList.remove('theme-anim'), 300)
|
||||
}
|
||||
const isDark = site.themeMode === 'dark' || (site.themeMode === 'auto' && systemPrefersDark())
|
||||
// vivid 自带亮/暗两套调色板,不复用 paper/sage/rose —— 否则两套 token 会互相打架。
|
||||
// vivid 自带亮/暗两套调色板,不复用 classic 的纸感/墨色 —— 否则两套 token 会互相打架。
|
||||
const vivid = !adminScope && site.ui_id === 'vivid'
|
||||
const theme = vivid
|
||||
? (isDark ? 'vivid-dark' : 'vivid')
|
||||
@@ -157,6 +162,7 @@ export async function loadSite() {
|
||||
// 响应结构:{ settings: {…}, uploads_public_base }
|
||||
const { uploads_public_base, settings } = resp || {}
|
||||
setThumbBase(uploads_public_base)
|
||||
site.uploads_public_base = uploads_public_base || ''
|
||||
Object.assign(site, settings)
|
||||
// 防御性:服务端返回的 light_skin_id 必须是白名单之一,否则兜底 paper
|
||||
if (!isValidLightSkin(site.light_skin_id)) site.light_skin_id = 'paper'
|
||||
|
||||
+136
-71
@@ -31,56 +31,34 @@
|
||||
--col-main: 640px;
|
||||
--col-right: 264px;
|
||||
--gutter: 28px;}
|
||||
:root[data-theme='ink'] {--paper: #1f1d1a;
|
||||
--card: #25221e;
|
||||
--paper-sunken: #2b2722;
|
||||
--ink: #ece5d2;
|
||||
--ink-soft: #c3b58f;
|
||||
--muted: #8c8270;
|
||||
--faint: #6a6155;
|
||||
--line: #3a352e;
|
||||
--line-soft: #2f2b25;
|
||||
--accent: #c3a972;
|
||||
--accent-soft: rgba(195, 169, 114, 0.14);
|
||||
--accent-line: rgba(195, 169, 114, 0.4);}
|
||||
:root[data-theme='sage'] {--paper: #eef0e6;
|
||||
--card: #f6f7ef;
|
||||
--paper-sunken: #e2e6d6;
|
||||
--ink: #2a3127;
|
||||
--ink-soft: #475042;
|
||||
--muted: #6f7a68;
|
||||
--faint: #94a08d;
|
||||
--line: #d6dcc9;
|
||||
--line-soft: #e6e9d9;
|
||||
--accent: #5f7b5c;
|
||||
--accent-soft: rgba(95, 123, 92, 0.12);
|
||||
--accent-line: rgba(95, 123, 92, 0.38);}
|
||||
:root[data-theme='rose'] {--paper: #f7eee6;
|
||||
--card: #fdf5ee;
|
||||
--paper-sunken: #ecdfd3;
|
||||
--ink: #3a2922;
|
||||
--ink-soft: #5e463d;
|
||||
--muted: #9a7c6f;
|
||||
--faint: #b89c91;
|
||||
--line: #ead9cb;
|
||||
--line-soft: #f0e2d5;
|
||||
--accent: #a55a4a;
|
||||
--accent-soft: rgba(165, 90, 74, 0.1);
|
||||
--accent-line: rgba(165, 90, 74, 0.38);}
|
||||
:root[data-admin-theme='dark'] {--admin-bg: #1a1815;
|
||||
:root[data-theme='ink'] {/* 墨:暖炭底、暖白字、鎏金点缀。比旧版更中性(褪掉黄褐相),
|
||||
层次靠三档灰阶拉开;强调金提亮提纯,暗底上对比更足 */
|
||||
--paper: #191817;
|
||||
--card: #201e1c;
|
||||
--paper-sunken: #262420;
|
||||
--ink: #e7e3da;
|
||||
--ink-soft: #b8b2a6;
|
||||
--muted: #867f73;
|
||||
--faint: #5f594f;
|
||||
--line: #34302b;
|
||||
--line-soft: #292623;
|
||||
--accent: #d9b97c;
|
||||
--accent-soft: rgba(217, 185, 124, 0.12);
|
||||
--accent-line: rgba(217, 185, 124, 0.4);}
|
||||
:root[data-admin-theme='dark'] {--admin-bg: #191817;
|
||||
--admin-paper: var(--admin-bg);
|
||||
--admin-card: #25221e;
|
||||
--admin-paper-sunken: #2f2b25;
|
||||
--admin-ink: #ece5d2;
|
||||
--admin-ink-soft: #c3b58f;
|
||||
--admin-muted: #9a8f7e;
|
||||
--admin-faint: #6e6557;
|
||||
--admin-line: #3a352e;
|
||||
--admin-line-soft: #2f2b25;
|
||||
--admin-accent: #c3a972;
|
||||
--admin-accent-soft: rgba(195, 169, 114, 0.16);
|
||||
--admin-accent-line: rgba(195, 169, 114, 0.42);
|
||||
--admin-on-accent: #1a1815;
|
||||
--admin-card: #201e1c;
|
||||
--admin-paper-sunken: #262420;
|
||||
--admin-ink: #e7e3da;
|
||||
--admin-ink-soft: #b8b2a6;
|
||||
--admin-muted: #948c7f;
|
||||
--admin-faint: #635c51;
|
||||
--admin-line: #34302b;
|
||||
--admin-line-soft: #292623;
|
||||
--admin-accent: #d9b97c;
|
||||
--admin-accent-soft: rgba(217, 185, 124, 0.16);
|
||||
--admin-accent-line: rgba(217, 185, 124, 0.42);
|
||||
--admin-on-accent: #191817;
|
||||
--admin-danger: #d68d75;
|
||||
--admin-shadow: 0 4px 14px rgba(0, 0, 0, 0.4);
|
||||
--admin-overlay: rgba(0, 0, 0, 0.6);}
|
||||
@@ -230,7 +208,10 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
min-width: 0;}
|
||||
.prose {font-size: 16.5px;
|
||||
line-height: var(--lh);
|
||||
color: var(--ink);}
|
||||
color: var(--ink);
|
||||
/* anywhere 而非 break-word:长 URL/长 token 要参与 min-content 计算,
|
||||
否则时间线正文里的裸链接会把列撑破(真机上浏览器缩放适配后整页缩小+右侧留白) */
|
||||
overflow-wrap: anywhere;}
|
||||
.prose > :first-child {margin-top: 22px;}
|
||||
.prose p {margin: 0 0 1.1em;}
|
||||
.prose > p:first-of-type::first-letter {float: left;
|
||||
@@ -254,6 +235,17 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
margin-top: 8px;
|
||||
background: var(--accent);}
|
||||
.prose h4 {font-size: 16.5px;}
|
||||
/* 悬停浮现的标题锚点(enhanceProse 注入,指向 heading id) */
|
||||
.prose .h-anchor {opacity: 0;
|
||||
margin-left: 8px;
|
||||
font-family: var(--mono);
|
||||
font-size: 0.72em;
|
||||
color: var(--faint);
|
||||
text-decoration: none;
|
||||
border-bottom: 0;
|
||||
transition: opacity .2s;}
|
||||
.prose h2:hover .h-anchor, .prose h3:hover .h-anchor, .prose h4:hover .h-anchor {opacity: 1;}
|
||||
.prose .h-anchor:hover {color: var(--accent);}
|
||||
.prose blockquote {margin: 1.4em 0;
|
||||
padding: 2px 0 2px 18px;
|
||||
border-left: 2px solid var(--accent-line);
|
||||
@@ -273,12 +265,32 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
background: var(--paper-sunken);
|
||||
padding: 1px 5px;
|
||||
border-radius: 3px;}
|
||||
.prose .pre-wrap {position: relative;}
|
||||
.pre-copy {position: absolute;
|
||||
top: 8px;
|
||||
right: 8px;
|
||||
z-index: 1;
|
||||
padding: 3px 10px;
|
||||
border: 0;
|
||||
border-radius: 5px;
|
||||
font-size: 12px;
|
||||
color: inherit;
|
||||
background: color-mix(in srgb, var(--ink) 14%, transparent);
|
||||
opacity: 0;
|
||||
cursor: pointer;
|
||||
transition: opacity .15s, transform .08s;}
|
||||
.pre-copy:hover {opacity: 1;}
|
||||
.pre-wrap:hover .pre-copy {opacity: 0.85;}
|
||||
.pre-copy:active {transform: translateY(2px);}
|
||||
.pre-copy.done {opacity: 1;
|
||||
color: var(--accent);}
|
||||
.prose pre {background: var(--paper-sunken);
|
||||
border: 1px solid var(--line-soft);
|
||||
border-radius: 4px;
|
||||
padding: 14px 16px;
|
||||
overflow-x: auto;
|
||||
line-height: 1.7;}
|
||||
border-radius: 10px;
|
||||
padding: 16px 18px;
|
||||
overflow: auto;
|
||||
line-height: 1.7;
|
||||
max-height: 30.5em;}
|
||||
.prose pre code {background: none;
|
||||
padding: 0;
|
||||
font-size: 13.5px;}
|
||||
@@ -289,14 +301,22 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
background: var(--line);
|
||||
margin: 2em 0;}
|
||||
.prose table {width: 100%;
|
||||
border-collapse: collapse;
|
||||
margin: 1.4em 0;
|
||||
font-size: 15px;}
|
||||
.prose th, .prose td {border: 1px solid var(--line);
|
||||
padding: 7px 10px;
|
||||
border-collapse: separate;
|
||||
border-spacing: 0;
|
||||
margin: 1.6em 0;
|
||||
font-size: 14.5px;
|
||||
border: 1px solid var(--line);
|
||||
border-radius: 10px;
|
||||
overflow: hidden;}
|
||||
.prose th, .prose td {border: 0;
|
||||
border-bottom: 1px solid var(--line-soft);
|
||||
padding: 11px 16px;
|
||||
text-align: left;}
|
||||
.prose tr > * + * {border-left: 1px solid var(--line-soft);}
|
||||
.prose tbody tr:last-child td {border-bottom: 0;}
|
||||
.prose th {background: var(--paper-sunken);
|
||||
font-weight: 600;}
|
||||
.prose tbody tr:nth-child(even) {background: color-mix(in srgb, var(--paper-sunken) 55%, transparent);}
|
||||
.prose-short {font-size: 20px;
|
||||
line-height: 1.9;}
|
||||
.prose-short > p:first-of-type::first-letter {float: none;
|
||||
@@ -835,17 +855,37 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
0%, 100% {opacity: 1;}
|
||||
50% {opacity: 0.3;}
|
||||
}
|
||||
/* md 页签容器现在是 CodeMirror 挂载点(原为 textarea) */
|
||||
.md-pane {width: 100%;
|
||||
min-height: 460px;
|
||||
border: 1px solid var(--admin-line);
|
||||
border-radius: 3px;
|
||||
background: var(--admin-card);
|
||||
padding: 18px 22px;
|
||||
font-family: var(--mono);
|
||||
font-size: 14px;
|
||||
line-height: 1.7;
|
||||
padding: 6px 14px;
|
||||
color: var(--admin-ink);
|
||||
resize: vertical;
|
||||
overflow: hidden;}
|
||||
.md-pane:focus-within {border-color: var(--admin-accent);}
|
||||
/* 轻提示栈:上传进度 / 转存结果 / 校验失败 */
|
||||
.toast-stack {position: fixed;
|
||||
right: 18px;
|
||||
bottom: 18px;
|
||||
z-index: 90;
|
||||
display: flex;
|
||||
flex-direction: column;
|
||||
gap: 8px;
|
||||
max-width: 360px;}
|
||||
.toast {padding: 9px 14px;
|
||||
border-radius: 6px;
|
||||
font-size: 13px;
|
||||
line-height: 1.6;
|
||||
color: var(--admin-ink);
|
||||
background: var(--admin-card);
|
||||
border: 1px solid var(--admin-line);
|
||||
box-shadow: 0 6px 24px rgba(0,0,0,.12);
|
||||
overflow-wrap: anywhere;}
|
||||
.toast.ok {border-color: color-mix(in srgb, var(--admin-accent) 55%, transparent);}
|
||||
.toast.err {border-color: #c26a55;
|
||||
color: #b4553f;
|
||||
outline: none;}
|
||||
.md-pane:focus {border-color: var(--admin-accent);}
|
||||
.toolbar {display: flex;
|
||||
@@ -868,12 +908,13 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
color: var(--admin-muted);
|
||||
margin-right: 4px;
|
||||
text-transform: uppercase;}
|
||||
.tb-btn {width: 28px;
|
||||
height: 28px;
|
||||
/* xLog 式工具栏按钮:方形圆角、线性图标、悬停出底框 */
|
||||
.tb-btn {width: 32px;
|
||||
height: 32px;
|
||||
border: 1px solid transparent;
|
||||
border-radius: 3px;
|
||||
border-radius: 6px;
|
||||
background: transparent;
|
||||
color: var(--admin-ink-soft);
|
||||
color: var(--admin-muted);
|
||||
cursor: pointer;
|
||||
font-size: 12.5px;
|
||||
display: inline-flex;
|
||||
@@ -886,9 +927,12 @@ html.topbar-hidden {--topbar-h: 0px;}
|
||||
border-color: var(--admin-line);
|
||||
color: var(--admin-ink);}
|
||||
}
|
||||
.tb-btn.italic {font-style: italic;}
|
||||
.tb-btn.mono {font-family: var(--mono);
|
||||
font-size: 11.5px;}
|
||||
.tb-btn svg {width: 17px;
|
||||
height: 17px;}
|
||||
.tb-text {font-family: var(--mono);
|
||||
font-size: 11.5px;
|
||||
font-weight: 700;
|
||||
color: inherit;}
|
||||
.tb-popover {display: flex;
|
||||
gap: 6px;
|
||||
padding: 8px;
|
||||
@@ -1384,3 +1428,24 @@ a.cm-name-a:hover {color: var(--accent);}
|
||||
.cm-more-r {padding: 10px 0;}
|
||||
.cm-input {font-size: 16px;}
|
||||
}
|
||||
/* 编辑器图片缩放把手:Milkdown 图片块 hover 底部出现拖拽条(上下拖调高度,
|
||||
比例存进 markdown 的 alt)。默认半透明让访客知道它在那儿。 */
|
||||
.admin-shell .image-resize-handle {opacity: 0.45;}
|
||||
.admin-shell .image-wrapper:hover .image-resize-handle {opacity: 1;}
|
||||
|
||||
/* lightbox 打开时藏掉吸顶/固定栏:一是全屏观感,二是绕开真机上
|
||||
backdrop-filter 元素合成层盖过遮罩的 Chromium 绘制问题 */
|
||||
body.lb-open .sticky-head,
|
||||
body.lb-open .topbar,
|
||||
body.lb-open .reading-bar {visibility: hidden;}
|
||||
|
||||
/* classic 文章页阅读进度条:视口顶部细线,vivid 的同款能力 */
|
||||
.reading-bar {position: fixed;
|
||||
top: 0;
|
||||
left: 0;
|
||||
height: 2px;
|
||||
width: 0;
|
||||
background: var(--accent);
|
||||
z-index: 60;
|
||||
transition: width .1s linear;
|
||||
pointer-events: none;}
|
||||
@@ -1,6 +1,6 @@
|
||||
<script setup>
|
||||
import { computed, onBeforeUnmount, onMounted, ref } from 'vue'
|
||||
import { sanitizeHtml } from '../../utils'
|
||||
import { applyImageRatio, sanitizeHtml } from '../../utils'
|
||||
import { openLightbox } from '../../lightbox'
|
||||
import CommentSection from '../../components/comments/CommentSection.vue'
|
||||
import LinkCard from '../../components/LinkCard.vue'
|
||||
@@ -168,7 +168,7 @@ function onTocClick(e) {
|
||||
<!-- 短文不渲染标题:正文第一句就是全部,再给个截断标题是重复 -->
|
||||
<h1 v-if="isShort" class="sr-only">{{ title }}</h1>
|
||||
|
||||
<div class="prose" :class="{ 'prose-note': isShort }" v-html="sanitizeHtml(props.contentHtml)" />
|
||||
<div class="prose" :class="{ 'prose-note': isShort }" v-html="applyImageRatio(sanitizeHtml(props.contentHtml))" />
|
||||
|
||||
<!-- 短文配图:Twitter 式网格(快发盒上传);点图开预览 -->
|
||||
<div
|
||||
|
||||
@@ -1,6 +1,13 @@
|
||||
<script setup>
|
||||
import { RouterLink } from 'vue-router'
|
||||
import { site } from '../../site'
|
||||
import { socialIcon } from '../../socialIcons'
|
||||
|
||||
// 社交排只放站主自己的账号;源码仓库是「项目信息」,和 classic 页脚一样单独
|
||||
// 成行挂在版权旁边(RightRail 的 .foot-meta)。混在一起会让人以为这是本站的
|
||||
// 社交身份之一,而它其实是代码仓库入口。
|
||||
const PROJECT_REPO = 'https://git.gopher.ink/mirrors2/ONE'
|
||||
const social = (site.social_links || []).filter((s) => s && s.url && s.url !== PROJECT_REPO)
|
||||
|
||||
// 余白页脚。对应设计稿的 <footer class="foot">。
|
||||
//
|
||||
@@ -21,7 +28,20 @@ const links = [
|
||||
<template>
|
||||
<footer class="foot">
|
||||
<div class="quote">What’s left unsaid holds the most weight.</div>
|
||||
<div>{{ site.footer_note }}<template v-if="site.icp"> · {{ site.icp }}</template></div>
|
||||
<div v-if="social.length" class="foot-social">
|
||||
<a
|
||||
v-for="s in social"
|
||||
:key="s.label + s.url"
|
||||
:href="s.url"
|
||||
:title="s.label"
|
||||
:aria-label="s.label"
|
||||
:target="s.url.startsWith('http') ? '_blank' : undefined"
|
||||
:rel="s.url.startsWith('http') ? 'noopener' : undefined"
|
||||
>
|
||||
<svg v-if="socialIcon(s.url)" viewBox="0 0 24 24" aria-hidden="true"><path :d="socialIcon(s.url)" /></svg>
|
||||
<span v-else>{{ s.label }}</span>
|
||||
</a>
|
||||
</div>
|
||||
<div class="foot-nav">
|
||||
<template v-for="(l, i) in links" :key="l.to">
|
||||
<span v-if="i" class="sep">·</span>
|
||||
@@ -30,5 +50,13 @@ const links = [
|
||||
<span class="sep">·</span>
|
||||
<a href="/rss.xml">RSS</a>
|
||||
</div>
|
||||
<!-- 项目信息:固定的源码入口 + 版权,压在最后。和上面那排社交账号分开——
|
||||
它是代码仓库入口,不是站主的社交身份(顺序同 classic 的 RightRail) -->
|
||||
<div class="foot-meta">
|
||||
<a :href="PROJECT_REPO" title="项目源码" aria-label="项目源码" target="_blank" rel="noopener">
|
||||
<svg viewBox="0 0 24 24" aria-hidden="true"><path :d="socialIcon(PROJECT_REPO)" /></svg>
|
||||
</a>
|
||||
<span>{{ site.footer_note }}<template v-if="site.icp"> · {{ site.icp }}</template></span>
|
||||
</div>
|
||||
</footer>
|
||||
</template>
|
||||
@@ -3,6 +3,7 @@ import { nextTick, onBeforeUnmount, onMounted, ref, watch } from 'vue'
|
||||
import { RouterLink, useRoute } from 'vue-router'
|
||||
import { site } from '../../site'
|
||||
import NavBurger from '../../components/NavBurger.vue'
|
||||
import AuthorAvatar from '../../components/AuthorAvatar.vue'
|
||||
|
||||
// 余白顶栏。对应设计稿的 <header class="top">:品牌 / 导航 / 操作三块,
|
||||
// 滚动过 8px 加 .scrolled(设计稿的「四态里的第一态」)。
|
||||
@@ -27,7 +28,6 @@ const links = [
|
||||
{ to: '/about', label: '关于', en: 'About' }
|
||||
]
|
||||
|
||||
const initial = () => (site.author_name || site.site_title || 'O').trim().slice(0, 1).toUpperCase()
|
||||
const title = () => site.site_title?.split(/[·|]/)[0]?.trim() || 'ONE'
|
||||
|
||||
function isOn(l) {
|
||||
@@ -94,7 +94,7 @@ function toggleTheme() {
|
||||
<header class="top" :class="{ scrolled }">
|
||||
<div class="top-in">
|
||||
<RouterLink class="brand" to="/">
|
||||
<span class="av">{{ initial() }}</span>
|
||||
<span class="av"><AuthorAvatar /></span>
|
||||
<span>{{ title() }}</span>
|
||||
</RouterLink>
|
||||
<nav class="nav" aria-label="站点导航">
|
||||
@@ -115,7 +115,7 @@ function toggleTheme() {
|
||||
必须待在 .top 外面:.top 有 backdrop-filter,会给 fixed 后代当包含块。 -->
|
||||
<div class="dock">
|
||||
<RouterLink class="dock-brand" to="/">
|
||||
<span class="av">{{ initial() }}</span>
|
||||
<span class="av"><AuthorAvatar /></span>
|
||||
<span>{{ title() }}</span>
|
||||
</RouterLink>
|
||||
<NavBurger
|
||||
|
||||
@@ -96,8 +96,12 @@ html[data-ui='vivid'] .prose code {font-family:var(--mono);font-size:.88em;
|
||||
padding:2px 7px;border-radius:6px;}
|
||||
html[data-ui='vivid'] .prose pre {background:color-mix(in srgb,var(--ink) 92%,var(--accent));
|
||||
color:#e8e8f0;padding:18px 20px;border-radius:12px;
|
||||
overflow-x:auto;font-size:13.5px;line-height:1.7;
|
||||
box-shadow:var(--shadow-lg);}
|
||||
overflow:auto;font-size:13.5px;line-height:1.7;
|
||||
box-shadow:var(--shadow-lg);
|
||||
max-height:30.5em;}
|
||||
/* 复制按钮(vivid 配色:浅字浮在深底上) */
|
||||
html[data-ui='vivid'] .pre-copy {color:#e8e8f0;
|
||||
background:rgba(255,255,255,.14);}
|
||||
/* 暗色下「92% ink」混出的是浅底,浅底配浅字没法读;暗端换深底微混强调色 */
|
||||
html[data-ui='vivid'][data-theme='vivid-dark'] .prose pre {
|
||||
background:color-mix(in srgb,var(--paper) 86%,var(--accent));
|
||||
@@ -215,3 +219,17 @@ html[data-ui='vivid'] .sr-only {position: absolute;
|
||||
white-space: nowrap;
|
||||
border: 0;}
|
||||
html[data-ui='vivid'] .toc a:active { color: var(--accent); }
|
||||
|
||||
/* ---- 表格(xLog 式:圆角容器 + 斑马纹,替代满格线) ---- */
|
||||
html[data-ui='vivid'] .prose table {width:100%;
|
||||
border-collapse:separate;border-spacing:0;
|
||||
margin:1.8em 0;font-size:14px;
|
||||
border:1px solid var(--line);border-radius:12px;overflow:hidden;}
|
||||
html[data-ui='vivid'] .prose th, html[data-ui='vivid'] .prose td {border:0;
|
||||
border-bottom:1px solid var(--line-soft);
|
||||
padding:12px 18px;text-align:left;}
|
||||
html[data-ui='vivid'] .prose tr > * + * {border-left:1px solid var(--line-soft);}
|
||||
html[data-ui='vivid'] .prose tbody tr:last-child td {border-bottom:0;}
|
||||
html[data-ui='vivid'] .prose th {background:var(--accent-soft);font-weight:600;}
|
||||
html[data-ui='vivid'] .prose tbody tr:nth-child(even) {background:var(--card);}
|
||||
/* 标题锚点 + 复制按钮沿用 classic 的 .h-anchor/.pre-copy 基础样式 */
|
||||
@@ -15,15 +15,8 @@ html[data-ui='vivid'] .brand {display:flex;align-items:center;gap:10px;
|
||||
@media (hover: hover) and (pointer: fine) {
|
||||
html[data-ui='vivid'] .brand:hover {transform:scale(1.04)}
|
||||
}
|
||||
/* .av 品牌标记:顶栏一枚,菜单里那枚随菜单头一起撤了(顶栏浮在菜单上) */
|
||||
html[data-ui='vivid'] .brand .av {width:30px;height:30px;border-radius:50%;
|
||||
background:linear-gradient(135deg,var(--accent),var(--accent-deep));
|
||||
display:grid;place-items:center;color:#fff;font-size:13px;font-weight:800;
|
||||
box-shadow:0 0 0 2px var(--paper),0 0 0 3.5px var(--accent-soft);
|
||||
position:relative;}
|
||||
html[data-ui='vivid'] .brand .av::after {content:"";position:absolute;right:-1px;bottom:-1px;
|
||||
width:9px;height:9px;border-radius:50%;
|
||||
background:#34c759;border:2px solid var(--paper);}
|
||||
/* .av 品牌标记:原来这里是一条 .brand .av 规则,但它被下面 :is(.brand,.dock-brand)
|
||||
那条同特指度、且位置更靠后的规则完整覆盖了——等于死规则。合并成一条,避免两处漂移。 */
|
||||
html[data-ui='vivid'] .nav {display:flex;gap:2px;flex:1;justify-content:center}
|
||||
html[data-ui='vivid'] .nav a {position:relative;font-size:13.5px;font-weight:600;color:var(--soft);
|
||||
padding:8px 14px;border-radius:999px;
|
||||
@@ -74,9 +67,10 @@ html[data-ui='vivid'] .dock-brand {display:flex;align-items:center;gap:9px;
|
||||
@media (max-width:720px) {
|
||||
html[data-ui='vivid'] .dock {display:flex}
|
||||
}
|
||||
html[data-ui='vivid'] :is(.brand, .dock-brand) .av {width:30px;height:30px;border-radius:50%;
|
||||
background:linear-gradient(135deg,var(--accent),var(--accent-deep));
|
||||
display:grid;place-items:center;color:#fff;font-size:13px;font-weight:800;
|
||||
/* 品牌标记换成站标「一横」:它自身就是圆,所以去掉渐变圆盘与首字母字号;
|
||||
右下角那颗绿色在线点保留(它是「有人在写」的信号,不属于被替换的部分)。 */
|
||||
html[data-ui='vivid'] :is(.brand, .dock-brand) .av {width:30px;height:30px;flex:none;
|
||||
color:var(--ink);
|
||||
box-shadow:0 0 0 2px var(--paper),0 0 0 3.5px var(--accent-soft);
|
||||
position:relative;}
|
||||
html[data-ui='vivid'] :is(.brand, .dock-brand) .av::after {content:"";position:absolute;right:-1px;bottom:-1px;
|
||||
@@ -169,6 +163,25 @@ html[data-ui='vivid'] .foot {max-width:1100px;margin:40px auto 0;padding:28px 28
|
||||
border-top:1px solid var(--line);
|
||||
text-align:center;color:var(--muted);font-size:12.5px;line-height:2;}
|
||||
html[data-ui='vivid'] .foot a {color:var(--accent);font-weight:600;transition:opacity .25s}
|
||||
/* 页脚社交排:图标居中一行,与 classic 页脚同步 */
|
||||
html[data-ui='vivid'] .foot-social {display:flex;justify-content:center;align-items:center;
|
||||
gap:18px;margin:14px 0 18px;}
|
||||
html[data-ui='vivid'] .foot-social a {color:var(--soft);font-weight:400;
|
||||
display:inline-flex;align-items:center;justify-content:center;
|
||||
width:30px;height:30px;border-radius:8px;transition:color .25s,background .25s;}
|
||||
html[data-ui='vivid'] .foot-social a:hover {color:var(--accent);background:var(--accent-soft);}
|
||||
html[data-ui='vivid'] .foot-social svg {width:17px;height:17px;fill:currentColor;}
|
||||
html[data-ui='vivid'] .foot-social span {font-size:12px;}
|
||||
/* 项目信息行:源码入口 + 版权。刻意不并进 .foot-social——那一排是站主的社交
|
||||
身份,源码是仓库入口,混在一起会让人以为它也是一个社交账号。
|
||||
放在 .foot a 规则之后:两者特指度相同,靠后者才能压掉默认的强调色。 */
|
||||
html[data-ui='vivid'] .foot-meta {display:flex;justify-content:center;align-items:center;
|
||||
gap:8px;margin:16px 0 0;color:var(--muted);}
|
||||
html[data-ui='vivid'] .foot-meta a {display:inline-flex;align-items:center;justify-content:center;
|
||||
width:26px;height:26px;border-radius:7px;color:var(--soft);font-weight:400;
|
||||
transition:color .25s,background .25s;}
|
||||
html[data-ui='vivid'] .foot-meta a:hover {color:var(--accent);background:var(--accent-soft);}
|
||||
html[data-ui='vivid'] .foot-meta svg {width:15px;height:15px;fill:currentColor;}
|
||||
@media (hover: hover) and (pointer: fine) {
|
||||
html[data-ui='vivid'] .foot a:hover {opacity:.75}
|
||||
}
|
||||
|
||||
@@ -121,7 +121,12 @@ html[data-ui='vivid'] .note {display:block;background:transparent;
|
||||
}
|
||||
html[data-ui='vivid'] .note .meta {display:flex;gap:10px;align-items:center;
|
||||
font-size:12px;color:var(--muted);font-weight:600;margin-top:16px;}
|
||||
html[data-ui='vivid'] .note .body {margin:0;font-size:15.5px;line-height:1.8;color:var(--text);}
|
||||
html[data-ui='vivid'] .note .body {margin:0;font-size:15.5px;line-height:1.8;color:var(--text);
|
||||
/* 短文正文用的是 .body 而不是 .prose,所以拿不到 styles.css 里 .prose 的
|
||||
overflow-wrap:anywhere——裸链接这种不可断行的长 token 会把整列撑到 550px+,
|
||||
手机上表现为页面横向能滚、右侧留白。用 anywhere 而非 break-word:
|
||||
要让它参与 min-content 计算才真正压得住列宽。 */
|
||||
overflow-wrap:anywhere;}
|
||||
html[data-ui='vivid'] .note .body a {color:var(--accent);font-weight:600;
|
||||
border-bottom:1px solid color-mix(in srgb,var(--accent) 40%,transparent);
|
||||
transition:border-color .25s;}
|
||||
|
||||
+37
-1
@@ -3,7 +3,7 @@ import DOMPurify from 'dompurify'
|
||||
// 后端 goldmark 已转义原始 HTML,这里再过一道 DOMPurify 作纵深防御,
|
||||
// 所有 v-html 出口必须经过它。
|
||||
export function sanitizeHtml(html) {
|
||||
return DOMPurify.sanitize(html || '')
|
||||
return enhanceProse(DOMPurify.sanitize(html || ''))
|
||||
}
|
||||
|
||||
// ---------- 缩略图 ----------
|
||||
@@ -28,6 +28,42 @@ export function thumbURL(u, w = 480) {
|
||||
return '/uploads/thumb/' + key + '?w=' + w
|
||||
}
|
||||
|
||||
// ---------- xLog 式排版增强 ----------
|
||||
// 对消毒后的正文 HTML 做三件展示层增强(markdown/库里内容不动):
|
||||
// 1) pre 包一层容器并注入悬停复制按钮;
|
||||
// 2) 带 id 的标题(withHeadingIds 生成)尾部加 # 锚点;
|
||||
// 3) (盘古之白在后端渲染出口做,见 backend/internal/render/pangu.go)
|
||||
export function enhanceProse(html) {
|
||||
if (!html) return html
|
||||
// 复制按钮:包在 .pre-wrap 里,按钮悬浮于 pre 右上
|
||||
html = html
|
||||
.replace(/<pre\b/g, '<div class="pre-wrap"><button type="button" class="pre-copy" aria-label="复制代码">复制</button><pre')
|
||||
.replace(/<\/pre>/g, '</pre></div>')
|
||||
// 标题锚点:h2-h4 且有 id 的,末尾补一个 # 链接(悬停浮现)
|
||||
html = html.replace(
|
||||
/<h([2-4])([^>]*\bid="([^"]+)"[^>]*)>([\s\S]*?)<\/h\1>/g,
|
||||
(m, lvl, attrs, id, inner) =>
|
||||
`<h${lvl}${attrs}>${inner}<a class="h-anchor" href="#${id}" aria-label="标题链接">#</a></h${lvl}>`
|
||||
)
|
||||
return html
|
||||
}
|
||||
|
||||
// 编辑器拖拽缩放的比例展示:Milkdown 图片块把高度比例写进 markdown 的 alt
|
||||
// (),渲染出的 <img alt="0.6"> 在这里还原成对应的宽度并居中。
|
||||
// 纯数字 alt 才生效(>=1 的当 100% 处理),正常图片的描述性 alt 不受影响。
|
||||
export function applyImageRatio(html) {
|
||||
if (!html) return html
|
||||
return html.replace(/<img\b[^>]*>/gi, (tag) => {
|
||||
const m = tag.match(/\balt="(\d*\.?\d+)"/i)
|
||||
if (!m) return tag
|
||||
const ratio = Number.parseFloat(m[1])
|
||||
if (!Number.isFinite(ratio) || ratio <= 0 || ratio >= 1) return tag
|
||||
const style = `display:block;width:${(ratio * 100).toFixed(1)}%;max-width:100%;height:auto;margin-inline:auto;`
|
||||
if (/\bstyle="/i.test(tag)) return tag.replace(/\bstyle="/i, 'style="' + style)
|
||||
return tag.replace(/^<img/i, '<img style="' + style + '"')
|
||||
})
|
||||
}
|
||||
|
||||
// 时间线正文 HTML(短文全文 / 长文 600 字符截断)里的 <img> 换缩略图 + 补懒加载。
|
||||
// 只在展示层重写,库里存的正文不动。截断的 HTML 可能带半截标签,
|
||||
// 正则只匹配完整的 <img ...src="..."> ,坏尾巴交给 sanitize/浏览器容错。
|
||||
|
||||
@@ -1,15 +1,16 @@
|
||||
<script setup>
|
||||
import { computed, onMounted, ref, watch } from 'vue'
|
||||
import { computed, onBeforeUnmount, onMounted, ref, watch } from 'vue'
|
||||
import { useRoute } from 'vue-router'
|
||||
import LeftNav from '../components/LeftNav.vue'
|
||||
import RightRail from '../components/RightRail.vue'
|
||||
import YohakuArticle from '../ui/yohaku/YohakuArticle.vue'
|
||||
import CommentSection from '../components/comments/CommentSection.vue'
|
||||
import LinkCard from '../components/LinkCard.vue'
|
||||
import AuthorAvatar from '../components/AuthorAvatar.vue'
|
||||
import { openLightbox } from '../lightbox'
|
||||
import { publicApi } from '../api'
|
||||
import { site, applyDocTitle } from '../site'
|
||||
import { formatDate, minutesLabel, sanitizeHtml } from '../utils'
|
||||
import { applyImageRatio, formatDate, minutesLabel, sanitizeHtml } from '../utils'
|
||||
|
||||
const route = useRoute()
|
||||
const post = ref(null)
|
||||
@@ -33,6 +34,14 @@ function withHeadingIds(html) {
|
||||
const contentHtml = ref('')
|
||||
const headings = ref([])
|
||||
|
||||
// 顶部阅读进度条(classic):滚动过正文才算数,短文太短不显示
|
||||
const progress = ref(0)
|
||||
function onScroll() {
|
||||
const doc = document.documentElement
|
||||
const total = doc.scrollHeight - window.innerHeight
|
||||
progress.value = total > 300 ? Math.min(100, (window.scrollY / total) * 100) : 0
|
||||
}
|
||||
|
||||
async function load() {
|
||||
loading.value = true
|
||||
error.value = ''
|
||||
@@ -42,7 +51,7 @@ async function load() {
|
||||
try {
|
||||
post.value = await publicApi.post(route.params.slug)
|
||||
const prepared = withHeadingIds(post.value.content_html)
|
||||
contentHtml.value = prepared.html
|
||||
contentHtml.value = applyImageRatio(prepared.html)
|
||||
headings.value = prepared.headings
|
||||
applyDocTitle(post.value.kind === 'short' ? '短文' : post.value.title)
|
||||
} catch (e) {
|
||||
@@ -52,11 +61,14 @@ async function load() {
|
||||
}
|
||||
}
|
||||
|
||||
onMounted(load)
|
||||
onMounted(() => {
|
||||
load()
|
||||
window.addEventListener('scroll', onScroll, { passive: true })
|
||||
})
|
||||
onBeforeUnmount(() => window.removeEventListener('scroll', onScroll))
|
||||
watch(() => route.params.slug, load)
|
||||
|
||||
const isShort = computed(() => post.value && post.value.kind === 'short')
|
||||
const initial = computed(() => (site.author_name || 'O').trim().slice(0, 1).toUpperCase())
|
||||
</script>
|
||||
|
||||
<template>
|
||||
@@ -71,6 +83,8 @@ const initial = computed(() => (site.author_name || 'O').trim().slice(0, 1).toUp
|
||||
/>
|
||||
|
||||
<div v-else class="shell">
|
||||
<!-- 阅读进度:贴在视口顶部的细线 -->
|
||||
<div class="reading-bar" :style="{ width: progress + '%' }" aria-hidden="true"></div>
|
||||
<div class="layout">
|
||||
<!-- LeftNav / RightRail 之前 import 了却没渲染,导致整页掉进 236px 的左列。
|
||||
补上,和 HomeView 的三栏一致。 -->
|
||||
@@ -86,7 +100,7 @@ const initial = computed(() => (site.author_name || 'O').trim().slice(0, 1).toUp
|
||||
<article v-else class="wrap" :class="{ short: isShort }">
|
||||
<header class="head">
|
||||
<div class="byline">
|
||||
<div class="avatar">{{ initial }}</div>
|
||||
<div class="avatar"><AuthorAvatar /></div>
|
||||
<div class="who">
|
||||
<span class="author">{{ site.author_name || 'ONE' }}</span>
|
||||
<span class="sub">
|
||||
@@ -146,7 +160,7 @@ const initial = computed(() => (site.author_name || 'O').trim().slice(0, 1).toUp
|
||||
<!-- 评论区(和 vivid 共用同一个组件,见 components/comments/) -->
|
||||
<CommentSection v-if="post" :post-id="post.id" />
|
||||
</main>
|
||||
<RightRail />
|
||||
<RightRail :toc="isShort ? [] : headings" />
|
||||
</div>
|
||||
</div>
|
||||
</template>
|
||||
@@ -174,17 +188,11 @@ const initial = computed(() => (site.author_name || 'O').trim().slice(0, 1).toUp
|
||||
gap: 12px;
|
||||
}
|
||||
|
||||
/* 站标自身是圆,原来的 accent-soft 圆底与衬线首字母一并去掉,只留尺寸与颜色 */
|
||||
.avatar {
|
||||
width: 44px;
|
||||
height: 44px;
|
||||
border-radius: 50%;
|
||||
background: var(--accent-soft);
|
||||
color: var(--accent);
|
||||
display: flex;
|
||||
align-items: center;
|
||||
justify-content: center;
|
||||
font-family: var(--serif);
|
||||
font-size: 18px;
|
||||
color: var(--ink);
|
||||
}
|
||||
|
||||
.who {
|
||||
|
||||
@@ -0,0 +1,78 @@
|
||||
// WebAuthn 的浏览器侧胶水。
|
||||
//
|
||||
// 存在的理由只有一句话:navigator.credentials 要 ArrayBuffer,
|
||||
// 后端 go-webauthn 要 base64url 字符串,两边不会自动转换。
|
||||
// JSON.stringify 一个 PublicKeyCredential 会把 ArrayBuffer 变成 {},
|
||||
// 所以响应必须手工组装成 base64url。
|
||||
//
|
||||
// 只用标准 Web API,不引 @simplewebauthn/browser 之类的包。
|
||||
|
||||
export function isSupported() {
|
||||
return typeof window !== 'undefined' && !!window.PublicKeyCredential && !!navigator.credentials
|
||||
}
|
||||
|
||||
// base64url 字符串 -> ArrayBuffer
|
||||
function toBuf(s) {
|
||||
const bin = atob(s.replace(/-/g, '+').replace(/_/g, '/').padEnd(Math.ceil(s.length / 4) * 4, '='))
|
||||
const out = new Uint8Array(bin.length)
|
||||
for (let i = 0; i < bin.length; i++) out[i] = bin.charCodeAt(i)
|
||||
return out.buffer
|
||||
}
|
||||
|
||||
// ArrayBuffer -> base64url(无填充)
|
||||
function toB64(buf) {
|
||||
const bytes = new Uint8Array(buf)
|
||||
let bin = ''
|
||||
for (let i = 0; i < bytes.length; i++) bin += String.fromCharCode(bytes[i])
|
||||
return btoa(bin).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '')
|
||||
}
|
||||
|
||||
// 服务端给的 options 里这些字段是 base64url,要用前逐个还原成 ArrayBuffer
|
||||
function decodeOptions(pk) {
|
||||
const out = { ...pk }
|
||||
out.challenge = toBuf(pk.challenge)
|
||||
if (pk.user) {
|
||||
out.user = { ...pk.user, id: toBuf(pk.user.id) }
|
||||
}
|
||||
if (Array.isArray(pk.excludeCredentials)) {
|
||||
out.excludeCredentials = pk.excludeCredentials.map((c) => ({ ...c, id: toBuf(c.id) }))
|
||||
}
|
||||
if (Array.isArray(pk.allowCredentials)) {
|
||||
out.allowCredentials = pk.allowCredentials.map((c) => ({ ...c, id: toBuf(c.id) }))
|
||||
}
|
||||
return out
|
||||
}
|
||||
|
||||
// 浏览器返回的凭据 -> 后端能解析的 JSON(全部 base64url)
|
||||
function encodeResponse(cred) {
|
||||
const r = cred.response
|
||||
const pick = ['clientDataJSON', 'attestationObject', 'authenticatorData', 'signature']
|
||||
const response = {}
|
||||
for (const k of pick) {
|
||||
if (r[k] != null) response[k] = toB64(r[k])
|
||||
}
|
||||
// userHandle 可能是 null(发现式登录未回填时),保留 null 而不是转成字符串
|
||||
if ('userHandle' in r) response.userHandle = r.userHandle ? toB64(r.userHandle) : null
|
||||
return {
|
||||
id: cred.id,
|
||||
rawId: toB64(cred.rawId),
|
||||
type: cred.type,
|
||||
authenticatorAttachment: cred.authenticatorAttachment || undefined,
|
||||
clientExtensionResults: cred.getClientExtensionResults ? cred.getClientExtensionResults() : {},
|
||||
response
|
||||
}
|
||||
}
|
||||
|
||||
// register 注册一把新凭据。options 是后端 BeginRegistration 的产物。
|
||||
export async function register(options) {
|
||||
if (!isSupported()) throw new Error('这个浏览器不支持 passkey')
|
||||
const cred = await navigator.credentials.create({ publicKey: decodeOptions(options.publicKey || options) })
|
||||
return encodeResponse(cred)
|
||||
}
|
||||
|
||||
// assert 用已有凭据登录。options 是后端 BeginLogin 的产物。
|
||||
export async function assert(options) {
|
||||
if (!isSupported()) throw new Error('这个浏览器不支持 passkey')
|
||||
const cred = await navigator.credentials.get({ publicKey: decodeOptions(options.publicKey || options) })
|
||||
return encodeResponse(cred)
|
||||
}
|
||||
Reference in new issue
Block a user