后台新增 /admin/account 一页,四块:公开资料、密码、第三方账号、Passkey。 - schema:users 加 role(默认 reader),新表 user_identities、passkeys。 user_identities 上双 UNIQUE —— (provider, extern_uid) 防一个外部账号顶两个身份, (user_id, provider) 防一站主绑两个同平台号,绑错也劫持不了。 extern_uid 存平台稳定 ID,不存用户名(用户名可改)。 - 头像存 files 里的 key 而非 URL,换存储/CDN 不失效;单 key SetSetting 写入, 避开 UpdateSettings 的整表替换会把它抹掉。站主名/简介从设置页挪到账户页, 一个字段只留一个编辑入口。 - OAuth 绑定要求先有后台会话(绑定动作本身是提权路径);已绑的站主身份登录后 直接发 one_session,读者身份仍发 one_reader。 - passkey 走 go-webauthn v0.15.0(最后一条吃 go 1.24 的版本线),可发现凭据登录。 必须显式设 ONE_WEBAUTHN_ORIGINS 才启用,不配就安静关掉。 签名计数只记克隆警告、不硬拦 —— 云同步 passkey 的计数本就不单调。 - 密码故意留在 ONE_ADMIN_PASSWORD,不做哈希入库:这是「解绑一切、删光 passkey 也还能进门」的保底,比 env 明文更值得守。memos 那个 SSO 建号随机密码无重置 入口的坑,从设计上绕开。 已知限制:会话仍是有状态无关的 HMAC cookie,删 passkey / 解绑不会让已发出的 7 天后台会话失效 —— 要修得加一张吊销表。
79 lines
3.0 KiB
JavaScript
79 lines
3.0 KiB
JavaScript
// WebAuthn 的浏览器侧胶水。
|
||
//
|
||
// 存在的理由只有一句话:navigator.credentials 要 ArrayBuffer,
|
||
// 后端 go-webauthn 要 base64url 字符串,两边不会自动转换。
|
||
// JSON.stringify 一个 PublicKeyCredential 会把 ArrayBuffer 变成 {},
|
||
// 所以响应必须手工组装成 base64url。
|
||
//
|
||
// 只用标准 Web API,不引 @simplewebauthn/browser 之类的包。
|
||
|
||
export function isSupported() {
|
||
return typeof window !== 'undefined' && !!window.PublicKeyCredential && !!navigator.credentials
|
||
}
|
||
|
||
// base64url 字符串 -> ArrayBuffer
|
||
function toBuf(s) {
|
||
const bin = atob(s.replace(/-/g, '+').replace(/_/g, '/').padEnd(Math.ceil(s.length / 4) * 4, '='))
|
||
const out = new Uint8Array(bin.length)
|
||
for (let i = 0; i < bin.length; i++) out[i] = bin.charCodeAt(i)
|
||
return out.buffer
|
||
}
|
||
|
||
// ArrayBuffer -> base64url(无填充)
|
||
function toB64(buf) {
|
||
const bytes = new Uint8Array(buf)
|
||
let bin = ''
|
||
for (let i = 0; i < bytes.length; i++) bin += String.fromCharCode(bytes[i])
|
||
return btoa(bin).replace(/\+/g, '-').replace(/\//g, '_').replace(/=+$/, '')
|
||
}
|
||
|
||
// 服务端给的 options 里这些字段是 base64url,要用前逐个还原成 ArrayBuffer
|
||
function decodeOptions(pk) {
|
||
const out = { ...pk }
|
||
out.challenge = toBuf(pk.challenge)
|
||
if (pk.user) {
|
||
out.user = { ...pk.user, id: toBuf(pk.user.id) }
|
||
}
|
||
if (Array.isArray(pk.excludeCredentials)) {
|
||
out.excludeCredentials = pk.excludeCredentials.map((c) => ({ ...c, id: toBuf(c.id) }))
|
||
}
|
||
if (Array.isArray(pk.allowCredentials)) {
|
||
out.allowCredentials = pk.allowCredentials.map((c) => ({ ...c, id: toBuf(c.id) }))
|
||
}
|
||
return out
|
||
}
|
||
|
||
// 浏览器返回的凭据 -> 后端能解析的 JSON(全部 base64url)
|
||
function encodeResponse(cred) {
|
||
const r = cred.response
|
||
const pick = ['clientDataJSON', 'attestationObject', 'authenticatorData', 'signature']
|
||
const response = {}
|
||
for (const k of pick) {
|
||
if (r[k] != null) response[k] = toB64(r[k])
|
||
}
|
||
// userHandle 可能是 null(发现式登录未回填时),保留 null 而不是转成字符串
|
||
if ('userHandle' in r) response.userHandle = r.userHandle ? toB64(r.userHandle) : null
|
||
return {
|
||
id: cred.id,
|
||
rawId: toB64(cred.rawId),
|
||
type: cred.type,
|
||
authenticatorAttachment: cred.authenticatorAttachment || undefined,
|
||
clientExtensionResults: cred.getClientExtensionResults ? cred.getClientExtensionResults() : {},
|
||
response
|
||
}
|
||
}
|
||
|
||
// register 注册一把新凭据。options 是后端 BeginRegistration 的产物。
|
||
export async function register(options) {
|
||
if (!isSupported()) throw new Error('这个浏览器不支持 passkey')
|
||
const cred = await navigator.credentials.create({ publicKey: decodeOptions(options.publicKey || options) })
|
||
return encodeResponse(cred)
|
||
}
|
||
|
||
// assert 用已有凭据登录。options 是后端 BeginLogin 的产物。
|
||
export async function assert(options) {
|
||
if (!isSupported()) throw new Error('这个浏览器不支持 passkey')
|
||
const cred = await navigator.credentials.get({ publicKey: decodeOptions(options.publicKey || options) })
|
||
return encodeResponse(cred)
|
||
}
|