Passkey: 账户设置绑定 + 免密登录(WebAuthn)

- 引入 go-webauthn, Passkey 表存凭据, challenge 会话内存存储(带过期)
- API: /webauthn/register|login begin/complete, /webauthn/passkeys 列表/删除
- 配置 OT_WEBAUTHN_RP_ID/RP_ORIGIN/RP_NAME;登录成功发 JWT+refresh cookie
- 前端 lib/webauthn(编解码+凭据序列化+安全上下文检测), 账户设置绑定区, 登录页免密按钮
- 需 HTTPS 或 localhost(安全上下文)

Co-Authored-By: Claude <noreply@anthropic.com>
This commit is contained in:
Sakurasan
2026-08-16 02:00:08 +08:00
co-authored by Claude
parent 057b1b2c0b
commit 9324a782d5
14 changed files with 677 additions and 13 deletions
+11
View File
@@ -200,6 +200,16 @@ type BalanceLog struct {
CreatedAt time.Time `json:"created_at"`
}
// Passkey WebAuthn 凭据(passkey 绑定/登录)
type Passkey struct {
ID uint64 `gorm:"primaryKey;autoIncrement" json:"id"`
UserID uint64 `gorm:"index;not null" json:"user_id"`
Name string `gorm:"size:64" json:"name"`
CredentialID []byte `gorm:"size:255;not null" json:"-"` // credential.ID
Credential []byte `gorm:"type:blob;not null" json:"-"` // json.Marshal(webauthn.Credential)
CreatedAt time.Time `json:"created_at"`
}
// SystemConfig 系统配置(PLANNING §6.9)
type SystemConfig struct {
Key string `gorm:"primaryKey;size:64" json:"key"`
@@ -218,6 +228,7 @@ func AllModels() []any {
&UsageDaily{},
&RechargeOrder{},
&BalanceLog{},
&Passkey{},
&SystemConfig{},
}
}