diff --git a/internal/service/bot_features_test.go b/internal/service/bot_features_test.go
index 651ab4e..b379bb7 100644
--- a/internal/service/bot_features_test.go
+++ b/internal/service/bot_features_test.go
@@ -555,3 +555,104 @@ func TestBotAdminCodeAndUserCommands(t *testing.T) {
t.Fatalf("delete without confirm should be rejected, got %q", reply.Text)
}
}
+
+func TestBotAdminUnbindMultipleUsers(t *testing.T) {
+ ctx := context.Background()
+ repos, bot := newBotTestService(t)
+ admin := &model.User{Username: "root", PasswordHash: "x", Role: "admin", IsActive: true}
+ viewer := &model.User{Username: "viewer", PasswordHash: "x", Role: "user", IsActive: true}
+ guest := &model.User{Username: "guest", PasswordHash: "x", Role: "user", IsActive: true}
+ for _, user := range []*model.User{admin, viewer, guest} {
+ if err := repos.User.Create(ctx, user); err != nil {
+ t.Fatal(err)
+ }
+ }
+ bindings := []model.TelegramBinding{
+ {TelegramUserID: 9401, TelegramName: "@root", ChatID: 9401, UserID: admin.ID},
+ {TelegramUserID: 9402, TelegramName: "@viewer", ChatID: 9402, UserID: viewer.ID},
+ {TelegramUserID: 9403, TelegramName: "@guest", ChatID: 9403, UserID: guest.ID},
+ }
+ for i := range bindings {
+ if err := repos.DB.Create(&bindings[i]).Error; err != nil {
+ t.Fatal(err)
+ }
+ }
+ channel := &model.NotifyChannel{Name: "Telegram", Type: "telegram", Enabled: true, Config: `{"admin_user_ids":"9401"}`}
+ msg := &TelegramMessage{From: TelegramUser{ID: 9401, Username: "root"}, Chat: TelegramChat{ID: 9401, Type: "private"}}
+
+ reply, err := bot.executeCommand(ctx, channel, msg, "/unbind viewer,guest missing root")
+ if err != nil {
+ t.Fatal(err)
+ }
+ if !strings.Contains(reply.Text, "已解绑:2") || !strings.Contains(reply.Text, "root(管理员)") || !strings.Contains(reply.Text, "missing") {
+ t.Fatalf("unexpected unbind reply: %q", reply.Text)
+ }
+ for _, user := range []*model.User{viewer, guest} {
+ var count int64
+ if err := repos.DB.Model(&model.TelegramBinding{}).Where("user_id = ?", user.ID).Count(&count).Error; err != nil {
+ t.Fatal(err)
+ }
+ if count != 0 {
+ t.Fatalf("%s binding count = %d, want 0", user.Username, count)
+ }
+ }
+ if binding := bot.telegramBinding(ctx, 9401); binding == nil {
+ t.Fatal("admin binding should be protected from /unbind by username")
+ }
+}
+
+func TestBotAdminUnbindInactiveAndInvalidBindings(t *testing.T) {
+ ctx := context.Background()
+ repos, bot := newBotTestService(t)
+ oldTime := time.Now().Add(-45 * 24 * time.Hour)
+ recentTime := time.Now().Add(-2 * 24 * time.Hour)
+ admin := &model.User{Username: "root", PasswordHash: "x", Role: "admin", IsActive: true, LastLoginAt: &oldTime}
+ oldUser := &model.User{Username: "old", PasswordHash: "x", Role: "user", IsActive: true, LastLoginAt: &oldTime}
+ recentUser := &model.User{Username: "recent", PasswordHash: "x", Role: "user", IsActive: true, LastLoginAt: &recentTime}
+ for _, user := range []*model.User{admin, oldUser, recentUser} {
+ if err := repos.User.Create(ctx, user); err != nil {
+ t.Fatal(err)
+ }
+ }
+ for _, binding := range []model.TelegramBinding{
+ {TelegramUserID: 9501, TelegramName: "@root", ChatID: 9501, UserID: admin.ID},
+ {TelegramUserID: 9502, TelegramName: "@old", ChatID: 9502, UserID: oldUser.ID},
+ {TelegramUserID: 9503, TelegramName: "@recent", ChatID: 9503, UserID: recentUser.ID},
+ {TelegramUserID: 9504, TelegramName: "@ghost", ChatID: 9504, UserID: "missing-user"},
+ } {
+ row := binding
+ if err := repos.DB.Create(&row).Error; err != nil {
+ t.Fatal(err)
+ }
+ }
+ channel := &model.NotifyChannel{Name: "Telegram", Type: "telegram", Enabled: true, Config: `{"admin_user_ids":"9501"}`}
+ msg := &TelegramMessage{From: TelegramUser{ID: 9501, Username: "root"}, Chat: TelegramChat{ID: 9501, Type: "private"}}
+
+ reply, err := bot.executeCommand(ctx, channel, msg, "/unbind_inactive 30")
+ if err != nil {
+ t.Fatal(err)
+ }
+ if !strings.Contains(reply.Text, "已解绑:1") || !strings.Contains(reply.Text, "old") {
+ t.Fatalf("unexpected inactive unbind reply: %q", reply.Text)
+ }
+ if binding := bot.telegramBinding(ctx, 9502); binding != nil {
+ t.Fatal("old user binding should be removed")
+ }
+ if binding := bot.telegramBinding(ctx, 9501); binding == nil {
+ t.Fatal("admin binding should be skipped by inactive cleanup")
+ }
+ if binding := bot.telegramBinding(ctx, 9503); binding == nil {
+ t.Fatal("recent user binding should remain")
+ }
+
+ reply, err = bot.executeCommand(ctx, channel, msg, "/unbind_duplicates")
+ if err != nil {
+ t.Fatal(err)
+ }
+ if !strings.Contains(reply.Text, "已解绑:1") || !strings.Contains(reply.Text, "tg:9504") {
+ t.Fatalf("unexpected duplicate cleanup reply: %q", reply.Text)
+ }
+ if binding := bot.telegramBinding(ctx, 9504); binding != nil {
+ t.Fatal("invalid binding should be removed")
+ }
+}
diff --git a/internal/service/telegram_bot.go b/internal/service/telegram_bot.go
index dd3ab51..33c0ffb 100644
--- a/internal/service/telegram_bot.go
+++ b/internal/service/telegram_bot.go
@@ -449,6 +449,8 @@ func (s *TelegramBotService) cmdHelp(ctx context.Context, msg *TelegramMessage)
"/capacity / /users — 容量与用户管理(管理员)\n" +
"/gencode register|renew 天数 [有效天数] — 生成兑换码(管理员)\n" +
"/renew_user 用户名 天数 / /delete_user 用户名 confirm — 续期/删除用户(管理员)\n" +
+ "/unbind 用户1 用户2 — 批量解绑 Telegram 绑定(管理员)\n" +
+ "/unbind_duplicates / /unbind_inactive 天数 — 清理重复/无效绑定或久未登录绑定(管理员)\n" +
"/antishare on play=3 login=3 warn=2 — 防共享策略(管理员)\n" +
"/cleanup on|off|run — 删号规则开关/巡检(管理员)\n" +
"/cleanup_mode any|all|count 2 — 保号模式(管理员)\n" +
diff --git a/internal/service/telegram_commands.go b/internal/service/telegram_commands.go
index 25dfb93..9f2fc16 100644
--- a/internal/service/telegram_commands.go
+++ b/internal/service/telegram_commands.go
@@ -55,6 +55,9 @@ func (s *TelegramBotService) telegramCommandDefinitions(ctx context.Context, cha
{Aliases: []string{"/gencode"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdGenCode(ctx, msg, args), nil }},
{Aliases: []string{"/renew_user"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdUserRenew(ctx, args), nil }},
{Aliases: []string{"/delete_user"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdUserDelete(ctx, args), nil }},
+ {Aliases: []string{"/unbind"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdUnbind(ctx, args), nil }},
+ {Aliases: []string{"/unbind_duplicates"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdUnbindDuplicates(ctx), nil }},
+ {Aliases: []string{"/unbind_inactive"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdUnbindInactive(ctx, args), nil }},
{Aliases: []string{"/devicepolicy", "/policy"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdDevicePolicy(ctx, args), nil }},
{Aliases: []string{"/antishare"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdAntiShare(ctx, args), nil }},
{Aliases: []string{"/cleanup"}, AdminOnly: true, AdminOnlyText: adminOnly, Handle: func(args []string) (telegramCommandReply, error) { return s.cmdCleanup(ctx, args), nil }},
@@ -118,7 +121,7 @@ var telegramSupportedCommandSet = map[string]struct{}{
"/account": {}, "/me": {}, "/signin": {}, "/checkin": {}, "/devices": {}, "/kick": {}, "/setname": {}, "/rename": {}, "/setpass": {}, "/passwd": {}, "/password": {},
"/redeem": {}, "/redeem_register": {}, "/redeem_renew": {},
"/register": {}, "/reg": {}, "/signup": {}, "/registration": {}, "/reg_switch": {}, "/openreg": {},
- "/capacity": {}, "/users": {}, "/gencode": {}, "/renew_user": {}, "/delete_user": {},
+ "/capacity": {}, "/users": {}, "/gencode": {}, "/renew_user": {}, "/delete_user": {}, "/unbind": {}, "/unbind_duplicates": {}, "/unbind_inactive": {},
"/devicepolicy": {}, "/policy": {}, "/antishare": {}, "/cleanup": {}, "/cleanup_mode": {}, "/cleanup_rule": {},
"/ban": {}, "/unban": {}, "/status": {}, "/search": {}, "/downloads": {}, "/stats": {},
}
diff --git a/internal/service/telegram_menu.go b/internal/service/telegram_menu.go
index 6873b8b..cbd4a83 100644
--- a/internal/service/telegram_menu.go
+++ b/internal/service/telegram_menu.go
@@ -847,6 +847,215 @@ func (s *TelegramBotService) cmdUserDelete(ctx context.Context, args []string) t
return s.replyUserDelete(ctx, user.ID)
}
+func (s *TelegramBotService) cmdUnbind(ctx context.Context, args []string) telegramCommandReply {
+ targets := parseTelegramUnbindTargets(args)
+ if len(targets) == 0 {
+ return telegramCommandReply{Text: "用法:/unbind 用户名1 用户名2\n也支持逗号分隔,或使用 tg:TelegramID 按 Telegram ID 解绑。此命令只解绑 Bot,不删除媒体账号。"}
+ }
+ var removed int64
+ var done []string
+ var skipped []string
+ var missing []string
+ for _, target := range targets {
+ if tgIDRaw, ok := strings.CutPrefix(strings.ToLower(target), "tg:"); ok {
+ tgID, err := strconv.ParseInt(tgIDRaw, 10, 64)
+ if err != nil || tgID == 0 {
+ missing = append(missing, target)
+ continue
+ }
+ n, err := s.deleteTelegramBindings(ctx, "telegram_user_id = ?", tgID)
+ if err != nil {
+ return telegramCommandReply{Text: "解绑失败:" + err.Error()}
+ }
+ if n == 0 {
+ missing = append(missing, target)
+ continue
+ }
+ removed += n
+ done = append(done, target)
+ continue
+ }
+
+ user, _ := s.repo.User.FindByUsername(ctx, target)
+ if user == nil {
+ user, _ = s.repo.User.FindByID(ctx, target)
+ }
+ if user == nil {
+ missing = append(missing, target)
+ continue
+ }
+ if user.Role == "admin" {
+ skipped = append(skipped, user.Username+"(管理员)")
+ continue
+ }
+ n, err := s.deleteTelegramBindings(ctx, "user_id = ?", user.ID)
+ if err != nil {
+ return telegramCommandReply{Text: "解绑失败:" + err.Error()}
+ }
+ if n == 0 {
+ missing = append(missing, user.Username+"(未绑定)")
+ continue
+ }
+ removed += n
+ done = append(done, user.Username)
+ }
+ return formatUnbindResult("批量解绑完成", removed, done, skipped, missing)
+}
+
+func (s *TelegramBotService) cmdUnbindDuplicates(ctx context.Context) telegramCommandReply {
+ if s == nil || s.repo == nil || s.repo.DB == nil {
+ return telegramCommandReply{Text: "仓库不可用。"}
+ }
+ var bindings []model.TelegramBinding
+ if err := s.repo.DB.WithContext(ctx).Order("updated_at desc, created_at desc").Find(&bindings).Error; err != nil {
+ return telegramCommandReply{Text: "读取绑定失败:" + err.Error()}
+ }
+ seenTelegram := make(map[int64]string)
+ seenUser := make(map[string]string)
+ var removeIDs []string
+ var removedLabels []string
+ for _, binding := range bindings {
+ remove := false
+ if binding.UserID == "" || binding.TelegramUserID == 0 {
+ remove = true
+ } else if user, _ := s.repo.User.FindByID(ctx, binding.UserID); user == nil {
+ remove = true
+ } else if _, ok := seenTelegram[binding.TelegramUserID]; ok {
+ remove = true
+ } else if _, ok := seenUser[binding.UserID]; ok {
+ remove = true
+ }
+ if remove {
+ removeIDs = append(removeIDs, binding.ID)
+ removedLabels = append(removedLabels, fmt.Sprintf("tg:%d", binding.TelegramUserID))
+ continue
+ }
+ seenTelegram[binding.TelegramUserID] = binding.ID
+ seenUser[binding.UserID] = binding.ID
+ }
+ if len(removeIDs) == 0 {
+ return telegramCommandReply{Text: "未发现重复或无效绑定。"}
+ }
+ n, err := s.deleteTelegramBindings(ctx, "id IN ?", removeIDs)
+ if err != nil {
+ return telegramCommandReply{Text: "清理失败:" + err.Error()}
+ }
+ return formatUnbindResult("重复/无效绑定清理完成", n, removedLabels, nil, nil)
+}
+
+func (s *TelegramBotService) cmdUnbindInactive(ctx context.Context, args []string) telegramCommandReply {
+ if len(args) == 0 {
+ return telegramCommandReply{Text: "用法:/unbind_inactive 天数\n例如 /unbind_inactive 30 会解绑 30 天未登录的普通用户 Bot 绑定,不删除账号。"}
+ }
+ days, err := strconv.Atoi(strings.TrimSpace(args[0]))
+ if err != nil || days < 1 {
+ return telegramCommandReply{Text: "天数必须是大于 0 的整数。"}
+ }
+ users, err := s.repo.User.List(ctx)
+ if err != nil {
+ return telegramCommandReply{Text: "读取用户失败:" + err.Error()}
+ }
+ cutoff := time.Now().Add(-time.Duration(days) * 24 * time.Hour)
+ var userIDs []string
+ var done []string
+ for _, user := range users {
+ if user.Role == "admin" {
+ continue
+ }
+ lastActive := user.CreatedAt
+ if user.LastLoginAt != nil {
+ lastActive = *user.LastLoginAt
+ }
+ if lastActive.IsZero() || lastActive.After(cutoff) {
+ continue
+ }
+ var count int64
+ _ = s.repo.DB.WithContext(ctx).Model(&model.TelegramBinding{}).Where("user_id = ?", user.ID).Count(&count).Error
+ if count == 0 {
+ continue
+ }
+ userIDs = append(userIDs, user.ID)
+ done = append(done, user.Username)
+ }
+ if len(userIDs) == 0 {
+ return telegramCommandReply{Text: fmt.Sprintf("未发现 %d 天未登录且已绑定 Bot 的普通用户。", days)}
+ }
+ n, err := s.deleteTelegramBindings(ctx, "user_id IN ?", userIDs)
+ if err != nil {
+ return telegramCommandReply{Text: "解绑失败:" + err.Error()}
+ }
+ return formatUnbindResult(fmt.Sprintf("已解绑 %d 天未登录用户", days), n, done, nil, nil)
+}
+
+func parseTelegramUnbindTargets(args []string) []string {
+ seen := make(map[string]struct{})
+ var targets []string
+ for _, arg := range args {
+ for _, part := range strings.FieldsFunc(arg, func(r rune) bool {
+ return r == ',' || r == ',' || r == ';' || r == ';' || r == '\n' || r == '\t'
+ }) {
+ part = strings.TrimSpace(part)
+ if part == "" {
+ continue
+ }
+ key := strings.ToLower(part)
+ if _, ok := seen[key]; ok {
+ continue
+ }
+ seen[key] = struct{}{}
+ targets = append(targets, part)
+ }
+ }
+ return targets
+}
+
+func (s *TelegramBotService) deleteTelegramBindings(ctx context.Context, query string, args ...interface{}) (int64, error) {
+ if s == nil || s.repo == nil || s.repo.DB == nil {
+ return 0, nil
+ }
+ tx := s.repo.DB.WithContext(ctx).Unscoped().Where(query, args...).Delete(&model.TelegramBinding{})
+ return tx.RowsAffected, tx.Error
+}
+
+func formatUnbindResult(title string, removed int64, done, skipped, missing []string) telegramCommandReply {
+ var sb strings.Builder
+ sb.WriteString("")
+ sb.WriteString(title)
+ sb.WriteString("\n\n")
+ sb.WriteString(fmt.Sprintf("已解绑:%d 条绑定", removed))
+ if len(done) > 0 {
+ sb.WriteString("\n目标:")
+ sb.WriteString(formatShortList(done, 12))
+ }
+ if len(skipped) > 0 {
+ sb.WriteString("\n跳过:")
+ sb.WriteString(formatShortList(skipped, 8))
+ }
+ if len(missing) > 0 {
+ sb.WriteString("\n未找到/未绑定:")
+ sb.WriteString(formatShortList(missing, 8))
+ }
+ return telegramCommandReply{Text: sb.String()}
+}
+
+func formatShortList(items []string, limit int) string {
+ if len(items) == 0 {
+ return ""
+ }
+ if limit < 1 {
+ limit = 1
+ }
+ out := items
+ if len(out) > limit {
+ out = out[:limit]
+ }
+ text := "" + strings.Join(out, "、") + ""
+ if len(items) > limit {
+ text += fmt.Sprintf(" 等 %d 项", len(items))
+ }
+ return text
+}
+
// protectReason returns a non-empty message when a user must not be
// disabled/deleted (admins and the default admin are protected).
func (s *TelegramBotService) protectReason(ctx context.Context, userID string) string {