mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-30 03:36:37 +08:00
fix: enforce adult profile pin visibility
This commit is contained in:
+21
-2
@@ -1,6 +1,7 @@
|
||||
import axios, { AxiosError, type InternalAxiosRequestConfig } from 'axios'
|
||||
|
||||
import { useAuthStore } from '../stores/auth'
|
||||
import { getActivePlayProfileId, getActivePlayProfilePinToken } from '../stores/playProfile'
|
||||
|
||||
// Single axios instance used by every API helper. Adds the JWT to outgoing
|
||||
// requests and routes 401s back to the login page.
|
||||
@@ -31,6 +32,15 @@ api.interceptors.request.use((config) => {
|
||||
config.headers = config.headers ?? {}
|
||||
config.headers.Authorization = `Bearer ${token}`
|
||||
}
|
||||
const activeProfileId = getActivePlayProfileId()
|
||||
if (activeProfileId) {
|
||||
config.headers = config.headers ?? {}
|
||||
config.headers['X-Play-Profile-ID'] = activeProfileId
|
||||
const pinToken = getActivePlayProfilePinToken()
|
||||
if (pinToken) {
|
||||
config.headers['X-Play-Profile-PIN-Token'] = pinToken
|
||||
}
|
||||
}
|
||||
return config
|
||||
})
|
||||
|
||||
@@ -91,16 +101,25 @@ const tokenQuery = () => {
|
||||
return `token=${encodeURIComponent(t)}`
|
||||
}
|
||||
|
||||
const profileQuery = () => {
|
||||
const id = getActivePlayProfileId()
|
||||
if (!id) return ''
|
||||
const pinToken = getActivePlayProfilePinToken()
|
||||
return `&profile_id=${encodeURIComponent(id)}${
|
||||
pinToken ? `&profile_pin_token=${encodeURIComponent(pinToken)}` : ''
|
||||
}`
|
||||
}
|
||||
|
||||
// streamURL returns a direct-play URL for <video src>. The JWT is added as
|
||||
// a query parameter because <video> elements cannot send Authorization
|
||||
// headers.
|
||||
export function streamURL(mediaId: string): string {
|
||||
return `/api/stream/${encodeURIComponent(mediaId)}?${tokenQuery()}`
|
||||
return `/api/stream/${encodeURIComponent(mediaId)}?${tokenQuery()}${profileQuery()}`
|
||||
}
|
||||
|
||||
// hlsURL returns the m3u8 playlist URL fed into hls.js.
|
||||
export function hlsURL(mediaId: string): string {
|
||||
return `/api/hls/${encodeURIComponent(mediaId)}/index.m3u8?${tokenQuery()}`
|
||||
return `/api/hls/${encodeURIComponent(mediaId)}/index.m3u8?${tokenQuery()}${profileQuery()}`
|
||||
}
|
||||
|
||||
// imageURL converts a remote poster URL into a same-origin proxy URL so it
|
||||
|
||||
@@ -17,6 +17,12 @@ export interface PlayProfileInput {
|
||||
allowed_library_ids: string[]
|
||||
}
|
||||
|
||||
export interface PlayProfilePINVerifyResponse {
|
||||
profile: PlayProfile
|
||||
token: string
|
||||
expires_at: string
|
||||
}
|
||||
|
||||
// playProfilesAPI wraps /play-profiles. The admin variant adds ?all=true.
|
||||
export const playProfilesAPI = {
|
||||
list: (all = false) =>
|
||||
@@ -30,6 +36,11 @@ export const playProfilesAPI = {
|
||||
update: (id: string, input: PlayProfileInput) =>
|
||||
api.put<PlayProfile>(`/play-profiles/${id}`, input).then((r) => r.data),
|
||||
|
||||
verifyPin: (id: string, pin: string) =>
|
||||
api
|
||||
.post<PlayProfilePINVerifyResponse>(`/play-profiles/${id}/verify-pin`, { pin })
|
||||
.then((r) => r.data),
|
||||
|
||||
remove: (id: string) =>
|
||||
api.delete(`/play-profiles/${id}`).then((r) => r.data),
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user