fix: secure adult visibility and telegram bot access

This commit is contained in:
ShukeBta
2026-05-30 01:39:11 +08:00
parent db65e54c45
commit b5e11b6938
22 changed files with 913 additions and 114 deletions
+2
View File
@@ -40,6 +40,7 @@ type User struct {
Nickname string `gorm:"size:128" json:"nickname,omitempty"`
Email string `gorm:"size:128" json:"email,omitempty"`
AvatarURL string `gorm:"size:255" json:"avatar_url,omitempty"`
HideAdult bool `gorm:"default:false" json:"hide_adult"`
ForcePasswordReset bool `gorm:"default:false" json:"force_password_reset"`
IsActive bool `gorm:"default:true" json:"is_active"`
LastLoginAt *time.Time `json:"last_login_at,omitempty"`
@@ -318,6 +319,7 @@ func AllModels() []interface{} {
&ApiConfig{},
&DownloadClient{},
&NotifyChannel{},
&TelegramBinding{},
&STRMRecord{},
&PlayProfile{},
&StorageConfig{},
+12
View File
@@ -0,0 +1,12 @@
package model
// TelegramBinding links a Telegram account to a local MediaStationGo user.
// The binding is password-verified when /start is used, then reused for
// low-risk self-service actions such as toggling adult-library visibility.
type TelegramBinding struct {
Base
TelegramUserID int64 `gorm:"uniqueIndex;not null" json:"telegram_user_id"`
TelegramName string `gorm:"size:128" json:"telegram_name,omitempty"`
ChatID int64 `gorm:"index" json:"chat_id"`
UserID string `gorm:"index;size:36;not null" json:"user_id"`
}