mirror of
https://github.com/truewhile/MeBox.git
synced 2026-10-02 04:16:38 +08:00
fix: secure adult visibility and telegram bot access
This commit is contained in:
@@ -38,6 +38,6 @@ export const playProfilesAPI = {
|
||||
.post<PlayProfilePINVerifyResponse>(`/play-profiles/${id}/verify-pin`, { pin })
|
||||
.then((r) => r.data),
|
||||
|
||||
remove: (id: string) =>
|
||||
api.delete(`/play-profiles/${id}`).then((r) => r.data),
|
||||
remove: (id: string, proof?: { pin?: string; password?: string }) =>
|
||||
api.delete(`/play-profiles/${id}`, { data: proof ?? {} }).then((r) => r.data),
|
||||
}
|
||||
|
||||
@@ -2,7 +2,14 @@ import { api } from './client'
|
||||
import type { User } from '../types'
|
||||
|
||||
export const profileAPI = {
|
||||
update: (patch: { email?: string; avatar_url?: string }) =>
|
||||
update: (patch: {
|
||||
username?: string
|
||||
nickname?: string
|
||||
email?: string
|
||||
avatar_url?: string
|
||||
hide_adult?: boolean
|
||||
password?: string
|
||||
}) =>
|
||||
api.patch<User>('/me', patch).then((r) => r.data),
|
||||
|
||||
adminUpdateRole: (id: string, role: 'admin' | 'user') =>
|
||||
|
||||
@@ -0,0 +1,93 @@
|
||||
import { FormEvent, useState } from 'react'
|
||||
import { createRoot } from 'react-dom/client'
|
||||
import { KeyRound } from 'lucide-react'
|
||||
|
||||
type PasswordOptions = {
|
||||
title?: string
|
||||
message?: string
|
||||
confirmText?: string
|
||||
}
|
||||
|
||||
export function requestPassword(options: PasswordOptions): Promise<string | null> {
|
||||
return new Promise((resolve) => {
|
||||
const host = document.createElement('div')
|
||||
document.body.appendChild(host)
|
||||
const root = createRoot(host)
|
||||
const close = (value: string | null) => {
|
||||
root.unmount()
|
||||
host.remove()
|
||||
resolve(value)
|
||||
}
|
||||
root.render(<PasswordDialog options={options} onClose={close} />)
|
||||
})
|
||||
}
|
||||
|
||||
function PasswordDialog({
|
||||
options,
|
||||
onClose,
|
||||
}: {
|
||||
options: PasswordOptions
|
||||
onClose: (value: string | null) => void
|
||||
}) {
|
||||
const [password, setPassword] = useState('')
|
||||
|
||||
const onSubmit = (event: FormEvent) => {
|
||||
event.preventDefault()
|
||||
if (!password) return
|
||||
onClose(password)
|
||||
}
|
||||
|
||||
return (
|
||||
<div
|
||||
className="fixed inset-0 z-[110] flex items-center justify-center bg-black/35 p-4 backdrop-blur-sm"
|
||||
onClick={() => onClose(null)}
|
||||
>
|
||||
<form
|
||||
role="dialog"
|
||||
aria-modal="true"
|
||||
onSubmit={onSubmit}
|
||||
className="w-full max-w-sm overflow-hidden rounded-3xl border border-white/70 bg-white shadow-2xl"
|
||||
onClick={(event) => event.stopPropagation()}
|
||||
>
|
||||
<div className="flex gap-4 p-5">
|
||||
<div className="flex h-11 w-11 shrink-0 items-center justify-center rounded-2xl bg-primary-400/10 text-brand-500">
|
||||
<KeyRound size={22} />
|
||||
</div>
|
||||
<div className="min-w-0 flex-1">
|
||||
<h3 className="font-display text-lg font-bold text-ink-600">
|
||||
{options.title || '需要密码确认'}
|
||||
</h3>
|
||||
<p className="mt-2 text-sm leading-6 text-ink-50">
|
||||
{options.message || '请输入当前账号密码以继续。'}
|
||||
</p>
|
||||
<input
|
||||
autoFocus
|
||||
type="password"
|
||||
value={password}
|
||||
onChange={(event) => setPassword(event.target.value)}
|
||||
className="mt-4 w-full rounded-2xl border border-gray-200 bg-gray-50 px-4 py-3 text-ink-600 outline-none transition focus:border-brand-500 focus:bg-white focus:ring-4 focus:ring-brand-100/40"
|
||||
placeholder="当前账号密码"
|
||||
autoComplete="current-password"
|
||||
/>
|
||||
</div>
|
||||
</div>
|
||||
<div className="flex justify-end gap-2 border-t border-gray-100 bg-gray-50/80 px-5 py-4">
|
||||
<button
|
||||
type="button"
|
||||
onClick={() => onClose(null)}
|
||||
className="rounded-xl border border-gray-200 bg-white px-4 py-2 text-sm font-semibold text-ink-100 hover:bg-gray-50"
|
||||
>
|
||||
取消
|
||||
</button>
|
||||
<button
|
||||
type="submit"
|
||||
disabled={!password}
|
||||
className="rounded-xl bg-brand-500 px-4 py-2 text-sm font-semibold text-white shadow-sm transition hover:bg-brand-600 disabled:cursor-not-allowed disabled:opacity-50"
|
||||
>
|
||||
{options.confirmText || '确认'}
|
||||
</button>
|
||||
</div>
|
||||
</form>
|
||||
</div>
|
||||
)
|
||||
}
|
||||
@@ -183,7 +183,7 @@ function channelSummary(ch: NotifyChannel): string {
|
||||
const cfg = ch.config ?? {}
|
||||
switch (ch.type) {
|
||||
case 'telegram':
|
||||
return `Bot ${String(cfg.bot_token ?? '').slice(0, 10)}… → chat ${cfg.chat_id ?? '-'}`
|
||||
return `Bot ${String(cfg.bot_token ?? '').slice(0, 10)}… → 通知 ${cfg.chat_id ?? '-'} · 命令 ${cfg.command_chat_id ?? cfg.chat_id ?? '-'}`
|
||||
case 'wechat':
|
||||
return `SendKey ${String(cfg.sendkey ?? '').slice(0, 10)}…`
|
||||
case 'bark':
|
||||
@@ -200,7 +200,7 @@ function channelSummary(ch: NotifyChannel): string {
|
||||
// ─── Form Modal ─────────────────────────────────────────────────────────────
|
||||
|
||||
const EMPTY_CONFIG: Record<NotifyChannel['type'], Record<string, string>> = {
|
||||
telegram: { bot_token: '', chat_id: '' },
|
||||
telegram: { bot_token: '', chat_id: '', command_chat_id: '' },
|
||||
wechat: { sendkey: '' },
|
||||
bark: { device_key: '', server: '' },
|
||||
webhook: { url: '', method: 'POST', headers: '', body_template: '' },
|
||||
@@ -311,6 +311,17 @@ function ChannelFormModal({
|
||||
onChange={(e) => updateConfig('chat_id', e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
<Field label="命令群组/频道 Chat ID (可选)">
|
||||
<input
|
||||
className="input-base"
|
||||
placeholder="留空则使用上方 Chat ID;填写后只有该群组/频道可唤醒 Bot"
|
||||
value={config.command_chat_id ?? ''}
|
||||
onChange={(e) => updateConfig('command_chat_id', e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
<div className="rounded-2xl border border-primary-400/15 bg-primary-400/5 px-4 py-3 text-xs leading-6 text-ink-50">
|
||||
普通用户只能通过 <code>/start 用户名 密码</code> 绑定账号,并使用隐藏成人目录按钮;<code>/status</code>、<code>/search</code>、<code>/downloads</code>、<code>/stats</code> 仅管理员可用。
|
||||
</div>
|
||||
</>
|
||||
)}
|
||||
|
||||
|
||||
@@ -7,6 +7,7 @@ import { playProfilesAPI, type PlayProfileInput } from '../api/play_profiles'
|
||||
import { useAuthStore } from '../stores/auth'
|
||||
import { usePlayProfileStore } from '../stores/playProfile'
|
||||
import { confirmAction } from '../components/ConfirmDialog'
|
||||
import { requestPassword } from '../components/PasswordDialog'
|
||||
import { requestPIN } from '../components/PinDialog'
|
||||
import type { Library, PlayProfile } from '../types'
|
||||
|
||||
@@ -48,9 +49,27 @@ export function ProfileManagementPage() {
|
||||
}, [])
|
||||
|
||||
const onDelete = async (p: PlayProfile) => {
|
||||
if (!(await confirmAction({ title: '删除播放档案', message: `确定删除 Profile「${p.name}」?`, confirmText: '删除' }))) return
|
||||
if (!(await confirmAction({ title: '删除播放档案', message: `确定删除 Profile「${p.name}」? 删除前需要再次验证。`, confirmText: '继续删除' }))) return
|
||||
try {
|
||||
await playProfilesAPI.remove(p.id)
|
||||
const proof: { pin?: string; password?: string } = {}
|
||||
if (p.require_pin) {
|
||||
const pin = await requestPIN({
|
||||
title: '删除 Profile 需要 PIN',
|
||||
message: `请输入「${p.name}」的 PIN;也可以取消后改用账号密码删除。`,
|
||||
profileName: p.name,
|
||||
})
|
||||
if (!pin) return
|
||||
proof.pin = pin
|
||||
} else {
|
||||
const password = await requestPassword({
|
||||
title: '删除 Profile 需要密码',
|
||||
message: `请输入当前账号密码以删除「${p.name}」。`,
|
||||
confirmText: '删除',
|
||||
})
|
||||
if (!password) return
|
||||
proof.password = password
|
||||
}
|
||||
await playProfilesAPI.remove(p.id, proof)
|
||||
toast.success('已删除')
|
||||
await refresh()
|
||||
} catch (err: unknown) {
|
||||
|
||||
@@ -1,28 +1,51 @@
|
||||
import { FormEvent, useState } from 'react'
|
||||
import toast from 'react-hot-toast'
|
||||
import { KeyRound, Save } from 'lucide-react'
|
||||
import { EyeOff, KeyRound, Save } from 'lucide-react'
|
||||
|
||||
import { authAPI } from '../api/auth'
|
||||
import { profileAPI } from '../api/profile'
|
||||
import { requestPassword } from '../components/PasswordDialog'
|
||||
import { useAuthStore } from '../stores/auth'
|
||||
|
||||
export function ProfilePage() {
|
||||
const user = useAuthStore((s) => s.user)
|
||||
const setUser = useAuthStore((s) => s.setUser)
|
||||
|
||||
const [username, setUsername] = useState(user?.username ?? '')
|
||||
const [nickname, setNickname] = useState(user?.nickname ?? '')
|
||||
const [email, setEmail] = useState(user?.email ?? '')
|
||||
const [avatar, setAvatar] = useState(user?.avatar_url ?? '')
|
||||
const [hideAdult, setHideAdult] = useState(Boolean(user?.hide_adult))
|
||||
const [oldPwd, setOldPwd] = useState('')
|
||||
const [newPwd, setNewPwd] = useState('')
|
||||
|
||||
const onProfile = async (e: FormEvent) => {
|
||||
e.preventDefault()
|
||||
try {
|
||||
const u = await profileAPI.update({ email, avatar_url: avatar })
|
||||
let password: string | undefined
|
||||
if (hideAdult !== Boolean(user?.hide_adult)) {
|
||||
const input = await requestPassword({
|
||||
title: hideAdult ? '隐藏成人目录' : '取消隐藏成人目录',
|
||||
message: '此设置会同步影响 Web 与 Emby/Jellyfin/Infuse 等第三方客户端,请输入当前账号密码确认。',
|
||||
confirmText: '保存设置',
|
||||
})
|
||||
if (!input) return
|
||||
password = input
|
||||
}
|
||||
const u = await profileAPI.update({
|
||||
username,
|
||||
nickname,
|
||||
email,
|
||||
avatar_url: avatar,
|
||||
hide_adult: hideAdult,
|
||||
password,
|
||||
})
|
||||
setUser(u)
|
||||
toast.success('资料已更新')
|
||||
} catch {
|
||||
toast.error('保存失败')
|
||||
} catch (err: unknown) {
|
||||
const msg =
|
||||
(err as { response?: { data?: { error?: string } } })?.response?.data?.error ?? '保存失败'
|
||||
toast.error(msg)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -48,7 +71,20 @@ export function ProfilePage() {
|
||||
<form onSubmit={onProfile} className="glass-panel space-y-4">
|
||||
<h2 className="font-display text-lg font-semibold text-ink-600">基本信息</h2>
|
||||
<Field label="用户名">
|
||||
<input className="input-base" value={user?.username ?? ''} disabled />
|
||||
<input
|
||||
required
|
||||
className="input-base"
|
||||
value={username}
|
||||
onChange={(e) => setUsername(e.target.value)}
|
||||
autoComplete="username"
|
||||
/>
|
||||
</Field>
|
||||
<Field label="昵称">
|
||||
<input
|
||||
className="input-base"
|
||||
value={nickname}
|
||||
onChange={(e) => setNickname(e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
<Field label="角色">
|
||||
<input className="input-base" value={user?.role ?? ''} disabled />
|
||||
@@ -68,6 +104,22 @@ export function ProfilePage() {
|
||||
onChange={(e) => setAvatar(e.target.value)}
|
||||
/>
|
||||
</Field>
|
||||
<label className="flex items-start justify-between gap-4 rounded-2xl border border-gray-200 bg-white/70 p-4">
|
||||
<span>
|
||||
<span className="flex items-center gap-2 font-medium text-ink-600">
|
||||
<EyeOff size={16} /> 隐藏成人目录
|
||||
</span>
|
||||
<span className="mt-1 block text-sm leading-6 text-ink-50">
|
||||
开启后当前账号在网页、外部播放器链接以及 Emby/Jellyfin/Infuse 等第三方客户端中都不会显示成人媒体库和 NSFW 条目。
|
||||
</span>
|
||||
</span>
|
||||
<input
|
||||
type="checkbox"
|
||||
className="mt-1 h-5 w-5 accent-brand-500"
|
||||
checked={hideAdult}
|
||||
onChange={(e) => setHideAdult(e.target.checked)}
|
||||
/>
|
||||
</label>
|
||||
<button type="submit" className="neon-button">
|
||||
<Save size={16} /> 保存
|
||||
</button>
|
||||
|
||||
@@ -8,6 +8,7 @@ export interface User {
|
||||
nickname?: string
|
||||
email?: string
|
||||
avatar_url?: string
|
||||
hide_adult?: boolean
|
||||
force_password_reset: boolean
|
||||
is_active: boolean
|
||||
is_default_admin?: boolean
|
||||
|
||||
Reference in New Issue
Block a user