fix: secure adult visibility and telegram bot access

This commit is contained in:
ShukeBta
2026-05-30 01:39:11 +08:00
parent db65e54c45
commit b5e11b6938
22 changed files with 913 additions and 114 deletions
+2 -2
View File
@@ -38,6 +38,6 @@ export const playProfilesAPI = {
.post<PlayProfilePINVerifyResponse>(`/play-profiles/${id}/verify-pin`, { pin })
.then((r) => r.data),
remove: (id: string) =>
api.delete(`/play-profiles/${id}`).then((r) => r.data),
remove: (id: string, proof?: { pin?: string; password?: string }) =>
api.delete(`/play-profiles/${id}`, { data: proof ?? {} }).then((r) => r.data),
}
+8 -1
View File
@@ -2,7 +2,14 @@ import { api } from './client'
import type { User } from '../types'
export const profileAPI = {
update: (patch: { email?: string; avatar_url?: string }) =>
update: (patch: {
username?: string
nickname?: string
email?: string
avatar_url?: string
hide_adult?: boolean
password?: string
}) =>
api.patch<User>('/me', patch).then((r) => r.data),
adminUpdateRole: (id: string, role: 'admin' | 'user') =>
+93
View File
@@ -0,0 +1,93 @@
import { FormEvent, useState } from 'react'
import { createRoot } from 'react-dom/client'
import { KeyRound } from 'lucide-react'
type PasswordOptions = {
title?: string
message?: string
confirmText?: string
}
export function requestPassword(options: PasswordOptions): Promise<string | null> {
return new Promise((resolve) => {
const host = document.createElement('div')
document.body.appendChild(host)
const root = createRoot(host)
const close = (value: string | null) => {
root.unmount()
host.remove()
resolve(value)
}
root.render(<PasswordDialog options={options} onClose={close} />)
})
}
function PasswordDialog({
options,
onClose,
}: {
options: PasswordOptions
onClose: (value: string | null) => void
}) {
const [password, setPassword] = useState('')
const onSubmit = (event: FormEvent) => {
event.preventDefault()
if (!password) return
onClose(password)
}
return (
<div
className="fixed inset-0 z-[110] flex items-center justify-center bg-black/35 p-4 backdrop-blur-sm"
onClick={() => onClose(null)}
>
<form
role="dialog"
aria-modal="true"
onSubmit={onSubmit}
className="w-full max-w-sm overflow-hidden rounded-3xl border border-white/70 bg-white shadow-2xl"
onClick={(event) => event.stopPropagation()}
>
<div className="flex gap-4 p-5">
<div className="flex h-11 w-11 shrink-0 items-center justify-center rounded-2xl bg-primary-400/10 text-brand-500">
<KeyRound size={22} />
</div>
<div className="min-w-0 flex-1">
<h3 className="font-display text-lg font-bold text-ink-600">
{options.title || '需要密码确认'}
</h3>
<p className="mt-2 text-sm leading-6 text-ink-50">
{options.message || '请输入当前账号密码以继续。'}
</p>
<input
autoFocus
type="password"
value={password}
onChange={(event) => setPassword(event.target.value)}
className="mt-4 w-full rounded-2xl border border-gray-200 bg-gray-50 px-4 py-3 text-ink-600 outline-none transition focus:border-brand-500 focus:bg-white focus:ring-4 focus:ring-brand-100/40"
placeholder="当前账号密码"
autoComplete="current-password"
/>
</div>
</div>
<div className="flex justify-end gap-2 border-t border-gray-100 bg-gray-50/80 px-5 py-4">
<button
type="button"
onClick={() => onClose(null)}
className="rounded-xl border border-gray-200 bg-white px-4 py-2 text-sm font-semibold text-ink-100 hover:bg-gray-50"
>
取消
</button>
<button
type="submit"
disabled={!password}
className="rounded-xl bg-brand-500 px-4 py-2 text-sm font-semibold text-white shadow-sm transition hover:bg-brand-600 disabled:cursor-not-allowed disabled:opacity-50"
>
{options.confirmText || '确认'}
</button>
</div>
</form>
</div>
)
}
+13 -2
View File
@@ -183,7 +183,7 @@ function channelSummary(ch: NotifyChannel): string {
const cfg = ch.config ?? {}
switch (ch.type) {
case 'telegram':
return `Bot ${String(cfg.bot_token ?? '').slice(0, 10)}… → chat ${cfg.chat_id ?? '-'}`
return `Bot ${String(cfg.bot_token ?? '').slice(0, 10)}… → 通知 ${cfg.chat_id ?? '-'} · 命令 ${cfg.command_chat_id ?? cfg.chat_id ?? '-'}`
case 'wechat':
return `SendKey ${String(cfg.sendkey ?? '').slice(0, 10)}…`
case 'bark':
@@ -200,7 +200,7 @@ function channelSummary(ch: NotifyChannel): string {
// ─── Form Modal ─────────────────────────────────────────────────────────────
const EMPTY_CONFIG: Record<NotifyChannel['type'], Record<string, string>> = {
telegram: { bot_token: '', chat_id: '' },
telegram: { bot_token: '', chat_id: '', command_chat_id: '' },
wechat: { sendkey: '' },
bark: { device_key: '', server: '' },
webhook: { url: '', method: 'POST', headers: '', body_template: '' },
@@ -311,6 +311,17 @@ function ChannelFormModal({
onChange={(e) => updateConfig('chat_id', e.target.value)}
/>
</Field>
<Field label="命令群组/频道 Chat ID (可选)">
<input
className="input-base"
placeholder="留空则使用上方 Chat ID;填写后只有该群组/频道可唤醒 Bot"
value={config.command_chat_id ?? ''}
onChange={(e) => updateConfig('command_chat_id', e.target.value)}
/>
</Field>
<div className="rounded-2xl border border-primary-400/15 bg-primary-400/5 px-4 py-3 text-xs leading-6 text-ink-50">
普通用户只能通过 <code>/start 用户名 密码</code> 绑定账号,并使用隐藏成人目录按钮;<code>/status</code>、<code>/search</code>、<code>/downloads</code>、<code>/stats</code> 仅管理员可用。
</div>
</>
)}
+21 -2
View File
@@ -7,6 +7,7 @@ import { playProfilesAPI, type PlayProfileInput } from '../api/play_profiles'
import { useAuthStore } from '../stores/auth'
import { usePlayProfileStore } from '../stores/playProfile'
import { confirmAction } from '../components/ConfirmDialog'
import { requestPassword } from '../components/PasswordDialog'
import { requestPIN } from '../components/PinDialog'
import type { Library, PlayProfile } from '../types'
@@ -48,9 +49,27 @@ export function ProfileManagementPage() {
}, [])
const onDelete = async (p: PlayProfile) => {
if (!(await confirmAction({ title: '删除播放档案', message: `确定删除 Profile「${p.name}」?`, confirmText: '删除' }))) return
if (!(await confirmAction({ title: '删除播放档案', message: `确定删除 Profile「${p.name}」? 删除前需要再次验证。`, confirmText: '继续删除' }))) return
try {
await playProfilesAPI.remove(p.id)
const proof: { pin?: string; password?: string } = {}
if (p.require_pin) {
const pin = await requestPIN({
title: '删除 Profile 需要 PIN',
message: `请输入「${p.name}」的 PIN;也可以取消后改用账号密码删除。`,
profileName: p.name,
})
if (!pin) return
proof.pin = pin
} else {
const password = await requestPassword({
title: '删除 Profile 需要密码',
message: `请输入当前账号密码以删除「${p.name}」。`,
confirmText: '删除',
})
if (!password) return
proof.password = password
}
await playProfilesAPI.remove(p.id, proof)
toast.success('已删除')
await refresh()
} catch (err: unknown) {
+57 -5
View File
@@ -1,28 +1,51 @@
import { FormEvent, useState } from 'react'
import toast from 'react-hot-toast'
import { KeyRound, Save } from 'lucide-react'
import { EyeOff, KeyRound, Save } from 'lucide-react'
import { authAPI } from '../api/auth'
import { profileAPI } from '../api/profile'
import { requestPassword } from '../components/PasswordDialog'
import { useAuthStore } from '../stores/auth'
export function ProfilePage() {
const user = useAuthStore((s) => s.user)
const setUser = useAuthStore((s) => s.setUser)
const [username, setUsername] = useState(user?.username ?? '')
const [nickname, setNickname] = useState(user?.nickname ?? '')
const [email, setEmail] = useState(user?.email ?? '')
const [avatar, setAvatar] = useState(user?.avatar_url ?? '')
const [hideAdult, setHideAdult] = useState(Boolean(user?.hide_adult))
const [oldPwd, setOldPwd] = useState('')
const [newPwd, setNewPwd] = useState('')
const onProfile = async (e: FormEvent) => {
e.preventDefault()
try {
const u = await profileAPI.update({ email, avatar_url: avatar })
let password: string | undefined
if (hideAdult !== Boolean(user?.hide_adult)) {
const input = await requestPassword({
title: hideAdult ? '隐藏成人目录' : '取消隐藏成人目录',
message: '此设置会同步影响 Web 与 Emby/Jellyfin/Infuse 等第三方客户端,请输入当前账号密码确认。',
confirmText: '保存设置',
})
if (!input) return
password = input
}
const u = await profileAPI.update({
username,
nickname,
email,
avatar_url: avatar,
hide_adult: hideAdult,
password,
})
setUser(u)
toast.success('资料已更新')
} catch {
toast.error('保存失败')
} catch (err: unknown) {
const msg =
(err as { response?: { data?: { error?: string } } })?.response?.data?.error ?? '保存失败'
toast.error(msg)
}
}
@@ -48,7 +71,20 @@ export function ProfilePage() {
<form onSubmit={onProfile} className="glass-panel space-y-4">
<h2 className="font-display text-lg font-semibold text-ink-600">基本信息</h2>
<Field label="用户名">
<input className="input-base" value={user?.username ?? ''} disabled />
<input
required
className="input-base"
value={username}
onChange={(e) => setUsername(e.target.value)}
autoComplete="username"
/>
</Field>
<Field label="昵称">
<input
className="input-base"
value={nickname}
onChange={(e) => setNickname(e.target.value)}
/>
</Field>
<Field label="角色">
<input className="input-base" value={user?.role ?? ''} disabled />
@@ -68,6 +104,22 @@ export function ProfilePage() {
onChange={(e) => setAvatar(e.target.value)}
/>
</Field>
<label className="flex items-start justify-between gap-4 rounded-2xl border border-gray-200 bg-white/70 p-4">
<span>
<span className="flex items-center gap-2 font-medium text-ink-600">
<EyeOff size={16} /> 隐藏成人目录
</span>
<span className="mt-1 block text-sm leading-6 text-ink-50">
开启后当前账号在网页、外部播放器链接以及 Emby/Jellyfin/Infuse 等第三方客户端中都不会显示成人媒体库和 NSFW 条目。
</span>
</span>
<input
type="checkbox"
className="mt-1 h-5 w-5 accent-brand-500"
checked={hideAdult}
onChange={(e) => setHideAdult(e.target.checked)}
/>
</label>
<button type="submit" className="neon-button">
<Save size={16} /> 保存
</button>
+1
View File
@@ -8,6 +8,7 @@ export interface User {
nickname?: string
email?: string
avatar_url?: string
hide_adult?: boolean
force_password_reset: boolean
is_active: boolean
is_default_admin?: boolean