mirror of
https://github.com/truewhile/MeBox.git
synced 2026-09-29 19:36:36 +08:00
1dbd73b30b
== New domain models (7) ==
- UserPermission: per-user feature toggles (13 booleans)
- StorageConfig: encrypted Alist/S3/WebDAV adapters
- LicenseKey + LicenseActivation: offline license issuance
- DownloadClient: multi-client downloader configs
- AssistantSession + AssistantMessage: multi-turn AI chat persistence
== New services (5) ==
- PermissionService: admin grants always-true; user defaults seeded
- StorageConfigService: AES-GCM encryption + per-type connection probe
- LicenseService: 24-char hyphenated key generation, activation/heartbeat
- DownloadClientService: qB/Aria2/Transmission CRUD + WebUI test
- AssistantService: chat history + execute/undo stubs (op_id tracking)
== Extended AIService.Chat ==
- Multi-turn LLM call with chat history; offline fallback reply
== New endpoints (60+) ==
Auth:
POST /auth/refresh, /auth/logout, /auth/change-password
PATCH /auth/profile
GET /auth/permissions, /auth/me
Permissions admin:
GET/PUT /admin/users/:id/permissions
POST /admin/users/:id/permissions/reset
Search:
GET /search, /search/advanced, /search/tmdb, /search/sites
System:
GET /system/config, /settings/schema, /system/events/ticket
POST /admin/system/scheduler/:name/trigger
Stats:
GET /stats/user/:id, /stats/top-users
POST /stats/play
Sites:
GET /sites/:id/resource, /sites/:id/userdata
Subscriptions:
PUT /subscriptions/:id, POST /subscriptions/:id/search
Playlists:
POST /playlists/:id/reorder
DELETE /playlists/:id/items/by-id/:item_id
DLNA per-renderer:
POST /dlna/:uuid/{play,pause,stop}, GET /dlna/:uuid/status
Media:
POST/DELETE /media/:id/favorite, GET /media/:id/favorite/status
POST /media/:id/ai-scrape, /media/scrape/test, /media/organize
GET /favorites (alias)
Playback:
GET /playback/:id/info, /playback/:id/external-players, /playback/:id/external-url
POST /playback/:id/progress
GET /playback/transcode/:job_id/status
Downloads:
POST /download/:id/{pause,resume,organize}
POST /download/{organize,sync,start-auto-sync}
GET /download/tasks
Admin: full CRUD on /admin/download/clients + /admin/download/aria2/stats
License:
POST /license/{activate,heartbeat}
GET /license/{status,heartbeat-status}
Admin: /admin/license/{generate,list,:id/activations,:id/revoke,activation/:id/unbind}
Storage:
GET /admin/storage/{status,:type}
PUT /admin/storage/:type, POST /admin/storage/:type/test
Assistant (multi-turn AI):
GET/POST /admin/assistant/sessions
GET/DELETE /admin/assistant/session/:id
POST /admin/assistant/{chat,execute}
POST /admin/assistant/undo/:op_id
GET /admin/assistant/history
== New React pages (4) ==
- AssistantChatPage (/assistant): full multi-turn chat UI with sessions
sidebar, optimistic user-turn append, live AI response.
- DownloadClientsPage (/download-clients): typed CRUD form for
qBittorrent / Aria2 / Transmission + per-row Test action.
- LicensePage (/license): generate keys, list activations, revoke,
unbind individual devices.
- StorageConfigPage (/storage-config): tabbed Alist/WebDAV/S3 form
with secret-aware redaction + connection probe.
== New API helpers (5) ==
- assistant, download_clients, license, permissions, storage_config
== Layout ==
- Sidebar gains 4 new admin links (AI 对话, 下载器, 外部存储, 许可证).
160 lines
4.9 KiB
Go
160 lines
4.9 KiB
Go
// Package handler — system config + scheduler trigger + events ticket.
|
|
package handler
|
|
|
|
import (
|
|
"crypto/rand"
|
|
"encoding/hex"
|
|
"net/http"
|
|
"sync"
|
|
"time"
|
|
|
|
"github.com/gin-gonic/gin"
|
|
|
|
"github.com/ShukeBta/MediaStationGo/internal/middleware"
|
|
"github.com/ShukeBta/MediaStationGo/internal/model"
|
|
"github.com/ShukeBta/MediaStationGo/internal/service"
|
|
)
|
|
|
|
// listSystemConfigHandler is the non-admin alias for /admin/settings.
|
|
// It returns the same key/value rows so the Vue UI's `system.getConfig`
|
|
// helper keeps working.
|
|
func listSystemConfigHandler(svc *service.Container) gin.HandlerFunc {
|
|
return func(c *gin.Context) {
|
|
rows, err := svc.Repo.Setting.All(c.Request.Context())
|
|
if err != nil {
|
|
c.JSON(http.StatusInternalServerError, gin.H{"error": err.Error()})
|
|
return
|
|
}
|
|
// Hide secret-flavoured keys for non-admins.
|
|
role, _ := c.Get(middleware.CtxUserRole)
|
|
out := make([]model.Setting, 0, len(rows))
|
|
for _, s := range rows {
|
|
if role != "admin" && isSecretKey(s.Key) {
|
|
s.Value = "********"
|
|
}
|
|
out = append(out, s)
|
|
}
|
|
c.JSON(http.StatusOK, gin.H{"items": out})
|
|
}
|
|
}
|
|
|
|
func isSecretKey(k string) bool {
|
|
for _, suffix := range []string{".token", ".secret", ".password", ".api_key", ".cookie"} {
|
|
if endsWith(k, suffix) {
|
|
return true
|
|
}
|
|
}
|
|
return false
|
|
}
|
|
|
|
func endsWith(s, suffix string) bool {
|
|
return len(s) >= len(suffix) && s[len(s)-len(suffix):] == suffix
|
|
}
|
|
|
|
// schemaHandler returns the curated settings schema (used by the
|
|
// `getSchema()` Vue helper). It mirrors the SettingsPage groupings but
|
|
// in JSON so the upstream UI can render its dynamic form.
|
|
func schemaHandler(_ *service.Container) gin.HandlerFunc {
|
|
return func(c *gin.Context) {
|
|
c.JSON(http.StatusOK, gin.H{
|
|
"groups": []gin.H{
|
|
{
|
|
"key": "general",
|
|
"label": "常规",
|
|
"items": []gin.H{
|
|
{"key": "tmdb.language", "type": "select", "label": "TMDb 元数据语言"},
|
|
{"key": "transcode.enabled", "type": "toggle", "label": "启用转码"},
|
|
{"key": "transcode.hw_accel", "type": "select", "label": "硬件加速"},
|
|
{"key": "transcode.max_jobs", "type": "number", "label": "最大并发"},
|
|
{"key": "ffmpeg.path", "type": "text", "label": "FFmpeg 路径"},
|
|
{"key": "ffprobe.path", "type": "text", "label": "FFprobe 路径"},
|
|
},
|
|
},
|
|
{
|
|
"key": "organize",
|
|
"label": "整理 & 刮削",
|
|
"items": []gin.H{
|
|
{"key": "organize.auto", "type": "toggle"},
|
|
{"key": "organize.movie_format", "type": "text"},
|
|
{"key": "organize.tv_format", "type": "text"},
|
|
{"key": "organize.anime_format", "type": "text"},
|
|
{"key": "scrape.auto_on_scan", "type": "toggle"},
|
|
{"key": "scrape.providers", "type": "text"},
|
|
{"key": "scrape.language", "type": "text"},
|
|
},
|
|
},
|
|
{
|
|
"key": "adult",
|
|
"label": "Adult / NSFW",
|
|
"items": []gin.H{
|
|
{"key": "adult.enabled", "type": "toggle"},
|
|
{"key": "adult.require_pin", "type": "toggle"},
|
|
{"key": "adult.pin", "type": "text"},
|
|
},
|
|
},
|
|
{
|
|
"key": "qbittorrent",
|
|
"label": "qBittorrent",
|
|
"items": []gin.H{
|
|
{"key": "qbittorrent.url", "type": "text"},
|
|
{"key": "qbittorrent.username", "type": "text"},
|
|
{"key": "qbittorrent.password", "type": "text"},
|
|
{"key": "qbittorrent.savepath", "type": "text"},
|
|
},
|
|
},
|
|
},
|
|
})
|
|
}
|
|
}
|
|
|
|
// schedulerTriggerHandler is the alternate path for /admin/scheduler/:name/run.
|
|
func schedulerTriggerHandler(svc *service.Container) gin.HandlerFunc {
|
|
return func(c *gin.Context) {
|
|
if err := svc.Scheduler.RunNow(c.Request.Context(), c.Param("name")); err != nil {
|
|
c.JSON(http.StatusBadRequest, gin.H{"error": err.Error()})
|
|
return
|
|
}
|
|
c.JSON(http.StatusOK, gin.H{"ok": true})
|
|
}
|
|
}
|
|
|
|
// ─── SSE ticket store ───────────────────────────────────────────────────────
|
|
//
|
|
// The Vue UI's SSE event stream wants a one-time signed ticket so the
|
|
// EventSource (which can't set Authorization headers) can authenticate.
|
|
// We don't expose the SSE stream itself yet, but we persist short-lived
|
|
// tickets keyed to the user so the upstream consumer keeps working.
|
|
|
|
type ticket struct {
|
|
userID string
|
|
expires time.Time
|
|
}
|
|
|
|
var (
|
|
ticketStore = map[string]ticket{}
|
|
ticketStoreMu sync.Mutex
|
|
)
|
|
|
|
func newTicket(userID string) string {
|
|
buf := make([]byte, 16)
|
|
_, _ = rand.Read(buf)
|
|
t := hex.EncodeToString(buf)
|
|
ticketStoreMu.Lock()
|
|
defer ticketStoreMu.Unlock()
|
|
ticketStore[t] = ticket{userID: userID, expires: time.Now().Add(60 * time.Second)}
|
|
// GC expired tickets opportunistically.
|
|
for k, v := range ticketStore {
|
|
if time.Now().After(v.expires) {
|
|
delete(ticketStore, k)
|
|
}
|
|
}
|
|
return t
|
|
}
|
|
|
|
func systemEventsTicketHandler(_ *service.Container) gin.HandlerFunc {
|
|
return func(c *gin.Context) {
|
|
uid, _ := c.Get(middleware.CtxUserID)
|
|
c.JSON(http.StatusOK, gin.H{"ticket": newTicket(toString(uid))})
|
|
}
|
|
}
|