去除 access_token 访问写库逻辑

This commit is contained in:
ryan
2026-06-11 09:09:17 +08:00
parent 6cbc368dc1
commit 616242fad8
8 changed files with 32 additions and 19 deletions
+1 -2
View File
@@ -205,7 +205,6 @@ export const apiSections: PolicySection[] = [
"name": "my-dev-key",
"masked_token": "at_628d...29c9",
"is_admin": false,
"last_used_at": null,
"created_at": "2026-06-07T21:30:00+08:00"
}
}
@@ -219,7 +218,7 @@ export const apiSections: PolicySection[] = [
<h3 id="3-4-rotate-token" className="text-base md:text-lg font-semibold text-foreground mt-6 mb-2">3.4 轮换令牌密钥</h3>
<p><strong>接口:</strong>POST <code className="bg-muted px-1.5 py-0.5 rounded text-xs font-mono">/api/v1/user/access-tokens/:id/rotate</code></p>
<p><strong>说明:</strong>轮换指定令牌的物理密钥值。系统将废弃原有密钥,返回新生成的明文 Token,并将 `last_used_at` 置空,令牌名称与 ID 保持一致。</p>
<p><strong>说明:</strong>轮换指定令牌的物理密钥值。系统将废弃原有密钥,返回新生成的明文 Token,令牌名称与 ID 保持一致。</p>
</div>
),
children: [
@@ -206,11 +206,15 @@ export function AccessTokenMain() {
<div className="space-y-1">
<div className="flex items-center gap-2">
<span className="font-semibold text-sm text-foreground">{token.name}</span>
{token.is_admin && (
{token.is_admin ? (
<Badge variant="outline" className="text-[10px] px-1.5 py-0 h-4 border-rose-500/40 text-rose-500 bg-rose-500/5 font-semibold">
<Shield className="size-2.5 mr-0.5" />
管理员
</Badge>
) : (
<Badge variant="outline" className="text-[10px] px-1.5 py-0 h-4 border-border/50 text-muted-foreground bg-muted/10 font-semibold">
用户令牌
</Badge>
)}
</div>
<div className="flex flex-col gap-1 text-xs text-muted-foreground">
@@ -219,7 +223,6 @@ export function AccessTokenMain() {
</div>
<div className="flex flex-wrap gap-x-4 gap-y-0.5 pt-1">
<span>创建于: {formatDate(token.created_at)}</span>
<span>最后使用: {formatDate(token.last_used_at)}</span>
</div>
</div>
</div>
@@ -6,7 +6,6 @@ export interface AccessToken {
name: string;
masked_token: string;
is_admin: boolean;
last_used_at?: string;
created_at: string;
updated_at: string;
}
-4
View File
@@ -6,7 +6,6 @@ package oauth
import (
"net/http"
"time"
"github.com/Rain-kl/Wavelet/internal/common"
"github.com/Rain-kl/Wavelet/internal/db"
@@ -56,9 +55,6 @@ func LoginRequired() gin.HandlerFunc {
authenticated = true
tokenAuth = true
tokenAdmin = tokenRecord.IsAdmin
// update token last used time
now := time.Now()
db.DB(ctx).Model(&tokenRecord).Update("last_used_at", &now)
}
}
}
-1
View File
@@ -203,7 +203,6 @@ func RotateAccessToken(c *gin.Context) {
tokenRecord.TokenHash = newTokenHash
tokenRecord.MaskedToken = newMaskedToken
tokenRecord.LastUsedAt = nil // 轮换后重置使用时间
if err := db.DB(ctx).Save(&tokenRecord).Error; err != nil {
c.JSON(http.StatusOK, util.Err(err.Error()))
@@ -0,0 +1,9 @@
-- +goose Up
-- +goose StatementBegin
ALTER TABLE access_tokens DROP COLUMN IF EXISTS last_used_at;
-- +goose StatementEnd
-- +goose Down
-- +goose StatementBegin
ALTER TABLE access_tokens ADD COLUMN last_used_at TIMESTAMPTZ;
-- +goose StatementEnd
@@ -0,0 +1,9 @@
-- +goose Up
-- +goose StatementBegin
ALTER TABLE access_tokens DROP COLUMN last_used_at;
-- +goose StatementEnd
-- +goose Down
-- +goose StatementBegin
ALTER TABLE access_tokens ADD COLUMN last_used_at DATETIME;
-- +goose StatementEnd
+8 -9
View File
@@ -20,15 +20,14 @@ const (
// AccessToken 个人访问令牌实体
type AccessToken struct {
ID uint64 `json:"id" gorm:"primaryKey;autoIncrement"`
UserID uint64 `json:"user_id" gorm:"index;not null"`
Name string `json:"name" gorm:"size:128;not null"`
TokenHash string `json:"-" gorm:"size:64;uniqueIndex;not null"`
MaskedToken string `json:"masked_token" gorm:"size:64;not null"`
IsAdmin bool `json:"is_admin" gorm:"default:false"`
LastUsedAt *time.Time `json:"last_used_at"`
CreatedAt time.Time `json:"created_at" gorm:"autoCreateTime"`
UpdatedAt time.Time `json:"updated_at" gorm:"autoUpdateTime"`
ID uint64 `json:"id" gorm:"primaryKey;autoIncrement"`
UserID uint64 `json:"user_id" gorm:"index;not null"`
Name string `json:"name" gorm:"size:128;not null"`
TokenHash string `json:"-" gorm:"size:64;uniqueIndex;not null"`
MaskedToken string `json:"masked_token" gorm:"size:64;not null"`
IsAdmin bool `json:"is_admin" gorm:"default:false"`
CreatedAt time.Time `json:"created_at" gorm:"autoCreateTime"`
UpdatedAt time.Time `json:"updated_at" gorm:"autoUpdateTime"`
}
// GenerateTokenString 生成加密安全的随机 Token 值