mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-04 07:06:36 +08:00
去除 access_token 访问写库逻辑
This commit is contained in:
@@ -205,7 +205,6 @@ export const apiSections: PolicySection[] = [
|
|||||||
"name": "my-dev-key",
|
"name": "my-dev-key",
|
||||||
"masked_token": "at_628d...29c9",
|
"masked_token": "at_628d...29c9",
|
||||||
"is_admin": false,
|
"is_admin": false,
|
||||||
"last_used_at": null,
|
|
||||||
"created_at": "2026-06-07T21:30:00+08:00"
|
"created_at": "2026-06-07T21:30:00+08:00"
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -219,7 +218,7 @@ export const apiSections: PolicySection[] = [
|
|||||||
|
|
||||||
<h3 id="3-4-rotate-token" className="text-base md:text-lg font-semibold text-foreground mt-6 mb-2">3.4 轮换令牌密钥</h3>
|
<h3 id="3-4-rotate-token" className="text-base md:text-lg font-semibold text-foreground mt-6 mb-2">3.4 轮换令牌密钥</h3>
|
||||||
<p><strong>接口:</strong>POST <code className="bg-muted px-1.5 py-0.5 rounded text-xs font-mono">/api/v1/user/access-tokens/:id/rotate</code></p>
|
<p><strong>接口:</strong>POST <code className="bg-muted px-1.5 py-0.5 rounded text-xs font-mono">/api/v1/user/access-tokens/:id/rotate</code></p>
|
||||||
<p><strong>说明:</strong>轮换指定令牌的物理密钥值。系统将废弃原有密钥,返回新生成的明文 Token,并将 `last_used_at` 置空,令牌名称与 ID 保持一致。</p>
|
<p><strong>说明:</strong>轮换指定令牌的物理密钥值。系统将废弃原有密钥,返回新生成的明文 Token,令牌名称与 ID 保持一致。</p>
|
||||||
</div>
|
</div>
|
||||||
),
|
),
|
||||||
children: [
|
children: [
|
||||||
|
|||||||
@@ -206,11 +206,15 @@ export function AccessTokenMain() {
|
|||||||
<div className="space-y-1">
|
<div className="space-y-1">
|
||||||
<div className="flex items-center gap-2">
|
<div className="flex items-center gap-2">
|
||||||
<span className="font-semibold text-sm text-foreground">{token.name}</span>
|
<span className="font-semibold text-sm text-foreground">{token.name}</span>
|
||||||
{token.is_admin && (
|
{token.is_admin ? (
|
||||||
<Badge variant="outline" className="text-[10px] px-1.5 py-0 h-4 border-rose-500/40 text-rose-500 bg-rose-500/5 font-semibold">
|
<Badge variant="outline" className="text-[10px] px-1.5 py-0 h-4 border-rose-500/40 text-rose-500 bg-rose-500/5 font-semibold">
|
||||||
<Shield className="size-2.5 mr-0.5" />
|
<Shield className="size-2.5 mr-0.5" />
|
||||||
管理员
|
管理员
|
||||||
</Badge>
|
</Badge>
|
||||||
|
) : (
|
||||||
|
<Badge variant="outline" className="text-[10px] px-1.5 py-0 h-4 border-border/50 text-muted-foreground bg-muted/10 font-semibold">
|
||||||
|
用户令牌
|
||||||
|
</Badge>
|
||||||
)}
|
)}
|
||||||
</div>
|
</div>
|
||||||
<div className="flex flex-col gap-1 text-xs text-muted-foreground">
|
<div className="flex flex-col gap-1 text-xs text-muted-foreground">
|
||||||
@@ -219,7 +223,6 @@ export function AccessTokenMain() {
|
|||||||
</div>
|
</div>
|
||||||
<div className="flex flex-wrap gap-x-4 gap-y-0.5 pt-1">
|
<div className="flex flex-wrap gap-x-4 gap-y-0.5 pt-1">
|
||||||
<span>创建于: {formatDate(token.created_at)}</span>
|
<span>创建于: {formatDate(token.created_at)}</span>
|
||||||
<span>最后使用: {formatDate(token.last_used_at)}</span>
|
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
</div>
|
</div>
|
||||||
|
|||||||
@@ -6,7 +6,6 @@ export interface AccessToken {
|
|||||||
name: string;
|
name: string;
|
||||||
masked_token: string;
|
masked_token: string;
|
||||||
is_admin: boolean;
|
is_admin: boolean;
|
||||||
last_used_at?: string;
|
|
||||||
created_at: string;
|
created_at: string;
|
||||||
updated_at: string;
|
updated_at: string;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -6,7 +6,6 @@ package oauth
|
|||||||
|
|
||||||
import (
|
import (
|
||||||
"net/http"
|
"net/http"
|
||||||
"time"
|
|
||||||
|
|
||||||
"github.com/Rain-kl/Wavelet/internal/common"
|
"github.com/Rain-kl/Wavelet/internal/common"
|
||||||
"github.com/Rain-kl/Wavelet/internal/db"
|
"github.com/Rain-kl/Wavelet/internal/db"
|
||||||
@@ -56,9 +55,6 @@ func LoginRequired() gin.HandlerFunc {
|
|||||||
authenticated = true
|
authenticated = true
|
||||||
tokenAuth = true
|
tokenAuth = true
|
||||||
tokenAdmin = tokenRecord.IsAdmin
|
tokenAdmin = tokenRecord.IsAdmin
|
||||||
// update token last used time
|
|
||||||
now := time.Now()
|
|
||||||
db.DB(ctx).Model(&tokenRecord).Update("last_used_at", &now)
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -203,7 +203,6 @@ func RotateAccessToken(c *gin.Context) {
|
|||||||
|
|
||||||
tokenRecord.TokenHash = newTokenHash
|
tokenRecord.TokenHash = newTokenHash
|
||||||
tokenRecord.MaskedToken = newMaskedToken
|
tokenRecord.MaskedToken = newMaskedToken
|
||||||
tokenRecord.LastUsedAt = nil // 轮换后重置使用时间
|
|
||||||
|
|
||||||
if err := db.DB(ctx).Save(&tokenRecord).Error; err != nil {
|
if err := db.DB(ctx).Save(&tokenRecord).Error; err != nil {
|
||||||
c.JSON(http.StatusOK, util.Err(err.Error()))
|
c.JSON(http.StatusOK, util.Err(err.Error()))
|
||||||
|
|||||||
@@ -0,0 +1,9 @@
|
|||||||
|
-- +goose Up
|
||||||
|
-- +goose StatementBegin
|
||||||
|
ALTER TABLE access_tokens DROP COLUMN IF EXISTS last_used_at;
|
||||||
|
-- +goose StatementEnd
|
||||||
|
|
||||||
|
-- +goose Down
|
||||||
|
-- +goose StatementBegin
|
||||||
|
ALTER TABLE access_tokens ADD COLUMN last_used_at TIMESTAMPTZ;
|
||||||
|
-- +goose StatementEnd
|
||||||
@@ -0,0 +1,9 @@
|
|||||||
|
-- +goose Up
|
||||||
|
-- +goose StatementBegin
|
||||||
|
ALTER TABLE access_tokens DROP COLUMN last_used_at;
|
||||||
|
-- +goose StatementEnd
|
||||||
|
|
||||||
|
-- +goose Down
|
||||||
|
-- +goose StatementBegin
|
||||||
|
ALTER TABLE access_tokens ADD COLUMN last_used_at DATETIME;
|
||||||
|
-- +goose StatementEnd
|
||||||
@@ -20,15 +20,14 @@ const (
|
|||||||
|
|
||||||
// AccessToken 个人访问令牌实体
|
// AccessToken 个人访问令牌实体
|
||||||
type AccessToken struct {
|
type AccessToken struct {
|
||||||
ID uint64 `json:"id" gorm:"primaryKey;autoIncrement"`
|
ID uint64 `json:"id" gorm:"primaryKey;autoIncrement"`
|
||||||
UserID uint64 `json:"user_id" gorm:"index;not null"`
|
UserID uint64 `json:"user_id" gorm:"index;not null"`
|
||||||
Name string `json:"name" gorm:"size:128;not null"`
|
Name string `json:"name" gorm:"size:128;not null"`
|
||||||
TokenHash string `json:"-" gorm:"size:64;uniqueIndex;not null"`
|
TokenHash string `json:"-" gorm:"size:64;uniqueIndex;not null"`
|
||||||
MaskedToken string `json:"masked_token" gorm:"size:64;not null"`
|
MaskedToken string `json:"masked_token" gorm:"size:64;not null"`
|
||||||
IsAdmin bool `json:"is_admin" gorm:"default:false"`
|
IsAdmin bool `json:"is_admin" gorm:"default:false"`
|
||||||
LastUsedAt *time.Time `json:"last_used_at"`
|
CreatedAt time.Time `json:"created_at" gorm:"autoCreateTime"`
|
||||||
CreatedAt time.Time `json:"created_at" gorm:"autoCreateTime"`
|
UpdatedAt time.Time `json:"updated_at" gorm:"autoUpdateTime"`
|
||||||
UpdatedAt time.Time `json:"updated_at" gorm:"autoUpdateTime"`
|
|
||||||
}
|
}
|
||||||
|
|
||||||
// GenerateTokenString 生成加密安全的随机 Token 值
|
// GenerateTokenString 生成加密安全的随机 Token 值
|
||||||
|
|||||||
Reference in New Issue
Block a user