refactor(auth): improve session security, CAPTCHA validation and code hygiene

- Integrate CapWidget with dual-scope capability on the frontend and protect registration/send-email-code endpoints on the backend.
- Set session cookie SameSite mode to Lax.
- Propagate request context through auth source database operations and optimize username uniqueness validation.
- Standardize local error naming to camelCase and resolve references.
- Fix linter rules, missing SheetContent closing tag, and unit tests.
This commit is contained in:
ryan
2026-06-13 12:33:01 +08:00
parent 04280a7b11
commit b262880189
13 changed files with 241 additions and 111 deletions
+4 -4
View File
@@ -109,12 +109,12 @@ export class AuthService extends BaseService {
return this.post<User>('/user/login', request, headers ? ({ headers } as unknown as InternalAxiosRequestConfig) : undefined);
}
static async register(request: RegisterRequest): Promise<User> {
return this.post<User>('/user/register', request);
static async register(request: RegisterRequest, headers?: Record<string, string>): Promise<User> {
return this.post<User>('/user/register', request, headers ? ({ headers } as unknown as InternalAxiosRequestConfig) : undefined);
}
static async sendEmailCode(email: string, scene: 'register' | 'login'): Promise<void> {
return this.post<void>('/user/send-email-code', { email, scene });
static async sendEmailCode(email: string, scene: 'register' | 'login', headers?: Record<string, string>): Promise<void> {
return this.post<void>('/user/send-email-code', { email, scene }, headers ? ({ headers } as unknown as InternalAxiosRequestConfig) : undefined);
}
static async changePassword(request: ChangePasswordRequest): Promise<void> {