refactor(auth): improve session security, CAPTCHA validation and code hygiene

- Integrate CapWidget with dual-scope capability on the frontend and protect registration/send-email-code endpoints on the backend.
- Set session cookie SameSite mode to Lax.
- Propagate request context through auth source database operations and optimize username uniqueness validation.
- Standardize local error naming to camelCase and resolve references.
- Fix linter rules, missing SheetContent closing tag, and unit tests.
This commit is contained in:
ryan
2026-06-13 12:33:01 +08:00
parent 04280a7b11
commit b262880189
13 changed files with 241 additions and 111 deletions
+6 -4
View File
@@ -45,7 +45,7 @@ func isEmailRegisterVerificationEnabled(ctx context.Context) bool {
}
func isSMTPConfigured(ctx context.Context) bool {
var host, port, username string
var host, port, username, password string
var scHost model.SystemConfig
if err := scHost.GetByKey(ctx, model.ConfigKeySMTPHost); err == nil {
@@ -59,8 +59,12 @@ func isSMTPConfigured(ctx context.Context) bool {
if err := scUser.GetByKey(ctx, model.ConfigKeySMTPUsername); err == nil {
username = scUser.Value
}
var scPass model.SystemConfig
if err := scPass.GetByKey(ctx, model.ConfigKeySMTPPassword); err == nil {
password = scPass.Value
}
return host != "" && port != "" && username != ""
return host != "" && port != "" && username != "" && password != ""
}
func generateVerificationCode() (string, error) {
@@ -241,8 +245,6 @@ func validateRegisterEmailVerification(ctx context.Context, req *registerRequest
return nil
}
type updateProfileRequest struct {
Nickname string `json:"nickname"`
Email string `json:"email"`