diff --git a/docs/changelog/index.md b/docs/changelog/index.md index 167d2aa6..c2608d27 100644 --- a/docs/changelog/index.md +++ b/docs/changelog/index.md @@ -18,6 +18,12 @@ sidebar: false ## [unreleased] +## [v3.1.1] - 2026-07-06 + +### 修改 + +- 将 `cap_login_enabled` 默认值由 `true` 变更为 `false`,默认关闭登录界面 PoW 人机验证。 + ## [v3.1.0] - 2026-07-04 ### 修改 diff --git a/docs/reference/configuration.md b/docs/reference/configuration.md index d7f7108f..d5f3deb2 100644 --- a/docs/reference/configuration.md +++ b/docs/reference/configuration.md @@ -161,7 +161,7 @@ Server 的所有核心基础配置定义在 `config.yaml` 中,且均支持环 ### 2. 人机安全校验 (PoW Captcha) | 配置键 (Key) | 数据类型 | 作用说明 | 默认值 | | --- | --- | --- | --- | -| `cap_login_enabled` | `bool` | 是否在登录界面强制要求进行本地 PoW 算力防爆破人机验证 | `true` | +| `cap_login_enabled` | `bool` | 是否在登录界面强制要求进行本地 PoW 算力防爆破人机验证 | `false` | | `cap_auto_solve` | `bool` | 打开页面后是否由浏览器自动开始后台背景计算算力(无需用户手动点击)| `true` | | `cap_challenge_count` | `int` | 人机验证所需的计算难题数。数量越大,计算要求时间越长(推荐 1~5) | `1` | | `cap_challenge_difficulty`| `int`| 每次计算所需的 PoW 哈希前缀匹配难度。推荐数值在 3-5 之间 | `4` | diff --git a/frontend/components/auth/login-form.tsx b/frontend/components/auth/login-form.tsx index 50d456b7..fd0e19cd 100644 --- a/frontend/components/auth/login-form.tsx +++ b/frontend/components/auth/login-form.tsx @@ -73,7 +73,7 @@ export function LoginForm({ onOTPStateChange }: { onOTPStateChange?: (show: bool queryFn: () => AuthService.getAuthSources(), }) - const capEnabled = configBool(publicConfigQuery.data?.cap_login_enabled, true) + const capEnabled = configBool(publicConfigQuery.data?.cap_login_enabled, false) const capAutoSolve = configBool(publicConfigQuery.data?.cap_auto_solve, true) const loginMutation = useMutation({ diff --git a/frontend/components/auth/register-form.tsx b/frontend/components/auth/register-form.tsx index 2af38076..452b4bad 100644 --- a/frontend/components/auth/register-form.tsx +++ b/frontend/components/auth/register-form.tsx @@ -68,7 +68,7 @@ export function RegisterForm() { const emailRegisterEnabled = configBool(publicConfigQuery.data?.email_register_verification_enabled, false) - const capEnabled = configBool(publicConfigQuery.data?.cap_login_enabled, true) + const capEnabled = configBool(publicConfigQuery.data?.cap_login_enabled, false) const capAutoSolve = configBool(publicConfigQuery.data?.cap_auto_solve, true) const [capScope, setCapScope] = useState<'send_email_code' | 'register'>('send_email_code') diff --git a/frontend/components/common/docs/api.tsx b/frontend/components/common/docs/api.tsx index 919932a5..52d58b71 100644 --- a/frontend/components/common/docs/api.tsx +++ b/frontend/components/common/docs/api.tsx @@ -245,7 +245,7 @@ export const apiSections: PolicySection[] = [ "registration_enabled": "false", "password_login_enabled": "true", "password_register_enabled": "false", - "cap_login_enabled": "true", + "cap_login_enabled": "false", "oidc_login_enabled": "true" } }`} diff --git a/internal/apps/cap/runtime_settings_test.go b/internal/apps/cap/runtime_settings_test.go index c62b19ee..f04ca5ee 100644 --- a/internal/apps/cap/runtime_settings_test.go +++ b/internal/apps/cap/runtime_settings_test.go @@ -56,13 +56,13 @@ func TestProtectionEnabledReflectsLoginSwitch(t *testing.T) { ResetRuntimeSettingsForTest() - if !ProtectionEnabled(ctx) { - t.Fatal("ProtectionEnabled() = false, want true from seed defaults") + if ProtectionEnabled(ctx) { + t.Fatal("ProtectionEnabled() = true, want false from seed defaults") } if err := db.DB(ctx).Model(&model.SystemConfig{}). Where("key = ?", model.ConfigKeyCapLoginEnabled). - Update("value", "false").Error; err != nil { + Update("value", "true").Error; err != nil { t.Fatalf("Update(cap_login_enabled) error = %v", err) } if err := repository.InvalidateSystemConfigCache(ctx, model.ConfigKeyCapLoginEnabled); err != nil { @@ -70,8 +70,8 @@ func TestProtectionEnabledReflectsLoginSwitch(t *testing.T) { } InvalidateRuntimeSettings() - if ProtectionEnabled(ctx) { - t.Fatal("ProtectionEnabled() = true, want false after config update") + if !ProtectionEnabled(ctx) { + t.Fatal("ProtectionEnabled() = false, want true after config update") } } diff --git a/internal/db/migrator/goose/postgres/202606090001_initial_schema.sql b/internal/db/migrator/goose/postgres/202606090001_initial_schema.sql index c53cc515..3b6f72a6 100644 --- a/internal/db/migrator/goose/postgres/202606090001_initial_schema.sql +++ b/internal/db/migrator/goose/postgres/202606090001_initial_schema.sql @@ -137,7 +137,7 @@ CREATE INDEX IF NOT EXISTS idx_templates_created_at ON templates (created_at); CREATE INDEX IF NOT EXISTS idx_templates_updated_at ON templates (updated_at); INSERT INTO system_configs (key, value, type, visibility, description, created_at, updated_at) VALUES - ('cap_login_enabled', 'true', 'system', 1, '是否启用登录人机验证(true/false)', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), + ('cap_login_enabled', 'false', 'system', 1, '是否启用登录人机验证(true/false)', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), ('cap_auto_solve', 'true', 'system', 1, '打开页面后是否自动开始计算,关闭则需用户手动点击触发', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), ('cap_challenge_count', '1', 'system', 0, '客户端需求解的 PoW 难题总数,默认 1,推荐 1~5', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), ('cap_challenge_size', '32', 'system', 0, '人机验证盐值长度', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), diff --git a/internal/db/migrator/goose/postgres/202606200002_update_security_defaults.sql b/internal/db/migrator/goose/postgres/202606200002_update_security_defaults.sql index e1790f7d..68484a8b 100644 --- a/internal/db/migrator/goose/postgres/202606200002_update_security_defaults.sql +++ b/internal/db/migrator/goose/postgres/202606200002_update_security_defaults.sql @@ -7,10 +7,6 @@ UPDATE w_system_configs SET value = 'false', updated_at = CURRENT_TIMESTAMP WHERE key = 'password_register_enabled' AND value = 'true'; -UPDATE w_system_configs -SET value = 'true', updated_at = CURRENT_TIMESTAMP -WHERE key = 'cap_login_enabled' AND value = 'false'; - -- +goose Down UPDATE w_system_configs SET value = 'true', updated_at = CURRENT_TIMESTAMP @@ -18,8 +14,4 @@ WHERE key = 'registration_enabled' AND value = 'false'; UPDATE w_system_configs SET value = 'true', updated_at = CURRENT_TIMESTAMP -WHERE key = 'password_register_enabled' AND value = 'false'; - -UPDATE w_system_configs -SET value = 'false', updated_at = CURRENT_TIMESTAMP -WHERE key = 'cap_login_enabled' AND value = 'true'; \ No newline at end of file +WHERE key = 'password_register_enabled' AND value = 'false'; \ No newline at end of file diff --git a/internal/db/migrator/goose/sqlite/202606090001_initial_schema.sql b/internal/db/migrator/goose/sqlite/202606090001_initial_schema.sql index 73eb79b3..2240fb98 100644 --- a/internal/db/migrator/goose/sqlite/202606090001_initial_schema.sql +++ b/internal/db/migrator/goose/sqlite/202606090001_initial_schema.sql @@ -137,7 +137,7 @@ CREATE INDEX IF NOT EXISTS idx_templates_created_at ON templates (created_at); CREATE INDEX IF NOT EXISTS idx_templates_updated_at ON templates (updated_at); INSERT INTO system_configs (key, value, type, visibility, description, created_at, updated_at) VALUES - ('cap_login_enabled', 'true', 'system', 1, '是否启用登录人机验证(true/false)', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), + ('cap_login_enabled', 'false', 'system', 1, '是否启用登录人机验证(true/false)', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), ('cap_auto_solve', 'true', 'system', 1, '打开页面后是否自动开始计算,关闭则需用户手动点击触发', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), ('cap_challenge_count', '1', 'system', 0, '客户端需求解的 PoW 难题总数,默认 1,推荐 1~5', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), ('cap_challenge_size', '32', 'system', 0, '人机验证盐值长度', CURRENT_TIMESTAMP, CURRENT_TIMESTAMP), diff --git a/internal/db/migrator/goose/sqlite/202606200002_update_security_defaults.sql b/internal/db/migrator/goose/sqlite/202606200002_update_security_defaults.sql index e1790f7d..68484a8b 100644 --- a/internal/db/migrator/goose/sqlite/202606200002_update_security_defaults.sql +++ b/internal/db/migrator/goose/sqlite/202606200002_update_security_defaults.sql @@ -7,10 +7,6 @@ UPDATE w_system_configs SET value = 'false', updated_at = CURRENT_TIMESTAMP WHERE key = 'password_register_enabled' AND value = 'true'; -UPDATE w_system_configs -SET value = 'true', updated_at = CURRENT_TIMESTAMP -WHERE key = 'cap_login_enabled' AND value = 'false'; - -- +goose Down UPDATE w_system_configs SET value = 'true', updated_at = CURRENT_TIMESTAMP @@ -18,8 +14,4 @@ WHERE key = 'registration_enabled' AND value = 'false'; UPDATE w_system_configs SET value = 'true', updated_at = CURRENT_TIMESTAMP -WHERE key = 'password_register_enabled' AND value = 'false'; - -UPDATE w_system_configs -SET value = 'false', updated_at = CURRENT_TIMESTAMP -WHERE key = 'cap_login_enabled' AND value = 'true'; \ No newline at end of file +WHERE key = 'password_register_enabled' AND value = 'false'; \ No newline at end of file diff --git a/internal/testhelper/test_helper.go b/internal/testhelper/test_helper.go index 3d279aa5..6c0d4327 100644 --- a/internal/testhelper/test_helper.go +++ b/internal/testhelper/test_helper.go @@ -142,7 +142,7 @@ func getSeedConfigsPart1() []model.SystemConfig { }, { Key: model.ConfigKeyCapLoginEnabled, - Value: configValueTrue, + Value: configValueFalse, Type: configTypeSystem, Description: "是否启用登录人机验证(true/false)", },