ryan
c27da41b64
fix(auth): forward session cookies through the Next API proxy
...
Login Set-Cookie was dropped by Next rewrites, so non-admin sessions
never stuck and every later API looked unauthenticated. Proxy JSON
APIs in proxy.ts, copy Set-Cookie, send 401 to login and 403 to /403.
2026-09-02 18:49:42 +08:00
ryan
05606dfb56
feat(frontend): add a dedicated 403 forbidden page
...
Show /403 instead of toasting or staying on the denied screen when
the API returns 403 or a non-admin opens an admin route.
2026-09-02 18:39:11 +08:00
ryan
b7e5e811d1
fix(auth): register CAP scope, 400 on captcha, 403 for permission
...
Navigating from login reused a send_email_code token on register.
Captcha failure used 401 so the client stored /register as the
post-login target and never left the page. Permission denials now
return 403, and the API client no longer wipes the session on 401.
2026-09-02 18:26:22 +08:00
ryan
6a53619dd2
feat(framework): 回灌 OpenFlare 分层、安全与运行时改进
...
将平台域持久化收敛为 repository 唯一入口,model 去掉 IO。
邮件头写入前清除 CR/LF,防止 header 注入。
httppool 支持可配置 Transport;batchwriter 增加 MinBatchSize/Stats,flush 失败交回批次;任务 PermanentError 作为 SkipRetry 终态。
设置与推送页的确认改为 AlertDialog;axios 去尾斜杠并按 Gin 数组序列化查询参数。
升级共享 Go 依赖(Gin、Asynq、OTel、GORM、Redis 等)。
2026-08-16 11:07:20 +08:00
ryan
9f15f42b47
fix(frontend): keep browser API on same-origin rewrites in dev
...
Document that NEXT_PUBLIC_WAVELET_BACKEND_URL must stay unset for local
next dev so axios hits /api/* and Next rewrites proxy to the backend.
2026-08-03 21:25:22 +08:00
ryan
e0eb4e5975
prettier
2026-07-13 15:17:45 +08:00
ryan
49bd850c8b
fix(frontend): repair login session flow
...
Resolve login-page 401 hangs and redirect races by relying on the shared user state. Keep protected-route redirects intact, clean pending requests without unhandled rejections, and allow the dynamic icon route through the page proxy.
2026-06-13 11:27:30 +08:00
ryan
2ae55da52e
seo 检索开关
2026-06-09 08:56:25 +08:00
ryan
b0023787c5
fix
2026-06-09 08:51:53 +08:00
ryan
7579d3865f
eslint
2026-06-09 08:19:38 +08:00
ryan
72d72810b2
cap 与系统信息
2026-06-08 20:37:47 +08:00
ryan
48d414e197
裁剪
...
swagger
移除 merchant
swagger
改造首页内容为通用后台管理系统定位
- 修改首页标题从 'LINUX DO Credit' 改为 'Modern Platform'
- 更新副标题为 '为二次开发而生'
- 更新首页描述为通用平台的特点
- 更新首页特性标签为 '开箱即用、高度可扩展、工业级基建'
- 修改展示卡片为技术栈和二次开发相关
- 更新开发者示例代码为通用的注册和 API Key 获取示例
- 更新页脚品牌名为 'Modern Platform'
- 调整页脚导航链接为通用平台相关内容
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
去除遗留
裁剪
移除 /api/v1/user/pay-key 相关代码
- 删除后端 UpdatePayKey 处理器函数和 UpdatePayKeyRequest 结构体
- 删除 User 模型中的 PayKey 字段
- 删除 User.VerifyPayKey 方法
- 删除 EncryptPayKeyFailed 错误常量
- 删除 /api/v1/user/pay-key PUT 路由
- 删除 OAuth 返回中的 IsPayKey 字段
- 删除前端 UserService.updatePayKey 方法
- 删除前端所有支付密钥 UI 和逻辑
- 更新相关的导出和注释
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com >
去除遗留
api 修正
系统配置
前端裁剪
后端裁剪
init
2026-06-08 20:34:28 +08:00
ryan
8a782525de
压缩历史至 95081aff
2026-06-08 20:34:27 +08:00