fix: harden auth, config access, and backups

This commit is contained in:
sagitchu
2026-05-13 23:53:06 +08:00
parent ec9fb77eb5
commit 465815cf34
28 changed files with 1376 additions and 97 deletions
+2
View File
@@ -253,6 +253,8 @@ export const getConfigs = () =>
Network.post<Record<string, string>>("/config/list");
export const getConfigByName = (name: string) =>
Network.post<{ name: string; value: string }>("/config/get", { name });
export const getPublicConfigByName = (name: string) =>
Network.post<{ name: string; value: string }>("/public/config/get", { name });
export const updateConfigs = (configMap: Record<string, string>) =>
Network.post("/config/update", configMap);
export const updateConfig = (name: string, value: string) =>
+62 -39
View File
@@ -1,4 +1,5 @@
import { getConfigByName, getConfigs } from "@/api";
import { getConfigByName, getConfigs, getPublicConfigByName } from "@/api";
import { isLoggedIn } from "@/utils/auth";
export type SiteConfig = typeof siteConfig;
@@ -8,9 +9,58 @@ const VERSION = import.meta.env.VITE_APP_VERSION || "dev";
const APP_VERSION = "1.0.3";
const DEFAULT_FAVICON = "/favicon.ico";
const FAVICON_LINK_ID = "app-favicon";
const PUBLIC_BRAND_CONFIG_KEYS = [
"app_name",
"app_logo",
"app_favicon",
"app_bg_image",
] as const;
const GITHUB_REPO =
import.meta.env.VITE_GITHUB_REPO || "https://github.com/Sagit-chu/flux-panel";
const readCachedConfigs = (keys: readonly string[]) => {
const cachedConfigs: Record<string, string> = {};
let hasCachedData = false;
keys.forEach((key) => {
const cachedValue = configCache.get(key);
if (cachedValue !== null) {
cachedConfigs[key] = cachedValue;
hasCachedData = true;
}
});
return { cachedConfigs, hasCachedData };
};
const fetchPublicBrandConfigs = async (): Promise<Record<string, string>> => {
const publicConfigMap: Record<string, string> = {};
await Promise.all(
PUBLIC_BRAND_CONFIG_KEYS.map(async (key) => {
try {
const response = await getPublicConfigByName(key);
if (
response.code === 0 &&
response.data &&
typeof response.data.value === "string"
) {
const value = response.data.value;
publicConfigMap[key] = value;
configCache.set(key, value);
}
} catch {
// ignore single key fetch error
}
}),
);
return publicConfigMap;
};
const getInitialConfig = () => {
if (typeof window === "undefined") {
return {
@@ -129,46 +179,19 @@ export const getCachedConfig = async (key: string): Promise<string | null> => {
// 获取所有配置(优先从缓存)
export const getCachedConfigs = async (): Promise<Record<string, string>> => {
// 尝试从缓存获取所有配置
const configKeys = ["app_name", "app_logo", "app_favicon", "app_bg_image"];
const cachedConfigs: Record<string, string> = {};
let hasCachedData = false;
const { cachedConfigs, hasCachedData } = readCachedConfigs(
PUBLIC_BRAND_CONFIG_KEYS,
);
configKeys.forEach((key) => {
const cachedValue = configCache.get(key);
if (!isLoggedIn()) {
const publicConfigs = await fetchPublicBrandConfigs();
if (cachedValue !== null) {
cachedConfigs[key] = cachedValue;
hasCachedData = true;
if (Object.keys(publicConfigs).length > 0) {
return { ...cachedConfigs, ...publicConfigs };
}
});
const fetchPublicConfigs = async (): Promise<Record<string, string>> => {
const publicConfigMap: Record<string, string> = {};
await Promise.all(
configKeys.map(async (key) => {
try {
const response = await getConfigByName(key);
if (
response.code === 0 &&
response.data &&
typeof response.data.value === "string"
) {
const value = response.data.value;
publicConfigMap[key] = value;
configCache.set(key, value);
}
} catch {
// ignore single key fetch error
}
}),
);
return publicConfigMap;
};
return cachedConfigs;
}
// 从API获取最新配置
try {
@@ -189,14 +212,14 @@ export const getCachedConfigs = async (): Promise<Record<string, string>> => {
return cachedConfigs;
}
return await fetchPublicConfigs();
return await fetchPublicBrandConfigs();
} catch {
// API失败时返回缓存的数据
if (hasCachedData) {
return cachedConfigs;
}
return await fetchPublicConfigs();
return await fetchPublicBrandConfigs();
}
};
+2 -2
View File
@@ -10,7 +10,7 @@ import { Button } from "@/shadcn-bridge/heroui/button";
import { siteConfig } from "@/config/site";
import { VersionFooter } from "@/components/version-footer";
import { BrandLogo } from "@/components/brand-logo";
import { login, LoginData, checkCaptcha, getConfigByName } from "@/api";
import { login, LoginData, checkCaptcha, getPublicConfigByName } from "@/api";
import { writeLoginSession } from "@/utils/session";
import { useWebViewMode } from "@/hooks/useWebViewMode";
@@ -128,7 +128,7 @@ export default function IndexPage() {
if (checkResponse.data === 0) {
await performLogin();
} else {
const configResp = await getConfigByName("cloudflare_site_key");
const configResp = await getPublicConfigByName("cloudflare_site_key");
if (configResp.code === 0 && configResp.data && configResp.data.value) {
setSiteKey(configResp.data.value);