fix: address critical security and data integrity issues from cross-audit
- Add expire_time > NOW() filter to findActive() preventing stale subscriptions - Add express-rate-limit on login endpoints (user: 10/15min, admin: 5/15min) - Add production guard for default admin credentials - Fix BLE bindDevice userId encoding (uint32 instead of hexToBytes on numeric) - Wrap adminCreate in transaction to prevent race condition - Add settings cache invalidation after admin saves - Read trial_days from settings instead of hardcoding 7 - Fix double JSON.stringify in commandDao.finish call - Cancel stale pending bindings before creating new ones - Reduce token refresh grace period from 3 days to 1 day - Fix subscribe-success to fetch expiry from server (correct for renewals) - Add keep-alive name property to DashboardView and SettingsView - Fix BLE disconnect() to preserve listener registrations across reconnects
这个提交包含在:
@@ -113,6 +113,7 @@ import { get } from '../utils/request'
|
||||
import { formatDate as formatDateUtil } from '../utils/format'
|
||||
|
||||
export default {
|
||||
name: 'DashboardView',
|
||||
data() {
|
||||
return {
|
||||
stats: {},
|
||||
|
||||
@@ -129,6 +129,7 @@
|
||||
import { get, post } from '../utils/request'
|
||||
|
||||
export default {
|
||||
name: 'SettingsView',
|
||||
data() {
|
||||
return {
|
||||
settings: {
|
||||
|
||||
在新工单中引用
屏蔽一个用户