fix: comprehensive security, quality and consistency fixes

Server:
- Block startup with default JWT secrets in production
- Make subscription verify admin-only (no payment integration yet)
- Add device ownership validation on command/result, event, treatment/sync
- Remove admin token from request body fallback
- Add pageParams boundary protection (pageSize capped at 100)
- Fix COS getObjectUrl to use callback-based Promise
- Add settings key whitelist matching frontend fields
- Add user existence check before subscription creation
- Fix firmware always returning has_update:true
- Replace hardcoded trial subscription with actual DB query
- Extract shared utilities (limitClause, toMysqlDate, formatDate)

Miniprogram:
- Replace fake PD random data with placeholder
- Mark client-timer treatment completions with source field
- Disable mock.js
- Fix BLE listener leaks (save refs, cleanup in onUnload)
- Fix ble.off clearing all listeners (pass specific callback)
- Add BLE disconnect detection via onBLEConnectionStateChange
- Fix subscription status type consistency (number not string)
- Fix scan callback accumulation in ble.js
- Fix history stats accumulation across pages
- Fix subscribe-success/treatment-done hardcoded values
- Fix profile subscription view logic
- Replace purchase flow with admin-contact modal
- Add error logging in command-sync report

Admin console:
- Fix AdminLayout logout (require->import, logout->clearToken)
- Remove all mock data from production request.js
- Replace dashboard fake data with real API calls
- Replace monthly_revenue with subscription_count
- Fix subscription stats fallback (|| -> ??)
- Add token expiry tracking (7 days)
- Unify device status map and subscription status text
- Fix user page record link navigation
- Fix subscription createForm.user_id type handling
- Add error feedback in all empty catch blocks
- Remove unused remember checkbox and uview-plus dependency
- Extract common CSS to shared stylesheet (-900 lines)
- Extract formatDate to shared utils/format.js
- Show real admin name in layout header
这个提交包含在:
Guoguo
2026-04-28 08:46:59 -07:00
父节点 543808b76e
当前提交 b80e872600
修改 42 个文件,包含 495 行新增1216 行删除
+20 -16
查看文件
@@ -7,6 +7,7 @@ Page({
scanProgress: 0,
regions: 0x7F,
regionData: [],
timeout: false,
error: ''
},
@@ -21,42 +22,45 @@ Page({
startScan: function () {
var self = this
self.setData({ scanning: true, scanProgress: 0 })
self.setData({ scanning: true, scanProgress: 0, timeout: false })
var progressTimer = setInterval(function () {
this._progressTimer = setInterval(function () {
var p = self.data.scanProgress + 2
if (p > 98) p = 98
self.setData({ scanProgress: p })
}, 100)
ble.on('status', function (status) {
this._onStatus = function (status) {
if (status.mode_state === 0x01) {
self.setData({ scanProgress: 50 })
} else if (status.mode_state === 0x04 || status.mode_state === 0x00) {
clearInterval(progressTimer)
clearInterval(self._progressTimer)
self.setData({ scanning: false, scanProgress: 100 })
if (status.region_mask) {
self.parseScanResults(status)
}
var names = ble.getRegionName(status.region_mask || 0x7F)
self.setData({ regionData: self.parseScanResults(names) })
}
})
}
ble.on('status', this._onStatus)
ble.queryStatus().catch(function () {})
setTimeout(function () {
clearInterval(progressTimer)
clearInterval(self._progressTimer)
if (!self.data.scanning) return
self.setData({ scanning: false, scanProgress: 100 })
self.parseScanResults({ region_mask: self.data.regions })
self.setData({ scanning: false, timeout: true })
wx.showToast({ title: '扫描超时,请重试', icon: 'none' })
}, 5000)
},
parseScanResults: function (status) {
var regions = ble.getRegionName(status.region_mask || 0x7F)
var data = regions.map(function (name) {
return { region: name, pd: (Math.random() * 0.3 + 0.3).toFixed(2) }
parseScanResults: function (regions) {
return regions.map(function (name) {
return { region: name, pd: '--' }
})
this.setData({ regionData: data })
},
onUnload: function () {
if (this._progressTimer) clearInterval(this._progressTimer)
if (this._onStatus) ble.off('status', this._onStatus)
},
onNext: function () {