fix: comprehensive security, quality and consistency fixes

Server:
- Block startup with default JWT secrets in production
- Make subscription verify admin-only (no payment integration yet)
- Add device ownership validation on command/result, event, treatment/sync
- Remove admin token from request body fallback
- Add pageParams boundary protection (pageSize capped at 100)
- Fix COS getObjectUrl to use callback-based Promise
- Add settings key whitelist matching frontend fields
- Add user existence check before subscription creation
- Fix firmware always returning has_update:true
- Replace hardcoded trial subscription with actual DB query
- Extract shared utilities (limitClause, toMysqlDate, formatDate)

Miniprogram:
- Replace fake PD random data with placeholder
- Mark client-timer treatment completions with source field
- Disable mock.js
- Fix BLE listener leaks (save refs, cleanup in onUnload)
- Fix ble.off clearing all listeners (pass specific callback)
- Add BLE disconnect detection via onBLEConnectionStateChange
- Fix subscription status type consistency (number not string)
- Fix scan callback accumulation in ble.js
- Fix history stats accumulation across pages
- Fix subscribe-success/treatment-done hardcoded values
- Fix profile subscription view logic
- Replace purchase flow with admin-contact modal
- Add error logging in command-sync report

Admin console:
- Fix AdminLayout logout (require->import, logout->clearToken)
- Remove all mock data from production request.js
- Replace dashboard fake data with real API calls
- Replace monthly_revenue with subscription_count
- Fix subscription stats fallback (|| -> ??)
- Add token expiry tracking (7 days)
- Unify device status map and subscription status text
- Fix user page record link navigation
- Fix subscription createForm.user_id type handling
- Add error feedback in all empty catch blocks
- Remove unused remember checkbox and uview-plus dependency
- Extract common CSS to shared stylesheet (-900 lines)
- Extract formatDate to shared utils/format.js
- Show real admin name in layout header
这个提交包含在:
Guoguo
2026-04-28 08:46:59 -07:00
父节点 543808b76e
当前提交 b80e872600
修改 42 个文件,包含 495 行新增1216 行删除
+17 -12
查看文件
@@ -16,7 +16,6 @@ Page({
paused: false,
completed: false,
startedAt: 0,
localTimer: null
},
onLoad: function (options) {
@@ -31,18 +30,21 @@ Page({
startedAt: Date.now()
})
ble.on('status', this.onStatus.bind(this))
ble.on('treatment_complete', this.onComplete.bind(this))
ble.on('exception', this.onException.bind(this))
this._onStatus = this.onStatus.bind(this)
this._onComplete = this.onComplete.bind(this)
this._onException = this.onException.bind(this)
ble.on('status', this._onStatus)
ble.on('treatment_complete', this._onComplete)
ble.on('exception', this._onException)
this.startLocalTimer()
this.syncCommands()
},
onUnload: function () {
ble.off('status')
ble.off('treatment_complete')
ble.off('exception')
if (this.data.localTimer) clearInterval(this.data.localTimer)
if (this._onStatus) ble.off('status', this._onStatus)
if (this._onComplete) ble.off('treatment_complete', this._onComplete)
if (this._onException) ble.off('exception', this._onException)
if (this._localTimer) clearInterval(this._localTimer)
},
startLocalTimer: function () {
@@ -57,7 +59,7 @@ Page({
self.finishAsComplete()
}
}, 1000)
this.setData({ localTimer: timer })
this._localTimer = timer
},
updateProgress: function (remaining) {
@@ -95,12 +97,14 @@ Page({
var app = getApp()
app.globalData.currentTreatment = result
var self = this
setTimeout(function () {
wx.redirectTo({
url: '/pages/treatment-done/treatment-done?session_id=' + result.session_id +
'&regions=' + result.regions +
'&duration=' + result.total_duration_ms +
'&avg_pd=' + result.avg_pd
'&avg_pd=' + result.avg_pd +
'&mode=' + (self.data.mode || 0)
})
}, 1000)
},
@@ -108,10 +112,11 @@ Page({
finishAsComplete: function () {
var elapsed = Math.min(this.data.duration, Date.now() - this.data.startedAt)
this.onComplete({
session_id: 'SESS' + Date.now(),
session_id: 'LOCAL_' + Date.now(),
regions: this.data.regions,
total_duration_ms: elapsed,
avg_pd: 0
avg_pd: 0,
source: 'client_timer'
})
},