fix: comprehensive security, quality and consistency fixes
Server: - Block startup with default JWT secrets in production - Make subscription verify admin-only (no payment integration yet) - Add device ownership validation on command/result, event, treatment/sync - Remove admin token from request body fallback - Add pageParams boundary protection (pageSize capped at 100) - Fix COS getObjectUrl to use callback-based Promise - Add settings key whitelist matching frontend fields - Add user existence check before subscription creation - Fix firmware always returning has_update:true - Replace hardcoded trial subscription with actual DB query - Extract shared utilities (limitClause, toMysqlDate, formatDate) Miniprogram: - Replace fake PD random data with placeholder - Mark client-timer treatment completions with source field - Disable mock.js - Fix BLE listener leaks (save refs, cleanup in onUnload) - Fix ble.off clearing all listeners (pass specific callback) - Add BLE disconnect detection via onBLEConnectionStateChange - Fix subscription status type consistency (number not string) - Fix scan callback accumulation in ble.js - Fix history stats accumulation across pages - Fix subscribe-success/treatment-done hardcoded values - Fix profile subscription view logic - Replace purchase flow with admin-contact modal - Add error logging in command-sync report Admin console: - Fix AdminLayout logout (require->import, logout->clearToken) - Remove all mock data from production request.js - Replace dashboard fake data with real API calls - Replace monthly_revenue with subscription_count - Fix subscription stats fallback (|| -> ??) - Add token expiry tracking (7 days) - Unify device status map and subscription status text - Fix user page record link navigation - Fix subscription createForm.user_id type handling - Add error feedback in all empty catch blocks - Remove unused remember checkbox and uview-plus dependency - Extract common CSS to shared stylesheet (-900 lines) - Extract formatDate to shared utils/format.js - Show real admin name in layout header
这个提交包含在:
@@ -9,6 +9,7 @@ Page({
|
||||
regions: 0,
|
||||
duration: 0,
|
||||
avgPd: 0,
|
||||
mode: 0,
|
||||
durationText: '',
|
||||
regionNames: [],
|
||||
syncing: false,
|
||||
@@ -34,6 +35,7 @@ Page({
|
||||
duration: durationMs,
|
||||
avgPd: options.avg_pd || 0,
|
||||
durationText: durationText,
|
||||
mode: parseInt(options.mode) || 0,
|
||||
regionNames: ble.getRegionName(parseInt(options.regions) || 0)
|
||||
})
|
||||
|
||||
@@ -42,6 +44,7 @@ Page({
|
||||
|
||||
syncRecord: function () {
|
||||
var self = this
|
||||
var treatment = (app.globalData.currentTreatment) || {}
|
||||
self.setData({ syncing: true })
|
||||
|
||||
http.post('/api/v1/treatment/sync', {
|
||||
@@ -51,8 +54,9 @@ Page({
|
||||
end_time: new Date().toISOString(),
|
||||
regions: self.data.regions,
|
||||
total_duration_ms: self.data.duration,
|
||||
mode: 0,
|
||||
avg_pd: self.data.avgPd
|
||||
mode: self.data.mode,
|
||||
avg_pd: self.data.avgPd,
|
||||
source: treatment.source || 'device'
|
||||
}).then(function () {
|
||||
self.setData({ syncing: false, synced: true })
|
||||
}).catch(function () {
|
||||
|
||||
在新工单中引用
屏蔽一个用户