fix: comprehensive security, quality and consistency fixes

Server:
- Block startup with default JWT secrets in production
- Make subscription verify admin-only (no payment integration yet)
- Add device ownership validation on command/result, event, treatment/sync
- Remove admin token from request body fallback
- Add pageParams boundary protection (pageSize capped at 100)
- Fix COS getObjectUrl to use callback-based Promise
- Add settings key whitelist matching frontend fields
- Add user existence check before subscription creation
- Fix firmware always returning has_update:true
- Replace hardcoded trial subscription with actual DB query
- Extract shared utilities (limitClause, toMysqlDate, formatDate)

Miniprogram:
- Replace fake PD random data with placeholder
- Mark client-timer treatment completions with source field
- Disable mock.js
- Fix BLE listener leaks (save refs, cleanup in onUnload)
- Fix ble.off clearing all listeners (pass specific callback)
- Add BLE disconnect detection via onBLEConnectionStateChange
- Fix subscription status type consistency (number not string)
- Fix scan callback accumulation in ble.js
- Fix history stats accumulation across pages
- Fix subscribe-success/treatment-done hardcoded values
- Fix profile subscription view logic
- Replace purchase flow with admin-contact modal
- Add error logging in command-sync report

Admin console:
- Fix AdminLayout logout (require->import, logout->clearToken)
- Remove all mock data from production request.js
- Replace dashboard fake data with real API calls
- Replace monthly_revenue with subscription_count
- Fix subscription stats fallback (|| -> ??)
- Add token expiry tracking (7 days)
- Unify device status map and subscription status text
- Fix user page record link navigation
- Fix subscription createForm.user_id type handling
- Add error feedback in all empty catch blocks
- Remove unused remember checkbox and uview-plus dependency
- Extract common CSS to shared stylesheet (-900 lines)
- Extract formatDate to shared utils/format.js
- Show real admin name in layout header
这个提交包含在:
Guoguo
2026-04-28 08:46:59 -07:00
父节点 543808b76e
当前提交 b80e872600
修改 42 个文件,包含 495 行新增1216 行删除
+1 -1
查看文件
@@ -38,7 +38,7 @@ async function requireUser(ctx) {
}
async function requireAdmin(ctx) {
const token = readBearer(ctx.headers) || (ctx.body && ctx.body.token)
const token = readBearer(ctx.headers)
if (!token) return null
try {
const payload = jwt.verify(token, config.jwt.adminSecret)
+11 -6
查看文件
@@ -14,12 +14,17 @@ function getClient() {
}
function getObjectUrl(key, expiresSeconds) {
return getClient().getObjectUrl({
Bucket: config.cos.bucket,
Region: config.cos.region,
Key: key,
Sign: true,
Expires: expiresSeconds || 600
return new Promise((resolve, reject) => {
getClient().getObjectUrl({
Bucket: config.cos.bucket,
Region: config.cos.region,
Key: key,
Sign: true,
Expires: expiresSeconds || 3600
}, (err, data) => {
if (err) reject(err)
else resolve(data.Url)
})
})
}
+5 -1
查看文件
@@ -45,4 +45,8 @@ async function transaction(work) {
}
}
module.exports = { getPool, query, one, transaction }
function limitClause(pageSize, offset) {
return ' LIMIT ' + Number(pageSize) + ' OFFSET ' + Number(offset)
}
module.exports = { getPool, query, one, transaction, limitClause }
+12
查看文件
@@ -0,0 +1,12 @@
function toMysqlDate(value) {
if (!value) return null
const d = new Date(value)
if (Number.isNaN(d.getTime())) return null
return d.toISOString().slice(0, 19).replace('T', ' ')
}
function formatDate(date) {
return toMysqlDate(date)
}
module.exports = { toMysqlDate, formatDate }