fix: comprehensive security, quality and consistency fixes
Server: - Block startup with default JWT secrets in production - Make subscription verify admin-only (no payment integration yet) - Add device ownership validation on command/result, event, treatment/sync - Remove admin token from request body fallback - Add pageParams boundary protection (pageSize capped at 100) - Fix COS getObjectUrl to use callback-based Promise - Add settings key whitelist matching frontend fields - Add user existence check before subscription creation - Fix firmware always returning has_update:true - Replace hardcoded trial subscription with actual DB query - Extract shared utilities (limitClause, toMysqlDate, formatDate) Miniprogram: - Replace fake PD random data with placeholder - Mark client-timer treatment completions with source field - Disable mock.js - Fix BLE listener leaks (save refs, cleanup in onUnload) - Fix ble.off clearing all listeners (pass specific callback) - Add BLE disconnect detection via onBLEConnectionStateChange - Fix subscription status type consistency (number not string) - Fix scan callback accumulation in ble.js - Fix history stats accumulation across pages - Fix subscribe-success/treatment-done hardcoded values - Fix profile subscription view logic - Replace purchase flow with admin-contact modal - Add error logging in command-sync report Admin console: - Fix AdminLayout logout (require->import, logout->clearToken) - Remove all mock data from production request.js - Replace dashboard fake data with real API calls - Replace monthly_revenue with subscription_count - Fix subscription stats fallback (|| -> ??) - Add token expiry tracking (7 days) - Unify device status map and subscription status text - Fix user page record link navigation - Fix subscription createForm.user_id type handling - Add error feedback in all empty catch blocks - Remove unused remember checkbox and uview-plus dependency - Extract common CSS to shared stylesheet (-900 lines) - Extract formatDate to shared utils/format.js - Show real admin name in layout header
这个提交包含在:
+1
-1
@@ -38,7 +38,7 @@ async function requireUser(ctx) {
|
||||
}
|
||||
|
||||
async function requireAdmin(ctx) {
|
||||
const token = readBearer(ctx.headers) || (ctx.body && ctx.body.token)
|
||||
const token = readBearer(ctx.headers)
|
||||
if (!token) return null
|
||||
try {
|
||||
const payload = jwt.verify(token, config.jwt.adminSecret)
|
||||
|
||||
+11
-6
@@ -14,12 +14,17 @@ function getClient() {
|
||||
}
|
||||
|
||||
function getObjectUrl(key, expiresSeconds) {
|
||||
return getClient().getObjectUrl({
|
||||
Bucket: config.cos.bucket,
|
||||
Region: config.cos.region,
|
||||
Key: key,
|
||||
Sign: true,
|
||||
Expires: expiresSeconds || 600
|
||||
return new Promise((resolve, reject) => {
|
||||
getClient().getObjectUrl({
|
||||
Bucket: config.cos.bucket,
|
||||
Region: config.cos.region,
|
||||
Key: key,
|
||||
Sign: true,
|
||||
Expires: expiresSeconds || 3600
|
||||
}, (err, data) => {
|
||||
if (err) reject(err)
|
||||
else resolve(data.Url)
|
||||
})
|
||||
})
|
||||
}
|
||||
|
||||
|
||||
+5
-1
@@ -45,4 +45,8 @@ async function transaction(work) {
|
||||
}
|
||||
}
|
||||
|
||||
module.exports = { getPool, query, one, transaction }
|
||||
function limitClause(pageSize, offset) {
|
||||
return ' LIMIT ' + Number(pageSize) + ' OFFSET ' + Number(offset)
|
||||
}
|
||||
|
||||
module.exports = { getPool, query, one, transaction, limitClause }
|
||||
|
||||
@@ -0,0 +1,12 @@
|
||||
function toMysqlDate(value) {
|
||||
if (!value) return null
|
||||
const d = new Date(value)
|
||||
if (Number.isNaN(d.getTime())) return null
|
||||
return d.toISOString().slice(0, 19).replace('T', ' ')
|
||||
}
|
||||
|
||||
function formatDate(date) {
|
||||
return toMysqlDate(date)
|
||||
}
|
||||
|
||||
module.exports = { toMysqlDate, formatDate }
|
||||
在新工单中引用
屏蔽一个用户