05e990eda572ac3dc2ced0f0574e1708549ec5f3
CRITICAL fixes: - C1: Notify amount validation now unconditional (was skippable if amount field missing) - C2: Sync endpoint validates payer_total against order amount before activation - C3: Order ID uses crypto.randomBytes(6) instead of Math.random (collision-safe) HIGH fixes: - H1: Payment endpoints rate limited to 5/min per IP - H2: Max 5 pending orders per user, reject new ones until completed/cancelled - H3: Purchase endpoint returns error (not mock) when wxpay unconfigured in production Also fixed: - Notify handler asserts Buffer body, rejects non-Buffer (L3) - Notify error response is generic, no internal message leak (M1) - Private key cached in memory after first read (L2) - Fixed duplicate paymentOrderDao const declaration
Hox 文档目录
本目录集中存放项目说明、设计文档、协议资料、计划清单和原型文件,根目录只保留代码目录与仓库级配置。
目录结构
| 目录 | 内容 |
|---|---|
requirements/ |
产品说明、系统说明等需求来源文档 |
design/ |
业务流程、接口、数据库、后台、安全、测试等设计文档 |
protocols/ |
BLE、云端通信等协议文档;部分 IoT/MQTT 内容为历史设计参考 |
planning/ |
开发计划、当前进度交接、待确认事项、缺口清单 |
reviews/ |
代码与文档对比、评审和分析材料;旧评审可能是历史快照 |
prototypes/ |
小程序和管理后台原型文件 |
reference/ |
原始资料包、UI 导出页、截图等参考材料 |
当前入口
planning/PROGRESS.md— 当前实现和部署状态,以此为准deploy/tencent-cloud.md— 腾讯云函数、MySQL、COS 部署说明requirements/软件系统说明.docxrequirements/光子美容仪软件系统说明.docxdesign/01-BLE通信协议明细.mdprotocols/BLE协议冲突与问题清单.mdprotocols/协议简述-补充解析.mddesign/02-小程序业务流程与状态机.mdplanning/需求缺口清单.mdreviews/代码与设计文档对比分析.md— 历史阶段评审,不能代表当前实现
当前实现提示
- 当前后端是
server/下的腾讯云 HTTP 函数,不是微信云开发函数。 - 当前小程序通过 HTTPS API 调后端,不再使用
wx.cloud.callFunction()。 - 当前设备不直接连云端 MQTT,设备通信主路径是小程序 BLE 中转。
- 登录资料授权使用
wx.getUserProfile()官方弹窗;微信可能返回微信用户等脱敏资料。
语言
JavaScript
77.2%
Vue
22%
CSS
0.7%