文件
jw-beauty/miniprogram/services/command-sync.js
T
Guoguo b80e872600 fix: comprehensive security, quality and consistency fixes
Server:
- Block startup with default JWT secrets in production
- Make subscription verify admin-only (no payment integration yet)
- Add device ownership validation on command/result, event, treatment/sync
- Remove admin token from request body fallback
- Add pageParams boundary protection (pageSize capped at 100)
- Fix COS getObjectUrl to use callback-based Promise
- Add settings key whitelist matching frontend fields
- Add user existence check before subscription creation
- Fix firmware always returning has_update:true
- Replace hardcoded trial subscription with actual DB query
- Extract shared utilities (limitClause, toMysqlDate, formatDate)

Miniprogram:
- Replace fake PD random data with placeholder
- Mark client-timer treatment completions with source field
- Disable mock.js
- Fix BLE listener leaks (save refs, cleanup in onUnload)
- Fix ble.off clearing all listeners (pass specific callback)
- Add BLE disconnect detection via onBLEConnectionStateChange
- Fix subscription status type consistency (number not string)
- Fix scan callback accumulation in ble.js
- Fix history stats accumulation across pages
- Fix subscribe-success/treatment-done hardcoded values
- Fix profile subscription view logic
- Replace purchase flow with admin-contact modal
- Add error logging in command-sync report

Admin console:
- Fix AdminLayout logout (require->import, logout->clearToken)
- Remove all mock data from production request.js
- Replace dashboard fake data with real API calls
- Replace monthly_revenue with subscription_count
- Fix subscription stats fallback (|| -> ??)
- Add token expiry tracking (7 days)
- Unify device status map and subscription status text
- Fix user page record link navigation
- Fix subscription createForm.user_id type handling
- Add error feedback in all empty catch blocks
- Remove unused remember checkbox and uview-plus dependency
- Extract common CSS to shared stylesheet (-900 lines)
- Extract formatDate to shared utils/format.js
- Show real admin name in layout header
2026-04-28 08:46:59 -07:00

69 行
1.9 KiB
JavaScript

var ble = require('./ble')
var http = require('../utils/request')
var syncing = false
function commandPayload(command) {
return command.payload || {}
}
function execute(command) {
var payload = commandPayload(command)
switch (Number(command.opcode)) {
case ble.CMD.SET_PARAMS:
return ble.setParams({
region_mask: payload.region_mask,
wavelength: payload.wavelength,
brightness: payload.brightness,
duration_ms: payload.duration_ms,
mode: payload.mode
})
case ble.CMD.START:
return ble.startTreatment(payload.region_mask)
case ble.CMD.STOP:
return ble.stopTreatment()
case ble.CMD.QUERY_STATUS:
return ble.queryStatus()
default:
return Promise.reject({ error_code: 0xFE, error_msg: 'unsupported opcode' })
}
}
function report(command, success, result) {
return http.post('/api/v1/device/command/result', {
command_id: command.seq || command.command_id,
seq: command.seq || command.command_id,
success: success,
opcode: command.opcode,
result: result || null
}).catch(function (err) { console.error('[command-sync] report failed:', err) })
}
function runOne(command) {
return execute(command).then(function (result) {
return report(command, true, result)
}).catch(function (err) {
return report(command, false, err)
})
}
function sync(deviceId) {
if (syncing || !deviceId || !ble.isConnected()) return Promise.resolve()
syncing = true
return http.get('/api/v1/device/command/pending', { device_id: deviceId }).then(function (data) {
var chain = Promise.resolve()
var commands = data.commands || []
commands.forEach(function (command) {
chain = chain.then(function () { return runOne(command) })
})
return chain
}).catch(function () {}).then(function () {
syncing = false
})
}
module.exports = {
sync: sync,
execute: execute
}