Repository navigation
支持网页配置密码长度及 URL 密码快速解锁 - #30
Merged
Merged
Conversation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
管理员现在可以在“通用配置 → 账号策略”中将账号密码、网页/说明书/文件分享密码及公开文件分享码长度配置到 4。保留默认 15/8/6,仅约束新建或修改操作,已有密码及分享码继续有效。旧配置读取、历史回滚与迁移校验和保持兼容。
网页
/p/.../?code=1234先从地址栏移除全部 code,再通过现有 POST 接口解锁。正确密码打开原页面,错误密码显示“密码不正确”并允许手动重试;保留其他查询参数和锚点。已有 Cookie、所有者及不可见页面均处理 URL 清理,原访问权限不变。应用日志脱敏,Nginx 模板补充 /p/ 日志保护。验证:115 项前端测试、7 项原分享浏览器回归、4 项自动解锁/404 Chromium 用例及生产前端构建通过;GitHub Actions 完整 Go 构建、隔离 MariaDB/Redis、HTTP/DAL、Python 客户端与 skill 回归通过。独立 Agent 两轮审查,发现的历史回滚与 404 清理问题已修复,最终审查通过。
提交 08ddbec 已部署至 pi,39 个文件的 SHA-256 清单校验通过。前后端 active、两个 HTTPS 入口健康及公开策略通过,动态配置版本保持不变;保留旧 release。pi 侧代理日志配置已应用,TLS 网关模板日志保护待取得网关 SSH 登录信息后应用。发布新策略后旧后端不能识别新增字段,回退须使用兼容版本,详见部署文档。