复查修复(四): 独立审查发现的问题

- S1/S2: 会话锁改 RLock(持锁可重入调 _save_sessions);cookie 时间戳改整数+解析兼容(会话创建/验证往返已实测)
- M1: api_login 接入 verify_user(账号锁定/失败计数生效),DB 无用户时才回退 config 凭据
- M3+L5: handler _do_auth 统一入口加 IP 白名单检查;未知 auth_type 返回 401
- M4+L10: metrics 与无版本 /api/admin/ 加入受保护端点
- M6: debug 日志敏感头脱敏;main.py 不再打印 token 前缀
- M7: auth_token.txt / auth_sessions.json chmod 600
- M9: verify_user 统一错误消息防用户枚举
- M10: AdminAPI 复用共享 APIAuthManager(修复会话状态分裂)
- L7: check_auth 大小写不敏感匹配(防 /API/.. 大写绕过)
- L8: token_expires_at 显式 is not None 判断
- L11: verify_password 对非 bcrypt 哈希回退 PBKDF2(重写,修复 ValueError 分支不落回退的问题)
This commit is contained in:
HYC Fixer
2026-09-02 00:45:01 +08:00
parent f77a51247c
commit abdbec85a4
7 changed files with 807 additions and 754 deletions
+4 -3
View File
@@ -373,19 +373,20 @@ def main():
existing_token = f.read().strip()
if existing_token:
config['auth_token'] = existing_token
print(f" 已从文件加载 auth_token: {config['auth_token'][:16]}...")
print(" 已从文件加载 auth_token")
except Exception as e:
print(f" 警告: 读取 auth_token 失败: {e}")
# 如果没有现有 token,生成新的
if not existing_token:
config['auth_token'] = secrets.token_hex(32)
print(f" 已生成新的 auth_token: {config['auth_token'][:16]}...")
print(" 已生成新的 auth_token (保存在 auth_token.txt)")
# 保存新的 token 到文件
# 保存新的 token 到文件(收紧权限)
try:
with open(token_file, 'w') as f:
f.write(config['auth_token'])
os.chmod(token_file, 0o600)
print(f" 已保存 auth_token 到: {token_file}")
except Exception as e:
print(f" 警告: 保存 auth_token 失败: {e}")