feat: OAuth 绑定安全增强及限流配置优化

- 新增一次性绑定令牌机制,避免在 URL 中暴露 access_token
- 绑定流程改为新标签页打开,完成后自动刷新状态
- 放宽认证相关接口的 IP 限流配置
- 登录添加 429 限流错误的友好提示
- OAuth 绑定列表添加 Provider 图标显示

Close #106
This commit is contained in:
fawney19
2026-01-19 19:34:31 +08:00
parent b53e3f14d6
commit 427f173b38
10 changed files with 259 additions and 42 deletions

View File

@@ -96,6 +96,11 @@ export const oauthApi = {
return response.data.links || []
},
async createBindToken(providerType: string): Promise<string> {
const response = await apiClient.post<{ bind_token: string }>(`/api/user/oauth/${providerType}/bind-token`)
return response.data.bind_token
},
async unbind(providerType: string): Promise<{ message: string }> {
const response = await apiClient.delete<{ message: string }>(`/api/user/oauth/${providerType}`)
return response.data

View File

@@ -242,17 +242,7 @@ import RegisterDialog from './RegisterDialog.vue'
import { authApi } from '@/api/auth'
import { oauthApi, type OAuthProviderInfo } from '@/api/oauth'
import { getApiUrl } from '@/utils/url'
// OAuth provider icons
const OAUTH_ICONS: Record<string, string> = {
linuxdo: `<svg viewBox="0 0 120 120" xmlns="http://www.w3.org/2000/svg"><clipPath id="ld"><circle cx="60" cy="60" r="47"/></clipPath><circle fill="#f0f0f0" cx="60" cy="60" r="50"/><rect fill="#1c1c1e" clip-path="url(#ld)" x="10" y="10" width="100" height="30"/><rect fill="#f0f0f0" clip-path="url(#ld)" x="10" y="40" width="100" height="40"/><rect fill="#ffb003" clip-path="url(#ld)" x="10" y="80" width="100" height="30"/></svg>`,
github: `<svg viewBox="0 0 24 24" fill="currentColor"><path d="M12 0c-6.626 0-12 5.373-12 12 0 5.302 3.438 9.8 8.207 11.387.599.111.793-.261.793-.577v-2.234c-3.338.726-4.033-1.416-4.033-1.416-.546-1.387-1.333-1.756-1.333-1.756-1.089-.745.083-.729.083-.729 1.205.084 1.839 1.237 1.839 1.237 1.07 1.834 2.807 1.304 3.492.997.107-.775.418-1.305.762-1.604-2.665-.305-5.467-1.334-5.467-5.931 0-1.311.469-2.381 1.236-3.221-.124-.303-.535-1.524.117-3.176 0 0 1.008-.322 3.301 1.23.957-.266 1.983-.399 3.003-.404 1.02.005 2.047.138 3.006.404 2.291-1.552 3.297-1.23 3.297-1.23.653 1.653.242 2.874.118 3.176.77.84 1.235 1.911 1.235 3.221 0 4.609-2.807 5.624-5.479 5.921.43.372.823 1.102.823 2.222v3.293c0 .319.192.694.801.576 4.765-1.589 8.199-6.086 8.199-11.386 0-6.627-5.373-12-12-12z"/></svg>`,
google: `<svg viewBox="0 0 24 24"><path fill="#4285F4" d="M22.56 12.25c0-.78-.07-1.53-.2-2.25H12v4.26h5.92c-.26 1.37-1.04 2.53-2.21 3.31v2.77h3.57c2.08-1.92 3.28-4.74 3.28-8.09z"/><path fill="#34A853" d="M12 23c2.97 0 5.46-.98 7.28-2.66l-3.57-2.77c-.98.66-2.23 1.06-3.71 1.06-2.86 0-5.29-1.93-6.16-4.53H2.18v2.84C3.99 20.53 7.7 23 12 23z"/><path fill="#FBBC05" d="M5.84 14.09c-.22-.66-.35-1.36-.35-2.09s.13-1.43.35-2.09V7.07H2.18C1.43 8.55 1 10.22 1 12s.43 3.45 1.18 4.93l2.85-2.22.81-.62z"/><path fill="#EA4335" d="M12 5.38c1.62 0 3.06.56 4.21 1.64l3.15-3.15C17.45 2.09 14.97 1 12 1 7.7 1 3.99 3.47 2.18 7.07l3.66 2.84c.87-2.6 3.3-4.53 6.16-4.53z"/></svg>`,
}
function getOAuthIcon(providerType: string): string {
return OAUTH_ICONS[providerType] || OAUTH_ICONS.github
}
import { getOAuthIcon } from '@/utils/oauth-icons'
const props = defineProps<{
modelValue: boolean

View File

@@ -50,6 +50,9 @@ export const useAuthStore = defineStore('auth', () => {
error.value = '邮箱或密码错误'
} else if (err.response?.status === 422) {
error.value = '请输入有效的邮箱地址'
} else if (err.response?.status === 429) {
// 限流错误,显示后端返回的具体信息
error.value = err.response?.data?.detail || '请求过于频繁,请稍后重试'
} else if (err.response?.status === 500) {
error.value = '服务器错误,请稍后重试'
} else {

View File

@@ -0,0 +1,13 @@
// OAuth provider icons (inline SVG)
export const OAUTH_ICONS: Record<string, string> = {
linuxdo: `<svg viewBox="0 0 120 120" xmlns="http://www.w3.org/2000/svg"><clipPath id="ld"><circle cx="60" cy="60" r="47"/></clipPath><circle fill="#f0f0f0" cx="60" cy="60" r="50"/><rect fill="#1c1c1e" clip-path="url(#ld)" x="10" y="10" width="100" height="30"/><rect fill="#f0f0f0" clip-path="url(#ld)" x="10" y="40" width="100" height="40"/><rect fill="#ffb003" clip-path="url(#ld)" x="10" y="80" width="100" height="30"/></svg>`,
github: `<svg viewBox="0 0 24 24" fill="currentColor"><path d="M12 0c-6.626 0-12 5.373-12 12 0 5.302 3.438 9.8 8.207 11.387.599.111.793-.261.793-.577v-2.234c-3.338.726-4.033-1.416-4.033-1.416-.546-1.387-1.333-1.756-1.333-1.756-1.089-.745.083-.729.083-.729 1.205.084 1.839 1.237 1.839 1.237 1.07 1.834 2.807 1.304 3.492.997.107-.775.418-1.305.762-1.604-2.665-.305-5.467-1.334-5.467-5.931 0-1.311.469-2.381 1.236-3.221-.124-.303-.535-1.524.117-3.176 0 0 1.008-.322 3.301 1.23.957-.266 1.983-.399 3.003-.404 1.02.005 2.047.138 3.006.404 2.291-1.552 3.297-1.23 3.297-1.23.653 1.653.242 2.874.118 3.176.77.84 1.235 1.911 1.235 3.221 0 4.609-2.807 5.624-5.479 5.921.43.372.823 1.102.823 2.222v3.293c0 .319.192.694.801.576 4.765-1.589 8.199-6.086 8.199-11.386 0-6.627-5.373-12-12-12z"/></svg>`,
google: `<svg viewBox="0 0 24 24"><path fill="#4285F4" d="M22.56 12.25c0-.78-.07-1.53-.2-2.25H12v4.26h5.92c-.26 1.37-1.04 2.53-2.21 3.31v2.77h3.57c2.08-1.92 3.28-4.74 3.28-8.09z"/><path fill="#34A853" d="M12 23c2.97 0 5.46-.98 7.28-2.66l-3.57-2.77c-.98.66-2.23 1.06-3.71 1.06-2.86 0-5.29-1.93-6.16-4.53H2.18v2.84C3.99 20.53 7.7 23 12 23z"/><path fill="#FBBC05" d="M5.84 14.09c-.22-.66-.35-1.36-.35-2.09s.13-1.43.35-2.09V7.07H2.18C1.43 8.55 1 10.22 1 12s.43 3.45 1.18 4.93l2.85-2.22.81-.62z"/><path fill="#EA4335" d="M12 5.38c1.62 0 3.06.56 4.21 1.64l3.15-3.15C17.45 2.09 14.97 1 12 1 7.7 1 3.99 3.47 2.18 7.07l3.66 2.84c.87-2.6 3.3-4.53 6.16-4.53z"/></svg>`,
}
// Default icon when provider type is not found
const DEFAULT_ICON = OAUTH_ICONS.github
export function getOAuthIcon(providerType: string): string {
return OAUTH_ICONS[providerType.toLowerCase()] || DEFAULT_ICON
}

View File

@@ -164,7 +164,7 @@
>
<div
:title="item.tooltip"
:class="['flex items-center gap-1', item.tooltip ? 'cursor-help' : '']"
class="flex items-center gap-1"
>
<span class="text-[10px] text-muted-foreground/60 w-4">{{ item.label }}</span>
<div class="w-12 h-1.5 bg-border rounded-full overflow-hidden">

View File

@@ -173,12 +173,18 @@
:key="link.provider_type"
class="flex items-center justify-between gap-3 rounded-lg border border-border bg-muted/30 p-4"
>
<div class="min-w-0 flex-1">
<div class="text-sm font-medium truncate">
{{ link.display_name }}
</div>
<div class="text-xs text-muted-foreground truncate">
{{ link.provider_username || link.provider_email || '已绑定' }}
<div class="flex items-center gap-3 min-w-0 flex-1">
<div
class="oauth-icon shrink-0"
v-html="getOAuthIcon(link.provider_type)"
/>
<div class="min-w-0">
<div class="text-sm font-medium truncate">
{{ link.display_name }}
</div>
<div class="text-xs text-muted-foreground truncate">
{{ link.provider_username || link.provider_email || '已绑定' }}
</div>
</div>
</div>
<Button
@@ -197,12 +203,18 @@
:key="p.provider_type"
class="flex items-center justify-between gap-3 rounded-lg border border-dashed border-border p-4 hover:border-primary/50 transition-colors"
>
<div class="min-w-0 flex-1">
<div class="text-sm font-medium truncate">
{{ p.display_name }}
</div>
<div class="text-xs text-muted-foreground">
未绑定
<div class="flex items-center gap-3 min-w-0 flex-1">
<div
class="oauth-icon shrink-0"
v-html="getOAuthIcon(p.provider_type)"
/>
<div class="min-w-0">
<div class="text-sm font-medium truncate">
{{ p.display_name }}
</div>
<div class="text-xs text-muted-foreground">
未绑定
</div>
</div>
</div>
<Button
@@ -432,6 +444,7 @@ import { useAuthStore } from '@/stores/auth'
import { meApi, type Profile } from '@/api/me'
import { authApi } from '@/api/auth'
import { oauthApi, type OAuthLinkInfo, type OAuthProviderInfo } from '@/api/oauth'
import { getOAuthIcon } from '@/utils/oauth-icons'
import { useDarkMode, type ThemeMode } from '@/composables/useDarkMode'
import Card from '@/components/ui/card.vue'
import Button from '@/components/ui/button.vue'
@@ -601,7 +614,42 @@ async function loadOAuthBindings() {
function handleBind(providerType: string) {
// 保存返回路径OAuth callback 会读取)
sessionStorage.setItem('redirectPath', route.fullPath)
window.location.href = getApiUrl(`/api/user/oauth/${providerType}/bind`)
// 先获取一次性绑定令牌,再在新标签页打开(避免在 URL 中暴露 access_token
oauthActionLoading.value = true
oauthApi.createBindToken(providerType)
.then((bindToken) => {
// getApiUrl 可能返回相对路径,需要拼接完整 URL
const basePath = getApiUrl(`/api/user/oauth/${providerType}/bind`)
const bindUrl = basePath.startsWith('http')
? new URL(basePath)
: new URL(basePath, window.location.origin)
bindUrl.searchParams.set('bind_token', bindToken)
// 新标签页打开 OAuth 流程
const newTab = window.open(bindUrl.toString(), '_blank')
// 监听标签页关闭,刷新绑定状态
if (newTab) {
const MAX_WAIT_MS = 10 * 60 * 1000 // 10 分钟超时
const startTime = Date.now()
const checkClosed = setInterval(() => {
if (newTab.closed || Date.now() - startTime > MAX_WAIT_MS) {
clearInterval(checkClosed)
oauthActionLoading.value = false
loadOAuthBindings()
}
}, 500)
} else {
// 被浏览器阻止,回退到当前页面跳转
oauthActionLoading.value = false
window.location.href = bindUrl.toString()
}
})
.catch((err) => {
oauthActionLoading.value = false
showError(getErrorMessage(err, '获取绑定令牌失败'))
})
}
async function handleUnbind(providerType: string) {
@@ -776,3 +824,15 @@ function formatDate(dateString?: string): string {
})
}
</script>
<style scoped>
.oauth-icon {
width: 24px;
height: 24px;
}
.oauth-icon :deep(svg) {
width: 100%;
height: 100%;
}
</style>