fix: restore security hardening compatibility and validation

Restore authorized rule reveal, explicit full HTTP capture and retention, video task business fields, and valid payment URLs. Add opt-in credential preservation for trusted recovery, fix frontend type contracts and async races, and eliminate PostgreSQL test fixture resource leaks. Document audit coverage and successful fmt and CI-scoped Clippy checks.
This commit is contained in:
elky
2026-09-07 21:14:27 +08:00
parent a5c3699ae9
commit a90d564931
191 changed files with 6785 additions and 1643 deletions
+5 -3
View File
@@ -739,7 +739,7 @@ function editUser(user: User) {
editingUser.value = {
id: user.id,
username: user.username,
email: user.email,
email: user.email ?? '',
unlimited: user.unlimited,
role: user.role,
is_active: user.is_active,
@@ -1120,6 +1120,8 @@ async function closeNewApiKeyDialog() {
}
async function deleteApiKey(apiKey: ApiKey) {
const user = selectedUser.value
if (!user) return
const confirmed = await confirmDanger(
locale.value === 'en-US'
? `Delete this API key?\n\n${apiKey.key_display || '****'}\n\nThis action cannot be undone.`
@@ -1130,8 +1132,8 @@ async function deleteApiKey(apiKey: ApiKey) {
if (!confirmed) return
try {
await usersStore.deleteApiKey(selectedUser.value.id, apiKey.id)
await loadUserApiKeys(selectedUser.value.id)
await usersStore.deleteApiKey(user.id, apiKey.id)
if (selectedUser.value?.id === user.id) await loadUserApiKeys(user.id)
success(legacyT('API Key已删除'))
} catch (err: unknown) {
error(localizedApiError(err, '未知错误'), legacyT('删除 API Key 失败'))