elky
579f2c7cc1
feat(security): harden gateway boundaries and usage policies
...
Consolidate subscription usage policy enforcement, privacy-safe persistence, and gateway security hardening into one reviewable change.
Includes bounded HTTP and execution envelopes, header and protocol guards, DNS and relay validation, authentication and secret projection hardening, secure backup/install paths, and regression coverage.
2026-09-04 03:45:52 +08:00
elky
8616fe6ee2
refactor(workspace): enforce layered crate boundaries
2026-07-15 23:47:19 +08:00
RWDai
e818443841
Add frontend audit admin auth semantics
2026-05-14 13:38:45 +08:00
fawney19 and LewisPen
c4bb6b8161
feat(auth): 重构认证系统,引入 session 会话管理
...
- 新增 user_sessions 数据库表及 Alembic 迁移
- 实现 SessionService 会话生命周期管理(创建/刷新/撤销/清理)
- 认证流程改用 refresh token cookie + access token 双令牌模式
- 前端实现自动静默刷新、跨标签页同步及设备指纹
- 用户设置页新增会话管理和密码修改功能
- 管理员用户管理新增强制登出和会话查看
- 密码策略增强,支持强度校验和泄露检测
- OAuth 登录流程适配新会话机制
- 新增完整的单元测试和 API 测试覆盖
Closes #232
Co-authored-by: LewisPen <[email protected] >
2026-03-17 16:34:09 +08:00
fawney19
cf2eee222e
refactor: 前端全面替换 any 为 unknown 并统一错误处理,后端用量记录补写请求头/体
...
- 前端 API 层、stores、conversation 解析器、组件全面替换 any 为 unknown/具体类型
- 错误处理统一使用 parseApiError/getErrorStatus 替代 err.response?.data?.detail 模式
- 后端 handler/TaskService/UsageLifecycle/StreamTracker 链路传递 request_headers/request_body
- streaming/pending 状态更新时可补写客户端和提供商的请求头及请求体
- 新增 TaskService 和 UsageService 相关测试
2026-02-22 00:43:41 +08:00
fawney19
427f173b38
feat: OAuth 绑定安全增强及限流配置优化
...
- 新增一次性绑定令牌机制,避免在 URL 中暴露 access_token
- 绑定流程改为新标签页打开,完成后自动刷新状态
- 放宽认证相关接口的 IP 限流配置
- 登录添加 429 限流错误的友好提示
- OAuth 绑定列表添加 Provider 图标显示
Close #106
2026-01-19 19:34:31 +08:00
RWDai
9bfb295238
feat: add ldap login
2026-01-02 16:17:24 +08:00
fawney19
f784106826
Initial commit
2025-12-10 20:52:44 +08:00