From 3cdc812f2b452bbcd0e523dab462786d2487eaa7 Mon Sep 17 00:00:00 2001 From: gr Date: Mon, 28 Sep 2026 14:53:47 +0800 Subject: [PATCH] =?UTF-8?q?;rgb:0000/0000/0000=20=E6=9B=B4=E6=96=B0?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- server/app/adminapi/controller/DesktopController.php | 2 +- server/app/common/enum/AdminTerminalEnum.php | 5 +++-- server/sql/1.9.20260928/add_wecom_rpa_remote_menu.sql | 2 +- server/tests/AdminDesktopAuthContractTest.php | 8 ++++++-- server/tests/AdminDesktopSessionBehaviorTest.php | 7 ++++--- 5 files changed, 15 insertions(+), 9 deletions(-) diff --git a/server/app/adminapi/controller/DesktopController.php b/server/app/adminapi/controller/DesktopController.php index caf3191d4..f0272a4b9 100644 --- a/server/app/adminapi/controller/DesktopController.php +++ b/server/app/adminapi/controller/DesktopController.php @@ -28,7 +28,7 @@ class DesktopController extends BaseAdminController if (empty($identity) || empty($identity['admin_id'])) { return $this->fail('登录已失效,请重新登录'); } - // 桌面软件(7)和客服后台代登的手机控制台(8)都用这个接口换身份; + // 桌面软件(7)和客服后台代登的手机控制台(9)都用这个接口换身份; // 返回真实终端,客服后台据此区分两种会话,桌面令牌不能冒充手机令牌。 $terminal = (int)($identity['terminal'] ?? 0); if (!in_array($terminal, AdminTerminalEnum::wecomRpaTerminals(), true)) { diff --git a/server/app/common/enum/AdminTerminalEnum.php b/server/app/common/enum/AdminTerminalEnum.php index ddd01aa1f..70fd2e33a 100755 --- a/server/app/common/enum/AdminTerminalEnum.php +++ b/server/app/common/enum/AdminTerminalEnum.php @@ -27,9 +27,10 @@ class AdminTerminalEnum const MOBILE = 2; // 企业微信客服桌面软件。与网页端分开保存会话,桌面登录不会顶掉浏览器登录。 const WECOM_RPA = 7; + // 8 已被 AI 浏览器(app/mcp/service/ConsoleService::TERMINAL)占用,不要复用。 // 企业微信客服手机远程控制台。由客服后台服务端代为登录,单独保存会话, - // 手机登录既不会顶掉桌面软件(7),也不会和网页后台(1)互踢。 - const WECOM_RPA_MOBILE = 8; + // 手机登录既不会顶掉桌面软件(7),也不会和网页后台(1)、AI 浏览器(8)互踢。 + const WECOM_RPA_MOBILE = 9; /** * 可以调用 /adminapi/desktop/session 换取客服身份的终端。 diff --git a/server/sql/1.9.20260928/add_wecom_rpa_remote_menu.sql b/server/sql/1.9.20260928/add_wecom_rpa_remote_menu.sql index 71f49e896..b5bcea240 100644 --- a/server/sql/1.9.20260928/add_wecom_rpa_remote_menu.sql +++ b/server/sql/1.9.20260928/add_wecom_rpa_remote_menu.sql @@ -1,4 +1,4 @@ --- 企业微信客服助手:手机远程控制台(终端 8)使用的菜单权限。 +-- 企业微信客服助手:手机远程控制台(终端 9)使用的菜单权限。 -- -- 新增一个不在侧边栏显示的目录“企微客服助手”,下挂四个按钮权限。客服后台只读取 -- /adminapi/desktop/session 返回的 permissions 做校验,ZYT 这边没有对应页面。 diff --git a/server/tests/AdminDesktopAuthContractTest.php b/server/tests/AdminDesktopAuthContractTest.php index 2192a0bd4..2f39d3b53 100644 --- a/server/tests/AdminDesktopAuthContractTest.php +++ b/server/tests/AdminDesktopAuthContractTest.php @@ -15,9 +15,13 @@ function adminDesktopExpect(bool $condition, string $message): void } adminDesktopExpect(AdminTerminalEnum::WECOM_RPA === 7, 'desktop admin terminal remains 7'); -adminDesktopExpect(AdminTerminalEnum::WECOM_RPA_MOBILE === 8, 'mobile console terminal is 8'); +adminDesktopExpect(AdminTerminalEnum::WECOM_RPA_MOBILE === 9, 'mobile console terminal is 9'); adminDesktopExpect( - AdminTerminalEnum::wecomRpaTerminals() === [7, 8], + AdminTerminalEnum::WECOM_RPA_MOBILE !== \app\mcp\service\ConsoleService::TERMINAL, + 'mobile console must not share the AI browser console terminal' +); +adminDesktopExpect( + AdminTerminalEnum::wecomRpaTerminals() === [7, 9], 'only the desktop and mobile console terminals may read the desktop session' ); diff --git a/server/tests/AdminDesktopSessionBehaviorTest.php b/server/tests/AdminDesktopSessionBehaviorTest.php index 3333c1a26..06d13bf20 100644 --- a/server/tests/AdminDesktopSessionBehaviorTest.php +++ b/server/tests/AdminDesktopSessionBehaviorTest.php @@ -91,10 +91,11 @@ namespace { Admin::$row['root'] = 0; desktopCheck($result['data']['terminal'] === 7, 'desktop token reports the desktop terminal'); - $mobile = $invoke(array_replace($valid, ['terminal' => 8])); - desktopCheck($mobile['code'] === 1, 'mobile console token (terminal 8) is accepted'); - desktopCheck($mobile['data']['terminal'] === 8, 'mobile console token reports terminal 8'); + $mobile = $invoke(array_replace($valid, ['terminal' => 9])); + desktopCheck($mobile['code'] === 1, 'mobile console token (terminal 9) is accepted'); + desktopCheck($mobile['data']['terminal'] === 9, 'mobile console token reports terminal 9'); desktopCheck($mobile['data']['user_id'] === 'admin:9', 'mobile console maps to the same tenant identity'); + desktopCheck($invoke(array_replace($valid, ['terminal' => 8]))['code'] === 0, 'AI browser console token rejected'); desktopCheck($invoke([])['code'] === 0, 'missing or expired cached identity rejected'); desktopCheck($invoke(array_replace($valid, ['terminal' => 1]))['code'] === 0, 'web token rejected');