更新
This commit is contained in:
@@ -27,11 +27,20 @@ class GrantService
|
||||
*/
|
||||
public static function issue(array $input, string $ip): array
|
||||
{
|
||||
$account = trim((string) ($input['account'] ?? ''));
|
||||
$password = (string) ($input['password'] ?? '');
|
||||
$client = substr(trim((string) ($input['client'] ?? 'xingzhi')), 0, 32) ?: 'xingzhi';
|
||||
$instance = substr(trim((string) ($input['client_instance'] ?? '')), 0, 64);
|
||||
$label = mb_substr(trim((string) ($input['label'] ?? '')), 0, 100);
|
||||
$admin = self::verifyPassword((string) ($input['account'] ?? ''), (string) ($input['password'] ?? ''), $ip, '再绑定 AI 助手');
|
||||
return self::issueFor($admin, $client, $instance, $label, $ip);
|
||||
}
|
||||
|
||||
/**
|
||||
* 账号密码校验(按 IP 限流、连续错误锁定)加各项门禁,通过返回后台账号。授权接口与登录行知(SsoService)共用。
|
||||
* $then:初始密码未修改时提示“请先在甄养堂后台修改初始密码,{$then}”。
|
||||
*/
|
||||
public static function verifyPassword(string $account, string $password, string $ip, string $then): Admin
|
||||
{
|
||||
$account = trim($account);
|
||||
if ($account === '' || $password === '' || mb_strlen($account) > 64 || strlen($password) > 128) {
|
||||
throw new McpException('请输入正确的账号和密码', 'invalid_request');
|
||||
}
|
||||
@@ -57,9 +66,16 @@ class GrantService
|
||||
|
||||
self::assertAdminUsable($admin);
|
||||
if (McpConfig::requirePasswordChanged() && array_key_exists('is_paw', $admin->getData()) && (int) $admin['is_paw'] !== 1) {
|
||||
throw new McpException('请先在甄养堂后台修改初始密码,再绑定 AI 助手', 'need_change_password');
|
||||
throw new McpException('请先在甄养堂后台修改初始密码,' . $then, 'need_change_password');
|
||||
}
|
||||
return $admin;
|
||||
}
|
||||
|
||||
/**
|
||||
* 给已通过校验的后台账号签发只读令牌;同一客户端实例的旧授权作废。
|
||||
*/
|
||||
public static function issueFor(Admin $admin, string $client, string $instance, string $label, string $ip): array
|
||||
{
|
||||
$now = time();
|
||||
$token = TokenService::generate();
|
||||
$expire = $now + McpConfig::tokenTtlDays() * 86400;
|
||||
@@ -197,8 +213,8 @@ class GrantService
|
||||
];
|
||||
}
|
||||
|
||||
/** 停用、企微强制绑定、AI 权限点:签发和每次调用都检查 */
|
||||
private static function assertAdminUsable(Admin $admin): void
|
||||
/** 停用、企微强制绑定、AI 权限点:签发、每次调用和登录行知都检查 */
|
||||
public static function assertAdminUsable(Admin $admin): void
|
||||
{
|
||||
if ((int) $admin['disable'] === 1) {
|
||||
throw new McpException('甄养堂账号已停用', 'disabled');
|
||||
|
||||
Reference in New Issue
Block a user