全项目扫描修复: Docker数据卷修复+安全requireAdmin+12页SEO+API白名单+脚本超时+常量提取+假数据删除
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
#!/bin/bash
|
||||
# Get CSRF token via curl
|
||||
CSRF=$(curl -s -c /tmp/ck3.txt http://localhost:8301/api/auth/csrf | python3 -c "import sys,json; print(json.load(sys.stdin)['csrfToken'])")
|
||||
echo "CSRF token: ${CSRF:0:20}..."
|
||||
|
||||
# Build POST data
|
||||
python3 -c "
|
||||
import json
|
||||
with open('/tmp/ck3.txt') as f:
|
||||
content = f.read()
|
||||
# Extract csrf token from response
|
||||
import subprocess
|
||||
token = subprocess.check_output(['curl', '-s', 'http://localhost:8301/api/auth/csrf']).decode()
|
||||
token = json.loads(token)['csrfToken']
|
||||
print(f'csrfToken={token}&email=admin@zhuiguang.com&password=Admin123!')
|
||||
" > /tmp/login_data3.txt
|
||||
|
||||
cat /tmp/login_data3.txt | head -c 40
|
||||
echo "..."
|
||||
|
||||
# Login
|
||||
curl -sv -b /tmp/ck3.txt -c /tmp/ck4.txt \
|
||||
-X POST http://localhost:8301/api/auth/callback/credentials \
|
||||
-H "Content-Type: application/x-www-form-urlencoded" \
|
||||
-d @/tmp/login_data3.txt 2>&1 | grep -E "location:|HTTP/|set-cookie"
|
||||
|
||||
# Session
|
||||
echo "=== Session ==="
|
||||
curl -s -b /tmp/ck4.txt http://localhost:8301/api/auth/session
|
||||
Reference in New Issue
Block a user