全项目扫描修复: Docker数据卷修复+安全requireAdmin+12页SEO+API白名单+脚本超时+常量提取+假数据删除

This commit is contained in:
ZhuiGuangAI Dev
2026-06-12 17:27:47 +08:00
parent 464924aea0
commit 4c325c8699
454 changed files with 33647 additions and 980 deletions
+29
View File
@@ -0,0 +1,29 @@
#!/bin/bash
# Get CSRF token via curl
CSRF=$(curl -s -c /tmp/ck3.txt http://localhost:8301/api/auth/csrf | python3 -c "import sys,json; print(json.load(sys.stdin)['csrfToken'])")
echo "CSRF token: ${CSRF:0:20}..."
# Build POST data
python3 -c "
import json
with open('/tmp/ck3.txt') as f:
content = f.read()
# Extract csrf token from response
import subprocess
token = subprocess.check_output(['curl', '-s', 'http://localhost:8301/api/auth/csrf']).decode()
token = json.loads(token)['csrfToken']
print(f'csrfToken={token}&email=admin@zhuiguang.com&password=Admin123!')
" > /tmp/login_data3.txt
cat /tmp/login_data3.txt | head -c 40
echo "..."
# Login
curl -sv -b /tmp/ck3.txt -c /tmp/ck4.txt \
-X POST http://localhost:8301/api/auth/callback/credentials \
-H "Content-Type: application/x-www-form-urlencoded" \
-d @/tmp/login_data3.txt 2>&1 | grep -E "location:|HTTP/|set-cookie"
# Session
echo "=== Session ==="
curl -s -b /tmp/ck4.txt http://localhost:8301/api/auth/session