全项目扫描修复: Docker数据卷修复+安全requireAdmin+12页SEO+API白名单+脚本超时+常量提取+假数据删除

This commit is contained in:
ZhuiGuangAI Dev
2026-06-12 17:27:47 +08:00
parent 464924aea0
commit 4c325c8699
454 changed files with 33647 additions and 980 deletions
+44
View File
@@ -0,0 +1,44 @@
import urllib.request, json, http.cookiejar
class NoRedirectHandler(urllib.request.HTTPRedirectHandler):
def redirect_request(self, req, fp, code, msg, headers, newurl):
return None
http_error_301 = http_error_302 = http_error_303 = http_error_307 = lambda self, req, fp, code, msg, headers: fp
cj = http.cookiejar.CookieJar()
opener = urllib.request.build_opener(
urllib.request.HTTPCookieProcessor(cj),
NoRedirectHandler
)
# Get CSRF
csrf = json.loads(opener.open('http://localhost:8301/api/auth/csrf').read())
print('CSRF:', csrf['csrfToken'][:30])
# Login
data = urllib.parse.urlencode({
'csrfToken': csrf['csrfToken'],
'email': 'admin@zhuiguang.com',
'password': 'Admin123!'
}).encode()
req = urllib.request.Request('http://localhost:8301/api/auth/callback/credentials', data=data, method='POST')
resp = opener.open(req)
print('Status:', resp.status)
loc = resp.headers.get('location', 'NONE')
print('Location:', loc)
if 'error=CredentialsSignin' in (loc or ''):
print('>>> FAIL: Invalid credentials')
elif 'csrf=true' in (loc or ''):
print('>>> FAIL: CSRF token mismatch')
elif '/api/auth/signin' not in (loc or ''):
print('>>> SUCCESS: Login accepted, redirecting to caller page')
# Session
opener2 = urllib.request.build_opener(urllib.request.HTTPCookieProcessor(cj))
sess = json.loads(opener2.open('http://localhost:8301/api/auth/session').read())
if sess.get('user'):
print('Session OK:', sess['user'].get('email'), '| role:', sess['user'].get('role'))
else:
print('Session EMPTY - user not logged in')