全面审查优化: 43项修复(安全/性能/可靠性)+ 文档更新
🔴 P0 安全: .env入gitignore, CSP/HSTS, Logo安全(5MB限制+SVG消毒+SHA256), middleware权限收紧(VIP不能访问admin), 发布去重, GitHub认证, 删除危险API, skill-discoverer绕过审核修复, prisma默认连接修复 🔴 P0 可靠性: deepseek/github超时重试, 脚本层DeepSeek保护, 脚本启动验证, OAuth竞态修复 🔴 P0 性能: skill-discoverer N+1优化(↓94%), 后台API分页限制, getUserStats聚合优化 🟡 P1: 分类动态加载, 星级字段统一, fetch-logos并发Bug修复, 批量发布冲突不删除, check-tools重试, 前端空指针修复(13处), logo-fetcher日志, rate-limit清理, 公开API缓存
This commit is contained in:
+27
-12
@@ -80,18 +80,33 @@ export const authOptions = {
|
||||
});
|
||||
|
||||
if (!existing) {
|
||||
const newUser = await prisma.user.create({
|
||||
data: {
|
||||
email: email || `github_${oauthId}@placeholder.com`,
|
||||
name: profile.name || user.name || null,
|
||||
avatarUrl: profile.avatar_url || user.image || null,
|
||||
oauthProvider: "github",
|
||||
oauthId,
|
||||
role: "user",
|
||||
},
|
||||
});
|
||||
user.id = newUser.id.toString();
|
||||
user.role = newUser.role;
|
||||
try {
|
||||
const newUser = await prisma.user.create({
|
||||
data: {
|
||||
email: email || `github_${oauthId}@placeholder.com`,
|
||||
name: profile.name || user.name || null,
|
||||
avatarUrl: profile.avatar_url || user.image || null,
|
||||
oauthProvider: "github",
|
||||
oauthId,
|
||||
role: "user",
|
||||
},
|
||||
});
|
||||
user.id = newUser.id.toString();
|
||||
user.role = newUser.role;
|
||||
} catch (createErr: unknown) {
|
||||
const ce = createErr as { code?: string };
|
||||
if (ce.code === "P2002") {
|
||||
const retry = await prisma.user.findFirst({
|
||||
where: { oauthProvider: "github", oauthId },
|
||||
});
|
||||
if (retry) {
|
||||
user.id = retry.id.toString();
|
||||
user.role = retry.role;
|
||||
return true;
|
||||
}
|
||||
}
|
||||
throw createErr;
|
||||
}
|
||||
} else {
|
||||
user.id = existing.id.toString();
|
||||
user.role = existing.role;
|
||||
|
||||
Reference in New Issue
Block a user