diff --git a/.workbuddy/memory/2026-08-31.md b/.workbuddy/memory/2026-08-31.md new file mode 100644 index 0000000..46b963a --- /dev/null +++ b/.workbuddy/memory/2026-08-31.md @@ -0,0 +1,29 @@ +# 2026-08-31 工作日志 + +## 账号体系:登录/注册/个人中心/硬门禁(全链路落地) +- 用户决策:①视觉沿用站点黑白极简编辑风;②硬门禁(未登录一碰筛选/翻页弹登录框);③仅预置内部账号,不开放注册。 +- 现状诊断:此前登录注册是半成品——前端 Login/Signup 链接与 `#auth-slot` 被注释、无 login/register 页面、api.ts 删了 `saveSession`;后端 `/auth/register|/login` 已下线、JWT 签发器被注释、`users` 表从未创建。 +- 后端:恢复 `jwt.Manager.Generate`;`user_repository` 加 `FindByAccount`(username|email,忽略 is_deleted);`auth_service` 加 `Login`(bcrypt 校验→签发);`auth_handler` 加 `Login`;路由挂 `POST /api/v1/auth/login`(公开)。`go build ./internal/...` 通过;seed 建 users 表 + 预置 admin,实测登录返回 token(180) 成功(LOGIN_OK)。 +- 前端:api.ts 恢复 `saveSession` + 新增 `login()`;routes 加 `account`;dictionary 加登录/账户文案;`Layout` 接回 `#auth-slot`(仅 Login 链接,去 Signup,footer 已登录显示 Hi+Logout);新建 `login.astro` / `account.astro`(en/cn,黑白极简,Alpine 表单);RunwayLooks/StreetSnaps 加 `requireLogin` 拦截 + 内嵌登录弹窗,首屏 init 不拦。 +- 验证:`npm run build` EXIT=0;后端 login 实测 LOGIN_OK;seed 创建 admin / admin@studio.local。 +- 默认账号 admin / Studio#2026!Admin(env `SEED_ADMIN_PASSWORD` 可改,务必改默认密码)。 + +## 收尾验证(17:40 续) +- 启动 Astro dev server(npx astro dev --background,http://localhost:4321),预览 /en/login 渲染正常。 +- 复查 account.astro:未登录重定向走 Alpine `init()` 客户端 `getUser()`(非服务端),无"服务端读不到 localStorage 导致永远重定向"的坑。 +- i18n 键核对齐全(login prompt / please log in / sign out / my collections / my history / coming soon 等均在 dictionary.ts)。 +- 后端现状::8090 已有实例在跑(端口被占,新 go run 起不来属预期)。实测登录 POST /api/v1/auth/login(account=admin)→ STATUS=200 返回合法 JWT + user{id:7,username:admin,email:admin@studio.local}。此前 curl 报 400 是 PowerShell 把密码里 `#`/`!` 吞掉所致,非代码问题。 +- 结论:登录/门禁全链路验证通过(构建过、页面渲染、API 200 签 token、BASE_API=localhost:8090 已就位)。硬门禁 UX 行为按 requireLogin 代码逻辑确认,未做浏览器点击自动化。 + +## JWT 双令牌 + 踢下线(19:35 续) +- 用户问"JWT 怎么做刷新 token、能不能踢下线"→ 落地双令牌方案:access 2h(无状态)+ refresh 30d(落库 refresh_tokens,SHA256 存哈希)。 +- 后端:`config.JWT` 加 `RefreshExpireHours`;`AuthService` 加 `Refresh/Logout/RevokeAllByRefresh`;新增 `RefreshTokenRepository` + `model.RefreshToken`;`dto.LoginResponse` 改 `{access_token,refresh_token,expires_in,user}`;handler 加 `Refresh/Logout/LogoutAll`;router 挂 `/auth/refresh|/logout|/logout-all`;`main` 装配 `refreshRepo`。建表 `scripts/sql/006_create_refresh_tokens.sql` + 迁移脚本 `scripts/migrate_refresh/main.go`(go run 建表成功)。 +- 前端 `api.ts`:saveSession 存 fa_token/fa_refresh/fa_user;新增 refreshSession、authedFetch(fetchMe 遇 401 静默刷新)、logout(吊销+清态)、logoutAll(踢下线+清态);Layout/account 登出改调 logout()。组件 login() 调用兼容(仅 await 成功)。 +- 验证:`go build -o bin/server.exe ./cmd/server` EXIT=0;杀旧 8090 进程、起新后端;Node 端到端脚本 ALL_OK:login(200,expires_in=7200) → refresh(200) → logout-all(revoked:1) → 再 refresh=401。前端 `npm run build` EXIT=0。 +- 说明:refresh 复用不轮换;"普通踢"=吊销 refresh,已签发 access 2h 内仍有效(非即时);即时吊销需另加 token_version,未做。默认账号仍为 admin/Studio#2026!Admin。 + +## 登录互斥(同账号单会话,19:59 续) +- 用户澄清动机:做踢下线是因为"不希望同一账号被不同的人同时登录"。原 `Login` 只新发 refresh、不吊销旧的,导致同账号可并存多条会话,与诉求相反。 +- 改动 `auth_service.Login`:签发前先 `RevokeAllByUser(userID)` 吊销该用户全部既有 refresh,仅保留本次新签发的这一条 → 同账号同一时刻只有一条活性会话。 +- 重建 `bin/server.exe` EXIT=0;重启 :8090(杀旧进程 PID 7368 → 起新 PID 1776)。Node 互斥测试 MUTEX_OK:同账号二次 login 后,首次 refresh=401(被顶掉)、二次 refresh=200(有效)。 +- 残留边界:redis/access 为无状态 JWT(2h),被顶掉的旧会话其已签发的 access 在 2h 内仍有效,到期后才被弹回登录;要访问令牌即时失效需 token_version 方案(未做)。logout-all 手动端点保留(可用于"登出其他设备"按钮/管理员强踢)。 diff --git a/.workbuddy/memory/MEMORY.md b/.workbuddy/memory/MEMORY.md index c39fbf3..fc63bf2 100644 --- a/.workbuddy/memory/MEMORY.md +++ b/.workbuddy/memory/MEMORY.md @@ -46,5 +46,24 @@ - **详情页统一 `/item`**:走秀 lookbook 与街拍详情全部收口到 `src/pages/{locale}/item/[id].astro`,服务端按 `getSsrArticle(id)` → `getSsrStreetSnap(id)` 回落渲染(先 runway 后 street)。`ROUTES.article` 与 `ROUTES.streetSnap` 均指向 `/item/${id}`(`runway-looks/[id]`、`street-snaps/[id]`、`article.astro(?id=)` 等旧详情页均已删除)。列表页回链仍指向列表 `/runway-looks`、`/street-snaps`。 - **列表页共享资源**:两个列表组件(RunwayLooks / StreetSnaps)同构,抽成 `src/styles/look-grid.css`(卡片/网格/分页/侧栏/spinner/骨架/动画)+ `src/lib/looks-grid.ts`(`SPIN_SVG`、`makeCardSlots(images,count,opts)`、`buildPageList(total,cur)`);品牌筛选弹窗 `src/components/BrandModal.astro`(仅 RunwayLooks 用,`openBrandModal/confirmBrandModal` 等由页面脚本驱动)。卡片标记因在 Alpine `x-for` 内客户端渲染,**不能**提成 Astro 组件。 +## 账号体系(2026-08-31) +- 决策:仅预置内部账号,**不开放注册**(前端无注册入口,避免垃圾账号/撞库)。账号由 seed 脚本预置。 +- 默认内部账号:`admin` / `admin@studio.local` / 密码 `Studio#2026!Admin`(env `SEED_ADMIN_PASSWORD` 可覆盖;**务必改默认密码**)。 +- **双令牌 JWT(2026-08-31 落地)**:access token 短命(默认 **2h**,无状态 JWT,仅前端请求用)+ refresh token 长命(默认 **30d**,随机串只存 SHA256 哈希落库 `refresh_tokens`)。纯无状态 JWT 无法吊销,故 refresh 必须落库才能做踢下线。 + - 接口(均在 `/api/v1/auth/`,除 /me 外均公开、无需 Bearer): + - `POST /login` → `{access_token, refresh_token, expires_in(秒), user}`(login 返回结构已从 `{token,user}` 改为双 token,前端已同步)。**登录即顶旧会话**:签发前先吊销该用户全部既有 refresh,保证同账号同一时刻只有一条活性会话(用户明确诉求:不希望同一账号被不同人同时登录)。 + - `POST /refresh` → `{access_token, expires_in}`(用 refresh_token 换 access;**refresh 复用、不轮换**)。 + - `POST /logout` → `{ok:true}`(吊销当前 refresh,单设备登出)。 + - `POST /logout-all` → `{revoked:N}`(按 refresh 反查用户,吊销其全部 refresh = **踢下线/全设备登出**)。 + - `GET /me`(Bearer 校验)保留。 + - 后端改动:`config.JWT` 新增 `RefreshExpireHours`(env `JWT_REFRESH_EXPIRE_HOURS`);`AuthService` 加 `Refresh/Logout/RevokeAllByRefresh`;`RefreshTokenRepository`(Create/FindByHash/Revoke/RevokeAllByUser/DeleteExpired);`model.RefreshToken`(gorm 表 `refresh_tokens`)。 + - 建表:`scripts/sql/006_create_refresh_tokens.sql`;一键建表脚本 `scripts/migrate_refresh/main.go`(`go run ./scripts/migrate_refresh`,DSN 默认 root:root@127.0.0.1:3306/db_dev,可由 `DB_DSN` 覆盖)。 + - 前端 `api.ts`(2026-08-31 改):`saveSession(access,refresh,user)` 存 `fa_token`/`fa_refresh`/`fa_user`;新增 `refreshSession()`(POST /auth/refresh,刷新 access、复用 refresh);`fetchMe()` 走 `authedFetch`(遇 401 静默 refresh 一次再重试);`logout()`(吊销当前 refresh 再清本地)、`logoutAll()`(踢下线再清本地)。`clearSession()` 一并清三键。 + - 踢下线效果:**普通踢**=吊销 refresh,已签发 access 在 2h 窗口内仍有效,到期后才被弹回登录(非即时,内部工具足够);未做 `token_version` 即时吊销方案(如需访问令牌即时失效再加 `users.token_version` 并在 `middleware.Auth` 比对)。 + - 验证(2026-08-31):`go build -o bin/server.exe ./cmd/server` EXIT=0;端到端 Node 脚本确认 login→refresh→logout-all(revoked:1)→再 refresh=401(ALL_OK);同账号二次 login 后首次 refresh 返回 401、二次 refresh 返回 200(MUTEX_OK,互斥登录生效)。前端 `npm run build` EXIT=0。 +- **硬门禁(用户拍板)**:RunwayLooks / StreetSnaps 的筛选与翻页入口调 `requireLogin()`,未登录则弹出内嵌登录表单(`showLoginModal`);登录成功后 `loadPage(1)` 按当前筛选刷新。首屏 `init()` 的 `loadPage(1)` 不拦(保证未登录能看到第一页)。 +- 页面:`src/pages/{en,cn}/login.astro`(黑白极简风,Alpine 表单,登录后跳 `?redirect=` 或 /account)、`account.astro`(资料+登出+收藏/历史占位,未登录跳 /login?redirect=/account)。 +- 视觉:登录/个人中心沿用站点黑白极简编辑风(monospace + 细线下划线输入框 + Georgia 衬线大标题 + hover:opacity-60)。 + ## 部署(Docker + Gitea Actions) - 交付文件:前端 Dockerfile / nginx.conf / docker-compose.yml / deploy.sh / .gitea/workflows/deploy.yml / .env.example / DEPLOY.md;后端 Dockerfile。nginx 拦截 `/api/v1/ssg/` 404;健康检查 `/api/v1/public/brands`。 diff --git a/_tmp_build.log b/_tmp_build.log index f0efecc..efb3cf3 100644 --- a/_tmp_build.log +++ b/_tmp_build.log @@ -9,30 +9,34 @@ > test@0.0.1 build > astro build -19:01:18 [@astrojs/node] Enabling sessions with filesystem storage -19:01:18 [types] Generated 92ms -19:01:18 [build] output: "static" -19:01:18 [build] mode: "server" -19:01:18 [build] directory: D:\project\frontend_v2\dist\ -19:01:18 [build] adapter: @astrojs/node -19:01:18 [build] Collecting build info... -19:01:18 [build] ✓ Completed in 191ms. -19:01:18 [build] Building server entrypoints... -19:01:19 [vite] ✓ built in 802ms -19:01:19 [vite] ✓ built in 392ms -19:01:20 [vite] ✓ built in 282ms +17:37:35 [@astrojs/node] Enabling sessions with filesystem storage +17:37:35 [types] Generated 106ms +17:37:35 [build] output: "static" +17:37:35 [build] mode: "server" +17:37:35 [build] directory: D:\project\frontend_v2\dist\ +17:37:35 [build] adapter: @astrojs/node +17:37:35 [build] Collecting build info... +17:37:35 [build] ✓ Completed in 207ms. +17:37:35 [build] Building server entrypoints... +17:37:37 [vite] ✓ built in 1.65s +17:37:38 [vite] ✓ built in 865ms +17:37:39 [vite] ✓ built in 676ms  prerendering static routes  -19:01:20 ├─ /cn/runway-looks/index.html (+48ms) -19:01:20 ├─ /cn/street-snaps/index.html (+9ms) -19:01:20 ├─ /cn/index.html (+35ms) -19:01:20 ├─ /en/runway-looks/index.html (+15ms) -19:01:20 ├─ /en/street-snaps/index.html (+7ms) -19:01:20 ├─ /en/index.html (+24ms) -19:01:20 ├─ /index.html (+20ms) -19:01:20 ✓ Completed in 183ms. +17:37:39 ├─ /cn/account/index.html (+67ms) +17:37:39 ├─ /cn/login/index.html (+16ms) +17:37:39 ├─ /cn/runway-looks/index.html (+344ms) +17:37:39 ├─ /cn/street-snaps/index.html (+22ms) +17:37:39 ├─ /cn/index.html (+75ms) +17:37:39 ├─ /en/account/index.html (+18ms) +17:37:39 ├─ /en/login/index.html (+12ms) +17:37:39 ├─ /en/runway-looks/index.html (+23ms) +17:37:39 ├─ /en/street-snaps/index.html (+19ms) +17:37:39 ├─ /en/index.html (+47ms) +17:37:39 ├─ /index.html (+41ms) +17:37:39 ✓ Completed in 746ms.  -19:01:20 [build] Rearranging server assets... -19:01:20 [build] ✓ Completed in 1.78s. -19:01:20 [build] Server built in 1.98s -19:01:20 [build] Complete! +17:37:39 [build] Rearranging server assets... +17:37:39 [build] ✓ Completed in 4.10s. +17:37:39 [build] Server built in 4.33s +17:37:39 [build] Complete! diff --git a/src/components/RunwayLooks.astro b/src/components/RunwayLooks.astro index df9c669..5a4a4bd 100644 --- a/src/components/RunwayLooks.astro +++ b/src/components/RunwayLooks.astro @@ -8,6 +8,15 @@ import "@/styles/look-grid.css" const { locale, t, getRelativeLocaleUrl } = getI18n(Astro) +// 登录门禁弹窗文案 +const loginModalTitle = t('login') +const loginModalPrompt = t('login to continue') +const loginModalAccountLabel = t('username or email') +const loginModalPasswordLabel = t('password') +const loginModalSubmitLabel = t('login') +const loginModalClose = t('close') +const loginModalFail = t('login failed') + // 热门品牌:走 SSG 专属接口 /api/v1/ssg/brands/hot,后端固定返回热度前 30 个、按热度顺序排列。 // 侧栏 filter 展示前 10 个(模板内 slice(0,10)),品牌弹窗 HOT 标签展示全部 30 个。 // 接口不可用时回落假数据先看效果。 @@ -64,7 +73,7 @@ const seasonOptions: { value: string; label: string }[] = [ --- -
+
@@ -252,7 +261,31 @@ const seasonOptions: { value: string; label: string }[] = [ - + +
+
+
+

{loginModalTitle}

+ +
+

{loginModalPrompt}

+
+
+ + +
+
+ + +
+

+ +
+
+
@@ -262,7 +295,7 @@ const seasonOptions: { value: string; label: string }[] = [ @@ -217,7 +253,7 @@ const cityOptions: { value: string; label: string }[] = [ diff --git a/src/pages/cn/login.astro b/src/pages/cn/login.astro new file mode 100644 index 0000000..2f72b34 --- /dev/null +++ b/src/pages/cn/login.astro @@ -0,0 +1,69 @@ +--- +import Layout from '@/layouts/Layout.astro' +import { getI18n } from '@/i18n/utils' +const { locale, t } = getI18n(Astro) +const loginLabel = t('login') +const promptLabel = t('login prompt') +const accountLabel = t('username or email') +const passwordLabel = t('password') +const failLabel = t('login failed') +--- + +
+

{loginLabel}

+

{promptLabel}

+ +
+
+ + +
+
+ + +
+ +

+ + +
+
+
+ + diff --git a/src/pages/en/account.astro b/src/pages/en/account.astro new file mode 100644 index 0000000..9435a8d --- /dev/null +++ b/src/pages/en/account.astro @@ -0,0 +1,74 @@ +--- +import Layout from '@/layouts/Layout.astro' +import { getI18n } from '@/i18n/utils' +import { href, ROUTES } from '@/lib/routes' +const { locale, t } = getI18n(Astro) +const titleLabel = t('my account') +const pleaseLabel = t('please log in') +const loginLabel = t('login') +const accountLabel = t('account') +const emailLabel = t('email') +const signOutLabel = t('sign out') +const collectionsLabel = t('my collections') +const historyLabel = t('my history') +const soonLabel = t('coming soon') +--- + +
+

{titleLabel}

+ +